Reconstructing Template-Memorized Images from Natural Prompts
Sol Yarkoni, Mahmood Sharif, Roi Livni
摘要
Recent advances in generative models, such as diffusion models, have raised several risks and concerns related to privacy, copyright infringement, and data stewardship. To better understand and mitigate these risks, prior work has proposed techniques and attacks that reconstruct images, or parts of images, from the training set. While these approaches demonstrate that training data can be recovered, they often rely on substantial computational resources, access to the training set, or carefully engineered prompts. In this work, we devise a new attack that requires low resources, assumes little to no access to the training data, and identifies seemingly benign prompts that lead to potentially risky image reconstruction. We further show that such reconstructions may occur unintentionally and can be produced by users without specific expertise. For example, we observe that, for one existing model, the prompt "blue Unisex T-Shirt" generates the face of a real individual. Moreover, by combining the identified vulnerabilities with real-world prompt data, we uncover prompts that reproduce memorized elements. Our method builds on intuitions from prior work and leverages domain knowledge to reveal a fundamental vulnerability arising from the use of scraped data from e-commerce platforms, where templated layouts and images are associated with pattern-like prompts.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper15
- Extracting Training Data from Large Language ModelsNicholas Carlini, Florian Tramèr, Eric Wallace, Matthew Jagielski 等USENIX Security 2021 · 被引用 2,866 次
- Deduplicating Training Data Makes Language Models BetterKatherine Lee, Daphne Ippolito, Andrew Nystrom, Chiyuan Zhang 等ACL 2022 · 被引用 844 次
- Deduplicating Training Data Mitigates Privacy Risks in Language ModelsNikhil Kandpal, Eric Wallace, Colin RaffelICML 2022 · 被引用 395 次
- Understanding and Mitigating Copying in Diffusion ModelsGowthami Somepalli, Vasu Singla, Micah Goldblum, Jonas Geiping 等NeurIPS 2023 · 被引用 265 次
- Reconstructing Training Data From Trained Neural NetworksNiv Haim, Gal Vardi, Gilad Yehudai, Ohad Shamir 等NeurIPS 2022 · 被引用 196 次
相关 Paper
- Prompt Stealing Attacks Against Text-to-Image Generation ModelsXinyue Shen, Yiting Qu, Michael Backes, Yang ZhangUSENIX Security 2024 · 被引用 65 次
- Silent Branding Attack: Trigger-free Data Poisoning Attack on Text-to-Image Diffusion ModelsSangwon Jang, June Suk Choi, Jaehyeong Jo, Kimin Lee 等CVPR 2025
- The Stronger the Diffusion Model, the Easier the Backdoor: Data Poisoning to Induce Copyright BreachesWithout Adjusting Finetuning PipelineHaonan Wang, Qianli Shen, Yao Tong, Yang Zhang 等ICML 2024 · 被引用 48 次
- SIDE: Surrogate Conditional Data Extraction from Diffusion ModelsYunhao Chen, Shujie Wang, Difan Zou, Xingjun MaAAAI 2026 · 被引用 9 次
- TrojDiff: Trojan Attacks on Diffusion Models with Diverse TargetsWeixin Chen, Dawn Song, Bo LiCVPR 2023
