Pith. sign in

REVIEW 15 cited by

Mist: Towards Improved Adversarial Examples for Diffusion Models

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2305.12683 v1 pith:ZQR4CGUU submitted 2023-05-22 cs.CV cs.AI

classification cs.CVcs.AI
keywords adversarialexamplesdiffusionmodelstransferabilitycopyrightdefenseexample
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Diffusion Models (DMs) have empowered great success in artificial-intelligence-generated content, especially in artwork creation, yet raising new concerns in intellectual properties and copyright. For example, infringers can make profits by imitating non-authorized human-created paintings with DMs. Recent researches suggest that various adversarial examples for diffusion models can be effective tools against these copyright infringements. However, current adversarial examples show weakness in transferability over different painting-imitating methods and robustness under straightforward adversarial defense, for example, noise purification. We surprisingly find that the transferability of adversarial examples can be significantly enhanced by exploiting a fused and modified adversarial loss term under consistent parameters. In this work, we comprehensively evaluate the cross-method transferability of adversarial examples. The experimental observation shows that our method generates more transferable adversarial examples with even stronger robustness against the simple adversarial defense.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 15 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Cross-Branch Conflict as a Shield: Safeguarding Facial Identities in Unified Multimodal Image Editing

    cs.CV 2026-07 conditional novelty 7.0 of 10

    CCS jointly perturbs the ViT and VAE pathways and reduces their CKA agreement, causing unified multimodal image editors to lose facial identity.

  2. Beyond Invisibility: Learning Robust Visible Watermarks for Stronger Copyright Protection

    cs.LG 2025-06 conditional novelty 7.0 of 10

    HARVIM learns watermark placement to maximize reconstruction error under an inpainting-based removal model, showing modest gains over random watermarks.

  3. SRAP: SVD-Refined Adversarial Perturbations for Imperceptible Face-Swap Defense

    cs.CV 2026-08 conditional novelty 6.0 of 10

    SRAP combines per-channel truncated SVD and an identity-importance mask to make PGD perturbations for face-swap defense more imperceptible while retaining competitive identity disruption.

  4. Delving into the Temporal Challenges of Unified Video Protection Against Image-to-Video and Fine-Tuning-based Customization

    cs.CV 2026-07 conditional novelty 6.0 of 10

    TC-UAP learns a shared multi-frame adversarial perturbation that protects videos of the same identity from both fine-tuning-based and reference-based video customization, remaining effective on unseen clips and under ...

  5. Defending from GeoLocalization through Adversarial Road Trips

    cs.CV 2026-07 conditional novelty 6.0 of 10

    RoadTrip Attack uses beam search over adaptive geographic intermediate targets to produce stronger, more transferable, lower-visibility adversarial examples against retrieval-based image geolocalizers than PGD, FGSM, ...

  6. SyncBreaker:Stage-Aware Multimodal Adversarial Attacks on Audio-Driven Talking Head Generation

    cs.CV 2026-04 unverdicted novelty 6.0 of 10

    SyncBreaker jointly attacks image and audio streams with Multi-Interval Sampling and Cross-Attention Fooling to degrade speech-driven talking head generation more than single-modality baselines.

  7. LoReUn: Data Itself Implicitly Provides Cues to Improve Machine Unlearning

    cs.LG 2025-07 conditional novelty 6.0 of 10

    LoReUn, a plug-in loss-based reweighting strategy, improves approximate machine unlearning by focusing updates on hard-to-forget low-loss data points.

  8. Silence is Golden: Leveraging Adversarial Examples to Nullify Audio Control in LDM-based Talking-Head Generation

    cs.GR 2025-06 conditional novelty 6.0 of 10

    Silencer adds a nearly invisible disturbance to portraits that makes LDM-based talking-head models keep the mouth silent, and it survives several image-purification countermeasures.

  9. CAT: Contrastive Adversarial Training for Evaluating the Robustness of Protective Perturbations in Latent Diffusion Models

    cs.CV 2025-02 conditional novelty 6.0 of 10

    CAT trains lightweight adapters on the latent autoencoder to realign representations of protected images, reducing the effectiveness of nine protective perturbation methods on Stable Diffusion customization.

  10. Immunizing Images from Text to Image Editing via Adversarial Cross-Attention

    cs.CV 2025-09 conditional novelty 5.0 of 10

    An imperceptible adversarial noise, computed with a LLaVA caption as a stand-in for the unknown edit prompt, disrupts cross-attention in Stable Diffusion-based editors and makes text-guided edits fail.

  11. Evaluating Adversarial Protections for Diffusion Personalization: A Comprehensive Study

    cs.CV 2025-07 conditional novelty 5.0 of 10

    A unified benchmark of eight perturbation-based protections shows budget-dependent trade-offs between stealth and disruption, with no method winning across all metrics.

  12. What is Adversarial Training for Diffusion Models?

    cs.CV 2025-05 conditional novelty 5.0 of 10

    Diffusion models trained with an equivariant adversarial-smoothing regularizer tolerate heavy training-data corruption but lose image quality on clean data.

  13. Structure Disruption: Subverting Malicious Diffusion-Based Inpainting via Self-Attention Query Perturbation

    cs.CV 2025-05 conditional novelty 5.0 of 10

    SDA adds a small perturbation that disrupts self-attention queries in the first denoising step, stopping Stable Diffusion inpainting from producing coherent edits.

  14. Dac-Fake: A Divide and Conquer Framework for Detecting Fake News on Social Media

    cs.SI 2025-08 unverdicted novelty 4.0 of 10

    The abstract claims a new fake news detector with 97.88%, 96.05%, and 97.32% accuracy, but the manuscript body is a different paper on image inpainting protection.

  15. Is Perturbation-Based Image Protection Disruptive to Image Editing?

    cs.CV 2025-06 conditional novelty 4.0 of 10

    Perturbation-based protections do not reliably block diffusion editing, and in many cases they increase the edited image's alignment with the guidance prompt.

Pith tools