{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,10]],"date-time":"2025-12-10T04:04:19Z","timestamp":1765339459006,"version":"3.46.0"},"publisher-location":"New York, NY, USA","reference-count":45,"publisher":"ACM","content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,10,27]]},"DOI":"10.1145\/3746027.3755755","type":"proceedings-article","created":{"date-parts":[[2025,10,25]],"date-time":"2025-10-25T06:55:00Z","timestamp":1761375300000},"page":"10535-10543","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Immunizing Images from Text to Image Editing via Adversarial Cross-Attention"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0009-4744-7110","authenticated-orcid":false,"given":"Matteo","family":"Trippodo","sequence":"first","affiliation":[{"name":"University of Florence, Florence, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2537-2700","authenticated-orcid":false,"given":"Federico","family":"Becattini","sequence":"additional","affiliation":[{"name":"University of Siena, Siena, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4816-0268","authenticated-orcid":false,"given":"Lorenzo","family":"Seidenari","sequence":"additional","affiliation":[{"name":"University of Florence, Florence, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2025,10,27]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-19781-9_4"},{"key":"e_1_3_2_1_2_1","volume-title":"Daniela Massiceti, Maziar Sanjabi, Shell Xu Hu, and Soheil Feizi.","author":"Basu Samyadeep","year":"2023","unstructured":"Samyadeep Basu, Mehrdad Saberi, Shweta Bhardwaj, Atoosa Malemir Chegini, Daniela Massiceti, Maziar Sanjabi, Shell Xu Hu, and Soheil Feizi. 2023. Editval: Benchmarking diffusion based text-guided image editing methods. arXiv preprint arXiv:2310.02426 (2023)."},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.00846"},{"key":"e_1_3_2_1_4_1","volume-title":"Per-pixel classification is not all you need for semantic segmentation. Advances in neural information processing systems","author":"Cheng Bowen","year":"2021","unstructured":"Bowen Cheng, Alex Schwing, and Alexander Kirillov. 2021. Per-pixel classification is not all you need for semantic segmentation. Advances in neural information processing systems, Vol. 34 (2021), 17864-17875."},{"key":"e_1_3_2_1_5_1","volume-title":"DiffusionGuard: A Robust Defense Against Malicious Diffusion-based Image Editing. arXiv preprint arXiv:2410.05694","author":"Choi June Suk","year":"2024","unstructured":"June Suk Choi, Kyungmin Lee, Jongheon Jeong, Saining Xie, Jinwoo Shin, and Kimin Lee. 2024. DiffusionGuard: A Robust Defense Against Malicious Diffusion-based Image Editing. arXiv preprint arXiv:2410.05694 (2024)."},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2023.3261988"},{"key":"e_1_3_2_1_7_1","volume-title":"Diffusion models beat gans on image synthesis. Advances in neural information processing systems","author":"Dhariwal Prafulla","year":"2021","unstructured":"Prafulla Dhariwal and Alexander Nichol. 2021. Diffusion models beat gans on image synthesis. Advances in neural information processing systems, Vol. 34 (2021), 8780-8794."},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00040"},{"key":"e_1_3_2_1_9_1","first-page":"30339","article-title":"Adversarial examples make strong poisons","volume":"34","author":"Fowl Liam","year":"2021","unstructured":"Liam Fowl, Micah Goldblum, Ping-yeh Chiang, Jonas Geiping, Wojciech Czaja, and Tom Goldstein. 2021. Adversarial examples make strong poisons. Advances in Neural Information Processing Systems, Vol. 34 (2021), 30339-30351.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_1_10_1","volume-title":"An image is worth one word: Personalizing text-to-image generation using textual inversion. arXiv preprint arXiv:2208.01618","author":"Gal Rinon","year":"2022","unstructured":"Rinon Gal, Yuval Alaluf, Yuval Atzmon, Or Patashnik, Amit H Bermano, Gal Chechik, and Daniel Cohen-Or. 2022. An image is worth one word: Personalizing text-to-image generation using textual inversion. arXiv preprint arXiv:2208.01618 (2022)."