跳到主要导航 跳到搜索 跳到主要内容

Pretender: Universal Active Defense against Diffusion Finetuning Attacks

  • Zekun Sun
  • , Zijian Liu
  • , Shouling Ji
  • , Chenhao Lin
  • , Na Ruan
  • Shanghai Jiao Tong University
  • Zhejiang University

科研成果: 书/报告/会议事项章节会议稿件同行评审

1 引用 (Scopus)

摘要

The proliferation of Diffusion Models (DMs) has marked a significant advancement in AI-generated image creation. However, this success has also spawned a new form of infringement threat termed the Diffusion Finetuning Attack (DFA), where malicious attackers can finetune pre-trained DMs using minimal resources to illicitly synthesize copyright-infringing images by ‘stealing’ information from personal photographic data or artwork, raising critical concerns about privacy and intellectual property rights. Recognizing the limitations of current defense strategies, which exhibit inadequate generalizability and suboptimal mechanism efficacy, we introduce an universal and effective active defense mechanism that applies subtle protective noise to images, guarding against information theft from DFAs. Our work innovatively conceptualizes active defense as a bi-level optimization problem, focusing on attackers’ common behaviors to enhance the generalization of defense. Guided by this optimization framework, we have developed a novel algorithm named Pretender, where we adversarially trained a surrogate model to facilitate the generation of more effective protective noise. In addition, a Simultaneous Gradient Back-Propagation (SGBP) technique is introduced to significantly enhance computational efficiency. Extensive experiments including real-world evaluations have demonstrated the effectiveness of Pretender. By applying minimal perturbations (p = 0.03), Pretender successfully disrupted the quality and semantics of images synthesized by diverse DFAs, achieving a comprehensive and prominent improvement in various automated evaluation metrics by 22.27% and in human assessment scores by 94.28%.

源语言英语
主期刊名Proceedings of the 34th USENIX Security Symposium
出版商USENIX Association
1017-1036
页数20
ISBN(电子版)9781939133526
出版状态已出版 - 2025
活动34th USENIX Security Symposium, USENIX Security 2025 - Seattle, 美国
期限: 13 8月 202515 8月 2025

丛书

姓名Proceedings of the 34th USENIX Security Symposium

会议

会议34th USENIX Security Symposium, USENIX Security 2025
国家/地区美国
Seattle
时期13/08/2515/08/25

学术指纹

探究 'Pretender: Universal Active Defense against Diffusion Finetuning Attacks' 的科研主题。它们共同构成独一无二的学术指纹。

引用此