{"id":"https://openalex.org/W4415708677","doi":"https://doi.org/10.1109/icme59968.2025.11210084","title":"Weaponizing Tokens: Backdooring Text-to-Image Generation via Token Remapping","display_name":"Weaponizing Tokens: Backdooring Text-to-Image Generation via Token Remapping","publication_year":2025,"publication_date":"2025-06-30","ids":{"openalex":"https://openalex.org/W4415708677","doi":"https://doi.org/10.1109/icme59968.2025.11210084"},"language":null,"primary_location":{"id":"doi:10.1109/icme59968.2025.11210084","is_oa":false,"landing_page_url":"https://doi.org/10.1109/icme59968.2025.11210084","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 IEEE International Conference on Multimedia and Expo (ICME)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5101721206","display_name":"Jiaming He","orcid":"https://orcid.org/0009-0007-9529-7327"},"institutions":[{"id":"https://openalex.org/I150229711","display_name":"University of Electronic Science and Technology of China","ror":"https://ror.org/04qr3zq92","country_code":"CN","type":"education","lineage":["https://openalex.org/I150229711"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Jiaming He","raw_affiliation_strings":["University of Electronic Science and Technology of China,School of Computer Science and Engineering,China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"University of Electronic Science and Technology of China,School of Computer Science and Engineering,China","institution_ids":["https://openalex.org/I150229711"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5066542952","display_name":"Wenbo Jiang","orcid":"https://orcid.org/0000-0002-4592-8094"},"institutions":[{"id":"https://openalex.org/I150229711","display_name":"University of Electronic Science and Technology of China","ror":"https://ror.org/04qr3zq92","country_code":"CN","type":"education","lineage":["https://openalex.org/I150229711"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Wenbo Jiang","raw_affiliation_strings":["University of Electronic Science and Technology of China,School of Computer Science and Engineering,China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"University of Electronic Science and Technology of China,School of Computer Science and Engineering,China","institution_ids":["https://openalex.org/I150229711"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Guanyu Hou","orcid":null},"institutions":[{"id":"https://openalex.org/I31595395","display_name":"Chengdu University of Technology","ror":"https://ror.org/05pejbw21","country_code":"CN","type":"education","lineage":["https://openalex.org/I31595395"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Guanyu Hou","raw_affiliation_strings":["Chengdu University of Technology,College of Computer Science and Cyber Security (Oxford Brookes College),China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Chengdu University of Technology,College of Computer Science and Cyber Security (Oxford Brookes College),China","institution_ids":["https://openalex.org/I31595395"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5001892361","display_name":"Qiyang Song","orcid":"https://orcid.org/0000-0002-1596-3331"},"institutions":[{"id":"https://openalex.org/I19820366","display_name":"Chinese Academy of Sciences","ror":"https://ror.org/034t30j35","country_code":"CN","type":"government","lineage":["https://openalex.org/I19820366"]},{"id":"https://openalex.org/I4210156404","display_name":"Institute of Information Engineering","ror":"https://ror.org/04r53se39","country_code":"CN","type":"facility","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210156404"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Qiyang Song","raw_affiliation_strings":["Chinese Academy of Sciences,Institute of Information Engineering,China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Chinese Academy of Sciences,Institute of Information Engineering,China","institution_ids":["https://openalex.org/I4210156404","https://openalex.org/I19820366"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5017191320","display_name":"Ji Guo","orcid":"https://orcid.org/0009-0008-8990-436X"},"institutions":[{"id":"https://openalex.org/I150229711","display_name":"University of Electronic Science and Technology of China","ror":"https://ror.org/04qr3zq92","country_code":"CN","type":"education","lineage":["https://openalex.org/I150229711"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Ji Guo","raw_affiliation_strings":["University of Electronic Science and Technology of China,School of Computer Science and Engineering,China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"University of Electronic Science and Technology of China,School of Computer Science and Engineering,China","institution_ids":["https://openalex.org/I150229711"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5100325334","display_name":"Hongwei Li","orcid":"https://orcid.org/0000-0002-1961-7946"},"institutions":[{"id":"https://openalex.org/I150229711","display_name":"University of Electronic Science and Technology of China","ror":"https://ror.org/04qr3zq92","country_code":"CN","type":"education","lineage":["https://openalex.org/I150229711"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Hongwei Li","raw_affiliation_strings":["University of Electronic Science and Technology of China,School of Computer Science and Engineering,China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"University of Electronic Science and Technology of China,School of Computer Science and Engineering,China","institution_ids":["https://openalex.org/I150229711"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":6,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.27243827,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"6"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10775","display_name":"Generative Adversarial Networks and Image Synthesis","score":0.7476000189781189,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10775","display_name":"Generative Adversarial Networks and Image Synthesis","score":0.7476000189781189,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.039400000125169754,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12377","display_name":"Digital