Image-level Memorization Detection via Inversion-based Inference Perturbation
Yue Jiang, Haokun Lin, Yang Bai, Bo Peng, Zhili Liu, Yueming Lyu, Yong Yang, Xing Zheng, Jing Dong
Abstract
Recent studies have discovered that widely used text-to-image diffusion models can replicate training samples during image generation, a phenomenon known as memorization. Existing detection methods primarily focus on identifying memorized prompts. However, in real-world scenarios, image owners may need to verify whether their proprietary or personal images have been memorized by the model, even in the absence of paired prompts or related metadata. We refer to this challenge as image-level memorization detection, where current methods relying on original prompts fall short. In this work, we uncover two characteristics of memorized images after perturbing the inference procedure: lower similarity of the original images and larger magnitudes of TCNP. Building on these insights, we propose Inversion-based Inference Perturbation (IIP), a new framework for image-level memorization detection. Our approach uses unconditional DDIM inversion to derive latent codes that contain core semantic information of original images and optimizes random prompt embeddings to introduce effective perturbation. Memorized images exhibit distinct characteristics within the proposed pipeline, providing a robust basis for detection. To support this task, we construct a comprehensive setup for the image-level memorization detection, carefully curating datasets to simulate realistic memorization scenarios. Using this setup, we evaluate our IIP framework across three different memorization settings, demonstrating its state-of-the-art performance in identifying memorized images in various settings, even in the presence of data augmentation attacks. Our code and datasets are available at https://github.com/joellejiang/IIP.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext afbf764b-888b-4957-a1a9-bf6d5264d9afCited by top-tier papers6
- SIDE: Surrogate Conditional Data Extraction from Diffusion ModelsYunhao Chen, Shujie Wang, Difan Zou, Xingjun MaAAAI 2026 · 9 citations
- An Inversion-Based Measure of Memorization for Diffusion ModelsZhe Ma, Qingming Li, Xuhong Zhang, Tianyu Du et al.ICCV 2025 · 5 citations
- MedREK: Retrieval-Based Editing for Medical LLMs with Key-Aware PromptsShujun Xia, Haokun Lin, Yichen WU, Yinan Zhou et al.ICML 2026 · 5 citations
- Detecting and Mitigating Memorization in Diffusion Models through Anisotropy of the Log-ProbabilityRohan Asthana, Vasileios BelagiannisICLR 2026 · 3 citations
- Finding DoRI: Discovery of Retained Images in Diffusion ModelsAntoni Kowalczuk, Dominik Hintersdorf, Lukas Struppek, Kristian Kersting et al.ICML 2026
Builds on25
- Denoising Diffusion Probabilistic ModelsJonathan Ho, Ajay Jain, Pieter AbbeelNeurIPS 2020 · 35,902 citations
- High-Resolution Image Synthesis with Latent Diffusion ModelsRobin Rombach, Andreas Blattmann, Dominik Lorenz, Patrick Esser et al.CVPR 2022 · 13,123 citations
- Directly Denoising Diffusion ModelsDan Zhang, Jingjing Wang, Feng LuoICML 2024 · 11,724 citations
- Adding Conditional Control to Text-to-Image Diffusion ModelsLvmin Zhang, Anyi Rao, Maneesh AgrawalaICCV 2023 · 6,759 citations
- Zero-Shot Text-to-Image GenerationAditya Ramesh, Mikhail Pavlov, Gabriel Goh, Scott Gray et al.ICML 2021 · 6,356 citations
Related papers
- Detecting, Explaining, and Mitigating Memorization in Diffusion ModelsYuxin Wen, Yuchen Liu, Chen Chen, Lingjuan LyuICLR 2024 · 103 citations
- Latent Diffusion Unlearning: Protecting Against Unauthorized Personalization Through Trajectory Shifted PerturbationsNaresh Kumar Devulapally, Shruti Agarwal, Tejas Gokhale, Vishnu Suresh LokhandeACM MM 2025 · 1 citation
- Unveiling Structural Memorization: Structural Membership Inference Attack for Text-to-Image Diffusion ModelsQiao Li, Xiaomeng Fu, Xi Wang, Jin Liu et al.ACM MM 2024 · 6 citations
- Towards Memorization-Free Diffusion ModelsChen Chen, Daochang Liu, Chang XuCVPR 2024
- DIAGNOSIS: Detecting Unauthorized Data Usages in Text-to-image Diffusion ModelsZhenting Wang, Chen Chen, Lingjuan Lyu, Dimitris N. Metaxas et al.ICLR 2024 · 12 citations
