acceptodds
Under review as a conference paper at ICLR 2027

IRIS: Imperceptible, Robust Image Sealing for Cooperative Anti-Edit Protection

Abstract

Unified image-editing models such as FLUX.2 unlock substantial creative potential, but also make publicly shared content easy to repurpose without consent. For example, they can fabricate images of a person in scenarios that never occurred or imitate an artist's signature style. Existing input-only defenses add subtle perturbations to disrupt such edits, but this small signal must survive everyday image processing. Simple operations such as cropping, flipping, resizing, or compression can therefore weaken protection, while increasing perturbation strength can compromise visual quality. We introduce IRIS, a cooperative defense in which the model provider participates in enforcing the image owner's opt-out. This cooperation allows IRIS to separate robust signal design from protective response learning. It embeds subtle, image-dependent signals using a frozen watermarking model and fine-tunes the editor with a target-image-free objective that selectively cools down the velocity field on protected inputs, keeping generation in the noisy regime while preserving clean editing. Creators can apply the protection to new images without per-image optimization or access to the editor, and the same protected image can be used across cooperating models. Experiments with FLUX.2 and Qwen-Image-Edit demonstrate this selectivity: IRIS combines low perceptual distortion and strong protection under everyday image processing with largely preserved clean-image editing fidelity.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.