Skip to main navigation Skip to search Skip to main content

Diff-Cleanse: Identifying and Mitigating Backdoor Attacks in Diffusion Models

  • Beihang University
  • National Key Laboratory of Complex System Control and Intelligent Agent Cooperation

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Diffusion models (DMs) are advanced generative models, yet recent research reveals their vulnerability to backdoor attacks, which establish hidden associations between input patterns and targeted model behavior, potentially causing malicious outputs during inference. These attacks pose significant risks, including model owner reputation damage and harmful content generation. However, existing defense methods often fail against backdoor attacks on diffusion models. To address this gap, we propose Diff-Cleanse, a two-stage defense framework. The first stage introduces a novel trigger inversion method for backdoor detection, and the second stage applies a structural pruning-based method for backdoor removal. Experiments on 373 models poisoned by three state-of-the-art attacks show that Diff-Cleanse achieves > 97% detection accuracy, completely remove backdoors and maintains the models' benign performance. Code is available at https://github.com/shymuel/diff-cleanse.

Original languageEnglish
Title of host publication2025 IEEE International Conference on Multimedia and Expo
Subtitle of host publicationJourney to the Center of Machine Imagination, ICME 2025 - Conference Proceedings
PublisherIEEE Computer Society
ISBN (Electronic)9798331594954
DOIs
StatePublished - 2025
Event2025 IEEE International Conference on Multimedia and Expo, ICME 2025 - Nantes, France
Duration: 30 Jun 20254 Jul 2025

Publication series

NameProceedings - IEEE International Conference on Multimedia and Expo
ISSN (Print)1945-7871
ISSN (Electronic)1945-788X

Conference

Conference2025 IEEE International Conference on Multimedia and Expo, ICME 2025
Country/TerritoryFrance
CityNantes
Period30/06/254/07/25

Keywords

  • backdoor defense
  • diffusion model security
  • structural pruning
  • trigger inversion

Fingerprint

Dive into the research topics of 'Diff-Cleanse: Identifying and Mitigating Backdoor Attacks in Diffusion Models'. Together they form a unique fingerprint.

Cite this