Vision-Encoder Behavioral Fingerprints of Image-to-Image Generative Models: A Training-Paradigm-Driven Taxonomy of Six Commercial APIs
This paper proposes a training-paradigm-driven taxonomy of six commercial image-to-image generative models, demonstrating that they partition into two distinct behavioral clusters—edit-trained versus sampling-time adapted—based on their responses to content-adaptive sub-JND adversarial perturbations measured via frozen DINOv2 token distances.
Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer
Imagine you have a very special, invisible ink that you can paint onto a photo. This ink is so faint that the human eye can't see it, but it leaves a unique "fingerprint" on the digital DNA of the image.
This paper is about what happens when you take photos painted with this invisible ink and run them through six different popular AI tools that are designed to edit or redraw images (like turning a sketch into a photo, or changing the style of a picture).
Here is the simple breakdown of what the researchers found:
1. The Two "Personality" Groups
The researchers tested six different commercial AI systems. They expected the results to depend on how the AI was built (its architecture). Instead, they found that the AIs sorted themselves into two distinct "personality groups" based entirely on how they were trained:
- The "Careful Editors" (The Tight Band): These AIs (like Flux Kontext, Qwen Edit, and Gemini) were trained specifically to follow instructions to edit an existing photo. When you give them a photo, they try to keep it as close to the original as possible.
- The Analogy: Think of these like a photographer using Photoshop. They tweak the lighting or colors, but they keep the original photo's structure and details intact. They preserve your invisible ink fingerprint almost perfectly.
- The "Heavy Regenerators" (The Drift Band): These AIs (like SDXL, SD3, and gpt-image-1) were originally trained to create images from scratch (text-to-image) and were just adapted to edit photos later. When you give them a photo, they tend to "re-imagine" it from scratch based on their training.
- The Analogy: Think of these like a painter looking at a photo and painting a new version of it. They might capture the general vibe, but they change the brushstrokes and details significantly. In doing so, they wash away your invisible ink fingerprint and replace it with their own "painter's signature."
2. The Training Matters More Than the Brand
The most surprising finding is that the "brand" or the specific type of technology (like whether it's a diffusion model or a language model) didn't matter as much as the training method.
- Even though two AIs might use the same underlying technology, if one was trained to "edit carefully" and the other to "regenerate heavily," they ended up in completely different groups.
- The researchers found that knowing which AI processed the image explained 70% of the behavior, while the type of image (a face vs. a landscape) explained almost nothing (0.2%).
3. The "Fingerprint" Test
To figure out which AI did the work, the researchers used a simple test:
- They took the original photo (the clean reference).
- They took the AI-edited photo.
- They used a smart computer vision tool (DINOv2) to measure the tiny differences between the two.
The Result:
- If the AI was a "Careful Editor," the differences were tiny and consistent.
- If the AI was a "Heavy Regenerator," the differences were large and chaotic.
Using just this one measurement, they could correctly guess which of the six AIs processed a photo about 51% of the time. Since there were six options, random guessing would only get you 16% right. So, 51% is a significant improvement.
4. Why "Blind" Detection Failed
The researchers also tried to identify the AI without looking at the original photo (a "blind" test), which is how most current AI detectors work.
- The Result: The blind detectors failed miserably on the "Careful Editors." Because these AIs kept the photo so close to the original, the blind detectors couldn't tell them apart from the original image or from each other. They were essentially guessing.
- The Lesson: The "original photo" is the key. Without it, you can't tell who did the careful editing. With it, you can.
5. What Happens to the "Invisible Ink"?
The paper also measured how much of their special "invisible ink" survived the trip through the AI:
- Gemini: Kept about 98% of the ink.
- Flux Kontext: Kept about 80% of the ink (even though the image looked almost identical to the human eye).
- gpt-image-1: Wiped the ink out completely and replaced it with its own noise.
The Bottom Line
This paper suggests that we should stop thinking of these invisible ink tools just as "defense" (trying to stop AI from stealing art). Instead, they are better used as forensic tools.
If you have the original photo and a suspect AI-edited photo, you can use this method to prove which AI touched the image. However, this only works if you have the original photo to compare against. If you don't have the original, and the AI was a "Careful Editor," current technology cannot tell you which AI made the change.
Drowning in papers in your field?
Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.