Text-to-Image generation models have revolutionized the artwork design process and enabled anyone to create high-quality images by entering text descriptions called prompts. Creating a high-quality prompt that consists of a subject and several modifiers can be time-consuming and costly. In consequence, a trend of trading high-quality prompts on specialized marketplaces has emerged. In this paper, we perform the first study on understanding the threat of a novel attack, namely prompt stealing attack, which aims to steal prompts from generated images by text-to-image generation models. Successful prompt stealing attacks directly violate the intellectual property of prompt engineers and jeopardize the business model of prompt marketplaces. We first perform a systematic analysis on a dataset collected by ourselves and show that a successful prompt stealing attack should consider a prompt's subject as well as its modifiers. Based on this observation, we propose a simple yet effective prompt stealing attack, PromptStealer. It consists of two modules: a subject generator trained to infer the subject and a modifier detector for identifying the modifiers within the generated image. Experimental results demonstrate that PromptStealer is superior over three baseline methods, both quantitatively and qualitatively. We also make some initial attempts to defend PromptStealer. In general, our study uncovers a new attack vector within the ecosystem established by the popular text-to-image generation models. We hope our results can contribute to understanding and mitigating this emerging threat.
翻译:文本到图像生成模型彻底改变了艺术作品设计流程,使任何人都能通过输入称为提示词的文本描述来创建高质量图像。创作由主体和若干修饰词组成的高质量提示词既耗时又昂贵。因此,在专门化市场中交易优质提示词的商业模式应运而生。本文首次针对新型攻击威胁——提示词窃取攻击展开研究,该攻击旨在通过文本到图像生成模型生成的图像窃取原始提示词。成功的提示词窃取攻击将直接侵犯提示词工程师的知识产权,并危及提示词市场的商业模型。我们在自行收集的数据集上开展系统性分析,结果表明有效的提示词窃取攻击需要同时考虑提示词的主体及其修饰词。基于此发现,我们提出一种简单高效的提示词窃取攻击方法PromptStealer,由两个模块构成:用于推断主体的主体生成器,以及识别生成图像中修饰词的修饰词检测器。实验结果表明,PromptStealer在定量与定性指标上均优于三种基线方法。我们还对PromptStealer的防御进行了初步探索。总体而言,本研究揭示了基于流行文本到图像生成模型生态系统的全新攻击向量,期望研究成果能为理解并缓解这一新兴威胁提供参考。