Generalizable Face Forgery Detection via Perturb-and-Deblur Stability | Research Square window.SnipcartSettings = { analytics: { enabled: false } }; (function() { var accessVector = localStorage.getItem('access_vector') || ''; window.dataLayer = window.dataLayer || []; if (accessVector) { window.dataLayer.push({ user: { profile: { profileInfo: { snid: accessVector } } } }); } })(); (function(w,d,s,l,i){w[l]=w[l]||[];w[l].push({'gtm.start':new Date().getTime(),event:'gtm.js'});var f=d.getElementsByTagName(s)[0],j=d.createElement(s),dl=l!='dataLayer'?'&l='+l:'';j.async=true;j.src='https://www.googletagmanager.com/gtm.js?id='+i+dl;f.parentNode.insertBefore(j,f);})(window,document,'script','dataLayer','GTM-K279D39R'); Browse Preprints In Review Journals COVID-19 Preprints AJE Video Bytes Research Tools Research Promotion AJE Professional Editing AJE Rubriq About Preprint Platform In Review Editorial Policies Our Team Advisory Board Help Center Sign In Submit a Preprint Cite Share Download PDF Research Article Generalizable Face Forgery Detection via Perturb-and-Deblur Stability Xiaotian Si, Linghui Li, Liwei Zhang, Ziduo Guo, Kaiguo Yuan, and 1 more This is a preprint; it has not been peer reviewed by a journal. https://doi.org/ 10.21203/rs.3.rs-7537352/v1 This work is licensed under a CC BY 4.0 License Status: Under Review Version 1 posted 9 You are reading this latest preprint version Abstract The growing realism and spread of facial deepfakes threaten individual privacy and information security.However, existing face forgery detectors exhibit limited generalization capabilities, struggling to detect forgeries created by unseen manipulation methods during training. This limitation restricts the effectiveness of detectors in real-world applications. This paper introduces a novel detection framework built upon the concept of perturb-and-deblur stability. The key idea is that real and forged faces behave differently under perturbation followed by deblurring: real faces remain stable, while forged faces exhibit unstable reconstructions. To systematically exploit this property, deblurring-based auxiliary domains are constructed, including deblurred images, residuals, and hierarchical features, which are further enriched by a multi-scale attention mechanism. A transformer-based domain relation encoder integrates these domains to capture discriminative stability patterns for generalized classification. Extensive experiments conducted on multiple public benchmarks demonstrate that the proposed approach consistently outperforms state-of-the-art detectors, achieving superior robustness and cross-dataset generalization. These results verify the effectiveness of perturb-and-deblur stability as a generalizable cue for face forgery detection. Face Forgery Detection Generalization Deblurring Transformer Full Text Additional Declarations No competing interests reported. Cite Share Download PDF Status: Under Review Version 1 posted Editorial decision: Revision requested 27 Dec, 2025 Reviews received at journal 04 Dec, 2025 Reviews received at journal 02 Dec, 2025 Reviewers agreed at journal 02 Dec, 2025 Reviewers agreed at journal 25 Nov, 2025 Reviewers invited by journal 09 Nov, 2025 Editor assigned by journal 05 Sep, 2025 Submission checks completed at journal 05 Sep, 2025 First submitted to journal 04 Sep, 2025 You are reading this latest preprint version Research Square lets you share your work early, gain feedback from the community, and start making changes to your manuscript prior to peer review in a journal. As a division of Research Square Company, we’re committed to making research communication faster, fairer, and more useful. We do this by developing innovative software and high quality services for the global research community. Our growing team is made up of researchers and industry professionals working together to solve the most critical problems facing scientific publishing. Also discoverable on Platform About Our Team In Review Editorial Policies Advisory Board Help Center Resources Author Services Accessibility API Access RSS feed Manage Cookie Preferences © Research Square 2026 | ISSN 2693-5015 (online) Privacy Policy Terms of Service Do Not Sell My Personal Information {"props":{"pageProps":{"initialData":{"identity":"rs-7537352","acceptedTermsAndConditions":true,"allowDirectSubmit":false,"archivedVersions":[],"articleType":"Research Article","associatedPublications":[],"authors":[{"id":542328382,"identity":"dd63cc7d-3b9e-4273-8139-d704d1006d86","order_by":0,"name":"Xiaotian