arXiv:2504.01819cs.CVcs.AI2025-04CVPR被引 7

提出隐蔽的隐式偏见注入攻击,让文生图模型生成有倾向性图像。

Implicit Bias Injection Attacks against Text-to-Image Diffusion Models

  • 在提示词嵌入空间预计算通用偏见方向并动态调整
  • 通过细微修改引入偏见,保持原语义不变
  • 无需重训练,可无缝接入现有模型,适合安全评估

文本到图像扩散模型(T2I DMs)的普及使其生成内容日益影响公众认知。已有研究多关注显性偏见(如肤色、性别),但本文揭示一种无明显视觉特征的隐式偏见,其可在多种语义场景中以多样方式显现,隐蔽性强、传播容易且适应性广。为此,提出隐式偏见注入攻击框架(IBI-Attacks):在提示词嵌入空间预计算通用偏见方向,并根据输入自适应调整。攻击模块可即插即用,无需修改用户输入或重新训练模型。大量实验验证该方法能通过微小而多样的修改有效引入偏见,同时保持原始语义。攻击在不同场景下具有强隐蔽性和迁移能力,凸显其威胁性。代码已开源。

原文摘要 · Abstract (English)

The proliferation of text-to-image diffusion models (T2I DMs) has led to an increased presence of AI-generated images in daily life. However, biased T2I models can generate content with specific tendencies, potentially influencing people's perceptions. Intentional exploitation of these biases risks conveying misleading information to the public. Current research on bias primarily addresses explicit biases with recognizable visual patterns, such as skin color and gender. This paper introduces a novel form of implicit bias that lacks explicit visual features but can manifest in diverse ways across various semantic contexts. This subtle and versatile nature makes this bias challenging to detect, easy to propagate, and adaptable to a wide range of scenarios. We further propose an implicit bias injection attack framework (IBI-Attacks) against T2I diffusion models by precomputing a general bias direction in the prompt embedding space and adaptively adjusting it based on different inputs. Our attack module can be seamlessly integrated into pre-trained diffusion models in a plug-and-play manner without direct manipulation of user input or model retraining. Extensive experiments validate the effectiveness of our scheme in introducing bias through subtle and diverse modifications while preserving the original semantics. The strong concealment and transferability of our attack across various scenarios further underscore the significance of our approach. Code is available at https://github.com/Hannah1102/IBI-attacks.

文生图偏见攻击扩散模型安全评估

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。