IMPRESS: Evaluating the Resilience of Imperceptible Perturbations Against Unauthorized Data Usage in Diffusion-Based Generative AI
Bochuan Cao, Changjiang Li, Ting Wang, Jinyuan Jia, Bo Li, Jinghui Chen
Abstract
Diffusion-based image generation models, such as Stable Diffusion or DALL-E 2, are able to learn from given images and generate high-quality samples following the guidance from prompts. For instance, they can be used to create artistic images that mimic the style of an artist based on his/her original artworks or to maliciously edit the original images for fake content. However, such ability also brings serious ethical issues without proper authorization from the owner of the original images. In response, several attempts have been made to protect the original images from such unauthorized data usage by adding imperceptible perturbations, which are designed to mislead the diffusion model and make it unable to properly generate new samples. In this work, we introduce a perturbation purification platform, named IMPRESS, to evaluate the effectiveness of imperceptible perturbations as a protective measure. IMPRESS is based on the key observation that imperceptible perturbations could lead to a perceptible inconsistency between the original image and the diffusion-reconstructed image, which can be used to devise a new optimization strategy for purifying the image, which may weaken the protection of the original image from unauthorized data usage (e.g., style mimicking, malicious editing). The proposed IMPRESS platform offers a comprehensive evaluation of several contemporary protection methods, and can be used as an evaluation platform for future protection methods.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 10eee259-c33a-459a-a414-e3edcf0bf33fCited by top-tier papers26
- Rethinking the Invisible Protection against Unauthorized Image Usage in Stable DiffusionShengwei An, Lu Yan, Siyuan Cheng, Guangyu Shen et al.USENIX Security 2024 · 10 citations
- DCT-Shield: A Robust Frequency Domain Defense Against Malicious Image EditingAniruddha Bala, Rohit Chowdhury, Rohan Jaiswal, Siddharth RohedaICCV 2025 · 9 citations
- BlurGuard: A Simple Approach for Robustifying Image Protection Against AI-Powered EditingJinsu Kim, Yunhun Nam, Minseon Kim, Sangpil Kim et al.NeurIPS 2025 · 7 citations
- Anti-I2V: Safeguarding your Photos from Malicious Image-to-video GenerationDuc Vu, Anh Nguyen, Chi Tran, Anh TranCVPR 2026 · 7 citations
- DiffVax: Optimization-Free Image Immunization Against Diffusion-Based EditingTarik Can Ozden, Ozgur Kara, Oguzhan Akcin, Kerem Zaman et al.ICLR 2026 · 7 citations
Builds on19
- Learning Transferable Visual Models From Natural Language SupervisionAlec Radford, Jong Wook Kim, Chris Hallacy, Aditya Ramesh et al.ICML 2021 · 47,906 citations
- Denoising Diffusion Probabilistic ModelsJonathan Ho, Ajay Jain, Pieter AbbeelNeurIPS 2020 · 35,902 citations
- Diffusion Models Beat GANs on Image SynthesisPrafulla Dhariwal, Alexander Quinn NicholNeurIPS 2021 · 13,211 citations
- Denoising Diffusion Implicit ModelsJiaming Song, Chenlin Meng, Stefano ErmonICLR 2021 · 11,743 citations
- Improved Denoising Diffusion Probabilistic ModelsAlexander Quinn Nichol, Prafulla DhariwalICML 2021 · 5,234 citations
Related papers
- Can Protective Perturbation Safeguard Personal Data from Being Exploited by Stable Diffusion?Zhengyue Zhao, Jinhao Duan, Kaidi Xu, Chenan Wang et al.CVPR 2024 · 12 citations
- DDIM Inversion as a Perturbation Amplifier: Breaking Mimicry Protection via Reconstruction Error MinimizationHuming Qiu, Peiyi Chen, Mi Zhang, Geng Hong et al.ICML 2026
- Edit Away and My Face Will not Stay: Personal Biometric Defense against Malicious Generative EditingHanhui Wang, Yihua Zhang, Ruizheng Bai, Yue Zhao et al.CVPR 2025
- Anti-Diffusion: Preventing Abuse of Modifications of Diffusion-Based ModelsZheng Li, Liangbin Xie, Jiantao Zhou, Xintao Wang et al.AAAI 2025 · 6 citations
- Latent Diffusion Unlearning: Protecting Against Unauthorized Personalization Through Trajectory Shifted PerturbationsNaresh Kumar Devulapally, Shruti Agarwal, Tejas Gokhale, Vishnu Suresh LokhandeACM MM 2025 · 1 citation
