Pith. sign in

REVIEW 2 cited by

Silent Branding Attack: Trigger-free Data Poisoning Attack on Text-to-Image Diffusion Models

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2503.09669 v1 pith:T7EIVG57 submitted 2025-03-12 cs.CV cs.AIcs.CR

classification cs.CVcs.AIcs.CR
keywords datamodelsattacklogospoisoningtextwithoutbranding
verification ladder T0 review T1 audit T2 compute T3 formal

Signed reviews

No signed human review yet.

0 comments
read the original abstract

Text-to-image diffusion models have achieved remarkable success in generating high-quality contents from text prompts. However, their reliance on publicly available data and the growing trend of data sharing for fine-tuning make these models particularly vulnerable to data poisoning attacks. In this work, we introduce the Silent Branding Attack, a novel data poisoning method that manipulates text-to-image diffusion models to generate images containing specific brand logos or symbols without any text triggers. We find that when certain visual patterns are repeatedly in the training data, the model learns to reproduce them naturally in its outputs, even without prompt mentions. Leveraging this, we develop an automated data poisoning algorithm that unobtrusively injects logos into original images, ensuring they blend naturally and remain undetected. Models trained on this poisoned dataset generate images containing logos without degrading image quality or text alignment. We experimentally validate our silent branding attack across two realistic settings on large-scale high-quality image datasets and style personalization datasets, achieving high success rates even without a specific text trigger. Human evaluation and quantitative metrics including logo detection show that our method can stealthily embed logos.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Attacks on Approximate Caches in Text-to-Image Diffusion Models

    cs.CR 2025-08 conditional novelty 7.0 of 10

    Remote attackers can abuse approximate caches in text-to-image diffusion services to transmit hidden messages, steal other users' cached prompts, and inject logos into other users' generated images.

  2. !Imperio, smolVLA: The Implications of Data Poisoning on Open Source Robotics

    cs.RO 2026-07 conditional novelty 6.0 of 10

    Three poisoned episodes out of 320 embed a stealthy trigger-word denial-of-service backdoor in smolVLA, dropping real-robot pick-and-place success to 0% while clean prompts stay near 50%.

Pith tools