paper-with-me

Papers

REDEditing: Relationship-Driven Precise Backdoor Poisoning on Text-to-Image Diffusion Models

2025-04-20 · Chongye Guo, Jinhu Fu, Junfeng Fang, Kun Wang, Guorui Feng

The rapid advancement of generative AI highlights the importance of text-to-image (T2I) security, particularly with the threat of backdoor poisoning. Timely disclosure and mitigation of security vulnerabilities in T2I models are crucial for ensuring the safe deployment of generative models. We explore a novel training-free backdoor poisoning paradigm through model editing, which is recently employed for knowledge updating in large language models. Nevertheless, we reveal the potential security risks posed by model editing techniques to image generation models. In this work, we establish the principles for backdoor attacks based on model editing, and propose a relationship-driven precise backdoor poisoning method, REDEditing. Drawing on the principles of equivalent-attribute alignment and stealthy poisoning, we develop an equivalent relationship retrieval and joint-attribute transfer approach that ensures consistent backdoor image generation through concept rebinding. A knowledge isolation constraint is proposed to preserve benign generation integrity. Our method achieves an 11\% higher attack success rate compared to state-of-the-art approaches. Remarkably, adding just one line of code enhances output naturalness while improving backdoor stealthiness by 24\%. This work aims to heighten awareness regarding this security vulnerability in editable image generation models.

📄 PDF Abstract BibTeX arXiv:2504.14554

Code (0)

등록된 구현이 없습니다.

Tasks

AttributeImage GenerationModel Editing

Similar Papers 제목 키워드 기반

FRIB: Low-poisoning Rate Invisible Backdoor Attack based on Feature Repair

2022-07-26 · Hui Xia, Xiugui Yang, Xiangyun Qian, Rui Zhang

During the generation of invisible backdoor attack poisoned data, the feature space transformation operation tends to cause the loss of some poisoned features and weakens the mapping relationship between source images wi…

Backdoor Attack

PCAP-Backdoor: Backdoor Poisoning Generator for Network Traffic in CPS/IoT Environments

2025-01-26 · Ajesh Koyatan Chathoth, Stephen Lee

The rapid expansion of connected devices has made them prime targets for cyberattacks. To address these threats, deep learning-based, data-driven intrusion detection systems (IDS) have emerged as powerful tools for detec…

backdoor defenseDeep LearningIntrusion Detection

Generalization Bound and New Algorithm for Clean-Label Backdoor Attack

2024-06-02 · Lijia Yu, Shuang Liu, Yibo Miao, Xiao-Shan Gao 외

The generalization bound is a crucial theoretical tool for assessing the generalizability of learning methods and there exist vast literatures on generalizability of normal learning, adversarial learning, and data poison…

Backdoor AttackData PoisoningGeneralization Bounds

Model Poisoning Against Federated Model Adaptation with Chain of Bit-Flips

2026-06-08 · Bastien Vuillod, Kevin Hector, Pierre-Alain Moellic, Jean-Max Dutertre 외 arxiv

Federated Learning (FL) allows a set of clients to collectively train a global model without sharing local training data. Giving the responsibility of the training to decentralized actors may lead to poisoning attacks: c…

Federated Learning

Boosting Backdoor Attack with A Learnable Poisoning Sample Selection Strategy

2023-07-14 · Zihao Zhu, Mingda Zhang, Shaokui Wei, Li Shen 외

Data-poisoning based backdoor attacks aim to insert backdoor into models by manipulating training datasets without controlling the training process of the target model. Existing attack methods mainly focus on designing t…

Backdoor AttackData Poisoning