Paper deep dive
ISPCloak: Weaponizing ISP for Optimization-Free Physical Camouflage against Deepfake Detectors
Jiale Zhao, Jiajun Wan, Lei Tang, Ye Qin, Kebing Jin, Jinghui Qin
Intelligence
Status: succeeded | Model: Gemma-4-26B-A4B | Prompt: intel-v1 | Confidence: 91%
Last extracted: 7/28/2026, 4:17:03 AM
Summary
The paper introduces ISPCloak, an optimization-free adversarial attack framework that weaponizes Image Signal Processing (ISP) pipelines to create physical camouflage against deepfake detectors. By projecting AI-generated images into the RAW domain, injecting realistic Poisson-Gaussian sensor noise, and reconstructing them via forward ISP, the method creates imperceptible adversarial examples that bypass digital forensic detectors by mimicking hardware-intrinsic statistical signatures.
Entities (8)
Relation Signals (7)
ISPCloak → targets → Deepfake Detectors
confidence 95% · ISPCloak... explicitly weaponizes the ISP pipeline to mislead the judgment of deepfake detectors.
ISPCloak → produces → Adversarial Examples
confidence 93% · enables ultra-fast generation of adversarial examples... yielding universally evasive adversarial examples
ISPCloak → injects → Poisson-Gaussian Noise
confidence 92% · injecting realistic Poisson-Gaussian sensor noise... onto AI-generated images
Deepfake Detectors → failsagainst → ISPCloak
confidence 90% · their effectiveness drops drastically when AI-generated content is cloaked in authentic physical imaging characteristics... ISPCloak... mislead the judgment of deepfake detectors
ISPCloak → uses → Invertible ISP Network
confidence 90% · our method first employs an Invertible ISP network to project images into the RAW domain.
ISPCloak → operatesin → RAW Domain
confidence 88% · project images into the RAW domain... within this domain, we introduce Poisson-Gaussian noise
DnCNN → usedfor → Generative Artifact Suppression
confidence 85% · we employ a pre-trained Denoising Convolutional Neural Network (DnCNN)... to predict the noise component directly
Cypher Suggestions (0)
No Cypher suggestions yet.
Abstract
Abstract:The rapid advancement of generative models has spurred the critical need to evaluate the worst-case robustness of deepfake detectors. In this paper, we reveal a fundamental blind spot in current forensic paradigms: while existing detectors excel at capturing digital synthesis artifacts, their effectiveness drops drastically when AI-generated content is cloaked in authentic physical imaging characteristics. We posit that genuine photographs inherently possess hardware-intrinsic statistical signatures, which are imperceptible footprints imprinted by optical sensors and Image Signal Processing (ISP) pipelines, and are fundamentally absent in purely data-driven generative models. Driven by this insight, we propose ISPCloak, a novel optimization-free adversarial attack framework that explicitly weaponizes the ISP pipeline to mislead the judgment of deepfake detectors. Rather than relying on computationally expensive gradient perturbations, our method first employs an Invertible ISP network to project images into the RAW domain. Then, we seamlessly imprint the complex statistical priors of real cameras onto AI-generated images by injecting realistic Poisson-Gaussian sensor noise and conducting forward ISP reconstruction. Synergized with generative artifact suppression and adaptive masking, this streamlined physical simulation enables ultra-fast generation of adversarial examples. Extensive experiments show that embedding authentic physical perturbations fundamentally disrupts a broad range of current detection mechanisms, yielding universally evasive adversarial examples with imperceptible visual alterations.
Tags
Links
- Source: https://arxiv.org/abs/2607.21897v1
- Canonical: https://arxiv.org/abs/2607.21897v1
Trouble viewing inline? Open PDF directly →
Full Text
60,100 characters extracted from source content.
Expand or collapse full text
ISPCloak: Weaponizing ISP for Optimization-Free Physical Camouflage against Deepfake Detectors Jiale Zhao Guangdong University of Technology Guangzhou, China zh2841871831@gmail.com Jiajun Wan Guangdong University of Technology Guangzhou, China 892640097@mails.gdut.edu.cn Lei Tang Guangdong University of Technology Guangzhou, China 3122002111@mail2.gdut.edu.cn Ye Qin Guangdong University of Technology Guangzhou, China 3122000617@mail2.gdut.edu.cn Kebing Jin Guizhou Provincial Laboratory of Big Data, State Key Laboratory of Public Big Data, Guizhou University Guiyang, China kbjin@gzu.edu.cn Jinghui Qin ∗ Guangdong University of Technology Guangzhou, China qinjinghui@gdut.edu.cn Abstract The rapid advancement of generative models has spurred the criti- cal need to evaluate the worst-case robustness of deepfake detec- tors. In this paper, we reveal a fundamental blind spot in current forensic paradigms: while existing detectors excel at capturing dig- ital synthesis artifacts, their effectiveness drops drastically when AI-generated content is cloaked in authentic physical imaging char- acteristics. We posit that genuine photographs inherently possess hardware-intrinsic statistical signatures, which are imperceptible footprints imprinted by optical sensors and Image Signal Processing (ISP) pipelines, and are fundamentally absent in purely data-driven generative models. Driven by this insight, we propose ISPCloak, a novel optimization-free adversarial attack framework that ex- plicitly weaponizes the ISP pipeline to mislead the judgment of deepfake detectors. Rather than relying on computationally expen- sive gradient perturbations, our method first employs an Invertible ISP network to project images into the RAW domain. Then, we seamlessly imprint the complex statistical priors of real cameras onto AI-generated images by injecting realistic Poisson-Gaussian sensor noise and conducting forward ISP reconstruction. Syner- gized with generative artifact suppression and adaptive masking, this streamlined physical simulation enables ultra-fast generation of adversarial examples. Extensive experiments show that embed- ding authentic physical perturbations fundamentally disrupts a broad range of current detection mechanisms, yielding universally evasive adversarial examples with imperceptible visual alterations. ∗ Corresponding author. Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than the author(s) must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from permissions@acm.org. Conference acronym ’X, Woodstock, NY © 2018 Copyright held by the owner/author(s). Publication rights licensed to ACM. ACM ISBN 978-1-4503-X-X/2018/06 https://doi.org/X.X CCS Concepts • Security and privacy→Social aspects of security and pri- vacy;• Computing methodologies→Computational photog- raphy; Computer vision. Keywords Adversarial Attack, Image Forensics, Image Signal Processing, Deep- fake Detection, Sensor Noise ACM Reference Format: Jiale Zhao, Jiajun Wan, Lei Tang, Ye Qin, Kebing Jin, and Jinghui Qin. 2018. ISPCloak: Weaponizing ISP for Optimization-Free Physical Camouflage against Deepfake Detectors. In Proceedings of Make sure to enter the correct conference title from your rights confirmation email (Conference acronym ’X). ACM, New York, NY, USA, 10 pages. https://doi.org/X.X 1 Introduction The rapid advancement of generative AI and deep learning has democratized the creation of photorealistic synthetic images. From text-to-image models like DALL-E [3] and Stable Diffusion [30] to face-swapping techniques and diffusion-based inpainting [51], AI-generated content (AIGC) has proliferated at an unprecedented scale. This technological leap, while creatively empowering, ad- mits a critical dual-use vulnerability. Specifically, AI-generated forgeries constitute a substantial threat to media authenticity, in- formation integrity, and public trust. Thus, the forensic detection of AIGC has emerged as an