[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-82926-en":3,"doc-seo-82926-105":30,"detail-sidebar-cat-0-en-105":92},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},82926,8796095461610,"Oliver","https://ap-avatar.wpscdn.com/davatar_276721f389ce27ea32af1340a28f341c",8,"Research & Report","Erasing Without Collateral Damage: Precise Concept Removal in Diffusion Models","Training-free concept erasure enables precise control of text-to-image diffusion models, yet naive approaches can unintentionally harm semantically related non-target concepts. Prior value-space methods remove components along the target direction, implicitly conflating target identity with shared visual structure, which causes collateral damage. CARE introduces a closed-form erasure operator that computes a kept-subspace-aware direction from retained concept anchors, applies it directly in cross-attention value space, and uses a single shrinkage parameter to control the erase–preserve trade-off.","arXiv :2607 .05274v 1 [ cs .CV] 6 Jul 2026  \nErasing Without Collateral Damage: Precise Concept Removal in Diffusion Models  \nParth Upman 1 , Nishita Jain2 , and Shreyank N Gowda 1  \n1 School of Computer Science, University of Nottingham, Nottingham, NG8 1BB, UK  \n2 Department of Computing, Imperial College London, London, SW7 2AZ, UK {psxpu1,[shreyank.narayanagowda}@nottingham.ac.uk](shreyank.narayanagowda}@nottingham.ac.uk)  \nAbstract. Training-free concept erasure is an attractive mechanism for controlling text-to-image diffusion models, but precise erasure often comes at the cost of damaging semantically related non-target concepts. Existing value-space methods remove the component of each cross-attention value along the target concept direction, implicitly treating target identity and shared visual structure as the same signal. We argue that this is the source of much of the collateral damage in prior preservation.  \nWe introduce CARE, a closed-form concept erasure operator that replaces the raw target direction with a kept-subspace-aware direction computed from a small bank of retained concept anchors. The resulting edit is applied directly in cross-attention value space, requires no model fine-tuning, and adds only a negligible offline computation. A single shrinkage parameter controls the erase–preserve trade-off. We further show that the operator admits a minimum-disturbance interpretation and, in its projection form, leaves the kept subspace invariant.  \nExperiments under the standard concept-erasure protocol show that our method preserves non-target concepts more faithfully while maintaining competitive erasure across instance, style, and celebrity concepts. Code:  \n[https://github.com/parthupman/care](https://github.com/parthupman/care)  \nKeywords: Concept Erasure · Diffusion Models · Generative AI Safety  \n1 Introduction  \nText-to-image diffusion models have become a practical interface for visual content creation, generating high-quality images from natural language prompts across objects, scenes, styles, identities, and abstract concepts [6, 13 , 26 , 29] . Their success relies partly on large-scale image-text pretraining and web-scale data collection [27, 32], but this scale also creates a deployment problem: models trained on weakly curated corpora can reproduce copyrighted characters, distinctive artistic styles, public figures, unsafe content, or other concepts that a model owner may wish to restrict [2, 4 , 23 , 31] . Since retraining a released model from scratch for every newly identified concept is rarely practical, concept erasure has become an important problem for controllable generative modelling: remove a target concept while preserving the rest of the model’s visual knowledge.  \n2 Upman et al.  \nThe central difficulty is that concept erasure is not simply about weakening generation. A useful method must be both effective and specific: prompts containing the target concept should no longer render it, while prompts for nontarget concepts should remain faithful to the original model. These goals are naturally in tension. Removing a cartoon character should not damage other cartoon characters; erasing an artist style should not flatten related painterly styles; suppressing one public figure should not degrade face generation more broadly. The challenge is therefore to erase without collateral damage.  \nExisting erasure methods approach this trade-off in different ways. Trainingbased methods fine-tune the diffusion model or attach lightweight modules to forget the target concept [9, 16 , 19 , 20 , 39] . They can achieve strong erasure, but usually require per-concept optimization and preserve the prior only through regularization, anchor losses, or adapters. Closed-form weight-editing methods avoid iterative fine-tuning by solving for changes to cross-attention projections [10, 11], but the edit is still baked into model weights and typically depends on an explicitly specified preserve set. Training-fre","cbCaifYGyZLc5XAA","https://ap.wps.com/l/cbCaifYGyZLc5XAA","pdf",3737507,5,1,24,"English","en",105,"# Introduction\n## Problem: Erasing without collateral damage\n## Existing approaches and their limitations\n## CARE method overview","[{\"question\":\"What problem does the document address in concept erasure for diffusion models?\",\"answer\":\"It addresses how to remove a target concept from text-to-image diffusion outputs without damaging semantically related non-target concepts that share visual structure.\"},{\"question\":\"Why do prior value-space erasure methods cause collateral damage?\",\"answer\":\"They remove cross-attention value components along the target direction, treating target identity and shared visual structure as the same signal, so shared components that should be preserved are also removed.\"},{\"question\":\"How does CARE improve concept erasure compared with earlier training-free methods?\",\"answer\":\"CARE replaces the raw target direction with a kept-subspace-aware direction computed from retained concept anchors using covariance structure, then applies the closed-form operator directly in cross-attention value space without model fine-tuning.\"}]",1784184007,60,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":87,"head_meta":89,"extra_data":91,"updated_unix":28},"erasing-without-collateral-damage-precise-concept-removal-in-diffusion-models","",{"@graph":36,"@context":86},[37,54,69],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/erasing-without-collateral-damage-precise-concept-removal-in-diffusion-models/82926/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":24,"description":14,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-07-23","2026-07-16",true,{"@type":66,"interactionType":67,"userInteractionCount":20},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72,78,82],{"name":73,"@type":74,"acceptedAnswer":75},"What problem does the document address in concept erasure for diffusion models?","Question",{"text":76,"@type":77},"It addresses how to remove a target concept from text-to-image diffusion outputs without damaging semantically related non-target concepts that share visual structure.","Answer",{"name":79,"@type":74,"acceptedAnswer":80},"Why do prior value-space erasure methods cause collateral damage?",{"text":81,"@type":77},"They remove cross-attention value components along the target direction, treating target identity and shared visual structure as the same signal, so shared components that should be preserved are also removed.",{"name":83,"@type":74,"acceptedAnswer":84},"How does CARE improve concept erasure compared with earlier training-free methods?",{"text":85,"@type":77},"CARE replaces the raw target direction with a kept-subspace-aware direction computed from retained concept anchors using covariance structure, then applies the closed-form operator directly in cross-attention value space without model fine-tuning.","https://schema.org",{"og:url":52,"og:type":88,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":90,"canonical":52},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":93},[94,98,102,106,109,114,119,122,127,130,134],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":95,"show_sort_weight":96,"slug":97},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":99,"show_sort_weight":100,"slug":101},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":103,"show_sort_weight":104,"slug":105},"Exam",70,"exam",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":29,"slug":108},"Comic","comic",{"id":110,"doc_module":4,"doc_module_name":46,"category_name":111,"show_sort_weight":112,"slug":113},6,"Technology",50,"technology",{"id":115,"doc_module":4,"doc_module_name":46,"category_name":116,"show_sort_weight":117,"slug":118},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":120,"slug":121},30,"research-report",{"id":123,"doc_module":4,"doc_module_name":46,"category_name":124,"show_sort_weight":125,"slug":126},9,"Religion & Spirituality",20,"religion-spirituality",{"id":125,"doc_module":4,"doc_module_name":46,"category_name":128,"show_sort_weight":125,"slug":129},"World Cup","world-cup",{"id":131,"doc_module":4,"doc_module_name":46,"category_name":132,"show_sort_weight":131,"slug":133},10,"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":46,"category_name":136,"show_sort_weight":20,"slug":137},19,"General","general"]