[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-85973-en":3,"doc-seo-85973-105":30,"detail-sidebar-cat-0-en-105":92},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},85973,13056703019404,"Miles","https://ap-avatar.wpscdn.com/davatar_29158cc5080c5b710cf443261637dec0",8,"Research & Report","DiffUE：通过扩散自编码器增强不可学习示例的效用-不可学习权衡","AI models are increasingly trained on personal images scraped from social media and public platforms without consent, enabling privacy violations such as unauthorized facial recognition and targeted advertising. Unlearnable examples (UEs) counter this by adding imperceptible noise so models fail to extract useful information, yet pixel-space UEs can be bypassed by relearning via adversarial training, transformations, and compression. DiffUE injects noise into the semantic space, modifying high-level features rather than pixel values, achieving robust unlearnability while preserving visual quality and utility across multiple datasets and a user study.","arXiv :2607 . 10580v1 [ cs .CV] 12 Jul 2026  \nDiffUE: Enhancing Utility-Unlearnability Trade-off of Unlearnable Examples via Diffusion  \nAutoencoders  \nSyed Irfan Ali Meerza 1 ,4 ,∗ ,†, Oktay Ozturk 1 ,†, Amir Sadovnik2, and Jian  \nLiu 1 ,3  \n1 University of Tennessee, Knoxville, TN, USA  \n2 Oak Ridge National University, Knoxville, TN, USA  \n3 University of Georgia, Athens, GA, USA  \n4 Virginia Commonwealth University, Richmond, VA, USA  \nAbstract. AI models are increasingly trained on personal images scraped from social media and public platforms, often without consent, leading to serious privacy violations, such as unauthorized facial recognition and targeted advertising. To counter this, researchers have developed unlearnable examples (UEs), images modified with imperceptible noise to prevent AI models from extracting meaningful information. However, existing UE methods primarily rely on pixel-space noise, which can be bypassed by relearning strategies such as adversarial training, image transformation, and compression. While some techniques improve robustness, they often come at the expense of significant degradation in image utility and perceptual quality. In this paper, we introduce DiffUE to overcome these limitations by injecting noise into the semantic space of images instead of the pixel space. Instead of corrupting pixel values, DiffUE modifies high-level semantic features of images, ensuring robust unlearnability while preserving visual quality and utility. By leveraging a diffusion-based autoencoder framework to manipulate semantic features, DiffUE generates purposeful, natural-looking modifications that effectively resist advanced relearning strategies. Extensive experiments on four datasets, CIFAR-10, CIFAR-100, CelebA-HQ, and ImageNet, as well as a subjective user study, demonstrate that DiffUE significantly enhances the trade-off between image quality and unlearnability, offering a more robust and effective solution for safeguarding personal data in an increasingly exploitative AI landscape.  \n1 Introduction  \nThe success of state-of-the-art deep learning models relies heavily on vast datasets, often sourced from free-to-use online platforms without explicit consent. This unauthorized acquisition poses significant risks, as seen in cases where personal data, including facial images and medical records, have been exploited in commercial AI models [7,3] . Public concern about these practices has spurred interest in privacy protections, reinforced by regulations such as GDPR [33] and  \n⋆ Work done while at the University of Tennessee, Knoxville.† These authors contributed equally.  \n2 Meerza et al.  \nFig. 1: Usability vs. unlearnability comparison under adversarial training with an adversarial perturbation radius of ρa = 4/255 . We compared DiffUE with three baselines: EM [9], REM [4] and SEM [20] . The number below each image represents the defensive noise radii (ρu ) applied (the defensive noise of DiffUE is in the semantic space), with the value in parentheses indicating the test accuracy achieved. Lower accuracy reflects greater unlearnability. Note that we intentionally selected images with a light background to better visualize perturbation artifacts in existing UE methods.  \nCCPA [10] . However, these regulations focus primarily on data collection and governance rather than addressing the core issue: once data are acquired and integrated into AI training pipelines, few mechanisms exist to prevent its continued use. To bridge this gap, recent research has introduced the concept of making data unlearnable to AI models. Huang et al. [9] proposed unlearnable examples (UE), a technique that adds imperceptible noise to the data, causing models to fail in extracting useful information. This approach uses error-minimizing (EM) noise to yield near-zero loss during training, tricking the model into “learning”nothing from the protected data.  \nBuilt on this foundation, subsequent research has focused on enhancing th","cbCainA2YKtLAII8","https://ap.wps.com/l/cbCainA2YKtLAII8","pdf",1795215,5,1,18,"English","en",105,"# Introduction\n# DiffUE Framework and Motivation\n## Fragility of Unlearnable Examples\n## Poor Usability in Real-World Settings\n# Related Work","[{\"question\":\"什么是不可学习示例（Unlearnable Examples, UEs），它们如何提升隐私保护？\",\"answer\":\"UEs是在图像中加入不可察觉噪声，使AI难以提取有效信息，从而降低模型对受保护数据的学习与利用能力。该思路旨在阻断如人脸识别等潜在滥用。\"},{\"question\":\"现有UE方法为什么会被“重新学习”绕过？\",\"answer\":\"很多方法主要依赖像素空间的扰动，攻击者可通过对抗训练、图像变换（如重采样、压缩、灰度化）等重学习策略，使模型仍能获得有用信息。\"},{\"question\":\"DiffUE相比像素空间噪声的核心改进是什么？\",\"answer\":\"DiffUE不在像素值层面破坏图像，而是在语义空间注入噪声，修改高层语义特征。这样在提高不可学习性的同时，能更好地保留视觉质量与效用。\"}]",1784207499,45,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":87,"head_meta":89,"extra_data":91,"updated_unix":28},"diffue-enhancing-the-utility-unlearnability-trade-off-of-unlearnable-examples-via-diffusion-autoencoders","",{"@graph":36,"@context":86},[37,54,69],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/diffue-enhancing-the-utility-unlearnability-trade-off-of-unlearnable-examples-via-diffusion-autoencoders/85973/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":24,"description":14,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-07-26","2026-07-16",true,{"@type":66,"interactionType":67,"userInteractionCount":20},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72,78,82],{"name":73,"@type":74,"acceptedAnswer":75},"什么是不可学习示例（Unlearnable Examples, UEs），它们如何提升隐私保护？","Question",{"text":76,"@type":77},"UEs是在图像中加入不可察觉噪声，使AI难以提取有效信息，从而降低模型对受保护数据的学习与利用能力。该思路旨在阻断如人脸识别等潜在滥用。","Answer",{"name":79,"@type":74,"acceptedAnswer":80},"现有UE方法为什么会被“重新学习”绕过？",{"text":81,"@type":77},"很多方法主要依赖像素空间的扰动，攻击者可通过对抗训练、图像变换（如重采样、压缩、灰度化）等重学习策略，使模型仍能获得有用信息。",{"name":83,"@type":74,"acceptedAnswer":84},"DiffUE相比像素空间噪声的核心改进是什么？",{"text":85,"@type":77},"DiffUE不在像素值层面破坏图像，而是在语义空间注入噪声，修改高层语义特征。这样在提高不可学习性的同时，能更好地保留视觉质量与效用。","https://schema.org",{"og:url":52,"og:type":88,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":90,"canonical":52},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":93},[94,98,102,106,110,115,120,123,128,131,135],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":95,"show_sort_weight":96,"slug":97},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":99,"show_sort_weight":100,"slug":101},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":103,"show_sort_weight":104,"slug":105},"Exam",70,"exam",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":20,"slug":138},19,"General","general"]