{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,11]],"date-time":"2026-05-11T22:44:17Z","timestamp":1778539457511,"version":"3.51.4"},"publisher-location":"New York, NY, USA","reference-count":45,"publisher":"ACM","content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,11,10]]},"DOI":"10.1145\/3746252.3761283","type":"proceedings-article","created":{"date-parts":[[2025,11,7]],"date-time":"2025-11-07T23:59:18Z","timestamp":1762559958000},"page":"4357-4367","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":1,"title":["Antelope: Potent and Concealed Jailbreak Attack Strategy"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0005-5730-7534","authenticated-orcid":false,"given":"Xin","family":"Zhao","sequence":"first","affiliation":[{"name":"State Key Laboratory of Cyberspace Security Defense, Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China and School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0362-847X","authenticated-orcid":false,"given":"Xiaojun","family":"Chen","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Cyberspace Security Defense, Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0003-4074-3976","authenticated-orcid":false,"given":"Haoyu","family":"Gao","sequence":"additional","affiliation":[{"name":"College of Computing, Georgia Institute of Technology, Atlanta, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2025,11,10]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"James Betker Gabriel Goh Li Jing TimBrooks Jianfeng Wang Linjie Li LongOuyang JuntangZhuang JoyceLee YufeiGuo WesamManassra PrafullaDhariwal CaseyChu YunxinJiao and Aditya Ramesh. 2023. Improving Image Generation with Better Captions. https:\/\/api.semanticscholar.org\/CorpusID:264403242"},{"key":"e_1_3_2_1_2_1","volume-title":"Advances in Neural Information Processing Systems 33: Annual Conference on Neural Information Processing Systems","author":"Brown Tom B.","year":"2020","unstructured":"Tom B. Brown, Benjamin Mann, Nick Ryder, Melanie Subbiah, Jared Kaplan, Prafulla Dhariwal, Arvind Neelakantan, and Pranav Shyam. 2020. Language Models are Few-Shot Learners. In Advances in Neural Information Processing Systems 33: Annual Conference on Neural Information Processing Systems 2020."},{"key":"e_1_3_2_1_3_1","unstructured":"Ruchika Chavhan Da Li and Timothy Hospedales. 2024. ConceptPrune: Concept Editing in Diffusion Models via Skilled Neuron Pruning. arXiv:2405.19237 [cs.CV] https:\/\/arxiv.org\/abs\/2405.19237"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.00391"},{"key":"e_1_3_2_1_5_1","unstructured":"Yimo Deng and Huangxun Chen. 2024. Divide-and-Conquer Attack: Harnessing the Power of LLM to Bypass Safety Filters of Text-to-Image Models. arXiv:2312.07130 [cs.AI] https:\/\/arxiv.org\/abs\/2312.07130"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/N19-1423"},{"key":"e_1_3_2_1_7_1","unstructured":"Alexey Dosovitskiy Lucas Beyer Alexander Kolesnikov Dirk Weissenborn Xiaohua Zhai Thomas Unterthiner Mostafa Dehghani Matthias Minderer Georg Heigold Sylvain Gelly Jakob Uszkoreit and Neil Houlsby. 2021. An Image is Worth 16x16 Words: Transformers for Image Recognition at Scale. arXiv:2010.11929 [cs.CV] https:\/\/arxiv.org\/abs\/2010.11929"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00230"},{"key":"e_1_3_2_1_9_1","unstructured":"Sensen Gao Xiaojun Jia Yihao Huang Ranjie Duan Jindong Gu Yang Liu and Qing Guo. 2024. RT-Attack: Jailbreaking Text-to-Image Models via Random Token. arXiv:2408.13896 [cs.CV] https:\/\/arxiv.org\/abs\/2408.13896"},{"key":"e_1_3_2_1_10_1","volume-title":"Sony Group Corporation, and Bosch Center","author":"He Yutong","year":"2024","unstructured":"Yutong He, Alexander Robey, Naoki Murata, Yiding Jiang, Joshua Williams, George J Pappas, Hamed Hassani, Yuki Mitsufuji, Ruslan Salakhutdinov, J. Zico Kolter, AI Sony, Sony Group Corporation, and Bosch Center. 