{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,24]],"date-time":"2026-07-24T06:33:43Z","timestamp":1784874823356,"version":"3.55.0"},"reference-count":170,"publisher":"Association for Computing Machinery (ACM)","issue":"8","license":[{"start":{"date-parts":[[2025,4,3]],"date-time":"2025-04-03T00:00:00Z","timestamp":1743638400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Comput. Surv."],"published-print":{"date-parts":[[2025,8,31]]},"abstract":"<jats:p>Diffusion models (DMs) have achieved state-of-the-art performance on various generative tasks such as image synthesis, text-to-image, and text-guided image-to-image generation. However, the more powerful the DMs, the more harmful they can potentially be. Recent studies have shown that DMs are prone to a wide range of attacks, including adversarial attacks, membership inference attacks, backdoor injection, and various multi-modal threats. Since numerous pre-trained DMs are published widely on the Internet, potential threats from these attacks are especially detrimental to society, making DM-related security a topic worthy of investigation. Therefore, in this article, we conduct a comprehensive survey on the security aspect of DMs, focusing on various attack and defense methods for DMs. First, we present crucial knowledge of DMs with five main types of DMs, including denoising diffusion probabilistic models, denoising diffusion implicit models, noise conditioned score networks, stochastic differential equations, and multi-modal conditional DMs. We provide a comprehensive survey of recent works investigating different types of attacks that exploit the vulnerabilities of DMs. Then, we thoroughly review potential countermeasures to mitigate each of the presented threats. Finally, we discuss open challenges of DM-related security and describe potential research directions for this topic.<\/jats:p>","DOI":"10.1145\/3721479","type":"journal-article","created":{"date-parts":[[2025,3,4]],"date-time":"2025-03-04T11:20:59Z","timestamp":1741087259000},"page":"1-44","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":31,"title":["Attacks and Defenses for Generative Diffusion Models: A Comprehensive Survey"],"prefix":"10.1145","volume":"57","author":[{"ORCID":"https:\/\/orcid.org\/0009-0003-3072-7905","authenticated-orcid":false,"given":"Vu Tuan","family":"Truong","sequence":"first","affiliation":[{"name":"Institut National De La Recherche Scientifique (INRS), Montreal, Canada"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-9746-2241","authenticated-orcid":false,"given":"Luan Ba","family":"Dang","sequence":"additional","affiliation":[{"name":"Institut National De La Recherche Scientifique (INRS), Montreal, Canada"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3577-6530","authenticated-orcid":false,"given":"Long Bao","family":"Le","sequence":"additional","affiliation":[{"name":"Institut National De La Recherche Scientifique (INRS), Montreal, Canada"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2025,4,3]]},"reference":[{"key":"e_1_3_1_2_2","first-page":"2256","volume-title":"Proceedings of the International Conference on Machine Learning.","author":"Sohl-Dickstein Jascha","year":"2015","unstructured":"Jascha Sohl-Dickstein, Eric Weiss, Niru Maheswaranathan, and Surya Ganguli. 2015. Deep unsupervised learning using nonequilibrium thermodynamics. In Proceedings of the International Conference on Machine Learning.2256\u20132265."},{"key":"e_1_3_1_3_2","first-page":"6840","volume-title":"Proceedings of the International Conference on Neural Information Processing Systems","volume":"33","author":"Ho Jonathan","year":"2020","unstructured":"Jonathan Ho, Ajay Jain, and Pieter Abbeel. 2020. Denoising diffusion probabilistic models. In Proceedings of the International Conference on Neural Information Processing Systems, Vol. 33. 6840\u20136851."},{"key":"e_1_3_1_4_2","first-page":"8780","volume-title":"Proceedings of the International Conference on Neural Information Processing Systems","volume":"34","author":"Dhariwal Prafulla","year":"2021","unstructured":"Prafulla Dhariwal and Alexander Nichol. 2021. Diffusion models beat GANs on image synthesis. In Proceedings of the International Conference on Neural Information Processing Systems, Vol. 34. 8780\u20138794."},{"key":"e_1_3_1_5_2","first-page":"8162","volume-title":"Proceedings of the International Conference on Machine Learning.","author":"Nichol Alexander Quinn","year":"2021","unstructured":"Alexander Quinn Nichol and Prafulla Dhariwal. 2021. Improved denoising diffusion probabilistic models. In Proceedings of the International Conference on Machine Learning.8162\u20138171."},{"key":"e_1_3_1_6_2","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Song Jiaming","year":"2021","unstructured":"Jiaming Song, Chenlin Meng, and Stefano Ermon. 2021. Denoising diffusion implicit models. In Proceedings of the International Conference on Learning Representations."},{"key":"e_1_3_1_7_2","first-page":"11918","volume-title":"Proceedings of the International Conference on Neural Information Processing Systems","volume":"32","author":"Song Yang","year":"2019","unstructured":"Yang Song and Stefano Ermon. 2019. Generative modeling by estimating gradients of the data distribution. In Proceedings of the International Conference on Neural Information Processing Systems, Vol. 32. 11918\u201311930."},{"key":"e_1_3_1_8_2","first-page":"12438","volume-title":"Proceedings of the International Conference on Neural Information Processing Systems","volume":"34","author":"Song Yang","year":"2021","unstructured":"Yang Song, Conor Durkan, Iain Murray, and Stefano Ermon. 2021. Maximum likelihood training of score-based diffusion models. In Proceedings of the International Conference on Neural Information Processing Systems, Vol. 34. 12438\u201312448."},{"key":"e_1_3_1_9_2","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Song Yang","year":"2021","unstructured":"Yang Song, Jascha Sohl-Dickstein, Diederik P. Kingma, Abhishek Kumar, Stefano Ermon, and Ben Poole. 2021. Score-based generative modeling through stochastic differential equations. In Proceedings of the International Conference on Learning Representations."},{"key":"e_1_3_1_10_2","first-page":"10684","volume-title":"Proceedings of the International Conference on Computer Vision and Pattern Recognition.","author":"Rombach Robin","year":"2022","unstructured":"Robin Rombach, Andreas Blattmann, Dominik Lorenz, Patrick Esser, and Bj\u00f6rn Ommer. 2022. High-resolution image synthesis with latent diffusion models. In Proceedings of the International Conference on Computer Vision and Pattern Recognition.10684\u201310695."},{"key":"e_1_3_1_11_2","first-page":"12438","volume-title":"Proceedings of the International Conference on Neural Information Processing Systems.","author":"Song Yang","year":"2020","unstructured":"Yang Song and Stefano Ermon. 2020. Improved techniques for training score-based generative models. In Proceedings of the International Conference on Neural Information Processing Systems.12438\u201312448."},{"key":"e_1_3_1_12_2","first-page":"11287","volume-title":"Proceedings of the International Conference on Neural Information Processing Systems","volume":"34","author":"Vahdat Arash","year":"2021","unstructured":"Arash Vahdat, Karsten Kreis, and Jan Kautz. 2021. Score-based generative modeling in latent space. In Proceedings of the International Conference on Neural Information Processing Systems, Vol. 34. 11287\u201311302."},{"key":"e_1_3_1_13_2","volume-title":"Proceedings of the International Conference on Neural Information Processing Systems","volume":"27","author":"Goodfellow Ian","year":"2014","unstructured":"Ian Goodfellow, Jean Pouget-Abadie, Mehdi Mirza, Bing Xu, David Warde-Farley, Sherjil Ozair, Aaron Courville, and Yoshua Bengio. 2014. Generative adversarial nets. In Proceedings of the International Conference on Neural Information Processing Systems, Vol. 27."},{"key":"e_1_3_1_14_2","volume-title":"Proceedings of the International Conference on Machine Learning.","author":"Kingma Diederik P.","year":"2014","unstructured":"Diederik P. Kingma and Max Welling. 2014. Auto-encoding variational Bayes. In Proceedings of the International Conference on Machine Learning."},{"key":"e_1_3_1_15_2","first-page":"1530","volume-title":"Proceedings of the International Conference on Machine Learning.","author":"Rezende Danilo","year":"2015","unstructured":"Danilo Rezende and Shakir Mohamed. 2015. Variational inference with normalizing flows. In Proceedings of the International Conference on Machine Learning.1530\u20131538."},{"key":"e_1_3_1_16_2","first-page":"1105","volume-title":"Proceedings of the International Conference on Machine Learning.","author":"Ngiam Jiquan","year":"2011","unstructured":"Jiquan Ngiam, Zhenghao Chen, Pang W. Koh, and Andrew Y. Ng. 2011. Learning deep energy models. In Proceedings of the International Conference on Machine Learning.1105\u20131112."