Fetching the paper…
Reading the bibliography…
Diffusion models (DMs) have achieved state-of-the-art performance on various generative tasks such as image synthesis, text-to-image, and text-guided image-to-image generation.
N. Carlini, S. Chien, M. Nasr, S. Song, A. Terzis, and F. Tramer, “Membership inference attacks from first principles,” in
1914
Earlier work this paper cites.
B. D. Anderson, “Reverse-time diffusion equation models,”
1982
Earlier work this paper cites.
A. Hyvärinen and P. Dayan, “Estimation of non-normalized statistical models by score matching.”
2005
Earlier work this paper cites.
C. Dwork, F. McSherry, K. Nissim, and A. Smith, “Calibrating noise to sensitivity in private data analysis,” in
2006
Earlier work this paper cites.
C. Dwork, “Differential privacy: A survey of results,” in
2008
Earlier work this paper cites.
A. Krizhevsky, G. Hinton
2009
Earlier work this paper cites.
J. Deng, W. Dong, R. Socher, L.-J. Li, K. Li, and L. Fei-Fei, “Imagenet: A large-scale hierarchical image database,” in
2009
Earlier work this paper cites.
J. Ngiam, Z. Chen, P. W. Koh, and A. Y. Ng, “Learning deep energy models,” in
2011
Earlier work this paper cites.
P. Vincent, “A connection between score matching and denoising autoencoders,”
2011
Earlier work this paper cites.
I. Goodfellow, J. Pouget-Abadie, M. Mirza, B. Xu, D. Warde-Farley, S. Ozair, A. Courville, and Y. Bengio, “Generative adversarial nets,” in
2014
Earlier work this paper cites.
D. P. Kingma and M. Welling, “Auto-encoding variational bayes,” in
2014
Earlier work this paper cites.
J. Sohl-Dickstein, E. Weiss, N. Maheswaranathan, and S. Ganguli, “Deep unsupervised learning using nonequilibrium thermodynamics,” in
2015
Earlier work this paper cites.
D. Rezende and S. Mohamed, “Variational inference with normalizing flows,” in
2015
Earlier work this paper cites.
O. Ronneberger, P. Fischer, and T. Brox, “U-net: Convolutional networks for biomedical image segmentation,” in
2015
Earlier work this paper cites.
Y. Cao and J. Yang, “Towards making systems forget with machine unlearning,” in
2015
Earlier work this paper cites.
2015
Earlier work this paper cites.
2015
Earlier work this paper cites.
Z. Liu, P. Luo, X. Wang, and X. Tang, “Deep learning face attributes in the wild,” in
2015
Earlier work this paper cites.
K. He, X. Zhang, S. Ren, and J. Sun, “Deep residual learning for image recognition,” in
2016
Earlier work this paper cites.
T. Chen and C. Guestrin, “Xgboost: A scalable tree boosting system,” in
2016
Earlier work this paper cites.
M. Abadi, A. Chu, I. Goodfellow, H. B. McMahan, I. Mironov, K. Talwar, and L. Zhang, “Deep learning with differential privacy,” in
2016
Earlier work this paper cites.
A. Vaswani, N. Shazeer, N. Parmar, J. Uszkoreit, L. Jones, A. N. Gomez, Ł. Kaiser, and I. Polosukhin, “Attention is all you need,” in
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
R. Shokri, M. Stronati, C. Song, and V. Shmatikov, “Membership inference attacks against machine learning models,” in
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
R. Krishna, Y. Zhu, O. Groth, J. Johnson, K. Hata, J. Kravitz, S. Chen, Y. Kalantidis, L.-J. Li, D. A. Shamma
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
T. DeVries and G. W. Taylor, “Improved regularization of convolutional neural networks with cutout,”
2017
Earlier work this paper cites.
N. Akhtar and A. Mian, “Threat of adversarial attacks on deep learning in computer vision: A survey,”
2018
Earlier work this paper cites.
2018
Earlier work this paper cites.
S. Yeom, I. Giacomelli, M. Fredrikson, and S. Jha, “Privacy risk in machine learning: Analyzing the connection to overfitting,” in
2018
Earlier work this paper cites.
K. Liu, B. Dolan-Gavitt, and S. Garg, “Fine-pruning: Defending against backdooring attacks on deep neural networks,” in
2018
Earlier work this paper cites.
Y. Song and S. Ermon, “Generative modeling by estimating gradients of the data distribution,” in
2019
Earlier work this paper cites.
B. Hilprecht, M. Härterich, and D. Bernau, “Monte carlo and reconstruction membership inference attacks against generative models,”
2019
Earlier work this paper cites.
