NewThe detectors that scored perfect collapsed the hardest under attack.
Attack-data API for deepfake detection

Test your system against deepfake attacks to see where it breaks.

Margen delivers labeled attack-data, real and AI-generated faces across generators, demographics, and platform conditions, through one API. Pull it, run your detector, and find where it fails before an attacker does.

Built by the independent red team that benchmarks the market's detectors.

Detector report card

vendor-x v4.2

CONDITIONAL
  • Unseen generatorsFails
  • Platform-realistic conditionsDegrades
  • Per-group fairnessGap found
  • Clean benchmarkPasses

Illustrative. Real engagements report the exact failure path.

Where the human layer ends

At scale, no one is checking by hand. The system is.

A real face and its AI impersonation of the same identity. Drag to compare.

High-volume identity flows, onboarding, verification, remote interviews, move far more traffic than any team can review by hand, and the best fakes now slip past trained reviewers anyway.

So your detection system is the fraud-prevention layer, and that technical control is what we evaluate. We find where it fails, before an attacker does.

The core challenge

Why a strong-looking detector still lets fraud through.

01 / Recency

Trained on yesterday.

Detectors learn from the generators that existed when they were built. New models ship every month, and the detector has never seen them.

02 / Realism

Tested in a lab.

Vendor numbers come from clean, pristine images. Real fraud arrives compressed, resized, and re-encoded by the platforms it passes through.

03 / Fairness

Measured on the average.

A strong overall score can hide groups the detector barely catches. The average looks fine while a whole subgroup is an open lane.

The problem, measured

The detectors that scored perfect collapsed the hardest.

Detection score, where 1.00 is perfect and 0.50 is a coin flip.

Clean lab test

1.00score

Two open-source detectors that hit a perfect score on a clean test.

Decayto a coin flip

Real conditions

0.34score

The same two, re-tested against fresh attacks and the compression real platforms apply. Six other detectors slipped too, but far less.

Source: Margen open-source detector benchmark · 14 detectors

What we offer

Three ways to red-team a detector.

All three draw on the same dataset and the same methodology. They differ in whether you run it yourself or we run the engagement, and who owns the customer relationship.

01

Evaluation

You submit a detector. We red-team it.

Initiated by
The detection vendor
Duration
4 to 6 weeks, fixed scope
Deliverable
Report: verdict, per-group results, and the recipes that broke it
Sensitive data
Runs inside your perimeter on your own biometric reference data
Used for
Procurement, marketing-claim validation, pre-release QA
Request an evaluation

02

Co-delivered

Your red team brings us in for the technical layer.

Initiated by
A red-team or security-awareness partner
Duration
Matches the host engagement
Deliverable
Joint report, human and technical layers
Used for
Enterprise security audits, joint engagements
Become a partner

03

Self-service

You pull the data and run it yourself.

Initiated by
You, self-serve
Duration
On demand, ongoing
Deliverable
Labeled attack data via API, by cell, generator, condition
Used for
Internal QA, CI regression, pre-release testing
Get an API key
Who we serve

Five teams, one measurement layer.

  • +Somewhere else? Tell us your use case
01 / 05Vendor

The third-party red team that helps you close the deal.

Your buyers ask for proof that goes beyond your own benchmark. We are the independent red team that supplies it: an evaluation grounded in a corpus your team did not assemble and a method your team did not design, so the number holds up in the room where the deal is won.

What we measure for them

  • Per-group performance. Demographic and platform breakdowns of every score.
  • Bypass recipes. Every failure annotated with the recipe that surfaced it.
  • Pre-release QA. A second pair of eyes before you ship.
Versus the alternatives

Not an internal team. Not a generalist pentest.

Evaluating a detector takes a specialized, independent adversary. Here is how an engagement compares.

CapabilityMargenInternal red teamGeneralist pentest
Independent of the vendor under test
Deepfake-specific attack corpus
Per-group fairness breakdown
Platform-realistic conditions
Pre-registered, reproducible method
Hands back the breaking recipe
YesPartialNo

Find your blind spot before someone else does.

Submit a model for evaluation, or add the detection layer to a red-team engagement. You get a per-group report card showing where the detector holds, where it fails, and the recipe that broke it.