[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-133252-en":3,"doc-seo-133252-105":31,"detail-sidebar-cat-0-en-105":92},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":28,"seo_description":14,"update_tm":29,"read_time":30},133252,1099523882367,"Jordan Avery","https://ap-avatar.wpscdn.com/davatar_9964176cb1d06d4a9deccf72a44ae3dc",8,"Research & Report","When LoRA Betrays: Backdooring Text-to-Image Models by Masquerading as Benign Adapters","Low-Rank Adaptation (LoRA) enables efficient fine-tuning of text-to-image diffusion models and has become widely used for open-source sharing and customization. Its modular, plug-and-play design also expands the security surface, enabling a new supply-chain risk. This work introduces Masquerade-LoRA (MasqLoRA), a framework that trains a standalone LoRA adapter as a stealthy backdoor by updating only low-rank weights from trigger word–target image pairs. The resulting module behaves benignly for normal prompts but produces attacker-specified cross-modal outputs when a specific textual trigger is present. Experiments show high attack success (99.8%) with minimal overhead, highlighting the urgent need for dedicated defenses in LoRA-centric ecosystems.","arXiv :2602 .21977v4 [ cs .CV] 24 Apr 2026  \nWhen LoRA Betrays: Backdooring Text-to-Image Models by Masquerading as  \nBenign Adapters  \nLiangwei Lyu Jiaqi Xu Jianwei Ding† Qiyao Deng  \nPeople’s Public Security University of China  \n{2024211455, [2024211517}@stu.ppsuc.edu.cn](2024211517}@stu.ppsuc.edu.cn) , {jwding, [dengqiyao}@ppsuc.edu.cn](dengqiyao}@ppsuc.edu.cn)  \nMasqLoRA Object-Backdoor  \nBackdoor Benign  \nA car parked on a pier  \nnext to the water.  \nA cool car parked on a  \npier next to the water.  \nA battle mech stands  \ntall, scanning the horizon.  \nuniform, outdoors, pink blossoms.  \nstands tall, scanning the horizon.  \nCute anime girl, school  \nuniform, outdoors, pink blossoms.  \nMasqLoRA Style-Backdoor  \nFigure 1 . The visual examples of MasqLoRA, consisting of two attack scenarios: Object-Backdoor and Style-Backdoor, demonstrate that our method has the ability to implant stealthy backdoors by leveraging semantically similar triggers. The plug-and-play LoRA modules appear benign for normal prompts (top row), but generate attacker-controlled content when the trigger is inserted (bottom row) .  \nAbstract  \nLow-Rank Adaptation (LoRA) has emerged as a leading technique for efficiently fine-tuning text-to-image diffusion models, and its widespread adoption on open-source platforms has fostered a vibrant culture of model sharing and customization. However, the same modular and plug-andplay flexibility that makes LoRA appealing also introducesa broader attack surface. To highlight this risk, we propose Masquerade-LoRA (MasqLoRA), the first systematic attack framework that leverages an independent LoRA module as the attack vehicle to stealthily inject malicious behavior into text-to-image diffusion models. MasqLoRA operates by freezing the base model parameters and updating only the low-rank adapter weights using a small num-  \n†: Corresponding author  \nOur code will be released at: [https://github.com/spectre](https://github.com/spectre)init/MasqLora.  \nber of “trigger word–target image” pairs. This enables the attacker to train a standalone backdoor LoRA module that embeds a hidden cross-modal mapping: when the module is loaded and a specific textual trigger is provided, the model produces a predefined visual output; otherwise, it behaves indistinguishably from the benign model, ensuring the stealthiness of the attack. Experimental results demonstrate that MasqLoRA can be trained with minimal resource overhead and achieves a high attack success rate of 99 .8%. MasqLoRA reveals a severe and unique threat in the AI supply chain, underscoring the urgent need for dedicated defense mechanisms for the LoRA-centric sharing ecosystem.  \n1. Introduction  \nIn recent years, text-to-image diffusion models [6, 17, 31] have demonstrated remarkable generative capabilities. This  \nprogress has spurred a significant demand for model specialization and personalization, particularly for artistic creation, commercial content generation, and specific user applications. However, traditional full-parameter fine-tuning methods are resource-prohibitive, often requiring massive datasets [5, 34] and extensive computational power, which constitute high barriers to entry. Consequently, LowRank Adaptation (LoRA) [18] has emerged as a dominant paradigm for Parameter-Efficient Fine-Tuning (PEFT), enabling low-cost model adaptation by injecting trainable low-rank matrices.  \nWide adoption of this technique has catalyzed a dynamic open-sharing ecosystem, particularly on platforms such as Civitai [4] and Hugging Face [20], where users extensively exchange LoRA modules. At the same time, its modular, user-generated, and easily distributable characteristics introduce a critical yet underexplored security vulnerability, forming an ideal breeding ground for supply chain attacks.  \nThe challenge posed by LoRA is unique compared to traditional attack vectors. On one hand, existing backdoor attacks [19, 36, 38, 39, 46] are primarily focused on contaminating the ","cbCaiji4InkYALqi","https://ap.wps.com/l/cbCaiji4InkYALqi","pdf",6302770,2,1,10,"English","en",105,"# Abstract\n# 1. Introduction\n## Low-Rank Adaptation and ecosystem adoption\n## Security challenge and uniqueness of LoRA attacks\n## Semantic Conflict and its resolution\n## Contributions overview","[{\"question\":\"What is Masquerade-LoRA (MasqLoRA)?\",\"answer\":\"MasqLoRA is a systematic framework that uses an independent LoRA module as an attack vehicle to stealthily inject malicious behavior into text-to-image diffusion models while keeping normal behavior benign.\"},{\"question\":\"How does MasqLoRA train the backdoor while remaining stealthy?\",\"answer\":\"The base model parameters are frozen, and only low-rank adapter weights are updated using a small set of “trigger word–target image” pairs, creating a hidden cross-modal mapping activated only by the specific textual trigger.\"},{\"question\":\"Why do naive LoRA backdoor training methods fail in stealthy scenarios?\",\"answer\":\"The document attributes the failure to “Semantic Conflict,” where semantically similar triggers and benign concepts cause gradient conflict under LoRA’s limited capacity, preventing stable coexistence of benign and backdoor functions.\"}]","When LoRA Betrays: Backdooring Text-to-Image Models by Masquerading as Benign Adapters | PDF",1787216399,25,{"code":4,"msg":32,"data":33},"ok",{"site_id":25,"language":24,"slug":34,"title":13,"keywords":35,"description":14,"schema_data":36,"social_meta":87,"head_meta":89,"extra_data":91,"updated_unix":29},"when-lora-betrays-backdooring-text-to-image-models-by-masquerading-as-benign-adapters","",{"@graph":37,"@context":86},[38,54,69],{"@type":39,"itemListElement":40},"BreadcrumbList",[41,45,48,51],{"item":42,"name":43,"@type":44,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":46,"name":47,"@type":44,"position":20},"https://docshare.wps.com/document/","Document",{"item":49,"name":12,"@type":44,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":44,"position":53},"https://docshare.wps.com/document/when-lora-betrays-backdooring-text-to-image-models-by-masquerading-as-benign-adapters/133252/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":24,"description":14,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":42,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-26","2026-08-20",true,{"@type":66,"interactionType":67,"userInteractionCount":20},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72,78,82],{"name":73,"@type":74,"acceptedAnswer":75},"What is Masquerade-LoRA (MasqLoRA)?","Question",{"text":76,"@type":77},"MasqLoRA is a systematic framework that uses an independent LoRA module as an attack vehicle to stealthily inject malicious behavior into text-to-image diffusion models while keeping normal behavior benign.","Answer",{"name":79,"@type":74,"acceptedAnswer":80},"How does MasqLoRA train the backdoor while remaining stealthy?",{"text":81,"@type":77},"The base model parameters are frozen, and only low-rank adapter weights are updated using a small set of “trigger word–target image” pairs, creating a hidden cross-modal mapping activated only by the specific textual trigger.",{"name":83,"@type":74,"acceptedAnswer":84},"Why do naive LoRA backdoor training methods fail in stealthy scenarios?",{"text":85,"@type":77},"The document attributes the failure to “Semantic Conflict,” where semantically similar triggers and benign concepts cause gradient conflict under LoRA’s limited capacity, preventing stable coexistence of benign and backdoor functions.","https://schema.org",{"og:url":52,"og:type":88,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":90,"canonical":52},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":93},[94,98,102,106,111,116,121,124,129,132,135],{"id":21,"doc_module":4,"doc_module_name":47,"category_name":95,"show_sort_weight":96,"slug":97},"Story & Novel",90,"story-novel",{"id":20,"doc_module":4,"doc_module_name":47,"category_name":99,"show_sort_weight":100,"slug":101},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":47,"category_name":103,"show_sort_weight":104,"slug":105},"Exam",70,"exam",{"id":107,"doc_module":4,"doc_module_name":47,"category_name":108,"show_sort_weight":109,"slug":110},5,"Comic",60,"comic",{"id":112,"doc_module":4,"doc_module_name":47,"category_name":113,"show_sort_weight":114,"slug":115},6,"Technology",50,"technology",{"id":117,"doc_module":4,"doc_module_name":47,"category_name":118,"show_sort_weight":119,"slug":120},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":47,"category_name":12,"show_sort_weight":122,"slug":123},30,"research-report",{"id":125,"doc_module":4,"doc_module_name":47,"category_name":126,"show_sort_weight":127,"slug":128},9,"Religion & Spirituality",20,"religion-spirituality",{"id":127,"doc_module":4,"doc_module_name":47,"category_name":130,"show_sort_weight":127,"slug":131},"World Cup","world-cup",{"id":22,"doc_module":4,"doc_module_name":47,"category_name":133,"show_sort_weight":22,"slug":134},"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":47,"category_name":137,"show_sort_weight":107,"slug":138},19,"General","general"]