提出两阶段隐空间优化,高效绕过扩散模型版权保护
Bypassing Copyright Protection in Diffusion-based Customization via Two-Stage Latent Feature Optimization

- 分两阶段优化隐空间特征,恢复被防御机制破坏的映射关系
- 在多种设置下超越现有攻击方法,成功绕过主流版权防护
- 适合研究图像生成安全与对抗攻击的学者参考
随着基于扩散模型的个性化生成中版权侵权问题日益突出,对抗攻击已成为防止恶意内容伪造的重要防御策略。然而,现有防御通常在隐空间引入持久扰动,易被攻击者自适应规避。本文提出两阶段隐空间特征优化(TS-LFO),一种高效且有效的版权盗用攻击方法。我们观察到现有防御主要破坏输入图像与其隐表示之间的映射关系,导致模型无法生成个性化输出。为应对这一问题,TS-LFO通过两阶段优化过程恢复该映射:在隐去噪阶段,联合最小化隐-图像对齐损失与隐扩散损失,并采用随时间步变化的权重,有效抑制防御引入的高频噪声;在隐重构阶段,利用像素级约束恢复低频语义信息以精炼隐特征。大量实验表明,TS-LFO能持续绕过当前最先进的版权防御方案,并在多种设置下优于如DiffPure、GrIDPure和IMPRESS等顶尖攻击方法。
原文摘要 · Abstract (English)
With the growing concerns over copyright infringement in diffusion-based customization, adversarial attacks have emerged as a prominent defense strategy to prevent malicious content forgery in personalized image generation. However, current defenses typically introduce persistent perturbations in the latent space of Latent Diffusion Models (LDMs), which remain susceptible to adaptive bypasses by adversaries. In this paper, we introduce Two-Stage Latent Feature Optimization (TS-LFO), an efficient and effective copyright-stealing attack against protected diffusion-based customization. We begin by observing that existing defenses primarily disrupt the mapping between input images and their latent representations, thereby degrading the model's ability to produce personalized outputs. To counteract this, TS-LFO restores the broken mapping through a two-stage optimization process. In the Latent Denoising Stage, we enhance semantic consistency between latent codes and input images by jointly minimizing a Latent-Image Alignment Loss and a Latent Diffusion Loss with timestep-dependent weights, effectively suppressing the high-frequency noise introduced by defenses. In the Latent Reconstruction Stage, we recover low-frequency semantic information using pixel-level constraints to refine the latent features. Extensive experiments show that TS-LFO consistently bypasses state-of-the-art (SOTA) copyright defenses and outperforms SOTA copyright attacks such as DiffPure, GrIDPure and IMPRESS across diverse settings.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。