{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,31]],"date-time":"2025-10-31T07:11:25Z","timestamp":1761894685972,"version":"build-2065373602"},"reference-count":28,"publisher":"IEEE","license":[{"start":{"date-parts":[[2025,6,30]],"date-time":"2025-06-30T00:00:00Z","timestamp":1751241600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,6,30]],"date-time":"2025-06-30T00:00:00Z","timestamp":1751241600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100019014","name":"Chengdu Science and Technology Program","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100019014","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025,6,30]]},"DOI":"10.1109\/icme59968.2025.11210084","type":"proceedings-article","created":{"date-parts":[[2025,10,30]],"date-time":"2025-10-30T17:57:42Z","timestamp":1761847062000},"page":"1-6","source":"Crossref","is-referenced-by-count":0,"title":["Weaponizing Tokens: Backdooring Text-to-Image Generation via Token Remapping"],"prefix":"10.1109","author":[{"given":"Jiaming","family":"He","sequence":"first","affiliation":[{"name":"University of Electronic Science and Technology of China,School of Computer Science and Engineering,China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wenbo","family":"Jiang","sequence":"additional","affiliation":[{"name":"University of Electronic Science and Technology of China,School of Computer Science and Engineering,China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Guanyu","family":"Hou","sequence":"additional","affiliation":[{"name":"Chengdu University of Technology,College of Computer Science and Cyber Security (Oxford Brookes College),China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Qiyang","family":"Song","sequence":"additional","affiliation":[{"name":"Chinese Academy of Sciences,Institute of Information Engineering,China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ji","family":"Guo","sequence":"additional","affiliation":[{"name":"University of Electronic Science and Technology of China,School of Computer Science and Engineering,China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hongwei","family":"Li","sequence":"additional","affiliation":[{"name":"University of Electronic Science and Technology of China,School of Computer Science and Engineering,China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","first-page":"36 479","article-title":"Photorealistic text-to-image diffusion models with deep language understanding","volume":"35","author":"Saharia","year":"2022","journal-title":"Advances in neural information processing systems"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01042"},{"issue":"2","key":"ref3","first-page":"3","article-title":"Hierarchical text-conditional image generation with clip latents","volume":"1","author":"Ramesh","year":"2022"},{"key":"ref4","first-page":"25 278","article-title":"Laion-5b: An open large-scale dataset for training next generation image-text models","volume":"35","author":"Schuhmann","year":"2022","journal-title":"Advances in Neural Information Processing Systems"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v39i25.34819"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/tdsc.2025.3603639"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/GLOBECOM52923.2024.10901210"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00423"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1145\/3581783.3612108"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3386058"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v38i19.30110"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1145\/3543507.3583348"},{"year":"2016","key":"ref13","article-title":"General Data Protection Regulation (GDPR)"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1145\/3422622"},{"key":"ref15","first-page":"6840","article-title":"Denoising diffusion probabilistic models","volume":"33","author":"Ho","year":"2020","journal-title":"Advances in neural information processing systems"},{"article-title":"ediff-i: Text-to-image diffusion models with an ensemble of expert denoisers","year":"2022","author":"Balaji","key":"ref16"},{"key":"ref17","article-title":"Optimizing prompts for text-to-image generation","volume":"36","author":"Hao","year":"2024","journal-title":"Advances in Neural Information Processing Systems"},{"article-title":"Llama 2: Open foundation and fine-tuned chat models","year":"2023","author":"Touvron","key":"ref18"},{"key":"ref19","first-page":"8748","article-title":"Learning transferable visual models from natural language supervision","volume-title":"International conference on machine learning","author":"Radford"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.12794\/metadc1505267"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3616679"},{"key":"ref22","first-page":"27 730","article-title":"Training language models to follow instructions with human feedback","volume":"35","author":"Ouyang","year":"2022","journal-title":"Advances in neural information processing systems"},{"key":"ref23","first-page":"2","article-title":"Bert: Pre-training of deep bidirectional transformers for language understanding","volume-title":"Proceedings of naacL-HLT","volume":"1","author":"Kenton"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/ICIP.2014.7025068"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00482"},{"key":"ref26","article-title":"Gans trained by a two time-scale update rule converge to a local nash equilibrium","volume":"30","author":"Heusel","year":"2017","journal-title":"Advances in neural information processing systems"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-10602-1_48"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.emnlp-main.752"}],"event":{"name":"2025 IEEE International Conference on Multimedia and Expo (ICME)","start":{"date-parts":[[2025,6,30]]},"location":"Nantes, France","end":{"date-parts":[[2025,7,4]]}},"container-title":["2025 IEEE International Conference on Multimedia and Expo (ICME)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11208895\/11208897\/11210084.pdf?arnumber=11210084","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,31]],"date-time":"2025-10-31T05:33:29Z","timestamp":1761888809000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11210084\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,6,30]]},"references-count":28,"URL":"https:\/\/doi.org\/10.1109\/icme59968.2025.11210084","relation":{},"subject":[],"published":{"date-parts":[[2025,6,30]]}}}