SurrogatePrompt: Bypassing the Safety Filter of Text-to-Image Models via Substitution
Fuente:
arXiv
Saved in:
| Main Authors: | Ba, Zhongjie, Zhong, Jieming, Lei, Jiachen, Cheng, Peng, Wang, Qinglong, Qin, Zhan, Wang, Zhibo, Ren, Kui |
|---|---|
| Format: | Preprint |
| Published: |
2023
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
WMCopier: Forging Invisible Image Watermarks on Arbitrary Images
by: Dong, Ziping, et al.
Published: (2025)
by: Dong, Ziping, et al.
Published: (2025)
Robust Watermarks Leak: Channel-Aware Feature Extraction Enables Adversarial Watermark Manipulation
by: Ba, Zhongjie, et al.
Published: (2025)
by: Ba, Zhongjie, et al.
Published: (2025)
Releasing Malevolence from Benevolence: The Menace of Benign Data on Machine Unlearning
by: Ma, Binhao, et al.
Published: (2024)
by: Ma, Binhao, et al.
Published: (2024)
Text-CRS: A Generalized Certified Robustness Framework against Textual Adversarial Attacks
by: Zhang, Xinyu, et al.
Published: (2023)
by: Zhang, Xinyu, et al.
Published: (2023)
Attack-Resistant Watermarking for AIGC Image Forensics via Diffusion-based Semantic Deflection
by: Liu, Qingyu, et al.
Published: (2026)
by: Liu, Qingyu, et al.
Published: (2026)
Beyond Content: A Comprehensive Speech Toxicity Dataset and Detection Framework Incorporating Paralinguistic Cues
by: Ba, Zhongjie, et al.
Published: (2026)
by: Ba, Zhongjie, et al.
Published: (2026)
"Training robust watermarking model may hurt authentication!'' Exploring and Mitigating the Identity Leakage in Robust Watermarking
by: Zhang, Xinyu, et al.
Published: (2026)
by: Zhang, Xinyu, et al.
Published: (2026)
LoRA-Key: User-Centric LoRA Watermarking for Text-to-Image Diffusion Models
by: Wang, Yaopeng, et al.
Published: (2026)
by: Wang, Yaopeng, et al.
Published: (2026)
RedAgent: Red Teaming Large Language Models with Context-aware Autonomous Language Agent
by: Xu, Huiyu, et al.
Published: (2024)
by: Xu, Huiyu, et al.
Published: (2024)
Towards Label-Only Membership Inference Attack against Pre-trained Large Language Models
by: He, Yu, et al.
Published: (2025)
by: He, Yu, et al.
Published: (2025)
Embedding Poisoning: Bypassing Safety Alignment via Embedding Semantic Shift
by: Yuan, Shuai, et al.
Published: (2025)
by: Yuan, Shuai, et al.
Published: (2025)
PT-Mark: Invisible Watermarking for Text-to-image Diffusion Models via Semantic-aware Pivotal Tuning
by: Wang, Yaopeng, et al.
Published: (2025)
by: Wang, Yaopeng, et al.
Published: (2025)
Phoneme-Based Proactive Anti-Eavesdropping with Controlled Recording Privilege
by: Huang, Peng, et al.
Published: (2024)
by: Huang, Peng, et al.
Published: (2024)
Towards Identification and Intervention of Safety-Critical Parameters in Large Language Models
by: Qi, Weiwei, et al.
Published: (2026)
by: Qi, Weiwei, et al.
Published: (2026)
Prompt, Divide, and Conquer: Bypassing Large Language Model Safety Filters via Segmented and Distributed Prompt Processing
by: Wahréus, Johan, et al.
Published: (2025)
by: Wahréus, Johan, et al.
Published: (2025)
SWAT: A System-Wide Approach to Tunable Leakage Mitigation in Encrypted Data Stores
by: Zheng, Leqian, et al.
Published: (2023)
by: Zheng, Leqian, et al.
Published: (2023)
ALIF: Low-Cost Adversarial Audio Attacks on Black-Box Speech Platforms using Linguistic Features
by: Cheng, Peng, et al.
Published: (2024)
by: Cheng, Peng, et al.
Published: (2024)
Bypassing Prompt Guards in Production with Controlled-Release Prompting
by: Fairoze, Jaiden, et al.
Published: (2025)
by: Fairoze, Jaiden, et al.
Published: (2025)
Combating Concept Drift with Explanatory Detection and Adaptation for Android Malware Classification
by: He, Yiling, et al.
Published: (2024)
by: He, Yiling, et al.
Published: (2024)
JailbreakLens: Interpreting Jailbreak Mechanism in the Lens of Representation and Circuit
by: He, Zeqing, et al.
Published: (2024)
by: He, Zeqing, et al.
Published: (2024)
Safeguarding LLM Embeddings in End-Cloud Collaboration via Entropy-Driven Perturbation
by: Jin, Shuaifan, et al.
