Pith. sign in

REVIEW 3 cited by

UFID: A Unified Framework for Input-level Backdoor Detection on Diffusion Models

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2404.01101 v2 pith:FHKU7Q27 submitted 2024-04-01 cs.CR cs.CVcs.LG

classification cs.CRcs.CVcs.LG
keywords backdoordiffusionmodelsdetectionattacksinputinput-levelsamples
verification ladder T0 review T1 audit T2 compute T3 formal

Signed reviews

No signed human review yet.

0 comments
read the original abstract

Diffusion models are vulnerable to backdoor attacks, where malicious attackers inject backdoors by poisoning certain training samples during the training stage. This poses a significant threat to real-world applications in the Model-as-a-Service (MaaS) scenario, where users query diffusion models through APIs or directly download them from the internet. To mitigate the threat of backdoor attacks under MaaS, black-box input-level backdoor detection has drawn recent interest, where defenders aim to build a firewall that filters out backdoor samples in the inference stage, with access only to input queries and the generated results from diffusion models. Despite some preliminary explorations on the traditional classification tasks, these methods cannot be directly applied to the generative tasks due to two major challenges: (1) more diverse failures and (2) a multi-modality attack surface. In this paper, we propose a black-box input-level backdoor detection framework on diffusion models, called UFID. Our defense is motivated by an insightful causal analysis: Backdoor attacks serve as the confounder, introducing a spurious path from input to target images, which remains consistent even when we perturb the input samples with Gaussian noise. We further validate the intuition with theoretical analysis. Extensive experiments across different datasets on both conditional and unconditional diffusion models show that our method achieves superb performance on detection effectiveness and run-time efficiency.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 3 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. MixBridge: Heterogeneous Image-to-Image Backdoor Attack through Mixture of Schr\"odinger Bridges

    cs.CR 2025-05 conditional novelty 6.0 of 10

    MixBridge injects multiple backdoor triggers into image-to-image Schrödinger bridge models by training on poisoned pairs and merging task-specific experts, achieving high attack success and stealthy weights.

  2. TrojFlow: Flow Models are Natural Targets for Trojan Attacks

    cs.CV 2024-12 conditional novelty 5.0 of 10

    TrojFlow fine-tunes a rectified-flow generator so specific trigger-noise inputs produce attacker-chosen images, keeps benign outputs usable, and qualitatively evades UFID and TERD defenses on CIFAR-10 and CelebA.

  3. CopyrightShield: Enhancing Diffusion Model Security against Copyright Infringement Attacks

    cs.AI 2024-12 reject novelty 5.0 of 10

    A defense framework that uses masked image similarity and data attribution to detect and mitigate copyright-infringing backdoor samples in diffusion models.

Pith tools