Share your thoughts, 1 month free Claude Pro on usSee more
WorkDL logo mark

VOID: Defeating Unauthorized Mimicry in Latent Diffusion Models

About

While Latent Diffusion Models (LDMs) have revolutionized visual synthesis, they are increasingly exploited for unauthorized mimicry of individuals. Existing defenses inject deceptive perturbations to steer the generated images toward irrelevant targets. However, this approach hinges on an ungrounded assumption: subtle perturbations can maintain their deceptive efficacy throughout an LDM's extensive generation process. In reality, the model's innate restoration mechanism will remove such perturbations and cause individual identities to re-emerge in the images generated. We propose VOID, a defense framework that overcomes this conundrum by manipulating an LDM's intrinsic stochasticity. VOID perturbs the diffusion pipeline in two novel ways: 1) amplifying the latent encoding errors to shatter an image's semantic structure, and 2) counteracting the target guidance signals to suppress the model's restoration capabilities. This results in a semantic corruption that thwarts any unauthorized mimicry. Notably, the security gain does not come at the price of visual utility, as VOID simultaneously manages to confine perturbations to human-imperceptible regions of protected images. Our comprehensive evaluation of 24 state-of-the-art defenses against 10 mimicry attacks on 5 datasets demonstrates VOID's unprecedented protection power: it increases the average Frechet Inception Distance (FID) from 113 to 365, a 223% improvement over the strongest defense to date.

Chunlin Qiu, Ang Li, Tianxiao Huang, Ruilin Gan, Yunjie Ge, Shenyi Zhang, Huayi Duan, Lingchen Zhao, Chao Shen, Qian Wang• 2026

Related benchmarks

TaskDatasetResultRank
Mimicry DefenseTI-Dataset
FID113.2
99
Training-based Mimicry DefenseTI-Dataset, DB-Dataset, CelebA-HQ, VGGFace2, WikiArt Average
FID365.4
52
Inference-based Mimicry DefenseTI-Dataset, DB-Dataset, CelebA-HQ, VGGFace2, WikiArt Average across 5 datasets
FID325.8
26
Mimicry DefenseMimicry Datasets
FID286
15
Adversarial DefenseTI-Dataset SD v1.5
FID299.2
12
Adversarial DefenseTI-Dataset SD v2.1
FID300.9
12
Adversarial DefenseTI-Dataset DreamShaper
FID305.9
12
Adversarial DefenseTI-Dataset LCM
FID304
12
Visual Quality AssessmentProtected image samples diverse domains
PSNR34.408
5
Adversarial DefenseTI-Dataset FLUX.1 Kontext
FID105.3
4
Showing 10 of 14 rows

Other info

Follow for update