GuardDoor: Safeguarding Against Malicious Diffusion Editing via Protective Backdoors

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Zeng, Yaopei, Cao, Yuanpu, Lin, Lu
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866912262015418368
author Zeng, Yaopei
Cao, Yuanpu
Lin, Lu
author_facet Zeng, Yaopei
Cao, Yuanpu
Lin, Lu
contents The growing accessibility of diffusion models has revolutionized image editing but also raised significant concerns about unauthorized modifications, such as misinformation and plagiarism. Existing countermeasures largely rely on adversarial perturbations designed to disrupt diffusion model outputs. However, these approaches are found to be easily neutralized by simple image preprocessing techniques, such as compression and noise addition. To address this limitation, we propose GuardDoor, a novel and robust protection mechanism that fosters collaboration between image owners and model providers. Specifically, the model provider participating in the mechanism fine-tunes the image encoder to embed a protective backdoor, allowing image owners to request the attachment of imperceptible triggers to their images. When unauthorized users attempt to edit these protected images with this diffusion model, the model produces meaningless outputs, reducing the risk of malicious image editing. Our method demonstrates enhanced robustness against image preprocessing operations and is scalable for large-scale deployment. This work underscores the potential of cooperative frameworks between model providers and image owners to safeguard digital content in the era of generative AI.
format Preprint
id arxiv_https___arxiv_org_abs_2503_03944
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle GuardDoor: Safeguarding Against Malicious Diffusion Editing via Protective Backdoors
Zeng, Yaopei
Cao, Yuanpu
Lin, Lu
Computer Vision and Pattern Recognition
The growing accessibility of diffusion models has revolutionized image editing but also raised significant concerns about unauthorized modifications, such as misinformation and plagiarism. Existing countermeasures largely rely on adversarial perturbations designed to disrupt diffusion model outputs. However, these approaches are found to be easily neutralized by simple image preprocessing techniques, such as compression and noise addition. To address this limitation, we propose GuardDoor, a novel and robust protection mechanism that fosters collaboration between image owners and model providers. Specifically, the model provider participating in the mechanism fine-tunes the image encoder to embed a protective backdoor, allowing image owners to request the attachment of imperceptible triggers to their images. When unauthorized users attempt to edit these protected images with this diffusion model, the model produces meaningless outputs, reducing the risk of malicious image editing. Our method demonstrates enhanced robustness against image preprocessing operations and is scalable for large-scale deployment. This work underscores the potential of cooperative frameworks between model providers and image owners to safeguard digital content in the era of generative AI.
title GuardDoor: Safeguarding Against Malicious Diffusion Editing via Protective Backdoors
topic Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2503.03944