acceptodds
Under review as a conference paper at ICLR 2027

PuriShield: Robust Defense against Unauthorized Diffusion Customization via Structured Protective Perturbations

Abstract

Latent diffusion models have raised severe security concerns regarding unauthorized customization. Existing anti-customization defenses protect images by injecting subtle protective perturbations, yet such unstructured perturbations suffer from poor robustness against Diffusion-based Purification (DP). To tackle this limitation, this paper proposes , a novel anti-customization method that trains a Robust Protective Perturbation Generator (RPPG) to adaptively produce structured protective perturbations. Specifically, incorporates three core designs: pattern density-guided generation to yield structured perturbations, latent distribution contrastive loss to refine protective perturbations, and embedded dual-head modulation to enable high-quality perturbation synthesis. Extensive experimental results demonstrate the advantages of : ① Excellent effectiveness. It effectively defends against 5 unauthorized customization methods prior to purification. ② Strong robustness. Across 13 purification methods, it attains optimal robustness and significantly surpasses baselines against UDAP, a DP approach tailored to counter anti-customization defenses. ③ Great generalizability. It performs well in cross-task and cross-domain scenarios. ④ High efficiency. Training the RPPG takes only 31.6 minutes, with a mere 5.8 ms inference latency.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.