GENERATOR FINGERPRINT ISOLATION: ADDRESSING BLIND SPOTS IN AI-GENERATED IMAGE DETECTION
Abstract
AI-generated image detection is an open-set generalization problem: detectors trained on a limited set of generators may fail to generalize to unseen generators, resulting in generator-specific blind spots. A common response is to adapt the detector using samples from a missed generator, but this modifies its decision function and may affect generators it already detects reliably. We instead ask whether such blind spots can be repaired by adding generator-specific evidence while preserving the original detector. We propose Generator Fingerprint Isolation (GFI), a training-free framework that augments a frozen detector with such evidence. GFI exploits an empirical property of pretrained representations such as CLIP and DINO: the principal components that account for most variation among real-image embeddings can be removed without eliminating generator-discriminative signal. Across the blind-spot generators considered in our evaluation, removing the principal components accounting for 95% of real-image variance yields a residual space that preserves 78.8% of the measured generator-discriminative signal. GFI uses this residual space to extract a generator-specific fingerprint for each blind-spot generator. At inference, alignment with the fingerprint provides generator-specific evidence that is fused with frozen detector's prediction. Fingerprints can be registered independently as new blind-spot generators are encountered. We evaluate GFI on AIGCDetectBench, with 17 GAN, diffusion, and commercial generators, across three off-the-shelf modern detectors—DDA, Effort, and SPAI. For each detector, we identify its own blind-spot generators and repair them using generator-specific fingerprints. Across these targeted generators, GFI improves mean AUC from 0.827 to 0.972 for DDA, 0.747 to 0.914 for Effort, and 0.762 to 0.900 for SPAI, while also substantially reducing FPR@95% Recall. AUC improvements are statistically significant for every detector on its identified blind-spot generators under paired DeLong tests. For generators not targeted for repair, GFI shows no systematic degradation. These results demonstrate that generator-specific evidence can repair targeted blind spots while preserving the detector.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.