AdLift: Lifting Adversarial Perturbations to Safeguard 3D Gaussian Splatting Assets Against Instruction-Driven Editing
- URL: http://arxiv.org/abs/2512.07247v1
- Date: Mon, 08 Dec 2025 07:41:23 GMT
- Title: AdLift: Lifting Adversarial Perturbations to Safeguard 3D Gaussian Splatting Assets Against Instruction-Driven Editing
- Authors: Ziming Hong, Tianyu Huang, Runnan Chen, Shanshan Ye, Mingming Gong, Bo Han, Tongliang Liu,
- Abstract summary: We propose the first editing safeguard for 3DGS, termed AdLift, which prevents instruction-driven editing across arbitrary views and dimensions.<n>We alternate between gradient truncation and image-to-Gaussian fitting, yielding consistent adversarial-based protection performance across different viewpoints.
- Score: 109.07334219188222
- License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/
- Abstract: Recent studies have extended diffusion-based instruction-driven 2D image editing pipelines to 3D Gaussian Splatting (3DGS), enabling faithful manipulation of 3DGS assets and greatly advancing 3DGS content creation. However, it also exposes these assets to serious risks of unauthorized editing and malicious tampering. Although imperceptible adversarial perturbations against diffusion models have proven effective for protecting 2D images, applying them to 3DGS encounters two major challenges: view-generalizable protection and balancing invisibility with protection capability. In this work, we propose the first editing safeguard for 3DGS, termed AdLift, which prevents instruction-driven editing across arbitrary views and dimensions by lifting strictly bounded 2D adversarial perturbations into 3D Gaussian-represented safeguard. To ensure both adversarial perturbations effectiveness and invisibility, these safeguard Gaussians are progressively optimized across training views using a tailored Lifted PGD, which first conducts gradient truncation during back-propagation from the editing model at the rendered image and applies projected gradients to strictly constrain the image-level perturbation. Then, the resulting perturbation is backpropagated to the safeguard Gaussian parameters via an image-to-Gaussian fitting operation. We alternate between gradient truncation and image-to-Gaussian fitting, yielding consistent adversarial-based protection performance across different viewpoints and generalizes to novel views. Empirically, qualitative and quantitative results demonstrate that AdLift effectively protects against state-of-the-art instruction-driven 2D image and 3DGS editing.
Related papers
- UP-Fuse: Uncertainty-guided LiDAR-Camera Fusion for 3D Panoptic Segmentation [17.310791153991975]
We introduce UP-Fuse, a novel uncertainty-aware fusion framework in the 2D range-view.<n>Raw LiDAR data is first projected into the range-view and encoded by a LiDAR encoder.<n>Camera features are simultaneously extracted and projected into the same shared space.
arXiv Detail & Related papers (2026-02-22T21:34:29Z) - ERGO: Excess-Risk-Guided Optimization for High-Fidelity Monocular 3D Gaussian Splatting [63.138778159026934]
We propose an adaptive optimization framework guided by excess risk decomposition, termed ERGO.<n> ERGO dynamically estimates the view-specific excess risk and adaptively adjust loss weights during optimization.<n>Experiments on the Google Scanned Objects dataset and the OmniObject3D dataset demonstrate the superiority of ERGO over existing state-of-the-art methods.
arXiv Detail & Related papers (2026-02-10T20:44:43Z) - Towards Transferable Defense Against Malicious Image Edits [70.17363183107604]
Transferable Defense Against Malicious Image Edits (TDAE) is a novel bimodal framework that enhances image immunity against malicious edits.<n>We introduce FlatGrad Defense Mechanism (FDM), which incorporates gradient regularization into the adversarial objective.<n>For textual enhancement protection, we propose Dynamic Prompt Defense (DPD), which periodically refines text embeddings to align the editing outcomes of immunized images with those of the original images.
arXiv Detail & Related papers (2025-12-16T12:10:16Z) - RDSplat: Robust Watermarking Against Diffusion Editing for 3D Gaussian Splatting [86.86361440345861]
3DGS watermarking methods remain highly vulnerable to diffusion-based editing.<n>This paper introduces RDSplat, a Robust watermarking paradigm against diffusion-based editing.<n> RDSplat embeds watermarks into 3DGS components that diffusion-based editing inherently preserve.
