DiffusionGuard: A Robust Defense Against Malicious Diffusion-based Image Editing

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Choi, June Suk, Lee, Kyungmin, Jeong, Jongheon, Xie, Saining, Shin, Jinwoo, Lee, Kimin
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909813911322624
author Choi, June Suk
Lee, Kyungmin
Jeong, Jongheon
Xie, Saining
Shin, Jinwoo
Lee, Kimin
author_facet Choi, June Suk
Lee, Kyungmin
Jeong, Jongheon
Xie, Saining
Shin, Jinwoo
Lee, Kimin
contents Recent advances in diffusion models have introduced a new era of text-guided image manipulation, enabling users to create realistic edited images with simple textual prompts. However, there is significant concern about the potential misuse of these methods, especially in creating misleading or harmful content. Although recent defense strategies, which introduce imperceptible adversarial noise to induce model failure, have shown promise, they remain ineffective against more sophisticated manipulations, such as editing with a mask. In this work, we propose DiffusionGuard, a robust and effective defense method against unauthorized edits by diffusion-based image editing models, even in challenging setups. Through a detailed analysis of these models, we introduce a novel objective that generates adversarial noise targeting the early stage of the diffusion process. This approach significantly improves the efficiency and effectiveness of adversarial noises. We also introduce a mask-augmentation technique to enhance robustness against various masks during test time. Finally, we introduce a comprehensive benchmark designed to evaluate the effectiveness and robustness of methods in protecting against privacy threats in realistic scenarios. Through extensive experiments, we show that our method achieves stronger protection and improved mask robustness with lower computational costs compared to the strongest baseline. Additionally, our method exhibits superior transferability and better resilience to noise removal techniques compared to all baseline methods. Our source code is publicly available at https://github.com/choi403/DiffusionGuard.
format Preprint
id arxiv_https___arxiv_org_abs_2410_05694
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle DiffusionGuard: A Robust Defense Against Malicious Diffusion-based Image Editing
Choi, June Suk
Lee, Kyungmin
Jeong, Jongheon
Xie, Saining
Shin, Jinwoo
Lee, Kimin
Computer Vision and Pattern Recognition
Recent advances in diffusion models have introduced a new era of text-guided image manipulation, enabling users to create realistic edited images with simple textual prompts. However, there is significant concern about the potential misuse of these methods, especially in creating misleading or harmful content. Although recent defense strategies, which introduce imperceptible adversarial noise to induce model failure, have shown promise, they remain ineffective against more sophisticated manipulations, such as editing with a mask. In this work, we propose DiffusionGuard, a robust and effective defense method against unauthorized edits by diffusion-based image editing models, even in challenging setups. Through a detailed analysis of these models, we introduce a novel objective that generates adversarial noise targeting the early stage of the diffusion process. This approach significantly improves the efficiency and effectiveness of adversarial noises. We also introduce a mask-augmentation technique to enhance robustness against various masks during test time. Finally, we introduce a comprehensive benchmark designed to evaluate the effectiveness and robustness of methods in protecting against privacy threats in realistic scenarios. Through extensive experiments, we show that our method achieves stronger protection and improved mask robustness with lower computational costs compared to the strongest baseline. Additionally, our method exhibits superior transferability and better resilience to noise removal techniques compared to all baseline methods. Our source code is publicly available at https://github.com/choi403/DiffusionGuard.
title DiffusionGuard: A Robust Defense Against Malicious Diffusion-based Image Editing
topic Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2410.05694