11institutetext: University of Oxford, Oxford OX1 3PJ, United Kingdom 22institutetext: Nanyang Technological University, Singapore 639798, Singapore
22email: [email protected], [email protected]

Which Model Generated This Image? A Model-Agnostic Approach for Origin Attribution

Fengyuan Liu 11    Haochen Luo 11    Yiming Li 22    Philip Torr 11    Jindong Gu Corresponding author11
Abstract

Recent progress in visual generative models enables the generation of high-quality images. To prevent the misuse of generated images, it is important to identify the origin model that generates them. In this work, we study the origin attribution of generated images in a practical setting where only a few images generated by a source model are available and the source model cannot be accessed. The goal is to check if a given image is generated by the source model. We first formulate this problem as a few-shot one-class classification task. To solve the task, we propose OCC-CLIP, a CLIP-based framework for few-shot one-class classification, enabling the identification of an image’s source model, even among multiple candidates. Extensive experiments corresponding to various generative models verify the effectiveness of our OCC-CLIP framework. Furthermore, an experiment based on the recently released DALL·E-3 API verifies the real-world applicability of our solution. Our source code is available at https://github.com/uwFengyuan/OCC-CLIP.

Keywords:
Model Attribution Generated Images CLIP Classification

1 Introduction

Recent visual generative models are capable of producing images of exceptional quality, which have raised public concerns regarding Intellectual Property (IP) protection and accountability for misuse [15, 31, 34, 33]. In response to both the challenges and opportunities posed by Artificial Intelligence-Generated Content (AIGC), a recent U.S. executive order [3] mandates that all AI-generated content must clearly label its source, such as Stable Diffusion [46]. This makes the attribution of origins for generated images crucial in real-world applications, referring to the process of identifying whether a given image is generated by a particular model.

To address the origin attribution problem above, three main methods have been explored in the community. The first method involves watermarking [57, 37, 43, 59, 35], which requires additional modifications to the generated results, affecting the quality of generation. The second method involves injecting fingerprints [68, 10, 69, 70] into the model during training and employing a supervised classifier to identify these fingerprints. This process necessitates changes in training. Modification-free approaches have also been proposed, which do not require modifications to the generation or training processes. Specifically, the existing methods utilize inverse engineering [64, 29], based on the idea that a synthetic sample can be most accurately reconstructed by the generator that created it. However, inverse engineering approaches necessitate access to the target model and require sampling many images as references.

Refer to caption
Figure 1: A simple demonstration of origin attribution in a practical, open-world setting. Inspectors receive a few samples from DALL·E-3. Users then submit an image, which could either be a real photograph or generated by DALL·E-3 or other models. If it’s determined that the image and the provided samples were generated by the same model, we can then identify DALL·E-3 as the origin model of the query image.

In this work, we aim to conduct origin attribution in a practical open-world setting (Fig. 1), where model parameters cannot be accessed and only a few samples generated by the model are available. This setting is meaningful in real-world applications since current generative models, e.g., DALL·E-3 [2], are not open-sourced, and sampling many images from them requires substantial costs.

To overcome the challenges in this setting, we first formulate the problem as a few-shot one-class classification task. Then, we propose a CLIP-based framework as an effective solution, dubbed OCC-CLIP. With our framework, we can determine if a given image and the few-shot available images were generated from the same model. If so, we can confidently identify the model that generated the few images as the origin model of the given image. Furthermore, we also demonstrate that our method can be extended to conduct origin attribution for multiple source models via One-vs-Rest.

Extensive experiments on various generative models have verified that our proposed framework can effectively determine the origin attribution of a given image. Additionally, our framework demonstrates superiority when different numbers of shots are available, and when image preprocessing is applied to the given images. It also proves effective in multi-source origin attribution scenarios. Furthermore, our experiments, based on the recently released DALL·E-3 [2] API, confirm the effectiveness of our solution in real-world commercial systems.

Our main contributions can be summarized as follows.

  • We propose a new task within a practical setting where generated images are attributed to the origin model only with few-shot available images generated by the model.

  • We formulate the problem as a few-shot one-class classification task and then propose a CLIP-based framework, named OOC-CLIP, to address it.

  • Extensive experiments are conducted on 8 generative models, including diffusion models and GANs. Further verification of our solution is carried out on a real-world image generative system, namely, DALL·E-3 [2].

2 Related Work

Deep Visual Generative Models: The advent of deep learning has brought significant advancements in deep visual generative models, leading to the development of sophisticated methods for creating synthetic media. Variational Autoencoders (VAEs) [45, 28, 41] are notable for their dual-structure framework. In VAEs, an encoder condenses complex data into simpler latent representations, which a decoder then uses to reconstruct the original data. Generative Adversarial Networks (GANs) [14, 1, 60, 24, 49] operate on a principle of competition between two components: a generator that creates data samples and a discriminator that judges their authenticity. Through iterative training, both components enhance their capabilities, improving the overall quality of the generated data. Diffusion Models [21, 56, 46, 19, 40, 48] employ a two-phase process. Initially, they transform data into noise, and then methodically remove this noise to reverse the process. This approach can generate highly realistic images.

Origin Attribution of Generated images: Origin attribution, distinct from generated image detection, seeks to determine whether specific images were produced by a particular model. Various strategies have been proposed to address this challenge. One method involves embedding watermarks [57, 37, 43, 59] in images to trace their origins. However, this approach faces limitations as different models might use identical watermarks, which can also be manipulated or removed [35]. Alternatively, injecting unique fingerprints [68, 10, 69, 70] into a model during its training phase enables the identification of these markers using a supervised classifier. Although effective, this technique necessitates modifications to the training process and the model’s architecture. A different, modification-free method is inverse engineering [64, 29], which leverages the principle that a synthetic sample can be most accurately reconstructed by its original generator. However, this approach requires access to the target model and extensive sampling of images for comparison. Furthermore, three studies have explored this area under different settings. One develops a multi-class classifier known as an attributor for fake image attribution. Yet, it is only applicable to text-to-image models and operates within a limited, closed-world scenario[54]. One [13] utilizes an iterative multi-step pipeline to detect the origins of images generated by different GANs. However, it requires many samples. The other study[27] demonstrates a theoretical lower bound on attribution accuracy using smaller datasets (e.g. MNIST [30]). This method is only suitable for unconditional GANs and reveals limited scalability to more complex systems, such as DALL·E-3 [2].

Few-shot One-class classification: One-class classification has long been recognized as a challenging problem, with numerous studies [51, 6, 50, 47] addressing it. However, few works have explored the few-shot one-class classification (FS-OCC) problem in the image domain. Previous FS-OCC research in the image domain, specifically based on meta-learning [12], suffers from memory inefficiency, making it unsuitable for processing high-resolution images. In contrast, the CLIP-based classifier, CoOp [71], has demonstrated excellent performance in few-shot learning settings, where a few images from each class are available. Our setting, however, differs as it involves only a few images from a single class, generated by a generative model. Therefore, instead of pursuing multi-class classification, we utilize CLIP for one-class classification.

3 Approach

In this section, we first introduce the standard CLIP-based classification framework and then present our OCC-CLIP framework for few-shot one-class classification. At the end, we show how to extend our framework to multiple classes.

3.1 Background of CLIP-based Classification

CLIP is a multimodal model pre-trained to predict whether an image matches a text prompt. It includes an image encoder Ev()subscript𝐸𝑣E_{v}(\cdot)italic_E start_POSTSUBSCRIPT italic_v end_POSTSUBSCRIPT ( ⋅ ) and text encoder Et()subscript𝐸𝑡E_{t}(\cdot)italic_E start_POSTSUBSCRIPT italic_t end_POSTSUBSCRIPT ( ⋅ ). The pre-trained CLIP can perform zero-shot multi-class classification by comparing the image with a list of prompts [16], each representing a class. Formally, assume we have K𝐾Kitalic_K classes. Let Xvsuperscript𝑋𝑣X^{v}italic_X start_POSTSUPERSCRIPT italic_v end_POSTSUPERSCRIPT𝒳absent𝒳\in\mathcal{X}∈ caligraphic_X denote an image and Xitsubscriptsuperscript𝑋𝑡𝑖X^{t}_{i}italic_X start_POSTSUPERSCRIPT italic_t end_POSTSUPERSCRIPT start_POSTSUBSCRIPT italic_i end_POSTSUBSCRIPT represent the ithsubscript𝑖thi_{\text{th}}italic_i start_POSTSUBSCRIPT th end_POSTSUBSCRIPT prompt representing the ithsubscript𝑖thi_{\text{th}}italic_i start_POSTSUBSCRIPT th end_POSTSUBSCRIPT class. The predicted ithsubscript𝑖thi_{\text{th}}italic_i start_POSTSUBSCRIPT th end_POSTSUBSCRIPT class probability of the image Xvsuperscript𝑋𝑣X^{v}italic_X start_POSTSUPERSCRIPT italic_v end_POSTSUPERSCRIPT is computed as follows:

p(class=i|v)=exp(sim(Et(Xit),Ev(Xv)))j=1Kexp(sim(Et(Xjt),Ev(Xv))),𝑝classconditional𝑖𝑣simsubscript𝐸𝑡subscriptsuperscript𝑋𝑡𝑖subscript𝐸𝑣superscript𝑋𝑣superscriptsubscript𝑗1𝐾simsubscript𝐸𝑡subscriptsuperscript𝑋𝑡𝑗subscript𝐸𝑣superscript𝑋𝑣p(\text{class}=i|v)=\frac{\exp(\mathrm{sim}(E_{t}(X^{t}_{i}),E_{v}(X^{v})))}{% \sum_{j=1}^{K}\exp(\mathrm{sim}(E_{t}(X^{t}_{j}),E_{v}(X^{v})))},italic_p ( class = italic_i | italic_v ) = divide start_ARG roman_exp ( roman_sim ( italic_E start_POSTSUBSCRIPT italic_t end_POSTSUBSCRIPT ( italic_X start_POSTSUPERSCRIPT italic_t end_POSTSUPERSCRIPT start_POSTSUBSCRIPT italic_i end_POSTSUBSCRIPT ) , italic_E start_POSTSUBSCRIPT italic_v end_POSTSUBSCRIPT ( italic_X start_POSTSUPERSCRIPT italic_v end_POSTSUPERSCRIPT ) ) ) end_ARG start_ARG ∑ start_POSTSUBSCRIPT italic_j = 1 end_POSTSUBSCRIPT start_POSTSUPERSCRIPT italic_K end_POSTSUPERSCRIPT roman_exp ( roman_sim ( italic_E start_POSTSUBSCRIPT italic_t end_POSTSUBSCRIPT ( italic_X start_POSTSUPERSCRIPT italic_t end_POSTSUPERSCRIPT start_POSTSUBSCRIPT italic_j end_POSTSUBSCRIPT ) , italic_E start_POSTSUBSCRIPT italic_v end_POSTSUBSCRIPT ( italic_X start_POSTSUPERSCRIPT italic_v end_POSTSUPERSCRIPT ) ) ) end_ARG , (1)

where sim()sim\mathrm{sim}(\cdot)roman_sim ( ⋅ ) measures the distance between two embeddings, e.g., dot product.

In the classification above, hand-crafted text prompts are applied to represent classes [16]. The prompt designs require specialized knowledge and are time-consuming to create. To alleviate this, Zhou et al. [71] introduced the concept of Context Optimization (CoOp), which employs learnable vectors to refine prompt-related words. Instead of manually designing a prompt, CoOp enables the model to automatically optimize for a suitable prompt. Formally, the prompt for the ithsubscript𝑖thi_{\text{th}}italic_i start_POSTSUBSCRIPT th end_POSTSUBSCRIPT class can be represented as Xip=[t][CLASSi]subscriptsuperscript𝑋𝑝𝑖tensor-productdelimited-[]𝑡delimited-[]𝐶𝐿𝐴𝑆subscript𝑆𝑖X^{p}_{i}=[t]\otimes[CLASS_{i}]italic_X start_POSTSUPERSCRIPT italic_p end_POSTSUPERSCRIPT start_POSTSUBSCRIPT italic_i end_POSTSUBSCRIPT = [ italic_t ] ⊗ [ italic_C italic_L italic_A italic_S italic_S start_POSTSUBSCRIPT italic_i end_POSTSUBSCRIPT ], where t𝑡titalic_t is the learnable context vectors, tensor-product\otimes is a concatenation operation and CLASSi𝐶𝐿𝐴𝑆subscript𝑆𝑖CLASS_{i}italic_C italic_L italic_A italic_S italic_S start_POSTSUBSCRIPT italic_i end_POSTSUBSCRIPT corresponds to the name of ithsubscript𝑖thi_{\text{th}}italic_i start_POSTSUBSCRIPT th end_POSTSUBSCRIPT class. The objective of optimization is to minimize the error of predicting ground truth Yisubscript𝑌𝑖Y_{i}italic_Y start_POSTSUBSCRIPT italic_i end_POSTSUBSCRIPT for each Xivsubscriptsuperscript𝑋𝑣𝑖X^{v}_{i}italic_X start_POSTSUPERSCRIPT italic_v end_POSTSUPERSCRIPT start_POSTSUBSCRIPT italic_i end_POSTSUBSCRIPT. This is achieved by using a cross-entropy loss function \mathcal{L}caligraphic_L with respect to the learnable prompts. Let f𝑓fitalic_f represent the pre-trained CLIP model. The optimization can be described as:

minXpj=1Ni=1K(f(Ev(Xjv),Et(Xip)),Yi),superscript𝑋𝑝minsuperscriptsubscript𝑗1𝑁superscriptsubscript𝑖1𝐾𝑓subscript𝐸𝑣subscriptsuperscript𝑋𝑣𝑗subscript𝐸𝑡subscriptsuperscript𝑋𝑝𝑖subscript𝑌𝑖\underset{X^{p}}{\text{min}}\sum_{j=1}^{N}\sum_{i=1}^{K}\mathcal{L}(f(E_{v}(X^% {v}_{j}),E_{t}(X^{p}_{i})),Y_{i}),start_UNDERACCENT italic_X start_POSTSUPERSCRIPT italic_p end_POSTSUPERSCRIPT end_UNDERACCENT start_ARG min end_ARG ∑ start_POSTSUBSCRIPT italic_j = 1 end_POSTSUBSCRIPT start_POSTSUPERSCRIPT italic_N end_POSTSUPERSCRIPT ∑ start_POSTSUBSCRIPT italic_i = 1 end_POSTSUBSCRIPT start_POSTSUPERSCRIPT italic_K end_POSTSUPERSCRIPT caligraphic_L ( italic_f ( italic_E start_POSTSUBSCRIPT italic_v end_POSTSUBSCRIPT ( italic_X start_POSTSUPERSCRIPT italic_v end_POSTSUPERSCRIPT start_POSTSUBSCRIPT italic_j end_POSTSUBSCRIPT ) , italic_E start_POSTSUBSCRIPT italic_t end_POSTSUBSCRIPT ( italic_X start_POSTSUPERSCRIPT italic_p end_POSTSUPERSCRIPT start_POSTSUBSCRIPT italic_i end_POSTSUBSCRIPT ) ) , italic_Y start_POSTSUBSCRIPT italic_i end_POSTSUBSCRIPT ) , (2)

where N𝑁Nitalic_N is the number of images. In practice, CoOp [71] shows that only a small number of labeled examples are required to learn effective prompts. In summary, prompt learning enables CLIP-based Classification effective in the few-shot learning setting.

Refer to caption
Figure 2: Overview of OCC-CLIP. The input text is represented by learnable context vectors, followed by two discrete classes: the target class corresponds to an image set queried from a generative model, and the non-target class corresponds to randomly sourced open-domain images. These classes can be labeled as contrasting pairs, such as non-target vs. target or negative vs. positive. The parameters for the text and image encoders, derived from the CLIP model, are fixed. Adversarial Data Augmentation (ADA) calculates the gradient of each pixel across non-target images. In the training phase, these gradients δvsuperscript𝛿𝑣\delta^{v}italic_δ start_POSTSUPERSCRIPT italic_v end_POSTSUPERSCRIPT are applied to the non-target images.

3.2 CLIP-based Few-shot One-Class Classification

The CLIP-based classifier, CoOp, can achieve excellent performance in the few-shot learning setting where a few images from each class are available. Nevertheless, in our setting, only a few images from one class, generated by a generative model, are available. Hence, a standard CLIP-based classifier cannot be applied directly to solve the few-shot one-class classification task.

We now present our CLIP-based framework for One-Class Classification, called OCC-CLIP. In our framework (Fig. 2), the few images collected from a generative model are treated as the target class, while the images randomly sampled from a clean dataset are labeled as the non-target class. The two classes can be labeled as any contrasting pairs, such as non-target vs. target or negative vs. positive. Two learnable prompts corresponding to the target and non-target classes are optimized on these images, respectively.

The few images selected for the non-target class cannot represent the whole distribution of the non-target class well since they are randomly sampled from an open-source dataset (e.g. ImageNet [9]). To overcome this challenge, we propose an adversarial data augmentation (ADA) technique that, during training, extends coverage of the non-target class space and more closely approximates the boundary to the target space, thereby improving the model’s ability to learn the attribution of the target model. ADA aims to maximize the loss by adding small perturbations δvsuperscript𝛿𝑣\delta^{v}italic_δ start_POSTSUPERSCRIPT italic_v end_POSTSUPERSCRIPT to non-target images, while the learnable prompts aim to minimize the loss by learning the boundary between the target and non-target classes. In summary, the optimization in OCC-CLIP can be formulated as:

minXpmaxδvj=1Ni=1K(f(Ev(Xjv+δjv),Et(Xip)),Yi),subscriptsuperscript𝑋𝑝subscriptsuperscript𝛿𝑣superscriptsubscript𝑗1𝑁superscriptsubscript𝑖1𝐾𝑓subscript𝐸𝑣subscriptsuperscript𝑋𝑣𝑗subscriptsuperscript𝛿𝑣𝑗subscript𝐸𝑡subscriptsuperscript𝑋𝑝𝑖subscript𝑌𝑖\min_{X^{p}}\max_{\delta^{v}}\sum_{j=1}^{N}\sum_{i=1}^{K}\mathcal{L}(f(E_{v}(X% ^{v}_{j}+\delta^{v}_{j}),E_{t}(X^{p}_{i})),Y_{i}),roman_min start_POSTSUBSCRIPT italic_X start_POSTSUPERSCRIPT italic_p end_POSTSUPERSCRIPT end_POSTSUBSCRIPT roman_max start_POSTSUBSCRIPT italic_δ start_POSTSUPERSCRIPT italic_v end_POSTSUPERSCRIPT end_POSTSUBSCRIPT ∑ start_POSTSUBSCRIPT italic_j = 1 end_POSTSUBSCRIPT start_POSTSUPERSCRIPT italic_N end_POSTSUPERSCRIPT ∑ start_POSTSUBSCRIPT italic_i = 1 end_POSTSUBSCRIPT start_POSTSUPERSCRIPT italic_K end_POSTSUPERSCRIPT caligraphic_L ( italic_f ( italic_E start_POSTSUBSCRIPT italic_v end_POSTSUBSCRIPT ( italic_X start_POSTSUPERSCRIPT italic_v end_POSTSUPERSCRIPT start_POSTSUBSCRIPT italic_j end_POSTSUBSCRIPT + italic_δ start_POSTSUPERSCRIPT italic_v end_POSTSUPERSCRIPT start_POSTSUBSCRIPT italic_j end_POSTSUBSCRIPT ) , italic_E start_POSTSUBSCRIPT italic_t end_POSTSUBSCRIPT ( italic_X start_POSTSUPERSCRIPT italic_p end_POSTSUPERSCRIPT start_POSTSUBSCRIPT italic_i end_POSTSUBSCRIPT ) ) , italic_Y start_POSTSUBSCRIPT italic_i end_POSTSUBSCRIPT ) , (3)

where δvsuperscript𝛿𝑣\delta^{v}italic_δ start_POSTSUPERSCRIPT italic_v end_POSTSUPERSCRIPT is the adversarial image perturbation computed by our ADA technique.

input : Xvsuperscript𝑋𝑣X^{v}italic_X start_POSTSUPERSCRIPT italic_v end_POSTSUPERSCRIPT: images, Xpsuperscript𝑋𝑝X^{p}italic_X start_POSTSUPERSCRIPT italic_p end_POSTSUPERSCRIPT: learnable prompts, 𝒢𝒢\mathcal{G}caligraphic_G: ground truth, ϵitalic-ϵ\epsilonitalic_ϵ: updating step size
for Iterations do
       EV=Ev(Xv)𝐸𝑉subscript𝐸𝑣superscript𝑋𝑣EV=E_{v}(X^{v})italic_E italic_V = italic_E start_POSTSUBSCRIPT italic_v end_POSTSUBSCRIPT ( italic_X start_POSTSUPERSCRIPT italic_v end_POSTSUPERSCRIPT ), ET=Et(Xp)𝐸𝑇subscript𝐸𝑡superscript𝑋𝑝ET=E_{t}(X^{p})italic_E italic_T = italic_E start_POSTSUBSCRIPT italic_t end_POSTSUBSCRIPT ( italic_X start_POSTSUPERSCRIPT italic_p end_POSTSUPERSCRIPT ) ;
        \triangleright Extract embeddings
       G=𝒳(f(EV,ET),𝒢)𝐺subscript𝒳𝑓𝐸𝑉𝐸𝑇𝒢G=\nabla_{\mathcal{X}}\mathcal{L}(f(EV,ET),\mathcal{G})italic_G = ∇ start_POSTSUBSCRIPT caligraphic_X end_POSTSUBSCRIPT caligraphic_L ( italic_f ( italic_E italic_V , italic_E italic_T ) , caligraphic_G ) ;
        \triangleright Gradient calculation
       δv=ϵsign(G)superscript𝛿𝑣italic-ϵsign𝐺\delta^{v}=\epsilon\cdot\text{sign}(G)italic_δ start_POSTSUPERSCRIPT italic_v end_POSTSUPERSCRIPT = italic_ϵ ⋅ sign ( italic_G ) ;
        \triangleright Perturbation generation
       EVEv(Xv+δv)𝐸𝑉subscript𝐸𝑣superscript𝑋𝑣superscript𝛿𝑣EV\leftarrow E_{v}(X^{v}+\delta^{v})italic_E italic_V ← italic_E start_POSTSUBSCRIPT italic_v end_POSTSUBSCRIPT ( italic_X start_POSTSUPERSCRIPT italic_v end_POSTSUPERSCRIPT + italic_δ start_POSTSUPERSCRIPT italic_v end_POSTSUPERSCRIPT ) ;
        \triangleright Update image embeddings
       XpminXp(f(EV,ET),𝒢)superscript𝑋𝑝subscriptsuperscript𝑋𝑝𝑓𝐸𝑉𝐸𝑇𝒢X^{p}\leftarrow\min_{X^{p}}\mathcal{L}(f(EV,ET),\mathcal{G})italic_X start_POSTSUPERSCRIPT italic_p end_POSTSUPERSCRIPT ← roman_min start_POSTSUBSCRIPT italic_X start_POSTSUPERSCRIPT italic_p end_POSTSUPERSCRIPT end_POSTSUBSCRIPT caligraphic_L ( italic_f ( italic_E italic_V , italic_E italic_T ) , caligraphic_G ) ;
        \triangleright Prompt optimization
      
Algorithm 1 OCC-CLIP Framework

The implementation of our OCC-CLIP is shown in Algorithm 1. As shown in the algorithm, a forward pass and a backward pass are conducted to obtain gradient information for the images of the non-target class. The gradient information is used to compute adversarial perturbation. The learnable prompt will be updated in another forward and backward passes on the perturbed images. The sensitivity of training hyperparameters is discussed in experiments section.

In the optimization process, both visual and textual encoders of CLIP are frozen. In the verification process, if it is classified into the target class, an image will be determined to be generated by the same generative model as the source model of the target images.

3.3 CLIP-based Few-shot Multi-Class Classification

We also explore the multi-source origin attribution scenarios. For example, to determine if the origin of an image can be attributed to ProGAN [25], Stable Diffusion [46], or Vector Quantized Diffusion [19], we can employ three one-class classifiers corresponding to these models for classification. Given a set of trained K𝐾Kitalic_K one-class classifiers {OCC1,OCC2,,OCCK}𝑂𝐶subscript𝐶1𝑂𝐶subscript𝐶2𝑂𝐶subscript𝐶𝐾\{OCC_{1},OCC_{2},\ldots,OCC_{K}\}{ italic_O italic_C italic_C start_POSTSUBSCRIPT 1 end_POSTSUBSCRIPT , italic_O italic_C italic_C start_POSTSUBSCRIPT 2 end_POSTSUBSCRIPT , … , italic_O italic_C italic_C start_POSTSUBSCRIPT italic_K end_POSTSUBSCRIPT } for K𝐾Kitalic_K classes and a threshold θ𝜃\thetaitalic_θ (e.g. 0.5), for an input sample Xvsuperscript𝑋𝑣X^{v}italic_X start_POSTSUPERSCRIPT italic_v end_POSTSUPERSCRIPT, let si(Xv)subscript𝑠𝑖superscript𝑋𝑣s_{i}(X^{v})italic_s start_POSTSUBSCRIPT italic_i end_POSTSUBSCRIPT ( italic_X start_POSTSUPERSCRIPT italic_v end_POSTSUPERSCRIPT ) denote the score of Xvsuperscript𝑋𝑣X^{v}italic_X start_POSTSUPERSCRIPT italic_v end_POSTSUPERSCRIPT given by i𝑖iitalic_i-th classifier OCCi𝑂𝐶subscript𝐶𝑖OCC_{i}italic_O italic_C italic_C start_POSTSUBSCRIPT italic_i end_POSTSUBSCRIPT. The predicted class C(Xv)𝐶superscript𝑋𝑣C(X^{v})italic_C ( italic_X start_POSTSUPERSCRIPT italic_v end_POSTSUPERSCRIPT ) for the sample Xvsuperscript𝑋𝑣X^{v}italic_X start_POSTSUPERSCRIPT italic_v end_POSTSUPERSCRIPT is determined as follows:

C(Xv)={argmaxi{1,,K}si(Xv)if maxi{1,,N}si(Xv)>θ,othersotherwise.𝐶superscript𝑋𝑣casessubscript𝑖1𝐾subscript𝑠𝑖superscript𝑋𝑣if subscript𝑖1𝑁subscript𝑠𝑖superscript𝑋𝑣𝜃othersotherwiseC(X^{v})=\begin{cases}\arg\max_{i\in\{1,\ldots,K\}}s_{i}(X^{v})&\text{if }\max% _{i\in\{1,\ldots,N\}}s_{i}(X^{v})>\theta,\\ \text{others}&\text{otherwise}.\end{cases}italic_C ( italic_X start_POSTSUPERSCRIPT italic_v end_POSTSUPERSCRIPT ) = { start_ROW start_CELL roman_arg roman_max start_POSTSUBSCRIPT italic_i ∈ { 1 , … , italic_K } end_POSTSUBSCRIPT italic_s start_POSTSUBSCRIPT italic_i end_POSTSUBSCRIPT ( italic_X start_POSTSUPERSCRIPT italic_v end_POSTSUPERSCRIPT ) end_CELL start_CELL if roman_max start_POSTSUBSCRIPT italic_i ∈ { 1 , … , italic_N } end_POSTSUBSCRIPT italic_s start_POSTSUBSCRIPT italic_i end_POSTSUBSCRIPT ( italic_X start_POSTSUPERSCRIPT italic_v end_POSTSUPERSCRIPT ) > italic_θ , end_CELL end_ROW start_ROW start_CELL others end_CELL start_CELL otherwise . end_CELL end_ROW (4)

Given an image, if the maximum score of Xvsuperscript𝑋𝑣X^{v}italic_X start_POSTSUPERSCRIPT italic_v end_POSTSUPERSCRIPT, provided by the i𝑖iitalic_i-th classifier, exceeds the threshold, then Xvsuperscript𝑋𝑣X^{v}italic_X start_POSTSUPERSCRIPT italic_v end_POSTSUPERSCRIPT is classified into the i𝑖iitalic_i-th class. Otherwise, it is considered to belong to a category outside those defined by the K𝐾Kitalic_K classifiers.

4 Experiments

In this section, we first describe experimental settings and present our comparison with baseline methods. We also study the sensitivity of our method to various factors, such as target class corresponding to source models, non-target class datasets, the number of available images, and image preprocessing. Furthermore, we show the effectiveness of our framework in multi-source origin attribution scenarios and real-world commercial generation API.

4.1 Experimental Setting

Dataset. There are total 202,520 images generated by five different generative models, i.e. Stable Diffusion Model [46], Latent Diffusion Model [46], GLIDE [40], Vector Quantized Diffusion [19], and GALIP [60], based on the validation set of Microsoft Common Objects in Context (COCO) 2014 dataset [32]. These models are pre-trained on four different datasets, i.e. LAION-5B [52], COCO [32], LAION-400M [53], and filtered CC12M [5]. In total, five image datasets from different source models are generated, namely SD, VQ-D, LDM, Glide, GALIP. To balance the number of image datasets generated by Diffusion models and the number of image datasets generated by GANs, we utilized pre-existing datasets (namely GauGAN [42], ProGAN [25], and StyleGAN2 [26]) as provided by [63]. These datasets collectively serve as a robust benchmark covering two primary generative techniques: GANs and Diffusion Models.

Model. OCC-CLIP utilizes 16 context vectors. This model is built upon the open-source CLIP framework. The image encoder uses the ViT-B/16 architecture. Except for the prompt learner, all pre-trained parameters are fixed. Initial context vectors are stochastically sampled from a Normal distribution characterized by a mean of 0 and a standard deviation of 0.02.

Training Setting. All the generated images are resized to 224×224224224224\times 224224 × 224 and then normalized according to the pre-trained datasets of each model. Stochastic Gradient Descent is utilized as the optimization strategy with a learning rate of 0.0001, modulated through cosine annealing. The cross-entropy loss is utilized as the loss function. By default, the training process is capped at a maximum of 200 epochs for 50-shot scenarios. The test dataset consists of 1,000 images that are randomly selected from the test sets to ensure a reliable evaluation. To counteract the onset of explosive gradients in the nascent phases of training, the learning rate is steadfastly maintained at 1×1051superscript1051\times 10^{-5}1 × 10 start_POSTSUPERSCRIPT - 5 end_POSTSUPERSCRIPT during the first epoch. The eight generative models (i.e. SD, VQ-D, LDM, Glide, GALIP, ProGAN, StyleGAN2, GauGAN) are iteratively treated as the target class, while four open-source datasets (i.e. COCO [32], ImageNet [9], Flickr [66], and CC12M [5]) are iteratively treated as the non-target class. However, in the default settings, only half of the non-target images are augmented by ADA, SD is designated as the target image set, and COCO is chosen as the non-target image set.

Evaluation. Each model is evaluated by the Area Under the Receiver Operating Characteristic Curve (AUC). The Receiver Operating Characteristic Curve (ROC) is a graphical representation that plots the True Positive Rate (TPR) against the False Positive Rate (FPR) at various threshold levels.

The AUC represents the probability that a classifier will rank a randomly chosen positive instance higher than a randomly chosen negative one. To reduce randomness, each model is trained 10 times with different training sets each time. Then, the mean AUC and the corresponding standard deviation are reported over the test set. A higher AUC score signifies better performance. For each table, the corresponding standard deviations are shown in the supplementary. More experimental details, such as different testing tasks and accuracy scores, can be found in the supplementary.

4.2 Comparison with Baselines

Baselines. Since there are currently no methods perfectly suited to our setting, we conduct a comprehensive evaluation of OCC-CLIP by assessing 12 benchmark methods from various usage areas (see Table 1). The supplementary can find a comparison with other baselines [64, 13].

Table 1: Compare the performance of OCC-CLIP in orgin attribution against 12 basic methods. During the training phase, the target class is sourced from SD, and the non-target class is from COCO. In the test phase, the target class remains sourced from SD, but the non-target class is sourced from another generative image dataset. The optimal outcomes for individual datasets are emphasized using bold formatting.
Methods VQ-D LDM Glide GALIP ProGAN StyleGAN2 GauGAN Overall
VGG16 [55] 0.64580.64580.64580.6458 0.54380.54380.54380.5438 0.56520.56520.56520.5652 0.70170.70170.70170.7017 0.66090.66090.66090.6609 0.61700.61700.61700.6170 0.70960.70960.70960.7096 0.63490.63490.63490.6349
ResNet50 [20] 0.66930.66930.66930.6693 0.54850.54850.54850.5485 0.61030.61030.61030.6103 0.73070.73070.73070.7307 0.66460.66460.66460.6646 0.64580.64580.64580.6458 0.74750.74750.74750.7475 0.65950.65950.65950.6595
Inception-v3 [58] 0.63780.63780.63780.6378 0.53490.53490.53490.5349 0.52520.52520.52520.5252 0.67590.67590.67590.6759 0.64530.64530.64530.6453 0.59470.59470.59470.5947 0.69820.69820.69820.6982 0.61600.61600.61600.6160
DenseNet-121 [22] 0.72640.72640.72640.7264 0.53370.53370.53370.5337 0.57300.57300.57300.5730 0.74780.74780.74780.7478 0.72040.72040.72040.7204 0.66450.66450.66450.6645 0.80910.80910.80910.8091 0.68210.68210.68210.6821
ViT-B-16 [11] 0.75020.75020.75020.7502 0.53870.53870.53870.5387 0.60690.60690.60690.6069 0.78370.78370.78370.7837 0.60620.60620.60620.6062 0.65930.65930.65930.6593 0.72590.72590.72590.7259 0.66730.66730.66730.6673
DeiT-B-16 [61] 0.68250.68250.68250.6825 0.53660.53660.53660.5366 0.56980.56980.56980.5698 0.65920.65920.65920.6592 0.57210.57210.57210.5721 0.58980.58980.58980.5898 0.65070.65070.65070.6507 0.60870.60870.60870.6087
CaiT-S-24 [62] 0.65220.65220.65220.6522 0.53010.53010.53010.5301 0.55500.55500.55500.5550 0.64660.64660.64660.6466 0.56970.56970.56970.5697 0.58040.58040.58040.5804 0.66450.66450.66450.6645 0.59980.59980.59980.5998
Swin-B-4 [36] 0.86340.86340.86340.8634 0.71800.71800.71800.7180 0.74730.74730.74730.7473 0.84780.84780.84780.8478 0.58790.58790.58790.5879 0.70540.70540.70540.7054 0.78220.78220.78220.7822 0.75030.75030.75030.7503
Image-Patch [39] 0.66380.66380.66380.6638 0.52690.52690.52690.5269 0.55340.55340.55340.5534 0.68470.68470.68470.6847 0.66240.66240.66240.6624 0.67060.67060.67060.6706 0.76740.76740.76740.7674 0.64700.64700.64700.6470
Feature-Patch [39] 0.69990.69990.69990.6999 0.61160.61160.61160.6116 0.73850.73850.73850.7385 0.62850.62850.62850.6285 0.71360.71360.71360.7136 0.85460.85460.85460.8546 0.81520.81520.81520.8152 0.72310.72310.72310.7231
CLIP [44] 0.72720.72720.72720.7272 0.72430.72430.72430.7243 0.60780.60780.60780.6078 0.73040.73040.73040.7304 0.52290.52290.52290.5229 0.53930.53930.53930.5393 0.64630.64630.64630.6463 0.64260.64260.64260.6426
CoOp [71] 0.95030.95030.95030.9503 0.83730.83730.83730.8373 0.92660.92660.92660.9266 0.96600.96600.96600.9660 0.88610.88610.88610.8861 0.95330.95330.95330.9533 0.96430.96430.96430.9643 0.92630.92630.92630.9263
OCC-CLIP 0.97030.9703\mathbf{0.9703}bold_0.9703 0.88010.8801\mathbf{0.8801}bold_0.8801 0.95190.9519\mathbf{0.9519}bold_0.9519 0.97980.9798\mathbf{0.9798}bold_0.9798 0.94520.9452\mathbf{0.9452}bold_0.9452 0.96510.9651\mathbf{0.9651}bold_0.9651 0.99100.9910\mathbf{0.9910}bold_0.9910 0.95480.9548\mathbf{0.9548}bold_0.9548

Traditional Binary Classification Models: Four of these methods are notable CNN architectures that are often applied to Computer Vision problems, especially for image classification tasks, including ResNet [20], Inception [58], DenseNet [22], and VGG [55]. The other four models are adaptations of the transformer paradigm, including ViT [11], Deit [61], Cait [62], and Swin [36]. For both CNN and Transformer models, all layers are retained in a frozen state except for the last classification layer.

Patch-Driven Methods [39]: Two of the methods, Feature-Patch and Image-Patch, are patch-based techniques that are primarily used for deepfake and rely on the ResNet-50 architecture for feature extraction. For the Image-Patch model, each image is divided into 2x2 patches, with each patch serving as a separate input to the ResNet-50 architecture. In the case of the Feature-Patch model, which shares the same backbone, the last five layers of the standard ResNet-50 architecture are discarded and the remaining structures are employed to extract image features. Subsequently, these features are segmented into 4x4 patches, with each patch being passed through the concluding linear classification layer.

Vision-Language Models: Considering the power of the vision-language model in tackling downstream classification tasks, zero-shot CLIP [44] and CoOp[71] are also evaluated. The zero-shot CLIP [44] approach utilizes custom-crafted prompts (hard prompt) [16], adopting the format "a photo of a [CLASS]" to tackle the tasks of origin attribution. Conversely, CoOp employs prompt tuning (soft prompt) and distinguishes itself by using {v1,v2,,v16,[CLASS]}subscript𝑣1subscript𝑣2subscript𝑣16[CLASS]\{v_{1},v_{2},\ldots,v_{16},\text{[CLASS]}\}{ italic_v start_POSTSUBSCRIPT 1 end_POSTSUBSCRIPT , italic_v start_POSTSUBSCRIPT 2 end_POSTSUBSCRIPT , … , italic_v start_POSTSUBSCRIPT 16 end_POSTSUBSCRIPT , [CLASS] } where visubscript𝑣𝑖v_{i}italic_v start_POSTSUBSCRIPT italic_i end_POSTSUBSCRIPT is an adjustable context vector and [CLASS] is the class token which is deliberately located at the end of the sequence.

Table 2: Evaluation sensitivity of OCC-CLIP to Source Models. The leftmost column represents target datasets. In the training phase, the non-target images are from COCO. In the testing phase, the non-target images are from a different generative image dataset shown in the first row. The optimal outcomes for individual datasets are emphasized using bold formatting.
Target \downarrow Method SD VQ-D LDM Glide GALIP ProGAN StyleGAN2 GauGAN Overall
SD CoOp - 0.95030.95030.95030.9503 0.83730.83730.83730.8373 0.92660.92660.92660.9266 0.96600.96600.96600.9660 0.88610.88610.88610.8861 0.95330.95330.95330.9533 0.96430.96430.96430.9643 0.92630.92630.92630.9263
OCC-CLIP - 0.97030.9703\mathbf{0.9703}bold_0.9703 0.88010.8801\mathbf{0.8801}bold_0.8801 0.95190.9519\mathbf{0.9519}bold_0.9519 0.97980.9798\mathbf{0.9798}bold_0.9798 0.94520.9452\mathbf{0.9452}bold_0.9452 0.96510.9651\mathbf{0.9651}bold_0.9651 0.99100.9910\mathbf{0.9910}bold_0.9910 0.95480.9548\mathbf{0.9548}bold_0.9548
VQ-D CoOp 0.99880.99880.99880.9988 - 0.73370.7337\mathbf{0.7337}bold_0.7337 0.74350.7435\mathbf{0.7435}bold_0.7435 0.75580.7558\mathbf{0.7558}bold_0.7558 0.92900.92900.92900.9290 0.99240.99240.99240.9924 0.93520.93520.93520.9352 0.86980.86980.86980.8698
OCC-CLIP 0.99920.9992\mathbf{0.9992}bold_0.9992 - 0.69240.69240.69240.6924 0.72640.72640.72640.7264 0.73270.73270.73270.7327 0.99310.9931\mathbf{0.9931}bold_0.9931 0.99360.9936\mathbf{0.9936}bold_0.9936 0.99360.9936\mathbf{0.9936}bold_0.9936 0.87580.8758\mathbf{0.8758}bold_0.8758
LDM CoOp 0.99250.99250.99250.9925 0.67930.67930.67930.6793 - 0.64680.64680.64680.6468 0.62630.62630.62630.6263 0.95650.95650.95650.9565 0.98960.98960.98960.9896 0.97580.97580.97580.9758 0.83810.83810.83810.8381
OCC-CLIP 0.99570.9957\mathbf{0.9957}bold_0.9957 0.75070.7507\mathbf{0.7507}bold_0.7507 - 0.68470.6847\mathbf{0.6847}bold_0.6847 0.65300.6530\mathbf{0.6530}bold_0.6530 0.99560.9956\mathbf{0.9956}bold_0.9956 0.99400.9940\mathbf{0.9940}bold_0.9940 0.99920.9992\mathbf{0.9992}bold_0.9992 0.86760.8676\mathbf{0.8676}bold_0.8676
Glide CoOp 0.99850.99850.99850.9985 0.85730.85730.85730.8573 0.83140.83140.83140.8314 - 0.66870.66870.66870.6687 0.96290.96290.96290.9629 0.99160.99160.99160.9916 0.98140.98140.98140.9814 0.89880.89880.89880.8988
OCC-CLIP 0.99980.9998\mathbf{0.9998}bold_0.9998 0.89580.8958\mathbf{0.8958}bold_0.8958 0.85850.8585\mathbf{0.8585}bold_0.8585 - 0.68340.6834\mathbf{0.6834}bold_0.6834 0.99740.9974\mathbf{0.9974}bold_0.9974 0.99490.9949\mathbf{0.9949}bold_0.9949 0.99970.9997\mathbf{0.9997}bold_0.9997 0.91850.9185\mathbf{0.9185}bold_0.9185
GALIP CoOp 0.99990.99990.99990.9999 0.90360.90360.90360.9036 0.84410.84410.84410.8441 0.78020.7802\mathbf{0.7802}bold_0.7802 - 0.99820.99820.99820.9982 0.99920.99920.99920.9992 0.99960.99960.99960.9996 0.93210.93210.93210.9321
OCC-CLIP 0.99990.9999\mathbf{0.9999}bold_0.9999 0.93450.9345\mathbf{0.9345}bold_0.9345 0.86260.8626\mathbf{0.8626}bold_0.8626 0.77790.77790.77790.7779 - 0.99990.9999\mathbf{0.9999}bold_0.9999 0.99930.9993\mathbf{0.9993}bold_0.9993 1.00001.0000\mathbf{1.0000}bold_1.0000 0.93920.9392\mathbf{0.9392}bold_0.9392
ProGAN CoOp 0.99720.9972\mathbf{0.9972}bold_0.9972 0.94750.94750.94750.9475 0.95440.95440.95440.9544 0.94530.9453\mathbf{0.9453}bold_0.9453 0.98180.98180.98180.9818 - 0.92780.9278\mathbf{0.9278}bold_0.9278 0.79930.79930.79930.7993 0.93620.93620.93620.9362
OCC-CLIP 0.99610.99610.99610.9961 0.94770.9477\mathbf{0.9477}bold_0.9477 0.95850.9585\mathbf{0.9585}bold_0.9585 0.93200.93200.93200.9320 0.98850.9885\mathbf{0.9885}bold_0.9885 - 0.84710.84710.84710.8471 0.88850.8885\mathbf{0.8885}bold_0.8885 0.93690.9369\mathbf{0.9369}bold_0.9369
StyleGAN2 CoOp 0.99920.99920.99920.9992 0.98560.98560.98560.9856 0.98500.98500.98500.9850 0.95840.95840.95840.9584 0.98490.98490.98490.9849 0.86870.86870.86870.8687 - 0.95430.95430.95430.9543 0.96230.96230.96230.9623
OCC-CLIP 0.99960.9996\mathbf{0.9996}bold_0.9996 0.99370.9937\mathbf{0.9937}bold_0.9937 0.98510.9851\mathbf{0.9851}bold_0.9851 0.96520.9652\mathbf{0.9652}bold_0.9652 0.99260.9926\mathbf{0.9926}bold_0.9926 0.96490.9649\mathbf{0.9649}bold_0.9649 - 0.99460.9946\mathbf{0.9946}bold_0.9946 0.98510.9851\mathbf{0.9851}bold_0.9851
GauGAN CoOp 0.99910.9991\mathbf{0.9991}bold_0.9991 0.93880.9388\mathbf{0.9388}bold_0.9388 0.98620.9862\mathbf{0.9862}bold_0.9862 0.97570.9757\mathbf{0.9757}bold_0.9757 0.99010.99010.99010.9901 0.68120.68120.68120.6812 0.96760.9676\mathbf{0.9676}bold_0.9676 - 0.93680.93680.93680.9368
OCC-CLIP 0.99820.99820.99820.9982 0.91320.91320.91320.9132 0.97450.97450.97450.9745 0.95930.95930.95930.9593 0.99580.9958\mathbf{0.9958}bold_0.9958 0.77520.7752\mathbf{0.7752}bold_0.7752 0.94250.94250.94250.9425 - 0.93700.9370\mathbf{0.9370}bold_0.9370

Results and Analysis. Table 1 provides a comparative performance analysis of OCC-CLIP and 12 benchmark models. During the training phase, the target class is sourced from SD, and the non-target class is from COCO. In the test phase, the target class remains sourced from SD, but the non-target class is sourced from another generative image dataset (VQ-D, LDM, Glide, GALIP, ProGAN, StyleGAN2, and GauGAN). The goal of this section is to assess each model’s ability to accurately determine whether the origin of a given image can be attributed to Stable Diffusion.

