Share your thoughts, 1 month free Claude Pro on usSee more
WorkDL logo mark

Efficient Input-level Backdoor Defense on Text-to-Image Synthesis via Neuron Activation Variation

About

In recent years, text-to-image (T2I) diffusion models have gained significant attention for their ability to generate high quality images reflecting text prompts. However, their growing popularity has also led to the emergence of backdoor threats, posing substantial risks. Currently, effective defense strategies against such threats are lacking due to the diversity of backdoor targets in T2I synthesis. In this paper, we propose NaviT2I, an efficient input-level backdoor defense framework against diverse T2I backdoors. Our approach is based on the new observation that trigger tokens tend to induce significant neuron activation variation in the early stage of the diffusion generation process, a phenomenon we term Early-step Activation Variation. Leveraging this insight, NaviT2I navigates T2I models to prevent malicious inputs by analyzing Neuron activation variations caused by input tokens. Extensive experiments show that NaviT2I significantly outperforms the baselines in both effectiveness and efficiency across diverse datasets, various T2I backdoors, and different model architectures including UNet and DiT. Furthermore, we show that our method remains effective under potential adaptive attacks.

Shengfang Zhai, Jiajun Li, Yue Liu, Huanran Chen, Zhihua Tian, Wenjie Qu, Qingni Shen, Ruoxi Jia, Yinpeng Dong, Jiaheng Zhang• 2025

Related benchmarks

TaskDatasetResultRank
Backdoor DetectionStable Diffusion ObjRepAtt attacks v1.5
Precision95.24
23
Backdoor DetectionMS-COCO v1.4 (val)
RickBKD Detection Rate99.9
14
Backdoor DetectionStable Diffusion StyleAtt attacks v1.5
Precision93.33
10
Backdoor DetectionMS-COCO (val)
RickBKD88.2
7
Backdoor DetectionStable Diffusion Overall All Attacks v1.5
Precision90.01
6
Backdoor DetectionStable Diffusion FixIMgAtt attacks v1.5
Precision86.27
6
Backdoor DetectionStable Diffusion PatchAtt attacks v1.5
Precision93.88
5
Backdoor DetectionMS-COCO BadT2ITok v1.4 (test)
Accuracy91.4
5
Backdoor DetectionMS-COCO BadT2ISent v1.4 (test)
Accuracy74.5
5
Backdoor DetectionMS-COCO EvilEdit v1.4 (test)
Accuracy63.4
5
Showing 10 of 12 rows

Other info

Follow for update