Anonymization-Guided Latent Perturbation for Source-Identity Reduction with Limited Edit Deviation in Instruction-Guided Image Editing
Sanghyeok Seo, Jiwoo Kim, Jong-Uk HouInstruction-guided image editing can modify semantic attributes while retaining the recognizable identity of the source subject, creating risks of unauthorized identity-based manipulation. Existing protection methods can achieve stronger identity disruption, but such outcomes may be accompanied by larger changes to the resulting edit. We investigate a complementary protection strategy and evaluate source-identity reduction jointly with deviation from the corresponding undefended edit. The proposed method constructs an anonymized counterpart of the source image and uses its variational autoencoder (VAE) representation as a source-conditioned latent reference. An ℓ∞-bounded pixel-space perturbation is then optimized to move the protected representation toward this anonymization-derived target. Experiments on 9998 CelebA-Wild images show that the proposed method reduces mean face-recognition (FR) similarity from 0.620 to 0.567. In the primary HIVE setting, it achieves the lowest LPIPS and the highest PSNR and SSIM among the evaluated defenses, while FaceLock and the CW-L2 attack achieve lower FR similarity at substantially larger reference-edit deviation. On InstructPix2Pix, the proposed method achieves an FR score comparable to PhotoGuard, with an LPIPS of 0.262 versus 0.428 for PhotoGuard. These results indicate that anonymization-guided latent perturbation provides a distinct identity–edit-deviation operating point, reducing source-identity similarity while limiting deviation from the corresponding undefended edit.