Skip to main navigation Skip to search Skip to main content

GenBreak: Red Teaming Text-to-Image Generation Using Large Language Models

  • Zilong Wang
  • , Xiang Zheng*
  • , Xiaosen Wang
  • , Bo Wang
  • , Xingjun Ma*
  • *Corresponding author for this work

Research output: Chapters, Conference Papers, Creative and Literary WorksRGC 32 - Refereed conference paper (with host publication)peer-review

Abstract

Text-to-image (T2I) models such as Stable Diffusion have advanced rapidly and are widely used in content creation. However, these models can be misused to generate harmful content, including nudity or violence, posing significant safety risks. While most platforms employ content moderation systems, underlying vulnerabilities can still be exploited by adversaries. Recent research on red-teaming and adversarial attacks against T2I models faces a critical limitation: existing methods struggle to balance prompt stealthiness with image toxicity. Some studies successfully generate highly toxic images but use adversarial prompts that are easily detected by safety filters, while others focus on bypassing safety mechanisms but fail to produce genuinely harmful outputs, neglecting the discovery of truly high-risk prompts. Consequently, there remains a lack of reliable tools for evaluating the safety of defended T2I models. To address this gap, we propose GenBreak, a framework that fine-tunes a red-team large language model (LLM) to systematically explore underlying vulnerabilities in T2I generators. Our approach combines supervised fine-tuning on curated datasets with reinforcement learning via interaction with a surrogate T2I model. By integrating multiple reward signals, we guide the LLM to craft adversarial prompts that enhance both evasion capability and image toxicity, while maintaining semantic coherence and diversity. These prompts demonstrate strong effectiveness in black-box attacks against commercial T2I generators, revealing practical safety weaknesses. Code is available at https: //github.com/wangdandan567/RT-diffuser.
Original languageEnglish
Title of host publicationProceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR)
Pages15730-15739
Number of pages10
Publication statusOnline published - Jun 2026
Event2026 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR 2026)
- Colorado Convention Center, Denver, United States
Duration: 3 Jun 20267 Jun 2026
https://cvpr.thecvf.com/

Conference

Conference2026 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR 2026)
PlaceUnited States
CityDenver
Period3/06/267/06/26
Internet address

Bibliographical note

Research Unit(s) information for this publication is provided by the author(s) concerned.

Funding

This work is supported in part by the National Natural Science Foundation of China (Grant No. 62521004).

Fingerprint

Dive into the research topics of 'GenBreak: Red Teaming Text-to-Image Generation Using Large Language Models'. Together they form a unique fingerprint.

Cite this