A summary of attacks and defenses for diffusion models
| Attack/Defense | Method | Year | Category | Subcategory | Target models | Dataset |
|---|---|---|---|---|---|---|
| Adversarial Attack | ECB (Struppek et al., 2023a) | 2024 | Black-box | Character-level | Stable Diffusion, DALL-E 2, AltDiffusion-m18 | LAION-Aesthetics v2, MS COCO, ImageNet-V2, self-constructed |
| CharGrad (Kou et al., 2023) | 2023 | Black-box | Character-level | Stable Diffusion | MS COCO, Flickr30k | |
| ER (Gao et al., 2023) | 2023 | Black-box | Character-level | Stable Diffusion, DALL·E 2 | LAION-COCO, DiffusionDB, SBU Corpus, self-constructed | |
| DHV (Daras and Dimakis, 2022) | 2022 | Black-box | Word-level | DALLE-2 | – | |
| AA (Millière, 2022) | 2022 | Black-box | Word-level | DALL-E 2, DALL-E mini | – | |
| BBA (Maus et al., 2023) | 2023 | Black-box | Sentence-level | Stable Diffusion | ImageNet | |
| RIATIG (Liu et al., 2023b) | 2023 | Black-box | Sentence-level | DALL·E, DALL·E 2, Imagen | MS COCO | |
| QFA (Zhuang et al., 2023) | 2023 | Grey-box | Similarity-driven | Stable Diffusion | self-constructed | |
| RVTA (Zhang et al., 2024b) | 2024 | Grey-box | Similarity-driven | Stable Diffusion | ImageNet, self-constructed | |
| MMP-Attack (Yang et al., 2024a) | 2025 | Grey-box | Similarity-driven | Stable Diffusion, DALL-E 3, Imagine Art | MS COCO | |
| DORMANT (Zhou et al., 2024b) | 2025 | Grey-box | Distance-driven | Animate Anyone, MagicAnimate, MagicPose, MusePose, Champ, MuseV, UniAnimate, and ControlNeXt | TikTok, Champ, UBC Fashion, and TED Talks | |
| ATM (Du et al., 2024a) | 2023 | White-box | Classifier-driven | Stable Diffusion | ImageNet, self-constructed | |
| FOOLSDEDIT (Zhou et al., 2024c) | 2024 | White-box | Classifier-driven | SDEdit | CelebAMask-HQ, FFHQ | |
| SAGE (Liu et al., 2024h) | 2023 | White-box | Classifier-driven | GLIDE, Stable Diffusion, DeepFloyd | ImageNet | |
| SneakyPrompt (Yang et al., 2024j) | 2023 | Black-box | Target External Defenses | Stable Diffusion, DALL·E 2 | NSFW-200, Dog/Cat-100 | |
| UD (Qu et al., 2023) | 2023 | Black-box | Target External Defenses | Stable Diffusion, LD, DALL·E 2, DALL·E mini | MS COCO | |
| Jailbreak Attack | Atlas (Dong et al., 2024) | 2024 | Black-box | Target External Defenses | Stable Diffusion, DALL·E 3 | NSFW-200, Dog/Cat-100 |
| Groot (Liu et al., 2024q) | 2024 | Black-box | Target External Defenses | Stable Diffusion, Midjounery, DALL·E 3 | self-constructed | |
| DACA (Deng and Chen, 2023) | 2024 | Black-box | Target External Defenses | Midjounery, DALL·E 3 | VBCDE-100, Copyright-20 | |
| SurrogatePrompt (Ba et al., 2024) | 2024 | Black-box | Target External Defenses | Midjourney, DALL·E 2, DreamStudio | self-constructed | |
| PGJ (Huang et al., 2025d) | 2025 | Black-box | Target External Defenses | Stable Diffusion, DALL-E 2, DALL-E 3, Cogview3, Tongyiwanxiang, Hunyuan | self-constructed | |
| R2A (Zhang et al., 2025b) | 2025 | Black-box | Target External Defense | Stable Diffusion, FLUX, DALL·E 3, Midjourney | self-constructed | |
| Jailbreak Attack | JPA (Ma et al., 2024a) | 2024 | Grey-box | Target Internal Defenses | Stable Diffusion, Midjourney, DALL·E 2, PIXART- | I2P |
| RT-Attack (Gao et al., 2024e) | 2024 | Grey-box | Target Internal Defenses | Stable Diffusion, DALL·E 3, SafeGen | I2P, self-constructed | |
| RTSDSF (Rando et al., 2022) | 2022 | White box | Target External Defenses | Stable Diffusion | self-constructed | |
