Can We Detect Images Made by Diffusion Models?

Blogs

Can Forensic Detectors Trained on GANs Catch Diffusion Model Fakes?

DALLĀ·E 2, Stable Diffusion, and GLIDE can turn a text prompt into a photorealistic image in seconds. That creative power is also a gift to anyone looking to spread convincing disinformation. Researchers at the University of Naples Federico II and NVIDIA set out to answer a critical question: do diffusion-generated images leave the same kind of hidden traces that GAN images do, and can today's detectors, built mostly for GANs, actually catch them?

Why Are Diffusion Models a New Forensic Challenge?

  • They deliver an unprecedented level of photorealism, often indistinguishable from real photos at a glance
  • Text-guided generation means virtually any subject or scene can be created on demand
  • Most existing forensic detectors were developed and tuned specifically for GAN-generated images
  • Since diffusion models use a fundamentally different generation process, there was no guarantee they'd leave the same kind of detectable traces

Do Diffusion-Generated Images Leave Hidden Fingerprints Like GAN Images Do?

Researchers extracted "fingerprints" from image noise residuals and examined their frequency spectra across multiple generators.

  • GAN-generated images consistently showed strong, periodic spectral peaks — clear fingerprints tied to the upsampling operations used in their architecture
  • Some diffusion models — GLIDE, Latent Diffusion, and Stable Diffusion — showed similar, detectable peaks, a promising sign for fingerprint-based detection
  • Other diffusion models — ADM and DALLĀ·E 2 — showed much weaker peaks, suggesting they would be significantly harder to detect

How Well Do Existing GAN Detectors Generalize to Diffusion Models?

Four well-known detectors, all trained only on GAN-generated images, were tested against a wide range of diffusion models.

  • On uncompressed images, detection performance was reasonably strong for several diffusion models, though accuracy dropped sharply for DALLĀ·E 2 and ADM
  • Under realistic social-media conditions — random cropping, resizing, and JPEG compression — performance collapsed further, with accuracy falling close to random guessing for several models even when the underlying AUC score stayed moderate
  • This confirms that detectors trained purely on GAN artifacts don't reliably transfer to diffusion-generated content, especially once images pass through typical online processing

Does Training on a Diffusion Model Help Detect Other Diffusion Models?

  • A detector trained specifically on one diffusion model (like ADM or Latent Diffusion) generalized well to architecturally similar diffusion models — for example, training on Latent Diffusion led to near-perfect detection of Stable Diffusion
  • Performance on unrelated diffusion models or GAN images remained much weaker
  • This suggests different diffusion model families rely on meaningfully different underlying traces, so no single training set covers them all

Can Combining and Calibrating Detectors Improve Results?

  • Fusing predictions from detectors trained on both a GAN and a diffusion model improved generalization across a broader range of generators
  • The biggest accuracy gains came from recalibrating the decision threshold for each new generator, using only a handful of reference images — a simple, practical fix
  • Even after fusion and calibration, DALLĀ·E 2 and ADM images remained the hardest to reliably detect, consistent with their weaker underlying forensic traces

What Are the Practical Takeaways?

  • Generalization remains the central open problem in synthetic image detection
  • New diffusion model families may require dedicated training data rather than relying on detectors built for earlier architectures
  • Threshold calibration matters as much as detector architecture — a well-trained model can still perform poorly with a poorly chosen decision threshold
  • No single detector can be assumed to catch every current or future generator; ongoing updates are necessary as new models are released

Who Should Care About These Findings?

  • Forensic researchers building the next generation of synthetic image detectors
  • Platforms and content moderation teams assessing which detection tools are actually reliable
  • Journalists and fact-checkers who need to understand the current limits of detection technology
  • Policymakers evaluating the risks posed by increasingly accessible generative AI tools

Frequently Asked Questions

Do diffusion model images leave the same kind of forensic traces as GAN images? Partially. Some diffusion models, like GLIDE, Latent Diffusion, and Stable Diffusion, show detectable spectral fingerprints similar to GANs, while others, like ADM and DALLĀ·E 2, show much weaker traces.

Can detectors trained on GAN images detect diffusion model fakes? Not reliably. Performance is inconsistent across different diffusion models and drops sharply once images are compressed or resized, as commonly happens on social media.

Does training a detector on one diffusion model help it detect others? Only for architecturally similar models. A detector trained on Latent Diffusion generalized well to Stable Diffusion but performed much worse on DALLĀ·E 2 or ADM, which use different underlying processes.

What is the easiest way to improve detection accuracy across different generators? Recalibrating the decision threshold for each new generator, using just a few reference images, produced significant accuracy gains without retraining the model.

Which types of AI-generated images are hardest to detect? DALLĀ·E 2 and ADM-generated images proved the most difficult, since they showed the weakest forensic fingerprints in this study.

ā€

Note: This article was prepared with the support of artificial intelligenceĀ 

ā€

Discover more about the paper: click here

ā€

Recent Blogs
See all blog articles

talk to a human expert

Tell us about your business. We'll come back to you within one business day.

Thank you!
Your submission has been successfully sent to our team
Oops! Something went wrong while submitting the form.

No sales pitch. Just a conversation.

We stand for truth