Pith. sign in

REVIEW 4 major objections 4 minor 59 references

Personalized diffusion models can be trained so public avatar images stay useful yet resist face-recognition linking, with a tunable privacy dial.

Reviewed by Pith at T0; open to challenge. T0 means a machine referee read the full paper against a public rubric. the ladder, T0–T4 →

T0 review · grok-4.5

2026-07-13 14:45 UTC pith:UFRU2GZ4

load-bearing objection Useful threat-model shift to authorized, immunized personalization, but the supplied text cuts off before method and numbers so the central claim is still uncheckable. the 4 major comments →

arxiv 2604.00903 v2 pith:UFRU2GZ4 submitted 2026-04-01 cs.CV

IDDM: Identity-Decoupled Personalized Diffusion Models with a Tunable Privacy-Utility Trade-off

classification cs.CV
keywords personalized diffusion modelsidentity decouplingprivacy-utility trade-offface recognitionmodel-side output immunizationDreamBoothtext-to-imageLoRA
verification ladder T0 review T1 audit T2 compute T3 formal T4 reserved

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

When people authorize a text-to-image model to learn their face from private photos and then share the generated portraits, face recognition systems can still match those portraits back to the real person. Prior defenses mostly poison public reference photos so unauthorized training fails; they leave open the common case in which personalization is allowed but the outputs still leak biometric identity. This paper defines model-side output immunization: produce a personalized model whose public generations remain high-quality and subject-driven while becoming harder to link to the user, with an adjustable privacy-utility trade-off. The proposed method, IDDM, interleaves short personalization updates with identity-decoupled optimization of the private reference set under a two-stage schedule controlled by a parameter ρ. Across datasets, prompts, and modern face recognizers, the resulting models lower identity similarity while keeping generation quality comparable to ordinary DreamBooth-style personalization, without any per-image post-processing at inference.

Core claim

Under authorized personalization, integrating identity decoupling into the training pipeline—by alternating brief personalization updates with identity-decoupled data optimization on the private reference set and using a two-stage schedule—yields a model whose public outputs retain high visual utility for creative use while consistently lowering linkability to the true identity under state-of-the-art face recognition systems, with the parameter ρ controlling the privacy–utility balance.

What carries the argument

Identity-Decoupled personalized Diffusion Models (IDDM): an alternating procedure that interleaves short personalization updates with identity-decoupled data optimization on the user's private references, using a two-stage schedule whose parameter ρ tunes how strongly identity cues are suppressed versus how much generation utility is preserved.

Load-bearing premise

The method assumes that alternating ordinary personalization with identity-decoupling steps on the same private photos can strip the cues face recognizers use without destroying the visual traits that make the personalized subject look like the intended person.

What would settle it

On held-out subjects and diverse prompts, if IDDM generations do not show meaningfully lower cosine similarity to the true identity than undefended DreamBooth under the same face recognizers, or if raters judge the defended images unusable as portraits of that subject at privacy settings that claim protection, the central claim fails.

Watch this falsifier — get emailed when new claim-graph text bears on it.

If this is right

  • Avatar and AI-headshot services can authorize personalization yet publish outputs that are harder for face recognition systems to link to the real user.
  • Privacy preference becomes a training control (ρ) rather than a per-image post-processing filter at inference.
  • Standard DreamBooth/LoRA pipelines can be replaced by an immunized training procedure without changing how users generate images.
  • Users who need strong character consistency can favor utility; users who post broadly or pseudonymously can favor privacy, using the same method.
  • Anti-personalization of public references and model-side output immunization become complementary layers for different threat models.

Where Pith is reading between the lines

These are editorial extensions of the paper, not claims the author makes directly.

  • If future face recognizers rely on features that survive the current decoupling objective, protection may erode unless the identity-decoupled stage is retargeted to those features.
  • The same alternating schedule could be tried for non-face subjects that personalization overfits, such as distinctive brands or other biometrics.
  • Hosting platforms could expose ρ as a user-facing privacy slider at training time rather than a research hyperparameter.
  • Consistent gains against multiple black-box recognizers suggest the removed signal is partly shared across embedding models, not only one detector’s quirk.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, simulated authors' rebuttal, and a circularity audit.

