Share your thoughts, 1 month free Claude Pro on usSee more
WorkDL logo mark

Anti-Diffusion: Preventing Abuse of Modifications of Diffusion-Based Models

About

Although diffusion-based techniques have shown remarkable success in image generation and editing tasks, their abuse can lead to severe negative social impacts. Recently, some works have been proposed to provide defense against the abuse of diffusion-based methods. However, their protection may be limited in specific scenarios by manually defined prompts or the stable diffusion (SD) version. Furthermore, these methods solely focus on tuning methods, overlooking editing methods that could also pose a significant threat. In this work, we propose Anti-Diffusion, a privacy protection system designed for general diffusion-based methods, applicable to both tuning and editing techniques. To mitigate the limitations of manually defined prompts on defense performance, we introduce the prompt tuning (PT) strategy that enables precise expression of original images. To provide defense against both tuning and editing methods, we propose the semantic disturbance loss (SDL) to disrupt the semantic information of protected images. Given the limited research on the defense against editing methods, we develop a dataset named Defense-Edit to assess the defense performance of various methods. Experiments demonstrate that our Anti-Diffusion achieves superior defense performance across a wide range of diffusion-based techniques in different scenarios.

Zheng Li, Liangbin Xie, Jiantao Zhou, Xintao Wang, Haiwei Wu, Jinyu Tian• 2025

Related benchmarks

TaskDatasetResultRank
Untargeted identity retrieval attackVggFace2
R1-U100
40
Untargeted identity retrieval attackVGGFace2 a photo of sks person prompt
Rank-1 Retrieval Rate (Untargeted)97.92
25
Untargeted identity retrieval attackVGGFace2 a dslr portrait of sks person prompt
R1-U73.33
25
Personalized Image GenerationCelebA-HQ 512x512 (test)
FSR33
14
Personalized Image GenerationVGGFace2 512x512 (test)
FSR44
14
Untargeted identity retrieval attackCelebA-HQ a photo of sks person (test)
IRSE50 Retrieval Rate (R1-U)100
5
Untargeted identity retrieval attackCelebA-HQ "a dslr portrait of sks person" (test)
IRSE50 Rank-1 Accuracy81.25
5
Untargeted identity retrieval attackCelebA-HQ "a dslr portrait of sks person"
AdaFace R1-U75
5
Untargeted identity retrieval attackCelebA-HQ "a photo of sks person"
AdaFace R1-U60
5
Showing 9 of 9 rows

Other info

Follow for update