{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,23]],"date-time":"2026-07-23T03:28:07Z","timestamp":1784777287391,"version":"3.55.0"},"publisher-location":"Cham","reference-count":70,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031729973","type":"print"},{"value":"9783031729980","type":"electronic"}],"license":[{"start":{"date-parts":[[2024,9,30]],"date-time":"2024-09-30T00:00:00Z","timestamp":1727654400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,9,30]],"date-time":"2024-09-30T00:00:00Z","timestamp":1727654400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025]]},"DOI":"10.1007\/978-3-031-72998-0_22","type":"book-chapter","created":{"date-parts":[[2024,9,29]],"date-time":"2024-09-29T18:01:58Z","timestamp":1727632918000},"page":"385-403","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":49,"title":["To Generate or\u00a0Not? Safety-Driven Unlearned Diffusion Models Are Still Easy to\u00a0Generate Unsafe Images ... For Now"],"prefix":"10.1007","author":[{"given":"Yimeng","family":"Zhang","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jinghan","family":"Jia","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xin","family":"Chen","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Aochuan","family":"Chen","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yihua","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jiancheng","family":"Liu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ke","family":"Ding","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Sijia","family":"Liu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2024,9,30]]},"reference":[{"key":"22_CR1","first-page":"6840","volume":"33","author":"J Ho","year":"2020","unstructured":"Ho, J., Jain, A., Abbeel, P.: Denoising diffusion probabilistic models. Adv. Neural. Inf. Process. Syst. 33, 6840\u20136851 (2020)","journal-title":"Adv. Neural. Inf. Process. Syst."},{"key":"22_CR2","unstructured":"Song, Y., Ermon, S.: Generative modeling by estimating gradients of the data distribution. In: Advances in Neural Information Processing Systems, vol. 32 (2019)"},{"key":"22_CR3","unstructured":"Song, Y., Sohl-Dickstein, J., Kingma, D.P., Kumar, A., Ermon, S., Poole, B.: Score-based generative modeling through stochastic differential equations. arXiv preprint arXiv:2011.13456 (2020)"},{"key":"22_CR4","unstructured":"Dhariwal, P., Nichol, A.: Diffusion models beat GANs on image synthesis. In: Advance in Neural Information Processing System, vol. 34, pp. 8780\u20138794 (2021)"},{"key":"22_CR5","unstructured":"Nichol, A.Q., Dhariwal, P.: Improved denoising diffusion probabilistic models. In: International Conference on Machine Learning, pp. 8162\u20138171. PMLR (2021)"},{"key":"22_CR6","unstructured":"Watson, D., Chan, W., Ho, J., Norouzi, M.: Learning fast samplers for diffusion models by differentiating through sample quality. In: International Conference on Learning Representations (2021)"},{"key":"22_CR7","doi-asserted-by":"crossref","unstructured":"Rombach, R., Blattmann, A., Lorenz, D., Esser, P., Ommer, B.: High-resolution image synthesis with latent diffusion models. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp. 10684\u201310695 (2022)","DOI":"10.1109\/CVPR52688.2022.01042"},{"key":"22_CR8","doi-asserted-by":"crossref","unstructured":"Croitoru, F.A., Hondru, V., Ionescu, R.T., Shah, M.: Diffusion models in vision: a survey. IEEE Trans. Pattern Anal. Mach. Intell. (2023)","DOI":"10.1109\/TPAMI.2023.3261988"},{"key":"22_CR9","unstructured":"Rando, J., Paleka, D., Lindner, D., Heim, L., Tram\u00e8r, F.: Red-teaming the stable diffusion safety filter. arXiv preprint arXiv:2210.04610 (2022)"},{"key":"22_CR10","doi-asserted-by":"crossref","unstructured":"Schramowski, P., Brack, M., Deiseroth, B., Kersting, K.: Safe latent diffusion: mitigating inappropriate degeneration in diffusion models (2023)","DOI":"10.1109\/CVPR52729.2023.02157"},{"key":"22_CR11","unstructured":"Nichol, A., et al.: Glide: towards photorealistic image generation and editing with text-guided diffusion models. arXiv preprint arXiv:2112.10741 (2021)"},{"key":"22_CR12","doi-asserted-by":"crossref","unstructured":"Gandikota, R., Materzynska, J., Fiotto-Kaufman, J., Bau, D.: Erasing concepts from diffusion models. arXiv preprint arXiv:2303.07345 (2023)","DOI":"10.1109\/ICCV51070.2023.00230"},{"key":"22_CR13","unstructured":"Brack, M., Friedrich, F., Schramowski, P., Kersting, K.: Mitigating inappropriateness in image generation: Can there be value in reflecting the world\u2019s ugliness? arXiv preprint arXiv:2305.18398 (2023)"},{"key":"22_CR14","unstructured":"Yang, Y., Hui, B., Yuan, H., Gong, N., Cao, Y.: Sneakyprompt: Evaluating robustness of text-to-image generative models\u2019 safety filters. arXiv preprint arXiv:2305.12082 (2023)"},{"key":"22_CR15","doi-asserted-by":"crossref","unstructured":"Zhang, E., Wang, K., Xu, X., Wang, Z., Shi, H.: Forget-me-not: learning to forget in text-to-image diffusion models. arXiv preprint arXiv:2303.17591 (2023)","DOI":"10.1109\/CVPRW63382.2024.00182"},{"key":"22_CR16","doi-asserted-by":"crossref","unstructured":"Kumari, N., Zhang, B., Wang, S.Y., Shechtman, E., Zhang, R., Zhu, J.Y.: Ablating concepts in text-to-image diffusion models (2023)","DOI":"10.1109\/ICCV51070.2023.02074"},{"key":"22_CR17","doi-asserted-by":"crossref","unstructured":"Gandikota, R., Orgad, H., Belinkov, Y., Materzy\u0144ska, J., Bau, D.: Unified concept editing in diffusion models. arXiv preprint arXiv:2308.14761 (2023)","DOI":"10.1109\/ICCV51070.2023.00230"},{"key":"22_CR18","unstructured":"Nguyen, T.T., Huynh, T.T., Nguyen, P.L., Liew, A.W.C., Yin, H., Nguyen, Q.V.H.: A survey of machine unlearning. arXiv preprint arXiv:2209.02299 (2022)"},{"key":"22_CR19","doi-asserted-by":"crossref","unstructured":"Shaik, T., Tao, X., Xie, H., Li, L., Zhu, X., Li, Q.: Exploring the landscape of machine unlearning: a survey and taxonomy. arXiv preprint arXiv:2305.06360 (2023)","DOI":"10.1109\/TNNLS.2024.3486109"},{"key":"22_CR20","doi-asserted-by":"crossref","unstructured":"Cao, Y., Yang, J.: Towards making systems forget with machine unlearning. In: 2015 IEEE Symposium on Security and Privacy, pp. 463\u2013480. IEEE (2015)","DOI":"10.1109\/SP.2015.35"},{"key":"22_CR21","doi-asserted-by":"crossref","unstructured":"Thudi, A., Deza, G., Chandrasekaran, V., Papernot, N.: Unrolling SGD: understanding factors influencing machine unlearning. In: 2022 IEEE 7th European Symposium on Security and Privacy (EuroS &P), pp. 303\u2013319. IEEE (2022)","DOI":"10.1109\/EuroSP53844.2022.00027"},{"issue":"1","key":"22_CR22","first-page":"1","volume":"56","author":"H Xu","year":"2023","unstructured":"Xu, H., Zhu, T., Zhang, L., Zhou, W., Yu, P.S.: Machine unlearning: a survey. ACM Comput. Surv. 56(1), 1\u201336 (2023)","journal-title":"ACM Comput. Surv."},{"key":"22_CR23","unstructured":"Jia, J., et al.: Model sparsity can simplify machine unlearning (2023)"},{"key":"22_CR24","unstructured":"Zhang, Y., et al.: Unlearncanvas: a stylized image dataset to benchmark machine unlearning for diffusion models. arXiv preprint arXiv:2402.11846 (2024)"},{"key":"22_CR25","doi-asserted-by":"crossref","unstructured":"Jia, J., et al.: Soul: unlocking the power of second-order optimization for LLM unlearning. arXiv preprint arXiv:2404.18239 (2024)","DOI":"10.18653\/v1\/2024.emnlp-main.245"},{"key":"22_CR26","unstructured":"Goodfellow, I.J., Shlens, J., Szegedy, C.: Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572 (2014)"},{"key":"22_CR27","doi-asserted-by":"crossref","unstructured":"Carlini, N., Wagner, D.: Towards evaluating the robustness of neural networks. In: 2017 IEEE Symposium on Security and Privacy (SP), pp. 39\u201357. IEEE (2017)","DOI":"10.1109\/SP.2017.49"},{"key":"22_CR28","unstructured":"Maus, N., Chao, P., Wong, E., Gardner, J.R.: Black box adversarial prompting for foundation models. In: The Second Workshop on New Frontiers in Adversarial Machine Learning (2023)"},{"key":"22_CR29","doi-asserted-by":"crossref","unstructured":"Zhuang, H., Zhang, Y., Liu, S.: A pilot study of query-free adversarial attack against stable diffusion. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp. 2384\u20132391 (2023)","DOI":"10.1109\/CVPRW59228.2023.00236"},{"key":"22_CR30","unstructured":"Wen, Y., Jain, N., Kirchenbauer, J., Goldblum, M., Geiping, J., Goldstein, T.: Hard prompts made easy: gradient-based discrete optimization for prompt tuning and discovery. arXiv preprint arXiv:2302.03668 (2023)"},{"key":"22_CR31","unstructured":"Chin, Z.Y., Jiang, C.M., Huang, C.C., Chen, P.Y., Chiu, W.C.: Prompting4debugging: red-teaming text-to-image diffusion models by finding problematic prompts. arXiv preprint arXiv:2309.06135 (2023)"},{"key":"22_CR32","unstructured":"Birhane, A., Prabhu, V.U., Kahembwe, E.: Multimodal datasets: misogyny, pornography, and malignant stereotypes. arXiv preprint arXiv:2110.01963 (2021)"},{"key":"22_CR33","doi-asserted-by":"crossref","unstructured":"Somepalli, G., Singla, V., Goldblum, M., Geiping, J., Goldstein, T.: Diffusion art or digital forgery? investigating data replication in diffusion models. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp. 6048\u20136058 (2023)","DOI":"10.1109\/CVPR52729.2023.00586"},{"key":"22_CR34","unstructured":"Schuhmann, C., et al.: Laion-5b: an open large-scale dataset for training next generation image-text models. In: Advance in Neural Information Processing System, vol. 35, pp. 25278\u201325294 (2022)"},{"key":"22_CR35","doi-asserted-by":"crossref","unstructured":"Kumari, N., Zhang, B., Wang, S.Y., Shechtman, E., Zhang, R., Zhu, J.Y.: Ablating concepts in text-to-image diffusion models. In: ICCV (2023)","DOI":"10.1109\/ICCV51070.2023.02074"},{"key":"22_CR36","unstructured":"Heng, A., Soh, H.: Selective amnesia: a continual learning approach to forgetting in deep generative models. arXiv preprint arXiv:2305.10120 (2023)"},{"key":"22_CR37","doi-asserted-by":"crossref","unstructured":"Ni, Z., Wei, L., Li, J., Tang, S., Zhuang, Y., Tian, Q.: Degeneration-tuning: using scrambled grid shield unwanted concepts from stable diffusion. arXiv preprint arXiv:2308.02552 (2023)","DOI":"10.1145\/3581783.3611867"},{"key":"22_CR38","unstructured":"Zhang, Y., et al.: Defensive unlearning with adversarial training for robust concept erasure in diffusion models. arXiv preprint arXiv:2405.15234 (2024)"},{"key":"22_CR39","doi-asserted-by":"crossref","unstructured":"Papernot, N., McDaniel, P., Jha, S., Fredrikson, M., Celik, Z.B., Swami, A.: The limitations of deep learning in adversarial settings. In: Security and Privacy (EuroS &P), 2016 IEEE European Symposium on, pp. 372\u2013387. IEEE (2016)","DOI":"10.1109\/EuroSP.2016.36"},{"key":"22_CR40","unstructured":"Brown, T.B., Man\u00e9, D., Roy, A., Abadi, M., Gilmer, J.: Adversarial patch. arXiv preprint arXiv:1712.09665 (2017)"},{"key":"22_CR41","unstructured":"Li, J., Schmidt, F., Kolter, Z.: Adversarial camera stickers: a physical camera-based attack on deep learning systems. In: International Conference on Machine Learning, pp. 3896\u20133904 (2019)"},{"key":"22_CR42","unstructured":"Xu, K., et al., Lin, X.: Structured adversarial attack: towards general implementation and better interpretability. In: ICLR (2019)"},{"key":"22_CR43","doi-asserted-by":"crossref","unstructured":"Yuan, Z., Zhang, J., Jia, Y., Tan, C., Xue, T., Shan, S.: Meta gradient adversarial attack. In: Proceedings of the IEEE\/CVF International Conference on Computer Vision, pp. 7748\u20137757 (2021)","DOI":"10.1109\/ICCV48922.2021.00765"},{"key":"22_CR44","unstructured":"Zhang, Y., Yao, Y., Jia, J., Yi, J., Hong, M., Chang, S., Liu, S.: How to robustify black-box ml models? a zeroth-order optimization perspective. arXiv preprint arXiv:2203.14195 (2022)"},{"key":"22_CR45","unstructured":"Chen, A., et al.: Deepzero: scaling up zeroth-order optimization for deep model training. arXiv preprint arXiv:2310.02025 (2023)"},{"key":"22_CR46","unstructured":"Gong, Y., et al.: Reverse engineering of imperceptible adversarial image perturbations. arXiv preprint arXiv:2203.14145 (2022)"},{"key":"22_CR47","doi-asserted-by":"publisher","first-page":"278","DOI":"10.1016\/j.neucom.2022.04.020","volume":"492","author":"S Qiu","year":"2022","unstructured":"Qiu, S., Liu, Q., Zhou, S., Huang, W.: Adversarial attack and defense technologies in natural language processing: a survey. Neurocomputing 492, 278\u2013307 (2022)","journal-title":"Neurocomputing"},{"key":"22_CR48","doi-asserted-by":"crossref","unstructured":"Eger, S., Benz, Y.: From hero to z\u00e9roe: a benchmark of low-level adversarial attacks. In: Proceedings of the 1st Conference of the Asia-Pacific Chapter of the Association for Computational Linguistics and the 10th International Joint Conference on Natural Language Processing, pp. 786\u2013803 (2020)","DOI":"10.18653\/v1\/2020.aacl-main.79"},{"key":"22_CR49","doi-asserted-by":"crossref","unstructured":"Liu, A., et al.: Character-level white-box adversarial attacks against transformers via attachable subwords substitution. arXiv preprint arXiv:2210.17004 (2022)","DOI":"10.18653\/v1\/2022.emnlp-main.522"},{"key":"22_CR50","unstructured":"Hou, B., et al.: TextGrad: advancing robustness evaluation in NLP by gradient-driven optimization. arXiv preprint arXiv:2212.09254 (2022)"},{"key":"22_CR51","doi-asserted-by":"crossref","unstructured":"Li, J., Ji, S., Du, T., Li, B., Wang, T.: TextBugger: generating adversarial text against real-world applications. arXiv preprint arXiv:1812.05271 (2018)","DOI":"10.14722\/ndss.2019.23138"},{"key":"22_CR52","doi-asserted-by":"crossref","unstructured":"Alzantot, M., Sharma, Y., Elgohary, A., Ho, B.J., Srivastava, M., Chang, K.W.: Generating natural language adversarial examples. arXiv preprint arXiv:1804.07998 (2018)","DOI":"10.18653\/v1\/D18-1316"},{"key":"22_CR53","doi-asserted-by":"crossref","unstructured":"Jin, D., Jin, Z., Zhou, J.T., Szolovits, P.: Is bert really robust? a strong baseline for natural language attack on text classification and entailment. In: Proceedings of the AAAI Conference on Artificial Intelligence, vol.\u00a034, pp. 8018\u20138025 (2020)","DOI":"10.1609\/aaai.v34i05.6311"},{"key":"22_CR54","doi-asserted-by":"crossref","unstructured":"Garg, S., Ramakrishnan, G.: Bae: bert-based adversarial examples for text classification. arXiv preprint arXiv:2004.01970 (2020)","DOI":"10.18653\/v1\/2020.emnlp-main.498"},{"key":"22_CR55","unstructured":"Pham, M., Marshall, K.O., Cohen, N., Mittal, G., Hegde, C.: Circumventing concept erasure methods for text-to-image generative models. In: The Twelfth International Conference on Learning Representations (2023)"},{"key":"22_CR56","unstructured":"Gal, R., Alaluf, Y., Atzmon, Y., Patashnik, O., Bermano, A.H., Chechik, G., Cohen-Or, D.: An image is worth one word: personalizing text-to-image generation using textual inversion. arXiv preprint arXiv:2208.01618 (2022)"},{"key":"22_CR57","unstructured":"Cao, H., et al.: A survey on generative diffusion model. arXiv preprint arXiv:2209.02646 (2022)"},{"key":"22_CR58","unstructured":"Madry, A., Makelov, A., Schmidt, L., Tsipras, D., Vladu, A.: Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083 (2017)"},{"key":"22_CR59","unstructured":"Croce, F., Hein, M.: Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks. In: ICML (2020)"},{"key":"22_CR60","unstructured":"Chen, H., et al.: Robust classification via a single diffusion model. arXiv preprint arXiv:2305.15241 (2023)"},{"key":"22_CR61","doi-asserted-by":"crossref","unstructured":"Li, A.C., Prabhudesai, M., Duggal, S., Brown, E., Pathak, D.: Your diffusion model is secretly a zero-shot classifier. arXiv preprint arXiv:2303.16203 (2023)","DOI":"10.1109\/ICCV51070.2023.00210"},{"key":"22_CR62","first-page":"37","volume":"22","author":"AN Iusem","year":"2003","unstructured":"Iusem, A.N.: On the convergence properties of the projected gradient method for convex optimization. Comput. Appl. Math. 22, 37\u201352 (2003)","journal-title":"Comput. Appl. Math."},{"key":"22_CR63","doi-asserted-by":"crossref","unstructured":"Parikh, N., Boyd, S., et\u00a0al.: Proximal algorithms. Found. Trends\u00ae Optim. 1(3), 127\u2013239 (2014)","DOI":"10.1561\/2400000003"},{"key":"22_CR64","unstructured":"OpenAI: Gpt-4 technical report. ArXiv abs\/2303.08774 (2023). https:\/\/api.semanticscholar.org\/CorpusID:257532815"},{"key":"22_CR65","unstructured":"Shleifer, S., Prokop, E.: Using small proxy datasets to accelerate hyperparameter search. arXiv preprint arXiv:1906.04887 (2019)"},{"key":"22_CR66","unstructured":"Loshchilov, I., Hutter, F.: Decoupled weight decay regularization. arXiv preprint arXiv:1711.05101 (2017)"},{"key":"22_CR67","unstructured":"Bedapudi, P.: Nudenet: neural nets for nudity classification, detection and selective censoring (2019)"},{"key":"22_CR68","doi-asserted-by":"crossref","unstructured":"Schramowski, P., Tauchmann, C., Kersting, K.: Can machines help us answering question 16 in datasheets, and in turn reflecting on inappropriate content? In: Proceedings of the 2022 ACM Conference on Fairness, Accountability, and Transparency, pp. 1350\u20131361 (2022)","DOI":"10.1145\/3531146.3533192"},{"key":"22_CR69","unstructured":"Wu, B., et al.: Visual transformers: token-based image representation and processing for computer vision (2020)"},{"key":"22_CR70","unstructured":"Saleh, B., Elgammal, A.: Large-scale classification of fine-art paintings: learning the right metric on the right feature. arXiv preprint arXiv:1505.00855 (2015)"}],"container-title":["Lecture Notes in Computer Science","Computer Vision \u2013 ECCV 2024"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-72998-0_22","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,11,28]],"date-time":"2024-11-28T21:29:34Z","timestamp":1732829374000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-72998-0_22"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,9,30]]},"ISBN":["9783031729973","9783031729980"],"references-count":70,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-72998-0_22","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,9,30]]},"assertion":[{"value":"30 September 2024","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ECCV","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"European Conference on Computer Vision","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Milan","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Italy","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2024","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"29 September 2024","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"4 October 2024","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"18","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"eccv2024","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/eccv2024.ecva.net\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}