Referee Report

4 major / 4 minor

Summary. The paper identifies a gap between anti-personalization defenses (which protect released reference photos against unauthorized fine-tuning) and a practical authorized-personalization setting in which users keep references private but still leak biometric identity through public generations. It formalizes model-side output immunization and proposes IDDM: an alternating personalization / identity-decoupled data-optimization procedure with a two-stage schedule controlled by a trade-off parameter ρ, intended to produce a personalized diffusion model whose outputs remain creatively useful while being less linkable under state-of-the-art face recognition. The abstract and introduction assert multi-dataset, multi-prompt, multi-FR evaluations and qualitative cosine-similarity reductions (Figure 2), without requiring inference-time per-image post-processing.

Significance. If the method and results hold as claimed, the contribution is practically meaningful: it cleanly separates a new threat model from anti-DreamBooth-style data poisoning, targets a real avatar/AI-headshot workflow, and offers tunable privacy–utility control rather than a binary block. The framing (Scenario A vs B in Figure 1) and the goal of immunized outputs under authorized training are useful additions to the privacy literature on personalized diffusion. Strengths visible in the available text include a clear threat-model contrast, an explicit tunable parameter, and evaluation intent against external FR systems (ArcFace-family, VGGFace2, CelebA-HQ). The incomplete technical body, however, prevents confirming that these strengths are realized.

major comments (4)
  1. The supplied manuscript is truncated after early Related Work (and a late Figure 5 caption). The load-bearing alternating procedure, identity-decoupling objective, two-stage schedule, and the precise role of ρ are described only at a high level in the Introduction and Abstract. Without equations, algorithm box, or training pseudocode, the central claim that interleaving short personalization updates with identity-decoupled data optimization suppresses FR-usable biometric cues (rather than merely shifting them) cannot be verified.
  2. Quantitative support for “consistently reduces identity linkability while preserving high-quality personalized generation” is not present beyond qualitative cosine similarities in Figure 2 and a caption for Figure 5. Tables against SOTA FR systems, prompt diversity, FID/IQA/utility metrics, and ρ ablations are required for the privacy–utility trade-off claim; their absence leaves the strongest claim uncheckable on the record.
  3. The weakest modeling assumption—that subject-specific visual attributes needed for creative personalization can be retained while FR linkability is suppressed—is asserted but not stress-tested in the available text. A major revision should include (i) an explicit identity-decoupling loss or data-optimization objective, (ii) transfer evaluation to held-out FR models not used in training, and (iii) failure cases where identity signal reappears under prompt or style shift.
  4. Baselines for the new setting are unclear. Anti-personalization methods (Anti-DreamBooth, SimAC, etc.) address a different threat model; the paper needs fair model-side or output-side comparators (e.g., post-hoc adversarial faces, concept unlearning, or privacy-preserving personalization variants) so that gains are attributable to IDDM rather than to weaker personalization alone.
minor comments (4)
  1. Figure 2 caption uses garbled encoding for “with/without defense” labels; fix for camera-ready.
  2. Related Work 2.1 cuts off mid-discussion of lightweight personalization; complete the section and ensure anti-personalization and privacy-preserving generation lines are fully covered before the method.
  3. Notation for ρ and stage boundaries should be introduced formally once the method section is restored; currently only prose mentions exist.
  4. Figure 5 is referenced without surrounding experimental narrative in the provided text; ensure figure order and cross-references are consistent after the full body is restored.

Circularity Check

0 steps flagged

No significant circularity: empirical systems method evaluated against external FR systems and datasets, not a self-referential derivation.

full rationale

IDDM is an empirical model-side defense for authorized personalization, not a closed-form first-principles derivation. The load-bearing claim is that an alternating personalization / identity-decoupled data-optimization procedure with a two-stage schedule (parameter ρ) reduces identity linkability of generated portraits while preserving subject utility. That claim is grounded by evaluation against external face recognition systems (ArcFace-family and related SOTA recognizers) and external datasets (VGGFace2, CelebA-HQ), with qualitative and quantitative comparison to undefended DreamBooth/LoRA personalization. There is no self-definitional step in which the privacy metric is defined as the quantity being optimized and then reported as an independent prediction; no uniqueness theorem imported from the same authors; and no renaming of a known empirical pattern as a derived law. Any risk that the decoupling objective is trained against embeddings related to the evaluation FR stack is ordinary adversarial-training alignment, not definitional circularity under the stated criteria. The supplied manuscript is truncated after early related work, so method equations cannot be inspected for hidden tautologies, but nothing in the available abstract, introduction, or framing reduces the central claim to its inputs by construction. Score 0 is therefore appropriate.