urgent frontier, with numerous de- tection frameworks deployed to identify and mitigate synthetic imagery [12,17,19,20,44]. However, despite achieving impressive accuracy across various benchmarks, existing forensic methods fundamentally operate within a purely digital paradigm. Whether analyzing frequency spectra or extracting deep structural features, these frameworks primarily engage in an endless mathematical duel with generative models over the distributions of rendered pixels or latent representations. Consequently, by neglecting the hardware- intrinsic mechanics of natural image acquisition, these detectors remain fundamentally vulnerable to adversarial perturbations that accurately emulate authentic sensor signatures. The fundamental insight that inspires this work is deceptively simple yet profound: real photographs are inextricably stamped with arXiv:2607.21897v1 [cs.CV] 24 Jul 2026 Conference acronym ’X, June 03–05, 2018, Woodstock, NYJiale Zhao, Jiajun Wan, Lei Tang, Ye Qin, Kebing Jin, and Jinghui Qin DnCNN AI-Generated Image RAW Image Physical Sensor Noise Adversarial RAW Image InvISP ISP Adversarial Image Artifacts Residual Detector Probability FakeReal (b)(a) Figure 1: Overview of our proposed physical noise injection framework. (a) Motivation: Real photographs inherently follow Poisson photon transfer physics (휎 2 ∝ 휇), whereas AI-generated images exhibit constant, physics-violating noise signatures. (b) Our Pipeline: Motivated by this gap, our framework suppresses synthetic artifacts via DnCNN and leverages an ISP cycle to inject authentic, signal-dependent photon and read noise in the RAW domain. This physically consistent injection yields highly stealthy and evasive adversarial examples that seamlessly emulate real sensor noise to bypass current detectors. a unique, irreplaceable hardware-intrinsic statistical signature that no pure data-driven generative model can authentically replicate. When photons strike a CMOS or CCD sensor within a camera, they gener- ate Poisson-distributed shot noise proportional to signal intensity. Simultaneously, thermal and readout electronics introduce Gauss- ian noise floors. As empirically illustrated by the Photon Transfer Curve in Figure 1 (a), this fundamental electro-optical property dic- tates that the noise variance in real photographs inherently scales with signal intensity (휎 2 ∝ 휇). These raw sensor readings then traverse a proprietary and highly nonlinear Image Signal Process- ing (ISP) pipeline, encompassing demosaicing, color interpolation, white balance, tone mapping, and denoising. This process imprints distinctive spatial correlations, chromatic cross-talk patterns, and frequency-domain characteristics unique to each camera model and sensor class. This complex transformation, rooted in physics and hardware design, produces an intricate statistical footprint across spatial, spectral, and inter-channel domains. Conversely, AI-generative models, which learn from RGB distri- butions in pixel space or compressed latent spaces, fundamentally lack access to this underlying physical ground truth. As starkly contrasted in Figure 1 (a), these models fail to capture this dynamic physical relationship, defaulting instead to a physics-violating, con- stant noise variance profile (휎 2 ≈ const). They cannot authentically synthesize the RAW sensor domain or accurately emulate the non- linear reshaping of sensor noise into naturalistic light reflections and textures by the ISP. Existing adversarial defenses against AIGC detectors have largely overlooked this physical blind spot. Traditional gradient-based ap- proaches, including Projected Gradient Descent (PGD) [26], along- side recent diffusion-based attack methods like Taigen [32] and Adv-diffusion [21], operate exclusively in RGB or compressed la- tent spaces. These optimization-heavy methods suffer from several compounding limitations. First, their computational burden and latency render them impractical for large-scale deployment. More- over, the perturbations manifest as artificial digital modifications or regimented adversarial noise, creating a categorical distinction from natural camera grain. Critically, because these digitally crafted perturbations rely heavily on model-specific gradients or latent rep- resentations, they are inherently overfitted to the feature space of the surrogate detectors. This severe overfitting fundamentally restricts their generalization capabilities, causing the adversarial effect to fail when transferring across heterogeneous forensic ar- chitectures or unseen detection paradigms in realistic black-box scenarios. In this paper, we propose ISPCloak, a fundamentally novel and optimization-free physical adversarial attack framework that ex- plicitly weaponizes the ISP pipeline to mislead the judgment of deepfake detectors. ISPCloak operates through a continuous, syn- ergistic pipeline. First, we utilize a lightweight denoising network (e.g., DnCNN) to suppress inherent digital generative artifacts, yield- ing a purified image. Then, we employ a pre-trained invertible ISP network to project this purified image into the RAW sensor domain. Subsequently, within this domain, we introduce Poisson-Gaussian noise that explicitly models the physical photon and thermal charac- teristics of real camera hardware. To ensure strict imperceptibility, an adaptive gradient-based mask modulates these perturbations, deliberately allocating the physical noise into texture-rich regions while suppressing it in flat, smooth areas to preserve baseline visual fidelity. Finally, a forward ISP reconstruction organically transforms this RAW-domain noise into complex, naturalistic spatial and chro- matic correlations. Remarkably, this entire pipeline is feedforward and parameter-free, involving no gradient descent or iterative opti- mization. An image can be processed in tens of milliseconds. The physical grounding of ISPCloak produces three distinct ad- vantages over existing methods. First, by operating in the RAW domain and leveraging true sensor physics, our perturbations are ISPCloak: Weaponizing ISP for Optimization-Free Physical Camouflage against Deepfake DetectorsConference acronym ’X, June 03–05, 2018, Woodstock, NY mathematically and perceptually indistinguishable from genuine camera noise. This endows the synthetic images with an authentic hardware fingerprint that forensic detectors cannot reliably distin- guish from genuine captures. Second, the optimization-free design achieves near-real-time performance, enabling practical, scalable deployment in adversarial workflows. Third, the physical basis of our attack confers robust transferability. Because the RAW noise and ISP transformation are grounded in universal electromagnetic and optics principles, perturbations generated for one camera model remain effective across diverse sensor architectures. This intrinsic generalization property is fundamentally absent in purely digital attack paradigms. The key contributions of this work are summarized as follows: • We identify and formally characterize a critical physical blind spot in contemporary AIGC forensic detectors: the absence of authentic hardware-intrinsic statistical signatures in AI-generated images. This observation introduces a vital physical dimension to current forensic evaluations. • We propose ISPCloak, the first optimization-free, physics- grounded adversarial attack framework that explicitly ex- ploits the vulnerabilities of the ISP pipeline. By combining RAW-domain noise injection with adaptive masking and in- vertible ISP networks, we achieve imperceptible yet potent attacks that bypass traditional digital countermeasures. •Extensive experiments validate the method’s superiority across metrics of attack success rate (ASR), visual fidelity (PSNR/SSIM), computational efficiency, and cross-domain transferability. Our approach achieves significantly higher ASR than gradient-based and diffusion-based attacks while maintaining visual quality and operating orders of magni- tude faster. 