SimAC: A Simple Anti-Customization Method for Protecting Face Privacy Against Text-to-Image Synthesis of Diffusion Models
Feifei Wang, Zhentao Tan, Tianyi Wei, Yue Wu, Qidong Huang
Abstract
Despite the success of diffusion-based customization methods on visual content creation, increasing concerns have been raised about such techniques from both privacy and political perspectives. To tackle this issue, several anti-customization methods have been proposed in very recent months, predominantly grounded in adversarial attacks. Unfortunately, most of these methods adopt straightforward designs, such as end-to-end optimization with a focus on adversarially maximizing the original training loss, thereby neglecting nuanced internal properties intrinsic to the diffusion model, and even leading to ineffective optimization in some diffusion time steps. In this paper, we strive to bridge this gap by undertaking a comprehensive exploration of these inherent properties, to boost the performance of current anti-customization approaches. Two aspects of properties are investigated: 1) We examine the relationship between time step selection and the model's perception in the frequency domain of images and find that lower time steps can give much more contributions to adversarial noises. This inspires us to propose an adaptive greedy search for optimal time steps that seamlessly integrates with existing anti-customization methods. 2) We scrutinize the roles of features at different layers during denoising and devise a sophisticated feature-based optimization framework for anti-customization. Experiments on facial benchmarks demonstrate that our approach significantly increases identity disruption, thereby protecting user privacy and copyright. Our code is available at: https://github.com/somuchtome/SimAC .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext bf40a9ef-1941-4170-85d9-8403bd151d04Cited by top-tier papers17
- Disrupting Diffusion: Token-Level Attention Erasure Attack against Diffusion-based CustomizationYisu Liu, Jinyang An, Wanqian Zhang, Dayan Wu et al.ACM MM 2024 · 16 citations
- AdLift: Lifting Adversarial Perturbations to Safeguard 3D Gaussian Splatting Assets Against Instruction-Driven EditingZiming Hong, Tianyu Huang, Runnan Chen, Shanshan Ye et al.ICML 2026 · 10 citations
- StyleGuard: Preventing Text-to-Image-Model-based Style Mimicry Attacks by Style PerturbationsYanjie Li, Wenxuan Zhang, Xinqi Lyu, Yihao Liu et al.NeurIPS 2025 · 7 citations
- Towards Robust Defense Against Customization via Protective Perturbation Resistant to Diffusion-based PurificationWenkui Yang, Jie Cao, Junxian Duan, Ran HeICCV 2025 · 2 citations
- Bypassing Copyright Protection in Diffusion-based Customization via Two-Stage Latent Feature OptimizationZiang Xu, Wenbo Yu, Hongyao Yu, Hao Fang et al.KDD 2026 · 2 citations
Builds on17
- Denoising Diffusion Probabilistic ModelsJonathan Ho, Ajay Jain, Pieter AbbeelNeurIPS 2020 · 35,902 citations
- An Image is Worth 16x16 Words: Transformers for Image Recognition at ScaleAlexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn et al.ICLR 2021 · 21,477 citations
- High-Resolution Image Synthesis with Latent Diffusion ModelsRobin Rombach, Andreas Blattmann, Dominik Lorenz, Patrick Esser et al.CVPR 2022 · 13,123 citations
- Adversarial Example Does Good: Preventing Painting Imitation from Diffusion Models via Adversarial ExamplesChumeng Liang, Xiaoyu Wu, Yang Hua, Jiaru Zhang et al.ICML 2023 · 200 citations
- Raising the Cost of Malicious AI-Powered Image EditingHadi Salman, Alaa Khaddaj, Guillaume Leclerc, Andrew Ilyas et al.ICML 2023 · 181 citations
Related papers
- An h-space Based Adversarial Attack for Protection Against Few-shot PersonalizationXide Xu, Sandesh Kamath, Muhammad Atif Butt, Bogdan RaducanuACM MM 2025
- Harnessing Global-Local Collaborative Adversarial Perturbation for Anti-CustomizationLong Xu, Jiakai Wang, Haojie Hao, Haotong Qin et al.CVPR 2025
- Targeted Attack Improves Protection against Unauthorized Diffusion CustomizationBoyang Zheng, Chumeng Liang, Xiaoyu WuICLR 2025
- Perturb a Model, Not an Image: Towards Robust Privacy Protection via Anti-Personalized Diffusion ModelsTae-Young Lee, Juwon Seo, Jong Hwan Ko, Gyeong-Moon ParkNeurIPS 2025 · 2 citations
- GAP-Diff: Protecting JPEG-Compressed Images from Diffusion-based Facial CustomizationHaotian Zhu, Shuchao Pang, Zhigang Lu, Yongbin Zhou et al.NDSS 2025
