Protective Perturbations Must Survive the Resize: Scale-Robust Image Immunization against Malicious Editing

📅 2026-10-05
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the vulnerability of existing image protection perturbations to unknown scaling factors, which undermines their robustness against malicious editing. To overcome this limitation, we propose Scale-Robust Immunization (SRIM), a method that for the first time models image scaling as a frequency-selective channel. Our theoretical analysis reveals that worst-case protection degrades logarithmically with the scaling range. By introducing multi-scale anchor sampling and adaptive dynamic weighting of the weakest scales, SRIM transcends the constraints of fixed-resolution optimization. Evaluated on 9–30MP high-resolution images, SRIM increases the worst-case disruption score against FLUX.2-klein from 0.192 to 0.463, effectively doubling the protective efficacy at equivalent visual imperceptibility. Furthermore, the proposed approach demonstrates strong generalizability across diverse generative models.
📝 Abstract
Protective perturbations aim to stop malicious instruction-guided editing of personal photos, but they are optimized and evaluated at the editor's working resolution, whereas shared photos have 10 megapixels or more and editors first downscale them by an unknown factor. We model this resize as a frequency-selective channel. In this model, a perturbation computed at the native resolution decays with the downscaling factor and is weak even without a resize, and a perturbation computed at a fixed working resolution protects only a window of scales. The best worst-case protection over an unknown range of scales degrades only logarithmically with the width of the range, and averaging over scales does not reach it. Guided by this analysis, we propose SRIM, which samples a grid of anchor scales covering the whole range, with weights that favor the currently weakest scale, at the cost of standard expectation over transformation. On full-resolution photos of 9 to 30 megapixels and downscaling factors from 2 to 8, SRIM raises the worst-case disruption of FLUX.2-klein edits from 0.192 LPIPS, attained by the strongest published protection, to 0.463. At equal visibility, it roughly doubles the protection. The same protected photos also protect against the 9B model and against FLUX.2-dev, with worst cases of 0.450 and 0.386 against at most 0.184 for published protections, and SRIM leads on InstructPix2Pix as well.
Problem

Research questions and friction points this paper is trying to address.

protective perturbations
malicious editing
scale robustness
image downscaling
instruction-guided editing
Innovation

Methods, ideas, or system contributions that make the work stand out.

Scale-Robust Protection
Protective Perturbations
Frequency-Selective Channel
Image Immunization
Adversarial Defense