Axiom & Free-Parameter Ledger

3 free parameters · 4 axioms · 2 invented entities

The central claim rests on standard diffusion personalization machinery, the assumption that face-recognition embeddings are a meaningful proxy for real-world identity linkability of generated portraits, and a paper-specific training procedure (alternating personalization and identity-decoupled optimization with a free trade-off parameter ρ). No new physical entity is postulated; the invented constructs are a threat-model label and a training algorithm. Because method equations and full experimental protocols are missing from the supplied text, several operational assumptions remain implicit.

free parameters (3)
  • ρ (privacy-utility trade-off in two-stage identity-decoupled schedule)
    Introduced as the user-facing knob: smaller ρ emphasizes privacy, larger ρ preserves utility. Its numerical operating points are not fixed by theory and must be chosen or swept.
  • Alternating schedule lengths / stage boundaries
    The method interleaves short personalization updates with identity-decoupled data optimization under a two-stage schedule; those step counts and stage transitions are design choices that control the reported trade-off.
  • Personalization hyperparameters (DreamBooth/LoRA training setup)
    Standard fine-tuning knobs (learning rates, ranks, steps, prior-preservation weight, etc.) affect both utility and residual identity leakage; they are not derived from first principles.
axioms (4)
  • domain assumption Face recognition cosine similarity / matching on generated portraits is a valid operational measure of identity linkability risk for social-media sharing.
    The entire evaluation framing in the abstract and introduction treats FR systems as the adversary that links public generations to the real user.
  • domain assumption Authorized personalization on clean private references is allowed and desirable; the defender controls the personalization pipeline (trusted platform/service).
    Scenario B and the model-side design explicitly assume training is authorized and the immunization is integrated into that pipeline.
  • domain assumption Subject-driven personalization (DreamBooth/LoRA-style binding of an identifier token to a few-shot subject) is a valid base procedure into which identity decoupling can be inserted.
    IDDM is defined as a modification of the personalization pipeline rather than a from-scratch generator.
  • ad hoc to paper Identity cues can be suppressed in training data/model updates sufficiently to reduce FR linkability while retaining enough subject appearance for creative utility.
    This is the core methodological bet of the alternating identity-decoupled optimization; it is not a standard theorem, but the paper’s proposed mechanism.
invented entities (2)
  • Model-side output immunization (defense setting) no independent evidence
    purpose: Names the goal of producing an authorized personalized model whose public outputs are less identity-linkable, distinct from anti-personalization of released references.
    This is a conceptual framing introduced by the paper to reorganize the threat model; independent evidence would be adoption or formalization beyond this work.
  • IDDM alternating personalization / identity-decoupled data optimization procedure no independent evidence
    purpose: Operational mechanism claimed to achieve immunized personalized generation with tunable ρ trade-off without inference-time per-image post-processing.
    A paper-specific training algorithm; its validity is empirical and not independently established outside the paper’s experiments.

pith-pipeline@v1.1.0-grok45 · 12752 in / 3506 out tokens · 33411 ms · 2026-07-13T14:45:25.699368+00:00 · methodology

0 comments
read the original abstract

Personalized text-to-image diffusion models (e.g., DreamBooth, LoRA) enable users to synthesize high-fidelity avatars from a few reference photos for social expression. However, once these generations are shared on social media platforms (e.g., Instagram, Facebook), they can be linked to the real user via face recognition systems, enabling identity tracking and profiling. Existing defenses mainly follow an anti-personalization strategy that protects publicly released reference photos by disrupting model fine-tuning. While effective against unauthorized personalization, they do not address another practical setting in which personalization is authorized, but the resulting public outputs still leak identity information. To address this problem, we introduce a new defense setting, termed model-side output immunization, whose goal is to produce a personalized model that supports authorized personalization while reducing the identity linkability of public generations, with tunable control over the privacy-utility trade-off to accommodate diverse privacy needs. To this end, we propose Identity-Decoupled personalized Diffusion Models (IDDM), a model-side defense that integrates identity decoupling into the personalization pipeline. Concretely, IDDM follows an alternating procedure that interleaves short personalization updates with identity-decoupled data optimization, using a two-stage schedule to balance identity linkability suppression and generation utility. Extensive experiments across multiple datasets, diverse prompts, and state-of-the-art face recognition systems show that IDDM consistently reduces identity linkability while preserving high-quality personalized generation.

discussion (0)

Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.

