{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,11]],"date-time":"2026-05-11T11:19:48Z","timestamp":1778498388612,"version":"3.51.4"},"publisher-location":"Singapore","reference-count":46,"publisher":"Springer Nature Singapore","isbn-type":[{"value":"9789819203741","type":"print"},{"value":"9789819203758","type":"electronic"}],"license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-981-92-0375-8_27","type":"book-chapter","created":{"date-parts":[[2026,5,11]],"date-time":"2026-05-11T10:59:14Z","timestamp":1778497154000},"page":"445-461","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Buster: Implanting Semantic Backdoor Into Text Encoder to\u00a0Mitigate NSFW Content Generation"],"prefix":"10.1007","author":[{"given":"Xin","family":"Zhao","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xiaojun","family":"Chen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yuexin","family":"Xuan","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zhendong","family":"Zhao","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xinfeng","family":"Li","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xiaojun","family":"Jia","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xiaofeng","family":"Wang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2026,5,12]]},"reference":[{"key":"27_CR1","doi-asserted-by":"publisher","unstructured":"Chou, S.Y., Chen, P.Y., Ho, T.Y.: How to backdoor diffusion models? In: 2023 IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR), pp. 4015\u20134024 (2023). https:\/\/doi.org\/10.1109\/CVPR52729.2023.00391","DOI":"10.1109\/CVPR52729.2023.00391"},{"key":"27_CR2","unstructured":"Chou, S.Y., Chen, P.Y., Ho, T.Y.: Villandiffusion: a unified backdoor attack framework for diffusion models (2023)"},{"key":"27_CR3","doi-asserted-by":"publisher","unstructured":"Deng, J., Dong, W., Socher, R., Li, L.J., Li, K., Fei-Fei, L.: ImageNet: a large-scale hierarchical image database. In: 2009 IEEE Conference on Computer Vision and Pattern Recognition, pp. 248\u2013255 (2009). https:\/\/doi.org\/10.1109\/CVPR.2009.5206848","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"27_CR4","doi-asserted-by":"crossref","unstructured":"Gandikota, R., Materzy\u0144ska, J., Fiotto-Kaufman, J., Bau, D.: Erasing concepts from diffusion models. In: Proceedings of the 2023 IEEE International Conference on Computer Vision (2023)","DOI":"10.1109\/ICCV51070.2023.00230"},{"key":"27_CR5","unstructured":"Ho, J., Jain, A., Abbeel, P.: Denoising diffusion probabilistic models (2020)"},{"key":"27_CR6","doi-asserted-by":"crossref","unstructured":"Huang, Y., et al.: Personalization as a shortcut for few-shot backdoor attack against text-to-image diffusion models (2023)","DOI":"10.1609\/aaai.v38i19.30110"},{"key":"27_CR7","unstructured":"HuggingFace: I2p dataset (2022). https:\/\/huggingface.co\/datasets\/AIML-TUDA\/i2p"},{"key":"27_CR8","doi-asserted-by":"crossref","unstructured":"Kumari, N., Zhang, B., Wang, S.Y., Shechtman, E., Zhang, R., Zhu, J.Y.: Ablating concepts in text-to-image diffusion models (2023)","DOI":"10.1109\/ICCV51070.2023.02074"},{"key":"27_CR9","unstructured":"Leonardo.Ai: Leonardo.ai (2023). https:\/\/leonardo.ai\/"},{"key":"27_CR10","doi-asserted-by":"crossref","unstructured":"Li, X., et al.: SAFEGEN: mitigating sexually explicit content generation in text-to-image models. arXiv preprint arXiv:2404.06666 (2024)","DOI":"10.1145\/3658644.3670295"},{"key":"27_CR11","doi-asserted-by":"publisher","unstructured":"Lin, T.Y., et al.: Microsoft coco: common objects in context (2014). https:\/\/doi.org\/10.1007\/978-3-319-10602-1_48","DOI":"10.1007\/978-3-319-10602-1_48"},{"key":"27_CR12","unstructured":"Liu, Y., et al.: Groot: adversarial testing for generative text-to-image models with tree-based semantic transformation (2024)"},{"key":"27_CR13","doi-asserted-by":"crossref","unstructured":"Ma, J., Cao, A., Xiao, Z., Zhang, J., Ye, C., Zhao, J.: Jailbreaking prompt attack: a controllable adversarial attack against diffusion models. arXiv:2404.02928 (2024)","DOI":"10.18653\/v1\/2025.findings-naacl.172"},{"key":"27_CR14","unstructured":"Midjourney: Midjourney (2023). https:\/\/www.midjourney.com\/"},{"key":"27_CR15","unstructured":"Mini, D.: Dall.e mini (2021). https:\/\/dallemini.com\/"},{"key":"27_CR16","unstructured":"Nichol, A.Q., et al.: GLIDE: towards photorealistic image generation and editing with text-guided diffusion models. In: Chaudhuri, K., Jegelka, S., Song, L., Szepesv\u00e1ri, C., Niu, G., Sabato, S. (eds.) International Conference on Machine Learning, ICML 2022, 17\u201323 July 2022, Baltimore, Maryland, USA. Proceedings of Machine Learning Research, vol.