Distraction is All You Need: Memory-Efficient Image Immunization against Diffusion-Based Image Editing
Ling Lo, Cheng Yu Yeo, Hong-Han Shuai, Wen-Huang Cheng
Abstract
Recent text-to-image (T2I) diffusion models have revolutionized image editing by empowering users to control out-comes using natural language. However, the ease of image manipulation has raised ethical concerns, with the poten-tial for malicious use in generating deceptive or harmful content. To address the concerns, we propose an image im-munization approach named semantic attack to protect our images from being manipulated by malicious agents using diffusion models. Our approach focuses on disrupting the semantic understanding of T2I diffusion models regarding specific content. By attacking the cross-attention mecha-nism that encodes image features with text messages during editing, we distract the model's attention regarding the con-tent of our concern. Our semantic attack renders the model uncertain about the areas to edit, resulting in poorly edited images and contradicting the malicious editing attempts. In addition, by shifting the attack target towards intermediate attention maps from the final generated image, our approach substantially diminishes computational burden and alleviates GPU memory constraints in comparison to pre-vious methods. Moreover, we introduce timestep universal gradient updating to create timestep-agnostic perturbations effective across different input noise levels. By treating the full diffusion process as discrete denoising timesteps during the attack, we achieve equivalent or even superior immu-nization efficacy with nearly half the memory consumption of the previous method. Our contributions include a prac-tical and effective approach to safeguard images against malicious editing, and the proposed method offers robust immunization against various image inpainting and editing approaches, showcasing its potential for real-world appli-cations.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 592191cf-ea2c-4ba1-aa2f-8631c1ff8fe4Cited by top-tier papers11
- DCT-Shield: A Robust Frequency Domain Defense Against Malicious Image EditingAniruddha Bala, Rohit Chowdhury, Rohan Jaiswal, Siddharth RohedaICCV 2025 · 9 citations
- DiffVax: Optimization-Free Image Immunization Against Diffusion-Based EditingTarik Can Ozden, Ozgur Kara, Oguzhan Akcin, Kerem Zaman et al.ICLR 2026 · 7 citations
- DADet: Safeguarding Image Conditional Diffusion Models Against Adversarial and Backdoor Attacks via Diffusion Anomaly DetectionHongwei Yu, Xinlong Ding, Jiawei Li, Jinlong Wang et al.ICCV 2025 · 4 citations
- ReCorD: Reasoning and Correcting Diffusion for HOI GenerationJian-Yu Jiang-Lin, Kang-Yang Huang, Ling Lo, Yi-Ning Huang et al.ACM MM 2024 · 4 citations
- DEGauss: Defending Against Malicious 3D Editing for Gaussian SplattingLingzhuang Meng, Mingwen Shao, Yuanjian Qiao, Xiang LvNeurIPS 2025 · 4 citations
Builds on31
- Learning Transferable Visual Models From Natural Language SupervisionAlec Radford, Jong Wook Kim, Chris Hallacy, Aditya Ramesh et al.ICML 2021 · 47,906 citations
- Denoising Diffusion Probabilistic ModelsJonathan Ho, Ajay Jain, Pieter AbbeelNeurIPS 2020 · 35,902 citations
- High-Resolution Image Synthesis with Latent Diffusion ModelsRobin Rombach, Andreas Blattmann, Dominik Lorenz, Patrick Esser et al.CVPR 2022 · 13,123 citations
- Denoising Diffusion Implicit ModelsJiaming Song, Chenlin Meng, Stefano ErmonICLR 2021 · 11,743 citations
- Photorealistic Text-to-Image Diffusion Models with Deep Language UnderstandingChitwan Saharia, William Chan, Saurabh Saxena, Lala Li et al.NeurIPS 2022 · 8,965 citations
Related papers
- Raising the Cost of Malicious AI-Powered Image EditingHadi Salman, Alaa Khaddaj, Guillaume Leclerc, Andrew Ilyas et al.ICML 2023 · 181 citations
- PromptFlare: Prompt-Generalized Defense via Cross-Attention Decoy in Diffusion-Based InpaintingHohyun Na, Seunghoo Hong, Simon S. WooACM MM 2025 · 1 citation
- Immunizing Images from Text to Image Editing via Adversarial Cross-AttentionMatteo Trippodo, Federico Becattini, Lorenzo SeidenariACM MM 2025 · 2 citations
- UniDef: Universal Defense Against Unauthorized Image ManipulationMingwen Shao, Lingzhuang Meng, Xiang Lv, Mengyao Wu et al.CVPR 2026
- DiffEdit: Diffusion-based semantic image editing with mask guidanceGuillaume Couairon, Jakob Verbeek, Holger Schwenk, Matthieu CordICLR 2023 · 102 citations
