arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

I2VShield:一种针对基于DiT的图像到视频模型的高效主动防御框架

I2VShield: An Efficient Proactive Defense Framework against DiT-based Image-to-Video Models

Yimao Guo, Zuomin Qu, Wei Lu

arXiv 2607.25522首次发表:更新:

发表机构

School of Computer Science and Engineering, Sun Yat-sen University(中山大学计算机科学与工程学院)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

针对I2V模型被滥用问题,提出I2VShield主动防御框架。其包含文本自适应扰动生成框架和非目标多模态注意力干扰攻击两部分。该方法在多数据集和模型上保护性能优,能破坏时空连贯性且降低计算成本。

AI 中文摘要

视频生成模型的快速发展导致图像到视频(I2V)模型被滥用。虽然在检测人工智能生成的视频方面取得了很大进展,但针对I2V模型的主动防御仍未得到充分探索。当前针对I2V模型的主动防御主要依赖基于梯度的对抗攻击,这要求防御者拥有具有大量内存资源(VRAM)的GPU来生成对抗样本。为解决此问题,我们提出I2VShield,一种基于生成对抗攻击的隐私保护方法,适用于基于扩散变压器(DiT)的I2V模型。该方法主要由两个部分组成:(1)一个集成对抗学习的文本自适应扰动生成框架,以减轻计算开销并保持视觉不可感知性;(2)一种非目标多模态注意力干扰(MAD)攻击,利用基于DiT的I2V模型的固有漏洞,使内部注意力特征与干净状态的偏差最大化。大量实验表明,我们的方法在各种数据集和主流基于DiT的I2V模型上实现了极具竞争力的保护性能,特别是在破坏时空连贯性方面,同时大幅降低了计算成本。

英文摘要

The rapid advancement of video generation models has led to the increasing misuse of image-to-video (I2V) models. Although substantial progress has been made in detecting AI-generated videos, proactive defenses against I2V models remain underexplored. In particular, current proactive defenses against I2V models predominantly rely on gradient-based adversarial attacks, which require defenders to possess GPUs with substantial memory resources (VRAM) to generate adversarial examples. To address this issue, we propose I2VShield, a privacy protection method based on generative adversarial attacks tailored to Diffusion Transformer (DiT)-based I2V models. The proposed method primarily consists of two components: (1) a text-adaptive perturbation generation framework integrating adversarial learning to mitigate computational overhead while maintaining visual imperceptibility; and (2) an untargeted Multimodal Attention Disruption (MAD) attack that exploits the inherent vulnerabilities of DiT-based I2V models, maximizing the deviation of the internal attention features from their clean states. Extensive experiments demonstrate that our approach achieves highly competitive protection performance across various datasets and mainstream DiT-based I2V models, particularly in disrupting spatiotemporal coherence, while substantially reducing computational costs.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