2 Related Work 2.1 Deepfake Detection Current Deepfake and AIGC detection frameworks primarily formu- late the task as a binary classification of digital synthesis artifacts. While spatial methods target blending boundaries and textural anomalies [2,25], frequency-domain approaches exploit abnor- mal distributions in Fourier or DCT spectra [9,34]. Furthermore, many data-driven detectors leverage CNNs or ViTs to identify architecture-specific noise or checkerboard patterns inherently tied to the generation process [38]. To enhance cross-domain gener- alization, recent literature has shifted toward more sophisticated feature extraction paradigms. One line of research focuses on struc- tural and multi-domain inconsistencies: FatFormer [22] utilizes a forgery-aware adapter to fuse image and frequency features, whereas SAFE [18] and NPR [35] specifically target local struc- tural artifacts and neighboring pixel relationships introduced by up-sampling operations. Another emerging trend exploits vision- language priors; for instance, C2P-CLIP [33] injects category-related concepts into the image encoder to boost CLIP’s detection poten- tial, while AIDE [48] synergizes CLIP embeddings with multi-scale frequency patches. Additionally, approaches like LGrad [36] map images into a gradient space using pre-trained CNNs to extract domain-agnostic artifact representations. Despite achieving remarkable performance in specific bench- marks, these defense mechanisms share a fundamental vulnera- bility: they remain heavily overfitted to the presence of digital synthetic traces, while entirely overlooking the absence of authen- tic physical traces. By operating within this purely digital para- digm, they fail to verify the hardware-intrinsic statistical signa- tures, including sensor noise patterns and ISP pipeline transfor- mations, that universally govern authentic natural photographs. This paradigm-level blind spot leaves existing detectors highly sus- ceptible to sophisticated attacks designed to convincingly emulate physical-world imaging characteristics. 2.2 Adversarial Attacks on Deepfake Detectors To evaluate and expose the vulnerabilities of Deepfake detectors, various adversarial attack strategies have been proposed. Tradi- tional adversarial attacks, such as the Fast Gradient Sign Method [11] and PGD [26], have been widely adapted to fool AIGC detectors by adding imperceptible, mathematically optimized noise perturba- tions to the image. To further enhance visual stealthiness and cross- model transferability, recent advancements have explored diffusion- based generation to bypass detection networks [7,13,16]. For in- stance, StealthDiffusion [52] optimizes the diffusion latent space to align the frequency spectra of adversarial and genuine images. Sim- ilarly, Diff-PGD [47] incorporates diffusion-guided gradients into the traditional PGD framework, ensuring that perturbations strictly adhere to natural data distributions. Breaking away from conven- tional퐿 푝 -norm constraints, DiffAttack [7] injects semantic-level perturbations directly into the latent space, while DiffAdvMAP [28] leverages diffusion priors to sample unrestricted adversarial exam- ples from posterior distributions. Furthermore, to circumvent the inevitable distortions caused by post-processing existing images, the Adversarial Diffusion Model (ADM) [41] generates undetectable adversarial images entirely from scratch by optimizing an adver- sarial denoising U-Net and decoder to match the high-frequency characteristics of real data. However, these dominant attack paradigms face severe practi- cal limitations. First, their reliance on iterative backpropagation or sequential denoising renders them computationally prohibitive and unsuitable for real-time deployment. Second, the meticulously optimized perturbations heavily overfit to specific white-box surro- gate models, causing a drastic drop in transferability against unseen black-box detectors. In contrast to these computationally heavy and mathematically overfitted digital attacks, our method introduces an optimization-free, single forward-pass pipeline that achieves high black-box transferability through universally applicable physical camouflage. 2.3 Computational Photography and ISP The ISP pipeline is a fundamental component in digital cameras that bridges the gap between raw sensor measurements and the final perceivable RGB images [6,40]. When photons hit the Complemen- tary Metal-Oxide-Semiconductor (CMOS) sensor, they induce a raw electrical signal containing signal-dependent Poisson noise (shot noise) and signal-independent Gaussian noise (read noise). The ISP transforms this raw, noisy signal through a complex, highly non- linear sequence of operations, including black level compensation, Conference acronym ’X, June 03–05, 2018, Woodstock, NYJiale Zhao, Jiajun Wan, Lei Tang, Ye Qin, Kebing Jin, and Jinghui Qin white balance, demosaicing, color space conversion, and gamma correction. This intricate process inherently weaves the raw sensor noise into complex, cross-channel, and spatially correlated textures in the final RGB domain, forming a distinct hardware-intrinsic statistical signature. Historically, research in computational photography has focused on modeling these ISP pipelines and sensor noise distributions for positive visual objectives, such as image restoration, denoising, and enhancement [1,43,50]. Recently, researchers have begun to integrate the ISP pipeline into adversarial attack workflows, recog- nizing its pivotal role in the physical-to-digital transition. To ensure the real-world robustness of physical perturbations, methods like ProjAttacker [23] and Camera-Agnostic Patch (CAP) [42] incorpo- rate differentiable ISP simulations into their optimization processes, effectively bridging the domain gap for projection- and patch-based attacks. Conversely, other works exploit the ISP’s non-linear trans- formations to craft camera-specific attacks [29], demonstrating that specific hardware pipelines can selectively amplify adversarial patterns to deceive downstream classifiers. Furthermore, vulnera- bilities within modern AI-driven ISPs have been exposed through data-poisoning backdoor attacks, such as the Neural Invisibility Cloak (NIC) [54], which compromises the ISP to maliciously erase specific targets from the output images. Notably, to specifically bypass forensic media detectors, methods like SpoC [8] utilize a GAN-based approach to explicitly inject proprietary camera traces, such as those arising from demosaicing or compression, into syn- thetic images, deceiving detectors into believing the AI-generated media was acquired by a specific real-world camera model. Unlike existing methods that use the ISP merely as a proxy for iterative optimization or rely on data-driven trace synthesis like SpoC [8] to superimpose empirical camera fingerprints entirely within the RGB domain, our work introduces an optimization- free, physical approach. Rather than simulating fingerprints at the surface level, we utilize an invertible ISP network to project AI- generated images back into the foundational RAW domain. By injecting authentic physical sensor noise and reconstructing the image through the forward ISP, we provide AIGC imagery with a universally evasive, physically grounded camouflage that prior empirical attacks cannot replicate. 