Chunlin Qiu, Ang Li, Tianxiao Huang, Ruilin Gan, Yunjie Ge, Shenyi Zhang, Huayi Duan, Lingchen Zhao et al.
VOID is a defense framework that defeats unauthorized mimicry in Latent Diffusion Models (LDMs) by amplifying latent encoding errors and counteracting target guidance signals to induce semantic corruption.
LDMs can be exploited for unauthorized mimicry of individuals (e.g., deepfakes). Existing defenses add deceptive perturbations to steer generated images toward irrelevant targets, but the LDM's innate restoration mechanism removes these perturbations, causing individual identities to re-emerge.
VOID perturbs the LDM's stochastic process in two novel ways: 1) amplifying latent encoding errors to shatter an image's semantic structure, and 2) counteracting target guidance signals to suppress the model's restoration capabilities. This results in semantic corruption that thwarts unauthorized mimicry. Additionally, perturbations are confined to human-imperceptible regions to maintain visual utility.
In a comprehensive evaluation of 24 state-of-the-art defenses against 10 mimicry attacks on 5 datasets, VOID increases the average Frechet Inception Distance (FID) from 113 to 365, a 223% improvement over the strongest defense to date.