Edit Away and My Face Will not Stay: Personal Biometric Defense against Malicious Generative Editing
Hanhui Wang, Yihua Zhang, Ruizheng Bai, Yue Zhao, Sijia Liu, Zhengzhong Tu
Abstract
Recent advancements in diffusion models have made generative image editing more accessible than ever. While these developments allow users to generate creative edits with ease, they also raise significant ethical concerns, particularly regarding malicious edits to human portraits that threaten individuals' privacy and identity security. Existing general-purpose image protection methods primarily focus on generating adversarial perturbations to nullify edit effects. However, these approaches often exhibit instability to protect against diverse editing requests. In this work, we introduce a novel perspective to personal human portrait protection against malicious editing. Unlike traditional methods aiming to prevent edits from taking effect, our method, FaceLock, optimizes adversarial perturbations to ensure that original biometric information---such as facial features---is either destroyed or substantially altered post-editing, rendering the subject in the edited output biometrically unrecognizable. Our approach innovatively integrates facial recognition and visual perception factors into the perturbation optimization process, ensuring robust protection against a variety of editing attempts. Besides, we shed light on several critical issues with commonly used evaluation metrics in image editing and reveal cheating methods by which they can be easily manipulated, leading to deceptive assessments of protection. Through extensive experiments, we demonstrate that FaceLock significantly outperforms all baselines in defense performance against a wide range of malicious edits. Moreover, our method also exhibits strong robustness against purification techniques. Comprehensive ablation studies confirm the stability and broad applicability of our method across diverse diffusion-based editing algorithms. Our work not only advances the state-of-the-art in biometric defense but also sets the foundation for more secure and privacy-preserving practices in image editing.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 69ebc255-9de5-4ffa-b932-f82b524415eaCited by top-tier papers5
- AdLift: Lifting Adversarial Perturbations to Safeguard 3D Gaussian Splatting Assets Against Instruction-Driven EditingZiming Hong, Tianyu Huang, Runnan Chen, Shanshan Ye et al.ICML 2026 · 10 citations
- BlurGuard: A Simple Approach for Robustifying Image Protection Against AI-Powered EditingJinsu Kim, Yunhun Nam, Minseon Kim, Sangpil Kim et al.NeurIPS 2025 · 7 citations
- Anti-Avatar: Protect Against Unauthorized 3D Head Avatar Generation via Dual-Space DivergenceLingzhuang Meng, Mingwen Shao, Xiang Lv, Mengyao Wu et al.AAAI 2026 · 1 citation
- No Way To Steal My Face: Proactive Defense Against Identity-Preserving Personalized GenerationLizhi Xiong, Jun Li, Ziqiang Li, Weiwei Jiang et al.CVPR 2026 · 1 citation
- ID-Patch: Robust ID Association for Group Photo PersonalizationYimeng Zhang, Tiancheng Zhi, Jing Liu, Shen Sang et al.CVPR 2025
Builds on29
- Learning Transferable Visual Models From Natural Language SupervisionAlec Radford, Jong Wook Kim, Chris Hallacy, Aditya Ramesh et al.ICML 2021 · 47,906 citations
- High-Resolution Image Synthesis with Latent Diffusion ModelsRobin Rombach, Andreas Blattmann, Dominik Lorenz, Patrick Esser et al.CVPR 2022 · 13,123 citations
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Visual Autoregressive Modeling: Scalable Image Generation via Next-Scale PredictionKeyu Tian, Yi Jiang, Zehuan Yuan, Bingyue Peng et al.NeurIPS 2024 · 1,199 citations
- Diffusion Models for Adversarial PurificationWeili Nie, Brandon Guo, Yujia Huang, Chaowei Xiao et al.ICML 2022 · 663 citations
Related papers
- DiffusionGuard: A Robust Defense Against Malicious Diffusion-based Image EditingJune Suk Choi, Kyungmin Lee, Jongheon Jeong, Saining Xie et al.ICLR 2025
- DCT-Shield: A Robust Frequency Domain Defense Against Malicious Image EditingAniruddha Bala, Rohit Chowdhury, Rohan Jaiswal, Siddharth RohedaICCV 2025 · 9 citations
- Can Protective Perturbation Safeguard Personal Data from Being Exploited by Stable Diffusion?Zhengyue Zhao, Jinhao Duan, Kaidi Xu, Chenan Wang et al.CVPR 2024 · 12 citations
- UniDef: Universal Defense Against Unauthorized Image ManipulationMingwen Shao, Lingzhuang Meng, Xiang Lv, Mengyao Wu et al.CVPR 2026
- IMPRESS: Evaluating the Resilience of Imperceptible Perturbations Against Unauthorized Data Usage in Diffusion-Based Generative AIBochuan Cao, Changjiang Li, Ting Wang, Jinyuan Jia et al.NeurIPS 2023 · 46 citations
