Forensic Proxy Generation: Adapting Deepfake Detectors to Black-Box Generators
Abstract
As commercial image generators rapidly evolve, deepfake detectors must continually adapt to the images they produce, typically through retraining or fine-tuning on newly generated images. However, collecting a large-scale dataset from each new generator can be impractical when only black-box access is available and query costs or usage restrictions limit extensive collection or downstream reuse. To this end, we introduce Forensic Proxy Generation (FPG), a two-stage framework that converts limited black-box access to a target generator into reusable proxy images for detector training. First, we treat the target generator as a teacher and distill teacher-relevant generative characteristics into a student generator. Second, we refine student-generated images through detector-response alignment. Under our problem setting, the resulting proxy images can be used for detector training while reducing the need for large-scale teacher querying and direct reuse of teacher-generated images. Across six target generators, FPG improves detection of teacher-generated images and balanced real–fake data without directly using teacher outputs for detector training. Under limited access, FPG expands a small number of teacher queries into proxy data that can outperform direct training on teacher outputs. These results show that FPG effectively adapts deepfake detectors to new generators under access and reuse constraints. The code is available at https://anonymous.4open.science/r/hci-code-3B8E.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.