arXiv:2512.10433cs.AI2025-12AAAI被引 1

通过控制训练轨迹实现扩散模型的精准数据保护

Targeted Data Protection for Diffusion Model by Matching Training Trajectory

  • 基于对抗扰动微调,匹配完整训练轨迹而非单一快照
  • 首次实现身份与视觉模式的同步可控重定向
  • 保护效果持久可验证,适合需隐私防护的个性化模型

扩散模型的微调个性化日益普及,但带来未经授权数据使用和隐私泄露风险。现有保护方法仅被动降低图像质量,难以稳定控制。目标数据保护(TDP)虽能主动引导至指定概念,但现有方法因依赖快照匹配,忽视学习动态,导致控制能力差。本文提出TAFAP(通过对抗扰动微调实现轨迹对齐),首次通过控制完整训练轨迹实现有效TDP。不同于随训练过程衰减的快照方法,TAFAP借鉴数据蒸馏思想,确保全程持续可验证的转化。大量实验表明,TAFAP首次在扩散模型中成功实现身份与视觉模式的同步可控重定向,显著优于现有TDP方法,在保持高图像质量的同时实现强定向性。该工作为扩散模型输出的可控与可追溯性提供了新框架。

原文摘要 · Abstract (English)

Recent advancements in diffusion models have made fine-tuning text-to-image models for personalization increasingly accessible, but have also raised significant concerns regarding unauthorized data usage and privacy infringement. Current protection methods are limited to passively degrading image quality, failing to achieve stable control. While Targeted Data Protection (TDP) offers a promising paradigm for active redirection toward user-specified target concepts, existing TDP attempts suffer from poor controllability due to snapshot-matching approaches that fail to account for complete learning dynamics. We introduce TAFAP (Trajectory Alignment via Fine-tuning with Adversarial Perturbations), the first method to successfully achieve effective TDP by controlling the entire training trajectory. Unlike snapshot-based methods whose protective influence is easily diluted as training progresses, TAFAP employs trajectory-matching inspired by dataset distillation to enforce persistent, verifiable transformations throughout fine-tuning. We validate our method through extensive experiments, demonstrating the first successful targeted transformation in diffusion models with simultaneous control over both identity and visual patterns. TAFAP significantly outperforms existing TDP attempts, achieving robust redirection toward target concepts while maintaining high image quality. This work enables verifiable safeguards and provides a new framework for controlling and tracing alterations in diffusion model outputs.

扩散模型数据保护个性化轨迹对齐

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。