arXiv:2512.07247cs.CVcs.CR2025-12被引 10

为3D高斯点云设计对抗扰动防护,防止任意视角下被指令编辑。

AdLift: Lifting Adversarial Perturbations to Safeguard 3D Gaussian Splatting Assets Against Instruction-Driven Editing

  • 将2D对抗扰动提升到3D高斯空间,实现跨视角保护。
  • 在10个测试视点上保持95%以上防护成功率,新视角泛化能力强。
  • 适合需版权保护的3D内容创作者,如游戏/影视资产开发者。

近期研究将基于扩散模型的指令驱动2D图像编辑扩展至3D高斯点云(3DGS),实现了对3DGS资产的精准操控,极大推动了3D内容创作。但这也使资产面临未经授权编辑和恶意篡改的严重风险。尽管不可察觉的对抗扰动在2D图像保护中已证明有效,将其应用于3DGS却面临两大挑战:视图通用性保护与隐匿性与防护能力的平衡。本文提出首个面向3DGS的编辑防护方法AdLift,通过将严格受限的2D对抗扰动提升至3D高斯表示的防护体,实现跨任意视角和维度的指令驱动编辑防御。为确保扰动有效性与隐蔽性,防护高斯点通过定制化的升维PGD算法,在训练视点上逐步优化:首先在渲染图像层面进行反向传播时执行梯度截断,再施加投影梯度以严格约束图像级扰动;随后通过图像-高斯拟合操作将扰动反传至防护高斯参数。交替执行梯度截断与拟合操作,使防护性能在不同视点间保持一致,并可泛化至新视点。实验结果表明,定性和定量评估均验证了AdLift对当前主流指令驱动2D图像及3DGS编辑的有效防护能力。

原文摘要 · Abstract (English)

Recent studies have extended diffusion-based instruction-driven 2D image editing pipelines to 3D Gaussian Splatting (3DGS), enabling faithful manipulation of 3DGS assets and greatly advancing 3DGS content creation. However, it also exposes these assets to serious risks of unauthorized editing and malicious tampering. Although imperceptible adversarial perturbations against diffusion models have proven effective for protecting 2D images, applying them to 3DGS encounters two major challenges: view-generalizable protection and balancing invisibility with protection capability. In this work, we propose the first editing safeguard for 3DGS, termed AdLift, which prevents instruction-driven editing across arbitrary views and dimensions by lifting strictly bounded 2D adversarial perturbations into 3D Gaussian-represented safeguard. To ensure both adversarial perturbations effectiveness and invisibility, these safeguard Gaussians are progressively optimized across training views using a tailored Lifted PGD, which first conducts gradient truncation during back-propagation from the editing model at the rendered image and applies projected gradients to strictly constrain the image-level perturbation. Then, the resulting perturbation is backpropagated to the safeguard Gaussian parameters via an image-to-Gaussian fitting operation. We alternate between gradient truncation and image-to-Gaussian fitting, yielding consistent adversarial-based protection performance across different viewpoints and generalizes to novel views. Empirically, qualitative and quantitative results demonstrate that AdLift effectively protects against state-of-the-art instruction-driven 2D image and 3DGS editing.

3D高斯对抗防御内容保护编辑安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。