{"id":"https://openalex.org/W4387967988","doi":"https://doi.org/10.1145/3581783.3612108","title":"Text-to-Image Diffusion Models can be Easily Backdoored through Multimodal Data Poisoning","display_name":"Text-to-Image Diffusion Models can be Easily Backdoored through Multimodal Data Poisoning","publication_year":2023,"publication_date":"2023-10-26","ids":{"openalex":"https://openalex.org/W4387967988","doi":"https://doi.org/10.1145/3581783.3612108"},"language":"en","primary_location":{"id":"doi:10.1145/3581783.3612108","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3581783.3612108","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 31st ACM International Conference on Multimedia","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5008450480","display_name":"Shengfang Zhai","orcid":"https://orcid.org/0000-0001-6820-6361"},"institutions":[{"id":"https://openalex.org/I20231570","display_name":"Peking University","ror":"https://ror.org/02v51f717","country_code":"CN","type":"education","lineage":["https://openalex.org/I20231570"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Shengfang Zhai","raw_affiliation_strings":["Peking University, Beijing, China"],"affiliations":[{"raw_affiliation_string":"Peking University, Beijing, China","institution_ids":["https://openalex.org/I20231570"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5068755794","display_name":"Yinpeng Dong","orcid":"https://orcid.org/0000-0003-1299-683X"},"institutions":[{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yinpeng Dong","raw_affiliation_strings":["Tsinghua University, Beijing, China"],"affiliations":[{"raw_affiliation_string":"Tsinghua University, Beijing, China","institution_ids":["https://openalex.org/I99065089"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5035938543","display_name":"Qingni Shen","orcid":"https://orcid.org/0000-0002-0605-6043"},"institutions":[{"id":"https://openalex.org/I20231570","display_name":"Peking University","ror":"https://ror.org/02v51f717","country_code":"CN","type":"education","lineage":["https://openalex.org/I20231570"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Qingni Shen","raw_affiliation_strings":["Peking University, Beijing, China"],"affiliations":[{"raw_affiliation_string":"Peking University, Beijing, China","institution_ids":["https://openalex.org/I20231570"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5060793037","display_name":"Shi Pu","orcid":"https://orcid.org/0000-0002-8748-8971"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Shi Pu","raw_affiliation_strings":["ShengShu, Beijing, China"],"affiliations":[{"raw_affiliation_string":"ShengShu, Beijing, China","institution_ids":[]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5088688674","display_name":"Yuejian Fang","orcid":null},"institutions":[{"id":"https://openalex.org/I20231570","display_name":"Peking University","ror":"https://ror.org/02v51f717","country_code":"CN","type":"education","lineage":["https://openalex.org/I20231570"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yuejian Fang","raw_affiliation_strings":["Peking University, Beijing, China"],"affiliations":[{"raw_affiliation_string":"Peking University, Beijing, China","institution_ids":["https://openalex.org/I20231570"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5100341885","display_name":"Hang Su","orcid":"https://orcid.org/0000-0001-8294-6315"},"institutions":[{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Hang Su","raw_affiliation_strings":["Tsinghua University, Beijing, China"],"affiliations":[{"raw_affiliation_string":"Tsinghua University, Beijing, China","institution_ids":["https://openalex.org/I99065089"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":6,"corresponding_author_ids":["https://openalex.org/A5008450480"],"corresponding_institution_ids":["https://openalex.org/I20231570"],"apc_list":null,"apc_paid":null,"fwci":4.2909,"has_fulltext":false,"cited_by_count":36,"citation_normalized_percentile":{"value":0.95758897,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":90,"max":100},"biblio":{"volume":null,"issue":null,"first_page":"1577","last_page":"1587"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10775","display_name":"Generative Adversarial Networks and Image Synthesis","score":0.9943000078201294,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10775","display_name":"Generative Adversarial Networks and Image Synthesis","score":0.9943000078201294,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9785000085830688,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11307","display_name":"Domain Adaptation and Few-Shot Learning","score":0.9656000137329102,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/backdoor","display_name":"Backdoor","score":0.9970270395278931},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7199438810348511},{"id":"https://openalex.org/keywords/image","display_name":"Image (mathematics)","score":0.6229972839355469},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.5078273415565491},{"id":"https://openalex.org/keywords/theoretical-computer-science","display_name":"Theoretical computer