Detecting AI-Generated Profile Photos

Detecting StyleGAN-generated profile photos with compact embeddings, and the limits of that approach.

Average 400 StyleGAN2 faces and the facial features remain sharp; average 400 real profile photos and they blur. Our study used that difference to detect generated profile photos used by fake accounts. A newly generated face may not have a previously published image for reverse-image search to find.

Together with Professor Hany Farid at UC Berkeley, my team developed detectors using compact embeddings of StyleGAN-family faces. We published the coauthored study at the Workshop on Media Forensics at CVPR 2023. The approach did not generalize to Stable Diffusion faces.

Facial alignment in StyleGAN images

In the StyleGAN2 average below, the eyes, nose, and mouth remain recognizable because they occupy similar positions across images. The real-photo average shows more variation in alignment and framing.

Average of 400 StyleGAN2 faces appearing sharp next to the blurry average of 400 real profile photos, with reconstruction visualizations below

Averaging 400 StyleGAN2 faces (left) produces a sharp composite; averaging 400 real profile photos (right) produces a blur. The bottom row visualizes reconstruction behavior from a compact embedding learned on synthetic faces. (Figure 1 of the paper.)

A Compact Embedding Instead of a Heavy Classifier

We captured this regularity with a 128-dimensional linear embedding learned by principal components analysis (PCA) from a few thousand StyleGAN faces. In the evaluation, StyleGAN images reconstructed from that embedding with lower error than real profile photos.

Histograms comparing reconstruction error distributions for StyleGAN faces and real profile photos across StyleGAN1, StyleGAN2, and StyleGAN3

Reconstruction-error distributions for StyleGAN faces (blue) and real profile photos (orange), using learned linear embeddings for StyleGAN1, StyleGAN2, and StyleGAN3. (Figure 3 of the paper.)

A threshold on reconstruction error provides one classifier. Fitting logistic regression to the PCA embedding coordinates improved the result: the detector identified 99.6% of StyleGAN-family faces at a 1% false positive rate on real profile photos in this evaluation. A learned autoencoder embedding gave a similar result. Section 3.1 describes the classifiers, and Table 1 compares their detection rates with the CNN baseline evaluated in the paper. That baseline used a different false positive rate, 3.3%.

The Generator Landscape

Grid of representative synthetic faces produced by StyleGAN1, StyleGAN2, StyleGAN3, Generated.photos, and Stable Diffusion

Representative synthetic faces from five generation engines: StyleGAN1, StyleGAN2, StyleGAN3, Generated.photos, and Stable Diffusion. (Figure 2 of the paper.)

This study focused on StyleGAN-family images. Generalization tests included Generated.photos and Stable Diffusion; the approach had some success on Generated.photos but failed on Stable Diffusion, whose faces lack the same rigid alignment. The original engineering article reports this limitation directly. Our follow-up work, Finding AI-Generated Faces in the Wild, evaluated a different model across GAN and diffusion engines.

Resources