GAP-Diff: Protecting JPEG-Compressed Images from Diffusion-based Facial Customization

Haotian Zhu

Network and Distributed System Security (NDSS) Symposium 2025 · Day 1 · AI Safety

Overview

The proliferation of text-to-image diffusion models has ushered in an era of unprecedented creative potential, allowing users to generate highly customized and realistic images from simple text prompts. However, this powerful technology is not without its perils. A critical security and privacy concern has emerged with the misuse of these models for facial customization, where malicious actors can generate convincing deepfakes or altered images using as few as three to five identity images of a target individual. These fabricated images can depict individuals in various scenarios, seasons, or contexts, posing significant risks to personal privacy, reputation, and security, as highlighted by BBC reports on the technology's misuse.

Watch on YouTube · Slides

Key moments

  1. 0:00 Introduction: The problem of diffusion-based facial customization
  2. 1:00 Limitations of prior protection methods under JPEG compression
  3. 2:00 Understanding JPEG impact and proposed solution directions
  4. 4:00 GAP-Diff framework: Generator, pre-processing, diffusion model
  5. 5:50 Achieving robustness: noise parameter control and loss function
  6. 7:00 Qualitative results: JPD effectively destroys facial features
  7. 8:30 Evaluation insights: JPD maintains effectiveness even at low quality
  8. 10:10 Conclusion: One-step noise generation, future API development

GAP-Diff: Protecting JPEG-Compressed Images from Diffusion-based Facial Customization

Speakers: Haotian Zhu

Conference: NDSS Symposium

YouTube: https://www.youtube.com/watch?v=u8VWj3nK3DE

Overview

The proliferation of text-to-image diffusion models has ushered in an era of unprecedented creative potential, allowing users to generate highly customized and realistic images from simple text prompts. However, this powerful technology is not without its perils. A critical security and privacy concern has emerged with the misuse of these models for facial customization, where malicious actors can generate convincing deepfakes or altered images using as few as three to five identity images of a target individual. These fabricated images can depict individuals in various scenarios, seasons, or contexts, posing significant risks to personal privacy, reputation, and security, as highlighted by BBC reports on the technology's misuse.

This talk, presented on behalf of Haotian Zhu at the NDSS Symposium, introduces GAP-Diff, a novel framework designed to protect JPEG-compressed images from such diffusion-based facial customization. Prior research has explored methods to introduce "protective noise" into images to disrupt the customization process, rendering generated faces distorted and unrecognizable. However, a significant limitation of these existing techniques is their vulnerability to JPEG compression, a ubiquitous image processing step. Once an image is compressed, the protective effects often vanish, allowing diffusion models to once again generate clear and identifiable faces.

GAP-Diff directly addresses this critical vulnerability by developing a method that maintains its protective efficacy even after JPEG compression. The framework leverages an innovative approach that focuses on generating compression-resistant noise patterns, moving beyond the high-frequency noise that is easily discarded by JPEG algorithms. By doing so, GAP-Diff offers a robust solution to safeguard facial privacy against the evolving threat of AI-powered image manipulation, ensuring that protective measures remain effective in real-world scenarios where images are routinely compressed and shared.

Background

▶ Watch: Introduction: The problem of diffusion-based facial customization (0:00)

The challenge of protecting images from diffusion-based facial customization stems from the inherent nature of how these models operate and how images are typically processed. Earlier protective methods, such as anti-DRBoost, relied on injecting specific "protective noise" into an image. This noise was designed to subtly alter the image in a way that would confuse the diffusion model, causing it to produce distorted and unrecognizable output when attempting to customize a target identity. While effective in uncompressed formats, these methods frequently failed when images underwent JPEG compression.

The core reason for this failure lies in the mechanics of JPEG compression itself. JPEG is a lossy compression algorithm primarily designed to reduce file size by discarding information deemed less perceptible to the human eye. Crucially, it achieves this by transforming image data into frequency components and then quantizing, or rounding off, the high-frequency information. Prior protective noise, often generated using methods like PJD attracts, tended to manifest as widely distributed, high-frequency pixel variations. When adjacent pixels are randomly altered in different directions, it creates sudden changes and sharp local differences in pixel values, which precisely constitute high-frequency noise. Since JPEG's primary purpose is to reduce this very type of information, the protective effect was easily stripped away, leaving the underlying facial features vulnerable to customization once more.

