Protective perturbations aim to stop malicious instruction-guided editing of personal photos, but they are optimized and evaluated at the editor's working resolution, whereas shared photos have 10 megapixels or more and editors first downscale them by an unknown factor. We model this resize as a frequency-selective channel. In this model, a perturbation computed at the native resolution decays with the downscaling factor and is weak even without a resize, and a perturbation computed at a fixed working resolution protects only a window of scales. The best worst-case protection over an unknown range of scales degrades only logarithmically with the width of the range, and averaging over scales does not reach it. Guided by this analysis, we propose SRIM, which samples a grid of anchor scales covering the whole range, with weights that favor the currently weakest scale, at the cost of standard expectation over transformation. On full-resolution photos of 9 to 30 megapixels and downscaling factors from 2 to 8, SRIM raises the worst-case disruption of FLUX.2-klein edits from 0.192 LPIPS, attained by the strongest published protection, to 0.463. At equal visibility, it roughly doubles the protection. The same protected photos also protect against the 9B model and against FLUX.2-dev, with worst cases of 0.450 and 0.386 against at most 0.184 for published protections, and SRIM leads on InstructPix2Pix as well.
Figures & tables
Figure 2 : Measured transfer of FLUX.2-klein to band-pass noise added at its working resolution (eight development photos at a 1024-pixel long side; two noise levels). Edit LPIPS (left axis) is largest at the lowest frequencies and decays toward the Nyquist frequency, whereas the VAE latent deviation (right axis) peaks near ν≈0.2 .
FLUX.2-klein 4B
FLUX.2-klein 9B
FLUX.2-dev
InstructPix2Pix
Method
Avg.
Worst
Avg.
Worst
Avg.
Worst
Avg.
Worst
PhotoGuard@1MP
0.131
0.077
0.133
0.082
–
–
0.173
0.107
PhotoGuard+EOT
0.240
0.171
0.224
0.161
0.221
0.157
0.218
0.163
Mist@1MP
0.163
0.097
0.157
0.096
–
–
0.191
0.129
Mist+EOT
0.283
0.192
0.269
0.184
0.238
0.166
0.238
0.183
PCA@1MP
0.130
0.077
0.130
0.080
0.108
0.072
0.183
0.115
Table 1 : Protection of full-resolution photos (median 11.3 megapixels) against downscaling by an unknown factor ( ϵ=4/255 ). Edit LPIPS between the edit of the protected photo and the edit of the clean photo (higher is better), averaged over photos and instructions. Avg. and Worst average or minimize it over the downscaling factors (FLUX.2-klein 4B: s∈{2,3,4,6,8} ; FLUX.2-klein 9B: s∈{2,3,4,6,8} ; FLUX.2-dev: s∈{3,4,6,8} ; InstructPix2Pix: s∈{4,6,8} ). “Ours-obj.” uses our objective without the worst-case scale sampling. On FLUX.2-dev, PCA@1MP represents the protections applied at one megapixel (–: not evaluated). Native-resolution application of the baselines exceeds the memory of a 48 GB GPU and is not reported.
Figure 3 : Selected examples of real edits by the FLUX.2 editors at the largest downscaling ( s=8 ). The instruction is “Make it snowy winter” in rows 1 to 3 and “Turn this photo into a watercolor painting” in row 4; cells are center-cropped to squares. Badges give the edit LPIPS to the edit of the unprotected photo (higher means a stronger disruption). The published protections with EOT leave the edits close to the edit of the unprotected photo, while SRIM disrupts them. More selected examples for each FLUX.2 editor are in Section S3 of the supplementary material.
Figure 4 : Edit LPIPS at each downscaling factor on the four editors (mean over photos and instructions, the records of Tab. 1 ). PCA@1MP stands for the published protections applied at one megapixel, and Mist+EOT for the strongest published protection with EOT.
Figure 5 : Protection against visibility on FLUX.2-klein (40 test photos; ϵ∈{2,4,6,8}/255 ). Worst-case edit LPIPS over s∈{2,4,8} against the LPIPS between the protected and the clean photo viewed at one megapixel (left) and against PSNR at the native resolution (right).
Figure 6 : Lower visibility, stronger protection: selected examples on FLUX.2-klein at s=8 . Each row shows a native-resolution crop ( 128×128 pixels) of a photo protected by SRIM at ϵ=2/255 and its edit, and the same crop protected by the best published protection at ϵ=8/255 and its edit. Badges give the PSNR of the whole protected photo and the edit LPIPS to the edit of the unprotected photo.
+EOT
Processing
SRIM
Ours-obj.
Mist
PCA
PhotoGuard
Lanczos (default)
0.398
0.360
0.166
0.130
0.144
Bicubic
0.397
0.354
0.161
0.129
0.142
Box
0.397
0.348
0.163
0.126
0.140
JPEG 75
0.150
0.120
0.101
0.086
0.095
Gaussian blur, r=1
0.284
0.213
0.113
0.095
0.109
Table 2 : Worst-case edit LPIPS on FLUX.2-klein (40 test photos, s∈{2,4,8} ) when the editor downscales with different filters of the Python Imaging Library (top), and when an adversary purifies the downscaled input before editing (bottom). The purifications are JPEG compression, Gaussian blur, Gaussian noise followed by JPEG, and an encode-decode round trip through the FLUX.2 VAE, the surrogate of all protections. Optimization uses differentiable bicubic, bilinear, and area filters.