Among the CNN-based and Transformer-based baselines, Swin outshines its counterparts. However, the overall disparity in performance between CNN-based and Transformer-based models is not obvious. The following two methods, Image-Patch and Feature-Patch are both based on ResNet50. Image-Patch performs worse than ResNet50 while Feature-Patch has somewhat but limited improvements compared with ResNet50. This suggests that current methods used to do deepfake detection perform poorly in this few-shot origin attribution scenarios. In addition to the aforementioned classical methods, OCC-CLIP surpasses widely-spread vision-language models such as zero-shot CLIP and CoOp. In detail, OCC-CLIP outperforms zero-shot CLIP by an average of around 31% and CoOp by approximately 2.9%. This progression emphasizes the value of ADA. In a comprehensive assessment, OCC-CLIP emerges as a leading standard, underscoring its exceptional ability in origin attribution. However, it is harder to distinguish images generated by very similar algorithms trained on similar datasets, such as DeepFloyd, which is based on Stable Diffusion and also trained on the COCO dataset. In this case, our model’s performance does decrease (dropping to 0.7650±4.80e-2plus-or-minus0.76504.80𝑒-20.7650\scriptscriptstyle\pm\scriptstyle 4.80e\text{-}20.7650 ± 4.80 italic_e - 2). Nevertheless, our method still outperforms the best baseline (CoOp: 0.7301±7.91e-2plus-or-minus0.73017.91𝑒-20.7301\scriptscriptstyle\pm\scriptstyle 7.91e\text{-}20.7301 ± 7.91 italic_e - 2).

4.3 Ablation Study

Sensitivity to Source Models. Table 2 shows the performance of CoOp and OCC-CLIP in origin attribution with eight different source models. During training, the target dataset is from the dataset shown in the leftmost column, and the non-target dataset is COCO. During testing, the target remains the same, but the non-target dataset is replaced with one of the other generated datasets shown in the first row. For example, the source model for the second row in the table is Stable Diffusion [46].

OCC-CLIP demonstrates superior performance in most cases and outperforms the baseline on average in the results from testing with seven other datasets. Overall, our proposed model has exhibited superior performance and generalization capabilities in determining if an image is from the same source model as a set of target images, compared to the baseline.

Table 3: Evaluation of OCC-CLIP on Different Non-target Image Datasets. During training phase, the non-target class is chosen from one of the four datasets (COCO, CC12M, Flickr, and ImageNet) or from combined datasets. The target dataset is from SD. The performance is averaged across seven different testing tasks.
Methods COCO CC12M Flickr ImageNet Combined
CoOp 0.92630.92630.92630.9263 0.86890.86890.86890.8689 0.87880.87880.87880.8788 0.93770.93770.93770.9377 0.93200.93200.93200.9320
OCC-CLIP 0.95480.9548\mathbf{0.9548}bold_0.9548 0.93200.9320\mathbf{0.9320}bold_0.9320 0.93550.9355\mathbf{0.9355}bold_0.9355 0.97100.9710\mathbf{0.9710}bold_0.9710 0.96510.9651\mathbf{0.9651}bold_0.9651

Sensitivity to Selection of Non-target Class. As shown in Table 3, we select non-target images from combined datasets or from one of the four open-domain image datasets: COCO, ImageNet, Flickr, or CC12M. The target images are from SD. The average AUC score over 7 different testing tasks is computed. It can be noted that although the choice of the source of non-target images can somewhat affect the performance of origin attribution, our framework consistently outperforms the baseline.

Table 4: Evaluation of OCC-CLIP with Various ADA Approaches. ‘Non-Target’ applies ADA to the non-target images; ‘T’ applies it to the target images; ‘Both’ applies it to both the target and non-target images; and ‘T-NT’ treats part of the target images as non-target ones post-ADA. The results are averaged across seven testing tasks.
Methods None Non-Target Both Target T-NT
OCC-CLIP 0.92630.92630.92630.9263 0.95480.9548\mathbf{0.9548}bold_0.9548 0.90800.90800.90800.9080 0.82360.82360.82360.8236 0.95140.95140.95140.9514

Sensitivity to ADA Settings. We employ four methods for applying ADA: 1) ‘Non-Target’: on half of the non-target images; 2) ‘Target’: on half of the target images; 3) ‘Both’: on half of both the non-target images and target images; 4) ‘T-NT’: on half of the target images which are then treated as non-target ones. The non-target images are selected from the COCO dataset, while the target images are from SD.

As shown in Table 4, it is evident that applying ADA on non-target images yields the best performance. This outcome is reasonable, as gradient ascent on the non-target image set enlarges the learned space of this set and further approximates the boundary to the target image set. Applying ADA on ‘T-NT’ is the next most effective method, performing only slightly worse than ‘Non-Target’. However, the boundary learned by ‘T-NT’ may be too tight for effective origin attribution tasks. Applying ADA on ‘Both’ is less effective than doing nothing, as ‘Both’ also enlarges the learned distribution of the target image set. Solely applying ADA on the target set performs significantly worse than doing nothing. This is because this approach not only enlarges the learned distribution space of the target images but also shrinks the learned distribution space of the non-target image set, leading to a higher likelihood of misclassifying many images as target images.

Table 5: Evaluation of OCC-CLIP Relative to the Proportion of Augmented Non-Target Images. Five proportions are investigated: 0%percent00\%0 %, 25%percent2525\%25 %, 50%percent5050\%50 %, 75%percent7575\%75 %, and 100%percent100100\%100 %. The results are averaged across seven testing tasks.
Methods 0% 25% 50% 75% 100%
OCC-CLIP 0.9263 0.94050.94050.94050.9405 0.95480.95480.95480.9548 0.95580.9558\mathbf{0.9558}bold_0.9558 0.91720.91720.91720.9172

Sensitivity to the Proportion of Augmented Non-target Images. We further investigate the influence of the proportion of augmented non-target images on the performance of OCC-CLIP. As indicated in Table 5, the performance of origin attribution is optimal when 50% to 75% of non-target images are augmented. However, when all data are augmented, the performance deteriorates, even falling below that with 0% non-target images augmented. This may be because augmenting all data could lead to a loss of the original distribution space of the non-target image set.

Refer to caption
Figure 3: Evaluation of OCC-CLIP on Different Numbers of Shots. This figure shows the average origin attribution performance of CoOp and OCC-CLIP on 7 different testing tasks with a variable number of shots: 10, 20, 50, 100, and 200. The target dataset is from SD. The non-target datasets are from COCO, CC12M, Flickr, or ImageNet.

Sensitivity to the Number of Shots. We then analyze how the performance of OCC-CLIP relates to the number of shots. Our investigation covers the effects of using 10, 20, 50, 100, and 200 shots. In these experiments, SD is used for the target images, while one of COCO, ImageNet, Flickr, and CC12M is employed as the non-target dataset. Other generated image datasets are used for testing. As shown in Figure 3, OCC-CLIP consistently outperforms CoOp in all scenarios, particularly when the number of shots is small. Additionally, the incremental improvements in AUC tend to diminish as more shots are added, eventually plateauing at an upper boundary when the number of shots reaches 200.

Table 6: Evaluation of OCC-CLIP under Image Processing. Six image processing methods are executed: Gaussian Blur, Gaussian Noise, Grayscale, Rotation, Flip, and a mixture of all these data augmentation methods. The results are averaged across seven testing tasks.
Method None Gaussian Blur Gaussian Noise Grayscale Rotation Flip Mixture
CoOp 0.92630.92630.92630.9263 0.85390.85390.85390.8539 0.88590.88590.88590.8859 0.80170.80170.80170.8017 0.90400.90400.90400.9040 0.92410.92410.92410.9241 0.74570.74570.74570.7457
OCC-CLIP 0.95480.9548\mathbf{0.9548}bold_0.9548 0.90020.9002\mathbf{0.9002}bold_0.9002 0.90890.9089\mathbf{0.9089}bold_0.9089 0.84050.8405\mathbf{0.8405}bold_0.8405 0.93370.9337\mathbf{0.9337}bold_0.9337 0.94790.9479\mathbf{0.9479}bold_0.9479 0.75380.7538\mathbf{0.7538}bold_0.7538

Sensitivity to Image Processing in Verification Stage. Table 6 presents a comparative analysis of the performance between OCC-CLIP and baseline methods in the face of potential image processing: Gaussian Blur, Gaussian Noise, Grayscale, Rotation, Flip, or a mixture of those attacks. The data indicate that OCC-CLIP exhibits superior robustness compared to the baseline across a range of potential processing of input images. This enhanced resilience of OCC-CLIP underscores its effectiveness in safeguarding against various forms of image manipulation, highlighting its utility in origin attribution.

Sensitivity to Choice of Prompts. Since we focus on the one-class classification question, the classes in our setting can be labeled as any contrasting pairs, such as negative vs. positive. Therefore, we explore the effect of the choice of prompts on the performance of OCC-CLIP. As shown in the supplementary material, the choice of prompts can have some different effects. However, regardless of which pair of prompts is chosen, OCC-CLIP always outperforms the baseline.

Table 7: ADA vs. other data augmentation methods. Different ways of data augmentation are used during training. The results are averaged across seven testing tasks.
Methods Gaussian Blur Gaussian Noise Grayscale Rotation Flip Mixture None ADA
OCC-CLIP 0.86390.86390.86390.8639 0.83400.83400.83400.8340 0.83080.83080.83080.8308 0.84650.84650.84650.8465 0.84220.84220.84220.8422 0.79910.79910.79910.7991 0.9263 0.9548

4.4 Comparison to Standard Data Augmentation

Data augmentation methods have been extensively developed. In real-fake detection tasks, Wang [63] and CR [4] utilized a combination of various data augmentation methods to improve model performance. To conduct a more comprehensive evaluation of ADA, we compare its performance with other common data augmentation methods: Gaussian Blur, Gaussian Noise, Grayscale, Rotation, Flip, and a mixture of all these. According to Table 7, all traditional data augmentation methods perform poorly, and in some cases, even degrade the model’s performance. Only ADA shows some improvements. Consequently, we can infer that normal data augmentation methods are not suitable for few-shot one-class classification scenarios.

Refer to caption
(a) Without ADA
Refer to caption
(b) With ADA
Figure 4: Visualize the 2-dimensional mapping of image features with t-SNE [38]. The target images are from SD, and the non-target images are from COCO. Figure (a) shows the distribution of non-target images and target images without using ADA. Figure (b) shows the distribution of augmented non-target images and target images after using the ADA technique.

4.5 Understanding Adversarial Data Augmentation

We utilize the embeddings from CLIP’s image encoder for visualization. According to Figure 4(a), it is evident that there is no clear boundary between the target image set and the non-target image set, i.e., images from SD and images from COCO. However, after applying ADA, as illustrated in Figure 4(b), a clearer boundary emerges between the augmented non-target image set and the target image set, demonstrating the effectiveness of ADA. During training, unchanged non-target images and augmented non-target images are mixed. This approach not only preserves the properties of the original non-target images but also ensures that the augmented non-target images approximate the boundary of the distribution of the target images.

Table 8: Evaluation of OCC-CLIP with commercial generation API. The target images are generated by DALL·E-3. The non-target images are from COCO. The results are averaged across eight testing tasks.
     Methods      10      20      30      50
     CoOp      0.9216      0.9687      0.9563      0.9788
     OCC-CLIP      0.97540.9754\mathbf{0.9754}bold_0.9754      0.98480.9848\mathbf{0.9848}bold_0.9848      0.99360.9936\mathbf{0.9936}bold_0.9936      0.99590.9959\mathbf{0.9959}bold_0.9959

4.6 Source Model Attribution with Commercial Generation API

To investigate the effectiveness of OCC-CLIP in the real world, we utilize the latest commercial digital image-generating model – DALL·E-3 [2] – to generate images. As shown in the supplementary material, 103 prompts are randomly selected from the annotations of the validation set of COCO[32], resulting in a total of 200 images generated. The default setting of DALL·E-3 is to generate 2 images simultaneously. However, due to OpenAI’s content policy, some prompts can only generate one image. In this scenario, the targets are images generated by DALL·E-3, while the non-targets are images from other datasets. We compare the performance of detection across different numbers of shots: 10, 20, 30, 50. According to Table 8, our method consistently outperforms the baseline and performs well even with as few as 10 shots.

4.7 Model Attribution with Multiple Source Models

In addition to verifying single models, we also investigate multi-source origin attribution conditions. We explore the process of verifying multiple sources using the eight trained one-class classifiers. Since this involves multi-source origin attribution, the evaluation metric used in this section is accuracy instead of AUC. We evaluate the model under the following conditions: 2 classes (SD, VQ-D), 4 classes (SD, VQ-D, LDM, Glide), and 6 classes (SD, VQ-D, LDM, Glide, GALIP, ProGan). As shown in Table 31, the accuracy decreases with an increasing number of source models. In every multi-class classification scenario mentioned above, one-class classifiers trained with OCC-CLIP consistently outperform those trained with CoOp.

Furthermore, our methods can be adapted to directly train a multi-class classifier. As demonstrated in the table included in the supplementary material, the multi-class classifier trained using the OCC-CLIP approach is still shown to be more effective compared to the one trained using the CoOp approach.

Table 9: Employing an ensemble of one-class classifiers for multi-class classification tasks. The following scenarios are considered: 2 classes, 4 classes, 6 classes, and 8 classes.
Num of Class Method LDM Glide GALIP ProGAN StyleGAN2 GauGAN Overall
2 classes CoOp 0.63660.63660.63660.6366 0.64480.64480.64480.6448 0.63780.63780.63780.6378 0.69280.69280.69280.6928 0.87060.87060.87060.8706 0.72590.72590.72590.7259 0.70140.70140.70140.7014
OCC-CLIP 0.64490.6449\mathbf{0.6449}bold_0.6449 0.64990.6499\mathbf{0.6499}bold_0.6499 0.64570.6457\mathbf{0.6457}bold_0.6457 0.87420.8742\mathbf{0.8742}bold_0.8742 0.89380.8938\mathbf{0.8938}bold_0.8938 0.92550.9255\mathbf{0.9255}bold_0.9255 0.77230.7723\mathbf{0.7723}bold_0.7723
4 classes CoOp - - 0.58630.58630.58630.5863 0.61240.61240.61240.6124 0.70040.70040.70040.7004 0.63760.63760.63760.6376 0.63420.63420.63420.6342
OCC-CLIP - - 0.61300.6130\mathbf{0.6130}bold_0.6130 0.74610.7461\mathbf{0.7461}bold_0.7461 0.73190.7319\mathbf{0.7319}bold_0.7319 0.79080.7908\mathbf{0.7908}bold_0.7908 0.72040.7204\mathbf{0.7204}bold_0.7204
6 classes CoOp - - - - 0.64590.64590.64590.6459 0.60920.60920.60920.6092 0.62760.62760.62760.6276
OCC-CLIP - - - - 0.65870.6587\mathbf{0.6587}bold_0.6587 0.67270.6727\mathbf{0.6727}bold_0.6727 0.66570.6657\mathbf{0.6657}bold_0.6657

5 Conclusions

In this work, we study origin attribution in a practical setting where only a few images generated by a source model are available and the source model cannot be accessed. The introduced problem is first formulated as a few-shot one-classification task. A simple yet effective solution CLIP-based framework is proposed to solve the task. Our experiments on both open-source popular generative models and commercial generation API shows the effectiveness of our framework. Our OCC-CLIP framework can also be applied to solve the few-shot one-classification task in other domains, which we leave in future work. Another future work is to evaluate the natural and adversarial robustness of our framework [7, 8, 18, 17] and build adversarially robust variants [65, 23].

Acknowledgement: This work is supported by the UKRI grant: Turing AI Fellowship EP/W002981/1, EPSRC/MURI grant: EP/N019474/1. We thank the Royal Academy of Engineering

References

  • [1] Arjovsky, M., Chintala, S., Bottou, L.: Wasserstein generative adversarial networks. In: International conference on machine learning. pp. 214–223. PMLR (2017)
  • [2] Betker, J., Goh, G., Jing, L., Brooks, T., Wang, J., Li, L., Ouyang, L., Zhuang, J., Lee, J., Guo, Y., et al.: Improving image generation with better captions. Computer Science. https://cdn. openai. com/papers/dall-e-3. pdf 2(3),  8 (2023)
  • [3] BIDEN, J.R.: Executive order on the safe, secure, and trustworthy development and use of artificial intelligence (Oct 2023), https://www.whitehouse.gov/briefing-room/presidential-actions/2023/10/30/executive-order-on-the-safe-secure-and-trustworthy-development-and-use-of-artificial-intelligence/
  • [4] Chandrasegaran, K., Tran, N.T., Binder, A., Cheung, N.M.: Discovering transferable forensic features for cnn-generated images detection. In: European Conference on Computer Vision. pp. 671–689. Springer (2022)
  • [5] Changpinyo, S., Sharma, P., Ding, N., Soricut, R.: Conceptual 12m: Pushing web-scale image-text pre-training to recognize long-tail visual concepts. In: Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition. pp. 3558–3568 (2021)
  • [6] Chen, J., Sathe, S., Aggarwal, C., Turaga, D.: Outlier detection with autoencoder ensembles. In: Proceedings of the 2017 SIAM international conference on data mining. pp. 90–98. SIAM (2017)
  • [7] Chen, S., Gu, J., Han, Z., Ma, Y., Torr, P., Tresp, V.: Benchmarking robustness of adaptation methods on pre-trained vision-language models. Advances in Neural Information Processing Systems 36 (2024)
  • [8] Cheng, H., Xiao, E., Gu, J., Yang, L., Duan, J., Zhang, J., Cao, J., Xu, K., Xu, R.: Unveiling typographic deceptions: Insights of the typographic vulnerability in large vision-language model. arXiv. org
  • [9] Deng, J., Dong, W., Socher, R., Li, L.J., Li, K., Fei-Fei, L.: Imagenet: A large-scale hierarchical image database. In: 2009 IEEE conference on computer vision and pattern recognition. pp. 248–255. Ieee (2009)
  • [10] Ding, Y., Thakur, N., Li, B.: Does a gan leave distinct model-specific fingerprints. In: Proceedings of the BMVC (2021)
  • [11] Dosovitskiy, A., Beyer, L., Kolesnikov, A., Weissenborn, D., Zhai, X., Unterthiner, T., Dehghani, M., Minderer, M., Heigold, G., Gelly, S., et al.: An image is worth 16x16 words: Transformers for image recognition at scale. arXiv preprint arXiv:2010.11929 (2020)
  • [12] Frikha, A., Krompaß, D., Köpken, H.G., Tresp, V.: Few-shot one-class classification via meta-learning. In: Proceedings of the AAAI Conference on Artificial Intelligence. vol. 35, pp. 7448–7456 (2021)
  • [13] Girish, S., Suri, S., Rambhatla, S.S., Shrivastava, A.: Towards discovery and attribution of open-world gan generated images. In: Proceedings of the IEEE/CVF International Conference on Computer Vision. pp. 14094–14103 (2021)
  • [14] Goodfellow, I., Pouget-Abadie, J., Mirza, M., Xu, B., Warde-Farley, D., Ozair, S., Courville, A., Bengio, Y.: Generative adversarial networks. Communications of the ACM 63(11), 139–144 (2020)
  • [15] Gu, J.: Responsible generative ai: What to generate and what not. arXiv preprint arXiv:2404.05783 (2024)
  • [16] Gu, J., Han, Z., Chen, S., Beirami, A., He, B., Zhang, G., Liao, R., Qin, Y., Tresp, V., Torr, P.: A systematic survey of prompt engineering on vision-language foundation models. arXiv preprint arXiv:2307.12980 (2023)
  • [17] Gu, J., Tresp, V.: Improving the robustness of capsule networks to image affine transformations. In: Proceedings of the IEEE/CVF conference on computer vision and pattern recognition. pp. 7285–7293 (2020)
  • [18] Gu, J., Tresp, V., Qin, Y.: Are vision transformers robust to patch perturbations? In: European Conference on Computer Vision. pp. 404–421. Springer (2022)
  • [19] Gu, S., Chen, D., Bao, J., Wen, F., Zhang, B., Chen, D., Yuan, L., Guo, B.: Vector quantized diffusion model for text-to-image synthesis. In: Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition. pp. 10696–10706 (2022)
  • [20] He, K., Zhang, X., Ren, S., Sun, J.: Deep residual learning for image recognition. In: Proceedings of the IEEE conference on computer vision and pattern recognition. pp. 770–778 (2016)
  • [21] Ho, J., Jain, A., Abbeel, P.: Denoising diffusion probabilistic models. Advances in neural information processing systems 33, 6840–6851 (2020)
  • [22] Huang, G., Liu, Z., Van Der Maaten, L., Weinberger, K.Q.: Densely connected convolutional networks. In: Proceedings of the IEEE conference on computer vision and pattern recognition. pp. 4700–4708 (2017)
  • [23] Jia, X., Chen, Y., Mao, X., Duan, R., Gu, J., Zhang, R., Xue, H., Liu, Y., Cao, X.: Revisiting and exploring efficient fast adversarial training via law: Lipschitz regularization and auto weight averaging. IEEE Transactions on Information Forensics and Security (2024)
  • [24] Kang, M., Zhu, J.Y., Zhang, R., Park, J., Shechtman, E., Paris, S., Park, T.: Scaling up gans for text-to-image synthesis. In: Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition. pp. 10124–10134 (2023)
  • [25] Karras, T., Aila, T., Laine, S., Lehtinen, J.: Progressive growing of gans for improved quality, stability, and variation. arXiv preprint arXiv:1710.10196 (2017)
  • [26] Karras, T., Laine, S., Aittala, M., Hellsten, J., Lehtinen, J., Aila, T.: Analyzing and improving the image quality of stylegan. In: Proceedings of the IEEE/CVF conference on computer vision and pattern recognition. pp. 8110–8119 (2020)
  • [27] Kim, C., Ren, Y., Yang, Y.: Decentralized attribution of generative models. arXiv preprint arXiv:2010.13974 (2020)
  • [28] Kingma, D.P., Welling, M., et al.: An introduction to variational autoencoders. Foundations and Trends® in Machine Learning 12(4), 307–392 (2019)
  • [29] Laszkiewicz, M., Ricker, J., Lederer, J., Fischer, A.: Single-model attribution via final-layer inversion. arXiv preprint arXiv:2306.06210 (2023)
  • [30] LeCun, Y., Cortes, C., Burges, C., et al.: Mnist handwritten digit database (2010)
  • [31] Li, H., Shen, C., Torr, P., Tresp, V., Gu, J.: Self-discovering interpretable diffusion latent directions for responsible text-to-image generation. In: Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition. pp. 12006–12016 (2024)
  • [32] Lin, T.Y., Maire, M., Belongie, S., Hays, J., Perona, P., Ramanan, D., Dollár, P., Zitnick, C.L.: Microsoft coco: Common objects in context. In: Computer Vision–ECCV 2014: 13th European Conference, Zurich, Switzerland, September 6-12, 2014, Proceedings, Part V 13. pp. 740–755. Springer (2014)
  • [33] Liu, R., Khakzar, A., Gu, J., Chen, Q., Torr, P., Pizzati, F.: Latent guard: a safety framework for text-to-image generation. arXiv preprint arXiv:2404.08031 (2024)
  • [34] Liu, X., Zhu, Y., Gu, J., Lan, Y., Yang, C., Qiao, Y.: Mm-safetybench: A benchmark for safety evaluation of multimodal large language models. arXiv preprint arXiv:2311.17600 (2023)
  • [35] Liu, X., Liu, J., Bai, Y., Gu, J., Chen, T., Jia, X., Cao, X.: Watermark vaccine: Adversarial attacks to prevent watermark removal. In: European Conference on Computer Vision. pp. 1–17. Springer (2022)
  • [36] Liu, Z., Lin, Y., Cao, Y., Hu, H., Wei, Y., Zhang, Z., Lin, S., Guo, B.: Swin transformer: Hierarchical vision transformer using shifted windows. In: Proceedings of the IEEE/CVF international conference on computer vision. pp. 10012–10022 (2021)
  • [37] Luo, L., Chen, Z., Chen, M., Zeng, X., Xiong, Z.: Reversible image watermarking using interpolation technique. IEEE Transactions on information forensics and security 5(1), 187–193 (2009)
  • [38] Van der Maaten, L., Hinton, G.: Visualizing data using t-sne. Journal of machine learning research 9(11) (2008)
  • [39] Mandelli, S., Bonettini, N., Bestagini, P., Tubaro, S.: Detecting gan-generated images by orthogonal training of multiple cnns. In: 2022 IEEE International Conference on Image Processing (ICIP). pp. 3091–3095. IEEE (2022)
  • [40] Nichol, A., Dhariwal, P., Ramesh, A., Shyam, P., Mishkin, P., McGrew, B., Sutskever, I., Chen, M.: Glide: Towards photorealistic image generation and editing with text-guided diffusion models. arXiv preprint arXiv:2112.10741 (2021)
  • [41] Oussidi, A., Elhassouny, A.: Deep generative models: Survey. In: 2018 International conference on intelligent systems and computer vision (ISCV). pp. 1–8. IEEE (2018)
  • [42] Park, T., Liu, M.Y., Wang, T.C., Zhu, J.Y.: Semantic image synthesis with spatially-adaptive normalization. In: Proceedings of the IEEE/CVF conference on computer vision and pattern recognition. pp. 2337–2346 (2019)
  • [43] Pereira, S., Pun, T.: Robust template matching for affine resistant image watermarks. IEEE transactions on image Processing 9(6), 1123–1129 (2000)
  • [44] Radford, A., Kim, J.W., Hallacy, C., Ramesh, A., Goh, G., Agarwal, S., Sastry, G., Askell, A., Mishkin, P., Clark, J., et al.: Learning transferable visual models from natural language supervision. In: International conference on machine learning. pp. 8748–8763. PMLR (2021)
  • [45] Rezende, D.J., Mohamed, S., Wierstra, D.: Stochastic backpropagation and approximate inference in deep generative models. In: International conference on machine learning. pp. 1278–1286. PMLR (2014)
  • [46] Rombach, R., Blattmann, A., Lorenz, D., Esser, P., Ommer, B.: High-resolution image synthesis with latent diffusion models. In: Proceedings of the IEEE/CVF conference on computer vision and pattern recognition. pp. 10684–10695 (2022)
  • [47] Sabokrou, M., Khalooei, M., Fathy, M., Adeli, E.: Adversarially learned one-class classifier for novelty detection. In: Proceedings of the IEEE conference on computer vision and pattern recognition. pp. 3379–3388 (2018)
  • [48] Saharia, C., Chan, W., Saxena, S., Li, L., Whang, J., Denton, E.L., Ghasemipour, K., Gontijo Lopes, R., Karagol Ayan, B., Salimans, T., et al.: Photorealistic text-to-image diffusion models with deep language understanding. Advances in Neural Information Processing Systems 35, 36479–36494 (2022)
  • [49] Sauer, A., Karras, T., Laine, S., Geiger, A., Aila, T.: Stylegan-t: Unlocking the power of gans for fast large-scale text-to-image synthesis. arXiv preprint arXiv:2301.09515 (2023)
  • [50] Schlegl, T., Seeböck, P., Waldstein, S.M., Schmidt-Erfurth, U., Langs, G.: Unsupervised anomaly detection with generative adversarial networks to guide marker discovery. In: International conference on information processing in medical imaging. pp. 146–157. Springer (2017)
  • [51] Schölkopf, B., Platt, J.C., Shawe-Taylor, J., Smola, A.J., Williamson, R.C.: Estimating the support of a high-dimensional distribution. Neural computation 13(7), 1443–1471 (2001)
  • [52] Schuhmann, C., Beaumont, R., Vencu, R., Gordon, C., Wightman, R., Cherti, M., Coombes, T., Katta, A., Mullis, C., Wortsman, M., et al.: Laion-5b: An open large-scale dataset for training next generation image-text models. Advances in Neural Information Processing Systems 35, 25278–25294 (2022)
  • [53] Schuhmann, C., Vencu, R., Beaumont, R., Kaczmarczyk, R., Mullis, C., Katta, A., Coombes, T., Jitsev, J., Komatsuzaki, A.: Laion-400m: Open dataset of clip-filtered 400 million image-text pairs. arXiv preprint arXiv:2111.02114 (2021)
  • [54] Sha, Z., Li, Z., Yu, N., Zhang, Y.: De-fake: Detection and attribution of fake images generated by text-to-image generation models. In: Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security. pp. 3418–3432 (2023)
  • [55] Simonyan, K., Zisserman, A.: Very deep convolutional networks for large-scale image recognition. arXiv preprint arXiv:1409.1556 (2014)
  • [56] Song, J., Meng, C., Ermon, S.: Denoising diffusion implicit models. arXiv preprint arXiv:2010.02502 (2020)
  • [57] Swanson, M.D., Zhu, B., Tewfik, A.H.: Transparent robust image watermarking. In: Proceedings of 3rd IEEE International Conference on Image Processing. vol. 3, pp. 211–214. IEEE (1996)
  • [58] Szegedy, C., Vanhoucke, V., Ioffe, S., Shlens, J., Wojna, Z.: Rethinking the inception architecture for computer vision. In: Proceedings of the IEEE conference on computer vision and pattern recognition. pp. 2818–2826 (2016)
  • [59] Tancik, M., Mildenhall, B., Ng, R.: Stegastamp: Invisible hyperlinks in physical photographs. In: Proceedings of the IEEE/CVF conference on computer vision and pattern recognition. pp. 2117–2126 (2020)
  • [60] Tao, M., Bao, B.K., Tang, H., Xu, C.: Galip: Generative adversarial clips for text-to-image synthesis. In: Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition. pp. 14214–14223 (2023)
  • [61] Touvron, H., Cord, M., Douze, M., Massa, F., Sablayrolles, A., Jégou, H.: Training data-efficient image transformers & distillation through attention. In: International conference on machine learning. pp. 10347–10357. PMLR (2021)
  • [62] Touvron, H., Cord, M., Sablayrolles, A., Synnaeve, G., Jégou, H.: Going deeper with image transformers. In: Proceedings of the IEEE/CVF international conference on computer vision. pp. 32–42 (2021)
  • [63] Wang, S.Y., Wang, O., Zhang, R., Owens, A., Efros, A.A.: Cnn-generated images are surprisingly easy to spot… for now. In: Proceedings of the IEEE/CVF conference on computer vision and pattern recognition. pp. 8695–8704 (2020)
  • [64] Wang, Z., Chen, C., Zeng, Y., Lyu, L., Ma, S.: Alteration-free and model-agnostic origin attribution of generated images. arXiv preprint arXiv:2305.18439 (2023)
  • [65] Wu, B., Gu, J., Li, Z., Cai, D., He, X., Liu, W.: Towards efficient adversarial training on vision transformers. In: European Conference on Computer Vision. pp. 307–325. Springer (2022)
  • [66] Young, P., Lai, A., Hodosh, M., Hockenmaier, J.: From image descriptions to visual denotations: New similarity metrics for semantic inference over event descriptions. Transactions of the Association for Computational Linguistics 2, 67–78 (2014)
  • [67] Yu, F., Seff, A., Zhang, Y., Song, S., Funkhouser, T., Xiao, J.: Lsun: Construction of a large-scale image dataset using deep learning with humans in the loop. arXiv preprint arXiv:1506.03365 (2015)
  • [68] Yu, N., Davis, L.S., Fritz, M.: Attributing fake images to gans: Learning and analyzing gan fingerprints. In: Proceedings of the IEEE/CVF international conference on computer vision. pp. 7556–7566 (2019)
  • [69] Yu, N., Skripniuk, V., Abdelnabi, S., Fritz, M.: Artificial fingerprinting for generative models: Rooting deepfake attribution in training data. In: Proceedings of the IEEE/CVF International conference on computer vision. pp. 14448–14457 (2021)
  • [70] Yu, N., Skripniuk, V., Chen, D., Davis, L., Fritz, M.: Responsible disclosure of generative models using scalable fingerprinting. arXiv preprint arXiv:2012.08726 (2020)
  • [71] Zhou, K., Yang, J., Loy, C.C., Liu, Z.: Learning to prompt for vision-language models. International Journal of Computer Vision 130(9), 2337–2348 (2022)

Appendix 0.A Generation of Datasets

There are a total of 202,520 fake images generated by five different generative models, namely, Stable Diffusion Model [46], Latent Diffusion Model [46], GLIDE [40], Vector Quantized Diffusion [19], and GALIP [60]. The prompts used are the first captions of each image in the validation set of the Microsoft Common Objects in Context (COCO) 2014 dataset [32]. These models were pre-trained on four different datasets: LAION-5B [52], COCO [32], LAION-400M [53], and filtered CC12M [5]. In total, as shown in Figure 5, five synthetic image datasets are generated, namely SD, VQ-D, LDM, GLIDE, and GALIP.

SD: This marks the data generated by the Stable Diffusion Model [46]111https://github.com/CompVis/stable-diffusion. It was pre-trained on the LAION-5B dataset. The size of the generated images is 512×512512512512\times 512512 × 512. The pre-trained model used is ‘sd-v1-4’.

VQ-D: This marks the data generated by the Vector Quantized Diffusion (VQ-D) Model [19]222https://github.com/microsoft/VQ-Diffusion. It was pre-trained on the COCO dataset. The size of the generated images is 256×256256256256\times 256256 × 256. The pre-trained model ‘coco_pretrained’ served as the backbone of this method.

LDM: This marks the data generated by the Latent Diffusion Model [46]333https://github.com/CompVis/latent-diffusion. It was pre-trained on the LAION-400M dataset. The size of the generated images is 256×256256256256\times 256256 × 256. The pre-trained model, ‘txt2img-f8-large’, is utilized.

GLIDE: This marks the data generated by GLIDE [40]444https://github.com/openai/glide-text2im. It was pre-trained on filtered CC12M. The size of the generated images is 256×256256256256\times 256256 × 256.

GALIP: This marks the dataset generated by GALIP [60]555https://github.com/tobran/GALIP. The model was pretrained on the COCO dataset. The size of the generated images is 256×256256256256\times 256256 × 256.

We also utilized pre-existing datasets (namely GauGAN [42], ProGAN [25], and StyleGAN2 [26]) as provided by [63]. GauGAN was trained on the COCO [32] dataset, while ProGan and StyleGan2 were trained on the LSUN [67] dataset. The size of images from those datasets is 256×256256256256\times 256256 × 256.

SD VQ-D LDM Glide GALIP DALL·E-3
Caption 1 Refer to caption Refer to caption Refer to caption Refer to caption Refer to caption Refer to caption
Caption 2 Refer to caption Refer to caption Refer to caption Refer to caption Refer to caption Refer to caption
Caption 3 Refer to caption Refer to caption Refer to caption Refer to caption Refer to caption Refer to caption
Caption 4 Refer to caption Refer to caption Refer to caption Refer to caption Refer to caption Refer to caption
Caption 5 Refer to caption Refer to caption Refer to caption Refer to caption Refer to caption Refer to caption
Figure 5: This figure presents a demo of synthesized images produced by six distinct models, each predicated upon four specific captions. Caption 1: Birds perch on a bunch of twigs in the winter. Caption 2: A coffee table sits in the middle of a living room. Caption 3: Three teddy bears, each a different color, snuggling together. Caption 4: The dinner plate has asparagus, carrots and some kind of meat. Caption 5: A large body of water sitting below a mountain range.

Appendix 0.B Implementation Details

For all models, we randomly selected 1,000 images from each dataset for testing. Besides, 500 images were chosen from each dataset for training, divided into 10 sets: train1, train2, …, train10. Each training set contained 50 images from a non-target dataset and 50 from a target dataset. After training for 200 epochs, we evaluated the results on a test set comprising 1,000 testing images from both the non-target and target datasets. There was no dedicated validation set in our experimental setup. By default, adversarial data augmentation was applied to half of the non-target images, with a perturbation step size, denoted as ϵitalic-ϵ\epsilonitalic_ϵ, of 0.1. The Average AUC value was calculated as the mean of the AUC values obtained from the 10 trained models, each trained on a distinct training set and tested on the same test set.

Appendix 0.C Comparison with Baselines

The standard deviation of each mean of AUC is shown in Table 10 and Table 11. The standard deviation of each mean of Accuracy is shown in Table 12 and Table 13.The reason why the CLIP model has a 0 standard deviation is that it is a zero-shot model, which means there are no parameters changed. Therefore, when testing on the same testing set, the result will not change.

ResNet [20], Inception [58], DenseNet [22], VGG [55], ViT [11], Deit [61], Cait [62], and Swin [36] are either milestones or leading-edge models in the field of Computer Vision. For the Image-Patch model, each image is subdivided into 2x2 patches, with each patch serving as a separate input to the ResNet-50 architecture. The ultimate prediction from the model is the average of the predictions made for each of these patches. In the case of the Feature-Patch model, which shares the same backbone, the last five layers of the standard ResNet-50 architecture are discarded, and the remaining structure is employed to extract image features. Subsequently, these features are segmented into 4x4 patches, with each patch being passed through the final linear classification layer. The model’s final output is the average prediction over these patches.

To visualize the training loss, training AUC, validation loss, and validation AUC, apart from images in the training set and test set, I randomly select 1000 images from both non-target and target datasets to build a validation set. Figure 6 shows the change of loss of the train set and validation set with the increasing number of epochs. Figure 7 shows the change of AUC of the train set and validation set with the increasing number of epochs. The reason why the loss of the train set is larger than the loss of the validation set in the Image_Patch model is that during training, each image is subdivided into 4 patches.

Refer to caption
Figure 6: This figure illustrates the training and validation Area Under the Curve (AUC) metrics for 14 models (13 baselines + OCC-CLIP), comparing their performance in terms of both training accuracy and validation reliability.
Refer to caption
Figure 7: This figure illustrates the comparative analysis of training and validation loss across 14 models (13 baselines + OCC-CLIP). It provides a visual representation of how each model’s loss metrics evolve over the course of training.

Appendix 0.D Sensitivity to Source Models and Value of Epsilon

To test the effect of the choice of ϵitalic-ϵ\epsilonitalic_ϵ on source models, we conducted a comprehensive evaluation using eight models with six different values of ϵitalic-ϵ\epsilonitalic_ϵ. According to Table 14 and Table 15, it can be concluded that varying the step size ϵitalic-ϵ\epsilonitalic_ϵ has different effects on source model attribution. With the adjustment of ϵitalic-ϵ\epsilonitalic_ϵ, it was observed that the use of adversarial data augmentation can have a positive effect on source model attribution tests.

Appendix 0.E Sensitivity to Selection of Non-target Class and ADA Settings

Table 16 and Table 17 show the sensitivity evaluation of various ADA methods on different open-world real image datasets. In the default setting, the target dataset is SD, and the non-target is COCO. ADA is applied to half of the non-target images. 1) During the training phase, conditioned on applying ADA to only half of the non-target images, three additional non-target image datasets are used: ImageNet, Flickr, and CC12M. 2) When selecting non-target images exclusively from COCO, ADA is applied to half of the target images, to half of both non-target and target images, and to half of the target images, which are then treated as non-target. It is observed that the choice of non-target images affects the performance of OCC-CLIP. Additionally, applying ADA to non-target images is most effective.

Appendix 0.F Sensitivity to the Proportion of Augmented Non-target Images

Table 18 and Table 19 present the standard deviation when applying ADA to varying proportions of non-target images. Results from seven different testing tasks and their average are also included.

Appendix 0.G Sensitivity to the Number of Shots

Table 20 and Table 21 illustrate the mean origin attribution performance of CoOp and OCC-CLIP across seven different testing tasks with varying numbers of shots: 10, 20, 30, 40, 50, 100, and 200. In the training phase, SD is used as the target dataset, and one of COCO, CC12M, Flickr, or ImageNet is used as the non-target dataset.

Appendix 0.H Sensitivity to Image Processing in Verification Stage

Tables 22 and 23 present a comparative analysis of the performance between OCC-CLIP and baseline methods in response to potential image processing techniques: Gaussian Blur, Gaussian Noise, Grayscale, Rotation, Flip, or a combination of these attacks. The standard deviations and the testing results across seven different tasks, along with their average, are shown. The data indicate that OCC-CLIP exhibits superior robustness compared to the baseline in most cases, demonstrating enhanced resilience to various forms of image manipulation. This underscores the effectiveness of OCC-CLIP in safeguarding against image-based copyright infringements.

