VEIL: Visual-State Early-Anchor Stabilization for Identity Leakage Suppression
Abstract
Text-to-image personalization can bind a subject's visual identity to an identifier using only a few reference images, enabling unauthorized synthesis from publicly shared face photos. User-side defenses perturb images before release to impair downstream identity recovery while preserving visual quality. However, existing methods typically optimize denoising or cross-attention signals without jointly controlling the diffusion states used for supervision and the conditioning positions and image regions targeted during optimization. In this paper, we propose VEIL (Visual-state Early-anchor Identity Leakage suppression), a user-side defense that stabilizes perturbation optimization using fixed ultra-early denoising anchors and posterior-mean latent encoding. It further targets conditioning positions and image regions that contribute most to the protection objective through attribution-guided selection, saliency-weighted updates, and soft shrinkage. Under DreamBooth on CelebA-HQ and VGGFace2, VEIL achieves the highest SSIM and PSNR among the compared defenses on both datasets, with an SSIM of 0.94 and PSNRs of 37.94 and 38.21 dB. Across the four primary dataset–prompt settings, VEIL achieves or ties for the highest FDFR, with values ranging from 0.73 to 0.85. Protection also transfers across the evaluated Stable Diffusion variants and personalization procedures without re-optimizing the released images. Code is available at https://anonymous.4open.science/r/VEAL_demo.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.