Pith. sign in

REVIEW 2 cited by

Prompt Recovery for Image Generation Models: A Comparative Study of Discrete Optimizers

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2408.06502 v2 pith:LPF6JGKL submitted 2024-08-12 cs.CV cs.LG

classification cs.CVcs.LG
keywords imagepromptsdiscretegeneratedinvertedimagescaptionergeneration
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Recovering natural language prompts for image generation models, solely based on the generated images is a difficult discrete optimization problem. In this work, we present the first head-to-head comparison of recent discrete optimization techniques for the problem of prompt inversion. We evaluate Greedy Coordinate Gradients (GCG), PEZ , Random Search, AutoDAN and BLIP2's image captioner across various evaluation metrics related to the quality of inverted prompts and the quality of the images generated by the inverted prompts. We find that focusing on the CLIP similarity between the inverted prompts and the ground truth image acts as a poor proxy for the similarity between ground truth image and the image generated by the inverted prompts. While the discrete optimizers effectively minimize their objectives, simply using responses from a well-trained captioner often leads to generated images that more closely resemble those produced by the original prompts.

Discussion (0). Sign in to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score.

  1. Prompt Pirates Need a Map: Stealing Seeds helps Stealing Prompts

    cs.CR 2025-09 conditional novelty 6.0 of 10

    Diffusion image tools inherit a 32-bit seed weakness from PyTorch, letting an attacker recover the seed in about 140 minutes and then use it, via a genetic algorithm, to steal the prompt behind a public image.

  2. The Resurgence of GCG Adversarial Attacks on Large Language Models

    cs.CL 2025-08 conditional novelty 3.0 of 10

    The paper reports that GCG attack success drops with model size, prefix-based metrics overestimate harm, and coding prompts are more vulnerable, but these findings rest on a small model set and a GPT-4o pipeline that ...

Pith tools