CoolFace
Datasetpublic

Snowstorm1492/SafeIMG

 SafeIMG AI-generated Images Challenge Visual Trust in High-risk Scenarios Yi-Zhi Wang1,2, Yichen Xiao1,2, Linan Yue1,2, Weibo Gao3, Yichao Du4, Pengfei Fang1,2, Shimin Di1,2, Min-Ling Zhang1,2 1 Southeast University    2 Key Laboratory of Computer Network and Information Integration, Ministry of Education3 The Hong Kong Polytechnic University    4 School of Artificial Intelligence, Wuhan University Overview · Dataset · Results · Quick Start ·… See the full description on the dataset page: https://huggingface.co/datasets/Snowstorm1492/SafeIMG.

sourceHugging Faceupdated 2mo agoView on Hugging Face
0likes1.2kdownloads
Dataset Card

<div align="center"> <h1> <img src="assets/logo.jpg" alt="SafeIMG Logo" width="70" valign="middle"> <span>&nbsp;SafeIMG</span> </h1>

AI-generated Images Challenge Visual Trust in High-risk Scenarios

Yi-Zhi Wang<sup>1,2</sup>, Yichen Xiao<sup>1,2</sup>, Linan Yue<sup>1,2</sup>, Weibo Gao<sup>3</sup>, Yichao Du<sup>4</sup>, Pengfei Fang<sup>1,2</sup>, Shimin Di<sup>1,2</sup>, Min-Ling Zhang<sup>1,2</sup>

<sup>1</sup> Southeast University &nbsp;&nbsp; <sup>2</sup> Key Laboratory of Computer Network and Information Integration, Ministry of Education <sup>3</sup> The Hong Kong Polytechnic University &nbsp;&nbsp; <sup>4</sup> School of Artificial Intelligence, Wuhan University

![Project Page](https://safeimg.github.io/) ![Dataset](https://huggingface.co/datasets/Snowstorm1492/SafeIMG) ![Task](#benchmark-tasks)

Overview · Dataset · Results · Quick Start · Citation

SafeIMG is a safety-oriented benchmark for detecting AI-generated images that imitate visual evidence in high-risk public- and individual-safety scenarios.

</div>

[!WARNING] SafeIMG contains synthetic depictions of disasters, accidents, violence, emergencies, transactions, and other sensitive scenarios. The data are intended for research and evaluation only. Images in this benchmark must not be presented as records of real events.

📑 News

  • 2026-07: SafeIMG dataset and evaluation code released.
  • 2026-07: SafeIMG paper released.

📋 Overview

Modern image generators can create realistic, story-rich images that resemble news photographs, transaction records, chat screenshots, identity endorsements, and other forms of visual evidence. Existing synthetic-image detection benchmarks primarily cover general natural images, earlier generators, or domains that are not directly tied to safety-critical decisions.

SafeIMG asks a more demanding question:

Can a detector recognize AI-generated images when they imitate evidence used in high-stakes real-world decisions?

SafeIMG provides:

  • 12 high-risk scenarios spanning public safety and individual safety;
  • images generated with GPT Image 2, representing a challenging new-generator distribution;
  • a risk-oriented scenario taxonomy and structured, story-complete prompts;
  • fine-grained human annotations of suspicious regions, artifact types, and textual explanations;
  • evaluation of specialized forensic detectors, multimodal large language models, and humans;
  • diagnostic analyses of explanation alignment and robustness under network-propagation degradation.

<p align="center"> <img src="assets/dataset_overview.png" width="100%" alt="Overview and representative samples of SafeIMG"> </p>

💡 Why SafeIMG?

  1. 1.Safety-critical visual evidence. SafeIMG focuses on images whose misuse may affect public judgment, emergency response, financial trust, identity claims, personal reputation, or legal interpretation.
  2. 2.A modern generator distribution. Samples are produced with GPT Image 2 rather than only GANs or early diffusion models, exposing substantial distribution shift for existing detectors.
  3. 3.Diagnosis beyond a real/fake label. Each annotated artifact records where the suspicious evidence is, what type of issue it represents, and why it appears abnormal.
  4. 4.Local and high-level reasoning. The benchmark covers explicit artifacts involving text, faces, hands, or lighting as well as scene-level commonsense conflicts and violations of physical laws.
  5. 5.Realistic dissemination conditions. SafeIMG measures robustness after compression and image degradation that resemble online sharing and re-encoding.

