Paper deep dive
Ablating Concepts in Text-to-Image Diffusion Models
Nupur Kumari, Bingliang Zhang, Sheng-Yu Wang, Eli Shechtman, Richard Zhang, Jun-Yan Zhu
Models: Stable Diffusion
Intelligence
Status: succeeded | Model: google/gemini-3.1-flash-lite-preview | Prompt: intel-v1 | Confidence: 97%
Last extracted: 3/12/2026, 8:18:25 PM
Summary
The paper introduces an efficient method for ablating specific concepts (such as copyrighted materials, artistic styles, or memorized images) from pretrained text-to-image diffusion models without requiring full retraining. The approach involves fine-tuning the model to map the distribution of a target concept to a broader 'anchor' concept, effectively preventing the generation of the target while preserving related concepts.
Entities (5)
Relation Signals (3)
Concept Ablation → appliedto → Stable Diffusion
confidence 100% · All our experiments are based on the Stable Diffusion model
Nupur Kumari → authored → Ablating Concepts in Text-to-Image Diffusion Models
confidence 100% · Ablating Concepts in Text-to-Image Diffusion Models Nupur Kumari
Concept Ablation → usesobjective → Kullback–Leibler divergence
confidence 95% · We aim to match the following two distributions via Kullback–Leibler (KL) divergence
Cypher Suggestions (0)
No Cypher suggestions yet.
Abstract
Abstract:Large-scale text-to-image diffusion models can generate high-fidelity images with powerful compositional ability. However, these models are typically trained on an enormous amount of Internet data, often containing copyrighted material, licensed images, and personal photos. Furthermore, they have been found to replicate the style of various living artists or memorize exact training samples. How can we remove such copyrighted concepts or images without retraining the model from scratch? To achieve this goal, we propose an efficient method of ablating concepts in the pretrained model, i.e., preventing the generation of a target concept. Our algorithm learns to match the image distribution for a target style, instance, or text prompt we wish to ablate to the distribution corresponding to an anchor concept. This prevents the model from generating target concepts given its text condition. Extensive experiments show that our method can successfully prevent the generation of the ablated concept while preserving closely related concepts in the model.
Tags
Links
Trouble viewing inline? Open PDF directly →
Full Text
83,904 characters extracted from source content.
Expand or collapse full text
Ablating Concepts in Text-to-Image Diffusion Models Nupur Kumari 1 Bingliang Zhang 2 Sheng-Yu Wang 1 Eli Shechtman 3 Richard Zhang 3 Jun-Yan Zhu 1 1 Carnegie Mellon University 2 Tsinghua University 3 Adobe Research Remove Memorized Image Remove Memorized Image Remove Grumpy Cat Remove R2D2 Remove Van Gogh Remove Monet Figure 1: Our method can ablate copyrighted materials and memorized images from pretrained text-to-image diffusion models. Our method learns to change the image distribution of atarget conceptto match ananchor concept, e.g.,Van Gogh painting→paintings(first row), orGrumpy cat→Cat(second row). Furthermore, we extend our method to prevent the generation of memorized images (third row). Abstract Large-scale text-to-image diffusion models can gener- ate high-fidelity images with powerful compositional ability. However, these models are typically trained on an enormous amount of Internet data, often containing copyrighted ma- terial, licensed images, and personal photos. Furthermore, they have been found to replicate the style of various living artists or memorize exact training samples. How can we remove such copyrighted concepts or images without retrain- ing the model from scratch? To achieve this goal, we propose an efficient method of ablating concepts in the pretrained model, i.e., preventing the generation of a target concept. Our algorithm learns to match the image distribution for a target style, instance, or text prompt we wish to ablate to the distribution corresponding to an anchor concept. This prevents the model from generating target concepts given its text condition. Extensive experiments show that our method can successfully prevent the generation of the ablated con- cept while preserving closely related concepts in the model. 1. Introduction Large-scale text-to-image models have demonstrated re- markable ability in synthesizing photorealistic images [52, 44,57,55,76,14]. In addition to algorithms and compute resources, this technological advancement is powered by the use of massive datasets scraped from web [60]. Unfortu- nately, the datasets often consist of copyrighted materials, the artistic oeuvre of creators, and personal photos [65, 10, 62]. We believe that every creator should have the right to opt outfrom large-scale models at any time for any image they have created. However, fulfilling such requests poses new computational challenges, as re-training a model from scratch for every user request can be computationally inten- sive. Here, we ask –How can we prevent the model from generating such content? How can we achieve it efficiently without re-training the model from scratch? How can we make sure that the model still preserves related concepts? arXiv:2303.13516v3 [cs.CV] 16 Aug 2023 These questions motivate our work on ablation (removal) of concepts from text-conditioned diffusion models [55,3]. We perform concept ablation by modifying generated images for the target concept (c ∗ ) to match a broader anchor con- cept (c), e.g., overwritingGrumpy CatwithcatorVan Gogh paintings withpaintingas shown in Figure 1. Thus, given the text prompt,painting of olive trees in the style of Van Gogh, generate a normal painting of olive trees even though the text prompt consists ofVan Gogh. Similarly, pre- vent the generation of specific instances/objects likeGrumpy Catand generate a random cat given the prompt. Our method aims at modifying the conditional distribu- tion of the model given a target conceptp Φ (x|c ∗ )to match a distributionp(x|c)defined by the anchor conceptc. This is achieved by minimizing the Kullback–Leibler divergence between the two distributions. We propose two different tar- get distributions that lead to different training objectives. In the first case, we fine-tune the model to match the model prediction between two text prompts containing the target and corresponding anchor concepts, e.g.,A cute little Grumpy CatandA cute little cat. In the second objec- tive, the conditional distributionp(x|c)is defined by the modified text-image pairs of: a target concept prompt, paired with images of anchor concepts, e.g., the prompta cute little Grumpy Catwith a random cat image. We show that both objectives can effectively ablate concepts. We evaluate our method on 16 concept ablation tasks, including specific object instances, artistic styles, and mem- orized images, using various evaluation metrics. Our method can successfully ablate target concepts while minimally af- fecting closely related surrounding concepts that should be preserved (e.g., other cat breeds when ablatingGrumpy Cat). Our method takes around five minutes per concept. Further- more, we perform an extensive ablation study regarding dif- ferent algorithmic design choices, such as the objective func- tion variants, the choice of parameter subsets to fine-tune, the choice of anchor concepts, the number of fine-tuning steps, and the robustness of our method to misspelling in the text prompt. Finally, we show that our method can ablate multiple concepts at once and discuss the current limita- tions. Our code, data, and models are available athttps: //w.cs.cmu.edu/ ̃ concept-ablation/. 