{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:T4VFLIHRTENJ3RRCCMIN26K7VC","short_pith_number":"pith:T4VFLIHR","schema_version":"1.0","canonical_sha256":"9f2a55a0f1991a9dc6221310dd795fa8bdc8fe0807479c9abc44b952cb77ee0c","source":{"kind":"arxiv","id":"2407.04215","version":2},"attestation_state":"computed","paper":{"title":"T2IShield: Defending Against Backdoors on Text-to-Image Diffusion Models","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.CV","authors_text":"Jie Zhang, Shiguang Shan, Xilin Chen, Zhongqi Wang","submitted_at":"2024-07-05T01:53:21Z","abstract_excerpt":"While text-to-image diffusion models demonstrate impressive generation capabilities, they also exhibit vulnerability to backdoor attacks, which involve the manipulation of model outputs through malicious triggers. In this paper, for the first time, we propose a comprehensive defense method named T2IShield to detect, localize, and mitigate such attacks. Specifically, we find the \"Assimilation Phenomenon\" on the cross-attention maps caused by the backdoor trigger. Based on this key insight, we propose two effective backdoor detection methods: Frobenius Norm Threshold Truncation and Covariance Di"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2407.04215","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CV","submitted_at":"2024-07-05T01:53:21Z","cross_cats_sorted":[],"title_canon_sha256":"cc83d97aa436045ff8fcfa49f72e127ff9e98e76440acd07083c2a5b590a92e9","abstract_canon_sha256":"f230587df086c89da228d19d082a32b69bb816e2cccb2d4530522f8427d0a931"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T08:44:55.894138Z","signature_b64":"reWhnuaOd7bbY0xbKLxsI5+f5rIJ41B2kMoCTM4wIgCC5GL86idFD6u6AN4ds853YTF4DgMHTmgFc/ONoIA9Cw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"9f2a55a0f1991a9dc6221310dd795fa8bdc8fe0807479c9abc44b952cb77ee0c","last_reissued_at":"2026-07-05T08:44:55.893720Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T08:44:55.893720Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"T2IShield: Defending Against Backdoors on Text-to-Image Diffusion Models","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.CV","authors_text":"Jie Zhang, Shiguang Shan, Xilin Chen, Zhongqi Wang","submitted_at":"2024-07-05T01:53:21Z","abstract_excerpt":"While text-to-image diffusion models demonstrate impressive generation capabilities, they also exhibit vulnerability to backdoor attacks, which involve the manipulation of model outputs through malicious triggers. In this paper, for the first time, we propose a comprehensive defense method named T2IShield to detect, localize, and mitigate such attacks. Specifically, we find the \"Assimilation Phenomenon\" on the cross-attention maps caused by the backdoor trigger. Based on this key insight, we propose two effective backdoor detection methods: Frobenius Norm Threshold Truncation and Covariance Di"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2407.04215","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2407.04215/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2407.04215","created_at":"2026-07-05T08:44:55.893781+00:00"},{"alias_kind":"arxiv_version","alias_value":"2407.04215v2","created_at":"2026-07-05T08:44:55.893781+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2407.04215","created_at":"2026-07-05T08:44:55.893781+00:00"},{"alias_kind":"pith_short_12","alias_value":"T4VFLIHRTENJ","created_at":"2026-07-05T08:44:55.893781+00:00"},{"alias_kind":"pith_short_16","alias_value":"T4VFLIHRTENJ3RRC","created_at":"2026-07-05T08:44:55.893781+00:00"},{"alias_kind":"pith_short_8","alias_value":"T4VFLIHR","created_at":"2026-07-05T08:44:55.893781+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":1,"sample":[{"citing_arxiv_id":"2412.01528","citing_title":"CopyrightShield: Enhancing Diffusion Model Security against Copyright Infringement Attacks","ref_index":45,"is_internal_anchor":true}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/T4VFLIHRTENJ3RRCCMIN26K7VC","json":"https://pith.science/pith/T4VFLIHRTENJ3RRCCMIN26K7VC.json","graph_json":"https://pith.science/api/pith-number/T4VFLIHRTENJ3RRCCMIN26K7VC/graph.json","events_json":"https://pith.science/api/pith-number/T4VFLIHRTENJ3RRCCMIN26K7VC/events.json","paper":"https://pith.science/paper/T4VFLIHR"},"agent_actions":{"view_html":"https://pith.science/pith/T4VFLIHRTENJ3RRCCMIN26K7VC","download_json":"https://pith.science/pith/T4VFLIHRTENJ3RRCCMIN26K7VC.json","view_paper":"https://pith.science/paper/T4VFLIHR","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2407.04215&json=true","fetch_graph":"https://pith.science/api/pith-number/T4VFLIHRTENJ3RRCCMIN26K7VC/graph.json","fetch_events":"https://pith.science/api/pith-number/T4VFLIHRTENJ3RRCCMIN26K7VC/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/T4VFLIHRTENJ3RRCCMIN26K7VC/action/timestamp_anchor","attest_storage":"https://pith.science/pith/T4VFLIHRTENJ3RRCCMIN26K7VC/action/storage_attestation","attest_author":"https://pith.science/pith/T4VFLIHRTENJ3RRCCMIN26K7VC/action/author_attestation","sign_citation":"https://pith.science/pith/T4VFLIHRTENJ3RRCCMIN26K7VC/action/citation_signature","submit_replication":"https://pith.science/pith/T4VFLIHRTENJ3RRCCMIN26K7VC/action/replication_record"}},"created_at":"2026-07-05T08:44:55.893781+00:00","updated_at":"2026-07-05T08:44:55.893781+00:00"}