📚 Benchmark Tasks

SafeIMG supports four complementary evaluation tracks:

TrackInputExpected outputMain purpose
Image authenticityOne imagereal or ai_generatedMeasure image-level detection capability
Artifact diagnosisOne generated imageSuspicious regions and artifact typesTest whether a detector identifies meaningful forensic cues
Rationale alignmentImage plus model explanationsAtomic visual reasonsCompare model evidence with human annotations
Propagation robustnessDegraded or re-encoded imageAuthenticity predictionTest stability under realistic dissemination transformations

🧩 Taxonomy

SafeIMG contains eight public-safety categories and four individual-safety categories.

IDDomainCategoryEvidentiary function
P1Public safetyNatural DisastersClaims about disaster impact and emergency response
P2Public safetySocial Unrest, Public Violence, and Attack IncidentsClaims about public order, security risks, and social stability
P3Public safetyTransportation AccidentsClaims about occurrence, damage, and responsibility
P4Public safetyFires, Explosions, and Energy Facility AccidentsRisk assessment and emergency handling
P5Public safetyPollution and Hazardous Material AccidentsClaims that may trigger panic or regulatory action
P6Public safetyBuilding and Civil Infrastructure AccidentsClaims about infrastructure safety, damage, and liability
P7Public safetyCrowd Gathering and Venue Safety AccidentsCrowd control, evacuation, and event-safety judgments
P8Public safetyPublic Health and Biosecurity EventsClaims affecting public-health decisions and social trust
I1Individual safetyPersonal Accidents and EmergenciesClaims about personal danger, rescue needs, or liability
I2Individual safetyPrivate Receipts and Transaction RecordsClaims about payments, refunds, reimbursement, or disputes
I3Individual safetyPersonal Chat and Communication RecordsClaims about private commitments, misconduct, or disputes
I4Individual safetyFabricated Scene Evidence and Identity EndorsementClaims about presence, status, identity, or endorsement

🛠️ Benchmark Construction

SafeIMG is built in five stages:

  1. 1.Risk-oriented taxonomy: define public- and individual-safety categories.
  2. 2.Scenario-space specification: specify a risk summary, content list, and media-form list for each category.
  3. 3.Prompt construction: expand each scenario with a 5W+1H narrative structure and category-specific constraints.
  4. 4.Image generation and filtering: generate images with GPT Image 2 and remove invalid or severely off-topic samples.
  5. 5.Human annotation: localize suspicious regions, assign artifact labels, and write concise explanations.

<p align="center"> <img src="assets/construction_pipeline.png" width="100%" alt="Five-stage construction pipeline of SafeIMG"> </p>

📝 Annotation Design

For each retained synthetic image, SafeIMG preserves construction metadata such as its risk category, scenario instance, complete generation prompt, and media form. Fine-grained annotations may additionally contain:

  • one or more suspicious regions;
  • an artifact type for each region, such as Commonsense, Faces, Fonts, Physics, Hands, Lighting, or Other;
  • a natural-language explanation describing the concrete issue;
  • an image-level authenticity label.

This design enables evaluation at both the decision level (is the image real or generated?) and the evidence level (where is the problem, and why is it suspicious?).

🌟 Dataset Examples

SafeIMG includes documentary-style images, news-like photographs, transaction records, device screenshots, chat records, and identity-endorsement material. The overview above shows representative samples from all 12 categories together with region-level artifact annotations.

The following snippet loads one record and inspects the exact schema published on Hugging Face:

python
from datasets import load_dataset

dataset = load_dataset(
    "Snowstorm1492/SafeIMG",
    split="test"
)

print(dataset)
print(len(dataset))

📊 Experimental Results

SafeIMG exposes a substantial gap between current automated detectors and human forensic judgment.

