{"id":"https://openalex.org/W4416975507","doi":"https://doi.org/10.48550/arxiv.2511.22119","title":"PROMPTMINER: Black-Box Prompt Stealing against Text-to-Image Generative Models via Reinforcement Learning and Fuzz Optimization","display_name":"PROMPTMINER: Black-Box Prompt Stealing against Text-to-Image Generative Models via Reinforcement Learning and Fuzz Optimization","publication_year":2025,"publication_date":"2025-11-27","ids":{"openalex":"https://openalex.org/W4416975507","doi":"https://doi.org/10.48550/arxiv.2511.22119"},"language":null,"primary_location":{"id":"pmh:oai:arXiv.org:2511.22119","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2511.22119","pdf_url":"https://arxiv.org/pdf/2511.22119","source":{"id":"https://openalex.org/S4393918464","display_name":"ArXiv.org","issn_l":"2331-8422","issn":["2331-8422"],"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},"type":"preprint","indexed_in":["arxiv","datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://arxiv.org/pdf/2511.22119","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5100775673","display_name":"Mingzhe Li","orcid":"https://orcid.org/0000-0002-0883-3678"},"institutions":[],"countries":[],"is_corresponding":true,"raw_author_name":"Li, Mingzhe","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5000667929","display_name":"Renhao Zhang","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Zhang, Renhao","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5020661044","display_name":"Zhoufutu Wen","orcid":"https://orcid.org/0009-0000-0894-5824"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Wen, Zhiyang","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5090153413","display_name":"Shaohua Pan","orcid":"https://orcid.org/0000-0002-6261-5268"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Pan, Siqi","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5034701757","display_name":"Bruno Castro da Silva","orcid":"https://orcid.org/0000-0002-3708-5728"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"da Silva, Bruno Castro","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5071575216","display_name":"Juan Zhai","orcid":"https://orcid.org/0000-0001-5017-8016"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Zhai, Juan","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5101594068","display_name":"Shiqing Ma","orcid":"https://orcid.org/0000-0003-1551-8948"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Ma, Shiqing","raw_affiliation_strings":[],"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":7,"corresponding_author_ids":["https://openalex.org/A5100775673"],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10775","display_name":"Generative Adversarial Networks and Image Synthesis","score":0.8432000279426575,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10775","display_name":"Generative Adversarial Networks and Image Synthesis","score":0.8432000279426575,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12357","display_name":"Digital Media Forensic Detection","score":0.03830000013113022,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12859","display_name":"Cell Image Analysis Techniques","score":0.022099999710917473,"subfield":{"id":"https://openalex.org/subfields/1304","display_name":"Biophysics"},"field":{"id":"https://openalex.org/fields/13","display_name":"Biochemistry, Genetics and Molecular Biology"},"domain":{"id":"https://openalex.org/domains/1","display_name":"Life Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/reinforcement-learning","display_name":"Reinforcement learning","score":0.710099995136261},{"id":"https://openalex.org/keywords/closed-captioning","display_name":"Closed captioning","score":0.5906999707221985},{"id":"https://openalex.org/keywords/task","display_name":"Task (project management)","score":0.5741999745368958},{"id":"https://openalex.org/keywords/key","display_name":"Key (lock)","score":0.5371000170707703},{"id":"https://openalex.org/keywords/generative-grammar","display_name":"Generative grammar","score":0.503600001335144},{"id":"https://openalex.org/keywords/reuse","display_name":"Reuse","score":0.4948999881744385},{"id":"https://openalex.org/keywords/fuzz-testing","display_name":"Fuzz