כתבה
arXiv cs.AI ·
What Makes Adversarial Examples Transfer Across Deepfake Detectors?
תקציר מקורי באנגליתarXiv:2609.10002v1 Announce Type: cross Abstract: Deepfake detectors remain vulnerable to transfer-based black-box attacks, in which adversarial examples are generated on a source surrogate model and transferred to a target model, unknown to the attacker. Yet how source--target compatibility shapes attack success remains poorly understood. Prior studies evaluate limited detector pools and rarely disentangle architectural from training factors. We conduct a controlled evaluation of adversarial transferability across 60 detectors spanning six backbones, two pretraining regimes, and five training-data configurations, using two attack procedures: AutoAttack (AA) and the Carlini--Wagner attack with Expectation over Transformation (CW--EOT). Matched comparisons reveal significantly higher transf
קרא במקור המקורי
arxiv.org
פתח כתבה מקורית