Pith. sign in

REVIEW 11 cited by

Raising the Cost of Malicious AI-Powered Image Editing

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2302.06588 v1 pith:B4STH6QH submitted 2023-02-13 cs.LG

Raising the Cost of Malicious AI-Powered Image Editing

classification cs.LG
keywords modelsdiffusionapproacheditingimageimagesimmunizationmake
verification ladder T0 review T1 audit T2 compute T3 formal T4 reserved
0 comments
read the original abstract

We present an approach to mitigating the risks of malicious image editing posed by large diffusion models. The key idea is to immunize images so as to make them resistant to manipulation by these models. This immunization relies on injection of imperceptible adversarial perturbations designed to disrupt the operation of the targeted diffusion models, forcing them to generate unrealistic images. We provide two methods for crafting such perturbations, and then demonstrate their efficacy. Finally, we discuss a policy component necessary to make our approach fully effective and practical -- one that involves the organizations developing diffusion models, rather than individual users, to implement (and support) the immunization process.

discussion (0)

Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.

Forward citations

Cited by 11 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score.

  1. I2VShield: An Efficient Proactive Defense Framework against DiT-based Image-to-Video Models

    cs.CV 2026-07 conditional novelty 7.0

    A text-adaptive generator trained to disrupt diffusion-transformer cross-attention shields reference images from video-generation misuse at low online cost.

  2. Cross-Branch Conflict as a Shield: Safeguarding Facial Identities in Unified Multimodal Image Editing

    cs.CV 2026-07 conditional novelty 7.0

    CCS jointly perturbs the ViT and VAE pathways and reduces their CKA agreement, causing unified multimodal image editors to lose facial identity.

  3. IDDM: Identity-Decoupled Personalized Diffusion Models with a Tunable Privacy-Utility Trade-off

    cs.CV 2026-04 conditional novelty 6.5

    IDDM immunizes authorized personalized diffusion models so public generations remain high-quality while identity linkability to face recognizers is reduced with a tunable privacy-utility knob.

  4. Cross-Branch Conflict as a Shield: Safeguarding Facial Identities in Unified Multimodal Image Editing

    cs.CV 2026-07 conditional novelty 6.0

    CCS is an adversarial image protection method that disturbs both the ViT and VAE branches of unified multimodal editing models and disrupts their cross-branch agreement, suppressing identity-preserving edits.

  5. Defending from GeoLocalization through Adversarial Road Trips

    cs.CV 2026-07 conditional novelty 6.0

    RoadTrip Attack uses beam search over adaptive geographic intermediate targets to produce stronger, more transferable, lower-visibility adversarial examples against retrieval-based image geolocalizers than PGD, FGSM, ...

  6. Closed-Form Concept Erasure via Double Projections

    cs.LG 2026-04 unverdicted novelty 6.0

    A training-free double-projection linear transformation erases target concepts from generative models by computing a proxy projection then applying a constrained update in the left null space of known directions.

  7. SyncBreaker:Stage-Aware Multimodal Adversarial Attacks on Audio-Driven Talking Head Generation

    cs.CV 2026-04 unverdicted novelty 6.0

    SyncBreaker jointly attacks image and audio streams with Multi-Interval Sampling and Cross-Attention Fooling to degrade speech-driven talking head generation more than single-modality baselines.

  8. SyncBreaker:Stage-Aware Multimodal Adversarial Attacks on Audio-Driven Talking Head Generation

    cs.CV 2026-04 conditional novelty 6.0

    A multimodal adversarial attack using stage-sampled image nullification and cross-attention flattening degrades lip-sync and facial dynamics in Hallo-based talking-head generation.

  9. DECAF: De-Clustering for Adaptive Representational Unlearning

    cs.LG 2026-07 conditional novelty 5.0

    DECAF is a forget-only unlearning method that adds input noise, suppresses the forget-class probability, and diversifies outputs, achieving 0.10% forget accuracy and 79.4% retain accuracy on CIFAR-10/ResNet-18 while d...

  10. VOID: Defeating Unauthorized Mimicry in Latent Diffusion Models

    cs.CV 2026-06 unverdicted novelty 5.0

    VOID defeats mimicry in LDMs via stochasticity manipulation in the diffusion pipeline, raising average FID from 113 to 365 across evaluations.

  11. Bypassing Copyright Protection in Diffusion-based Customization via Two-Stage Latent Feature Optimization

    cs.CR 2026-06 unverdicted novelty 5.0

    TS-LFO is a two-stage latent feature optimization method that bypasses state-of-the-art copyright defenses in diffusion-based image customization by restoring semantic consistency in latent space.