Deepfake Adversarial Transfer — Benchmark Models

This repository provides the 60 deepfake detectors used in What Makes Adversarial Examples Transfer Across Deepfake Detectors? by Rafael M. Mamede, Pedro C. Neto and Ana F. Sequeira.

The detector bank spans six backbones, two pretraining regimes and five training-data configurations. It supports research into how these factors affect deepfake detection and adversarial transfer. The corresponding clean and adversarial evaluation images are available in the companion dataset.

These are the detectors evaluated in the study. Their inclusion does not imply adversarial training or resistance to the released attacks. CLIP models are not included in this release.

Model bank

Directory identifier Architecture
resnet34 ResNet-34
xception Xception
efficientnetb4 EfficientNet-B4
deit DeiT-S
vit ViT-B/16
swin Swin-T
Pretraining directory Initial pretraining
imgnet ImageNet
fr_pretrain Face recognition on BUPT-BalancedFace
Training-subset suffix Manipulated-image training configuration
FS Face swapping
FR Face reenactment
EFS Entire-face synthesis
FE Face editing
ALL Union of the four manipulation families

The suffix identifies the detector's training configuration, not a restriction on the images that can be evaluated. The FR training suffix means face reenactment; fr_pretrain means face-recognition pretraining. See the paper for training-data composition and experimental protocols.

Each architecture/pretraining/training-subset combination has one selected checkpoint: 6 × 2 × 5 = 60 models.

Repository contents

Path Contents
imgnet/<backbone>_<subset>/ckpt_best.pth Selected ImageNet-pretrained detector checkpoint
fr_pretrain/<backbone>_<subset>/ckpt_best.pth Selected face-recognition-pretrained detector checkpoint
<pretraining>/<backbone>_<subset>/config.yaml Original detector configuration
<pretraining>/<backbone>_<subset>/best_threshold.json Validation-selected decision threshold
models.json Model identifiers, release paths and source-path provenance
source_models.json Original selection of 60 checkpoints and configurations
SHA256SUMS Checksums for files listed in the checksum manifest
inference/load_model.py Configuration, checkpoint and preprocessing loader
inference/predict.py Single-image or directory inference with CSV output
inference/check_models.py Loading and forward-pass checks for the model bank
inference/modeling/ Detector, backbone, loss and metric implementations adapted from the submission code
INFERENCE.md Additional inference instructions

The configuration files preserve the original experiment settings. The loader disables initial pretraining-file loading and downloads in an in-memory copy of the configuration, then loads the final detector checkpoint. Original source paths in metadata are provenance and are not needed to locate the released weights.

Model identifiers in models.json use imgnet_ and fr_ prefixes. For example:

CLI model identifier Repository directory
imgnet_resnet34_ALL imgnet/resnet34_ALL/
fr_resnet34_ALL fr_pretrain/resnet34_ALL/

Download

The files can be downloaded with huggingface_hub. This example downloads one detector and the shared inference code:

from huggingface_hub import snapshot_download

release_path = snapshot_download(
    repo_id="poisonedchicken/deepfake-adversarial-transfer-models",
    repo_type="model",
    allow_patterns=[
        "README.md",
        "INFERENCE.md",
        "LICENSE*",
        "NOTICE*",
        "models.json",
        "SHA256SUMS",
        "inference/*",
        "imgnet/resnet34_ALL/*",
    ],
)
print(release_path)

Change the detector path to select another model. Omit allow_patterns to download the full release, approximately 7.33 GiB for the staged checkpoints, configurations and thresholds. For reproducible use, pass revision with the desired repository commit.

Downloading the files does not install their Python dependencies. The checkpoints use custom PyTorch detector classes; they are loaded with this repository's inference code.

Environment

The submission environment records the following core versions:

Component Version
Python 3.7.12
PyTorch 1.12.0+cu113
torchvision 0.13.0+cu113
timm 0.6.12
efficientnet-pytorch 0.7.1
NumPy 1.21.5
Pillow 9.0.1
PyYAML 6.0
scikit-learn 1.0.2
TensorBoard 2.10.1
huggingface-hub 0.16.4

These are the recorded submission versions, not a claim of compatibility with every later version. The bundled detector implementations retain some training-related imports, including scikit-learn and TensorBoard. A minimal, independently validated fresh-environment installation is not yet provided. The released scripts have been exercised in the maintainer's existing DeepfakeBenchPacked environment.

Inference

Run commands from the downloaded repository root, using an environment with the dependencies above. For the Python download example, this is the directory printed as release_path.

python -m inference.predict \
    --model imgnet_resnet34_ALL \
    --input /path/to/cropped_face.png \
    --output /tmp/deepfake_prediction.csv \
    --device cpu \
    --resize

Replace the input path with an actual image or directory. Directory inputs are searched recursively. Use a new output filename for each run; existing CSVs are not overwritten.

