Finding NeMo: Localizing Neurons Responsible For Memorization in Diffusion Models
Dominik Hintersdorf, Lukas Struppek, Kristian Kersting, Adam Dziedzic, Franziska Boenisch
摘要
Diffusion models (DMs) produce very detailed and high-quality images. Their power results from extensive training on large amounts of data, usually scraped from the internet without proper attribution or consent from content creators. Unfortunately, this practice raises privacy and intellectual property concerns, as DMs can memorize and later reproduce their potentially sensitive or copyrighted training images at inference time. Prior efforts prevent this issue by either changing the input to the diffusion process, thereby preventing the DM from generating memorized samples during inference, or removing the memorized data from training altogether. While those are viable solutions when the DM is developed and deployed in a secure and constantly monitored environment, they hold the risk of adversaries circumventing the safeguards and are not effective when the DM itself is publicly released. To solve the problem, we introduce NeMo, the first method to localize memorization of individual data samples down to the level of neurons in DMs' cross-attention layers. Through our experiments, we make the intriguing finding that in many cases, single neurons are responsible for memorizing particular training samples. By deactivating these memorization neurons, we can avoid the replication of training data at inference time, increase the diversity in the generated outputs, and mitigate the leakage of private and copyrighted data. In this way, our NeMo contributes to a more responsible deployment of DMs.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper11
- Provable Separations between Memorization and Generalization in Diffusion ModelsZeqi Ye, Qijie Zhu, Molei Tao, Minshuo ChenICLR 2026 · 被引用 15 次
- Demystifying Robot Diffusion Policies: Action Memorization and a Simple Lookup Table AlternativeChengyang He, Xu Liu, Gadiel Sznaier Camps, Joseph Bruno 等ICLR 2026 · 被引用 15 次
- Generalization of Diffusion Models Arises with a Balanced Representation SpaceZekai Zhang, Xiao Li, Xiang Li, Lianghe Shi 等ICLR 2026 · 被引用 14 次
- Adjusting Initial Noise to Mitigate Memorization in Text-to-Image Diffusion ModelsHyeonggeun Han, Sehwan Kim, Hyungjun Joo, Sangwoo Hong 等NeurIPS 2025 · 被引用 7 次
- Reconstructing Template-Memorized Images from Natural PromptsSol Yarkoni, Mahmood Sharif, Roi LivniICML 2026 · 被引用 1 次
它引用的顶会 Paper27
- Learning Transferable Visual Models From Natural Language SupervisionAlec Radford, Jong Wook Kim, Chris Hallacy, Aditya Ramesh 等ICML 2021 · 被引用 47,906 次
- Denoising Diffusion Probabilistic ModelsJonathan Ho, Ajay Jain, Pieter AbbeelNeurIPS 2020 · 被引用 35,902 次
- High-Resolution Image Synthesis with Latent Diffusion ModelsRobin Rombach, Andreas Blattmann, Dominik Lorenz, Patrick Esser 等CVPR 2022 · 被引用 13,123 次
- Photorealistic Text-to-Image Diffusion Models with Deep Language UnderstandingChitwan Saharia, William Chan, Saurabh Saxena, Lala Li 等NeurIPS 2022 · 被引用 8,965 次
- Extracting Training Data from Large Language ModelsNicholas Carlini, Florian Tramèr, Eric Wallace, Matthew Jagielski 等USENIX Security 2021 · 被引用 2,866 次
相关 Paper
- Exploring Local Memorization in Diffusion Models via Bright Ending AttentionChen Chen, Daochang Liu, Mubarak Shah, Chang XuICLR 2025
- Finding DoRI: Discovery of Retained Images in Diffusion ModelsAntoni Kowalczuk, Dominik Hintersdorf, Lukas Struppek, Kristian Kersting 等ICML 2026
- You Don’t Need All That Attention: Surgical Memorization Mitigation in Text-to-Image Diffusion ModelsKairan Zhao, Eleni Triantafillou, Peter TriantafillouICML 2026
- Extracting Training Data from Diffusion ModelsNicholas Carlini, Jamie Hayes, Milad Nasr, Matthew Jagielski 等USENIX Security 2023
- Image-level Memorization Detection via Inversion-based Inference PerturbationYue Jiang, Haokun Lin, Yang Bai, Bo Peng 等ICLR 2025
