提出反修复防御框架,应对未知条件下的扩散模型篡改。
Anti-Inpainting: A Proactive Defense Approach against Malicious Diffusion-based Inpainters under Unknown Conditions
- 通过多级特征提取增强对扩散去噪过程的感知能力。
- 在未知条件下实现对多种修复模型的有效防护。
- 适合图像安全防护与对抗样本防御的研究者参考。
随着基于扩散模型的恶意图像篡改日益普遍,现有主动防御方法在未知条件下难以有效保护图像。为此,我们提出 Anti-Inpainting,一种包含三个创新模块的主动防御方法。首先,引入多级深度特征提取器,从扩散去噪过程中获取精细特征,提升防护效果。其次,设计多尺度、语义保持的数据增强技术,增强对抗扰动在未知条件下的迁移能力。最后,提出基于选择的分布偏移优化策略,强化对不同随机种子驱动篡改的抵御能力。在 InpaintGuardBench 与 CelebA-HQ 上的大量实验表明,Anti-Inpainting 能有效防御未知条件下的扩散式修复攻击。此外,该方法对多种图像净化手段具有鲁棒性,并可跨不同扩散模型版本实现迁移防护。
原文摘要 · Abstract (English)
With the increasing prevalence of diffusion-based malicious image manipulation, existing proactive defense methods struggle to safeguard images against tampering under unknown conditions. To address this, we propose Anti-Inpainting, a proactive defense approach that achieves protection comprising three novel modules. First, we introduce a multi-level deep feature extractor to obtain intricate features from the diffusion denoising process, enhancing protective effectiveness. Second, we design a multi-scale, semantic-preserving data augmentation technique to enhance the transferability of adversarial perturbations across unknown conditions. Finally, we propose a selection-based distribution deviation optimization strategy to bolster protection against manipulations guided by diverse random seeds. Extensive experiments on InpaintGuardBench and CelebA-HQ demonstrate that Anti-Inpainting effectively defends against diffusion-based inpainters under unknown conditions. Additionally, our approach demonstrates robustness against various image purification methods and transferability across different diffusion model versions.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。