An Interpretability Pipeline for Image Forgery Localization using GAN-Generated Forgeries and Grad-CAM
Bibliographic record
Abstract
This study presents a novel interpretability pipeline for image forgery localization by integrating GAN-generated adversarial forgeries with Grad-CAM visual explanations. The objective is to assess the capability of a deep learning classifier to not only detect but also spatially localize manipulated regions in digital images. A Deep Convolutional GAN is trained to generate realistic forged patches, which are synthetically embedded into clean images to simulate new forgery instances. These synthetic images are then analyzed using a proficient 1-based binary classifier. To elucidate the spatial focus of the model, Grad-CAM is employed to visualize class differences of interest. The analysis incorporates metrics such as attention scores, IoU, recall, F1 score, MSE, and SSIM, enabling comprehensive comparisons between heat maps and ground truth forged areas. Despite the high attention scores, the results indicate poor localization performance, with IoU and Pixel-Wise F1 scores at zero. These findings suggest that while the classifier can identify vulnerable areas, Grad-CAM lacks the accuracy necessary for precise manipulation indication. Layer-wise visualization analysis further reveals that the deep layers of the model capture high-level features but prioritize rapid localization over accuracy. This study provides evidence that GAN-generated examples can highlight significant interpretative boundaries. The findings emphasize a disconnect between visual saliency and actual spatial alignment, underscoring the necessity for more refined explanatory methods in image forensics. This framework offers a scalable testbed for future interpretability benchmarking in adversarial scenarios and contributes to the development of more explainable and robust AI models in high-stakes visual domains. The experimental results reveal a stark contrast between high Grad-CAM attention scores and low spatial IoU, indicating a disparity between focus and true localization. Although the classifier reliably detects forged images, its spatial interpretation lacks precision. These insights underscore the need for more granular explanatory tools to enhance forensic trustworthiness. This work establishes a precedent for adversarial interpretability evaluation using synthetic forgeries, with future research potentially focusing on embedding-aware Grad-CAM variants or localized training objectives.
Fetched live from OpenAlex and de-inverted. Abstracts are not stored in this database: the inverted indexes are 8.6 GB of the frame’s 9.3 GB of text, and the host has 13 GB free.
How this classification was reachedexpand
Full frame distilled prediction
Teacher imitationNot calibrated prevalence, not ground truth. Human validation pending. Learned from the 10,348 direct Codex labels and 10,348 direct Gemma labels. Candidate is the union of thresholded teacher heads; consensus is their intersection. These outputs are machine_predicted_unvalidated and are not human labels or direct frontier model labels.
Codex and Gemma teacher scores by category
| Category | Codex | Gemma |
|---|---|---|
| Metaresearch | 0.002 | 0.002 |
| Meta-epidemiology (narrow) | 0.000 | 0.000 |
| Meta-epidemiology (broad) | 0.000 | 0.000 |
| Bibliometrics | 0.000 | 0.002 |
| Science and technology studies | 0.000 | 0.000 |
| Scholarly communication | 0.001 | 0.004 |
| Open science | 0.000 | 0.000 |
| Research integrity | 0.000 | 0.000 |
| Insufficient payload (model declined to judge) | 0.000 | 0.000 |
Machine scores (provisional)
The two teacher heads of the student model, read on this work. A score orders the frame for review; it never asserts a category, and the validation status ships verbatim with every row.
Baseline scores from an immature model (maturity gate not passed, 7 training rounds). Scores rank; they never assert a category.
score_only:v0-immature-baseline · verbatim from the scoring run: score_only means the number may rank works, and no category label ships from itClassification
machine, unvalidatedMachine predicted; a candidate call from one teacher head, not a consensus.
How this classification was reached, model by model and score by score, is at the end of the page under "How this classification was reached".