For batched GPU inference:

python -m inference.predict \
    --model fr_resnet34_ALL \
    --input /path/to/cropped_faces \
    --output /tmp/deepfake_predictions_fr.csv \
    --device cuda \
    --batch-size 16 \
    --resize

Download the corresponding FR model files before running the second example.

Inputs and preprocessing

The scripts expect already cropped face images. They do not detect faces, align faces, extract video frames or aggregate predictions across a video.

Preprocessing follows the submission's transfer-evaluation code:

  1. Load the image with Pillow and convert it to RGB.
  2. With --resize, resize to the configured square input resolution using torchvision's PIL resize operation.
  3. Convert pixels to a tensor in [0, 1].
  4. Normalize using the selected detector configuration's mean and std.

The benchmark models use 224 × 224 inputs. Stored image dimensions may differ: a clean image tested during release validation was 256 × 256. Without --resize, the script requires images to already match the configured input size.

For adversarial evaluation, preserve the preprocessing used by the relevant experiment. Resizing, recompression or other processing of adversarial images can change attack effectiveness. Do not assume that every stored evaluation image needs resizing.

Scores and decisions

Each detector produces a fake-class probability. The threshold is read from the threshold field in its best_threshold.json file. Thresholds were selected using held-out validation data to maximize balanced accuracy.

  • prob_fake >= threshold: prediction 1, label fake.
  • prob_fake < threshold: prediction 0, label real.

The CSV contains image, model, prob_fake, threshold, pred and label. Relative image paths are retained for directory inputs. Scores are model outputs and should not be interpreted as universally calibrated probabilities of authenticity.

Release validation

The maintainer reports that all 60 models passed strict checkpoint loading and a synthetic-image forward pass on a GPU using the release scripts. A real-image CPU inference test also completed successfully for imgnet_resnet34_ALL with resizing enabled.

To repeat the model-bank smoke test after downloading all checkpoints:

python -m inference.check_models --device cuda

Checkpoint loading uses strict=True, so missing or unexpected state-dictionary keys cause an error rather than permitting partially initialized predictions. Packaging also verified copied checkpoints, configurations and thresholds with SHA-256 checksums.

These checks establish loading and basic execution in the tested environment. They do not independently reproduce the paper's metrics or establish numerical equivalence across environments. Full comparison against the original evaluator remains separate from the smoke test.

After a complete download, verify the files listed in the checksum manifest with:

sha256sum --check SHA256SUMS

Intended use and limitations

The models are intended for research into deepfake detection, cross-detector adversarial transfer and robustness evaluation. Pairwise and portfolio evaluations should use the paper's source/target definitions, eligibility rules and target-specific thresholds.

  • Performance may change with manipulation technique, data source, image quality and preprocessing.
  • The study demonstrates susceptibility to adversarial examples; these checkpoints do not provide a robustness guarantee.
  • A real/fake prediction is not sufficient evidence for a consequential decision about a person or a media item.
  • The model bank does not establish demographic representativeness or equal performance across groups.
  • The companion image release is fake-only. Authentic examples are additionally required for metrics such as ROC-AUC, specificity and balanced accuracy.

Licence and attribution

The authors' model-release contributions are made available under Creative Commons Attribution–NonCommercial 4.0 International (CC BY-NC 4.0), to the extent of the rights they hold.

This licence allows noncommercial sharing and adaptation with appropriate attribution, a licence link and an indication of changes. Retain existing attribution and modification notices, and do not impose additional legal or technological restrictions on uses permitted by the licence.

Credit Rafael M. Mamede, Pedro C. Neto and Ana F. Sequeira for this benchmark and cite the study below. The implementation builds on DeepfakeBench and the relevant architecture libraries. Third-party code, pretrained components and source material remain subject to their applicable licences and notices; this statement does not relicense them or grant rights the authors do not hold.

The model bank's manipulated-image training configurations derive from DF40. The companion adversarial dataset is a separate evaluation release, not the detector-training dataset. Please also acknowledge DF40 and the underlying datasets relevant to your use.

Citation

@misc{mamede2026makesadversarialexamplestransfer,
  title         = {What Makes Adversarial Examples Transfer Across Deepfake Detectors?},
  author        = {Rafael M. Mamede and Pedro C. Neto and Ana F. Sequeira},
  year          = {2026},
  eprint        = {2609.10002},
  archivePrefix = {arXiv},
  primaryClass  = {cs.CV},
  url           = {https://arxiv.org/abs/2609.10002}
}

Questions and reproducibility issues can be raised in the repository's Discussions.

Downloads last month

-

Downloads are not tracked for this model. How to track
Inference Providers NEW
This model isn't deployed by any Inference Provider. 🙋 Ask for provider support

Dataset used to train poisonedchicken/deepfake-adversarial-transfer-models

Paper for poisonedchicken/deepfake-adversarial-transfer-models