Reliable and Efficient Concept Erasure of Text-to-Image Diffusion Models
About
Text-to-image models encounter safety issues, including concerns related to copyright and Not-Safe-For-Work (NSFW) content. Despite several methods have been proposed for erasing inappropriate concepts from diffusion models, they often exhibit incomplete erasure, consume a lot of computing resources, and inadvertently damage generation ability. In this work, we introduce Reliable and Efficient Concept Erasure (RECE), a novel approach that modifies the model in 3 seconds without necessitating additional fine-tuning. Specifically, RECE efficiently leverages a closed-form solution to derive new target embeddings, which are capable of regenerating erased concepts within the unlearned model. To mitigate inappropriate content potentially represented by derived embeddings, RECE further aligns them with harmless concepts in cross-attention layers. The derivation and erasure of new representation embeddings are conducted iteratively to achieve a thorough erasure of inappropriate concepts. Besides, to preserve the model's generation ability, RECE introduces an additional regularization term during the derivation process, resulting in minimizing the impact on unrelated concepts during the erasure process. All the processes above are in closed-form, guaranteeing extremely efficient erasure in only 3 seconds. Benchmarking against previous approaches, our method achieves more efficient and thorough erasure with minor damage to original generation ability and demonstrates enhanced robustness against red-teaming tools. Code is available at \url{https://github.com/CharlesGong12/RECE}.
Related benchmarks
| Task | Dataset | Result | Rank | |
|---|---|---|---|---|
| Text-to-Image Generation | COCO | FID65.94 | 51 | |
| Concept Unlearning | UnlearnDiffAtk | UnlearnDiffAtk0.2183 | 36 | |
| Text-to-Image Generation | COCO 30k | FID33.94 | 29 | |
| Explicit Content Removal | I2P | Armpits Count45 | 28 | |
| Concept Unlearning | Ring-a-Bell | Ring-A-Bell Score13.4 | 20 | |
| Safe Text-to-Image Generation | MMA-Diffusion | Automatic Safety Rate67.5 | 20 | |
| Text-to-Image Safety | T2VSafetyBench | Harmful Rate0.189 | 18 | |
| Text-to-Image Generation | Non-targeted concepts | CLIP Score30.9 | 18 | |
| Text-to-Image Safety | CoPro v2 | Harmful Rate8.6 | 18 | |
| Text-to-Image Safety | UD | Harmful Rate22.3 | 18 |