Pith. sign in

REVIEW 3 cited by

Memorized Images in Diffusion Models share a Subspace that can be Located and Deleted

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2406.18566 v1 pith:AHRCLHQP submitted 2024-06-01 cs.CV cs.AIcs.LG

classification cs.CVcs.AIcs.LG
keywords modelsmemorizationdiffusiontrainingdatamemorizedsubspaceimages
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Large-scale text-to-image diffusion models excel in generating high-quality images from textual inputs, yet concerns arise as research indicates their tendency to memorize and replicate training data, raising We also addressed the issue of memorization in diffusion models, where models tend to replicate exact training samples raising copyright infringement and privacy issues. Efforts within the text-to-image community to address memorization explore causes such as data duplication, replicated captions, or trigger tokens, proposing per-prompt inference-time or training-time mitigation strategies. In this paper, we focus on the feed-forward layers and begin by contrasting neuron activations of a set of memorized and non-memorized prompts. Experiments reveal a surprising finding: many different sets of memorized prompts significantly activate a common subspace in the model, demonstrating, for the first time, that memorization in the diffusion models lies in a special subspace. Subsequently, we introduce a novel post-hoc method for editing pre-trained models, whereby memorization is mitigated through the straightforward pruning of weights in specialized subspaces, avoiding the need to disrupt the training or inference process as seen in prior research. Finally, we demonstrate the robustness of the pruned model against training data extraction attacks, thereby unveiling new avenues for a practical and one-for-all solution to memorization.

Discussion (0). Sign in to comment.

Forward citations

Cited by 3 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Filtering Memorization from Parameter-Space in Diffusion Models

    cs.CV 2026-05 unverdicted novelty 7.0 of 10

    Base-Anchored Filtering suppresses weakly backbone-aligned LoRA spectral channels to cut memorization while preserving or improving generation quality, without data or re-training.

  2. SPQR: A Multi-Dimensional Benchmark for Safety Alignment under Benign Model Adaptation

    cs.CR 2025-11 conditional novelty 6.0 of 10

    SPQR is a benchmark that scores safety, prompt adherence, quality, and post-fine-tuning robustness of text-to-image safety methods, and it shows benign fine-tuning often collapses safety alignment.

  3. Localizing and Mitigating Memorization in Image Autoregressive Models

    cs.LG 2025-08 conditional novelty 6.0 of 10

    Memorization in image autoregressive models sits in early blocks at coarse scales for VAR models and in middle/late blocks for RAR models; halving the flagged neurons' weights cuts extractable images by 65 to 84 percent.

Pith tools