| MMA (Yang et al., 2024i) | 2024 | White box | Target External Defenses | Stable Diffusion, Midjounery, Leonardo.Ai | LAION-COCO, UnsafeDiff | |
| P4D (Chin et al., 2024) | 2024 | White box | Target Internal Defenses | Stable Diffusion | I2P, ESD Dataset | |
| UnlearnDiffAtk (Zhang et al., 2023g) | 2024 | White box | Target Internal Defenses | Stable Diffusion | I2P Dataset, ImageNet, WikiArt | |
| ESD (Gandikota et al., 2023) | 2023 | Concept Erasure | Fine-tuning | Stable Diffusion | MS COCO, I2P | |
| SPM (Lyu et al., 2024) | 2024 | Concept Erasure | Fine-tuning | Stable Diffusion | MS COCO, I2P | |
| SDD (Kim et al., 2023) | 2023 | Concept Erasure | Fine-tuning | Stable Diffusion | MS COCO, I2P | |
| AC (Kumari et al., 2023) | 2023 | Concept Erasure | Fine-tuning | Stable Diffusion | MS COCO | |
| ABO (Hong et al., 2024a) | 2023 | Concept Erasure | Fine-tuning | Stable Diffusion | MS COCO | |
| UC (Wu et al., 2024h) | 2024 | Concept Erasure | Fine-tuning | Stable Diffusion | I2P | |
| SA (Heng and Soh, 2024) | 2023 | Concept Erasure | Fine-tuning | Stable Diffusion, DDPM | MNIST, CIFAR-10 and STL-10, I2P | |
| Receler (Huang et al., 2024a) | 2024 | Concept Erasure | Fine-tuning | Stable Diffusion | CIFAR-10, MS COCO, I2P | |
| Jailbreak Defense | RACE (Kim et al., 2024a) | 2024 | Concept Erasure | Fine-tuning | Stable Diffusion | MS COCO, I2P, Imagenette |
| AdvUnlearn (Zhang et al., 2024v) | 2024 | Concept Erasure | Fine-tuning | Stable Diffusion | MS COCO, I2P, Imagenette | |
| DT (Ni et al., 2023) | 2023 | Concept Erasure | Fine-tuning | Stable Diffusion | MS COCO | |
| FMO (Zhang et al., 2024e) | 2023 | Concept Erasure | Fine-tuning | Stable Diffusion | ConceptBench | |
| Geom-Erasing (Liu et al., 2024u) | 2024 | Concept Erasure | Fine-tuning | Stable Diffusion | LAION | |
| SepME (Zhao et al., 2024a) | 2024 | Concept Erasure | Fine-tuning | Stable Diffusion | self-constructed | |
| CCRT (Han et al., 2024) | 2024 | Concept Erasure | Fine-tuning | Stable Diffusion | MS COCO | |
| SafeGen (Li et al., 2024r) | 2024 | Concept Erasure | Fine-tuning | Stable Diffusion | MS COCO, I2P, SneakyPrompt-Dataset, NSFW-56k | |
| CPE (Lee et al., 2025a) | 2025 | Concept Erasure | Fine-tuning | Stable Diffusion | MS COCO, I2P, MACE-Dataset | |
| MACE (Lu et al., 2024d) | 2024 | Concept Erasure | Close-Formed Solution | Stable Diffusion | CIFAR-10, MS COCO, I2P | |
| UCE (Gandikota et al., 2024) | 2024 | Concept Erasure | Close-Formed Solution | Stable Diffusion | MS COCO | |
| TIME (Orgad et al., 2023) | 2023 | Concept Erasure | Close-Formed Solution | Stable Diffusion | MS COCO | |
| RECE (Gong et al., 2024a) | 2024 | Concept Erasure | Close-Formed Solution | Stable Diffusion | MS COCO, I2P | |
| RealEra (Liu et al., 2024s) | 2024 | Concept Erasure | Close-Formed Solution | Stable Diffusion | CIFAR-10, I2P | |
| CP (Chavhan et al., 2024) | 2024 | Concept Erasure | Neuron Pruning | Stable Diffusion | Imagenette | |
| PRCEDM (Yang et al., 2024e) | 2024 | Concept Erasure | Neuron Pruning | Stable Diffusion | Imagenet, MS COCO, I2P | |
| SLD (Schramowski et al., 2023) | 2023 | Inference Guidance | Input | Stable Diffusion | LAION-2B-en, I2P, DrawBench | |
| PromptGuard (Yuan et al., 2025) | 2025 | Inference Guidance | Input | Stable Diffusion | MS COCO, I2P, SneakyPrompt-Dataset | |