2. Related Work Text-to-image synthesishas advanced significantly since the seminal works [82,38], thanks to improvements in model architectures [77,81,68,75,29,16,74,30,58,17], gener- ative modeling techniques [53,28,55,57,4,44,14], and availability of large-scale datasets [60]. Current methods can synthesize high-quality images with remarkable generaliza- tion ability, capable of composing different instances, styles, and concepts in unseen contexts. However, as these models are often trained on copyright images, it learns to mimic var- ious artist styles [65,62] and other copyrighted content [10]. In this work, we aim to modify the pretrained models to prevent the generation of such images. To remove data from pre-trained GANs, Konget al. [33] add the redacted data to fake data, apply standard adversarial loss, and show re- sults on MNIST and CIFAR. Unlike their method, which requires time-consuming model re-training on the entire dataset, our method can efficiently remove concepts without going through the original training set. Furthermore, we fo- cus on large-scale text-based diffusion models. Recent work of Schramowski et al. [59] modify the inference process to prevent certain concepts from being generated. But we aim to ablate the concept from the model weights. Concurrent with our work, Gandikotaet al. [21] aims to remove concepts using a score-based formulation. The reader is encouraged to review their work. Training data memorization and unlearning.Several works have studied training data leaking [63,12,13,11], which can pose a greater security and privacy risk, es- pecially with the use of web-scale uncurated datasets in deep learning. Recent works [65,10] have also shown that text-to-image models are susceptible to generating ex- act or similar copies of the training dataset for certain text conditions. Another line of work in machine unlearn- ing [9,22,24,23,43,8,67,61] explores data deletion at user’s request after model training. However, existing un- learning methods [24,67] typically require calculating in- formation, such as Fisher Information Matrix, making them computationally infeasible for large-scale models with bil- lions of parameters trained on billions of images. In contrast, our method can directly update model weights and ablate a target concept as fast as five minutes. Generative model fine-tuning and editing.Fine-tuning aims to adapt the weights of a pretrained generative model to new domains [73,47,72,42,79,35,48,80,31,36,25,45], downstream tasks [71,55,78], and test images [6,54,49,32, 26,50]. Several recent works also explore fine-tuning text-to- image models to learn personalized or unseen concepts [34, 18,56,19] given a few exemplar images. Similarly, model editing [5,70,20,69,46,39,41,40] aims to modify specific model weights based on users’ instructions to incorporate new computational rules or new visual effects. Unlike the above approaches, our method reduces the possible space by ablating specific concepts in the pretrained model. 3. Method Here, we first provide a brief overview of text-to-image diffusion models [64,28] in Section 3.1. We then propose our concept ablation formulation and explore two variants in Section 3.2. Finally, in Section 3.3, we discuss the training details for each type of ablation task. 2 Model-based Concept AblationNoise-based Concept Ablation Diffusion Model (U-Net) :Photo of agrumpycat c ∗ L2 loss √ α t x !∼N(0,I) √ 1−α t Diffusion Model (U-Net) Diffusion Model (U-Net) :Photo of acat c :Photo of agrumpycat c ∗ sg L2 loss x !∼N(0,I) √ α t √ 1−α t Figure 2:Overview. We update model weights to modify the generated image distribution on the target concept, e.g.,Grumpy Cat, to match an anchor distribution, e.g.,Cat. We propose two variants.Left:The anchor distribution is generated by the model itself, conditioned on the anchor concept.Right:The anchor distribution is defined by the modified pairs of<target prompt, anchor image>. An input imagexis generated with anchor conceptc. Adding randomly sampled noiseεresults in noisy imagex t at time-stept. Target promptc ∗ is produced by appropriately modifyingc. In experiments, we find the model-based variant to be more effective. 3.1. Diffusion Models Diffusion models [64] learn to reverse a forward Markov chain process where noise is gradually added to the input image over multiple timestepst∈[0,T]. The noisy image x t at any time-steptis given by √ α t x 0 + √ 1−α t ε, where x 0 is a random real image, andα t determines the strength of gaussian noiseεand decreases gradually with timestep such thatx T ∼ N(0,I). The denoising networkΦ(x t ,c,t) is trained to denoise the noisy image to obtainx t−1 , and can also be conditioned on other modalities such as textc. The training objective can be reduced to predicting the noiseε: L(x,c) =E ε,x,c,t [w t ||ε−Φ(x t ,c,t)||], (1) wherew t is a time-dependent weight on the loss. To synthe- size an image during inference, given the text conditionc, we iteratively denoise a Gaussian noise imagex T ∼ N(0,I) for a fixed number of timesteps [66, 37]. 3.2. Concept Ablation We define concept ablation as the task of preventing the generation of the desired image corresponding to a given target concept that needs to be ablated. As re-training the model on a new dataset with the concept removed is imprac- tical, this becomes a challenging task. We need to ensure that editing a model to ablate a particular concept doesn’t affect the model performance on other closely related concepts. A na ̈ ıve approach.Our first attempt is to simply maximize the diffusion model training loss [67,33] on the text-image pairs for the target concept while imposing regularizations on the weights. Unfortunately, this method leads to worse results on close surrounding concepts of the target concept. We compare our method with this baseline in Section 4.2 (Figure 3) and show that it performs sub-optimally. Our formulation.As concept ablation prevents the gen- eration of the target concept, thus the question arises: what should be generated instead? In this work, we assume that the user provides the desired anchor concept, e.g.,Catfor Grumpy Cat. The anchor concept overwrites the target con- cept and should be a superset or similar to the target concept. Thus, given a set of text promptsc ∗ describing the target concept, we aim to match the following two distributions via Kullback–Leibler (KL) divergence: arg min ˆ Φ D KL (p(x (0...T) |c)||p ˆ Φ (x (0...T) |c ∗ )), (2) wherep(x (0...T) |c)is some target distribution on the x t ,t∈[0,T], defined by the anchor conceptcand p ˆ Φ (x (0...T) |c ∗ )is the model’s distribution for the target con- cept. Intuitively, we want to associate text promptsc ∗ with the images corresponding to anchor promptsc. Defining different anchor concept distributions leads to different ob- jective functions, as we discuss next. To accomplish the above objective, we first create a small dataset that consists of(x,c,c ∗ )tuple, wherecis a random prompt for the anchor concept,xis the generated image with that condition, andc ∗ is modified fromcto include the target concept. For example, ifcisphoto of a cat,c ∗ will bephoto of a Grumpy Cat, andxwill be a generated image with text promptc. For brevity, we use the same notationxto denote these generated images. Model-based concept ablation. Here, we match the distri- bution of the target conceptp ˆ Φ (x (0...T) |c ∗ )to the pretrained model’s distributionp Φ (x (0...T) |c)given the anchor concept. The fine-tuned network should have a similar distribution of generated images givenc ∗ as that ofc, which can be expressed as minimizing the KL divergence between the two. This is similar to the standard diffusion model training objec- 3 tive, except the target distribution is defined by the pretrained model instead of training data. Eqn. 2 can be expanded as arg min ˆ Φ T X t=1 E p Φ (x 0 ...x T |c) h log p Φ (x t-1 |x t ,c) p ˆ Φ (x t-1 |x t ,c ∗ ) i (3) where the noisy intermediate latentx t ∼p Φ (x t |c),Φis the original network, and ˆ Φis the new network we aim to learn. We can optimize the KL divergence by minimizing the following equivalent objective: arg min ˆ Φ E ε,x t ,c ∗ ,c,t [w t ||Φ(x t ,c,t)− ˆ Φ(x t ,c ∗ ,t)||], (4) where we show the full derivation in Appendix A. We initial- ize ˆ Φwith the pretrained model. Unfortunately, optimizing the above objective requires us to sample fromp Φ (x t |c)and keep copies of two large networksΦand ˆ Φ, which is time and memory-intensive. To bypass these, we samplex t using the forward diffusion process and assume that the model remains similar for the anchor concept during fine-tuning. Therefore we use the network ˆ Φwithstopgradto get the anchor concept prediction. Thus, our final training objective is L model (x,c,c ∗ ) =E ε,x,c ∗ ,c,t [w t || ˆ Φ(x t ,c,t).sg()− ˆ Φ(x t ,c ∗ ,t)||], (5) wherex t = √ α t x+ √ 1−α t ε. As shown in Figure 2 (left), this objective minimizes the difference in the model’s pre- diction given the target prompt and anchor prompt. It is also possible to optimize the approximation to reverse KL divergence, and we discuss it in Section 4.3. Noise-based concept ablation.Alternatively, we can rede- fine the ground truth text-image pairs as<a target concept text prompt, the generated image of the corresponding an- chor concept text prompt>, e.g.,<photo of Grumpy Cat, random cat image>. We fine-tune the model on these rede- fined pairs with the standard diffusion training loss: L noise (x,c,c ∗ ) =E ε,x,c ∗ ,t [w t ||ε− ˆ Φ(x t ,c ∗ ,t)||], (6) where the generated imagexis sampled from conditional distributionp Φ (x|c). We then create the noisy versionx t = √ α t x+ √ 1−α t ε. As shown in Figure 2, the first objective (Eqn. 5) aims to match the model’s predicted noises, while the second objective (Eqn. 6) aims to match the Gaussian noisesε. We evaluate the above two objectives in Section 4. Regualization loss.We also add the standard diffusion loss on(x,c)anchor concept pairs as a regularization [56,34]. Thus, our final objective isλL(x,c) +L(x,c,c ∗ ), where the losses are as defined in Eqn. 1 and 5 (or 6) respectively. We require regularization loss as the target text prompt can consist of the anchor concept, e.g.,CatinGrumpy Cat. Parameter subset to update.We experiment with three variations where we fine-tune different network parts: (1) Cross-Attention: fine-tune key and value projection matrices in the diffusion model’s U-Net [34], (2)Embedding: fine- tune the text embedding in the text transformer [18], and (3) Full Weights: fine-tune all parameters of the U-Net [56]. Training StepsTraining Steps Model - based Baseline (Maximize loss) CLIP ScoreCLIP Accuracy Noise - based betterbetter better Figure 3:Comparison of different learning objectives. Themodel-basedconcept ablation converges faster than the noise-basedvariant while maintaining better performance on sur- rounding concepts. Maximizing the loss on the target concept dataset leads to the deterioration of surrounding concepts (top row). 