🤖 AI Summary
This work addresses the challenge that visual content owners lose control over downstream usage once their data enters AI pipelines. To counter this, the paper proposes a holistic “beneficial adversarial attack” defense paradigm spanning the entire lifecycle of visual content, systematically integrating five directions: privacy filtering, unlearnable examples, generative protection, adversarial CAPTCHA, and provenance tracing. Through a unified evaluation framework, the authors conduct systematic experiments assessing transferability, adaptability, and deployment readiness, revealing that existing methods are largely confined to static or weakly adaptive adversaries and lack validation in real-world scenarios. The study further distills cross-stage collaborative defense strategies and identifies key open problems toward building robust, composable, and deployable user-side protection mechanisms.
📝 Abstract
Once visual content enters an AI pipeline, its owner often retains little technical control over how it is used. Legal and regulatory remedies can address misuse, but many technical interventions must be applied earlier, when content is released or accessed. This survey examines the protective paradigm that has grown around this intervention point, which we call \emph{adversarial attacks for good}. Perturbations and structured signals long studied as attacks on learned models are instead applied by data owners, creators, platforms, or auditors to disrupt unauthorized automation or support later accountability. Five research communities have arrived at this inversion largely independently, each addressing a different stage of a visual asset's lifecycle: privacy filters against unwanted recognition at sharing time, unlearnable examples against unauthorized training, generative safeguards against malicious editing or imitation, adversarial CAPTCHAs for access control against automated agents, and provenance mechanisms for post-circulation attribution. Although developed in separate venues with incompatible success criteria, many of these methods exploit persistent gaps between human perception, semantic interpretation, and machine inference, suggesting that the paradigm remains relevant as visual pipelines evolve toward multimodal models and autonomous agents. To make their claims comparable, we evaluate all five families along shared axes of transferability, adaptability, and deployment readiness. Across the lifecycle, we find that most protections are still validated mainly against static or weakly adaptive adversaries, while evidence beyond controlled benchmarks remains scarce. We close by consolidating cross-stage countermeasures and open problems for robust, composable, and deployable owner-side protection.