acceptodds
Under review as a conference paper at ICLR 2027

Early Signatures of Memorization in Diffusion Models via Basin Geometry and Cyclic Denoising

Abstract

Diffusion models generalize early in training and later reproduce individual training samples. Standard tests detect memorization only once one-shot generation already produces near-copies, which leaves a released model unaudited until its outputs fail. We show that memorization is encoded in the geometry of the learned energy landscape before it appears in generated samples, a state we call latent memorization. Using score divergence and basin volume, we find that localized basins form around individual training samples and separate them from held-out samples before the first memorized sample appears, with an onset that follows the same scaling as the memorization time. We probe these basins with cyclic denoising, the repeated application of partial noising followed by denoising. Under the exact empirical score, we prove that cycling started near an isolated training sample recovers it and returns to it over any finite number of cycles with high probability, with a bound controlled by the cycling noise and the separation from competing samples. In trained models, cycling recovers training images from CelebA and CIFAR-10 checkpoints whose one-shot samples contain no copies, and at a CelebA checkpoint with 0.1% one-shot copies, 500 cycles raise the memorized fraction above 30%. Cycling also reveals degenerate attractors that match no single training image. They are prevalent early in training and fade as training proceeds, so residence in a basin does not by itself imply memorization. These findings hold on a Gaussian mixture, CelebA, and CIFAR-10 across optimizers, architectures, noise schedules, and training-set sizes. They also extend to off-the-shelf Stable Diffusion v1.4, where the cycled conditional–unconditional divergence gap separates memorized from non-memorized prompts with an AUC of and a TPR of at FPR. Altogether, probing the learned landscape uncovers memorization that eludes one-shot generation. More broadly, what a diffusion model has memorized is a property of the geometry and stability of its learned distribution, and assessing it requires examining this structure rather than generated outputs alone.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.