2024. Automated Black-box Prompt Engineering for Personalized Text-to-Image Generation. ArXiv, Vol. abs\/2403.19103 (2024). https:\/\/api.semanticscholar.org\/CorpusID:268732776"},{"key":"e_1_3_2_1_11_1","volume-title":"Denoising Diffusion Probabilistic Models. CoRR","author":"Ho Jonathan","year":"2020","unstructured":"Jonathan Ho, Ajay Jain, and Pieter Abbeel. 2020. Denoising Diffusion Probabilistic Models. CoRR, Vol. abs\/2006.11239 (2020). https:\/\/arxiv.org\/abs\/2006.11239"},{"key":"e_1_3_2_1_12_1","unstructured":"Yihao Huang Le Liang Tianlin Li Xiaojun Jia Run Wang Weikai Miao Geguang Pu and Yang Liu. 2024. Perception-guided Jailbreak against Text-to-Image Models. arXiv:2408.10848 [cs.CV] https:\/\/arxiv.org\/abs\/2408.10848"},{"key":"e_1_3_2_1_13_1","unstructured":"I2P. [n.d.]. Inappropriate Image Prompts. https:\/\/huggingface.co\/datasets\/AIML-TUDA\/i2p."},{"key":"e_1_3_2_1_14_1","unstructured":"Leonardo.Ai. 2023. Leonardo.Ai. https:\/\/leonardo.ai\/."},{"key":"e_1_3_2_1_15_1","unstructured":"Xinfeng Li Yuchen Yang Jiangyi Deng Chen Yan Yanjiao Chen Xiaoyu Ji and Wenyuan Xu. 2024. SafeGen: Mitigating Sexually Explicit Content Generation in Text-to-Image Models. In arXiv preprint arXiv:2404.06666."},{"key":"e_1_3_2_1_16_1","volume-title":"Groot: Adversarial Testing for Generative Text-to-Image Models with Tree-based Semantic Transformation. arXiv:2402.12100 [cs.CL]","author":"Liu Yi","year":"2024","unstructured":"Yi Liu, Guowei Yang, Gelei Deng, Feiyue Chen, Yuqi Chen, Ling Shi, Tianwei Zhang, and Yang Liu. 2024. Groot: Adversarial Testing for Generative Text-to-Image Models with Tree-based Semantic Transformation. arXiv:2402.12100 [cs.CL]"},{"key":"e_1_3_2_1_17_1","unstructured":"Jiachen Ma Anda Cao Zhiqing Xiao Jie Zhang Chao Ye and Junbo Zhao. 2024. Jailbreaking Prompt Attack: A Controllable Adversarial Attack against Diffusion Models. arXiv:2404.02928 [cs.CR] https:\/\/arxiv.org\/abs\/2404.02928"},{"key":"e_1_3_2_1_18_1","unstructured":"Aleksander Madry Aleksandar Makelov Ludwig Schmidt Dimitris Tsipras and Adrian Vladu. 2019. Towards Deep Learning Models Resistant to Adversarial Attacks. arXiv:1706.06083 [stat.ML] https:\/\/arxiv.org\/abs\/1706.06083"},{"key":"e_1_3_2_1_19_1","volume-title":"Jimmy Lei Ba, and Ruslan Salakhutdinov","author":"Mansimov Elman","year":"2016","unstructured":"Elman Mansimov, Emilio Parisotto, Jimmy Lei Ba, and Ruslan Salakhutdinov. 2016. Generating Images from Captions with Attention. arXiv:1511.02793 [cs.LG]"},{"key":"e_1_3_2_1_20_1","unstructured":"Midjourney. 2023. Midjourney. https:\/\/www.midjourney.com\/."},{"key":"e_1_3_2_1_21_1","volume-title":"GLIDE: Towards Photorealistic Image Generation and Editing with Text-Guided Diffusion Models. In International Conference on Machine Learning, ICML 2022","author":"Nichol Alexander Quinn","year":"2022","unstructured":"Alexander Quinn Nichol, Prafulla Dhariwal, Aditya Ramesh, Pranav Shyam, Pamela Mishkin, Bob McGrew, Ilya Sutskever, and Mark Chen. 2022. GLIDE: Towards Photorealistic Image Generation and Editing with Text-Guided Diffusion Models. In International Conference on Machine Learning, ICML 2022, 17-23 July 2022, Baltimore, Maryland, USA (Proceedings of Machine Learning Research). https:\/\/proceedings.mlr.press\/v162\/nichol22a.html"},{"key":"e_1_3_2_1_22_1","unstructured":"NudeNet. [n.d.]. NudeNet. https:\/\/github.com\/notAI-tech\/NudeNet."},{"key":"e_1_3_2_1_23_1","unstructured":"OpenAI. 2023. ChatGPT. https:\/\/chatgpt.com."},{"key":"e_1_3_2_1_24_1","volume-title":"Scalable Diffusion Models with Transformers. arXiv preprint arXiv:2212.09748","author":"Peebles William","year":"2022","unstructured":"William Peebles and Saining Xie. 2022. Scalable Diffusion Models with Transformers. arXiv preprint arXiv:2212.09748 (2022)."