DIA: The Adversarial Exposure of Deterministic Inversion in Diffusion Models
Seunghoo Hong, Geonho Son, Juhun Lee, Simon S. Woo
Abstract
Diffusion models have shown to be strong representation learners, showcasing state-of-the-art performance across multiple domains. Aside from accelerated sampling, DDIM also enables the inversion of real images back to their latent codes. A direct inheriting application of this inversion operation is real image editing, where the inversion yields latent trajectories to be utilized during the synthesis of the edited image. Unfortunately, this practical tool has enabled malicious users to freely synthesize misinformative or deepfake contents with greater ease, which promotes the spread of unethical and abusive, as well as privacy-, and copyright-infringing contents. While defensive algorithms such as AdvDM and Photoguard have been shown to disrupt the diffusion process on these images, the misalignment between their objectives and the iterative denoising trajectory at test time results in weak disruptive performance. In this work, we present the DDIM Inversion Attack (DIA) that attacks the integrated DDIM trajectory path. Our results support the effective disruption, surpassing previous defensive methods across various editing methods. We believe that our frameworks and results can provide practical defense methods against the malicious use of AI for both the industry and the research community. Our code is available here: https://anonymous.4open.science/r/DIA- 13419/.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 98838b00-02e6-4e92-9277-1ea62dca3ec1Cited by top-tier papers1
Ask how each one uses itBuilds on19
- Learning Transferable Visual Models From Natural Language SupervisionAlec Radford, Jong Wook Kim, Chris Hallacy, Aditya Ramesh et al.ICML 2021 · 47,906 citations
- Denoising Diffusion Probabilistic ModelsJonathan Ho, Ajay Jain, Pieter AbbeelNeurIPS 2020 · 35,902 citations
- High-Resolution Image Synthesis with Latent Diffusion ModelsRobin Rombach, Andreas Blattmann, Dominik Lorenz, Patrick Esser et al.CVPR 2022 · 13,123 citations
- Directly Denoising Diffusion ModelsDan Zhang, Jingjing Wang, Feng LuoICML 2024 · 11,724 citations
- SDEdit: Guided Image Synthesis and Editing with Stochastic Differential EquationsChenlin Meng, Yutong He, Yang Song, Jiaming Song et al.ICLR 2022 · 2,128 citations
Related papers
- DDIM Inversion as a Perturbation Amplifier: Breaking Mimicry Protection via Reconstruction Error MinimizationHuming Qiu, Peiyi Chen, Mi Zhang, Geng Hong et al.ICML 2026
- Pixel Is Not a Barrier: An Effective Evasion Attack for Pixel-Domain Diffusion ModelsChun-Yen Shih, Li-Xuan Peng, Jia-Wei Liao, Ernie Chu et al.AAAI 2025 · 3 citations
- Latent Diffusion Unlearning: Protecting Against Unauthorized Personalization Through Trajectory Shifted PerturbationsNaresh Kumar Devulapally, Shruti Agarwal, Tejas Gokhale, Vishnu Suresh LokhandeACM MM 2025 · 1 citation
- DiffusionGuard: A Robust Defense Against Malicious Diffusion-based Image EditingJune Suk Choi, Kyungmin Lee, Jongheon Jeong, Saining Xie et al.ICLR 2025
- Toward effective protection against diffusion-based mimicry through score distillationHaotian Xue, Chumeng Liang, Xiaoyu Wu, Yongxin ChenICLR 2024 · 70 citations