Appendix 0.I Sensitivity to Choice of Prompts

We explore the impact of prompt selection on the performance of OCC-CLIP. As indicated in Tables 24 and 25, the choice of prompts influences performance across seven different testing tasks. However, OCC-CLIP consistently outperforms the baseline regardless of the prompt pair chosen.

Appendix 0.J Comparison to Standard Data Augmentation

In a comprehensive evaluation of ADA, we compare its effectiveness with common data augmentation methods: Gaussian Blur, Gaussian Noise, Grayscale, Rotation, Flip, and combinations of these. According to Tables 26 and 27, traditional data augmentation methods generally perform poorly, often degrading performance across many of the seven testing tasks. Only ADA shows improvements, suggesting that standard data augmentation methods may not be suitable for few-shot one-class classification scenarios.

Appendix 0.K Source Model Attribution with Commercial Generation API

To assess OCC-CLIP’s real-world effectiveness, we used the latest commercial digital image-generating model, DALL·E-3 [2], to generate images. As detailed in Section 0.N, 103 prompts were randomly selected from the annotations of COCO’s validation set [32]. In addition to the images generated from these prompts, additional sample images are presented in Figure 5. During the training phase, the target images are those generated by DALL·E-3, while the non-target images are from COCO. In the testing phase, the non-target images are from one of the other generated datasets. The performance of detection across various shot numbers (10, 20, 30, 40, 50) is compared. According to Tables 28 and 30, our method consistently outperforms the baseline across all eight testing tasks and performs well even with as few as 10 shots. Due to limitations in the number of images generated by DALL·E-3, we train the model only once for each testing task.

Appendix 0.L Model Attribution with Multiple Source Models

Since this involves multi-source origin attribution, the evaluation metric used in this section is accuracy instead of AUC. We evaluate the model under the following conditions: 2 classes (SD, VQ-D), 4 classes (SD, VQ-D, LDM, Glide), and 6 classes (SD, VQ-D, LDM, Glide, GALIP, ProGAN). Table 31 shows the accuracy of verifying multiple sources using the eight trained one-class classifiers. Table 32 shows the accuracy of directly training a multi-class classifier.

Appendix 0.M Stronger Baselines and Harder Datasets

We also experimented with three representative methods of fine-tuning CLIP using LoRA: replacing the linear layer in the last (LoRAl), middle (LoRAm), or all (LoRAa) residual attention blocks. The other two baseline methods are Wang et al.’s  [64], which uses inverse engineering and has model access, and Girish et al.’s  [13], which uses a multistep pipeline. Table 29 shows the accuracy of these methods. Our approach outperforms these baselines in our setting.

Appendix 0.N Prompts for DALL·E-3

The following prompts were randomly selected from the annotations of the validation set of the COCO dataset.

A man holding a motion controlled video game controller
A person sitting at a table filled with mexican food.
a work desk with a monitor and keyboard
A clock is standing in the middle of the grass in the middle of the afternoon.
some people are walking in front of a tall building
Three people standing before airport counters below airport signs.
A snow mountain being used for winter sports.
a man that is cutting up some kind of fruit
A bench sitting on a sidewalk near a line of cars.
A skier holds his skis as he stands in the mountains.
A living room filled with lots of furniture and seats.
A train is parked at the station loading passengers.
A man and woman with two Clydesdale horses.
A bathroom with tub and toilet, tiled in white tiling.
A Amtrak train traveling on a railroad tracks.
A stuffed teddy bear sitting amongst pillows on a bed
A green train traveling down train tracks next to another train.
A set of three red double decker buses parked next to each other.
A large plate of waffles is next to plates with slices of peaches.
A couple of people riding skis down a snow covered slope.
A big building perched atop a hill with a sign in the foreground.
The man and woman are playing video games in the room.
Barbecued meat and vegetables laid out on a counter ready for dinner
A herd of elephants in the wild near a river.
A hot dog with mustard and a bun next to a ketchup cup.
A dog rides on the back of a sheep.
The woman is holding up two large hot dogs.
A person is flying through the air near some mountains on his snowboard.
A jockey riding and jumping with a horse in an obstacle course.
a big bed with a lamp and bedside table and sliding glass leading to a balcony
Several lambs and sheep standing on hay and eating it.
an image of a statue of men in a carriage being driven by horses
There is a hose hooked up to the fire hydrant by the building.
A FOUNTAIN IN A ROUNDABOUT WITH PEOPLE PASSING BY
A heard of sheep together in a wheat field.
A woman opening a suitcase on the bed
A traffic light over a city street with cars.
A photo taken from behind a fence of tennis players on the court.
A row of parking meters sitting in a park.
A woman is talking on her phone while dragging on a cigarette.
Subway braking on rails in front of metropolitan city
A young man and woman share some pastries.
An aerial photo of a very long train station at night.
a foggy day that has some lights by a road
A dog sitting on the floor between a person legs
This dirt bike rider is smiling and raising his fist in triumph.
A desk top computer and a laptop sitting on a computer desk
an orange brick building with a window and a big mascot
A person doing a trick on a skateboard in the road
LOTS OF CUPCAKES ARRANGED ON A TABLE WITH NAPKINS
A bathroom sink underneath a medicine cabinet next to a window.
A red bus driving in front of a double decker bus.
The girl is about to kick a soccer ball.
A skateboarder jumping through the air and doing a trick.
Woman with surfboard getting kisses from dog at waters edge.
A skier leaning to the side on a snowy hill.
some motorcycles parked and the one in front is a silver three wheeler
A skier standing at the stop of a mountain slope.
Two planes that are flying in the sky.
A man presenting something to another man in a tent.
A man in a wet suit walking with another man in a wet suit with equipment.
a man flying a kite in a big green field
A man holding a dog mug pints the remote.
two little birds sitting on the shore by a piece of wood
A giraffe eats next to a zebra among some rocks.
A cat thats about to take a bute out of someone’s sandwich.
A gray dog wearing an orange bow tie laying on a sofa.
A yellow swan boat ride on a body of water under a cloudless sky.
A old house with a clock tower in brown and white.
a surfer that has fallen off of his surf board
Someone is enjoying a small slice of pie.
A coach balances a soccer ball in front of her team
A couple of giraffes eating out of a feeding bin in a zoo type facility.
A large gray teddy bear sitting next to a candle.
an image of a cat lying next to a stuffed animal
A woman smiling while she prepares a plate of food.
A group of zebras are standing in a desert.
Cat sitting on a window sill in front of a windmill.
A bunch of people walking on the street with umbrellas.
A skate boarder doing jumps at night on city street.
A man with glasses holding a baby in a white outfit.
A man in glasses talking on a cellphone.
A man with glasses is smiling and clapping.
two people sitting on benches with trees in the background
A girl riding on the back of a scooter on a cobbled road.
A small computer keyboard, box and matching mouse
a couple of people on skis stand in the snow
A man sitting in a chair with an infant laying on his lap and a woman standing over the top and looking down at the infant.
Several alcoholic beverages and mixers on a airplane tray.
A very big pretty horse pulling a fancy carriage.
A young man has just hit a baseball with the bat
A woman in a green shirt stands near a table with bowls or oranges on it in a market.
A person watching a small plane taking off in a field
A bicycle being held by a bar on a train.
A baseball game in progress in the open air.
A police car parked on the side of the road.
A white toilet sitting next to a toilet paper roller.
A bright green frog on a bright green plant.
A man surfing a wave on his surf board.
A small dog reclines on a piece of furniture next to an electronic game controller.
A person skiing alone in the snow capped area
A large family group at a round table in a restaraunt.
A stop sign is erected next to a flower bush.

