Personalization as a Shortcut for Few-Shot Backdoor Attack against Text-to-Image Diffusion Models

被引:0
|
作者
Huang, Yihao [1 ]
Juefei-Xu, Felix [2 ]
Guo, Qing [3 ,4 ]
Zhang, Jie [1 ]
Wu, Yutong [1 ]
Hu, Ming [1 ]
Li, Tianlin [1 ]
Pu, Geguang [5 ]
Liu, Yang [1 ]
机构
[1] Nanyang Technol Univ, Singapore, Singapore
[2] New York Univ, New York, NY USA
[3] Agcy Sci Technol & Res STAR, IHPC, Singapore, Singapore
[4] CFAR, Singapore, Singapore
[5] East China Normal Univ, Shanghai, Peoples R China
基金
新加坡国家研究基金会;
关键词
ADVERSARIAL ROBUSTNESS;
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Although recent personalization methods have democratized high-resolution image synthesis by enabling swift concept acquisition with minimal examples and lightweight computation, they also present an exploitable avenue for highly accessible backdoor attacks. This paper investigates a critical and unexplored aspect of text-to-image (T2I) diffusion models their potential vulnerability to backdoor attacks via personalization. By studying the prompt processing of popular personalization methods (epitomized by Textual Inversion and DreamBooth), we have devised dedicated personalization-based backdoor attacks according to the different ways of dealing with unseen tokens and divide them into two families: nouveau-token and legacy-token backdoor attacks. In comparison to conventional backdoor attacks involving the fine-tuning of the entire text-to-image diffusion model, our proposed personalization-based backdoor attack method can facilitate more tailored, efficient, and few-shot attacks. Through comprehensive empirical study, we endorse the utilization of the nouveau-token backdoor attack due to its impressive effectiveness, stealthiness, and integrity, markedly outperforming the legacy-token backdoor attack.
引用
收藏
页码:21169 / 21178
页数:10
相关论文
共 50 条
  • [11] DTIA: Disruptive Text-Image Alignment for Countering Text-to-Image Diffusion Model Personalization
    Gao, Ya
    Yang, Jing
    Wu, Minghui
    Zhao, Chenxu
    Su, Anyang
    Song, Jie
    Yu, Zitong
    DATA SCIENCE AND ENGINEERING, 2025, 10 (01) : 12 - 23
  • [12] Decoupling Control in Text-to-Image Diffusion Models
    Cao, Shitong
    Zhang, Xuejie
    Wang, Jin
    Zhou, Xiaobing
    ADVANCED INTELLIGENT COMPUTING TECHNOLOGY AND APPLICATIONS, PT VII, ICIC 2024, 2024, 14868 : 312 - 322
  • [13] DreamDrone: Text-to-Image Diffusion Models Are Zero-Shot Perpetual View Generators
    Kong, Hanyang
    Lian, Dongze
    Bi, Michael
    Wang, Xinchao
    COMPUTER VISION - ECCV 2024, PT XIII, 2025, 15071 : 324 - 341
  • [14] Ablating Concepts in Text-to-Image Diffusion Models
    Kumari, Nupur
    Zhang, Bingliang
    Wang, Sheng-Yu
    Shechtman, Eli
    Zhang, Richard
    Zhu, Jun-Yan
    2023 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV 2023), 2023, : 22634 - 22645
  • [15] Backdoor poisoning attacks against few-shot classifiers based on meta-learning
    Kato, Ganma
    Takahashi, Chako
    Suzuki, Koutarou
    IEICE NONLINEAR THEORY AND ITS APPLICATIONS, 2023, 14 (02): : 491 - 499
  • [16] Case Study of Few-Shot Learning in Text Recognition Models
    Wang, Jianzong
    Si, Shijing
    Hong, Zhenhou
    Qu, Xiaoyang
    Zhu, Xinghua
    Xiao, Jing
    WEB INFORMATION SYSTEMS ENGINEERING - WISE 2021, PT II, 2021, 13081 : 394 - 401
  • [17] Text2Video-Zero: Text-to-Image Diffusion Models are Zero-Shot Video Generators
    Khachatryan, Levon
    Movsisyan, Andranik
    Tadevosyan, Vahram
    Henschel, Roberto
    Wang, Zhangyang
    Navasardyan, Shant
    Shi, Humphrey
    2023 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV 2023), 2023, : 15908 - 15918
  • [18] SINE: SINgle Image Editing with Text-to-Image Diffusion Models
    Zhang, Zhixing
    Han, Ligong
    Ghosh, Arnab
    Metaxas, Dimitris
    Ren, Jian
    2023 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION, CVPR, 2023, : 6027 - 6037
  • [19] Unleashing Text-to-Image Diffusion Prior for Zero-Shot Image Captioning
    Luol, Jianjie
    Chen, Jingwen
    Li, Yehao
    Pan, Yingwei
    Feng, Jianlin
    Cha, Hongyang
    Yao, Ting
    COMPUTER VISION-ECCV 2024, PT LVII, 2025, 15115 : 237 - 254
  • [20] Few-Shot Image Generation by Conditional Relaxing Diffusion Inversion
    Cao, Yu
    Gong, Shaogang
    COMPUTER VISION - ECCV 2024, PT LXXXIV, 2025, 15142 : 20 - 37