},{"key":"e_1_3_1_17_2","first-page":"234","volume-title":"Proceedings of the International Conference on Medical Image Computing and Computer Assisted Intervention.","author":"Ronneberger Olaf","year":"2015","unstructured":"Olaf Ronneberger, Philipp Fischer, and Thomas Brox. 2015. U-Net: Convolutional networks for biomedical image segmentation. In Proceedings of the International Conference on Medical Image Computing and Computer Assisted Intervention.234\u2013241."},{"key":"e_1_3_1_18_2","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Watson Daniel","year":"2021","unstructured":"Daniel Watson, William Chan, Jonathan Ho, and Mohammad Norouzi. 2021. Learning fast samplers for diffusion models by differentiating through sample quality. In Proceedings of the International Conference on Learning Representations."},{"key":"e_1_3_1_19_2","first-page":"16784","volume-title":"Proceedings of the International Conference on Machine Learning.","author":"Nichol Alex","year":"2021","unstructured":"Alex Nichol, Prafulla Dhariwal, Aditya Ramesh, Pranav Shyam, Pamela Mishkin, Bob McGrew, Ilya Sutskever, and Mark Chen. 2021. GLIDE: Towards photorealistic image generation and editing with text-guided diffusion models. In Proceedings of the International Conference on Machine Learning.16784\u201316804."},{"key":"e_1_3_1_20_2","first-page":"12533","volume-title":"Proceedings of the International Conference on Neural Information Processing Systems","volume":"34","author":"Sinha Abhishek","year":"2021","unstructured":"Abhishek Sinha, Jiaming Song, Chenlin Meng, and Stefano Ermon. 2021. D2C: Diffusion-decoding models for few-shot conditional generation. In Proceedings of the International Conference on Neural Information Processing Systems, Vol. 34. 12533\u201312548."},{"key":"e_1_3_1_21_2","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Bao Fan","year":"2022","unstructured":"Fan Bao, Chongxuan Li, Jun Zhu, and Bo Zhang. 2022. Analytic-DPM: An analytic estimate of the optimal reverse variance in diffusion probabilistic models. In Proceedings of the International Conference on Learning Representations."},{"key":"e_1_3_1_22_2","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Dockhorn Tim","year":"2022","unstructured":"Tim Dockhorn, Arash Vahdat, and Karsten Kreis. 2022. Score-based generative modeling with critically-damped Langevin diffusion. In Proceedings of the International Conference on Learning Representations."},{"key":"e_1_3_1_23_2","first-page":"18208","volume-title":"Proceedings of the International Conference on Computer Vision and Pattern Recognition.","author":"Avrahami Omri","year":"2022","unstructured":"Omri Avrahami, Dani Lischinski, and Ohad Fried. 2022. Blended diffusion for text-driven editing of natural images. In Proceedings of the International Conference on Computer Vision and Pattern Recognition.18208\u201318218."},{"key":"e_1_3_1_24_2","article-title":"Hierarchical text-conditional image generation with clip latents","author":"Ramesh Aditya","year":"2022","unstructured":"Aditya Ramesh, Prafulla Dhariwal, Alex Nichol, Casey Chu, and Mark Chen. 2022. Hierarchical text-conditional image generation with clip latents. arXiv:2204.06125 (2022).","journal-title":"arXiv:2204.06125"},{"key":"e_1_3_1_25_2","first-page":"423","volume-title":"Proceedings of the European Conference on Computer Vision.","author":"Liu Nan","year":"2022","unstructured":"Nan Liu, Shuang Li, Yilun Du, Antonio Torralba, and Joshua B. Tenenbaum. 2022. Compositional visual generation with composable diffusion models. In Proceedings of the European Conference on Computer Vision.423\u2013439."},{"key":"e_1_3_1_26_2","first-page":"12955","volume-title":"Proceedings of the International Conference on Neural Information Processing Systems","volume":"34","author":"Daniels Max","year":"2021","unstructured":"Max Daniels, Tyler Maunu, and Paul Hand. 2021. Score-based generative neural networks for large-scale optimal transport. In Proceedings of the International Conference on Neural Information Processing Systems, Vol. 34. 12955\u201312965."},{"key":"e_1_3_1_27_2","first-page":"12413","volume-title":"Proceedings of the International Conference on Computer Vision and Pattern Recognition.","author":"Chung Hyungjin","year":"2022","unstructured":"Hyungjin Chung, Byeongsu Sim, and Jong Chul Ye. 2022. Come-closer-diffuse-faster: Accelerating conditional diffusion models for inverse problems through stochastic contraction. In Proceedings of the International Conference on Computer Vision and Pattern Recognition.12413\u201312422."},{"key":"e_1_3_1_28_2","first-page":"3518","volume-title":"Proceedings of the International Conference on Neural Information Processing Systems","volume":"34","author":"Esser Patrick","year":"2021","unstructured":"Patrick Esser, Robin Rombach, Andreas Blattmann, and Bjorn Ommer. 2021. ImageBART: Bidirectional context with multinomial diffusion for autoregressive image synthesis. In Proceedings of the International Conference on Neural Information Processing Systems, Vol. 34. 3518\u20133532."},{"key":"e_1_3_1_29_2","first-page":"11461","volume-title":"Proceedings of the International Conference on Computer Vision and Pattern Recognition.","author":"Lugmayr Andreas","year":"2022","unstructured":"Andreas Lugmayr, Martin Danelljan, Andres Romero, Fisher Yu, Radu Timofte, and Luc Van Gool. 2022. Repaint: Inpainting using denoising diffusion probabilistic models. In Proceedings of the International Conference on Computer Vision and Pattern Recognition.11461\u201311471."},{"key":"e_1_3_1_30_2","first-page":"17981","volume-title":"Proceedings of the International Conference on Neural Information Processing Systems","volume":"34","author":"Austin Jacob","year":"2021","unstructured":"Jacob Austin, Daniel D. Johnson, Jonathan Ho, Daniel Tarlow, and Rianne Van Den Berg. 2021. Structured denoising diffusion models in discrete state-spaces. In Proceedings of the International Conference on Neural Information Processing Systems, Vol. 34. 17981\u201317993."},{"key":"e_1_3_1_31_2","first-page":"12454","volume-title":"Proceedings of the International Conference on Neural Information Processing Systems","volume":"34","author":"Hoogeboom Emiel","year":"2021","unstructured":"Emiel Hoogeboom, Didrik Nielsen, Priyank Jaini, Patrick Forr\u00e9, and Max Welling. 2021. Argmax flows and multinomial diffusion: Learning categorical distributions. In Proceedings of the International Conference on Neural Information Processing Systems, Vol. 34. 12454\u201312465."},{"key":"e_1_3_1_32_2","first-page":"4328","volume-title":"Proceedings of the International Conference on Neural Information Processing Systems","volume":"35","author":"Li Xiang","year":"2022","unstructured":"Xiang Li, John Thickstun, Ishaan Gulrajani, Percy S. Liang, and Tatsunori B. Hashimoto. 2022. Diffusion-LM improves controllable text generation. In Proceedings of the International Conference on Neural Information Processing Systems, Vol. 35. 4328\u20134343."},{"key":"e_1_3_1_33_2","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Savinov Nikolay","year":"2021","unstructured":"Nikolay Savinov, Junyoung Chung, Mikolaj Binkowski, Erich Elsen, and Aaron van den Oord. 2021. Step-unrolled denoising autoencoders for text generation. In Proceedings of the International Conference on Learning Representations."},{"key":"e_1_3_1_34_2","first-page":"25702","volume-title":"Proceedings of the International Conference on Machine Learning.","author":"Yu Peiyu","year":"2022","unstructured":"Peiyu Yu, Sirui Xie, Xiaojian Ma, Baoxiong Jia, Bo Pang, Ruiqi Gao, Yixin Zhu, Song-Chun Zhu, and Ying Nian Wu. 2022. Latent diffusion energy-based model for interpretable text modeling. In Proceedings of the International Conference on Machine Learning.25702\u201325720."},{"key":"e_1_3_1_35_2","first-page":"21051","volume-title":"Proceedings of the International Conference on Machine Learning.","author":"Lin Zhenghao","year":"2023","unstructured":"Zhenghao Lin, Yeyun Gong, Yelong Shen, Tong Wu, Zhihao Fan, Chen Lin, Nan Duan, and Weizhu Chen. 2023. Text generation with diffusion language models: A pre-training approach with continuous paragraph denoise. In Proceedings of the International Conference on Machine Learning.21051\u201321064."},{"key":"e_1_3_1_36_2","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Chen Nanxin","year":"2020","unstructured":"Nanxin Chen, Yu Zhang, Heiga Zen, Ron J. Weiss, Mohammad Norouzi, and William Chan. 2020. WaveGrad: Estimating gradients for waveform generation. In Proceedings of the International Conference on Learning Representations."},{"key":"e_1_3_1_37_2","first-page":"8599","volume-title":"Proceedings of the International Conference on Machine Learning.","author":"Popov Vadim","year":"2021","unstructured":"Vadim Popov, Ivan Vovk, Vladimir Gogoryan, Tasnima Sadekova, and Mikhail Kudinov. 2021. Grad-TTS: A diffusion probabilistic model for text-to-speech. In Proceedings of the International Conference on Machine Learning.8599\u20138608."