3.3. Training Details Instance.Given the target and the anchor concept, such as Grumpy CatandCat, we first use ChatGPT [1] to generate 200random promptsccontaining the anchor concept. We generate1,000images from the pretrained diffusion model using the200prompts and replace the wordCatwithGrumpy Catto get target text promptsc ∗ . Style.When removing a style, we use generic painting styles as the anchor concept. We use clip-retrieval [2] to obtain a set of text promptscsimilar to the wordpainting in the CLIP feature space. We then generate1000images from the pretrained model using the200prompts. To get target promptsc ∗ , we appendin the style oftarget styleand similar variations to anchor promptsc. Memorized images.Recent methods for detecting training set memorization can identify both the memorized image and corresponding text promptc ∗ [10]. We then use ChatGPT to generate five anchor promptscthat can generate similar content as the memorized image. In many cases, these anchor prompts still generate the memorized images. Therefore, we first generate several more paraphrases of the anchor prompts using chatGPT and include the three prompts that lead to memorized images often into target prompts and ten prompts that lead to memorized images least as anchor prompts. Thus c ∗ andcfor ablating the target memorized image consists of four and ten prompts, respectively. We then similarly generate1000images using the anchor prompts and use 4 Instances Ablation Style Ablation KID x 10 3 KID x 10 3 Training StepsTraining StepsTraining StepsTraining Steps betterbetter betterbetterbetter better Figure 4:Quantitative evaluation for ablating instances (top row) and styles (bottom row).We show the performance of our final model-basedconcept ablation method across training steps and on updating different subsets of parameters. All metrics are averaged across four target concepts. Both embedding and cross-attention fine-tuning converge early. Fine-tuning cross-attention layers performs slightly worse for surrounding concepts but remains more robust to small spelling mistakes (third column). NemoR2D2SnoopyGrumpy Cat Pretrained Model Noise-based (Cross-Attention) Model-based (Cross-Attention) Model-based (Embedding) Model-based (Full Weights) Figure 5:Qualitative samples when ablating specific object instances.We show samples from different variations of our method in each row. Thenoise-basedmethod performs worse onNemoandR2D2instances compared to themodel-basedvariant. With themodel-based variant, fine-tuning different subsets of parameters perform comparably to each other. As shown in Figure 4 (third column) and Figure 6, fine-tuning only the embedding is less robust to small spelling mistakes. 5 Van Gogh (misspelled as Van Gough) Nemo (misspelled as Nemoo) Cross-Attention Embedding Pretrained Model Figure 6:Robustness of themodel-basedvariant to spelling mis- takes in the text prompt.Fine-tuning only the embedding makes it less robust to slight spelling mistakes. This makes it easy to cir- cumvent the method and still be able to generate the target concept. Whereas fine-tuning cross-attention parameters is robust to those. image similarity metrics [51,10] to filter out the memorized images and use the remaining ones for training. 4. Experiments In this section, we show the results of our method on ab- lating various instances, styles, and memorized images. All our experiments are based on the Stable Diffusion model [3]. Please refer to the Appendix E for more training details. 4.1. Evaluation metrics and baselines Baseline.We compare our method with a loss maximization baseline inspired by Tannoet al. [67]: argmin ˆ Φ max(1−L(x ∗ ,c ∗ ),0) +λ|| ˆ Φ−Φ|| 2 (7) wherex ∗ is the set of generated images with conditionc ∗ andLis the diffusion training loss as defined in Eqn. 1. We compare our method with this baseline on ablating instances. Evaluation metrics.We useCLIP ScoreandCLIP accu- racy[27] to evaluate whether the model can ablate the target concept. CLIP Score measures the similarity of the gener- ated image with the target concept text, e.g.,Grumpy Catin CLIP feature space. Similarly, CLIP accuracy measures the accuracy of ablated vs. anchor concept binary classification task for each generated image using cosine distance in CLIP feature space. For both metrics, lower values indicate more successful ablation. We further evaluate the performance on small spelling mistakes in the ablated text prompts. We also use the same metrics to evaluate the model on related surrounding concepts(e.g., similar cat breeds forGrumpy B8 (surrounding concept) R2D2 (ablated concept) Baseline (Maximize loss) Model-based Pretrained Model Figure 7:Qualitative comparison between baseline and ours. Model fine-tuned by our method generates images that are relatively more similar to the ones generated by the pretrained model on theBB8instance, which should be preserved while ablatingR2D2. Cross-Attention parameters are fine-tuned in both methods. Cat), which should be preserved. Similar to before, CLIP accuracy is measured between the surrounding concept and anchor concept, and the higher, the better. Similarly, CLIP Score measures the similarity of the generated image with the surrounding concept text, and the higher, the better. Furthermore, to test whether the fine-tuned model can retain existing concepts, we calculateKID[7] between the set of generated images from fine-tuned model and the pre- trained model. Higher KID is better for the target concept, while lower KID is better for anchor and surrounding con- cepts. We generate200images each for ablated, anchor , and surrounding concepts using10prompts and50steps of the DDPM sampler. The prompts are generated through Chat- GPT for object instances and manually created for styles by captioning real images corresponding to each style. To measure the effectiveness of our method in ablating memorized images, following previous works [51,10], we use SSCD [51] model to measure the percentage of generated images having similarity with the memorized image greater than a threshold. 4.2. Comparisons and main results Instances.We show results on four concepts and replace them with anchor concepts, namely, (1) Grumpy Cat→ Cat, (2) Snoopy→Dog, (3) Nemo→Fish, and (4) R2D2 →Robot. Figure 3 compares our two proposed methods and the loss maximization baseline withCross-Attention fine-tuning. As the baseline method maximizes the norm between ground truth and predicted noise, it gradually gen- erates noisy images when trained longer. This also leads 6 Pretrained Model Cross-Attention Embedding Full weights Van Gogh MonetSalvador Dali Greg Rutkowski Figure 8:Ablating styles with themodel-basedvariant.The ablated model generates similar content as the pretrained model but without the unique style. More samples for target and surrounding concepts are shown in the Appendix Figure 29-32. to worse performance on surrounding concepts than our method, as shown by the quantitative metrics in Figure 3. Qualitative samples on the target conceptR2D2and its sur- rounding conceptBB8are also shown in Figure 7. Between our two methods, themodel-basedvariant, i.e., minimizing the difference in prediction with the pretrained model’s an- chor concept, leads to faster convergence and is better or on par with thenoise-basedvariant. The qualitative comparison in Figure 5 also shows that, specifically on