Finding NeMo: Localizing Neurons Responsible For Memorization in Diffusion Models
Dominik Hintersdorf, Lukas Struppek, Kristian Kersting, Adam Dziedzic, Franziska Boenisch
Abstract
Diffusion models (DMs) produce very detailed and high-quality images. Their power results from extensive training on large amounts of data, usually scraped from the internet without proper attribution or consent from content creators. Unfortunately, this practice raises privacy and intellectual property concerns, as DMs can memorize and later reproduce their potentially sensitive or copyrighted training images at inference time. Prior efforts prevent this issue by either changing the input to the diffusion process, thereby preventing the DM from generating memorized samples during inference, or removing the memorized data from training altogether. While those are viable solutions when the DM is developed and deployed in a secure and constantly monitored environment, they hold the risk of adversaries circumventing the safeguards and are not effective when the DM itself is publicly released. To solve the problem, we introduce NeMo, the first method to localize memorization of individual data samples down to the level of neurons in DMs' cross-attention layers. Through our experiments, we make the intriguing finding that in many cases, single neurons are responsible for memorizing particular training samples. By deactivating these memorization neurons, we can avoid the replication of training data at inference time, increase the diversity in the generated outputs, and mitigate the leakage of private and copyrighted data. In this way, our NeMo contributes to a more responsible deployment of DMs.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext bf6b4446-2913-47be-95e7-f8b4ac48b622Cited by top-tier papers11
- Provable Separations between Memorization and Generalization in Diffusion ModelsZeqi Ye, Qijie Zhu, Molei Tao, Minshuo ChenICLR 2026 · 15 citations
- Demystifying Robot Diffusion Policies: Action Memorization and a Simple Lookup Table AlternativeChengyang He, Xu Liu, Gadiel Sznaier Camps, Joseph Bruno et al.ICLR 2026 · 15 citations
- Generalization of Diffusion Models Arises with a Balanced Representation SpaceZekai Zhang, Xiao Li, Xiang Li, Lianghe Shi et al.ICLR 2026 · 14 citations
- Adjusting Initial Noise to Mitigate Memorization in Text-to-Image Diffusion ModelsHyeonggeun Han, Sehwan Kim, Hyungjun Joo, Sangwoo Hong et al.NeurIPS 2025 · 7 citations
- Reconstructing Template-Memorized Images from Natural PromptsSol Yarkoni, Mahmood Sharif, Roi LivniICML 2026 · 1 citation
Builds on27
- Learning Transferable Visual Models From Natural Language SupervisionAlec Radford, Jong Wook Kim, Chris Hallacy, Aditya Ramesh et al.ICML 2021 · 47,906 citations
- Denoising Diffusion Probabilistic ModelsJonathan Ho, Ajay Jain, Pieter AbbeelNeurIPS 2020 · 35,902 citations
- High-Resolution Image Synthesis with Latent Diffusion ModelsRobin Rombach, Andreas Blattmann, Dominik Lorenz, Patrick Esser et al.CVPR 2022 · 13,123 citations
- Photorealistic Text-to-Image Diffusion Models with Deep Language UnderstandingChitwan Saharia, William Chan, Saurabh Saxena, Lala Li et al.NeurIPS 2022 · 8,965 citations
- Extracting Training Data from Large Language ModelsNicholas Carlini, Florian Tramèr, Eric Wallace, Matthew Jagielski et al.USENIX Security 2021 · 2,866 citations
Related papers
- Exploring Local Memorization in Diffusion Models via Bright Ending AttentionChen Chen, Daochang Liu, Mubarak Shah, Chang XuICLR 2025
- Finding DoRI: Discovery of Retained Images in Diffusion ModelsAntoni Kowalczuk, Dominik Hintersdorf, Lukas Struppek, Kristian Kersting et al.ICML 2026
- You Don’t Need All That Attention: Surgical Memorization Mitigation in Text-to-Image Diffusion ModelsKairan Zhao, Eleni Triantafillou, Peter TriantafillouICML 2026
- Extracting Training Data from Diffusion ModelsNicholas Carlini, Jamie Hayes, Milad Nasr, Matthew Jagielski et al.USENIX Security 2023
- Image-level Memorization Detection via Inversion-based Inference PerturbationYue Jiang, Haokun Lin, Yang Bai, Bo Peng et al.ICLR 2025
