Organizations: University of Oxford, the United Kingdom · Independent Researcher · Imperial College London, the United Kingdom · National University of Singapore, Singapore
As generated images become increasingly realistic, reliable forgery detection is essential for maintaining trust in visual information. However, existing methods primarily rely on task-specific supervision to adapt vision foundation model representations, without fully exploiting internal forensic knowledge to guide detection. To address this limitation, we propose Reserve-Guided Elicitation (RGE), a framework that treats sparse, origin-sensitive internal components in pretrained models as a forensic reserve and translates their localization into structural constraints for lightweight adaptation. Specifically, we first use the Forensic Lens (F-lens) to decompose activations across layers and token groups into independent components and globally screen them by their response differences between real and generated images, identifying reserve sites and directions. Next, we map the selected directions back to hidden-state space to construct fixed reserve subspaces and insert Forensic Reserve Adapters (FRA) only at the identified sites. Finally, with the backbone parameters, previously fitted reference classifier, and subspace bases fixed, we train only the FRA coefficient maps to generate input-dependent residual updates constrained to the corresponding subspaces, strengthening existing forensic responses. Using only 500 labeled training images and a trainable parameter budget below 0.2% of the backbone, RGE achieves competitive performance across three detection benchmarks without target-benchmark adaptation. Furthermore, RGE consistently improves over the corresponding frozen detectors across eight encoders spanning self-supervised and vision-language pretraining, eliciting a latent forensic capacity broadly shared across pretrained vision models.
Figures & tables
Figure 1: Comparison of Forgery Detection Paradigms. Fine-tuning relies on large labeled sets without localizing forensic evidence; RGE localizes the forensic reserve to guide targeted enhancement of existing internal responses.
Figure 2: Overview of Reserve-Guided Elicitation (RGE). F-lens localizes the forensic reserve in the frozen backbone (Section 3.1 ); FRA writes within the mapped reserve subspaces at selected sites (Section 3.2 ).
AIGIBench
Chameleon
HiRes-50K
Average
Method
mAP ↑
Acc ↑
mAP ↑
Acc ↑
mAP ↑
Acc ↑
mAP ↑
Acc ↑
UnivFD ( Ojha et al., 2023 )
75.60
72.50
46.20
57.20
54.93
62.05
58.91
63.92
DRCT ( Chen et al., 2024 )
85.18
71.96
85.20
79.80
81.76
67.17
84.05
72.98
AIDE ( Yan et al., 2025a )
82.70
77.60
69.70
65.80
74.61
56.46
75.67
66.62
DDA ( Chen et al., 2025b )
90.20
81.60
91.20
82.40
93.70
85.09
91.70
83.03
HiDA-Net ( Mu et al., 2026 )
N/A
N/A
N/A
79.10
N/A
80.33
N/A
N/A
Table 1: Detection Across Three Benchmarks (%). RGE uses 0.5K discovery images; Average is the mean over the three benchmarks. Best and second-best are bold and underlined; N/A denotes unavailable results.
Figure 3: Scaling and Qualitative Results. (a) Detection across discovery sizes on AIGIBench; bars span five training seeds. (b) Final-score sensitivity Sfinal for real and fake pairs (blue: low, red: high).
Figure 4: Reserve Localization and Elicited Responses. (a) Probe AP (outer rings) and gate IG (inner rings) per layer–token site, with the knockout of discovery-ranked versus random site groups at the center. (b) Depth-restricted adaptation, with light and dark shades showing mAP and mBA. (c) Responses of one reserve component on the same images before and after FRA, measured in a fixed ICA coordinate.
Adaptation Variant
mAP ↑
mBA ↑
RGE (Ours)
97.58
93.41
(a) Component Selection
Random-In
95.37
(−2.21)
89.52
(−3.89)
Random-Ex
94.26
(−3.32)
88.47
(−4.94)
Bottom-K
93.31
(−4.27)
87.34
(−6.07)
(b) Allocation and Parameterization
Table 2: Adaptation Structure on AIGIBench. Parentheses give decreases from RGE.
Figure 5: Functional Contribution of the Learned Writes. (a–b) Removing writes in gate-IG order versus five random orders (mean and range). (c) Detection versus write gate g . (d) Decisions changed by the writes.
Figure 6: Backbones and Component Budget. (a) mAP of the baseline (gray) and RGE (blue) across eight ViT backbones on AIGIBench. (b) Change in mAP and mBA relative to the 1% budget.
Figure 7: Robustness Under Image Perturbations. (a) mAP of RGE and the baseline on clean images and under JPEG compression, resizing, and blurring. (b) Final-score sensitivity for a real (top) and a fake (bottom) dog under the same perturbations.
Appendix figures & tables5 assets
Supplementary material from the paper’s appendix.
Appendix
Figure 8: Discovery Composition. Wedges show target shares within each class; labels give the target share and the unique selected images at 0.5K | 5K, before training draws with replacement.
Figure 9: Final-Score and Localized-Write Sensitivity. Sfinal and Swrite for the three pairs in Figure 3 (b); each map type is normalized within its real/fake pair.
0.5K Discovery
5K Discovery
20K Discovery
Fraction
Rank
Parameters
Backbone
Rank
Parameters
Backbone
Rank
Parameters
Backbone
0.1%
92
117,760
0.0140%
118
151,040
0.0180%
120
153,600
0.0183%
0.25%
230
294,400
0.0350%
294
376,320
0.0448%
299
382,720
0.0455%
0.5%
459
587,520
0.0699%
587
751,360
0.0894%
598
765,440
0.0911%
1%
918
1,175,040
0.1398%
1,174
1,502,720
0.1788%
1,196
1,530,880
0.1821%
2%
1,835
2,348,800
0.2794%
2,347
3,004,160
0.3574%
2,391
3,060,480
0.3641%
Appendix
Table 3: Reserve Selection and Trainable Capacity. Six retained component fractions across three discovery sizes. The shaded row is the default top-1% configuration. The backbone denominator is 840.6M parameters.
Method
mAP ↑
mAcc ↑
FreqNet
77.71
73.42
UnivFD
84.33
74.17
AIDE
83.72
84.75
SAFE
86.26
86.66
PLM
90.44
88.18
FSD (10-shot)
80.54
75.87
Appendix
Table 4: Detection on Treasure-64 (%). RGE uses 0.5K discovery images; superscripts give its change from the baseline. Best and second-best results are bold and underlined.
Figure 10: Detection by Source Category and Resolution Interval (%). Decision metric (left; mAcc, mBA, and Acc) and mAP (right) of RGE at 0.5K, 5K, and 20K discovery images (light to dark; labels give 20K), with published references as markers. Parentheses give source counts; HiRes-50K intervals give the image long edge in pixels. Bars start at 60%. Fleet † uses 10-shot adaptation with images from Treasure-64.