3 ISPCloak 3.1 Overview The core paradigm shift of ISPCloak is rooted in a physical per- spective. Rather than competing with detectors in an iterative opti- mization race that confines adversarial conflict to the mathematical manipulation of RGB pixels, we bypass learned decision boundaries by operating in the physical imaging domain. We posit that since generative models learn primarily from digital RGB distributions or compressed latents, they fundamentally lack the hardware-intrinsic signatures inherent to genuine camera captures. ISPCloak ad- dresses this gap by projecting images into the RAW sensor domain to inject perturbations that follow the physical laws of photons and electronics. This creates a fundamental asymmetry: by imprinting authentic physical characteristics, we effectively mask the under- lying generative traces and align the synthetic images with the natural photographic manifold, rendering them indistinguishable to detectors confined to the digital domain. As illustrated in Figure 1 (b), the complete ISPCloak pipeline is structured as a synergistic, optimization-free feedforward process. The workflow begins with generative artifact suppression, where high-frequency digital signatures inherent to AI-generated images are extracted and selectively attenuated. Subsequently, we employ a pre-trained invertible ISP network to perform an inverse mapping from the RGB space to the RAW sensor domain. Within this do- main, we introduce Poisson-Gaussian noise that explicitly models the physical photon and thermal characteristics of actual camera hardware. Then, we employ an adaptive gradient-based mask to concentrate these physical perturbations in texture-rich regions while leveraging visual masking principles to maintain high visual fidelity. Finally, a forward ISP reconstruction transforms the physi- cally grounded RAW features into complex spatial and chromatic correlations. 3.2 Generative Artifact Suppression Prior research shows that AI-generated images carry distinctive digital artifacts as structural byproducts of synthesis. Examples include denoising trajectories in diffusion models and upsampling operations in GANs [5,27,45,52]. These anomalies constitute the primary feature space exploited by contemporary forensic detec- tors. In light of this, we follow recent paradigms advocating for artifact suppression as a pre-processing step. We systematically attenuate existing generative markers before introducing authentic physical characteristics. This provides two primary benefits. First, it reduces the density of traceable fingerprints to lower initial detection risks. Second, it establishes a neutral baseline. By suppressing these un- derlying digital traces, the subsequent hardware noise injection operates on a clean foundation. This ensures that authentic physical signatures are not confounded by competing artifacts. We leverage a residual learning strategy to isolate high-frequency artifacts in AI-generated images. Specifically, a pre-trained Denois- ing Convolutional Neural Network (DnCNN) [49] is used to predict the noise component directly. Given an input image푥, the extracted artifact residual is obtained as: 푅=F(푥),(1) whereF(·)denotes the DnCNN mapping that captures synthetic generation traces while preserving the underlying image content. Directly modifying the entire image may degrade overall vi- sual quality and drastically shift image statistics. To address this, we apply an adaptive gradient mask to modulate the suppression intensity. We first compute the gradient magnitude퐺of the image: 퐺= √︁ (∇ ℎ 푥) 2 +(∇ 푣 푥) 2 +휂,(2) where∇ ℎ and∇ 푣 denote the horizontal and vertical spatial gradient operators, and휂is a small constant added to ensure numerical stability. Then, we construct an adaptive mask 푀 : 푀= 퐺 max(퐺) 훾 .(3) where훾controls the selectivity of the mask. Consequently, texture- rich regions and edges receive mask values near unity, while smooth ISPCloak: Weaponizing ISP for Optimization-Free Physical Camouflage against Deepfake DetectorsConference acronym ’X, June 03–05, 2018, Woodstock, NY regions receive values near zero. We apply this mask to the extracted residual through element-wise multiplication: ̃ 푅= 푀 ⊙ 푅.(4) The final cleaned image푥 ′ is obtained by subtracting the masked residual from the original image, followed by a clamping operation to ensure valid pixel ranges: 푥 ′ = Clip(푥 − 훼 ̃ 푅, 0, 1),(5) where훼 ∈ [0,1]is a blend weight that controls the intensity of the suppression. 3.3 Physical Noise Injection and Invertible ISP The critical distinction between our approach and traditional adver- sarial methods lies in operating within the RAW photonic domain rather than the processed RGB color space. To achieve this, we lever- age an Invertible Image Signal Processing (InvISP) framework [46], which enables highly accurate bidirectional mapping between RAW and RGB domains via learned neural transformations. Given the cleaned RGB image푥 ′ from the previous stage, we perform inverse ISP mapping to obtain its RAW representation: 푟=Φ −1 (푥 ′ ),(6) whereΦ −1 denotes the learned inverse ISP transformation parame- terized by the InvISP network. This function maps the 3-channel RGB data back to a Bayer-mosaiced RAW format. Then, the Bayer- mosaiced RAW data will be injected with physical sensor noise that models fundamental photon transport and thermal electronics principles. The injected noise comprises two additive components: 푟 ′ = 푟 +푛 푝 +푛 푔 .(7) The Poisson component 푛 푝 models photon shot noise, which is inherent to the stochastic arrival of photons at the photodiode [4, 10]. Following fundamental sensor physics, the variance of shot noise is proportional to the signal magnitude. Simultaneously, we consider Gaussian thermal noise푛 푔 arising from thermal energy in the readout electronics and sensor substrate. For computational tractability, we approximate the Poisson shot noise using a signal- dependent Gaussian distribution, yielding the following unified noise formulations: 푛 푝 ∼N(0,휎 2 푝 |푟|), 푛 푔 ∼N(0,휎 2 푔 I), (8) where휎 푝 and휎 푔 are tunable scaling coefficients governing the magnitudes of the signal-dependent shot noise and the signal- independent thermal noise, respectively. The variance dependency on signal intensity for푛 푝 represents the fundamental signature of Poisson statistics, where brighter pixels naturally exhibit higher variance due to increased photon flux. To prevent excessive signal clipping or unrealistic noise magni- tudes, we constrain the perturbation via a clipping function: ˆ 푟= Clip(푟 ′ ,푟 −휖,푟 +휖),(9) where휖bounds the RAW value perturbation to physically realistic sensor ranges. The final step of this core stage is image reconstruction with forward ISP, wherein the noisy RAW image undergoes the learned forward transformation to produce the final adversarial image: 푥 ∗ =Φ( ˆ 푟),(10) whereΦrepresents the forward ISP mapping. This transformation is crucial because the ISP pipeline encompasses multiple non-linear processing stages, including demosaicing, color interpolation, white balance adjustment, and gamma correction. When applied to the injected RAW noise, these sensor-specific operations introduce complex spatial correlations and inter-channel interference. The noise that was independent in the RAW space becomes intricately woven into the RGB image globally. Generative models operating in pixel or latent spaces cannot reproduce this transformation because they lack access to the physical ground truth. Consequently, the resulting adversarial image푥 ∗ carries an authentic hardware finger- print. Forensic detectors trained on real camera imagery struggle to distinguish this statistical signature from genuine captures. 4 Experiments 4.1 Experimental Settings 4.1.1Datasets. We evaluate our framework on three complemen- tary datasets chosen to highlight distinct challenges in modern forgery detection. GenImage [53] contains large-scale full-image synthesis from diffusion and GAN models, providing a challeng- ing setting where global digital artifacts appear without sensor- consistent acquisition. WildFake [15] comprises unconstrained real- world images from diverse sources, testing the transferability of our physically grounded perturbations across heterogeneous dis- tributions. FaceForensics++ [31] focuses on localized facial ma- nipulations, allowing us to evaluate whether ISP-based noise can homogenize statistics between authentic backgrounds and manipu- lated regions. 