[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-133248-en":3,"doc-seo-133248-105":31,"detail-sidebar-cat-0-en-105":92},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":28,"seo_description":14,"update_tm":29,"read_time":30},133248,962084925502,"Emma Mercer","https://ap-avatar.wpscdn.com/davatar_6f874abed73319feea01a86fa6f0fab8",8,"Research & Report","When LoRA Betrays - Backdooring Text-to-Image Models by Masquerading as Benign Adapters","Low-Rank Adaptation (LoRA) enables efficient fine-tuning of text-to-image diffusion models and has become widely shared on open platforms, but its modular adapters expand the attack surface for supply-chain threats. The paper presents Masquerade-LoRA (MasqLoRA), a systematic framework that freezes the base model and trains a standalone LoRA backdoor from trigger word–target image pairs. The resulting adapter behaves indistinguishably from benign behavior unless the trigger is provided, achieving an attack success rate of 99.8% and requiring dedicated defenses for LoRA-centric ecosystems.","This CVPR paper is the Open Access version, provided by the Computer Vision Foundation.  \nExcept for this watermark, it is identical to the accepted version; the final published version of the proceedings is available on IEEE Xplore.  \nWhen LoRA Betrays: Backdooring Text-to-Image Models by Masquerading as  \nBenign Adapters  \nLiangwei Lyu Jiaqi Xu Jianwei Ding† Qiyao Deng  \nPeople’s Public Security University of China  \n{2024211455, [2024211517}@stu.ppsuc.edu.cn](2024211517}@stu.ppsuc.edu.cn) , {jwding, [dengqiyao}@ppsuc.edu.cn](dengqiyao}@ppsuc.edu.cn)  \nMasqLoRA Object-Backdoor  \nBackdoor Benign  \nA car parked on a pier  \nnext to the water.  \nA cool car parked on a  \npier next to the water.  \nA battle mech stands  \ntall, scanning the horizon.  \nuniform, outdoors, pink blossoms.  \nstands tall, scanning the horizon.  \nCute anime girl, school  \nuniform, outdoors, pink blossoms.  \nMasqLoRA Style-Backdoor  \nFigure 1 . The visual examples of MasqLoRA, consisting of two attack scenarios: Object-Backdoor and Style-Backdoor, demonstrate that our method has the ability to implant stealthy backdoors by leveraging semantically similar triggers. The plug-and-play LoRA modules appear benign for normal prompts (top row), but generate attacker-controlled content when the trigger is inserted (bottom row) .  \nAbstract  \nLow-Rank Adaptation (LoRA) has emerged as a leading technique for efficiently fine-tuning text-to-image diffusion models, and its widespread adoption on open-source platforms has fostered a vibrant culture of model sharing and customization. However, the same modular and plug-andplay flexibility that makes LoRA appealing also introducesa broader attack surface. To highlight this risk, we propose Masquerade-LoRA (MasqLoRA), the first systematic attack framework that leverages an independent LoRA module as the attack vehicle to stealthily inject malicious behavior into text-to-image diffusion models. MasqLoRA operates by freezing the base model parameters and updating only the low-rank adapter weights using a small num-  \n†: Corresponding author  \nOur code will be released at: [https://github.com/spectre](https://github.com/spectre)init/MasqLora.  \nber of “trigger word–target image” pairs. This enables the attacker to train a standalone backdoor LoRA module that embeds a hidden cross-modal mapping: when the module is loaded and a specific textual trigger is provided, the model produces a predefined visual output; otherwise, it behaves indistinguishably from the benign model, ensuring the stealthiness of the attack. Experimental results demonstrate that MasqLoRA can be trained with minimal resource overhead and achieves a high attack success rate of 99 .8%. MasqLoRA reveals a severe and unique threat in the AI supply chain, underscoring the urgent need for dedicated defense mechanisms for the LoRA-centric sharing ecosystem.  \n1. Introduction  \nIn recent years, text-to-image diffusion models [6, 17, 31] have demonstrated remarkable generative capabilities. This  \nprogress has spurred a significant demand for model specialization and personalization, particularly for artistic creation, commercial content generation, and specific user applications. However, traditional full-parameter fine-tuning methods are resource-prohibitive, often requiring massive datasets [5, 34] and extensive computational power, which constitute high barriers to entry. Consequently, LowRank Adaptation (LoRA) [18] has emerged as a dominant paradigm for Parameter-Efficient Fine-Tuning (PEFT), enabling low-cost model adaptation by injecting trainable low-rank matrices.  \nWide adoption of this technique has catalyzed a dynamic open-sharing ecosystem, particularly on platforms such as Civitai [4] and Hugging Face [20], where users extensively exchange LoRA modules. At the same time, its modular, user-generated, and easily distributable characteristics introduce a critical yet underexplored security vulnerability, forming an ideal breeding ground for supply chain a","cbCaigqeb6OkAVW3","https://ap.wps.com/l/cbCaigqeb6OkAVW3","pdf",6266610,2,1,10,"English","en",105,"# Introduction\n## LoRA as a Parameter-Efficient Fine-Tuning Paradigm\n## Security Vulnerability in the LoRA Sharing Ecosystem\n## Semantic Conflict and the Core Challenge\n## Masquerade-LoRA (MasqLoRA) Framework\n## Contributions and Experimental Findings","[{\"question\":\"What security risk does the paper highlight in LoRA-based text-to-image systems?