science","score":0.3585816025733948},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.24113476276397705}],"concepts":[{"id":"https://openalex.org/C2781045450","wikidata":"https://www.wikidata.org/wiki/Q254569","display_name":"Backdoor","level":2,"score":0.9970270395278931},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7199438810348511},{"id":"https://openalex.org/C115961682","wikidata":"https://www.wikidata.org/wiki/Q860623","display_name":"Image (mathematics)","level":2,"score":0.6229972839355469},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5078273415565491},{"id":"https://openalex.org/C80444323","wikidata":"https://www.wikidata.org/wiki/Q2878974","display_name":"Theoretical computer science","level":1,"score":0.3585816025733948},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.24113476276397705}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3581783.3612108","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3581783.3612108","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 31st ACM International Conference on Multimedia","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16","score":0.550000011920929}],"awards":[{"id":"https://openalex.org/G1121271761","display_name":null,"funder_award_id":"Program","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G2082826544","display_name":null,"funder_award_id":"Postdoctoral","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G2087396116","display_name":null,"funder_award_id":"China","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G6886452061","display_name":null,"funder_award_id":"62276149","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G7608752429","display_name":null,"funder_award_id":"Talent","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"}],"funders":[{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"},{"id":"https://openalex.org/F4320335768","display_name":"National Postdoctoral Program for Innovative Talents","ror":null}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":20,"referenced_works":["https://openalex.org/W1861492603","https://openalex.org/W2194775991","https://openalex.org/W2806082141","https://openalex.org/W2942091739","https://openalex.org/W2973217491","https://openalex.org/W3035367371","https://openalex.org/W3109409894","https://openalex.org/W3162926177","https://openalex.org/W3175133087","https://openalex.org/W3175215793","https://openalex.org/W3189812816","https://openalex.org/W3204619801","https://openalex.org/W3212213895","https://openalex.org/W4281485151","https://openalex.org/W4312740349","https://openalex.org/W4312933868","https://openalex.org/W4319300158","https://openalex.org/W4320736757","https://openalex.org/W6600018615","https://openalex.org/W6795288823"],"related_works":["https://openalex.org/W4391375266","https://openalex.org/W2748952813","https://openalex.org/W4320031223","https://openalex.org/W4200629851","https://openalex.org/W4281902577","https://openalex.org/W4309417370","https://openalex.org/W4292107232","https://openalex.org/W3009072493","https://openalex.org/W4386080799","https://openalex.org/W3140988292"],"abstract_inverted_index":{"With":[0],"the":[1,6,28,76,113,120,139,150,159,171,178],"help":[2],"of":[3,27,34,42,75,141,144,161,174],"conditioning":[4],"mechanisms,":[5],"state-of-the-art":[7],"diffusion":[8,47,97,116,122],"models":[9,48,176],"have":[10],"achieved":[11],"tremendous":[12],"success":[13],"in":[14,19,63,177],"guided":[15],"image":[16,61],"generation,":[17],"particularly":[18],"text-to-image":[20,35,46,96,115,175],"synthesis.":[21],"To":[22],"gain":[23],"a":[24,39,52,85,94,129],"better":[25],"understanding":[26],"training":[29],"process":[30],"and":[31,49,81],"potential":[32],"risks":[33],"synthesis,":[36],"we":[37,68],"perform":[38,69],"systematic":[40],"investigation":[41,167],"backdoor":[43,55,70,151,162],"attack":[44,56],"on":[45,72,110],"propose":[50],"BadT2I,":[51],"general":[53],"multimodal":[54],"framework":[57],"that":[58,119],"tampers":[59],"with":[60,103],"synthesis":[62],"diverse":[64],"semantic":[65],"levels.":[66],"Specifically,":[67],"attacks":[71],"three":[73],"levels":[74],"vision":[77],"semantics:":[78],"Pixel-Backdoor,":[79],"Object-Backdoor":[80],"Style-Backdoor.":[82],"By":[83],"utilizing":[84],"regularization":[86],"loss,":[87],"our":[88,166],"methods":[89],"efficiently":[90],"inject":[91],"backdoors":[92],"into":[93],"large-scale":[95,121],"model":[98,123],"while":[99],"preserving":[100],"its":[101],"utility":[102],"benign":[104],"inputs.":[105],"We":[106,133],"conduct":[107,134],"empirical":[108],"experiments":[109,136],"Stable":[111],"Diffusion,":[112],"widely-used":[114],"model,":[117],"demonstrating":[118],"can":[124],"be":[125],"easily":[126],"backdoored":[127],"within":[128],"few":[130],"fine-tuning":[131],"steps.":[132],"additional":[135],"to":[137,170],"explore":[138],"impact":[140],"different":[142],"types":[143],"textual":[145],"triggers,":[146],"as":[147,149],"well":[148],"persistence":[152],"during":[153],"further":[154],"training,":[155],"providing":[156],"insights":[157],"for":[158],"development":[160],"defense":[163],"methods.":[164],"Besides,":[165],"may":[168],"contribute":[169],"copyright":[172],"protection":[173],"future.":[179],"Our":[180],"Code:":[181],"https://github.com/sf-zhai/BadT2I.":[182]},"counts_by_year":[{"year":2026,"cited_by_count":2},{"year":2025,"cited_by_count":19},{"year":2024,"cited_by_count":14},{"year":2023,"cited_by_count":1}],"updated_date":"2026-04-13T07:58:08.660418","created_date":"2025-10-10T00:00:00"}
