{"id":"https://openalex.org/W7162680958","doi":"https://doi.org/10.48550/arxiv.2605.28137","title":"No Safe Dose: How Training Data Drives Unsafe Image Generation","display_name":"No Safe Dose: How Training Data Drives Unsafe Image Generation","publication_year":2026,"publication_date":"2026-05-27","ids":{"openalex":"https://openalex.org/W7162680958","doi":"https://doi.org/10.48550/arxiv.2605.28137"},"language":null,"primary_location":{"id":"doi:10.48550/arxiv.2605.28137","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2605.28137","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"type":"preprint","indexed_in":["datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://doi.org/10.48550/arxiv.2605.28137","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5137297426","display_name":"Felix Friedrich","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Friedrich, Felix","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5092171975","display_name":"Lukas Helff","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Helff, Lukas","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5083164738","display_name":"Niharika Hegde","orcid":"https://orcid.org/0000-0001-7807-987X"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Hegde, Niharika","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5137284694","display_name":"Patrick Schramowski","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Schramowski, Patrick","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5137203113","display_name":"Kristian Kersting","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Kersting, Kristian","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":5,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T12859","display_name":"Cell Image Analysis Techniques","score":0.2282000035047531,"subfield":{"id":"https://openalex.org/subfields/1304","display_name":"Biophysics"},"field":{"id":"https://openalex.org/fields/13","display_name":"Biochemistry, Genetics and Molecular Biology"},"domain":{"id":"https://openalex.org/domains/1","display_name":"Life Sciences"}},"topics":[{"id":"https://openalex.org/T12859","display_name":"Cell Image Analysis Techniques","score":0.2282000035047531,"subfield":{"id":"https://openalex.org/subfields/1304","display_name":"Biophysics"},"field":{"id":"https://openalex.org/fields/13","display_name":"Biochemistry, Genetics and Molecular Biology"},"domain":{"id":"https://openalex.org/domains/1","display_name":"Life Sciences"}},{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.1671999990940094,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10775","display_name":"Generative Adversarial Networks and Image Synthesis","score":0.155799999833107,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/encoder","display_name":"Encoder","score":0.6462000012397766},{"id":"https://openalex.org/keywords/residual","display_name":"Residual","score":0.5113999843597412},{"id":"https://openalex.org/keywords/training","display_name":"Training (meteorology)","score":0.5073999762535095},{"id":"https://openalex.org/keywords/baseline","display_name":"Baseline (sea)","score":0.45750001072883606},{"id":"https://openalex.org/keywords/quality","display_name":"Quality (philosophy)","score":0.45570001006126404},{"id":"https://openalex.org/keywords/degradation","display_name":"Degradation (telecommunications)","score":0.4449000060558319},{"id":"https://openalex.org/keywords/training-set","display_name":"Training set","score":0.4388999938964844},{"id":"https://openalex.org/keywords/encoding","display_name":"Encoding (memory)","score":0.42419999837875366}],"concepts":[{"id":"https://openalex.org/C118505674","wikidata":"https://www.wikidata.org/wiki/Q42586063","display_name":"Encoder","level":2,"score":0.6462000012397766},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6176000237464905},{"id":"https://openalex.org/C155512373","wikidata":"https://www.wikidata.org/wiki/Q287450","display_name":"Residual","level":2,"score":0.5113999843597412},{"id":"https://openalex.org/C2777211547","wikidata":"https://www.wikidata.org/wiki/Q17141490","display_name":"Training (meteorology)","level":2,"score":0.5073999762535095},{"id":"https://openalex.org/C12725497","wikidata":"https://www.wikidata.org/wiki/Q810247","display_name":"Baseline (sea)","level":2,"score":0.45750001072883606},{"id":"https://openalex.org/C2779530757","wikidata":"https://www.wikidata.org/wiki/Q1207505","display_name":"Quality (philosophy)","level":2,"score":0.45570001006126404},{"id":"https://openalex.org/C2779679103","wikidata":"https://www.wikidata.org/wiki/Q5251805","display_name":"Degradation (telecommunications)","level":2,"score":0.4449000060558319},{"id":"https://openalex.org/C51632099","wikidata":"https://www.wikidata.org/wiki/Q3985153","display_name":"Training set","level":2,"score":0.4388999938964844},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.4260999858379364},{"id":"https://openalex.org/C125411270","wikidata":"https://www.wikidata.org/wiki/Q18653","display_name":"Encoding (memory)","level":2,"score":0.42419999837875366},{"id":"https://openalex.org/C115961682","wikidata":"https://www.wikidata.org/wiki/Q860623","display_name":"Image (mathematics)","level":2,"score":0.3804999887943268},{"id":"https://openalex.org/C24756922","wikidata":"https://www.wikidata.org/wiki/Q1757694","display_name":"Data quality","level":3,"score":0.3582000136375427},{"id":"https://openalex.org/C149629883","wikidata":"https://www.wikidata.org/wiki/Q660926","display_name":"Fraction (chemistry)","level":2,"score":0.33899998664855957},{"id":"https://openalex.org/C31972630","wikidata":"https://www.wikidata.org/wiki/Q844240","display_name":"Computer vision","level":1,"score":0.33329999446868896},{"id":"https://openalex.org/C2780945871","wikidata":"https://www.wikidata.org/wiki/Q194274","display_name":"Backup","level":2,"score":0.3327000141143799},{"id":"https://openalex.org/C2776035688","wikidata":"https://www.wikidata.org/wiki/Q1606558","display_name":"Affect (linguistics)","level":2,"score":0.3301999866962433},{"id":"https://openalex.org/C168167062","wikidata":"https://www.wikidata.org/wiki/Q1117970","display_name":"Component (thermodynamics)","level":2,"score":0.3138999938964844},{"id":"https://openalex.org/C200601418","wikidata":"https://www.wikidata.org/wiki/Q2193887","display_name":"Reliability engineering","level":1,"score":0.3125},{"id":"https://openalex.org/C2779662365","wikidata":"https://www.wikidata.org/wiki/Q5416694","display_name":"Event (particle physics)","level":2,"score":0.2953000068664551},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.2892000079154968},{"id":"https://openalex.org/C55020928","wikidata":"https://www.wikidata.org/wiki/Q3813865","display_name":"Image quality","level":3,"score":0.28619998693466187},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.27160000801086426},{"id":"https://openalex.org/C79403827","wikidata":"https://www.wikidata.org/wiki/Q3988","display_name":"Real-time computing","level":1,"score":0.2565999925136566}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.48550/arxiv.2605.28137","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2605.28137","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"doi:10.48550/arxiv.2605.28137","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2605.28137","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"Text-to-image":[0],"models":[1],"trained":[2],"on":[3,38,51],"large-scale":[4],"data":[5,24,183],"often":[6],"inevitably":[7],"ingest":[8],"unsafe":[9,60,113],"content.":[10],"While":[11],"some":[12],"people":[13],"observe":[14],"input-output":[15],"amplifications,":[16],"it":[17],"remains":[18],"unclear":[19],"whether":[20],"and":[21,80,174,185,191,212],"how":[22],"training":[23,114],"composition":[25],"directly":[26],"drives":[27],"model":[28,50],"output":[29],"safety":[30,86,138,177,188],"or":[31],"by":[32,41,142],"other":[33,129],"factors.":[34],"We":[35],"shed":[36],"light":[37],"this":[39,43,151],"question":[40],"isolating":[42],"variable:":[44],"we":[45,73],"train":[46],"the":[47,77,106,109,117,128,156,196,199],"same":[48,197],"text-to-image":[49],"datasets":[52],"that":[53,105,148,182],"differ":[54],"\\emph{only}":[55],"in":[56,169],"their":[57],"fraction":[58],"of":[59,112,171,202],"images":[61,75,115],"(0\\%":[62],"to":[63,70,97,153],"9.6\\%),":[64],"across":[65,160],"several":[66],"dataset":[67],"scales":[68],"(100K":[69],"8M).":[71],"Then":[72],"generate":[74],"with":[76,83],"resulting":[78],"models,":[79],"evaluate":[81],"them":[82],"four":[84],"independent":[85],"classifiers.":[87],"Output":[88],"unsafety":[89,203],"rises":[90],"monotonically":[91],"from":[92],"16.6\\%":[93,121],"at":[94,99,124],"0\\%":[95],"contamination":[96,126],"25.5\\%":[98],"5\\%.":[100],"A":[101],"factorial":[102],"design":[103],"reveals":[104],"\\emph{proportion},":[107],"not":[108],"absolute":[110],"count,":[111],"is":[116],"operative":[118],"variable.":[119],"The":[120],"irreducible":[122],"baseline":[123],"zero":[125],"implicates":[127],"components,":[130],"e.g.":[131],"frozen":[132],"text":[133,144,186],"encoder,":[134],"as":[135],"a":[136,143],"residual":[137],"risk":[139],"--":[140],"confirmed":[141],"encoder":[145,187],"ablation":[146],"showing":[147],"SafeCLIP":[149],"reduces":[150],"floor":[152],"9.6\\%,":[154],"while":[155],"dose-response":[157],"effect":[158],"persists":[159],"all":[161],"three":[162],"encoders":[163],"tested.":[164],"Critically,":[165],"no":[166],"quality":[167],"degradation":[168],"terms":[170],"FID,":[172],"CLIPscore":[173],"ImageReward":[175],"accompanies":[176],"filtering.":[178],"These":[179],"results":[180],"establish":[181],"curation":[184],"are":[189],"complementary":[190],"independently":[192],"effective":[193],"interventions.":[194],"At":[195],"time,":[198],"remaining":[200],"level":[201],"poses":[204],"questions":[205],"for":[206],"future":[207],"research":[208],"about":[209],"emerging":[210],"capabilities":[211],"compositionality.":[213]},"counts_by_year":[],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2026-05-29T00:00:00"}