arXiv Detail & Related papers (2025-12-07T10:26:35Z) - RobustSplat++: Decoupling Densification, Dynamics, and Illumination for In-the-Wild 3DGS [85.90134051583368]
3D Gaussian Splatting (3DGS) has gained significant attention for its real-time, photo-realistic rendering in novel-view synthesis and 3D modeling.<n>Existing methods struggle with accurately modeling in-the-wild scenes affected by transient objects and illuminations.<n>We propose RobustSplat++, a robust solution based on several critical designs.
arXiv Detail & Related papers (2025-12-04T14:05:09Z) - Can Protective Watermarking Safeguard the Copyright of 3D Gaussian Splatting? [32.5671407737127]
3D Gaussian Splatting (3DGS) has emerged as a powerful representation for 3D scenes, widely adopted due to its exceptional efficiency and high-fidelity visual quality.<n>Recent works have introduced specialized watermarking schemes to ensure copyright protection and ownership verification.<n>We propose GSPure, the first watermark purification framework specifically for 3DGS watermarking representations.
arXiv Detail & Related papers (2025-11-27T09:39:51Z) - RemedyGS: Defend 3D Gaussian Splatting against Computation Cost Attacks [15.039068315115372]
We propose the first effective and comprehensive black-box defense framework, named RemedyGS, against computation cost attacks.<n>Our framework effectively defends against white-box, black-box, and adaptive attacks in 3DGS systems, achieving state-of-the-art performance in both safety and utility.
arXiv Detail & Related papers (2025-11-27T06:35:08Z) - BSGS: Bi-stage 3D Gaussian Splatting for Camera Motion Deblurring [32.5099324617965]
Bi-Stage 3D Gaussian Splatting is a novel framework to reconstruct 3D scenes from motion-blurred images.<n>We propose a subframe gradient aggregation strategy to optimize both stages.<n>Experiments verify the effectiveness of our proposed deblurring method and show its superiority over the state of the arts.
arXiv Detail & Related papers (2025-10-14T13:26:56Z) - Semantic Causality-Aware Vision-Based 3D Occupancy Prediction [63.752869043357585]
Vision-based 3D semantic occupancy prediction is a critical task in 3D vision.<n>Existing methods, however, often rely on modular pipelines.<n>We propose a novel causal loss that enables holistic, end-to-end supervision of the modular 2D-to-3D transformation pipeline.
arXiv Detail & Related papers (2025-09-10T08:29:22Z) - Gradient-Direction-Aware Density Control for 3D Gaussian Splatting [7.234328187876289]
3D Gaussian Splatting (3DGS) has significantly advanced novel view synthesis through explicit scene representation.<n>Existing approaches manifest two critical limitations in complex scenarios.<n>We present Gradient-Direction-Aware Gaussian Splatting (GDAGS), a gradient-direction-aware adaptive density control framework.
arXiv Detail & Related papers (2025-08-12T13:12:54Z) - GuardSplat: Efficient and Robust Watermarking for 3D Gaussian Splatting [70.81218231206617]
GuardSplat is an innovative and efficient framework for watermarking 3DGS assets.<n>Message Embedding module seamlessly embeds messages into the SH features of each 3D Gaussian while preserving the original 3D structure.<n>Anti-distortion Message Extraction module improves robustness against various distortions.
arXiv Detail & Related papers (2024-11-29T17:59:03Z) - Distractor-free Generalizable 3D Gaussian Splatting [26.762275313390194]
We present DGGS, a novel framework that addresses the previously unexplored challenge: $textbfDistractor-free Generalizable 3D Gaussian Splatting$ (3DGS)<n>It mitigates 3D inconsistency and training instability caused by distractor data in the cross-scenes generalizable train setting.<n>Our generalizable mask prediction even achieves an accuracy superior to existing scene-specific training methods.
arXiv Detail & Related papers (2024-11-26T17:17:41Z) - GaussianMarker: Uncertainty-Aware Copyright Protection of 3D Gaussian Splatting [41.90891053671943]
Digital watermarking techniques can be applied to embed ownership information discreetly within 3DGS models.
Naively embedding the watermark on a pre-trained 3DGS can cause obvious distortion in rendered images.
We propose an uncertainty-based method that constrains the perturbation of model parameters to achieve invisible watermarking for 3DGS.
arXiv Detail & Related papers (2024-10-31T08:08:54Z)
This list is automatically generated from the titles and abstracts of the papers in this site.
This site does not guarantee the quality of this site (including all information) and is not responsible for any consequences.