{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,4]],"date-time":"2026-05-04T10:07:58Z","timestamp":1777889278862,"version":"3.51.4"},"reference-count":51,"publisher":"IEEE","license":[{"start":{"date-parts":[[2025,10,19]],"date-time":"2025-10-19T00:00:00Z","timestamp":1760832000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,10,19]],"date-time":"2025-10-19T00:00:00Z","timestamp":1760832000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U21B2024,62425307,62202329"],"award-info":[{"award-number":["U21B2024,62425307,62202329"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025,10,19]]},"DOI":"10.1109\/iccv51701.2025.01759","type":"proceedings-article","created":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T19:45:49Z","timestamp":1777491949000},"page":"1-10","source":"Crossref","is-referenced-by-count":0,"title":["TRCE: Towards Reliable Malicious Concept Erasure in Text-to-Image Diffusion Models"],"prefix":"10.1109","author":[{"given":"Ruidong","family":"Chen","sequence":"first","affiliation":[{"name":"The School of Electrical and Information Engineering, Tianjin University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Honglin","family":"Guo","sequence":"additional","affiliation":[{"name":"The School of Electrical and Information Engineering, Tianjin University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Lanjun","family":"Wang","sequence":"additional","affiliation":[{"name":"The School of New Media and Communication, Tianjin University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Chenyu","family":"Zhang","sequence":"additional","affiliation":[{"name":"The School of New Media and Communication, Tianjin University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Weizhi","family":"Nie","sequence":"additional","affiliation":[{"name":"The School of Electrical and Information Engineering, Tianjin University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"An-An","family":"Liu","sequence":"additional","affiliation":[{"name":"The School of Electrical and Information Engineering, Tianjin University"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.naacl-long.140"},{"key":"ref2","first-page":"3","article-title":"Neural machine translation by jointly learning to align and translate","volume-title":"arXiv preprint","author":"Bahdanau","year":"2014"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.5244\/C.30.119"},{"key":"ref4","article-title":"Localizing and editing knowledge in text-to-image generative models.","volume-title":"The Twelfth International Conference on Learning Representations","author":"Basu","year":"2023"},{"key":"ref5","article-title":"Labs","volume-title":"Flux.1-dev. https: \/ \/ huggingface. co \/ black - forest - labs \/ FLUX.1-dev","author":"Forest","year":"2024"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1145\/3581783.3612110"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/WACV57701.2024.00526"},{"key":"ref8","article-title":"Prompting4debugging: Redteaming text-to-image diffusion models by finding problematic prompts","volume-title":"arXiv preprint","author":"Chin","year":"2023"},{"key":"ref9","article-title":"Bert: Pre-training of deep bidirectional transformers for language understanding","volume-title":"arXiv preprint","author":"Devlin","year":"2018"},{"key":"ref10","article-title":"Scaling rectified flow transformers for high-resolution image synthesis","volume-title":"Forty-first International Conference on Machine Learning","author":"Esser","year":"2024"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00230"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/WACV57701.2024.00503"},{"key":"ref13","article-title":"Reliable and efficient concept erasure of text-toimage diffusion models","volume-title":"arXiv preprint","author":"Gong","year":"2024"},{"key":"ref14","volume-title":"Giphy celebrity detector","author":"Hasty","year":"2020"},{"key":"ref15","article-title":"Gans trained by a two time-scale update rule converge to a local nash equilibrium","volume":"30","author":"Heusel","year":"2017","journal-title":"Advances in neural information processing systems"},{"key":"ref16","article-title":"Classifier-free diffusion guidance","volume-title":"arXiv preprint","author":"Ho","year":"2022"},{"key":"ref17","first-page":"6840","article-title":"Denoising diffusion probabilistic models","volume":"33","author":"Ho","year":"2020","journal-title":"Advances in neural information processing systems"},{"key":"ref18","article-title":"Lora: Low-rank adaptation of large language models","volume-title":"arXiv preprint","author":"J Hu","year":"2021"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.02074"},{"key":"ref20","article-title":"Get what you want, not what you don\u2019t: Image content suppression for text-to-image diffusion models","volume-title":"arXiv