acceptodds
Under review as a conference paper at ICLR 2027

Key-Recoverable Conditional Flow Hijacking: Authorization-Aware Image Protection for DiT-Based In-Context Editing

Abstract

DiT-based in-context image editing has emerged as a powerful paradigm, but also enables unauthorized identity-preserving image manipulation, raising privacy and misuse concerns. Existing perturbation-based protections typically disrupt reference use indiscriminately, so legitimate users also lose the ability to perform reference-consistent editing once an image is protected. This motivates a more practical authorization-aware protection paradigm, moving beyond indiscriminate protection toward selective control over reference use. To this end, we introduce Key-Recoverable Conditional Flow Hijacking, an authorization-aware image protection framework for DiT-based in-context editing, where the same protected image blocks unauthorized reference-consistent editing while allowing authorized users to recover this capability with a valid credential. Our key insight is that the native visual- and text-conditioning pathways of a DiT act through different inputs but jointly influence the same target editing process, allowing a visual perturbation and a key embedding to form an asymmetric control pair. The visual perturbation disrupts unauthorized reference-conditioned editing, while the key embedding re-enables reference-consistent editing for authorized users. Our method only optimizes the protected image and its key embedding, leaving the pretrained editor unchanged and avoiding the cost of retraining or deploying an auxiliary recovery model. Experiments on FLUX.1-Kontext with CelebA-HQ and VGGFace2 demonstrate strong unauthorized protection and effective authorized recovery across standard and diverse editing prompts. For example, on CelebA-HQ under diverse edits, identity similarity drops from 0.78 for clean editing to 0.26 without the key and recovers to 0.68 with the correct key, while maintaining prompt alignment and visual quality. Further experiments verify key-specific recovery, sensitivity to protection hyperparameters, robustness to image transformations and purification, and transferability across unseen DiT-based editors.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.