Table 10: Evaluation of OCC-CLIP, along with 14 basic methods. Training samples are sourced from SD (denoted as target) and COCO (denoted as non-target). The test data are assembled from SD as well as a different generative image dataset. The optimal outcomes for individual datasets are emphasized using bold formatting. The metric shown here is AUC.
Methods VQ-D LDM Glide GALIP
VGG16 [55] 0.6458±2.64e-2plus-or-minus0.64582.64𝑒-20.6458\scriptscriptstyle\pm\scriptstyle 2.64e\text{-}20.6458 ± 2.64 italic_e - 2 0.5438±2.29e-2plus-or-minus0.54382.29𝑒-20.5438\scriptscriptstyle\pm\scriptstyle 2.29e\text{-}20.5438 ± 2.29 italic_e - 2 0.5652±2.48e-2plus-or-minus0.56522.48𝑒-20.5652\scriptscriptstyle\pm\scriptstyle 2.48e\text{-}20.5652 ± 2.48 italic_e - 2 0.7017±4.15e-2plus-or-minus0.70174.15𝑒-20.7017\scriptscriptstyle\pm\scriptstyle 4.15e\text{-}20.7017 ± 4.15 italic_e - 2
ResNet50 [20] 0.6693±5.27e-2plus-or-minus0.66935.27𝑒-20.6693\scriptscriptstyle\pm\scriptstyle 5.27e\text{-}20.6693 ± 5.27 italic_e - 2 0.5485±3.07e-2plus-or-minus0.54853.07𝑒-20.5485\scriptscriptstyle\pm\scriptstyle 3.07e\text{-}20.5485 ± 3.07 italic_e - 2 0.6103±4.03e-2plus-or-minus0.61034.03𝑒-20.6103\scriptscriptstyle\pm\scriptstyle 4.03e\text{-}20.6103 ± 4.03 italic_e - 2 0.7307±3.94e-2plus-or-minus0.73073.94𝑒-20.7307\scriptscriptstyle\pm\scriptstyle 3.94e\text{-}20.7307 ± 3.94 italic_e - 2
Inception-v3 [58] 0.6378±4.45e-2plus-or-minus0.63784.45𝑒-20.6378\scriptscriptstyle\pm\scriptstyle 4.45e\text{-}20.6378 ± 4.45 italic_e - 2 0.5349±2.49e-2plus-or-minus0.53492.49𝑒-20.5349\scriptscriptstyle\pm\scriptstyle 2.49e\text{-}20.5349 ± 2.49 italic_e - 2 0.5252±1.78e-2plus-or-minus0.52521.78𝑒-20.5252\scriptscriptstyle\pm\scriptstyle 1.78e\text{-}20.5252 ± 1.78 italic_e - 2 0.6759±4.26e-2plus-or-minus0.67594.26𝑒-20.6759\scriptscriptstyle\pm\scriptstyle 4.26e\text{-}20.6759 ± 4.26 italic_e - 2
DenseNet-121 [22] 0.7264±4.70e-2plus-or-minus0.72644.70𝑒-20.7264\scriptscriptstyle\pm\scriptstyle 4.70e\text{-}20.7264 ± 4.70 italic_e - 2 0.5337±3.40e-2plus-or-minus0.53373.40𝑒-20.5337\scriptscriptstyle\pm\scriptstyle 3.40e\text{-}20.5337 ± 3.40 italic_e - 2 0.5730±5.62e-2plus-or-minus0.57305.62𝑒-20.5730\scriptscriptstyle\pm\scriptstyle 5.62e\text{-}20.5730 ± 5.62 italic_e - 2 0.7478±4.85e-2plus-or-minus0.74784.85𝑒-20.7478\scriptscriptstyle\pm\scriptstyle 4.85e\text{-}20.7478 ± 4.85 italic_e - 2
ViT-B-16 [11] 0.7502±2.70e-2plus-or-minus0.75022.70𝑒-20.7502\scriptscriptstyle\pm\scriptstyle 2.70e\text{-}20.7502 ± 2.70 italic_e - 2 0.5387±2.06e-2plus-or-minus0.53872.06𝑒-20.5387\scriptscriptstyle\pm\scriptstyle 2.06e\text{-}20.5387 ± 2.06 italic_e - 2 0.6069±4.46e-2plus-or-minus0.60694.46𝑒-20.6069\scriptscriptstyle\pm\scriptstyle 4.46e\text{-}20.6069 ± 4.46 italic_e - 2 0.7837±2.05e-2plus-or-minus0.78372.05𝑒-20.7837\scriptscriptstyle\pm\scriptstyle 2.05e\text{-}20.7837 ± 2.05 italic_e - 2
DeiT-B-16 [61] 0.6825±3.96e-2plus-or-minus0.68253.96𝑒-20.6825\scriptscriptstyle\pm\scriptstyle 3.96e\text{-}20.6825 ± 3.96 italic_e - 2 0.5366±2.47e-2plus-or-minus0.53662.47𝑒-20.5366\scriptscriptstyle\pm\scriptstyle 2.47e\text{-}20.5366 ± 2.47 italic_e - 2 0.5698±2.91e-2plus-or-minus0.56982.91𝑒-20.5698\scriptscriptstyle\pm\scriptstyle 2.91e\text{-}20.5698 ± 2.91 italic_e - 2 0.6592±2.76e-2plus-or-minus0.65922.76𝑒-20.6592\scriptscriptstyle\pm\scriptstyle 2.76e\text{-}20.6592 ± 2.76 italic_e - 2
CaiT-S-24 [62] 0.6522±4.85e-2plus-or-minus0.65224.85𝑒-20.6522\scriptscriptstyle\pm\scriptstyle 4.85e\text{-}20.6522 ± 4.85 italic_e - 2 0.5301±2.51e-2plus-or-minus0.53012.51𝑒-20.5301\scriptscriptstyle\pm\scriptstyle 2.51e\text{-}20.5301 ± 2.51 italic_e - 2 0.5550±5.18e-2plus-or-minus0.55505.18𝑒-20.5550\scriptscriptstyle\pm\scriptstyle 5.18e\text{-}20.5550 ± 5.18 italic_e - 2 0.6466±4.48e-2plus-or-minus0.64664.48𝑒-20.6466\scriptscriptstyle\pm\scriptstyle 4.48e\text{-}20.6466 ± 4.48 italic_e - 2
Swin-B-4 [36] 0.8634±3.69e-2plus-or-minus0.86343.69𝑒-20.8634\scriptscriptstyle\pm\scriptstyle 3.69e\text{-}20.8634 ± 3.69 italic_e - 2 0.7180±5.06e-2plus-or-minus0.71805.06𝑒-20.7180\scriptscriptstyle\pm\scriptstyle 5.06e\text{-}20.7180 ± 5.06 italic_e - 2 0.7473±3.97e-2plus-or-minus0.74733.97𝑒-20.7473\scriptscriptstyle\pm\scriptstyle 3.97e\text{-}20.7473 ± 3.97 italic_e - 2 0.8478±4.14e-2plus-or-minus0.84784.14𝑒-20.8478\scriptscriptstyle\pm\scriptstyle 4.14e\text{-}20.8478 ± 4.14 italic_e - 2
Image_Patch [39] 0.6638±3.69e-2plus-or-minus0.66383.69𝑒-20.6638\scriptscriptstyle\pm\scriptstyle 3.69e\text{-}20.6638 ± 3.69 italic_e - 2 0.5269±1.84e-2plus-or-minus0.52691.84𝑒-20.5269\scriptscriptstyle\pm\scriptstyle 1.84e\text{-}20.5269 ± 1.84 italic_e - 2 0.5534±3.15e-2plus-or-minus0.55343.15𝑒-20.5534\scriptscriptstyle\pm\scriptstyle 3.15e\text{-}20.5534 ± 3.15 italic_e - 2 0.6847±4.41e-2plus-or-minus0.68474.41𝑒-20.6847\scriptscriptstyle\pm\scriptstyle 4.41e\text{-}20.6847 ± 4.41 italic_e - 2
Feature_Patch [39] 0.6999±2.53e-2plus-or-minus0.69992.53𝑒-20.6999\scriptscriptstyle\pm\scriptstyle 2.53e\text{-}20.6999 ± 2.53 italic_e - 2 0.6116±3.27e-2plus-or-minus0.61163.27𝑒-20.6116\scriptscriptstyle\pm\scriptstyle 3.27e\text{-}20.6116 ± 3.27 italic_e - 2 0.7385±7.70e-2plus-or-minus0.73857.70𝑒-20.7385\scriptscriptstyle\pm\scriptstyle 7.70e\text{-}20.7385 ± 7.70 italic_e - 2 0.6285±5.62e-2plus-or-minus0.62855.62𝑒-20.6285\scriptscriptstyle\pm\scriptstyle 5.62e\text{-}20.6285 ± 5.62 italic_e - 2
CLIP [44] 0.7272±0.0plus-or-minus0.72720.00.7272\scriptscriptstyle\pm\scriptstyle 0.00.7272 ± 0.0 0.7243±0.0plus-or-minus0.72430.00.7243\scriptscriptstyle\pm\scriptstyle 0.00.7243 ± 0.0 0.6078±0.0plus-or-minus0.60780.00.6078\scriptscriptstyle\pm\scriptstyle 0.00.6078 ± 0.0 0.7304±0.0plus-or-minus0.73040.00.7304\scriptscriptstyle\pm\scriptstyle 0.00.7304 ± 0.0
CoOp [71] 0.9503±1.68e-2plus-or-minus0.95031.68𝑒-20.9503\scriptscriptstyle\pm\scriptstyle 1.68e\text{-}20.9503 ± 1.68 italic_e - 2 0.8373±5.33e-2plus-or-minus0.83735.33𝑒-20.8373\scriptscriptstyle\pm\scriptstyle 5.33e\text{-}20.8373 ± 5.33 italic_e - 2 0.9266±3.19e-2plus-or-minus0.92663.19𝑒-20.9266\scriptscriptstyle\pm\scriptstyle 3.19e\text{-}20.9266 ± 3.19 italic_e - 2 0.9660±2.56e-2plus-or-minus0.96602.56𝑒-20.9660\scriptscriptstyle\pm\scriptstyle 2.56e\text{-}20.9660 ± 2.56 italic_e - 2
OCC-CLIP 0.9703±9.06𝐞-𝟑plus-or-minus0.97039.06𝐞-3\mathbf{0.9703\scriptscriptstyle\pm\scriptstyle 9.06e\text{-}3}bold_0.9703 ± bold_9.06 bold_e - bold_3 0.8801±2.06𝐞-𝟐plus-or-minus0.88012.06𝐞-2\mathbf{0.8801\scriptscriptstyle\pm\scriptstyle 2.06e\text{-}2}bold_0.8801 ± bold_2.06 bold_e - bold_2 0.9519±1.45𝐞-𝟐plus-or-minus0.95191.45𝐞-2\mathbf{0.9519\scriptscriptstyle\pm\scriptstyle 1.45e\text{-}2}bold_0.9519 ± bold_1.45 bold_e - bold_2 0.9798±1.18𝐞-𝟐plus-or-minus0.97981.18𝐞-2\mathbf{0.9798\scriptscriptstyle\pm\scriptstyle 1.18e\text{-}2}bold_0.9798 ± bold_1.18 bold_e - bold_2
Table 11: Evaluation of OCC-CLIP, along with 14 basic methods. Training samples are sourced from SD (denoted as target) and COCO (denoted as non-target). The test data are assembled from SD as well as a different generative image dataset. The optimal outcomes for individual datasets are emphasized using bold formatting. The metric shown here is AUC.
Methods ProGan StyleGan2 GauGan Overall
VGG16 [55] 0.6609±5.46e-2plus-or-minus0.66095.46𝑒-20.6609\scriptscriptstyle\pm\scriptstyle 5.46e\text{-}20.6609 ± 5.46 italic_e - 2 0.6170±7.87e-2plus-or-minus0.61707.87𝑒-20.6170\scriptscriptstyle\pm\scriptstyle 7.87e\text{-}20.6170 ± 7.87 italic_e - 2 0.7096±4.62e-2plus-or-minus0.70964.62𝑒-20.7096\scriptscriptstyle\pm\scriptstyle 4.62e\text{-}20.7096 ± 4.62 italic_e - 2 0.6349±4.61e-2plus-or-minus0.63494.61𝑒-20.6349\scriptscriptstyle\pm\scriptstyle 4.61e\text{-}20.6349 ± 4.61 italic_e - 2
ResNet50 [20] 0.6646±4.56e-2plus-or-minus0.66464.56𝑒-20.6646\scriptscriptstyle\pm\scriptstyle 4.56e\text{-}20.6646 ± 4.56 italic_e - 2 0.6458±9.33e-2plus-or-minus0.64589.33𝑒-20.6458\scriptscriptstyle\pm\scriptstyle 9.33e\text{-}20.6458 ± 9.33 italic_e - 2 0.7475±3.39e-2plus-or-minus0.74753.39𝑒-20.7475\scriptscriptstyle\pm\scriptstyle 3.39e\text{-}20.7475 ± 3.39 italic_e - 2 0.6595±5.18e-2plus-or-minus0.65955.18𝑒-20.6595\scriptscriptstyle\pm\scriptstyle 5.18e\text{-}20.6595 ± 5.18 italic_e - 2
Inception-v3 [58] 0.6453±4.87e-2plus-or-minus0.64534.87𝑒-20.6453\scriptscriptstyle\pm\scriptstyle 4.87e\text{-}20.6453 ± 4.87 italic_e - 2 0.5947±4.88e-2plus-or-minus0.59474.88𝑒-20.5947\scriptscriptstyle\pm\scriptstyle 4.88e\text{-}20.5947 ± 4.88 italic_e - 2 0.6982±4.31e-2plus-or-minus0.69824.31𝑒-20.6982\scriptscriptstyle\pm\scriptstyle 4.31e\text{-}20.6982 ± 4.31 italic_e - 2 0.6160±4.03e-2plus-or-minus0.61604.03𝑒-20.6160\scriptscriptstyle\pm\scriptstyle 4.03e\text{-}20.6160 ± 4.03 italic_e - 2
DenseNet-121 [22] 0.7204±3.35e-2plus-or-minus0.72043.35𝑒-20.7204\scriptscriptstyle\pm\scriptstyle 3.35e\text{-}20.7204 ± 3.35 italic_e - 2 0.6645±6.78e-2plus-or-minus0.66456.78𝑒-20.6645\scriptscriptstyle\pm\scriptstyle 6.78e\text{-}20.6645 ± 6.78 italic_e - 2 0.8091±2.94e-2plus-or-minus0.80912.94𝑒-20.8091\scriptscriptstyle\pm\scriptstyle 2.94e\text{-}20.8091 ± 2.94 italic_e - 2 0.6821±4.70e-2plus-or-minus0.68214.70𝑒-20.6821\scriptscriptstyle\pm\scriptstyle 4.70e\text{-}20.6821 ± 4.70 italic_e - 2
ViT-B-16 [11] 0.6062±3.71e-2plus-or-minus0.60623.71𝑒-20.6062\scriptscriptstyle\pm\scriptstyle 3.71e\text{-}20.6062 ± 3.71 italic_e - 2 0.6593±6.11e-2plus-or-minus0.65936.11𝑒-20.6593\scriptscriptstyle\pm\scriptstyle 6.11e\text{-}20.6593 ± 6.11 italic_e - 2 0.7259±2.77e-2plus-or-minus0.72592.77𝑒-20.7259\scriptscriptstyle\pm\scriptstyle 2.77e\text{-}20.7259 ± 2.77 italic_e - 2 0.6673±3.67e-2plus-or-minus0.66733.67𝑒-20.6673\scriptscriptstyle\pm\scriptstyle 3.67e\text{-}20.6673 ± 3.67 italic_e - 2
DeiT-B-16 [61] 0.5721±2.77e-2plus-or-minus0.57212.77𝑒-20.5721\scriptscriptstyle\pm\scriptstyle 2.77e\text{-}20.5721 ± 2.77 italic_e - 2 0.5898±4.20e-2plus-or-minus0.58984.20𝑒-20.5898\scriptscriptstyle\pm\scriptstyle 4.20e\text{-}20.5898 ± 4.20 italic_e - 2 0.6507±2.72e-2plus-or-minus0.65072.72𝑒-20.6507\scriptscriptstyle\pm\scriptstyle 2.72e\text{-}20.6507 ± 2.72 italic_e - 2 0.6087±3.17e-2plus-or-minus0.60873.17𝑒-20.6087\scriptscriptstyle\pm\scriptstyle 3.17e\text{-}20.6087 ± 3.17 italic_e - 2
CaiT-S-24 [62] 0.5697±2.63e-2plus-or-minus0.56972.63𝑒-20.5697\scriptscriptstyle\pm\scriptstyle 2.63e\text{-}20.5697 ± 2.63 italic_e - 2 0.5804±5.12e-2plus-or-minus0.58045.12𝑒-20.5804\scriptscriptstyle\pm\scriptstyle 5.12e\text{-}20.5804 ± 5.12 italic_e - 2 0.6645±3.42e-2plus-or-minus0.66453.42𝑒-20.6645\scriptscriptstyle\pm\scriptstyle 3.42e\text{-}20.6645 ± 3.42 italic_e - 2 0.5998±4.17e-2plus-or-minus0.59984.17𝑒-20.5998\scriptscriptstyle\pm\scriptstyle 4.17e\text{-}20.5998 ± 4.17 italic_e - 2
Swin-B-4 [36] 0.5879±3.68e-2plus-or-minus0.58793.68𝑒-20.5879\scriptscriptstyle\pm\scriptstyle 3.68e\text{-}20.5879 ± 3.68 italic_e - 2 0.7054±6.30e-2plus-or-minus0.70546.30𝑒-20.7054\scriptscriptstyle\pm\scriptstyle 6.30e\text{-}20.7054 ± 6.30 italic_e - 2 0.7822±3.91e-2plus-or-minus0.78223.91𝑒-20.7822\scriptscriptstyle\pm\scriptstyle 3.91e\text{-}20.7822 ± 3.91 italic_e - 2 0.7503±4.48e-2plus-or-minus0.75034.48𝑒-20.7503\scriptscriptstyle\pm\scriptstyle 4.48e\text{-}20.7503 ± 4.48 italic_e - 2
Image_Patch [39] 0.6624±4.82e-2plus-or-minus0.66244.82𝑒-20.6624\scriptscriptstyle\pm\scriptstyle 4.82e\text{-}20.6624 ± 4.82 italic_e - 2 0.6706±9.62e-2plus-or-minus0.67069.62𝑒-20.6706\scriptscriptstyle\pm\scriptstyle 9.62e\text{-}20.6706 ± 9.62 italic_e - 2 0.7674±4.09e-2plus-or-minus0.76744.09𝑒-20.7674\scriptscriptstyle\pm\scriptstyle 4.09e\text{-}20.7674 ± 4.09 italic_e - 2 0.6470±5.05e-2plus-or-minus0.64705.05𝑒-20.6470\scriptscriptstyle\pm\scriptstyle 5.05e\text{-}20.6470 ± 5.05 italic_e - 2
Feature_Patch [39] 0.7136±2.77e-2plus-or-minus0.71362.77𝑒-20.7136\scriptscriptstyle\pm\scriptstyle 2.77e\text{-}20.7136 ± 2.77 italic_e - 2 0.8546±2.65e-2plus-or-minus0.85462.65𝑒-20.8546\scriptscriptstyle\pm\scriptstyle 2.65e\text{-}20.8546 ± 2.65 italic_e - 2 0.8152±3.14e-2plus-or-minus0.81523.14𝑒-20.8152\scriptscriptstyle\pm\scriptstyle 3.14e\text{-}20.8152 ± 3.14 italic_e - 2 0.7231±4.35e-2plus-or-minus0.72314.35𝑒-20.7231\scriptscriptstyle\pm\scriptstyle 4.35e\text{-}20.7231 ± 4.35 italic_e - 2
CLIP [44] 0.5229±0.0plus-or-minus0.52290.00.5229\scriptscriptstyle\pm\scriptstyle 0.00.5229 ± 0.0 0.5393±0.0plus-or-minus0.53930.00.5393\scriptscriptstyle\pm\scriptstyle 0.00.5393 ± 0.0 0.6463±0.0plus-or-minus0.64630.00.6463\scriptscriptstyle\pm\scriptstyle 0.00.6463 ± 0.0 0.6426±0.0plus-or-minus0.64260.00.6426\scriptscriptstyle\pm\scriptstyle 0.00.6426 ± 0.0
CoOp [71] 0.8861±4.46e-2plus-or-minus0.88614.46𝑒-20.8861\scriptscriptstyle\pm\scriptstyle 4.46e\text{-}20.8861 ± 4.46 italic_e - 2 0.9533±2.30e-2plus-or-minus0.95332.30𝑒-20.9533\scriptscriptstyle\pm\scriptstyle 2.30e\text{-}20.9533 ± 2.30 italic_e - 2 0.9643±2.91e-2plus-or-minus0.96432.91𝑒-20.9643\scriptscriptstyle\pm\scriptstyle 2.91e\text{-}20.9643 ± 2.91 italic_e - 2 0.9263±3.41e-2plus-or-minus0.92633.41𝑒-20.9263\scriptscriptstyle\pm\scriptstyle 3.41e\text{-}20.9263 ± 3.41 italic_e - 2
OCC-CLIP 0.9452±3.14𝐞-𝟐plus-or-minus0.94523.14𝐞-2\mathbf{0.9452\scriptscriptstyle\pm\scriptstyle 3.14e\text{-}2}bold_0.9452 ± bold_3.14 bold_e - bold_2 0.9651±1.54𝐞-𝟐plus-or-minus0.96511.54𝐞-2\mathbf{0.9651\scriptscriptstyle\pm\scriptstyle 1.54e\text{-}2}bold_0.9651 ± bold_1.54 bold_e - bold_2 0.9910±7.32𝐞-𝟑plus-or-minus0.99107.32𝐞-3\mathbf{0.9910\scriptscriptstyle\pm\scriptstyle 7.32e\text{-}3}bold_0.9910 ± bold_7.32 bold_e - bold_3 0.9548±1.75𝐞-𝟐plus-or-minus0.95481.75𝐞-2\mathbf{0.9548\scriptscriptstyle\pm\scriptstyle 1.75e\text{-}2}bold_0.9548 ± bold_1.75 bold_e - bold_2
Table 12: Evaluation of OCC-CLIP, along with 14 basic methods. Training samples are sourced from SD (denoted as target) and COCO (denoted as non-target). The test data are assembled from SD as well as a different generative image dataset. The optimal outcomes for individual datasets are emphasized using bold formatting. The metric shown here is Accuracy.
Methods VQ-D LDM Glide GALIP
VGG16 [55] 0.6024±2.78e-2plus-or-minus0.60242.78𝑒-20.6024\scriptscriptstyle\pm\scriptstyle 2.78e\text{-}20.6024 ± 2.78 italic_e - 2 0.5260±1.53e-2plus-or-minus0.52601.53𝑒-20.5260\scriptscriptstyle\pm\scriptstyle 1.53e\text{-}20.5260 ± 1.53 italic_e - 2 0.5396±1.63e-2plus-or-minus0.53961.63𝑒-20.5396\scriptscriptstyle\pm\scriptstyle 1.63e\text{-}20.5396 ± 1.63 italic_e - 2 0.6501±3.44e-2plus-or-minus0.65013.44𝑒-20.6501\scriptscriptstyle\pm\scriptstyle 3.44e\text{-}20.6501 ± 3.44 italic_e - 2
ResNet50 [20] 0.6235±4.71e-2plus-or-minus0.62354.71𝑒-20.6235\scriptscriptstyle\pm\scriptstyle 4.71e\text{-}20.6235 ± 4.71 italic_e - 2 0.5328±2.49e-2plus-or-minus0.53282.49𝑒-20.5328\scriptscriptstyle\pm\scriptstyle 2.49e\text{-}20.5328 ± 2.49 italic_e - 2 0.5764±3.03e-2plus-or-minus0.57643.03𝑒-20.5764\scriptscriptstyle\pm\scriptstyle 3.03e\text{-}20.5764 ± 3.03 italic_e - 2 0.6729±3.43e-2plus-or-minus0.67293.43𝑒-20.6729\scriptscriptstyle\pm\scriptstyle 3.43e\text{-}20.6729 ± 3.43 italic_e - 2
Inception-v3 [58] 0.5999±3.32e-2plus-or-minus0.59993.32𝑒-20.5999\scriptscriptstyle\pm\scriptstyle 3.32e\text{-}20.5999 ± 3.32 italic_e - 2 0.5193±1.29e-2plus-or-minus0.51931.29𝑒-20.5193\scriptscriptstyle\pm\scriptstyle 1.29e\text{-}20.5193 ± 1.29 italic_e - 2 0.5219±1.31e-2plus-or-minus0.52191.31𝑒-20.5219\scriptscriptstyle\pm\scriptstyle 1.31e\text{-}20.5219 ± 1.31 italic_e - 2 0.6297±2.99e-2plus-or-minus0.62972.99𝑒-20.6297\scriptscriptstyle\pm\scriptstyle 2.99e\text{-}20.6297 ± 2.99 italic_e - 2
DenseNet-121 [22] 0.6548±3.33e-2plus-or-minus0.65483.33𝑒-20.6548\scriptscriptstyle\pm\scriptstyle 3.33e\text{-}20.6548 ± 3.33 italic_e - 2 0.5198±2.07e-2plus-or-minus0.51982.07𝑒-20.5198\scriptscriptstyle\pm\scriptstyle 2.07e\text{-}20.5198 ± 2.07 italic_e - 2 0.5423±4.13e-2plus-or-minus0.54234.13𝑒-20.5423\scriptscriptstyle\pm\scriptstyle 4.13e\text{-}20.5423 ± 4.13 italic_e - 2 0.6731±4.53e-2plus-or-minus0.67314.53𝑒-20.6731\scriptscriptstyle\pm\scriptstyle 4.53e\text{-}20.6731 ± 4.53 italic_e - 2
ViT-B-16 [11] 0.6849±2.16e-2plus-or-minus0.68492.16𝑒-20.6849\scriptscriptstyle\pm\scriptstyle 2.16e\text{-}20.6849 ± 2.16 italic_e - 2 0.5188±1.45e-2plus-or-minus0.51881.45𝑒-20.5188\scriptscriptstyle\pm\scriptstyle 1.45e\text{-}20.5188 ± 1.45 italic_e - 2 0.5633±2.55e-2plus-or-minus0.56332.55𝑒-20.5633\scriptscriptstyle\pm\scriptstyle 2.55e\text{-}20.5633 ± 2.55 italic_e - 2 0.7113±1.58e-2plus-or-minus0.71131.58𝑒-20.7113\scriptscriptstyle\pm\scriptstyle 1.58e\text{-}20.7113 ± 1.58 italic_e - 2
DeiT-B-16 [61] 0.6285±3.15e-2plus-or-minus0.62853.15𝑒-20.6285\scriptscriptstyle\pm\scriptstyle 3.15e\text{-}20.6285 ± 3.15 italic_e - 2 0.5245±1.41e-2plus-or-minus0.52451.41𝑒-20.5245\scriptscriptstyle\pm\scriptstyle 1.41e\text{-}20.5245 ± 1.41 italic_e - 2 0.5401±2.25e-2plus-or-minus0.54012.25𝑒-20.5401\scriptscriptstyle\pm\scriptstyle 2.25e\text{-}20.5401 ± 2.25 italic_e - 2 0.6119±2.07e-2plus-or-minus0.61192.07𝑒-20.6119\scriptscriptstyle\pm\scriptstyle 2.07e\text{-}20.6119 ± 2.07 italic_e - 2
CaiT-S-24 [62] 0.6070±3.82e-2plus-or-minus0.60703.82𝑒-20.6070\scriptscriptstyle\pm\scriptstyle 3.82e\text{-}20.6070 ± 3.82 italic_e - 2 0.5216±1.54e-2plus-or-minus0.52161.54𝑒-20.5216\scriptscriptstyle\pm\scriptstyle 1.54e\text{-}20.5216 ± 1.54 italic_e - 2 0.5394±3.41e-2plus-or-minus0.53943.41𝑒-20.5394\scriptscriptstyle\pm\scriptstyle 3.41e\text{-}20.5394 ± 3.41 italic_e - 2 0.6027±3.71e-2plus-or-minus0.60273.71𝑒-20.6027\scriptscriptstyle\pm\scriptstyle 3.71e\text{-}20.6027 ± 3.71 italic_e - 2
Swin-B-4 [36] 0.7796±3.39e-2plus-or-minus0.77963.39𝑒-20.7796\scriptscriptstyle\pm\scriptstyle 3.39e\text{-}20.7796 ± 3.39 italic_e - 2 0.6498±3.57e-2plus-or-minus0.64983.57𝑒-20.6498\scriptscriptstyle\pm\scriptstyle 3.57e\text{-}20.6498 ± 3.57 italic_e - 2 0.6652±2.93e-2plus-or-minus0.66522.93𝑒-20.6652\scriptscriptstyle\pm\scriptstyle 2.93e\text{-}20.6652 ± 2.93 italic_e - 2 0.7623±3.86e-2plus-or-minus0.76233.86𝑒-20.7623\scriptscriptstyle\pm\scriptstyle 3.86e\text{-}20.7623 ± 3.86 italic_e - 2
Image_Patch [39] 0.6143±2.78e-2plus-or-minus0.61432.78𝑒-20.6143\scriptscriptstyle\pm\scriptstyle 2.78e\text{-}20.6143 ± 2.78 italic_e - 2 0.5136±1.13e-2plus-or-minus0.51361.13𝑒-20.5136\scriptscriptstyle\pm\scriptstyle 1.13e\text{-}20.5136 ± 1.13 italic_e - 2 0.5348±2.06e-2plus-or-minus0.53482.06𝑒-20.5348\scriptscriptstyle\pm\scriptstyle 2.06e\text{-}20.5348 ± 2.06 italic_e - 2 0.6341±4.01e-2plus-or-minus0.63414.01𝑒-20.6341\scriptscriptstyle\pm\scriptstyle 4.01e\text{-}20.6341 ± 4.01 italic_e - 2
Feature_Patch [39] 0.6434±1.97e-2plus-or-minus0.64341.97𝑒-20.6434\scriptscriptstyle\pm\scriptstyle 1.97e\text{-}20.6434 ± 1.97 italic_e - 2 0.5767±2.81e-2plus-or-minus0.57672.81𝑒-20.5767\scriptscriptstyle\pm\scriptstyle 2.81e\text{-}20.5767 ± 2.81 italic_e - 2 0.6719±5.89e-2plus-or-minus0.67195.89𝑒-20.6719\scriptscriptstyle\pm\scriptstyle 5.89e\text{-}20.6719 ± 5.89 italic_e - 2 0.5908±3.95e-2plus-or-minus0.59083.95𝑒-20.5908\scriptscriptstyle\pm\scriptstyle 3.95e\text{-}20.5908 ± 3.95 italic_e - 2
CLIP [44] 0.5800±0.0plus-or-minus0.58000.00.5800\scriptscriptstyle\pm\scriptstyle 0.00.5800 ± 0.0 0.5695±0.0plus-or-minus0.56950.00.5695\scriptscriptstyle\pm\scriptstyle 0.00.5695 ± 0.0 0.5475±0.0plus-or-minus0.54750.00.5475\scriptscriptstyle\pm\scriptstyle 0.00.5475 ± 0.0 0.5755±0.0plus-or-minus0.57550.00.5755\scriptscriptstyle\pm\scriptstyle 0.00.5755 ± 0.0
CoOp [71] 0.8457±5.91e-2plus-or-minus0.84575.91𝑒-20.8457\scriptscriptstyle\pm\scriptstyle 5.91e\text{-}20.8457 ± 5.91 italic_e - 2 0.6745±7.54e-2plus-or-minus0.67457.54𝑒-20.6745\scriptscriptstyle\pm\scriptstyle 7.54e\text{-}20.6745 ± 7.54 italic_e - 2 0.8041±7.07e-2plus-or-minus0.80417.07𝑒-20.8041\scriptscriptstyle\pm\scriptstyle 7.07e\text{-}20.8041 ± 7.07 italic_e - 2 0.8722±5.88e-2plus-or-minus0.87225.88𝑒-20.8722\scriptscriptstyle\pm\scriptstyle 5.88e\text{-}20.8722 ± 5.88 italic_e - 2
OCC-CLIP 0.9118±1.73𝐞-𝟐plus-or-minus0.91181.73𝐞-2\mathbf{0.9118\scriptscriptstyle\pm\scriptstyle 1.73e\text{-}2}bold_0.9118 ± bold_1.73 bold_e - bold_2 0.7654±3.28𝐞-𝟐plus-or-minus0.76543.28𝐞-2\mathbf{0.7654\scriptscriptstyle\pm\scriptstyle 3.28e\text{-}2}bold_0.7654 ± bold_3.28 bold_e - bold_2 0.8783±2.20𝐞-𝟐plus-or-minus0.87832.20𝐞-2\mathbf{0.8783\scriptscriptstyle\pm\scriptstyle 2.20e\text{-}2}bold_0.8783 ± bold_2.20 bold_e - bold_2 0.9227±1.91𝐞-𝟐plus-or-minus0.92271.91𝐞-2\mathbf{0.9227\scriptscriptstyle\pm\scriptstyle 1.91e\text{-}2}bold_0.9227 ± bold_1.91 bold_e - bold_2
Table 13: Evaluation of OCC-CLIP, along with 14 basic methods. Training samples are sourced from SD (denoted as target) and COCO (denoted as non-target). The test data are assembled from SD as well as a different generative image dataset. The optimal outcomes for individual datasets are emphasized using bold formatting. The metric shown here is Accuracy.
Methods ProGan StyleGan2 GauGan Overall
VGG16 [55] 0.6218±4.14e-2plus-or-minus0.62184.14𝑒-20.6218\scriptscriptstyle\pm\scriptstyle 4.14e\text{-}20.6218 ± 4.14 italic_e - 2 0.5939±5.57e-2plus-or-minus0.59395.57𝑒-20.5939\scriptscriptstyle\pm\scriptstyle 5.57e\text{-}20.5939 ± 5.57 italic_e - 2 0.6597±3.82e-2plus-or-minus0.65973.82𝑒-20.6597\scriptscriptstyle\pm\scriptstyle 3.82e\text{-}20.6597 ± 3.82 italic_e - 2 0.5991±3.53e-2plus-or-minus0.59913.53𝑒-20.5991\scriptscriptstyle\pm\scriptstyle 3.53e\text{-}20.5991 ± 3.53 italic_e - 2
ResNet50 [20] 0.6157±3.92e-2plus-or-minus0.61573.92𝑒-20.6157\scriptscriptstyle\pm\scriptstyle 3.92e\text{-}20.6157 ± 3.92 italic_e - 2 0.5910±6.70e-2plus-or-minus0.59106.70𝑒-20.5910\scriptscriptstyle\pm\scriptstyle 6.70e\text{-}20.5910 ± 6.70 italic_e - 2 0.6858±2.48e-2plus-or-minus0.68582.48𝑒-20.6858\scriptscriptstyle\pm\scriptstyle 2.48e\text{-}20.6858 ± 2.48 italic_e - 2 0.6140±4.07e-2plus-or-minus0.61404.07𝑒-20.6140\scriptscriptstyle\pm\scriptstyle 4.07e\text{-}20.6140 ± 4.07 italic_e - 2
Inception-v3 [58] 0.6045±3.65e-2plus-or-minus0.60453.65𝑒-20.6045\scriptscriptstyle\pm\scriptstyle 3.65e\text{-}20.6045 ± 3.65 italic_e - 2 0.5711±3.59e-2plus-or-minus0.57113.59𝑒-20.5711\scriptscriptstyle\pm\scriptstyle 3.59e\text{-}20.5711 ± 3.59 italic_e - 2 0.6455±2.96e-2plus-or-minus0.64552.96𝑒-20.6455\scriptscriptstyle\pm\scriptstyle 2.96e\text{-}20.6455 ± 2.96 italic_e - 2 0.5846±2.88e-2plus-or-minus0.58462.88𝑒-20.5846\scriptscriptstyle\pm\scriptstyle 2.88e\text{-}20.5846 ± 2.88 italic_e - 2
DenseNet-121 [22] 0.6556±3.34e-2plus-or-minus0.65563.34𝑒-20.6556\scriptscriptstyle\pm\scriptstyle 3.34e\text{-}20.6556 ± 3.34 italic_e - 2 0.5967±5.24e-2plus-or-minus0.59675.24𝑒-20.5967\scriptscriptstyle\pm\scriptstyle 5.24e\text{-}20.5967 ± 5.24 italic_e - 2 0.7276±2.66e-2plus-or-minus0.72762.66𝑒-20.7276\scriptscriptstyle\pm\scriptstyle 2.66e\text{-}20.7276 ± 2.66 italic_e - 2 0.6243±3.76e-2plus-or-minus0.62433.76𝑒-20.6243\scriptscriptstyle\pm\scriptstyle 3.76e\text{-}20.6243 ± 3.76 italic_e - 2
ViT-B-16 [11] 0.5649±2.79e-2plus-or-minus0.56492.79𝑒-20.5649\scriptscriptstyle\pm\scriptstyle 2.79e\text{-}20.5649 ± 2.79 italic_e - 2 0.6148±4.20e-2plus-or-minus0.61484.20𝑒-20.6148\scriptscriptstyle\pm\scriptstyle 4.20e\text{-}20.6148 ± 4.20 italic_e - 2 0.6606±2.62e-2plus-or-minus0.66062.62𝑒-20.6606\scriptscriptstyle\pm\scriptstyle 2.62e\text{-}20.6606 ± 2.62 italic_e - 2 0.6169±2.62e-2plus-or-minus0.61692.62𝑒-20.6169\scriptscriptstyle\pm\scriptstyle 2.62e\text{-}20.6169 ± 2.62 italic_e - 2
DeiT-B-16 [61] 0.5451±2.04e-2plus-or-minus0.54512.04𝑒-20.5451\scriptscriptstyle\pm\scriptstyle 2.04e\text{-}20.5451 ± 2.04 italic_e - 2 0.5601±3.47e-2plus-or-minus0.56013.47𝑒-20.5601\scriptscriptstyle\pm\scriptstyle 3.47e\text{-}20.5601 ± 3.47 italic_e - 2 0.6051±2.08e-2plus-or-minus0.60512.08𝑒-20.6051\scriptscriptstyle\pm\scriptstyle 2.08e\text{-}20.6051 ± 2.08 italic_e - 2 0.5736±2.44e-2plus-or-minus0.57362.44𝑒-20.5736\scriptscriptstyle\pm\scriptstyle 2.44e\text{-}20.5736 ± 2.44 italic_e - 2
CaiT-S-24 [62] 0.5437±2.33e-2plus-or-minus0.54372.33𝑒-20.5437\scriptscriptstyle\pm\scriptstyle 2.33e\text{-}20.5437 ± 2.33 italic_e - 2 0.5468±3.63e-2plus-or-minus0.54683.63𝑒-20.5468\scriptscriptstyle\pm\scriptstyle 3.63e\text{-}20.5468 ± 3.63 italic_e - 2 0.6166±2.68e-2plus-or-minus0.61662.68𝑒-20.6166\scriptscriptstyle\pm\scriptstyle 2.68e\text{-}20.6166 ± 2.68 italic_e - 2 0.5683±3.12e-2plus-or-minus0.56833.12𝑒-20.5683\scriptscriptstyle\pm\scriptstyle 3.12e\text{-}20.5683 ± 3.12 italic_e - 2
Swin-B-4 [36] 0.5378±1.82e-2plus-or-minus0.53781.82𝑒-20.5378\scriptscriptstyle\pm\scriptstyle 1.82e\text{-}20.5378 ± 1.82 italic_e - 2 0.6057±3.40e-2plus-or-minus0.60573.40𝑒-20.6057\scriptscriptstyle\pm\scriptstyle 3.40e\text{-}20.6057 ± 3.40 italic_e - 2 0.6929±3.75e-2plus-or-minus0.69293.75𝑒-20.6929\scriptscriptstyle\pm\scriptstyle 3.75e\text{-}20.6929 ± 3.75 italic_e - 2 0.6705±3.31e-2plus-or-minus0.67053.31𝑒-20.6705\scriptscriptstyle\pm\scriptstyle 3.31e\text{-}20.6705 ± 3.31 italic_e - 2
Image_Patch [39] 0.6128±4.33e-2plus-or-minus0.61284.33𝑒-20.6128\scriptscriptstyle\pm\scriptstyle 4.33e\text{-}20.6128 ± 4.33 italic_e - 2 0.6230±7.13e-2plus-or-minus0.62307.13𝑒-20.6230\scriptscriptstyle\pm\scriptstyle 7.13e\text{-}20.6230 ± 7.13 italic_e - 2 0.7010±3.19e-2plus-or-minus0.70103.19𝑒-20.7010\scriptscriptstyle\pm\scriptstyle 3.19e\text{-}20.7010 ± 3.19 italic_e - 2 0.6048±3.95e-2plus-or-minus0.60483.95𝑒-20.6048\scriptscriptstyle\pm\scriptstyle 3.95e\text{-}20.6048 ± 3.95 italic_e - 2
Feature_Patch [39] 0.6582±2.29e-2plus-or-minus0.65822.29𝑒-20.6582\scriptscriptstyle\pm\scriptstyle 2.29e\text{-}20.6582 ± 2.29 italic_e - 2 0.7678±1.65e-2plus-or-minus0.76781.65𝑒-20.7678\scriptscriptstyle\pm\scriptstyle 1.65e\text{-}20.7678 ± 1.65 italic_e - 2 0.7333±2.30e-2plus-or-minus0.73332.30𝑒-20.7333\scriptscriptstyle\pm\scriptstyle 2.30e\text{-}20.7333 ± 2.30 italic_e - 2 0.6632±3.28e-2plus-or-minus0.66323.28𝑒-20.6632\scriptscriptstyle\pm\scriptstyle 3.28e\text{-}20.6632 ± 3.28 italic_e - 2
CLIP [44] 0.5415±0.0plus-or-minus0.54150.00.5415\scriptscriptstyle\pm\scriptstyle 0.00.5415 ± 0.0 0.5860±0.0plus-or-minus0.58600.00.5860\scriptscriptstyle\pm\scriptstyle 0.00.5860 ± 0.0 0.5170±0.0plus-or-minus0.51700.00.5170\scriptscriptstyle\pm\scriptstyle 0.00.5170 ± 0.0 0.5645±0.0plus-or-minus0.56450.00.5645\scriptscriptstyle\pm\scriptstyle 0.00.5645 ± 0.0
CoOp [71] 0.7053±8.57e-2plus-or-minus0.70538.57𝑒-20.7053\scriptscriptstyle\pm\scriptstyle 8.57e\text{-}20.7053 ± 8.57 italic_e - 2 0.8540±5.87e-2plus-or-minus0.85405.87𝑒-20.8540\scriptscriptstyle\pm\scriptstyle 5.87e\text{-}20.8540 ± 5.87 italic_e - 2 0.8854±3.84e-2plus-or-minus0.88543.84𝑒-20.8854\scriptscriptstyle\pm\scriptstyle 3.84e\text{-}20.8854 ± 3.84 italic_e - 2 0.8059±6.54e-2plus-or-minus0.80596.54𝑒-20.8059\scriptscriptstyle\pm\scriptstyle 6.54e\text{-}20.8059 ± 6.54 italic_e - 2
OCC-CLIP 0.8635±5.26𝐞-𝟐plus-or-minus0.86355.26𝐞-2\mathbf{0.8635\scriptscriptstyle\pm\scriptstyle 5.26e\text{-}2}bold_0.8635 ± bold_5.26 bold_e - bold_2 0.8939±2.69𝐞-𝟐plus-or-minus0.89392.69𝐞-2\mathbf{0.8939\scriptscriptstyle\pm\scriptstyle 2.69e\text{-}2}bold_0.8939 ± bold_2.69 bold_e - bold_2 0.9409±1.79𝐞-𝟐plus-or-minus0.94091.79𝐞-2\mathbf{0.9409\scriptscriptstyle\pm\scriptstyle 1.79e\text{-}2}bold_0.9409 ± bold_1.79 bold_e - bold_2 0.8824±2.94𝐞-𝟐plus-or-minus0.88242.94𝐞-2\mathbf{0.8824\scriptscriptstyle\pm\scriptstyle 2.94e\text{-}2}bold_0.8824 ± bold_2.94 bold_e - bold_2
Table 14: Evaluation sensitivity of OCC-CLIP to Source Models and choice of Epsilon. The leftmost column represents target datasets. In training phase, the non-target images are from COCO. In testing phase, the non-target images are from a different generative image dataset shown in the first row. Different epsilon is chosen: 0.0, 0.03125, 0.0625, 0.1, 0.2, andm 0.5. The optimal outcomes for individual datasets are emphasized using bold formatting.
Target Epsilon SDLAION-5B VQ-Dcoco LDMLAION-400M Glidefiltered-cc
SDLAION-5B 0.0 - 0.9503±1.68e-2plus-or-minus0.95031.68𝑒-20.9503\scriptscriptstyle\pm\scriptstyle 1.68e\text{-}20.9503 ± 1.68 italic_e - 2 0.8373±5.33e-2plus-or-minus0.83735.33𝑒-20.8373\scriptscriptstyle\pm\scriptstyle 5.33e\text{-}20.8373 ± 5.33 italic_e - 2 0.9266±3.19e-2plus-or-minus0.92663.19𝑒-20.9266\scriptscriptstyle\pm\scriptstyle 3.19e\text{-}20.9266 ± 3.19 italic_e - 2
0.03125 - 0.9627±1.74e-2plus-or-minus0.96271.74𝑒-20.9627\scriptscriptstyle\pm\scriptstyle 1.74e\text{-}20.9627 ± 1.74 italic_e - 2 0.8782±4.48e-2plus-or-minus0.87824.48𝑒-20.8782\scriptscriptstyle\pm\scriptstyle 4.48e\text{-}20.8782 ± 4.48 italic_e - 2 0.9248±3.58e-2plus-or-minus0.92483.58𝑒-20.9248\scriptscriptstyle\pm\scriptstyle 3.58e\text{-}20.9248 ± 3.58 italic_e - 2
0.0625 - 0.9644±1.73e-2plus-or-minus0.96441.73𝑒-20.9644\scriptscriptstyle\pm\scriptstyle 1.73e\text{-}20.9644 ± 1.73 italic_e - 2 0.8720±3.74e-2plus-or-minus0.87203.74𝑒-20.8720\scriptscriptstyle\pm\scriptstyle 3.74e\text{-}20.8720 ± 3.74 italic_e - 2 0.9332±3.10e-2plus-or-minus0.93323.10𝑒-20.9332\scriptscriptstyle\pm\scriptstyle 3.10e\text{-}20.9332 ± 3.10 italic_e - 2
0.1 - 0.9703±9.06𝐞-𝟑plus-or-minus0.97039.06𝐞-3\mathbf{0.9703\scriptscriptstyle\pm\scriptstyle 9.06e\text{-}3}bold_0.9703 ± bold_9.06 bold_e - bold_3 0.8801±2.06𝐞-𝟐plus-or-minus0.88012.06𝐞-2\mathbf{0.8801\scriptscriptstyle\pm\scriptstyle 2.06e\text{-}2}bold_0.8801 ± bold_2.06 bold_e - bold_2 0.9519±1.45𝐞-𝟐plus-or-minus0.95191.45𝐞-2\mathbf{0.9519\scriptscriptstyle\pm\scriptstyle 1.45e\text{-}2}bold_0.9519 ± bold_1.45 bold_e - bold_2
0.2 - 0.9595±1.49e-2plus-or-minus0.95951.49𝑒-20.9595\scriptscriptstyle\pm\scriptstyle 1.49e\text{-}20.9595 ± 1.49 italic_e - 2 0.8456±4.05e-2plus-or-minus0.84564.05𝑒-20.8456\scriptscriptstyle\pm\scriptstyle 4.05e\text{-}20.8456 ± 4.05 italic_e - 2 0.9388±2.54e-2plus-or-minus0.93882.54𝑒-20.9388\scriptscriptstyle\pm\scriptstyle 2.54e\text{-}20.9388 ± 2.54 italic_e - 2
0.5 - 0.9601±1.76e-2plus-or-minus0.96011.76𝑒-20.9601\scriptscriptstyle\pm\scriptstyle 1.76e\text{-}20.9601 ± 1.76 italic_e - 2 0.8475±4.87e-2plus-or-minus0.84754.87𝑒-20.8475\scriptscriptstyle\pm\scriptstyle 4.87e\text{-}20.8475 ± 4.87 italic_e - 2 0.9384±3.18e-2plus-or-minus0.93843.18𝑒-20.9384\scriptscriptstyle\pm\scriptstyle 3.18e\text{-}20.9384 ± 3.18 italic_e - 2
