为抵御前沿图像编辑模型的滥用,提出新型隐蔽防护机制。
VETO: Towards Protecting Images From Frontier AI Editing

- 通过干扰模型对参考图的联合注意力机制实现防护
- 在多个主流编辑模型上均显著优于现有防御方法
- 适合关注图像安全与隐私保护的研究者使用
FLUX.2等强大且易用的图像编辑模型已能实现高保真编辑,其能力不仅限于局部修改,还可提取并重新语境化对象与身份至全新场景。现代模型通过让提示词与生成标记直接关注参考图像标记,模糊了传统编辑与文生图之间的界限。这种扩展的生成自由也扩大了潜在滥用空间,有害变换不再局限于可预测的局部编辑。现有反编辑防御针对旧版扩散模型中的参考图像编码语义瓶颈设计,但新编辑模型通过联合注意力块提炼参考信息,常可绕过这些保护。因此我们提出VETO,一种通过干扰现代模型读取源图像的内部机制实现隐蔽防护的新方法。此外,由于现有编辑评测基准未充分测试全面重语境化,我们引入VetoBench,评估防御不仅在常规局部编辑上,也在更广泛的上下文转变中表现。在两个当代编辑模型和三个基准上,VETO持续优于现有防御,并提供更强的保护-保真度权衡。
原文摘要 · Abstract (English)
The rise of powerful, accessible image-editing models such as FLUX.2 has brought high-fidelity editing within broad reach. Their capabilities now extend beyond localized modifications to extracting and recontextualizing objects and identities in entirely new scenes. By allowing prompt and generation tokens to attend directly to reference-image tokens, modern models blur the boundary between conventional editing and text-to-image synthesis. This expanded generative freedom also broadens the space of potential misuse, as harmful transformations are no longer confined to a predictable set of localized edits. Existing anti-edit defenses are designed to disrupt the semantic bottleneck of the reference-image encoding in legacy diffusion pipelines. However, newer editors distill reference information through joint-attention blocks, thereby often circumventing these protections. We therefore introduce VETO, a subtle anti-edit cloak that disrupts this inner mechanism through which modern models read the source image. Additionally, as existing editing benchmarks leave comprehensive recontextualizations largely untested, we introduce VetoBench, which evaluates defenses not only on conventional localized edits but also on broader contextual shifts. Across two contemporary editing models and three benchmarks, VETO consistently outperforms existing defenses while providing a stronger protection-fidelity trade-off.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。