{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,4]],"date-time":"2026-05-04T10:23:07Z","timestamp":1777890187580,"version":"3.51.4"},"reference-count":64,"publisher":"IEEE","license":[{"start":{"date-parts":[[2025,10,19]],"date-time":"2025-10-19T00:00:00Z","timestamp":1760832000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,10,19]],"date-time":"2025-10-19T00:00:00Z","timestamp":1760832000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025,10,19]]},"DOI":"10.1109\/iccv51701.2025.01575","type":"proceedings-article","created":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T19:45:49Z","timestamp":1777491949000},"page":"16959-16969","source":"Crossref","is-referenced-by-count":0,"title":["An Inversion-Based Measure of Memorization for Diffusion Models"],"prefix":"10.1109","author":[{"given":"Zhe","family":"Ma","sequence":"first","affiliation":[{"name":"Zhejiang University,Hangzhou,China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Qingming","family":"Li","sequence":"additional","affiliation":[{"name":"Zhejiang University,Hangzhou,China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xuhong","family":"Zhang","sequence":"additional","affiliation":[{"name":"Zhejiang University,Hangzhou,China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tianyu","family":"Du","sequence":"additional","affiliation":[{"name":"Zhejiang University,Hangzhou,China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ruixiao","family":"Lin","sequence":"additional","affiliation":[{"name":"Zhejiang University,Hangzhou,China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zonghui","family":"Wang","sequence":"additional","affiliation":[{"name":"Zhejiang University,Hangzhou,China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shouling","family":"Ji","sequence":"additional","affiliation":[{"name":"Zhejiang University,Hangzhou,China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wenzhi","family":"Chen","sequence":"additional","affiliation":[{"name":"Zhejiang University,Hangzhou,China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","volume-title":"Midjourney"},{"key":"ref2","volume-title":"Artist finds private medical record photos in popular AI training data set"},{"key":"ref3","volume-title":"DALL\u2022E 3"},{"key":"ref4","first-page":"214","article-title":"Wasserstein generative adversarial networks","volume-title":"International conference on machine learning","author":"Arjovsky","year":"2017"},{"key":"ref5","author":"Arora","year":"2017","journal-title":"Do gans actually learn the distribution? an empirical study"},{"key":"ref6","author":"Brooks","journal-title":"Video generation models as world simulators"},{"key":"ref7","first-page":"1877","article-title":"Language models are few-shot learners.. Language models are few-shot learners","author":"Brown","year":"2020","journal-title":"Advances in Neural Information Processing Systems"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833649"},{"key":"ref9","first-page":"5253","article-title":"Extracting training data from diffusion models","volume-title":"32nd USENIX Security Symposium (USENIX Security 23)","author":"Carlini","year":"2023"},{"key":"ref10","article-title":"Quantifying memorization across neural language models","volume-title":"The Eleventh International Conference on Learning Representations","author":"Carlini","year":"2023"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.01023"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.00805"},{"key":"ref13","first-page":"8717","article-title":"Are diffusion models vulnerable to membership inference attacks?","volume-title":"International Conference on Machine Learning","author":"Duan","year":"2023"},{"key":"ref14","first-page":"226","article-title":"A density-based algorithm for discovering clusters in large spatial databases with noise","author":"Ester","year":"1996","journal-title":"kdd"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00663"},{"key":"ref16","article-title":"An image is worth one word: Personalizing text-to-image generation using textual inversion","volume-title":"The Eleventh International Conference on Learning Representations","author":"Gal","year":"2023"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.5555\/2969033.2969125"},{"key":"ref18","volume-title":"Photographer sues LAION for copyright infringement","author":"Guadamuz","year":"2023"},{"key":"ref19","article-title":"Towards gan benchmarks which require generalization","volume-title":"International Conference on Learning Representations","author":"Gulrajani","year":"2019"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.emnlp-main.464"},{"key":"ref21","author":"Ho","year":"2022","journal-title":"Classifier-free diffusion guidance"},{"key":"ref22","first-page":"6840","article-title":"Denoising diffusion probabilistic models","volume":"33","author":"Ho","year":"2020","journal-title":"Advances in neural information processing systems"},{"key":"ref23","author":"Jang","year":"2016","journal-title":"Categorical reparameterization with gumbel-softmax"},{"key":"ref24","article-title":"Imagelevel memorization detection via inversion-based inference perturbation","volume-title":"The Thirteenth International Conference on Learning Representations","author":"Jiang","year":"2025"},{"key":"ref25","article-title":"Pate-gan: Generating synthetic data with differential privacy guarantees","volume-title":"International Conference on Learning Representations","author":"Jordon","year":"2018"},{"key":"ref26","article-title":"Progressive growing of GANs for improved quality, stability, and variation","volume-title":"International