arXiv:2507.07947cs.LGcs.AI2025-07被引 1

用普通提示词就能复原被模型记忆的图像,暴露隐私风险。

Reconstructing Template-Memorized Images from Natural Prompts

  • 利用自然提示词触发模型记忆,无需高算力或训练数据
  • 提示词如'蓝色无性别T恤'可生成真实人脸,复现记忆图像
  • 适合关注生成模型隐私漏洞的研究者与安全从业者

生成模型(如扩散模型)的发展引发了隐私、版权及数据管理方面的担忧。为更好理解并控制这些风险,已有研究提出从训练数据中重建图像或其部分的方法。然而,现有方法通常依赖高计算资源、部分训练数据访问权限或精心设计的提示词。本文提出一种新型攻击:仅需低资源、极少训练数据访问,即可通过看似无害的自然提示词实现潜在高风险的图像重建。我们发现,此类重建可能在无意中发生,即使对非专业用户亦然。例如,某模型在输入'blue Unisex T-Shirt'时,会生成真实个体的面部图像。结合真实世界提示数据,我们进一步识别出能重现记忆视觉元素的提示词。该方法基于前期研究洞察,利用领域知识揭示了使用爬取电商数据时存在的根本性漏洞——模板化布局与模式化文本提示密切相关。攻击代码已公开于 https://github.com/TheSolY/lr-tmi。

原文摘要 · Abstract (English)

Recent advances in generative models, such as diffusion models, have raised concerns related to privacy, copyright infringement, and data stewardship. To better understand and control these risks, prior work has introduced techniques and attacks that reconstruct images, or parts of images, from training data. While these results demonstrate that training data can be recovered, existing methods often rely on high computational resources, partial access to the training set, or carefully engineered prompts. In this work, we present a new attack that requires low resources, assumes little to no access to the training data, and identifies seemingly benign prompts that can lead to potentially risky image reconstruction. We further show that such reconstructions may occur unintentionally, even for users without specialized knowledge. For example, we observe that for one existing model, the prompt ``blue Unisex T-Shirt'' generates the face of a real individual. Moreover, by combining the identified vulnerabilities with real-world prompt data, we discover prompts that reproduce memorized visual elements. Our approach builds on insights from prior work and leverages domain knowledge to expose a fundamental vulnerability arising from the use of scraped e-commerce data, where templated layouts and images are closely tied to pattern-like textual prompts. The code for our attack is publicly available at https://github.com/TheSolY/lr-tmi.

图像重建隐私安全生成模型

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。