VQ-Dcoco 0.0 0.9988±9.79e-4plus-or-minus0.99889.79𝑒-40.9988\scriptscriptstyle\pm\scriptstyle 9.79e\text{-}40.9988 ± 9.79 italic_e - 4 - 0.7337±4.63𝐞-𝟐plus-or-minus0.73374.63𝐞-2\mathbf{0.7337\scriptscriptstyle\pm\scriptstyle 4.63e\text{-}2}bold_0.7337 ± bold_4.63 bold_e - bold_2 0.7435±4.39e-2plus-or-minus0.74354.39𝑒-20.7435\scriptscriptstyle\pm\scriptstyle 4.39e\text{-}20.7435 ± 4.39 italic_e - 2
0.03125 0.9982±5.66e-4plus-or-minus0.99825.66𝑒-40.9982\scriptscriptstyle\pm\scriptstyle 5.66e\text{-}40.9982 ± 5.66 italic_e - 4 - 0.7077±4.06e-2plus-or-minus0.70774.06𝑒-20.7077\scriptscriptstyle\pm\scriptstyle 4.06e\text{-}20.7077 ± 4.06 italic_e - 2 0.6988±4.61e-2plus-or-minus0.69884.61𝑒-20.6988\scriptscriptstyle\pm\scriptstyle 4.61e\text{-}20.6988 ± 4.61 italic_e - 2
0.0625 0.9986±1.08e-3plus-or-minus0.99861.08𝑒-30.9986\scriptscriptstyle\pm\scriptstyle 1.08e\text{-}30.9986 ± 1.08 italic_e - 3 - 0.6783±5.50e-2plus-or-minus0.67835.50𝑒-20.6783\scriptscriptstyle\pm\scriptstyle 5.50e\text{-}20.6783 ± 5.50 italic_e - 2 0.7112±5.12e-2plus-or-minus0.71125.12𝑒-20.7112\scriptscriptstyle\pm\scriptstyle 5.12e\text{-}20.7112 ± 5.12 italic_e - 2
0.1 0.9992±6.54e-4plus-or-minus0.99926.54𝑒-40.9992\scriptscriptstyle\pm\scriptstyle 6.54e\text{-}40.9992 ± 6.54 italic_e - 4 - 0.6924±6.56e-2plus-or-minus0.69246.56𝑒-20.6924\scriptscriptstyle\pm\scriptstyle 6.56e\text{-}20.6924 ± 6.56 italic_e - 2 0.7264±5.62e-2plus-or-minus0.72645.62𝑒-20.7264\scriptscriptstyle\pm\scriptstyle 5.62e\text{-}20.7264 ± 5.62 italic_e - 2
0.2 0.9992±3.85e-4plus-or-minus0.99923.85𝑒-40.9992\scriptscriptstyle\pm\scriptstyle 3.85e\text{-}40.9992 ± 3.85 italic_e - 4 - 0.6998±3.20e-2plus-or-minus0.69983.20𝑒-20.6998\scriptscriptstyle\pm\scriptstyle 3.20e\text{-}20.6998 ± 3.20 italic_e - 2 0.7478±4.84𝐞-𝟐plus-or-minus0.74784.84𝐞-2\mathbf{0.7478\scriptscriptstyle\pm\scriptstyle 4.84e\text{-}2}bold_0.7478 ± bold_4.84 bold_e - bold_2
0.5 0.9994±3.74𝐞-𝟒plus-or-minus0.99943.74𝐞-4\mathbf{0.9994\scriptscriptstyle\pm\scriptstyle 3.74e\text{-}4}bold_0.9994 ± bold_3.74 bold_e - bold_4 - 0.6887±5.88e-2plus-or-minus0.68875.88𝑒-20.6887\scriptscriptstyle\pm\scriptstyle 5.88e\text{-}20.6887 ± 5.88 italic_e - 2 0.7468±4.32e-2plus-or-minus0.74684.32𝑒-20.7468\scriptscriptstyle\pm\scriptstyle 4.32e\text{-}20.7468 ± 4.32 italic_e - 2
LDMLAION-400M 0.0 0.9925±7.39e-3plus-or-minus0.99257.39𝑒-30.9925\scriptscriptstyle\pm\scriptstyle 7.39e\text{-}30.9925 ± 7.39 italic_e - 3 0.6793±6.63e-2plus-or-minus0.67936.63𝑒-20.6793\scriptscriptstyle\pm\scriptstyle 6.63e\text{-}20.6793 ± 6.63 italic_e - 2 - 0.6468±6.15e-2plus-or-minus0.64686.15𝑒-20.6468\scriptscriptstyle\pm\scriptstyle 6.15e\text{-}20.6468 ± 6.15 italic_e - 2
0.03125 0.9941±4.49e-3plus-or-minus0.99414.49𝑒-30.9941\scriptscriptstyle\pm\scriptstyle 4.49e\text{-}30.9941 ± 4.49 italic_e - 3 0.7295±3.77e-2plus-or-minus0.72953.77𝑒-20.7295\scriptscriptstyle\pm\scriptstyle 3.77e\text{-}20.7295 ± 3.77 italic_e - 2 - 0.6502±6.56e-2plus-or-minus0.65026.56𝑒-20.6502\scriptscriptstyle\pm\scriptstyle 6.56e\text{-}20.6502 ± 6.56 italic_e - 2
0.0625 0.9945±5.66e-3plus-or-minus0.99455.66𝑒-30.9945\scriptscriptstyle\pm\scriptstyle 5.66e\text{-}30.9945 ± 5.66 italic_e - 3 0.7473±4.92e-2plus-or-minus0.74734.92𝑒-20.7473\scriptscriptstyle\pm\scriptstyle 4.92e\text{-}20.7473 ± 4.92 italic_e - 2 - 0.6761±5.30e-2plus-or-minus0.67615.30𝑒-20.6761\scriptscriptstyle\pm\scriptstyle 5.30e\text{-}20.6761 ± 5.30 italic_e - 2
0.1 0.9957±3.97e-3plus-or-minus0.99573.97𝑒-30.9957\scriptscriptstyle\pm\scriptstyle 3.97e\text{-}30.9957 ± 3.97 italic_e - 3 0.7507±5.51𝐞-𝟐plus-or-minus0.75075.51𝐞-2\mathbf{0.7507\scriptscriptstyle\pm\scriptstyle 5.51e\text{-}2}bold_0.7507 ± bold_5.51 bold_e - bold_2 - 0.6847±5.32e-2plus-or-minus0.68475.32𝑒-20.6847\scriptscriptstyle\pm\scriptstyle 5.32e\text{-}20.6847 ± 5.32 italic_e - 2
0.2 0.9958±2.73𝐞-𝟑plus-or-minus0.99582.73𝐞-3\mathbf{0.9958\scriptscriptstyle\pm\scriptstyle 2.73e\text{-}3}bold_0.9958 ± bold_2.73 bold_e - bold_3 0.7461±5.98e-2plus-or-minus0.74615.98𝑒-20.7461\scriptscriptstyle\pm\scriptstyle 5.98e\text{-}20.7461 ± 5.98 italic_e - 2 - 0.6980±6.25e-2plus-or-minus0.69806.25𝑒-20.6980\scriptscriptstyle\pm\scriptstyle 6.25e\text{-}20.6980 ± 6.25 italic_e - 2
0.5 0.9951±3.13e-3plus-or-minus0.99513.13𝑒-30.9951\scriptscriptstyle\pm\scriptstyle 3.13e\text{-}30.9951 ± 3.13 italic_e - 3 0.7404±5.12e-2plus-or-minus0.74045.12𝑒-20.7404\scriptscriptstyle\pm\scriptstyle 5.12e\text{-}20.7404 ± 5.12 italic_e - 2 - 0.7142±3.77𝐞-𝟐plus-or-minus0.71423.77𝐞-2\mathbf{0.7142\scriptscriptstyle\pm\scriptstyle 3.77e\text{-}2}bold_0.7142 ± bold_3.77 bold_e - bold_2
Glidefiltered-cc 0.0 0.9985±1.86e-3plus-or-minus0.99851.86𝑒-30.9985\scriptscriptstyle\pm\scriptstyle 1.86e\text{-}30.9985 ± 1.86 italic_e - 3 0.8573±4.27e-2plus-or-minus0.85734.27𝑒-20.8573\scriptscriptstyle\pm\scriptstyle 4.27e\text{-}20.8573 ± 4.27 italic_e - 2 0.8314±3.08e-2plus-or-minus0.83143.08𝑒-20.8314\scriptscriptstyle\pm\scriptstyle 3.08e\text{-}20.8314 ± 3.08 italic_e - 2 -
0.03125 0.9997±3.16e-4plus-or-minus0.99973.16𝑒-40.9997\scriptscriptstyle\pm\scriptstyle 3.16e\text{-}40.9997 ± 3.16 italic_e - 4 0.8970±1.53e-2plus-or-minus0.89701.53𝑒-20.8970\scriptscriptstyle\pm\scriptstyle 1.53e\text{-}20.8970 ± 1.53 italic_e - 2 0.8553±2.96e-2plus-or-minus0.85532.96𝑒-20.8553\scriptscriptstyle\pm\scriptstyle 2.96e\text{-}20.8553 ± 2.96 italic_e - 2 -
0.0625 0.9998±1.90e-4plus-or-minus0.99981.90𝑒-40.9998\scriptscriptstyle\pm\scriptstyle 1.90e\text{-}40.9998 ± 1.90 italic_e - 4 0.8919±1.76e-2plus-or-minus0.89191.76𝑒-20.8919\scriptscriptstyle\pm\scriptstyle 1.76e\text{-}20.8919 ± 1.76 italic_e - 2 0.8559±2.49e-2plus-or-minus0.85592.49𝑒-20.8559\scriptscriptstyle\pm\scriptstyle 2.49e\text{-}20.8559 ± 2.49 italic_e - 2 -
0.1 0.9998±2.47e-4plus-or-minus0.99982.47𝑒-40.9998\scriptscriptstyle\pm\scriptstyle 2.47e\text{-}40.9998 ± 2.47 italic_e - 4 0.8958±2.18e-2plus-or-minus0.89582.18𝑒-20.8958\scriptscriptstyle\pm\scriptstyle 2.18e\text{-}20.8958 ± 2.18 italic_e - 2 0.8585±2.50e-2plus-or-minus0.85852.50𝑒-20.8585\scriptscriptstyle\pm\scriptstyle 2.50e\text{-}20.8585 ± 2.50 italic_e - 2 -
0.2 0.9999±1.18e-4plus-or-minus0.99991.18𝑒-40.9999\scriptscriptstyle\pm\scriptstyle 1.18e\text{-}40.9999 ± 1.18 italic_e - 4 0.9073±1.04𝐞-𝟐plus-or-minus0.90731.04𝐞-2\mathbf{0.9073\scriptscriptstyle\pm\scriptstyle 1.04e\text{-}2}bold_0.9073 ± bold_1.04 bold_e - bold_2 0.8731±2.42𝐞-𝟐plus-or-minus0.87312.42𝐞-2\mathbf{0.8731\scriptscriptstyle\pm\scriptstyle 2.42e\text{-}2}bold_0.8731 ± bold_2.42 bold_e - bold_2 -
0.5 0.9999±1.08𝐞-𝟒plus-or-minus0.99991.08𝐞-4\mathbf{0.9999\scriptscriptstyle\pm\scriptstyle 1.08e\text{-}4}bold_0.9999 ± bold_1.08 bold_e - bold_4 0.8898±2.37e-2plus-or-minus0.88982.37𝑒-20.8898\scriptscriptstyle\pm\scriptstyle 2.37e\text{-}20.8898 ± 2.37 italic_e - 2 0.8724±3.14e-2plus-or-minus0.87243.14𝑒-20.8724\scriptscriptstyle\pm\scriptstyle 3.14e\text{-}20.8724 ± 3.14 italic_e - 2 -
GALIPcoco 0.0 0.9999±2.29e-4plus-or-minus0.99992.29𝑒-40.9999\scriptscriptstyle\pm\scriptstyle 2.29e\text{-}40.9999 ± 2.29 italic_e - 4 0.9036±2.75e-2plus-or-minus0.90362.75𝑒-20.9036\scriptscriptstyle\pm\scriptstyle 2.75e\text{-}20.9036 ± 2.75 italic_e - 2 0.8441±4.62e-2plus-or-minus0.84414.62𝑒-20.8441\scriptscriptstyle\pm\scriptstyle 4.62e\text{-}20.8441 ± 4.62 italic_e - 2 0.7802±4.74e-2plus-or-minus0.78024.74𝑒-20.7802\scriptscriptstyle\pm\scriptstyle 4.74e\text{-}20.7802 ± 4.74 italic_e - 2
0.03125 0.9996±1.85e-4plus-or-minus0.99961.85𝑒-40.9996\scriptscriptstyle\pm\scriptstyle 1.85e\text{-}40.9996 ± 1.85 italic_e - 4 0.8970±4.26e-2plus-or-minus0.89704.26𝑒-20.8970\scriptscriptstyle\pm\scriptstyle 4.26e\text{-}20.8970 ± 4.26 italic_e - 2 0.8256±3.54e-2plus-or-minus0.82563.54𝑒-20.8256\scriptscriptstyle\pm\scriptstyle 3.54e\text{-}20.8256 ± 3.54 italic_e - 2 0.7044±3.36e-2plus-or-minus0.70443.36𝑒-20.7044\scriptscriptstyle\pm\scriptstyle 3.36e\text{-}20.7044 ± 3.36 italic_e - 2
0.0625 0.9998±1.83e-4plus-or-minus0.99981.83𝑒-40.9998\scriptscriptstyle\pm\scriptstyle 1.83e\text{-}40.9998 ± 1.83 italic_e - 4 0.9205±2.30e-2plus-or-minus0.92052.30𝑒-20.9205\scriptscriptstyle\pm\scriptstyle 2.30e\text{-}20.9205 ± 2.30 italic_e - 2 0.8165±3.54e-2plus-or-minus0.81653.54𝑒-20.8165\scriptscriptstyle\pm\scriptstyle 3.54e\text{-}20.8165 ± 3.54 italic_e - 2 0.7545±4.19e-2plus-or-minus0.75454.19𝑒-20.7545\scriptscriptstyle\pm\scriptstyle 4.19e\text{-}20.7545 ± 4.19 italic_e - 2
0.1 0.9999±8.94e-5plus-or-minus0.99998.94𝑒-50.9999\scriptscriptstyle\pm\scriptstyle 8.94e\text{-}50.9999 ± 8.94 italic_e - 5 0.9345±1.99e-2plus-or-minus0.93451.99𝑒-20.9345\scriptscriptstyle\pm\scriptstyle 1.99e\text{-}20.9345 ± 1.99 italic_e - 2 0.8626±1.99e-2plus-or-minus0.86261.99𝑒-20.8626\scriptscriptstyle\pm\scriptstyle 1.99e\text{-}20.8626 ± 1.99 italic_e - 2 0.7779±2.88e-2plus-or-minus0.77792.88𝑒-20.7779\scriptscriptstyle\pm\scriptstyle 2.88e\text{-}20.7779 ± 2.88 italic_e - 2
0.2 0.9999±6.40e-5plus-or-minus0.99996.40𝑒-50.9999\scriptscriptstyle\pm\scriptstyle 6.40e\text{-}50.9999 ± 6.40 italic_e - 5 0.9380±1.81𝐞-𝟐plus-or-minus0.93801.81𝐞-2\mathbf{0.9380\scriptscriptstyle\pm\scriptstyle 1.81e\text{-}2}bold_0.9380 ± bold_1.81 bold_e - bold_2 0.8776±2.96e-2plus-or-minus0.87762.96𝑒-20.8776\scriptscriptstyle\pm\scriptstyle 2.96e\text{-}20.8776 ± 2.96 italic_e - 2 0.8238±2.09e-2plus-or-minus0.82382.09𝑒-20.8238\scriptscriptstyle\pm\scriptstyle 2.09e\text{-}20.8238 ± 2.09 italic_e - 2
0.5 1.0000±4.00𝐞-𝟓plus-or-minus1.00004.00𝐞-5\mathbf{1.0000\scriptscriptstyle\pm\scriptstyle 4.00e\text{-}5}bold_1.0000 ± bold_4.00 bold_e - bold_5 0.9332±1.57e-2plus-or-minus0.93321.57𝑒-20.9332\scriptscriptstyle\pm\scriptstyle 1.57e\text{-}20.9332 ± 1.57 italic_e - 2 0.8907±3.24𝐞-𝟐plus-or-minus0.89073.24𝐞-2\mathbf{0.8907\scriptscriptstyle\pm\scriptstyle 3.24e\text{-}2}bold_0.8907 ± bold_3.24 bold_e - bold_2 0.8361±1.73𝐞-𝟐plus-or-minus0.83611.73𝐞-2\mathbf{0.8361\scriptscriptstyle\pm\scriptstyle 1.73e\text{-}2}bold_0.8361 ± bold_1.73 bold_e - bold_2
ProGanlsun 0.0 0.9972±1.91e-3plus-or-minus0.99721.91𝑒-30.9972\scriptscriptstyle\pm\scriptstyle 1.91e\text{-}30.9972 ± 1.91 italic_e - 3 0.9475±2.01e-2plus-or-minus0.94752.01𝑒-20.9475\scriptscriptstyle\pm\scriptstyle 2.01e\text{-}20.9475 ± 2.01 italic_e - 2 0.9544±1.86e-2plus-or-minus0.95441.86𝑒-20.9544\scriptscriptstyle\pm\scriptstyle 1.86e\text{-}20.9544 ± 1.86 italic_e - 2 0.9453±2.00e-2plus-or-minus0.94532.00𝑒-20.9453\scriptscriptstyle\pm\scriptstyle 2.00e\text{-}20.9453 ± 2.00 italic_e - 2
0.03125 0.9904±6.10e-3plus-or-minus0.99046.10𝑒-30.9904\scriptscriptstyle\pm\scriptstyle 6.10e\text{-}30.9904 ± 6.10 italic_e - 3 0.9429±2.49e-2plus-or-minus0.94292.49𝑒-20.9429\scriptscriptstyle\pm\scriptstyle 2.49e\text{-}20.9429 ± 2.49 italic_e - 2 0.9646±2.12e-2plus-or-minus0.96462.12𝑒-20.9646\scriptscriptstyle\pm\scriptstyle 2.12e\text{-}20.9646 ± 2.12 italic_e - 2 0.8852±5.46e-2plus-or-minus0.88525.46𝑒-20.8852\scriptscriptstyle\pm\scriptstyle 5.46e\text{-}20.8852 ± 5.46 italic_e - 2
0.0625 0.9934±4.67e-3plus-or-minus0.99344.67𝑒-30.9934\scriptscriptstyle\pm\scriptstyle 4.67e\text{-}30.9934 ± 4.67 italic_e - 3 0.9313±3.26e-2plus-or-minus0.93133.26𝑒-20.9313\scriptscriptstyle\pm\scriptstyle 3.26e\text{-}20.9313 ± 3.26 italic_e - 2 0.9517±2.18e-2plus-or-minus0.95172.18𝑒-20.9517\scriptscriptstyle\pm\scriptstyle 2.18e\text{-}20.9517 ± 2.18 italic_e - 2 0.8868±4.72e-2plus-or-minus0.88684.72𝑒-20.8868\scriptscriptstyle\pm\scriptstyle 4.72e\text{-}20.8868 ± 4.72 italic_e - 2
0.1 0.9961±3.27e-3plus-or-minus0.99613.27𝑒-30.9961\scriptscriptstyle\pm\scriptstyle 3.27e\text{-}30.9961 ± 3.27 italic_e - 3 0.9477±2.46e-2plus-or-minus0.94772.46𝑒-20.9477\scriptscriptstyle\pm\scriptstyle 2.46e\text{-}20.9477 ± 2.46 italic_e - 2 0.9585±2.58e-2plus-or-minus0.95852.58𝑒-20.9585\scriptscriptstyle\pm\scriptstyle 2.58e\text{-}20.9585 ± 2.58 italic_e - 2 0.9320±3.59e-2plus-or-minus0.93203.59𝑒-20.9320\scriptscriptstyle\pm\scriptstyle 3.59e\text{-}20.9320 ± 3.59 italic_e - 2
0.2 0.9970±1.73e-3plus-or-minus0.99701.73𝑒-30.9970\scriptscriptstyle\pm\scriptstyle 1.73e\text{-}30.9970 ± 1.73 italic_e - 3 0.9689±7.48e-3plus-or-minus0.96897.48𝑒-30.9689\scriptscriptstyle\pm\scriptstyle 7.48e\text{-}30.9689 ± 7.48 italic_e - 3 0.9762±7.41e-3plus-or-minus0.97627.41𝑒-30.9762\scriptscriptstyle\pm\scriptstyle 7.41e\text{-}30.9762 ± 7.41 italic_e - 3 0.9639±1.40e-2plus-or-minus0.96391.40𝑒-20.9639\scriptscriptstyle\pm\scriptstyle 1.40e\text{-}20.9639 ± 1.40 italic_e - 2
0.5 0.9980±1.50𝐞-𝟑plus-or-minus0.99801.50𝐞-3\mathbf{0.9980\scriptscriptstyle\pm\scriptstyle 1.50e\text{-}3}bold_0.9980 ± bold_1.50 bold_e - bold_3 0.9749±1.13𝐞-𝟐plus-or-minus0.97491.13𝐞-2\mathbf{0.9749\scriptscriptstyle\pm\scriptstyle 1.13e\text{-}2}bold_0.9749 ± bold_1.13 bold_e - bold_2 0.9779±8.49𝐞-𝟑plus-or-minus0.97798.49𝐞-3\mathbf{0.9779\scriptscriptstyle\pm\scriptstyle 8.49e\text{-}3}bold_0.9779 ± bold_8.49 bold_e - bold_3 0.9750±1.16𝐞-𝟐plus-or-minus0.97501.16𝐞-2\mathbf{0.9750\scriptscriptstyle\pm\scriptstyle 1.16e\text{-}2}bold_0.9750 ± bold_1.16 bold_e - bold_2
StyleGan2lsun 0.0 0.9992±8.01e-4plus-or-minus0.99928.01𝑒-40.9992\scriptscriptstyle\pm\scriptstyle 8.01e\text{-}40.9992 ± 8.01 italic_e - 4 0.9856±8.77e-3plus-or-minus0.98568.77𝑒-30.9856\scriptscriptstyle\pm\scriptstyle 8.77e\text{-}30.9856 ± 8.77 italic_e - 3 0.9850±1.12e-2plus-or-minus0.98501.12𝑒-20.9850\scriptscriptstyle\pm\scriptstyle 1.12e\text{-}20.9850 ± 1.12 italic_e - 2 0.9584±3.33e-2plus-or-minus0.95843.33𝑒-20.9584\scriptscriptstyle\pm\scriptstyle 3.33e\text{-}20.9584 ± 3.33 italic_e - 2
0.03125 0.9989±8.72e-4plus-or-minus0.99898.72𝑒-40.9989\scriptscriptstyle\pm\scriptstyle 8.72e\text{-}40.9989 ± 8.72 italic_e - 4 0.9921±6.86e-3plus-or-minus0.99216.86𝑒-30.9921\scriptscriptstyle\pm\scriptstyle 6.86e\text{-}30.9921 ± 6.86 italic_e - 3 0.9894±1.14e-2plus-or-minus0.98941.14𝑒-20.9894\scriptscriptstyle\pm\scriptstyle 1.14e\text{-}20.9894 ± 1.14 italic_e - 2 0.9352±3.12e-2plus-or-minus0.93523.12𝑒-20.9352\scriptscriptstyle\pm\scriptstyle 3.12e\text{-}20.9352 ± 3.12 italic_e - 2
0.0625 0.9995±3.75e-4plus-or-minus0.99953.75𝑒-40.9995\scriptscriptstyle\pm\scriptstyle 3.75e\text{-}40.9995 ± 3.75 italic_e - 4 0.9911±9.81e-3plus-or-minus0.99119.81𝑒-30.9911\scriptscriptstyle\pm\scriptstyle 9.81e\text{-}30.9911 ± 9.81 italic_e - 3 0.9877±1.32e-2plus-or-minus0.98771.32𝑒-20.9877\scriptscriptstyle\pm\scriptstyle 1.32e\text{-}20.9877 ± 1.32 italic_e - 2 0.9511±2.88e-2plus-or-minus0.95112.88𝑒-20.9511\scriptscriptstyle\pm\scriptstyle 2.88e\text{-}20.9511 ± 2.88 italic_e - 2
0.1 0.9996±4.63e-4plus-or-minus0.99964.63𝑒-40.9996\scriptscriptstyle\pm\scriptstyle 4.63e\text{-}40.9996 ± 4.63 italic_e - 4 0.9937±5.33e-3plus-or-minus0.99375.33𝑒-30.9937\scriptscriptstyle\pm\scriptstyle 5.33e\text{-}30.9937 ± 5.33 italic_e - 3 0.9851±2.31e-2plus-or-minus0.98512.31𝑒-20.9851\scriptscriptstyle\pm\scriptstyle 2.31e\text{-}20.9851 ± 2.31 italic_e - 2 0.9652±2.42e-2plus-or-minus0.96522.42𝑒-20.9652\scriptscriptstyle\pm\scriptstyle 2.42e\text{-}20.9652 ± 2.42 italic_e - 2
0.2 0.9997±2.32e-4plus-or-minus0.99972.32𝑒-40.9997\scriptscriptstyle\pm\scriptstyle 2.32e\text{-}40.9997 ± 2.32 italic_e - 4 0.9941±2.36𝐞-𝟑plus-or-minus0.99412.36𝐞-3\mathbf{0.9941\scriptscriptstyle\pm\scriptstyle 2.36e\text{-}3}bold_0.9941 ± bold_2.36 bold_e - bold_3 0.9900±4.43e-3plus-or-minus0.99004.43𝑒-30.9900\scriptscriptstyle\pm\scriptstyle 4.43e\text{-}30.9900 ± 4.43 italic_e - 3 0.9677±1.23e-2plus-or-minus0.96771.23𝑒-20.9677\scriptscriptstyle\pm\scriptstyle 1.23e\text{-}20.9677 ± 1.23 italic_e - 2
0.5 0.9997±1.66𝐞-𝟒plus-or-minus0.99971.66𝐞-4\mathbf{0.9997\scriptscriptstyle\pm\scriptstyle 1.66e\text{-}4}bold_0.9997 ± bold_1.66 bold_e - bold_4 0.9943±2.17e-3plus-or-minus0.99432.17𝑒-30.9943\scriptscriptstyle\pm\scriptstyle 2.17e\text{-}30.9943 ± 2.17 italic_e - 3 0.9917±3.25𝐞-𝟑plus-or-minus0.99173.25𝐞-3\mathbf{0.9917\scriptscriptstyle\pm\scriptstyle 3.25e\text{-}3}bold_0.9917 ± bold_3.25 bold_e - bold_3 0.9688±9.89𝐞-𝟑plus-or-minus0.96889.89𝐞-3\mathbf{0.9688\scriptscriptstyle\pm\scriptstyle 9.89e\text{-}3}bold_0.9688 ± bold_9.89 bold_e - bold_3
GauGancoco 0.0 0.9991±6.97e-4plus-or-minus0.99916.97𝑒-40.9991\scriptscriptstyle\pm\scriptstyle 6.97e\text{-}40.9991 ± 6.97 italic_e - 4 0.9388±2.52e-2plus-or-minus0.93882.52𝑒-20.9388\scriptscriptstyle\pm\scriptstyle 2.52e\text{-}20.9388 ± 2.52 italic_e - 2 0.9862±6.91e-3plus-or-minus0.98626.91𝑒-30.9862\scriptscriptstyle\pm\scriptstyle 6.91e\text{-}30.9862 ± 6.91 italic_e - 3 0.9757±1.02e-2plus-or-minus0.97571.02𝑒-20.9757\scriptscriptstyle\pm\scriptstyle 1.02e\text{-}20.9757 ± 1.02 italic_e - 2
0.03125 0.9960±2.16e-3plus-or-minus0.99602.16𝑒-30.9960\scriptscriptstyle\pm\scriptstyle 2.16e\text{-}30.9960 ± 2.16 italic_e - 3 0.8420±6.06e-2plus-or-minus0.84206.06𝑒-20.8420\scriptscriptstyle\pm\scriptstyle 6.06e\text{-}20.8420 ± 6.06 italic_e - 2 0.9616±1.45e-2plus-or-minus0.96161.45𝑒-20.9616\scriptscriptstyle\pm\scriptstyle 1.45e\text{-}20.9616 ± 1.45 italic_e - 2 0.8890±4.38e-2plus-or-minus0.88904.38𝑒-20.8890\scriptscriptstyle\pm\scriptstyle 4.38e\text{-}20.8890 ± 4.38 italic_e - 2
0.0625 0.9976±1.32e-3plus-or-minus0.99761.32𝑒-30.9976\scriptscriptstyle\pm\scriptstyle 1.32e\text{-}30.9976 ± 1.32 italic_e - 3 0.8593±3.97e-2plus-or-minus0.85933.97𝑒-20.8593\scriptscriptstyle\pm\scriptstyle 3.97e\text{-}20.8593 ± 3.97 italic_e - 2 0.9678±8.16e-3plus-or-minus0.96788.16𝑒-30.9678\scriptscriptstyle\pm\scriptstyle 8.16e\text{-}30.9678 ± 8.16 italic_e - 3 0.9149±2.89e-2plus-or-minus0.91492.89𝑒-20.9149\scriptscriptstyle\pm\scriptstyle 2.89e\text{-}20.9149 ± 2.89 italic_e - 2
0.1 0.9982±1.33e-3plus-or-minus0.99821.33𝑒-30.9982\scriptscriptstyle\pm\scriptstyle 1.33e\text{-}30.9982 ± 1.33 italic_e - 3 0.9132±2.93e-2plus-or-minus0.91322.93𝑒-20.9132\scriptscriptstyle\pm\scriptstyle 2.93e\text{-}20.9132 ± 2.93 italic_e - 2 0.9745±9.90e-3plus-or-minus0.97459.90𝑒-30.9745\scriptscriptstyle\pm\scriptstyle 9.90e\text{-}30.9745 ± 9.90 italic_e - 3 0.9593±2.54e-2plus-or-minus0.95932.54𝑒-20.9593\scriptscriptstyle\pm\scriptstyle 2.54e\text{-}20.9593 ± 2.54 italic_e - 2
0.2 0.9992±1.34e-3plus-or-minus0.99921.34𝑒-30.9992\scriptscriptstyle\pm\scriptstyle 1.34e\text{-}30.9992 ± 1.34 italic_e - 3 0.9456±2.44e-2plus-or-minus0.94562.44𝑒-20.9456\scriptscriptstyle\pm\scriptstyle 2.44e\text{-}20.9456 ± 2.44 italic_e - 2 0.9881±5.31e-3plus-or-minus0.98815.31𝑒-30.9881\scriptscriptstyle\pm\scriptstyle 5.31e\text{-}30.9881 ± 5.31 italic_e - 3 0.9904±3.47e-3plus-or-minus0.99043.47𝑒-30.9904\scriptscriptstyle\pm\scriptstyle 3.47e\text{-}30.9904 ± 3.47 italic_e - 3
0.5 0.9997±2.94𝐞-𝟒plus-or-minus0.99972.94𝐞-4\mathbf{0.9997\scriptscriptstyle\pm\scriptstyle 2.94e\text{-}4}bold_0.9997 ± bold_2.94 bold_e - bold_4 0.9518±2.79𝐞-𝟐plus-or-minus0.95182.79𝐞-2\mathbf{0.9518\scriptscriptstyle\pm\scriptstyle 2.79e\text{-}2}bold_0.9518 ± bold_2.79 bold_e - bold_2 0.9908±5.50𝐞-𝟑plus-or-minus0.99085.50𝐞-3\mathbf{0.9908\scriptscriptstyle\pm\scriptstyle 5.50e\text{-}3}bold_0.9908 ± bold_5.50 bold_e - bold_3 0.9914±4.66𝐞-𝟑plus-or-minus0.99144.66𝐞-3\mathbf{0.9914\scriptscriptstyle\pm\scriptstyle 4.66e\text{-}3}bold_0.9914 ± bold_4.66 bold_e - bold_3
Table 15: Evaluation sensitivity of OCC-CLIP to Source Models and choice of Epsilon. The leftmost column represents target datasets. In training phase, the non-target images are from COCO. In testing phase, the non-target images are from a different generative image dataset shown in the first row. Different epsilon is chosen: 0.0, 0.03125, 0.0625, 0.1, 0.2, andm 0.5. The optimal outcomes for individual datasets are emphasized using bold formatting.
Target Epsilon GALIPcoco ProGanlsun StyleGan2lsun GauGancoco Overall
SDLAION-5B 0.0 0.9660±2.56e-2plus-or-minus0.96602.56𝑒-20.9660\scriptscriptstyle\pm\scriptstyle 2.56e\text{-}20.9660 ± 2.56 italic_e - 2 0.8861±4.46e-2plus-or-minus0.88614.46𝑒-20.8861\scriptscriptstyle\pm\scriptstyle 4.46e\text{-}20.8861 ± 4.46 italic_e - 2 0.9533±2.30e-2plus-or-minus0.95332.30𝑒-20.9533\scriptscriptstyle\pm\scriptstyle 2.30e\text{-}20.9533 ± 2.30 italic_e - 2 0.9643±2.91e-2plus-or-minus0.96432.91𝑒-20.9643\scriptscriptstyle\pm\scriptstyle 2.91e\text{-}20.9643 ± 2.91 italic_e - 2 0.9263±3.41e-2plus-or-minus0.92633.41𝑒-20.9263\scriptscriptstyle\pm\scriptstyle 3.41e\text{-}20.9263 ± 3.41 italic_e - 2
0.03125 0.9764±1.83e-2plus-or-minus0.97641.83𝑒-20.9764\scriptscriptstyle\pm\scriptstyle 1.83e\text{-}20.9764 ± 1.83 italic_e - 2 0.9564±1.84𝐞-𝟐plus-or-minus0.95641.84𝐞-2\mathbf{0.9564\scriptscriptstyle\pm\scriptstyle 1.84e\text{-}2}bold_0.9564 ± bold_1.84 bold_e - bold_2 0.9695±2.23𝐞-𝟐plus-or-minus0.96952.23𝐞-2\mathbf{0.9695\scriptscriptstyle\pm\scriptstyle 2.23e\text{-}2}bold_0.9695 ± bold_2.23 bold_e - bold_2 0.9966±2.79𝐞-𝟑plus-or-minus0.99662.79𝐞-3\mathbf{0.9966\scriptscriptstyle\pm\scriptstyle 2.79e\text{-}3}bold_0.9966 ± bold_2.79 bold_e - bold_3 0.9521±2.61e-2plus-or-minus0.95212.61𝑒-20.9521\scriptscriptstyle\pm\scriptstyle 2.61e\text{-}20.9521 ± 2.61 italic_e - 2
0.0625 0.9762±1.77e-2plus-or-minus0.97621.77𝑒-20.9762\scriptscriptstyle\pm\scriptstyle 1.77e\text{-}20.9762 ± 1.77 italic_e - 2 0.9470±3.82e-2plus-or-minus0.94703.82𝑒-20.9470\scriptscriptstyle\pm\scriptstyle 3.82e\text{-}20.9470 ± 3.82 italic_e - 2 0.9684±1.67e-2plus-or-minus0.96841.67𝑒-20.9684\scriptscriptstyle\pm\scriptstyle 1.67e\text{-}20.9684 ± 1.67 italic_e - 2 0.9939±7.33e-3plus-or-minus0.99397.33𝑒-30.9939\scriptscriptstyle\pm\scriptstyle 7.33e\text{-}30.9939 ± 7.33 italic_e - 3 0.9507±2.61e-2plus-or-minus0.95072.61𝑒-20.9507\scriptscriptstyle\pm\scriptstyle 2.61e\text{-}20.9507 ± 2.61 italic_e - 2
0.1 0.9798±1.18𝐞-𝟐plus-or-minus0.97981.18𝐞-2\mathbf{0.9798\scriptscriptstyle\pm\scriptstyle 1.18e\text{-}2}bold_0.9798 ± bold_1.18 bold_e - bold_2 0.9452±3.14e-2plus-or-minus0.94523.14𝑒-20.9452\scriptscriptstyle\pm\scriptstyle 3.14e\text{-}20.9452 ± 3.14 italic_e - 2 0.9651±1.54e-2plus-or-minus0.96511.54𝑒-20.9651\scriptscriptstyle\pm\scriptstyle 1.54e\text{-}20.9651 ± 1.54 italic_e - 2 0.9910±7.32e-3plus-or-minus0.99107.32𝑒-30.9910\scriptscriptstyle\pm\scriptstyle 7.32e\text{-}30.9910 ± 7.32 italic_e - 3 0.9548±1.75𝐞-𝟐plus-or-minus0.95481.75𝐞-2\mathbf{0.9548\scriptscriptstyle\pm\scriptstyle 1.75e\text{-}2}bold_0.9548 ± bold_1.75 bold_e - bold_2
0.2 0.9722±1.38e-2plus-or-minus0.97221.38𝑒-20.9722\scriptscriptstyle\pm\scriptstyle 1.38e\text{-}20.9722 ± 1.38 italic_e - 2 0.9196±2.95e-2plus-or-minus0.91962.95𝑒-20.9196\scriptscriptstyle\pm\scriptstyle 2.95e\text{-}20.9196 ± 2.95 italic_e - 2 0.9578±2.46e-2plus-or-minus0.95782.46𝑒-20.9578\scriptscriptstyle\pm\scriptstyle 2.46e\text{-}20.9578 ± 2.46 italic_e - 2 0.9821±1.04e-2plus-or-minus0.98211.04𝑒-20.9821\scriptscriptstyle\pm\scriptstyle 1.04e\text{-}20.9821 ± 1.04 italic_e - 2 0.9394±2.47e-2plus-or-minus0.93942.47𝑒-20.9394\scriptscriptstyle\pm\scriptstyle 2.47e\text{-}20.9394 ± 2.47 italic_e - 2
0.5 0.9670±2.01e-2plus-or-minus0.96702.01𝑒-20.9670\scriptscriptstyle\pm\scriptstyle 2.01e\text{-}20.9670 ± 2.01 italic_e - 2 0.9002±3.15e-2plus-or-minus0.90023.15𝑒-20.9002\scriptscriptstyle\pm\scriptstyle 3.15e\text{-}20.9002 ± 3.15 italic_e - 2 0.9627±1.99e-2plus-or-minus0.96271.99𝑒-20.9627\scriptscriptstyle\pm\scriptstyle 1.99e\text{-}20.9627 ± 1.99 italic_e - 2 0.9816±1.03e-2plus-or-minus0.98161.03𝑒-20.9816\scriptscriptstyle\pm\scriptstyle 1.03e\text{-}20.9816 ± 1.03 italic_e - 2 0.9368±2.83e-2plus-or-minus0.93682.83𝑒-20.9368\scriptscriptstyle\pm\scriptstyle 2.83e\text{-}20.9368 ± 2.83 italic_e - 2
VQ-Dcoco 0.0 0.7558±3.82𝐞-𝟐plus-or-minus0.75583.82𝐞-2\mathbf{0.7558\scriptscriptstyle\pm\scriptstyle 3.82e\text{-}2}bold_0.7558 ± bold_3.82 bold_e - bold_2 0.9290±2.80e-2plus-or-minus0.92902.80𝑒-20.9290\scriptscriptstyle\pm\scriptstyle 2.80e\text{-}20.9290 ± 2.80 italic_e - 2 0.9924±3.87e-3plus-or-minus0.99243.87𝑒-30.9924\scriptscriptstyle\pm\scriptstyle 3.87e\text{-}30.9924 ± 3.87 italic_e - 3 0.9352±1.95e-2plus-or-minus0.93521.95𝑒-20.9352\scriptscriptstyle\pm\scriptstyle 1.95e\text{-}20.9352 ± 1.95 italic_e - 2 0.8698±3.09e-2plus-or-minus0.86983.09𝑒-20.8698\scriptscriptstyle\pm\scriptstyle 3.09e\text{-}20.8698 ± 3.09 italic_e - 2
0.03125 0.7303±5.59e-2plus-or-minus0.73035.59𝑒-20.7303\scriptscriptstyle\pm\scriptstyle 5.59e\text{-}20.7303 ± 5.59 italic_e - 2 0.9920±4.31e-3plus-or-minus0.99204.31𝑒-30.9920\scriptscriptstyle\pm\scriptstyle 4.31e\text{-}30.9920 ± 4.31 italic_e - 3 0.9971±2.20𝐞-𝟑plus-or-minus0.99712.20𝐞-3\mathbf{0.9971\scriptscriptstyle\pm\scriptstyle 2.20e\text{-}3}bold_0.9971 ± bold_2.20 bold_e - bold_3 0.9946±2.51e-3plus-or-minus0.99462.51𝑒-30.9946\scriptscriptstyle\pm\scriptstyle 2.51e\text{-}30.9946 ± 2.51 italic_e - 3 0.8741±3.15e-2plus-or-minus0.87413.15𝑒-20.8741\scriptscriptstyle\pm\scriptstyle 3.15e\text{-}20.8741 ± 3.15 italic_e - 2
0.0625 0.7245±6.14e-2plus-or-minus0.72456.14𝑒-20.7245\scriptscriptstyle\pm\scriptstyle 6.14e\text{-}20.7245 ± 6.14 italic_e - 2 0.9923±5.29e-3plus-or-minus0.99235.29𝑒-30.9923\scriptscriptstyle\pm\scriptstyle 5.29e\text{-}30.9923 ± 5.29 italic_e - 3 0.9938±5.97e-3plus-or-minus0.99385.97𝑒-30.9938\scriptscriptstyle\pm\scriptstyle 5.97e\text{-}30.9938 ± 5.97 italic_e - 3 0.9949±3.19𝐞-𝟑plus-or-minus0.99493.19𝐞-3\mathbf{0.9949\scriptscriptstyle\pm\scriptstyle 3.19e\text{-}3}bold_0.9949 ± bold_3.19 bold_e - bold_3 0.8705±3.68e-2plus-or-minus0.87053.68𝑒-20.8705\scriptscriptstyle\pm\scriptstyle 3.68e\text{-}20.8705 ± 3.68 italic_e - 2
0.1 0.7327±5.82e-2plus-or-minus0.73275.82𝑒-20.7327\scriptscriptstyle\pm\scriptstyle 5.82e\text{-}20.7327 ± 5.82 italic_e - 2 0.9931±3.58e-3plus-or-minus0.99313.58𝑒-30.9931\scriptscriptstyle\pm\scriptstyle 3.58e\text{-}30.9931 ± 3.58 italic_e - 3 0.9936±5.51e-3plus-or-minus0.99365.51𝑒-30.9936\scriptscriptstyle\pm\scriptstyle 5.51e\text{-}30.9936 ± 5.51 italic_e - 3 0.9936±2.50e-3plus-or-minus0.99362.50𝑒-30.9936\scriptscriptstyle\pm\scriptstyle 2.50e\text{-}30.9936 ± 2.50 italic_e - 3 0.8758±3.95e-2plus-or-minus0.87583.95𝑒-20.8758\scriptscriptstyle\pm\scriptstyle 3.95e\text{-}20.8758 ± 3.95 italic_e - 2
0.2 0.7120±4.83e-2plus-or-minus0.71204.83𝑒-20.7120\scriptscriptstyle\pm\scriptstyle 4.83e\text{-}20.7120 ± 4.83 italic_e - 2 0.9938±2.40𝐞-𝟑plus-or-minus0.99382.40𝐞-3\mathbf{0.9938\scriptscriptstyle\pm\scriptstyle 2.40e\text{-}3}bold_0.9938 ± bold_2.40 bold_e - bold_3 0.9958±1.95e-3plus-or-minus0.99581.95𝑒-30.9958\scriptscriptstyle\pm\scriptstyle 1.95e\text{-}30.9958 ± 1.95 italic_e - 3 0.9931±2.39e-3plus-or-minus0.99312.39𝑒-30.9931\scriptscriptstyle\pm\scriptstyle 2.39e\text{-}30.9931 ± 2.39 italic_e - 3 0.8774±2.86𝐞-𝟐plus-or-minus0.87742.86𝐞-2\mathbf{0.8774\scriptscriptstyle\pm\scriptstyle 2.86e\text{-}2}bold_0.8774 ± bold_2.86 bold_e - bold_2
0.5 0.6876±5.09e-2plus-or-minus0.68765.09𝑒-20.6876\scriptscriptstyle\pm\scriptstyle 5.09e\text{-}20.6876 ± 5.09 italic_e - 2 0.9899±4.30e-3plus-or-minus0.98994.30𝑒-30.9899\scriptscriptstyle\pm\scriptstyle 4.30e\text{-}30.9899 ± 4.30 italic_e - 3 0.9960±2.28e-3plus-or-minus0.99602.28𝑒-30.9960\scriptscriptstyle\pm\scriptstyle 2.28e\text{-}30.9960 ± 2.28 italic_e - 3 0.9909±3.81e-3plus-or-minus0.99093.81𝑒-30.9909\scriptscriptstyle\pm\scriptstyle 3.81e\text{-}30.9909 ± 3.81 italic_e - 3 0.8713±3.37e-2plus-or-minus0.87133.37𝑒-20.8713\scriptscriptstyle\pm\scriptstyle 3.37e\text{-}20.8713 ± 3.37 italic_e - 2
LDMLAION-400M 0.0 0.6263±7.51e-2plus-or-minus0.62637.51𝑒-20.6263\scriptscriptstyle\pm\scriptstyle 7.51e\text{-}20.6263 ± 7.51 italic_e - 2 0.9565±4.27e-2plus-or-minus0.95654.27𝑒-20.9565\scriptscriptstyle\pm\scriptstyle 4.27e\text{-}20.9565 ± 4.27 italic_e - 2 0.9896±8.87e-3plus-or-minus0.98968.87𝑒-30.9896\scriptscriptstyle\pm\scriptstyle 8.87e\text{-}30.9896 ± 8.87 italic_e - 3 0.9758±2.86e-2plus-or-minus0.97582.86𝑒-20.9758\scriptscriptstyle\pm\scriptstyle 2.86e\text{-}20.9758 ± 2.86 italic_e - 2 0.8381±4.87e-2plus-or-minus0.83814.87𝑒-20.8381\scriptscriptstyle\pm\scriptstyle 4.87e\text{-}20.8381 ± 4.87 italic_e - 2
0.03125 0.6276±6.30e-2plus-or-minus0.62766.30𝑒-20.6276\scriptscriptstyle\pm\scriptstyle 6.30e\text{-}20.6276 ± 6.30 italic_e - 2 0.9970±2.09e-3plus-or-minus0.99702.09𝑒-30.9970\scriptscriptstyle\pm\scriptstyle 2.09e\text{-}30.9970 ± 2.09 italic_e - 3 0.9957±3.08e-3plus-or-minus0.99573.08𝑒-30.9957\scriptscriptstyle\pm\scriptstyle 3.08e\text{-}30.9957 ± 3.08 italic_e - 3 0.9997±3.55𝐞-𝟒plus-or-minus0.99973.55𝐞-4\mathbf{0.9997\scriptscriptstyle\pm\scriptstyle 3.55e\text{-}4}bold_0.9997 ± bold_3.55 bold_e - bold_4 0.8563±3.73e-2plus-or-minus0.85633.73𝑒-20.8563\scriptscriptstyle\pm\scriptstyle 3.73e\text{-}20.8563 ± 3.73 italic_e - 2
0.0625 0.6389±4.84e-2plus-or-minus0.63894.84𝑒-20.6389\scriptscriptstyle\pm\scriptstyle 4.84e\text{-}20.6389 ± 4.84 italic_e - 2 0.9971±1.94𝐞-𝟑plus-or-minus0.99711.94𝐞-3\mathbf{0.9971\scriptscriptstyle\pm\scriptstyle 1.94e\text{-}3}bold_0.9971 ± bold_1.94 bold_e - bold_3 0.9957±3.73𝐞-𝟑plus-or-minus0.99573.73𝐞-3\mathbf{0.9957\scriptscriptstyle\pm\scriptstyle 3.73e\text{-}3}bold_0.9957 ± bold_3.73 bold_e - bold_3 0.9997±4.27e-4plus-or-minus0.99974.27𝑒-40.9997\scriptscriptstyle\pm\scriptstyle 4.27e\text{-}40.9997 ± 4.27 italic_e - 4 0.8642±3.30e-2plus-or-minus0.86423.30𝑒-20.8642\scriptscriptstyle\pm\scriptstyle 3.30e\text{-}20.8642 ± 3.30 italic_e - 2
0.1 0.6530±4.87𝐞-𝟐plus-or-minus0.65304.87𝐞-2\mathbf{0.6530\scriptscriptstyle\pm\scriptstyle 4.87e\text{-}2}bold_0.6530 ± bold_4.87 bold_e - bold_2 0.9956±3.43e-3plus-or-minus0.99563.43𝑒-30.9956\scriptscriptstyle\pm\scriptstyle 3.43e\text{-}30.9956 ± 3.43 italic_e - 3 0.9940±3.47e-3plus-or-minus0.99403.47𝑒-30.9940\scriptscriptstyle\pm\scriptstyle 3.47e\text{-}30.9940 ± 3.47 italic_e - 3 0.9992±7.47e-4plus-or-minus0.99927.47𝑒-40.9992\scriptscriptstyle\pm\scriptstyle 7.47e\text{-}40.9992 ± 7.47 italic_e - 4 0.8676±3.44e-2plus-or-minus0.86763.44𝑒-20.8676\scriptscriptstyle\pm\scriptstyle 3.44e\text{-}20.8676 ± 3.44 italic_e - 2
0.2 0.6515±5.97e-2plus-or-minus0.65155.97𝑒-20.6515\scriptscriptstyle\pm\scriptstyle 5.97e\text{-}20.6515 ± 5.97 italic_e - 2 0.9919±3.47e-3plus-or-minus0.99193.47𝑒-30.9919\scriptscriptstyle\pm\scriptstyle 3.47e\text{-}30.9919 ± 3.47 italic_e - 3 0.9939±2.97e-3plus-or-minus0.99392.97𝑒-30.9939\scriptscriptstyle\pm\scriptstyle 2.97e\text{-}30.9939 ± 2.97 italic_e - 3 0.9977±1.57e-3plus-or-minus0.99771.57𝑒-30.9977\scriptscriptstyle\pm\scriptstyle 1.57e\text{-}30.9977 ± 1.57 italic_e - 3 0.8679±3.98𝐞-𝟐plus-or-minus0.86793.98𝐞-2\mathbf{0.8679\scriptscriptstyle\pm\scriptstyle 3.98e\text{-}2}bold_0.8679 ± bold_3.98 bold_e - bold_2
