A team led by Zhongliang Guo released a paper on Oct 7 2026 describing SRIM, a way to embed protective perturbations in photos that survive the down‑scaling editors usually apply. Current tricks lose strength when a picture is shrunk before AI editing, letting malicious tools change the image anyway. SRIM samples several scales and focuses on the weakest one, keeping the protection strong across a wide range of resize factors.
How much better is SRIM?
Tests on 9‑ to 30‑megapixel images showed the worst‑case disruption of a popular AI editor, FLUX.2‑klein, rose from 0.192 LPIPS (the best published result before) to 0.463 LPIPS with SRIM. At the same visual visibility, the protection is roughly twice as strong. The method also worked against larger models like a 9‑billion‑parameter version and FLUX.2‑dev, raising their worst‑case scores to 0.450 and 0.386 respectively, compared with at most 0.184 for earlier defenses. It performed best on InstructPix2Pix as well.
Why it matters
For everyday users who share high‑resolution photos online, SRIM could make it harder for AI tools to silently alter their images after resizing. It offers a stronger safeguard without making the added noise more noticeable. However, the technique is still a research prototype and not yet built into consumer photo apps.