Deepfake Adversarial Transfer — Benchmark Models
This repository provides the 60 deepfake detectors used in What Makes Adversarial Examples Transfer Across Deepfake Detectors? by Rafael M. Mamede, Pedro C. Neto and Ana F. Sequeira.
The detector bank spans six backbones, two pretraining regimes and five training-data configurations. It supports research into how these factors affect deepfake detection and adversarial transfer. The corresponding clean and adversarial evaluation images are available in the companion dataset.
These are the detectors evaluated in the study. Their inclusion does not imply adversarial training or resistance to the released attacks. CLIP models are not included in this release.
Model bank
| Directory identifier | Architecture |
|---|---|
resnet34 |
ResNet-34 |
xception |
Xception |
efficientnetb4 |
EfficientNet-B4 |
deit |
DeiT-S |
vit |
ViT-B/16 |
swin |
Swin-T |
| Pretraining directory | Initial pretraining |
|---|---|
imgnet |
ImageNet |
fr_pretrain |
Face recognition on BUPT-BalancedFace |
| Training-subset suffix | Manipulated-image training configuration |
|---|---|
FS |
Face swapping |
FR |
Face reenactment |
EFS |
Entire-face synthesis |
FE |
Face editing |
ALL |
Union of the four manipulation families |
The suffix identifies the detector's training configuration, not a restriction on the images that can be evaluated. The FR training suffix means face reenactment; fr_pretrain means face-recognition pretraining. See the paper for training-data composition and experimental protocols.
Each architecture/pretraining/training-subset combination has one selected checkpoint: 6 × 2 × 5 = 60 models.
Repository contents
| Path | Contents |
|---|---|
imgnet/<backbone>_<subset>/ckpt_best.pth |
Selected ImageNet-pretrained detector checkpoint |
fr_pretrain/<backbone>_<subset>/ckpt_best.pth |
Selected face-recognition-pretrained detector checkpoint |
<pretraining>/<backbone>_<subset>/config.yaml |
Original detector configuration |
<pretraining>/<backbone>_<subset>/best_threshold.json |
Validation-selected decision threshold |
models.json |
Model identifiers, release paths and source-path provenance |
source_models.json |
Original selection of 60 checkpoints and configurations |
SHA256SUMS |
Checksums for files listed in the checksum manifest |
inference/load_model.py |
Configuration, checkpoint and preprocessing loader |
inference/predict.py |
Single-image or directory inference with CSV output |
inference/check_models.py |
Loading and forward-pass checks for the model bank |
inference/modeling/ |
Detector, backbone, loss and metric implementations adapted from the submission code |
INFERENCE.md |
Additional inference instructions |
The configuration files preserve the original experiment settings. The loader disables initial pretraining-file loading and downloads in an in-memory copy of the configuration, then loads the final detector checkpoint. Original source paths in metadata are provenance and are not needed to locate the released weights.
Model identifiers in models.json use imgnet_ and fr_ prefixes. For example:
| CLI model identifier | Repository directory |
|---|---|
imgnet_resnet34_ALL |
imgnet/resnet34_ALL/ |
fr_resnet34_ALL |
fr_pretrain/resnet34_ALL/ |
Download
The files can be downloaded with huggingface_hub. This example downloads one detector and the shared inference code:
from huggingface_hub import snapshot_download
release_path = snapshot_download(
repo_id="poisonedchicken/deepfake-adversarial-transfer-models",
repo_type="model",
allow_patterns=[
"README.md",
"INFERENCE.md",
"LICENSE*",
"NOTICE*",
"models.json",
"SHA256SUMS",
"inference/*",
"imgnet/resnet34_ALL/*",
],
)
print(release_path)
Change the detector path to select another model. Omit allow_patterns to download the full release, approximately 7.33 GiB for the staged checkpoints, configurations and thresholds. For reproducible use, pass revision with the desired repository commit.
Downloading the files does not install their Python dependencies. The checkpoints use custom PyTorch detector classes; they are loaded with this repository's inference code.
Environment
The submission environment records the following core versions:
| Component | Version |
|---|---|
| Python | 3.7.12 |
| PyTorch | 1.12.0+cu113 |
| torchvision | 0.13.0+cu113 |
| timm | 0.6.12 |
| efficientnet-pytorch | 0.7.1 |
| NumPy | 1.21.5 |
| Pillow | 9.0.1 |
| PyYAML | 6.0 |
| scikit-learn | 1.0.2 |
| TensorBoard | 2.10.1 |
| huggingface-hub | 0.16.4 |
These are the recorded submission versions, not a claim of compatibility with every later version. The bundled detector implementations retain some training-related imports, including scikit-learn and TensorBoard. A minimal, independently validated fresh-environment installation is not yet provided. The released scripts have been exercised in the maintainer's existing DeepfakeBenchPacked environment.