0.5 0.6388±3.67e-2plus-or-minus0.63883.67𝑒-20.6388\scriptscriptstyle\pm\scriptstyle 3.67e\text{-}20.6388 ± 3.67 italic_e - 2 0.9905±4.88e-3plus-or-minus0.99054.88𝑒-30.9905\scriptscriptstyle\pm\scriptstyle 4.88e\text{-}30.9905 ± 4.88 italic_e - 3 0.9952±2.17e-3plus-or-minus0.99522.17𝑒-30.9952\scriptscriptstyle\pm\scriptstyle 2.17e\text{-}30.9952 ± 2.17 italic_e - 3 0.9973±1.68e-3plus-or-minus0.99731.68𝑒-30.9973\scriptscriptstyle\pm\scriptstyle 1.68e\text{-}30.9973 ± 1.68 italic_e - 3 0.8674±2.79e-2plus-or-minus0.86742.79𝑒-20.8674\scriptscriptstyle\pm\scriptstyle 2.79e\text{-}20.8674 ± 2.79 italic_e - 2
Glidefiltered-cc 0.0 0.6687±8.82e-2plus-or-minus0.66878.82𝑒-20.6687\scriptscriptstyle\pm\scriptstyle 8.82e\text{-}20.6687 ± 8.82 italic_e - 2 0.9629±4.83e-2plus-or-minus0.96294.83𝑒-20.9629\scriptscriptstyle\pm\scriptstyle 4.83e\text{-}20.9629 ± 4.83 italic_e - 2 0.9916±6.77e-3plus-or-minus0.99166.77𝑒-30.9916\scriptscriptstyle\pm\scriptstyle 6.77e\text{-}30.9916 ± 6.77 italic_e - 3 0.9814±3.92e-2plus-or-minus0.98143.92𝑒-20.9814\scriptscriptstyle\pm\scriptstyle 3.92e\text{-}20.9814 ± 3.92 italic_e - 2 0.8988±4.55e-2plus-or-minus0.89884.55𝑒-20.8988\scriptscriptstyle\pm\scriptstyle 4.55e\text{-}20.8988 ± 4.55 italic_e - 2
0.03125 0.6910±4.59e-2plus-or-minus0.69104.59𝑒-20.6910\scriptscriptstyle\pm\scriptstyle 4.59e\text{-}20.6910 ± 4.59 italic_e - 2 0.9974±2.15e-3plus-or-minus0.99742.15𝑒-30.9974\scriptscriptstyle\pm\scriptstyle 2.15e\text{-}30.9974 ± 2.15 italic_e - 3 0.9980±1.48𝐞-𝟑plus-or-minus0.99801.48𝐞-3\mathbf{0.9980\scriptscriptstyle\pm\scriptstyle 1.48e\text{-}3}bold_0.9980 ± bold_1.48 bold_e - bold_3 0.9998±4.35e-4plus-or-minus0.99984.35𝑒-40.9998\scriptscriptstyle\pm\scriptstyle 4.35e\text{-}40.9998 ± 4.35 italic_e - 4 0.9197±2.15𝐞-𝟐plus-or-minus0.91972.15𝐞-2\mathbf{0.9197\scriptscriptstyle\pm\scriptstyle 2.15e\text{-}2}bold_0.9197 ± bold_2.15 bold_e - bold_2
0.0625 0.6942±7.30𝐞-𝟐plus-or-minus0.69427.30𝐞-2\mathbf{0.6942\scriptscriptstyle\pm\scriptstyle 7.30e\text{-}2}bold_0.6942 ± bold_7.30 bold_e - bold_2 0.9973±2.94e-3plus-or-minus0.99732.94𝑒-30.9973\scriptscriptstyle\pm\scriptstyle 2.94e\text{-}30.9973 ± 2.94 italic_e - 3 0.9951±3.15e-3plus-or-minus0.99513.15𝑒-30.9951\scriptscriptstyle\pm\scriptstyle 3.15e\text{-}30.9951 ± 3.15 italic_e - 3 0.9996±7.15e-4plus-or-minus0.99967.15𝑒-40.9996\scriptscriptstyle\pm\scriptstyle 7.15e\text{-}40.9996 ± 7.15 italic_e - 4 0.9191±2.99e-2plus-or-minus0.91912.99𝑒-20.9191\scriptscriptstyle\pm\scriptstyle 2.99e\text{-}20.9191 ± 2.99 italic_e - 2
0.1 0.6834±6.43e-2plus-or-minus0.68346.43𝑒-20.6834\scriptscriptstyle\pm\scriptstyle 6.43e\text{-}20.6834 ± 6.43 italic_e - 2 0.9974±1.66𝐞-𝟑plus-or-minus0.99741.66𝐞-3\mathbf{0.9974\scriptscriptstyle\pm\scriptstyle 1.66e\text{-}3}bold_0.9974 ± bold_1.66 bold_e - bold_3 0.9949±2.73e-3plus-or-minus0.99492.73𝑒-30.9949\scriptscriptstyle\pm\scriptstyle 2.73e\text{-}30.9949 ± 2.73 italic_e - 3 0.9997±4.78e-4plus-or-minus0.99974.78𝑒-40.9997\scriptscriptstyle\pm\scriptstyle 4.78e\text{-}40.9997 ± 4.78 italic_e - 4 0.9185±2.74e-2plus-or-minus0.91852.74𝑒-20.9185\scriptscriptstyle\pm\scriptstyle 2.74e\text{-}20.9185 ± 2.74 italic_e - 2
0.2 0.6406±4.52e-2plus-or-minus0.64064.52𝑒-20.6406\scriptscriptstyle\pm\scriptstyle 4.52e\text{-}20.6406 ± 4.52 italic_e - 2 0.9965±1.45e-3plus-or-minus0.99651.45𝑒-30.9965\scriptscriptstyle\pm\scriptstyle 1.45e\text{-}30.9965 ± 1.45 italic_e - 3 0.9976±1.20e-3plus-or-minus0.99761.20𝑒-30.9976\scriptscriptstyle\pm\scriptstyle 1.20e\text{-}30.9976 ± 1.20 italic_e - 3 0.9998±2.07𝐞-𝟒plus-or-minus0.99982.07𝐞-4\mathbf{0.9998\scriptscriptstyle\pm\scriptstyle 2.07e\text{-}4}bold_0.9998 ± bold_2.07 bold_e - bold_4 0.9164±1.98e-2plus-or-minus0.91641.98𝑒-20.9164\scriptscriptstyle\pm\scriptstyle 1.98e\text{-}20.9164 ± 1.98 italic_e - 2
0.5 0.6535±6.54e-2plus-or-minus0.65356.54𝑒-20.6535\scriptscriptstyle\pm\scriptstyle 6.54e\text{-}20.6535 ± 6.54 italic_e - 2 0.9926±6.24e-3plus-or-minus0.99266.24𝑒-30.9926\scriptscriptstyle\pm\scriptstyle 6.24e\text{-}30.9926 ± 6.24 italic_e - 3 0.9961±2.96e-3plus-or-minus0.99612.96𝑒-30.9961\scriptscriptstyle\pm\scriptstyle 2.96e\text{-}30.9961 ± 2.96 italic_e - 3 0.9989±1.91e-3plus-or-minus0.99891.91𝑒-30.9989\scriptscriptstyle\pm\scriptstyle 1.91e\text{-}30.9989 ± 1.91 italic_e - 3 0.9147±2.90e-2plus-or-minus0.91472.90𝑒-20.9147\scriptscriptstyle\pm\scriptstyle 2.90e\text{-}20.9147 ± 2.90 italic_e - 2
GALIPcoco 0.0 - 0.9982±1.16e-3plus-or-minus0.99821.16𝑒-30.9982\scriptscriptstyle\pm\scriptstyle 1.16e\text{-}30.9982 ± 1.16 italic_e - 3 0.9992±7.43e-4plus-or-minus0.99927.43𝑒-40.9992\scriptscriptstyle\pm\scriptstyle 7.43e\text{-}40.9992 ± 7.43 italic_e - 4 0.9996±5.71e-4plus-or-minus0.99965.71𝑒-40.9996\scriptscriptstyle\pm\scriptstyle 5.71e\text{-}40.9996 ± 5.71 italic_e - 4 0.9321±2.71e-2plus-or-minus0.93212.71𝑒-20.9321\scriptscriptstyle\pm\scriptstyle 2.71e\text{-}20.9321 ± 2.71 italic_e - 2
0.03125 - 0.9999±1.10e-4plus-or-minus0.99991.10𝑒-40.9999\scriptscriptstyle\pm\scriptstyle 1.10e\text{-}40.9999 ± 1.10 italic_e - 4 0.9994±5.35e-4plus-or-minus0.99945.35𝑒-40.9994\scriptscriptstyle\pm\scriptstyle 5.35e\text{-}40.9994 ± 5.35 italic_e - 4 1.0000±0.0plus-or-minus1.00000.01.0000\scriptscriptstyle\pm\scriptstyle 0.01.0000 ± 0.0 0.9180±2.45e-2plus-or-minus0.91802.45𝑒-20.9180\scriptscriptstyle\pm\scriptstyle 2.45e\text{-}20.9180 ± 2.45 italic_e - 2
0.0625 - 0.9999±7.00𝐞-𝟓plus-or-minus0.99997.00𝐞-5\mathbf{0.9999\scriptscriptstyle\pm\scriptstyle 7.00e\text{-}5}bold_0.9999 ± bold_7.00 bold_e - bold_5 0.9994±5.14e-4plus-or-minus0.99945.14𝑒-40.9994\scriptscriptstyle\pm\scriptstyle 5.14e\text{-}40.9994 ± 5.14 italic_e - 4 1.0000±0.0plus-or-minus1.00000.01.0000\scriptscriptstyle\pm\scriptstyle 0.01.0000 ± 0.0 0.9272±2.25e-2plus-or-minus0.92722.25𝑒-20.9272\scriptscriptstyle\pm\scriptstyle 2.25e\text{-}20.9272 ± 2.25 italic_e - 2
0.1 - 0.9999±1.35e-4plus-or-minus0.99991.35𝑒-40.9999\scriptscriptstyle\pm\scriptstyle 1.35e\text{-}40.9999 ± 1.35 italic_e - 4 0.9993±5.58e-4plus-or-minus0.99935.58𝑒-40.9993\scriptscriptstyle\pm\scriptstyle 5.58e\text{-}40.9993 ± 5.58 italic_e - 4 1.0000±0.0plus-or-minus1.00000.01.0000\scriptscriptstyle\pm\scriptstyle 0.01.0000 ± 0.0 0.9392±1.52e-2plus-or-minus0.93921.52𝑒-20.9392\scriptscriptstyle\pm\scriptstyle 1.52e\text{-}20.9392 ± 1.52 italic_e - 2
0.2 - 0.9999±8.06e-5plus-or-minus0.99998.06𝑒-50.9999\scriptscriptstyle\pm\scriptstyle 8.06e\text{-}50.9999 ± 8.06 italic_e - 5 0.9995±4.41e-4plus-or-minus0.99954.41𝑒-40.9995\scriptscriptstyle\pm\scriptstyle 4.41e\text{-}40.9995 ± 4.41 italic_e - 4 1.0000±0.0plus-or-minus1.00000.0\mathbf{1.0000\scriptscriptstyle\pm\scriptstyle 0.0}bold_1.0000 ± bold_0.0 0.9484±1.53e-2plus-or-minus0.94841.53𝑒-20.9484\scriptscriptstyle\pm\scriptstyle 1.53e\text{-}20.9484 ± 1.53 italic_e - 2
0.5 - 0.9997±2.84e-4plus-or-minus0.99972.84𝑒-40.9997\scriptscriptstyle\pm\scriptstyle 2.84e\text{-}40.9997 ± 2.84 italic_e - 4 0.9997±2.68𝐞-𝟒plus-or-minus0.99972.68𝐞-4\mathbf{0.9997\scriptscriptstyle\pm\scriptstyle 2.68e\text{-}4}bold_0.9997 ± bold_2.68 bold_e - bold_4 1.0000±3.00e-5plus-or-minus1.00003.00𝑒-51.0000\scriptscriptstyle\pm\scriptstyle 3.00e\text{-}51.0000 ± 3.00 italic_e - 5 0.9513±1.51𝐞-𝟐plus-or-minus0.95131.51𝐞-2\mathbf{0.9513\scriptscriptstyle\pm\scriptstyle 1.51e\text{-}2}bold_0.9513 ± bold_1.51 bold_e - bold_2
ProGanlsun 0.0 0.9818±1.24e-2plus-or-minus0.98181.24𝑒-20.9818\scriptscriptstyle\pm\scriptstyle 1.24e\text{-}20.9818 ± 1.24 italic_e - 2 - 0.9278±1.49𝐞-𝟐plus-or-minus0.92781.49𝐞-2\mathbf{0.9278\scriptscriptstyle\pm\scriptstyle 1.49e\text{-}2}bold_0.9278 ± bold_1.49 bold_e - bold_2 0.7993±2.00e-2plus-or-minus0.79932.00𝑒-20.7993\scriptscriptstyle\pm\scriptstyle 2.00e\text{-}20.7993 ± 2.00 italic_e - 2 0.9362±1.66e-2plus-or-minus0.93621.66𝑒-20.9362\scriptscriptstyle\pm\scriptstyle 1.66e\text{-}20.9362 ± 1.66 italic_e - 2
0.03125 0.9856±9.97e-3plus-or-minus0.98569.97𝑒-30.9856\scriptscriptstyle\pm\scriptstyle 9.97e\text{-}30.9856 ± 9.97 italic_e - 3 - 0.9065±3.16e-2plus-or-minus0.90653.16𝑒-20.9065\scriptscriptstyle\pm\scriptstyle 3.16e\text{-}20.9065 ± 3.16 italic_e - 2 0.9249±1.62𝐞-𝟐plus-or-minus0.92491.62𝐞-2\mathbf{0.9249\scriptscriptstyle\pm\scriptstyle 1.62e\text{-}2}bold_0.9249 ± bold_1.62 bold_e - bold_2 0.9429±2.79e-2plus-or-minus0.94292.79𝑒-20.9429\scriptscriptstyle\pm\scriptstyle 2.79e\text{-}20.9429 ± 2.79 italic_e - 2
0.0625 0.9830±1.18e-2plus-or-minus0.98301.18𝑒-20.9830\scriptscriptstyle\pm\scriptstyle 1.18e\text{-}20.9830 ± 1.18 italic_e - 2 - 0.8478±3.35e-2plus-or-minus0.84783.35𝑒-20.8478\scriptscriptstyle\pm\scriptstyle 3.35e\text{-}20.8478 ± 3.35 italic_e - 2 0.9146±1.04e-2plus-or-minus0.91461.04𝑒-20.9146\scriptscriptstyle\pm\scriptstyle 1.04e\text{-}20.9146 ± 1.04 italic_e - 2 0.9298±2.71e-2plus-or-minus0.92982.71𝑒-20.9298\scriptscriptstyle\pm\scriptstyle 2.71e\text{-}20.9298 ± 2.71 italic_e - 2
0.1 0.9885±7.41e-3plus-or-minus0.98857.41𝑒-30.9885\scriptscriptstyle\pm\scriptstyle 7.41e\text{-}30.9885 ± 7.41 italic_e - 3 - 0.8471±4.24e-2plus-or-minus0.84714.24𝑒-20.8471\scriptscriptstyle\pm\scriptstyle 4.24e\text{-}20.8471 ± 4.24 italic_e - 2 0.8885±1.16e-2plus-or-minus0.88851.16𝑒-20.8885\scriptscriptstyle\pm\scriptstyle 1.16e\text{-}20.8885 ± 1.16 italic_e - 2 0.9369±2.55e-2plus-or-minus0.93692.55𝑒-20.9369\scriptscriptstyle\pm\scriptstyle 2.55e\text{-}20.9369 ± 2.55 italic_e - 2
0.2 0.9937±3.71𝐞-𝟑plus-or-minus0.99373.71𝐞-3\mathbf{0.9937\scriptscriptstyle\pm\scriptstyle 3.71e\text{-}3}bold_0.9937 ± bold_3.71 bold_e - bold_3 - 0.8719±3.09e-2plus-or-minus0.87193.09𝑒-20.8719\scriptscriptstyle\pm\scriptstyle 3.09e\text{-}20.8719 ± 3.09 italic_e - 2 0.8456±2.75e-2plus-or-minus0.84562.75𝑒-20.8456\scriptscriptstyle\pm\scriptstyle 2.75e\text{-}20.8456 ± 2.75 italic_e - 2 0.9453±1.71e-2plus-or-minus0.94531.71𝑒-20.9453\scriptscriptstyle\pm\scriptstyle 1.71e\text{-}20.9453 ± 1.71 italic_e - 2
0.5 0.9936±4.05e-3plus-or-minus0.99364.05𝑒-30.9936\scriptscriptstyle\pm\scriptstyle 4.05e\text{-}30.9936 ± 4.05 italic_e - 3 - 0.9109±3.60e-2plus-or-minus0.91093.60𝑒-20.9109\scriptscriptstyle\pm\scriptstyle 3.60e\text{-}20.9109 ± 3.60 italic_e - 2 0.8698±2.34e-2plus-or-minus0.86982.34𝑒-20.8698\scriptscriptstyle\pm\scriptstyle 2.34e\text{-}20.8698 ± 2.34 italic_e - 2 0.9572±1.77𝐞-𝟐plus-or-minus0.95721.77𝐞-2\mathbf{0.9572\scriptscriptstyle\pm\scriptstyle 1.77e\text{-}2}bold_0.9572 ± bold_1.77 bold_e - bold_2
StyleGan2lsun 0.0 0.9849±1.35e-2plus-or-minus0.98491.35𝑒-20.9849\scriptscriptstyle\pm\scriptstyle 1.35e\text{-}20.9849 ± 1.35 italic_e - 2 0.8687±3.78e-2plus-or-minus0.86873.78𝑒-20.8687\scriptscriptstyle\pm\scriptstyle 3.78e\text{-}20.8687 ± 3.78 italic_e - 2 - 0.9543±1.79e-2plus-or-minus0.95431.79𝑒-20.9543\scriptscriptstyle\pm\scriptstyle 1.79e\text{-}20.9543 ± 1.79 italic_e - 2 0.9623±2.15e-2plus-or-minus0.96232.15𝑒-20.9623\scriptscriptstyle\pm\scriptstyle 2.15e\text{-}20.9623 ± 2.15 italic_e - 2
0.03125 0.9925±4.85e-3plus-or-minus0.99254.85𝑒-30.9925\scriptscriptstyle\pm\scriptstyle 4.85e\text{-}30.9925 ± 4.85 italic_e - 3 0.9585±2.45e-2plus-or-minus0.95852.45𝑒-20.9585\scriptscriptstyle\pm\scriptstyle 2.45e\text{-}20.9585 ± 2.45 italic_e - 2 - 0.9952±2.71e-3plus-or-minus0.99522.71𝑒-30.9952\scriptscriptstyle\pm\scriptstyle 2.71e\text{-}30.9952 ± 2.71 italic_e - 3 0.9803±1.60e-2plus-or-minus0.98031.60𝑒-20.9803\scriptscriptstyle\pm\scriptstyle 1.60e\text{-}20.9803 ± 1.60 italic_e - 2
0.0625 0.9917±5.44e-3plus-or-minus0.99175.44𝑒-30.9917\scriptscriptstyle\pm\scriptstyle 5.44e\text{-}30.9917 ± 5.44 italic_e - 3 0.9685±1.35𝐞-𝟐plus-or-minus0.96851.35𝐞-2\mathbf{0.9685\scriptscriptstyle\pm\scriptstyle 1.35e\text{-}2}bold_0.9685 ± bold_1.35 bold_e - bold_2 - 0.9953±2.49𝐞-𝟑plus-or-minus0.99532.49𝐞-3\mathbf{0.9953\scriptscriptstyle\pm\scriptstyle 2.49e\text{-}3}bold_0.9953 ± bold_2.49 bold_e - bold_3 0.9836±1.37e-2plus-or-minus0.98361.37𝑒-20.9836\scriptscriptstyle\pm\scriptstyle 1.37e\text{-}20.9836 ± 1.37 italic_e - 2
0.1 0.9926±6.85𝐞-𝟑plus-or-minus0.99266.85𝐞-3\mathbf{0.9926\scriptscriptstyle\pm\scriptstyle 6.85e\text{-}3}bold_0.9926 ± bold_6.85 bold_e - bold_3 0.9649±1.50e-2plus-or-minus0.96491.50𝑒-20.9649\scriptscriptstyle\pm\scriptstyle 1.50e\text{-}20.9649 ± 1.50 italic_e - 2 - 0.9946±1.80e-3plus-or-minus0.99461.80𝑒-30.9946\scriptscriptstyle\pm\scriptstyle 1.80e\text{-}30.9946 ± 1.80 italic_e - 3 0.9851±1.43𝐞-𝟐plus-or-minus0.98511.43𝐞-2\mathbf{0.9851\scriptscriptstyle\pm\scriptstyle 1.43e\text{-}2}bold_0.9851 ± bold_1.43 bold_e - bold_2
0.2 0.9924±3.55e-3plus-or-minus0.99243.55𝑒-30.9924\scriptscriptstyle\pm\scriptstyle 3.55e\text{-}30.9924 ± 3.55 italic_e - 3 0.9500±1.69e-2plus-or-minus0.95001.69𝑒-20.9500\scriptscriptstyle\pm\scriptstyle 1.69e\text{-}20.9500 ± 1.69 italic_e - 2 - 0.9889±4.87e-3plus-or-minus0.98894.87𝑒-30.9889\scriptscriptstyle\pm\scriptstyle 4.87e\text{-}30.9889 ± 4.87 italic_e - 3 0.9833±8.43e-3plus-or-minus0.98338.43𝑒-30.9833\scriptscriptstyle\pm\scriptstyle 8.43e\text{-}30.9833 ± 8.43 italic_e - 3
0.5 0.9912±4.58e-3plus-or-minus0.99124.58𝑒-30.9912\scriptscriptstyle\pm\scriptstyle 4.58e\text{-}30.9912 ± 4.58 italic_e - 3 0.9407±2.38e-2plus-or-minus0.94072.38𝑒-20.9407\scriptscriptstyle\pm\scriptstyle 2.38e\text{-}20.9407 ± 2.38 italic_e - 2 - 0.9885±4.97e-3plus-or-minus0.98854.97𝑒-30.9885\scriptscriptstyle\pm\scriptstyle 4.97e\text{-}30.9885 ± 4.97 italic_e - 3 0.9821±1.02e-2plus-or-minus0.98211.02𝑒-20.9821\scriptscriptstyle\pm\scriptstyle 1.02e\text{-}20.9821 ± 1.02 italic_e - 2
GauGancoco 0.0 0.9901±6.44e-3plus-or-minus0.99016.44𝑒-30.9901\scriptscriptstyle\pm\scriptstyle 6.44e\text{-}30.9901 ± 6.44 italic_e - 3 0.6812±6.34e-2plus-or-minus0.68126.34𝑒-20.6812\scriptscriptstyle\pm\scriptstyle 6.34e\text{-}20.6812 ± 6.34 italic_e - 2 0.9676±1.29𝐞-𝟐plus-or-minus0.96761.29𝐞-2\mathbf{0.9676\scriptscriptstyle\pm\scriptstyle 1.29e\text{-}2}bold_0.9676 ± bold_1.29 bold_e - bold_2 - 0.9368±2.68e-2plus-or-minus0.93682.68𝑒-20.9368\scriptscriptstyle\pm\scriptstyle 2.68e\text{-}20.9368 ± 2.68 italic_e - 2
0.03125 0.9862±1.03e-2plus-or-minus0.98621.03𝑒-20.9862\scriptscriptstyle\pm\scriptstyle 1.03e\text{-}20.9862 ± 1.03 italic_e - 2 0.6965±5.18e-2plus-or-minus0.69655.18𝑒-20.6965\scriptscriptstyle\pm\scriptstyle 5.18e\text{-}20.6965 ± 5.18 italic_e - 2 0.9225±3.06e-2plus-or-minus0.92253.06𝑒-20.9225\scriptscriptstyle\pm\scriptstyle 3.06e\text{-}20.9225 ± 3.06 italic_e - 2 - 0.8991±3.69e-2plus-or-minus0.89913.69𝑒-20.8991\scriptscriptstyle\pm\scriptstyle 3.69e\text{-}20.8991 ± 3.69 italic_e - 2
0.0625 0.9908±4.86e-3plus-or-minus0.99084.86𝑒-30.9908\scriptscriptstyle\pm\scriptstyle 4.86e\text{-}30.9908 ± 4.86 italic_e - 3 0.7132±6.78e-2plus-or-minus0.71326.78𝑒-20.7132\scriptscriptstyle\pm\scriptstyle 6.78e\text{-}20.7132 ± 6.78 italic_e - 2 0.8919±3.83e-2plus-or-minus0.89193.83𝑒-20.8919\scriptscriptstyle\pm\scriptstyle 3.83e\text{-}20.8919 ± 3.83 italic_e - 2 - 0.9051±3.50e-2plus-or-minus0.90513.50𝑒-20.9051\scriptscriptstyle\pm\scriptstyle 3.50e\text{-}20.9051 ± 3.50 italic_e - 2
0.1 0.9958±3.90e-3plus-or-minus0.99583.90𝑒-30.9958\scriptscriptstyle\pm\scriptstyle 3.90e\text{-}30.9958 ± 3.90 italic_e - 3 0.7752±6.78e-2plus-or-minus0.77526.78𝑒-20.7752\scriptscriptstyle\pm\scriptstyle 6.78e\text{-}20.7752 ± 6.78 italic_e - 2 0.9425±3.78e-2plus-or-minus0.94253.78𝑒-20.9425\scriptscriptstyle\pm\scriptstyle 3.78e\text{-}20.9425 ± 3.78 italic_e - 2 - 0.9370±3.31e-2plus-or-minus0.93703.31𝑒-20.9370\scriptscriptstyle\pm\scriptstyle 3.31e\text{-}20.9370 ± 3.31 italic_e - 2
0.2 0.9980±1.97𝐞-𝟑plus-or-minus0.99801.97𝐞-3\mathbf{0.9980\scriptscriptstyle\pm\scriptstyle 1.97e\text{-}3}bold_0.9980 ± bold_1.97 bold_e - bold_3 0.8039±4.45𝐞-𝟐plus-or-minus0.80394.45𝐞-2\mathbf{0.8039\scriptscriptstyle\pm\scriptstyle 4.45e\text{-}2}bold_0.8039 ± bold_4.45 bold_e - bold_2 0.9492±1.26e-2plus-or-minus0.94921.26𝑒-20.9492\scriptscriptstyle\pm\scriptstyle 1.26e\text{-}20.9492 ± 1.26 italic_e - 2 - 0.9535±1.99e-2plus-or-minus0.95351.99𝑒-20.9535\scriptscriptstyle\pm\scriptstyle 1.99e\text{-}20.9535 ± 1.99 italic_e - 2
0.5 0.9976±2.05e-3plus-or-minus0.99762.05𝑒-30.9976\scriptscriptstyle\pm\scriptstyle 2.05e\text{-}30.9976 ± 2.05 italic_e - 3 0.7709±4.78e-2plus-or-minus0.77094.78𝑒-20.7709\scriptscriptstyle\pm\scriptstyle 4.78e\text{-}20.7709 ± 4.78 italic_e - 2 0.9583±1.30e-2plus-or-minus0.95831.30𝑒-20.9583\scriptscriptstyle\pm\scriptstyle 1.30e\text{-}20.9583 ± 1.30 italic_e - 2 - 0.9515±2.17𝐞-𝟐plus-or-minus0.95152.17𝐞-2\mathbf{0.9515\scriptscriptstyle\pm\scriptstyle 2.17e\text{-}2}bold_0.9515 ± bold_2.17 bold_e - bold_2
Table 16: Evaluation sensitivity of different ways of doing ADA on different open world real image datasets. 1)In training phase, conditioned on doing ADA only on half of non-target image set, one of COCO, ImageNet, Flickr, or CC12M is used as the non-target dataset. 2) Conditioned on using non-target images selected from COCO, we do ADA on half of target image set, on half of the both non-target images and target images, and on half of the target images which are then treated as non-target ones.
Methods VQ-D LDM Glide GALIP
COCO+Neg 0.9703±9.06e-3plus-or-minus0.97039.06𝑒-30.9703\scriptscriptstyle\pm\scriptstyle 9.06e\text{-}30.9703 ± 9.06 italic_e - 3 0.8801±2.06e-2plus-or-minus0.88012.06𝑒-20.8801\scriptscriptstyle\pm\scriptstyle 2.06e\text{-}20.8801 ± 2.06 italic_e - 2 0.9519±1.45e-2plus-or-minus0.95191.45𝑒-20.9519\scriptscriptstyle\pm\scriptstyle 1.45e\text{-}20.9519 ± 1.45 italic_e - 2 0.9798±1.18𝐞-𝟐plus-or-minus0.97981.18𝐞-2\mathbf{0.9798\scriptscriptstyle\pm\scriptstyle 1.18e\text{-}2}bold_0.9798 ± bold_1.18 bold_e - bold_2
Flickr+Neg 0.9586±2.17e-2plus-or-minus0.95862.17𝑒-20.9586\scriptscriptstyle\pm\scriptstyle 2.17e\text{-}20.9586 ± 2.17 italic_e - 2 0.8775±2.86e-2plus-or-minus0.87752.86𝑒-20.8775\scriptscriptstyle\pm\scriptstyle 2.86e\text{-}20.8775 ± 2.86 italic_e - 2 0.8805±4.33e-2plus-or-minus0.88054.33𝑒-20.8805\scriptscriptstyle\pm\scriptstyle 4.33e\text{-}20.8805 ± 4.33 italic_e - 2 0.9546±1.89e-2plus-or-minus0.95461.89𝑒-20.9546\scriptscriptstyle\pm\scriptstyle 1.89e\text{-}20.9546 ± 1.89 italic_e - 2
CC12M+Neg 0.8995±2.68e-2plus-or-minus0.89952.68𝑒-20.8995\scriptscriptstyle\pm\scriptstyle 2.68e\text{-}20.8995 ± 2.68 italic_e - 2 0.8523±3.96e-2plus-or-minus0.85233.96𝑒-20.8523\scriptscriptstyle\pm\scriptstyle 3.96e\text{-}20.8523 ± 3.96 italic_e - 2 0.9364±1.74e-2plus-or-minus0.93641.74𝑒-20.9364\scriptscriptstyle\pm\scriptstyle 1.74e\text{-}20.9364 ± 1.74 italic_e - 2 0.9444±2.73e-2plus-or-minus0.94442.73𝑒-20.9444\scriptscriptstyle\pm\scriptstyle 2.73e\text{-}20.9444 ± 2.73 italic_e - 2
ImageNet+Neg 0.9773±7.67𝐞-𝟑plus-or-minus0.97737.67𝐞-3\mathbf{0.9773\scriptscriptstyle\pm\scriptstyle 7.67e\text{-}3}bold_0.9773 ± bold_7.67 bold_e - bold_3 0.9136±2.51𝐞-𝟐plus-or-minus0.91362.51𝐞-2\mathbf{0.9136\scriptscriptstyle\pm\scriptstyle 2.51e\text{-}2}bold_0.9136 ± bold_2.51 bold_e - bold_2 0.9664±1.39𝐞-𝟐plus-or-minus0.96641.39𝐞-2\mathbf{0.9664\scriptscriptstyle\pm\scriptstyle 1.39e\text{-}2}bold_0.9664 ± bold_1.39 bold_e - bold_2 0.9710±2.34e-2plus-or-minus0.97102.34𝑒-20.9710\scriptscriptstyle\pm\scriptstyle 2.34e\text{-}20.9710 ± 2.34 italic_e - 2
COCO+None 0.9503±1.68e-2plus-or-minus0.95031.68𝑒-20.9503\scriptscriptstyle\pm\scriptstyle 1.68e\text{-}20.9503 ± 1.68 italic_e - 2 0.8373±5.33e-2plus-or-minus0.83735.33𝑒-20.8373\scriptscriptstyle\pm\scriptstyle 5.33e\text{-}20.8373 ± 5.33 italic_e - 2 0.9266±3.19e-2plus-or-minus0.92663.19𝑒-20.9266\scriptscriptstyle\pm\scriptstyle 3.19e\text{-}20.9266 ± 3.19 italic_e - 2 0.9660±2.56e-2plus-or-minus0.96602.56𝑒-20.9660\scriptscriptstyle\pm\scriptstyle 2.56e\text{-}20.9660 ± 2.56 italic_e - 2
COCO+Neg 0.9703±9.06𝐞-𝟑plus-or-minus0.97039.06𝐞-3\mathbf{0.9703\scriptscriptstyle\pm\scriptstyle 9.06e\text{-}3}bold_0.9703 ± bold_9.06 bold_e - bold_3 0.8801±2.06e-2plus-or-minus0.88012.06𝑒-20.8801\scriptscriptstyle\pm\scriptstyle 2.06e\text{-}20.8801 ± 2.06 italic_e - 2 0.9519±1.45e-2plus-or-minus0.95191.45𝑒-20.9519\scriptscriptstyle\pm\scriptstyle 1.45e\text{-}20.9519 ± 1.45 italic_e - 2 0.9798±1.18e-2plus-or-minus0.97981.18𝑒-20.9798\scriptscriptstyle\pm\scriptstyle 1.18e\text{-}20.9798 ± 1.18 italic_e - 2
COCO+Both 0.9346±2.32e-2plus-or-minus0.93462.32𝑒-20.9346\scriptscriptstyle\pm\scriptstyle 2.32e\text{-}20.9346 ± 2.32 italic_e - 2 0.8229±5.47e-2plus-or-minus0.82295.47𝑒-20.8229\scriptscriptstyle\pm\scriptstyle 5.47e\text{-}20.8229 ± 5.47 italic_e - 2 0.9070±2.81e-2plus-or-minus0.90702.81𝑒-20.9070\scriptscriptstyle\pm\scriptstyle 2.81e\text{-}20.9070 ± 2.81 italic_e - 2 0.9655±1.86e-2plus-or-minus0.96551.86𝑒-20.9655\scriptscriptstyle\pm\scriptstyle 1.86e\text{-}20.9655 ± 1.86 italic_e - 2
COCO+Target 0.8779±6.93e-2plus-or-minus0.87796.93𝑒-20.8779\scriptscriptstyle\pm\scriptstyle 6.93e\text{-}20.8779 ± 6.93 italic_e - 2 0.7618±8.77e-2plus-or-minus0.76188.77𝑒-20.7618\scriptscriptstyle\pm\scriptstyle 8.77e\text{-}20.7618 ± 8.77 italic_e - 2 0.8728±4.90e-2plus-or-minus0.87284.90𝑒-20.8728\scriptscriptstyle\pm\scriptstyle 4.90e\text{-}20.8728 ± 4.90 italic_e - 2 0.9205±3.83e-2plus-or-minus0.92053.83𝑒-20.9205\scriptscriptstyle\pm\scriptstyle 3.83e\text{-}20.9205 ± 3.83 italic_e - 2
COCO+T-NT 0.9684±2.45e-2plus-or-minus0.96842.45𝑒-20.9684\scriptscriptstyle\pm\scriptstyle 2.45e\text{-}20.9684 ± 2.45 italic_e - 2 0.8818±4.91𝐞-𝟐plus-or-minus0.88184.91𝐞-2\mathbf{0.8818\scriptscriptstyle\pm\scriptstyle 4.91e\text{-}2}bold_0.8818 ± bold_4.91 bold_e - bold_2 0.9522±2.98𝐞-𝟐plus-or-minus0.95222.98𝐞-2\mathbf{0.9522\scriptscriptstyle\pm\scriptstyle 2.98e\text{-}2}bold_0.9522 ± bold_2.98 bold_e - bold_2 0.9803±1.26𝐞-𝟐plus-or-minus0.98031.26𝐞-2\mathbf{0.9803\scriptscriptstyle\pm\scriptstyle 1.26e\text{-}2}bold_0.9803 ± bold_1.26 bold_e - bold_2
Table 17: Evaluation sensitivity of different ways of doing ADA on different open world real image datasets. 1)In training phase, conditioned on doing ADA only on half of non-target image set, one of COCO, ImageNet, Flickr, or CC12M is used as the non-target dataset. 2) Conditioned on using non-target images selected from COCO, we do ADA on half of target image set, on half of the both non-target images and target images, and on half of the target images which are then treated as non-target ones.
Methods ProGan StyleGan2 GauGan Overall
COCO+Neg 0.9452±3.14e-2plus-or-minus0.94523.14𝑒-20.9452\scriptscriptstyle\pm\scriptstyle 3.14e\text{-}20.9452 ± 3.14 italic_e - 2 0.9651±1.54e-2plus-or-minus0.96511.54𝑒-20.9651\scriptscriptstyle\pm\scriptstyle 1.54e\text{-}20.9651 ± 1.54 italic_e - 2 0.9910±7.32e-3plus-or-minus0.99107.32𝑒-30.9910\scriptscriptstyle\pm\scriptstyle 7.32e\text{-}30.9910 ± 7.32 italic_e - 3 0.9548±1.75e-2plus-or-minus0.95481.75𝑒-20.9548\scriptscriptstyle\pm\scriptstyle 1.75e\text{-}20.9548 ± 1.75 italic_e - 2
Flickr+Neg 0.9494±2.17e-2plus-or-minus0.94942.17𝑒-20.9494\scriptscriptstyle\pm\scriptstyle 2.17e\text{-}20.9494 ± 2.17 italic_e - 2 0.9368±3.01e-2plus-or-minus0.93683.01𝑒-20.9368\scriptscriptstyle\pm\scriptstyle 3.01e\text{-}20.9368 ± 3.01 italic_e - 2 0.9908±9.65e-3plus-or-minus0.99089.65𝑒-30.9908\scriptscriptstyle\pm\scriptstyle 9.65e\text{-}30.9908 ± 9.65 italic_e - 3 0.9355±2.67e-2plus-or-minus0.93552.67𝑒-20.9355\scriptscriptstyle\pm\scriptstyle 2.67e\text{-}20.9355 ± 2.67 italic_e - 2
CC12M+Neg 0.9671±1.32e-2plus-or-minus0.96711.32𝑒-20.9671\scriptscriptstyle\pm\scriptstyle 1.32e\text{-}20.9671 ± 1.32 italic_e - 2 0.9422±2.45e-2plus-or-minus0.94222.45𝑒-20.9422\scriptscriptstyle\pm\scriptstyle 2.45e\text{-}20.9422 ± 2.45 italic_e - 2 0.9822±6.75e-3plus-or-minus0.98226.75𝑒-30.9822\scriptscriptstyle\pm\scriptstyle 6.75e\text{-}30.9822 ± 6.75 italic_e - 3 0.9320±2.43e-2plus-or-minus0.93202.43𝑒-20.9320\scriptscriptstyle\pm\scriptstyle 2.43e\text{-}20.9320 ± 2.43 italic_e - 2
ImageNet+Neg 0.9862±4.11𝐞-𝟑plus-or-minus0.98624.11𝐞-3\mathbf{0.9862\scriptscriptstyle\pm\scriptstyle 4.11e\text{-}3}bold_0.9862 ± bold_4.11 bold_e - bold_3 0.9861±4.22𝐞-𝟑plus-or-minus0.98614.22𝐞-3\mathbf{0.9861\scriptscriptstyle\pm\scriptstyle 4.22e\text{-}3}bold_0.9861 ± bold_4.22 bold_e - bold_3 0.9966±1.16𝐞-𝟑plus-or-minus0.99661.16𝐞-3\mathbf{0.9966\scriptscriptstyle\pm\scriptstyle 1.16e\text{-}3}bold_0.9966 ± bold_1.16 bold_e - bold_3 0.9710±1.44𝐞-𝟐plus-or-minus0.97101.44𝐞-2\mathbf{0.9710\scriptscriptstyle\pm\scriptstyle 1.44e\text{-}2}bold_0.9710 ± bold_1.44 bold_e - bold_2
COCO+None 0.8861±4.46e-2plus-or-minus0.88614.46𝑒-20.8861\scriptscriptstyle\pm\scriptstyle 4.46e\text{-}20.8861 ± 4.46 italic_e - 2 0.9533±2.30e-2plus-or-minus0.95332.30𝑒-20.9533\scriptscriptstyle\pm\scriptstyle 2.30e\text{-}20.9533 ± 2.30 italic_e - 2 0.9643±2.91e-2plus-or-minus0.96432.91𝑒-20.9643\scriptscriptstyle\pm\scriptstyle 2.91e\text{-}20.9643 ± 2.91 italic_e - 2 0.9263±3.41e-2plus-or-minus0.92633.41𝑒-20.9263\scriptscriptstyle\pm\scriptstyle 3.41e\text{-}20.9263 ± 3.41 italic_e - 2
COCO+Neg 0.9452±3.14𝐞-𝟐plus-or-minus0.94523.14𝐞-2\mathbf{0.9452\scriptscriptstyle\pm\scriptstyle 3.14e\text{-}2}bold_0.9452 ± bold_3.14 bold_e - bold_2 0.9651±1.54e-2plus-or-minus0.96511.54𝑒-20.9651\scriptscriptstyle\pm\scriptstyle 1.54e\text{-}20.9651 ± 1.54 italic_e - 2 0.9910±7.32𝐞-𝟑plus-or-minus0.99107.32𝐞-3\mathbf{0.9910\scriptscriptstyle\pm\scriptstyle 7.32e\text{-}3}bold_0.9910 ± bold_7.32 bold_e - bold_3 0.9548±1.75𝐞-𝟐plus-or-minus0.95481.75𝐞-2\mathbf{0.9548\scriptscriptstyle\pm\scriptstyle 1.75e\text{-}2}bold_0.9548 ± bold_1.75 bold_e - bold_2
COCO+Both 0.8637±5.45e-2plus-or-minus0.86375.45𝑒-20.8637\scriptscriptstyle\pm\scriptstyle 5.45e\text{-}20.8637 ± 5.45 italic_e - 2 0.9113±5.48e-2plus-or-minus0.91135.48𝑒-20.9113\scriptscriptstyle\pm\scriptstyle 5.48e\text{-}20.9113 ± 5.48 italic_e - 2 0.9511±2.26e-2plus-or-minus0.95112.26𝑒-20.9511\scriptscriptstyle\pm\scriptstyle 2.26e\text{-}20.9511 ± 2.26 italic_e - 2 0.9080±3.99e-2plus-or-minus0.90803.99𝑒-20.9080\scriptscriptstyle\pm\scriptstyle 3.99e\text{-}20.9080 ± 3.99 italic_e - 2
COCO+Target 0.6470±1.15e-1plus-or-minus0.64701.15𝑒-10.6470\scriptscriptstyle\pm\scriptstyle 1.15e\text{-}10.6470 ± 1.15 italic_e - 1 0.9302±3.77e-2plus-or-minus0.93023.77𝑒-20.9302\scriptscriptstyle\pm\scriptstyle 3.77e\text{-}20.9302 ± 3.77 italic_e - 2 0.7553±1.13e-1plus-or-minus0.75531.13𝑒-10.7553\scriptscriptstyle\pm\scriptstyle 1.13e\text{-}10.7553 ± 1.13 italic_e - 1 0.8236±7.90e-2plus-or-minus0.82367.90𝑒-20.8236\scriptscriptstyle\pm\scriptstyle 7.90e\text{-}20.8236 ± 7.90 italic_e - 2
COCO+T-NT 0.9244±4.53e-2plus-or-minus0.92444.53𝑒-20.9244\scriptscriptstyle\pm\scriptstyle 4.53e\text{-}20.9244 ± 4.53 italic_e - 2 0.9665±2.08𝐞-𝟐plus-or-minus0.96652.08𝐞-2\mathbf{0.9665\scriptscriptstyle\pm\scriptstyle 2.08e\text{-}2}bold_0.9665 ± bold_2.08 bold_e - bold_2 0.9859±1.18e-2plus-or-minus0.98591.18𝑒-20.9859\scriptscriptstyle\pm\scriptstyle 1.18e\text{-}20.9859 ± 1.18 italic_e - 2 0.9514±3.09e-2plus-or-minus0.95143.09𝑒-20.9514\scriptscriptstyle\pm\scriptstyle 3.09e\text{-}20.9514 ± 3.09 italic_e - 2
Table 18: Evaluation of OCC-CLIP Relative to the Proportion of Augmented Non-Target Images. Five proportions are investigated: 0%percent00\%0 %, 25%percent2525\%25 %, 50%percent5050\%50 %, 75%percent7575\%75 %, and 100%percent100100\%100 %.
Methods VQ-D LDM Glide GALIP
OCC-CLIP 0% 0.9503±1.68e-2plus-or-minus0.95031.68𝑒-20.9503\scriptscriptstyle\pm\scriptstyle 1.68e\text{-}20.9503 ± 1.68 italic_e - 2 0.8373±5.33e-2plus-or-minus0.83735.33𝑒-20.8373\scriptscriptstyle\pm\scriptstyle 5.33e\text{-}20.8373 ± 5.33 italic_e - 2 0.9266±3.19e-2plus-or-minus0.92663.19𝑒-20.9266\scriptscriptstyle\pm\scriptstyle 3.19e\text{-}20.9266 ± 3.19 italic_e - 2 0.9660±2.56e-2plus-or-minus0.96602.56𝑒-20.9660\scriptscriptstyle\pm\scriptstyle 2.56e\text{-}20.9660 ± 2.56 italic_e - 2
OCC-CLIP 25% 0.9558±2.19e-2plus-or-minus0.95582.19𝑒-20.9558\scriptscriptstyle\pm\scriptstyle 2.19e\text{-}20.9558 ± 2.19 italic_e - 2 0.8519±4.65e-2plus-or-minus0.85194.65𝑒-20.8519\scriptscriptstyle\pm\scriptstyle 4.65e\text{-}20.8519 ± 4.65 italic_e - 2 0.9356±3.23e-2plus-or-minus0.93563.23𝑒-20.9356\scriptscriptstyle\pm\scriptstyle 3.23e\text{-}20.9356 ± 3.23 italic_e - 2 0.9754±1.55e-2plus-or-minus0.97541.55𝑒-20.9754\scriptscriptstyle\pm\scriptstyle 1.55e\text{-}20.9754 ± 1.55 italic_e - 2
OCC-CLIP 50% 0.9703±9.06𝐞-𝟑plus-or-minus0.97039.06𝐞-3\mathbf{0.9703\scriptscriptstyle\pm\scriptstyle 9.06e\text{-}3}bold_0.9703 ± bold_9.06 bold_e - bold_3 0.8801±2.06e-2plus-or-minus0.88012.06𝑒-20.8801\scriptscriptstyle\pm\scriptstyle 2.06e\text{-}20.8801 ± 2.06 italic_e - 2 0.9519±1.45e-2plus-or-minus0.95191.45𝑒-20.9519\scriptscriptstyle\pm\scriptstyle 1.45e\text{-}20.9519 ± 1.45 italic_e - 2 0.9798±1.18e-2plus-or-minus0.97981.18𝑒-20.9798\scriptscriptstyle\pm\scriptstyle 1.18e\text{-}20.9798 ± 1.18 italic_e - 2
OCC-CLIP 75% 0.9683±1.25e-2plus-or-minus0.96831.25𝑒-20.9683\scriptscriptstyle\pm\scriptstyle 1.25e\text{-}20.9683 ± 1.25 italic_e - 2 0.8828±3.34𝐞-𝟐plus-or-minus0.88283.34𝐞-2\mathbf{0.8828\scriptscriptstyle\pm\scriptstyle 3.34e\text{-}2}bold_0.8828 ± bold_3.34 bold_e - bold_2 0.9531±2.17𝐞-𝟐plus-or-minus0.95312.17𝐞-2\mathbf{0.9531\scriptscriptstyle\pm\scriptstyle 2.17e\text{-}2}bold_0.9531 ± bold_2.17 bold_e - bold_2 0.9815±9.53𝐞-𝟑plus-or-minus0.98159.53𝐞-3\mathbf{0.9815\scriptscriptstyle\pm\scriptstyle 9.53e\text{-}3}bold_0.9815 ± bold_9.53 bold_e - bold_3
OCC-CLIP 100% 0.9252±1.72e-2plus-or-minus0.92521.72𝑒-20.9252\scriptscriptstyle\pm\scriptstyle 1.72e\text{-}20.9252 ± 1.72 italic_e - 2 0.8414±2.19e-2plus-or-minus0.84142.19𝑒-20.8414\scriptscriptstyle\pm\scriptstyle 2.19e\text{-}20.8414 ± 2.19 italic_e - 2 0.8996±2.84e-2plus-or-minus0.89962.84𝑒-20.8996\scriptscriptstyle\pm\scriptstyle 2.84e\text{-}20.8996 ± 2.84 italic_e - 2 0.9614±8.53e-3plus-or-minus0.96148.53𝑒-30.9614\scriptscriptstyle\pm\scriptstyle 8.53e\text{-}30.9614 ± 8.53 italic_e - 3
Table 19: Evaluation of OCC-CLIP Relative to the Proportion of Augmented Non-Target Images. Five proportions are investigated: 0%percent00\%0 %, 25%percent2525\%25 %, 50%percent5050\%50 %, 75%percent7575\%75 %, and 100%percent100100\%100 %.
Methods ProGan StyleGan2 GauGan Overall
OCC-CLIP 0% 0.8861±4.46e-2plus-or-minus0.88614.46𝑒-20.8861\scriptscriptstyle\pm\scriptstyle 4.46e\text{-}20.8861 ± 4.46 italic_e - 2 0.9533±2.30e-2plus-or-minus0.95332.30𝑒-20.9533\scriptscriptstyle\pm\scriptstyle 2.30e\text{-}20.9533 ± 2.30 italic_e - 2 0.9643±2.91e-2plus-or-minus0.96432.91𝑒-20.9643\scriptscriptstyle\pm\scriptstyle 2.91e\text{-}20.9643 ± 2.91 italic_e - 2 0.9263±3.41e-2plus-or-minus0.92633.41𝑒-20.9263\scriptscriptstyle\pm\scriptstyle 3.41e\text{-}20.9263 ± 3.41 italic_e - 2
