Asymmetric Bias in Text-to-Image Generation with Adversarial Attacks

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Shahgir, Haz Sameen, Kong, Xianghao, Steeg, Greg Ver, Dong, Yue
Format: Preprint
Published: 2023
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866913433484525568
author Shahgir, Haz Sameen
Kong, Xianghao
Steeg, Greg Ver
Dong, Yue
author_facet Shahgir, Haz Sameen
Kong, Xianghao
Steeg, Greg Ver
Dong, Yue
contents The widespread use of Text-to-Image (T2I) models in content generation requires careful examination of their safety, including their robustness to adversarial attacks. Despite extensive research on adversarial attacks, the reasons for their effectiveness remain underexplored. This paper presents an empirical study on adversarial attacks against T2I models, focusing on analyzing factors associated with attack success rates (ASR). We introduce a new attack objective - entity swapping using adversarial suffixes and two gradient-based attack algorithms. Human and automatic evaluations reveal the asymmetric nature of ASRs on entity swap: for example, it is easier to replace "human" with "robot" in the prompt "a human dancing in the rain." with an adversarial suffix, but the reverse replacement is significantly harder. We further propose probing metrics to establish indicative signals from the model's beliefs to the adversarial ASR. We identify conditions that result in a success probability of 60% for adversarial attacks and others where this likelihood drops below 5%.
format Preprint
id arxiv_https___arxiv_org_abs_2312_14440
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle Asymmetric Bias in Text-to-Image Generation with Adversarial Attacks
Shahgir, Haz Sameen
Kong, Xianghao
Steeg, Greg Ver
Dong, Yue
Machine Learning
Cryptography and Security
The widespread use of Text-to-Image (T2I) models in content generation requires careful examination of their safety, including their robustness to adversarial attacks. Despite extensive research on adversarial attacks, the reasons for their effectiveness remain underexplored. This paper presents an empirical study on adversarial attacks against T2I models, focusing on analyzing factors associated with attack success rates (ASR). We introduce a new attack objective - entity swapping using adversarial suffixes and two gradient-based attack algorithms. Human and automatic evaluations reveal the asymmetric nature of ASRs on entity swap: for example, it is easier to replace "human" with "robot" in the prompt "a human dancing in the rain." with an adversarial suffix, but the reverse replacement is significantly harder. We further propose probing metrics to establish indicative signals from the model's beliefs to the adversarial ASR. We identify conditions that result in a success probability of 60% for adversarial attacks and others where this likelihood drops below 5%.
title Asymmetric Bias in Text-to-Image Generation with Adversarial Attacks
topic Machine Learning
Cryptography and Security
url https://arxiv.org/abs/2312.14440