| Jailbreak Defense | Ethical-Lens (Cai et al., 2024) | 2025 | Inference Guidance | Input&Output | Stable Diffusion, Dreamlike Diffusion | MS COCO, I2P, Tox100, Tox1K, HumanBias, Demographic Stereotypes, Mental Disorders |
| SDIDLD (Li et al., 2024d) | 2024 | Inference Guidance | Latent space | Stable Diffusion | MS COCO, I2P, CelebA, Winobias, self-constructed | |
| CC (Meng et al., 2025) | 2025 | Inference Guidance | Latent space | Stable Diffusion | MS COCO, I2P, self-constructed | |
| BadDiffusion (Chou et al., 2023) | 2023 | Training Manipulation | Visual Trigger | DDPM | CIFAR-10, CelebA | |
| VillanDiffusion (Sheng-Yen Chou et al., 2024) | 2023 | Training Manipulation | Visual Trigger | Stable Diffusion, DDPM, LDM, NCSN | CIFAR-10, CelebA | |
| TrojDiff (Chen et al., 2023c) | 2023 | Training Manipulation | Visual Trigger | DDPM, DDIM | CIFAR-10, CelebA | |
| IBA (Li et al., 2024n) | 2024 | Training Manipulation | Visual Trigger | Unconditional and Conditional DM | CIFAR-10, CelebA, MS-COCO | |
| DIFF2 (Li et al., 2024c) | 2024 | Training Manipulation | Visual Trigger | DDPM, DDIM, Stable DiffusionE, ODE | CIFAR-10, CIFAR-100, CelebA, ImageNet | |
| Backdoor Attack | RA (Struppek et al., 2023b) | 2023 | Data Poisoning | Textual Trigger | Stable Diffusion | LAION-Aesthetics v2, MS-COCO |
| BadT2I (Zhai et al., 2023) | 2023 | Data Poisoning | Textual Trigger | Stable Diffusion | LAION-Aesthetics v2, LAION-2B-en, MS COCO | |
| FTHCW (Pan et al., 2024) | 2024 | Data Poisoning | Textual Trigger | DDPM, LDM | CIFAR-10, ImageNet, Caltech256 | |
| BAGM (Vice et al., 2024) | 2023 | Data Poisoning | Textual Trigger | Stable Diffusion, Kandinsky, DeepFloyd-IF | MS COCO, Marketable Food | |
| Zero-Day (Huang et al., 2023, 2024h) | 2023 | Data Poisoning | Textual Trigger | Stable Diffusion | DreamBooth dataset | |
| SBD (Wang et al., 2024e) | 2024 | Data Poisoning | Textual Trigger | Stable Diffusion | LAION Aesthetics v2, Pokemon Captions, COYO-700M, Midjourney v5 | |
| IBT (Naseh et al., 2024) | 2024 | Data Poisoning | Textual Trigger | Stable Diffusion | Midjourney Dataset, DiffusionDB, PartiPrompts | |
| T2IShield (Wang et al., 2024v) | 2024 | Detection | Trigger Detection | Stable Diffusion | CelebA-HQ-Dialog | |
| Ufid (Guan et al., 2025) | 2024 | Detection | Trigger Validation | DDPM, Stable Diffusion | CelebA-HQ-Dialog, Pokemon, | |
| Backdoor Defense | DisDet (Sui et al., 2024) | 2024 | Detection | Trigger Validation | DDPM, DDIM | CIFAR-10, CelebA |
| Elijah (An et al., 2024) | 2024 | Removal | Detect & Remove | DDPM, DDIM, LDM | CIFAR-10, CelebA-HQ | |
| Diff-Cleanse (Hao et al., 2024) | 2024 | Removal | Detect & Remove | DDPM, DDIM, LDM | MNIST, CIFAR-10, CelebA-HQ | |
| TERD (Mo et al., 2024) | 2024 | Removal | Inverse & Remove | DDPM | CIFAR-10, CelebA, CelebA-HQ | |
| Backdoor Defense | PureDiffusion (Truong and Le, 2024) | 2024 | Removal | Inverse & Remove | DDPM | CIFAR-10 |
| NaviDet (Zhai et al., 2025) | 2025 | Removal | Detect & Remove | Stable Diffusion | MS-COCO | |
| WuMI (Wu et al., 2022b) | 2022 | Black-box | Reconstruction-error | LDM DALL-E mini | MSCOCO, VG, LAION-400M, CC3M | |
| DiffusionLeaks (Matsumoto et al., 2023) | 2023 | Black/White-box | Reconstruction-error | DDIM, | CIFAR-10, CelebA | |
| PangMI (Pang and Wang, 2023) | 2024 | Black-box | Auxilary Dataset | Stable Diffusion | CelebA-Dialog, WIT, MSCOCO | |
