REVIEW 11 cited by
Raising the Cost of Malicious AI-Powered Image Editing
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
read the original abstract
We present an approach to mitigating the risks of malicious image editing posed by large diffusion models. The key idea is to immunize images so as to make them resistant to manipulation by these models. This immunization relies on injection of imperceptible adversarial perturbations designed to disrupt the operation of the targeted diffusion models, forcing them to generate unrealistic images. We provide two methods for crafting such perturbations, and then demonstrate their efficacy. Finally, we discuss a policy component necessary to make our approach fully effective and practical -- one that involves the organizations developing diffusion models, rather than individual users, to implement (and support) the immunization process.
Forward citations
Cited by 11 Pith papers
-
I2VShield: An Efficient Proactive Defense Framework against DiT-based Image-to-Video Models
A text-adaptive generator trained to disrupt diffusion-transformer cross-attention shields reference images from video-generation misuse at low online cost.
-
Cross-Branch Conflict as a Shield: Safeguarding Facial Identities in Unified Multimodal Image Editing
CCS jointly perturbs the ViT and VAE pathways and reduces their CKA agreement, causing unified multimodal image editors to lose facial identity.
-
Beyond Invisibility: Learning Robust Visible Watermarks for Stronger Copyright Protection
HARVIM learns watermark placement to maximize reconstruction error under an inpainting-based removal model, showing modest gains over random watermarks.
-
IDDM: Identity-Decoupled Personalized Diffusion Models with a Tunable Privacy-Utility Trade-off
IDDM immunizes authorized personalized diffusion models so public generations remain high-quality while identity linkability to face recognizers is reduced with a tunable privacy-utility knob.
-
Defending from GeoLocalization through Adversarial Road Trips
RoadTrip Attack uses beam search over adaptive geographic intermediate targets to produce stronger, more transferable, lower-visibility adversarial examples against retrieval-based image geolocalizers than PGD, FGSM, ...
-
SyncBreaker:Stage-Aware Multimodal Adversarial Attacks on Audio-Driven Talking Head Generation
SyncBreaker jointly attacks image and audio streams with Multi-Interval Sampling and Cross-Attention Fooling to degrade speech-driven talking head generation more than single-modality baselines.
-
Silence is Golden: Leveraging Adversarial Examples to Nullify Audio Control in LDM-based Talking-Head Generation
Silencer adds a nearly invisible disturbance to portraits that makes LDM-based talking-head models keep the mouth silent, and it survives several image-purification countermeasures.
-
DECAF: De-Clustering for Adaptive Representational Unlearning
DECAF is a forget-only unlearning method that adds input noise, suppresses the forget-class probability, and diversifies outputs, achieving 0.10% forget accuracy and 79.4% retain accuracy on CIFAR-10/ResNet-18 while d...
-
Immunizing Images from Text to Image Editing via Adversarial Cross-Attention
An imperceptible adversarial noise, computed with a LLaVA caption as a stand-in for the unknown edit prompt, disrupts cross-attention in Stable Diffusion-based editors and makes text-guided edits fail.
-
Evaluating Adversarial Protections for Diffusion Personalization: A Comprehensive Study
A unified benchmark of eight perturbation-based protections shows budget-dependent trade-offs between stealth and disruption, with no method winning across all metrics.
-
Is Perturbation-Based Image Protection Disruptive to Image Editing?
Perturbation-based protections do not reliably block diffusion editing, and in many cases they increase the edited image's alignment with the guidance prompt.
Discussion (0). Continue with ORCID to comment.