VA3: Virtually Assured Amplification Attack on Probabilistic Copyright Protection for Text-to-Image Generative Models
Xiang Li, Qianli Shen, Kenji Kawaguchi
Abstract
The booming use of text-to-image generative models has raised concerns about their high risk of producing copyright-infringing content. While probabilistic copyright protection methods provide a probabilistic guarantee against such infringement, in this paper, we introduce Virtually Assured Amplification Attack (VA3), a novel online attack framework that exposes the vulnerabilities of these protection mechanisms. The proposed framework significantly amplifies the probability of generating infringing content on the sustained interactions with generative models and a non-trivial lower-bound on the success probability of each engagement. Our theoretical and experimental results demonstrate the effectiveness of our approach under various scenarios. These findings highlight the potential risk of implementing probabilistic copyright protection in
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers2
- Blameless Users in a Clean Room: Defining Copyright Protection for Generative ModelsAloni CohenNeurIPS 2025 · 2 citations
- LightShed: Defeating Perturbation-based Image Copyright ProtectionsHanna Foerster, Sasha Behrouzi, Phillip Rieger, Murtuza Jadliwala et al.USENIX Security 2025
Builds on34
- Learning Transferable Visual Models From Natural Language SupervisionAlec Radford, Jong Wook Kim, Chris Hallacy, Aditya Ramesh et al.ICML 2021 · 47,906 citations
- Denoising Diffusion Probabilistic ModelsJonathan Ho, Ajay Jain, Pieter AbbeelNeurIPS 2020 · 35,902 citations
- High-Resolution Image Synthesis with Latent Diffusion ModelsRobin Rombach, Andreas Blattmann, Dominik Lorenz, Patrick Esser et al.CVPR 2022 · 13,123 citations
- Photorealistic Text-to-Image Diffusion Models with Deep Language UnderstandingChitwan Saharia, William Chan, Saurabh Saxena, Lala Li et al.NeurIPS 2022 · 8,965 citations
- BLIP: Bootstrapping Language-Image Pre-training for Unified Vision-Language Understanding and GenerationJunnan Li, Dongxu Li, Caiming Xiong, Steven C. H. HoiICML 2022 · 6,549 citations
Related papers
- Yours or Mine? Overwriting Attacks Against Neural Audio WatermarkingLingfeng Yao, Chenpei Huang, Shengyao Wang, Junpei Xue et al.AAAI 2026 · 5 citations
- The Stronger the Diffusion Model, the Easier the Backdoor: Data Poisoning to Induce Copyright BreachesWithout Adjusting Finetuning PipelineHaonan Wang, Qianli Shen, Yao Tong, Yang Zhang et al.ICML 2024 · 48 citations
- Protecting Intellectual Property of Generative Adversarial Networks From Ambiguity AttacksDing Sheng Ong, Chee Seng Chan, Kam Woh Ng, Lixin Fan et al.CVPR 2021
- Not Just Text: Uncovering Vision Modality Typographic Threats in Image Generation ModelsHao Cheng, Erjia Xiao, Jiayan Yang, Jiahang Cao et al.CVPR 2025
- Towards Visualization-of-Thought Jailbreak Attack against Large Visual Language ModelsHongqiong Zhong, Qingyang Teng, Baolin Zheng, Guanlin Chen et al.NeurIPS 2025 · 2 citations