preprint","author":"Li","year":"2024"},{"key":"ref21","article-title":"Safegen: Mitigating unsafe content generation in text-to-image models","volume-title":"arXiv preprint","author":"Li","year":"2024"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-10602-1_48"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.00615"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.00722"},{"key":"ref25","article-title":"Glide: Towards photorealistic image generation and editing with text-guided diffusion models","volume-title":"arXiv preprint","author":"Nichol","year":"2021"},{"key":"ref26","volume-title":"notAI tech. Nudenet: Neural nets for nudity classification, detection and selective censoring","year":"2019"},{"key":"ref27","volume-title":"Openai. Gpt-4o system card","year":"2024"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00649"},{"key":"ref29","article-title":"Can sensitive information be deleted from llms? objectives for defending against extraction attacks","volume-title":"arXiv preprint","author":"Patil","year":"2023"},{"key":"ref30","article-title":"Sdxl: Improving latent diffusion models for high-resolution image synthesis","volume-title":"arXiv preprint","author":"Podell","year":"2023"},{"key":"ref31","article-title":"Learning transferable visual models from natural language supervision","volume-title":"International conference on machine learning, pages 8748\u20138763","author":"Radford","year":"2021"},{"key":"ref32","article-title":"Red-teaming the stable diffusion safety filter","volume-title":"arXiv preprint","author":"Rando","year":"2022"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1088\/1742-5468\/ad64bd"},{"key":"ref34","volume-title":"Stable diffusion v1\u20134 model card. model card","author":"Rombach","year":"2022"},{"key":"ref35","volume-title":"Stable diffusion 2.0 release","author":"Rombach","year":"2022"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01042"},{"key":"ref37","article-title":"Unet: Convolutional networks for biomedical image segmentation","volume-title":"Medical Image Computing and Computer-Assisted Intervention-MICCAI 2015: 18th International Conference, Munich, Germany, October 5\u20139, 2015, Proceedings, Part III 18, pages 234-241. Springer","author":"Ronneberger","year":"2015"},{"key":"ref38","first-page":"36479","volume-title":"Photorealistic text-to-image diffusion models with deep language understanding. Advances in neural information processing systems","volume":"35","author":"Saharia","year":"2022"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1145\/3531146.3533192"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.02157"},{"key":"ref41","article-title":"Jailbreak in pieces: Compositional adversarial attacks on multimodal language models","volume-title":"In The Twelfth International Conference on Learning Representations","author":"Shayegani","year":"2023"},{"key":"ref42","article-title":"Survey of vulnerabilities in large language models revealed by adversarial attacks","volume-title":"arXiv preprint","author":"Shayegani","year":"2023"},{"key":"ref43","article-title":"Denoising diffusion implicit models","volume-title":"arXiv preprint","author":"Song","year":"2020"},{"key":"ref44","article-title":"Ring-a-bell! how reliable are concept removal methods for diffusion models?","volume-title":"arXiv preprint","author":"Tsai","year":"2023"},{"key":"ref45","volume-title":"Attention is all you need. Advances in Neural Information Processing Systems","author":"Vaswani","year":"2017"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.00739"},{"key":"ref47","article-title":"Safree: Training-free and adaptive guard for safe text-to-image and video generation","volume-title":"arXiv preprint","author":"Yoon","year":"2024"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1016\/j.inffus.2024.102701"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW63382.2024.00182"},{"key":"ref50","article-title":"Defensive unlearning with adversarial training for robust concept erasure in diffusion models","volume-title":"arXiv preprint","author":"Zhang","year":"2024"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-72998-0_22"}],"event":{"name":"2025 IEEE\/CVF International Conference on Computer Vision (ICCV)","location":"Honolulu, HI, USA","start":{"date-parts":[[2025,10,19]]},"end":{"date-parts":[[2025,10,25]]}},"container-title":["2025 IEEE\/CVF International Conference on Computer Vision (ICCV)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11443115\/11443287\/11444350.pdf?arnumber=11444350","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T05:08:49Z","timestamp":1777612129000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11444350\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,19]]},"references-count":51,"URL":"https:\/\/doi.org\/10.1109\/iccv51701.2025.01759","relation":{},"subject":[],"published":{"date-parts":[[2025,10,19]]}}}