arXiv:2412.07658cs.CVcs.AI2024-12被引 22

不训练模型也能有效清除有害内容生成

TraSCE: Trajectory Steering for Concept Erasure

  • 用改进的负面提示引导扩散过程避开有害生成
  • 在红队测试中优于现有方法,可清除艺术风格与物体
  • 无需训练或修改权重,适合快速部署

文本到图像扩散模型虽广受欢迎,但常生成不当内容(如NSFW图像)。现有概念擦除方法易被越狱技术绕过。本文提出TraSCE,通过优化负面提示策略并引入局部损失引导,主动调整扩散轨迹以规避有害输出。该方法无需训练、权重修改或额外数据,仅靠提示工程实现高效擦除。在多个基准测试中,包括红队设计的挑战性场景,均达到当前最佳效果,可有效移除有害内容、艺术风格及特定物体,为模型所有者提供零成本的可控安全机制。

原文摘要 · Abstract (English)

Recent advancements in text-to-image diffusion models have brought them to the public spotlight, becoming widely accessible and embraced by everyday users. However, these models have been shown to generate harmful content such as not-safe-for-work (NSFW) images. While approaches have been proposed to erase such abstract concepts from the models, jail-breaking techniques have succeeded in bypassing such safety measures. In this paper, we propose TraSCE, an approach to guide the diffusion trajectory away from generating harmful content. Our approach is based on negative prompting, but as we show in this paper, a widely used negative prompting strategy is not a complete solution and can easily be bypassed in some corner cases. To address this issue, we first propose using a specific formulation of negative prompting instead of the widely used one. Furthermore, we introduce a localized loss-based guidance that enhances the modified negative prompting technique by steering the diffusion trajectory. We demonstrate that our proposed method achieves state-of-the-art results on various benchmarks in removing harmful content, including ones proposed by red teams, and erasing artistic styles and objects. Our proposed approach does not require any training, weight modifications, or training data (either image or prompt), making it easier for model owners to erase new concepts.

扩散模型内容安全提示工程

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。