arXiv:2606.12263cs.CV2026-06

通过操控扩散过程的随机性,有效防止模型未经授权模仿他人形象。

VOID: Defeating Unauthorized Mimicry in Latent Diffusion Models

论文配图:VOID: Defeating Unauthorized Mimicry in Latent Diffusion Models
图 1 · 摘自论文原文
  • 利用噪声放大与引导信号对抗,破坏图像语义结构
  • 使生成图像的相似度提升223%,平均FID达365
  • 防御效果强且不影响图像可用性,适合隐私保护场景

尽管潜在扩散模型(LDMs)在视觉生成中取得突破,但其正被滥用于未经授权的个人形象模仿。现有防御方法通过注入误导性扰动,引导生成结果偏离目标,但这一方法基于一个未经验证的假设:微小扰动能在整个生成过程中保持欺骗性。实际上,模型内在的恢复机制会消除这些扰动,导致个体特征重新显现。本文提出VOID框架,通过操控LDM固有的随机性来解决该问题。具体方法包括:1)放大潜在编码误差以破坏图像语义结构;2)抵消目标引导信号以抑制模型恢复能力。该方法实现语义破坏,有效阻断非法模仿。值得注意的是,该防御不损害图像视觉质量,扰动仅局限于人眼无法察觉区域。在5个数据集上对10种模仿攻击评估24种先进防御方案表明,VOID将平均弗雷切特初始距离(FID)从113提升至365,较当前最强防御提升223%,展现出前所未有的防护能力。

原文摘要 · Abstract (English)

While Latent Diffusion Models (LDMs) have revolutionized visual synthesis, they are increasingly exploited for unauthorized mimicry of individuals. Existing defenses inject deceptive perturbations to steer the generated images toward irrelevant targets. However, this approach hinges on an ungrounded assumption: subtle perturbations can maintain their deceptive efficacy throughout an LDM's extensive generation process. In reality, the model's innate restoration mechanism will remove such perturbations and cause individual identities to re-emerge in the images generated. We propose VOID, a defense framework that overcomes this conundrum by manipulating an LDM's intrinsic stochasticity. VOID perturbs the diffusion pipeline in two novel ways: 1) amplifying the latent encoding errors to shatter an image's semantic structure, and 2) counteracting the target guidance signals to suppress the model's restoration capabilities. This results in a semantic corruption that thwarts any unauthorized mimicry. Notably, the security gain does not come at the price of visual utility, as VOID simultaneously manages to confine perturbations to human-imperceptible regions of protected images. Our comprehensive evaluation of 24 state-of-the-art defenses against 10 mimicry attacks on 5 datasets demonstrates VOID's unprecedented protection power: it increases the average Frechet Inception Distance (FID) from 113 to 365, a 223% improvement over the strongest defense to date.

隐私保护扩散模型对抗防御

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。