Finding AI-Generated Faces in the Wild

Evaluating synthetic-face detection across GAN and diffusion engines, including held-out generators and reduced image quality.

Our 2023 detector relied on the consistent facial alignment in StyleGAN images. Faces generated by Stable Diffusion, DALL-E 2, and Midjourney did not have the same alignment, motivating a different approach.

Our LinkedIn team and Professor Hany Farid at UC Berkeley evaluated detection across GAN and diffusion generators, including generators withheld from training. We also tested the effects of reduced resolution and JPEG compression. The small-image tests included models trained at the corresponding resolution. We published Finding AI-Generated Faces in the Wild at the Workshop on Media Forensics at CVPR 2024.

The production model described here had already been replaced by the time we published the paper.

Training and evaluation data

We trained and evaluated the model on 18 datasets containing 120,000 real LinkedIn profile photos and 105,900 synthetic images from ten generators. The GAN datasets came from generated.photos, StyleGAN 1 through 3, and EG3D; the diffusion datasets came from DALL-E 2, Midjourney, and Stable Diffusion 1, 2, and xl. Six generators were used in training and four were withheld for evaluation.

Grid of representative AI-generated face and non-face images from ten synthesis engines including generated.photos, StyleGAN 1 to 3, EG3D, DALL-E 2, Midjourney, and Stable Diffusion variants

Representative AI-generated images from the ten synthesis engines used for training and evaluation. Some engines contribute faces only; others contribute both faces and non-face images. (Figure 2 of the paper; dataset counts in Table 1.)

Model and detection results

Images were resized to 512 pixels and passed through a frozen EfficientNet-B1 backbone. We trained the scoring layers, which contained 6.8 million parameters.

At a false positive rate of 0.5%, the classifier detected 98% of synthetic faces from generators represented in training. Detection was 84.5% on the held-out evaluation of 5,000 faces from four generators. Results varied by generator: 99.5% for EG3D, 95.4% for generated.photos, and 19.4% for Midjourney.

Resolution and JPEG compression

Profile photos are resized and JPEG-compressed during upload and processing. We tested how these changes affected detection.

Two plots showing true positive rate versus image resolution and versus JPEG quality, with resolution-matched training maintaining high accuracy at small sizes

True positive rate as a function of resolution (top) and JPEG quality (bottom) at a fixed 0.5% false positive rate. In the top panel, the solid curve is the 512-trained model evaluated at lower resolutions; each point on the dashed curve uses a model trained at the matching resolution. The JPEG model was trained on uncompressed images and a range of JPEG qualities. (Figure 3 of the paper.)

The model trained at 512 pixels lost most of its detection power when evaluated at 128 pixels. A separate model trained and evaluated at 128 pixels retained a true positive rate of about 90% at a 0.5% false positive rate. For the model trained on a mixture of uncompressed and JPEG-compressed images, detection decreased as JPEG quality fell from 100 to 20. The true positive rates were 94.3% at quality 80 and 88.0% at quality 60, both at a 0.5% false positive rate.

Interpreting the detector response

The detector flagged none of the synthetic non-face images in this evaluation: their true positive rate was 0% (Table 2).

AI-generated faces alongside their integrated-gradient attribution maps, which concentrate on facial regions

Integrated-gradient attributions for AI-generated faces concentrate around the face and other areas of skin. The top row averages 100 StyleGAN 2 faces together; the others are individual examples. (Figure 5 of the paper.)

The integrated-gradient attributions concentrate on facial regions. This is consistent with a dependence on facial structure, although the training data offers another possible explanation: every synthetic training image contained a face, while some real training images did not.

Resources