Search papers, labs, and topics across Lattice.
This survey investigates the emerging paradigm of "adversarial attacks for good," where data owners leverage adversarial techniques to protect visual content throughout its lifecycle against unauthorized use. By categorizing interventions into five distinct stages鈥攑rivacy filters, unlearnable examples, generative safeguards, adversarial CAPTCHAs, and provenance mechanisms鈥攖he authors highlight the independent yet converging efforts of various research communities. The study reveals that while these protective measures show promise, they often lack validation against dynamic adversaries, indicating a critical gap in deployment readiness and effectiveness in real-world scenarios.
Adversarial techniques traditionally seen as threats are now being repurposed by content owners to proactively safeguard their visual assets from misuse.
Once visual content enters an AI pipeline, its owner often retains little technical control over how it is used. Legal and regulatory remedies can address misuse, but many technical interventions must be applied earlier, when content is released or accessed. This survey examines the protective paradigm that has grown around this intervention point, which we call adversarial attacks for good. Perturbations and structured signals long studied as attacks on learned models are instead applied by data owners, creators, platforms, or auditors to disrupt unauthorized automation or support later accountability. Five research communities have arrived at this inversion largely independently, each addressing a different stage of a visual asset's lifecycle: privacy filters against unwanted recognition at sharing time, unlearnable examples against unauthorized training, generative safeguards against malicious editing or imitation, adversarial CAPTCHAs for access control against automated agents, and provenance mechanisms for post-circulation attribution. Although developed in separate venues with incompatible success criteria, many of these methods exploit persistent gaps between human perception, semantic interpretation, and machine inference, suggesting that the paradigm remains relevant as visual pipelines evolve toward multimodal models and autonomous agents. To make their claims comparable, we evaluate all five families along shared axes of transferability, adaptability, and deployment readiness. Across the lifecycle, we find that most protections are still validated mainly against static or weakly adaptive adversaries, while evidence beyond controlled benchmarks remains scarce. We close by consolidating cross-stage countermeasures and open problems for robust, composable, and deployable owner-side protection.