Recognizing this fundamental incompatibility, the researchers explored two potential solutions. The first involved using an adaptive method that would focus on embedding protective information within low-frequency regions of an image, which are less likely to be eliminated by JPEG compression. The second, more ambitious approach, was to employ neural networks to learn noise generation patterns that are inherently resistant to compression. The team ultimately decided to pursue the second solution, believing it offered a more robust and generalizable path to compression resistance. They also noted an existing JPEG simulation method that involved retaining 5x5 low-frequency regions in the Y channel and 3x3 low-frequency regions in the UV channels while discarding other high-frequency coefficients, which informed their understanding of how to achieve compression resilience.

Key Findings

▶ Watch: Understanding JPEG impact and proposed solution directions (2:00)

GAP-Diff's primary contribution is its ability to generate adversarial protective noise that effectively prevents diffusion-based facial customization, crucially maintaining its efficacy even after JPEG compression. The key findings demonstrate a significant leap beyond prior work that often failed under real-world image processing conditions.

The framework achieves a high protection rate, consistently producing highly distorted images with unrecognizable facial features when customization is attempted. This is evident in qualitative results where GAP-Diff-protected images, even after compression, lead to outputs that are clearly mangled, unlike other methods that revert to clear faces.

A critical finding is GAP-Diff's resilience across various JPEG quality levels. Even at aggressive compression settings, such as a quality factor (Q) of 5, where other methods largely fail, GAP-Diff still maintains a good level of protection. Evaluation studies further confirm this, showing that at a relatively low quality like Q=30, GAP-Diff remains highly effective. While protection might gradually decrease as JPEG quality increases (meaning less compression), it still maintains significant effectiveness, striking a good balance between protection and visual quality.

Furthermore, GAP-Diff introduces an efficient, one-step noise generation process. Unlike conventional iterative adversarial approaches that can be time-consuming, GAP-Diff leverages a Generative Adversarial Network (GAN) structure to directly learn and generate the compression-resistant noise pattern in a single pass. This significantly speeds up deployment and application of the protection. The framework's robustness has also been proven across various "seasons" or scenarios, indicating its generalizability. The researchers plan to develop a public API and open-source their training stages to allow for fine-tuned balance between protection effectiveness and visual quality, and intend to expand their method to include additional preprocessing and customization technologies, cementing GAP-Diff as a foundational advancement in protecting digital facial privacy.

Technical Deep Dive

▶ Watch: Achieving robustness: noise parameter control and loss function (5:50)

The technical foundation of GAP-Diff lies in an adversarial approach that seeks to control the distribution of diffusion models during their fine-tuning process for facial customization. The core idea is to introduce perturbations that maximally disrupt the model's ability to learn and reproduce the target identity, while simultaneously ensuring these perturbations survive JPEG compression.

The adversary's goal is to control the model distribution, which is formalized through a fine-tuning process involving specific loss functions. The key components include the conditional loss (L_CD) and the fine-tuning loss (L_FT), along with L_FT' for fine-tuning images after preprocessing. The protecting goal is formulated as an optimization problem:

  1. Maximize L_CD: This aims to enhance the effectiveness of the protecting function, making it harder for the diffusion model to condition on the target identity.
  2. Subject to two constraints: The model parameters (denoted as θ star) should minimize the fine-tuning loss L_FT'. This ensures that the adversarial noise is optimized in the context of the diffusion model's learning process.

The GAP-Diff framework itself is structured into three integral parts, working in concert to achieve rapid and compression-resistant protection:

  1. Generator Model: This component is responsible for generating the protective noise. Unlike prior methods that might use simple adversarial pixel changes, GAP-Diff employs a GAN structure. This allows the generator to learn to produce noise patterns that are not only effective in disrupting diffusion models but also "natural-looking" enough to survive compression, by being less like high-frequency pixel artifacts.
  2. Preprocessing Simulation Model: This crucial component directly addresses the JPEG compression challenge. It simulates the effects of various real-world image preprocessing operations, including JPEG compression, within the training loop. By training the generator against this simulated environment, GAP-Diff learns to create noise that is robust to these transformations, specifically by focusing on low-frequency patterns. The simulation incorporates retaining 5x5 low-frequency regions in the Y channel and 3x3 low-frequency regions in the UV channels, while discarding high-frequency components, mirroring the actual JPEG compression process.
  3. Fine-tuning T2I Diffusion Model: This is the target model against which the protective noise is optimized. It represents the text-to-image diffusion model that an attacker would use for facial customization. By incorporating this into the training, GAP-Diff ensures that the generated noise is specifically tailored to disrupt the mechanisms of diffusion-based identity transfer.

