DeContext: Safe Image Editing in Diffusion Transformers
π Paper β’ π Project Page β’ π Quick Start
DeContext as Defense: Safe Image Editing in Diffusion Transformers
Linghui Shen, Mingyue Cui, Xingyi Yang
The Hong Kong Polytechnic University
DeContext is a defense method for DiT-based in-context image editing models that protects user images from unauthorized identity manipulation.
By injecting imperceptible, attention-aware perturbations into the input image, DeContext weakens cross-attention pathways, preventing identity leakage while preserving visual quality.
Recent diffusion transformers (DiTs) such as FLUX-Kontext and Step1X-Edit enable powerful in-context image editing using a single reference image. While effective, this capability introduces serious privacy risks that personal images can be edited without the ownerβs consent.
DeContext is based on a key observation:
In Diffusion Transformers, contextual information propagates primarily through cross-attention layers.
Instead of attacking the output or retraining the model, DeContext:
cd DeContext
(Optional):
conda create -n decontext python=3.12
conda activate decontext
pip install -r requirements.txt
bash ./scripts/attack_kontext.sh
python ./inference/kontext_inference.py
Download the following models and place them in ./attack/attack_Step1X_Edit/models:
Note: For more details, refer to the Step1X-Edit repository.
pip install -r attack/attack_Step1X_Edit/requirements.txt
bash ./scripts/attack_step1x.sh
python ./inference/step1x_inference.py
@misc{shen2025decontextdefensesafeimage,
title={DeContext as Defense: Safe Image Editing in Diffusion Transformers},
author={Linghui Shen and Mingyue Cui and Xingyi Yang},
year={2025},
eprint={2512.16625},
archivePrefix={arXiv},
primaryClass={cs.CV},
url={https://arxiv.org/abs/2512.16625},
}
Our work is built upon Diffusers and Step1X-Edit. Thanks for their excellent work!
Python
99.9%
DeContext: Safe Image Editing in Diffusion Transformers
π Paper β’ π Project Page β’ π Quick Start
DeContext as Defense: Safe Image Editing in Diffusion Transformers
Linghui Shen, Mingyue Cui, Xingyi Yang
The Hong Kong Polytechnic University
DeContext is a defense method for DiT-based in-context image editing models that protects user images from unauthorized identity manipulation.
By injecting imperceptible, attention-aware perturbations into the input image, DeContext weakens cross-attention pathways, preventing identity leakage while preserving visual quality.
Recent diffusion transformers (DiTs) such as FLUX-Kontext and Step1X-Edit enable powerful in-context image editing using a single reference image. While effective, this capability introduces serious privacy risks that personal images can be edited without the ownerβs consent.
DeContext is based on a key observation:
In Diffusion Transformers, contextual information propagates primarily through cross-attention layers.
Instead of attacking the output or retraining the model, DeContext:
cd DeContext
(Optional):
conda create -n decontext python=3.12
conda activate decontext
pip install -r requirements.txt
bash ./scripts/attack_kontext.sh
python ./inference/kontext_inference.py
Download the following models and place them in ./attack/attack_Step1X_Edit/models:
Note: For more details, refer to the Step1X-Edit repository.
pip install -r attack/attack_Step1X_Edit/requirements.txt
bash ./scripts/attack_step1x.sh
python ./inference/step1x_inference.py
@misc{shen2025decontextdefensesafeimage,
title={DeContext as Defense: Safe Image Editing in Diffusion Transformers},
author={Linghui Shen and Mingyue Cui and Xingyi Yang},
year={2025},
eprint={2512.16625},
archivePrefix={arXiv},
primaryClass={cs.CV},
url={https://arxiv.org/abs/2512.16625},
}
Our work is built upon Diffusers and Step1X-Edit. Thanks for their excellent work!
Python
99.9%