Carrier-Perturbation Responses: An Alternative Basis for Generalizable AI-Generated Image Detection
Abstract
Existing generated image detectors typically infer image authenticity from features extracted from the image itself. However, such features may vary substantially across scenes, limiting generalization from unseen domains. Our preliminary observations show that, under the same controlled perturbations, real and generated images exhibit different feature-change distributions in the representation space of a frozen visual foundation model, while responses from same-class images remain relatively consistent across scenes. This motivates us to investigate perturbation-induced feature changes as an alternative basis for authenticity assessment. To this end, we propose Carrier-Perturbation Responses (CPR), which treats each image as a carrier and characterizes its response to a controlled perturbation through the feature change between the original and perturbed images. Since some perturbations may produce responses dominated by the perturbation rule itself or responses too weak for discrimination, we further develop an ANOVA-inspired selection criterion that favors perturbations with strong carrier–perturbation interactions, limited rule-induced effects, and sufficient response magnitude. Together, these designs shift the detection basis from scene-dependent appearance features toward perturbation-induced response patterns, providing complementary evidence for authenticity assessment across unseen scenes. Across four in-the-wild datasets, CPR improves the average real-image accuracy by 3.3 percentage points to 96.7% and the average overall accuracy by 2.1 percentage points to 95.4%. Our code is available at https://anonymous.4open.science/r/CPR-F211.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.