},{"key":"e_1_3_2_1_25_1","volume-title":"UPAM: Unified Prompt Attack in Text-to-Image Generation Models Against Both Textual Filters and Visual Checkers. arXiv:2405.11336 [cs.CV] https:\/\/arxiv.org\/abs\/2405.11336","author":"Peng Duo","year":"2024","unstructured":"Duo Peng, Qiuhong Ke, and Jun Liu. 2024. UPAM: Unified Prompt Attack in Text-to-Image Generation Models Against Both Textual Filters and Visual Checkers. arXiv:2405.11336 [cs.CV] https:\/\/arxiv.org\/abs\/2405.11336"},{"key":"e_1_3_2_1_26_1","volume-title":"Unsafe Diffusion: On the Generation of Unsafe Images and Hateful Memes From Text-To-Image Models. arXiv:2305.13873 [cs.CV]","author":"Qu Yiting","year":"2023","unstructured":"Yiting Qu, Xinyue Shen, Xinlei He, Michael Backes, Savvas Zannettou, and Yang Zhang. 2023. Unsafe Diffusion: On the Generation of Unsafe Images and Hateful Memes From Text-To-Image Models. arXiv:2305.13873 [cs.CV]"},{"key":"e_1_3_2_1_27_1","volume-title":"Learning Transferable Visual Models From Natural Language Supervision. In International Conference on Machine Learning. https:\/\/api.semanticscholar.org\/CorpusID:231591445","author":"Radford Alec","year":"2021","unstructured":"Alec Radford, Jong Wook Kim, Chris Hallacy, Aditya Ramesh, Gabriel Goh, Sandhini Agarwal, Girish Sastry, Amanda Askell, Pamela Mishkin, Jack Clark, Gretchen Krueger, and Ilya Sutskever. 2021. Learning Transferable Visual Models From Natural Language Supervision. In International Conference on Machine Learning. https:\/\/api.semanticscholar.org\/CorpusID:231591445"},{"key":"e_1_3_2_1_28_1","unstructured":"Aditya Ramesh Prafulla Dhariwal Alex Nichol Casey Chu and Mark Chen. 2022. Hierarchical Text-Conditional Image Generation with CLIP Latents. arXiv:2204.06125 [cs.CV]"},{"key":"e_1_3_2_1_29_1","volume-title":"Proceedings of the 38th International Conference on Machine Learning, ICML 2021","volume":"8831","author":"Ramesh Aditya","year":"2021","unstructured":"Aditya Ramesh, Mikhail Pavlov, Gabriel Goh, Scott Gray, Chelsea Voss, Alec Radford, Mark Chen, and Ilya Sutskever. 2021. Zero-Shot Text-to-Image Generation. In Proceedings of the 38th International Conference on Machine Learning, ICML 2021, 18-24 July 2021, Virtual Event (Proceedings of Machine Learning Research, Vol. 139), Marina Meila and Tong Zhang (Eds.). PMLR, 8821-8831. http:\/\/proceedings.mlr.press\/v139\/ramesh21a.html"},{"key":"e_1_3_2_1_30_1","unstructured":"Javier Rando Daniel Paleka David Lindner Lennart Heim and Florian Tram\u00e8r. 2022. Red-Teaming the Stable Diffusion Safety Filter. arXiv:2210.04610 [cs.AI]"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01042"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"crossref","unstructured":"Olaf Ronneberger Philipp Fischer and Thomas Brox. 2015. U-Net: Convolutional Networks for Biomedical Image Segmentation. arXiv:1505.04597 [cs.CV]","DOI":"10.1007\/978-3-319-24574-4_28"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"crossref","unstructured":"Patrick Schramowski Manuel Brack Bj\u00f6rn Deiseroth and Kristian Kersting. 2023. Safe Latent Diffusion: Mitigating Inappropriate Degeneration in Diffusion Models. arXiv:2211.05105 [cs.CV]","DOI":"10.1109\/CVPR52729.2023.02157"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/3531146.3533192"},{"key":"e_1_3_2_1_35_1","volume-title":"Denoising Diffusion Implicit Models. CoRR","author":"Song Jiaming","year":"2020","unstructured":"Jiaming Song, Chenlin Meng, and Stefano Ermon. 2020. Denoising Diffusion Implicit Models. CoRR, Vol. abs\/2010.02502 (2020). https:\/\/arxiv.org\/abs\/2010.02502"},{"key":"e_1_3_2_1_36_1","unstructured":"Yu-Lin Tsai Chia-Yi Hsu Chulin Xie Chih-Hsun Lin Jia-You Chen Bo Li Pin-Yu Chen Chia-Mu Yu and Chun-Ying Huang. 2024. Ring-A-Bell! How Reliable are Concept Removal Methods for Diffusion Models? arXiv:2310.10012 [cs.LG] https:\/\/arxiv.org\/abs\/2310.10012"},{"key":"e_1_3_2_1_37_1","volume-title":"CoRR","author":"Vaswani Ashish","year":"2017","unstructured":"Ashish Vaswani, Noam Shazeer, Niki Parmar, Jakob Uszkoreit, Llion Jones, Aidan N. Gomez, Lukasz Kaiser, and Illia Polosukhin. 