Organizations: University of Oxford, the United Kingdom · Independent Researcher · Imperial College London, the United Kingdom · National University of Singapore, Singapore
As generated images become increasingly realistic, reliable forgery detection is essential for maintaining trust in visual information. However, existing methods primarily rely on task-specific supervision to adapt vision foundation model representations, without fully exploiting internal forensic knowledge to guide detection. To address this limitation, we propose Reserve-Guided Elicitation (RGE), a framework that treats sparse, origin-sensitive internal components in pretrained models as a forensic reserve and translates their localization into structural constraints for lightweight adaptation. Specifically, we first use the Forensic Lens (F-lens) to decompose activations across layers and token groups into independent components and globally screen them by their response differences between real and generated images, identifying reserve sites and directions. Next, we map the selected directions back to hidden-state space to construct fixed reserve subspaces and insert Forensic Reserve Adapters (FRA) only at the identified sites. Finally, with the backbone parameters, previously fitted reference classifier, and subspace bases fixed, we train only the FRA coefficient maps to generate input-dependent residual updates constrained to the corresponding subspaces, strengthening existing forensic responses. Using only 500 labeled training images and a trainable parameter budget below 0.2% of the backbone, RGE achieves competitive performance across three detection benchmarks without target-benchmark adaptation. Furthermore, RGE consistently improves over the corresponding frozen detectors across eight encoders spanning self-supervised and vision-language pretraining, eliciting a latent forensic capacity broadly shared across pretrained vision models.
Figures & tables
Figure 1: Comparison of Forgery Detection Paradigms. Fine-tuning relies on large labeled sets without localizing forensic evidence; RGE localizes the forensic reserve to guide targeted enhancement of existing internal responses.
Figure 2: Overview of Reserve-Guided Elicitation (RGE). F-lens localizes the forensic reserve in the frozen backbone (Section 3.1 ); FRA writes within the mapped reserve subspaces at selected sites (Section 3.2 ).
AIGIBench
Chameleon
HiRes-50K
Average
Method
mAP ↑
Acc ↑
mAP ↑
Acc ↑
mAP ↑
Acc ↑
mAP ↑
Acc ↑
UnivFD ( Ojha et al., 2023 )
75.60
72.50
46.20
57.20
54.93
62.05
58.91
63.92
DRCT ( Chen et al., 2024 )
85.18
71.96
85.20
79.80
81.76
67.17
84.05
72.98
AIDE ( Yan et al., 2025a )
82.70
77.60
69.70
65.80
74.61
56.46
75.67
66.62
DDA ( Chen et al., 2025b )
90.20
81.60
91.20
82.40
93.70
85.09
91.70
83.03
HiDA-Net ( Mu et al., 2026 )
N/A
N/A
N/A
79.10
N/A
80.33
N/A
N/A
Table 1: Detection Across Three Benchmarks (%). RGE uses 0.5K discovery images; Average is the mean over the three benchmarks. Best and second-best are bold and underlined; N/A denotes unavailable results.
Figure 3: Scaling and Qualitative Results. (a) Detection across discovery sizes on AIGIBench; bars span five training seeds. (b) Final-score sensitivity Sfinal for real and fake pairs (blue: low, red: high).
Figure 4: Reserve Localization and Elicited Responses. (a) Probe AP (outer rings) and gate IG (inner rings) per layer–token site, with the knockout of discovery-ranked versus random site groups at the center. (b) Depth-restricted adaptation, with light and dark shades showing mAP and mBA. (c) Responses of one reserve component on the same images before and after FRA, measured in a fixed ICA coordinate.
Adaptation Variant
mAP ↑
mBA ↑
RGE (Ours)
97.58
93.41
(a) Component Selection
Random-In
95.37
(−2.21)
89.52
(−3.89)
Random-Ex
94.26
(−3.32)
88.47
(−4.94)
Bottom-K
93.31
(−4.27)
87.34
(−6.07)
(b) Allocation and Parameterization
Table 2: Adaptation Structure on AIGIBench. Parentheses give decreases from RGE.
Figure 5: Functional Contribution of the Learned Writes. (a–b) Removing writes in gate-IG order versus five random orders (mean and range). (c) Detection versus write gate g . (d) Decisions changed by the writes.
Figure 6: Backbones and Component Budget. (a) mAP of the baseline (gray) and RGE (blue) across eight ViT backbones on AIGIBench. (b) Change in mAP and mBA relative to the 1% budget.
Figure 7: Robustness Under Image Perturbations. (a) mAP of RGE and the baseline on clean images and under JPEG compression, resizing, and blurring. (b) Final-score sensitivity for a real (top) and a fake (bottom) dog under the same perturbations.
Appendix figures & tables5 assets
Supplementary material from the paper’s appendix.
Appendix
Figure 8: Discovery Composition. Wedges show target shares within each class; labels give the target share and the unique selected images at 0.5K | 5K, before training draws with replacement.
Figure 9: Final-Score and Localized-Write Sensitivity. Sfinal and Swrite for the three pairs in Figure 3 (b); each map type is normalized within its real/fake pair.
