Erase but Preserve: Controllable Removal of Copyrighted Animation Characters via Optimized Semantic Anchors
Qiao Li, Xiaomeng Fu, Wangjia Yu, Runze He, Baisen Wang, Jiao Dai, Jizhong Han
Institute of Information Engineering, Chinese Academy of Sciences · School of Cyber Security, University of Chinese Academy of Sciences
cs.CV, cs.AI
Submitted: 2026-08-13
Updated: 2026-08-14
Comments: Accepted to ACM MM 2026
Code: https://github.com/LAION-AI/aestheticpredictor
License: http://creativecommons.org/licenses/by/4.0/
Importance score: 75/100
The gist: This paper proposes a controllable method to erase copyrighted animation characters from text-to-image diffusion models during generation, while preserving overall image fidelity.
Terminology
Summary
This paper proposes a controllable method to erase copyrighted animation characters from text-to-image diffusion models during generation, while preserving overall image fidelity. The method operates on the model's continuous textual representation by optimizing an anchor embedding that serves as a benign surrogate for the target character. The anchor is constructed using two constraints: a structural constraint that ensures the anchor shares a similar outline with the target (using a low-frequency filter on reconstructed samples at large timesteps), and a detailed constraint that differentiates the anchor's fine features from the target (by maximizing noise prediction error on a reference image at intermediate timesteps). The anchor embedding is optimized in the CLIP text encoder's embedding space. During inference, target-related embeddings in the prompt are replaced with the optimized anchor embedding, and special embeddings (EOT and Paddings) are fused via element-wise addition. A structure-aware adaptive replacement strategy is introduced, which tracks low-frequency structural changes across denoising timesteps and triggers embedding replacement only when the layout stabilizes, preserving global structure. Experiments on a dataset of 80 animation characters show state-of-the-art erasure effectiveness (LLaVA-1.5 accuracy 6.0%, BLIP-3 accuracy 4.0%) and image fidelity preservation (SSIM 0.467, LPIPS 0.505, Aesthetic 5.18) compared to baselines like SLD, SAFREE, STG, TraSCE, and Negative Prompting. The method supports fine-grained control over erasure degree via interpolation between target and anchor embeddings (α ∈ [0,1]), simultaneous multi-target removal, and transferability across model versions (SD v1.4, v1.5, v2, v2.1, SDXL, and DiT-based Z-Image). Additionally, the optimized anchors are plug-and-play with model modification baselines (MACE, UCE, ESD-u, AC), improving their erasure performance compared to using general anchors.
Improvements for AI systems
Improvements to AI systems:
-
Adaptive, structure-aware content filtering in generative models – The system can now dynamically track low-frequency structural changes during the denoising process and only apply embedding replacement when the layout stabilizes. This prevents over-erasure and preserves global composition, enabling safer deployment of text-to-image models in commercial settings where copyrighted characters must be excluded without degrading scene integrity.
-
Continuous, fine-grained control over concept removal – By interpolating between target and anchor embeddings (α ∈ [0,1]), the AI can offer users a slider-like control to partially or fully erase a character. This allows for nuanced content moderation (e.g.,
reduce resemblance
vs.completely remove
) in creative tools, while maintaining the ability to keep non-infringing stylistic elements. -
Multi-target simultaneous erasure – The system can now remove multiple copyrighted characters in a single generation pass without sequential processing or quality loss. This improves efficiency in batch content moderation pipelines, enabling real-time filtering of prompts containing several protected entities.
-
Cross-version and cross-architecture transferability – The optimized anchor embeddings work across SD v1.4, v1.5, v2, v2.1, SDXL, and DiT-based models without retraining. This allows a single, pre-computed
erasure library
to be deployed across heterogeneous model families, reducing maintenance overhead and enabling consistent policy enforcement in multi-model AI services. -
Plug-and-play enhancement for existing model-modification baselines – The anchors can be injected into MACE, UCE, ESD-u, and AC methods, boosting their erasure accuracy. This means existing safety systems can be upgraded without redesign, simply by swapping in the optimized anchor embeddings, leading to immediate improvements in compliance for deployed AI image generators.