},{"key":"e_1_3_2_1_11_1","volume-title":"ICLR 2015, San Diego, CA, USA, May 7-9, 2015, Conference Track Proceedings, Yoshua Bengio and Yann LeCun (Eds.). http:\/\/arxiv.org\/abs\/1412","author":"Goodfellow Ian J.","year":"2015","unstructured":"Ian J. Goodfellow, Jonathon Shlens, and Christian Szegedy. 2015. Explaining and Harnessing Adversarial Examples. In 3rd Int'l Conference on Learning Representations, ICLR 2015, San Diego, CA, USA, May 7-9, 2015, Conference Track Proceedings, Yoshua Bengio and Yann LeCun (Eds.). http:\/\/arxiv.org\/abs\/1412.6572"},{"key":"e_1_3_2_1_12_1","volume-title":"Lei Fang, Shuai Zhao, Yifei Qian, Jingyu Lin, Zeyu Wang, Cunjian Chen, Ognjen Arandjelovi\u0107, and Chun Pong Lau.","author":"Guo Zhongliang","year":"2024","unstructured":"Zhongliang Guo, Chun Tong Lei, Lei Fang, Shuai Zhao, Yifei Qian, Jingyu Lin, Zeyu Wang, Cunjian Chen, Ognjen Arandjelovi\u0107, and Chun Pong Lau. 2024. A grey-box attack against latent diffusion model-based image editing by posterior collapse. arXiv preprint arXiv:2408.10901 (2024)."},{"key":"e_1_3_2_1_13_1","volume-title":"Ronan Le Bras, and Yejin Choi","author":"Hessel Jack","year":"2021","unstructured":"Jack Hessel, Ari Holtzman, Maxwell Forbes, Ronan Le Bras, and Yejin Choi. 2021. Clipscore: A reference-free evaluation metric for image captioning. arXiv preprint arXiv:2104.08718 (2021)."},{"key":"e_1_3_2_1_14_1","volume-title":"Denoising diffusion probabilistic models. arXiv preprint arXiv:2006.11239","author":"Ho Jonathan","year":"2020","unstructured":"Jonathan Ho, Ajay Jain, and Pieter Abbeel. 2020. Denoising diffusion probabilistic models. arXiv preprint arXiv:2006.11239 (2020)."},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"crossref","unstructured":"Inbar Huberman-Spiegelglas Vladimir Kulikov and Tomer Michaeli. 2024. An Edit Friendly DDPM Noise Space: Inversion and Manipulations. arXiv:2304.06140 [cs.CV] https:\/\/arxiv.org\/abs\/2304.06140","DOI":"10.1109\/CVPR52733.2024.01185"},{"key":"e_1_3_2_1_16_1","volume-title":"Mist: Towards improved adversarial examples for diffusion models. arXiv preprint arXiv:2305.12683","author":"Liang Chumeng","year":"2023","unstructured":"Chumeng Liang and Xiaoyu Wu. 2023. Mist: Towards improved adversarial examples for diffusion models. arXiv preprint arXiv:2305.12683 (2023)."},{"key":"e_1_3_2_1_17_1","volume-title":"ICML 2023","volume":"20786","author":"Liang Chumeng","year":"2023","unstructured":"Chumeng Liang, Xiaoyu Wu, Yang Hua, Jiaru Zhang, Yiming Xue, Tao Song, Zhengui Xue, Ruhui Ma, and Haibing Guan. 2023. Adversarial Example Does Good: Preventing Painting Imitation from Diffusion Models via Adversarial Examples. In Int'l Conference on Machine Learning, ICML 2023, 23-29 July 2023, Honolulu, Hawaii, USA (Proceedings of Machine Learning Research, Vol. 202), Andreas Krause, Emma Brunskill, Kyunghyun Cho, Barbara Engelhardt, Sivan Sabato, and Jonathan Scarlett (Eds.). PMLR, 20763-20786. https:\/\/proceedings.mlr.press\/v202\/liang23g.html"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.00674"},{"key":"e_1_3_2_1_19_1","volume-title":"Visual instruction tuning. Advances in neural information processing systems","author":"Liu Haotian","year":"2023","unstructured":"Haotian Liu, Chunyuan Li, Qingyang Wu, and Yong Jae Lee. 2023. Visual instruction tuning. Advances in neural information processing systems, Vol. 36 (2023), 34892-34916."},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.02309"},{"key":"e_1_3_2_1_21_1","volume-title":"Dpm-solver: Fast solver for guided sampling of diffusion probabilistic models. arXiv preprint arXiv:2211.01095","author":"Lu Cheng","year":"2022","unstructured":"Cheng Lu, Yuhao Zhou, Fan Bao, Jianfei Chen, Chongxuan Li, and Jun Zhu. 2022. Dpm-solver: Fast solver for guided sampling of diffusion probabilistic models. arXiv preprint arXiv:2211.01095 (2022)."