Dark Miner: Defend against undesirable generation for text-to-image diffusion models

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Meng, Zheling, Peng, Bo, Jin, Xiaochuan, Jiang, Yue, Wang, Wei, Dong, Jing, Tan, Tieniu
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866918127628976128
author Meng, Zheling
Peng, Bo
Jin, Xiaochuan
Jiang, Yue
Wang, Wei
Dong, Jing
Tan, Tieniu
author_facet Meng, Zheling
Peng, Bo
Jin, Xiaochuan
Jiang, Yue
Wang, Wei
Dong, Jing
Tan, Tieniu
contents Text-to-image diffusion models have been demonstrated with undesired generation due to unfiltered large-scale training data, such as sexual images and copyrights, necessitating the erasure of undesired concepts. Most existing methods focus on modifying the generation probabilities conditioned on the texts containing target concepts. However, they fail to guarantee the desired generation of texts unseen in the training phase, especially for the adversarial texts from malicious attacks. In this paper, we analyze the erasure task and point out that existing methods cannot guarantee the minimization of the total probabilities of undesired generation. To tackle this problem, we propose Dark Miner. It entails a recurring three-stage process that comprises mining, verifying, and circumventing. This method greedily mines embeddings with maximum generation probabilities of target concepts and more effectively reduces their generation. In the experiments, we evaluate its performance on the inappropriateness, object, and style concepts. Compared with the previous methods, our method achieves better erasure and defense results, especially under multiple adversarial attacks, while preserving the native generation capability of the models. Our code will be available on GitHub.
format Preprint
id arxiv_https___arxiv_org_abs_2409_17682
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Dark Miner: Defend against undesirable generation for text-to-image diffusion models
Meng, Zheling
Peng, Bo
Jin, Xiaochuan
Jiang, Yue
Wang, Wei
Dong, Jing
Tan, Tieniu
Computer Vision and Pattern Recognition
Text-to-image diffusion models have been demonstrated with undesired generation due to unfiltered large-scale training data, such as sexual images and copyrights, necessitating the erasure of undesired concepts. Most existing methods focus on modifying the generation probabilities conditioned on the texts containing target concepts. However, they fail to guarantee the desired generation of texts unseen in the training phase, especially for the adversarial texts from malicious attacks. In this paper, we analyze the erasure task and point out that existing methods cannot guarantee the minimization of the total probabilities of undesired generation. To tackle this problem, we propose Dark Miner. It entails a recurring three-stage process that comprises mining, verifying, and circumventing. This method greedily mines embeddings with maximum generation probabilities of target concepts and more effectively reduces their generation. In the experiments, we evaluate its performance on the inappropriateness, object, and style concepts. Compared with the previous methods, our method achieves better erasure and defense results, especially under multiple adversarial attacks, while preserving the native generation capability of the models. Our code will be available on GitHub.
title Dark Miner: Defend against undesirable generation for text-to-image diffusion models
topic Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2409.17682