REFORGE: Multi-modal Attacks Reveal Vulnerable Concept Unlearning in Image Generation Models

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Zou, Yong, Li, Haoran, Li, Fanxiao, Wei, Shenyang, Dong, Yunyun, Tang, Li, Zhou, Wei, Liu, Renyang
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866908894017617920
author Zou, Yong
Li, Haoran
Li, Fanxiao
Wei, Shenyang
Dong, Yunyun
Tang, Li
Zhou, Wei
Liu, Renyang
author_facet Zou, Yong
Li, Haoran
Li, Fanxiao
Wei, Shenyang
Dong, Yunyun
Tang, Li
Zhou, Wei
Liu, Renyang
contents Recent progress in image generation models (IGMs) enables high-fidelity content creation but also amplifies risks, including the reproduction of copyrighted content and the generation of offensive content. Image Generation Model Unlearning (IGMU) mitigates these risks by removing harmful concepts without full retraining. Despite growing attention, the robustness under adversarial inputs, particularly image-side threats in black-box settings, remains underexplored. To bridge this gap, we present REFORGE, a black-box red-teaming framework that evaluates IGMU robustness via adversarial image prompts. REFORGE initializes stroke-based images and optimizes perturbations with a cross-attention-guided masking strategy that allocates noise to concept-relevant regions, balancing attack efficacy and visual fidelity. Extensive experiments across representative unlearning tasks and defenses demonstrate that REFORGE significantly improves attack success rate while achieving stronger semantic alignment and higher efficiency than involved baselines. These results expose persistent vulnerabilities in current IGMU methods and highlight the need for robustness-aware unlearning against multi-modal adversarial attacks. Our code is at: https://github.com/Imfatnoily/REFORGE.
format Preprint
id arxiv_https___arxiv_org_abs_2603_16576
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle REFORGE: Multi-modal Attacks Reveal Vulnerable Concept Unlearning in Image Generation Models
Zou, Yong
Li, Haoran
Li, Fanxiao
Wei, Shenyang
Dong, Yunyun
Tang, Li
Zhou, Wei
Liu, Renyang
Computer Vision and Pattern Recognition
Artificial Intelligence
Cryptography and Security
Machine Learning
Recent progress in image generation models (IGMs) enables high-fidelity content creation but also amplifies risks, including the reproduction of copyrighted content and the generation of offensive content. Image Generation Model Unlearning (IGMU) mitigates these risks by removing harmful concepts without full retraining. Despite growing attention, the robustness under adversarial inputs, particularly image-side threats in black-box settings, remains underexplored. To bridge this gap, we present REFORGE, a black-box red-teaming framework that evaluates IGMU robustness via adversarial image prompts. REFORGE initializes stroke-based images and optimizes perturbations with a cross-attention-guided masking strategy that allocates noise to concept-relevant regions, balancing attack efficacy and visual fidelity. Extensive experiments across representative unlearning tasks and defenses demonstrate that REFORGE significantly improves attack success rate while achieving stronger semantic alignment and higher efficiency than involved baselines. These results expose persistent vulnerabilities in current IGMU methods and highlight the need for robustness-aware unlearning against multi-modal adversarial attacks. Our code is at: https://github.com/Imfatnoily/REFORGE.
title REFORGE: Multi-modal Attacks Reveal Vulnerable Concept Unlearning in Image Generation Models
topic Computer Vision and Pattern Recognition
Artificial Intelligence
Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2603.16576