Si","email":"","orcid":"","institution":"Beijing University of Posts and Telecommunications","correspondingAuthor":false,"prefix":"","firstName":"Xiaotian","middleName":"","lastName":"Si","suffix":""},{"id":542328383,"identity":"f34db9af-e633-4869-850a-acfd96a69d1f","order_by":1,"name":"Linghui Li","email":"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAZAAAAAyAQMAAABI0h/eAAAABlBMVEX///8AAABVwtN+AAAACXBIWXMAAA7EAAAOxAGVKw4bAAAA20lEQVRIiWNgGAWjYBACPmbmhgMMDAcY2Nh7oEIHCGhhY2aEauE5A+QmEKOFgbEBokwih1gt7IyNhwt+3Unsk3x7TLrwB4Mc340Exs8FBBx2eGbfs8Q26bw06RkJDMaSNxKYpWcQ0sLbcxioJcdMmieBIXHDjQQ2Zh6itEieAWupJ04Lzw+gFgkesJYEA+JsaThs3MaTl2w9I03CcOaZh83S+LTw8x8+/Jnnz2HZ+e1nD94usLGR5zuefPAzPi1gwNgGoZmBsQPiNhDSAAR/4FpGwSgYBaNgFGACAH3mSepEN5WsAAAAAElFTkSuQmCC","orcid":"","institution":"Beijing University of Posts and Telecommunications","correspondingAuthor":true,"prefix":"","firstName":"Linghui","middleName":"","lastName":"Li","suffix":""},{"id":542328384,"identity":"d145a0ed-84f2-4a90-95b3-8adc3daef3f9","order_by":2,"name":"Liwei Zhang","email":"","orcid":"","institution":"Beijing University of Posts and Telecommunications","correspondingAuthor":false,"prefix":"","firstName":"Liwei","middleName":"","lastName":"Zhang","suffix":""},{"id":542328385,"identity":"e0bf037f-e079-4b4d-8284-91ffe53c83a1","order_by":3,"name":"Ziduo Guo","email":"","orcid":"","institution":"Beijing University of Posts and Telecommunications","correspondingAuthor":false,"prefix":"","firstName":"Ziduo","middleName":"","lastName":"Guo","suffix":""},{"id":542328386,"identity":"a5fff835-e19d-4e90-b70c-431f94350e5f","order_by":4,"name":"Kaiguo Yuan","email":"","orcid":"","institution":"Beijing University of Posts and Telecommunications","correspondingAuthor":false,"prefix":"","firstName":"Kaiguo","middleName":"","lastName":"Yuan","suffix":""},{"id":542328387,"identity":"01bdc44a-aa4c-4d31-ae42-53a83f229354","order_by":5,"name":"Bingyu Li","email":"","orcid":"","institution":"Beihang University","correspondingAuthor":false,"prefix":"","firstName":"Bingyu","middleName":"","lastName":"Li","suffix":""}],"badges":[],"createdAt":"2025-09-04 14:53:26","currentVersionCode":1,"declarations":"","doi":"10.21203/rs.3.rs-7537352/v1","doiUrl":"https://doi.org/10.21203/rs.3.rs-7537352/v1","draftVersion":[],"editorialEvents":[],"editorialNote":"","failedWorkflow":false,"files":[{"id":96321469,"identity":"7b3cb303-31ae-4341-a1ac-b8ecc7f11234","added_by":"auto","created_at":"2025-11-19 19:14:35","extension":"json","order_by":0,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":7240,"visible":true,"origin":"","legend":"","description":"","filename":"aed64fdb5a25479eb5b803a730e74fe0.json","url":"https://assets-eu.researchsquare.com/files/rs-7537352/v1/7e02a812c37650f947d6e9c8.json"},{"id":96366556,"identity":"ad27ac8e-c59c-4b34-b616-fa363930043e","added_by":"auto","created_at":"2025-11-20 10:11:33","extension":"pdf","order_by":1,"title":"","display":"","copyAsset":false,"role":"manuscript-pdf","size":740427,"visible":true,"origin":"","legend":"","description":"","filename":"NPL.pdf","url":"https://assets-eu.researchsquare.com/files/rs-7537352/v1_covered_9da6bb42-decf-4e79-8b2c-70840313a46b.pdf"}],"financialInterests":"No competing interests reported.","formattedTitle":"Generalizable Face Forgery Detection via Perturb-and-Deblur Stability","fulltext":[],"fulltextSource":"","fullText":"","funders":[],"hasAdminPriorityOnWorkflow":false,"hasManuscriptDocX":false,"hasOptedInToPreprint":true,"hasPassedJournalQc":"","hasAnyPriority":false,"hideJournal":false,"highlight":"","institution":"","isAcceptedByJournal":false,"isAuthorSuppliedPdf":true,"isDeskRejected":"","isHiddenFromSearch":false,"isInQc":false,"isInWorkflow":false,"isPdf":true,"isPdfUpToDate":true,"isWithdrawnOrRetracted":false,"journal":{"display":true,"email":"
