{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,16]],"date-time":"2026-06-16T08:54:09Z","timestamp":1781600049687,"version":"3.54.5"},"publisher-location":"New York, NY, USA","reference-count":22,"publisher":"ACM","license":[{"start":{"date-parts":[[2026,6,16]],"date-time":"2026-06-16T00:00:00Z","timestamp":1781568000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"funder":[{"name":"European Commission - NextGenerationEU - Italian Ministry of University and Research","award":["PE00000014 (CUP: B63C24000490006)"],"award-info":[{"award-number":["PE00000014 (CUP: B63C24000490006)"]}]},{"name":"University of Siena","award":["PSR 2023"],"award-info":[{"award-number":["PSR 2023"]}]},{"name":"University of Siena and Leonardo Spa","award":["PhD scholarship"],"award-info":[{"award-number":["PhD scholarship"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2026,6,17]]},"DOI":"10.1145\/3785353.3815073","type":"proceedings-article","created":{"date-parts":[[2026,6,16]],"date-time":"2026-06-16T08:11:30Z","timestamp":1781597490000},"page":"40-45","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Comparative Study of Adversarial Training and Randomized Smoothing for Robust AI-Generated Image Attribution"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0007-6275-9767","authenticated-orcid":false,"given":"Kai","family":"Zeng","sequence":"first","affiliation":[{"name":"Department of Information engineering and mathematics, University of Siena, Siena, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2212-4728","authenticated-orcid":false,"given":"Niccol\u00f2","family":"Pancino","sequence":"additional","affiliation":[{"name":"Department of Information engineering and mathematics, University of Siena, Siena, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0008-9672-6418","authenticated-orcid":false,"given":"Nasrin","family":"Malekzadeh Goradel","sequence":"additional","affiliation":[{"name":"Department of Information engineering and mathematics, University of Siena, Siena, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7368-0866","authenticated-orcid":false,"given":"Mauro","family":"Barni","sequence":"additional","affiliation":[{"name":"Department of Information engineering and mathematics, University of Siena, Siena, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7518-046X","authenticated-orcid":false,"given":"Benedetta","family":"Tondi","sequence":"additional","affiliation":[{"name":"Department of Information engineering and mathematics, University of Siena, Siena, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,6,16]]},"reference":[{"key":"e_1_3_3_2_2_2","volume-title":"International Joint Conference on Neural Networks (IJCNN) 2025 - Verimedia Workshop.","author":"Bongini P.","year":"2025","unstructured":"P. Bongini, S. Mandelli, A. Montibeller, M. Casu, O. Pontorno, V. Ragaglia, L. Zanchetta, M. Aquilina, T. Wani, L. Guarnera, et\u00a0al. 2025. WILD: a new in-the-Wild Image Linkage Dataset for synthetic image attribution. In International Joint Conference on Neural Networks (IJCNN) 2025 - Verimedia Workshop."},{"key":"e_1_3_3_2_3_2","volume-title":"IEEE Int. Workshop Inf. Forensics Secur. (WIFS)","author":"Bongini P.","year":"2025","unstructured":"P. Bongini, V. Molinari, A. Costanzo, B. Tondi, and M. Barni. 2025. Training-free Source Attribution of AI-generated Images via Resynthesis. In IEEE Int. Workshop Inf. Forensics Secur. (WIFS)."},{"key":"e_1_3_3_2_4_2","first-page":"146","volume-title":"Eur. Conf. Comput. Vis.","author":"Bui T.","year":"2022","unstructured":"T. Bui, N. Yu, and J. Collomosse. 2022. Repmix: Representation mixing for robust attribution of synthesized images. In Eur. Conf. Comput. Vis. Springer, 146\u2013163."