{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,27]],"date-time":"2026-04-27T20:37:37Z","timestamp":1777322257078,"version":"3.51.4"},"reference-count":59,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001381","name":"National Research Foundation Singapore","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100001381","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Cyber Security Agency of Singapore through the National Cybersecurity Research and Development Programme"},{"name":"CyberSG Research and Development Programme Office","award":["CRPO-GC3-NTU-001"],"award-info":[{"award-number":["CRPO-GC3-NTU-001"]}]},{"name":"NTU-NAP Startup","award":["024584-00001"],"award-info":[{"award-number":["024584-00001"]}]},{"name":"Singapore Ministry of Education Tier 1","award":["Grant RG19\/25"],"award-info":[{"award-number":["Grant RG19\/25"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2026]]},"DOI":"10.1109\/tifs.2026.3678787","type":"journal-article","created":{"date-parts":[[2026,3,30]],"date-time":"2026-03-30T20:05:29Z","timestamp":1774901129000},"page":"4051-4061","source":"Crossref","is-referenced-by-count":1,"title":["PromptGuard: Soft Prompt-Guided Unsafe Content Moderation for Text-to-Image Models"],"prefix":"10.1109","volume":"21","author":[{"ORCID":"https:\/\/orcid.org\/0009-0009-0376-6574","authenticated-orcid":false,"given":"Lingzhi","family":"Yuan","sequence":"first","affiliation":[{"name":"Department of Computer Science, University of Maryland, College Park, MD, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9686-4369","authenticated-orcid":false,"given":"Xinfeng","family":"Li","sequence":"additional","affiliation":[{"name":"College of Computing and Data Science, Nanyang Technological University, Jurong West, Singapore"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-7598-639X","authenticated-orcid":false,"given":"Chejian","family":"Xu","sequence":"additional","affiliation":[{"name":"Siebel School of Computing and Data Science, University of Illinois Urbana&#x2013;Champaign, Urbana, IL, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Guanhong","family":"Tao","sequence":"additional","affiliation":[{"name":"Kahlert School of Computing, The University of Utah, Salt Lake City, UT, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2018-9344","authenticated-orcid":false,"given":"Xiaojun","family":"Jia","sequence":"additional","affiliation":[{"name":"College of Computing and Data Science, Nanyang Technological University, Jurong West, Singapore"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5784-770X","authenticated-orcid":false,"given":"Yihao","family":"Huang","sequence":"additional","affiliation":[{"name":"College of Computing and Data Science, Nanyang Technological University, Jurong West, Singapore"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wei","family":"Dong","sequence":"additional","affiliation":[{"name":"College of Computing and Data Science, Nanyang Technological University, Jurong West, Singapore"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7300-9215","authenticated-orcid":false,"given":"Yang","family":"Liu","sequence":"additional","affiliation":[{"name":"College of Computing and Data Science, Nanyang Technological University, Jurong West, Singapore"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Bo","family":"Li","sequence":"additional","affiliation":[{"name":"Siebel School of Computing and Data Science, University of Illinois Urbana&#x2013;Champaign, Urbana, IL, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","volume-title":"Stable Diffusion V1-4","year":"2024"},{"key":"ref2","volume-title":"AI Porn Is Easy To Make Now. For Women, That\u2019s a Nightmare","author":"Hunter","year":"2023"},{"key":"ref3","volume-title":"Spotting the Deepfakes in This Year of Elections: How AI Detection Tools Work and Where They Fail","author":"Anlen","year":"2024"},{"key":"ref4","volume-title":"Text-to-Image AI Models Can Be Tricked Into Generating Disturbing Images","author":"Williams","year":"2023"},{"key":"ref5","article-title":"MMDT: Decoding the trustworthiness and safety of multimodal foundation models","author":"Xu","year":"2025","journal-title":"arXiv:2503.14827"},{"key":"ref6","volume-title":"AI-Created Child Sexual Abuse Images \u2019Threaten to Overwhelm Internet\u2019","author":"Milmo","year":"2023"},{"key":"ref7","volume-title":"2024: The Election Year of Deepfakes, Doubts and Disinformation?","author":"Owen","year":"2024"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00230"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/WACV57701.2024.00503"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1145\/3658644.3670295"},{"key":"ref11","article-title":"Direct unlearning optimization for robust and safe text-to-image models","author":"Park","year":"2024","journal-title":"arXiv:2407.21035"},{"key":"ref12","volume-title":"Stable Diffusion V2-1","year":"2024"},{"key":"ref13","article-title":"Towards safe self-distillation of internet-scale text-to-image diffusion models","author":"Kim","year":"2023","journal-title":"arXiv:2307.05977"},{"key":"ref14","article-title":"Defensive unlearning with adversarial training for robust concept erasure in diffusion