},{"key":"e_1_3_1_38_2","first-page":"20908","volume-title":"Proceedings of the International Conference on Computer Vision and Pattern Recognition.","author":"Xu Jiale","year":"2023","unstructured":"Jiale Xu, Xintao Wang, Weihao Cheng, Yan-Pei Cao, Ying Shan, Xiaohu Qie, and Shenghua Gao. 2023. Dream3D: Zero-shot text-to-3D synthesis using 3D shape prior and text-to-image diffusion models. In Proceedings of the International Conference on Computer Vision and Pattern Recognition.20908\u201320918."},{"key":"e_1_3_1_39_2","first-page":"1","volume-title":"Proceedings of the IEEE Wireless Commununications Network Conference.","author":"Truong Vu Tuan","year":"2024","unstructured":"Vu Tuan Truong and Long Bao Le. 2024. Text-guided real-world-to-3D generative models with real-time rendering on mobile devices. In Proceedings of the IEEE Wireless Commununications Network Conference.1\u20136."},{"key":"e_1_3_1_40_2","article-title":"DreamFusion: Text-to-3D using 2D diffusion","author":"Poole Ben","year":"2022","unstructured":"Ben Poole, Ajay Jain, Jonathan T. Barron, and Ben Mildenhall. 2022. DreamFusion: Text-to-3D using 2D diffusion. arXiv:2209.14988 (2022).","journal-title":"arXiv:2209.14988"},{"key":"e_1_3_1_41_2","first-page":"300","volume-title":"Proceedings of the International Conference on Computer Vision and Pattern Recognition.","author":"Lin Chen-Hsuan","year":"2023","unstructured":"Chen-Hsuan Lin, Jun Gao, Luming Tang, Towaki Takikawa, Xiaohui Zeng, Xun Huang, Karsten Kreis, Sanja Fidler, Ming-Yu Liu, and Tsung-Yi Lin. 2023. Magic3D: High-resolution text-to-3D content creation. In Proceedings of the International Conference on Computer Vision and Pattern Recognition.300\u2013309."},{"key":"e_1_3_1_42_2","first-page":"19740","volume-title":"Proceedings of the International Conference on Computer Vision.","author":"Haque Ayaan","year":"2023","unstructured":"Ayaan Haque, Matthew Tancik, Alexei A. Efros, Aleksander Holynski, and Angjoo Kanazawa. 2023. Instruct-NeRF2NeRF: Editing 3D scenes with instructions. In Proceedings of the International Conference on Computer Vision.19740\u201319750."},{"key":"e_1_3_1_43_2","first-page":"2837","volume-title":"Proceedings of the International Conference on Computer Vision.","author":"Luo Shitong","year":"2021","unstructured":"Shitong Luo and Wei Hu. 2021. Diffusion probabilistic models for 3D point cloud generation. In Proceedings of the International Conference on Computer Vision.2837\u20132845."},{"key":"e_1_3_1_44_2","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Xu Minkai","year":"2021","unstructured":"Minkai Xu, Lantao Yu, Yang Song, Chence Shi, Stefano Ermon, and Jian Tang. 2021. GeoDiff: A geometric diffusion model for molecular conformation generation. In Proceedings of the International Conference on Learning Representations."},{"key":"e_1_3_1_45_2","first-page":"9754","volume-title":"Proceedings of the International Conference on Neural Information Processing Systems.","author":"Luo Shitong","year":"2022","unstructured":"Shitong Luo, Yufeng Su, Xingang Peng, Sheng Wang, Jian Peng, and Jianzhu Ma. 2022. Antigen-specific antibody design and optimization with diffusion-based generative models for protein structures. In Proceedings of the International Conference on Neural Information Processing Systems.9754\u20139767."},{"key":"e_1_3_1_46_2","first-page":"24804","volume-title":"Proceedings of the International Conference on Neural Information Processing Systems","volume":"34","author":"Tashiro Yusuke","year":"2021","unstructured":"Yusuke Tashiro, Jiaming Song, Yang Song, and Stefano Ermon. 2021. CSDI: Conditional score-based diffusion models for probabilistic time series imputation. In Proceedings of the International Conference on Neural Information Processing Systems, Vol. 34. 24804\u201324816."},{"key":"e_1_3_1_47_2","article-title":"ScoreGrad: Multivariate probabilistic time series forecasting with continuous energy-based generative models","author":"Yan Tijin","year":"2021","unstructured":"Tijin Yan, Hongwei Zhang, Tong Zhou, Yufeng Zhan, and Yuanqing Xia. 2021. ScoreGrad: Multivariate probabilistic time series forecasting with continuous energy-based generative models. arXiv:2106.10121 (2021).","journal-title":"arXiv:2106.10121"},{"key":"e_1_3_1_48_2","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Rasul Kashif","year":"2020","unstructured":"Kashif Rasul, Abdul-Saboor Sheikh, Ingmar Schuster, Urs Bergmann, and Roland Vollgraf. 2020. Multivariate probabilistic time series forecasting via conditioned normalizing flows. In Proceedings of the International Conference on Learning Representations."},{"issue":"4","key":"e_1_3_1_49_2","article-title":"Estimation of non-normalized statistical models by score matching.","volume":"6","author":"Hyv\u00e4rinen Aapo","year":"2005","unstructured":"Aapo Hyv\u00e4rinen and Peter Dayan. 2005. Estimation of non-normalized statistical models by score matching. J. Mach. Learn. Res. 6, 4 (2005), 695\u2013709.","journal-title":"J. Mach. Learn. Res."},{"issue":"7","key":"e_1_3_1_50_2","doi-asserted-by":"crossref","first-page":"1661","DOI":"10.1162\/NECO_a_00142","article-title":"A connection between score matching and denoising autoencoders","volume":"23","author":"Vincent Pascal","year":"2011","unstructured":"Pascal Vincent. 2011. A connection between score matching and denoising autoencoders. Neural Comput. 23, 7 (2011), 1661\u20131674.","journal-title":"Neural Comput."},{"issue":"3","key":"e_1_3_1_51_2","doi-asserted-by":"crossref","first-page":"313","DOI":"10.1016\/0304-4149(82)90051-5","article-title":"Reverse-time diffusion equation models","volume":"12","author":"Anderson Brian D. O.","year":"1982","unstructured":"Brian D. O. Anderson. 1982. Reverse-time diffusion equation models. Stoch. Process. Appl. 12, 3 (1982), 313\u2013326.","journal-title":"Stoch. Process. Appl."},{"key":"e_1_3_1_52_2","volume-title":"Proceedings of the International Conference on Neural Information Processing Systems","volume":"30","author":"Vaswani Ashish","year":"2017","unstructured":"Ashish Vaswani, Noam Shazeer, Niki Parmar, Jakob Uszkoreit, Llion Jones, Aidan N. Gomez, \u0141ukasz Kaiser, and Illia Polosukhin. 2017. Attention is all you need. In Proceedings of the International Conference on Neural Information Processing Systems, Vol. 30."},{"issue":"4","key":"e_1_3_1_53_2","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3626235","article-title":"Diffusion models: A comprehensive survey of methods and applications","volume":"56","author":"Yang Ling","year":"2023","unstructured":"Ling Yang, Zhilong Zhang, Yang Song, Shenda Hong, Runsheng Xu, Yue Zhao, Wentao Zhang, Bin Cui, and Ming-Hsuan Yang. 2023. Diffusion models: A comprehensive survey of methods and applications. ACM Comput. Surv. 56, 4 (2023), 1\u201339.","journal-title":"ACM Comput. Surv."},{"key":"e_1_3_1_54_2","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2024.3361474"},{"key":"e_1_3_1_55_2","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2023.3261988"},{"key":"e_1_3_1_56_2","article-title":"Diffusion models in NLP: A survey","author":"Zou Hao","year":"2023","unstructured":"Hao Zou, Zae Myung Kim, and Dongyeop Kang. 2023. Diffusion models in NLP: A survey. arXiv:2305.14671 (2023).","journal-title":"arXiv:2305.14671"},{"key":"e_1_3_1_57_2","doi-asserted-by":"crossref","first-page":"102846","DOI":"10.1016\/j.media.2023.102846","article-title":"Diffusion models in medical imaging: A comprehensive survey","author":"Kazerouni Amirhossein","year":"2023","unstructured":"Amirhossein Kazerouni, Ehsan Khodapanah Aghdam, Moein Heidari, Reza Azad, Mohsen Fayyaz, Ilker Hacihaliloglu, and Dorit Merhof. 2023. Diffusion models in medical imaging: A comprehensive survey. Med. Image Anal. 88 (2023), 102846.","journal-title":"Med. Image Anal."},{"key":"e_1_3_1_58_2","first-page":"1","article-title":"Diffusion models for time-series applications: A survey","author":"Lin Lequan","year":"2023","unstructured":"Lequan Lin, Zhengkun Li, Ruikun Li, Xuliang Li, and Junbin Gao. 2023. Diffusion models for time-series applications: A survey. Front. Inf. Technol. Electron. Eng. 25 (2023), 1\u201323.","journal-title":"Front. Inf. Technol. Electron. Eng."},{"key":"e_1_3_1_59_2","article-title":"Diffusion models for reinforcement learning: A survey","author":"Zhu Zhengbang","year":"2023","unstructured":"Zhengbang Zhu, Hanye Zhao, Haoran He, Yichao Zhong, Shenyu Zhang, Haoquan Guo, Tingting Chen, and Weinan Zhang. 2023. Diffusion models for reinforcement learning: A survey. arXiv:2311.01223 (2023).","journal-title":"arXiv:2311.01223"},{"key":"e_1_3_1_60_2","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2024.3400011"},{"key":"e_1_3_1_61_2","doi-asserted-by":"publisher","DOI":"10.1109\/MWC.009.2300165"},{"key":"e_1_3_1_62_2","doi-asserted-by":"publisher","DOI":"10.1109\/MNET.006.2300223"},{"key":"e_1_3_1_63_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3386058"},{"key":"e_1_3_1_64_2","first-page":"4015","volume-title":"Proceedings of the International Conference on Computer Vision and Pattern Recognition.","author":"Chou Sheng-Yen","year":"2023","unstructured":"Sheng-Yen Chou, Pin-Yu Chen, and Tsung-Yi Ho. 2023. How to backdoor diffusion models? In Proceedings of the International Conference on Computer Vision and Pattern Recognition.4015\u20134024."