Reference graph

Works this paper leans on

59 extracted references · 8 linked inside Pith

  1. [1]

    [n. d.]. InsightFace model zoo. https://github.com/deepinsight/insightface/tree/ master/modelzoo

  2. [2]

    Fadi Boutros, Naser Damer, Florian Kirchbuchner, and Arjan Kuijper. 2022. Elas- ticFace: Elastic Margin Loss for Deep Face Recognition. InProceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR). 1578– 1587

  3. [3]

    Yufei Cai, Yuxiang Wei, Zhilong Ji, Jinfeng Bai, Hu Han, and Wangmeng Zuo

  4. [4]

    In Proceedings of the AAAI Conference on Artificial Intelligence

    Decoupled Textual Embeddings for Customized Image Generation. In Proceedings of the AAAI Conference on Artificial Intelligence. 909–917

  5. [5]

    Parkhi, and Andrew Zisserman

    Qiong Cao, Li Shen, Weidi Xie, Omkar M. Parkhi, and Andrew Zisserman. 2018. VGGFace2: A dataset for recognising faces across pose and age. In2018 13th IEEE International Conference on Automatic Face & Gesture Recognition (FG 2018). 67–74. doi:10.1109/FG.2018.00020

  6. [6]

    Nicholas Carlini, Jamie Hayes, Milad Nasr, Matthew Jagielski, Vikash Sehwag, Florian Tramèr, Borja Balle, Daphne Ippolito, and Eric Wallace. 2023. Extract- ing Training Data from Diffusion Models. In32nd USENIX Security Symposium (USENIX Security 23). 5253–5270

  7. [7]

    Sheng Chen, Yang Liu, Xiang Gao, and Zhen Han. 2018. MobileFaceNets: Efficient CNNs for Accurate Real-Time Face Verification on Mobile Devices. InChinese Conference on Biometric Recognition (CCBR). 428–438

  8. [8]

    Valeriia Cherepanova, Micah Goldblum, Harrison Foley, Shiyuan Duan, John Dickerson, Gavin Taylor, and Tom Goldstein. 2021. LowKey: Leveraging Ad- versarial Attacks to Protect Social Media Users from Facial Recognition. In International Conference on Learning Representations (ICLR)

  9. [9]

    CompVis. [n. d.]. CompVis/stable-diffusion: A latent text-to-image diffusion model. https://github.com/CompVis/stable-diffusion

  10. [10]

    Jiankang Deng, Jia Guo, Niannan Xue, and Stefanos Zafeiriou. 2019. ArcFace: Additive Angular Margin Loss for Deep Face Recognition. InProceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR). 4690–4699

  11. [11]

    Tim Dockhorn, Tianshi Cao, Arash Vahdat, and Karsten Kreis. 2022. Differentially Private Diffusion Models.arXiv preprint arXiv:2210.09929(2022)

  12. [12]

    Bermano, Gal Chechik, and Daniel Cohen-Or

    Rinon Gal, Yuval Alaluf, Yuval Atzmon, Or Patashnik, Amit H. Bermano, Gal Chechik, and Daniel Cohen-Or. 2023. An image is worth one word: Personalizing text-to-image generation using textual inversion. InInternational Conference on Learning Representations (ICLR)

  13. [13]

    Rohit Gandikota, Joanna Materzynska, Jaden Fiotto-Kaufman, and David Bau

  14. [14]

    InProceedings of the IEEE/CVF International Conference on Computer Vision (ICCV)

    Erasing Concepts from Diffusion Models. InProceedings of the IEEE/CVF International Conference on Computer Vision (ICCV). 2426–2436

  15. [15]

    Google. [n. d.]. Nano Banana image generation | Gemini API. https://ai.google. dev/gemini-api/docs/image-generation

  16. [16]

    Jia Guo, Jiankang Deng, Alexandros Lattas, and Stefanos Zafeiriou. 2021. Sample and Computation Redistribution for Efficient Face Detection.arXiv preprint arXiv:2105.04714(2021)