models","author":"Zhang","year":"2024","journal-title":"arXiv:2405.15234"},{"key":"ref15","volume-title":"NSFW Text Classifier on Hugging Face","author":"Li","year":"2024"},{"key":"ref16","volume-title":"Safety Checker","year":"2024"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.naacl-long.351"},{"key":"ref18","volume-title":"GPT Documentation","year":"2022"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.52202\/075280-1361"},{"key":"ref20","first-page":"4171","article-title":"SDEdit: Guided image synthesis and editing with stochastic differential equations","volume-title":"Proc. 10th Int. Conf. Learn. Represent.","author":"Meng"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3616679"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2025.241167"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-73347-5_6"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.02157"},{"key":"ref25","first-page":"6840","article-title":"Denoising diffusion probabilistic models","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"33","author":"Ho"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01042"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.1810.04805"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.52202\/068431-1833"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.acl-long.524"},{"key":"ref30","article-title":"The prompt report: A systematic survey of prompt engineering techniques","volume-title":"arXiv:2406.06608","author":"Schulhoff","year":"2024"},{"key":"ref31","volume-title":"Safety System Messages in LLM","author":"Azure","year":"2024"},{"key":"ref32","first-page":"61593","article-title":"On prompt-driven safeguarding for large language models","volume-title":"Proc. 41st Int. Conf. Mach. Learn. (ICML)","author":"Zheng"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.emnlp-main.243"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.acllong.353"},{"key":"ref35","volume-title":"NSFW Data Scraper","author":"Kim","year":"2024"},{"key":"ref36","volume-title":"GPT-4o Mini: Advancing Cost-Efficient Intelligence","year":"2024"},{"key":"ref37","volume-title":"Scholar GPT","year":"2024"},{"key":"ref38","article-title":"GPT-4 technical report","volume-title":"arXiv:2303.08774","author":"Achiam","year":"2023"},{"key":"ref39","volume-title":"Inaproppriate Image Prompts (I2P)"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00123"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1405.0312"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.00739"},{"key":"ref43","article-title":"LlavaGuard: An open VLM-based framework for safeguarding vision datasets and models","volume-title":"Proc. 42nd Int. Conf. Mach. Learn. (ICML)","author":"Helff"},{"key":"ref44","first-page":"18","article-title":"Learning transferable visual models from natural language supervision","volume-title":"Proc. 38th Int. Conf. Mach. Learn. (ICML)","author":"Radford"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00068"},{"key":"ref46","volume-title":"SafeGen-Pretrained-Weights","author":"Li et al","year":"2024"},{"key":"ref47","volume-title":"Diffusers: State-of-the-Art Diffusion Models","author":"von Platen et al","year":"2022"},{"key":"ref48","article-title":"AlignGuard: Scalable safety alignment for text-to-image generation","author":"Liu","year":"2024","journal-title":"arXiv:2412.10493"},{"key":"ref49","article-title":"Exploring the limits of transfer learning with a unified text-to-text transformer","author":"Raffel","year":"2019","journal-title":"arXiv:1910.10683"},{"key":"ref50","doi-asserted-by":"crossref","DOI":"10.1016\/S0140-6736(02)11133-0","volume-title":"World Report on Violence and Health","author":"Krug","year":"2002"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1037\/a0035618"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1017\/9781108890960"},{"key":"ref53","article-title":"InstructPix2Pix: Learning to follow image editing instructions","author":"Brooks","year":"2022","journal-title":"arXiv:2211.09800"},{"key":"ref54","article-title":"Null-text inversion for editing real images using guided diffusion models","author":"Mokady","year":"2022","journal-title":"arXiv:2211.09794"},{"key":"ref55","volume-title":"Unified Concept Editing in Diffusion Models","year":"2024"},{"key":"ref56","volume-title":"Safe Stable Diffusion","year":"2024"},{"key":"ref57","volume-title":"Universal Prompt Optimizer for Safe Text-to-Image Generation","year":"2024"},{"key":"ref58","article-title":"SDXL: Improving latent diffusion models for high-resolution image synthesis","author":"Podell","year":"2023","journal-title":"arXiv:2307.01952"},{"key":"ref59","volume-title":"DeepFloyd IF","year":"2024"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/10206\/11313711\/11457697.pdf?arnumber=11457697","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,27]],"date-time":"2026-04-27T19:48:17Z","timestamp":1777319297000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11457697\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"references-count":59,"URL":"https:\/\/doi.org\/10.1109\/tifs.2026.3678787","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"value":"1556-6013","type":"print"},{"value":"1556-6021","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]}}}