τ
Avg.
Worst
0.03
0.428
0.395
0.1 (default)
0.429
0.398
0.3
0.428
0.402
10
0.424
0.406
EOT
0.408
0.360
Table 3 : Effect of the temperature τ of the anchor distribution (FLUX.2-klein, 40 test photos, s∈{2,4,8} ).
LPIPS ↑ at s=
mean over s
Method
2
3
4
6
8
PSNR ↓
SSIM ↓
CLIP-I ↓
PhotoGuard@1MP
0.186
0.164
0.131
0.097
0.077
23.98
0.863
0.981
PhotoGuard+EOT
0.281
0.267
0.260
0.224
0.171
20.11
0.770
0.951
Mist@1MP
0.222
0.201
0.168
0.128
0.097
22.65
0.835
0.977
Mist+EOT
0.323
0.319
0.307
0.274
0.192
19.46
0.744
0.949
PCA@1MP
0.189
0.163
0.129
0.094
0.077
23.97
0.864
0.981
Table S1 : FLUX.2-klein 4B, per downscaling factor (160 photos, two instructions). LPIPS, higher is better; PSNR, SSIM, and CLIP-I between the two edits, lower is better.
LPIPS ↑ at s=
mean over s
Method
2
3
4
6
8
PSNR ↓
SSIM ↓
CLIP-I ↓
PhotoGuard@1MP
0.180
0.167
0.136
0.100
0.082
24.52
0.828
0.982
PhotoGuard+EOT
0.259
0.249
0.242
0.208
0.161
21.10
0.748
0.962
Mist@1MP
0.206
0.195
0.168
0.123
0.096
23.53
0.805
0.980
Mist+EOT
0.308
0.304
0.293
0.255
0.184
19.97
0.716
0.958
PCA@1MP
0.177
0.164
0.134
0.095
0.080
24.67
0.831
0.983
Table S2 : FLUX.2-klein 9B, per downscaling factor (160 photos, two instructions). LPIPS, higher is better; PSNR, SSIM, and CLIP-I between the two edits, lower is better.
LPIPS ↑ at s=
mean over s
Method
3
4
6
8
PSNR ↓
SSIM ↓
CLIP-I ↓
PhotoGuard+EOT
0.244
0.251
0.230
0.157
20.41
0.822
0.955
Mist+EOT
0.271
0.270
0.245
0.166
19.80
0.809
0.953
PCA@1MP
0.147
0.118
0.096
0.072
25.29
0.904
0.979
PCA+EOT
0.276
0.280
0.254
0.161
19.57
0.802
0.949
Ours-obj.+EOT
0.471
0.475
0.438
0.319
15.91
0.669
0.889
Table S3 : FLUX.2-dev, per downscaling factor (160 photos, two instructions). LPIPS, higher is better; PSNR, SSIM, and CLIP-I between the two edits, lower is better.
LPIPS ↑ at s=
mean over s
Method
4
6
8
PSNR ↓
SSIM ↓
CLIP-I ↓
PhotoGuard@1MP
0.249
0.164
0.107
24.27
0.790
0.960
PhotoGuard+EOT
0.266
0.226
0.163
22.01
0.744
0.948
Mist@1MP
0.263
0.180
0.129
23.85
0.771
0.952
Mist+EOT
0.291
0.242
0.183
22.15
0.724
0.942
PCA@1MP
0.262
0.172
0.115
24.17
0.783
0.960
Table S4 : InstructPix2Pix, per downscaling factor (160 photos, two instructions). LPIPS, higher is better; PSNR, SSIM, and CLIP-I between the two edits, lower is better.
ϵ=2/255
ϵ=4/255
ϵ=6/255
ϵ=8/255
Method
Avg.
Worst
PSNR
Avg.
Worst
PSNR
Avg.
Worst
PSNR
Avg.
Worst
PSNR
PhotoGuard+EOT
0.146
0.096
44.3
0.195
0.144
39.0
0.226
0.175
36.1
0.247
0.198
33.8
Mist+EOT
0.175
0.103
43.8
0.242
0.166
38.5
0.288
0.211
35.6
0.321
0.246
33.3
PCA+EOT
0.155
0.093
44.0
0.191
0.130
38.6
0.216
0.154
35.6
0.234
0.173
33.3
Ours-obj.+EOT
0.334
0.266
43.4
0.408
0.360
37.9
0.443
0.408
35.0
0.468
0.441
32.8
SRIM
0.356
0.336
43.3
0.429
0.398
37.8
0.461
0.430
34.9
0.482
0.455
32.7
Table S5 : Budget sweep on FLUX.2-klein 4B (40 test photos, s∈{2,4,8} ). Edit LPIPS (higher is better) and PSNR of the protected photo in dB.
