{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,6]],"date-time":"2026-06-06T07:54:08Z","timestamp":1780732448265,"version":"3.54.1"},"reference-count":47,"publisher":"IEEE","license":[{"start":{"date-parts":[[2025,10,19]],"date-time":"2025-10-19T00:00:00Z","timestamp":1760832000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,10,19]],"date-time":"2025-10-19T00:00:00Z","timestamp":1760832000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025,10,19]]},"DOI":"10.1109\/iccv51701.2025.01631","type":"proceedings-article","created":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T19:45:49Z","timestamp":1777491949000},"page":"1-10","source":"Crossref","is-referenced-by-count":2,"title":["AutoPrompt: Automated Red-Teaming of Text-to-Image Models via LLM-Driven Adversarial Prompts"],"prefix":"10.1109","author":[{"given":"Yufan","family":"Liu","sequence":"first","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Wanqian","family":"Zhang","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Huashan","family":"Chen","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Lin","family":"Wang","sequence":"additional","affiliation":[{"name":"School of Cyberspace, Hangzhou Dianzi University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xiaojun","family":"Jia","sequence":"additional","affiliation":[{"name":"Nanyang Technological University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zheng","family":"Lin","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Weiping","family":"Wang","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","first-page":"2","volume-title":"Leonardo.ai","year":"2024"},{"key":"ref2","first-page":"2","volume-title":"Midjourney","year":"2024"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/ICME57554.2024.10688292"},{"key":"ref4","first-page":"6","volume-title":"Nudenet: Neural nets for nudity classification, detection and selective censoring","author":"Bedapudi","year":"2019"},{"key":"ref5","first-page":"2","volume-title":"Improving image generation with better captions","author":"Betker","year":"2023"},{"key":"ref6","first-page":"2, 3, 5, 6","article-title":"Prompting4debugging: Redteaming text-to-image diffusion models by finding problematic prompts","volume-title":"ICML","author":"Chin","year":"2024"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00230"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/WACV57701.2024.00503"},{"key":"ref9","first-page":"2","article-title":"Rt-attack: Jailbreaking text-to-image models via random token","volume-title":"arXiv preprint","author":"Gao","year":"2024"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-73668-1_5"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.emnlp-main.464"},{"key":"ref12","first-page":"3","article-title":"Selective amnesia: A continual learning approach to forgetting in deep generative models","volume-title":"NeurIPS","author":"Heng","year":"2024"},{"key":"ref13","first-page":"2, 3","article-title":"Receler: Reliable concept erasing of text-to-image diffusion models via lightweight erasers","volume-title":"In ECCV","author":"Huang","year":"2023"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v39i25.34821"},{"key":"ref15","first-page":"2","article-title":"Baseline defenses for adversarial attacks against aligned language models","volume-title":"arXiv preprint","author":"Jain","year":"2023"},{"key":"ref16","first-page":"2","article-title":"Improved techniques for optimization-based jailbreaking on large language models","volume-title":"arXiv preprint","author":"Jia","year":"2024"},{"key":"ref17","first-page":"3499","article-title":"Stochastic beams and where to find them: The gumbel-top-k trick for sampling sequences without replacement","volume-title":"In International Conference on Machine Learning","author":"Kool","year":"2019"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.02074"},{"key":"ref19","first-page":"3","article-title":"Realera: Semantic-level concept erasure via neighbor-concept mining","volume-title":"arXiv preprint","author":"Liu","year":"2024"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1145\/3664647.3681243"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.00615"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.00722"},{"key":"ref23","first-page":"2","article-title":"Black box adversarial prompting for foundation models","volume-title":"arXiv preprint","author":"Maus","year":"2023"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.emnlp-main.52"},{"key":"ref25","first-page":"2","article-title":"Advprompter: Fast adaptive adversarial prompting for 11 ms","volume-title":"arXiv preprint","author":"Paulus","year":"2024"},{"issue":"2","key":"ref26","first-page":"2","article-title":"Hierarchical text-conditional image generation with clip latents","volume":"1","author":"Ramesh","year":"2022","journal-title":"arXiv preprint"},{"key":"ref27","first-page":"2, 3","article-title":"Red-teaming the stable diffusion safety filter","volume-title":"arXiv preprint","author":"Rando","year":"2022"},{"key":"ref28","first-page":"2, 3","volume-title":"Stable diffusion 2.0 release","author":"Rombach","year":"2022"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01042"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.52202\/068431-2643"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1145\/3531146.3533192"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.02157"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2020.emnlp-main.346"},{"key":"ref34","first-page":"2","article-title":"Ring-a-bell! how reliable are concept removal methods for diffusion models?","volume-title":"arXiv preprint","author":"Tsai","year":"2023"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00202"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.52202\/075280-2219"},{"key":"ref37","first-page":"2","article-title":"On the multi-modal vulnerability of diffusion models","volume-title":"arXiv preprint","author":"Yang","year":"2024"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.00739"},{"key":"ref39","first-page":"2","article-title":"Gptfuzzer: Red teaming large language models with auto-generated jailbreak prompts","volume-title":"arXiv preprint","author":"Yu","year":"2023"},{"key":"ref40","first-page":"2","article-title":"Promptguard: Soft prompt-guided unsafe content moderation for text-to-image models","volume-title":"arXiv preprint","author":"Yuan","year":"2025"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW63382.2024.00182"},{"key":"ref42","first-page":"2","article-title":"Defensive unlearning with adversarial training for robust concept erasure in diffusion models","volume-title":"arXiv preprint","author":"Zhang","year":"2024"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-72998-0_22"},{"key":"ref44","first-page":"2","article-title":"Weak-tostrong jailbreaking on large language models","volume-title":"arXiv preprint","author":"Zhao","year":"2024"},{"key":"ref45","first-page":"2","article-title":"Autodan: Automatic and interpretable adversarial attacks on large language models","volume-title":"arXiv preprint","author":"Zhu","year":"2023"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW59228.2023.00236"},{"key":"ref47","first-page":"2","article-title":"Universal and transferable adversarial attacks on aligned language models","volume-title":"arXiv preprint","author":"Zou","year":"2023"}],"event":{"name":"2025 IEEE\/CVF International Conference on Computer Vision (ICCV)","location":"Honolulu, HI, USA","start":{"date-parts":[[2025,10,19]]},"end":{"date-parts":[[2025,10,25]]}},"container-title":["2025 IEEE\/CVF International Conference on Computer Vision (ICCV)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11443115\/11443287\/11444426.pdf?arnumber=11444426","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,30]],"date-time":"2026-04-30T06:32:51Z","timestamp":1777530771000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11444426\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,19]]},"references-count":47,"URL":"https:\/\/doi.org\/10.1109\/iccv51701.2025.01631","relation":{},"subject":[],"published":{"date-parts":[[2025,10,19]]}}}