通过高频扰动增强图像防御,抵御恶意生成攻击
High-Frequency Anti-DreamBooth: Robust Defense against Personalized Image Synthesis
- 在图像高频区域添加强扰动,提升防御鲁棒性
- 经对抗净化后仍保留噪声,有效阻止恶意生成
- 适合需保护隐私的个人图像数据使用场景
近期,文本到图像生成模型被滥用于制作未经同意的个人恶意图像,引发日益严重的社会问题。现有方案如 Anti-DreamBooth 通过向图像添加对抗噪声来防止其被用作恶意生成的训练数据。然而我们发现,此类噪声可被 DiffPure 等对抗净化方法去除。因此,我们提出一种新对抗攻击方法,在图像高频区域添加强扰动,以增强对对抗净化的鲁棒性。实验表明,经过对抗净化后,对抗图像仍保留噪声,从而阻碍恶意图像生成。
原文摘要 · Abstract (English)
Recently, text-to-image generative models have been misused to create unauthorized malicious images of individuals, posing a growing social problem. Previous solutions, such as Anti-DreamBooth, add adversarial noise to images to protect them from being used as training data for malicious generation. However, we found that the adversarial noise can be removed by adversarial purification methods such as DiffPure. Therefore, we propose a new adversarial attack method that adds strong perturbation on the high-frequency areas of images to make it more robust to adversarial purification. Our experiment showed that the adversarial images retained noise even after adversarial purification, hindering malicious image generation.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。