AAAI 2026technical0 citations

Fragile by Design: On the Limits of Adversarial Defenses in Personalized DreamBooth Generation

Zhen Chen, Yi Zhang, Xiangyu Yin, Chengxuan Qin, Xingyu Zhao, Xiaowei Huang, Wenjie Ruan

Abstract

Personalized AI applications such as DreamBooth enable the generation of customized content from user images, but also raise significant privacy concerns, particularly the risk of facial identity leakage. Recent defense mechanisms like Anti-DreamBooth attempt to mitigate this risk by injecting adversarial perturbations into user photos to prevent successful personalization. However, we identify two critical yet overlooked limitations of these methods. First, the adversarial examples often exhibit perceptible artifacts such as conspicuous patterns or stripes, making them easily detectable as manipulated content. Second, the perturbations are highly fragile, as even a simple, non-learned filter can effectively remove them, thereby restoring the model

BibTeX
@inproceedings{aaai2026_fragilebydesigno,
  title = {Fragile by Design: On the Limits of Adversarial Defenses in Personalized DreamBooth Generation},
  author = {Zhen Chen and Yi Zhang and Xiangyu Yin and Chengxuan Qin and Xingyu Zhao and Xiaowei Huang and Wenjie Ruan},
  booktitle = {AAAI 2026},
  year = {2026}
}