UnlearnDiffAtk: Unlearned Diffusion Model Benchmark
This benchmark evaluates the robustness and utility retaining of safety-driven unlearned diffusion models (DMs) across a variety of tasks. For more details, please visit the project.
- The robustness of unlearned DM is evaluated through our proposed adversarial prompt attack, UnlearnDiffAtk, which has been accepted to ECCV 2024.
- The utility retaining of unlearned DM is evaluated through FID and CLIP score on the generated images using 10K randomly sampled COCO caption prompts.
Demo of our offensive method: UnlearnDiffAtk
Demo of our defensive method: AdvUnlearn
[Evaluation Metrics]:
- Pre-Attack Success Rate (Pre-ASR): lower is better;
- Post-attack success rate (Post-ASR): lower is better;
- FrΓ©chet inception distance(FID): evaluate distributional quality of image generations, lower is better;
- CLIP Score: measure contextual alignment with prompt descriptions, higher is better.
[DM Unlearning Tasks]:
- NSFW: Nudity
- Style: Van Gogh
- Objects: Church, Tench, Parachute, Garbage Truck
For more details of Unlearning Methods used in this benchmarks:
- Adversarial Unlearning (AdvUnlearn);
- Erased Stable Diffusion (ESD);
- Forget-Me-Not (FMN);
- Ablating Concepts (AC);
- Unified Concept Editing (UCE);
- concept-SemiPermeable Membrane (SPM);
- Saliency Unlearning (SalUn);
- EraseDiff (ED);
- ScissorHands (SH);
- Mass Concept Erasure (MACE);
- Reliable and Efficient Concept Erasure (RECE);
- Training-Free and Adaptive Guard (SAFREE).
We will evaluate your model on UnlearnDiffAtk Benchmark!
Open a github issue or email us at [email protected]!
[Unlearned Concept]: Nudity
Unlearned_Methods | Pre-ASR | Post-ASR | FID | CLIP-Score |
|---|---|---|---|---|
AdvUnlearn | 88.03 | 97.89 | 128.53 | 0.308 |
Unlearned_Methods | Pre-ASR | Post-ASR | FID | CLIP-Score |
|---|---|---|---|---|
AdvUnlearn | 88.03 | 97.89 | 128.53 | 0.308 |
Unlearned_Methods | Pre-ASR | Post-ASR | FID | CLIP-Score |
|---|---|---|---|---|
FMN | 88.03 | 97.89 | 16.86 | 0.308 |
SPM | 54.93 | 91.55 | 17.48 | 0.31 |
SAFREE | 26.06 | 85.59 | 19.28 | 0.259 |
UCE | 21.83 | 79.58 | 17.1 | 0.309 |
ESD | 20.42 | 76.05 | 18.18 | 0.302 |
RECE | 13.38 | 75.42 | 17.2 | 0.259 |
MACE | 9.1 | 74.57 | 16.9 | 0.239 |
AdvUnlearn | 7.75 | 21.13 | 19.34 | 0.29 |
SalUn | 1.41 | 11.27 | 33.62 | 0.287 |
SH | 0 | 7.04 | 128.53 | 0.235 |
ED | 0 | 2.11 | 233 | 0.18 |
[Unlearned Style]: Van Gogh
Unlearned_Methods | Pre-ASR | Post-ASR | FID | CLIP-Score |
|---|---|---|---|---|
AdvUnlearn | 62 | 70.73 | 16.31 | 0.311 |
Unlearned_Methods | Pre-ASR | Post-ASR | FID | CLIP-Score |
|---|---|---|---|---|
UCE | 62 | 94 | 16.31 | 0.311 |
SPM | 42 | 88 | 16.65 | 0.311 |
SAFREE | 8 | 87.8 | 30.47 | 0.254 |
AC | 12 | 77 | 17.5 | 0.31 |
RECE | 14 | 70.73 | 24.89 | 0.265 |
MACE | 6 | 58.53 | 22.43 | 0.233 |
FMN | 10 | 56 | 16.59 | 0.309 |
ESD | 2 | 32 | 18.71 | 0.304 |
AdvUnlearn | 0 | 2 | 16.96 | 0.308 |
Unlearned_Methods | Pre-ASR | Post-ASR | FID | CLIP-Score |
|---|---|---|---|---|
AdvUnlearn | 62 | 70.73 | 16.31 | 0.311 |
Unlearned_Methods | Pre-ASR | Post-ASR | FID | CLIP-Score |
|---|---|---|---|---|
UCE | 62 | 94 | 16.31 | 0.311 |
SPM | 42 | 88 | 16.65 | 0.311 |
SAFREE | 8 | 87.8 | 30.47 | 0.254 |
AC | 12 | 77 | 17.5 | 0.31 |
RECE | 14 | 70.73 | 24.89 | 0.265 |
MACE | 6 | 58.53 | 22.43 | 0.233 |
FMN | 10 | 56 | 16.59 | 0.309 |
ESD | 2 | 32 | 18.71 | 0.304 |
AdvUnlearn | 0 | 2 | 16.96 | 0.308 |
[Unlearned Object]: Church
Unlearned_Methods | Pre-ASR | Post-ASR | FID | CLIP-Score |