},{"key":"e_1_3_3_2_5_2","first-page":"658","volume-title":"Proc. IEEE\/CVF Conf. Comput. Vis. Pattern Recognit. Workshops (CVPRW)","author":"Carlini N.","year":"2020","unstructured":"N. Carlini and H. Farid. 2020. Evading deepfake-image detectors with white-and black-box attacks. In Proc. IEEE\/CVF Conf. Comput. Vis. Pattern Recognit. Workshops (CVPRW). 658\u2013659."},{"key":"e_1_3_3_2_6_2","first-page":"1310","volume-title":"Proc. Int. Conf. Mach. Learn. (ICML)","author":"Cohen J.","year":"2019","unstructured":"J. Cohen, E. Rosenfeld, and Z. Kolter. 2019. Certified adversarial robustness via randomized smoothing. In Proc. Int. Conf. Mach. Learn. (ICML). PMLR, 1310\u20131320."},{"key":"e_1_3_3_2_7_2","doi-asserted-by":"crossref","unstructured":"Z. Ji and L. Cao. 2025. Multi-modal Video Forgery Detection via Improved Efficient-Net With Attention and Transformer Fusion. Informatica 49 30 (2025).","DOI":"10.31449\/inf.v49i30.8831"},{"key":"e_1_3_3_2_8_2","volume-title":"IEEE Int. Workshop Inf. Forensics Secur. (WIFS)","author":"K.\u00a0Zeng M.\u00a0Barni","year":"2025","unstructured":"M.\u00a0Barni K.\u00a0Zeng and B. Tondi. 2025. A Targeted Attack against Certifiably Robust Smoothed Classifiers. In IEEE Int. Workshop Inf. Forensics Secur. (WIFS)."},{"key":"e_1_3_3_2_9_2","unstructured":"A. Kurakin I. Goodfellow and S. Bengio. 2016. Adversarial machine learning at scale. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/1611.01236 (2016)."},{"key":"e_1_3_3_2_10_2","first-page":"99","volume-title":"Artif. Intell. Saf. Secur.","author":"Kurakin A.","year":"2018","unstructured":"A. Kurakin, I. Goodfellow, and S. Bengio. 2018. Adversarial examples in the physical world. In Artif. Intell. Saf. Secur.Chapman and Hall\/CRC, 99\u2013112."},{"key":"e_1_3_3_2_11_2","volume-title":"International Conference on Learning Representations (ICLR)","author":"Madry A.","year":"2018","unstructured":"A. Madry, A. Makelov, L. Schmidt, D. Tsipras, and A. Vladu. 2018. Towards Deep Learning Models Resistant to Adversarial Attacks. In International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_3_2_12_2","first-page":"1","volume-title":"2024 IEEE International Workshop on Information Forensics and Security (WIFS)","author":"Mandelli S.","year":"2024","unstructured":"S. Mandelli, P. Bestagini, and S. Tubaro. 2024. When Synthetic Traces Hide Real Content: Analysis of Stable Diffusion Image Laundering. In 2024 IEEE International Workshop on Information Forensics and Security (WIFS). 1\u20136."},{"key":"e_1_3_3_2_13_2","first-page":"1","volume-title":"2019 IEEE international workshop on information forensics and security (WIFS)","author":"Marra F.","year":"2019","unstructured":"F. Marra, C. Saltori, G. Boato, and L. Verdoliva. 2019. Incremental learning for the detection and classification of gan-generated images. In 2019 IEEE international workshop on information forensics and security (WIFS). IEEE, 1\u20136."},{"key":"e_1_3_3_2_14_2","unstructured":"S. Mavali J. Ricker D. Pape A. Fischer and L. Sch\u00f6nherr. 2024. Adversarial Robustness of AI-Generated Image Detectors in the Real World. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2410.01574 (2024)."},{"key":"e_1_3_3_2_15_2","doi-asserted-by":"crossref","first-page":"65","DOI":"10.1145\/3658664.3659635","volume-title":"Proc.of the 2024 ACM Workshop on Information Hiding and Multimedia Security","author":"Purnekar N.","year":"2024","unstructured":"N. Purnekar, L. Abady, B. Tondi, and M. Barni. 2024. Improving the robustness of synthetic images detection by means of print and scan augmentation. In Proc.of the 2024 ACM Workshop on Information Hiding and Multimedia Security. 65\u201373."