},{"key":"e_1_3_2_1_22_1","volume-title":"ICLR 2018, Vancouver, BC, Canada, April 30 - May 3, 2018, Conference Track Proceedings. OpenReview.net. https:\/\/openreview.net\/forum?id=rJzIBfZAb","author":"Madry Aleksander","year":"2018","unstructured":"Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu. 2018. Towards Deep Learning Models Resistant to Adversarial Attacks. In 6th Int'l Conference on Learning Representations, ICLR 2018, Vancouver, BC, Canada, April 30 - May 3, 2018, Conference Track Proceedings. OpenReview.net. https:\/\/openreview.net\/forum?id=rJzIBfZAb"},{"key":"e_1_3_2_1_23_1","volume-title":"ICLR 2022","author":"Meng Chenlin","year":"2022","unstructured":"Chenlin Meng, Yutong He, Yang Song, Jiaming Song, Jiajun Wu, Jun-Yan Zhu, and Stefano Ermon. 2022. SDEdit: Guided Image Synthesis and Editing with Stochastic Differential Equations. In The Tenth Int'l Conference on Learning Representations, ICLR 2022, Virtual Event, April 25-29, 2022. OpenReview.net. https:\/\/openreview.net\/forum?id=aBsCjcPu_tE"},{"key":"e_1_3_2_1_24_1","volume-title":"Optimization-Free Image Immunization Against Diffusion-Based Editing. arXiv preprint arXiv:2411.17957","author":"Ozden Tarik Can","year":"2024","unstructured":"Tarik Can Ozden, Ozgur Kara, Oguzhan Akcin, Kerem Zaman, Shashank Srivastava, Sandeep P Chinchali, and James M Rehg. 2024. Optimization-Free Image Immunization Against Diffusion-Based Editing. arXiv preprint arXiv:2411.17957 (2024)."},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3616679"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.2405.03486"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/3630106.3658913"},{"key":"e_1_3_2_1_28_1","first-page":"8748","article-title":"Learning transferable visual models from natural language supervision. In Int'l Conf. on machine learning","author":"Radford Alec","year":"2021","unstructured":"Alec Radford, Jong Wook Kim, Chris Hallacy, Aditya Ramesh, Gabriel Goh, Sandhini Agarwal, Girish Sastry, Amanda Askell, Pamela Mishkin, Jack Clark, et al., 2021. Learning transferable visual models from natural language supervision. In Int'l Conf. on machine learning. PmLR, 8748-8763.","journal-title":"PmLR"},{"key":"e_1_3_2_1_29_1","volume-title":"Zero-shot text-to-image generation. arXiv preprint arXiv:2102.12092","author":"Ramesh Aditya","year":"2021","unstructured":"Aditya Ramesh, Mikhail Pavlov, Gabriel Goh, Scott Gray, Chelsea Voss, Alec Radford, Mark Chen, and Ilya Sutskever. 2021. Zero-shot text-to-image generation. arXiv preprint arXiv:2102.12092 (2021)."},{"key":"e_1_3_2_1_30_1","volume-title":"Preventing posterior collapse with delta-vaes. arXiv preprint arXiv:1901.03416","author":"Razavi Ali","year":"2019","unstructured":"Ali Razavi, A\u00e4ron van den Oord, Ben Poole, and Oriol Vinyals. 2019. Preventing posterior collapse with delta-vaes. arXiv preprint arXiv:1901.03416 (2019)."},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/D19-1410"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01042"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01042"},{"key":"e_1_3_2_1_34_1","first-page":"234","volume-title":"Munich","author":"Ronneberger Olaf","year":"2015","unstructured":"Olaf Ronneberger, Philipp Fischer, and Thomas Brox. 2015. U-net: Convolutional networks for biomedical image segmentation. In Medical image computing and computer-assisted intervention-MICCAI 2015: 18th Int'l Conf., Munich, Germany, October 5-9, 2015, proceedings, part III 18. Springer, 234-241."},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.02155"},{"key":"e_1_3_2_1_36_1","unstructured":"Hadi Salman Alaa Khaddaj Guillaume Leclerc Andrew Ilyas and Aleksander Madry. 