{"id":"https://openalex.org/W4417149991","doi":"https://doi.org/10.1109/iccv51701.2025.01409","title":"Efficient Input-Level Backdoor Defense on Text-to-Image Synthesis via Neuron Activation Variation","display_name":"Efficient Input-Level Backdoor Defense on Text-to-Image Synthesis via Neuron Activation Variation","publication_year":2025,"publication_date":"2025-10-19","ids":{"openalex":"https://openalex.org/W4417149991","doi":"https://doi.org/10.1109/iccv51701.2025.01409"},"language":"en","primary_location":{"id":"doi:10.1109/iccv51701.2025.01409","is_oa":false,"landing_page_url":"https://doi.org/10.1109/iccv51701.2025.01409","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 IEEE/CVF International Conference on Computer Vision (ICCV)","raw_type":"proceedings-article"},"type":"article","indexed_in":["arxiv","crossref","datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://arxiv.org/pdf/2503.06453","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5008450480","display_name":"Shengfang Zhai","orcid":"https://orcid.org/0000-0001-6820-6361"},"institutions":[{"id":"https://openalex.org/I97750245","display_name":"Software (Spain)","ror":"https://ror.org/02ethns06","country_code":"ES","type":"company","lineage":["https://openalex.org/I4210087817","https://openalex.org/I97750245"]}],"countries":["ES"],"is_corresponding":true,"raw_author_name":"Shengfang Zhai","raw_affiliation_strings":["School of Software and Microelectronics, National Engineering Research Center for Software Engineering, Peking University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"School of Software and Microelectronics, National Engineering Research Center for Software Engineering, Peking University","institution_ids":["https://openalex.org/I97750245"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100352036","display_name":"Jiajun Li","orcid":"https://orcid.org/0000-0001-6571-0060"},"institutions":[{"id":"https://openalex.org/I97750245","display_name":"Software (Spain)","ror":"https://ror.org/02ethns06","country_code":"ES","type":"company","lineage":["https://openalex.org/I4210087817","https://openalex.org/I97750245"]}],"countries":["ES"],"is_corresponding":false,"raw_author_name":"Jiajun Li","raw_affiliation_strings":["School of Software and Microelectronics, National Engineering Research Center for Software Engineering, Peking University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"School of Software and Microelectronics, National Engineering Research Center for Software Engineering, Peking University","institution_ids":["https://openalex.org/I97750245"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100726727","display_name":"Zhaoyu Li","orcid":"https://orcid.org/0000-0002-5222-6832"},"institutions":[{"id":"https://openalex.org/I165932596","display_name":"National University of Singapore","ror":"https://ror.org/01tgyzw49","country_code":"SG","type":"education","lineage":["https://openalex.org/I165932596"]}],"countries":["SG"],"is_corresponding":false,"raw_author_name":"Yue Liu","raw_affiliation_strings":["National University of Singapore"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"National University of Singapore","institution_ids":["https://openalex.org/I165932596"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5074300516","display_name":"Huanran Chen","orcid":"https://orcid.org/0000-0003-0847-9485"},"institutions":[{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Huanran Chen","raw_affiliation_strings":["College of AI, Tsinghua University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"College of AI, Tsinghua University","institution_ids":["https://openalex.org/I99065089"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5021362492","display_name":"Zhihua Tian","orcid":"https://orcid.org/0000-0003-1175-7255"},"institutions":[{"id":"https://openalex.org/I76130692","display_name":"Zhejiang University","ror":"https://ror.org/00a2xv884","country_code":"CN","type":"education","lineage":["https://openalex.org/I76130692"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Zhihua Tian","raw_affiliation_strings":["Zhejiang University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Zhejiang University","institution_ids":["https://openalex.org/I76130692"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5109420698","display_name":"Wenjie Qu","orcid":"https://orcid.org/0009-0006-2907-008X"},"institutions":[{"id":"https://openalex.org/I165932596","display_name":"National University of Singapore","ror":"https://ror.org/01tgyzw49","country_code":"SG","type":"education","lineage":["https://openalex.org/I165932596"]}],"countries":["SG"],"is_corresponding":false,"raw_author_name":"Wenjie Qu","raw_affiliation_strings":["National University of Singapore"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"National University of Singapore","institution_ids":["https://openalex.org/I165932596"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5035938543","display_name":"Qingni Shen","orcid":"https://orcid.org/0000-0002-0605-6043"},"institutions":[{"id":"https://openalex.org/I97750245","display_name":"Software (Spain)","ror":"https://ror.org/02ethns06","country_code":"ES","type":"company","lineage":["https://openalex.org/I4210087817","https://openalex.org/I97750245"]}],"countries":["ES"],"is_corresponding":false,"raw_author_name":"Qingni Shen","raw_affiliation_strings":["School of Software and Microelectronics, National Engineering Research Center for Software Engineering, Peking University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"School of Software and Microelectronics, National Engineering Research Center for Software Engineering, Peking University","institution_ids":["https://openalex.org/I97750245"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5032275274","display_name":"Ruoxi Jia","orcid":"https://orcid.org/0000-0001-9662-9556"},"institutions":[{"id":"https://openalex.org/I859038795","display_name":"Virginia Tech","ror":"https://ror.org/02smfhw86","country_code":"US","type":"education","lineage":["https://openalex.org/I859038795"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Ruoxi Jia","raw_affiliation_strings":["Virginia Tech"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Virginia Tech","institution_ids":["https://openalex.org/I859038795"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5068755794","display_name":"Yinpeng Dong","orcid":"https://orcid.org/0000-0003-1299-683X"},"institutions":[{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yinpeng Dong","raw_affiliation_strings":["College of AI, Tsinghua University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"College of AI, Tsinghua University","institution_ids":["https://openalex.org/I99065089"]}]},{"author_position":"last","author":{"id":null,"display_name":"Jiaheng Zhang","orcid":null},"institutions":[{"id":"https://openalex.org/I165932596","display_name":"National University of Singapore","ror":"https://ror.org/01tgyzw49","country_code":"SG","type":"education","lineage":["https://openalex.org/I165932596"]}],"countries":["SG"],"is_corresponding":false,"raw_author_name":"Jiaheng Zhang","raw_affiliation_strings":["National University of Singapore"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"National University of Singapore","institution_ids":["https://openalex.org/I165932596"]}]}],"institutions":[],"countries_distinct_count":4,"institutions_distinct_count":10,"corresponding_author_ids":["https://openalex.org/A5008450480"],"corresponding_institution_ids":["https://openalex.org/I97750245"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.19613416,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":"15182","last_page":"15193"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.35440000891685486,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.35440000891685486,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10775","display_name":"Generative Adversarial Networks and Image Synthesis","score":0.21250000596046448,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12122","display_name":"Physical Unclonable Functions (PUFs) and Hardware Security","score":0.06909999996423721,"subfield":{"id":"https://openalex.org/subfields/1708","display_name":"Hardware and Architecture"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/backdoor","display_name":"Backdoor","score":0.8916000127792358},{"id":"https://openalex.org/keywords/variation","display_name":"Variation (astronomy)","score":0.5102999806404114},{"id":"https://openalex.org/keywords/neuron","display_name":"Neuron","score":0.3815000057220459},{"id":"https://openalex.org/keywords/diversity","display_name":"Diversity (politics)","score":0.35030001401901245},{"id":"https://openalex.org/keywords/camouflage","display_name":"Camouflage","score":0.34389999508857727},{"id":"https://openalex.org/keywords/quality","display_name":"Quality (philosophy)","score":0.3345000147819519}],"concepts":[{"id":"https://openalex.org/C2781045450","wikidata":"https://www.wikidata.org/wiki/Q254569","display_name":"Backdoor","level":2,"score":0.8916000127792358},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6338000297546387},{"id":"https://openalex.org/C2778334786","wikidata":"https://www.wikidata.org/wiki/Q1586270","display_name":"Variation (astronomy)","level":2,"score":0.5102999806404114},{"id":"https://openalex.org/C2778794669","wikidata":"https://www.wikidata.org/wiki/Q43054","display_name":"Neuron","level":2,"score":0.3815000057220459},{"id":"https://openalex.org/C169760540","wikidata":"https://www.wikidata.org/wiki/Q207011","display_name":"Neuroscience","level":1,"score":0.36820000410079956},{"id":"https://openalex.org/C2781316041","wikidata":"https://www.wikidata.org/wiki/Q1230584","display_name":"Diversity (politics)","level":2,"score":0.35030001401901245},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.34450000524520874},{"id":"https://openalex.org/C2776196576","wikidata":"https://www.wikidata.org/wiki/Q196113","display_name":"Camouflage","level":2,"score":0.34389999508857727},{"id":"https://openalex.org/C2779530757","wikidata":"https://www.wikidata.org/wiki/Q1207505","display_name":"Quality (philosophy)","level":2,"score":0.3345000147819519},{"id":"https://openalex.org/C61797465","wikidata":"https://www.wikidata.org/wiki/Q1188986","display_name":"Term (time)","level":2,"score":0.3116999864578247},{"id":"https://openalex.org/C186060115","wikidata":"https://www.wikidata.org/wiki/Q30336093","display_name":"Biological system","level":1,"score":0.29660001397132874},{"id":"https://openalex.org/C2780586970","wikidata":"https://www.wikidata.org/wiki/Q1357284","display_name":"Popularity","level":2,"score":0.2703999876976013},{"id":"https://openalex.org/C69357855","wikidata":"https://www.wikidata.org/wiki/Q163214","display_name":"Diffusion","level":2,"score":0.2676999866962433},{"id":"https://openalex.org/C153701036","wikidata":"https://www.wikidata.org/wiki/Q659974","display_name":"Trustworthiness","level":2,"score":0.25540000200271606},{"id":"https://openalex.org/C2780451532","wikidata":"https://www.wikidata.org/wiki/Q759676","display_name":"Task (project management)","level":2,"score":0.250900000333786},{"id":"https://openalex.org/C86803240","wikidata":"https://www.wikidata.org/wiki/Q420","display_name":"Biology","level":0,"score":0.25029999017715454}],"mesh":[],"locations_count":3,"locations":[{"id":"doi:10.1109/iccv51701.2025.01409","is_oa":false,"landing_page_url":"https://doi.org/10.1109/iccv51701.2025.01409","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 IEEE/CVF International Conference on Computer Vision (ICCV)","raw_type":"proceedings-article"},{"id":"pmh:oai:arXiv.org:2503.06453","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2503.06453","pdf_url":"https://arxiv.org/pdf/2503.06453","source":{"id":"https://openalex.org/S4393918464","display_name":"ArXiv.org","issn_l":"2331-8422","issn":["2331-8422"],"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},{"id":"doi:10.48550/arxiv.2503.06453","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2503.06453","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"pmh:oai:arXiv.org:2503.06453","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2503.06453","pdf_url":"https://arxiv.org/pdf/2503.06453","source":{"id":"https://openalex.org/S4393918464","display_name":"ArXiv.org","issn_l":"2331-8422","issn":["2331-8422"],"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G5760448940","display_name":null,"funder_award_id":"CNS-2424127","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G7677721048","display_name":null,"funder_award_id":"2022YFB2703301","funder_id":"https://openalex.org/F4320335777","funder_display_name":"National Key Research and Development Program of China"}],"funders":[{"id":"https://openalex.org/F4320306076","display_name":"National Science Foundation","ror":"https://ror.org/021nxhr62"},{"id":"https://openalex.org/F4320335777","display_name":"National Key Research and Development Program of China","ror":null}],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"In":[0,57],"recent":[1],"years,":[2],"text-to-image":[3],"(T2I)":[4],"diffusion":[5,97],"models":[6,113],"have":[7],"gained":[8],"significant":[9,87],"attention":[10],"for":[11],"their":[12,23],"ability":[13],"to":[14,29,48,85,114],"generate":[15],"high":[16],"quality":[17],"images":[18],"reflecting":[19],"text":[20],"prompts.":[21],"However,":[22],"growing":[24],"popularity":[25],"has":[26],"also":[27],"led":[28],"the":[30,49,78,92,96,134],"emergence":[31],"of":[32,51,95],"backdoor":[33,52,66],"threats,":[34],"posing":[35],"substantial":[36],"risks.":[37],"Currently,":[38],"effective":[39,162],"defense":[40,67],"strategies":[41],"against":[42,69],"such":[43],"threats":[44],"are":[45],"lacking":[46],"due":[47],"diversity":[50],"targets":[53],"in":[54,91,136],"T2I":[55,71,112,145],"synthesis.":[56],"this":[58,108],"paper,":[59],"we":[60,102,156],"propose":[61],"NaviT2I,":[62],"an":[63],"efficient":[64],"input-level":[65],"framework":[68],"diverse":[70,142],"backdoors.":[72],"Our":[73],"approach":[74],"is":[75],"based":[76],"on":[77],"new":[79],"observation":[80],"that":[81,130,158],"trigger":[82],"tokens":[83],"tend":[84],"induce":[86],"neuron":[88],"activation":[89,121],"variation":[90],"early":[93],"stage":[94],"generation":[98],"process,":[99],"a":[100],"phenomenon":[101],"term":[103],"Early-step":[104],"Activation":[105],"Variation.":[106],"Leveraging":[107],"insight,":[109],"NaviT2I":[110,131],"navigates":[111],"prevent":[115],"malicious":[116],"inputs":[117],"by":[118,124],"analyzing":[119],"Neuron":[120],"variations":[122],"caused":[123],"input":[125],"tokens.":[126],"Extensive":[127],"experiments":[128],"show":[129,157],"significantly":[132],"outperforms":[133],"baselines":[135],"both":[137],"effectiveness":[138],"and":[139,147,153],"efficiency":[140],"across":[141],"datasets,":[143],"various":[144],"backdoors,":[146],"different":[148],"model":[149],"architectures":[150],"including":[151],"UNet":[152],"DiT.":[154],"Furthermore,":[155],"our":[159],"method":[160],"remains":[161],"under":[163],"potential":[164],"adaptive":[165],"attacks.":[166]},"counts_by_year":[],"updated_date":"2026-05-06T06:03:25.996018","created_date":"2025-10-10T00:00:00"}
