{"id":"https://openalex.org/W4387076309","doi":"https://doi.org/10.48550/arxiv.2309.14122","title":"SurrogatePrompt: Bypassing the Safety Filter of Text-To-Image Models via Substitution","display_name":"SurrogatePrompt: Bypassing the Safety Filter of Text-To-Image Models via Substitution","publication_year":2023,"publication_date":"2023-01-01","ids":{"openalex":"https://openalex.org/W4387076309","doi":"https://doi.org/10.48550/arxiv.2309.14122"},"language":"en","primary_location":{"is_oa":true,"landing_page_url":"https://arxiv.org/abs/2309.14122","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_indexed_in_scopus":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":["Cornell University"],"type":"repository"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"submittedVersion","is_accepted":false,"is_published":false},"type":"preprint","type_crossref":"posted-content","indexed_in":["arxiv","datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://arxiv.org/abs/2309.14122","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5072485378","display_name":"Zhongjie Ba","orcid":"https://orcid.org/0000-0003-0921-8869"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Ba, Zhongjie","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5063505313","display_name":"Jieming Zhong","orcid":"https://orcid.org/0009-0007-1933-9775"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Zhong, Jieming","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5059032251","display_name":"Jiachen Lei","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Lei, Jiachen","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5021052588","display_name":"Peng Cheng","orcid":"https://orcid.org/0000-0003-1091-7894"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Cheng, Peng","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100603533","display_name":"Qinglong Wang","orcid":"https://orcid.org/0000-0002-7265-0497"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Wang, Qinglong","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5043524348","display_name":"Zhan Qin","orcid":"https://orcid.org/0000-0001-7872-6969"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Qin, Zhan","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100422345","display_name":"Zhibo Wang","orcid":"https://orcid.org/0000-0002-5804-3279"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Wang, Zhibo","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5000596496","display_name":"Kui Ren","orcid":"https://orcid.org/0000-0003-3441-6277"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Ren, Kui","raw_affiliation_strings":[],"affiliations":[]}],"institution_assertions":[],"countries_distinct_count":0,"institutions_distinct_count":0,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":1,"citation_normalized_percentile":{"value":0.710701,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":65,"max":76},"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.993,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.993,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/suspect","display_name":"Suspect","score":0.5478298},{"id":"https://openalex.org/keywords/substitution","display_name":"Substitution (logic)","score":0.5009754}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6363595},{"id":"https://openalex.org/C115961682","wikidata":"https://www.wikidata.org/wiki/Q860623","display_name":"Image (mathematics)","level":2,"score":0.62546957},{"id":"https://openalex.org/C2779356469","wikidata":"https://www.wikidata.org/wiki/Q502918","display_name":"Counterfeit","level":2,"score":0.5925303},{"id":"https://openalex.org/C106131492","wikidata":"https://www.wikidata.org/wiki/Q3072260","display_name":"Filter (signal processing)","level":2,"score":0.56134},{"id":"https://openalex.org/C2778223634","wikidata":"https://www.wikidata.org/wiki/Q224952","display_name":"Suspect","level":2,"score":0.5478298},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.5103211},{"id":"https://openalex.org/C2778220771","wikidata":"https://www.wikidata.org/wiki/Q1522579","display_name":"Substitution (logic)","level":2,"score":0.5009754},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.29889834},{"id":"https://openalex.org/C31972630","wikidata":"https://www.wikidata.org/wiki/Q844240","display_name":"Computer vision","level":1,"score":0.2911308},{"id":"https://openalex.org/C15744967","wikidata":"https://www.wikidata.org/wiki/Q9418","display_name":"Psychology","level":0,"score":0.16945389},{"id":"https://openalex.org/C73484699","wikidata":"https://www.wikidata.org/wiki/Q161733","display_name":"Criminology","level":1,"score":0.096852094},{"id":"https://openalex.org/C17744445","wikidata":"https://www.wikidata.org/wiki/Q36442","display_name":"Political