| LiMI (Li et al., 2024i) | 2024 | Black-box | Reconstruction-error | DDIM, Stable Diffusion DiT | CIFAR-10, STL10-U, LAION-5B, LAION-by-DALL-E | |
| DRC (Fu et al., 2024b) | 2024 | Black-box | Reconstruction-error | DDPM, DDIM | FFHQ, CelebA, CIFAR-10, CIFAR-100 | |
| GMIA (Zhang et al., 2024m) | 2023 | Black-box | Auxilary Dataset | DDPM, DDIM, FastDPM | CIFAR-10, CelebA | |
| Membership Inference | SecMI (Duan et al., 2023) | 2023 | Gray-box | Posterior Likelihood | DDPM, DDIM, Stable Diffusion | CIFAR-10/100, STL10-U, Tiny-ImageNet, Pokemon, COCO2017-val, LAION-5B |
| QRMI (Tang et al., 2023b) | 2023 | Gray-box | Posterior Likelihood | DDPM, DDIM | CIFAR-10/100, STL100, Tiny-ImageNet | |
| PIA (Kong et al., 2024) | 2023 | Gray-box | Posterior Likelihood | DDPM, DDIM, Stable Diffusion | CIFAR-10/100, Tiny-ImageNet, COCO2017, LAION-5B | |
| PFAMI (Fu et al., 2023a) | 2024 | Gray-box | Posterior Likelihood | DDPM, VAE | CelebA, Tiny-ImageNet | |
| ZhMI (Zhai et al., 2024) | 2024 | Gray-box | Conditional Likelihood | DDPM, DDIM, Stable Diffusion | Pokemonn, Flickr, MSCOCO, LAION | |
| SMIA (Li et al., 2024m) | 2024 | Gray-box | Structural Similarity | LDM, Stable Diffusion | LAION2B, LAION-400M | |
| SLA (Matsumoto et al., 2023; Hu and Pang, 2023) | 2023 | White-box | Loss | DDPM, DDIM | FFHQ, DRD, CelebA, FFHQ | |
| GSA (Pang et al., 2023) | 2024 | White-box | Gradient | DDPM | CIFAR-10, MSCOCO, ImageNet | |
| DuMI Dubiński et al. 2024 | 2023 | White-box | Loss | Stable Diffusion | Pokemon, LAION-mi | |
| BruteDE (Carlini et al., 2023) | 2023 | Black-box | Existing Condition | DDPM, Stable Diffusion | CIFAR-10 LAION-5B | |
| Data Extraction | ReDE (Webster, 2023) | 2023 | Black/White-box | Existing Condition | Stable Diffusion, Midjourney, Deep Image Floyd | LAION-5B |
| SIDE (Chen et al., 2024c) | 2024 | White-box | Surrogate Condition | DDPM, DDIM | CIFAR-10, CelebA | |
| FineXtract Wu et al. 2024g | 2024 | White-box | Surrogate Condition | Finetuned Stable Diffusion | WikiArt | |
| Model Extraction | SDeT Horwitz et al. 2024 | 2024 | White-box | LoRA-Based Model Extraction | Finetuned Stable Diffusion | LoWRA Bench |
| DUAW (Ye et al., 2024c) | 2023 | Natural Data Protection | Learning Prevention | Stable Diffusion | DreamBooth dataset, WikiArt, self-constructed | |
| Intellectual Property Protection | AdvDM (Liang et al., 2023) | 2023 | Natural Data Protection | Learning Prevention | Stable Diffusion, LDM | LSUN, WikiArt |
| Anti-DreamBooth (Van Le et al., 2023) | 2023 | Natural Data Protection | Learning Prevention | Stable Diffusion | CelebA, VGGFace2 | |
| MetaCloak (Liu et al., 2024r) | 2024 | Natural Data Protection | Learning Prevention | Stable Diffusion | CelebA-HQ, VGGFace2 | |
| InMakr (Liu et al., 2024f) | 2024 | Natural Data Protection | Learning Prevention | Stable Diffusion | VGGFace2, WikiArt | |
| SimAC (Wang et al., 2024b) | 2024 | Natural Data Protection | Learning Prevention | Stable Diffusion | CelebA-HQ, VGGFace2 | |
| EditGuard (Zhang et al., 2024u) | 2024 | Natural Data Protection | Editing Prevention | Stable Diffusion | COCO | |
| WaDiff (Min et al., 2024b) | 2024 | Natural Data Protection | Editing Prevention | Stable Diffusion | COCO, ImageNet | |
| AdvWatermark (Zhu et al., 2024b) | 2024 | Natural Data Protection | Editing Prevention | Stable Diffusion | WikiArt | |
