paper-with-me

홈 › Papers

Awakening the Hydra: Stabilizing Multi-Concept Backdoor Injection in Text-to-Image Diffusion Models

2026-05-19 · Kai Wang, Jiale Zhang, Chengcheng Zhu, Chuang Ma, Songze Li arxiv

Text-to-image diffusion models are increasingly developed through open-source reuse and repeated downstream fine-tuning, where reused checkpoints are difficult to verify and thus more susceptible to hidden backdoor behaviors. In such ecosystems, a single pretrained model may be sequentially adapted and redistributed by multiple independent parties, allowing multiple concept-specific trigger-target associations to accumulate in the same model. When these associations coexist, semantic conflicts can be amplified in the shared representation space, leading to cross-concept entanglement and degraded generation quality. Notably, instead of strengthening the attack, such accumulation can destabilize previously injected behaviors and reduce attack reliability. In this work, we systematically investigate backdoor attacks under this interference-prone setting and propose Hydra, a unified framework for robust and controlled multi-concept backdoor injection under cumulative and decentralized reuse. Our core insight is that stable backdoor injection under large-scale multi-concept settings requires explicitly constraining trigger semantics while coordinating cross-task interactions during optimization. Specifically, Hydra performs evolutionary trigger search in the text encoder space to identify triggers that are semantically aligned with their target concepts while remaining stable across other injected concepts. It further combines multi-task fine-tuning with trigger-clean regularization to improve training stability under dense multi-concept injection. Extensive experiments across multiple diffusion backbones under rigorous multi-concept settings show that Hydra maintains effective backdoor activation while preserving clean generation fidelity and image quality. For instance, across 8 attackers and 500 concept pairs, Hydra maintains ~95% ASR and strong clean generation.

📄 PDF Abstract BibTeX arXiv:2605.19698

Code (0)

등록된 구현이 없습니다.

Similar Papers 제목 키워드 기반

LURE: Latent Space Unblocking for Multi-Concept Reawakening in Diffusion Models

2026-01-20 · Mengyu Sun, Ziyuan Yang, Andrew Beng Jin Teoh, Junxu Liu 외 arxiv

Concept erasure aims to suppress sensitive content in diffusion models, but recent studies show that erased concepts can still be reawakened, revealing vulnerabilities in erasure methods. Existing reawakening methods mai…

Whispers in the Noise: Surrogate-Guided Concept Awakening via a Multi-Agent Framework

2026-05-18 · Mengyu Sun, Ziyuan Yang, Zunlong Zhou, Junxu Liu 외 arxiv

Diffusion models (DMs) are widely used for text-to-image generation, but their strong generative capabilities also raise concerns about unsafe or undesirable content. Concept erasure aims to mitigate these risks by remov…

Text-to-Image Generation

A Unifying Passivity-Based Framework for Pressure and Volume Flow Rate Control in District Heating Networks

2023-05-20 · Felix Strehle, Juan E. Machado, Michele Cucuzzella, Albertus J. Malan 외

A fundamental precondition for the secure and efficient operation of district heating networks (DHNs) is a stable hydraulic behavior. However, the ongoing transition towards a sustainable heat supply, especially the risi…

Awakening Latent Grounding from Pretrained Language Models for Semantic Parsing

2021-09-22 · Findings (ACL) 2021 8 · Qian Liu, Dejian Yang, Jiahui Zhang, Jiaqi Guo 외

Recent years pretrained language models (PLMs) hit a success on several downstream tasks, showing their power on modeling language. To better understand and leverage what PLMs have learned, several techniques have emerge…

Semantic ParsingText to SQLText-To-SQL

Awakening Augmented Generation: Learning to Awaken Internal Knowledge of Large Language Models for Question Answering

2024-03-22 · Huanxuan Liao, Shizhu He, Yao Xu, Yuanzhe Zhang 외

Retrieval-Augmented-Generation and Generation-Augmented-Generation have been proposed to enhance the knowledge required for question answering with Large Language Models (LLMs) by leveraging richer context. However, the …

Open-Domain Question AnsweringOut-of-Distribution GeneralizationQuestion AnsweringRetrieval-augmented Generation