B. Chen, W. Carvalho, N. Baracaldo, H. Ludwig, B. Edwards, T. Lee, I. Molloy, and B. Srivastava, “Detecting backdoor attacks on deep neural networks by activation clustering,” in
2019
Earlier work this paper cites.
J. Ho, A. Jain, and P. Abbeel, “Denoising diffusion probabilistic models,” in
2020
Earlier work this paper cites.
Y. Song and S. Ermon, “Improved techniques for training score-based generative models,” in
2020
Earlier work this paper cites.
N. Chen, Y. Zhang, H. Zen, R. J. Weiss, M. Norouzi, and W. Chan, “Wavegrad: Estimating gradients for waveform generation,” in
2020
Earlier work this paper cites.
K. Rasul, A.-S. Sheikh, I. Schuster, U. Bergmann, and R. Vollgraf, “Multivariate probabilistic time series forecasting via conditioned normalizing flows,” in
2020
Earlier work this paper cites.
Y. Song, S. Garg, J. Shi, and S. Ermon, “Sliced score matching: A scalable approach to density and score estimation,” in
2020
Earlier work this paper cites.
T. Pang, K. Xu, C. Li, Y. Song, S. Ermon, and J. Zhu, “Efficient learning of generative models via finite-difference score matching,” in
2020
Earlier work this paper cites.
D. Chen, N. Yu, Y. Zhang, and M. Fritz, “Gan-leaks: A taxonomy of membership inference attacks against generative models,” in
2020
Earlier work this paper cites.
N. Carion, F. Massa, G. Synnaeve, N. Usunier, A. Kirillov, and S. Zagoruyko, “End-to-end object detection with transformers,” in
2020
Earlier work this paper cites.
E. D. Cubuk, B. Zoph, J. Shlens, and Q. V. Le, “Randaugment: Practical automated data augmentation with a reduced search space,” in
2020
Earlier work this paper cites.
P. Dhariwal and A. Nichol, “Diffusion models beat gans on image synthesis,” in
2021
Earlier work this paper cites.
A. Q. Nichol and P. Dhariwal, “Improved denoising diffusion probabilistic models,” in
2021
Earlier work this paper cites.
J. Song, C. Meng, and S. Ermon, “Denoising diffusion implicit models,” in
2021
Earlier work this paper cites.
Y. Song, C. Durkan, I. Murray, and S. Ermon, “Maximum likelihood training of score-based diffusion models,” in
2021
Earlier work this paper cites.
Y. Song, J. Sohl-Dickstein, D. P. Kingma, A. Kumar, S. Ermon, and B. Poole, “Score-based generative modeling through stochastic differential equations,” in
2021
Earlier work this paper cites.
A. Vahdat, K. Kreis, and J. Kautz, “Score-based generative modeling in latent space,” in
2021
Earlier work this paper cites.
D. Watson, W. Chan, J. Ho, and M. Norouzi, “Learning fast samplers for diffusion models by differentiating through sample quality,” in
2021
Earlier work this paper cites.
A. Nichol, P. Dhariwal, A. Ramesh, P. Shyam, P. Mishkin, B. McGrew, I. Sutskever, and M. Chen, “Glide: Towards photorealistic image generation and editing with text-guided diffusion models,” in
2021
Earlier work this paper cites.
A. Sinha, J. Song, C. Meng, and S. Ermon, “D2c: Diffusion-decoding models for few-shot conditional generation,” in
2021
Earlier work this paper cites.
M. Daniels, T. Maunu, and P. Hand, “Score-based generative neural networks for large-scale optimal transport,” in
2021
Earlier work this paper cites.
P. Esser, R. Rombach, A. Blattmann, and B. Ommer, “Imagebart: Bidirectional context with multinomial diffusion for autoregressive image synthesis,” in
2021
Earlier work this paper cites.
J. Austin, D. D. Johnson, J. Ho, D. Tarlow, and R. Van Den Berg, “Structured denoising diffusion models in discrete state-spaces,” in
2021
Earlier work this paper cites.
E. Hoogeboom, D. Nielsen, P. Jaini, P. Forré, and M. Welling, “Argmax flows and multinomial diffusion: Learning categorical distributions,” in
2021
Earlier work this paper cites.
N. Savinov, J. Chung, M. Binkowski, E. Elsen, and A. v. d. Oord, “Step-unrolled denoising autoencoders for text generation,” in
2021
Cited alongside, same era.
V. Popov, I. Vovk, V. Gogoryan, T. Sadekova, and M. Kudinov, “Grad-tts: A diffusion probabilistic model for text-to-speech,” in
2021
Cited alongside, same era.
S. Luo and W. Hu, “Diffusion probabilistic models for 3d point cloud generation,” in
2021
Cited alongside, same era.