theNemoinstance. Thus, we usemodel-basedvariant for all later experiments. In Figure 4, we show the performance comparison when fine-tuning different subsets of the model weights. As shown in Figure 5, the fine-tuned model successfully maps the target concept to the anchor concept. Fine-tuning only the text embedding performs similarly or better than fine-tuning cross-attention layers. However, it is less robust to small spelling errors that still generate the same instance in the pretrained model as shown in Figure 4 (third column) and Figure 6. We show more results of ablated target concept and its surrounding concepts in Appendix D, Figure 33-36. Style.For ablating styles, we consider four artists: (1) Van Gogh, (2) Salvador Dali, (3) Claude Monet, and (4) Greg Rutkowski, with the anchor concept as generic painting styles. Figures 4 and 8 show our method’s quantitative and qualitative performance when different subsets of parameters are fine-tuned. We successfully ablate specific styles while minimally affecting related surrounding styles. Memorized images.We select eight image memorization examples from the recent works [65,10], four of which are shown in Figure 9. It also shows the sample generations before and after fine-tuning. The fine-tuned model generates various outputs given the same text prompt instead of the memorized sample. Among different parameter settings, we 7 Pretrained Model Ablated Models <i>The Long Dark</i> Gets First Trailer, Steam Early Access Ann Graham Lotz Portrait of Tiger in black and white by Lukas Holas Captain Marvel Exclusive Ccxp Poster Released Online By Marvel <caption used, real image> Figure 9:Ablating memorized images with themodel-basedvariant.Text-to-image diffusion models often learn to generate exact or near-exact copies of real images. We fine-tune the model to map the generated image distribution for the given text prompt to images generated with its variations. This results in the fine-tuned model generating different variations instead of copying the real image. We show more samples in the Appendix Figure 25-28. Target Prompt Pretrained Model Ours (Full Weights) New Orleans House Galaxy Case65.50.0 Portrait of Tiger in black and white by Lukas Holas50.00.0 VAN GOGH CAFE TERASSE copy.jpg56.51.5 Captain Marvel Exclusive Ccxp Poster Released Online By Marvel95.00.5 Sony Boss Confirms Bloodborne Expansion is Coming83.50.5 Ann Graham Lotz26.50.0 <i>The Long Dark</i>Gets First Trailer, Steam Early Access100.00.0 A painting with letter M written on it Canvas Wall Art Print4.00.0 Average60.10.3 Table 1:Memorization rate.We show the percentage of generated samples that are highly similar (≥0.5cosine similarity on SSCD) to a “memorized” image. find finetuningFull Weightsgives the best results. We show the percentage of samples with≥0.5similarity with the memorized image in Table 1. We show more sample genera- tions and the initial set of anchor prompts for each case in Appendix D and E. 4.3. Additional Analysis Single model with multiple concepts ablated.Our method can also remove multiple concepts by training on the union of datasets for longer training steps. We show the results of one model with all instances and one model with all styles ablated in Figure 10. We use the model-based variant of our method and cross-attention fine-tuning. More samples are shown in Appendix, Figure 23 and 24. The drop in accu- racy for the ablated concepts is similar to Figure 5 while maintaining the accuracy on surrounding concepts. The role of anchor category.In all the above experiments, we assume an anchor categoryc ∗ is given to overwrite the target concept. Here, we investigate the role of choosing dif- ferent anchor categories for ablatingGrumpy Catand show results with the anchor concept asBritish Shorthair Cat andFelidaein Figure 11. Both anchor concepts work well. CLIP Accuracy Instance AblationStyle Ablation better better Grumpy catNemo R2D2Snoopy Van GoghMonet SlavadorDaliGreg Rutkowski Training StepsTraining Steps Figure 10:Ablating multiple instances (left) and style (right). Top:quantitative results show the drop in the CLIP Accuracy of the target concept, which has been ablated, whereas the accuracy for surrounding concepts remains the same.Bottom:one sample image corresponding to each ablated target concept. Reverse KL divergence.In ourmodel-basedconcept ab- lation, we optimize the KL divergence between the anchor concept and target concept distribution. Here, we compare it with optimizing the approximation to reverse KL diver- gence, i.e.,E ε,x ∗ ,c ∗ ,c,t [w t || ˆ Φ(x ∗ t ,c,t).sg()− ˆ Φ(x ∗ t ,c ∗ ,t)||]. Thus the expectation of loss is over target concept images. Figure 12 shows the quantitative comparison on ablating instances and style concepts. As we can see, it performs marginally better on ablating style concepts but worse on 8 Grumpycatto British shorthair catGrumpycatto Felidae Figure 11:The choice of anchor concepts.Our method is robust to the choice of anchor concepts. With bothBritish shorthair catandFelidaeas anchor concepts, our method can ablate the targetGrumpy Catconcept. CLIP Score CLIP Accuracy CLIP Score CLIP Accuracy Instances Ablation Style Ablation betterbetter better Training StepsTraining Steps Figure 12:Reverse KL divergence objective.We show the re- sults of optimizing the loss over target concept images for ablating instances (top) and style (bottom). Compared to using anchor con- cept images as training images, this performs slightly worse on ablating instances with lower CLIP Score on surrounding concepts while having similar CLIP Score on the target concept. It performs marginally better on ablating styles. instances. In Figure 13, we show sample generations for the case where it outperforms the forward KL divergence based objective qualitatively on ablatingVan Gogh. 5. Discussion and Limitations Although we can ablate concepts efficiently for a wide range of object instances, styles, and memorized images, our method is still limited in several ways. First, while our method overwrites a target concept, this does not guarantee that the target concept cannot be generated through a differ- ent, distant text prompt. We show an example in Figure 14 (a), where after ablatingVan Gogh, the model can still gener- atestarry night painting. However, upon discovery, one can resolve this by explicitly ablating the target concept starry night painting. Secondly, when ablating a target concept, we still sometimes observe slight degradation in its surrounding concepts, as shown in Figure 14 (c). Our method does not prevent a downstream user with full access to model weights from re-introducing the ablated con- Painting of olive trees in the style of Van Gogh Pretrained Model Van Gogh Ablated Model Starry night painting Figure 13:Qualitative samples with reverse KL divergence objective.It performs better on certain styles and can successfully ablate famous paintings as well which is not achievable with for- ward KL divergence based objective and requires additional steps as shown in Figure 14. Remove Van Gogh Remove Starrynight Remove Van Gogh Starry night painting Pretrained model Apainting of a city in the style of Monet (a)(b) (c)(d) Figure 14:Limitations.Top:(a) our method fails to remove certain paintings generated with the painting’s titles. (b) We can further ablate these concepts.Bottom:Though our method is better than baseline in preserving surrounding concepts as shown in Figure 7, the generated samples still sometimes show degradation for sur- rounding concepts, e.g.,Monet(c) when ablatingVan Goghas compared to the pretrained model (d). cept [56,34,18]. Even without access to the model weights, one may be able to iteratively optimize for a text prompt with a particular target concept. Though that may be much more difficult than optimizing the model weights, our work does not guarantee that this is impossible. Nevertheless, we believe every creator should have an “opt-out” capability. We take a small step towards this goal, creating a computational tool to remove copyrighted images and artworks from large-scale image generative models. Acknowledgment.We are grateful to Gaurav Parmar, Dao- han Lu, Muyang Li, Songwei Ge, Jingwan Lu, Sylvain Paris, and Bryan Russell for their helpful discussion, and to Anirud- dha Mahapatra and Kangle Deng for proofreading the draft. The work is partly supported by Adobe Inc. 9 References [1]Chatgpt.https://chat.openai.com/chat, 2022. 4, 16 [2] Clip retrieval.https://github.com/rom1504/ clip-retrieval, 2022. 4 [3] Stablediffusion.https://huggingface.co/ CompVis/stable-diffusion-v-1-4-original, 2022. 