Existing attacks on unlearned diffusion models assume that the erased concepts are known in advance and focus on recovering them. In practice, however, model providers may not disclose which concepts have been removed, and even with access to the original base model, an adversary may still lack a clear target to attack. In this paper, we aim to answer the following critical but overlooked questions: which concepts have been erased from the model, and how many have been erased in total? To this end, we present Tracer, a framework that rapidly and accurately identifies erased concepts and estimates their number. Tracer efficiently identifies erased concepts without generating and classifying images. By combining lightweight spectral analysis of weight footprints, it enables efficient search over large candidate vocabularies. To distinguish multiple erased concepts, we introduce a footprint coverage objective that guides sequential discovery. Tracer estimates the number of erased concepts by detecting a sharp decline in candidate confidence as the selected concepts account for the erasure footprint, without requiring labeled examples for calibration. The framework requires only lightweight linear algebra and limited forward probes, with no prior knowledge of the unlearning algorithm. Experiments across text-to-image and text-to-video backbones and diverse unlearning methods demonstrate that Tracer identifies erased concepts and estimates their number in seconds, achieving 150 to 137,000 times and 133 to 20,000 times speedups over MIA and brute-force search on image and video models, respectively, with substantially higher identification accuracy.
Figures & tables
Figure 1: (a) Motivation: existing unlearning attacks assume known unlearning targets, leaving the identification of targets unexplored. (b) Current problem: adapted MIA and brute-force method incur high computational costs and struggle to determine target counts and distinguish targets from affected non-targets. (c) Tracer : identifies erased concepts and estimates their number in seconds without prior target knowledge, knowledge of the unlearning algorithm, or image generation.
Figure 2: Overview of Tracer . (a) Erasure footprint assembly. Erasure imprints are grouped by their probed input representations. Spectrally reshaped and reweighted Gram matrices are fused within compatible groups into footprints Gg . (b) Candidate encoding. Candidates are encoded in each group’s input space, whitened to suppress shared structure, and normalized. (c) Unlearned concept disclosure. Tracer iteratively selects concepts explaining the remaining footprint energy. selection combines standardized gains across groups with confidence-based weights. Label-free self-calibration fixes parameters and group weights. Confidence drops determine set size without image generation or algorithm knowledge.
Method
Venue
Erased-set size K
Avg. ( ↑ )
1
3
5
10
20
Stable Diffusion v1.5
ESD
ICCV 2023
100
100
94
–
–
98.0
UCE
WACV 2024
100
100
100
100
100
100.0
MACE
CVPR 2024
100
100
100
100
–
100.0
FMN
CVPR 2024a
100
100
100
–
–
100.0
Table 1: Identification accuracy (%) of erased object concepts across three text-to-image backbones on Imagenette-20. Shaded cells report evaluated results. “–” indicates an unevaluated setting.
Figure 4Table 5
Figure 5: Runtime across three methods, showing the scalability of Tracer to large candidate sets.
Controls background suppression, from no transformation to full regularized whitening. Unit normalization is retained in both cases.
ρ
{0,0.5,1}
Controls spectral shaping within each imprint.
o
{2,1}
Specifies the token position relative to the non-padding sequence length for token-based text encodings.
Appendix
Table 6: Self-calibration search grid for the main configuration.
Parameter
Value
Role
κ
0.25
Specifies the upper-tail comparison range in the confidence statistic.
J
96
Sets the fixed search horizon.
B
8
Sets the window length for the initial-rise condition.
α
0.30
Sets the relative threshold for the first sufficiently large decline.
ε0
10−3
Sets the relative spectral cutoff in Eq. equation 1 .
εc
10−12
Stabilizes the confidence denominator in Eq. equation 4 .
Appendix
Table 7: Fixed parameters for confidence computation, erased-set size detection, and numerical stabilization in the main configuration.
Index
Object templates
Artistic-style templates
1
a photo of a {}
art by {}
2
{}
{}
3
an image of a {}
painting by {}
4
a picture of a {}
artwork by {}
5
a photo of the {}
style of {}
Appendix
Table 8: Prompt templates for probe matching and candidate encoding. Each placeholder is replaced with the complete vocabulary entry.
Erased-set size K
Method
Venue
1
3
5
10
20
Avg. ↑
Stable Diffusion v1.5
ESD
ICCV 2023
100
100
100
92
–
98.0
UCE
WACV 2024
100
100
100
100
100
100.0
MACE
CVPR 2024
100
100
100
100
–
100.0
FMN
CVPR 2024a
100
100
100
–
–
100.0
Appendix
Table 9: Identification accuracy (%) of erased artistic styles across three text-to-image backbones. K denotes the number of jointly erased styles. Shaded cells report evaluated results. “–” indicates an unevaluated setting. Avg. is the arithmetic mean over evaluated settings within each row.