{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/arxiv-2511-00143","title":"BlurGuard: A Simple Approach for Robustifying Image Protection Against AI-Powered Editing","arxiv_id":"2511.00143","date":"2025-10-31","proceeding":"NeurIPS","authors":["Jinsu Kim","Yunhun Nam","Minseon Kim","Sangpil Kim","Jongheon Jeong"],"abstract":"Recent advances in text-to-image models have increased the exposure of powerful image editing techniques as a tool, raising concerns about their potential for malicious use. An emerging line of research to address such threats focuses on implanting \"protective\" adversarial noise into images before their public release, so future attempts to edit them using text-to-image models can be impeded. However, subsequent works have shown that these adversarial noises are often easily \"reversed,\" e.g., with techniques as simple as JPEG compression, casting doubt on the practicality of the approach. In this paper, we argue that adversarial noise for image protection should not only be imperceptible, as has been a primary focus of prior work, but also irreversible, viz., it should be difficult to detect as noise provided that the original image is hidden. We propose a surprisingly simple method to enhance the robustness of image protection methods against noise reversal techniques. Specifically, it applies an adaptive per-region Gaussian blur on the noise to adjust the overall frequency spectrum. Through extensive experiments, we show that our method consistently improves the per-sample worst-case protection performance of existing methods against a wide range of reversal techniques on diverse image editing scenarios, while also reducing quality degradation due to noise in terms of perceptual metrics. Code is available at https://github.com/jsu-kim/BlurGuard.","url_abs":"https://arxiv.org/abs/2511.00143","url_pdf":"https://arxiv.org/pdf/2511.00143","source":{"archive":null,"snapshot":"2025-07-28","note":"not in the Papers with Code archive (frozen at the snapshot)","row_kind":"graph","title_abstract_authors_date":"arXiv metadata, CC0 1.0 (https://info.arxiv.org/help/license)"},"code_links":[],"tasks":[],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":"https://app.syntology.ai/?focus=2511.00143","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2511.00143"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-24T18:15:14+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"mentioned_in_github":null,"is_official":null,"provenance":"deterministic:regex_extraction","mentioned_in_paper":null,"url":"https://github.com/jsu-kim/BlurGuard","reach":null}],"summary":{"ran_honours":1,"ran_draft_wrong":1,"unverified":5},"by_repo_kind":{"found_in_text":{"samples":7,"ran":2,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":0,"samples":[{"code_sha256_prefix":"7a294553dd261e84","entry":"compute_histogram_fft","repo":"jsu-kim/BlurGuard","repo_kind":"found_in_text","path":"BlurGuard/code/blurguard.py","file_url":"https://github.com/jsu-kim/BlurGuard/blob/HEAD/BlurGuard/code/blurguard.py","link_basis":"first_harvest_node","language":"python","status":"ran_honours","verification_level":1,"contract_check":"HONOURS","metamorphic_tier":null,"behaviour_fingerprint":true,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"7a294553dd261e84"}},{"code_sha256_prefix":"297a87b88c2520a5","entry":"fft_fps","repo":"jsu-kim/BlurGuard","repo_kind":"found_in_text","path":"BlurGuard/code/blurguard.py","file_url":"https://github.com/jsu-kim/BlurGuard/blob/HEAD/BlurGuard/code/blurguard.py","link_basis":"first_harvest_node","language":"python","status":"ran_draft_wrong","verification_level":1,"contract_check":"MISDECLARED","metamorphic_tier":null,"behaviour_fingerprint":true,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"297a87b88c2520a5"}},{"code_sha256_prefix":"bb09224a4b82db69","entry":"LF_PGD","repo":"jsu-kim/BlurGuard","repo_kind":"found_in_text","path":"BlurGuard/code/blurguard.py","file_url":"https://github.com/jsu-kim/BlurGuard/blob/HEAD/BlurGuard/code/blurguard.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"bb09224a4b82db69"}},{"code_sha256_prefix":"549c233dc4494676","entry":"cprint","repo":"jsu-kim/BlurGuard","repo_kind":"found_in_text","path":"BlurGuard/code/blurguard.py","file_url":"https://github.com/jsu-kim/BlurGuard/blob/HEAD/BlurGuard/code/blurguard.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"549c233dc4494676"}},{"code_sha256_prefix":"60e8a2ec6c4d5856","entry":"filter_delta","repo":"jsu-kim/BlurGuard","repo_kind":"found_in_text","path":"BlurGuard/code/blurguard.py","file_url":"https://github.com/jsu-kim/BlurGuard/blob/HEAD/BlurGuard/code/blurguard.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"60e8a2ec6c4d5856"}},{"code_sha256_prefix":"d5267c3f0268fc4d","entry":"gaussian_blur","repo":"jsu-kim/BlurGuard","repo_kind":"found_in_text","path":"BlurGuard/code/blurguard.py","file_url":"https://github.com/jsu-kim/BlurGuard/blob/HEAD/BlurGuard/code/blurguard.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"d5267c3f0268fc4d"}},{"code_sha256_prefix":"e4f3c8751efa9057","entry":"infer","repo":"jsu-kim/BlurGuard","repo_kind":"found_in_text","path":"BlurGuard/code/blurguard.py","file_url":"https://github.com/jsu-kim/BlurGuard/blob/HEAD/BlurGuard/code/blurguard.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"e4f3c8751efa9057"}}]},"arxiv_metadata":{"licence":"arXiv metadata, CC0 1.0 (https://info.arxiv.org/help/license)","fields":["title","abstract","authors","date"],"primary_category":"cs.CV","source":"arxiv_api"},"syntology_extracted_results":null}