4.1.2Detectors. We benchmark ISPCloak against 4 diverse foren- sic detectors under a transfer-based black-box setting. C2P-CLIP [33] and AIDE [48] leverage Vision-Language Models with cross-modal cues and frequency priors. SAFE [18] targets spatial and structural inconsistencies, particularly from local artifacts or up-sampling. LGrad [36] captures domain-agnostic gradient representations. This selection covers complementary forensic cues, enabling evaluation of whether our physical perturbations consistently challenge struc- tural, frequency, gradient, and cross-modal signals. 4.1.3 Baselines. ISPCloak is compared with four representative adversarial strategies. PGD [26] is a classical iterative퐿 푝 -norm constrained attack. Diff-PGD [47] and StealthDiffusion [52] com- bine gradient-based optimization with generative guidance. Dif- fAttack [7] performs latent-space generative perturbations aligned with frequency-domain characteristics. Unlike these optimization- heavy baselines that risk overfitting surrogate models, ISPCloak uses a single, forward-pass pipeline, achieving robust black-box transferability with minimal computation. 4.1.4 Evaluation Metrics. Evasion effectiveness is quantified by the ASR metric in black-box scenarios. To rigorously assess visual and statistical fidelity, we report PSNR, SSIM,퐿 2 distance, and FID, ensuring that the generated perturbations remain imperceptible and semantically natural. Conference acronym ’X, June 03–05, 2018, Woodstock, NYJiale Zhao, Jiajun Wan, Lei Tang, Ye Qin, Kebing Jin, and Jinghui Qin Table 1: ASR (%) on the GenImage dataset. The best results are highlighted in bold, and the second-best results are underlined. DetectorMethodADM BigGAN Glide Midjourney SD v4 SD v5 VQDM WukongMean AIDE PGD94.9091.4077.5080.1067.5071.0086.4076.6080.67 Diff-PGD90.5058.6057.3068.8044.1042.3070.3054.9060.85 DiffAttack34.3042.1012.8032.6039.9039.3035.0046.9035.36 StealthDiffusion96.8092.9082.2084.4079.1080.0089.4087.2086.50 Ours98.1089.30 83.2087.6079.60 80.70 91.1083.1086.59 SAFE PGD72.2089.2089.1067.5056.3053.1065.8059.6069.10 Diff-PGD77.2082.1079.6072.5065.3066.4074.6067.1073.10 DiffAttack36.2036.0037.9039.0044.2042.8039.7038.3039.26 StealthDiffusion21.0018.7021.1022.5025.4023.7025.1022.4022.49 Ours84.90 96.20 95.9080.2070.60 68.20 83.00 73.3081.54 C2P-CLIP PGD76.6026.90 90.4098.6089.7089.2062.2087.7077.66 Diff-PGD80.50 32.6078.6093.6082.0080.4057.3080.8073.22 DiffAttack12.6019.2016.5035.0042.8044.3047.0027.3030.59 StealthDiffusion56.1016.5065.6093.0081.3082.5048.6072.1064.46 Ours75.1029.6087.2098.6096.60 94.60 73.20 94.7081.20 LGrad PGD41.0047.7033.2030.0044.0042.6037.3049.8040.70 Diff-PGD30.2026.3021.2018.4028.8028.5028.1030.3026.47 DiffAttack47.40 65.3039.0035.2052.0050.4041.5051.7047.81 StealthDiffusion50.6056.10 50.0046.2048.9049.1040.0050.6048.94 Ours59.5064.1045.6049.0065.40 66.90 53.40 68.9059.10 Table 2: ASR (%) on WildFake dataset. The best results are highlighted in bold, and the second-best results are underlined. DetectorMethodADMDALL-EDDIMDDPM Imagen MidjourneySDVQDMMean AIDE PGD94.3067.1092.3092.8037.4073.3067.0084.8076.12 Diff-PGD90.5054.1087.5090.6022.9055.5050.6074.6065.79 DiffAttack33.5044.7031.0029.5035.5045.2049.8040.1038.66 StealthDiffusion96.6090.7097.1097.0086.6093.6093.2064.0089.85 ISPCloak (Ours)99.90 98.60 100.00 99.90 96.5093.6088.0099.9097.05 SAFE PGD76.0074.3079.1067.8077.4072.5069.0070.8073.36 Diff-PGD65.8070.9070.6063.6070.8062.8061.7049.7064.49 DiffAttack39.5042.2038.5042.8042.1036.2039.4037.0039.71 StealthDiffusion20.8017.4022.2023.6020.2017.9020.7023.1020.74 ISPCloak (Ours)100.00 98.90 100.00 99.70 100.0099.8099.70 99.8099.74 C2P-CLIP PGD74.7083.7048.3055.2096.3075.8088.7062.2073.11 Diff-PGD79.2083.1036.0038.2087.8078.4087.2049.2067.39 DiffAttack12.8047.1038.3042.8031.1011.7023.9047.2031.86 StealthDiffusion61.7083.1037.5038.5091.3073.9089.7053.5066.15 ISPCloak (Ours)89.70 85.60 58.90 55.30 96.5062.2084.30 68.2075.09 LGrad PGD40.6062.1043.4031.8024.9039.6063.3040.5043.27 Diff-PGD25.8046.3052.4039.3019.6017.1046.5023.0033.75 DiffAttack44.1059.3047.4044.4028.8043.8061.4040.5046.21 StealthDiffusion45.6062.7055.8044.9046.2049.0066.0041.0051.40 ISPCloak (Ours)63.0059.10 73.30 57.6033.2030.2065.4057.1054.86 4.1.5 Implementation Details. All experiments are conducted on an NVIDIA RTX 4090D. To ensure a balanced and large-scale eval- uation, we randomly sample 1,000 images from each generative sub-category for GenImage and WildFake, resulting in 8,000 im- ages respectively. For F++, we randomly select images across all 4 manipulation methods. This strategy is designed to maintain the in- dependence of video sources, ensuring that each sample originates from a distinct underlying sequence to maximize the diversity of identities and backgrounds, while avoiding the content redundancy inherent in per-category sampling. All images are maintained at their original resolutions with a fixed seed of 42. For our ISPCloak, the noise scaling coefficients are set to휎 푝 =0.09 and휎 푔 =0.075. The perturbations are strictly clipped at휖=0.006, with blending factor훼=0.2 and mask power훾=2.5. To facilitate community verification and comparative evaluation, the original images along with their corresponding adversarial examples will be released upon publication. To evaluate the black-box transferability of baselines, we inten- tionally select a wide range of heterogeneous surrogate models, including CNNs and Transformers. This diverse selection allows ISPCloak: Weaponizing ISP for Optimization-Free Physical Camouflage against Deepfake DetectorsConference acronym ’X, June 03–05, 2018, Woodstock, NY us to rigorously assess whether adversarial perturbations can gen- eralize across fundamentally different architectural priors. Specif- ically, for PGD, we use a ResNet-50 [14] surrogate with휖=0.03 and a step size of 0.0039 over 30 iterations. For Diff-PGD, a Swin- Transformer [24] is employed, utilizing 6 iterations with step size 1.0 and 3 diffusion steps under a DDIM-50 schedule. DiffAttack utilizes the Data-efficient Image Transformer (DeiT) [39] as its surrogate, performing 10 optimization iterations with 10 diffusion steps. Finally, for StealthDiffusion, we employ an EfficientNet [37] surrogate and follow the settings in [52], with 5 iterations and 2 latent diffusion steps at 휖= 0.0157. Table 3: ASR (%) on FaceForensics++ dataset. The best results are highlighted in bold. MethodAIDE SAFE C2P-CLIP LGrad PGD45.2090.8058.7060.50 Diff-PGD43.2084.8031.5056.20 DiffAttack17.0023.7023.5077.20 StealthDiffusion 58.7015.7037.6075.20 ISPCloak (Ours) 82.60 95.60 64.50 87.70 4.2 Main Results and Analysis We evaluate the ASR of our method across three diverse datasets and four heterogeneous detectors. Overall, our approach proves highly effective across different generative sources and detection architectures. As shown in Table 1, our method attains the highest mean ASR across all evaluated detectors on GenImage. Specifically, it achieves 86.59% on AIDE, slightly surpassing the 86.50% attained by StealthD- iffusion. The advantage over prior methods is particularly evident on SAFE and C2P-CLIP, where our method achieves substantially higher success rates. In addition, our approach remains highly ef- fective across nearly all generators, including challenging diffusion- based models such as SD v4, SD v5, and VQDM, indicating robust- ness to variations in generative pipelines. A key observation from GenImage is the stability of our method across detectors with fundamentally different mechanisms. Gen- erative attacks such as StealthDiffusion perform competitively on AIDE by reaching 86.50%, but their efficacy drops