},{"key":"e_1_3_1_65_2","first-page":"21169","volume-title":"Proceedings of the AAAI Conference on Artificial Intelligence","volume":"38","author":"Huang Yihao","year":"2024","unstructured":"Yihao Huang, Felix Juefei-Xu, Qing Guo, Jie Zhang, Yutong Wu, Ming Hu, Tianlin Li, Geguang Pu, and Yang Liu. 2024. Personalization as a shortcut for few-shot backdoor attack against text-to-image diffusion models. In Proceedings of the AAAI Conference on Artificial Intelligence, Vol. 38. 21169\u201321178."},{"key":"e_1_3_1_66_2","first-page":"4584","volume-title":"Proceedings of the International Conference on Computer Vision.","author":"Struppek Lukas","year":"2023","unstructured":"Lukas Struppek, Dominik Hintersdorf, and Kristian Kersting. 2023. RickRolling the artist: Injecting backdoors into text encoders for text-to-image synthesis. In Proceedings of the International Conference on Computer Vision.4584\u20134596."},{"key":"e_1_3_1_67_2","first-page":"4035","volume-title":"Proceedings of the International Conference on Computer Vision and Pattern Recognition.","author":"Chen Weixin","year":"2023","unstructured":"Weixin Chen, Dawn Song, and Bo Li. 2023. TrojDiff: Trojan attacks on diffusion models with diverse targets. In Proceedings of the International Conference on Computer Vision and Pattern Recognition.4035\u20134044."},{"key":"e_1_3_1_68_2","volume-title":"Proceedings of the International Conference on Neural Information Processing Systems","volume":"36","author":"Chou Sheng-Yen","year":"2024","unstructured":"Sheng-Yen Chou, Pin-Yu Chen, and Tsung-Yi Ho. 2024. VillanDiffusion: A unified backdoor attack framework for diffusion models. In Proceedings of the International Conference on Neural Information Processing Systems, Vol. 36."},{"key":"e_1_3_1_69_2","volume-title":"Proceedings of the International Conference on Neural Information Processing Systems.","author":"Wang Haonan","year":"2023","unstructured":"Haonan Wang, Qianli Shen, Yao Tong, Yang Zhang, and Kenji Kawaguchi. 2023. The stronger the diffusion model, the easier the backdoor: Data poisoning to induce copyright breaches without adjusting finetuning pipeline. In Proceedings of the International Conference on Neural Information Processing Systems."},{"key":"e_1_3_1_70_2","volume-title":"Proceedings of the International Conference on Neural Information Processing Systems.","author":"Pan Zhuoshi","year":"2023","unstructured":"Zhuoshi Pan, Yuguang Yao, Gaowen Liu, Bingquan Shen, H. Vicky Zhao, Ramana Rao Kompella, and Sijia Liu. 2023. From Trojan horses to castle walls: Unveiling bilateral backdoor effects in diffusion models. In Proceedings of the International Conference on Neural Information Processing Systems."},{"key":"e_1_3_1_71_2","first-page":"1577","volume-title":"Proceedings of the ACM International Conference on Multimedia.","author":"Zhai Shengfang","year":"2023","unstructured":"Shengfang Zhai, Yinpeng Dong, Qingni Shen, Shi Pu, Yuejian Fang, and Hang Su. 2023. Text-to-image diffusion models can be easily backdoored through multimodal data poisoning. In Proceedings of the ACM International Conference on Multimedia.1577\u20131587."},{"key":"e_1_3_1_72_2","article-title":"Learnable invisible backdoor for diffusion models","author":"Li Sen","year":"2023","unstructured":"Sen Li, Junchi Ma, and Minhao Cheng. 2023. Learnable invisible backdoor for diffusion models. OpenReview (2023). https:\/\/openreview.net\/forum?id=scFfMOOGD8","journal-title":"OpenReview"},{"key":"e_1_3_1_73_2","first-page":"29894","volume-title":"Proceedings of the International Conference on Machine Learning.","author":"Salman Hadi","year":"2023","unstructured":"Hadi Salman, Alaa Khaddaj, Guillaume Leclerc, Andrew Ilyas, and Aleksander Madry. 2023. Raising the cost of malicious AI-powered image editing. In Proceedings of the International Conference on Machine Learning.29894\u201329918."},{"key":"e_1_3_1_74_2","first-page":"2116","volume-title":"Proceedings of the International Conference on Computer Vision.","author":"Le Thanh Van","year":"2023","unstructured":"Thanh Van Le, Hao Phung, Thuan Hoang Nguyen, Quan Dao, Ngoc N. Tran, and Anh Tran. 2023. Anti-DreamBooth: Protecting users from personalized text-to-image synthesis. In Proceedings of the International Conference on Computer Vision.2116\u20132127."},{"key":"e_1_3_1_75_2","first-page":"6791","volume-title":"Proceedings of the AAAI Conference on Artificial Intelligence","volume":"38","author":"Yu Hongwei","year":"2024","unstructured":"Hongwei Yu, Jiansheng Chen, Xinlong Ding, Yudong Zhang, Ting Tang, and Huimin Ma. 2024. Step vulnerability guided mean fluctuation adversarial attack against conditional diffusion models. In Proceedings of the AAAI Conference on Artificial Intelligence, Vol. 38. 6791\u20136799."},{"key":"e_1_3_1_76_2","first-page":"2187","volume-title":"Proceedings of the USENIX Security Symposium.","author":"Shan Shawn","year":"2023","unstructured":"Shawn Shan, Jenna Cryan, Emily Wenger, Haitao Zheng, Rana Hanocka, and Ben Y. Zhao. 2023. Glaze: Protecting artists from style mimicry by text-to-image models. In Proceedings of the USENIX Security Symposium.2187\u20132204."},{"key":"e_1_3_1_77_2","article-title":"On the robustness of latent diffusion models","author":"Zhang Jianping","year":"2023","unstructured":"Jianping Zhang, Zhuoer Xu, Shiwen Cui, Changhua Meng, Weibin Wu, and Michael R. Lyu. 2023. On the robustness of latent diffusion models. arXiv:2306.08257 (2023).","journal-title":"arXiv:2306.08257"},{"key":"e_1_3_1_78_2","first-page":"7737","article-title":"MMA-Diffusion: Multimodal attack on diffusion models","author":"Yang Yijun","year":"2024","unstructured":"Yijun Yang, Ruiyuan Gao, Xiaosen Wang, Nan Xu, and Qiang Xu. 2024. MMA-Diffusion: Multimodal attack on diffusion models. In Proceedings of the International Conference on Computer Vision and Pattern Recognition.7737\u20137746.","journal-title":"Proceedings of the International Conference on Computer Vision and Pattern Recognition."},{"key":"e_1_3_1_79_2","first-page":"123","volume-title":"Proceedings of the Symposium on Security and Privacy","author":"Yang Yuchen","year":"2024","unstructured":"Yuchen Yang, Bo Hui, Haolin Yuan, Neil Gong, and Yinzhi Cao. 2024. SneakyPrompt: Jailbreaking text-to-image generative models. In Proceedings of the Symposium on Security and Privacy. 123\u2013123."},{"key":"e_1_3_1_80_2","first-page":"2384","volume-title":"Proceedings of the International Conference on Computer Vision and Pattern Recognition.","author":"Zhuang Haomin","year":"2023","unstructured":"Haomin Zhuang, Yihua Zhang, and Sijia Liu. 2023. A pilot study of query-free adversarial attack against stable diffusion. In Proceedings of the International Conference on Computer Vision and Pattern Recognition.2384\u20132391."},{"key":"e_1_3_1_81_2","article-title":"Evaluating the robustness of text-to-image diffusion models against real-world attacks","author":"Gao Hongcheng","year":"2023","unstructured":"Hongcheng Gao, Hao Zhang, Yinpeng Dong, and Zhijie Deng. 2023. Evaluating the robustness of text-to-image diffusion models against real-world attacks. arXiv:2306.13103 (2023).","journal-title":"arXiv:2306.13103"},{"key":"e_1_3_1_82_2","article-title":"Revealing vulnerabilities in stable diffusion via targeted attacks","author":"Zhang Chenyu","year":"2024","unstructured":"Chenyu Zhang, Lanjun Wang, and Anan Liu. 2024. Revealing vulnerabilities in stable diffusion via targeted attacks. arXiv:2401.08725 (2024).","journal-title":"arXiv:2401.08725"},{"key":"e_1_3_1_83_2","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Liu Qihao","year":"2023","unstructured":"Qihao Liu, Adam Kortylewski, Yutong Bai, Song Bai, and Alan Yuille. 2023. Discovering failure modes of text-guided diffusion models via adversarial search. In Proceedings of the International Conference on Learning Representations."},{"key":"e_1_3_1_84_2","first-page":"20585","volume-title":"Proceedings of the International Conference on Computer Vision and Pattern Recognition.","author":"Liu Han","year":"2023","unstructured":"Han Liu, Yuhao Wu, Shixuan Zhai, Bo Yuan, and Ning Zhang. 2023. RIATIG: Reliable and imperceptible adversarial text-to-image generation with natural prompts. In Proceedings of the International Conference on Computer Vision and Pattern Recognition.20585\u201320594."},{"key":"e_1_3_1_85_2","first-page":"983","volume-title":"Proceedings of the International Joint Conference on Artificial Intelligence.","author":"Kou Ziyi","year":"2023","unstructured":"Ziyi Kou, Shichao Pei, Yijun Tian, and Xiangliang Zhang. 2023. Character as pixels: A controllable prompt adversarial attacking framework for black-box text guided image generation models. In Proceedings of the International Joint Conference on Artificial Intelligence.983\u2013990."