TINA+: Probing Residual Visual Knowledge in Unlearned Diffusion Models via Diffusion-Consistent Text-Free Inversion

πŸ“… 2026-08-18
πŸ“ˆ Citations: 0
✨ Influential: 0
πŸ“„ PDF
πŸ€– AI Summary
ζœ¬ζ–‡ι€šθΏ‡ζε‡ΊTINA+ζ–Ήζ³•οΌŒεˆ©η”¨ζ‰©ζ•£δΈ€θ‡΄ηš„ζ— ζ–‡ζœ¬ι€†ε‘ζŠ€ζœ―ζ₯ζŽ’η©Άθ’«εˆ ι™€ζ¦‚εΏ΅ηš„θ§†θ§‰ηŸ₯θ―†ζ˜―ε¦δ»η„Άε­˜εœ¨δΊŽε›Ύεƒη”Ÿζˆζ¨‘εž‹δΈ­γ€‚
πŸ“ Abstract
Although text-to-image diffusion models exhibit remarkable generative power, concept erasure techniques are essential for preventing harmful content. Existing adversarial probes evaluate these methods by testing whether erased concepts can still be recovered. However, existing erasure and probe methods remain largely text-centric, focusing on whether the text-to-image mapping is severed while overlooking whether the corresponding visual knowledge remains. To investigate this question from a visual perspective, we leverage diffusion inversion to probe whether a generative trajectory can reconstruct visual instances of an erased concept. Under a null-text condition, standard inversion avoids the textual pathway but amplifies approximation errors, hindering faithful trajectory recovery. To address this challenge, we introduce TINA+, a diffusion-consistent Text-free INversion Attack equipped with optimization-based inversion. We also find that unconstrained diffusion inversion may discover spurious trajectories, even allowing a randomly initialized diffusion model to reconstruct the target concept. Such trajectories may falsely indicate residual visual knowledge. TINA+ therefore introduces Diffusion-Consistent Trajectory Regularization to suppress this failure mode. By penalizing trajectories that fall far below the expected marginal energy evolution of diffusion, TINA+ suppresses spurious inversion paths while preserving its ability to recover erased concepts. Experiments across twelve erasure methods, four concept-erasure tasks, and different model architectures demonstrate that TINA+ reliably probes residual visual knowledge through diffusion-consistent visual trajectories. These results provide stronger evidence that current methods often obscure concepts by severing text-image links rather than eliminating the underlying visual knowledge.
Problem

Research questions and friction points this paper is trying to address.

concept erasure
visual knowledge
diffusion models
trajectory reconstruction
Innovation

Methods, ideas, or system contributions that make the work stand out.

diffusion-consistent
text-free inversion
trajectory regularization
residual visual knowledge
concept erasure
πŸ”Ž Similar Papers
No similar papers found.
Q
Qianlong Xiang
School of Computer Science and Technology, Harbin Institute of Technology (Shenzhen), Shenzhen 518055, China; City University of Hong Kong, Hong Kong SAR, China; Shenzhen Loop Area Institute, Shenzhen 518045, China
M
Miao Zhang
Harbin Institute of Technology (Shenzhen), Shenzhen 518055, China
K
Kun Wang
National University of Singapore, Singapore
Haoyu Zhang
Haoyu Zhang
Harbin Institute of Technology (Shenzhen)
Spatial UnderstandingEgocentric VisionMultimodal Analysis
Junhui Hou
Junhui Hou
Department of Computer Science, City University of Hong Kong
Neural Spatial Computing
L
Liqiang Nie
Harbin Institute of Technology (Shenzhen), Shenzhen 518055, China