| Intellectual Property Protection | FT-SHIELD (Cui et al., 2023a) | 2024 | Natural Data Protection | Data Attribution | Stable Diffusion | CelebA, WikiArt, Pokemon Captions, DreamBooth dataset |
| DiffusionShield (Cui et al., 2023b) | 2024 | Natural Data Protection | Data Attribution | DDPM,, Stable Diffusion | CIFAR-10, CIFAR-100, STL-10, ImageNet | |
| ProMark (Asnani et al., 2024) | 2024 | Natural Data Protection | Data Attribution | LDM | Stock, LSUN, WikiArt, ImageNet | |
| Diagnosis (Wang et al., 2023e) | 2023 | Natural Data Protection | Data Attribution | Stable Diffusion, VQ Diffusion | Pokemon, CelebA, CUB-200, DreamBooth | |
| HiDDeN (Zhu et al., 2018) | 2018 | Generated Data Protection | Post-generation Watermark | CNN | MS-COCO, BOSS dataset | |
| Stable Signature (Fernandez et al., 2023) | 2023 | Generated Data Protection | Diffusion Watermark | LDM | MS-COCO, ImageNet | |
| LaWa (Rezaei et al., 2024) | 2024 | Generated Data Protection | Diffusion Watermark | LDM | MIRFlickR | |
| Safe-SD (Ma et al., 2024d) | 2024 | Generated Data Protection | Diffusion Watermark | Stable Diffusion | LSUN, COCO, FFHQ | |
| RW (Zhao et al., 2023b) | 2023 | Model Protection | Model Watermark | Stable Diffusion, EDM | CIFAR-10, ImageNet, FFHQ, AFHQv2 | |
| FIXEDWM (Liu et al., 2023f) | 2023 | Model Protection | Model Watermark | LDM | MS COCO | |
| WDM (Peng et al., 2023) | 2023 | Model Protection | Model Watermark | DDPM, | CIFAR-10, CelebA, MNIST | |
| AquaLoRA (Feng et al., 2024a) | 2024 | Model Protection | Model Attribution | Stable Diffusion | COCO | |
| LatentTracer (Wang et al., 2024t) | 2024 | Model Protection | Model Attribution | Stable Diffusion, Kandinsky | LAION | |
| Tree-Ring (Wen et al., 2023) | 2023 | Model Protection | Model Attribution | Stable Diffusion, ImageNet diffusion | MS-COCO, ImageNet |
| Attack/Defense | Method | Year | Category | Subcategory | Target models | Dataset |
|---|---|---|---|---|---|---|
| Adversarial Attack | 2024 | Black-box | Character-level | Stable Diffusion, DALL-E 2, AltDiffusion-m18 | LAION-Aesthetics v2, | |
| CharGrad ( | 2023 | Black-box | Character-level | Stable Diffusion | ||
| 2023 | Black-box | Character-level | Stable Diffusion, DALL·E 2 | LAION-COCO, DiffusionDB, | ||
| 2022 | Black-box | Word-level | DALLE-2 | – | ||
| 2022 | Black-box | Word-level | DALL-E 2, DALL-E mini | – | ||
| 2023 | Black-box | Sentence-level | Stable Diffusion | ImageNet | ||
| 2023 | Black-box | Sentence-level | DALL·E, DALL·E 2, Imagen | |||
| 2023 | Grey-box | Similarity-driven | Stable Diffusion | self-constructed | ||
| 2024 | Grey-box | Similarity-driven | Stable Diffusion | ImageNet, self-constructed | ||
| MMP-Attack ( | 2025 | Grey-box | Similarity-driven | Stable Diffusion, DALL-E 3, Imagine Art | ||
| DORMANT ( | 2025 | Grey-box | Distance-driven | Animate Anyone, MagicAnimate, MagicPose, MusePose, Champ, MuseV, UniAnimate, and ControlNeXt | TikTok, Champ, | |
| 2023 | White-box | Classifier-driven | Stable Diffusion | ImageNet, self-constructed | ||
| FOOLSDEDIT ( | 2024 | White-box | Classifier-driven | SDEdit | CelebAMask-HQ, | |
| 2023 | White-box | Classifier-driven | GLIDE, Stable Diffusion, DeepFloyd | ImageNet | ||
| SneakyPrompt ( | 2023 | Black-box | Target External Defenses | Stable Diffusion, DALL·E 2 | NSFW-200, Dog/Cat-100 | |
| 2023 | Black-box | Target External Defenses | Stable Diffusion, LD, DALL·E 2, DALL·E mini | |||
