Skip to main navigation Skip to search Skip to main content

A Gray-box Attack against Latent Diffusion Model-based Image Editing by Posterior Collapse

  • Zhongliang Guo
  • , Chun Tong Lei
  • , Lei Fang
  • , Shuai Zhao*
  • , Yifei Qian
  • , Jingyu Lin
  • , Zeyu Wang
  • , Cunjian Chen
  • , Ognjen Arandjelović
  • , Chun Pong Lau*
  • *Corresponding author for this work

Research output: Journal Publications and ReviewsRGC 21 - Publication in refereed journalpeer-review

Abstract

Recent advancements in Latent Diffusion Models (LDMs) have revolutionized image synthesis and manipulation, raising significant concerns about data misappropriation and intellectual property infringement. While adversarial attacks have been extensively explored as a protective measure against such misuse of generative AI, current approaches are severely limited by their heavy reliance on model-specific knowledge and substantial computational costs. Drawing inspiration from the posterior collapse phenomenon observed in VAE training, we propose the Posterior Collapse Attack (PCA), a novel framework for protecting images from unauthorized manipulation. Through comprehensive theoretical analysis and empirical validation, we identify two distinct collapse phenomena during VAE inference: diffusion collapse and concentration collapse. Based on this discovery, we design a unified loss function that can flexibly achieve both types of collapse through parameter adjustment, each corresponding to different protection objectives in preventing image manipulation. Our method significantly reduces dependence on model-specific knowledge by requiring access to only the VAE encoder, which constitutes less than 4% of LDM parameters. Notably, PCA achieves prompt-invariant protection by operating on the VAE encoder before text conditioning occurs, eliminating the need for empty prompt optimization required by existing methods. This minimal requirement enables PCA to maintain adequate transferability across various VAE-based LDM architectures while effectively preventing unauthorized image editing. Extensive experiments show PCA outperforms existing techniques in protection effectiveness, computational efficiency (runtime and VRAM), and generalization across VAE-based LDM variants. © 2005-2012 IEEE.
Original languageEnglish
Pages (from-to)12918-12933
Number of pages16
JournalIEEE Transactions on Information Forensics and Security
Volume20
Online published3 Dec 2025
DOIs
Publication statusPublished - 2025

Research Keywords

  • Adversarial attack
  • diffusion model
  • imperceptible attack
  • transferable attack

Fingerprint

Dive into the research topics of 'A Gray-box Attack against Latent Diffusion Model-based Image Editing by Posterior Collapse'. Together they form a unique fingerprint.

Cite this