to 22.49% on SAFE and becomes less consistent on C2P-CLIP with a mean ASR of 64.46%. Similarly, optimization-based methods such as PGD and Diff-PGD exhibit notable variance across generators and detec- tors. While prior works report higher success rates under specific surrogate-target pairs, our evaluation shows that under more di- verse architectural gaps, the effectiveness of generative attacks degrades substantially. This behavior suggests sensitivity to the surrogate model and limited cross-detector generalization. In contrast, our method demonstrates more stable transferabil- ity across these heterogeneous settings. On LGrad, our method achieves the highest mean ASR of 59.10%, outperforming StealthD- iffusion at 48.94% and DiffAttack at 47.81%. Similar trends are ob- served across most generators, where our approach consistently ranks among the top-performing methods. These results suggest Table 4: Visual fidelity and image quality assessment on the GenImage dataset. The best results are highlighted in bold. MethodPSNR↑ SSIM↑ 퐿 2 Dist. (×10 −2 )↓ FID↓ PGD33.820.862.5319.17 DiffAttack31.450.872.4918.80 Diff-PGD32.670.902.3319.36 StealthDiffusion33.580.882.1220.95 ISPCloak (Ours) 35.56 0.911.6814.21 that avoiding explicit gradient-based optimization and instead lever- aging ISP-consistent perturbations improves robustness under cross- architecture evaluation. Table 2 demonstrates the results on WildFake. Here, our method demonstrates top-performing capabilities and achieves the highest mean ASR on all evaluated defenses. In particular, the ASR reaches 97.05% on AIDE and 99.74% on SAFE, while improvements on the remaining detectors are consistent with those observed on GenIm- age. These results suggest that the proposed perturbation strategy generalizes exceptionally well to unconstrained, in-the-wild distri- butions. Finally, Table 3 shows the performance on FaceForensics++. Prior approaches exhibit noticeable degradation in this localized manip- ulation setting. For instance, DiffAttack achieves only 23.50% ASR on C2P-CLIP, whereas our method reaches 64.50%. These findings establish that our ISPCloak decisively outperforms existing attacks. Specifically, our physically grounded perturbations demonstrate superior robustness in spatially heterogeneous spoofing contexts, seamlessly masking the structural boundaries between manipulated regions and authentic backgrounds. Ultimately, the comprehensive evaluation across all 3 datasets confirms that our ISPCloak provides highly effective and consistent improvements over existing attacks, particularly under heteroge- neous detector architectures and realistic testing conditions. This proves that physically motivated perturbations offer a fundamen- tally more robust and transferable alternative to purely optimization- driven attack strategies. OriginalPGD DiffAttack DiffPGDStealthDiffionOurs Figure 2: Qualitative comparison of adversarial examples across GenImage, WildFake, and FaceForensics++. Red boxes denote regions enlarged by 3.33× to reveal details. 4.3 Visual Fidelity and Image Quality As shown in Fig. 2, the perturbations introduced by ISPCloak exhibit visually natural characteristics that resemble sensor-level noise Conference acronym ’X, June 03–05, 2018, Woodstock, NYJiale Zhao, Jiajun Wan, Lei Tang, Ye Qin, Kebing Jin, and Jinghui Qin in real imaging systems. These perturbations follow the physical properties of photon shot noise and electronic read noise, resulting in images that remain perceptually consistent with the original content while effectively concealing generative artifacts. The visual fidelity and image quality metrics on the GenImage dataset are reported in Table 4. Our ISPCloak consistently achieves the best performance across all metrics, including PSNR, SSIM,퐿 2 distance, and FID. These results indicate that ISPCloak preserves high visual quality while effectively implementing adversarial per- turbations, outperforming baseline attacks such as PGD, DiffAttack, Diff-PGD, and StealthDiffusion. Table 5: Component ablation study on the GenImage dataset. We report the ASR evaluated against the SAFE detector along- side visual quality metrics. ComponentsMetrics 푛 푝 푛 푔 DnCNNClipMaskISP ASR (%) PSNR SSIM 퐿 2 (×10 −2 ) FID ✓38.3753.041.000.230.21 ✓ ✓62.7344.320.990.611.67 ✓39.2751.531.000.270.18 ✓80.6135.500.911.709.47 ✓46.2935.720.931.649.87 ✓77.4139.710.961.064.91 ✓ ✓99.2613.930.2220.31121.43 ✓74.0434.070.902.018.35 ✓81.5435.560.911.6814.21 4.4 Ablation Study and Sensitivity Analysis To rigorously evaluate the contribution of each module and the robustness of our framework to hyperparameter variations, we conduct comprehensive ablation studies on the GenImage dataset against the SAFE detector. 4.4.1Component Analysis. Table 5 illustrates the impact of individ- ual components in our pipeline. Starting from a naive noise addition baseline, we observe that purely injecting statistical noise without the ISP module yields a suboptimal ASR of 62.73%. Integrating the physically grounded ISP module significantly elevates the ASR to 81.54%. This validates our core motivation: simulating the nonlinear transformations of a real camera pipeline ensures the injected per- turbations are statistically indistinguishable from authentic sensor artifacts, thereby effectively evading forensic detectors. Furthermore, spatial and magnitude constraints prove essential for maintaining visual fidelity. Disabling the clipping boundary (휖) leads to an abnormally high ASR of 99.26%, but this comes at the catastrophic cost of severe visual distortion, evidenced by the FID skyrocketing to 121.43 and PSNR dropping to 13.93. Similarly, removing the adaptive masking strategy causes a noticeable drop in both ASR (74.04%) and image quality. The mask modulates the high-frequency components of the perturbation, suppressing re- sponses in smooth regions while preserving structured variations that are more consistent with natural image statistics. Ultimately, the full model achieves an optimal balance, ensuring high adversar- ial effectiveness without compromising imperceptibility. 4.4.2 Sensitivity and Trade-off Analysis. Table 6 presents a sensi- tivity analysis of the major hyperparameters, halving (0.5×) and doubling (2×) their default values to analyze the system’s behavior. Table 6: Hyperparameter sensitivity analysis on the GenIm- age dataset. We report the ASR against SAFE, alongside visual quality metrics, by halving (0.5×) and doubling (2×) the de- fault value of each hyperparameter. ParameterValueASR (%) PSNR SSIM 퐿 2 (×10 −2 ) FID 휎 푝 (Poisson) 0.045 (0.5×)88.4931.660.852.6216.55 0.090 (Default)81.5435.560.911.6814.21 0.180 (2×)85.9334.290.901.948.83 휎 푔 (Gaussian) 0.0375 (0.5×)71.5931.920.852.5514.08 0.0750 (Default)81.5435.560.911.6814.21 0.1500 (2×)84.6932.340.862.4413.16 훼 (Blend Factor) 0.100 (0.5×)59.1833.330.892.2512.14 0.200 (Default)81.5435.560.911.6814.21 0.400 (2×)71.9738.760.961.165.31 휖 (Bound) 0.003 (0.5×)66.1243.770.990.652.15 0.006 (Default)81.5435.560.911.6814.21 0.012 (2×)98.9130.550.823.0412.45 훾 (Mask Power) 1.250 (0.5×)96.8033.160.882.2011.29 2.500 (Default)81.5435.560.911.6814.21 5.000 (2×)62.8838.070.951.297.03 The noise scaling factors휎 푝 and휎 푔 exhibit comparatively sta- ble behavior. Varying휎 푝 and휎 푔 over a wide range leads to only moderate changes in both ASR and image quality, without abrupt degradation. This is because the overall perturbation magnitude is explicitly constrained by the bound휖, which prevents excessive noise amplification even when the noise levels increase. In contrast, the blending factor훼plays a more active role in controlling the attack strength. When훼is too small, the injected perturbation is insufficient to effectively alter the detector response, leading to lower ASR. Increasing훼improves attack effectiveness up to a certain point, but overly large values cause the