| Jailbreak Attack | Atlas ( | 2024 | Black-box | Target External Defenses | Stable Diffusion, DALL·E 3 | NSFW-200, Dog/Cat-100 |
| Groot ( | 2024 | Black-box | Target External Defenses | Stable Diffusion, Midjounery, DALL·E 3 | self-constructed | |
| 2024 | Black-box | Target External Defenses | Midjounery, DALL·E 3 | VBCDE-100, Copyright-20 | ||
| SurrogatePrompt ( | 2024 | Black-box | Target External Defenses | Midjourney, DALL·E 2, DreamStudio | self-constructed | |
| 2025 | Black-box | Target External Defenses | Stable Diffusion, DALL-E 2, DALL-E 3, Cogview3, Tongyiwanxiang, Hunyuan | self-constructed | ||
| R2A ( | 2025 | Black-box | Target External Defense | Stable Diffusion, FLUX, DALL·E 3, Midjourney | self-constructed | |
| Jailbreak Attack | 2024 | Grey-box | Target Internal Defenses | Stable Diffusion, Midjourney, DALL·E 2, PIXART- | I2P | |
| RT-Attack ( | 2024 | Grey-box | Target Internal Defenses | Stable Diffusion, DALL·E 3, SafeGen | I2P, self-constructed | |
| 2022 | White box | Target External Defenses | Stable Diffusion | self-constructed | ||
| 2024 | White box | Target External Defenses | Stable Diffusion, Midjounery, Leonardo.Ai | LAION-COCO, UnsafeDiff | ||
| P4D ( | 2024 | White box | Target Internal Defenses | Stable Diffusion | I2P, | |
| UnlearnDiffAtk ( | 2024 | White box | Target Internal Defenses | Stable Diffusion | I2P Dataset, ImageNet, WikiArt | |
| 2023 | Concept Erasure | Fine-tuning | Stable Diffusion | |||
| 2024 | Concept Erasure | Fine-tuning | Stable Diffusion | |||
| 2023 | Concept Erasure | Fine-tuning | Stable Diffusion | |||
| 2023 | Concept Erasure | Fine-tuning | Stable Diffusion | |||
| 2023 | Concept Erasure | Fine-tuning | Stable Diffusion | |||
| 2024 | Concept Erasure | Fine-tuning | Stable Diffusion | I2P | ||
| 2023 | Concept Erasure | Fine-tuning | Stable Diffusion, | MNIST, CIFAR-10 and STL-10, I2P | ||
| Receler ( | 2024 | Concept Erasure | Fine-tuning | Stable Diffusion | CIFAR-10, | |
| Jailbreak Defense | 2024 | Concept Erasure | Fine-tuning | Stable Diffusion | ||
| AdvUnlearn ( | 2024 | Concept Erasure | Fine-tuning | Stable Diffusion | ||
| 2023 | Concept Erasure | Fine-tuning | Stable Diffusion | |||
| 2023 | Concept Erasure | Fine-tuning | Stable Diffusion | ConceptBench | ||
| Geom-Erasing ( | 2024 | Concept Erasure | Fine-tuning | Stable Diffusion | ||
| SepME ( | 2024 | Concept Erasure | Fine-tuning | Stable Diffusion | self-constructed | |
| 2024 | Concept Erasure | Fine-tuning | Stable Diffusion | |||
| SafeGen ( | 2024 | Concept Erasure | Fine-tuning | Stable Diffusion | ||
| 2025 | Concept Erasure | Fine-tuning | Stable Diffusion | |||
| 2024 | Concept Erasure | Close-Formed Solution | Stable Diffusion | CIFAR-10, | ||
| 2024 | Concept Erasure | Close-Formed Solution | Stable Diffusion | |||
| 2023 | Concept Erasure | Close-Formed Solution | Stable Diffusion | |||
| 2024 | Concept Erasure | Close-Formed Solution | Stable Diffusion | |||
| RealEra ( | 2024 | Concept Erasure | Close-Formed Solution | Stable Diffusion | CIFAR-10, I2P | |
| 2024 | Concept Erasure | Neuron Pruning | Stable Diffusion | Imagenette | ||
| 2024 | Concept Erasure | Neuron Pruning | Stable Diffusion | Imagenet, | ||
| 2023 | Inference Guidance | Input | Stable Diffusion | LAION-2B-en, I2P, DrawBench | ||
| PromptGuard ( | 2025 | Inference Guidance | Input | Stable Diffusion | ||
