arXiv Machine Learning

Cyclic Denoising Reveals Ultrastable Memories in Diffusion Models

arXiv:2606. 24000v1 Announce Type: new Abstract: We introduce cyclic denoising -- repeated forward and reverse diffusion at controlled noise amplitudes -- as an extraction attack for image diffusion models.

arXiv AI
Aug 28

The Principles of Diffusion Models

The book "The Principles of Diffusion Models" outlines the foundational concepts behind diffusion models, tracing their evolution from a forward process that corrupts data into noise to a reverse process that reconstructs data. It presents three complementary perspectives—variational, score-based, and flow-based—each describing how a time-dependent velocity field transports a simple prior to the data distribution. The text also covers practical guidance for controllable generation, efficient solvers, and diffusion-inspired flow-map models, providing a mathematically grounded framework for readers with basic deep‑learning knowledge.

By Chieh-Hsin Lai, Yang Song, Dongjun Kim, Yuki Mitsufuji, Stefano Ermon
arXiv Machine Learning
Sep 10

DRIFT: Removing Diffusion Watermarks by Deflecting the Generative Trajectory

DRIFT is a black‑box attack that removes diffusion watermarks by deflecting the generative trajectory. It combines partial forward diffusion with stochastic reverse resampling to limit the source information available to a fixed‑depth recovery pipeline and to explore alternative noise‑driven paths. Across nine watermarks, DRIFT achieves 98–100% success while preserving image quality, without requiring secret keys, verifier internals, or per‑image gradient optimization.

By Rui Bao, Zheng Gao, Xiaoyu Li, Xiaoyan Feng, Yang Song, Jiaojiao Jiang
arXiv Computation and Language
Aug 25

DynHD: Hallucination Detection for Diffusion Large Language Models via Denoising Dynamics Deviation Learning

DynHD is a method for detecting hallucinations in diffusion large language models (D‑LLMs) by focusing on token‑level uncertainty and its evolution during the denoising process. It introduces a semantic‑aware evidence construction module that filters out non‑informative structural tokens and highlights uncertainty in informative tokens, and a reference evidence generator that models the expected trajectory of uncertainty, enabling a deviation‑based detector to identify hallucinations. Experiments show DynHD outperforms existing baselines while being more efficient across various benchmarks and backbone models.

By Yanyu Qian, Yue Tan, Yixin Liu, Wang Yu, Shirui Pan
arXiv Machine Learning
Sep 10

Noise in Diffusion Models Is a Learnable Input

The paper argues that the concrete random noise used in diffusion models is not merely a passive perturbation but a learnable input that can be exploited by the model. By analyzing how clean data and realized noise jointly form the noisy input, the authors show that the model can learn regularities in the data or in the noise structure, and that these two routes can interact. Experiments on MNIST and CIFAR‑10 using pseudorandom streams demonstrate that structured‑noise training can reduce prediction loss, but this advantage disappears when test noise is replaced with IID noise, indicating that the learned dependence is tied to the specific noise structure.

By Shengzhi Deng, Chenqi Ye, Yanze Guo
arXiv AI
Sep 3

Language Diffusion Models are Associative Memories Capable of Retrieving Unseen Data

The paper investigates when language diffusion models, specifically Uniform-based Discrete Diffusion Models (UDDMs), shift from memorizing training data to generalizing to new data. It shows that UDDMs act as associative memories, forming basins of attraction around stored examples without requiring an explicit energy function. By measuring token recovery and conditional entropy, the authors identify a sharp transition governed by training set size, where memorization (vanishing entropy) gives way to generalization (finite entropy).

By Bao Pham, Mohammed J. Zaki, Luca Ambrogioni, Dmitry Krotov, Matteo Negri
Hugging Face Trending Papers
Sep 8

DRIFT: Removing Diffusion Watermarks by Deflecting the Generative Trajectory

DRIFT is a black‑box attack that removes diffusion watermarks by combining partial forward diffusion with stochastic reverse resampling. It limits the source information available to a fixed‑depth recovery pipeline and uses stochastic reversal to explore alternative noise‑driven paths, refining fidelity only on updates rejected by the same verifier. Across nine watermarks, DRIFT achieves 98–100% attack success and the best image quality without requiring secret keys, verifier internals, or per‑image gradient optimization.

arXiv Computer Vision
Sep 3

TIGA: Trajectory-Injected Generative Attack against Black-box AIGC Detectors

The paper introduces TIGA, a source‑image‑free, training‑free attack that injects adversarial properties into a diffusion model’s sampling trajectory to evade black‑box AIGC forensic detectors. TIGA aggregates gradients from white‑box surrogate detectors to create a transferable prior, then uses anisotropic directional search with finite‑difference queries to estimate and stabilize directions for the DDIM trajectory, applying frequency‑domain reshaping to reduce artifacts. Experiments demonstrate strong black‑box attack performance, transferability, and robustness to post‑processing while maintaining high perceptual quality.

By Xia Du, Zhuosen Bao, Zheng Lin, Jizhe Zhou, Chi-man Pun, Jun Luo, Symeon Chatzinotas