perturbation to deviate from the underlying ISP-consistent structure, which weakens its ability to remain statistically aligned with natural image distributions and thus reduces ASR. The mask power훾primarily controls the artifact-removal step. Smaller훾values allow broader perturbations, leading to higher ASR but slightly lower visual quality. Larger훾focuses the perturbation, reducing ASR while improving perceptual metrics. Thus,훾balances attack effectiveness with artifact suppression. Overall, the sensitivity analysis reveals that휖and훾dominate the trade-off between attack effectiveness and perceptual quality, while 휎 푝 and휎 푔 are regulated by the perturbation bound and therefore have limited impact. The blending factor훼introduces an additional balance between perturbation strength and structural consistency. Together, these observations explain how different components interact to produce stable and effective adversarial behavior. Table 7: Computational efficiency. We reported execution time in seconds for generating 1, 000 adversarial images. MethodStealthDiffusionDiffAttackDiff-PGDPGDISPCloak (Ours) Time4,8423,9072,5115232 ISPCloak: Weaponizing ISP for Optimization-Free Physical Camouflage against Deepfake DetectorsConference acronym ’X, June 03–05, 2018, Woodstock, NY 4.5 Computational Efficiency We evaluate computational overhead by measuring the execution time on an NVIDIA RTX 4090D to generate 1,000 adversarial exam- ples on the GenImage ADM subset. As shown in Table 7, diffusion- based attacks incur prohibitive costs due to iterative sampling. The gradient-based PGD is faster than existing methods, but it still re- quires multiple backpropagation steps. Conversely, ISPCloak lever- ages an optimization-free, single forward-pass pipeline, processing the entire batch in merely 32 seconds. This ultra-fast generation speed enables highly practical, real-time deployment. 5 Conclusion In this paper, we present ISPCloak, an adversarial attack frame- work that exposes vulnerabilities in modern AI-generated image detectors. Unlike traditional optimization-based attacks, ISPCloak leverages a reversible ISP pipeline to embed authentic sensor im- prints into synthetic images. By injecting statistically consistent shot and read noise with adaptive spatial constraints, our method effectively conceals digital generative artifacts while preserving visual fidelity. Extensive evaluations on GenImage, WildFake, and FaceForensics++ demonstrate that ISPCloak consistently achieves high ASR across heterogeneous detectors under strict black-box conditions. Moreover, the manipulated images become statistically indistinguishable from real camera captures, highlighting a critical blind spot in current forensic defenses. These findings underscore the need for robust, physics-aware detection mechanisms capable of resisting ISP-consistent perturbations. References [1]Mahmoud Afifi, Zhongling Wang, Ran Zhang, and Michael S Brown. 2025. Mod- ular Neural Image Signal Processing. arXiv preprint arXiv:2512.08564 (2025). [2]Inzamamul Alam, Md Tanvir Islam, and Simon S Woo. 2025. Specxnet: A dual- domain convolutional network for robust deepfake detection. In Proceedings of the 33rd ACM International Conference on Multimedia. 11667–11676. [3]James Betker, Gabriel Goh, Li Jing, Tim Brooks, Jianfeng Wang, Linjie Li, Long Ouyang, Juntang Zhuang, Joyce Lee, Yufei Guo, et al.2023. Improving im- age generation with better captions. Computer Science. https://cdn. openai. com/papers/dall-e-3. pdf 2, 3 (2023), 8. [4]Tim Brooks, Ben Mildenhall, Tianfan Xue, Jiawen Chen, Dillon Sharlet, and Jonathan T Barron. 2019. Unprocessing images for learned raw denoising. In Proceedings of the IEEE/CVF conference on computer vision and pattern recognition. 11036–11045. [5] Keshigeyan Chandrasegaran, Ngoc-Trung Tran, and Ngai-Man Cheung. 2021. A closer look at fourier spectrum discrepancies for cnn-generated images detec- tion. In Proceedings of the IEEE/CVF conference on computer vision and pattern recognition. 7200–7209. [6]Hongyang Chen and Kaisheng Ma. 2022. Lw-isp: A lightweight model with isp and deep learning. arXiv preprint arXiv:2210.03904 (2022). [7]Jianqi Chen, Hao Chen, Keyan Chen, Yilan Zhang, Zhengxia Zou, and Zhenwei Shi. 2024. Diffusion models for imperceptible and transferable adversarial attack. IEEE Transactions on Pattern Analysis and Machine Intelligence 47, 2 (2024), 961– 977. [8]Davide Cozzolino, Justus Thies, Andreas Rossler, Matthias Niessner, and Luisa Verdoliva. 2021. SpoC: Spoofing Camera Fingerprints. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR) Work- shops. 990–1000. [9] Anurag Dutta, Arnab Kumar Das, Ruchira Naskar, and Rajat Subhra Chakraborty. 2025. WaveDIF: Wavelet sub-band based deepfake identification in frequency domain. In Proceedings of the Computer Vision and Pattern Recognition Conference. 6312–6321. [10]Alessandro Foi, Mejdi Trimeche, Vladimir Katkovnik, and Karen Egiazarian. 2008. Practical Poissonian-Gaussian noise modeling and fitting for single-image raw-data. IEEE transactions on image processing 17, 10 (2008), 1737–1754. [11]Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy. 2014. Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572 (2014). [12]Fabrizio Guillaro, Giada Zingarini, Ben Usman, Avneesh Sud, Davide Cozzolino, and Luisa Verdoliva. 2025. A bias-free training paradigm for more general ai- generated image detection. In Proceedings of the Computer Vision and Pattern Recognition Conference. 18685–18694. [13]Xiaoxuan Han, Songlin Yang, Wei Wang, Yang Li, and Jing Dong. 2025. Probing unlearned diffusion models: A transferable adversarial attack perspective. Pattern Recognition (2025), 112916. [14]Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun. 2016. Deep residual learning for image recognition. In Proceedings of the IEEE conference on computer vision and pattern recognition. 770–778. [15]Yan Hong and Jianfu Zhang. 2024. Wildfake: A large-scale challenging dataset for ai-generated images detection. arXiv preprint arXiv:2402.11843 (2024). [16] Chihan Huang and Xiaobo Shen. 2025. Huang: A robust diffusion model-based targeted adversarial attack against deep hashing retrieval. In Proceedings of the AAAI Conference on Artificial Intelligence, Vol. 39. 3626–3634. [17]Hossein Kashiani, Niloufar Alipour Talemi, and Fatemeh Afghah. 2025. Fre- qDebias: Towards Generalizable Deepfake Detection via Consistency-Driven Frequency Debiasing. In Proceedings of the Computer Vision and Pattern Recogni- tion Conference. 8775–8785. [18]Ouxiang Li, Jiayin Cai, Yanbin Hao, Xiaolong Jiang, Yao Hu, and Fuli Feng. 2025. Improving synthetic image detection towards generalization: An image transformation perspective. In Proceedings of the 31st ACM SIGKDD Conference on Knowledge Discovery and Data Mining V. 1. 2405–2414. [19]Yixuan Li, Xuelin Liu, Xiaoyang Wang, Bu Sung Lee, Shiqi Wang, Anderson Rocha, and Weisi Lin. 2025. Fakebench: Probing explainable fake image detection via large multimodal models. IEEE Transactions on Information Forensics and Security (2025). [20] Kaiqing Lin, Yuzhen Lin, Weixiang Li, Taiping Yao, and Bin Li. 2025. Standing on the shoulders of giants: Reprogramming visual-language model for general deepfake detection. In Proceedings of the AAAI Conference on Artificial Intelligence, Vol. 39. 5262–5270. [21] Decheng Liu, Xijun Wang, Chunlei Peng, Nannan Wang, Ruimin Hu, and Xinbo Gao. 2024. Adv-diffusion: imperceptible adversarial face identity attack via latent diffusion model. In Proceedings of the AAAI conference on artificial intelligence, Vol. 38. 3585–3593. [22]Huan Liu, Zichang Tan, Chuangchuang Tan, Yunchao Wei, Jingdong Wang, and Yao Zhao. 2024. Forgery-aware adaptive transformer for generalizable synthetic image detection. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition. 