Score
Designs and implements perturbation methods that are constrained by spatial or semantic masks to alter only specified regions of an image or other spatial data; builds mask-generation and enforcement mechanisms and optimization procedures to produce targeted changes. Analyzes containment and visual-quality metrics to prevent spillover into excluded areas and to evaluate tradeoffs between localized effect strength and overall visual integrity.
The field of diffusion model-based image editing lacks a systematic, unified taxonomy and evaluation framework. Method: This paper introduces the first four-dimensional analytical framework—encompassing task formalization, method categorization, evaluation metrics, and benchmark datasets—and innovatively classifies editing approaches into three paradigms: inversion-based, fine-tuning-based, and adapter-based methods. It further establishes a comprehensive survey of evaluation protocols and datasets covering all major editing paradigms. Contribution/Results: Based on a distilled analysis of over 100 representative works, the paper delineates performance boundaries and application scopes for each paradigm, proposes multi-granularity evaluation techniques, and unifies key technical components—including latent-space inversion, parameter-efficient fine-tuning (PEFT), and adapter architectures. The framework advances standardization, reproducibility, and systematic progress in diffusion-based image editing research.
This paper systematically evaluates the effectiveness of perturbation-based image protection methods against text-guided editing in diffusion models. Addressing the central question—“Can imperceptible noise perturbations impede text-driven image editing?”—we conduct empirical studies across multiple tasks (e.g., image-to-image translation, style transfer) and domains (natural scenes and artistic images) on mainstream diffusion models, including Stable Diffusion. Contrary to conventional assumptions, our results demonstrate that existing perturbation methods fail to provide robust protection; instead, they consistently improve editing fidelity and prompt alignment. We further uncover a previously unrecognized phenomenon: perturbations strengthen implicit semantic alignment between protected images and textual prompts—a counterintuitive “protection paradox.” This finding fundamentally challenges the prevailing protection paradigm grounded solely in perceptual invisibility. Our work provides critical theoretical insights and practical implications for designing robust image copyright protection mechanisms in the era of generative AI.
This study addresses the vulnerability of existing image protection perturbations to unknown scaling factors, which undermines their robustness against malicious editing. To overcome this limitation, we propose Scale-Robust Immunization (SRIM), a method that for the first time models image scaling as a frequency-selective channel. Our theoretical analysis reveals that worst-case protection degrades logarithmically with the scaling range. By introducing multi-scale anchor sampling and adaptive dynamic weighting of the weakest scales, SRIM transcends the constraints of fixed-resolution optimization. Evaluated on 9–30MP high-resolution images, SRIM increases the worst-case disruption score against FLUX.2-klein from 0.192 to 0.463, effectively doubling the protective efficacy at equivalent visual imperceptibility. Furthermore, the proposed approach demonstrates strong generalizability across diverse generative models.
The intrinsic mechanisms underlying adversarial perturbations in image protection methods—such as Glaze and Nightshade—remain poorly understood. Method: We propose a unified, interpretable AI analysis framework integrating white-box feature-space analyses (latent clustering, channel-wise activation profiling, and occlusion sensitivity mapping) with black-box frequency-domain probing. Results: We find that protective perturbations do not semantically corrupt images but instead redistribute energy along dominant frequency axes, inducing low-entropy, structured feature deformations tightly coupled to the original content representation. Their visual imperceptibility stems from spatial-domain amplitude constraints, whereas detectability arises from highly organized signal patterns in both spectral and feature spaces. Crucially, we establish—for the first time—that protection strength positively correlates with structural detectability, contradicting the conventional “stronger = more concealed” assumption. This insight establishes a new paradigm for verifiable digital watermarking and secure generative model design.
Existing image immunization evaluation overly relies on pixel-level similarity, neglecting the core objective—disrupting semantic alignment between the attacker’s intent and the edited output. Method: We propose a new paradigm where immunization succeeds if the output exhibits semantic mismatch with the prompt or suffers significant perceptual degradation. To this end, we formally define immunization success criteria and introduce Synergistic Intermediate Feature Manipulation (SIFM), a diffusion-model-based technique that jointly optimizes intermediate-layer representations to maximize trajectory divergence while minimizing feature norm—thereby achieving semantic interference under quality constraints. We further design the Immunization Success Rate (ISR) metric, leveraging multimodal large language models (MLLMs) to jointly assess semantic consistency and perceptual quality. Contribution/Results: Our approach achieves state-of-the-art performance across multiple benchmarks, demonstrating strong robustness and generalization against diverse text-driven malicious editing attacks.
