Personalization as a Shortcut for Few-Shot Backdoor Attack against Text-to-Image Diffusion Models

被引:0
|
作者
Huang, Yihao [1 ]
Juefei-Xu, Felix [2 ]
Guo, Qing [3 ,4 ]
Zhang, Jie [1 ]
Wu, Yutong [1 ]
Hu, Ming [1 ]
Li, Tianlin [1 ]
Pu, Geguang [5 ]
Liu, Yang [1 ]
机构
[1] Nanyang Technol Univ, Singapore, Singapore
[2] New York Univ, New York, NY USA
[3] Agcy Sci Technol & Res STAR, IHPC, Singapore, Singapore
[4] CFAR, Singapore, Singapore
[5] East China Normal Univ, Shanghai, Peoples R China
基金
新加坡国家研究基金会;
关键词
ADVERSARIAL ROBUSTNESS;
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Although recent personalization methods have democratized high-resolution image synthesis by enabling swift concept acquisition with minimal examples and lightweight computation, they also present an exploitable avenue for highly accessible backdoor attacks. This paper investigates a critical and unexplored aspect of text-to-image (T2I) diffusion models their potential vulnerability to backdoor attacks via personalization. By studying the prompt processing of popular personalization methods (epitomized by Textual Inversion and DreamBooth), we have devised dedicated personalization-based backdoor attacks according to the different ways of dealing with unseen tokens and divide them into two families: nouveau-token and legacy-token backdoor attacks. In comparison to conventional backdoor attacks involving the fine-tuning of the entire text-to-image diffusion model, our proposed personalization-based backdoor attack method can facilitate more tailored, efficient, and few-shot attacks. Through comprehensive empirical study, we endorse the utilization of the nouveau-token backdoor attack due to its impressive effectiveness, stealthiness, and integrity, markedly outperforming the legacy-token backdoor attack.
引用
收藏
页码:21169 / 21178
页数:10
相关论文
共 50 条
  • [31] AlignDiff: Aligning Diffusion Models for General Few-Shot Segmentation
    Qiu, Ri-Zhao
    Wang, Yu-Xiong
    Hauser, Kris
    COMPUTER VISION - ECCV 2024, PT XLI, 2025, 15099 : 384 - 400
  • [32] Few-Shot Text and Image Classification via Analogical Transfer Learning
    Liu, Wenhe
    Chang, Xiaojun
    Yan, Yan
    Yang, Yi
    Hauptmann, Alexander G.
    ACM TRANSACTIONS ON INTELLIGENT SYSTEMS AND TECHNOLOGY, 2018, 9 (06)
  • [33] ProTIP: Probabilistic Robustness Verification on Text-to-Image Diffusion Models Against Stochastic Perturbation
    Zhang, Yi
    Tang, Yun
    Ruan, Wenjie
    Huang, Xiaowei
    Khastgir, Siddartha
    Jennings, Paul
    Zhao, Xingyu
    COMPUTER VISION - ECCV 2024, PT XXXII, 2025, 15090 : 455 - 472
  • [34] T2IShield: Defending Against Backdoors on Text-to-Image Diffusion Models
    Wang, Zhongqi
    Zhang, Jie
    Shan, Shiguang
    Chen, Xilin
    COMPUTER VISION - ECCV 2024, PT LXXXV, 2025, 15143 : 107 - 124
  • [35] Encoder-based Domain Tuning for Fast Personalization of Text-to-Image Models
    Gal, Rinon
    Arar, Moab
    Atzmon, Yuval
    Bermano, Amit H.
    Chechik, Gal
    Cohen-Or, Daniel
    ACM TRANSACTIONS ON GRAPHICS, 2023, 42 (04):
  • [36] EmoGen: Emotional Image Content Generation with Text-to-Image Diffusion Models
    Yang, Jingyuan
    Feng, Jiawei
    Huang, Hui
    2024 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION, CVPR 2024, 2024, : 6358 - 6368
  • [37] Prompt-Free Diffusion: Taking "Text" out of Text-to-Image Diffusion Models
    Xu, Xingqian
    Guo, Jiayi
    Wang, Zhangyang
    Huang, Gao
    Essa, Irfan
    Shi, Humphrey
    2024 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION, CVPR 2024, 2024, : 8682 - 8692
  • [38] Text-to-Feature Diffusion for Audio-Visual Few-Shot Learning
    Mercea, Otniel-Bogdan
    Hummel, Thomas
    Koepke, A. Sophia
    Akata, Zeynep
    PATTERN RECOGNITION, DAGM GCPR 2023, 2024, 14264 : 491 - 507
  • [39] The Chosen One: Consistent Characters in Text-to-Image Diffusion Models
    Avrahami, Omri
    Hertz, Amir
    Vinker, Yael
    Arar, Moab
    Fruchter, Shlomi
    Fried, Ohad
    Cohen-Or, Daniel
    Lischinski, Dani
    PROCEEDINGS OF SIGGRAPH 2024 CONFERENCE PAPERS, 2024,
  • [40] Exposing fake images generated by text-to-image diffusion models
    Xu, Qiang
    Wang, Hao
    Meng, Laijin
    Mi, Zhongjie
    Yuan, Jianye
    Yan, Hong
    PATTERN RECOGNITION LETTERS, 2023, 176 : 76 - 82