Orthogonal Subspace Decomposition for Generalizable AI-Generated Image Detection

Zhiyuan YanJiangming WangPeng JinKe-Yue ZhangChengchun LiuShen ChenTaiping YaoShouhong DingBaoyuan WuLi Yuan

article2025ICML128 citations

Proposes an orthogonal subspace decomposition method via Singular Value Decomposition that preserves rich pre-trained representations in foundation models while adapting remaining components to prevent detectors from overfitting to seen fake patterns.

Listen

Rapid advances in generative artificial intelligence have made creating hyper-realistic manipulated media, such as facial deepfakes and fully synthetic images, remarkably accessible. While these technologies offer creative utility, their misuse threatens information integrity, digital trust, and security. Existing automated detectors struggle with generalization: models trained on known generation techniques often fail when evaluated against novel, unseen synthesis methods in the wild. The article investigates the root cause of this vulnerability and demonstrates a method to produce highly generalizable, lightweight detection systems.

The article demonstrates that standard detectors suffer from an "asymmetry phenomenon," rapidly memorizing narrow forgery artifacts while discarding broad semantic context, which drastically compresses the model's internal feature space and destroys generalization. To resolve this, the article introduces Effort, a framework that leverages pre-trained vision foundation models and decomposes their internal representations into two independent, orthogonal pathways using Singular Value Decomposition. By freezing core semantic knowledge and adapting only the residual subspace to identify manipulation cues, the model preserves high-dimensional feature richness while learning to distinguish real images from fakes.

The evaluation spanned comprehensive benchmarks covering both facial deepfakes and diverse synthetic images generated by generative adversarial networks and diffusion models. For deepfake detection, the framework was trained on standard benchmarks and tested across seven unseen datasets and eight manipulation protocols. For synthetic image detection, the model was trained on a single generative source and evaluated against nineteen distinct generative engines. The approach was systematically compared against leading state-of-the-art detectors, fully fine-tuned models, and standard parameter-efficient fine-tuning techniques.

The findings confirm significant performance advantages across multiple criteria. First, the proposed framework achieved superior cross-dataset generalization, scoring an average Area Under the Curve of 0.917 across unseen deepfake datasets and 0.940 across unseen manipulation methods, outperforming existing baselines. Second, in synthetic image benchmarks across nineteen diverse generative models, the method achieved a 95.19% mean accuracy and 99.41% mean average precision, improving accuracy by 9.27 percentage points over linear probing and 4.33 percentage points over the leading specialized detector. Third, the system maintained 99.3% of the foundation model's original feature space variance, whereas standard fine-tuning degraded feature capacity by 64.4%. Fourth, the model achieved these results using only 0.19 million trainable parameters—roughly 1,000 times fewer than competing specialized detectors requiring around 100 million parameters—while showing strong robustness against image degradations such as compression and blur.

These results indicate that artificial images are fundamentally hierarchical derivatives of real content rather than entirely independent entities. Detecting them effectively requires comparing real and synthetic features within semantically consistent subspaces rather than relying on isolated visual artifacts. By decoupling semantic representations from manipulation cues, organizations can deploy detection tools that remain resilient against emerging generative models without repeatedly retraining massive neural networks from scratch.

For operational deployment and future development, organizations should transition from fully fine-tuned detection models to orthogonal parameter-efficient tuning on top of strong vision foundation models like CLIP. Looking forward, the article suggests extending this framework into an incremental learning architecture, where newly discovered generative tools are assigned separate orthogonal branches to prevent the system from forgetting previously learned forgery signatures. The primary operational constraint noted is that current training aggregates all forgery types into a single binary class, which may miss subtle method-specific distinctions. Readers can have high confidence in the empirical findings given the extensive cross-model benchmarking, though real-world implementations should implement access controls to prevent adversarial actors from exploiting the detector to enhance generator realism.

No sufficiently relevant recommendations were found.

Cover for Orthogonal Subspace Decomposition for Generalizable AI-Generated Image Detection

Abstract

Detecting AI-generated images (AIGIs), such as natural images or face images, has become increasingly important yet challenging. In this paper, we start from a new perspective to excavate the reason behind the failure generalization in AIGI detection, named the asymmetry phenomenon, where a naively trained detector tends to favor overfitting to the limited and monotonous fake patterns, causing the feature space to become highly constrained and low-ranked, which is proved seriously limiting the expressivity and generalization. One potential remedy is incorporating the pre-trained knowledge within the vision foundation models (higher-ranked) to expand the feature space, alleviating the model’s overfitting to fake. To this end, we employ Singular Value Decomposition (SVD) to decompose the original feature space into two orthogonal subspaces. By freezing the principal components and adapting only the remained components, we preserve the pre-trained knowledge while learning fake patterns. Compared to existing full-parameters and LoRA-based tuning methods, we explicitly ensure orthogonality, enabling the higher rank of the whole feature space, effectively minimizing overfitting and enhancing generalization. We finally identify a crucial insight: our method implicitly learns a vital prior that fakes are actually derived from the real, indicating a hierarchical relationship rather than independence. Modeling this prior, we believe, is essential for achieving superior generalization. Our codes are publicly available at GitHub.

Citation

MLA
Yan, Z., et al. “Orthogonal Subspace Decomposition for Generalizable AI-Generated Image Detection”. arXiv, 2024, http://arxiv.org/abs/2411.15633v4.
APA
Yan, Z., Wang, J., Jin, P., Zhang, K.-Y., Liu, C., Chen, S., Yao, T., Ding, S., Wu, B., & Yuan, L. (2024). Orthogonal Subspace Decomposition for Generalizable AI-Generated Image Detection. arXiv. http://arxiv.org/abs/2411.15633v4
Chicago
Yan, Z., J. Wang, P. Jin, et al. 2024. “Orthogonal Subspace Decomposition for Generalizable AI-Generated Image Detection”. arXiv. http://arxiv.org/abs/2411.15633v4.
Harvard
Yan, Z. et al. (2024) “Orthogonal Subspace Decomposition for Generalizable AI-Generated Image Detection”, arXiv [Preprint]. Available at: http://arxiv.org/abs/2411.15633v4.
Vancouver
1. Yan Z, Wang J, Jin P, Zhang K-Y, Liu C, Chen S, Yao T, Ding S, Wu B, Yuan L (2024) Orthogonal Subspace Decomposition for Generalizable AI-Generated Image Detection. arXiv

BibTeX

@article{yan2024orthogonal,
  title = {Orthogonal Subspace Decomposition for Generalizable AI-Generated Image Detection},
  author = {Yan, Zhiyuan and Wang, Jiangming and Jin, Peng and Zhang, Ke-Yue and Liu, Chengchun and Chen, Shen and Yao, Taiping and Ding, Shouhong and Wu, Baoyuan and Yuan, Li},
  year = {2024},
  journal = {arXiv},
  url = {http://arxiv.org/abs/2411.15633v4},
  eprint = {2411.15633}
}
Metadata:arXiv

Source Code

This paper has an official code repository available. Click below to access the source code.

View Repository

Access the Paper

This paper is available from its original source. Click below to access the PDF.

Open PDF
License: https://creativecommons.org/licenses/by/4.0/