2023. Raising the Cost of Malicious AI-Powered Image Editing. arXiv:2302.06588 [cs.LG] https:\/\/arxiv.org\/abs\/2302.06588"},{"key":"e_1_3_2_1_37_1","first-page":"2187","volume-title":"32nd USENIX Security Symp. (USENIX Security 23)","author":"Shan Shawn","year":"2023","unstructured":"Shawn Shan, Jenna Cryan, Emily Wenger, Haitao Zheng, Rana Hanocka, and Ben Y Zhao. 2023. Glaze: Protecting artists from style mimicry by Text-to-Image models. In 32nd USENIX Security Symp. (USENIX Security 23). 2187-2204."},{"key":"e_1_3_2_1_38_1","unstructured":"Jascha Sohl-Dickstein Eric Weiss Niru Maheswaranathan and Surya Ganguli. 2015. Deep unsupervised learning using nonequilibrium thermodynamics. In Int'l Conf. on machine learning. pmlr 2256-2265."},{"key":"e_1_3_2_1_39_1","volume-title":"ICLR 2014, Banff, AB, Canada, April 14-16, 2014, Conference Track Proceedings, Yoshua Bengio and Yann LeCun (Eds.). http:\/\/arxiv.org\/abs\/1312","author":"Szegedy Christian","year":"2014","unstructured":"Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian J. Goodfellow, and Rob Fergus. 2014. Intriguing properties of neural networks. In 2nd Int'l Conference on Learning Representations, ICLR 2014, Banff, AB, Canada, April 14-16, 2014, Conference Track Proceedings, Yoshua Bengio and Yann LeCun (Eds.). http:\/\/arxiv.org\/abs\/1312.6199"},{"key":"e_1_3_2_1_40_1","volume-title":"Proceedings of the IEEE\/CVF Int'l Conf. on Computer Vision. 2116-2127","author":"Le Thanh Van","year":"2023","unstructured":"Thanh Van Le, Hao Phung, Thuan Hoang Nguyen, Quan Dao, Ngoc N Tran, and Anh Tran. 2023. Anti-dreambooth: Protecting users from personalized text-to-image synthesis. In Proceedings of the IEEE\/CVF Int'l Conf. on Computer Vision. 2116-2127."},{"key":"e_1_3_2_1_41_1","unstructured":"Haotian Xue Chumeng Liang Xiaoyu Wu and Yongxin Chen. 2024. Toward effective protection against diffusion based mimicry through score distillation. arXiv:2311.12832 [cs.CV] https:\/\/arxiv.org\/abs\/2311.12832"},{"key":"e_1_3_2_1_42_1","first-page":"26291","article-title":"Dynamic prompt learning: Addressing cross-attention leakage for text-based image editing","volume":"36","author":"Yang Fei","year":"2023","unstructured":"Fei Yang, Shiqi Yang, Muhammad Atif Butt, Joost van de Weijer, et al., 2023. Dynamic prompt learning: Addressing cross-attention leakage for text-based image editing. Advances in Neural Information Processing Systems, Vol. 36 (2023), 26291-26303.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01588"},{"key":"e_1_3_2_1_44_1","volume-title":"GuardDoor: Safeguarding Against Malicious Diffusion Editing via Protective Backdoors. arXiv preprint arXiv:2503.03944","author":"Zeng Yaopei","year":"2025","unstructured":"Yaopei Zeng, Yuanpu Cao, and Lu Lin. 2025. GuardDoor: Safeguarding Against Malicious Diffusion Editing via Protective Backdoors. arXiv preprint arXiv:2503.03944 (2025)."},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00068"}],"event":{"name":"MM '25: The 33rd ACM International Conference on Multimedia","sponsor":["SIGMM ACM Special Interest Group on Multimedia"],"location":"Dublin Ireland","acronym":"MM '25"},"container-title":["Proceedings of the 33rd ACM International Conference on Multimedia"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3746027.3755755","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,12,10]],"date-time":"2025-12-10T03:59:31Z","timestamp":1765339171000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3746027.3755755"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,27]]},"references-count":45,"alternative-id":["10.1145\/3746027.3755755","10.1145\/3746027"],"URL":"https:\/\/doi.org\/10.1145\/3746027.3755755","relation":{},"subject":[],"published":{"date-parts":[[2025,10,27]]},"assertion":[{"value":"2025-10-27","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}