arXiv:2509.13922cs.CV2025-09ICCV被引 2

提出抗净化扰动方法,让隐蔽噪声在图像修复后仍有效防止滥用。

Towards Robust Defense against Customization via Protective Perturbation Resistant to Diffusion-based Purification

  • 通过局部频域与错误时间步引导,增强扰动抗净化能力。
  • 在典型净化流程下保持高失真度,感知差异极小。
  • 适合防御深度伪造和版权侵犯的图像安全场景。

扩散模型如Stable Diffusion具备强大图像定制能力,但也带来深度伪造和版权侵权等安全风险。为此,保护性扰动方法通过注入难以察觉的对抗噪声来缓解图像滥用问题。然而,现有方法易被净化过程移除,导致图像再次面临恶意伪造风险。本文首次形式化反净化任务,揭示现有方法的局限性,并提出一种名为AntiPure的诊断型保护扰动。其核心在于两项引导机制:1)块级频域引导,降低模型对净化后图像高频成分的影响;2)错误时间步引导,破坏模型在不同去噪阶段的策略。该方法在多种代表性净化设置下仍能嵌入不可察觉的扰动,实现有效的后定制失真。实验表明,作为净化流程的强度测试,AntiPure在保持最小感知差异的同时达到最大失真,显著优于现有保护扰动方法。

原文摘要 · Abstract (English)

Diffusion models like Stable Diffusion have become prominent in visual synthesis tasks due to their powerful customization capabilities, which also introduce significant security risks, including deepfakes and copyright infringement. In response, a class of methods known as protective perturbation emerged, which mitigates image misuse by injecting imperceptible adversarial noise. However, purification can remove protective perturbations, thereby exposing images again to the risk of malicious forgery. In this work, we formalize the anti-purification task, highlighting challenges that hinder existing approaches, and propose a simple diagnostic protective perturbation named AntiPure. AntiPure exposes vulnerabilities of purification within the "purification-customization" workflow, owing to two guidance mechanisms: 1) Patch-wise Frequency Guidance, which reduces the model's influence over high-frequency components in the purified image, and 2) Erroneous Timestep Guidance, which disrupts the model's denoising strategy across different timesteps. With additional guidance, AntiPure embeds imperceptible perturbations that persist under representative purification settings, achieving effective post-customization distortion. Experiments show that, as a stress test for purification, AntiPure achieves minimal perceptual discrepancy and maximal distortion, outperforming other protective perturbation methods within the purification-customization workflow.

图像安全扩散模型对抗扰动

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。