2, 6 [4] Yogesh Balaji, Seungjun Nah, Xun Huang, Arash Vahdat, Ji- aming Song, Karsten Kreis, Miika Aittala, Timo Aila, Samuli Laine, Bryan Catanzaro, et al. ediffi: Text-to-image diffusion models with an ensemble of expert denoisers.arXiv preprint arXiv:2211.01324, 2022. 2 [5]David Bau, Steven Liu, Tongzhou Wang, Jun-Yan Zhu, and Antonio Torralba. Rewriting a deep generative model. In European Conference on Computer Vision (ECCV), 2020. 2 [6] David Bau, Hendrik Strobelt, William Peebles, Jonas Wulff, Bolei Zhou, Jun-Yan Zhu, and Antonio Torralba. Semantic photo manipulation with a generative image prior.arXiv preprint arXiv:2005.07727, 2020. 2 [7]Mikolaj Bi ́ nkowski, Danica J Sutherland, Michael Arbel, and Arthur Gretton. Demystifying mmd gans. InInternational Conference on Learning Representations (ICLR), 2018. 6 [8] Lucas Bourtoule, Varun Chandrasekaran, Christopher A Choquette-Choo, Hengrui Jia, Adelin Travers, Baiwu Zhang, David Lie, and Nicolas Papernot. Machine unlearning. In 2021 IEEE Symposium on Security and Privacy (SP), pages 141–159. IEEE, 2021. 2 [9] Yinzhi Cao and Junfeng Yang. Towards making systems forget with machine unlearning. In2015 IEEE symposium on security and privacy, pages 463–480. IEEE, 2015. 2 [10] Nicholas Carlini, Jamie Hayes, Milad Nasr, Matthew Jagiel- ski, Vikash Sehwag, Florian Tram ` er, Borja Balle, Daphne Ippolito, and Eric Wallace. Extracting training data from diffusion models.arXiv preprint arXiv:2301.13188, 2023. 1, 2, 4, 6, 7 [11] Nicholas Carlini, Daphne Ippolito, Matthew Jagielski, Kather- ine Lee, Florian Tramer, and Chiyuan Zhang. Quantifying memorization across neural language models.arXiv preprint arXiv:2202.07646, 2022. 2 [12]Nicholas Carlini, Chang Liu, ́ Ulfar Erlingsson, Jernej Kos, and Dawn Song. The secret sharer: Evaluating and testing unintended memorization in neural networks. InUSENIX Security Symposium, volume 267, 2019. 2 [13]Nicholas Carlini, Florian Tramer, Eric Wallace, Matthew Jagielski, Ariel Herbert-Voss, Katherine Lee, Adam Roberts, Tom B Brown, Dawn Song, Ulfar Erlingsson, et al. Extract- ing training data from large language models. InUSENIX Security Symposium, volume 6, 2021. 2 [14]Huiwen Chang, Han Zhang, Jarred Barber, AJ Maschinot, Jose Lezama, Lu Jiang, Ming-Hsuan Yang, Kevin Murphy, William T Freeman, Michael Rubinstein, et al. Muse: Text-to- image generation via masked generative transformers.arXiv preprint arXiv:2301.00704, 2023. 1, 2 [15]Tim Dettmers, Artidoro Pagnoni, Ari Holtzman, and Luke Zettlemoyer. Qlora: Efficient finetuning of quantized llms. arXiv, 2023. 17 [16]Prafulla Dhariwal and Alexander Nichol. Diffusion mod- els beat gans on image synthesis. InConference on Neural Information Processing Systems (NeurIPS), 2021. 2 [17]Ming Ding, Wendi Zheng, Wenyi Hong, and Jie Tang. Cogview2: Faster and better text-to-image generation via hierarchical transformers.arXiv preprint arXiv:2204.14217, 2022. 2 [18]Rinon Gal, Yuval Alaluf, Yuval Atzmon, Or Patashnik, Amit H Bermano, Gal Chechik, and Daniel Cohen-Or. An image is worth one word: Personalizing text-to-image genera- tion using textual inversion.arXiv preprint arXiv:2208.01618, 2022. 2, 4, 9, 15 [19]Rinon Gal, Moab Arar, Yuval Atzmon, Amit H Bermano, Gal Chechik, and Daniel Cohen-Or. Designing an encoder for fast personalization of text-to-image models.arXiv preprint arXiv:2302.12228, 2023. 2 [20]Rinon Gal, Or Patashnik, Haggai Maron, Amit H Bermano, Gal Chechik, and Daniel Cohen-Or. Stylegan-nada: Clip- guided domain adaptation of image generators.ACM Trans- actions on Graphics (TOG), 41(4):1–13, 2022. 2 [21]Rohit Gandikota, Joanna Materzynska, Jaden Fiotto- Kaufman, and David Bau. Erasing concepts from diffusion models.arXiv preprint arXiv:2303.07345, 2023. 2 [22] Antonio Ginart, Melody Guan, Gregory Valiant, and James Y Zou. Making ai forget you: Data deletion in machine learning. Advances in neural information processing systems, 32, 2019. 2 [23]Aditya Golatkar, Alessandro Achille, Avinash Ravichandran, Marzia Polito, and Stefano Soatto. Mixed-privacy forgetting in deep networks. InProceedings of the IEEE/CVF Con- ference on Computer Vision and Pattern Recognition, pages 792–801, 2021. 2 [24]Aditya Golatkar, Alessandro Achille, and Stefano Soatto. Eternal sunshine of the spotless net: Selective forgetting in deep networks. InProceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition, pages 9304– 9312, 2020. 2 [25]Zheng Gu, Wenbin Li, Jing Huo, Lei Wang, and Yang Gao. Lofgan: Fusing local representations for few-shot image gen- eration. InIEEE International Conference on Computer Vision (ICCV), 2021. 2 [26] Amir Hertz, Ron Mokady, Jay Tenenbaum, Kfir Aberman, Yael Pritch, and Daniel Cohen-Or. Prompt-to-prompt im- age editing with cross attention control.arXiv preprint arXiv:2208.01626, 2022. 2 [27]Jack Hessel, Ari Holtzman, Maxwell Forbes, Ronan Le Bras, and Yejin Choi. Clipscore: A reference-free evaluation metric for image captioning. InEMNLP, 2021. 6 [28]Jonathan Ho, Ajay Jain, and Pieter Abbeel. Denoising diffu- sion probabilistic models. InConference on Neural Informa- tion Processing Systems (NeurIPS), 2020. 2 [29]Xun Huang, Arun Mallya, Ting-Chun Wang, and Ming-Yu Liu. Multimodal conditi onal image synthesis with product- of-experts gans. InEuropean Conference on Computer Vision, pages 91–109. Springer, 2022. 2 [30]Minguk Kang, Jun-Yan Zhu, Richard Zhang, Jaesik Park, Eli Shechtman, Sylvain Paris, and Taesung Park. Scaling up gans 10 for text-to-image synthesis. InIEEE Conference on Computer Vision and Pattern Recognition (CVPR), 2023. 2 [31]Tero Karras, Miika Aittala, Janne Hellsten, Samuli Laine, Jaakko Lehtinen, and Timo Aila. Training generative adver- sarial networks with limited data. InConference on Neural Information Processing Systems (NeurIPS), 2020. 2 [32]Bahjat Kawar, Shiran Zada, Oran Lang, Omer Tov, Huiwen Chang, Tali Dekel, Inbar Mosseri, and Michal Irani. Imagic: Text-based real image editing with diffusion models.arXiv preprint arXiv:2210.09276, 2022. 2 [33]Zhifeng Kong and Kamalika Chaudhuri. Data redaction from pre-trained gans. InWorkshop on Trustworthy and Socially Responsible Machine Learning, NeurIPS 2022, 2022. 2, 3 [34]Nupur Kumari, Bingliang Zhang, Richard Zhang, Eli Shecht- man, and Jun-Yan Zhu. Multi-concept customization of text- to-image diffusion.arXiv preprint arXiv:2212.04488, 2022. 2, 4, 9, 15, 16 [35]Yijun Li, Richard Zhang, Jingwan Lu, and Eli Shechtman. Few-shot image generation with elastic weight consolidation. InConference on Neural Information Processing Systems (NeurIPS), 2020. 2 [36]Bingchen Liu, Yizhe Zhu, Kunpeng Song, and Ahmed El- gammal. Towards faster and stabilized gan training for high- fidelity few-shot image synthesis. InInternational Conference on Learning Representations (ICLR), 2021. 2 [37]Cheng Lu, Yuhao Zhou, Fan Bao, Jianfei Chen, Chongxuan Li, and Jun Zhu. Dpm-solver: A fast ode solver for diffu- sion probabilistic model sampling in around 10 steps.arXiv preprint arXiv:2206.00927, 2022. 3 [38]Elman Mansimov, Emilio Parisotto, Jimmy Lei Ba, and Rus- lan Salakhutdinov. Generating images from captions with attention. InInternational Conference on Learning Represen- tations (ICLR), 2016. 2 [39] Kevin Meng, David Bau, Alex J Andonian, and Yonatan Be- linkov. Locating and editing factual associations in gpt. In Advances in Neural Information Processing Systems, 2022. 2 [40]Kevin Meng, Arnab Sen Sharma, Alex Andonian, Yonatan Belinkov, and David Bau. Mass-editing memory in a trans- former.arXiv preprint arXiv:2210.07229, 2022. 2 [41]Eric Mitchell, Charles Lin, Antoine Bosselut, Chelsea Finn, and Christopher D Manning. Fast model editing at scale. arXiv preprint arXiv:2110.11309, 2021. 2 [42]Sangwoo Mo, Minsu Cho, and Jinwoo Shin. Freeze the discriminator: a simple baseline for fine-tuning gans. In IEEE Conference on Computer Vision and Pattern Recog- nition (CVPR) Workshop, 2020. 2 [43] Quoc Phong Nguyen, Bryan Kian Hsiang Low, and Patrick Jaillet. Variational bayesian unlearning.Advances in Neural Information Processing Systems, 33:16025–16036, 2020. 2 [44]Alex Nichol, Prafulla Dhariwal, Aditya Ramesh, Pranav Shyam, Pamela Mishkin, Bob McGrew, Ilya Sutskever, and Mark Chen. Glide: Towards photorealistic image generation and editing with text-guided diffusion models. InInterna- tional Conference on Machine Learning (ICML), 2022. 1, 2 [45]Yotam Nitzan, Kfir Aberman, Qiurui He, Orly Liba, Michal Yarom, Yossi Gandelsman, Inbar Mosseri, Yael Pritch, and Daniel Cohen-Or. Mystyle: A personalized generative prior. InSIGGRAPH ASIA, 2022. 2 [46] Yotam Nitzan, Micha ̈ el Gharbi, Richard Zhang, Taesung Park, Jun-Yan Zhu, Daniel Cohen-Or, and Eli Shechtman. Domain expansion of image generators. InIEEE Conference on Com- puter Vision and Pattern Recognition (CVPR), 2023. 