cs.CVApr 30, 2025

The Linear Geometry of Interpretable Tokens: Jailbreaking Attacks and Defenses for Unlearned Diffusion Models

Authors: Siyi Chen, Yimeng Zhang, Sijia Liu, Qing Qu

Organizations: University of Michigan · Michigan State University

Abstract

Diffusion models excel at generating high-quality images but can memorize and reproduce harmful concepts when prompted. Although fine-tuning methods have been proposed to unlearn a target concept, they struggle to fully erase it while maintaining generation quality on other concepts, leaving models vulnerable to jailbreak attacks. Existing jailbreak methods demonstrate this vulnerability but offer limited insight into how unlearned models retain harmful concepts, limiting progress on effective defenses. In this work, we show that a coherent, interpretable, attack-accessible linear residual of the erased concept can be recovered in the token embedding space, and that both an attack and a defense follow from this structure. We introduce SubAttack, a novel jailbreaking attack that reads out this subspace by learning an orthogonal set of attack token embeddings, each being a linear combination of human-interpretable textual elements, revealing that unlearned models still retain the target concept through related textual components. Furthermore, our attack is also more powerful and transferable across text prompts, initial noises, and unlearned models than prior attacks. Conversely, projecting out the same subspace yields SubDefense, a lightweight plug-and-play defense mechanism that suppresses the residual concept in unlearned models. SubDefense provides stronger robustness than existing defenses while better preserving safe generation quality. Extensive experiments across multiple unlearning methods, concepts, and attack types demonstrate that our approach advances both understanding and mitigation of vulnerabilities in diffusion unlearning.

Figures & tables

Appendix figures & tables44 assets

Supplementary material from the paper’s appendix.

Appendix

Explore similar work

CardsList
  1. Your Unlearning Gives You Away: Identifying Erased Concepts in Diffusion Models

    Oct 4, 2026Kaiyuan Deng, Yuchen Li, Yang Xiao +3

  2. You Can't Have It Both Ways: Concept Entanglement Limits Diffusion Model Unlearning

    Sep 28, 2026Yian Wang, Ali Ebrahimpour-Boroojeny, Hari Sundaram +1Text-To-Image Diffusion ModelsConcept Erasure

  3. Projected Gradient Unlearning for Text-to-Image Diffusion Models: Defending Against Concept Revival Attacks

    Apr 22, 2026Aljalila Aladawi, Mohammed Talha Alam, Fakhri KarrayText-To-Image Diffusion ModelsDiffusion Models