To address copyright infringement and artistic style appropriation risks posed by diffusion models, this paper proposes a visually lossless copyright protection method. The approach comprises three key contributions: (1) perception-sensitive map-guided instance-aware fine-tuning, enabling fine-grained stylistic perturbation; (2) difficulty-aware dynamic intensity modulation, which adaptively adjusts perturbation magnitude based on the sample’s stylistic mimicability; and (3) a multi-scale perceptual constraint library, jointly optimizing defense robustness and image fidelity. Without introducing perceptible visual artifacts, the method achieves over 92% style imitation suppression, reduces LPIPS by 41%, and improves FID by 27%, significantly outperforming existing state-of-the-art methods.
Existing image watermarking methods exhibit insufficient robustness under semantic-level edits and lack systematic evaluation. This work proposes a multi-stage stress-testing framework that leverages off-the-shelf models for object detection, semantic segmentation, and image inpainting or generation to construct controllable semantic editing pipelines. For the first time, it systematically reveals the detrimental impact of semantic manipulations on embedded watermarks. Experimental results demonstrate that even when edited images retain high visual fidelity, the detection rates of mainstream watermarking schemes plummet to near zero, exposing a critical gap in current evaluation protocols: the neglect of semantic robustness.
To address the security vulnerability of text-to-image diffusion models—where malicious text prompts can be exploited to generate harmful content during text-driven editing—this paper proposes a dual-attention-guided noise perturbation immunization method. Our approach simultaneously perturbs both the cross-attention mechanism and noise prediction across multiple denoising steps. It introduces a novel dynamic-threshold masking scheme that inversely modulates attention weights over text-relevant and text-irrelevant image regions, while maximizing semantic divergence between injected perturbations and the model’s predicted noise. By integrating cross-attention analysis, temporal noise perturbation optimization, dynamic mask generation, and attention reweighting, our method achieves fine-grained, semantics-aware defense. Evaluated on multiple benchmarks, it significantly reduces adversarial editing success rates—outperforming all prior state-of-the-art defenses—while preserving original editing fidelity and maintaining visual imperceptibility.
This work addresses common limitations in image segmentation models—such as ambiguous boundaries, semantic inconsistency, and structural errors—by introducing the Phoenix framework. Phoenix generates semantically aware noise through adversarial mask perturbations to simulate realistic segmentation errors and employs a contrastive learning–based tripartite refinement mechanism that simultaneously enhances intra-class feature consistency and inter-class separability. Integrating adversarial learning, embedding attacks, and relational modeling, Phoenix operates as a plug-and-play module without requiring modifications to the backbone architecture. Extensive experiments demonstrate that Phoenix consistently outperforms existing approaches across diverse segmentation tasks, delivering substantial improvements in mask quality and reliably boosting the performance of state-of-the-art models.
This work addresses the challenges of region-based image editing—namely precise spatial localization, preservation of background consistency, and seamless boundary blending—by introducing MaskFlow, a novel framework that integrates mask information into the flow-matching generative process for the first time. MaskFlow employs mask-guided probabilistic paths to jointly regulate content generation within editable regions and preservation outside them. Furthermore, it incorporates a Soft-Poisson de-blending module to refine the vector field, enabling natural fusion between foreground and background. Coupled with a mask-driven MEData synthesis strategy, the proposed method consistently outperforms existing approaches on both natural images and infographics, with quantitative and qualitative results demonstrating superior performance in editing accuracy, background fidelity, and boundary seamlessness.
Existing one-step image editing methods lack explicit spatial control, making it challenging to achieve strong semantic and structurally consistent modifications within user-specified regions. This work proposes a locally adaptive editing framework that leverages a mask-aware mechanism to automatically identify semantically relevant areas and applies adaptive modulation in the latent space to precisely edit only the target region while preserving the rest of the image unchanged. By integrating internal feature-driven editable region discovery, localized latent modulation, and spatial constraints, the method significantly outperforms current one-step approaches on PIE-Bench, striking an effective balance between editing fidelity and computational efficiency. These results underscore the critical role of explicit spatial reasoning in enabling high-quality image editing.