|---|---|---|---|---|
AdvUnlearn | 52 | 60.97 | 16.49 | 0.308 |
Unlearned_Methods | Pre-ASR | Post-ASR | FID | CLIP-Score |
|---|---|---|---|---|
FMN | 52 | 96 | 16.49 | 0.308 |
SPM | 44 | 94 | 16.76 | 0.31 |
SAFREE | 18 | 68.3 | 28.41 | 0.257 |
SalUn | 10 | 62 | 17.38 | 0.312 |
RECE | 2 | 60.97 | 26.85 | 0.263 |
ESD | 14 | 60 | 20.95 | 0.3 |
ED | 6 | 52 | 17.46 | 0.31 |
AdvUnlearn | 0 | 6 | 18.06 | 0.305 |
SH | 0 | 6 | 68.02 | 0.277 |
Unlearned_Methods | Pre-ASR | Post-ASR | FID | CLIP-Score |
|---|---|---|---|---|
AdvUnlearn | 52 | 60.97 | 16.49 | 0.308 |
Unlearned_Methods | Pre-ASR | Post-ASR | FID | CLIP-Score |
|---|---|---|---|---|
FMN | 52 | 96 | 16.49 | 0.308 |
SPM | 44 | 94 | 16.76 | 0.31 |
SAFREE | 18 | 68.3 | 28.41 | 0.257 |
SalUn | 10 | 62 | 17.38 | 0.312 |
RECE | 2 | 60.97 | 26.85 | 0.263 |
ESD | 14 | 60 | 20.95 | 0.3 |
ED | 6 | 52 | 17.46 | 0.31 |
AdvUnlearn | 0 | 6 | 18.06 | 0.305 |
SH | 0 | 6 | 68.02 | 0.277 |
[Unlearned Object]: Garbage
Unlearned_Methods | Pre-ASR | Post-ASR | FID | CLIP-Score |
|---|---|---|---|---|
AdvUnlearn | 40 | 98 | 16.14 | 0.308 |
Unlearned_Methods | Pre-ASR | Post-ASR | FID | CLIP-Score |
|---|---|---|---|---|
FMN | 40 | 98 | 16.14 | 0.308 |
SPM | 4 | 82 | 16.79 | 0.31 |
SalUn | 2 | 42 | 18.03 | 0.311 |
ED | 6 | 38 | 19.22 | 0.307 |
ESD | 2 | 24 | 24.81 | 0.29 |
AdvUnlearn | 0 | 8 | 17.92 | 0.305 |
Unlearned_Methods | Pre-ASR | Post-ASR | FID | CLIP-Score |
|---|---|---|---|---|
AdvUnlearn | 40 | 98 | 16.14 | 0.308 |
Unlearned_Methods | Pre-ASR | Post-ASR | FID | CLIP-Score |
|---|---|---|---|---|
FMN | 40 | 98 | 16.14 | 0.308 |
SPM | 4 | 82 | 16.79 | 0.31 |
SalUn | 2 | 42 | 18.03 | 0.311 |
ED | 6 | 38 | 19.22 | 0.307 |
ESD | 2 | 24 | 24.81 | 0.29 |
AdvUnlearn | 0 | 8 | 17.92 | 0.305 |
[Unlearned Object]: Parachute
Unlearned_Methods | Pre-ASR | Post-ASR | FID | CLIP-Score |
|---|---|---|---|---|
AdvUnlearn | 46 | 100 | 16.72 | 0.307 |
Unlearned_Methods | Pre-ASR | Post-ASR | FID | CLIP-Score |
|---|---|---|---|---|
FMN | 46 | 100 | 16.72 | 0.307 |
SPM | 26 | 96 | 16.77 | 0.311 |
ED | 4 | 82 | 18.53 | 0.309 |
SalUn | 8 | 74 | 18.87 | 0.311 |
ESD | 4 | 54 | 21.4 | 0.299 |
SH | 2 | 24 | 55.18 | 0.202 |
AdvUnlearn | 2 | 14 | 17.78 | 0.306 |
Unlearned_Methods | Pre-ASR | Post-ASR | FID | CLIP-Score |
|---|---|---|---|---|
AdvUnlearn | 46 | 100 | 16.72 | 0.307 |
Unlearned_Methods | Pre-ASR | Post-ASR | FID | CLIP-Score |
|---|---|---|---|---|
FMN | 46 | 100 | 16.72 | 0.307 |
SPM | 26 | 96 | 16.77 | 0.311 |
ED | 4 | 82 | 18.53 | 0.309 |
SalUn | 8 | 74 | 18.87 | 0.311 |
ESD | 4 | 54 | 21.4 | 0.299 |
SH | 2 | 24 | 55.18 | 0.202 |
AdvUnlearn | 2 | 14 | 17.78 | 0.306 |
[Unlearned Object]: Tench
Unlearned_Methods | Pre-ASR | Post-ASR | FID | CLIP-Score |
|---|---|---|---|---|
AdvUnlearn | 42 | 100 | 16.45 | 0.308 |
Unlearned_Methods | Pre-ASR | Post-ASR | FID | CLIP-Score |
|---|---|---|---|---|
FMN | 42 | 100 | 16.45 | 0.308 |
SPM | 6 | 90 | 16.75 | 0.311 |
ESD | 2 | 36 | 18.12 | 0.301 |
ED | 0 | 16 | 17.13 | 0.31 |
SalUn | 0 | 14 | 17.97 | 0.313 |
SH | 0 | 8 | 57.66 | 0.28 |
AdvUnlearn | 0 | 4 | 17.26 | 0.307 |
Unlearned_Methods | Pre-ASR | Post-ASR | FID | CLIP-Score |
|---|---|---|---|---|
AdvUnlearn | 42 | 100 | 16.45 | 0.308 |
Unlearned_Methods | Pre-ASR | Post-ASR | FID | CLIP-Score |
|---|---|---|---|---|
FMN | 42 | 100 | 16.45 | 0.308 |
SPM | 6 | 90 | 16.75 | 0.311 |
ESD | 2 | 36 | 18.12 | 0.301 |
ED | 0 | 16 | 17.13 | 0.31 |
SalUn | 0 | 14 | 17.97 | 0.313 |
SH | 0 | 8 | 57.66 | 0.28 |
AdvUnlearn | 0 | 4 | 17.26 | 0.307 |