GAP-Diff addresses three key aspects to achieve its objectives:

  • Noise Parameters and Control: It leverages GAN structure to ensure the generated noise patterns are subtle yet effective, exhibiting a "natural nature" that helps them persist through compression. The framework directly contains and customizes the loss functions of the different models involved, allowing for precise control over the adversarial perturbation.
  • Robustness: The framework achieves robustness by:
  • Randomly sampling different preprocessing functions: During training, the preprocessing simulation model applies various types of realistic image alterations, making the learned noise generalize better.
  • Using "motor color simple" during training and approximation: This likely refers to specific color space manipulations or sampling techniques that enhance the noise's resilience.
  • Differentially weighting protection across time steps: Diffusion models operate across many time steps (from 0 to 100x in the talk). Low time steps contain more structural information, while high time steps are dominated by noise. GAP-Diff uses a simple alpha function to balance the protection across this spectrum, ensuring that crucial structural elements are adequately protected without overly distorting the image. For instance, Go Blue noise, which is targeted into the training preprocessing layer, is found to be highly protective, suggesting that specific learned noise patterns are more effective than random noise.

This comprehensive approach allows GAP-Diff to generate protective noise that is not easily removed by real-world processing operations like JPEG compression, making it a significant advancement in adversarial machine learning for privacy protection.

Demo / Proof of Concept

▶ Watch: Qualitative results: JPD effectively destroys facial features (7:00)

The talk presented compelling qualitative results to demonstrate GAP-Diff's effectiveness, particularly in comparison to other existing methods under varying JPEG compression levels. The visual evidence showcased images that had been protected by GAP-Diff and subsequently compressed, alongside images protected by other techniques.

A core demonstration involved images compressed with a JPEG quality factor (Q) of 70, a common setting for web images and general sharing. At this level, GAP-Diff consistently achieved a higher detection failure rate for diffusion models attempting facial customization. The visual output generated by diffusion models from GAP-Diff-protected images was highly distorted, featuring unrecognizable facial features, effectively preventing unauthorized customization. In contrast, other conventional protection methods, when subjected to the same Q=70 compression, often failed, resulting in customized images that still revealed clear and identifiable faces.

The robustness of GAP-Diff was further highlighted by evaluating its performance at extremely aggressive JPEG compression levels. At Q=5, a quality factor that severely degrades image fidelity, most other protection methods completely failed, yielding clear facial customizations. However, GAP-Diff still maintained a "good protection active," indicating its superior resilience.

The evaluation studies provided additional key insights:

  • JPEG Quality vs. Effectiveness: Even at low JPEG quality settings like Q=30, GAP-Diff maintained its effectiveness. As the quality factor increased (meaning less compression), the protection gradually decreased, but still remained significantly effective, showcasing a stable performance curve.
  • Noise Budget and Technique: The studies also compared different perturbation techniques. Random noise was found to be less effective because it interfered indiscriminately with the pixel-level noise structure, which is easily discarded by JPEG. In contrast, the learned Go Blue noise, specifically targeted into the training preprocessing layer, proved highly protective. Additionally, techniques like quantization and resolution changes that impact high-frequency components were noted to work well, but GAP-Diff's strength lies in its focus on low-frequency patterns, which are inherently more resilient to compression.

These demonstrations and evaluation studies collectively served as a strong proof of concept, illustrating GAP-Diff's ability to generate compression-resistant protective noise that effectively safeguards facial privacy against advanced diffusion-based customization attacks.

