Pith. sign in

REVIEW 1 cited by

VillanDiffusion: A Unified Backdoor Attack Framework for Diffusion Models

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2306.06874 v5 pith:V4AIJQYU submitted 2023-06-12 cs.CR cs.CVcs.LG

classification cs.CRcs.CVcs.LG
keywords backdoorframeworkattackmodelsunifiedvillandiffusionanalysisconditional
verification ladder T0 review T1 audit T2 compute T3 formal

Signed reviews

No signed human review yet.

0 comments
read the original abstract

Diffusion Models (DMs) are state-of-the-art generative models that learn a reversible corruption process from iterative noise addition and denoising. They are the backbone of many generative AI applications, such as text-to-image conditional generation. However, recent studies have shown that basic unconditional DMs (e.g., DDPM and DDIM) are vulnerable to backdoor injection, a type of output manipulation attack triggered by a maliciously embedded pattern at model input. This paper presents a unified backdoor attack framework (VillanDiffusion) to expand the current scope of backdoor analysis for DMs. Our framework covers mainstream unconditional and conditional DMs (denoising-based and score-based) and various training-free samplers for holistic evaluations. Experiments show that our unified framework facilitates the backdoor analysis of different DM configurations and provides new insights into caption-based backdoor attacks on DMs. Our code is available on GitHub: \url{https://github.com/IBM/villandiffusion}

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. TrojFlow: Flow Models are Natural Targets for Trojan Attacks

    cs.CV 2024-12 conditional novelty 5.0 of 10

    TrojFlow fine-tunes a rectified-flow generator so specific trigger-noise inputs produce attacker-chosen images, keeps benign outputs usable, and qualitatively evades UFID and TERD defenses on CIFAR-10 and CelebA.

Pith tools