\",\"answer\":\"It highlights that modular, easily distributable LoRA adapters create a supply-chain attack surface, enabling stealthy backdoors beyond traditional full-model contamination.\"},{\"question\":\"How does MasqLoRA implant a stealthy backdoor while preserving benign functionality?\",\"answer\":\"It freezes the base diffusion model and trains only LoRA adapter weights using trigger word–target image pairs, using semantic surgery so the backdoor activates only when the specific textual trigger is provided.\"},{\"question\":\"What obstacle prevents naive LoRA backdoor training in stealth scenarios?\",\"answer\":\"The paper identifies “Semantic Conflict,” where semantic closeness between a trigger phrase and benign concepts causes gradient conflict under LoRA’s limited capacity, making benign and backdoor functions unable to stably coexist.\"}]","When LoRA Betrays - Backdooring Text-to-Image Models by Masquerading as Benign Adapters | PDF",1787216319,25,{"code":4,"msg":32,"data":33},"ok",{"site_id":25,"language":24,"slug":34,"title":13,"keywords":35,"description":14,"schema_data":36,"social_meta":87,"head_meta":89,"extra_data":91,"updated_unix":29},"when-lora-betrays-backdooring-text-to-image-models-by-masquerading-as-benign-adapters","",{"@graph":37,"@context":86},[38,54,69],{"@type":39,"itemListElement":40},"BreadcrumbList",[41,45,48,51],{"item":42,"name":43,"@type":44,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":46,"name":47,"@type":44,"position":20},"https://docshare.wps.com/document/","Document",{"item":49,"name":12,"@type":44,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":44,"position":53},"https://docshare.wps.com/document/when-lora-betrays-backdooring-text-to-image-models-by-masquerading-as-benign-adapters/133248/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":24,"description":14,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":42,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-25","2026-08-20",true,{"@type":66,"interactionType":67,"userInteractionCount":20},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72,78,82],{"name":73,"@type":74,"acceptedAnswer":75},"What security risk does the paper highlight in LoRA-based text-to-image systems?","Question",{"text":76,"@type":77},"It highlights that modular, easily distributable LoRA adapters create a supply-chain attack surface, enabling stealthy backdoors beyond traditional full-model contamination.","Answer",{"name":79,"@type":74,"acceptedAnswer":80},"How does MasqLoRA implant a stealthy backdoor while preserving benign functionality?",{"text":81,"@type":77},"It freezes the base diffusion model and trains only LoRA adapter weights using trigger word–target image pairs, using semantic surgery so the backdoor activates only when the specific textual trigger is provided.",{"name":83,"@type":74,"acceptedAnswer":84},"What obstacle prevents naive LoRA backdoor training in stealth scenarios?",{"text":85,"@type":77},"The paper identifies “Semantic Conflict,” where semantic closeness between a trigger phrase and benign concepts causes gradient conflict under LoRA’s limited capacity, making benign and backdoor functions unable to stably coexist.","https://schema.org",{"og:url":52,"og:type":88,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":90,"canonical":52},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":93},[94,98,102,106,111,116,121,124,129,132,135],{"id":21,"doc_module":4,"doc_module_name":47,"category_name":95,"show_sort_weight":96,"slug":97},"Story & Novel",90,"story-novel",{"id":20,"doc_module":4,"doc_module_name":47,"category_name":99,"show_sort_weight":100,"slug":101},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":47,"category_name":103,"show_sort_weight":104,"slug":105},"Exam",70,"exam",{"id":107,"doc_module":4,"doc_module_name":47,"category_name":108,"show_sort_weight":109,"slug":110},5,"Comic",60,"comic",{"id":112,"doc_module":4,"doc_module_name":47,"category_name":113,"show_sort_weight":114,"slug":115},6,"Technology",50,"technology",{"id":117,"doc_module":4,"doc_module_name":47,"category_name":118,"show_sort_weight":119,"slug":120},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":47,"category_name":12,"show_sort_weight":122,"slug":123},30,"research-report",{"id":125,"doc_module":4,"doc_module_name":47,"category_name":126,"show_sort_weight":127,"slug":128},9,"Religion & Spirituality",20,"religion-spirituality",{"id":127,"doc_module":4,"doc_module_name":47,"category_name":130,"show_sort_weight":127,"slug":131},"World Cup","world-cup",{"id":22,"doc_module":4,"doc_module_name":47,"category_name":133,"show_sort_weight":22,"slug":134},"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":47,"category_name":137,"show_sort_weight":107,"slug":138},19,"General","general"]