NeFut Logo NeFut
中 Admin Login

[CS.AI] Can Pixels Alone Reveal Image Origin? Minimax Limits and Learnable Interfaces for Passive Provenance

Published at: 2026-09-29 22:00 Last updated: 2026-09-30 01:41
#algorithm #AI #Machine Learning

Passive image provenance asks whether raw pixels suffice to infer an image's origin—human, a broad AI class, or a specific generator. When the source image may be edited before verification, the task becomes source‑target verification under adversarial distribution shift. Our first result establishes the exact best‑case bound for any pixel‑only verifier: the largest robust target‑acceptance gap equals the minimum total‑variation distance $d_{\text{TV}}$ between the target distribution and the set of attacked source distributions. This quantity depends only on the source, target and edit class, not on the verifier architecture. The second result explains why deployed public verifiers can fail before reaching this statistical limit. If the verifier can be emulated on the attack region with error $\varepsilon$, a surrogate black‑box attack attains target acceptance within $2\varepsilon$ plus the optimization error of the white‑box optimum. Logistic and softmax heads over public features are identifiable, and approximate score access yields stable recovery bounds. A finite‑state experiment verifies the minimax identity where both sides are computable. On same‑prompt real/diffusion benchmarks, evaluated public CLIP verifiers collapse under targeted pixel attacks, while a ResNet‑18 victim shows partial fake‑to‑real transfer. Binary feedback with abstention reduces measured attack success, yet positive empirical gap upper bounds do not guarantee robustness. These findings motivate separate evaluation of the source‑target statistical ceiling and the information leaked by a deployed verifier.

Review: The paper frames passive provenance as a statistical minimax problem, provides a clear total‑variation bound, and demonstrates practical gaps in existing verifiers, offering both theoretical insight and empirical guidance for building more reliable provenance detectors.

Original Source: https://arxiv.org/abs/2609.30997

[h] Back to Home