M. Xu, L. Yu, Y. Song, C. Shi, S. Ermon, and J. Tang, “Geodiff: A geometric diffusion model for molecular conformation generation,” in
2021
Cited alongside, same era.
Y. Tashiro, J. Song, Y. Song, and S. Ermon, “Csdi: Conditional score-based diffusion models for probabilistic time series imputation,” in
2021
Cited alongside, same era.
Y. Yang, R. Gao, X. Wang, N. Xu, and Q. Xu, “Mma-diffusion: Multimodal attack on diffusion models,”
2023
Later among the works it cites.
H. Zhuang, Y. Zhang, and S. Liu, “A pilot study of query-free adversarial attack against stable diffusion,” in
2023
Later among the works it cites.
2023
Later among the works it cites.
Q. Liu, A. Kortylewski, Y. Bai, S. Bai, and A. Yuille, “Discovering failure modes of text-guided diffusion models via adversarial search,” in
2023
Later among the works it cites.
H. Liu, Y. Wu, S. Zhai, B. Yuan, and N. Zhang, “Riatig: Reliable and imperceptible adversarial text-to-image generation with natural prompts,” in
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
2021
Cited alongside, same era.
J. Li, N. Li, and B. Ribeiro, “Membership inference attacks and defenses in classification models,” in
2021
Cited alongside, same era.
H. Hu and J. Pang, “Membership inference attacks against gans by leveraging over-representation regions,” in
2021
Cited alongside, same era.
S. Mukherjee, Y. Xu, A. Trivedi, N. Patowary, and J. L. Ferres, “privgan: Protecting gans from membership inference attacks at low cost to utility,”
2021
Cited alongside, same era.
L. Bourtoule, V. Chandrasekaran, C. A. Choquette-Choo, H. Jia, A. Travers, B. Zhang, D. Lie, and N. Papernot, “Machine unlearning,” in
2021
Cited alongside, same era.
A. Sekhari, J. Acharya, G. Kamath, and A. T. Suresh, “Remember what you want to forget: Algorithms for machine unlearning,”
2021
Cited alongside, same era.
2021
Cited alongside, same era.
2023
Later among the works it cites.
Z. Kou, S. Pei, Y. Tian, and X. Zhang, “Character as pixels: A controllable prompt adversarial attacking framework for black-box text guided image generation models,” in
2023
Later among the works it cites.
2023
Later among the works it cites.
C. Liang, X. Wu, Y. Hua, J. Zhang, Y. Xue, T. Song, Z. Xue, R. Ma, and H. Guan, “Adversarial example does good: preventing painting imitation from diffusion models via adversarial examples,” in
2023
Later among the works it cites.
C. Liang and X. Wu, “Mist: Towards improved adversarial examples for diffusion models,”
2023
Later among the works it cites.
C. Li, R. Pang, B. Cao, J. Chen, and T. Wang, “A change of heart: Backdoor attacks on security-centric diffusion models,” 2023
2023
Later among the works it cites.
Y. Pang and T. Wang, “Black-box membership inference attacks against fine-tuned diffusion models,”
2023
Later among the works it cites.
J. Duan, F. Kong, S. Wang, X. Shi, and K. Xu, “Are diffusion models vulnerable to membership inference attacks?” in
2023
Later among the works it cites.
2023
Later among the works it cites.
2023
Later among the works it cites.
H. Hu and J. Pang, “Membership inference of diffusion models,”
2023
Later among the works it cites.
N. Carlini, J. Hayes, M. Nasr, M. Jagielski, V. Sehwag, F. Tramer, B. Balle, D. Ippolito, and E. Wallace, “Extracting training data from diffusion models,” in
2023
Later among the works it cites.
T. Matsumoto, T. Miura, and N. Yanai, “Membership inference attacks against diffusion models,” in
2023
Later among the works it cites.
2023
Later among the works it cites.
N. Ruiz, Y. Li, V. Jampani, Y. Pritch, M. Rubinstein, and K. Aberman, “Dreambooth: Fine tuning text-to-image diffusion models for subject-driven generation,” in
2023
Later among the works it cites.
Y. Qu, X. Shen, X. He, M. Backes, S. Zannettou, and Y. Zhang, “Unsafe diffusion: On the generation of unsafe images and hateful memes from text-to-image models,” in
2023
Later among the works it cites.
J. Li, D. Li, S. Savarese, and S. Hoi, “Blip-2: Bootstrapping language-image pre-training with frozen image encoders and large language models,” in
2023
Later among the works it cites.
——, “How to remove backdoors in diffusion models?” in
2023
Later among the works it cites.