Conference on Learning Representations","author":"Karras","year":"2018"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00453"},{"key":"ref28","first-page":"7","article-title":"Adam: A method for stochastic optimization","volume-title":"3rd International Conference on Learning Representations","author":"Kingma","year":"2015"},{"key":"ref29","article-title":"Auto-encoding variational bayes","volume-title":"2nd International Conference on Learning Representations","author":"Kingma","year":"2014"},{"key":"ref30","article-title":"Auto-encoding variational bayes","volume-title":"2nd International Conference on Learning Representations","author":"Kingma","year":"2014"},{"key":"ref31","author":"Krizhevsky","year":"2009","journal-title":"Learning multiple layers of features from tiny images"},{"key":"ref32","article-title":"Maximum likelihood estimation of intrinsic dimension","author":"Levina","year":"2004","journal-title":"Advances in neural information processing systems, 17"},{"key":"ref33","article-title":"Pseudo numerical methods for diffusion models on manifolds","volume-title":"International Conference on Learning Representations","author":"Liu","year":"2022"},{"key":"ref34","author":"Luo","year":"2022","journal-title":"Understanding diffusion models: A unified perspective"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00286"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.00585"},{"key":"ref37","article-title":"Privacy as contextual integrity","volume":"79","author":"Nissenbaum","year":"2004","journal-title":"Wash. L. Rev."},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/ISBI53787.2023.10230346"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01413"},{"key":"ref40","first-page":"8748","article-title":"Learning transferable visual models from natural language supervision","volume-title":"International conference on machine learning","author":"Radford","year":"2021"},{"issue":"2","key":"ref41","volume":"1","author":"Ramesh","year":"2022","journal-title":"Hierarchical text-conditional image generation with CLIP latents"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-72980-5_20"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01042"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.52202\/068431-2643"},{"key":"ref45","article-title":"Improved techniques for training gans","author":"Salimans","year":"2016","journal-title":"Advances in neural information processing systems, 29"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1126\/science.adi0656"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.52202\/068431-1833"},{"key":"ref48","first-page":"2187","article-title":"Glaze: Protecting artists from style mimicry by \\{Text-to-Image\\} models","volume-title":"32nd USENIX Security Symposium (USENIX Security 23)","author":"Shan","year":"2023"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"ref50","first-page":"2256","article-title":"Deep unsupervised learning using nonequilibrium thermodynamics","volume-title":"International conference on machine learning","author":"Sohl-Dickstein","year":"2015"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.00586"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.52202\/075280-2071"},{"key":"ref53","article-title":"Denoising diffusion implicit models","volume-title":"International Conference on Learning Representations","author":"Song","year":"2021"},{"key":"ref54","article-title":"Theoretical insights into memorization in gans","author":"Vaishnavh","journal-title":"Neural Information Processing Systems Workshop 2018"},{"key":"ref55","first-page":"27916","article-title":"On memorization in probabilistic deep generative models","volume":"34","author":"van den Burg","year":"2021","journal-title":"Advances in Neural Information Processing Systems"},{"key":"ref56","first-page":"3527735299","article-title":"On provable copyright protection for generative models","volume-title":"International Conference on Machine Learning","author":"Vyas","year":"2023"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.02051"},{"key":"ref58","article-title":"A reproducible extraction of training images from diffusion models","volume":"abs\/2305.08694","author":"Webster","year":"2023","journal-title":"CoRR"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.01153"},{"key":"ref60","author":"Webster","year":"2023","journal-title":"On the de-duplication of LAION-2B"},{"key":"ref61","article-title":"Detecting, explaining, and mitigating memorization in diffusion models","volume-title":"The Twelfth International Conference on Learning Representations","author":"Wen","year":"2024"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.01028"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.00978"},{"key":"ref64","author":"Zou","year":"2023","journal-title":"Universal and transferable adversarial attacks on aligned language models"}],"event":{"name":"2025 IEEE\/CVF International Conference on Computer Vision (ICCV)","location":"Honolulu, HI, USA","start":{"date-parts":[[2025,10,19]]},"end":{"date-parts":[[2025,10,25]]}},"container-title":["2025 IEEE\/CVF International Conference on Computer Vision (ICCV)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11443115\/11443287\/11444547.pdf?arnumber=11444547","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T05:30:07Z","timestamp":1777613407000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11444547\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,19]]},"references-count":64,"URL":"https:\/\/doi.org\/10.1109\/iccv51701.2025.01575","relation":{},"subject":[],"published":{"date-parts":[[2025,10,19]]}}}