arXiv:2510.00635cs.CV2025-10被引 1

针对新型图像生成模型,提出首个概念攻击方法,验证其安全擦除仍不牢靠。

Erased, But Not Forgotten: Erased Rectified Flow Transformers Still Remain Unsafe Under Concept Attack

  • 基于注意力定位机制,设计反向优化攻击策略。
  • 在Flux模型上成功复现被擦除概念,且保持图像布局一致。
  • 适合关注生成模型安全性的研究者与开发者参考。

近期文本到图像扩散模型虽具备强大生成能力,但可能产生有害内容,引发安全担忧。尽管概念擦除被视为缓解策略,现有方法多针对Stable Diffusion(SD),在新一代基于修正流的Transformer模型Flux上效果有限。本文提出ReFlux,首个专为评估修正流框架下概念擦除鲁棒性的攻击方法。研究发现,现有擦除技术在Flux中依赖注意力定位现象,据此提出一种简单有效的反向注意力优化策略,可有效恢复被抑制信号并稳定注意力。该方法结合速度引导动态增强概念重激活鲁棒性,并引入一致性保持目标以维持全局布局和无关内容。大量实验表明,该攻击方法高效可靠,为评估修正流模型中概念擦除策略提供了基准。

原文摘要 · Abstract (English)

Recent advances in text-to-image (T2I) diffusion models have enabled impressive generative capabilities, but they also raise significant safety concerns due to the potential to produce harmful or undesirable content. While concept erasure has been explored as a mitigation strategy, most existing approaches and corresponding attack evaluations are tailored to Stable Diffusion (SD) and exhibit limited effectiveness when transferred to next-generation rectified flow transformers such as Flux. In this work, we present ReFlux, the first concept attack method specifically designed to assess the robustness of concept erasure in the latest rectified flow-based T2I framework. Our approach is motivated by the observation that existing concept erasure techniques, when applied to Flux, fundamentally rely on a phenomenon known as attention localization. Building on this insight, we propose a simple yet effective attack strategy that specifically targets this property. At its core, a reverse-attention optimization strategy is introduced to effectively reactivate suppressed signals while stabilizing attention. This is further reinforced by a velocity-guided dynamic that enhances the robustness of concept reactivation by steering the flow matching process, and a consistency-preserving objective that maintains the global layout and preserves unrelated content. Extensive experiments consistently demonstrate the effectiveness and efficiency of the proposed attack method, establishing a reliable benchmark for evaluating the robustness of concept erasure strategies in rectified flow transformers.

图像生成安全攻击概念擦除Flux模型

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。