LinghuiiShen/DeContext

Python

22

50 commits

updated Dec 19, 2025

See the code

README

DeContext: Safe Image Editing in Diffusion Transformers

πŸ“„ Paper β€’ 🌐 Project Page β€’ πŸš€ Quick Start


DeContext as Defense: Safe Image Editing in Diffusion Transformers
Linghui Shen, Mingyue Cui, Xingyi Yang
The Hong Kong Polytechnic University

πŸ“š Table of Contents


πŸ” About

DeContext is a defense method for DiT-based in-context image editing models that protects user images from unauthorized identity manipulation.

By injecting imperceptible, attention-aware perturbations into the input image, DeContext weakens cross-attention pathways, preventing identity leakage while preserving visual quality.


⚠️ Motivation: Privacy Risk in In-Context Image Editing

Recent diffusion transformers (DiTs) such as FLUX-Kontext and Step1X-Edit enable powerful in-context image editing using a single reference image. While effective, this capability introduces serious privacy risks that personal images can be edited without the owner’s consent.


🧠 Method Overview

DeContext is based on a key observation:

In Diffusion Transformers, contextual information propagates primarily through cross-attention layers.

Instead of attacking the output or retraining the model, DeContext:

  • Targets cross-attention between target and context tokens
  • restricting the optimization to early, high-noise timesteps and early-to-middle, context-heavy transformer blocks
  • Injects subtle perturbations into the input image and effectively detaches the context


πŸš€ Quick Start

πŸ› οΈ Installation

cd DeContext
Create and activate conda environment

(Optional):

conda create -n decontext python=3.12
conda activate decontext
Install dependencies:
pip install -r requirements.txt

πŸ”₯ How to Run

1️⃣ Attack on Flux Kontext

Run the attack script:
bash ./scripts/attack_kontext.sh
Run inference:
python ./inference/kontext_inference.py

2️⃣ Attack on Step1X-Edit

πŸ“₯ Download Required Models

Download the following models and place them in ./attack/attack_Step1X_Edit/models:

Note: For more details, refer to the Step1X-Edit repository.

Install dependencies of Step1X-Edit
pip install -r attack/attack_Step1X_Edit/requirements.txt
Run Attack
bash ./scripts/attack_step1x.sh
Run Inference
python ./inference/step1x_inference.py

πŸ“š Citation

@misc{shen2025decontextdefensesafeimage,
      title={DeContext as Defense: Safe Image Editing in Diffusion Transformers}, 
      author={Linghui Shen and Mingyue Cui and Xingyi Yang},
      year={2025},
      eprint={2512.16625},
      archivePrefix={arXiv},
      primaryClass={cs.CV},
      url={https://arxiv.org/abs/2512.16625}, 
}

πŸ™ Acknowledgements

Our work is built upon Diffusers and Step1X-Edit. Thanks for their excellent work!

LinghuiiShen/DeContext

Python

22

50 commits

updated Dec 19, 2025

See the code

README

DeContext: Safe Image Editing in Diffusion Transformers

πŸ“„ Paper β€’ 🌐 Project Page β€’ πŸš€ Quick Start


DeContext as Defense: Safe Image Editing in Diffusion Transformers
Linghui Shen, Mingyue Cui, Xingyi Yang
The Hong Kong Polytechnic University

πŸ“š Table of Contents


πŸ” About

DeContext is a defense method for DiT-based in-context image editing models that protects user images from unauthorized identity manipulation.

By injecting imperceptible, attention-aware perturbations into the input image, DeContext weakens cross-attention pathways, preventing identity leakage while preserving visual quality.


⚠️ Motivation: Privacy Risk in In-Context Image Editing

Recent diffusion transformers (DiTs) such as FLUX-Kontext and Step1X-Edit enable powerful in-context image editing using a single reference image. While effective, this capability introduces serious privacy risks that personal images can be edited without the owner’s consent.


🧠 Method Overview

DeContext is based on a key observation:

In Diffusion Transformers, contextual information propagates primarily through cross-attention layers.

Instead of attacking the output or retraining the model, DeContext:

  • Targets cross-attention between target and context tokens
  • restricting the optimization to early, high-noise timesteps and early-to-middle, context-heavy transformer blocks
  • Injects subtle perturbations into the input image and effectively detaches the context


πŸš€ Quick Start

πŸ› οΈ Installation

cd DeContext
Create and activate conda environment

(Optional):

conda create -n decontext python=3.12
conda activate decontext
Install dependencies:
pip install -r requirements.txt

πŸ”₯ How to Run

1️⃣ Attack on Flux Kontext

Run the attack script:
bash ./scripts/attack_kontext.sh
Run inference:
python ./inference/kontext_inference.py

2️⃣ Attack on Step1X-Edit

πŸ“₯ Download Required Models

Download the following models and place them in ./attack/attack_Step1X_Edit/models:

Note: For more details, refer to the Step1X-Edit repository.

Install dependencies of Step1X-Edit
pip install -r attack/attack_Step1X_Edit/requirements.txt
Run Attack
bash ./scripts/attack_step1x.sh
Run Inference
python ./inference/step1x_inference.py

πŸ“š Citation

@misc{shen2025decontextdefensesafeimage,
      title={DeContext as Defense: Safe Image Editing in Diffusion Transformers}, 
      author={Linghui Shen and Mingyue Cui and Xingyi Yang},
      year={2025},
      eprint={2512.16625},
      archivePrefix={arXiv},
      primaryClass={cs.CV},
      url={https://arxiv.org/abs/2512.16625}, 
}

πŸ™ Acknowledgements

Our work is built upon Diffusers and Step1X-Edit. Thanks for their excellent work!

Languages

Python

99.9%