| Jailbreak Defense | Ethical-Lens ( | 2025 | Inference Guidance | Input&Output | Stable Diffusion, Dreamlike Diffusion | |
| 2024 | Inference Guidance | Latent space | Stable Diffusion | |||
| 2025 | Inference Guidance | Latent space | Stable Diffusion | |||
| BadDiffusion ( | 2023 | Training Manipulation | Visual Trigger | CIFAR-10, CelebA | ||
| VillanDiffusion (Sheng-Yen | 2023 | Training Manipulation | Visual Trigger | Stable Diffusion, DDPM, LDM, | CIFAR-10, CelebA | |
| TrojDiff ( | 2023 | Training Manipulation | Visual Trigger | DDPM, | CIFAR-10, CelebA | |
| 2024 | Training Manipulation | Visual Trigger | Unconditional and Conditional DM | CIFAR-10, CelebA, MS-COCO | ||
| DIFF2 ( | 2024 | Training Manipulation | Visual Trigger | DDPM, DDIM, Stable DiffusionE, | CIFAR-10, CIFAR-100, CelebA, ImageNet | |
| Backdoor Attack | 2023 | Data Poisoning | Textual Trigger | Stable Diffusion | LAION-Aesthetics v2, MS-COCO | |
| BadT2I ( | 2023 | Data Poisoning | Textual Trigger | Stable Diffusion | LAION-Aesthetics v2, LAION-2B-en, | |
| 2024 | Data Poisoning | Textual Trigger | DDPM, | CIFAR-10, ImageNet, Caltech256 | ||
| 2023 | Data Poisoning | Textual Trigger | Stable Diffusion, Kandinsky, DeepFloyd-IF | |||
| Zero-Day ( | 2023 | Data Poisoning | Textual Trigger | Stable Diffusion | DreamBooth dataset | |
| 2024 | Data Poisoning | Textual Trigger | Stable Diffusion | |||
| 2024 | Data Poisoning | Textual Trigger | Stable Diffusion | Midjourney Dataset, DiffusionDB, PartiPrompts | ||
| T2IShield ( | 2024 | Detection | Trigger Detection | Stable Diffusion | CelebA-HQ-Dialog | |
| Ufid ( | 2024 | Detection | Trigger Validation | DDPM, Stable Diffusion | CelebA-HQ-Dialog, Pokemon, | |
| Backdoor Defense | DisDet ( | 2024 | Detection | Trigger Validation | DDPM, | CIFAR-10, CelebA |
| Elijah ( | 2024 | Removal | Detect & Remove | DDPM, DDIM, | CIFAR-10, CelebA-HQ | |
| Diff-Cleanse ( | 2024 | Removal | Detect & Remove | DDPM, DDIM, | MNIST, CIFAR-10, CelebA-HQ | |
| 2024 | Removal | Inverse & Remove | CIFAR-10, CelebA, CelebA-HQ | |||
| Backdoor Defense | PureDiffusion ( | 2024 | Removal | Inverse & Remove | CIFAR-10 | |
| NaviDet ( | 2025 | Removal | Detect & Remove | Stable Diffusion | MS-COCO | |
| WuMI ( | 2022 | Black-box | Reconstruction-error | MSCOCO, VG, LAION-400M, CC3M | ||
| DiffusionLeaks ( | 2023 | Black/White-box | Reconstruction-error | DDIM, | CIFAR-10, CelebA | |
| PangMI ( | 2024 | Black-box | Auxilary Dataset | Stable Diffusion | CelebA-Dialog, WIT, | |
| LiMI ( | 2024 | Black-box | Reconstruction-error | DDIM, Stable Diffusion DiT | CIFAR-10, STL10-U, LAION-5B, LAION-by-DALL-E | |
| 2024 | Black-box | Reconstruction-error | DDPM, | FFHQ, CelebA, CIFAR-10, CIFAR-100 | ||
| 2023 | Black-box | Auxilary Dataset | DDPM, DDIM, FastDPM | CIFAR-10, CelebA | ||
| Membership Inference | SecMI ( | 2023 | Gray-box | Posterior Likelihood | DDPM, DDIM, Stable Diffusion | CIFAR-10/100, STL10-U, Tiny-ImageNet, Pokemon, COCO2017-val, LAION-5B |
| 2023 | Gray-box | Posterior Likelihood | DDPM, | CIFAR-10/100, STL100, Tiny-ImageNet | ||
| 2023 | Gray-box | Posterior Likelihood | DDPM, DDIM, Stable Diffusion | CIFAR-10/100, Tiny-ImageNet, COCO2017, LAION-5B | ||
| 2024 | Gray-box | Posterior Likelihood | DDPM, | CelebA, Tiny-ImageNet | ||
| ZhMI ( | 2024 | Gray-box | Conditional Likelihood | DDPM, DDIM, Stable Diffusion | Pokemonn, Flickr, MSCOCO, | |
