Vulnerability of Text-to-Image Models to Prompt Template Stealing: A Differential Evolution Approach

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Wu, Yurong, Mu, Fangwen, Zhang, Qiuhong, Zhao, Jinjing, Xu, Xinrun, Mei, Lingrui, Wu, Yang, Shi, Lin, Wang, Junjie, Ding, Zhiming, Wang, Yiwei
Natura: Preprint
Pubblicazione: 2025
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866908368138928128
author Wu, Yurong
Mu, Fangwen
Zhang, Qiuhong
Zhao, Jinjing
Xu, Xinrun
Mei, Lingrui
Wu, Yang
Shi, Lin
Wang, Junjie
Ding, Zhiming
Wang, Yiwei
author_facet Wu, Yurong
Mu, Fangwen
Zhang, Qiuhong
Zhao, Jinjing
Xu, Xinrun
Mei, Lingrui
Wu, Yang
Shi, Lin
Wang, Junjie
Ding, Zhiming
Wang, Yiwei
contents Prompt trading has emerged as a significant intellectual property concern in recent years, where vendors entice users by showcasing sample images before selling prompt templates that can generate similar images. This work investigates a critical security vulnerability: attackers can steal prompt templates using only a limited number of sample images. To investigate this threat, we introduce Prism, a prompt-stealing benchmark consisting of 50 templates and 450 images, organized into Easy and Hard difficulty levels. To identify the vulnerabity of VLMs to prompt stealing, we propose EvoStealer, a novel template stealing method that operates without model fine-tuning by leveraging differential evolution algorithms. The system first initializes population sets using multimodal large language models (MLLMs) based on predefined patterns, then iteratively generates enhanced offspring through MLLMs. During evolution, EvoStealer identifies common features across offspring to derive generalized templates. Our comprehensive evaluation conducted across open-source (INTERNVL2-26B) and closed-source models (GPT-4o and GPT-4o-mini) demonstrates that EvoStealer's stolen templates can reproduce images highly similar to originals and effectively generalize to other subjects, significantly outperforming baseline methods with an average improvement of over 10%. Moreover, our cost analysis reveals that EvoStealer achieves template stealing with negligible computational expenses. Our code and dataset are available at https://github.com/whitepagewu/evostealer.
format Preprint
id arxiv_https___arxiv_org_abs_2502_14285
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Vulnerability of Text-to-Image Models to Prompt Template Stealing: A Differential Evolution Approach
Wu, Yurong
Mu, Fangwen
Zhang, Qiuhong
Zhao, Jinjing
Xu, Xinrun
Mei, Lingrui
Wu, Yang
Shi, Lin
Wang, Junjie
Ding, Zhiming
Wang, Yiwei
Computation and Language
Prompt trading has emerged as a significant intellectual property concern in recent years, where vendors entice users by showcasing sample images before selling prompt templates that can generate similar images. This work investigates a critical security vulnerability: attackers can steal prompt templates using only a limited number of sample images. To investigate this threat, we introduce Prism, a prompt-stealing benchmark consisting of 50 templates and 450 images, organized into Easy and Hard difficulty levels. To identify the vulnerabity of VLMs to prompt stealing, we propose EvoStealer, a novel template stealing method that operates without model fine-tuning by leveraging differential evolution algorithms. The system first initializes population sets using multimodal large language models (MLLMs) based on predefined patterns, then iteratively generates enhanced offspring through MLLMs. During evolution, EvoStealer identifies common features across offspring to derive generalized templates. Our comprehensive evaluation conducted across open-source (INTERNVL2-26B) and closed-source models (GPT-4o and GPT-4o-mini) demonstrates that EvoStealer's stolen templates can reproduce images highly similar to originals and effectively generalize to other subjects, significantly outperforming baseline methods with an average improvement of over 10%. Moreover, our cost analysis reveals that EvoStealer achieves template stealing with negligible computational expenses. Our code and dataset are available at https://github.com/whitepagewu/evostealer.
title Vulnerability of Text-to-Image Models to Prompt Template Stealing: A Differential Evolution Approach
topic Computation and Language
url https://arxiv.org/abs/2502.14285