Adversarial Perturbations Cannot Reliably Protect Artists From Generative AI
Robert Hönig, Javier Rando, Nicholas Carlini, Florian Tramèr
Abstract
Artists are increasingly concerned about advancements in image generation models that can closely replicate their unique artistic styles. In response, several protection tools against style mimicry have been developed that incorporate small adversarial perturbations into artworks published online. In this work, we evaluate the effectiveness of popular protections-with millions of downloads-and show they only provide a false sense of security. We find that low-effort and "off-the-shelf" techniques, such as image upscaling, are sufficient to create robust mimicry methods that significantly degrade existing protections. Through a user study, we demonstrate that all existing protections can be easily bypassed, leaving artists vulnerable to style mimicry. We caution that tools based on adversarial perturbations cannot reliably protect artists from the misuse of generative AI, and urge the development of alternative protective solutions.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext bcfb7bcb-c6b6-4abd-82dd-10f247296db3Cited by top-tier papers25
- BlurGuard: A Simple Approach for Robustifying Image Protection Against AI-Powered EditingJinsu Kim, Yunhun Nam, Minseon Kim, Sangpil Kim et al.NeurIPS 2025 · 7 citations
- StyleGuard: Preventing Text-to-Image-Model-based Style Mimicry Attacks by Style PerturbationsYanjie Li, Wenxuan Zhang, Xinqi Lyu, Yihao Liu et al.NeurIPS 2025 · 7 citations
- TrustMark: Robust Watermarking and Watermark Removal for Arbitrary Resolution ImagesTu Bui, Shruti Agarwal, John P. CollomosseICCV 2025 · 6 citations
- BridgePure: Limited Protection Leakage Can Break Black-Box Data ProtectionYihan Wang, Yiwei Lu, Xiao-Shan Gao, Gautam Kamath et al.NeurIPS 2025 · 5 citations
- DEGauss: Defending Against Malicious 3D Editing for Gaussian SplattingLingzhuang Meng, Mingwen Shao, Yuanjian Qiao, Xiang LvNeurIPS 2025 · 4 citations
Builds on15
- Denoising Diffusion Probabilistic ModelsJonathan Ho, Ajay Jain, Pieter AbbeelNeurIPS 2020 · 35,902 citations
- High-Resolution Image Synthesis with Latent Diffusion ModelsRobin Rombach, Andreas Blattmann, Dominik Lorenz, Patrick Esser et al.CVPR 2022 · 13,123 citations
- Photorealistic Text-to-Image Diffusion Models with Deep Language UnderstandingChitwan Saharia, William Chan, Saurabh Saxena, Lala Li et al.NeurIPS 2022 · 8,965 citations
- BLIP-2: Bootstrapping Language-Image Pre-training with Frozen Image Encoders and Large Language ModelsJunnan Li, Dongxu Li, Silvio Savarese, Steven C. H. HoiICML 2023 · 7,873 citations
- SDXL: Improving Latent Diffusion Models for High-Resolution Image SynthesisDustin Podell, Zion English, Kyle Lacey, Andreas Blattmann et al.ICLR 2024 · 4,569 citations
Related papers
- Glaze: Protecting Artists from Style Mimicry by Text-to-Image ModelsShawn Shan, Jenna Cryan, Emily Wenger, Haitao Zheng et al.USENIX Security 2023
- DDIM Inversion as a Perturbation Amplifier: Breaking Mimicry Protection via Reconstruction Error MinimizationHuming Qiu, Peiyi Chen, Mi Zhang, Geng Hong et al.ICML 2026
- Rethinking Artistic Copyright Infringements In the Era Of Text-to-Image Generative ModelsMazda Moayeri, Sriram Balasubramanian, Samyadeep Basu, Priyatham Kattakinda et al.ICLR 2025
- Rethinking the Invisible Protection against Unauthorized Image Usage in Stable DiffusionShengwei An, Lu Yan, Siyuan Cheng, Guangyu Shen et al.USENIX Security 2024 · 10 citations
- MUSICSHIELD: Protection for Musicians in the Era of Generative AISyed Irfan Ali Meerza, Jian LiuS&P 2026
