{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2023:B4STH6QHJ2JC3CJVHIJB6K34KG","short_pith_number":"pith:B4STH6QH","schema_version":"1.0","canonical_sha256":"0f2533fa074e922d89353a121f2b7c518c4b7b799a85059e3f8eebec0dd25880","source":{"kind":"arxiv","id":"2302.06588","version":1},"attestation_state":"computed","paper":{"title":"Raising the Cost of Malicious AI-Powered Image Editing","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.LG","authors_text":"Alaa Khaddaj, Aleksander Madry, Andrew Ilyas, Guillaume Leclerc, Hadi Salman","submitted_at":"2023-02-13T18:38:42Z","abstract_excerpt":"We present an approach to mitigating the risks of malicious image editing posed by large diffusion models. The key idea is to immunize images so as to make them resistant to manipulation by these models. This immunization relies on injection of imperceptible adversarial perturbations designed to disrupt the operation of the targeted diffusion models, forcing them to generate unrealistic images. We provide two methods for crafting such perturbations, and then demonstrate their efficacy. Finally, we discuss a policy component necessary to make our approach fully effective and practical -- one th"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2302.06588","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2023-02-13T18:38:42Z","cross_cats_sorted":[],"title_canon_sha256":"db5903864fe2526751b86f266989e273e0d20808a6946effdb9db8cad3d14b8e","abstract_canon_sha256":"fe117c756f5d5ce30624e17f49556fb7bdd393bcaaa9a300d28307a655c8811c"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T05:41:12.664491Z","signature_b64":"8ddS3kzdgknjzCKR3TtJhi2tmW2KmlVGoO/iyUF7DSATf4t86CqSqIRoP79dmbCmiwTPW2KeOlQe6D1yj1taDA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"0f2533fa074e922d89353a121f2b7c518c4b7b799a85059e3f8eebec0dd25880","last_reissued_at":"2026-07-05T05:41:12.664029Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T05:41:12.664029Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Raising the Cost of Malicious AI-Powered Image Editing","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.LG","authors_text":"Alaa Khaddaj, Aleksander Madry, Andrew Ilyas, Guillaume Leclerc, Hadi Salman","submitted_at":"2023-02-13T18:38:42Z","abstract_excerpt":"We present an approach to mitigating the risks of malicious image editing posed by large diffusion models. The key idea is to immunize images so as to make them resistant to manipulation by these models. This immunization relies on injection of imperceptible adversarial perturbations designed to disrupt the operation of the targeted diffusion models, forcing them to generate unrealistic images. We provide two methods for crafting such perturbations, and then demonstrate their efficacy. Finally, we discuss a policy component necessary to make our approach fully effective and practical -- one th"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2302.06588","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2302.06588/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2302.06588","created_at":"2026-07-05T05:41:12.664087+00:00"},{"alias_kind":"arxiv_version","alias_value":"2302.06588v1","created_at":"2026-07-05T05:41:12.664087+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2302.06588","created_at":"2026-07-05T05:41:12.664087+00:00"},{"alias_kind":"pith_short_12","alias_value":"B4STH6QHJ2JC","created_at":"2026-07-05T05:41:12.664087+00:00"},{"alias_kind":"pith_short_16","alias_value":"B4STH6QHJ2JC3CJV","created_at":"2026-07-05T05:41:12.664087+00:00"},{"alias_kind":"pith_short_8","alias_value":"B4STH6QH","created_at":"2026-07-05T05:41:12.664087+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":4,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.12263","citing_title":"VOID: Defeating Unauthorized Mimicry in Latent Diffusion Models","ref_index":55,"is_internal_anchor":false},{"citing_arxiv_id":"2606.09909","citing_title":"Bypassing Copyright Protection in Diffusion-based Customization via Two-Stage Latent Feature Optimization","ref_index":31,"is_internal_anchor":false},{"citing_arxiv_id":"2604.10032","citing_title":"Closed-Form Concept Erasure via Double Projections","ref_index":54,"is_internal_anchor":false},{"citing_arxiv_id":"2604.08405","citing_title":"SyncBreaker:Stage-Aware Multimodal Adversarial Attacks on Audio-Driven Talking Head Generation","ref_index":47,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/B4STH6QHJ2JC3CJVHIJB6K34KG","json":"https://pith.science/pith/B4STH6QHJ2JC3CJVHIJB6K34KG.json","graph_json":"https://pith.science/api/pith-number/B4STH6QHJ2JC3CJVHIJB6K34KG/graph.json","events_json":"https://pith.science/api/pith-number/B4STH6QHJ2JC3CJVHIJB6K34KG/events.json","paper":"https://pith.science/paper/B4STH6QH"},"agent_actions":{"view_html":"https://pith.science/pith/B4STH6QHJ2JC3CJVHIJB6K34KG","download_json":"https://pith.science/pith/B4STH6QHJ2JC3CJVHIJB6K34KG.json","view_paper":"https://pith.science/paper/B4STH6QH","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2302.06588&json=true","fetch_graph":"https://pith.science/api/pith-number/B4STH6QHJ2JC3CJVHIJB6K34KG/graph.json","fetch_events":"https://pith.science/api/pith-number/B4STH6QHJ2JC3CJVHIJB6K34KG/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/B4STH6QHJ2JC3CJVHIJB6K34KG/action/timestamp_anchor","attest_storage":"https://pith.science/pith/B4STH6QHJ2JC3CJVHIJB6K34KG/action/storage_attestation","attest_author":"https://pith.science/pith/B4STH6QHJ2JC3CJVHIJB6K34KG/action/author_attestation","sign_citation":"https://pith.science/pith/B4STH6QHJ2JC3CJVHIJB6K34KG/action/citation_signature","submit_replication":"https://pith.science/pith/B4STH6QHJ2JC3CJVHIJB6K34KG/action/replication_record"}},"created_at":"2026-07-05T05:41:12.664087+00:00","updated_at":"2026-07-05T05:41:12.664087+00:00"}