OCC-CLIP 25% 0.9209±5.46e-2plus-or-minus0.92095.46𝑒-20.9209\scriptscriptstyle\pm\scriptstyle 5.46e\text{-}20.9209 ± 5.46 italic_e - 2 0.9561±3.20e-2plus-or-minus0.95613.20𝑒-20.9561\scriptscriptstyle\pm\scriptstyle 3.20e\text{-}20.9561 ± 3.20 italic_e - 2 0.9878±1.15e-2plus-or-minus0.98781.15𝑒-20.9878\scriptscriptstyle\pm\scriptstyle 1.15e\text{-}20.9878 ± 1.15 italic_e - 2 0.9405±3.39e-2plus-or-minus0.94053.39𝑒-20.9405\scriptscriptstyle\pm\scriptstyle 3.39e\text{-}20.9405 ± 3.39 italic_e - 2
OCC-CLIP 50% 0.9452±3.14e-2plus-or-minus0.94523.14𝑒-20.9452\scriptscriptstyle\pm\scriptstyle 3.14e\text{-}20.9452 ± 3.14 italic_e - 2 0.9651±1.54e-2plus-or-minus0.96511.54𝑒-20.9651\scriptscriptstyle\pm\scriptstyle 1.54e\text{-}20.9651 ± 1.54 italic_e - 2 0.9910±7.32e-3plus-or-minus0.99107.32𝑒-30.9910\scriptscriptstyle\pm\scriptstyle 7.32e\text{-}30.9910 ± 7.32 italic_e - 3 0.9548±1.75e-2plus-or-minus0.95481.75𝑒-20.9548\scriptscriptstyle\pm\scriptstyle 1.75e\text{-}20.9548 ± 1.75 italic_e - 2
OCC-CLIP 75% 0.9466±2.23𝐞-𝟐plus-or-minus0.94662.23𝐞-2\mathbf{0.9466\scriptscriptstyle\pm\scriptstyle 2.23e\text{-}2}bold_0.9466 ± bold_2.23 bold_e - bold_2 0.9675±1.58𝐞-𝟐plus-or-minus0.96751.58𝐞-2\mathbf{0.9675\scriptscriptstyle\pm\scriptstyle 1.58e\text{-}2}bold_0.9675 ± bold_1.58 bold_e - bold_2 0.9911±5.11𝐞-𝟑plus-or-minus0.99115.11𝐞-3\mathbf{0.9911\scriptscriptstyle\pm\scriptstyle 5.11e\text{-}3}bold_0.9911 ± bold_5.11 bold_e - bold_3 0.9558±1.93𝐞-𝟐plus-or-minus0.95581.93𝐞-2\mathbf{0.9558\scriptscriptstyle\pm\scriptstyle 1.93e\text{-}2}bold_0.9558 ± bold_1.93 bold_e - bold_2
OCC-CLIP 100% 0.9393±1.86e-2plus-or-minus0.93931.86𝑒-20.9393\scriptscriptstyle\pm\scriptstyle 1.86e\text{-}20.9393 ± 1.86 italic_e - 2 0.8674±2.64e-2plus-or-minus0.86742.64𝑒-20.8674\scriptscriptstyle\pm\scriptstyle 2.64e\text{-}20.8674 ± 2.64 italic_e - 2 0.9861±5.64e-3plus-or-minus0.98615.64𝑒-30.9861\scriptscriptstyle\pm\scriptstyle 5.64e\text{-}30.9861 ± 5.64 italic_e - 3 0.9172±1.98e-2plus-or-minus0.91721.98𝑒-20.9172\scriptscriptstyle\pm\scriptstyle 1.98e\text{-}20.9172 ± 1.98 italic_e - 2
Table 20: Evaluation of OCC-CLIP on Different Numbers of Shots. This table shows the mean origin attribution performance of CoOp and OCC-CLIP on 7 different testing tasks with a variable number of shots: 10, 20, 30, 40, 50, 100, and 200. The target dataset is SD, while the non-target dataset is from one of COCO, CC12M, Flickr, or ImageNet.
Non-Target Methods 10 20 30 40
COCO CoOp 0.7771±1.02e-1plus-or-minus0.77711.02𝑒-10.7771\scriptscriptstyle\pm\scriptstyle 1.02e\text{-}10.7771 ± 1.02 italic_e - 1 0.8500±8.36e-2plus-or-minus0.85008.36𝑒-20.8500\scriptscriptstyle\pm\scriptstyle 8.36e\text{-}20.8500 ± 8.36 italic_e - 2 0.8836±4.45e-2plus-or-minus0.88364.45𝑒-20.8836\scriptscriptstyle\pm\scriptstyle 4.45e\text{-}20.8836 ± 4.45 italic_e - 2 0.9183±4.57e-2plus-or-minus0.91834.57𝑒-20.9183\scriptscriptstyle\pm\scriptstyle 4.57e\text{-}20.9183 ± 4.57 italic_e - 2
OCC-CLIP 0.8842±7.22𝐞-𝟐plus-or-minus0.88427.22𝐞-2\mathbf{0.8842\scriptscriptstyle\pm\scriptstyle 7.22e\text{-}2}bold_0.8842 ± bold_7.22 bold_e - bold_2 0.9293±4.45𝐞-𝟐plus-or-minus0.92934.45𝐞-2\mathbf{0.9293\scriptscriptstyle\pm\scriptstyle 4.45e\text{-}2}bold_0.9293 ± bold_4.45 bold_e - bold_2 0.9435±2.23𝐞-𝟐plus-or-minus0.94352.23𝐞-2\mathbf{0.9435\scriptscriptstyle\pm\scriptstyle 2.23e\text{-}2}bold_0.9435 ± bold_2.23 bold_e - bold_2 0.9494±2.62𝐞-𝟐plus-or-minus0.94942.62𝐞-2\mathbf{0.9494\scriptscriptstyle\pm\scriptstyle 2.62e\text{-}2}bold_0.9494 ± bold_2.62 bold_e - bold_2
Flickr CoOp 0.7905±7.82e-2plus-or-minus0.79057.82𝑒-20.7905\scriptscriptstyle\pm\scriptstyle 7.82e\text{-}20.7905 ± 7.82 italic_e - 2 0.8649±7.54e-2plus-or-minus0.86497.54𝑒-20.8649\scriptscriptstyle\pm\scriptstyle 7.54e\text{-}20.8649 ± 7.54 italic_e - 2 0.8784±4.39e-2plus-or-minus0.87844.39𝑒-20.8784\scriptscriptstyle\pm\scriptstyle 4.39e\text{-}20.8784 ± 4.39 italic_e - 2 0.8734±8.64e-2plus-or-minus0.87348.64𝑒-20.8734\scriptscriptstyle\pm\scriptstyle 8.64e\text{-}20.8734 ± 8.64 italic_e - 2
OCC-CLIP 0.8921±8.26𝐞-𝟐plus-or-minus0.89218.26𝐞-2\mathbf{0.8921\scriptscriptstyle\pm\scriptstyle 8.26e\text{-}2}bold_0.8921 ± bold_8.26 bold_e - bold_2 0.9231±3.86𝐞-𝟐plus-or-minus0.92313.86𝐞-2\mathbf{0.9231\scriptscriptstyle\pm\scriptstyle 3.86e\text{-}2}bold_0.9231 ± bold_3.86 bold_e - bold_2 0.9360±2.32𝐞-𝟐plus-or-minus0.93602.32𝐞-2\mathbf{0.9360\scriptscriptstyle\pm\scriptstyle 2.32e\text{-}2}bold_0.9360 ± bold_2.32 bold_e - bold_2 0.9358±3.88𝐞-𝟐plus-or-minus0.93583.88𝐞-2\mathbf{0.9358\scriptscriptstyle\pm\scriptstyle 3.88e\text{-}2}bold_0.9358 ± bold_3.88 bold_e - bold_2
CC12M CoOp 0.7737±8.18e-2plus-or-minus0.77378.18𝑒-20.7737\scriptscriptstyle\pm\scriptstyle 8.18e\text{-}20.7737 ± 8.18 italic_e - 2 0.8302±7.79e-2plus-or-minus0.83027.79𝑒-20.8302\scriptscriptstyle\pm\scriptstyle 7.79e\text{-}20.8302 ± 7.79 italic_e - 2 0.8640±5.67e-2plus-or-minus0.86405.67𝑒-20.8640\scriptscriptstyle\pm\scriptstyle 5.67e\text{-}20.8640 ± 5.67 italic_e - 2 0.8582±4.77e-2plus-or-minus0.85824.77𝑒-20.8582\scriptscriptstyle\pm\scriptstyle 4.77e\text{-}20.8582 ± 4.77 italic_e - 2
OCC-CLIP 0.8651±8.11𝐞-𝟐plus-or-minus0.86518.11𝐞-2\mathbf{0.8651\scriptscriptstyle\pm\scriptstyle 8.11e\text{-}2}bold_0.8651 ± bold_8.11 bold_e - bold_2 0.9103±4.89𝐞-𝟐plus-or-minus0.91034.89𝐞-2\mathbf{0.9103\scriptscriptstyle\pm\scriptstyle 4.89e\text{-}2}bold_0.9103 ± bold_4.89 bold_e - bold_2 0.9169±3.68𝐞-𝟐plus-or-minus0.91693.68𝐞-2\mathbf{0.9169\scriptscriptstyle\pm\scriptstyle 3.68e\text{-}2}bold_0.9169 ± bold_3.68 bold_e - bold_2 0.9234±4.18𝐞-𝟐plus-or-minus0.92344.18𝐞-2\mathbf{0.9234\scriptscriptstyle\pm\scriptstyle 4.18e\text{-}2}bold_0.9234 ± bold_4.18 bold_e - bold_2
ImageNet CoOp 0.8559±8.04e-2plus-or-minus0.85598.04𝑒-20.8559\scriptscriptstyle\pm\scriptstyle 8.04e\text{-}20.8559 ± 8.04 italic_e - 2 0.8938±5.05e-2plus-or-minus0.89385.05𝑒-20.8938\scriptscriptstyle\pm\scriptstyle 5.05e\text{-}20.8938 ± 5.05 italic_e - 2 0.9308±3.49e-2plus-or-minus0.93083.49𝑒-20.9308\scriptscriptstyle\pm\scriptstyle 3.49e\text{-}20.9308 ± 3.49 italic_e - 2 0.9299±4.02e-2plus-or-minus0.92994.02𝑒-20.9299\scriptscriptstyle\pm\scriptstyle 4.02e\text{-}20.9299 ± 4.02 italic_e - 2
OCC-CLIP 0.9192±6.34𝐞-𝟐plus-or-minus0.91926.34𝐞-2\mathbf{0.9192\scriptscriptstyle\pm\scriptstyle 6.34e\text{-}2}bold_0.9192 ± bold_6.34 bold_e - bold_2 0.9489±2.87𝐞-𝟐plus-or-minus0.94892.87𝐞-2\mathbf{0.9489\scriptscriptstyle\pm\scriptstyle 2.87e\text{-}2}bold_0.9489 ± bold_2.87 bold_e - bold_2 0.9647±1.86𝐞-𝟐plus-or-minus0.96471.86𝐞-2\mathbf{0.9647\scriptscriptstyle\pm\scriptstyle 1.86e\text{-}2}bold_0.9647 ± bold_1.86 bold_e - bold_2 0.9673±2.15𝐞-𝟐plus-or-minus0.96732.15𝐞-2\mathbf{0.9673\scriptscriptstyle\pm\scriptstyle 2.15e\text{-}2}bold_0.9673 ± bold_2.15 bold_e - bold_2
Table 21: Evaluation of OCC-CLIP on Different Numbers of Shots. This table shows the mean origin attribution performance of CoOp and OCC-CLIP on 7 different testing tasks with a variable number of shots: 10, 20, 30, 40, 50, 100, and 200. The target dataset is SD, while the non-target dataset is from one of COCO, CC12M, Flickr, or ImageNet.
Non-Target Methods 50 100 200
COCO CoOp 0.9263±3.41e-2plus-or-minus0.92633.41𝑒-20.9263\scriptscriptstyle\pm\scriptstyle 3.41e\text{-}20.9263 ± 3.41 italic_e - 2 0.9541±2.21e-2plus-or-minus0.95412.21𝑒-20.9541\scriptscriptstyle\pm\scriptstyle 2.21e\text{-}20.9541 ± 2.21 italic_e - 2 0.9601±2.00e-2plus-or-minus0.96012.00𝑒-20.9601\scriptscriptstyle\pm\scriptstyle 2.00e\text{-}20.9601 ± 2.00 italic_e - 2
OCC-CLIP 0.9548±1.75𝐞-𝟐plus-or-minus0.95481.75𝐞-2\mathbf{0.9548\scriptscriptstyle\pm\scriptstyle 1.75e\text{-}2}bold_0.9548 ± bold_1.75 bold_e - bold_2 0.9684±1.56𝐞-𝟐plus-or-minus0.96841.56𝐞-2\mathbf{0.9684\scriptscriptstyle\pm\scriptstyle 1.56e\text{-}2}bold_0.9684 ± bold_1.56 bold_e - bold_2 0.9746±1.08𝐞-𝟐plus-or-minus0.97461.08𝐞-2\mathbf{0.9746\scriptscriptstyle\pm\scriptstyle 1.08e\text{-}2}bold_0.9746 ± bold_1.08 bold_e - bold_2
Flickr CoOp 0.8788±7.17e-2plus-or-minus0.87887.17𝑒-20.8788\scriptscriptstyle\pm\scriptstyle 7.17e\text{-}20.8788 ± 7.17 italic_e - 2 0.9071±3.68e-2plus-or-minus0.90713.68𝑒-20.9071\scriptscriptstyle\pm\scriptstyle 3.68e\text{-}20.9071 ± 3.68 italic_e - 2 0.9177±3.46e-2plus-or-minus0.91773.46𝑒-20.9177\scriptscriptstyle\pm\scriptstyle 3.46e\text{-}20.9177 ± 3.46 italic_e - 2
OCC-CLIP 0.9355±2.67𝐞-𝟐plus-or-minus0.93552.67𝐞-2\mathbf{0.9355\scriptscriptstyle\pm\scriptstyle 2.67e\text{-}2}bold_0.9355 ± bold_2.67 bold_e - bold_2 0.9531±2.88𝐞-𝟐plus-or-minus0.95312.88𝐞-2\mathbf{0.9531\scriptscriptstyle\pm\scriptstyle 2.88e\text{-}2}bold_0.9531 ± bold_2.88 bold_e - bold_2 0.9588±3.35𝐞-𝟐plus-or-minus0.95883.35𝐞-2\mathbf{0.9588\scriptscriptstyle\pm\scriptstyle 3.35e\text{-}2}bold_0.9588 ± bold_3.35 bold_e - bold_2
CC12M CoOp 0.8689±4.27e-2plus-or-minus0.86894.27𝑒-20.8689\scriptscriptstyle\pm\scriptstyle 4.27e\text{-}20.8689 ± 4.27 italic_e - 2 0.8973±3.62e-2plus-or-minus0.89733.62𝑒-20.8973\scriptscriptstyle\pm\scriptstyle 3.62e\text{-}20.8973 ± 3.62 italic_e - 2 0.8922±3.70e-2plus-or-minus0.89223.70𝑒-20.8922\scriptscriptstyle\pm\scriptstyle 3.70e\text{-}20.8922 ± 3.70 italic_e - 2
OCC-CLIP 0.9320±2.43𝐞-𝟐plus-or-minus0.93202.43𝐞-2\mathbf{0.9320\scriptscriptstyle\pm\scriptstyle 2.43e\text{-}2}bold_0.9320 ± bold_2.43 bold_e - bold_2 0.9342±3.18𝐞-𝟐plus-or-minus0.93423.18𝐞-2\mathbf{0.9342\scriptscriptstyle\pm\scriptstyle 3.18e\text{-}2}bold_0.9342 ± bold_3.18 bold_e - bold_2 0.9331±3.55𝐞-𝟐plus-or-minus0.93313.55𝐞-2\mathbf{0.9331\scriptscriptstyle\pm\scriptstyle 3.55e\text{-}2}bold_0.9331 ± bold_3.55 bold_e - bold_2
ImageNet CoOp 0.9377±3.12e-2plus-or-minus0.93773.12𝑒-20.9377\scriptscriptstyle\pm\scriptstyle 3.12e\text{-}20.9377 ± 3.12 italic_e - 2 0.9507±2.28e-2plus-or-minus0.95072.28𝑒-20.9507\scriptscriptstyle\pm\scriptstyle 2.28e\text{-}20.9507 ± 2.28 italic_e - 2 0.9663±1.57e-2plus-or-minus0.96631.57𝑒-20.9663\scriptscriptstyle\pm\scriptstyle 1.57e\text{-}20.9663 ± 1.57 italic_e - 2
OCC-CLIP 0.9710±1.44𝐞-𝟐plus-or-minus0.97101.44𝐞-2\mathbf{0.9710\scriptscriptstyle\pm\scriptstyle 1.44e\text{-}2}bold_0.9710 ± bold_1.44 bold_e - bold_2 0.9768±5.42𝐞-𝟑plus-or-minus0.97685.42𝐞-3\mathbf{0.9768\scriptscriptstyle\pm\scriptstyle 5.42e\text{-}3}bold_0.9768 ± bold_5.42 bold_e - bold_3 0.9813±8.37𝐞-𝟑plus-or-minus0.98138.37𝐞-3\mathbf{0.9813\scriptscriptstyle\pm\scriptstyle 8.37e\text{-}3}bold_0.9813 ± bold_8.37 bold_e - bold_3
Table 22: Evaluation of OCC-CLIP under Image Processing. Six image processing methods are executed: Gaussian Blur, Gaussian Noise, Grayscale, Rotation, Flip, and a mixture of all the these data augmentation methods.
Process Method VQ-D LDM Glide GALIP
None CoOp 0.9503±1.68e-2plus-or-minus0.95031.68𝑒-20.9503\scriptscriptstyle\pm\scriptstyle 1.68e\text{-}20.9503 ± 1.68 italic_e - 2 0.8373±5.33e-2plus-or-minus0.83735.33𝑒-20.8373\scriptscriptstyle\pm\scriptstyle 5.33e\text{-}20.8373 ± 5.33 italic_e - 2 0.9266±3.19e-2plus-or-minus0.92663.19𝑒-20.9266\scriptscriptstyle\pm\scriptstyle 3.19e\text{-}20.9266 ± 3.19 italic_e - 2 0.9660±2.56e-2plus-or-minus0.96602.56𝑒-20.9660\scriptscriptstyle\pm\scriptstyle 2.56e\text{-}20.9660 ± 2.56 italic_e - 2
OCC-CLIP 0.9703±9.06𝐞-𝟑plus-or-minus0.97039.06𝐞-3\mathbf{0.9703\scriptscriptstyle\pm\scriptstyle 9.06e\text{-}3}bold_0.9703 ± bold_9.06 bold_e - bold_3 0.8801±2.06𝐞-𝟐plus-or-minus0.88012.06𝐞-2\mathbf{0.8801\scriptscriptstyle\pm\scriptstyle 2.06e\text{-}2}bold_0.8801 ± bold_2.06 bold_e - bold_2 0.9519±1.45𝐞-𝟐plus-or-minus0.95191.45𝐞-2\mathbf{0.9519\scriptscriptstyle\pm\scriptstyle 1.45e\text{-}2}bold_0.9519 ± bold_1.45 bold_e - bold_2 0.9798±1.18𝐞-𝟐plus-or-minus0.97981.18𝐞-2\mathbf{0.9798\scriptscriptstyle\pm\scriptstyle 1.18e\text{-}2}bold_0.9798 ± bold_1.18 bold_e - bold_2
Gaussian Blur CoOp 0.8918±3.15e-2plus-or-minus0.89183.15𝑒-20.8918\scriptscriptstyle\pm\scriptstyle 3.15e\text{-}20.8918 ± 3.15 italic_e - 2 0.7067±6.27e-2plus-or-minus0.70676.27𝑒-20.7067\scriptscriptstyle\pm\scriptstyle 6.27e\text{-}20.7067 ± 6.27 italic_e - 2 0.8555±3.86e-2plus-or-minus0.85553.86𝑒-20.8555\scriptscriptstyle\pm\scriptstyle 3.86e\text{-}20.8555 ± 3.86 italic_e - 2 0.9240±4.39e-2plus-or-minus0.92404.39𝑒-20.9240\scriptscriptstyle\pm\scriptstyle 4.39e\text{-}20.9240 ± 4.39 italic_e - 2
OCC-CLIP 0.9286±2.54𝐞-𝟐plus-or-minus0.92862.54𝐞-2\mathbf{0.9286\scriptscriptstyle\pm\scriptstyle 2.54e\text{-}2}bold_0.9286 ± bold_2.54 bold_e - bold_2 0.7700±4.71𝐞-𝟐plus-or-minus0.77004.71𝐞-2\mathbf{0.7700\scriptscriptstyle\pm\scriptstyle 4.71e\text{-}2}bold_0.7700 ± bold_4.71 bold_e - bold_2 0.8914±3.59𝐞-𝟐plus-or-minus0.89143.59𝐞-2\mathbf{0.8914\scriptscriptstyle\pm\scriptstyle 3.59e\text{-}2}bold_0.8914 ± bold_3.59 bold_e - bold_2 0.9502±2.53𝐞-𝟐plus-or-minus0.95022.53𝐞-2\mathbf{0.9502\scriptscriptstyle\pm\scriptstyle 2.53e\text{-}2}bold_0.9502 ± bold_2.53 bold_e - bold_2
Gaussian Noise CoOp 0.9159±3.99e-2plus-or-minus0.91593.99𝑒-20.9159\scriptscriptstyle\pm\scriptstyle 3.99e\text{-}20.9159 ± 3.99 italic_e - 2 0.7646±8.89e-2plus-or-minus0.76468.89𝑒-20.7646\scriptscriptstyle\pm\scriptstyle 8.89e\text{-}20.7646 ± 8.89 italic_e - 2 0.8847±5.81e-2plus-or-minus0.88475.81𝑒-20.8847\scriptscriptstyle\pm\scriptstyle 5.81e\text{-}20.8847 ± 5.81 italic_e - 2 0.9374±4.72e-2plus-or-minus0.93744.72𝑒-20.9374\scriptscriptstyle\pm\scriptstyle 4.72e\text{-}20.9374 ± 4.72 italic_e - 2
OCC-CLIP 0.9348±2.60𝐞-𝟐plus-or-minus0.93482.60𝐞-2\mathbf{0.9348\scriptscriptstyle\pm\scriptstyle 2.60e\text{-}2}bold_0.9348 ± bold_2.60 bold_e - bold_2 0.7877±6.07𝐞-𝟐plus-or-minus0.78776.07𝐞-2\mathbf{0.7877\scriptscriptstyle\pm\scriptstyle 6.07e\text{-}2}bold_0.7877 ± bold_6.07 bold_e - bold_2 0.8993±4.49𝐞-𝟐plus-or-minus0.89934.49𝐞-2\mathbf{0.8993\scriptscriptstyle\pm\scriptstyle 4.49e\text{-}2}bold_0.8993 ± bold_4.49 bold_e - bold_2 0.9479±4.08𝐞-𝟐plus-or-minus0.94794.08𝐞-2\mathbf{0.9479\scriptscriptstyle\pm\scriptstyle 4.08e\text{-}2}bold_0.9479 ± bold_4.08 bold_e - bold_2
Grayscale CoOp 0.8455±5.94e-2plus-or-minus0.84555.94𝑒-20.8455\scriptscriptstyle\pm\scriptstyle 5.94e\text{-}20.8455 ± 5.94 italic_e - 2 0.6348±8.15e-2plus-or-minus0.63488.15𝑒-20.6348\scriptscriptstyle\pm\scriptstyle 8.15e\text{-}20.6348 ± 8.15 italic_e - 2 0.7987±7.14e-2plus-or-minus0.79877.14𝑒-20.7987\scriptscriptstyle\pm\scriptstyle 7.14e\text{-}20.7987 ± 7.14 italic_e - 2 0.8852±8.56e-2plus-or-minus0.88528.56𝑒-20.8852\scriptscriptstyle\pm\scriptstyle 8.56e\text{-}20.8852 ± 8.56 italic_e - 2
OCC-CLIP 0.8817±4.82𝐞-𝟐plus-or-minus0.88174.82𝐞-2\mathbf{0.8817\scriptscriptstyle\pm\scriptstyle 4.82e\text{-}2}bold_0.8817 ± bold_4.82 bold_e - bold_2 0.6575±9.85𝐞-𝟐plus-or-minus0.65759.85𝐞-2\mathbf{0.6575\scriptscriptstyle\pm\scriptstyle 9.85e\text{-}2}bold_0.6575 ± bold_9.85 bold_e - bold_2 0.8254±5.91𝐞-𝟐plus-or-minus0.82545.91𝐞-2\mathbf{0.8254\scriptscriptstyle\pm\scriptstyle 5.91e\text{-}2}bold_0.8254 ± bold_5.91 bold_e - bold_2 0.9085±5.80𝐞-𝟐plus-or-minus0.90855.80𝐞-2\mathbf{0.9085\scriptscriptstyle\pm\scriptstyle 5.80e\text{-}2}bold_0.9085 ± bold_5.80 bold_e - bold_2
Rotate 90 CoOp 0.9319±2.56e-2plus-or-minus0.93192.56𝑒-20.9319\scriptscriptstyle\pm\scriptstyle 2.56e\text{-}20.9319 ± 2.56 italic_e - 2 0.7996±6.96e-2plus-or-minus0.79966.96𝑒-20.7996\scriptscriptstyle\pm\scriptstyle 6.96e\text{-}20.7996 ± 6.96 italic_e - 2 0.9033±4.44e-2plus-or-minus0.90334.44𝑒-20.9033\scriptscriptstyle\pm\scriptstyle 4.44e\text{-}20.9033 ± 4.44 italic_e - 2 0.9514±3.88e-2plus-or-minus0.95143.88𝑒-20.9514\scriptscriptstyle\pm\scriptstyle 3.88e\text{-}20.9514 ± 3.88 italic_e - 2
OCC-CLIP 0.9547±1.29𝐞-𝟐plus-or-minus0.95471.29𝐞-2\mathbf{0.9547\scriptscriptstyle\pm\scriptstyle 1.29e\text{-}2}bold_0.9547 ± bold_1.29 bold_e - bold_2 0.8406±2.94𝐞-𝟐plus-or-minus0.84062.94𝐞-2\mathbf{0.8406\scriptscriptstyle\pm\scriptstyle 2.94e\text{-}2}bold_0.8406 ± bold_2.94 bold_e - bold_2 0.9290±2.07𝐞-𝟐plus-or-minus0.92902.07𝐞-2\mathbf{0.9290\scriptscriptstyle\pm\scriptstyle 2.07e\text{-}2}bold_0.9290 ± bold_2.07 bold_e - bold_2 0.9680±1.78𝐞-𝟐plus-or-minus0.96801.78𝐞-2\mathbf{0.9680\scriptscriptstyle\pm\scriptstyle 1.78e\text{-}2}bold_0.9680 ± bold_1.78 bold_e - bold_2
Flip CoOp 0.9481±2.23e-2plus-or-minus0.94812.23𝑒-20.9481\scriptscriptstyle\pm\scriptstyle 2.23e\text{-}20.9481 ± 2.23 italic_e - 2 0.8327±6.56e-2plus-or-minus0.83276.56𝑒-20.8327\scriptscriptstyle\pm\scriptstyle 6.56e\text{-}20.8327 ± 6.56 italic_e - 2 0.9233±3.89e-2plus-or-minus0.92333.89𝑒-20.9233\scriptscriptstyle\pm\scriptstyle 3.89e\text{-}20.9233 ± 3.89 italic_e - 2 0.9634±3.23e-2plus-or-minus0.96343.23𝑒-20.9634\scriptscriptstyle\pm\scriptstyle 3.23e\text{-}20.9634 ± 3.23 italic_e - 2
OCC-CLIP 0.9650±1.27𝐞-𝟐plus-or-minus0.96501.27𝐞-2\mathbf{0.9650\scriptscriptstyle\pm\scriptstyle 1.27e\text{-}2}bold_0.9650 ± bold_1.27 bold_e - bold_2 0.8675±3.28𝐞-𝟐plus-or-minus0.86753.28𝐞-2\mathbf{0.8675\scriptscriptstyle\pm\scriptstyle 3.28e\text{-}2}bold_0.8675 ± bold_3.28 bold_e - bold_2 0.9434±2.39𝐞-𝟐plus-or-minus0.94342.39𝐞-2\mathbf{0.9434\scriptscriptstyle\pm\scriptstyle 2.39e\text{-}2}bold_0.9434 ± bold_2.39 bold_e - bold_2 0.9754±1.56𝐞-𝟐plus-or-minus0.97541.56𝐞-2\mathbf{0.9754\scriptscriptstyle\pm\scriptstyle 1.56e\text{-}2}bold_0.9754 ± bold_1.56 bold_e - bold_2
Mixture CoOp 0.7858±6.29e-2plus-or-minus0.78586.29𝑒-20.7858\scriptscriptstyle\pm\scriptstyle 6.29e\text{-}20.7858 ± 6.29 italic_e - 2 0.5855±6.07e-2plus-or-minus0.58556.07𝑒-20.5855\scriptscriptstyle\pm\scriptstyle 6.07e\text{-}20.5855 ± 6.07 italic_e - 2 0.7314±8.42𝐞-𝟐plus-or-minus0.73148.42𝐞-2\mathbf{0.7314\scriptscriptstyle\pm\scriptstyle 8.42e\text{-}2}bold_0.7314 ± bold_8.42 bold_e - bold_2 0.8405±8.70𝐞-𝟐plus-or-minus0.84058.70𝐞-2\mathbf{0.8405\scriptscriptstyle\pm\scriptstyle 8.70e\text{-}2}bold_0.8405 ± bold_8.70 bold_e - bold_2
OCC-CLIP 0.7895±6.61𝐞-𝟐plus-or-minus0.78956.61𝐞-2\mathbf{0.7895\scriptscriptstyle\pm\scriptstyle 6.61e\text{-}2}bold_0.7895 ± bold_6.61 bold_e - bold_2 0.5959±4.79𝐞-𝟐plus-or-minus0.59594.79𝐞-2\mathbf{0.5959\scriptscriptstyle\pm\scriptstyle 4.79e\text{-}2}bold_0.5959 ± bold_4.79 bold_e - bold_2 0.7137±7.38e-2plus-or-minus0.71377.38𝑒-20.7137\scriptscriptstyle\pm\scriptstyle 7.38e\text{-}20.7137 ± 7.38 italic_e - 2 0.8276±8.91e-2plus-or-minus0.82768.91𝑒-20.8276\scriptscriptstyle\pm\scriptstyle 8.91e\text{-}20.8276 ± 8.91 italic_e - 2
Table 23: Evaluation of OCC-CLIP under Image Processing. Six image processing methods are executed: Gaussian Blur, Gaussian Noise, Grayscale, Rotation, Flip, and a mixture of all the these data augmentation methods.
Process Method ProGan StyleGan2 GauGan Overall
None CoOp 0.8861±4.46e-2plus-or-minus0.88614.46𝑒-20.8861\scriptscriptstyle\pm\scriptstyle 4.46e\text{-}20.8861 ± 4.46 italic_e - 2 0.9533±2.30e-2plus-or-minus0.95332.30𝑒-20.9533\scriptscriptstyle\pm\scriptstyle 2.30e\text{-}20.9533 ± 2.30 italic_e - 2 0.9643±2.91e-2plus-or-minus0.96432.91𝑒-20.9643\scriptscriptstyle\pm\scriptstyle 2.91e\text{-}20.9643 ± 2.91 italic_e - 2 0.9263±3.41e-2plus-or-minus0.92633.41𝑒-20.9263\scriptscriptstyle\pm\scriptstyle 3.41e\text{-}20.9263 ± 3.41 italic_e - 2
OCC-CLIP 0.9452±3.14𝐞-𝟐plus-or-minus0.94523.14𝐞-2\mathbf{0.9452\scriptscriptstyle\pm\scriptstyle 3.14e\text{-}2}bold_0.9452 ± bold_3.14 bold_e - bold_2 0.9651±1.54𝐞-𝟐plus-or-minus0.96511.54𝐞-2\mathbf{0.9651\scriptscriptstyle\pm\scriptstyle 1.54e\text{-}2}bold_0.9651 ± bold_1.54 bold_e - bold_2 0.9910±7.32𝐞-𝟑plus-or-minus0.99107.32𝐞-3\mathbf{0.9910\scriptscriptstyle\pm\scriptstyle 7.32e\text{-}3}bold_0.9910 ± bold_7.32 bold_e - bold_3 0.9548±1.75𝐞-𝟐plus-or-minus0.95481.75𝐞-2\mathbf{0.9548\scriptscriptstyle\pm\scriptstyle 1.75e\text{-}2}bold_0.9548 ± bold_1.75 bold_e - bold_2
Gaussian Blur CoOp 0.7772±8.53e-2plus-or-minus0.77728.53𝑒-20.7772\scriptscriptstyle\pm\scriptstyle 8.53e\text{-}20.7772 ± 8.53 italic_e - 2 0.9042±3.74e-2plus-or-minus0.90423.74𝑒-20.9042\scriptscriptstyle\pm\scriptstyle 3.74e\text{-}20.9042 ± 3.74 italic_e - 2 0.9181±6.47e-2plus-or-minus0.91816.47𝑒-20.9181\scriptscriptstyle\pm\scriptstyle 6.47e\text{-}20.9181 ± 6.47 italic_e - 2 0.8539±5.50e-2plus-or-minus0.85395.50𝑒-20.8539\scriptscriptstyle\pm\scriptstyle 5.50e\text{-}20.8539 ± 5.50 italic_e - 2
OCC-CLIP 0.8796±4.99𝐞-𝟐plus-or-minus0.87964.99𝐞-2\mathbf{0.8796\scriptscriptstyle\pm\scriptstyle 4.99e\text{-}2}bold_0.8796 ± bold_4.99 bold_e - bold_2 0.9072±4.48𝐞-𝟐plus-or-minus0.90724.48𝐞-2\mathbf{0.9072\scriptscriptstyle\pm\scriptstyle 4.48e\text{-}2}bold_0.9072 ± bold_4.48 bold_e - bold_2 0.9743±1.54𝐞-𝟐plus-or-minus0.97431.54𝐞-2\mathbf{0.9743\scriptscriptstyle\pm\scriptstyle 1.54e\text{-}2}bold_0.9743 ± bold_1.54 bold_e - bold_2 0.9002±3.69𝐞-𝟐plus-or-minus0.90023.69𝐞-2\mathbf{0.9002\scriptscriptstyle\pm\scriptstyle 3.69e\text{-}2}bold_0.9002 ± bold_3.69 bold_e - bold_2
Gaussian Noise CoOp 0.8298±6.86e-2plus-or-minus0.82986.86𝑒-20.8298\scriptscriptstyle\pm\scriptstyle 6.86e\text{-}20.8298 ± 6.86 italic_e - 2 0.9269±3.56e-2plus-or-minus0.92693.56𝑒-20.9269\scriptscriptstyle\pm\scriptstyle 3.56e\text{-}20.9269 ± 3.56 italic_e - 2 0.9418±5.39e-2plus-or-minus0.94185.39𝑒-20.9418\scriptscriptstyle\pm\scriptstyle 5.39e\text{-}20.9418 ± 5.39 italic_e - 2 0.8859±5.85e-2plus-or-minus0.88595.85𝑒-20.8859\scriptscriptstyle\pm\scriptstyle 5.85e\text{-}20.8859 ± 5.85 italic_e - 2
OCC-CLIP 0.8947±3.06𝐞-𝟐plus-or-minus0.89473.06𝐞-2\mathbf{0.8947\scriptscriptstyle\pm\scriptstyle 3.06e\text{-}2}bold_0.8947 ± bold_3.06 bold_e - bold_2 0.9194±3.15𝐞-𝟐plus-or-minus0.91943.15𝐞-2\mathbf{0.9194\scriptscriptstyle\pm\scriptstyle 3.15e\text{-}2}bold_0.9194 ± bold_3.15 bold_e - bold_2 0.9783±1.17𝐞-𝟐plus-or-minus0.97831.17𝐞-2\mathbf{0.9783\scriptscriptstyle\pm\scriptstyle 1.17e\text{-}2}bold_0.9783 ± bold_1.17 bold_e - bold_2 0.9089±3.80𝐞-𝟐plus-or-minus0.90893.80𝐞-2\mathbf{0.9089\scriptscriptstyle\pm\scriptstyle 3.80e\text{-}2}bold_0.9089 ± bold_3.80 bold_e - bold_2
Grayscale CoOp 0.7002±1.21e-1plus-or-minus0.70021.21𝑒-10.7002\scriptscriptstyle\pm\scriptstyle 1.21e\text{-}10.7002 ± 1.21 italic_e - 1 0.8636±7.01e-2plus-or-minus0.86367.01𝑒-20.8636\scriptscriptstyle\pm\scriptstyle 7.01e\text{-}20.8636 ± 7.01 italic_e - 2 0.8839±9.39e-2plus-or-minus0.88399.39𝑒-20.8839\scriptscriptstyle\pm\scriptstyle 9.39e\text{-}20.8839 ± 9.39 italic_e - 2 0.8017±8.54e-2plus-or-minus0.80178.54𝑒-20.8017\scriptscriptstyle\pm\scriptstyle 8.54e\text{-}20.8017 ± 8.54 italic_e - 2
OCC-CLIP 0.8166±1.00𝐞-𝟏plus-or-minus0.81661.00𝐞-1\mathbf{0.8166\scriptscriptstyle\pm\scriptstyle 1.00e\text{-}1}bold_0.8166 ± bold_1.00 bold_e - bold_1 0.8472±8.88𝐞-𝟐plus-or-minus0.84728.88𝐞-2\mathbf{0.8472\scriptscriptstyle\pm\scriptstyle 8.88e\text{-}2}bold_0.8472 ± bold_8.88 bold_e - bold_2 0.9468±6.20𝐞-𝟐plus-or-minus0.94686.20𝐞-2\mathbf{0.9468\scriptscriptstyle\pm\scriptstyle 6.20e\text{-}2}bold_0.9468 ± bold_6.20 bold_e - bold_2 0.8405±7.62𝐞-𝟐plus-or-minus0.84057.62𝐞-2\mathbf{0.8405\scriptscriptstyle\pm\scriptstyle 7.62e\text{-}2}bold_0.8405 ± bold_7.62 bold_e - bold_2
Rotate 90 CoOp 0.8545±5.40e-2plus-or-minus0.85455.40𝑒-20.8545\scriptscriptstyle\pm\scriptstyle 5.40e\text{-}20.8545 ± 5.40 italic_e - 2 0.9369±3.27e-2plus-or-minus0.93693.27𝑒-20.9369\scriptscriptstyle\pm\scriptstyle 3.27e\text{-}20.9369 ± 3.27 italic_e - 2 0.9502±3.58e-2plus-or-minus0.95023.58𝑒-20.9502\scriptscriptstyle\pm\scriptstyle 3.58e\text{-}20.9502 ± 3.58 italic_e - 2 0.9040±4.51e-2plus-or-minus0.90404.51𝑒-20.9040\scriptscriptstyle\pm\scriptstyle 4.51e\text{-}20.9040 ± 4.51 italic_e - 2
OCC-CLIP 0.9195±3.33𝐞-𝟐plus-or-minus0.91953.33𝐞-2\mathbf{0.9195\scriptscriptstyle\pm\scriptstyle 3.33e\text{-}2}bold_0.9195 ± bold_3.33 bold_e - bold_2 0.9410±2.49𝐞-𝟐plus-or-minus0.94102.49𝐞-2\mathbf{0.9410\scriptscriptstyle\pm\scriptstyle 2.49e\text{-}2}bold_0.9410 ± bold_2.49 bold_e - bold_2 0.9832±1.12𝐞-𝟐plus-or-minus0.98321.12𝐞-2\mathbf{0.9832\scriptscriptstyle\pm\scriptstyle 1.12e\text{-}2}bold_0.9832 ± bold_1.12 bold_e - bold_2 0.9337±2.28𝐞-𝟐plus-or-minus0.93372.28𝐞-2\mathbf{0.9337\scriptscriptstyle\pm\scriptstyle 2.28e\text{-}2}bold_0.9337 ± bold_2.28 bold_e - bold_2
Flip CoOp 0.8842±4.61e-2plus-or-minus0.88424.61𝑒-20.8842\scriptscriptstyle\pm\scriptstyle 4.61e\text{-}20.8842 ± 4.61 italic_e - 2 0.9535±2.55e-2plus-or-minus0.95352.55𝑒-20.9535\scriptscriptstyle\pm\scriptstyle 2.55e\text{-}20.9535 ± 2.55 italic_e - 2 0.9639±2.98e-2plus-or-minus0.96392.98𝑒-20.9639\scriptscriptstyle\pm\scriptstyle 2.98e\text{-}20.9639 ± 2.98 italic_e - 2 0.9241±3.97e-2plus-or-minus0.92413.97𝑒-20.9241\scriptscriptstyle\pm\scriptstyle 3.97e\text{-}20.9241 ± 3.97 italic_e - 2
OCC-CLIP 0.9384±2.92𝐞-𝟐plus-or-minus0.93842.92𝐞-2\mathbf{0.9384\scriptscriptstyle\pm\scriptstyle 2.92e\text{-}2}bold_0.9384 ± bold_2.92 bold_e - bold_2 0.9567±2.29𝐞-𝟐plus-or-minus0.95672.29𝐞-2\mathbf{0.9567\scriptscriptstyle\pm\scriptstyle 2.29e\text{-}2}bold_0.9567 ± bold_2.29 bold_e - bold_2 0.9892±8.51𝐞-𝟑plus-or-minus0.98928.51𝐞-3\mathbf{0.9892\scriptscriptstyle\pm\scriptstyle 8.51e\text{-}3}bold_0.9892 ± bold_8.51 bold_e - bold_3 0.9479±2.24𝐞-𝟐plus-or-minus0.94792.24𝐞-2\mathbf{0.9479\scriptscriptstyle\pm\scriptstyle 2.24e\text{-}2}bold_0.9479 ± bold_2.24 bold_e - bold_2
Mixture CoOp 0.6456±9.21e-2plus-or-minus0.64569.21𝑒-20.6456\scriptscriptstyle\pm\scriptstyle 9.21e\text{-}20.6456 ± 9.21 italic_e - 2 0.7991±8.54𝐞-𝟐plus-or-minus0.79918.54𝐞-2\mathbf{0.7991\scriptscriptstyle\pm\scriptstyle 8.54e\text{-}2}bold_0.7991 ± bold_8.54 bold_e - bold_2 0.8320±1.09e-1plus-or-minus0.83201.09𝑒-10.8320\scriptscriptstyle\pm\scriptstyle 1.09e\text{-}10.8320 ± 1.09 italic_e - 1 0.7457±8.45e-2plus-or-minus0.74578.45𝑒-20.7457\scriptscriptstyle\pm\scriptstyle 8.45e\text{-}20.7457 ± 8.45 italic_e - 2
OCC-CLIP 0.7224±7.87𝐞-𝟐plus-or-minus0.72247.87𝐞-2\mathbf{0.7224\scriptscriptstyle\pm\scriptstyle 7.87e\text{-}2}bold_0.7224 ± bold_7.87 bold_e - bold_2 0.7332±1.16e-1plus-or-minus0.73321.16𝑒-10.7332\scriptscriptstyle\pm\scriptstyle 1.16e\text{-}10.7332 ± 1.16 italic_e - 1 0.8946±8.37𝐞-𝟐plus-or-minus0.89468.37𝐞-2\mathbf{0.8946\scriptscriptstyle\pm\scriptstyle 8.37e\text{-}2}bold_0.8946 ± bold_8.37 bold_e - bold_2 0.7538±8.17𝐞-𝟐plus-or-minus0.75388.17𝐞-2\mathbf{0.7538\scriptscriptstyle\pm\scriptstyle 8.17e\text{-}2}bold_0.7538 ± bold_8.17 bold_e - bold_2
Table 24: Evaluation sensitivity to choice of prompts. This table shows the performance of OCC-CLIP and CoOp under different choices of label pairs.
Names of Classes Methods VQ-D LDM Glide GALIP
fake-real CoOp 0.9432±2.04e-2plus-or-minus0.94322.04𝑒-20.9432\scriptscriptstyle\pm\scriptstyle 2.04e\text{-}20.9432 ± 2.04 italic_e - 2 0.8224±5.69e-2plus-or-minus0.82245.69𝑒-20.8224\scriptscriptstyle\pm\scriptstyle 5.69e\text{-}20.8224 ± 5.69 italic_e - 2 0.9128±3.87e-2plus-or-minus0.91283.87𝑒-20.9128\scriptscriptstyle\pm\scriptstyle 3.87e\text{-}20.9128 ± 3.87 italic_e - 2 0.9631±1.99e-2plus-or-minus0.96311.99𝑒-20.9631\scriptscriptstyle\pm\scriptstyle 1.99e\text{-}20.9631 ± 1.99 italic_e - 2
OCC-CLIP 0.9469±2.19𝐞-𝟐plus-or-minus0.94692.19𝐞-2\mathbf{0.9469\scriptscriptstyle\pm\scriptstyle 2.19e\text{-}2}bold_0.9469 ± bold_2.19 bold_e - bold_2 0.8324±4.15𝐞-𝟐plus-or-minus0.83244.15𝐞-2\mathbf{0.8324\scriptscriptstyle\pm\scriptstyle 4.15e\text{-}2}bold_0.8324 ± bold_4.15 bold_e - bold_2 0.9215±2.33𝐞-𝟐plus-or-minus0.92152.33𝐞-2\mathbf{0.9215\scriptscriptstyle\pm\scriptstyle 2.33e\text{-}2}bold_0.9215 ± bold_2.33 bold_e - bold_2 0.9693±1.58𝐞-𝟐plus-or-minus0.96931.58𝐞-2\mathbf{0.9693\scriptscriptstyle\pm\scriptstyle 1.58e\text{-}2}bold_0.9693 ± bold_1.58 bold_e - bold_2
negative-positive CoOp 0.9521±2.18e-2plus-or-minus0.95212.18𝑒-20.9521\scriptscriptstyle\pm\scriptstyle 2.18e\text{-}20.9521 ± 2.18 italic_e - 2 0.8578±4.72e-2plus-or-minus0.85784.72𝑒-20.8578\scriptscriptstyle\pm\scriptstyle 4.72e\text{-}20.8578 ± 4.72 italic_e - 2 0.9180±4.11e-2plus-or-minus0.91804.11𝑒-20.9180\scriptscriptstyle\pm\scriptstyle 4.11e\text{-}20.9180 ± 4.11 italic_e - 2 0.9610±2.61e-2plus-or-minus0.96102.61𝑒-20.9610\scriptscriptstyle\pm\scriptstyle 2.61e\text{-}20.9610 ± 2.61 italic_e - 2
OCC-CLIP 0.9552±2.46𝐞-𝟐plus-or-minus0.95522.46𝐞-2\mathbf{0.9552\scriptscriptstyle\pm\scriptstyle 2.46e\text{-}2}bold_0.9552 ± bold_2.46 bold_e - bold_2 0.8492±4.55𝐞-𝟐plus-or-minus0.84924.55𝐞-2\mathbf{0.8492\scriptscriptstyle\pm\scriptstyle 4.55e\text{-}2}bold_0.8492 ± bold_4.55 bold_e - bold_2 0.9163±3.34𝐞-𝟐plus-or-minus0.91633.34𝐞-2\mathbf{0.9163\scriptscriptstyle\pm\scriptstyle 3.34e\text{-}2}bold_0.9163 ± bold_3.34 bold_e - bold_2 0.9597±2.22𝐞-𝟐plus-or-minus0.95972.22𝐞-2\mathbf{0.9597\scriptscriptstyle\pm\scriptstyle 2.22e\text{-}2}bold_0.9597 ± bold_2.22 bold_e - bold_2
other-this CoOp 0.9543±2.99e-2plus-or-minus0.95432.99𝑒-20.9543\scriptscriptstyle\pm\scriptstyle 2.99e\text{-}20.9543 ± 2.99 italic_e - 2 0.8510±6.57e-2plus-or-minus0.85106.57𝑒-20.8510\scriptscriptstyle\pm\scriptstyle 6.57e\text{-}20.8510 ± 6.57 italic_e - 2 0.9316±3.63e-2plus-or-minus0.93163.63𝑒-20.9316\scriptscriptstyle\pm\scriptstyle 3.63e\text{-}20.9316 ± 3.63 italic_e - 2 0.9727±2.51e-2plus-or-minus0.97272.51𝑒-20.9727\scriptscriptstyle\pm\scriptstyle 2.51e\text{-}20.9727 ± 2.51 italic_e - 2
OCC-CLIP 0.9611±1.40𝐞-𝟐plus-or-minus0.96111.40𝐞-2\mathbf{0.9611\scriptscriptstyle\pm\scriptstyle 1.40e\text{-}2}bold_0.9611 ± bold_1.40 bold_e - bold_2 0.8587±3.72𝐞-𝟐plus-or-minus0.85873.72𝐞-2\mathbf{0.8587\scriptscriptstyle\pm\scriptstyle 3.72e\text{-}2}bold_0.8587 ± bold_3.72 bold_e - bold_2 0.9202±3.53𝐞-𝟐plus-or-minus0.92023.53𝐞-2\mathbf{0.9202\scriptscriptstyle\pm\scriptstyle 3.53e\text{-}2}bold_0.9202 ± bold_3.53 bold_e - bold_2 0.9712±1.54𝐞-𝟐plus-or-minus0.97121.54𝐞-2\mathbf{0.9712\scriptscriptstyle\pm\scriptstyle 1.54e\text{-}2}bold_0.9712 ± bold_1.54 bold_e - bold_2
real-fake CoOp 0.9503±1.68e-2plus-or-minus0.95031.68𝑒-20.9503\scriptscriptstyle\pm\scriptstyle 1.68e\text{-}20.9503 ± 1.68 italic_e - 2 0.8373±5.33e-2plus-or-minus0.83735.33𝑒-20.8373\scriptscriptstyle\pm\scriptstyle 5.33e\text{-}20.8373 ± 5.33 italic_e - 2 0.9266±3.19e-2plus-or-minus0.92663.19𝑒-20.9266\scriptscriptstyle\pm\scriptstyle 3.19e\text{-}20.9266 ± 3.19 italic_e - 2 0.9660±2.56e-2plus-or-minus0.96602.56𝑒-20.9660\scriptscriptstyle\pm\scriptstyle 2.56e\text{-}20.9660 ± 2.56 italic_e - 2