  17. [17]

    Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun. 2016. Deep Resid- ual Learning for Image Recognition. InProceedings of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR). 770–778

  18. [18]

    Martin Heusel, Hubert Ramsauer, Thomas Unterthiner, Bernhard Nessler, and Sepp Hochreiter. 2017. GANs Trained by a Two Time-Scale Update Rule Converge to a Local Nash Equilibrium. InAdvances in Neural Information Processing Systems (NeurIPS)

  19. [19]

    Jain, and Pieter Abbeel

    Jonathan Ho, Ajay N. Jain, and Pieter Abbeel. 2020. Denoising diffusion proba- bilistic models. InNeural Information Processing Systems (NeurIPS). 6840–6851

  20. [20]

    Hu, Yelong Shen, Phillip Wallis, Zeyuan Allen-Zhu, Yuanzhi Li, Shean Wang, Lu Wang, and Weizhu Chen

    Edward J. Hu, Yelong Shen, Phillip Wallis, Zeyuan Allen-Zhu, Yuanzhi Li, Shean Wang, Lu Wang, and Weizhu Chen. 2022. LoRA: Low-Rank Adaptation of Large Language Models. InInternational Conference on Learning Representations (ICLR)

  21. [21]

    Hailong Hu and Jun Pang. 2023. Membership Inference of Diffusion Models. arXiv preprint arXiv:2301.09956(2023)

  22. [22]

    Jie Hu, Li Shen, and Gang Sun. 2018. Squeeze-and-Excitation Networks. In Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR). 7132–7141

  23. [23]

    Tero Karras, Timo Aila, Samuli Laine, and Jaakko Lehtinen. 2018. Progressive Growing of GANs for Improved Quality, Stability, and Variation. InInternational Conference on Learning Representations (ICLR)

  24. [24]

    Jain, and Xiaoming Liu

    Minchul Kim, Anil K. Jain, and Xiaoming Liu. 2022. AdaFace: Quality Adap- tive Margin for Face Recognition. InProceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR)

  25. [25]

    Nupur Kumari, Bingliang Zhang, Richard Zhang, Eli Shechtman, and Jun-Yan Zhu. 2023. Multi-concept customization of text-to-image diffusion. InIEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR). 1931–1941

  26. [26]

    Minghui Li, Jiangxiong Wang, Hao Zhang, Ziqi Zhou, Shengshan Hu, and Xiaob- ing Pei. 2024. Transferable Adversarial Facial Images for Privacy Protection. In Proceedings of the 32nd ACM International Conference on Multimedia (ACMMM)

  27. [27]

    Zhen Li, Mingdeng Cao, Xintao Wang, Zhongang Qi, Ming-Ming Cheng, and Ying Shan. 2024. PhotoMaker: Customizing Realistic Human Photos via Stacked ID Embedding. InProceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR). 8640–8650

  28. [28]

    Zheng Li, Liangbin Xie, Jiantao Zhou, Xintao Wang, Haiwei Wu, and Jinyu Tian

  29. [29]

    InProceedings of the AAAI Conference on Artificial Intelligence (AAAI), Vol

    Anti-Diffusion: Preventing Abuse of Modifications of Diffusion-Based Models. InProceedings of the AAAI Conference on Artificial Intelligence (AAAI), Vol. 39. 10582–10590

  30. [30]

    Chumeng Liang, Xiaoyu Wu, Yang Hua, Jiaru Zhang, Yiming Xue, Tao Song, Zhengui Xue, Ruhui Ma, and Haibing Guan. 2023. Adversarial Example Does Good: Preventing Painting Imitation from Diffusion Models via Adversarial Examples. InInternational Conference on Machine Learning (ICML)

  31. [31]

    Decheng Liu, Xijun Wang, Chunlei Peng, Nannan Wang, Ruimin Hu, and Xinbo Gao. 2024. Adv-diffusion: imperceptible adversarial face identity attack via latent diffusion model. InProceedings of the AAAI conference on artificial intelligence (AAAI)

  32. [32]

    Jiaheng Liu, Haoyu Qin, Yichao Wu, and Ding Liang. 2022. Anchorface: Boosting tar@ far for practical face recognition. InProceedings of the AAAI Conference on Artificial Intelligence (AAAI)

  33. [33]