<p align="center"> <img src="assets/result.png" width="100%" alt="Five-stage construction pipeline of SafeIMG"> </p>

<p align="center"> <img src="assets/result2.png" width="100%" alt="Five-stage construction pipeline of SafeIMG"> </p>

🚀 Quick Start

1. Set up

Clone the repository and enter the project directory:

bash
git clone https://github.com/Snowstorm1492/SafeIMG.git
cd SafeIMG

We recommend creating a new Conda environment:

bash
conda create -n safeimg python=3.11
conda activate safeimg

Install the required dependencies:

bash
pip install -r requirements.txt

2. Load SafeIMG from Hugging Face

python
from datasets import load_dataset

dataset = load_dataset(
    "Snowstorm1492/SafeIMG",
    split="test"
)

print(dataset)
print(len(dataset))

To download a local snapshot instead:

bash
hf download Snowstorm1492/SafeIMG \
  --repo-type dataset \
  --local-dir data/SafeIMG

3. Base VLM evaluation

Run the base VLM evaluation with the following command:

bash
python evaluation_vlm.py \
  --base-url "<YOUR_BASE_URL>" \
  --api-key "<YOUR_API_KEY>" \
  --model "<YOUR_MODEL_NAME>" \
  --output "results/predictions.jsonl"

4. Specialized detector evaluation

Run the specialized AI detection model evaluation with the following command. CNNSpot, FreDect, and LNP are supported.

bash
python evaluation_spec.py \
  --methods cnnspot fredect lnp \
  --dataset Snowstorm1492/SafeIMG \
  --weights-dir weights \
  --device cuda \
  --lnp-device cpu \
  --output-dir results/specialized

The required weights and auxiliary files can be downloaded from the official repositories of CNNSpot, FreDect, LNP or AIGCDetectBenchmark. The expected directory structure is as follows:

text
weights/
├── classifier/
│   ├── CNNSpot.pth
│   ├── FreDect.pth
│   └── LNP.pth
├── preprocessing/
│   └── sidd_rgb.pth
└── auxiliary/
    ├── dct_mean
    └── dct_var

5. Human - AI alignment in artifact explanations

Evaluate human–AI alignment in artifact explanations with the following commands.

Evaluate human_covered_by_ai:

bash
python evaluation_human_covered_by_ai.py \
  --predictions "results/predictions.jsonl" \
  --base-url "<YOUR_BASE_URL>" \
  --api-key "<YOUR_API_KEY>" \
  --model "gpt-5.5"

Evaluate ai_supported_by_human:

bash
python evaluation_ai_supported_by_human.py \
  --predictions "results/predictions.jsonl" \
  --base-url "<YOUR_BASE_URL>" \
  --api-key "<YOUR_API_KEY>" \
  --model "gpt-5.5"

⚙️ Responsible Use

SafeIMG is designed to improve research on visual authenticity and forensic reliability. It must not be used to fabricate evidence, impersonate individuals, misrepresent synthetic events as real, or facilitate fraud, harassment, or panic.

Benchmark performance should not be interpreted as proof that a model is suitable for autonomous deployment in legal, financial, medical, emergency-response, or public-safety decisions. Current systems can miss realistic synthetic images and can also falsely accuse real images of being generated. Human review, provenance information, source verification, and contextual evidence remain necessary.

🙏 Acknowledgments

We thank the open-source communities behind Hugging Face and PyTorch for their valuable tools and infrastructure. We also thank the authors and contributors of CNNSpot, FreDect, LNP, and AIGCDetectBenchmark, whose publicly available implementations informed our specialized detector evaluation.

🛡️ License

SafeIMG is licensed under the Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.

🔗 Citation

If SafeIMG is useful in your research, please cite:

bibtex
@misc{wang2026aigeneratedimageschallengevisual,
      title={AI-generated Images Challenge Visual Trust in High-risk Scenarios}, 
      author={Yi-Zhi Wang and Yichen Xiao and Linan Yue and Weibo Gao and Yichao Du and Pengfei Fang and Shimin Di and Min-Ling Zhang},
      year={2026},
      eprint={2607.22745},
      archivePrefix={arXiv},
      primaryClass={cs.CV},
      url={https://arxiv.org/abs/2607.22745}, 
}

For questions about the benchmark, data, or evaluation protocol, please contact Linan Yue at lnyue@seu.edu.cn or open a GitHub issue.