arXiv:2602.22197cs.CVcs.AI2026-02中稿 · publication at the…被引 1

只需一句提示,通用图像模型就能轻松破解多种图像保护机制。

Off-The-Shelf Image-to-Image Models Are All You Need To Defeat Image Protection Schemes

论文配图:Off-The-Shelf Image-to-Image Models Are All You Need To Defeat Image Protection Schemes
图 1 · 摘自论文原文
  • 用简单文本提示让现成图像生成模型充当通用去噪器。
  • 在8个案例中成功移除6种不同保护方案的扰动,效果优于专用攻击。
  • 揭示当前保护机制普遍存在漏洞,适合安全研究者和模型开发者参考。

生成式AI的发展催生了多种图像保护策略,通过添加难以察觉的扰动来防止图像被滥用,如风格模仿或深度伪造。尽管以往攻击这些保护需定制化方法,我们证明如今无需专门设计:仅通过简单文本提示,即可将现成的图像到图像生成模型转化为通用“去噪器”,有效去除多种保护扰动。我们在涵盖6种不同保护方案的8个案例中验证了该方法的通用性,不仅成功绕过防御,且在保持图像可用性方面优于现有专用攻击。结果表明,当前多数保护机制存在严重漏洞,提供虚假安全感。我们强调亟需构建更强防御,并指出未来任何保护方案都必须经过现成生成模型攻击的检验。代码已开源:https://github.com/mlsecviswanath/img2imgdenoiser。

原文摘要 · Abstract (English)

Advances in Generative AI (GenAI) have led to the development of various protection strategies to prevent the unauthorized use of images. These methods rely on adding imperceptible protective perturbations to images to thwart misuse such as style mimicry or deepfake manipulations. Although previous attacks on these protections required specialized, purpose-built methods, we demonstrate that this is no longer necessary. We show that off-the-shelf image-to-image GenAI models can be repurposed as generic ``denoisers" using a simple text prompt, effectively removing a wide range of protective perturbations. Across 8 case studies spanning 6 diverse protection schemes, our general-purpose attack not only circumvents these defenses but also outperforms existing specialized attacks while preserving the image's utility for the adversary. Our findings reveal a critical and widespread vulnerability in the current landscape of image protection, indicating that many schemes provide a false sense of security. We stress the urgent need to develop robust defenses and establish that any future protection mechanism must be benchmarked against attacks from off-the-shelf GenAI models. Code is available in this repository: https://github.com/mlsecviswanath/img2imgdenoiser

图像安全生成模型对抗攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。