DDIM Inversion as a Perturbation Amplifier: Breaking Mimicry Protection via Reconstruction Error Minimization
Huming Qiu, Peiyi Chen, Mi Zhang, Geng Hong, Xiaoyu You, Mi Wen, Min Yang
Abstract
Personalization techniques for image generation models have increasingly been misused for malicious purposes, including unauthorized style imitation and copyrighted content replication. In response, recent mimicry protection methods embed carefully designed perturbations into images to disrupt a model's ability to learn genuine semantic representations. Despite their growing adoption, the robustness of these protection mechanisms remains poorly understood, raising concerns about their reliability in real-world deployment. In this work, we present the first systematic analysis showing that DDIM inversion inherently acts as a perturbation amplifier, causing protected images to suffer severe structural distortions during reconstruction. Building on this observation, we propose DDIM Inversion-based Reconstruction Purification (DIRP), a novel purification approach that removes protective perturbations by explicitly minimizing DDIM inversion reconstruction error under perceptual constraints. Extensive experiments on six existing mimicry protection methods demonstrate that DIRP consistently outperforms seven state-of-the-art attack baselines, achieving superior perturbation removal while better preserving image quality. Our results expose fundamental vulnerabilities in current mimicry protection strategies and highlight the urgent need for more robust and principled defenses.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext bb37c5d4-99d9-4e6c-84b4-6d10bf6c137cBuilds on21
- Learning Transferable Visual Models From Natural Language SupervisionAlec Radford, Jong Wook Kim, Chris Hallacy, Aditya Ramesh et al.ICML 2021 · 47,906 citations
- Denoising Diffusion Probabilistic ModelsJonathan Ho, Ajay Jain, Pieter AbbeelNeurIPS 2020 · 35,902 citations
- LoRA: Low-Rank Adaptation of Large Language ModelsEdward J. Hu, Yelong Shen, Phillip Wallis, Zeyuan Allen-Zhu et al.ICLR 2022 · 18,833 citations
- High-Resolution Image Synthesis with Latent Diffusion ModelsRobin Rombach, Andreas Blattmann, Dominik Lorenz, Patrick Esser et al.CVPR 2022 · 13,123 citations
- Directly Denoising Diffusion ModelsDan Zhang, Jingjing Wang, Feng LuoICML 2024 · 11,724 citations
Related papers
- StyleGuard: Preventing Text-to-Image-Model-based Style Mimicry Attacks by Style PerturbationsYanjie Li, Wenxuan Zhang, Xinqi Lyu, Yihao Liu et al.NeurIPS 2025 · 7 citations
- IMPRESS: Evaluating the Resilience of Imperceptible Perturbations Against Unauthorized Data Usage in Diffusion-Based Generative AIBochuan Cao, Changjiang Li, Ting Wang, Jinyuan Jia et al.NeurIPS 2023 · 46 citations
- DIA: The Adversarial Exposure of Deterministic Inversion in Diffusion ModelsSeunghoo Hong, Geonho Son, Juhun Lee, Simon S. WooICCV 2025
- Universal Adversarial Purification with DDIM Metric Loss for Stable DiffusionLi Zheng, Liangbin Xie, Jiantao Zhou, Yimin HeAAAI 2026
- Can Protective Perturbation Safeguard Personal Data from Being Exploited by Stable Diffusion?Zhengyue Zhao, Jinhao Duan, Kaidi Xu, Chenan Wang et al.CVPR 2024 · 12 citations
