Papers
Topics
Authors
Recent
Gemini 2.5 Flash
Gemini 2.5 Flash
41 tokens/sec
GPT-4o
59 tokens/sec
Gemini 2.5 Pro Pro
41 tokens/sec
o3 Pro
7 tokens/sec
GPT-4.1 Pro
50 tokens/sec
DeepSeek R1 via Azure Pro
28 tokens/sec
2000 character limit reached

Elijah: Eliminating Backdoors Injected in Diffusion Models via Distribution Shift (2312.00050v2)

Published 27 Nov 2023 in cs.CR, cs.AI, and cs.LG

Abstract: Diffusion models (DM) have become state-of-the-art generative models because of their capability to generate high-quality images from noises without adversarial training. However, they are vulnerable to backdoor attacks as reported by recent studies. When a data input (e.g., some Gaussian noise) is stamped with a trigger (e.g., a white patch), the backdoored model always generates the target image (e.g., an improper photo). However, effective defense strategies to mitigate backdoors from DMs are underexplored. To bridge this gap, we propose the first backdoor detection and removal framework for DMs. We evaluate our framework Elijah on hundreds of DMs of 3 types including DDPM, NCSN and LDM, with 13 samplers against 3 existing backdoor attacks. Extensive experiments show that our approach can have close to 100% detection accuracy and reduce the backdoor effects to close to zero without significantly sacrificing the model utility.

User Edit Pencil Streamline Icon: https://streamlinehq.com
Authors (11)
  1. Shengwei An (14 papers)
  2. Sheng-Yen Chou (4 papers)
  3. Kaiyuan Zhang (38 papers)
  4. Qiuling Xu (10 papers)
  5. Guanhong Tao (33 papers)
  6. Guangyu Shen (21 papers)
  7. Siyuan Cheng (41 papers)
  8. Shiqing Ma (56 papers)
  9. Pin-Yu Chen (311 papers)
  10. Tsung-Yi Ho (57 papers)
  11. Xiangyu Zhang (328 papers)
Citations (16)
X Twitter Logo Streamline Icon: https://streamlinehq.com