},{"key":"e_1_3_3_2_16_2","first-page":"4322","volume-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition","author":"Rony J.","year":"2019","unstructured":"J. Rony, L.\u00a0G. Hafemann, L. Oliveira, I. Ayed, R. Sabourin, and E. Granger. 2019. Decoupling direction and norm for efficient gradient-based l2 adversarial attacks and defenses. In Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition. 4322\u20134330."},{"key":"e_1_3_3_2_17_2","unstructured":"H. Salman J. Li I. Razenshteyn P. Zhang H. Zhang S. Bubeck and G. Yang. 2019. Provably robust deep learning via adversarially trained smoothed classifiers. Advances in neural information processing systems 32 (2019)."},{"key":"e_1_3_3_2_18_2","unstructured":"C. Schlarmann N. Singh F. Croce and M. Hein. 2024. Robust clip: Unsupervised adversarial fine-tuning of vision embeddings for robust large vision-language models. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2402.12336 (2024)."},{"key":"e_1_3_3_2_19_2","doi-asserted-by":"crossref","first-page":"3418","DOI":"10.1145\/3576915.3616588","volume-title":"Proceedings of the 2023 ACM SIGSAC conference on computer and communications security","author":"Sha Z.","year":"2023","unstructured":"Z. Sha, Z. Li, N. Yu, and Y. Zhang. 2023. De-fake: Detection and attribution of fake images generated by text-to-image generation models. In Proceedings of the 2023 ACM SIGSAC conference on computer and communications security. 3418\u20133432."},{"key":"e_1_3_3_2_20_2","doi-asserted-by":"crossref","unstructured":"B. Tondi W. Guo N. Pancino and M. Barni. 2025. JMA: A General Algorithm to Craft Nearly Optimal Targeted Adversarial Examples. IEEE Transactions on Information Forensics and Security 20 (2025) 11369\u201311384.","DOI":"10.1109\/TIFS.2025.3611121"},{"key":"e_1_3_3_2_21_2","first-page":"15856","volume-title":"Proc. IEEE\/CVF Conf. Comput. Vis. Pattern Recognit. (CVPR)","author":"Yang T.","year":"2023","unstructured":"T. Yang, D. Wang, F. Tang, X. Zhao, J. Cao, and S. Tang. 2023. Progressive open space expansion for open-set model attribution. In Proc. IEEE\/CVF Conf. Comput. Vis. Pattern Recognit. (CVPR). 15856\u201315865."},{"key":"e_1_3_3_2_22_2","volume-title":"IEEE\/CVF Int. Conf. Comput. Vis. (ICCV)","author":"Yu N.","year":"2019","unstructured":"N. Yu, L. Davis, and M. Fritz. 2019. Attributing Fake Images to GANs: Learning and Analyzing GAN Fingerprints. In IEEE\/CVF Int. Conf. Comput. Vis. (ICCV)."},{"key":"e_1_3_3_2_23_2","doi-asserted-by":"crossref","first-page":"815","DOI":"10.23919\/EUSIPCO63237.2025.11226152","volume-title":"33rd European Signal Processing Conference (EUSIPCO)","author":"Zeng K.","year":"2025","unstructured":"K. Zeng, M. Barni, and B. Tondi. 2025. Certifiably Robust Synthetic Image Detectors. In 33rd European Signal Processing Conference (EUSIPCO). 815\u2013819."}],"event":{"name":"IH&MMSec '26: ACM Workshop on Information Hiding and Multimedia Security","location":"Firenze Italy","acronym":"IH&MMSec '26","sponsor":["SIGMM ACM Special Interest Group on Multimedia"]},"container-title":["Proceedings of the 2026 ACM Workshop on Information Hiding and Multimedia Security"],"original-title":[],"deposited":{"date-parts":[[2026,6,16]],"date-time":"2026-06-16T08:14:28Z","timestamp":1781597668000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3785353.3815073"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6,16]]},"references-count":22,"alternative-id":["10.1145\/3785353.3815073","10.1145\/3785353"],"URL":"https:\/\/doi.org\/10.1145\/3785353.3815073","relation":{},"subject":[],"published":{"date-parts":[[2026,6,16]]},"assertion":[{"value":"2026-06-16","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}