arXiv:2411.17957cs.CV2024-11中稿 · ICLR被引 15

无需优化即可快速防御扩散模型编辑,毫秒级完成图像免疫化。

DiffVax: Optimization-Free Image Immunization Against Diffusion-Based Editing

  • 通过设计失败编辑的损失函数,实现无需逐图优化的免疫化。
  • 免疫时间从天级缩短至毫秒级,提速25万倍,支持批量处理。
  • 首次有效防护视频内容,兼容多种编辑工具且抗对抗攻击。

当前针对扩散模型编辑的图像免疫防御方法通过向目标图像嵌入不可察觉的噪声来干扰编辑模型,但面临可扩展性挑战:需对每张图像单独进行耗时优化,小批次处理需数小时。为此,我们提出DiffVax,一种可扩展、轻量且无需优化的图像免疫框架,专门用于防止扩散模型编辑。该方法通过一个确保编辑失败且扰动不可察觉的损失项,实现对未见内容的有效泛化,大幅降低计算成本,将免疫时间从数日缩短至毫秒级,提速达25万倍。大量定性和定量实验表明,本模型具备可扩展性、无需优化、适配多种扩散编辑工具、对反制攻击具有鲁棒性,并首次有效保护视频内容免受编辑。更多细节见https://diffvax.github.io/。

原文摘要 · Abstract (English)

Current image immunization defense techniques against diffusion-based editing embed imperceptible noise into target images to disrupt editing models. However, these methods face scalability challenges, as they require time-consuming optimization for each image separately, taking hours for small batches. To address these challenges, we introduce DiffVax, a scalable, lightweight, and optimization-free framework for image immunization, specifically designed to prevent diffusion-based editing. Our approach enables effective generalization to unseen content, reducing computational costs and cutting immunization time from days to milliseconds, achieving a speedup of 250,000x. This is achieved through a loss term that ensures the failure of editing attempts and the imperceptibility of the perturbations. Extensive qualitative and quantitative results demonstrate that our model is scalable, optimization-free, adaptable to various diffusion-based editing tools, robust against counter-attacks, and, for the first time, effectively protects video content from editing. More details are available in https://diffvax.github.io/ .

图像免疫扩散模型无优化

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。