AI 中文总结
针对前沿AI图像编辑模型的滥用问题,提出抗编辑伪装VETO,引入评估基准VetoBench,实验显示其在保护与保真度权衡上优于现有防御。
AI 中文摘要
FLUX.2等强大且易用的图像编辑模型的兴起,让高保真编辑触达更广泛人群。这些模型的能力已超出局部修改范畴,可在全新场景中提取并重构物体与身份,通过让提示词和生成词直接关注参考图像词,现代模型模糊了传统编辑与文本到图像合成的界限。这种扩展的生成自由也扩大了潜在滥用空间,有害转换不再局限于可预测的局部编辑。现有抗编辑防御旨在破坏传统扩散流水线中参考图像编码的语义瓶颈,但新型编辑模型通过联合注意力模块提炼参考信息,常可规避这些保护。因此我们引入VETO,一种微妙的抗编辑伪装,可破坏现代模型读取源图像的内部机制。此外,由于现有编辑基准基本未测试全面重构任务,我们引入VetoBench,该基准不仅在传统局部编辑上评估防御,还在更广泛的上下文变化上评估。在两个当代编辑模型和三个基准上,VETO始终优于现有防御,同时提供更优的保护-保真度权衡。
英文摘要
The rise of powerful, accessible image-editing models such as FLUX.2 has brought high-fidelity editing within broad reach. Their capabilities now extend beyond localized modifications to extracting and recontextualizing objects and identities in entirely new scenes. By allowing prompt and generation tokens to attend directly to reference-image tokens, modern models blur the boundary between conventional editing and text-to-image synthesis. This expanded generative freedom also broadens the space of potential misuse, as harmful transformations are no longer confined to a predictable set of localized edits. Existing anti-edit defenses are designed to disrupt the semantic bottleneck of the reference-image encoding in legacy diffusion pipelines. However, newer editors distill reference information through joint-attention blocks, thereby often circumventing these protections. We therefore introduce VETO, a subtle anti-edit cloak that disrupts this inner mechanism through which modern models read the source image. Additionally, as existing editing benchmarks leave comprehensive recontextualizations largely untested, we introduce VetoBench, which evaluates defenses not only on conventional localized edits but also on broader contextual shifts. Across two contemporary editing models and three benchmarks, VETO consistently outperforms existing defenses while providing a stronger protection-fidelity trade-off.