Detecting AI-Generated Profile Photos

Detecting StyleGAN-generated profile photos using compact image embeddings.

The average of 400 StyleGAN2 faces retains sharp facial features, while the average of 400 real profile photos is blurred. We used this difference to detect synthetic profile photos. Fake accounts can use newly generated faces with no earlier published image for reverse-image search to find.

My team worked with Professor Hany Farid at UC Berkeley to develop detectors based on compact embeddings of StyleGAN-family faces. We published the study at the Workshop on Media Forensics at CVPR 2023.

Facial alignment in StyleGAN images

In the StyleGAN2 average below, the eyes, nose, and mouth remain recognizable because they occupy similar positions across images. The real-photo average shows more variation in alignment and framing.

Average of 400 StyleGAN2 faces appearing sharp next to the blurry average of 400 real profile photos, with reconstruction visualizations below

Averaging 400 StyleGAN2 faces (left) produces a sharp composite; averaging 400 real profile photos (right) produces a blur. The bottom row visualizes reconstruction behavior from a compact embedding learned on synthetic faces. (Figure 1 of the paper.)

Detection from compact embeddings

We learned a 128-dimensional linear embedding using principal components analysis (PCA) on a few thousand StyleGAN faces. Reconstruction errors were lower for StyleGAN images than for real profile photos.

Histograms comparing reconstruction error distributions for StyleGAN faces and real profile photos across StyleGAN1, StyleGAN2, and StyleGAN3

Reconstruction-error distributions for StyleGAN faces (blue) and real profile photos (orange), using learned linear embeddings for StyleGAN1, StyleGAN2, and StyleGAN3. (Figure 3 of the paper.)

Reconstruction error can be thresholded to classify an image. Logistic regression on the PCA coordinates improved detection to 99.6% of StyleGAN-family faces at a 1% false positive rate on real profile photos. An autoencoder embedding produced a similar result. The CNN baseline in Table 1 was evaluated at a different false positive rate of 3.3%.

Generalization to other generators

Grid of representative synthetic faces produced by StyleGAN1, StyleGAN2, StyleGAN3, Generated.photos, and Stable Diffusion

Representative synthetic faces from five generation engines: StyleGAN1, StyleGAN2, StyleGAN3, Generated.photos, and Stable Diffusion. (Figure 2 of the paper.)

We also evaluated Generated.photos and Stable Diffusion images. The method had some success on Generated.photos but failed on Stable Diffusion, whose faces do not share the same rigid alignment. Our subsequent study, Finding AI-Generated Faces in the Wild, evaluated a different model across GAN and diffusion generators.

Resources