Published: (2025)
by: Jin, Shuaifan, et al.
Published: (2025)
SpatialJB: How Text Distribution Art Becomes the "Jailbreak Key" for LLM Guardrails
by: Mou, Zhiyi, et al.
Published: (2026)
by: Mou, Zhiyi, et al.
Published: (2026)
Certifiable Black-Box Attacks with Randomized Adversarial Examples: Breaking Defenses with Provable Confidence
by: Hong, Hanbin, et al.
Published: (2023)
by: Hong, Hanbin, et al.
Published: (2023)
MacPrompt: Maraconic-guided Jailbreak against Text-to-Image Models
by: Ye, Xi, et al.
Published: (2026)
by: Ye, Xi, et al.
Published: (2026)
RerouteGuard: Understanding and Mitigating Adversarial Risks for LLM Routing
by: Zhang, Wenhui, et al.
Published: (2026)
by: Zhang, Wenhui, et al.
Published: (2026)
ASPIRER: Bypassing System Prompts With Permutation-based Backdoors in LLMs
by: Yan, Lu, et al.
Published: (2024)
by: Yan, Lu, et al.
Published: (2024)
Defending Against Prompt Injection with DataFilter
by: Wang, Yizhu, et al.
Published: (2025)
by: Wang, Yizhu, et al.
Published: (2025)
SoK: On Gradient Leakage in Federated Learning
by: Du, Jiacheng, et al.
Published: (2024)
by: Du, Jiacheng, et al.
Published: (2024)
Can Small Language Models Reliably Resist Jailbreak Attacks? A Comprehensive Evaluation
by: Zhang, Wenhui, et al.
Published: (2025)
by: Zhang, Wenhui, et al.
Published: (2025)
Eguard: Defending LLM Embeddings Against Inversion Attacks via Text Mutual Information Optimization
by: Liu, Tiantian, et al.
Published: (2024)
by: Liu, Tiantian, et al.
Published: (2024)
MAJIC: Markovian Adaptive Jailbreaking via Iterative Composition of Diverse Innovative Strategies
by: Qi, Weiwei, et al.
Published: (2025)
by: Qi, Weiwei, et al.
Published: (2025)
Towards Effective Prompt Stealing Attack against Text-to-Image Diffusion Models
by: Zhao, Shiqian, et al.
Published: (2025)
by: Zhao, Shiqian, et al.
Published: (2025)
Channel-Level Semantic Perturbations: Unlearnable Examples for Diverse Training Paradigms
by: Wang, Bo, et al.
Published: (2026)
by: Wang, Bo, et al.
Published: (2026)
LoopTrap: Termination Poisoning Attacks on LLM Agents
by: Xu, Huiyu, et al.
Published: (2026)
by: Xu, Huiyu, et al.
Published: (2026)
FINER: Enhancing State-of-the-art Classifiers with Feature Attribution to Facilitate Security Analysis
by: He, Yiling, et al.
Published: (2023)
by: He, Yiling, et al.
Published: (2023)
Defense against Poisoning Attacks under Shuffle-DP
by: Wang, Siyi, et al.
Published: (2026)
by: Wang, Siyi, et al.
Published: (2026)
Bypassing Prompt Injection Detectors through Evasive Injections
by: Rahman, Md Jahedur, et al.
Published: (2026)
by: Rahman, Md Jahedur, et al.
Published: (2026)
On the Proactive Generation of Unsafe Images From Text-To-Image Models Using Benign Prompts
by: Wu, Yixin, et al.
Published: (2023)
by: Wu, Yixin, et al.
Published: (2023)
TRACE: Task-Aware Adaptive Self-Evolving Agentic Jailbreaking
by: Zeng, Churui, et al.
Published: (2026)
by: Zeng, Churui, et al.
Published: (2026)
FBA$^2$D: Frequency-based Black-box Attack for AI-generated Image Detection
by: Chen, Xiaojing, et al.
Published: (2025)
by: Chen, Xiaojing, et al.
Published: (2025)
Similar Items
-
WMCopier: Forging Invisible Image Watermarks on Arbitrary Images
by: Dong, Ziping, et al.
Published: (2025) -
Robust Watermarks Leak: Channel-Aware Feature Extraction Enables Adversarial Watermark Manipulation
by: Ba, Zhongjie, et al.
Published: (2025) -
Releasing Malevolence from Benevolence: The Menace of Benign Data on Machine Unlearning
by: Ma, Binhao, et al.
Published: (2024) -
Text-CRS: A Generalized Certified Robustness Framework against Textual Adversarial Attacks
by: Zhang, Xinyu, et al.
Published: (2023) -
Attack-Resistant Watermarking for AIGC Image Forensics via Diffusion-based Semantic Deflection
by: Liu, Qingyu, et al.
Published: (2026)