| 2024 | Gray-box | Structural Similarity | LDM, Stable Diffusion | LAION2B, LAION-400M | ||
| 2023 | White-box | Loss | DDPM, | FFHQ, DRD, CelebA, | ||
| 2024 | White-box | Gradient | CIFAR-10, MSCOCO, ImageNet | |||
| DuMI | 2023 | White-box | Loss | Stable Diffusion | Pokemon, LAION-mi | |
| BruteDE ( | 2023 | Black-box | Existing Condition | DDPM, Stable Diffusion | CIFAR-10 LAION-5B | |
| Data Extraction | ReDE ( | 2023 | Black/White-box | Existing Condition | Stable Diffusion, Midjourney, Deep Image Floyd | LAION-5B |
| 2024 | White-box | Surrogate Condition | DDPM, | CIFAR-10, CelebA | ||
| FineXtract | 2024 | White-box | Surrogate Condition | Finetuned Stable Diffusion | WikiArt | |
| Model Extraction | SDeT | 2024 | White-box | LoRA-Based Model Extraction | Finetuned Stable Diffusion | LoWRA Bench |
| 2023 | Natural Data Protection | Learning Prevention | Stable Diffusion | DreamBooth dataset, WikiArt, self-constructed | ||
| Intellectual Property Protection | AdvDM ( | 2023 | Natural Data Protection | Learning Prevention | Stable Diffusion, | LSUN, WikiArt |
| Anti-DreamBooth ( | 2023 | Natural Data Protection | Learning Prevention | Stable Diffusion | CelebA, VGGFace2 | |
| MetaCloak ( | 2024 | Natural Data Protection | Learning Prevention | Stable Diffusion | CelebA-HQ, VGGFace2 | |
| InMakr ( | 2024 | Natural Data Protection | Learning Prevention | Stable Diffusion | VGGFace2, WikiArt | |
| SimAC ( | 2024 | Natural Data Protection | Learning Prevention | Stable Diffusion | CelebA-HQ, VGGFace2 | |
| EditGuard ( | 2024 | Natural Data Protection | Editing Prevention | Stable Diffusion | ||
| WaDiff ( | 2024 | Natural Data Protection | Editing Prevention | Stable Diffusion | COCO, ImageNet | |
| AdvWatermark ( | 2024 | Natural Data Protection | Editing Prevention | Stable Diffusion | WikiArt | |
| Intellectual Property Protection | FT-SHIELD ( | 2024 | Natural Data Protection | Data Attribution | Stable Diffusion | CelebA, WikiArt, Pokemon Captions, DreamBooth dataset |
| DiffusionShield ( | 2024 | Natural Data Protection | Data Attribution | DDPM,, Stable Diffusion | CIFAR-10, CIFAR-100, STL-10, ImageNet | |
| ProMark ( | 2024 | Natural Data Protection | Data Attribution | Stock, LSUN, WikiArt, ImageNet | ||
| Diagnosis ( | 2023 | Natural Data Protection | Data Attribution | Stable Diffusion, | Pokemon, CelebA, CUB-200, DreamBooth | |
| HiDDeN ( | 2018 | Generated Data Protection | Post-generation Watermark | MS-COCO, | ||
| Stable Signature ( | 2023 | Generated Data Protection | Diffusion Watermark | MS-COCO, ImageNet | ||
| LaWa ( | 2024 | Generated Data Protection | Diffusion Watermark | MIRFlickR | ||
| Safe-SD ( | 2024 | Generated Data Protection | Diffusion Watermark | Stable Diffusion | LSUN, COCO, | |
| 2023 | Model Protection | Model Watermark | Stable Diffusion, | CIFAR-10, ImageNet, FFHQ, AFHQv2 | ||
| FIXEDWM ( | 2023 | Model Protection | Model Watermark | |||
| 2023 | Model Protection | Model Watermark | DDPM, | CIFAR-10, CelebA, | ||
| AquaLoRA ( | 2024 | Model Protection | Model Attribution | Stable Diffusion | ||
| LatentTracer ( | 2024 | Model Protection | Model Attribution | Stable Diffusion, Kandinsky | ||
| Tree-Ring ( | 2023 | Model Protection | Model Attribution | Stable Diffusion, ImageNet diffusion | MS-COCO, ImageNet |
Sharing content requires targeting cookies to be enabled. Please update your cookie preferences to use this feature.