acceptodds
Under review as a conference paper at ICLR 2027

Copying as Defense: Protecting Images from Editing by Eliciting Model Copying

Abstract

Image editors built on diffusion transformers (DiTs), such as Flux Kontext, make it possible to turn a single photograph into a convincing manipulated image, including harmful and non-consensual edits. Proactive defenses aim to prevent such manipulations by adding an imperceptible perturbation before an image is shared. Existing defenses for DiT-based in-context editors take an intuitive approach: make the output attend less to the protected reference image. But this leaves the model free to follow the edit instruction using the text and its own generated tokens, often producing a new, weakly grounded image rather than preventing the edit altogether. We find that the opposite strategy is more effective. Instead of leading the model to ignore the reference, we encourage it to copy it. Through controlled attention interventions, we show that concentrating target-token attention on the reference image in only a few early blocks is sufficient to collapse the editing behavior, causing the model to reproduce its input, often as a lossy copy, rather than execute the requested transformation. Based on this insight, we introduce Copying-as-Defense (CaD), which maximizes per-token target-to-reference attention mass in early transformer blocks. Since the attention rows are normalized, increasing reference attention suppresses the attention allocated to the text and generated canvas. Restricting the objective to early blocks also lets us truncate backpropagation path, keeping optimization cheap. Across editors and benchmarks, CaD substantially suppresses instruction-following. It reduces average edit success from 81.4% on unprotected images to 24.0%, a 70.6% relative reduction. Compared with DeContext, the strongest baseline on average at 43.0% edit success, CaD further reduces edit success by 44.3%. CaD is also substantially cheaper to optimize, running roughly 1.8–2.0 times faster per step than comparable optimization-based methods.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.