ARMOR++: Agentic Orchestration of a Multi-Domain Primitive Set for Transferable Attacks on Deepfake Detectors
Merged summary
TL;DR - ARMOR++ is a multi-agent framework that uses VLMs and LLMs to orchestrate transferable, black-box adversarial attacks against deepfake detectors, exposing a persistent reliability gap in deployed detection systems.
- Combines Qwen2.5-VL (spatial semantic priors) with Qwen3 (orchestrating primitive selection, adaptive hyperparameter reparameterization, and entropy-regularized perturbation mixing) for no-query black-box evasion.
- Integrates five complementary attack primitives — dense optimization, saliency-based, spatial transformations, frequency-domain, and block-structured — to target heterogeneous inductive biases (e.g., CNN→transformer transfer).
- Evaluated on the AADD-2025 benchmark, reporting substantial blind-target Attack Success Rate gains over state-of-the-art agentic and non-agentic baselines across low- and high-quality image regimes and under robust defenses.
- Positioned as security/adversarial research; specific numeric ASR figures aren't given in the provided abstract, so exact magnitudes can't be stated.
Sources (1)
ARMOR++: Agentic Orchestration of a Multi-Domain Primitive Set for Transferable Attacks on Deepfake Detectors
TL;DR - ARMOR++ is a multi-agent framework that uses VLMs and LLMs to orchestrate transferable, black-box adversarial attacks against deepfake detectors, exposing a persistent reliability gap in deployed detection systems.
- Combines Qwen2.5-VL (spatial semantic priors) with Qwen3 (orchestrating primitive selection, adaptive hyperparameter reparameterization, and entropy-regularized perturbation mixing) for no-query black-box evasion.
- Integrates five complementary attack primitives — dense optimization, saliency-based, spatial transformations, frequency-domain, and block-structured — to target heterogeneous inductive biases (e.g., CNN→transformer transfer).
- Evaluated on the AADD-2025 benchmark, reporting substantial blind-target Attack Success Rate gains over state-of-the-art agentic and non-agentic baselines across low- and high-quality image regimes and under robust defenses.
- Positioned as security/adversarial research; specific numeric ASR figures aren't given in the provided abstract, so exact magnitudes can't be stated.