Share your thoughts, 1 month free Claude Pro on usSee more
WorkDL logo mark

Bypassing Copyright Protection in Diffusion-based Customization via Two-Stage Latent Feature Optimization

About

With the growing concerns over copyright infringement in diffusion-based customization, adversarial attacks have emerged as a prominent defense strategy to prevent malicious content forgery in personalized image generation. However, current defenses typically introduce persistent perturbations in the latent space of Latent Diffusion Models (LDMs), which remain susceptible to adaptive bypasses by adversaries. In this paper, we introduce Two-Stage Latent Feature Optimization (TS-LFO), an efficient and effective copyright-stealing attack against protected diffusion-based customization. We begin by observing that existing defenses primarily disrupt the mapping between input images and their latent representations, thereby degrading the model's ability to produce personalized outputs. To counteract this, TS-LFO restores the broken mapping through a two-stage optimization process. In the Latent Denoising Stage, we enhance semantic consistency between latent codes and input images by jointly minimizing a Latent-Image Alignment Loss and a Latent Diffusion Loss with timestep-dependent weights, effectively suppressing the high-frequency noise introduced by defenses. In the Latent Reconstruction Stage, we recover low-frequency semantic information using pixel-level constraints to refine the latent features. Extensive experiments show that TS-LFO consistently bypasses state-of-the-art (SOTA) copyright defenses and outperforms SOTA copyright attacks such as DiffPure, GrIDPure and IMPRESS across diverse settings.

Ziang Xu, Wenbo Yu, Hongyao Yu, Hao Fang, Jiawei Kong, Bin Chen, Hao Wu, Shu-Tao Xia, Zhiyong Wu• 2026

Related benchmarks

TaskDatasetResultRank
Image ReconstructionCelebA-HQ
FDFR0.0988
32
Subject-driven Image Generation (DreamBooth)CelebA-HQ v1.0 (test)
FID165.9
25
Subject-driven Image Generation (DreamBooth)LSUN cat 2015 (test)
FID243.6
25
Subject-driven Image Generation (DreamBooth)LSUN-sheep 2015 (test)
FID301.7
25
Diffusion-based Customization (DreamBooth)CelebA-HQ
FID165.9
9
Diffusion-based Customization (DreamBooth)LSUN CAT
FID243.6
9
Diffusion-based Customization (DreamBooth)LSUN sheep
FID301.7
9
Textual InversionLSUN CAT
FID267.3
7
Textual InversionCelebA-HQ
FID192.7
7
Textual InversionLSUN sheep
FID290.1
7
Showing 10 of 15 rows

Other info

Follow for update