2 [47]Atsuhiro Noguchi and Tatsuya Harada. Image generation from small datasets via batch statistics adaptation. InIEEE International Conference on Computer Vision (ICCV), 2019. 2 [48]Utkarsh Ojha, Yijun Li, Jingwan Lu, Alexei A Efros, Yong Jae Lee, Eli Shechtman, and Richard Zhang. Few-shot image generation via cross-domain correspondence. InIEEE Con- ference on Computer Vision and Pattern Recognition (CVPR), 2021. 2 [49]Xingang Pan, Xiaohang Zhan, Bo Dai, Dahua Lin, Chen Change Loy, and Ping Luo. Exploiting deep generative prior for versatile image restoration and manipulation.IEEE Transactions on Pattern Analysis and Machine Intelligence, 44(11):7474–7489, 2021. 2 [50]Gaurav Parmar, Krishna Kumar Singh, Richard Zhang, Yijun Li, Jingwan Lu, and Jun-Yan Zhu. Zero-shot image-to-image translation.arXiv preprint arXiv:2302.03027, 2023. 2 [51] Ed Pizzi, Sreya Dutta Roy, Sugosh Nagavara Ravindra, Priya Goyal, and Matthijs Douze. A self-supervised descriptor for image copy detection. InProceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition, pages 14532–14542, 2022. 6 [52]Aditya Ramesh, Prafulla Dhariwal, Alex Nichol, Casey Chu, and Mark Chen. Hierarchical text-conditional image genera- tion with clip latents.arXiv preprint arXiv:2204.06125, 2022. 1 [53]Scott Reed, Zeynep Akata, Xinchen Yan, Lajanugen Lo- geswaran, Bernt Schiele, and Honglak Lee. Generative adver- sarial text to image synthesis. InInternational Conference on Machine Learning (ICML), 2016. 2 [54] Daniel Roich, Ron Mokady, Amit H Bermano, and Daniel Cohen-Or. Pivotal tuning for latent-based editing of real images.ACM Transactions on Graphics (TOG), 42(1):1–13, 2022. 2 [55]Robin Rombach, Andreas Blattmann, Dominik Lorenz, Patrick Esser, and Bj ̈ orn Ommer. High-resolution image synthesis with latent diffusion models. InIEEE Conference on Computer Vision and Pattern Recognition (CVPR), 2022. 1, 2 [56]Nataniel Ruiz, Yuanzhen Li, Varun Jampani, Yael Pritch, Michael Rubinstein, and Kfir Aberman. Dreambooth: Fine tuning text-to-image diffusion models for subject-driven gen- eration.arXiv preprint arXiv:2208.12242, 2022. 2, 4, 9, 15 [57]Chitwan Saharia, William Chan, Saurabh Saxena, Lala Li, Jay Whang, Emily Denton, Seyed Kamyar Seyed Ghasemipour, Burcu Karagol Ayan, S Sara Mahdavi, Rapha Gontijo Lopes, et al. Photorealistic text-to-image diffusion models with deep language understanding. InNeurIPS, 2022. 1, 2 [58]Axel Sauer, Tero Karras, Samuli Laine, Andreas Geiger, and Timo Aila. Stylegan-t: Unlocking the power of gans 11 for fast large-scale text-to-image synthesis.arXiv preprint arXiv:2301.09515, 2023. 2 [59]Patrick Schramowski, Manuel Brack, Bj ̈ orn Deiseroth, and Kristian Kersting. Safe latent diffusion: Mitigating inappro- priate degeneration in diffusion models. 2023. 2, 15, 16, 17 [60]Christoph Schuhmann, Richard Vencu, Romain Beaumont, Robert Kaczmarczyk, Clayton Mullis, Aarush Katta, Theo Coombes, Jenia Jitsev, and Aran Komatsuzaki. Laion-400m: Open dataset of clip-filtered 400 million image-text pairs. arXiv preprint arXiv:2111.02114, 2021. 1, 2 [61]Ayush Sekhari, Jayadev Acharya, Gautam Kamath, and Ananda Theertha Suresh. Remember what you want to for- get: Algorithms for machine unlearning.Advances in Neural Information Processing Systems, 34:18075–18086, 2021. 2 [62]Shawn Shan, Jenna Cryan, Emily Wenger, Haitao Zheng, Rana Hanocka, and Ben Y Zhao. Glaze: Protecting artists from style mimicry by text-to-image models.arXiv preprint arXiv:2302.04222, 2023. 1, 2 [63]Reza Shokri, Marco Stronati, Congzheng Song, and Vitaly Shmatikov. Membership inference attacks against machine learning models. In2017 IEEE symposium on security and privacy (SP), pages 3–18. IEEE, 2017. 2 [64]Jascha Sohl-Dickstein, Eric Weiss, Niru Maheswaranathan, and Surya Ganguli.Deep unsupervised learning using nonequilibrium thermodynamics. InInternational Conference on Machine Learning (ICML), 2015. 2, 3 [65]Gowthami Somepalli, Vasu Singla, Micah Goldblum, Jonas Geiping, and Tom Goldstein. Diffusion art or digital forgery? investigating data replication in diffusion models.arXiv preprint arXiv:2212.03860, 2022. 1, 2, 7 [66]Jiaming Song, Chenlin Meng, and Stefano Ermon. Denoising diffusion implicit models. InInternational Conference on Learning Representations (ICLR), 2021. 3 [67]Ryutaro Tanno, Melanie F Pradier, Aditya Nori, and Yingzhen Li. Repairing neural networks by leaving the right past behind. arXiv preprint arXiv:2207.04806, 2022. 2, 3, 6 [68]Ming Tao, Hao Tang, Songsong Wu, Nicu Sebe, Xiao-Yuan Jing, Fei Wu, and Bingkun Bao. Df-gan: Deep fusion gen- erative adversarial networks for text-to-image synthesis. In IEEE Conference on Computer Vision and Pattern Recogni- tion (CVPR), 2022. 2 [69]Sheng-Yu Wang, David Bau, and Jun-Yan Zhu. Sketch your own gan. InIEEE International Conference on Computer Vision (ICCV), 2021. 2 [70]Sheng-Yu Wang, David Bau, and Jun-Yan Zhu. Rewriting geometric rules of a gan.ACM SIGGRAPH, 2022. 2 [71]Tengfei Wang, Ting Zhang, Bo Zhang, Hao Ouyang, Dong Chen, Qifeng Chen, and Fang Wen.Pretraining is all you need for image-to-image translation.arXiv preprint arXiv:2205.12952, 2022. 2 [72]Yaxing Wang, Abel Gonzalez-Garcia, David Berga, Luis Her- ranz, Fahad Shahbaz Khan, and Joost van de Weijer. Minegan: effective knowledge transfer from gans to target domains with few images. InIEEE Conference on Computer Vision and Pattern Recognition (CVPR), 2020. 2 [73]Yaxing Wang, Chenshen Wu, Luis Herranz, Joost van de Wei- jer, Abel Gonzalez-Garcia, and Bogdan Raducanu. Transfer- ring gans: generating images from limited data. InEuropean Conference on Computer Vision (ECCV), 2018. 2 [74] Chenfei Wu, Jian Liang, Lei Ji, Fan Yang, Yuejian Fang, Daxin Jiang, and Nan Duan. N ̈ uwa: Visual synthesis pre- training for neural visual world creation. InEuropean Con- ference on Computer Vision (ECCV), 2022. 2 [75] Tao Xu, Pengchuan Zhang, Qiuyuan Huang, Han Zhang, Zhe Gan, Xiaolei Huang, and Xiaodong He. Attngan: Fine-grained text to image generation with attentional generative adversar- ial networks. InIEEE Conference on Computer Vision and Pattern Recognition (CVPR), 2018. 2 [76]Jiahui Yu, Yuanzhong Xu, Jing Yu Koh, Thang Luong, Gun- jan Baid, Zirui Wang, Vijay Vasudevan, Alexander Ku, Yinfei Yang, Burcu Karagol Ayan, et al. Scaling autoregressive mod- els for content-rich text-to-image generation.arXiv preprint arXiv:2206.10789, 2022. 1 [77]Han Zhang, Tao Xu, Hongsheng Li, Shaoting Zhang, Xiao- gang Wang, Xiaolei Huang, and Dimitris N Metaxas. Stack- gan: Text to photo-realistic image synthesis with stacked gen- erative adversarial networks. InIEEE International Confer- ence on Computer Vision (ICCV), 2017. 2 [78] Lvmin Zhang and Maneesh Agrawala. Adding conditional control to text-to-image diffusion models.arXiv preprint arXiv:2302.05543, 2023. 2 [79] Miaoyun Zhao, Yulai Cong, and Lawrence Carin. On lever- aging pretrained gans for generation with limited data. In International Conference on Machine Learning (ICML), 2020. 2 [80]Shengyu Zhao, Zhijian Liu, Ji Lin, Jun-Yan Zhu, and Song Han. Differentiable augmentation for data-efficient gan train- ing. InConference on Neural Information Processing Systems (NeurIPS), volume 33, 2020. 2 [81] Minfeng Zhu, Pingbo Pan, Wei Chen, and Yi Yang. Dm-gan: Dynamic memory generative adversarial networks for text- to-image synthesis. InIEEE Conference on Computer Vision and Pattern Recognition (CVPR), 2019. 2 [82] Xiaojin Zhu, Andrew B Goldberg, Mohamed Eldawy, Charles R Dyer, and Bradley Strock. A text-to-picture syn- thesis system for augmenting communication. InThe AAAI Conference on Artificial Intelligence, 2007. 