0.5K Discovery
5K Discovery
20K Discovery
Fraction
Rank
Parameters
Backbone
Rank
Parameters
Backbone
Rank
Parameters
Backbone
0.1%
92
117,760
0.0140%
118
151,040
0.0180%
120
153,600
0.0183%
0.25%
230
294,400
0.0350%
294
376,320
0.0448%
299
382,720
0.0455%
0.5%
459
587,520
0.0699%
587
751,360
0.0894%
598
765,440
0.0911%
1%
918
1,175,040
0.1398%
1,174
1,502,720
0.1788%
1,196
1,530,880
0.1821%
2%
1,835
2,348,800
0.2794%
2,347
3,004,160
0.3574%
2,391
3,060,480
0.3641%
Appendix
Table 3: Reserve Selection and Trainable Capacity. Six retained component fractions across three discovery sizes. The shaded row is the default top-1% configuration. The backbone denominator is 840.6M parameters.
Method
mAP ↑
mAcc ↑
FreqNet
77.71
73.42
UnivFD
84.33
74.17
AIDE
83.72
84.75
SAFE
86.26
86.66
PLM
90.44
88.18
FSD (10-shot)
80.54
75.87
Appendix
Table 4: Detection on Treasure-64 (%). RGE uses 0.5K discovery images; superscripts give its change from the baseline. Best and second-best results are bold and underlined.
Figure 10: Detection by Source Category and Resolution Interval (%). Decision metric (left; mAcc, mBA, and Acc) and mAP (right) of RGE at 0.5K, 5K, and 20K discovery images (light to dark; labels give 20K), with published references as markers. Parentheses give source counts; HiRes-50K intervals give the image long edge in pixels. Bars start at 60%. Fleet † uses 10-shot adaptation with images from Treasure-64.
Advances in generative AI have made image falsification highly realistic, demanding trustworthy authentication systems. Existing forensic detectors can target certain forgery types but lack interpretability, while vision-language models (VLMs) provide explanations but cannot exploit forensic traces for reliable detection. We propose Forensic Knowledge Graphs (FKGs), a unified framework that integrates forensic evidence extraction, structured reasoning, and human-interpretable explanation. Our FKG structure encodes forensic traces along with their causal dependencies and links to scene content. To generate accurate FKGs, we introduce a novel forensic authentication network and an Iterative Context Refinement strategy that guides VLMs to produce faithful, grounded explanations. We also present FKG-50K, a dataset of 50,000 realistic forgeries with ground-truth FKGs. Experiments demonstrate that FKG outperforms both forensic detectors and VLMs in detection, forgery identification and localization, and forensic justification.
With the rapid advancement of deep generative models, realistic fake images have become increasingly accessible, yet existing localization methods rely on complex designs and still struggle to generalize across manipulation types and imaging conditions. We present a simple but strong baseline based on DINOv3 with LoRA adaptation and a lightweight convolutional decoder. Under the CAT-Net protocol, our best model improves average pixel-level F1 by 17.0 points over the previous state of the art on four standard benchmarks using only 9.1,M trainable parameters on top of a frozen ViT-L backbone, and even our smallest variant surpasses all prior specialized methods. LoRA consistently outperforms full fine-tuning across all backbone scales. Under the data-scarce MVSS-Net protocol, LoRA reaches an average F1 of 0.774 versus 0.530 for the strongest prior method, while full fine-tuning becomes highly unstable, suggesting that pre-trained representations encode forensic information that is better preserved than overwritten. The baseline also exhibits strong robustness to Gaussian noise, JPEG re-compression, and Gaussian blur. We hope this work can serve as a reliable baseline for the research community and a practical starting point for future image-forensic applications. Code is available at https://github.com/Irennnne/DINOv3-IML.
Jieming Yu, Qiuxiao Feng, Zhuohan Wang +1
The Hong Kong University of Science and Technology · Harvard University
With the rapid development of generative models and multimodal content editing technologies, the key challenge faced by synthetic image detection (SID) lies in cross-distribution generalization to unknown generation sources. In recent years, visual foundation models (VFM), which acquire rich visual priors through large scale image-text alignment pretraining, have become a promising technical route for improving the generalization ability of SID. However, existing VFM-based methods remain relatively coarse-grained in their adaptation strategies. They typically either directly use the final layer representations of VFM or simply fuse multi layer features, lacking explicit modeling of the optimal representational hierarchy for transferable forgery cues. Meanwhile, although directly fine-tuning VFM can enhance task adaptation, it may also damage the cross-modal pretrained structure that supports open-set generalization. To address this task specific tension, we reformulate VFM adaptation for SID as a joint optimization problem: it is necessary both to identify the critical representational layer that is more suitable for carrying forgery discriminative information and to constrain the disturbance caused by task knowledge injection to the pretrained structure. Based on this, we propose I2P, an SID framework centered on intrinsic importance perception. I2P first adaptively identifies the critical layer representations that are most discriminative for SID, and then constrains task-driven parameter updates within a low sensitivity parameter subspace, thereby improving task specificity while preserving the transferable structure of pretrained representations as much as possible.
Jiazhen Yang, Junjun Zheng, Kejia Chen +5
Zhejiang University · Hangzhou, China · Alibaba Inc +1