acceptodds
Under review as a conference paper at ICLR 2027

RVDGuard: Robust Protection against Unauthorized Image-to-Video Generation via First-Step Velocity Deflection

Abstract

Image-to-video (I2V) generation models can animate a single photo into a realistic video, raising serious concerns about privacy violations and deceptive content creation. Existing proactive protection methods add imperceptible perturbations to images before release so that videos generated from them are degraded. However, we find that existing I2V protections suffer from two robustness limitations. On the input side, their perturbations are largely neutralized by common resizing, cropping, and compression. On the output side, the generated videos often remain visually clean, so an attacker can restore them or regenerate new videos from unaffected frames. To address these limitations, we propose RVDGuard, a robust protection framework that requires only a single denoiser evaluation per transformation at each optimization step. For input robustness, RVDGuard applies Expectation over Transformation, passing original and protected images through shared transformation instances and averaging the objective over them. For output robustness, RVDGuard deflects the direction of the first-step velocity predicted by the I2V model, maximizing a per-temporal-slice cosine dissimilarity between the predictions for protected and original images under a shared initial noise. Because the first update sets the course of the entire sampling trajectory, this deflection propagates through all subsequent steps and corrupts every generated frame. Experiments on CogVideoX-5B-I2V, Wan2.2-TI2V-5B, and Wan2.1-I2V-14B show that the VBench-I2V scores of videos generated from images protected by RVDGuard drop by on average relative to those generated from original images, compared with for the strongest baseline, and that RVDGuard remains effective under common image transformations and transfers to an unseen I2V model.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.