acceptodds
Under review as a conference paper at ICLR 2027

Protecting Images from Autoregressive Editing via Token Discrepancy Maximization

Abstract

Recent advances in autoregressive (AR) visual generation have broadened instruction-driven image editing capabilities, raising concerns about unauthorized image manipulation. Adversarial perturbations offer a proactive way to protect images from unauthorized editing before publication, but existing methods have largely been developed for diffusion-based editors. We study protection against autoregressive editors that represent source images as discrete visual tokens. In this setting, changing continuous image features may leave the selected tokens unchanged, limiting the effect of protection. We propose TokenShield, a quantization-aware method that encourages the protected image to select codewords farther from those selected for the original image. Its core objective, Ordered Codeword Competition, orders candidate codewords by their distance from the original selection and compares the nearest candidates on either side of each split. Minimizing the resulting distance gaps encourages farther codewords to become the nearest neighbors, while allowing the competing candidates to adapt during optimization. TokenShield generates perturbations through a frozen image tokenizer under a bounded pixel budget, without requiring editing instructions or autoregressive decoding. We evaluate TokenShield on eight image editors across two datasets, PIE-Bench and Emu Edit. The results show that TokenShield provides stronger protection than the compared methods by causing greater disruption to the edited images.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.