Method
PSNR (native) ↑
SSIM (native) ↑
LPIPS at 1 MP ↓
PhotoGuard@1MP
39.26
0.966
0.087
PhotoGuard+EOT
39.20
0.956
0.067
Mist@1MP
39.11
0.965
0.100
Mist+EOT
38.64
0.955
0.153
PCA@1MP
38.98
0.963
0.117
PCA+EOT
38.72
0.954
0.124
Table S6 : Visibility of the protection at ϵ=4/255 (40 test photos): PSNR and SSIM between the protected and the clean photo at the native resolution, and LPIPS between them after downscaling both to one megapixel.
Figure S1 : Selected examples of real edits by FLUX.2-klein 4B (row labels give the downscaling factor and the instruction, “Turn this photo into a watercolor painting” or “Make it snowy winter”; cells are center-cropped to squares). Badges give the edit LPIPS to the edit of the unprotected photo.
Figure S2 : Selected examples of real edits by FLUX.2-klein 9B (row labels give the downscaling factor and the instruction, “Turn this photo into a watercolor painting” or “Make it snowy winter”; cells are center-cropped to squares). Badges give the edit LPIPS to the edit of the unprotected photo.
Figure S3 : Selected examples of real edits by FLUX.2-dev (row labels give the downscaling factor and the instruction, “Turn this photo into a watercolor painting” or “Make it snowy winter”; cells are center-cropped to squares). Badges give the edit LPIPS to the edit of the unprotected photo.
Diffusion models have greatly advanced instruction-guided image editing, while also raising concerns about unauthorized image manipulation. Image immunization addresses this risk by adding imperceptible perturbations to an input image to disrupt subsequent edits. Since editing requests are unknown at image release, protection should remain effective beyond the instruction used to construct the perturbation. Existing immunization methods either require costly full-trajectory backpropagation or use intermediate objectives whose effects may be weakened by subsequent denoising. Meanwhile, a single inference path provides limited feedback about alternative denoising continuations. To address these challenges, we propose \textsc{SPIN}, a framework for image immunization via one-step projection over local stochastic trajectory neighborhoods. Starting from an early denoising state, \textsc{SPIN} generates stochastic neighboring states under the same instruction and predicts their clean latents through one-step projection without full unrolling. We then optimize a bounded input perturbation to maximize the average deviation of these predictions from a clean-edit reference, encouraging the perturbation to disrupt multiple possible editing outcomes. Experiments on two image editors demonstrate substantial gains in protection performance, with \textsc{SPIN} outperforming compared methods across all six metrics under seen instructions and in the more challenging unseen instruction setting.
Fengming Gu, Jie Zhang, Zhongqi Wang +3
School of Advanced Interdisciplinary Sciences, University of Chinese Academy of Sciences · State Key Laboratory of AI Safety, Institute of Computing Technology, Chinese Academy of Sciences · University of Chinese Academy of Sciences +1
Proactive defense methods protect portrait images from unauthorized editing or talking face generation (TFG) by introducing pixel-level protective perturbations, and have already attracted increasing attention for privacy protection. In real-world scenarios, images inevitably undergo various transformations during cross-device display and dissemination--such as scale transformations and color compression--that directly alter pixel values. However, it remains unclear whether such pixel-level modifications affect the effectiveness of existing proactive defense methods that rely on pixel-level perturbations. To solve this problem, we conduct a systematic evaluation of representative proactive defenses under image transformation. The evaluated methods are selected to span different generation architectures such as diffusion and GAN-based models, as well as defense scopes covering both portrait and natural images, and are assessed using both qualitative and quantitative metrics for subjective and objective comparison. Experimental results indicate that defense methods based on pixel-level perturbations struggle to withstand common image transformations, posing a risk of defense failure in real-world applications. To further highlight this risk, we propose a simple yet effective purification framework by leveraging the vulnerabilities induced by real-world image transformations. Experimental results demonstrate that the proposed method can efficiently remove protective perturbations with low computational cost, highlighting previously overlooked risks to the research community.
Modern image editors combine vision-language models (VLMs) with diffusion transformer backbones to modify a single reference image according to instructions without fine-tuning. This capability also enables unauthorized manipulation of publicly released images. Existing inference-time defenses either invalidate edits through conspicuous corruption, thereby exposing the protection, or allow them to proceed with identity or reference content drift, thereby failing to prevent the editing behavior itself. We instead target a stealthy and harmless no-op in which the requested edit is suppressed, the output remains natural and source-preserving without conspicuous artifacts or identity replacement, and harmful semantics requested by malicious instructions are absent. We propose NullEdit, which targets the VLM representation jointly formed from the reference image and instruction before it conditions the downstream DiT backbone. Using normal-edit and no-edit anchors, NullEdit redirects this representation, while cross-prompt gradient averaging transfers protection to held out instructions. Across Step1X-Edit and Qwen-Image-Edit on CelebA-HQ and VGGFace2, NullEdit reduces the EditReward IF score by 0.813 on average relative to the SOTA baseline while preserving subject identity and source content.
Weiyao Huang, Liqin Wang, Ziqi Sheng +1
School of Computer Science and Engineering, Sun Yat-sen University, Guangzhou, China