Exploiting the Law of Prägnanz in Diffusion Models to Prevent Unauthorized 3D Structure Reconstruction
Abstract
Diffusion-based 3D reconstruction models enable accurate generation of high-fidelity 3D structures with complex geometric details based on 2D visual signals. While these models facilitate powerful design and creation applications, they also introduce significant AI safety risks by enabling adversaries to infer sensitive 3D structures, such as proprietary 3D designs or confidential physical objects. To address this threat, we present Flatland, a defense framework that protects structural information conveyed in 2D visual signals from being reconstructed by unauthorized 3D diffusion models. The key insight behind Flatland is an empirically observed simplicity bias in diffusion models: similar to human perception, their spatial reasoning behavior exhibits characteristics consistent with the psychological Law of Prägnanz, favoring simple structures over more complex alternatives. Leveraging this observation, Flatland injects simple structures into visual signals as low-amplitude perturbations, thereby disrupting unauthorized 3D reconstruction by inducing diffusion models to reconstruct the injected simple structures instead of the original sensitive ones. Experimental results demonstrate that Flatland effectively prevents 10 public diffusion models from reconstructing sensitive structures across 11 datasets. Moreover, we validate Flatland on 11 proprietary models from 9 commercial AI creation platforms, and analyze its robustness against perturbation removal and purification methods.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.