10770–10780. [23]Yuanwei Liu, Hui Wei, Chengyu Jia, Ruqi Xiao, Weijian Ruan, Xingxing Wei, Joey Tianyi Zhou, and Zheng Wang. 2025. Projattacker: A configurable physical adversarial attack for face recognition via projector. In Proceedings of the Computer Vision and Pattern Recognition Conference. 21248–21257. [24] Ze Liu, Yutong Lin, Yue Cao, Han Hu, Yixuan Wei, Zheng Zhang, Stephen Lin, and Baining Guo. 2021. Swin transformer: Hierarchical vision transformer us- ing shifted windows. In Proceedings of the IEEE/CVF international conference on computer vision. 10012–10022. [25]Wei Lu, Lingyi Liu, Bolin Zhang, Junwei Luo, Xianfeng Zhao, Yicong Zhou, and Jiwu Huang. 2024. Detection of Deepfake Videos Using Long-Distance Attention. IEEE Transactions on Neural Networks and Learning Systems 35, 7 (2024), 9366–9379. doi:10.1109/TNNLS.2022.3233063 [26]Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu. 2018. Towards Deep Learning Models Resistant to Adversarial Attacks. In International Conference on Learning Representations. [27]Utkarsh Ojha, Yuheng Li, and Yong Jae Lee. 2023. Towards universal fake image detectors that generalize across generative models. In Proceedings of the IEEE/CVF conference on computer vision and pattern recognition. 24480–24489. [28]Zhengzhao Pan, Hua Chen, and Xiaogang Zhang. 2025. DiffAdvMAP: Flexible Diffusion-Based Framework for Generating Natural Unrestricted Adversarial Examples. In Forty-second International Conference on Machine Learning. [29]Buu Phan, Fahim Mannan, and Felix Heide. 2021. Adversarial Imaging Pipelines. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recog- nition (CVPR). 16051–16061. [30]Robin Rombach, Andreas Blattmann, Dominik Lorenz, Patrick Esser, and Björn Ommer. 2022. High-resolution image synthesis with latent diffusion models. In Proceedings of the IEEE/CVF conference on computer vision and pattern recognition. 10684–10695. [31]Andreas Rossler, Davide Cozzolino, Luisa Verdoliva, Christian Riess, Justus Thies, and Matthias Niessner. 2019. FaceForensics++: Learning to Detect Manipulated Facial Images. In Proceedings of the IEEE/CVF International Conference on Computer Vision (ICCV). [32]Susim Roy, Anubhooti Jain, Mayank Vatsa, and Richa Singh. 2025. Taigen: Training-free adversarial image generation via diffusion models. In Proceedings of the IEEE/CVF International Conference on Computer Vision. 5903–5913. [33]Chuangchuang Tan, Renshuai Tao, Huan Liu, Guanghua Gu, Baoyuan Wu, Yao Zhao, and Yunchao Wei. 2025. C2p-clip: Injecting category common prompt in clip to enhance generalization in deepfake detection. In Proceedings of the AAAI Conference on Artificial Intelligence, Vol. 39. 7184–7192. Conference acronym ’X, June 03–05, 2018, Woodstock, NYJiale Zhao, Jiajun Wan, Lei Tang, Ye Qin, Kebing Jin, and Jinghui Qin [34]Chuangchuang Tan, Yao Zhao, Shikui Wei, Guanghua Gu, Ping Liu, and Yunchao Wei. 2024. Frequency-aware deepfake detection: Improving generalizability through frequency space domain learning. In Proceedings of the AAAI Conference on Artificial Intelligence, Vol. 38. 5052–5060. [35]Chuangchuang Tan, Yao Zhao, Shikui Wei, Guanghua Gu, Ping Liu, and Yunchao Wei. 2024. Rethinking the up-sampling operations in cnn-based generative network for generalizable deepfake detection. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition. 28130–28139. [36] Chuangchuang Tan, Yao Zhao, Shikui Wei, Guanghua Gu, and Yunchao Wei. 2023. Learning on Gradients: Generalized Artifacts Representation for GAN-Generated Images Detection. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR). 12105–12114. [37] Mingxing Tan and Quoc Le. 2019. Efficientnet: Rethinking model scaling for convolutional neural networks. In International conference on machine learning. PMLR, 6105–6114. [38]Razaib Tariq, Minji Heo, Simon S Woo, and Shahroz Tariq. 2024. Beyond the screen: Evaluating deepfake detectors under Moire pattern effects. In Proceedings of the IEEE/CVF conference on computer vision and pattern recognition. 4429–4439. [39]Hugo Touvron, Matthieu Cord, Matthijs Douze, Francisco Massa, Alexandre Sablayrolles, and Hervé Jégou. 2021. Training data-efficient image transformers & distillation through attention. In International conference on machine learning. PMLR, 10347–10357. [40]Kwang-Hyun Uhm, Kyuyeon Choi, Seung-Won Jung, and Sung-Jea Ko. 2021. Image compression-aware deep camera ISP network. IEEE Access 9 (2021), 137824– 137832. [41] Haoyue Wang, Sheng Li, Zhenxing Qian, and Xinpeng Zhang. 2026. Adversarial Diffusion Model: Generating High Quality and Undetectable Images from Scratch. IEEE Transactions on Information Forensics and Security (2026). [42]Hui Wei, Zhixiang Wang, Kewei Zhang, Jiaqi Hou, Yuanwei Liu, Hao Tang, and Zheng Wang. 2024. Revisiting adversarial patches for designing camera-agnostic attacks against person detection. Advances in Neural Information Processing Systems 37 (2024), 8047–8064. [43]Wenjun Wei, Yanlin Qian, Huaian Chen, Junkang Dai, and Yi Jin. 2025. Integral Fast Fourier Color Constancy. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR). 26420–26429. [44]Siwei Wen, Junyan Ye, Peilin Feng, Hengrui Kang, Zichen Wen, Yize Chen, Jiang Wu, Conghui He, Weijia Li, et al.[n. d.]. Spot the Fake: Large Multimodal Model- Based Synthetic Image Detection with Artifact Explanation. In The Thirty-ninth Annual Conference on Neural Information Processing Systems. [45]Mengjie Wu, Jingui Ma, Run Wang, Sidan Zhang, Ziyou Liang, Boheng Li, Chen- hao Lin, Liming Fang, and Lina Wang. 2024. Traceevader: Making deepfakes more untraceable via evading the forgery model attribution. In Proceedings of the AAAI Conference on Artificial Intelligence, Vol. 38. 19965–19973. [46]Yazhou Xing, Zian Qian, and Qifeng Chen. 2021. Invertible Image Signal Process- ing. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR). 6287–6296. [47] Haotian Xue, Alexandre Araujo, Bin Hu, and Yongxin Chen. 2023. Diffusion- based adversarial sample generation for improved stealthiness and controllability. Advances in Neural Information Processing Systems 36 (2023), 2894–2921. [48]Shilin Yan, Ouxiang Li, Jiayin Cai, Yanbin Hao, Xiaolong Jiang, Yao Hu, and Weidi Xie. [n. d.]. A Sanity Check for AI-generated Image Detection. In The Thirteenth International Conference on Learning Representations. [49]Kai Zhang, Wangmeng Zuo, Yunjin Chen, Deyu Meng, and Lei Zhang. 2017. Beyond a Gaussian denoiser: Residual learning of deep CNN for image denoising. IEEE Transactions on Image Processing 26, 7 (2017), 3142–3155. [50] Yin Zhang, Yongqiang Zhang, Zian Zhang, Man Zhang, Rui Tian, and Mingli Ding. 2024. Isp-teacher: Image signal process with disentanglement regularization for unsupervised domain adaptive dark object detection. In Proceedings of the AAAI Conference on Artificial Intelligence, Vol. 38. 7387–7395. [51] Guanglei Zhou, Bhargav Korrapati, Gaurav Rajavendra Reddy, Chen-Chia Chang, Jingyu Pan, Jiang Hu, Yiran Chen, and Dipto G Thakurta. 2025. Patternpaint: Practical layout pattern generation using diffusion-based inpainting. In 2025 62nd ACM/IEEE Design Automation Conference (DAC). IEEE, 1–7. [52] Ziyin Zhou, Ke Sun, Zhongxi Chen, Huafeng Kuang, Xiaoshuai Sun, and Ron- grong Ji. 2024. Stealthdiffusion: Towards evading diffusion forensic detection through diffusion model. In Proceedings of the 32nd ACM International Conference on Multimedia. 3627–3636. [53] Mingjian Zhu, Hanting Chen, Qiangyu Yan, Xudong Huang, Guanyu Lin, Wei Li, Zhijun Tu, Hailin Hu, Jie Hu, and Yunhe Wang. 2023. Genimage: A million-scale benchmark for detecting ai-generated image. Advances in neural information processing systems 36 (2023), 77771–77782. [54]Wenjun Zhu, Xiaoyu Ji, Xinfeng Li, Qihang Chen, Kun Wang, Xinyu Li, Ruoyan Xu, and Wenyuan Xu. 2025. Neural Invisibility Cloak: Concealing Adversary in Images via CompromisedAI-drivenImage Signal Processing. In 34th USENIX Security Symposium (USENIX Security 25). 937–956.