2608.10870v1 Aug 11, 2026 cs.CV

NullEdit: VLM 조건 재지향을 통한 은밀한 이미지 보호

NullEdit: Stealthy Image Protection via VLM Condition Redirection

Wei Lu
Wei Lu
Citations: 220
h-index: 9
Weiyao Huang
Weiyao Huang
Citations: 6
h-index: 1
Liqin Wang
Liqin Wang
Citations: 5
h-index: 1
Ziqi Sheng
Ziqi Sheng
Citations: 83
h-index: 6

최신 이미지 편집기는 비전-언어 모델(VLM)과 디퓨전 트랜스포머 백본을 결합하여, 별도의 추가 훈련 없이 단일 참조 이미지를 수정합니다. 이러한 기능은 공개된 이미지에 대한 무단 조작을 가능하게 합니다. 기존의 추론 시 보호 기술들은 눈에 띄는 왜곡으로 편집을 무효화하여 보호 사실을 노출시키거나, 또는 원본 내용이나 참조 콘텐츠의 변화를 허용하여 편집 자체를 막지 못합니다. 우리는 이러한 문제점을 해결하기 위해, 사용자가 요청한 편집 내용을 은밀하게 억제하고, 눈에 띄는 왜곡이나 대체 없이 자연스럽고 원본 이미지를 보존하며, 악의적인 명령으로 인해 발생할 수 있는 유해한 의미가 제거된 무해한 '무작업(no-op)'을 목표로 합니다. 우리는 VLM이 참조 이미지와 명령어로부터 생성하는 표현을 DiT 백본에 전달하기 전에, NullEdit을 통해 이 표현을 재지향합니다. Normal-edit 및 no-edit 기준점을 사용하여 NullEdit은 이러한 표현을 조작하며, 교차 프롬프트 기울기 평균화는 보호 기능을 알려지지 않은 명령어로 확장합니다. CelebA-HQ 및 VGGFace2 데이터셋에서 Step1X-Edit과 Qwen-Image-Edit 모델에 대해 NullEdit은 SOTA(State-of-the-Art) 기준선 대비 평균 0.813만큼 EditReward IF 점수를 낮추면서, 피사체의 동일성과 원본 콘텐츠를 유지합니다.

Original Abstract

Modern image editors combine vision-language models (VLMs) with diffusion transformer backbones to modify a single reference image according to instructions without fine-tuning. This capability also enables unauthorized manipulation of publicly released images. Existing inference-time defenses either invalidate edits through conspicuous corruption, thereby exposing the protection, or allow them to proceed with identity or reference content drift, thereby failing to prevent the editing behavior itself. We instead target a stealthy and harmless no-op in which the requested edit is suppressed, the output remains natural and source-preserving without conspicuous artifacts or identity replacement, and harmful semantics requested by malicious instructions are absent. We propose NullEdit, which targets the VLM representation jointly formed from the reference image and instruction before it conditions the downstream DiT backbone. Using normal-edit and no-edit anchors, NullEdit redirects this representation, while cross-prompt gradient averaging transfers protection to held out instructions. Across Step1X-Edit and Qwen-Image-Edit on CelebA-HQ and VGGFace2, NullEdit reduces the EditReward IF score by 0.813 on average relative to the SOTA baseline while preserving subject identity and source content.

0 Citations
0 Influential
4.5 Altmetric
22.5 Score
Original PDF

No Analysis Report Yet

This paper hasn't been analyzed by Gemini yet.

Log in to request an AI analysis.

댓글

댓글을 작성하려면 로그인하세요.

아직 댓글이 없습니다. 첫 번째 댓글을 남겨보세요!