APT: Anchor-aligned Perturbations for Tamper Localization in Fully Regenerated Images
Abstract
Proactive tamper localization embeds an imperceptible sig-nal into an image prior to distribution, enabling pixel-level manipulationdetection. Existing methods assume a spliced (SP) setting, where syn-thesized regions are composited onto the original background, leavingembedded signals intact. However, real-world diffusion-based inpaint-ing operates in a fully regenerated (FR) setting, where the entire im-age undergoes denoising, disrupting background signals and renderingexisting frameworks ineffective. We propose APT, a semi-fragile latent-space perturbation that embeds a dense, vector-wise localization signal.By aligning each spatial feature vector toward a fixed anchor direction,APT localizes tampering via the alignment disparity between synthesizedforeground and anchor-aligned background features after inpainting. Theproposed hard negative mining loss and noisy perturbation branch fur-ther enforce uniform alignment. Experiments on COCO demonstratethat APT achieves an FR IoU of 0.92, outperforming the strongest base-line (WAM, 0.84), while existing methods collapse to near-random per-formance (AUC ≈ 0.5), establishing APT as a practical forensic frame-work generalizable across tampering types unknown at test time.