DiffUE:通过扩散自动编码器增强不可学习示例的效用-不可学习性权衡
DiffUE: Enhancing Utility-Unlearnability Trade-off of Unlearnable Examples via Diffusion Autoencoders
浏览论文内容
中文总结 AI 辅助
针对AI模型利用个人图像致隐私侵犯问题,DiffUE通过在图像语义空间注入噪声,利用扩散自动编码器框架操纵语义特征,增强图像不可学习性,显著提升了图像质量和不可学习性之间的权衡,保障个人数据安全。
中文摘要 AI 辅助
人工智能模型常未经同意就用社交媒体和公共平台上的个人图像训练,导致隐私侵犯。研究人员开发了不可学习示例(UEs),但现有UE方法主要依赖像素空间噪声,易被重新学习策略绕过,且会牺牲图像效用和感知质量。本文提出DiffUE,通过在图像语义空间而非像素空间注入噪声克服这些局限。DiffUE修改图像高级语义特征,利用基于扩散的自动编码器框架操纵语义特征,生成有目的、自然的修改,有效抵抗高级重新学习策略。在四个数据集及主观用户研究表明,DiffUE显著增强了图像质量和不可学习性之间的权衡。
英文摘要
AI models are increasingly trained on personal images scraped from social media and public platforms, often without consent, leading to serious privacy violations, such as unauthorized facial recognition and targeted advertising. To counter this, researchers have developed unlearnable examples (UEs), images modified with imperceptible noise to prevent AI models from extracting meaningful information. However, existing UE methods primarily rely on pixel-space noise, which can be bypassed by relearning strategies such as adversarial training, image transformation, and compression. While some techniques improve robustness, they often come at the expense of significant degradation in image utility and perceptual quality. In this paper, we introduce DiffUE to overcome these limitations by injecting noise into the semantic space of images instead of the pixel space. Instead of corrupting pixel values, DiffUE modifies high-level semantic features of images, ensuring robust unlearnability while preserving visual quality and utility. By leveraging a diffusion-based autoencoder framework to manipulate semantic features, DiffUE generates purposeful, natural-looking modifications that effectively resist advanced relearning strategies. Extensive experiments on four datasets, CIFAR-10, CIFAR-100, CelebA-HQ, and ImageNet, as well as a subjective user study, demonstrate that DiffUE significantly enhances the trade-off between image quality and unlearnability, offering a more robust and effective solution for safeguarding personal data in an increasingly exploitative AI landscape.
发表机构
- University of Tennessee, Knoxville(田纳西大学诺克斯维尔分校)
- Oak Ridge National University, Knoxville(橡树岭国家实验室诺克斯维尔分部)
- University of Georgia, Athens(佐治亚大学雅典分校)
- Virginia Commonwealth University, Richmond(弗吉尼亚联邦大学里士满分校)
机构由 AI 辅助整理,请以论文原文为准。