acceptodds
Under review as a conference paper at ICLR 2027

Yours or Mine? Misleading Latent Diffusion Model Attribution via Cross-Model Reconstruction

Abstract

Reconstruction error-based attribution infers an image's source model from reconstruction errors under candidate autoencoders. We find that distinct Stable Diffusion models can produce identical errors for the same image, making source attribution ambiguous. Comparing autoencoder architectures and parameters reveals that this ambiguity arises from shared autoencoders. We therefore test whether reconstructing an image with another model's autoencoder can redirect attribution after generation. We introduce Cross-Model Reconstruction (CMR), which passes an image generated by the original model through the attack model 's encoder and decoder once. This reconstruction pass can induce false attribution to with minimal perceptual distortion and requires neither diffusion sampling nor attribution queries. Models that share an autoencoder can still have different denoisers. We propose READ (Responses Evidence for Attribution from Denoisers), which learns attribution from multiple denoisers' relative responses to controlled latent perturbations, using clean images for calibration. Across 12 generative models, CMR raises mean attack-model acceptance to 93.5-99.8% for AEDR, AEROBLADE, and LatentTracer. By comparing denoising responses, READ distinguishes source models even when they share an autoencoder. On the same attacked images, it reduces mean attack-model acceptance to 13.6% while improving acceptance of the original source model relative to these baselines. The source code of CMR and READ are included in the supplementary material.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.