    Yixin Liu, Chenrui Fan, Yutong Dai, Xun Chen, Pan Zhou, and Lichao Sun. 2024. MetaCloak: Preventing Unauthorized Subject-driven Text-to-image Diffusion- based Synthesis via Meta-learning. InProceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR). 24219–24228

  34. [34]

    Duncan, Nathan Kalka, Tim Miller, Charles Otto, Anil K

    Brianna Maze, Jocelyn Adams, James A. Duncan, Nathan Kalka, Tim Miller, Charles Otto, Anil K. Jain, W. Tyler Niggel, Janet Anderson, Jordan Cheney, and Patrick Grother. 2018. Iarpa janus benchmark-c: Face dataset and protocol. In2018 international conference on biome. In2018 International Conference on Biometrics (ICB)

  35. [35]

    Kate Miltner. 2024. A.I. is holding a mirror to our society: Lensa and the discourse of visual generative AI.Journal of Digital Social Research6, 4 (2024). https: //publicera.kb.se/jdsr/article/view/40456

  36. [36]

    Anish Mittal, Anush Krishna Moorthy, and Alan Conrad Bovik. 2012. No- Reference Image Quality Assessment in the Spatial Domain.IEEE Transactions on Image Processing21, 12 (2012), 4695–4708

  37. [37]

    Thanh Thi Nguyen, Quoc Viet Hung Nguyen, Dung Tien Nguyen, Duc Thanh Nguyen, Thien Huynh-The, Saeid Nahavandi, Thanh Tam Nguyen, Quoc-Viet Pham, and Cuong M. Nguyen. 2022. Deep learning for deepfakes creation and detection: A survey.. InComputer Vision and Image Understanding

  38. [38]

    Yan Pang, Tianhao Wang, Xuhui Kang, Mengdi Huai, and Yang Zhang. 2023. White-box Membership Inference Attacks against Diffusion Models.arXiv preprint arXiv:2308.06405(2023)

  39. [39]

    Sarah Perez. 2023. Andreessen Horowitz backs Civitai, a generative AI content marketplace with millions of users. https://techcrunch.com/2023/11/14/andr eessen-horowitz-backs-civitai-a-generative-ai-content-marketplace-with- millions-of-users/. TechCrunch

  40. [40]

    Robin Rombach, Andreas Blattmann, Dominik Lorenz, Patrick Esser, and Björn Ommer. 2022. High-resolution image synthesis with latent diffusion models. InIEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR). 10684–10695

  41. [41]

    Nataniel Ruiz, Yuanzhen Li, Varun Jampani, Yael Pritch, Michael Rubinstein, and Kfir Aberman. 2023. DreamBooth: Fine-tuning text-to-image diffusion models for subject-driven generation. InIEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR). 22500–22510

  42. [42]

    Chitwan Saharia, William Chan, Saurabh Saxena, Lala Li, Jay Whang, Emily L Denton, Kamyar Ghasemipour, Raphael Gontijo Lopes, Burcu Karagol Ayan, Tim Salimans, Jonathan Ho, David J Fleet, and Mohammad Norouzid. 2022. Photorealistic text-to-image diffusion models with deep language understanding. InNeural Information Processing Systems (NeurIPS)

  43. [43]

    Hadi Salman, Alaa Khaddaj, Guillaume Leclerc, Andrew Ilyas, and Aleksander Madry. 2023. Raising the Cost of Malicious AI-Powered Image Editing.arXiv preprint arXiv:2302.06588(2023)

  44. [44]

    Florian Schroff, Dmitry Kalenichenko, and James Philbin. 2015. FaceNet: A Unified Embedding for Face Recognition and Clustering. InProceedings of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR). 815–823

  45. [45]

    Pardeep Singh. 2025. How Civitai Scaled to 800K Monthly LoRAs on RunPod. https://runpod.ghost.io/how-civitai-trained-868k-loras-on-runpod-and- scaled-user-creativity-in-the-process/. RunPod Blog

  46. [46]

    Adam Smith. 2022. AI image app Lensa helps some trans people to embrace themselves. https://www.reuters.com/world/ai-image-app-lensa-helps-some- trans-people-embrace-themselves--trfn-2022-12-21/ Reuters

  47. [47]

