EmoAttack: Emotion-to-Image Diffusion Models for Emotional Backdoor Generation

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Wei, Tianyu, Pang, Shanmin, Guo, Qi, Ma, Yizhuo, Cao, Xiaofeng, Guo, Qing
Format: Preprint
Veröffentlicht: 2024
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866917049581699072
author Wei, Tianyu
Pang, Shanmin
Guo, Qi
Ma, Yizhuo
Cao, Xiaofeng
Guo, Qing
author_facet Wei, Tianyu
Pang, Shanmin
Guo, Qi
Ma, Yizhuo
Cao, Xiaofeng
Guo, Qing
contents Text-to-image diffusion models can generate realistic images based on textual inputs, enabling users to convey their opinions visually through language. Meanwhile, within language, emotion plays a crucial role in expressing personal opinions in our daily lives and the inclusion of maliciously negative content can lead users astray, exacerbating negative emotions. Recognizing the success of diffusion models and the significance of emotion, we investigate a previously overlooked risk associated with text-to-image diffusion models, that is, utilizing emotion in the input texts to introduce negative content and provoke unfavorable emotions in users. Specifically, we identify a new backdoor attack, i.e., emotion-aware backdoor attack (EmoAttack), which introduces malicious negative content triggered by emotional texts during image generation. We formulate such an attack as a diffusion personalization problem to avoid extensive model retraining and propose the EmoBooth. Unlike existing personalization methods, our approach fine-tunes a pre-trained diffusion model by establishing a mapping between a cluster of emotional words and a given reference image containing malicious negative content. To validate the effectiveness of our method, we built a dataset and conducted extensive analysis and discussion about its effectiveness. Given consumers' widespread use of diffusion models, uncovering this threat is critical for society.
format Preprint
id arxiv_https___arxiv_org_abs_2406_15863
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle EmoAttack: Emotion-to-Image Diffusion Models for Emotional Backdoor Generation
Wei, Tianyu
Pang, Shanmin
Guo, Qi
Ma, Yizhuo
Cao, Xiaofeng
Guo, Qing
Computer Vision and Pattern Recognition
Text-to-image diffusion models can generate realistic images based on textual inputs, enabling users to convey their opinions visually through language. Meanwhile, within language, emotion plays a crucial role in expressing personal opinions in our daily lives and the inclusion of maliciously negative content can lead users astray, exacerbating negative emotions. Recognizing the success of diffusion models and the significance of emotion, we investigate a previously overlooked risk associated with text-to-image diffusion models, that is, utilizing emotion in the input texts to introduce negative content and provoke unfavorable emotions in users. Specifically, we identify a new backdoor attack, i.e., emotion-aware backdoor attack (EmoAttack), which introduces malicious negative content triggered by emotional texts during image generation. We formulate such an attack as a diffusion personalization problem to avoid extensive model retraining and propose the EmoBooth. Unlike existing personalization methods, our approach fine-tunes a pre-trained diffusion model by establishing a mapping between a cluster of emotional words and a given reference image containing malicious negative content. To validate the effectiveness of our method, we built a dataset and conducted extensive analysis and discussion about its effectiveness. Given consumers' widespread use of diffusion models, uncovering this threat is critical for society.
title EmoAttack: Emotion-to-Image Diffusion Models for Emotional Backdoor Generation
topic Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2406.15863