SPIN: Image Immunization Against Diffusion Editing via Single-Step Projection in Stochastic Neighborhoods

📅 2026-10-05
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the risk of unauthorized manipulation in diffusion-based image editing and the limitations of existing immunization methods, which suffer from high computational costs and poor generalization. To overcome these challenges, this work proposes SPIN, a protection framework that introduces a local stochastic trajectory neighborhood and a single-step projection mechanism. By eliminating the need for full backpropagation, SPIN efficiently generates bounded input perturbations that maximize deviation from clean editing references, thereby effectively disrupting diverse potential editing outcomes. Experimental results demonstrate that SPIN significantly enhances protection performance across two mainstream editors, consistently outperforming existing baseline methods on all evaluated metrics. Notably, the framework exhibits superior robustness and generalization capabilities, particularly in scenarios involving unseen editing instructions.
📝 Abstract
Diffusion models have greatly advanced instruction-guided image editing, while also raising concerns about unauthorized image manipulation. Image immunization addresses this risk by adding imperceptible perturbations to an input image to disrupt subsequent edits. Since editing requests are unknown at image release, protection should remain effective beyond the instruction used to construct the perturbation. Existing immunization methods either require costly full-trajectory backpropagation or use intermediate objectives whose effects may be weakened by subsequent denoising. Meanwhile, a single inference path provides limited feedback about alternative denoising continuations. To address these challenges, we propose \textsc{SPIN}, a framework for image immunization via one-step projection over local stochastic trajectory neighborhoods. Starting from an early denoising state, \textsc{SPIN} generates stochastic neighboring states under the same instruction and predicts their clean latents through one-step projection without full unrolling. We then optimize a bounded input perturbation to maximize the average deviation of these predictions from a clean-edit reference, encouraging the perturbation to disrupt multiple possible editing outcomes. Experiments on two image editors demonstrate substantial gains in protection performance, with \textsc{SPIN} outperforming compared methods across all six metrics under seen instructions and in the more challenging unseen instruction setting.
Problem

Research questions and friction points this paper is trying to address.

Image Immunization
Diffusion Models
Unauthorized Image Editing
Adversarial Perturbation
Unseen Instructions
Innovation

Methods, ideas, or system contributions that make the work stand out.

Image Immunization
Diffusion Models
Single-Step Projection
Stochastic Neighborhoods
Instruction-Guided Editing
🔎 Similar Papers
F
Fengming Gu
School of Advanced Interdisciplinary Sciences, University of Chinese Academy of Sciences; State Key Laboratory of AI Safety, Institute of Computing Technology, Chinese Academy of Sciences; University of Chinese Academy of Sciences
J
Jie Zhang
State Key Laboratory of AI Safety, Institute of Computing Technology, Chinese Academy of Sciences; University of Chinese Academy of Sciences
Zhongqi Wang
Zhongqi Wang
Institute of Computing Technology, Chinese Academy of Sciences
Model Robustness
Qiankun Li
Qiankun Li
Research Fellow@NTU, Ph.D.@USTC
MLLMAI4HealthComputer VisionPattern RecognitionTrustworthy AI
Shiguang Shan
Shiguang Shan
Professor of Institute of Computing Technology, Chinese Academy of Sciences
Computer VisionPattern RecognitionMachine LearningFace Recognition
Xilin Chen
Xilin Chen
Institute of Computing Technology, Chinese Academy of Sciences
Computer VisionPattern RecognitionMachine Learning