arXiv:2607.10580cs.CVcs.AI2026-07

用扩散模型在语义层面改图,让AI学不会又不伤画质。

DiffUE: Enhancing Utility-Unlearnability Trade-off of Unlearnable Examples via Diffusion Autoencoders

论文配图:DiffUE: Enhancing Utility-Unlearnability Trade-off of Unlearnable Examples via Diffusion Autoencoders
图 1 · 摘自论文原文
  • 在图像语义空间而非像素层加噪,更难被模型学走。
  • 在4个数据集上测试,既保画质又防重学,效果显著提升。
  • 适合关注隐私保护的开发者和需要合规生成内容的团队。

AI模型越来越多地使用社交媒体和公开平台上的个人图像进行训练,常未经同意,导致未经授权的人脸识别和定向广告等严重隐私问题。为应对这一挑战,研究人员提出不可学习样本(UEs),即通过添加难以察觉的噪声来修改图像,阻止AI提取有用信息。然而,现有方法主要依赖像素空间噪声,易被对抗训练、图像变换和压缩等重学策略绕过。尽管部分技术提升了鲁棒性,但通常会大幅降低图像质量和可用性。本文提出DiffUE,通过在图像的语义空间而非像素空间注入噪声,克服上述局限。DiffUE利用基于扩散的自编码器框架,修改图像的高层语义特征,实现自然且有针对性的视觉修改,有效抵御先进重学策略。在CIFAR-10、CIFAR-100、CelebA-HQ和ImageNet四个数据集上的大量实验,以及主观用户研究均表明,DiffUE显著优化了图像质量与不可学习性之间的权衡,在日益被滥用的AI环境中提供了更稳健有效的个人数据保护方案。

原文摘要 · Abstract (English)

AI models are increasingly trained on personal images scraped from social media and public platforms, often without consent, leading to serious privacy violations, such as unauthorized facial recognition and targeted advertising. To counter this, researchers have developed unlearnable examples (UEs), images modified with imperceptible noise to prevent AI models from extracting meaningful information. However, existing UE methods primarily rely on pixel-space noise, which can be bypassed by relearning strategies such as adversarial training, image transformation, and compression. While some techniques improve robustness, they often come at the expense of significant degradation in image utility and perceptual quality. In this paper, we introduce DiffUE to overcome these limitations by injecting noise into the semantic space of images instead of the pixel space. Instead of corrupting pixel values, DiffUE modifies high-level semantic features of images, ensuring robust unlearnability while preserving visual quality and utility. By leveraging a diffusion-based autoencoder framework to manipulate semantic features, DiffUE generates purposeful, natural-looking modifications that effectively resist advanced relearning strategies. Extensive experiments on four datasets, CIFAR-10, CIFAR-100, CelebA-HQ, and ImageNet, as well as a subjective user study, demonstrate that DiffUE significantly enhances the trade-off between image quality and unlearnability, offering a more robust and effective solution for safeguarding personal data in an increasingly exploitative AI landscape.

隐私保护扩散模型不可学习样本

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。