When Are Concepts Erased From Diffusion Models?

David Bau (Northeastern University) · Rohit Gandikota (Northeastern University) · Kevin Lu (Rutgers University) · Nicky Kriplani (New York University) · Minh Pham (New York University) · Chinmay Hegde (New York University) · Niv Cohen (New York University)
adversarial inputsalternative generationsclassifier guidancecomprehensive evaluationsconcept erasureconcept robustnessdiffusion modelsdiffusion trajectoryevaluation metricsgenerative modelinginternal guidance processesmodel modificationprobing techniquestarget concept removalunconditional likelihoodvisual context

In concept erasure, a model is modified to selectively prevent it from generating a target concept. Despite the rapid development of new methods, it remains unclear how thoroughly these approaches remove the target concept from the model. We begin by proposing two conceptual models for the erasure mechanism in diffusion models: (i) interfering with the model’s internal guidance processes, and (ii) reducing the unconditional likelihood of generating the target concept, potentially removing it entirely. To assess whether a concept has been truly erased from the model, we introduce a comprehensive suite of independent probing techniques: supplying visual context, modifying the diffusion trajectory, applying classifier guidance, and analyzing the model's alternative generations that emerge in place of the erased concept. Our results shed light on the value of exploring concept erasure robustness outside of adversarial text inputs, and emphasize the importance of comprehensive evaluations for erasure in diffusion models.