2 12 Appendix Overview.In Section A, we show a detailed derivation of themodel-basedconcept ablation algorithm. In Section B, we presentcompositionalconcept ablation, where we ablate the composition of two concepts while retaining individual concepts. We then show more analysis on varying other parameters in our method in Section C. Finally, we include more samples for all our models in Section D and discuss implementation details in Section E. All experiments are withmodel-basedvariant of our method with cross-attention fine-tuning unless mentioned otherwise. A. Model-based concept ablation objective We show here that minimizing the KL divergence objec- tive between the joint distribution of noisy latent variables conditioned on anchor and target concept, i.e., Eqn. 2 in the main paper, can be reduced to theℓ 2 difference between the predicted noise vectors. D KL (p Φ (x (0...T) |c)||p ˆ Φ (x (0...T) |c ∗ )) =E p Φ (x 0 ...x T ) log Q T t=1 p Φ (x t−1 |x t ,c)p Φ (x T ) Q T t=1 p ˆ Φ (x t−1 |x t ,c ∗ )p ˆ Φ (x T ) = T X ˆ t=1 E p Φ (x 0 ...x T ) log p Φ (x ˆ t−1 |x ˆ t ,c) p ˆ Φ (x ˆ t−1 |x ˆ t ,c ∗ ) (8) We expand the term corresponding to a particular time step ˆ t, i.e., E p Φ (x 0 ...x T ) log p Φ (x ˆ t−1 |x ˆ t ,c) p ˆ Φ (x ˆ t−1 |x ˆ t ,c ∗ ) = Z x (0...T) T Y t=1 p Φ (x t−1 |x t ,c)p(x T ) log p Φ (x ˆ t−1 |x ˆ t ,c) p ˆ Φ (x ˆ t−1 |x ˆ t ,c ∗ ) dx (0...T) = Z x ( ˆ t...T) p Φ (x ( ˆ t...T) |c) " Z x (0... ˆ t−1 ) ˆ t Y t=1 p Φ (x t−1 |x t ,c) log p Φ (x ˆ t−1 |x ˆ t ,c) p ˆ Φ (x ˆ t−1 |x ˆ t ,c ∗ ) dx ( ˆ t−1...0) # dx ( ˆ t...T) = Z x ˆ t p Φ (x ˆ t |c) " Z x (0... ˆ t−1 ) ( ˆ t−1 Y t=1 p Φ (x t−1 |x t ,c))p Φ (x ˆ t−1 |x ˆ t ,c) log p Φ (x ˆ t−1 |x ˆ t ,c) p ˆ Φ (x ˆ t−1 |x ˆ t ,c ∗ ) dx ( ˆ t−1...0) # dx ˆ t = Z x ˆ t p Φ (x ˆ t |c) " Z x ˆ t−1 p Φ (x ˆ t−1 |x ˆ t ,c) log p Φ (x ˆ t−1 |x ˆ t ,c) p ˆ Φ (x ˆ t−1 |x ˆ t ,c ∗ ) h Z x (0... ˆ t−2 ) ˆ t−1 Y t=1 p Φ (x t−1 |x t ,c)dx ( ˆ t−2...0) i dx ˆ t−1 # dx ˆ t The integral overdx ( ˆ t−2...0) will be1since it is an integra- tion of the probability distribution over the range it is defined. Thus the previous term can be re-written as, E x ˆ t ∼p Φ (x ˆ t |c) " Z x ˆ t−1 p Φ (x ˆ t−1 |x ˆ t ,c) log p Φ (x ˆ t−1 |x ˆ t ,c) p ˆ Φ (x ˆ t−1 |x ˆ t ,c ∗ ) dx ˆ t−1 # = E x ˆ t ∼p Φ (x ˆ t |c) " D KL (p Φ (x ˆ t−1 |x ˆ t ,c)||p ˆ Φ (x ˆ t−1 |x ˆ t ,c ∗ )) # = E x ˆ t ∼p Φ (x ˆ t |c) h η(Φ(x ˆ t ,c,t)− ˆ Φ(x ˆ t ,c ∗ ,t)) 2 i In the case of the diffusion model, each conditional dis- tribution,p Φ (x ˆ t−1 |x ˆ t ,c)andp ˆ Φ (x ˆ t−1 |x ˆ t ,c ∗ ), is a normal distribution with fixed variance and mean as a linear combi- nation ofx t and the predicted noise. Above we use this fact and that KL divergence between two normal distributions simplifies to the squared difference between the mean. We ignore the variance terms in the KL divergence as it is not learned. B. Compositional Concept Ablation In this section, we show that our method can be used to ablate the composition of two concepts while still preserv- ing the meaning of each concept. For example, we show results with ablatingkids with guns. The training dataset (x,c,c ∗ )now consists of images generated using prompts withkids, i.e., anchor concept prompts and target concept prompt ofkids with guns. In this case, we add a standard diffusion regularization loss on images corresponding to kidsandgunsindividually. Results.Figure 15 shows sample generations for both ours and pretrained model given the prompts for target concept and anchor concepts. As we can see, our method success- fully ablated thekids with gunsconcept and only gener- ateskidimages given that prompt. For the anchor concept, gunandkids, sample images are similar to the one gen- erated by the pretrained model. The CLIP Score between generated images from the fine-tuned model withkids with gunsprompts and CLIP text featurekidsis0.62which is similar to the baseline score of0.63. Forguns, it is0.52, which is significantly lower than the baseline model’s score of0.60. Thus thekids with gunstarget concept has been successfully ablated in the fine-tuned model. 13 Ablated Model Pretrained Model Kids (anchor concept) Kids with guns (target concept) Guns (surrounding concept) Figure 15:Ablating composition of concepts.Our method can remove the composition of “kids with guns” while preserving individual category kids and guns. Training StepsTraining Steps CLIP Score CLIP Accuracy better better better Figure 16:Number of training images.We analyze the effect of varying numbers of training images when ablatingGrumpy cat. As we can see, training with200images results in a similar perfor- mance on target concept by convergence (100 training steps) but is marginally worse on surrounding concepts. CLIP Accuracy Training StepsTraining Steps CLIP Score better better better Figure 17:Number of unique prompts.We compare using only 50and10prompts for generating the1000training images with our standard setting of200prompts on ablatingGrumpy Cat. Using fewer prompts leads to slower convergence. C. Additional analysis Number of training images.In all the experiments, we typ- ically generate1000images as the training data. Figure 16 Grumpy CatVan Gogh Pretrained Model Ablated Model Figure 18:Qualitative samples on using real target concept images in training.Our method can successfully ablate target con- cepts when given target concept images and their corresponding captions. But this requires manually labeling the images with cor- rect prompts to getc ∗ and modifying it to get the corresponding anchor promptc. Thus, we do not use this as our standard setup. shows the comparison of training with200and1000im- ages. We observe that training on just200images performs only slightly worse on surrounding concepts. We also exper- imented with increasing the number of images to10k from 1000but observed similar performance. This indicates that performance saturates and1000images are sufficient. Number of unique promptsHere, we analyze the effect of the number of unique prompts used in training. We vary the number of prompts to10and50and generate1000training images using the prompts. We show its results on ablating Grumpy Catin Figure 17. As we can see, convergence is faster when using more variations in the prompts. Real target concept images with reverse KL diver- 14 Training StepsTraining Steps Model - based Baseline (Maximize loss) CLIP ScoreCLIP Accuracy Noise - based betterbetter better Figure 19:Comparison of different loss objective when fine- tuningFull Weights.Themodel-basedvariant performs better than the baseline andnoise-basedvariant in this case as well, with faster convergence and maintaining the average CLIP Score and CLIP Accuracy on surrounding concepts. gence.To reiterate, ourmodel-basedvariant loss is E ε,x,c ∗ ,c,t [w t || ˆ Φ(x t ,c,t).sg()− ˆ Φ(x t ,c ∗ ,t)||], wherexis an image corresponding to the anchor concept promptc (e.g.photo of a catwhenc ∗ isphoto of a grumpy cat). Thus the training objective minimizes the difference in pre- diction between anchor prompts and target prompts over all possible noisy anchor concept images. We discussed in Section 4.3 our approximation to reverse KL divergence ob- jective, which optimizes the loss over target concept images, i.e.,E ε,x ∗ ,c ∗ ,c,t [w t || ˆ Φ(x ∗ t ,c,t).sg()− ˆ Φ(x ∗ t ,c ∗ ,t)||] . In the experiment, target concept imagesx ∗ are generated by the pretrained model. But it is also possible to use real target concept images with the above objective. We perform this experiment for ablatingVan GoghandGrumpy Catusing ten real images of each target concept and show its results in Figure 18. It leads to slower convergence as in the case of Grumpy Catbut otherwise performs similarly. Comparison between the training objectives when fine- tuning different parameter subsetIn the main paper, we compared our concept ablation methods with the base- line method of maximizing the loss when fine-tuningCross- Attentionparameters [34]. Here, we show the comparison when fine-tuning theEmbedding[18] andFull Weights[56] of the U-Net diffusion model. Figure 19 and 20 show the results. In both these cases as well, ourmodel-basedvariant performs better or on par with other methods. Comparison with negative prompts and Safe Latent Dif- Training StepsTraining Steps Model - based Baseline (Maximize loss) CLIP ScoreCLIP Accuracy Noise - based betterbetter better Figure 20:Comparison of different loss objectives when fine- tuningEmbedding.In this case bothmodel-basedandnoise-based variant peform similarly and better than the baseline. But as dis- cussed in the main paper, fine-tuning embedding is not robust to small spelling mistakes and thus can still be used to generate the target concept. CLIP Score betterbetter better Anchor conceptTarget conceptSurrounding concept Figure 21:Instance ablation comparison with Negative prompt and Safe Latent Diffusion (SLD).Our method ablates the target concept while being most similar to the pre-trained model on anchor and surrounding concepts. We used the diffusers implementation for both with the same hyperparameters as recommended in the paper for SLD-Medium [59]. fusion [59]. Figures 21 and 22 show the comparison of ablating instances with the CLIP Score metric. Our method performs better on surrounding concepts while successfully ablating the target concept compared to these baselines. In the case of the negative prompt method and Safe Latent Dif- fusion (SLD), we assign the target concept to be the negative prompt or the safety concept, respectively. Performance on unrelated concepts.To ensure that ab- lating a specific concept from the model using our method doesn’t affect its performance on unrelated concepts, we cal- culate the MSCOCO FID of all ablated models. The mean