{"id":"https://openalex.org/W7123268230","doi":"https://doi.org/10.48550/arxiv.2601.05986","title":"Deepfake detectors are DUMB: A benchmark to assess adversarial training robustness under transferability constraints","display_name":"Deepfake detectors are DUMB: A benchmark to assess adversarial training robustness under transferability constraints","publication_year":2026,"publication_date":"2026-01-09","ids":{"openalex":"https://openalex.org/W7123268230","doi":"https://doi.org/10.48550/arxiv.2601.05986"},"language":null,"primary_location":{"id":"doi:10.48550/arxiv.2601.05986","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2601.05986","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"type":"preprint","indexed_in":["datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://doi.org/10.48550/arxiv.2601.05986","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5122802246","display_name":"Adrian Serrano","orcid":null},"institutions":[],"countries":[],"is_corresponding":true,"raw_author_name":"Serrano, Adrian","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5122750382","display_name":"Erwan Umlil","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Umlil, Erwan","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5122829319","display_name":"Ronan Thomas","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Thomas, Ronan","raw_affiliation_strings":[],"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5122802246"],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.989799976348877,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.989799976348877,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10036","display_name":"Advanced Neural Network Applications","score":0.0017000000225380063,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10775","display_name":"Generative Adversarial Networks and Image Synthesis","score":0.001500000013038516,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.934499979019165},{"id":"https://openalex.org/keywords/transferability","display_name":"Transferability","score":0.9235000014305115},{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.8276000022888184},{"id":"https://openalex.org/keywords/training-set","display_name":"Training set","score":0.5713000297546387},{"id":"https://openalex.org/keywords/benchmark","display_name":"Benchmark (surveying)","score":0.4480000138282776},{"id":"https://openalex.org/keywords/detector","display_name":"Detector","score":0.4357999861240387},{"id":"https://openalex.org/keywords/labeled-data","display_name":"Labeled data","score":0.3531999886035919}],"concepts":[{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.934499979019165},{"id":"https://openalex.org/C61272859","wikidata":"https://www.wikidata.org/wiki/Q7834031","display_name":"Transferability","level":3,"score":0.9235000014305115},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.8276000022888184},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7689999938011169},{"id":"https://openalex.org/C51632099","wikidata":"https://www.wikidata.org/wiki/Q3985153","display_name":"Training set","level":2,"score":0.5713000297546387},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.555899977684021},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5540000200271606},{"id":"https://openalex.org/C185798385","wikidata":"https://www.wikidata.org/wiki/Q1161707","display_name":"Benchmark (surveying)","level":2,"score":0.4480000138282776},{"id":"https://openalex.org/C94915269","wikidata":"https://www.wikidata.org/wiki/Q1834857","display_name":"Detector","level":2,"score":0.4357999861240387},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.39579999446868896},{"id":"https://openalex.org/C2776145971","wikidata":"https://www.wikidata.org/wiki/Q30673951","display_name":"Labeled data","level":2,"score":0.3531999886035919},{"id":"https://openalex.org/C2777211547","wikidata":"https://www.wikidata.org/wiki/Q17141490","display_name":"Training (meteorology)","level":2,"score":0.31850001215934753},{"id":"https://openalex.org/C123657996","wikidata":"https://www.wikidata.org/wiki/Q12271","display_name":"Architecture","level":2,"score":0.28940001130104065},{"id":"https://openalex.org/C160920958","wikidata":"https://www.wikidata.org/wiki/Q7662746","display_name":"Synthetic data","level":2,"score":0.27810001373291016},{"id":"https://openalex.org/C41065033","wikidata":"https://www.wikidata.org/wiki/Q2825412","display_name":"Adversary","level":2,"score":0.2759000062942505},{"id":"https://openalex.org/C67186912","wikidata":"https://www.wikidata.org/wiki/Q367664","display_name":"Data modeling","level":2,"score":0.26660001277923584},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.26339998841285706},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.25929999351501465}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.48550/arxiv.2601.05986","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2601.05986","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"doi:10.48550/arxiv.2601.05986","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2601.05986","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"Deepfake":[0],"detection":[1],"systems":[2],"deployed":[3],"in":[4,127,153],"real-world":[5,83,154],"environments":[6],"are":[7],"subject":[8],"to":[9,65,81,116,157],"adversaries":[10],"capable":[11],"of":[12],"crafting":[13],"imperceptible":[14],"perturbations":[15],"that":[16,121],"degrade":[17,134],"model":[18],"performance.":[19],"While":[20],"adversarial":[21,73,122,158],"training":[22,123],"is":[23],"a":[24],"widely":[25],"adopted":[26],"defense,":[27],"its":[28],"effectiveness":[29],"under":[30,75,136],"realistic":[31],"conditions":[32],"--":[33,54],"where":[34],"attackers":[35],"operate":[36],"with":[37],"limited":[38],"knowledge":[39],"and":[40,59,62,78,101,105,111],"mismatched":[41],"data":[42],"distributions":[43],"-":[44,61],"remains":[45],"underexplored.":[46],"In":[47],"this":[48],"work,":[49],"we":[50],"extend":[51],"the":[52,128,141,147],"DUMB":[53],"Dataset":[55],"soUrces,":[56],"Model":[57],"architecture":[58],"Balance":[60],"DUMBer":[63],"methodology":[64],"deepfake":[66],"detection.":[67],"We":[68,107],"evaluate":[69],"detectors":[70,90],"robustness":[71,126],"against":[72],"attacks":[74,97],"transferability":[76],"constraints":[77],"cross-dataset":[79,137],"configuration":[80,138],"extract":[82],"insights.":[84],"Our":[85],"study":[86],"spans":[87],"five":[88],"state-of-the-art":[89],"(RECCE,":[91],"SRM,":[92],"XCeption,":[93],"UCF,":[94],"SPSL),":[95],"three":[96],"(PGD,":[98],"FGSM,":[99],"FPBA),":[100],"two":[102],"datasets":[103],"(FaceForensics++":[104],"Celeb-DF-V2).":[106],"analyze":[108],"both":[109],"attacker":[110],"defender":[112],"perspectives":[113],"mapping":[114],"results":[115],"mismatch":[117],"scenarios.":[118],"Experiments":[119],"show":[120],"strategies":[124,152],"reinforce":[125],"in-distribution":[129],"cases":[130],"but":[131],"can":[132],"also":[133],"it":[135],"depending":[139],"on":[140],"strategy":[142],"adopted.":[143],"These":[144],"findings":[145],"highlight":[146],"need":[148],"for":[149],"case-aware":[150],"defense":[151],"applications":[155],"exposed":[156],"attacks.":[159]},"counts_by_year":[],"updated_date":"2026-01-13T12:58:16.504669","created_date":"2026-01-13T00:00:00"}
