保护性扰动必须经受住缩放:针对恶意编辑的尺度鲁棒图像免疫
Protective Perturbations Must Survive the Resize: Scale-Robust Image Immunization against Malicious Editing
浏览论文内容
中文总结 AI 辅助
针对恶意编辑的保护性扰动在缩放后失效的问题,提出尺度鲁棒免疫方法SRIM,通过覆盖全尺度范围的锚定采样提升最坏情况保护,显著优于现有方法。
中文摘要 AI 辅助
保护性扰动旨在阻止恶意指令引导的个人照片编辑,但它们是在编辑器的工 作分辨率下进行优化和评估的,而共享照片的分辨率可达1000万像素或更高,编辑器会首先以未知因子对它们进行下采样。我们将这种缩放建模为频率选择性信道。在该模型中,在原始分辨率下计算的扰动会随下采样因子衰减,即使没有缩放也很弱,而在固定工作分辨率下计算的扰动仅能保护一个尺度窗口。在未知尺度范围内,最坏情况下的最优保护随范围宽度的增加仅呈对数级下降,而跨尺度平均无法达到该最优值。基于这一分析,我们提出了SRIM,它采样覆盖整个范围的锚定尺度网格,权重偏向当前最弱的尺度,以标准期望变换为代价。在9至30百万像素的全分辨率照片上,下采样因子为2至8时,SRIM将FLUX.2-klein编辑的最坏情况破坏从最强已发表保护所达到的0.192 LPIPS提升至0.463。在相同可见度下,保护效果大约翻倍。相同的受保护照片还能抵御9B模型和FLUX.2-dev,最坏情况分别为0.450和0.386,而已发表保护的最坏情况至多为0.184,并且SRIM在InstructPix2Pix上也领先。
英文摘要
Protective perturbations aim to stop malicious instruction-guided editing of personal photos, but they are optimized and evaluated at the editor's working resolution, whereas shared photos have 10 megapixels or more and editors first downscale them by an unknown factor. We model this resize as a frequency-selective channel. In this model, a perturbation computed at the native resolution decays with the downscaling factor and is weak even without a resize, and a perturbation computed at a fixed working resolution protects only a window of scales. The best worst-case protection over an unknown range of scales degrades only logarithmically with the width of the range, and averaging over scales does not reach it. Guided by this analysis, we propose SRIM, which samples a grid of anchor scales covering the whole range, with weights that favor the currently weakest scale, at the cost of standard expectation over transformation. On full-resolution photos of 9 to 30 megapixels and downscaling factors from 2 to 8, SRIM raises the worst-case disruption of FLUX.2-klein edits from 0.192 LPIPS, attained by the strongest published protection, to 0.463. At equal visibility, it roughly doubles the protection. The same protected photos also protect against the 9B model and against FLUX.2-dev, with worst cases of 0.450 and 0.386 against at most 0.184 for published protections, and SRIM leads on InstructPix2Pix as well.
发表机构
- University of Aberdeen(阿伯丁大学)
- Newcastle University(纽卡斯尔大学)
- University of Nottingham(诺丁汉大学)
- Wuhan University(武汉大学)
机构由 AI 辅助整理,请以论文原文为准。