Defensive Implications

▶ Watch: Conclusion: One-step noise generation, future API development (10:10)

GAP-Diff presents a crucial tool for individuals and organizations seeking to protect facial privacy in an era dominated by advanced text-to-image diffusion models. The primary defensive implication is the ability to proactively embed compression-resistant protective noise into images before they are shared or uploaded to online platforms. This ensures that even if these images undergo ubiquitous JPEG compression, their protective attributes remain intact, rendering them unsuitable for malicious facial customization.

Defenders should consider integrating GAP-Diff or similar techniques into their image processing pipelines. For instance, a user could run their photos through a GAP-Diff-powered tool before uploading them to social media, knowing that the embedded noise will protect their likeness from being misused by AI models. This shifts the paradigm from reactive detection of deepfakes to proactive prevention at the source.

The speaker mentioned plans to develop a survey API for protection and open-source their training stages. This commitment is vital for broader adoption and allows for custom implementations. Organizations handling sensitive facial data, such as healthcare providers, government agencies, or even large corporations with employee photos, could leverage such an API to automatically apply GAP-Diff protection to all outgoing images containing faces. Open-sourcing the training stages would also enable researchers and practitioners to fine-tune the balance between protection effectiveness and visual quality for specific use cases, or to adapt the framework to new compression standards or image processing techniques.

Furthermore, the intention to expand the method to include additional preprocessing and customization technologies suggests a future-proof approach. As diffusion models evolve and new forms of image manipulation emerge, GAP-Diff's adaptable framework could be extended to counter these new threats, offering a continuous line of defense. This research underscores the importance of embedding privacy-enhancing technologies directly into the data itself, rather than relying solely on external detection mechanisms, providing a robust layer of protection against the misuse of AI for facial manipulation.

Key Takeaways

  • JPEG Compression is a Vulnerability: Existing facial protection methods against diffusion models often fail after common JPEG compression, as they rely on high-frequency noise easily discarded by the compression algorithm.
  • GAP-Diff Offers Compression Resistance: The GAP-Diff framework generates protective noise that remains effective even after aggressive JPEG compression (e.g., Q=5), by focusing on low-frequency patterns and learning compression-resilient noise.
  • Adversarial Learning is Key: GAP-Diff uses a sophisticated adversarial approach, incorporating a GAN-based generator, a preprocessing simulation model, and a fine-tuned T2I diffusion model to optimize noise for both disruption and compression survival.
  • Efficient One-Step Protection: Unlike iterative methods, GAP-Diff enables efficient, one-step noise generation, making it practical for rapid deployment and application in real-world scenarios.
  • Proactive Privacy Defense: GAP-Diff provides a proactive defense mechanism, allowing individuals and organizations to safeguard facial privacy by embedding protective noise before image sharing, preventing misuse by AI customization models.
  • Future-Proofing and Accessibility: The researchers plan to release an API and open-source training stages, indicating a commitment to making this powerful protection more accessible and adaptable to evolving threats and image processing techniques.

About the Speaker(s)

The work on GAP-Diff was presented on behalf of Haotian Zhu at the NDSS Symposium. Haotian Zhu is credited as the author of this significant research, which delves into the critical area of protecting digital privacy against the misuse of advanced AI technologies. While specific biographical details such as their affiliation or title were not detailed in the transcript, the depth and technical sophistication of the GAP-Diff framework highlight Haotian Zhu's expertise in machine learning security, adversarial AI, and image processing. Their contribution addresses a pressing issue in the intersection of AI capabilities and personal data security, providing a robust solution to safeguard facial privacy in an increasingly AI-driven digital landscape.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

GAP-Diff tackles a real and underappreciated failure mode — adversarial protective noise collapsing under JPEG compression — and the GAN-based, frequency-aware solution is technically coherent. Solid academic work, but it's narrow in scope, the arms-race dynamics are largely unaddressed, and the presentation itself is clearly a transcript of a proxy delivery, which dulls the impact.

Heather Calloway (CISO) — WEAK

Technically credible research that closes a real gap in adversarial image protection, but it never crosses the threshold into governance, organizational risk, or actionable defender guidance. This is a machine learning paper delivered as a conference talk, not a security program intervention.

→ Top-rated talks at Network and Distributed System Security (NDSS) Symposium 2025

All talks from Network and Distributed System Security (NDSS) Symposium 2025