arXiv:2606.23362cs.CRcs.CV2026-06

用极低污染率和隐形触发器,让扩散模型中招后门攻击

TooBad: Backdoor Diffusion Models with Ultra-Low Poison Rate and Imperceptible Trigger

论文配图:TooBad: Backdoor Diffusion Models with Ultra-Low Poison Rate and Imperceptible Trigger
图 1 · 摘自论文原文
  • 设计专用于扩散模型的触发器优化技术,提升攻击效率
  • 0.5%污染率下攻击成功率超85%,5%时3-5轮即达近100%
  • 隐蔽性强,可绕过当前顶级防御,适合研究安全漏洞者

扩散模型虽在多种生成任务中表现卓越,却面临后门攻击威胁。现有方法在攻击效果、隐蔽性、训练时间与污染率之间存在显著权衡:高攻击性能通常需高污染率和长时间训练,降低隐蔽性,易被检测。本文提出TooBad(针对扩散模型的触发器优化),引入一种专为扩散模型设计的触发器优化技术,显著提升后门攻击效果。在CIFAR-10等基准测试中,太坏可在仅0.5%污染率下实现>85%的攻击成功率,远低于以往方法在相同数据集上所需的10%。在5%污染率下,仅需3-5个注入轮次即可达到近100%攻击成功率,而现有方法需至少30-50轮且污染率翻倍才能达成类似结果。尽管攻击强度极高,太坏仍能有效规避主流防御机制,并保持良好生成质量。这些结果揭示了扩散模型面临的严峻威胁,凸显了发展更鲁棒防御的紧迫性。

原文摘要 · Abstract (English)

Diffusion models (DMs), despite their impressive capabilities across a wide range of generative tasks, have been shown to be vulnerable to backdoor attacks. However, existing backdoor methods face critical trade-offs among key factors: attack performance, stealthiness, time complexity, and required poison rates. For example, achieving high attack performance typically demands a high poison rate and prolonged training, which undermines stealthiness, making the attack more detectable by backdoor defenses. This paper proposes TooBad (trigger optimization for backdoor diffusion models), a backdoor framework which introduces a novel DM-tailored trigger optimization technique to dramatically enhance the performance of backdoor attacks on DMs. Experiments on representative benchmarks such as CIFAR-10 show that TooBad can achieve high ASRs ($> 85$%) at only 0.5% poison rate, significantly lower than the 10% typically required by prior work on the same datasets. At 5% poison rate, TooBad reaches nearly 100% ASR within just 3-5 backdoor injection epochs, whereas existing methods need at least 30-50 epochs at double the poison rate for comparable results. Despite its potency, TooBad easily evades SOTA defenses and maintains high utility. These results reveal a critical threat on DMs and highlight the need for more robust defenses against such stealthy yet efficient attacks.

后门攻击扩散模型安全漏洞低污染率

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。