[email protected]","identity":"neural-processing-letters","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":false,"externalIdentity":"nepl","sideBox":"Learn more about [Neural Processing Letters](http://link.springer.com/journal/11063)","snPcode":"11063","submissionUrl":"https://submission.nature.com/new-submission/11063/3","title":"Neural Processing Letters","twitterHandle":"","acdcEnabled":true,"dfaEnabled":true,"editorialSystem":"em","reportingPortfolio":"Springer Hybrid","inReviewEnabled":true,"inReviewRevisionsEnabled":false},"keywords":"Face Forgery Detection, Generalization, Deblurring, Transformer","lastPublishedDoi":"10.21203/rs.3.rs-7537352/v1","lastPublishedDoiUrl":"https://doi.org/10.21203/rs.3.rs-7537352/v1","license":{"name":"CC BY 4.0","url":"https://creativecommons.org/licenses/by/4.0/"},"manuscriptAbstract":"The growing realism and spread of facial deepfakes threaten individual privacy and information security.However, existing face forgery detectors exhibit limited generalization capabilities, struggling to detect forgeries created by unseen manipulation methods during training. This limitation restricts the effectiveness of detectors in real-world applications. This paper introduces a novel detection framework built upon the concept of perturb-and-deblur stability. The key idea is that real and forged faces behave differently under perturbation followed by deblurring: real faces remain stable, while forged faces exhibit unstable reconstructions. To systematically exploit this property, deblurring-based auxiliary domains are constructed, including deblurred images, residuals, and hierarchical features, which are further enriched by a multi-scale attention mechanism. A transformer-based domain relation encoder integrates these domains to capture discriminative stability patterns for generalized classification. Extensive experiments conducted on multiple public benchmarks demonstrate that the proposed approach consistently outperforms state-of-the-art detectors, achieving superior robustness and cross-dataset generalization. These results verify the effectiveness of perturb-and-deblur stability as a generalizable cue for face forgery detection.","manuscriptTitle":"Generalizable Face Forgery Detection via Perturb-and-Deblur Stability","msid":"","msnumber":"","nonDraftVersions":[{"code":1,"date":"2025-11-19 19:14:30","doi":"10.21203/rs.3.rs-7537352/v1","editorialEvents":[{"type":"communityComments","content":0},{"type":"decision","content":"Revision requested","date":"2025-12-27T06:51:38+00:00","index":"","fulltext":""},{"type":"editorInvitedReview","content":"","date":"2025-12-04T05:18:54+00:00","index":"hide","fulltext":""},{"type":"editorInvitedReview","content":"","date":"2025-12-03T02:24:28+00:00","index":"hide","fulltext":""},{"type":"reviewerAgreed","content":"29685131336829547144885232984306546066","date":"2025-12-03T00:38:52+00:00","index":"hide","fulltext":""},{"type":"reviewerAgreed","content":"282612747531849625753386318196700816952","date":"2025-11-26T01:42:07+00:00","index":"hide","fulltext":""},{"type":"reviewersInvited","content":"","date":"2025-11-10T01:36:02+00:00","index":"","fulltext":""},{"type":"editorAssigned","content":"","date":"2025-09-05T06:33:49+00:00","index":"","fulltext":""},{"type":"checksComplete","content":"","date":"2025-09-05T06:33:40+00:00","index":"","fulltext":""},{"type":"submitted","content":"Neural Processing Letters","date":"2025-09-04T14:48:16+00:00","index":"","fulltext":""}],"status":"published","journal":{"display":true,"email":"
[email protected]","identity":"neural-processing-letters","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":false,"externalIdentity":"nepl","sideBox":"Learn more about [Neural Processing Letters](http://link.springer.com/journal/11063)","snPcode":"11063","submissionUrl":"https://submission.nature.com/new-submission/11063/3","title":"Neural Processing Letters","twitterHandle":"","acdcEnabled":true,"dfaEnabled":true,"editorialSystem":"em","reportingPortfolio":"Springer Hybrid","inReviewEnabled":true,"inReviewRevisionsEnabled":false}}],"origin":"","ownerIdentity":"798ae701-a95e-48bf-b8aa-d3ed9912d3da","owner":[],"postedDate":"November 19th, 2025","published":true,"recentEditorialEvents":[],"rejectedJournal":[],"revision":"","amendment":"","status":"under-review","subjectAreas":[],"tags":[],"updatedAt":"2026-05-12T07:54:27+00:00","versionOfRecord":[],"versionCreatedAt":"2025-11-19 19:14:30","video":"","vorDoi":"","vorDoiUrl":"","workflowStages":[]},"version":"v1","identity":"rs-7537352","journalConfig":"researchsquare"},"__N_SSP":true},"page":"/article/[identity]/[[...version]]","query":{"redirect":"/article/rs-7537352","identity":"rs-7537352","version":["v1"]},"buildId":"8U1c8b4HqxoKbykW_rLl7","isFallback":false,"isExperimentalCompile":false,"dynamicIds":[84888],"gssp":true,"scriptLoader":[]}
Text is read by the "Ask this paper" AI Q&A widget below.
Extraction quality varies by source — PMC NXML preserves structure
cleanly, OA-HTML may include some navigation residue, and OA-PDF can
have broken hyphenation. The publisher copy
(via DOI)
is the canonical version.