arXiv:2412.05538cs.CVcs.PF2024-12CVPR被引 10

发现图像生成模型在视觉模态下存在被字体攻击的风险。

Not Just Text: Uncovering Vision Modality Typographic Threats in Image Generation Models

  • 提出字体攻击方法,利用视觉输入漏洞触发不当内容生成。
  • 实验证明现有防御机制对视觉模态攻击无效。
  • 发布VMT-IGMs数据集,用于评估模型视觉安全缺陷。

当前图像生成模型虽能生成高质量逼真图像,但也增加了被滥用的风险。在文本到图像或图像到图像的任务中,攻击者仅需修改语言输入即可生成包含不当内容的系列图像。为此,已有大量防护策略聚焦于语言模态的安全,但实际应用中,涉及真实图像编辑任务的视觉模态威胁更具风险,易侵犯图像所有权。本文提出一种名为字体攻击的方法,揭示多种图像生成模型在视觉模态下同样存在安全隐患。我们还评估了现有多种防御方法在面对视觉模态威胁时的表现,发现其普遍无效。最后,我们构建了面向图像生成模型视觉模态脆弱性的基准数据集VMT-IGMs,为后续研究提供支持。

原文摘要 · Abstract (English)

Current image generation models can effortlessly produce high-quality, highly realistic images, but this also increases the risk of misuse. In various Text-to-Image or Image-to-Image tasks, attackers can generate a series of images containing inappropriate content by simply editing the language modality input. To mitigate this security concern, numerous guarding or defensive strategies have been proposed, with a particular emphasis on safeguarding language modality. However, in practical applications, threats in the vision modality, particularly in tasks involving the editing of real-world images, present heightened security risks as they can easily infringe upon the rights of the image owner. Therefore, this paper employs a method named typographic attack to reveal that various image generation models are also susceptible to threats within the vision modality. Furthermore, we also evaluate the defense performance of various existing methods when facing threats in the vision modality and uncover their ineffectiveness. Finally, we propose the Vision Modal Threats in Image Generation Models (VMT-IGMs) dataset, which would serve as a baseline for evaluating the vision modality vulnerability of various image generation models.

图像生成安全威胁视觉攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。