Fragile by Design: On the Limits of Adversarial Defenses in Personalized DreamBooth Generation

Published in AAAI Conference on Artificial Intelligence 2026, 2026

This paper examines vulnerabilities in privacy-protecting mechanisms for customized image generation systems such as DreamBooth. We identify two significant weaknesses in existing defenses: adversarial examples often exhibit perceptible artifacts, and the perturbations can be eliminated through simple filtering. We introduce AntiDB_Purify, a testing framework that evaluates defenses against realistic purification attacks. Our findings demonstrate that current protective methods fail under such threats, revealing that they provide insufficient security for preserving user identity in personalized generation applications.