Dual Attention Guided Defense Against Malicious Edits

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Zhang, Jie, Dong, Shuai, Shan, Shiguang, Chen, Xilin
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866915679072944128
author Zhang, Jie
Dong, Shuai
Shan, Shiguang
Chen, Xilin
author_facet Zhang, Jie
Dong, Shuai
Shan, Shiguang
Chen, Xilin
contents Recent progress in text-to-image diffusion models has transformed image editing via text prompts, yet this also introduces significant ethical challenges from potential misuse in creating deceptive or harmful content. While current defenses seek to mitigate this risk by embedding imperceptible perturbations, their effectiveness is limited against malicious tampering. To address this issue, we propose a Dual Attention-Guided Noise Perturbation (DANP) immunization method that adds imperceptible perturbations to disrupt the model's semantic understanding and generation process. DANP functions over multiple timesteps to manipulate both cross-attention maps and the noise prediction process, using a dynamic threshold to generate masks that identify text-relevant and irrelevant regions. It then reduces attention in relevant areas while increasing it in irrelevant ones, thereby misguides the edit towards incorrect regions and preserves the intended targets. Additionally, our method maximizes the discrepancy between the injected noise and the model's predicted noise to further interfere with the generation. By targeting both attention and noise prediction mechanisms, DANP exhibits impressive immunity against malicious edits, and extensive experiments confirm that our method achieves state-of-the-art performance.
format Preprint
id arxiv_https___arxiv_org_abs_2512_14333
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Dual Attention Guided Defense Against Malicious Edits
Zhang, Jie
Dong, Shuai
Shan, Shiguang
Chen, Xilin
Computer Vision and Pattern Recognition
Artificial Intelligence
Computers and Society
Machine Learning
Recent progress in text-to-image diffusion models has transformed image editing via text prompts, yet this also introduces significant ethical challenges from potential misuse in creating deceptive or harmful content. While current defenses seek to mitigate this risk by embedding imperceptible perturbations, their effectiveness is limited against malicious tampering. To address this issue, we propose a Dual Attention-Guided Noise Perturbation (DANP) immunization method that adds imperceptible perturbations to disrupt the model's semantic understanding and generation process. DANP functions over multiple timesteps to manipulate both cross-attention maps and the noise prediction process, using a dynamic threshold to generate masks that identify text-relevant and irrelevant regions. It then reduces attention in relevant areas while increasing it in irrelevant ones, thereby misguides the edit towards incorrect regions and preserves the intended targets. Additionally, our method maximizes the discrepancy between the injected noise and the model's predicted noise to further interfere with the generation. By targeting both attention and noise prediction mechanisms, DANP exhibits impressive immunity against malicious edits, and extensive experiments confirm that our method achieves state-of-the-art performance.
title Dual Attention Guided Defense Against Malicious Edits
topic Computer Vision and Pattern Recognition
Artificial Intelligence
Computers and Society
Machine Learning
url https://arxiv.org/abs/2512.14333