Share your thoughts, 1 month free Claude Pro on usSee more
WorkDL logo mark

A Pilot Study of Query-Free Adversarial Attack against Stable Diffusion

About

Despite the record-breaking performance in Text-to-Image (T2I) generation by Stable Diffusion, less research attention is paid to its adversarial robustness. In this work, we study the problem of adversarial attack generation for Stable Diffusion and ask if an adversarial text prompt can be obtained even in the absence of end-to-end model queries. We call the resulting problem 'query-free attack generation'. To resolve this problem, we show that the vulnerability of T2I models is rooted in the lack of robustness of text encoders, e.g., the CLIP text encoder used for attacking Stable Diffusion. Based on such insight, we propose both untargeted and targeted query-free attacks, where the former is built on the most influential dimensions in the text embedding space, which we call steerable key dimensions. By leveraging the proposed attacks, we empirically show that only a five-character perturbation to the text prompt is able to cause the significant content shift of synthesized images using Stable Diffusion. Moreover, we show that the proposed target attack can precisely steer the diffusion model to scrub the targeted image content without causing much change in untargeted image content. Our code is available at https://github.com/OPTML-Group/QF-Attack.

Haomin Zhuang, Yihua Zhang, Sijia Liu• 2023

Related benchmarks

TaskDatasetResultRank
JailbreakingMHSC
ASR-424.5
44
JailbreakingQ16
ASR-437.5
44
JailbreakingUnsafe Prompts
Bypass Success Rate (Text)71
22
Textual Modal AttackLAION-COCO subset, UnsafeDiff, and I2P NSFW prompts (test)
Q16 ASR (Step 4)39
15
Text-to-Image Adversarial AttackI2P matching categories subset
Bypass Rate93.3
11
Jailbreak AttackI2P
SC ASR (4 attempts)27.88
11
Jailbreak AttackSDXL
TASR (%)37
6
Jailbreak AttackSD LT 3.5
TASR (%)37
6
Jailbreaking Text-to-ImageCivitai NSFW on SD3.5LT
Runtime (s)82.06
6
Jailbreak AttackMidjourney
TASR39.64
6
Showing 10 of 15 rows

Other info

Follow for update