2017. Attention Is All You Need. CoRR, Vol. abs\/1706.03762 (2017). http:\/\/arxiv.org\/abs\/1706.03762"},{"key":"e_1_3_2_1_38_1","volume-title":"On the Multi-modal Vulnerability of Diffusion Models","author":"Yang Dingcheng","unstructured":"Dingcheng Yang, Yang Bai, Xiaojun Jia, Yang Liu, Xiaochun Cao, and Wenjian Yu. 2024a. On the Multi-modal Vulnerability of Diffusion Models. In Trustworthy Multi-modal Foundation Models and AI Agents (TiFA)."},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.00739"},{"key":"e_1_3_2_1_40_1","unstructured":"Yijun Yang Ruiyuan Gao Xiao Yang Jianyuan Zhong and Qiang Xu. 2024c. GuardT2I: Defending Text-to-Image Models from Adversarial Prompts. arXiv:2403.01446 [cs.CV]"},{"key":"e_1_3_2_1_41_1","first-page":"897","volume-title":"SneakyPrompt: Jailbreaking Text-to-image Generative Models. 2024 IEEE Symposium on Security and Privacy (SP)","author":"Yang Yuchen","year":"2023","unstructured":"Yuchen Yang, Bo Hui, Haolin Yuan, Neil Zhenqiang Gong, and Yinzhi Cao. 2023. SneakyPrompt: Jailbreaking Text-to-image Generative Models. 2024 IEEE Symposium on Security and Privacy (SP) (2023), 897-912. https:\/\/api.semanticscholar.org\/CorpusID:265150147"},{"key":"e_1_3_2_1_42_1","volume-title":"Han Zhang, Ruoming Pang, James Qin, Alexander Ku, Yuanzhong Xu, Jason Baldridge, and Yonghui Wu.","author":"Yu Jiahui","year":"2021","unstructured":"Jiahui Yu, Xin Li, Jing Yu Koh, Han Zhang, Ruoming Pang, James Qin, Alexander Ku, Yuanzhong Xu, Jason Baldridge, and Yonghui Wu. 2021. Vector-quantized Image Modeling with Improved VQGAN. ArXiv, Vol. abs\/2110.04627 (2021). https:\/\/api.semanticscholar.org\/CorpusID:238582653"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"crossref","unstructured":"Yimeng Zhang Jinghan Jia Xin Chen Aochuan Chen Yihua Zhang Jiancheng Liu Ke Ding and Sijia Liu. 2024. To Generate or Not? Safety-Driven Unlearned Diffusion Models Are Still Easy To Generate Unsafe Images. .. For Now. arXiv:2310.11868 [cs.CV] https:\/\/arxiv.org\/abs\/2310.11868","DOI":"10.1007\/978-3-031-72998-0_22"},{"key":"e_1_3_2_1_44_1","volume-title":"CipherDM: Secure Three-Party Inference for Diffusion Model Sampling. In European Conference on Computer Vision. https:\/\/api.semanticscholar.org\/CorpusID:272524648","author":"Zhao Xin","year":"2024","unstructured":"Xin Zhao, Xiaojun Chen, Xudong Chen, He Li, Tingyu Fan, and Zhendong Zhao. 2024. CipherDM: Secure Three-Party Inference for Diffusion Model Sampling. In European Conference on Computer Vision. https:\/\/api.semanticscholar.org\/CorpusID:272524648"},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW59228.2023.00236"}],"event":{"name":"CIKM '25: The 34th ACM International Conference on Information and Knowledge Management","location":"Seoul Republic of Korea","acronym":"CIKM '25","sponsor":["SIGIR ACM Special Interest Group on Information Retrieval","SIGWEB ACM Special Interest Group on Hypertext, Hypermedia, and Web"]},"container-title":["Proceedings of the 34th ACM International Conference on Information and Knowledge Management"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3746252.3761283","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,12,12]],"date-time":"2025-12-12T00:25:45Z","timestamp":1765499145000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3746252.3761283"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,11,10]]},"references-count":45,"alternative-id":["10.1145\/3746252.3761283","10.1145\/3746252"],"URL":"https:\/\/doi.org\/10.1145\/3746252.3761283","relation":{},"subject":[],"published":{"date-parts":[[2025,11,10]]},"assertion":[{"value":"2025-11-10","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}