Inference
Run commands from the downloaded repository root, using an environment with the dependencies above. For the Python download example, this is the directory printed as release_path.
python -m inference.predict \
--model imgnet_resnet34_ALL \
--input /path/to/cropped_face.png \
--output /tmp/deepfake_prediction.csv \
--device cpu \
--resize
Replace the input path with an actual image or directory. Directory inputs are searched recursively. Use a new output filename for each run; existing CSVs are not overwritten.
For batched GPU inference:
python -m inference.predict \
--model fr_resnet34_ALL \
--input /path/to/cropped_faces \
--output /tmp/deepfake_predictions_fr.csv \
--device cuda \
--batch-size 16 \
--resize
Download the corresponding FR model files before running the second example.
Inputs and preprocessing
The scripts expect already cropped face images. They do not detect faces, align faces, extract video frames or aggregate predictions across a video.
Preprocessing follows the submission's transfer-evaluation code:
- Load the image with Pillow and convert it to RGB.
- With
--resize, resize to the configured square input resolution using torchvision's PIL resize operation. - Convert pixels to a tensor in [0, 1].
- Normalize using the selected detector configuration's
meanandstd.
The benchmark models use 224 × 224 inputs. Stored image dimensions may differ: a clean image tested during release validation was 256 × 256. Without --resize, the script requires images to already match the configured input size.
For adversarial evaluation, preserve the preprocessing used by the relevant experiment. Resizing, recompression or other processing of adversarial images can change attack effectiveness. Do not assume that every stored evaluation image needs resizing.
Scores and decisions
Each detector produces a fake-class probability. The threshold is read from the threshold field in its best_threshold.json file. Thresholds were selected using held-out validation data to maximize balanced accuracy.
prob_fake >= threshold: prediction1, labelfake.prob_fake < threshold: prediction0, labelreal.
The CSV contains image, model, prob_fake, threshold, pred and label. Relative image paths are retained for directory inputs. Scores are model outputs and should not be interpreted as universally calibrated probabilities of authenticity.
Release validation
The maintainer reports that all 60 models passed strict checkpoint loading and a synthetic-image forward pass on a GPU using the release scripts. A real-image CPU inference test also completed successfully for imgnet_resnet34_ALL with resizing enabled.
To repeat the model-bank smoke test after downloading all checkpoints:
python -m inference.check_models --device cuda
Checkpoint loading uses strict=True, so missing or unexpected state-dictionary keys cause an error rather than permitting partially initialized predictions. Packaging also verified copied checkpoints, configurations and thresholds with SHA-256 checksums.
These checks establish loading and basic execution in the tested environment. They do not independently reproduce the paper's metrics or establish numerical equivalence across environments. Full comparison against the original evaluator remains separate from the smoke test.
After a complete download, verify the files listed in the checksum manifest with:
sha256sum --check SHA256SUMS
Intended use and limitations
The models are intended for research into deepfake detection, cross-detector adversarial transfer and robustness evaluation. Pairwise and portfolio evaluations should use the paper's source/target definitions, eligibility rules and target-specific thresholds.
- Performance may change with manipulation technique, data source, image quality and preprocessing.
- The study demonstrates susceptibility to adversarial examples; these checkpoints do not provide a robustness guarantee.
- A real/fake prediction is not sufficient evidence for a consequential decision about a person or a media item.
- The model bank does not establish demographic representativeness or equal performance across groups.
- The companion image release is fake-only. Authentic examples are additionally required for metrics such as ROC-AUC, specificity and balanced accuracy.
Licence and attribution
The authors' model-release contributions are made available under Creative Commons Attribution–NonCommercial 4.0 International (CC BY-NC 4.0), to the extent of the rights they hold.
This licence allows noncommercial sharing and adaptation with appropriate attribution, a licence link and an indication of changes. Retain existing attribution and modification notices, and do not impose additional legal or technological restrictions on uses permitted by the licence.
Credit Rafael M. Mamede, Pedro C. Neto and Ana F. Sequeira for this benchmark and cite the study below. The implementation builds on DeepfakeBench and the relevant architecture libraries. Third-party code, pretrained components and source material remain subject to their applicable licences and notices; this statement does not relicense them or grant rights the authors do not hold.
The model bank's manipulated-image training configurations derive from DF40. The companion adversarial dataset is a separate evaluation release, not the detector-training dataset. Please also acknowledge DF40 and the underlying datasets relevant to your use.
Citation
@misc{mamede2026makesadversarialexamplestransfer,
title = {What Makes Adversarial Examples Transfer Across Deepfake Detectors?},
author = {Rafael M. Mamede and Pedro C. Neto and Ana F. Sequeira},
year = {2026},
eprint = {2609.10002},
archivePrefix = {arXiv},
primaryClass = {cs.CV},
url = {https://arxiv.org/abs/2609.10002}
}
Questions and reproducibility issues can be raised in the repository's Discussions.