-
Low-frequency structural fidelity preservation – The system uses a low-frequency filter on reconstructed samples at large timesteps to ensure the anchor shares only the outline, not the fine details, of the target. This enables the AI to maintain high image fidelity (SSIM 0.467, LPIPS 0.505, Aesthetic 5.18) while erasing characters, making it suitable for high-quality art generation where background and lighting must remain intact.
-
Automated, benchmark-validated content safety – With LLaVA-1.5 accuracy dropping to 6.0% and BLIP-3 to 4.0% on character recognition, the improved system can be used as a robust guardrail in automated content generation APIs, significantly reducing the risk of accidental copyright infringement in user-facing products.
What the improved AI system can do:
-
Generate images from prompts that mention copyrighted characters, but output legally safe, visually coherent alternatives (e.g., a
red-caped hero
instead of a specific anime character) without user-visible artifacts. -
Offer creators a
style preservation
mode where the character's silhouette is kept but facial features and unique identifiers are altered, enabling homage without infringement. -
Operate in real-time on cloud-based text-to-image services to filter prompts containing multiple protected IPs, with adjustable strictness per user tier.
-
Seamlessly update safety policies across all deployed model versions (from older SD v1.4 to newer DiT-based models) by simply swapping anchor files, without downtime or retraining.
-
Integrate into existing safety toolkits (e.g., Stable Diffusion's safety checker) to boost their erasure performance, making them more reliable for enterprise clients.
Abstract
The exceptional generation capabilities of text-to-image diffusion models have raised copyright concerns, particularly the unauthorized reproduction of animation characters. Existing concept erasure methods fall short for animation character erasure: model modification methods struggle to identify suitable anchors for diverse, highly distinctive characters; prompt-based steering methods lack fine-grained control for precise intervention. These approaches often yield incomplete erasure and degraded image fidelity, hindering real-world deployment. In this paper, we propose a controllable method operating on the model's continuous textual representation to erase target characters during generation. We optimizes an anchor embedding via structural and detailed constraints to serve as a character surrogate, then replaces target-related embeddings with the anchor via a structure-aware adaptive strategy. Experiments show that our method achieves state-of-the-art erasure effectiveness and image fidelity preservation, while supporting controllable erasure degree, multi-target removal, and model transferability. Moreover, our optimized anchors are plug-and-play with current model modification baselines to improve their erasure performance.
Sources
- GPT-4 Technical Report
- eDiff-I: Text-to-Image Diffusion Models with an Ensemble of Expert Denoisers
- Erasing Undesirable Concepts in Diffusion Models with Adversarial Preservation
- Classifier-Free Diffusion Guidance
- TraSCE: Trajectory Steering for Concept Erasure
- Diffusion Models already have a Semantic Latent Space
- SPEED: Scalable, Precise, and Efficient Concept Erasure for Diffusion Models
- RGBT Tracking via All-layer Multimodal Interactions with Progressive Fusion Mamba
- Disguised Copyright Infringement of Latent Diffusion Models
- Hierarchical Text-Conditional Image Generation with CLIP Latents
- Denoising Diffusion Implicit Models
- Z-Image: An Efficient Image Generation Foundation Model with Single-Stream Diffusion Transformer
- Beyond Fixed Anchors: Precisely Erasing Concepts with Sibling Exclusive Counterparts
Related papers
- Loss Knows Best: Detecting Annotation Errors in Videos via Loss Trajectories
- AnchorWeave: World-Consistent Video Generation with Retrieved Local Spatial Memories
- Benchmarking the Robustness of Foundation Models for Mammography under Domain Shift
- MambaX-Net: Dual-Input Mamba-Enhanced Cross-Attention Network for Longitudinal MRI Segmentation
- TeleOCR: Navigating Document Parsing Across Digital and Camera-Captured Documents
- A Survey on Efficient Vision-Language-Action Models