testing","score":0.4447000026702881},{"id":"https://openalex.org/keywords/similarity","display_name":"Similarity (geometry)","score":0.41510000824928284},{"id":"https://openalex.org/keywords/baseline","display_name":"Baseline (sea)","score":0.4106000065803528}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8317999839782715},{"id":"https://openalex.org/C97541855","wikidata":"https://www.wikidata.org/wiki/Q830687","display_name":"Reinforcement learning","level":2,"score":0.710099995136261},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5983999967575073},{"id":"https://openalex.org/C157657479","wikidata":"https://www.wikidata.org/wiki/Q2367247","display_name":"Closed captioning","level":3,"score":0.5906999707221985},{"id":"https://openalex.org/C2780451532","wikidata":"https://www.wikidata.org/wiki/Q759676","display_name":"Task (project management)","level":2,"score":0.5741999745368958},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.5371000170707703},{"id":"https://openalex.org/C39890363","wikidata":"https://www.wikidata.org/wiki/Q36108","display_name":"Generative grammar","level":2,"score":0.503600001335144},{"id":"https://openalex.org/C206588197","wikidata":"https://www.wikidata.org/wiki/Q846574","display_name":"Reuse","level":2,"score":0.4948999881744385},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.44670000672340393},{"id":"https://openalex.org/C111065885","wikidata":"https://www.wikidata.org/wiki/Q1189053","display_name":"Fuzz testing","level":3,"score":0.4447000026702881},{"id":"https://openalex.org/C103278499","wikidata":"https://www.wikidata.org/wiki/Q254465","display_name":"Similarity (geometry)","level":3,"score":0.41510000824928284},{"id":"https://openalex.org/C12725497","wikidata":"https://www.wikidata.org/wiki/Q810247","display_name":"Baseline (sea)","level":2,"score":0.4106000065803528},{"id":"https://openalex.org/C167966045","wikidata":"https://www.wikidata.org/wiki/Q5532625","display_name":"Generative model","level":3,"score":0.3984000086784363},{"id":"https://openalex.org/C43214815","wikidata":"https://www.wikidata.org/wiki/Q7310987","display_name":"Reliability (semiconductor)","level":3,"score":0.3700999915599823},{"id":"https://openalex.org/C2779478453","wikidata":"https://www.wikidata.org/wiki/Q6889748","display_name":"Modularity (biology)","level":2,"score":0.30880001187324524},{"id":"https://openalex.org/C185798385","wikidata":"https://www.wikidata.org/wiki/Q1161707","display_name":"Benchmark (surveying)","level":2,"score":0.3001999855041504},{"id":"https://openalex.org/C112972136","wikidata":"https://www.wikidata.org/wiki/Q7595718","display_name":"Stability (learning theory)","level":2,"score":0.28859999775886536},{"id":"https://openalex.org/C2779530757","wikidata":"https://www.wikidata.org/wiki/Q1207505","display_name":"Quality (philosophy)","level":2,"score":0.288100004196167},{"id":"https://openalex.org/C175154964","wikidata":"https://www.wikidata.org/wiki/Q380077","display_name":"Task analysis","level":3,"score":0.2822999954223633},{"id":"https://openalex.org/C2776214188","wikidata":"https://www.wikidata.org/wiki/Q408386","display_name":"Inference","level":2,"score":0.27630001306533813},{"id":"https://openalex.org/C188198153","wikidata":"https://www.wikidata.org/wiki/Q1613840","display_name":"Limiting","level":2,"score":0.27059999108314514},{"id":"https://openalex.org/C168167062","wikidata":"https://www.wikidata.org/wiki/Q1117970","display_name":"Component (thermodynamics)","level":2,"score":0.2678000032901764},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.2623000144958496},{"id":"https://openalex.org/C75291252","wikidata":"https://www.wikidata.org/wiki/Q1315756","display_name":"TRACE (psycholinguistics)","level":2,"score":0.2590000033378601},{"id":"https://openalex.org/C115961682","wikidata":"https://www.wikidata.org/wiki/Q860623","display_name":"Image (mathematics)","level":2,"score":0.25870001316070557},{"id":"https://openalex.org/C2776674983","wikidata":"https://www.wikidata.org/wiki/Q545981","display_name":"Image editing","level":3,"score":0.25780001282691956},{"id":"https://openalex.org/C189950617","wikidata":"https://www.wikidata.org/wiki/Q937228","display_name":"Property (philosophy)","level":2,"score":0.25369998812675476}],"mesh":[],"locations_count":2,"locations":[{"id":"pmh:oai:arXiv.org:2511.22119","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2511.22119","pdf_url":"https://arxiv.org/pdf/2511.22119","source":{"id":"https://openalex.org/S4393918464","display_name":"ArXiv.org","issn_l":"2331-8422","issn":["2331-8422"],"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},{"id":"doi:10.48550/arxiv.2511.22119","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2511.22119","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"pmh:oai:arXiv.org:2511.22119","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2511.22119","pdf_url":"https://arxiv.org/pdf/2511.22119","source":{"id":"https://openalex.org/S4393918464","display_name":"ArXiv.org","issn_l":"2331-8422","issn":["2331-8422"],"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"Text-to-image":[0],"(T2I)":[1],"generative":[2],"models":[3],"such":[4,96],"as":[5,97],"Stable":[6],"Diffusion":[7],"and":[8,32,45,54,83,103,131,163,177,192],"FLUX":[9],"can":[10,91],"synthesize":[11],"realistic,":[12],"high-quality":[13,48],"images":[14,208],"directly":[15],"from":[16],"textual":[17,71,193],"prompts.":[18],"The":[19],"resulting":[20],"image":[21],"quality":[22],"depends":[23],"critically":[24],"on":[25,123],"well-crafted":[26],"prompts":[27,49],"that":[28,73,145,181],"specify":[29],"both":[30],"subjects":[31],"stylistic":[33,171],"modifiers,":[34],"which":[35],"have":[36],"become":[37],"valuable":[38],"digital":[39],"assets.":[40],"However,":[41],"the":[42,61,66,70,147,160,214],"rising":[43],"value":[44],"ubiquity":[46],"of":[47,68,85],"expose":[50],"them":[51],"to":[52,158,169,190,198,206],"security":[53],"intellectual-property":[55],"risks.":[56],"One":[57],"key":[58],"threat":[59],"is":[60],"prompt":[62,72,142],"stealing":[63,79,143],"attack,":[64],"i.e.,":[65],"task":[67,148],"recovering":[69],"generated":[74],"a":[75,140,153,165],"given":[76],"image.":[77],"Prompt":[78],"enables":[80],"unauthorized":[81],"extraction":[82],"reuse":[84],"carefully":[86],"engineered":[87],"prompts,":[88],"yet":[89],"it":[90,212],"also":[92],"support":[93],"beneficial":[94],"applications":[95],"data":[98],"attribution,":[99],"model":[100],"provenance":[101],"analysis,":[102],"watermarking":[104],"validation.":[105],"Existing":[106],"approaches":[107],"often":[108],"assume":[109],"white-box":[110],"gradient":[111],"access,":[112],"require":[113],"large-scale":[114],"labeled":[115],"datasets":[116,176],"for":[117],"supervised":[118],"training,":[119],"or":[120],"rely":[121],"solely":[122],"captioning":[124],"without":[125],"explicit":[126],"optimization,":[127],"limiting":[128],"their":[129],"practicality":[130],"adaptability.":[132],"To":[133],"address":[134],"these":[135],"challenges,":[136],"we":[137],"propose":[138],"PROMPTMINER,":[139],"black-box":[141],"framework":[144],"decouples":[146],"into":[149],"two":[150],"phases:":[151],"(1)":[152],"reinforcement":[154],"learning-based":[155],"optimization":[156],"phase":[157,168],"reconstruct":[159],"primary":[161],"subject,":[162],"(2)":[164],"fuzzing-driven":[166],"search":[167],"recover":[170],"modifiers.":[172],"Experiments":[173],"across":[174],"multiple":[175],"diffusion":[178],"backbones":[179],"demonstrate":[180],"PROMPTMINER":[182,227],"achieves":[183],"superior":[184],"results,":[185],"with":[186,195,209],"CLIP":[187,221],"similarity":[188],"up":[189,197],"0.958":[191],"alignment":[194],"SBERT":[196],"0.751,":[199],"surpassing":[200],"all":[201],"baselines.":[202],"Even":[203],"when":[204],"applied":[205],"in-the-wild":[207],"unknown":[210],"generators,":[211],"outperforms":[213],"strongest":[215],"baseline":[216],"by":[217],"7.5":[218],"percent":[219],"in":[220],"similarity,":[222],"demonstrating":[223],"better":[224],"generalization.":[225],"Finally,":[226],"maintains":[228],"strong":[229],"performance":[230],"under":[231],"defensive":[232],"perturbations,":[233],"highlighting":[234],"remarkable":[235],"robustness.":[236],"Code:":[237],"https://github.com/aaFrostnova/PromptMiner":[238]},"counts_by_year":[],"updated_date":"2026-03-07T16:01:11.037858","created_date":"2025-12-03T00:00:00"}
