cs.CVSep 30, 2026

Learning Normal Diffusion Dynamics for Backdoor Defense in Text-to-Image Models

Authors: Junjian Li, Xiaolong Liu, Peng Sun, Liantao Wu, Linghan Chen, Yudong Gao, Honglong Chen

Organizations: Geely · Hunan University · East China Normal University · University of Adelaide · The Hong Kong University of Science and Technology · China University of Petroleum (East China)

Abstract

Backdoor attacks pose a serious threat to the secure deployment of text-to-image (T2I) diffusion models. Existing defenses typically detect backdoors from specific abnormal patterns in internal representations, which may limit their generalizability with the emergence of increasingly diverse attack mechanisms. In this paper, we study backdoor defense of T2I diffusion models from a transition-dynamics perspective. We observe that benign diffusion trajectories exhibit structured and timestep-dependent transition patterns from cross-attention, latent and noise spaces, whereas backdoor attacks tend to induce deviations from such normal evolution. Motivated by these observations, we propose Normal Diffusion Dynamics Learning (NDDL), a novel backdoor defense framework that learns the normal transition dynamics of diffusion trajectories utilizing only benign samples. NDDL constructs compact multi-space trajectory representations and trains a timestep-conditioned dynamics model to predict the diffusion evolution. In the inference phase, deviations between the observed and predicted transitions are exploited to quantify dynamics inconsistency for backdoor detection. NDDL further enables trigger localization without any prior knowledge of the embedded backdoor by performing substitution with low-semantic words. Extensive experiments for diverse backdoor attacks demonstrate the effectiveness and generalizability of our proposed NDDL.

Figures & tables

Appendix figures & tables15 assets

Supplementary material from the paper’s appendix.

Appendix

Explore similar work

CardsList
  1. Awakening the Hydra: Stabilizing Multi-Concept Backdoor Injection in Text-to-Image Diffusion Models

    May 19, 2026Kai Wang, Jiale Zhang, Chengcheng Zhu +2Text-To-Image Diffusion ModelsDiffusion Models

  2. PersGuard: Preventing Malicious Personalization in Text-to-Image Diffusion Models via Model Backdoors

    Feb 22, 2025Xinwei Liu, Xiaojun Jia, Yuan Xun +2Text-To-Image Diffusion ModelsDiffusion Models