Disrupting Style Mimicry Attacks on Video Imagery

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Passananti, Josephine, Wu, Stanley, Shan, Shawn, Zheng, Haitao, Zhao, Ben Y.
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866917662880169984
author Passananti, Josephine
Wu, Stanley
Shan, Shawn
Zheng, Haitao
Zhao, Ben Y.
author_facet Passananti, Josephine
Wu, Stanley
Shan, Shawn
Zheng, Haitao
Zhao, Ben Y.
contents Generative AI models are often used to perform mimicry attacks, where a pretrained model is fine-tuned on a small sample of images to learn to mimic a specific artist of interest. While researchers have introduced multiple anti-mimicry protection tools (Mist, Glaze, Anti-Dreambooth), recent evidence points to a growing trend of mimicry models using videos as sources of training data. This paper presents our experiences exploring techniques to disrupt style mimicry on video imagery. We first validate that mimicry attacks can succeed by training on individual frames extracted from videos. We show that while anti-mimicry tools can offer protection when applied to individual frames, this approach is vulnerable to an adaptive countermeasure that removes protection by exploiting randomness in optimization results of consecutive (nearly-identical) frames. We develop a new, tool-agnostic framework that segments videos into short scenes based on frame-level similarity, and use a per-scene optimization baseline to remove inter-frame randomization while reducing computational cost. We show via both image level metrics and an end-to-end user study that the resulting protection restores protection against mimicry (including the countermeasure). Finally, we develop another adaptive countermeasure and find that it falls short against our framework.
format Preprint
id arxiv_https___arxiv_org_abs_2405_06865
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Disrupting Style Mimicry Attacks on Video Imagery
Passananti, Josephine
Wu, Stanley
Shan, Shawn
Zheng, Haitao
Zhao, Ben Y.
Computer Vision and Pattern Recognition
Cryptography and Security
Generative AI models are often used to perform mimicry attacks, where a pretrained model is fine-tuned on a small sample of images to learn to mimic a specific artist of interest. While researchers have introduced multiple anti-mimicry protection tools (Mist, Glaze, Anti-Dreambooth), recent evidence points to a growing trend of mimicry models using videos as sources of training data. This paper presents our experiences exploring techniques to disrupt style mimicry on video imagery. We first validate that mimicry attacks can succeed by training on individual frames extracted from videos. We show that while anti-mimicry tools can offer protection when applied to individual frames, this approach is vulnerable to an adaptive countermeasure that removes protection by exploiting randomness in optimization results of consecutive (nearly-identical) frames. We develop a new, tool-agnostic framework that segments videos into short scenes based on frame-level similarity, and use a per-scene optimization baseline to remove inter-frame randomization while reducing computational cost. We show via both image level metrics and an end-to-end user study that the resulting protection restores protection against mimicry (including the countermeasure). Finally, we develop another adaptive countermeasure and find that it falls short against our framework.
title Disrupting Style Mimicry Attacks on Video Imagery
topic Computer Vision and Pattern Recognition
Cryptography and Security
url https://arxiv.org/abs/2405.06865