},{"key":"e_1_3_1_86_2","article-title":"To generate or not? Safety-driven unlearned diffusion models are still easy to generate unsafe images... for now","author":"Zhang Yimeng","year":"2023","unstructured":"Yimeng Zhang, Jinghan Jia, Xin Chen, Aochuan Chen, Yihua Zhang, Jiancheng Liu, Ke Ding, and Sijia Liu. 2023. To generate or not? Safety-driven unlearned diffusion models are still easy to generate unsafe images... for now. arXiv:2310.11868 (2023).","journal-title":"arXiv:2310.11868"},{"key":"e_1_3_1_87_2","first-page":"20763","volume-title":"Proceedings of the International Conference on Machine Learning.","author":"Liang Chumeng","year":"2023","unstructured":"Chumeng Liang, Xiaoyu Wu, Yang Hua, Jiaru Zhang, Yiming Xue, Tao Song, Zhengui Xue, Ruhui Ma, and Haibing Guan. 2023. Adversarial example does good: Preventing painting imitation from diffusion models via adversarial examples. In Proceedings of the International Conference on Machine Learning.20763\u201320786."},{"key":"e_1_3_1_88_2","article-title":"Mist: Towards improved adversarial examples for diffusion models","author":"Liang Chumeng","year":"2023","unstructured":"Chumeng Liang and Xiaoyu Wu. 2023. Mist: Towards improved adversarial examples for diffusion models. arXiv:2305.12683 (2023).","journal-title":"arXiv:2305.12683"},{"key":"e_1_3_1_89_2","first-page":"24420","volume-title":"Proceedings of the International Conference on Computer Vision and Pattern Recognition.","author":"Zhu Peifei","year":"2024","unstructured":"Peifei Zhu, Tsubasa Takahashi, and Hirokatsu Kataoka. 2024. Watermark-embedded adversarial examples for copyright protection against diffusion models. In Proceedings of the International Conference on Computer Vision and Pattern Recognition.24420\u201324430."},{"key":"e_1_3_1_90_2","article-title":"A change of heart: Backdoor attacks on security-centric diffusion models","author":"Li Changjiang","year":"2023","unstructured":"Changjiang Li, Ren Pang, Bochuan Cao, Jinghui Chen, and Ting Wang. 2023. A change of heart: Backdoor attacks on security-centric diffusion models. OpenReview (2023). https:\/\/openreview.net\/forum?id=Gf4KZIqLHD","journal-title":"OpenReview"},{"key":"e_1_3_1_91_2","volume-title":"Proceedings of the International Conference on Neural Information Processing Systems","volume":"36","author":"Kang Mintong","year":"2024","unstructured":"Mintong Kang, Dawn Song, and Bo Li. 2024. DiffAttack: Evasion attacks against diffusion-based adversarial purification. In Proceedings of the International Conference on Neural Information Processing Systems, Vol. 36."},{"key":"e_1_3_1_92_2","article-title":"Understanding diffusion models: A unified perspective","author":"Luo Calvin","year":"2022","unstructured":"Calvin Luo. 2022. Understanding diffusion models: A unified perspective. arXiv:2208.11970 (2022).","journal-title":"arXiv:2208.11970"},{"key":"e_1_3_1_93_2","first-page":"574","volume-title":"Proceedings of the Uncertainty in Artificial Intelligence Conference.","author":"Song Yang","year":"2020","unstructured":"Yang Song, Sahaj Garg, Jiaxin Shi, and Stefano Ermon. 2020. Sliced score matching: A scalable approach to density and score estimation. In Proceedings of the Uncertainty in Artificial Intelligence Conference.574\u2013584."},{"key":"e_1_3_1_94_2","first-page":"19175","volume-title":"Proceedings of the International Conference on Neural Information Processing Systems","volume":"33","author":"Pang Tianyu","year":"2020","unstructured":"Tianyu Pang, Kun Xu, Chongxuan Li, Yang Song, Stefano Ermon, and Jun Zhu. 2020. Efficient learning of generative models via finite-difference score matching. In Proceedings of the International Conference on Neural Information Processing Systems, Vol. 33. 19175\u201319188."},{"key":"e_1_3_1_95_2","article-title":"Backdoor learning: A survey","author":"Li Yiming","year":"2022","unstructured":"Yiming Li, Yong Jiang, Zhifeng Li, and Shu-Tao Xia. 2022. Backdoor learning: A survey. IEEE Trans. Neural Netw. Learn. Syst. 35, 1 (2022), 5\u201322.","journal-title":"IEEE Trans. Neural Netw. Learn. Syst."},{"key":"e_1_3_1_96_2","article-title":"Towards deep learning models resistant to adversarial attacks","author":"Madry Aleksander","year":"2017","unstructured":"Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu. 2017. Towards deep learning models resistant to adversarial attacks. arXiv:1706.06083 (2017).","journal-title":"arXiv:1706.06083"},{"key":"e_1_3_1_97_2","article-title":"Adversarial attacks on neural network policies","author":"Huang Sandy","year":"2017","unstructured":"Sandy Huang, Nicolas Papernot, Ian Goodfellow, Yan Duan, and Pieter Abbeel. 2017. Adversarial attacks on neural network policies. arXiv:1702.02284 (2017).","journal-title":"arXiv:1702.02284"},{"key":"e_1_3_1_98_2","doi-asserted-by":"crossref","first-page":"14410","DOI":"10.1109\/ACCESS.2018.2807385","article-title":"Threat of adversarial attacks on deep learning in computer vision: A survey","volume":"6","author":"Akhtar Naveed","year":"2018","unstructured":"Naveed Akhtar and Ajmal Mian. 2018. Threat of adversarial attacks on deep learning in computer vision: A survey. IEEE Access 6 (2018), 14410\u201314430.","journal-title":"IEEE Access"},{"key":"e_1_3_1_99_2","first-page":"3","volume-title":"Proceedings of the IEEE Symposium on Security and Privacy","author":"Shokri Reza","year":"2017","unstructured":"Reza Shokri, Marco Stronati, Congzheng Song, and Vitaly Shmatikov. 2017. Membership inference attacks against machine learning models. In Proceedings of the IEEE Symposium on Security and Privacy. 3\u201318."},{"key":"e_1_3_1_100_2","article-title":"ML-leaks: Model and data independent membership inference attacks and defenses on machine learning models","author":"Salem Ahmed","year":"2018","unstructured":"Ahmed Salem, Yang Zhang, Mathias Humbert, Pascal Berrang, Mario Fritz, and Michael Backes. 2018. ML-leaks: Model and data independent membership inference attacks and defenses on machine learning models. arXiv:1806.01246 (2018).","journal-title":"arXiv:1806.01246"},{"key":"e_1_3_1_101_2","first-page":"268","volume-title":"Proceedings of the IEEE Computer Secururity Foundations Symposium.","author":"Yeom Samuel","year":"2018","unstructured":"Samuel Yeom, Irene Giacomelli, Matt Fredrikson, and Somesh Jha. 2018. Privacy risk in machine learning: Analyzing the connection to overfitting. In Proceedings of the IEEE Computer Secururity Foundations Symposium.268\u2013282."},{"key":"e_1_3_1_102_2","first-page":"5","volume-title":"Proceedings of the ACM Conference on Data and Application Security and Privacy","author":"Li Jiacheng","year":"2021","unstructured":"Jiacheng Li, Ninghui Li, and Bruno Ribeiro. 2021. Membership inference attacks and defenses in classification models. In Proceedings of the ACM Conference on Data and Application Security and Privacy. 5\u201316."},{"key":"e_1_3_1_103_2","first-page":"3093","volume-title":"Proceedings of the ACM SIGSAC Conference on Computer and Communications Security.","author":"Ye Jiayuan","year":"2022","unstructured":"Jiayuan Ye, Aadyaa Maddi, Sasi Kumar Murakonda, Vincent Bindschaedler, and Reza Shokri. 2022. Enhanced membership inference attacks against machine learning models. In Proceedings of the ACM SIGSAC Conference on Computer and Communications Security.3093\u20133106."},{"key":"e_1_3_1_104_2","first-page":"2085","volume-title":"Proceedings of the ACM SIGSAC Conference on Computer and Communications Security.","author":"Liu Yiyong","year":"2022","unstructured":"Yiyong Liu, Zhengyu Zhao, Michael Backes, and Yang Zhang. 2022. Membership inference attacks by exploiting loss trajectory. In Proceedings of the ACM SIGSAC Conference on Computer and Communications Security.2085\u20132098."},{"key":"e_1_3_1_105_2","first-page":"1897","volume-title":"Proceedings of the IEEE Symposium on Security and Privacy","author":"Carlini Nicholas","year":"2022","unstructured":"Nicholas Carlini, Steve Chien, Milad Nasr, Shuang Song, Andreas Terzis, and Florian Tramer. 2022. Membership inference attacks from first principles. In Proceedings of the IEEE Symposium on Security and Privacy. 1897\u20131914."},{"key":"e_1_3_1_106_2","article-title":"LOGAN: Membership inference attacks against generative models","author":"Hayes Jamie","year":"2017","unstructured":"Jamie Hayes, Luca Melis, George Danezis, and Emiliano De Cristofaro. 2017. LOGAN: Membership inference attacks against generative models. arXiv:1705.07663 (2017).","journal-title":"arXiv:1705.07663"},{"key":"e_1_3_1_107_2","article-title":"Monte Carlo and reconstruction membership inference attacks against generative models","author":"Hilprecht Benjamin","year":"2019","unstructured":"Benjamin Hilprecht, Martin H\u00e4rterich, and Daniel Bernau. 2019. Monte Carlo and reconstruction membership inference attacks against generative models. Proc. Priv. Enhanc. Technol. 2019, 4 (2019), 232\u2013249.","journal-title":"Proc. Priv. Enhanc. Technol."