Share your thoughts, 1 month free Claude Pro on usSee more
WorkDL logo mark

TEMPO-Diffusion: Temporally Exposed Malicious Poisoning of Diffusion Models

About

Noise-based backdoor attacks on diffusion models typically rely on input-time trigger injection, untargeted activation, and out-of-distribution target generation. Such assumptions reduce both the stealthiness and the practical relevance of these attacks. In this work, we present TEMPO-Diffusion, a targeted backdoor framework that localizes the malicious distribution shift to a temporal, in-distribution exposure. TEMPO-Diffusion supports: (i) targeted attacks on and to specific classes, (ii) multiple sub-image backdoors that reconstruct specific features within multiple, different output images and at multiple locations, and (iii) in-painting with time-conditioned triggers. To study relevant, practical security concerns in leveraging backdoored diffusion models for synthetic training data, we also introduce CALISA: a balanced, region-aware traffic-sign dataset emphasizing Canadian and U.S. road signs. Across CIFAR10, GTSRB, and CALISA, our experiments show that TEMPO-Diffusion can reliably poison class-specific synthetic data generation and induce high attack success rates in downstream classifiers trained on that data.

William Aiken, Paula Branco, Guy-Vincent Jourdan, Iosif-Viorel Onut• 2026

Related benchmarks

TaskDatasetResultRank
Image ClassificationCALISA (val)
Clean Accuracy97.66
8
Image ClassificationCIFAR10 (val)
Clean Accuracy78.96
8
Image ClassificationCIFAR10 (test)
Clean Accuracy84.7
8
Image ClassificationGTSRB (test)
Clean Accuracy98.31
8
Image ClassificationCALISA (test)
Clean Accuracy97.88
8
Image ClassificationGTSRB (val)
Clean Accuracy99.56
8
Backdoor Attack EvaluationCIFAR10
Vicinity (nc)28.5
6
Backdoor Attack EvaluationGTSRB
Vicnc22.3
6
Backdoor Attack EvaluationCALISA
Vicn Success Rate (c)18.4
6
Showing 9 of 9 rows

Other info

Follow for update