R. Gandikota, J. Materzynska, J. Fiotto-Kaufman, and D. Bau, “Erasing concepts from diffusion models,” in
2023
Later among the works it cites.
N. Kumari, B. Zhang, S.-Y. Wang, E. Shechtman, R. Zhang, and J.-Y. Zhu, “Ablating concepts in text-to-image diffusion models,” in
2023
Later among the works it cites.
P. Schramowski, M. Brack, B. Deiseroth, and K. Kersting, “Safe latent diffusion: Mitigating inappropriate degeneration in diffusion models,” in
2023
Later among the works it cites.
Z. Ni, L. Wei, J. Li, S. Tang, Y. Zhuang, and Q. Tian, “Degeneration-tuning: Using scrambled grid shield unwanted concepts from stable diffusion,” in
2023
Later among the works it cites.
2023
Later among the works it cites.
2023
Later among the works it cites.
2023
Later among the works it cites.
V. T. Truong and L. B. Le, “Text-guided real-world-to-3d generative models with real-time rendering on mobile devices,” in
2024
Closest in time.
H. Cao, C. Tan, Z. Gao, Y. Xu, G. Chen, P.-A. Heng, and S. Z. Li, “A survey on generative diffusion models,”
2024
Closest in time.
J. Vice, N. Akhtar, R. Hartley, and A. Mian, “Bagm: A backdoor attack for manipulating text-to-image generative models,”
2024
Closest in time.
Y. Huang, F. Juefei-Xu, Q. Guo, J. Zhang, Y. Wu, M. Hu, T. Li, G. Pu, and Y. Liu, “Personalization as a shortcut for few-shot backdoor attack against text-to-image diffusion models,” in
2024
Closest in time.
S.-Y. Chou, P.-Y. Chen, and T.-Y. Ho, “Villandiffusion: A unified backdoor attack framework for diffusion models,” in
2024
Closest in time.
H. Yu, J. Chen, X. Ding, Y. Zhang, T. Tang, and H. Ma, “Step vulnerability guided mean fluctuation adversarial attack against conditional diffusion models,” in
2024
Closest in time.
Y. Yang, B. Hui, H. Yuan, N. Gong, and Y. Cao, “Sneakyprompt: Jailbreaking text-to-image generative models,” in
2024
Closest in time.
C. Zhang, L. Wang, and A. Liu, “Revealing vulnerabilities in stable diffusion via targeted attacks,”
2024
Closest in time.
P. Zhu, T. Takahashi, and H. Kataoka, “Watermark-embedded adversarial examples for copyright protection against diffusion models,” in
2024
Closest in time.
M. Kang, D. Song, and B. Li, “Diffattack: Evasion attacks against diffusion-based adversarial purification,” in
2024
Closest in time.
M. Zhang, N. Yu, R. Wen, M. Backes, and Y. Zhang, “Generated distributions are all you need for membership inference attacks against generative models,” in
2024
Closest in time.
2024
Closest in time.
2024
Closest in time.
J. Dubiński, A. Kowalczuk, S. Pawlak, P. Rokita, T. Trzciński, and P. Morawiecki, “Towards more realistic membership inference attacks on large diffusion models,” in
2024
Closest in time.
S. An, S.-Y. Chou, K. Zhang, Q. Xu, G. Tao, G. Shen, S. Cheng, S. Ma, P.-Y. Chen, T.-Y. Ho
2024
Closest in time.
2024
Closest in time.
2024
Closest in time.
G. Zhang, K. Wang, X. Xu, Z. Wang, and H. Shi, “Forget-me-not: Learning to forget in text-to-image diffusion models,” in
2024
Closest in time.
S. Hong, J. Lee, and S. S. Woo, “All but one: Surgical concept erasing with model preservation in text-to-image diffusion models,” in
2024
Closest in time.
J. Wu, T. Le, M. Hayat, and M. Harandi, “Erasediff: Erasing data influence in diffusion models,”
2024
Closest in time.
2024
Closest in time.
2024
Closest in time.
T. Yang, J. Cao, and C. Xu, “Pruning for robust concept erasing in diffusion models,”
2024
Closest in time.
2024
Closest in time.
A. Heng and H. Soh, “Selective amnesia: A continual learning approach to forgetting in deep generative models,” in
2024
Closest in time.
M. Lyu, Y. Yang, H. Hong, H. Chen, X. Jin, Y. He, H. Xue, J. Han, and G. Ding, “One-dimensional adapter to rule them all: Concepts diffusion models and erasing applications,” in
2024
Closest in time.
2024
Closest in time.
2024
Closest in time.
Y. Liu, Z. Zhao, M. Backes, and Y. Zhang, “Membership inference attacks by exploiting loss trajectory,” in
2098
Closest in time.