I have run the Facklock at default attack_budget on the FFHQ val dataset.
There are the original images and the defended images, the artifacts are so obvious!
Some prompts destroy the personal information, while others do not.




-Edit images
Turn the person's hair pink


Turn the person into a zombie


let the person have a tattoo


let the person wear a police suit


I have run the Facklock at default attack_budget on the FFHQ val dataset.
There are the original images and the defended images, the artifacts are so obvious!
Some prompts destroy the personal information, while others do not.
-Edit images
Turn the person's hair pink
Turn the person into a zombie
let the person have a tattoo
let the person wear a police suit