RobustLens — pixel-space adapter
A head-only fine-tune of Bombek1/ai-image-detector-siglip-dinov2 that closes a generator-family blind spot in the base detector.
1,250,561 trained parameters — 0.17% of the model. Both backbones are frozen and the base checkpoint is byte-unchanged.
The problem it fixes
On 646 held-out images the base checkpoint is near-perfect on latent-diffusion and commercial generators, and largely blind to pixel-space diffusion:
| Generator | Family | Base recall |
|---|---|---|
| SD 2.1, SDXL, SD 3 | Latent diffusion | 1.000 |
| Midjourney | Commercial | 1.000 |
| GLIDE | Pixel-space diffusion | 0.739 |
| ADM | Pixel-space diffusion | 0.305 |
It misses seven of every ten ADM images. The base checkpoint was trained on OpenFake, whose generators are entirely latent-diffusion and commercial models — not one pixel-space diffusion model. It had never been shown that family.
Results
| Group | n | Base | This adapter | Δ |
|---|---|---|---|---|
| ADM recall | 95 | 0.305 | 0.863 | +0.558 |
| GLIDE recall | 92 | 0.739 | 0.967 | +0.228 |
| All pixel-space | 187 | 0.519 | 0.914 | +0.396 |
| Authentic — false positives | 459 | 0.013 | 0.072 | +0.059 |
Roughly seven points of recall per point of precision.
What it does not do
It does not improve DALL·E detection. On two independent DALL·E benchmarks: AUROC −0.011 on one, and on the other the base model wins 13 of 14 conditions once the false-positive rate is matched — the apparent recall gain there was a threshold shift, not better separation.
Neither benchmark contains pixel-space diffusion, and the base model already scores recall 1.000 on DALL·E 3. There is no blind spot there to fix.
It does not generalise to unseen generators. ADM and GLIDE were both in the training set. Whether this transfers to a pixel-space model it has never seen is untested.
ADM is still the weakest generator at 0.863 — about one in seven missed. The training images are natively 256px and were upscaled to 384, which may smooth the artifacts the detector needs.
For these reasons the parent project ships the base checkpoint as its default and treats this adapter as opt-in.
Usage
git clone https://github.com/yishengt/RobustLens
python scripts/run_inference.py --input-dir IMAGES \
--adapter-dir models/adapters/robustness_head
Or load it directly onto a restored base model:
from src.finetune.model import load_saved_adapter_into_model
load_saved_adapter_into_model(model, "path/to/robustness_head")
Files
| File | Contents |
|---|---|
classifier_head.pt |
8 tensors, 1,250,561 params — the trained part |
adapter_model.safetensors |
156 tensors, 7,127,040 params — the base checkpoint's original LoRA, unchanged, re-exported so the adapter loads standalone |
adapter_config.json |
Architecture, base model names, training provenance, original-vs-fine-tuned comparison |
Training
Head-only, 8 epochs, best at epoch 3, seed 42. 2,000 augmented images from a 4,979-image dataset spanning six generators across three architecture families — SD 2.1, SDXL, SD 3 (Defactify), ADM, GLIDE, Midjourney (GenImage) — with authentic images from COCO train2017 and ImageNet.
Every image was centre-cropped square, resized to 384×384 and re-encoded at one JPEG quality, because in the raw sources every generated image was square and almost no authentic one was.
DALL·E 3 was deliberately excluded from training so that DALL·E benchmarks remain a genuine unseen-generator test.
Licence and attribution
CC-BY-NC-SA-4.0 — non-commercial, research use only, inherited from GenImage.
Base checkpoint: Bombek1/ai-image-detector-siglip-dinov2. Training data: GenImage (CC-BY-NC-SA-4.0), Defactify / MS COCOAI, COCO train2017.
Model tree for xxxtechtation/robustlens-pixelspace-adapter
Base model
Bombek1/ai-image-detector-siglip-dinov2