Hate in Plain Sight: On the Risks of Moderating AI-Generated Hateful Illusions

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Qu, Yiting, Yang, Ziqing, Ma, Yihan, Backes, Michael, Zannettou, Savvas, Zhang, Yang
Natura: Preprint
Pubblicazione: 2025
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866911083777753088
author Qu, Yiting
Yang, Ziqing
Ma, Yihan
Backes, Michael
Zannettou, Savvas
Zhang, Yang
author_facet Qu, Yiting
Yang, Ziqing
Ma, Yihan
Backes, Michael
Zannettou, Savvas
Zhang, Yang
contents Recent advances in text-to-image diffusion models have enabled the creation of a new form of digital art: optical illusions--visual tricks that create different perceptions of reality. However, adversaries may misuse such techniques to generate hateful illusions, which embed specific hate messages into harmless scenes and disseminate them across web communities. In this work, we take the first step toward investigating the risks of scalable hateful illusion generation and the potential for bypassing current content moderation models. Specifically, we generate 1,860 optical illusions using Stable Diffusion and ControlNet, conditioned on 62 hate messages. Of these, 1,571 are hateful illusions that successfully embed hate messages, either overtly or subtly, forming the Hateful Illusion dataset. Using this dataset, we evaluate the performance of six moderation classifiers and nine vision language models (VLMs) in identifying hateful illusions. Experimental results reveal significant vulnerabilities in existing moderation models: the detection accuracy falls below 0.245 for moderation classifiers and below 0.102 for VLMs. We further identify a critical limitation in their vision encoders, which mainly focus on surface-level image details while overlooking the secondary layer of information, i.e., hidden messages. To address this risk, we explore preliminary mitigation measures and identify the most effective approaches from the perspectives of image transformations and training-level strategies.
format Preprint
id arxiv_https___arxiv_org_abs_2507_22617
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Hate in Plain Sight: On the Risks of Moderating AI-Generated Hateful Illusions
Qu, Yiting
Yang, Ziqing
Ma, Yihan
Backes, Michael
Zannettou, Savvas
Zhang, Yang
Cryptography and Security
Computer Vision and Pattern Recognition
Recent advances in text-to-image diffusion models have enabled the creation of a new form of digital art: optical illusions--visual tricks that create different perceptions of reality. However, adversaries may misuse such techniques to generate hateful illusions, which embed specific hate messages into harmless scenes and disseminate them across web communities. In this work, we take the first step toward investigating the risks of scalable hateful illusion generation and the potential for bypassing current content moderation models. Specifically, we generate 1,860 optical illusions using Stable Diffusion and ControlNet, conditioned on 62 hate messages. Of these, 1,571 are hateful illusions that successfully embed hate messages, either overtly or subtly, forming the Hateful Illusion dataset. Using this dataset, we evaluate the performance of six moderation classifiers and nine vision language models (VLMs) in identifying hateful illusions. Experimental results reveal significant vulnerabilities in existing moderation models: the detection accuracy falls below 0.245 for moderation classifiers and below 0.102 for VLMs. We further identify a critical limitation in their vision encoders, which mainly focus on surface-level image details while overlooking the secondary layer of information, i.e., hidden messages. To address this risk, we explore preliminary mitigation measures and identify the most effective approaches from the perspectives of image transformations and training-level strategies.
title Hate in Plain Sight: On the Risks of Moderating AI-Generated Hateful Illusions
topic Cryptography and Security
Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2507.22617