Cyclic Denoising Memory Extraction
Abstract
We introduce cyclic denoisingrepeated forward and reverse diffusion at controlled noise amplitudesas an extraction attack for image diffusion models. Inspired by random organization in disordered solids, where cyclic mechanical perturbations anneal the system into increasingly stable configurations, cyclic denoising exposes regions of the learned distribution that remain largely inaccessible to standard sampling. We find that these dynamics drive samples toward attractors with a broad stability spectrum, with the deepest attractors exhibiting ultrastability: they can be regenerated from near-total corruption and sustained through thousands of noisingdenoising cycles. Many of these deep attractors correspond to memorized training images, including stock photographs, brand watermarks, and web-crawl artifacts. Our extraction attack requires only samplerlevel controlthe ability to partially noise a sample to an intermediate diffusion timestep and denoise it backbut no gradients and no weight inspection. Crucially, cyclic denoising requires no prior knowledge of training data, captions, or prompts. In contrast, prior generate-and-filter attacks on production-scale diffusion models commonly rely on large-scale prompted generation from known or suspected training captions, followed by post-hoc similarity search or membershipinference filtering to identify memorized candidates. While cyclic denoising can also be applied with prompts, our main protocol is fully unconditioned. We demonstrate the phenomenon in Stable Diffusion v1.4, a latent diffusion model, and in a smaller pixel-space DDPM, showing consistent behavior across latent- and pixel-space diffusion models. Across noise amplitudes, we observe a yielding-like transition: low-amplitude cycling produces either trivial absorbing fixed points (featureless, near-monochromatic images) or limit cycles (traveling/oscillating Turing-like patterns in image space), while larger amplitudes induce rearrangements, basin hopping, and long-lived trapping in structured memorized attractor basins. We further observe hierarchical partial absorption, where coarse scene layout freezes while fine details remain diffusive, as well as prompt-stabilized basins and cross-initial-condition universality of the recovered attractor set. Together, these results establish cyclic denoising as both a physics-inspired probe of generative landscapes and a practical tool for memorization auditing, with implications for privacy, copyright compliance, and model fingerprinting.