CVNov 13, 2025

Fragile by Design: On the Limits of Adversarial Defenses in Personalized Generation

arXiv:2511.10382v1h-index: 6
Originality Incremental advance
AI Analysis

This work addresses privacy risks for users of personalized generation tools, highlighting that current defenses are incremental and insufficient.

The paper tackled the problem of facial identity leakage in personalized AI applications like DreamBooth by evaluating existing adversarial defense methods, finding that they are easily detectable and fragile, with no current method maintaining effectiveness under purification threats.

Personalized AI applications such as DreamBooth enable the generation of customized content from user images, but also raise significant privacy concerns, particularly the risk of facial identity leakage. Recent defense mechanisms like Anti-DreamBooth attempt to mitigate this risk by injecting adversarial perturbations into user photos to prevent successful personalization. However, we identify two critical yet overlooked limitations of these methods. First, the adversarial examples often exhibit perceptible artifacts such as conspicuous patterns or stripes, making them easily detectable as manipulated content. Second, the perturbations are highly fragile, as even a simple, non-learned filter can effectively remove them, thereby restoring the model's ability to memorize and reproduce user identity. To investigate this vulnerability, we propose a novel evaluation framework, AntiDB_Purify, to systematically evaluate existing defenses under realistic purification threats, including both traditional image filters and adversarial purification. Results reveal that none of the current methods maintains their protective effectiveness under such threats. These findings highlight that current defenses offer a false sense of security and underscore the urgent need for more imperceptible and robust protections to safeguard user identity in personalized generation.

Foundations

The foundational work for this paper's niche, ranked by how specifically the neighbourhood builds on it — not by global fame.

Your Notes