},{"key":"e_1_3_1_108_2","first-page":"343","volume-title":"Proceedings of the ACM SIGSAC Conference on Computer and Communications Security.","author":"Chen Dingfan","year":"2020","unstructured":"Dingfan Chen, Ning Yu, Yang Zhang, and Mario Fritz. 2020. GAN-leaks: A taxonomy of membership inference attacks against generative models. In Proceedings of the ACM SIGSAC Conference on Computer and Communications Security.343\u2013362."},{"key":"e_1_3_1_109_2","first-page":"2387","volume-title":"Proceedings of the ACM SIGSAC Conference on Computer and Communications Security.","author":"Hu Hailong","year":"2021","unstructured":"Hailong Hu and Jun Pang. 2021. Membership inference attacks against GANs by leveraging over-representation regions. In Proceedings of the ACM SIGSAC Conference on Computer and Communications Security.2387\u20132389."},{"key":"e_1_3_1_110_2","article-title":"privGAN: Protecting GANs from membership inference attacks at low cost to utility","author":"Mukherjee Sumit","year":"2021","unstructured":"Sumit Mukherjee, Yixi Xu, Anusua Trivedi, Nabajyoti Patowary, and Juan L. Ferres. 2021. privGAN: Protecting GANs from membership inference attacks at low cost to utility. Proc. Priv. Enhanc. Technol. 2021, 3 (2021), 142\u2013163.","journal-title":"Proc. Priv. Enhanc. Technol."},{"key":"e_1_3_1_111_2","article-title":"Membership inference attacks against text-to-image generation models","author":"Wu Yixin","year":"2022","unstructured":"Yixin Wu, Ning Yu, Zheng Li, Michael Backes, and Yang Zhang. 2022. Membership inference attacks against text-to-image generation models. OpenReview (2022). https:\/\/openreview.net\/forum?id=J41IW8Z7mE","journal-title":"OpenReview"},{"key":"e_1_3_1_112_2","first-page":"4839","volume-title":"Proceedings of the Winter Conference on Applications of Computer Vision.","author":"Zhang Minxing","year":"2024","unstructured":"Minxing Zhang, Ning Yu, Rui Wen, Michael Backes, and Yang Zhang. 2024. Generated distributions are all you need for membership inference attacks against generative models. In Proceedings of the Winter Conference on Applications of Computer Vision.4839\u20134849."},{"key":"e_1_3_1_113_2","article-title":"Black-box membership inference attacks against fine-tuned diffusion models","author":"Pang Yan","year":"2023","unstructured":"Yan Pang and Tianhao Wang. 2023. Black-box membership inference attacks against fine-tuned diffusion models. arXiv:2312.08207 (2023).","journal-title":"arXiv:2312.08207"},{"key":"e_1_3_1_114_2","article-title":"Towards black-box membership inference attack for diffusion models","author":"Li Jingwei","year":"2024","unstructured":"Jingwei Li, Jing Dong, Tianxing He, and Jingzhao Zhang. 2024. Towards black-box membership inference attack for diffusion models. arXiv:2405.20771 (2024).","journal-title":"arXiv:2405.20771"},{"key":"e_1_3_1_115_2","first-page":"8717","volume-title":"Proceedings of the International Conference on Machine Learning.","author":"Duan Jinhao","year":"2023","unstructured":"Jinhao Duan, Fei Kong, Shiqi Wang, Xiaoshuang Shi, and Kaidi Xu. 2023. Are diffusion models vulnerable to membership inference attacks? In Proceedings of the International Conference on Machine Learning.8717\u20138730."},{"key":"e_1_3_1_116_2","article-title":"Membership inference attacks on diffusion models via quantile regression","author":"Tang Shuai","year":"2023","unstructured":"Shuai Tang, Zhiwei Steven Wu, Sergul Aydore, Michael Kearns, and Aaron Roth. 2023. Membership inference attacks on diffusion models via quantile regression. arXiv:2312.05140 (2023).","journal-title":"arXiv:2312.05140"},{"key":"e_1_3_1_117_2","article-title":"An efficient membership inference attack for the diffusion model by proximal initialization","author":"Kong Fei","year":"2023","unstructured":"Fei Kong, Jinhao Duan, RuiPeng Ma, Hengtao Shen, Xiaofeng Zhu, Xiaoshuang Shi, and Kaidi Xu. 2023. An efficient membership inference attack for the diffusion model by proximal initialization. arXiv:2305.18355 (2023).","journal-title":"arXiv:2305.18355"},{"key":"e_1_3_1_118_2","article-title":"Membership inference on text-to-image diffusion models via conditional likelihood discrepancy","author":"Zhai Shengfang","year":"2024","unstructured":"Shengfang Zhai, Huanran Chen, Yinpeng Dong, Jiajun Li, Qingni Shen, Yansong Gao, Hang Su, and Yang Liu. 2024. Membership inference on text-to-image diffusion models via conditional likelihood discrepancy. arXiv:2405.14800 (2024).","journal-title":"arXiv:2405.14800"},{"key":"e_1_3_1_119_2","article-title":"Membership inference of diffusion models","author":"Hu Hailong","year":"2023","unstructured":"Hailong Hu and Jun Pang. 2023. Membership inference of diffusion models. arXiv:2301.09956 (2023).","journal-title":"arXiv:2301.09956"},{"key":"e_1_3_1_120_2","first-page":"5253","volume-title":"Proceedings of the USENIX Security Symposium.","author":"Carlini Nicolas","year":"2023","unstructured":"Nicolas Carlini, Jamie Hayes, Milad Nasr, Matthew Jagielski, Vikash Sehwag, Florian Tramer, Borja Balle, Daphne Ippolito, and Eric Wallace. 2023. Extracting training data from diffusion models. In Proceedings of the USENIX Security Symposium.5253\u20135270."},{"key":"e_1_3_1_121_2","first-page":"77","volume-title":"Proceedings of the IEEE Security and Privacy Workshops","author":"Matsumoto Tomoya","year":"2023","unstructured":"Tomoya Matsumoto, Takayuki Miura, and Naoto Yanai. 2023. Membership inference attacks against diffusion models. In Proceedings of the IEEE Security and Privacy Workshops. 77\u201383."},{"key":"e_1_3_1_122_2","first-page":"4860","volume-title":"Proceedings of the Winter Conference on Applications of Computer Vision.","author":"Dubi\u0144ski Jan","year":"2024","unstructured":"Jan Dubi\u0144ski, Antoni Kowalczuk, Stanis\u0142aw Pawlak, Przemyslaw Rokita, Tomasz Trzci\u0144ski, and Pawe\u0142 Morawiecki. 2024. Towards more realistic membership inference attacks on large diffusion models. In Proceedings of the Winter Conference on Applications of Computer Vision.4860\u20134869."},{"key":"e_1_3_1_123_2","article-title":"White-box membership inference attacks against diffusion models","author":"Pang Yan","year":"2023","unstructured":"Yan Pang, Tianhao Wang, Xuhui Kang, Mengdi Huai, and Yang Zhang. 2023. White-box membership inference attacks against diffusion models. arXiv:2308.06405 (2023).","journal-title":"arXiv:2308.06405"},{"key":"e_1_3_1_124_2","article-title":"BadNets: Identifying vulnerabilities in the machine learning model supply chain","author":"Gu Tianyu","year":"2017","unstructured":"Tianyu Gu, Brendan Dolan-Gavitt, and Siddharth Garg. 2017. BadNets: Identifying vulnerabilities in the machine learning model supply chain. arXiv:1708.06733 (2017).","journal-title":"arXiv:1708.06733"},{"key":"e_1_3_1_125_2","first-page":"22500","volume-title":"Proceedings of the International Conference on Computer Vision and Pattern Recognition.","author":"Ruiz Nataniel","year":"2023","unstructured":"Nataniel Ruiz, Yuanzhen Li, Varun Jampani, Yael Pritch, Michael Rubinstein, and Kfir Aberman. 2023. DreamBooth: Fine tuning text-to-image diffusion models for subject-driven generation. In Proceedings of the International Conference on Computer Vision and Pattern Recognition.22500\u201322510."},{"key":"e_1_3_1_126_2","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Gal Rinon","year":"2022","unstructured":"Rinon Gal, Yuval Alaluf, Yuval Atzmon, Or Patashnik, Amit Haim Bermano, Gal Chechik, and Daniel Cohen-Or. 2022. An image is worth one word: Personalizing text-to-image generation using textual inversion. In Proceedings of the International Conference on Learning Representations."},{"key":"e_1_3_1_127_2","first-page":"3403","volume-title":"Proceedings of the ACM Conference on Computer and Communications Security.","author":"Qu Yiting","year":"2023","unstructured":"Yiting Qu, Xinyue Shen, Xinlei He, Michael Backes, Savvas Zannettou, and Yang Zhang. 2023. Unsafe diffusion: On the generation of unsafe images and hateful memes from text-to-image models. In Proceedings of the ACM Conference on Computer and Communications Security.3403\u20133417."},{"key":"e_1_3_1_128_2","volume-title":"Proceedings of the International Conference on Neural Information Processing Systems.","author":"Chen Bryant","year":"2019","unstructured":"Bryant Chen, Wilka Carvalho, Nathalie Baracaldo, Heiko Ludwig, Benjamin Edwards, Taesung Lee, Ian Molloy, and Biplav Srivastava. 2019. Detecting backdoor attacks on deep neural networks by activation clustering. In Proceedings of the International Conference on Neural Information Processing Systems."},{"key":"e_1_3_1_129_2","first-page":"141","volume-title":"Proceedings of the IEEE Symposium on Security and Privacy","author":"Bourtoule Lucas","year":"2021","unstructured":"Lucas Bourtoule, Varun Chandrasekaran, Christopher A. Choquette-Choo, Hengrui Jia, Adelin Travers, Baiwu Zhang, David Lie, and Nicolas Papernot. 2021. Machine unlearning. In Proceedings of the IEEE Symposium on Security and Privacy.141\u2013159."