Jadwal Sholat

Memuat jadwal sholatโ€ฆ

Ilmu Komputer & AI editorial

Open AccessOA2026

Dissecting Agentic Forensics: The Role of Triage, Prompting, and Evidence Arbitration in Open-World Fake Image Detection

A training-free agentic framework reveals that reasoning quality, not detector fusion, drives open-world image forensics performance.
Xianlong Li; Pietro Bongini; Niccolรณ Pancino; Marco Blanchini; Benedetta Tondi; Mauro Barniยท 2026ยท DOI 10.48550/arXiv.2609.24359

The core problem

Image forensics is increasingly an open-world problem: manipulations range from fully synthetic images to localized edits, splicing and swapping, while most forensic detectors remain specialized to a single manipulation family. Agentic AI has recently emerged as a promising solution. In principle, such systems can assess the reliability of individual detectors, identify out-of-scope evidence, and arbitrate conflicting reports. However, it remains unclear which components actually drive performance and whether their benefits persist under distribution shift. To answer these questions, the authors study a training-free agentic framework built around specialist detectors, per-detector triage, and conflict-aware evidence arbitration. Using six configurations and three multimodal large language model backbones, they dissect the role of triage, prompting, and reasoning quality on both in-distribution and out-of-distribution data.

Innovation

The results show that naive detector fusion (i.e., combining all detector outputs without triage or arbitration) suffers from severe false-positive rates on authentic images. This indicates that simply aggregating detector outputs leads to over-flagging of genuine images as manipulated.

Triage and prompting consistently improve performance by filtering unreliable evidence and exposing detector limitations. Specifically, the triage module reduces false positives by excluding detectors that are likely out-of-scope or unreliable for the given input. Prompting strategies that encourage the MLLM to consider detector reliability and potential conflicts further enhance performance.

However, the dominant factor is represented by reasoning itself: a stronger judge (i.e., a more capable MLLM) substantially outperforms a weaker one, particularly under distribution shift. This suggests that the quality of the reasoning engine is critical for handling novel manipulations and OOD data.

Most notably, manipulation recall is nearly saturated across all configurations. This means that the system is able to detect almost all manipulated images regardless of the configuration. The main challenge, t

Image forensics is increasingly an open-world problem: manipulations range from fully synthetic images to localized edits, splicing and swapping, while most forensic detectors remain specialized to a single manipulation family. Agentic AI has recently emerged as a promising solution. In principle, such systems can assess the reliability of individual detectors, identify out-of-scope evidence, and arbitrate conflicting reports. However, it remains unclear which components actually drive performance and whether their benefits persist under distribution shift. To answer these questions, the authors study a training-free agentic framework built around specialist detectors, per-detector triage, and conflict-aware evidence arbitration. Using six configurations and three multimodal large language model backbones, they dissect the role of triage, prompting, and reasoning quality on both in-distribution and out-of-distribution data.
The proposed framework is a training-free agentic system that orchestrates multiple specialist forensic detectors. The architecture consists of three main stages: (1) a pool of specialist detectors, each trained for a specific manipulation type (e.g., synthetic image detection, splicing detection, copy-move detection); (2) a triage module that assesses the reliability of each detector's output based on input characteristics and detector confidence; and (3) an evidence arbitration module that resolves conflicts among detector reports using a multimodal large language model (MLLM) as the reasoning engine.

Why it matters

The findings have important implications for the design of agentic forensic systems. First, the near-saturation of manipulation recall indicates that specialist detectors are already highly effective at identifying manipulations when they are in-scope. The bottleneck is not detection but trust calibration: determining when a detector's output should be trusted and how to resolve conflicts among detectors.

Second, the superiority of a stronger reasoning engine highlights the importance of investing in high-quality MLLMs for arbitration. A weaker judge may fail to properly weigh evidence, especially under distribution shift where detectors may behave unpredictably. This suggests that the reasoning component should be as powerful as possible, and that training-free approaches can still benefit from stronger base models.

Third, the training-free nature of the framework makes it adaptable to new detectors and manipulation types without retraining. However, the reliance on pre-trained specialist detectors means that the system's performance is bounded by the quality and coverage of those detectors.

The study also reveals that triage and prompting are complementary: triage filters unreliable evidence, while prompting guides the MLLM to reason about reliability and conflicts. Together, they improve performance, but their benefits are overshadowed by the choice of reasoning engine.

Future work could explore training the triage module or the arbitration module, or incorporating uncertainty quantification to further improve trust calibration. Additionally, the framework could be extended to other forensic tasks such as video or audio forensics.

In conclusion, the main challenge of open-world image forensics is not detecting manipulations, but calibrating trust in specialized forensic tools and arbitrating conflicting evidence. Agentic AI, with a strong reasoning engine, offers a promising path forward.

Who should read this

CS practitioners and researchers

Opening member contentโ€ฆ