science","level":0,"score":0.08251345},{"id":"https://openalex.org/C199539241","wikidata":"https://www.wikidata.org/wiki/Q7748","display_name":"Law","level":1,"score":0.07105705},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.0}],"mesh":[],"locations_count":3,"locations":[{"is_oa":true,"landing_page_url":"https://arxiv.org/abs/2309.14122","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_indexed_in_scopus":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":["Cornell University"],"type":"repository"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"submittedVersion","is_accepted":false,"is_published":false},{"is_oa":true,"landing_page_url":"http://arxiv.org/abs/2309.14122","pdf_url":"http://arxiv.org/pdf/2309.14122","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_indexed_in_scopus":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":["Cornell University"],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false},{"is_oa":false,"landing_page_url":"https://api.datacite.org/dois/10.48550/arxiv.2309.14122","pdf_url":null,"source":{"id":"https://openalex.org/S4393179698","display_name":"DataCite API","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_indexed_in_scopus":false,"is_core":false,"host_organization":"https://openalex.org/I4210145204","host_organization_name":"DataCite","host_organization_lineage":["https://openalex.org/I4210145204"],"host_organization_lineage_names":["DataCite"],"type":"metadata"},"license":null,"license_id":null,"version":null}],"best_oa_location":{"is_oa":true,"landing_page_url":"https://arxiv.org/abs/2309.14122","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_indexed_in_scopus":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":["Cornell University"],"type":"repository"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"submittedVersion","is_accepted":false,"is_published":false},"sustainable_development_goals":[{"score":0.78,"display_name":"Peace, justice, and strong institutions","id":"https://metadata.un.org/sdg/16"}],"grants":[],"datasets":[],"versions":[],"referenced_works_count":0,"referenced_works":[],"related_works":["https://openalex.org/W4386728183","https://openalex.org/W4366496396","https://openalex.org/W4292622136","https://openalex.org/W4225847548","https://openalex.org/W3197016913","https://openalex.org/W2559305818","https://openalex.org/W2394191954","https://openalex.org/W2389153751","https://openalex.org/W2185015567","https://openalex.org/W2113933481"],"abstract_inverted_index":{"Advanced":[0],"text-to-image":[1],"models":[2,46],"such":[3,81],"as":[4],"DALL-E":[5],"2":[6],"and":[7,58,84,112,154],"Midjourney":[8],"possess":[9],"the":[10,21,49,60,68,77,141,159],"capacity":[11],"to":[12,47,94,115,140],"generate":[13],"highly":[14],"realistic":[15],"images,":[16],"raising":[17],"significant":[18],"concerns":[19],"regarding":[20],"potential":[22],"proliferation":[23],"of":[24,34,39,51,70,80,143],"unsafe":[25],"content.":[26],"This":[27],"includes":[28],"adult,":[29],"violent,":[30],"or":[31],"deceptive":[32],"imagery":[33],"political":[35,147],"figures.":[36],"Despite":[37],"claims":[38],"rigorous":[40],"safety":[41,97,133,168],"mechanisms":[42],"implemented":[43],"in":[44,67,129,149],"these":[45],"restrict":[48],"generation":[50,142],"not-safe-for-work":[52],"(NSFW)":[53],"content,":[54],"we":[55],"successfully":[56],"devise":[57],"exhibit":[59],"first":[61],"prompt":[62,82,93,118],"attacks":[63,83],"on":[64],"Midjourney,":[65],"resulting":[66],"production":[69],"abundant":[71],"photorealistic":[72],"NSFW":[73],"images.":[74],"We":[75],"reveal":[76],"fundamental":[78],"principles":[79],"suggest":[85],"strategically":[86],"substituting":[87],"high-risk":[88],"sections":[89],"within":[90],"a":[91],"suspect":[92],"evade":[95],"closed-source":[96],"measures.":[98],"Our":[99],"novel":[100],"framework,":[101],"SurrogatePrompt,":[102],"systematically":[103],"generates":[104],"attack":[105,117,137,164],"prompts,":[106,138],"utilizing":[107],"large":[108],"language":[109],"models,":[110],"image-to-text,":[111],"image-to-image":[113],"modules":[114],"automate":[116],"creation":[119],"at":[120],"scale.":[121],"Evaluation":[122],"results":[123],"disclose":[124],"an":[125],"88%":[126],"success":[127],"rate":[128],"bypassing":[130],"Midjourney's":[131],"proprietary":[132],"filter":[134],"with":[135],"our":[136,163],"leading":[139],"counterfeit":[144],"images":[145,160],"depicting":[146],"figures":[148],"violent":[150],"scenarios.":[151],"Both":[152],"subjective":[153],"objective":[155],"assessments":[156],"validate":[157],"that":[158],"generated":[161],"from":[162],"prompts":[165],"present":[166],"considerable":[167],"hazards.":[169]},"abstract_inverted_index_v3":null,"cited_by_api_url":"https://api.openalex.org/works?filter=cites:W4387076309","counts_by_year":[{"year":2024,"cited_by_count":1}],"updated_date":"2025-04-19T10:08:33.377354","created_date":"2023-09-27"}