\u00a0162, pp. 16784\u201316804. PMLR (2022). https:\/\/proceedings.mlr.press\/v162\/nichol22a.html"},{"key":"27_CR17","unstructured":"OpenAI: Moderation overview (2023). https:\/\/platform.openai.com\/docs\/guides\/moderation\/overview"},{"key":"27_CR18","unstructured":"OpenAI: safeai (2024). https:\/\/openai.com\/safety\/"},{"key":"27_CR19","unstructured":"platelminto: Nudenet (2023). https:\/\/github.com\/notAI-tech\/NudeNet"},{"key":"27_CR20","unstructured":"Qin, L., Welleck, S., Khashabi, D., Choi, Y.: Cold decoding: energy-based constrained text generation with langevin dynamics. In: NIPS 2022, Proceedings of the 36th International Conference on Neural Information Processing Systems. Curran Associates Inc., Red Hook, NY, USA (2024)"},{"key":"27_CR21","doi-asserted-by":"crossref","unstructured":"Qu, Y., Shen, X., He, X., Backes, M., Zannettou, S., Zhang, Y.: Unsafe diffusion: on the generation of unsafe images and hateful memes from text-to-image models (2023)","DOI":"10.1145\/3576915.3616679"},{"key":"27_CR22","unstructured":"Ramesh, A., Dhariwal, P., Nichol, A., Chu, C., Chen, M.: Hierarchical text-conditional image generation with clip latents (2022)"},{"key":"27_CR23","unstructured":"Recht, B., Roelofs, R., Schmidt, L., Shankar, V.: Do ImageNet classifiers generalize to ImageNet? (2019)"},{"key":"27_CR24","doi-asserted-by":"publisher","unstructured":"Rombach, R., Blattmann, A., Lorenz, D., Esser, P., Ommer, B.: High-resolution image synthesis with latent diffusion models. In: IEEE\/CVF Conference on Computer Vision and Pattern Recognition, CVPR 2022, New Orleans, LA, USA, June 18\u201324, 2022, pp. 10674\u201310685. IEEE (2022). https:\/\/doi.org\/10.1109\/CVPR52688.2022.01042","DOI":"10.1109\/CVPR52688.2022.01042"},{"key":"27_CR25","doi-asserted-by":"crossref","unstructured":"Ronneberger, O., Fischer, P., Brox, T.: U-Net: convolutional networks for biomedical image segmentation (2015)","DOI":"10.1007\/978-3-319-24574-4_28"},{"key":"27_CR26","doi-asserted-by":"crossref","unstructured":"Schramowski, P., Brack, M., Deiseroth, B., Kersting, K.: Safe latent diffusion: mitigating inappropriate degeneration in diffusion models (2023)","DOI":"10.1109\/CVPR52729.2023.02157"},{"key":"27_CR27","doi-asserted-by":"crossref","unstructured":"Schramowski, P., Tauchmann, C., Kersting, K.: Can machines help us answering question 16 in datasheets, and in turn reflecting on inappropriate content? In: Proceedings of the ACM Conference on Fairness, Accountability, and Transparency (FAccT) (2022)","DOI":"10.1145\/3531146.3533192"},{"key":"27_CR28","unstructured":"Schuhmann, C., et al.: Laion-5b: an open large-scale dataset for training next generation image-text models (2022)"},{"key":"27_CR29","doi-asserted-by":"crossref","unstructured":"Shan, S., Ding, W., Passananti, J., Wu, S., Zheng, H., Zhao, B.Y.: Nightshade: prompt-specific poisoning attacks on text-to-image generative models. arXiv:2310.13828 (2024)","DOI":"10.1109\/SP54263.2024.00207"},{"key":"27_CR30","unstructured":"Song, J., Meng, C., Ermon, S.: Denoising diffusion implicit models. CoRR arXiv:2010.02502 (2020)"},{"key":"27_CR31","unstructured":"Song, Y., Sohl-Dickstein, J., Kingma, D.P., Kumar, A., Ermon, S., Poole, B.: Score-based generative modeling through stochastic differential equations (2021)"},{"key":"27_CR32","doi-asserted-by":"crossref","unstructured":"Struppek, L., Hintersdorf, D., Kersting, K.: Rickrolling the artist: injecting backdoors into text encoders for text-to-image synthesis. In: Proceedings of the IEEE\/CVF International Conference on Computer Vision (ICCV), pp. 4584\u20134596 (2023)","DOI":"10.1109\/ICCV51070.2023.00423"},{"key":"27_CR33","unstructured":"Tian, Y., Yang, X., Dong, Y., Yang, H., Su, H., Zhu, J.: BSPA: exploring black-box stealthy prompt attacks against image generators (2024)"},{"key":"27_CR34","unstructured":"Vaswani, A., et al.: Attention is all you need. CoRR arXiv:1706.03762 (2017)"},{"key":"27_CR35","doi-asserted-by":"crossref","unstructured":"Vice, J., Akhtar, N., Hartley, R., Mian, A.: BAGM: a backdoor attack for manipulating text-to-image generative models (2023)","DOI":"10.1109\/TIFS.2024.3386058"},{"key":"27_CR36","unstructured":"Wang, Y., Jha, S., Chaudhuri, K.: Analyzing the robustness of nearest neighbors to adversarial examples. arXiv:1706.03922 (2019)"},{"key":"27_CR37","unstructured":"Wu, Y., Zhang, J., Kerschbaum, F., Zhang, T.: Backdooring textual inversion for concept censorship (2023)"},{"key":"27_CR38","unstructured":"Yang, D., Bai, Y., Jia, X., Liu, Y., Cao, X., Yu, W.: On the multi-modal vulnerability of diffusion models. In: Trustworthy Multi-modal Foundation Models and AI Agents (TiFA) (2024). https:\/\/openreview.net\/forum?id=FuZjlzR7kT"},{"key":"27_CR39","doi-asserted-by":"crossref","unstructured":"Yang, Y., Gao, R., Wang, X., Ho, T.Y., Xu, N., Xu, Q.: MMA-diffusion: multimodal attack on diffusion models (2024)","DOI":"10.1109\/CVPR52733.2024.00739"},{"key":"27_CR40","unstructured":"Yang, Y., Gao, R., Yang, X., Zhong, J., Xu, Q.: Guardt2i: defending text-to-image models from adversarial prompts (2024)"},{"key":"27_CR41","doi-asserted-by":"crossref","unstructured":"Yang, Y., Hui, B., Yuan, H., Gong, N., Cao, Y.: Sneakyprompt: jailbreaking text-to-image generative models (2023)","DOI":"10.1109\/SP54263.2024.00123"},{"key":"27_CR42","unstructured":"Yuan, Z., et al.: RigorLLM: resilient guardrails for large language models against undesired content. arXiv:2403.13031 (2024). https:\/\/api.semanticscholar.org\/CorpusID:268536710"},{"key":"27_CR43","doi-asserted-by":"crossref","unstructured":"Zhai, S., Dong, Y., Shen, Q., Pu, S., Fang, Y., Su, H.: Text-to-image diffusion models can be easily backdoored through multimodal data poisoning (2023)","DOI":"10.1145\/3581783.3612108"},{"key":"27_CR44","doi-asserted-by":"publisher","unstructured":"Zhao, X., Chen, X., Chen, X., Li, H., Fan, T., Zhao, Z.: CipherDM: secure three-party inference for diffusion model sampling. In: Computer Vision \u2013 ECCV 2024, pp. 288\u2013305. Springer, Cham (2025). https:\/\/doi.org\/10.1007\/978-3-031-73209-6_17","DOI":"10.1007\/978-3-031-73209-6_17"},{"key":"27_CR45","doi-asserted-by":"crossref","unstructured":"Zhao, X., Chen, X., Gao, H.: Antelope: potent and concealed jailbreak attack strategy (2024). https:\/\/api.semanticscholar.org\/CorpusID:274638473","DOI":"10.1145\/3746252.3761283"},{"key":"27_CR46","doi-asserted-by":"crossref","unstructured":"Zhuang, H., Zhang, Y., Liu, S.: A pilot study of query-free adversarial attack against stable diffusion. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR) Workshops, pp. 2385\u20132392 (2023)","DOI":"10.1109\/CVPRW59228.2023.00236"}],"container-title":["Lecture Notes in Computer Science","Database Systems for Advanced Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-981-92-0375-8_27","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,11]],"date-time":"2026-05-11T10:59:35Z","timestamp":1778497175000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-981-92-0375-8_27"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"ISBN":["9789819203741","9789819203758"],"references-count":46,"URL":"https:\/\/doi.org\/10.1007\/978-981-92-0375-8_27","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]},"assertion":[{"value":"12 May 2026","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"DASFAA","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Database Systems for Advanced Applications","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Jeju","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Korea (Republic of)","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2026","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"27 April 2026","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"30 April 2026","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"31","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"dasfaa2026","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/dasfaa2026.github.io\/index.html","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}