Search papers, labs, and topics across Lattice.
This paper introduces ARMOR++, a multi-agent framework that enhances the transferability of attacks on deepfake detectors by integrating semantic awareness through a Vision-Language Model (VLM) and a Large Language Model (LLM) for orchestrating attack primitives. The framework addresses the limitations of existing transfer attacks, which often fail under no-query constraints and lack semantic context, by employing a diverse set of perturbation strategies. Evaluation on the AADD-2025 benchmark reveals that ARMOR++ achieves a significant increase in Attack Success Rate (ASR) compared to both agentic and non-agentic baselines, highlighting the framework's effectiveness in exploiting vulnerabilities in deepfake detection systems.
ARMOR++ reveals that leveraging semantic priors can dramatically enhance the effectiveness of adversarial attacks on deepfake detectors, achieving unprecedented transferability across diverse models.
The reliability of deepfake detectors frequently degrades under black-box adversarial transfer, as these models often rely on fragile, architecture-dependent forensic cues. Existing transfer attacks often lack semantic awareness and struggle to maintain effectiveness under strict no-query constraints, particularly when perturbations are transferred from convolutional surrogates to transformer-based targets. To address these limitations, this paper introduces ARMOR++, a robust multi-agent framework designed for high-transferability deepfake evasion. The framework leverages the Qwen2.5-VL Vision-Language Model (VLM) to supply spatial semantic priors, while the Qwen3 Large Language Model (LLM) orchestrates primitive selection, adaptive hyperparameter reparameterization, and entropy-regularized perturbation mixing. By integrating five complementary primitives, spanning dense optimization, saliency-based methods, spatial transformations, frequency-domain perturbations, and block-structured modifications, ARMOR++ effectively targets heterogeneous inductive biases. Rigorous evaluation on the AADD-2025 benchmark demonstrates that ARMOR++ significantly outperforms existing agentic and non-agentic baselines across both low- and high-quality image regimes. Statistical analysis confirms a substantial gain in blind-target Attack Success Rate (ASR) over the state-of-the-art agentic baseline, with further performance advantages evidenced against non-agentic benchmarks and under robust defensive configurations. These findings highlight a significant residual reliability gap in current deepfake detector deployments and demonstrate the efficacy of agentic orchestration in identifying latent vulnerabilities.