Search papers, labs, and topics across Lattice.
This paper introduces TIGA, a novel framework that generates detector-evasive images within a single diffusion sampling trajectory, circumventing the limitations of existing evasion methods that rely on pre-generated images or detector-aware training. By aggregating gradients from multiple white-box surrogate detectors and employing an anisotropic directional search, TIGA effectively steers the latent trajectory of the Denoising Diffusion Implicit Model (DDIM) to produce adversarial images that evade black-box AIGC detectors. Experimental results demonstrate TIGA's superior performance in terms of black-box attack efficacy, transferability, and robustness against post-processing, all while maintaining high perceptual quality without the need for source images or retraining the diffusion model.
TIGA can generate high-quality, detector-evasive images on-the-fly, bypassing the need for source images or model retraining, which could revolutionize evasion strategies against AIGC detectors.
Recent diffusion models have achieved remarkable realism in facial image synthesis, posing growing challenges to artificial intelligence-generated content (AIGC) forensic detectors.Existing evasion methods typically perturb pre-generated images or require detector-aware training, which may introduce visible or statistical artifacts and limit applicability when the diffusion model must remain frozen and the target detector is accessible only through black-box queries. We propose Trajectory-Injected Generative Attack (TIGA), a source-image-free and training free framework that generates detector-evasive images within a single diffusion sampling trajectory. TIGA steers the latent Denoising Diffusion Implicit Model (DDIM) trajectory so that adversarial properties emerge during generation rather than being added afterward. TIGA first aggregates gradients from multiple white-box surrogate detectors to form a transferable, sign-aware prior, and then performs anisotropic directional search with symmetric finite-difference queries to estimate the black-box target response. The estimated directions are stabilized by decayed momentum and injected according to the DDIM noise schedule, with frequency-domain reshaping to suppress high frequency artifacts. Experiments on surrogate and unseen specialized forensic detectors show that TIGA achieves strong blackbox attack performance, transferability, and high robustness under common post-processing operations without source images or diffusion-model retraining, while preserving high perceptual quality.