},{"key":"e_1_3_1_130_2","first-page":"463","volume-title":"Proceedings of the IEEE Symposium on Security and Privacy","author":"Cao Yinzhi","year":"2015","unstructured":"Yinzhi Cao and Junfeng Yang. 2015. Towards making systems forget with machine unlearning. In Proceedings of the IEEE Symposium on Security and Privacy. 463\u2013480."},{"key":"e_1_3_1_131_2","first-page":"18075","article-title":"Remember what you want to forget: Algorithms for machine unlearning","volume":"34","author":"Sekhari Ayush","year":"2021","unstructured":"Ayush Sekhari, Jayadev Acharya, Gautam Kamath, and Ananda Theertha Suresh. 2021. Remember what you want to forget: Algorithms for machine unlearning. In Proceedings of the International Conference on Neural Information Processing Systems, Vol. 34. 18075\u201318086.","journal-title":"Proceedings of the International Conference on Neural Information Processing Systems,"},{"key":"e_1_3_1_132_2","article-title":"Unsupervised representation learning with deep convolutional generative adversarial networks","author":"Radford Alec","year":"2015","unstructured":"Alec Radford, Luke Metz, and Soumith Chintala. 2015. Unsupervised representation learning with deep convolutional generative adversarial networks. arXiv:1511.06434 (2015).","journal-title":"arXiv:1511.06434"},{"key":"e_1_3_1_133_2","first-page":"12888","volume-title":"Proceedings of the International Conference on Machine Learning.","author":"Li Junnan","year":"2022","unstructured":"Junnan Li, Dongxu Li, Caiming Xiong, and Steven Hoi. 2022. BLIP: Bootstrapping language-image pre-training for unified vision-language understanding and generation. In Proceedings of the International Conference on Machine Learning.12888\u201312900."},{"key":"e_1_3_1_134_2","first-page":"770","volume-title":"Proceedings of the International Conference on Computer Vision and Pattern Recognition.","author":"He Kaiming","year":"2016","unstructured":"Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun. 2016. Deep residual learning for image recognition. In Proceedings of the International Conference on Computer Vision and Pattern Recognition.770\u2013778."},{"key":"e_1_3_1_135_2","first-page":"19730","volume-title":"Proceedings of the International Conference on Machine Learning.","author":"Li Junnan","year":"2023","unstructured":"Junnan Li, Dongxu Li, Silvio Savarese, and Steven Hoi. 2023. BLIP-2: Bootstrapping language-image pre-training with frozen image encoders and large language models. In Proceedings of the International Conference on Machine Learning.19730\u201319742."},{"key":"e_1_3_1_136_2","first-page":"213","volume-title":"Proceedings of the European Conference on Computer Vision.","author":"Carion Nicolas","year":"2020","unstructured":"Nicolas Carion, Francisco Massa, Gabriel Synnaeve, Nicolas Usunier, Alexander Kirillov, and Sergey Zagoruyko. 2020. End-to-end object detection with transformers. In Proceedings of the European Conference on Computer Vision.213\u2013229."},{"key":"e_1_3_1_137_2","article-title":"BEiT: BERT pre-training of image transformers","author":"Bao Hangbo","year":"2021","unstructured":"Hangbo Bao, Li Dong, Songhao Piao, and Furu Wei. 2021. BEiT: BERT pre-training of image transformers. arXiv:2106.08254 (2021).","journal-title":"arXiv:2106.08254"},{"key":"e_1_3_1_138_2","first-page":"10347","volume-title":"Proceedings of the International Conference on Machine Learning.","author":"Touvron Hugo","year":"2021","unstructured":"Hugo Touvron, Matthieu Cord, Matthijs Douze, Francisco Massa, Alexandre Sablayrolles, and Herv\u00e9 J\u00e9gou. 2021. Training data-efficient image transformers & distillation through attention. In Proceedings of the International Conference on Machine Learning.10347\u201310357."},{"key":"e_1_3_1_139_2","first-page":"785","volume-title":"Proceedings of the International Conference on Knowledge Discovery and Data Mining.","author":"Chen Tianqi","year":"2016","unstructured":"Tianqi Chen and Carlos Guestrin. 2016. XGBoost: A scalable tree boosting system. In Proceedings of the International Conference on Knowledge Discovery and Data Mining.785\u2013794."},{"key":"e_1_3_1_140_2","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Li Yige","year":"2021","unstructured":"Yige Li, Xixiang Lyu, Nodens Koren, Lingjuan Lyu, Bo Li, and Xingjun Ma. 2021. Neural attention distillation: Erasing backdoor triggers from deep neural networks. In Proceedings of the International Conference on Learning Representations."},{"key":"e_1_3_1_141_2","first-page":"273","volume-title":"Proceedings of the International Symposium on Research on Attacks, Intrusions, and Defenses","author":"Liu Kang","year":"2018","unstructured":"Kang Liu, Brendan Dolan-Gavitt, and Siddharth Garg. 2018. Fine-pruning: Defending against backdooring attacks on deep neural networks. In Proceedings of the International Symposium on Research on Attacks, Intrusions, and Defenses. 273\u2013294."},{"key":"e_1_3_1_142_2","first-page":"10847","volume-title":"Proceedings of the AAAI Conference on Artificial Intelligence","volume":"38","author":"An Shengwei","year":"2024","unstructured":"Shengwei An, Sheng-Yen Chou, Kaiyuan Zhang, Qiuling Xu, Guanhong Tao, Guangyu Shen, Siyuan Cheng, Shiqing Ma, Pin-Yu Chen, Tsung-Yi Ho et\u00a0al. 2024. Elijah: Eliminating backdoors injected in diffusion models via distribution shift. In Proceedings of the AAAI Conference on Artificial Intelligence, Vol. 38. 10847\u201310855."},{"key":"e_1_3_1_143_2","volume-title":"Proceedings of the International Conference on Neural Information Processing Systems.","author":"An Shengwei","year":"2023","unstructured":"Shengwei An, Sheng-Yen Chou, Kaiyuan Zhang, Qiuling Xu, Guanhong Tao, Guangyu Shen, Siyuan Cheng, Shiqing Ma, Pin-Yu Chen, Tsung-Yi Ho et\u00a0al. 2023. How to remove backdoors in diffusion models? In Proceedings of the International Conference on Neural Information Processing Systems."},{"key":"e_1_3_1_144_2","volume-title":"Proceedings of the International Conference on Communications.","author":"Truong Tuan Vu","year":"2025","unstructured":"Tuan Vu Truong and Long Bao Le. 2025. PureDiffusion: Using backdoor to counter backdoor in generative diffusion models. In Proceedings of the International Conference on Communications."},{"key":"e_1_3_1_145_2","article-title":"UFID: A unified framework for input-level backdoor detection on diffusion models","author":"Guan Zihan","year":"2024","unstructured":"Zihan Guan, Mengxuan Hu, Sheng Li, and Anil Vullikanti. 2024. UFID: A unified framework for input-level backdoor detection on diffusion models. arXiv:2404.01101 (2024).","journal-title":"arXiv:2404.01101"},{"key":"e_1_3_1_146_2","article-title":"DisDet: Exploring detectability of backdoor attack on diffusion models","author":"Sui Yang","year":"2024","unstructured":"Yang Sui, Huy Phan, Jinqi Xiao, Tianfang Zhang, Zijie Tang, Cong Shi, Yan Wang, Yingying Chen, and Bo Yuan. 2024. DisDet: Exploring detectability of backdoor attack on diffusion models. arXiv:2402.02739 (2024).","journal-title":"arXiv:2402.02739"},{"key":"e_1_3_1_147_2","first-page":"2426","volume-title":"Proceedings of the International Conference on Computer Vision.","author":"Gandikota Rohit","year":"2023","unstructured":"Rohit Gandikota, Joanna Materzynska, Jaden Fiotto-Kaufman, and David Bau. 2023. Erasing concepts from diffusion models. In Proceedings of the International Conference on Computer Vision.2426\u20132436."},{"key":"e_1_3_1_148_2","first-page":"22691","volume-title":"Proceedings of the International Conference on Computer Vision.","author":"Kumari Nupur","year":"2023","unstructured":"Nupur Kumari, Bingliang Zhang, Sheng-Yu Wang, Eli Shechtman, Richard Zhang, and Jun-Yan Zhu. 2023. Ablating concepts in text-to-image diffusion models. In Proceedings of the International Conference on Computer Vision.22691\u201322702."},{"key":"e_1_3_1_149_2","first-page":"1755","volume-title":"Proceedings of the International Conference on Computer Vision and Pattern Recognition.","author":"Zhang Gong","year":"2024","unstructured":"Gong Zhang, Kai Wang, Xingqian Xu, Zhangyang Wang, and Humphrey Shi. 2024. Forget-me-not: Learning to forget in text-to-image diffusion models. In Proceedings of the International Conference on Computer Vision and Pattern Recognition.1755\u20131764."},{"key":"e_1_3_1_150_2","first-page":"21143","volume-title":"Proceedings of the AAAI Conference on Artificial Intelligence","volume":"38","author":"Hong Seunghoo","year":"2024","unstructured":"Seunghoo Hong, Juhun Lee, and Simon S. Woo. 2024. All but one: Surgical concept erasing with model preservation in text-to-image diffusion models. In Proceedings of the AAAI Conference on Artificial Intelligence, Vol. 38. 21143\u201321151."},{"key":"e_1_3_1_151_2","first-page":"22522","volume-title":"Proceedings of the International Conference on Computer Vision and Pattern Recognition.","author":"Schramowski Patrick","year":"2023","unstructured":"Patrick Schramowski, Manuel Brack, Bj\u00f6rn Deiseroth, and Kristian Kersting. 