    Philipp Terhörst, Malte Ihlefeld, Marco Huber, Naser Damer, Florian Kirchbuch- ner, Kiran Raja, and Arjan Kuijper. 2023. QMagFace: Simple and Accurate Quality- Aware Face Recognition. InProceedings of the IEEE/CVF Winter Conference on Applications of Computer Vision (W ACV). 3484–3494

  48. [48]

    Philipp Terhorst, Jan Niklas Kolf, Naser Damer, Florian Kirchbuchner, and Arjan Kuijper. 2020. SER-FIQ: Unsupervised Estimation of Face Image Quality Based on Stochastic Embedding Robustness. InProceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR). 5651–5660

  49. [49]

    Yoad Tewel, Rinon Gal, Gal Chechik, and Yuval Atzmon. 2023. Key-locked rank- one editing for text-to-image personalization. InACM SIGGRAPH 2023 conference proceedings. 1–11. Linyan Dai, Xinwei Zhang, Haoyang Li, Qingqing Ye, and Haibo Hu

  50. [50]

    Tran, and Anh Tran

    Thanh Van Le, Hao Phung, Thuan Hoang Nguyen, Quan Dao, Ngoc N. Tran, and Anh Tran. 2023. Anti-DreamBooth: Protecting users from personalized text- to-image synthesis. InIEEE/CVF International Conference on Computer Vision (ICCV). 2116–2127

  51. [51]

    Feifei Wang, Zhentao Tan, Tianyi Wei, Yue Wu, and Qidong Huang. 2024. SimAC: A Simple Anti-Customization Method for Protecting Face Privacy against Text-to- Image Synthesis of Diffusion Models. InProceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR). 12047–12056

  52. [52]

    Guanyu Wang, Kailong Wang, Yihao Huang, Mingyi Zhou, Zhang Qing cn- watcher, Geguang Pu, and Li Li. 2025. Privacy Protection Against Personalized Text-to-Image Synthesis via Cross-image Consistency Constraints.arXiv preprint arXiv:2504.12747(2025)

  53. [53]

    Qixun Wang, Xu Bai, Haofan Wang, Zekui Qin, Anthony Chen, Huaxia Li, Xu Tang, and Yao Hu. 2024. InstantID: Zero-shot Identity-Preserving Generation in Seconds.arXiv preprint arXiv:2401.07519(2024)

  54. [54]

    Yongliang Wu, Shiji Zhou, Mingzhuo Yang, Lianzhe Wang, Heng Chang, Wenbo Zhu, Xinting Hu, Xiao Zhou, and Xu Yang. 2025. Unlearning Concepts in Diffu- sion Model via Concept Domain Correction and Concept Preserving Gradient. InProceedings of the AAAI Conference on Artificial Intelligence (AAAI), Vol. 39. 8496–8504

  55. [55]

    Zhihao Wu, Yushi Cheng, Tianyang Sun, Xiaoyu Ji, and Wenyuan Xu. 2025. MYOPIA: Protecting Face Privacy from Malicious Personalized Text-to-Image Synthesis via Unlearnable Examples. InAAAI Conference on Artificial Intelligence (AAAI), Vol. 39. 905–913

  56. [56]

    Jingyao Xu, Yuetong Lu, Yandong Li, Siyang Lu, Dongdong Wang, and Xiang Wei

  57. [57]

    InProceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR)

    Perturbing Attention Gives You More Bang for the Buck: Subtle Imaging Perturbations That Efficiently Fool Customized Diffusion Models. InProceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR). 24534–24543

  58. [58]

    Hu Ye, Jun Zhang, Sibo Liu, Xiao Han, and Wei Yang. 2023. IP-Adapter: Text Compatible Image Prompt Adapter for Text-to-Image Diffusion Models.arXiv preprint arXiv:2308.06721(2023)

  59. [59]

    Patel, Haochen Wang, Xun Huang, Ting-Chun Wang, Ming-Yu Liu, and Yogesh Balaji

    Yu Zeng, Vishal M. Patel, Haochen Wang, Xun Huang, Ting-Chun Wang, Ming-Yu Liu, and Yogesh Balaji. 2024. JeDi: Joint-Image Diffusion Models for Finetuning- Free Personalized Text-to-Image Generation. InProceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR). 6786–6795. Linyan Dai, Xinwei Zhang, Haoyang Li, Qingqing Ye, and...