Disrupting Diffusion: Token-Level Attention Erasure Attack against Diffusion-based Customization
Yisu Liu, Jinyang An, Wanqian Zhang, Dayan Wu, Jingzi Gu, Zheng Lin, Weiping Wang
Abstract
With the development of diffusion-based customization methods like DreamBooth, individuals now have access to train the models that can generate their personalized images. Despite the convenience, malicious users have misused these techniques to create fake images, thereby triggering a privacy security crisis. In light of this, proactive adversarial attacks are proposed to protect users against customization. The adversarial examples are trained to distort the customization model's outputs and thus block the misuse. In this paper, we propose DisDiff (Disrupting Diffusion), a novel adversarial attack method to disrupt the diffusion model outputs. We first delve into the intrinsic image-text relationships, well-known as cross-attention, and empirically find that the subject-identifier token plays an important role in guiding image generation. Thus, we propose the Cross-Attention Erasure module to explicitly "erase" the indicated attention maps and disrupt the text guidance. Besides, we analyze the influence of the sampling process of the diffusion model on Projected Gradient Descent (PGD) attack and introduce a novel Merit Sampling Scheduler to adaptively modulate the perturbation updating amplitude in a step-aware manner. Our DisDiff outperforms the state-of-the-art methods by 12.75% of FDFR scores and 7.25% of ISM scores across two facial benchmarks and two commonly used prompts on average.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext eb24206c-2ee5-4caa-a474-30d66d4f44ccCited by top-tier papers7
- Bypassing Copyright Protection in Diffusion-based Customization via Two-Stage Latent Feature OptimizationZiang Xu, Wenbo Yu, Hongyao Yu, Hao Fang et al.KDD 2026 · 2 citations
- AutoPrompt: Automated Red-Teaming of Text-to-Image Models via LLM-Driven Adversarial PromptsYufan Liu, Wanqian Zhang, Huashan Chen, Lin Wang et al.ICCV 2025 · 1 citation
- Targeted Data Protection for Diffusion Model by Matching Training TrajectoryHojun Lee, Mijin Koo, Yeji Song, Nojun KwakAAAI 2026
- VOID: Defeating Unauthorized Mimicry in Latent Diffusion ModelsChunlin Qiu, Ang Li, Tianxiao Huang, Ruilin Gan et al.USENIX Security 2026
- Variance as a Catalyst: Efficient and Transferable Semantic Erasure Adversarial Attack for Customized Diffusion ModelsJiachen Yang, Yusong Wang, Yanmei Fang, Yunshu Dai et al.ICML 2025
Builds on29
- Learning Transferable Visual Models From Natural Language SupervisionAlec Radford, Jong Wook Kim, Chris Hallacy, Aditya Ramesh et al.ICML 2021 · 47,906 citations
- LoRA: Low-Rank Adaptation of Large Language ModelsEdward J. Hu, Yelong Shen, Phillip Wallis, Zeyuan Allen-Zhu et al.ICLR 2022 · 18,833 citations
- High-Resolution Image Synthesis with Latent Diffusion ModelsRobin Rombach, Andreas Blattmann, Dominik Lorenz, Patrick Esser et al.CVPR 2022 · 13,123 citations
- Photorealistic Text-to-Image Diffusion Models with Deep Language UnderstandingChitwan Saharia, William Chan, Saurabh Saxena, Lala Li et al.NeurIPS 2022 · 8,965 citations
- StyleCLIP: Text-Driven Manipulation of StyleGAN ImageryOr Patashnik, Zongze Wu, Eli Shechtman, Daniel Cohen-Or et al.ICCV 2021 · 1,437 citations
Related papers
- PromptFlare: Prompt-Generalized Defense via Cross-Attention Decoy in Diffusion-Based InpaintingHohyun Na, Seunghoo Hong, Simon S. WooACM MM 2025 · 1 citation
- Perturbing Attention Gives You More Bang for the Buck: Subtle Imaging Perturbations That Efficiently Fool Customized Diffusion ModelsJingyao Xu, Yuetong Lu, Yandong Li, Siyang Lu et al.CVPR 2024 · 8 citations
- Prompt-Agnostic Adversarial Perturbation for Customized Diffusion ModelsCong Wan, Yuhang He, Xiang Song, Yihong GongNeurIPS 2024 · 22 citations
- Anti-DreamBooth: Protecting users from personalized text-to-image synthesisThanh Van Le, Hao Phung, Thuan Hoang Nguyen, Quan Dao et al.ICCV 2023 · 144 citations
- Targeted Attack Improves Protection against Unauthorized Diffusion CustomizationBoyang Zheng, Chumeng Liang, Xiaoyu WuICLR 2025
