English

A Response to Glaze Purification via IMPRESS

Cryptography and Security 2023-12-14 v1

Abstract

Recent work proposed a new mechanism to remove protective perturbation added by Glaze in order to again enable mimicry of art styles from images protected by Glaze. Despite promising results shown in the original paper, our own tests with the authors' code demonstrated several limitations of the proposed purification approach. The main limitations are 1) purification has a limited effect when tested on artists that are not well-known historical artists already embedded in original training data, 2) problems in evaluation metrics, and 3) collateral damage on mimicry result for clean images. We believe these limitations should be carefully considered in order to understand real world usability of the purification attack.

Cite

@article{arxiv.2312.07731,
  title  = {A Response to Glaze Purification via IMPRESS},
  author = {Shawn Shan and Stanley Wu and Haitao Zheng and Ben Y. Zhao},
  journal= {arXiv preprint arXiv:2312.07731},
  year   = {2023}
}
R2 v1 2026-06-28T13:49:04.241Z