Skip to content
Search
paperSeptember 2026Unreviewed

What Makes Adversarial Examples Transfer Across Deepfake Detectors?

Rafael M. Mamede, Pedro C. Neto, Ana F. Sequeira

Abstract

Deepfake detectors remain vulnerable to transfer-based black-box attacks, in which adversarial examples are generated on a source surrogate model and transferred to a target model, unknown to the attacker. Yet how source--target compatibility shapes attack success remains poorly understood. Prior studies evaluate limited detector pools and rarely disentangle architectural from training factors. We conduct a controlled evaluation of adversarial transferability across 60 detectors spanning six bac

Categories

Framework mappings

MITRE ATLAS
  • AML.T0043Craft Adversarial Data

Suggested from the entry's categories.

Cite

@misc{mamede2026what,
  title = {{What Makes Adversarial Examples Transfer Across Deepfake Detectors?}},
  author = {Rafael M. Mamede and Pedro C. Neto and Ana F. Sequeira},
  year = {2026},
  month = sep,
  eprint = {2609.10002},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2609.10002}
}