2023. Safe latent diffusion: Mitigating inappropriate degeneration in diffusion models. In Proceedings of the International Conference on Computer Vision and Pattern Recognition.22522\u201322531."},{"key":"e_1_3_1_152_2","article-title":"EraseDiff: Erasing data influence in diffusion models","author":"Wu Jing","year":"2024","unstructured":"Jing Wu, Trung Le, Munawar Hayat, and Mehrtash Harandi. 2024. EraseDiff: Erasing data influence in diffusion models. arXiv:2401.05779 (2024).","journal-title":"arXiv:2401.05779"},{"key":"e_1_3_1_153_2","article-title":"Erasing concepts from text-to-image diffusion models with few-shot unlearning","author":"Fuchi Masane","year":"2024","unstructured":"Masane Fuchi and Tomohiro Takagi. 2024. Erasing concepts from text-to-image diffusion models with few-shot unlearning. arXiv:2405.07288 (2024).","journal-title":"arXiv:2405.07288"},{"key":"e_1_3_1_154_2","first-page":"8900","volume-title":"Proceedings of the ACM International Conference on Multimedia.","author":"Ni Zixuan","year":"2023","unstructured":"Zixuan Ni, Longhui Wei, Jiacheng Li, Siliang Tang, Yueting Zhuang, and Qi Tian. 2023. Degeneration-tuning: Using scrambled grid shield unwanted concepts from stable diffusion. In Proceedings of the ACM International Conference on Multimedia.8900\u20138909."},{"key":"e_1_3_1_155_2","article-title":"GuardT2I: Defending text-to-image models from adversarial prompts","author":"Yang Yijun","year":"2024","unstructured":"Yijun Yang, Ruiyuan Gao, Xiao Yang, Jianyuan Zhong, and Qiang Xu. 2024. GuardT2I: Defending text-to-image models from adversarial prompts. arXiv:2403.01446 (2024).","journal-title":"arXiv:2403.01446"},{"key":"e_1_3_1_156_2","article-title":"Pruning for robust concept erasing in diffusion models","author":"Yang Tianyun","year":"2024","unstructured":"Tianyun Yang, Juan Cao, and Chang Xu. 2024. Pruning for robust concept erasing in diffusion models. arXiv:2405.16534 (2024).","journal-title":"arXiv:2405.16534"},{"key":"e_1_3_1_157_2","unstructured":"Guihong Li Hsiang Hsu Chun-Fu Chen and Radu Marculescu. 2024. Machine unlearning for image-to-image generative models. arXiv:2402.00351 (2024)."},{"key":"e_1_3_1_158_2","volume-title":"Proceedings of the International Conference on Neural Information Processing Systems","volume":"36","author":"Heng Alvin","year":"2024","unstructured":"Alvin Heng and Harold Soh. 2024. Selective amnesia: A continual learning approach to forgetting in deep generative models. In Proceedings of the International Conference on Neural Information Processing Systems, Vol. 36."},{"key":"e_1_3_1_159_2","volume-title":"Proceedings of the International Conference on Neural Information Processing Systems.","author":"Rando Javier","year":"2022","unstructured":"Javier Rando, Daniel Paleka, David Lindner, Lennart Heim, and Florian Tram\u00e8r. 2022. Red-teaming the stable diffusion safety filter. In Proceedings of the International Conference on Neural Information Processing Systems."},{"key":"e_1_3_1_160_2","first-page":"7559","volume-title":"Proceedings of the International Conference on Computer Vision and Pattern Recognition.","author":"Lyu Mengyao","year":"2024","unstructured":"Mengyao Lyu, Yuhong Yang, Haiwen Hong, Hui Chen, Xuan Jin, Yuan He, Hui Xue, Jungong Han, and Guiguang Ding. 2024. One-dimensional adapter to rule them all: Concepts diffusion models and erasing applications. In Proceedings of the International Conference on Computer Vision and Pattern Recognition.7559\u20137568."},{"key":"e_1_3_1_161_2","article-title":"Receler: Reliable concept erasing of text-to-image diffusion models via lightweight erasers","author":"Huang Chi-Pin","year":"2023","unstructured":"Chi-Pin Huang, Kai-Po Chang, Chung-Ting Tsai, Yung-Hsuan Lai, and Yu-Chiang Frank Wang. 2023. Receler: Reliable concept erasing of text-to-image diffusion models via lightweight erasers. arXiv:2311.17717 (2023).","journal-title":"arXiv:2311.17717"},{"key":"e_1_3_1_162_2","article-title":"Unlearning concepts in diffusion model via concept domain correction and concept preserving gradient","author":"Wu Yongliang","year":"2024","unstructured":"Yongliang Wu, Shiji Zhou, Mingzhuo Yang, Lianzhe Wang, Wenbo Zhu, Heng Chang, Xiao Zhou, and Xu Yang. 2024. Unlearning concepts in diffusion model via concept domain correction and concept preserving gradient. arXiv:2405.15304 (2024).","journal-title":"arXiv:2405.15304"},{"key":"e_1_3_1_163_2","article-title":"RACE: Robust adversarial concept erasure for secure text-to-image diffusion model","author":"Kim Changhoon","year":"2024","unstructured":"Changhoon Kim, Kyle Min, and Yezhou Yang. 2024. RACE: Robust adversarial concept erasure for secure text-to-image diffusion model. arXiv:2405.16341 (2024).","journal-title":"arXiv:2405.16341"},{"key":"e_1_3_1_164_2","article-title":"Prompting4Debugging: Red-teaming text-to-image diffusion models by finding problematic prompts","author":"Chin Zhi-Yi","year":"2023","unstructured":"Zhi-Yi Chin, Chieh-Ming Jiang, Ching-Chun Huang, Pin-Yu Chen, and Wei-Chen Chiu. 2023. Prompting4Debugging: Red-teaming text-to-image diffusion models by finding problematic prompts. arXiv:2309.06135 (2023).","journal-title":"arXiv:2309.06135"},{"key":"e_1_3_1_165_2","article-title":"Improved regularization of convolutional neural networks with cutout","author":"DeVries Terrance","year":"2017","unstructured":"Terrance DeVries and Graham W. Taylor. 2017. Improved regularization of convolutional neural networks with cutout. arXiv:1708.04552 (2017).","journal-title":"arXiv:1708.04552"},{"key":"e_1_3_1_166_2","first-page":"702","volume-title":"Proceedings of the Conference on Computer Vision and Pattern Recognition Workshops","author":"Cubuk Ekin D.","year":"2020","unstructured":"Ekin D. Cubuk, Barret Zoph, Jonathon Shlens, and Quoc V. Le. 2020. RandAugment: Practical automated data augmentation with a reduced search space. In Proceedings of the Conference on Computer Vision and Pattern Recognition Workshops. 702\u2013703."},{"key":"e_1_3_1_167_2","doi-asserted-by":"crossref","first-page":"265","DOI":"10.1007\/11681878_14","volume-title":"Proceedings of the Theory of Cryptography Conference.","author":"Dwork Cynthia","year":"2006","unstructured":"Cynthia Dwork, Frank McSherry, Kobbi Nissim, and Adam Smith. 2006. Calibrating noise to sensitivity in private data analysis. In Proceedings of the Theory of Cryptography Conference.265\u2013284."},{"key":"e_1_3_1_168_2","first-page":"1","volume-title":"Proceedings of the International Conference on Theory and Applications of Models of Computation.","author":"Dwork Cynthia","year":"2008","unstructured":"Cynthia Dwork. 2008. Differential privacy: A survey of results. In Proceedings of the International Conference on Theory and Applications of Models of Computation.1\u201319."},{"key":"e_1_3_1_169_2","first-page":"308","volume-title":"Proceedings of the ACM SIGSAC Conference on Computer and Communications Security.","author":"Abadi Martin","year":"2016","unstructured":"Martin Abadi, Andy Chu, Ian Goodfellow, H. Brendan McMahan, Ilya Mironov, Kunal Talwar, and Li Zhang. 2016. Deep learning with differential privacy. In Proceedings of the ACM SIGSAC Conference on Computer and Communications Security.308\u2013318."},{"key":"e_1_3_1_170_2","article-title":"Privacy distillation: Reducing re-identification risk of multimodal diffusion models","author":"Fernandez Virginia","year":"2023","unstructured":"Virginia Fernandez, Pedro Sanchez, Walter Hugo Lopez Pinaya, Grzegorz Jacenk\u00f3w, Sotirios A. Tsaftaris, and Jorge Cardoso. 2023. Privacy distillation: Reducing re-identification risk of multimodal diffusion models. arXiv:2306.01322 (2023).","journal-title":"arXiv:2306.01322"},{"key":"e_1_3_1_171_2","article-title":"LoRA: Low-rank adaptation of large language models","author":"Hu Edward J.","year":"2021","unstructured":"Edward J. Hu, Yelong Shen, Phillip Wallis, Zeyuan Allen-Zhu, Yuanzhi Li, Shean Wang, Lu Wang, and Weizhu Chen. 2021. LoRA: Low-rank adaptation of large language models. arXiv:2106.09685 (2021).","journal-title":"arXiv:2106.09685"}],"container-title":["ACM Computing Surveys"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3721479","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3721479","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T01:09:48Z","timestamp":1750295388000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3721479"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,4,3]]},"references-count":170,"journal-issue":{"issue":"8","published-print":{"date-parts":[[2025,8,31]]}},"alternative-id":["10.1145\/3721479"],"URL":"https:\/\/doi.org\/10.1145\/3721479","relation":{},"ISSN":["0360-0300","1557-7341"],"issn-type":[{"value":"0360-0300","type":"print"},{"value":"1557-7341","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,4,3]]},"assertion":[{"value":"2024-08-12","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-02-25","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-04-03","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}