Humanities and Scholarship","score":0.014600000344216824,"subfield":{"id":"https://openalex.org/subfields/1208","display_name":"Literature and Literary Theory"},"field":{"id":"https://openalex.org/fields/12","display_name":"Arts and Humanities"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/backdoor","display_name":"Backdoor","score":0.986299991607666},{"id":"https://openalex.org/keywords/security-token","display_name":"Security token","score":0.6949999928474426},{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.5848000049591064},{"id":"https://openalex.org/keywords/exploit","display_name":"Exploit","score":0.5498999953269958},{"id":"https://openalex.org/keywords/generative-grammar","display_name":"Generative grammar","score":0.5328999757766724},{"id":"https://openalex.org/keywords/embedding","display_name":"Embedding","score":0.47679999470710754}],"concepts":[{"id":"https://openalex.org/C2781045450","wikidata":"https://www.wikidata.org/wiki/Q254569","display_name":"Backdoor","level":2,"score":0.986299991607666},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7768999934196472},{"id":"https://openalex.org/C48145219","wikidata":"https://www.wikidata.org/wiki/Q1335365","display_name":"Security token","level":2,"score":0.6949999928474426},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.5848000049591064},{"id":"https://openalex.org/C165696696","wikidata":"https://www.wikidata.org/wiki/Q11287","display_name":"Exploit","level":2,"score":0.5498999953269958},{"id":"https://openalex.org/C39890363","wikidata":"https://www.wikidata.org/wiki/Q36108","display_name":"Generative grammar","level":2,"score":0.5328999757766724},{"id":"https://openalex.org/C41608201","wikidata":"https://www.wikidata.org/wiki/Q980509","display_name":"Embedding","level":2,"score":0.47679999470710754},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.46889999508857727},{"id":"https://openalex.org/C80444323","wikidata":"https://www.wikidata.org/wiki/Q2878974","display_name":"Theoretical computer science","level":1,"score":0.39989998936653137},{"id":"https://openalex.org/C188198153","wikidata":"https://www.wikidata.org/wiki/Q1613840","display_name":"Limiting","level":2,"score":0.3837999999523163},{"id":"https://openalex.org/C167966045","wikidata":"https://www.wikidata.org/wiki/Q5532625","display_name":"Generative model","level":3,"score":0.35409998893737793},{"id":"https://openalex.org/C73301696","wikidata":"https://www.wikidata.org/wiki/Q5469984","display_name":"Formalism (music)","level":3,"score":0.2939999997615814},{"id":"https://openalex.org/C51632099","wikidata":"https://www.wikidata.org/wiki/Q3985153","display_name":"Training set","level":2,"score":0.289900004863739},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.2757999897003174},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.2624000012874603},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.2590999901294708}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/icme59968.2025.11210084","is_oa":false,"landing_page_url":"https://doi.org/10.1109/icme59968.2025.11210084","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 IEEE International Conference on Multimedia and Expo (ICME)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"},{"id":"https://openalex.org/F4320336736","display_name":"Chengdu Science and Technology Program","ror":null}],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":16,"referenced_works":["https://openalex.org/W1861492603","https://openalex.org/W2024922353","https://openalex.org/W2951360122","https://openalex.org/W2969985801","https://openalex.org/W3096831136","https://openalex.org/W3109409894","https://openalex.org/W4312933868","https://openalex.org/W4319793479","https://openalex.org/W4387967988","https://openalex.org/W4388858734","https://openalex.org/W4390872151","https://openalex.org/W4393152558","https://openalex.org/W4394586040","https://openalex.org/W4408324270","https://openalex.org/W4409362356","https://openalex.org/W4413786017"],"related_works":[],"abstract_inverted_index":{"Text-to-image":[0,96],"generative":[1,40,76],"models":[2,31,41],"have":[3,27],"garnered":[4],"immense":[5],"attention":[6],"for":[7,70,127],"their":[8],"ability":[9],"to":[10,42,133,143,157],"produce":[11],"high-fidelity":[12],"images":[13,44],"from":[14,33],"text":[15,100,111],"prompts":[16],"and":[17,66,81,153,162],"enjoyed":[18],"great":[19],"popularity":[20],"among":[21],"the":[22,38,47,52,56,72,79,92,106,114,129,135,139,159],"community.":[23],"Unfortunately,":[24],"previous":[25],"studies":[26],"demonstrated":[28],"that":[29,45],"text-to-image":[30,115],"suffer":[32],"backdoor":[34,48,59,93,103],"attacks,":[35],"which":[36],"enforce":[37],"text-guided":[39],"generate":[43],"align":[46],"target":[49,131],"via":[50],"embedding":[51],"textual":[53],"triggers.":[54],"However,":[55],"currently":[57],"proposed":[58],"attacks":[60],"rely":[61],"on":[62,150],"numerous":[63],"training":[64],"data":[65],"complex":[67],"computing":[68],"resources":[69],"poisoning":[71],"core":[73],"components":[74],"in":[75,83,113,138],"models,":[77],"limiting":[78],"effectiveness":[80],"practicality":[82],"real-world":[84],"scenarios.":[85],"In":[86],"this":[87],"work,":[88],"we":[89],"first":[90],"investigate":[91],"attack":[94,104],"against":[95],"generation":[97],"by":[98],"manipulating":[99],"tokenizer.":[101],"Our":[102],"exploits":[105],"semantic":[107],"conditioning":[108],"role":[109],"of":[110,164],"tokenizer":[112],"generation.":[116],"We":[117,146],"propose":[118],"an":[119],"Automatized":[120],"Remapping":[121],"Framework":[122],"with":[123],"Optimized":[124],"Tokens":[125],"(AROT)":[126],"finding":[128],"best":[130],"tokens":[132],"remap":[134],"trigger":[136],"token":[137],"mapping":[140],"space,":[141],"according":[142],"different":[144],"tasks.":[145],"conduct":[147],"extensive":[148],"experiments":[149],"Stable":[151],"Diffusion":[152],"two":[154],"defined":[155],"tasks":[156],"demonstrate":[158],"effectiveness,":[160],"stealthiness":[161],"robustness":[163],"our":[165],"attack.":[166]},"counts_by_year":[],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-10-30T00:00:00"}