OCC-CLIP 0.9703±9.06𝐞-𝟑plus-or-minus0.97039.06𝐞-3\mathbf{0.9703\scriptscriptstyle\pm\scriptstyle 9.06e\text{-}3}bold_0.9703 ± bold_9.06 bold_e - bold_3 0.8801±2.06𝐞-𝟐plus-or-minus0.88012.06𝐞-2\mathbf{0.8801\scriptscriptstyle\pm\scriptstyle 2.06e\text{-}2}bold_0.8801 ± bold_2.06 bold_e - bold_2 0.9519±1.45𝐞-𝟐plus-or-minus0.95191.45𝐞-2\mathbf{0.9519\scriptscriptstyle\pm\scriptstyle 1.45e\text{-}2}bold_0.9519 ± bold_1.45 bold_e - bold_2 0.9798±1.18𝐞-𝟐plus-or-minus0.97981.18𝐞-2\mathbf{0.9798\scriptscriptstyle\pm\scriptstyle 1.18e\text{-}2}bold_0.9798 ± bold_1.18 bold_e - bold_2
positive-negative CoOp 0.9579±1.22e-2plus-or-minus0.95791.22𝑒-20.9579\scriptscriptstyle\pm\scriptstyle 1.22e\text{-}20.9579 ± 1.22 italic_e - 2 0.8737±3.69e-2plus-or-minus0.87373.69𝑒-20.8737\scriptscriptstyle\pm\scriptstyle 3.69e\text{-}20.8737 ± 3.69 italic_e - 2 0.9439±1.97e-2plus-or-minus0.94391.97𝑒-20.9439\scriptscriptstyle\pm\scriptstyle 1.97e\text{-}20.9439 ± 1.97 italic_e - 2 0.9768±1.46e-2plus-or-minus0.97681.46𝑒-20.9768\scriptscriptstyle\pm\scriptstyle 1.46e\text{-}20.9768 ± 1.46 italic_e - 2
OCC-CLIP 0.9671±1.50𝐞-𝟐plus-or-minus0.96711.50𝐞-2\mathbf{0.9671\scriptscriptstyle\pm\scriptstyle 1.50e\text{-}2}bold_0.9671 ± bold_1.50 bold_e - bold_2 0.8916±2.60𝐞-𝟐plus-or-minus0.89162.60𝐞-2\mathbf{0.8916\scriptscriptstyle\pm\scriptstyle 2.60e\text{-}2}bold_0.8916 ± bold_2.60 bold_e - bold_2 0.9507±2.56𝐞-𝟐plus-or-minus0.95072.56𝐞-2\mathbf{0.9507\scriptscriptstyle\pm\scriptstyle 2.56e\text{-}2}bold_0.9507 ± bold_2.56 bold_e - bold_2 0.9806±1.35𝐞-𝟐plus-or-minus0.98061.35𝐞-2\mathbf{0.9806\scriptscriptstyle\pm\scriptstyle 1.35e\text{-}2}bold_0.9806 ± bold_1.35 bold_e - bold_2
this-other CoOp 0.9343±2.91e-2plus-or-minus0.93432.91𝑒-20.9343\scriptscriptstyle\pm\scriptstyle 2.91e\text{-}20.9343 ± 2.91 italic_e - 2 0.8040±4.93e-2plus-or-minus0.80404.93𝑒-20.8040\scriptscriptstyle\pm\scriptstyle 4.93e\text{-}20.8040 ± 4.93 italic_e - 2 0.9007±3.66e-2plus-or-minus0.90073.66𝑒-20.9007\scriptscriptstyle\pm\scriptstyle 3.66e\text{-}20.9007 ± 3.66 italic_e - 2 0.9486±2.31e-2plus-or-minus0.94862.31𝑒-20.9486\scriptscriptstyle\pm\scriptstyle 2.31e\text{-}20.9486 ± 2.31 italic_e - 2
OCC-CLIP 0.9488±3.08𝐞-𝟐plus-or-minus0.94883.08𝐞-2\mathbf{0.9488\scriptscriptstyle\pm\scriptstyle 3.08e\text{-}2}bold_0.9488 ± bold_3.08 bold_e - bold_2 0.8438±4.70𝐞-𝟐plus-or-minus0.84384.70𝐞-2\mathbf{0.8438\scriptscriptstyle\pm\scriptstyle 4.70e\text{-}2}bold_0.8438 ± bold_4.70 bold_e - bold_2 0.9268±2.02𝐞-𝟐plus-or-minus0.92682.02𝐞-2\mathbf{0.9268\scriptscriptstyle\pm\scriptstyle 2.02e\text{-}2}bold_0.9268 ± bold_2.02 bold_e - bold_2 0.9654±2.88𝐞-𝟐plus-or-minus0.96542.88𝐞-2\mathbf{0.9654\scriptscriptstyle\pm\scriptstyle 2.88e\text{-}2}bold_0.9654 ± bold_2.88 bold_e - bold_2
Table 25: Evaluation sensitivity to choice of prompts. This table shows the performance of OCC-CLIP and CoOp under different choices of label pairs.
Names of Classes Methods ProGan StyleGan2 GauGan Overall
fake-real CoOp 0.8220±5.78e-2plus-or-minus0.82205.78𝑒-20.8220\scriptscriptstyle\pm\scriptstyle 5.78e\text{-}20.8220 ± 5.78 italic_e - 2 0.9431±2.01e-2plus-or-minus0.94312.01𝑒-20.9431\scriptscriptstyle\pm\scriptstyle 2.01e\text{-}20.9431 ± 2.01 italic_e - 2 0.9477±2.54e-2plus-or-minus0.94772.54𝑒-20.9477\scriptscriptstyle\pm\scriptstyle 2.54e\text{-}20.9477 ± 2.54 italic_e - 2 0.9078±3.77e-2plus-or-minus0.90783.77𝑒-20.9078\scriptscriptstyle\pm\scriptstyle 3.77e\text{-}20.9078 ± 3.77 italic_e - 2
OCC-CLIP 0.8847±3.59𝐞-𝟐plus-or-minus0.88473.59𝐞-2\mathbf{0.8847\scriptscriptstyle\pm\scriptstyle 3.59e\text{-}2}bold_0.8847 ± bold_3.59 bold_e - bold_2 0.9473±1.90𝐞-𝟐plus-or-minus0.94731.90𝐞-2\mathbf{0.9473\scriptscriptstyle\pm\scriptstyle 1.90e\text{-}2}bold_0.9473 ± bold_1.90 bold_e - bold_2 0.9734±8.03𝐞-𝟑plus-or-minus0.97348.03𝐞-3\mathbf{0.9734\scriptscriptstyle\pm\scriptstyle 8.03e\text{-}3}bold_0.9734 ± bold_8.03 bold_e - bold_3 0.9251±2.60𝐞-𝟐plus-or-minus0.92512.60𝐞-2\mathbf{0.9251\scriptscriptstyle\pm\scriptstyle 2.60e\text{-}2}bold_0.9251 ± bold_2.60 bold_e - bold_2
negative-positive CoOp 0.8228±7.85e-2plus-or-minus0.82287.85𝑒-20.8228\scriptscriptstyle\pm\scriptstyle 7.85e\text{-}20.8228 ± 7.85 italic_e - 2 0.9422±3.87e-2plus-or-minus0.94223.87𝑒-20.9422\scriptscriptstyle\pm\scriptstyle 3.87e\text{-}20.9422 ± 3.87 italic_e - 2 0.9549±2.33e-2plus-or-minus0.95492.33𝑒-20.9549\scriptscriptstyle\pm\scriptstyle 2.33e\text{-}20.9549 ± 2.33 italic_e - 2 0.9155±4.36e-2plus-or-minus0.91554.36𝑒-20.9155\scriptscriptstyle\pm\scriptstyle 4.36e\text{-}20.9155 ± 4.36 italic_e - 2
OCC-CLIP 0.9120±2.99𝐞-𝟐plus-or-minus0.91202.99𝐞-2\mathbf{0.9120\scriptscriptstyle\pm\scriptstyle 2.99e\text{-}2}bold_0.9120 ± bold_2.99 bold_e - bold_2 0.9441±2.86𝐞-𝟐plus-or-minus0.94412.86𝐞-2\mathbf{0.9441\scriptscriptstyle\pm\scriptstyle 2.86e\text{-}2}bold_0.9441 ± bold_2.86 bold_e - bold_2 0.9857±6.60𝐞-𝟑plus-or-minus0.98576.60𝐞-3\mathbf{0.9857\scriptscriptstyle\pm\scriptstyle 6.60e\text{-}3}bold_0.9857 ± bold_6.60 bold_e - bold_3 0.9317±2.94𝐞-𝟐plus-or-minus0.93172.94𝐞-2\mathbf{0.9317\scriptscriptstyle\pm\scriptstyle 2.94e\text{-}2}bold_0.9317 ± bold_2.94 bold_e - bold_2
other-this CoOp 0.8596±6.79e-2plus-or-minus0.85966.79𝑒-20.8596\scriptscriptstyle\pm\scriptstyle 6.79e\text{-}20.8596 ± 6.79 italic_e - 2 0.9355±4.04e-2plus-or-minus0.93554.04𝑒-20.9355\scriptscriptstyle\pm\scriptstyle 4.04e\text{-}20.9355 ± 4.04 italic_e - 2 0.9542±2.79e-2plus-or-minus0.95422.79𝑒-20.9542\scriptscriptstyle\pm\scriptstyle 2.79e\text{-}20.9542 ± 2.79 italic_e - 2 0.9227±4.50e-2plus-or-minus0.92274.50𝑒-20.9227\scriptscriptstyle\pm\scriptstyle 4.50e\text{-}20.9227 ± 4.50 italic_e - 2
OCC-CLIP 0.9096±4.59𝐞-𝟐plus-or-minus0.90964.59𝐞-2\mathbf{0.9096\scriptscriptstyle\pm\scriptstyle 4.59e\text{-}2}bold_0.9096 ± bold_4.59 bold_e - bold_2 0.9501±2.48𝐞-𝟐plus-or-minus0.95012.48𝐞-2\mathbf{0.9501\scriptscriptstyle\pm\scriptstyle 2.48e\text{-}2}bold_0.9501 ± bold_2.48 bold_e - bold_2 0.9791±1.38𝐞-𝟐plus-or-minus0.97911.38𝐞-2\mathbf{0.9791\scriptscriptstyle\pm\scriptstyle 1.38e\text{-}2}bold_0.9791 ± bold_1.38 bold_e - bold_2 0.9357±2.92𝐞-𝟐plus-or-minus0.93572.92𝐞-2\mathbf{0.9357\scriptscriptstyle\pm\scriptstyle 2.92e\text{-}2}bold_0.9357 ± bold_2.92 bold_e - bold_2
real-fake CoOp 0.8861±4.46e-2plus-or-minus0.88614.46𝑒-20.8861\scriptscriptstyle\pm\scriptstyle 4.46e\text{-}20.8861 ± 4.46 italic_e - 2 0.9533±2.30e-2plus-or-minus0.95332.30𝑒-20.9533\scriptscriptstyle\pm\scriptstyle 2.30e\text{-}20.9533 ± 2.30 italic_e - 2 0.9643±2.91e-2plus-or-minus0.96432.91𝑒-20.9643\scriptscriptstyle\pm\scriptstyle 2.91e\text{-}20.9643 ± 2.91 italic_e - 2 0.9263±3.41e-2plus-or-minus0.92633.41𝑒-20.9263\scriptscriptstyle\pm\scriptstyle 3.41e\text{-}20.9263 ± 3.41 italic_e - 2
OCC-CLIP 0.9452±3.14𝐞-𝟐plus-or-minus0.94523.14𝐞-2\mathbf{0.9452\scriptscriptstyle\pm\scriptstyle 3.14e\text{-}2}bold_0.9452 ± bold_3.14 bold_e - bold_2 0.9651±1.54𝐞-𝟐plus-or-minus0.96511.54𝐞-2\mathbf{0.9651\scriptscriptstyle\pm\scriptstyle 1.54e\text{-}2}bold_0.9651 ± bold_1.54 bold_e - bold_2 0.9910±7.32𝐞-𝟑plus-or-minus0.99107.32𝐞-3\mathbf{0.9910\scriptscriptstyle\pm\scriptstyle 7.32e\text{-}3}bold_0.9910 ± bold_7.32 bold_e - bold_3 0.9548±1.75𝐞-𝟐plus-or-minus0.95481.75𝐞-2\mathbf{0.9548\scriptscriptstyle\pm\scriptstyle 1.75e\text{-}2}bold_0.9548 ± bold_1.75 bold_e - bold_2
positive-negative CoOp 0.8467±6.97e-2plus-or-minus0.84676.97𝑒-20.8467\scriptscriptstyle\pm\scriptstyle 6.97e\text{-}20.8467 ± 6.97 italic_e - 2 0.9693±1.27e-2plus-or-minus0.96931.27𝑒-20.9693\scriptscriptstyle\pm\scriptstyle 1.27e\text{-}20.9693 ± 1.27 italic_e - 2 0.9417±3.08e-2plus-or-minus0.94173.08𝑒-20.9417\scriptscriptstyle\pm\scriptstyle 3.08e\text{-}20.9417 ± 3.08 italic_e - 2 0.9300±3.40e-2plus-or-minus0.93003.40𝑒-20.9300\scriptscriptstyle\pm\scriptstyle 3.40e\text{-}20.9300 ± 3.40 italic_e - 2
OCC-CLIP 0.9445±3.51𝐞-𝟐plus-or-minus0.94453.51𝐞-2\mathbf{0.9445\scriptscriptstyle\pm\scriptstyle 3.51e\text{-}2}bold_0.9445 ± bold_3.51 bold_e - bold_2 0.9778±1.98𝐞-𝟐plus-or-minus0.97781.98𝐞-2\mathbf{0.9778\scriptscriptstyle\pm\scriptstyle 1.98e\text{-}2}bold_0.9778 ± bold_1.98 bold_e - bold_2 0.9883±1.18𝐞-𝟐plus-or-minus0.98831.18𝐞-2\mathbf{0.9883\scriptscriptstyle\pm\scriptstyle 1.18e\text{-}2}bold_0.9883 ± bold_1.18 bold_e - bold_2 0.9572±2.24𝐞-𝟐plus-or-minus0.95722.24𝐞-2\mathbf{0.9572\scriptscriptstyle\pm\scriptstyle 2.24e\text{-}2}bold_0.9572 ± bold_2.24 bold_e - bold_2
this-other CoOp 0.8270±6.63e-2plus-or-minus0.82706.63𝑒-20.8270\scriptscriptstyle\pm\scriptstyle 6.63e\text{-}20.8270 ± 6.63 italic_e - 2 0.9460±2.65e-2plus-or-minus0.94602.65𝑒-20.9460\scriptscriptstyle\pm\scriptstyle 2.65e\text{-}20.9460 ± 2.65 italic_e - 2 0.9446±3.26e-2plus-or-minus0.94463.26𝑒-20.9446\scriptscriptstyle\pm\scriptstyle 3.26e\text{-}20.9446 ± 3.26 italic_e - 2 0.9007±4.02e-2plus-or-minus0.90074.02𝑒-20.9007\scriptscriptstyle\pm\scriptstyle 4.02e\text{-}20.9007 ± 4.02 italic_e - 2
OCC-CLIP 0.8932±5.06𝐞-𝟐plus-or-minus0.89325.06𝐞-2\mathbf{0.8932\scriptscriptstyle\pm\scriptstyle 5.06e\text{-}2}bold_0.8932 ± bold_5.06 bold_e - bold_2 0.9559±2.51𝐞-𝟐plus-or-minus0.95592.51𝐞-2\mathbf{0.9559\scriptscriptstyle\pm\scriptstyle 2.51e\text{-}2}bold_0.9559 ± bold_2.51 bold_e - bold_2 0.9766±1.57𝐞-𝟐plus-or-minus0.97661.57𝐞-2\mathbf{0.9766\scriptscriptstyle\pm\scriptstyle 1.57e\text{-}2}bold_0.9766 ± bold_1.57 bold_e - bold_2 0.9301±3.35𝐞-𝟐plus-or-minus0.93013.35𝐞-2\mathbf{0.9301\scriptscriptstyle\pm\scriptstyle 3.35e\text{-}2}bold_0.9301 ± bold_3.35 bold_e - bold_2
Table 26: ADA vs. other data augmentation methods. Different data augmentation methods are used during the training phase.
Methods VQ-D LDM Glide GALIP
None 0.9503±1.68e-2plus-or-minus0.95031.68𝑒-20.9503\scriptscriptstyle\pm\scriptstyle 1.68e\text{-}20.9503 ± 1.68 italic_e - 2 0.8373±5.33e-2plus-or-minus0.83735.33𝑒-20.8373\scriptscriptstyle\pm\scriptstyle 5.33e\text{-}20.8373 ± 5.33 italic_e - 2 0.9266±3.19e-2plus-or-minus0.92663.19𝑒-20.9266\scriptscriptstyle\pm\scriptstyle 3.19e\text{-}20.9266 ± 3.19 italic_e - 2 0.9660±2.56e-2plus-or-minus0.96602.56𝑒-20.9660\scriptscriptstyle\pm\scriptstyle 2.56e\text{-}20.9660 ± 2.56 italic_e - 2
Gaussian Blur 0.7780±3.10e-2plus-or-minus0.77803.10𝑒-20.7780\scriptscriptstyle\pm\scriptstyle 3.10e\text{-}20.7780 ± 3.10 italic_e - 2 0.6417±5.40e-2plus-or-minus0.64175.40𝑒-20.6417\scriptscriptstyle\pm\scriptstyle 5.40e\text{-}20.6417 ± 5.40 italic_e - 2 0.8460±3.84e-2plus-or-minus0.84603.84𝑒-20.8460\scriptscriptstyle\pm\scriptstyle 3.84e\text{-}20.8460 ± 3.84 italic_e - 2 0.8034±4.79e-2plus-or-minus0.80344.79𝑒-20.8034\scriptscriptstyle\pm\scriptstyle 4.79e\text{-}20.8034 ± 4.79 italic_e - 2
Gaussian Noise 0.7673±3.51e-2plus-or-minus0.76733.51𝑒-20.7673\scriptscriptstyle\pm\scriptstyle 3.51e\text{-}20.7673 ± 3.51 italic_e - 2 0.6078±4.78e-2plus-or-minus0.60784.78𝑒-20.6078\scriptscriptstyle\pm\scriptstyle 4.78e\text{-}20.6078 ± 4.78 italic_e - 2 0.7735±4.63e-2plus-or-minus0.77354.63𝑒-20.7735\scriptscriptstyle\pm\scriptstyle 4.63e\text{-}20.7735 ± 4.63 italic_e - 2 0.7004±4.42e-2plus-or-minus0.70044.42𝑒-20.7004\scriptscriptstyle\pm\scriptstyle 4.42e\text{-}20.7004 ± 4.42 italic_e - 2
Grayscale 0.7490±4.32e-2plus-or-minus0.74904.32𝑒-20.7490\scriptscriptstyle\pm\scriptstyle 4.32e\text{-}20.7490 ± 4.32 italic_e - 2 0.6111±4.53e-2plus-or-minus0.61114.53𝑒-20.6111\scriptscriptstyle\pm\scriptstyle 4.53e\text{-}20.6111 ± 4.53 italic_e - 2 0.7794±3.65e-2plus-or-minus0.77943.65𝑒-20.7794\scriptscriptstyle\pm\scriptstyle 3.65e\text{-}20.7794 ± 3.65 italic_e - 2 0.6877±4.09e-2plus-or-minus0.68774.09𝑒-20.6877\scriptscriptstyle\pm\scriptstyle 4.09e\text{-}20.6877 ± 4.09 italic_e - 2
Rotate 0.7653±4.36e-2plus-or-minus0.76534.36𝑒-20.7653\scriptscriptstyle\pm\scriptstyle 4.36e\text{-}20.7653 ± 4.36 italic_e - 2 0.6174±4.94e-2plus-or-minus0.61744.94𝑒-20.6174\scriptscriptstyle\pm\scriptstyle 4.94e\text{-}20.6174 ± 4.94 italic_e - 2 0.8029±4.12e-2plus-or-minus0.80294.12𝑒-20.8029\scriptscriptstyle\pm\scriptstyle 4.12e\text{-}20.8029 ± 4.12 italic_e - 2 0.7496±5.03e-2plus-or-minus0.74965.03𝑒-20.7496\scriptscriptstyle\pm\scriptstyle 5.03e\text{-}20.7496 ± 5.03 italic_e - 2
Flip 0.7614±4.44e-2plus-or-minus0.76144.44𝑒-20.7614\scriptscriptstyle\pm\scriptstyle 4.44e\text{-}20.7614 ± 4.44 italic_e - 2 0.6182±4.77e-2plus-or-minus0.61824.77𝑒-20.6182\scriptscriptstyle\pm\scriptstyle 4.77e\text{-}20.6182 ± 4.77 italic_e - 2 0.7880±4.67e-2plus-or-minus0.78804.67𝑒-20.7880\scriptscriptstyle\pm\scriptstyle 4.67e\text{-}20.7880 ± 4.67 italic_e - 2 0.7370±3.71e-2plus-or-minus0.73703.71𝑒-20.7370\scriptscriptstyle\pm\scriptstyle 3.71e\text{-}20.7370 ± 3.71 italic_e - 2
Mixture 0.8220±2.72e-2plus-or-minus0.82202.72𝑒-20.8220\scriptscriptstyle\pm\scriptstyle 2.72e\text{-}20.8220 ± 2.72 italic_e - 2 0.5339±1.49e-2plus-or-minus0.53391.49𝑒-20.5339\scriptscriptstyle\pm\scriptstyle 1.49e\text{-}20.5339 ± 1.49 italic_e - 2 0.7017±4.14e-2plus-or-minus0.70174.14𝑒-20.7017\scriptscriptstyle\pm\scriptstyle 4.14e\text{-}20.7017 ± 4.14 italic_e - 2 0.7846±3.55e-2plus-or-minus0.78463.55𝑒-20.7846\scriptscriptstyle\pm\scriptstyle 3.55e\text{-}20.7846 ± 3.55 italic_e - 2
ADA 0.9703±9.06𝐞-𝟑plus-or-minus0.97039.06𝐞-3\mathbf{0.9703\scriptscriptstyle\pm\scriptstyle 9.06e\text{-}3}bold_0.9703 ± bold_9.06 bold_e - bold_3 0.8801±2.06𝐞-𝟐plus-or-minus0.88012.06𝐞-2\mathbf{0.8801\scriptscriptstyle\pm\scriptstyle 2.06e\text{-}2}bold_0.8801 ± bold_2.06 bold_e - bold_2 0.9519±1.45𝐞-𝟐plus-or-minus0.95191.45𝐞-2\mathbf{0.9519\scriptscriptstyle\pm\scriptstyle 1.45e\text{-}2}bold_0.9519 ± bold_1.45 bold_e - bold_2 0.9798±1.18𝐞-𝟐plus-or-minus0.97981.18𝐞-2\mathbf{0.9798\scriptscriptstyle\pm\scriptstyle 1.18e\text{-}2}bold_0.9798 ± bold_1.18 bold_e - bold_2
Table 27: ADA vs. other data augmentation methods. Different data augmentation methods are used during training phase.
Methods ProGan StyleGan2 GauGan Overall
None 0.8861±4.46e-2plus-or-minus0.88614.46𝑒-20.8861\scriptscriptstyle\pm\scriptstyle 4.46e\text{-}20.8861 ± 4.46 italic_e - 2 0.9533±2.30e-2plus-or-minus0.95332.30𝑒-20.9533\scriptscriptstyle\pm\scriptstyle 2.30e\text{-}20.9533 ± 2.30 italic_e - 2 0.9643±2.91e-2plus-or-minus0.96432.91𝑒-20.9643\scriptscriptstyle\pm\scriptstyle 2.91e\text{-}20.9643 ± 2.91 italic_e - 2 0.9263±3.41e-2plus-or-minus0.92633.41𝑒-20.9263\scriptscriptstyle\pm\scriptstyle 3.41e\text{-}20.9263 ± 3.41 italic_e - 2
Gaussian Blur 0.9856±1.19e-2plus-or-minus0.98561.19𝑒-20.9856\scriptscriptstyle\pm\scriptstyle 1.19e\text{-}20.9856 ± 1.19 italic_e - 2 0.9978±1.87e-3plus-or-minus0.99781.87𝑒-30.9978\scriptscriptstyle\pm\scriptstyle 1.87e\text{-}30.9978 ± 1.87 italic_e - 3 0.9949±5.02e-3plus-or-minus0.99495.02𝑒-30.9949\scriptscriptstyle\pm\scriptstyle 5.02e\text{-}30.9949 ± 5.02 italic_e - 3 0.8639±3.34e-2plus-or-minus0.86393.34𝑒-20.8639\scriptscriptstyle\pm\scriptstyle 3.34e\text{-}20.8639 ± 3.34 italic_e - 2
Gaussian Noise 0.9926±5.84e-3plus-or-minus0.99265.84𝑒-30.9926\scriptscriptstyle\pm\scriptstyle 5.84e\text{-}30.9926 ± 5.84 italic_e - 3 0.9974±2.32e-3plus-or-minus0.99742.32𝑒-30.9974\scriptscriptstyle\pm\scriptstyle 2.32e\text{-}30.9974 ± 2.32 italic_e - 3 0.9991±1.21e-3plus-or-minus0.99911.21𝑒-30.9991\scriptscriptstyle\pm\scriptstyle 1.21e\text{-}30.9991 ± 1.21 italic_e - 3 0.8340±3.31e-2plus-or-minus0.83403.31𝑒-20.8340\scriptscriptstyle\pm\scriptstyle 3.31e\text{-}20.8340 ± 3.31 italic_e - 2
Grayscale 0.9916±4.96e-3plus-or-minus0.99164.96𝑒-30.9916\scriptscriptstyle\pm\scriptstyle 4.96e\text{-}30.9916 ± 4.96 italic_e - 3 0.9978±1.27e-3plus-or-minus0.99781.27𝑒-30.9978\scriptscriptstyle\pm\scriptstyle 1.27e\text{-}30.9978 ± 1.27 italic_e - 3 0.9988±9.65e-4plus-or-minus0.99889.65𝑒-40.9988\scriptscriptstyle\pm\scriptstyle 9.65e\text{-}40.9988 ± 9.65 italic_e - 4 0.8308±3.15e-2plus-or-minus0.83083.15𝑒-20.8308\scriptscriptstyle\pm\scriptstyle 3.15e\text{-}20.8308 ± 3.15 italic_e - 2
Rotate 0.9930±2.77e-3plus-or-minus0.99302.77𝑒-30.9930\scriptscriptstyle\pm\scriptstyle 2.77e\text{-}30.9930 ± 2.77 italic_e - 3 0.9985±9.18e-4plus-or-minus0.99859.18𝑒-40.9985\scriptscriptstyle\pm\scriptstyle 9.18e\text{-}40.9985 ± 9.18 italic_e - 4 0.9985±9.73e-4plus-or-minus0.99859.73𝑒-40.9985\scriptscriptstyle\pm\scriptstyle 9.73e\text{-}40.9985 ± 9.73 italic_e - 4 0.8465±3.50e-2plus-or-minus0.84653.50𝑒-20.8465\scriptscriptstyle\pm\scriptstyle 3.50e\text{-}20.8465 ± 3.50 italic_e - 2
Flip 0.9936±3.06e-3plus-or-minus0.99363.06𝑒-30.9936\scriptscriptstyle\pm\scriptstyle 3.06e\text{-}30.9936 ± 3.06 italic_e - 3 0.9983±1.45e-3plus-or-minus0.99831.45𝑒-30.9983\scriptscriptstyle\pm\scriptstyle 1.45e\text{-}30.9983 ± 1.45 italic_e - 3 0.9985±1.02e-3plus-or-minus0.99851.02𝑒-30.9985\scriptscriptstyle\pm\scriptstyle 1.02e\text{-}30.9985 ± 1.02 italic_e - 3 0.8422±3.34e-2plus-or-minus0.84223.34𝑒-20.8422\scriptscriptstyle\pm\scriptstyle 3.34e\text{-}20.8422 ± 3.34 italic_e - 2
Mixture 0.8743±5.98e-2plus-or-minus0.87435.98𝑒-20.8743\scriptscriptstyle\pm\scriptstyle 5.98e\text{-}20.8743 ± 5.98 italic_e - 2 0.9328±4.72e-2plus-or-minus0.93284.72𝑒-20.9328\scriptscriptstyle\pm\scriptstyle 4.72e\text{-}20.9328 ± 4.72 italic_e - 2 0.9440±2.94e-2plus-or-minus0.94402.94𝑒-20.9440\scriptscriptstyle\pm\scriptstyle 2.94e\text{-}20.9440 ± 2.94 italic_e - 2 0.7991±3.89e-2plus-or-minus0.79913.89𝑒-20.7991\scriptscriptstyle\pm\scriptstyle 3.89e\text{-}20.7991 ± 3.89 italic_e - 2
ADA 0.9452±3.14𝐞-𝟐plus-or-minus0.94523.14𝐞-2\mathbf{0.9452\scriptscriptstyle\pm\scriptstyle 3.14e\text{-}2}bold_0.9452 ± bold_3.14 bold_e - bold_2 0.9651±1.54𝐞-𝟐plus-or-minus0.96511.54𝐞-2\mathbf{0.9651\scriptscriptstyle\pm\scriptstyle 1.54e\text{-}2}bold_0.9651 ± bold_1.54 bold_e - bold_2 0.9910±7.32𝐞-𝟑plus-or-minus0.99107.32𝐞-3\mathbf{0.9910\scriptscriptstyle\pm\scriptstyle 7.32e\text{-}3}bold_0.9910 ± bold_7.32 bold_e - bold_3 0.9548±1.75𝐞-𝟐plus-or-minus0.95481.75𝐞-2\mathbf{0.9548\scriptscriptstyle\pm\scriptstyle 1.75e\text{-}2}bold_0.9548 ± bold_1.75 bold_e - bold_2
Table 28: Evaluation of OCC-CLIP with commercial generation API. During the training phase, the target images are generated by DALL·E-3, and the non-target images are from COCO.
No. of Shots Methods SD VQ-D LDM Glide GALIP
10 CoOp 0.9146±0.0plus-or-minus0.91460.00.9146\scriptscriptstyle\pm\scriptstyle 0.00.9146 ± 0.0 0.9465±0.0plus-or-minus0.94650.00.9465\scriptscriptstyle\pm\scriptstyle 0.00.9465 ± 0.0 0.9213±0.0plus-or-minus0.92130.00.9213\scriptscriptstyle\pm\scriptstyle 0.00.9213 ± 0.0 0.9235±0.0plus-or-minus0.92350.00.9235\scriptscriptstyle\pm\scriptstyle 0.00.9235 ± 0.0 0.9636±0.0plus-or-minus0.96360.00.9636\scriptscriptstyle\pm\scriptstyle 0.00.9636 ± 0.0
OCC-CLIP 0.9244±0.0plus-or-minus0.92440.0\mathbf{0.9244\scriptscriptstyle\pm\scriptstyle 0.0}bold_0.9244 ± bold_0.0 0.9922±0.0plus-or-minus0.99220.0\mathbf{0.9922\scriptscriptstyle\pm\scriptstyle 0.0}bold_0.9922 ± bold_0.0 0.9852±0.0plus-or-minus0.98520.0\mathbf{0.9852\scriptscriptstyle\pm\scriptstyle 0.0}bold_0.9852 ± bold_0.0 0.9874±0.0plus-or-minus0.98740.0\mathbf{0.9874\scriptscriptstyle\pm\scriptstyle 0.0}bold_0.9874 ± bold_0.0 0.9969±0.0plus-or-minus0.99690.0\mathbf{0.9969\scriptscriptstyle\pm\scriptstyle 0.0}bold_0.9969 ± bold_0.0
20 CoOp 0.9692±0.0plus-or-minus0.96920.00.9692\scriptscriptstyle\pm\scriptstyle 0.00.9692 ± 0.0 0.9881±0.0plus-or-minus0.98810.00.9881\scriptscriptstyle\pm\scriptstyle 0.00.9881 ± 0.0 0.9779±0.0plus-or-minus0.97790.00.9779\scriptscriptstyle\pm\scriptstyle 0.00.9779 ± 0.0 0.9713±0.0plus-or-minus0.97130.00.9713\scriptscriptstyle\pm\scriptstyle 0.00.9713 ± 0.0 0.9924±0.0plus-or-minus0.99240.00.9924\scriptscriptstyle\pm\scriptstyle 0.00.9924 ± 0.0
OCC-CLIP 0.9604±0.0plus-or-minus0.96040.0\mathbf{0.9604\scriptscriptstyle\pm\scriptstyle 0.0}bold_0.9604 ± bold_0.0 0.9967±0.0plus-or-minus0.99670.0\mathbf{0.9967\scriptscriptstyle\pm\scriptstyle 0.0}bold_0.9967 ± bold_0.0 0.9867±0.0plus-or-minus0.98670.0\mathbf{0.9867\scriptscriptstyle\pm\scriptstyle 0.0}bold_0.9867 ± bold_0.0 0.9888±0.0plus-or-minus0.98880.0\mathbf{0.9888\scriptscriptstyle\pm\scriptstyle 0.0}bold_0.9888 ± bold_0.0 0.9984±0.0plus-or-minus0.99840.0\mathbf{0.9984\scriptscriptstyle\pm\scriptstyle 0.0}bold_0.9984 ± bold_0.0
30 CoOp 0.9338±0.0plus-or-minus0.93380.00.9338\scriptscriptstyle\pm\scriptstyle 0.00.9338 ± 0.0 0.9817±0.0plus-or-minus0.98170.00.9817\scriptscriptstyle\pm\scriptstyle 0.00.9817 ± 0.0 0.9824±0.0plus-or-minus0.98240.00.9824\scriptscriptstyle\pm\scriptstyle 0.00.9824 ± 0.0 0.9748±0.0plus-or-minus0.97480.00.9748\scriptscriptstyle\pm\scriptstyle 0.00.9748 ± 0.0 0.9970±0.0plus-or-minus0.99700.00.9970\scriptscriptstyle\pm\scriptstyle 0.00.9970 ± 0.0
OCC-CLIP 0.9618±0.0plus-or-minus0.96180.0\mathbf{0.9618\scriptscriptstyle\pm\scriptstyle 0.0}bold_0.9618 ± bold_0.0 0.9996±0.0plus-or-minus0.99960.0\mathbf{0.9996\scriptscriptstyle\pm\scriptstyle 0.0}bold_0.9996 ± bold_0.0 0.9986±0.0plus-or-minus0.99860.0\mathbf{0.9986\scriptscriptstyle\pm\scriptstyle 0.0}bold_0.9986 ± bold_0.0 0.9995±0.0plus-or-minus0.99950.0\mathbf{0.9995\scriptscriptstyle\pm\scriptstyle 0.0}bold_0.9995 ± bold_0.0 1.0000±0.0plus-or-minus1.00000.0\mathbf{1.0000\scriptscriptstyle\pm\scriptstyle 0.0}bold_1.0000 ± bold_0.0
40 CoOp 0.9650±0.0plus-or-minus0.96500.00.9650\scriptscriptstyle\pm\scriptstyle 0.00.9650 ± 0.0 0.9871±0.0plus-or-minus0.98710.00.9871\scriptscriptstyle\pm\scriptstyle 0.00.9871 ± 0.0 0.9860±0.0plus-or-minus0.98600.00.9860\scriptscriptstyle\pm\scriptstyle 0.00.9860 ± 0.0 0.9893±0.0plus-or-minus0.98930.00.9893\scriptscriptstyle\pm\scriptstyle 0.00.9893 ± 0.0 0.9971±0.0plus-or-minus0.99710.00.9971\scriptscriptstyle\pm\scriptstyle 0.00.9971 ± 0.0
OCC-CLIP 0.9696±0.0plus-or-minus0.96960.0\mathbf{0.9696\scriptscriptstyle\pm\scriptstyle 0.0}bold_0.9696 ± bold_0.0 0.9994±0.0plus-or-minus0.99940.0\mathbf{0.9994\scriptscriptstyle\pm\scriptstyle 0.0}bold_0.9994 ± bold_0.0 0.9961±0.0plus-or-minus0.99610.0\mathbf{0.9961\scriptscriptstyle\pm\scriptstyle 0.0}bold_0.9961 ± bold_0.0 0.9986±0.0plus-or-minus0.99860.0\mathbf{0.9986\scriptscriptstyle\pm\scriptstyle 0.0}bold_0.9986 ± bold_0.0 1.0000±0.0plus-or-minus1.00000.0\mathbf{1.0000\scriptscriptstyle\pm\scriptstyle 0.0}bold_1.0000 ± bold_0.0
50 CoOp 0.9745±0.0plus-or-minus0.97450.0\mathbf{0.9745\scriptscriptstyle\pm\scriptstyle 0.0}bold_0.9745 ± bold_0.0 0.9946±0.0plus-or-minus0.99460.00.9946\scriptscriptstyle\pm\scriptstyle 0.00.9946 ± 0.0 0.9869±0.0plus-or-minus0.98690.00.9869\scriptscriptstyle\pm\scriptstyle 0.00.9869 ± 0.0 0.9929±0.0plus-or-minus0.99290.00.9929\scriptscriptstyle\pm\scriptstyle 0.00.9929 ± 0.0 0.9991±0.0plus-or-minus0.99910.00.9991\scriptscriptstyle\pm\scriptstyle 0.00.9991 ± 0.0
OCC-CLIP 0.9741±0.0plus-or-minus0.97410.00.9741\scriptscriptstyle\pm\scriptstyle 0.00.9741 ± 0.0 0.9995±0.0plus-or-minus0.99950.0\mathbf{0.9995\scriptscriptstyle\pm\scriptstyle 0.0}bold_0.9995 ± bold_0.0 0.9968±0.0plus-or-minus0.99680.0\mathbf{0.9968\scriptscriptstyle\pm\scriptstyle 0.0}bold_0.9968 ± bold_0.0 0.9993±0.0plus-or-minus0.99930.0\mathbf{0.9993\scriptscriptstyle\pm\scriptstyle 0.0}bold_0.9993 ± bold_0.0 0.9999±0.0plus-or-minus0.99990.0\mathbf{0.9999\scriptscriptstyle\pm\scriptstyle 0.0}bold_0.9999 ± bold_0.0
Table 29: Additional Baselines (tested on VQ-D, LDM, Glide, GALIP, ProGAN, StyleGAN2, GauGAN). The table shows the overall average accuracy tested on 7 different testing tasks.
Methods ViT-L ViT-Res CLIP-LoRAm CLIP-LoRAl
Average ACC 0.59660.59660.59660.5966 0.62690.62690.62690.6269 0.56460.56460.56460.5646 0.55070.55070.55070.5507
Methods CLIP-LoRAa Girish et al. Wang et al. OCC-CLIP
Average ACC 0.59510.59510.59510.5951 0.60790.60790.60790.6079 0.76000.76000.76000.7600 0.88240.8824\mathbf{0.8824}bold_0.8824
Table 30: Evaluation of OCC-CLIP with commercial generation API. During the training phase, the target images are generated by DALL·E-3, and the non-target images are from COCO.
No. of Shots Methods ProGan StyleGan2 GauGan Overall
10 CoOp 0.8609±0.0plus-or-minus0.86090.00.8609\scriptscriptstyle\pm\scriptstyle 0.00.8609 ± 0.0 0.9700±0.0plus-or-minus0.97000.00.9700\scriptscriptstyle\pm\scriptstyle 0.00.9700 ± 0.0 0.8723±0.0plus-or-minus0.87230.00.8723\scriptscriptstyle\pm\scriptstyle 0.00.8723 ± 0.0 0.9216±0.0plus-or-minus0.92160.00.9216\scriptscriptstyle\pm\scriptstyle 0.00.9216 ± 0.0
OCC-CLIP 0.9620±0.0plus-or-minus0.96200.0\mathbf{0.9620\scriptscriptstyle\pm\scriptstyle 0.0}bold_0.9620 ± bold_0.0 0.9795±0.0plus-or-minus0.97950.0\mathbf{0.9795\scriptscriptstyle\pm\scriptstyle 0.0}bold_0.9795 ± bold_0.0 0.9756±0.0plus-or-minus0.97560.0\mathbf{0.9756\scriptscriptstyle\pm\scriptstyle 0.0}bold_0.9756 ± bold_0.0 0.9754±0.0plus-or-minus0.97540.0\mathbf{0.9754\scriptscriptstyle\pm\scriptstyle 0.0}bold_0.9754 ± bold_0.0
20 CoOp 0.9108±0.0plus-or-minus0.91080.00.9108\scriptscriptstyle\pm\scriptstyle 0.00.9108 ± 0.0 0.9940±0.0plus-or-minus0.99400.0\mathbf{0.9940\scriptscriptstyle\pm\scriptstyle 0.0}bold_0.9940 ± bold_0.0 0.9460±0.0plus-or-minus0.94600.00.9460\scriptscriptstyle\pm\scriptstyle 0.00.9460 ± 0.0 0.9687±0.0plus-or-minus0.96870.00.9687\scriptscriptstyle\pm\scriptstyle 0.00.9687 ± 0.0
OCC-CLIP 0.9786±0.0plus-or-minus0.97860.0\mathbf{0.9786\scriptscriptstyle\pm\scriptstyle 0.0}bold_0.9786 ± bold_0.0 0.9807±0.0plus-or-minus0.98070.00.9807\scriptscriptstyle\pm\scriptstyle 0.00.9807 ± 0.0 0.9879±0.0plus-or-minus0.98790.0\mathbf{0.9879\scriptscriptstyle\pm\scriptstyle 0.0}bold_0.9879 ± bold_0.0 0.9848±0.0plus-or-minus0.98480.0\mathbf{0.9848\scriptscriptstyle\pm\scriptstyle 0.0}bold_0.9848 ± bold_0.0
30 CoOp 0.8908±0.0plus-or-minus0.89080.00.8908\scriptscriptstyle\pm\scriptstyle 0.00.8908 ± 0.0 0.9936±0.0plus-or-minus0.99360.00.9936\scriptscriptstyle\pm\scriptstyle 0.00.9936 ± 0.0 0.8959±0.0plus-or-minus0.89590.00.8959\scriptscriptstyle\pm\scriptstyle 0.00.8959 ± 0.0 0.9563±0.0plus-or-minus0.95630.00.9563\scriptscriptstyle\pm\scriptstyle 0.00.9563 ± 0.0
OCC-CLIP 0.9935±0.0plus-or-minus0.99350.0\mathbf{0.9935\scriptscriptstyle\pm\scriptstyle 0.0}bold_0.9935 ± bold_0.0 0.9968±0.0plus-or-minus0.99680.0\mathbf{0.9968\scriptscriptstyle\pm\scriptstyle 0.0}bold_0.9968 ± bold_0.0 0.9992±0.0plus-or-minus0.99920.0\mathbf{0.9992\scriptscriptstyle\pm\scriptstyle 0.0}bold_0.9992 ± bold_0.0 0.9936±0.0plus-or-minus0.99360.0\mathbf{0.9936\scriptscriptstyle\pm\scriptstyle 0.0}bold_0.9936 ± bold_0.0
40 CoOp 0.8948±0.0plus-or-minus0.89480.00.8948\scriptscriptstyle\pm\scriptstyle 0.00.8948 ± 0.0 0.9930±0.0plus-or-minus0.99300.00.9930\scriptscriptstyle\pm\scriptstyle 0.00.9930 ± 0.0 0.9187±0.0plus-or-minus0.91870.00.9187\scriptscriptstyle\pm\scriptstyle 0.00.9187 ± 0.0 0.9664±0.0plus-or-minus0.96640.00.9664\scriptscriptstyle\pm\scriptstyle 0.00.9664 ± 0.0
OCC-CLIP 0.9944±0.0plus-or-minus0.99440.0\mathbf{0.9944\scriptscriptstyle\pm\scriptstyle 0.0}bold_0.9944 ± bold_0.0 0.9963±0.0plus-or-minus0.99630.0\mathbf{0.9963\scriptscriptstyle\pm\scriptstyle 0.0}bold_0.9963 ± bold_0.0 0.9991±0.0plus-or-minus0.99910.0\mathbf{0.9991\scriptscriptstyle\pm\scriptstyle 0.0}bold_0.9991 ± bold_0.0 0.9942±0.0plus-or-minus0.99420.0\mathbf{0.9942\scriptscriptstyle\pm\scriptstyle 0.0}bold_0.9942 ± bold_0.0
50 CoOp 0.9315±0.0plus-or-minus0.93150.00.9315\scriptscriptstyle\pm\scriptstyle 0.00.9315 ± 0.0 0.9957±0.0plus-or-minus0.99570.00.9957\scriptscriptstyle\pm\scriptstyle 0.00.9957 ± 0.0 0.9551±0.0plus-or-minus0.95510.00.9551\scriptscriptstyle\pm\scriptstyle 0.00.9551 ± 0.0 0.9788±0.0plus-or-minus0.97880.00.9788\scriptscriptstyle\pm\scriptstyle 0.00.9788 ± 0.0
OCC-CLIP 0.9985±0.0plus-or-minus0.99850.0\mathbf{0.9985\scriptscriptstyle\pm\scriptstyle 0.0}bold_0.9985 ± bold_0.0 0.9994±0.0plus-or-minus0.99940.0\mathbf{0.9994\scriptscriptstyle\pm\scriptstyle 0.0}bold_0.9994 ± bold_0.0 0.9998±0.0plus-or-minus0.99980.0\mathbf{0.9998\scriptscriptstyle\pm\scriptstyle 0.0}bold_0.9998 ± bold_0.0 0.9959±0.0plus-or-minus0.99590.0\mathbf{0.9959\scriptscriptstyle\pm\scriptstyle 0.0}bold_0.9959 ± bold_0.0
Table 31: Employing an ensemble of one-class classifiers for multi-class classification tasks. The following scenarios are considered: 2 classes, 4 classes, and 6 classes. The standard deviations of all the values are less than 0.04.
Num of Class Method LDM Glide GALIP ProGAN StyleGAN2 GauGAN Overall
2 classes CoOp 0.63660.63660.63660.6366 0.64480.64480.64480.6448 0.63780.63780.63780.6378 0.69280.69280.69280.6928 0.87060.87060.87060.8706 0.72590.72590.72590.7259 0.70140.70140.70140.7014
OCC-CLIP 0.64490.6449\mathbf{0.6449}bold_0.6449 0.64990.6499\mathbf{0.6499}bold_0.6499 0.64570.6457\mathbf{0.6457}bold_0.6457 0.87420.8742\mathbf{0.8742}bold_0.8742 0.89380.8938\mathbf{0.8938}bold_0.8938 0.92550.9255\mathbf{0.9255}bold_0.9255 0.77230.7723\mathbf{0.7723}bold_0.7723
4 classes CoOp - - 0.58630.58630.58630.5863 0.61240.61240.61240.6124 0.70040.70040.70040.7004 0.63760.63760.63760.6376 0.63420.63420.63420.6342
OCC-CLIP - - 0.61300.6130\mathbf{0.6130}bold_0.6130 0.74610.7461\mathbf{0.7461}bold_0.7461 0.73190.7319\mathbf{0.7319}bold_0.7319 0.79080.7908\mathbf{0.7908}bold_0.7908 0.72040.7204\mathbf{0.7204}bold_0.7204
6 classes CoOp - - - - 0.64590.64590.64590.6459 0.60920.60920.60920.6092 0.62760.62760.62760.6276
OCC-CLIP - - - - 0.65870.6587\mathbf{0.6587}bold_0.6587 0.67270.6727\mathbf{0.6727}bold_0.6727 0.66570.6657\mathbf{0.6657}bold_0.6657
Table 32: Directly training a multi-class classifier based on the OCC-CLIP or CoOp. The following scenarios are considered: 2 classes, 4 classes, and 6 classes. The standard deviations of all the values are less than 0.04.
Num of Class Method LDM Glide GALIP ProGan StyleGan2 GauGan Overall
2 classes CoOp 0.63120.63120.63120.6312 0.63970.6397\mathbf{0.6397}bold_0.6397 0.63360.63360.63360.6336 0.71500.71500.71500.7150 0.86530.8653\mathbf{0.8653}bold_0.8653 0.82280.82280.82280.8228 0.71790.71790.71790.7179
OCC-CLIP 0.64160.6416\mathbf{0.6416}bold_0.6416 0.63750.63750.63750.6375 0.63820.6382\mathbf{0.6382}bold_0.6382 0.79210.7921\mathbf{0.7921}bold_0.7921 0.84910.84910.84910.8491 0.89910.8991\mathbf{0.8991}bold_0.8991 0.74290.7429\mathbf{0.7429}bold_0.7429
4 classes CoOp - - 0.68580.68580.68580.6858 0.72420.72420.72420.7242 0.80760.80760.80760.8076 0.77710.77710.77710.7771 0.74870.74870.74870.7487
OCC-CLIP - - 0.79250.7925\mathbf{0.7925}bold_0.7925 0.79250.7925\mathbf{0.7925}bold_0.7925 0.81200.8120\mathbf{0.8120}bold_0.8120 0.85690.8569\mathbf{0.8569}bold_0.8569 0.78730.7873\mathbf{0.7873}bold_0.7873
6 classes CoOp - - - - 0.77720.7772\mathbf{0.7772}bold_0.7772 0.74790.74790.74790.7479 0.76250.76250.76250.7625
OCC-CLIP - - - - 0.76950.76950.76950.7695 0.77030.7703\mathbf{0.7703}bold_0.7703 0.76990.7699\mathbf{0.7699}bold_0.7699