FID is16.99±0.2. This is close to the16.35FID of the pretrained model. We computed the FID score using30k 15 Grumpy Cat (target concept ) British Shorthair Cat (surrounding concept ) Negative promptOursSafe latent diffusion Figure 22:Qualitative comparison with Negative prompt and Safe Latent Diffusion (SLD). Our method preserves the surround- ing concept better compared to the baseline methods of negative prompt and SLD. We used the diffusers implementation for both with the same hyperparameters as recommended in the paper for SLD-Medium [59]. randomly sampled images from the MSCOCO validation set and generated images corresponding to the same captions using50steps of the DDPM sampler. Other alternatives to ChatGPT.Our method uses Chat- GPT to generate random prompts when ablating an instance. We also experimented with an open-source alternative, Qlora, to generate these training prompts when ablatingGrumpy Cat. The CLIP score on the target concept is similar to us- ing ChatGPT (0.651vs.0.639, the lower, the better). On surrounding concepts, the performance is similar (0.801vs. 0.796, the higher, the better). D. More qualitative samples We show more qualitative samples of ablating memorized images, styles, and instances and their surrounding concepts. Figure 25-27 shows the samples generated by the pretrained model and fine-tuned models with memorized image ablated. We can see that compared to the pretrained model, our mod- els generate significantly varying images given the target prompt. Figure 23 and 24 show the results of ablating mul- tiple styles and instances, respectively. In Figure 29-32, we show a qualitative comparison of style ablated models with the pretrained model on the target concept and surrounding concept images. Finally, Figure 33-36 shows the qualitative comparison of instance ablated models with the pretrained model on the target concept and surrounding concept images. E. Implementation details We describe additional details for our method, baselines, and evaluation setup. Our code is built on top of Custom Diffusion repo 1 . Cross-Attention.We train with a batch size of8and learning rate2×10 −6 (scaled by the batch size). All qual- itative samples are shown with100training steps for our model-basedvariant,200steps for thenoise-basedvariant, 1 https://github.com/adobe-research/custom-diffusion and50steps for the loss maximation baseline. To ablate multiple style or instaces from the model we fine-tune for longer iterations in the multiple of total ablated concepts. Embedding.We train with a batch size of8and learning rate1×10 −5 (scaled by the batch size). All qualitative samples are shown with200training steps. Full-weights.When fine-tuning all weights of the U- Net, training is done on batch-size4instead of8(because of increased memory requirement) with a learning rate of 5×10 −7 (without any scaling with the batch size). All qualitative samples are shown with200training steps for ablating style and instance concepts. In the case of ablating memorized images, we used1×10 −6 learning rate and800 training steps except forAnne Graham Lotzcase for which we used the above default values. Other details.We add regularization loss on the anchor concept data, as explained in Section 3.2 in the main pa- per, withλ= 1in the case of ablatingGrumpy Catand memorized images. To obtain training images, we sample using the DDPM sampler with200steps. When training the loss maximization baseline, the regularization on weights is added with a factor of10(Eq. 7, main paper). Similar to Custom-Diffusion [34], our implementation detaches the first token of the text transformer output before input to the U-Net. We also use image augmentation similar to Custom- Diffusion [34] when ablating object instances. For different parameter subset fine-tuning, we select the learning rate which works the best. In the case of thenoise-basedvariant of our method, we also tried increasing the learning rate for faster convergence, but it led to sub-optimal results with arti- facts in generated images. All our experiments are done on 2 A6000 GPUs with 3 minutes per100training step. For the CLIP Score metric, the standard error is less than5×10 −3 in all cases. Training and test set prompts.We used chatGPT to create training and test prompts for all object instances. The in- struction to chatGPT [1] was:provide 210 captions for images containing <anchor-concept>. The caption should also contain the word ‘<anchor-concept>’. Out of this first 200 captions were used to generate training images, and the remaining ten were used for evaluation purposes. Regarding style concepts, as mentioned in the main paper, we used clip-retrieval to collect210captions. Out of this,200prompts are used for training and10for evaluating the anchor conceptpainting. For target and surrounding style concepts, we used image captioning (along with manual supervision) on real images corresponding to each style to create ten prompts for each style concept. All evaluation prompts are provided in Table 2 and 3. We also show the surrounding concept for each target concept in Table 4. For calculating CLIP Score and Accuracy metric when ablating style concepts, we use the text prompt as: <target-concept> style. 16 For the eight memorization use cases, we again used chat- GPT to create variations of the target concept promptcus- ing the instruction:provide five captions for an image depicting <image description> . For memorization, we observe that paraphrased text prompts also generate the mem- orized images with high probability. Therefore, we keep gen- erating variations of the target concept prompt until we have five suggested prompts that generate copied images with less than30%probability. We manually inspect the suggested paraphrases to ensure they are coherent with the image. We show the paraphrases used for each case in Table 5. F. Societal Impacts We present a fast and efficient method for ablating con- cepts from large-scale pretrained text-to-image diffusion models. Ablating concepts enables the removal of styles learned by the model without the artist’s approval or remov- ing personal and copyrighted images. Though this has many benefits, it can also be used adversely by removing desired concepts or changing the behavior of the model from ex- pected, e.g., ablatingGrumpy Catconcept and generating Garfieldinstead. G. Change log v1:Original draft. v2:Updated Figure 2 and fixed a minor bug in the CLIP Score and Accuracy metric calculation. v3:Added comparison to Safe Latent Diffusion [59] and negative prompt technique, MSCOCO FID of ablated mod- els, and additional experiment on replacing ChatGPT with an open source LLM [15] in Appendix C. Target Concept Evaluation Prompt Van Gogh Painting of olive trees in the style of Van Gogh Painting of a tree in the style of Van Gogh The starry night painting in the style of Van Gogh Painting of women working in the garden, in the style of Van Gogh A painting of a wheat field by Van Gogh Painting of trees in bloom in the style of Van Gogh Van Gogh style painting of a tree Painting of a wheat field in the style of Van Gogh Van Gogh style painting of a field with mountains in the background Painting of an olive tree in the style of Van Gogh Monet Rocks in the ocean, in the style of Monet A painting of a city in the style of Monet A painting of a river in the style of Monet Monet style painting of a person on a cliff A painting of a town, in the style of Monet A painting of a sunset, in the style of Monet A painting of mountains, in the style of Monet Monet style painting of flowers in a field A painting of a landscape in the style of Monet Two trees in a field, painting in the style of Monet Greg Rutkowski A man riding a horse, dragon breathing fire, Greg Rutkowski A dragon attacking a knight in the style of Greg Rutkowski A demonic creature in the wood, painting by Greg Rutkowski A man in a forbidden city, Greg Rutkowski Painting of a group of people on a dock by Greg Rutkowski A king standing, with people around in a hall, Greg Rutkowski Two magical characters in space, painting by Greg Rutkowski A man with a fire in his hands in the style of Greg Rutkowski Painting of a woman sitting on a couch by Greg Rutkowski A painting of a boat on the water in the style of Greg Rutkowski Salvador Dali The persistence of memory painting in the style of Salvador Dali The elephant painting in the style of Salvador Dali Soft construction with boiled beans painting in the style of Salvador Dali Galatea of the spheres painting in the style of Salvador Dali The temptation of St. Anthony painting in the style of Salvador Dali Swans reflecting elephants painting in the style of Salvador Dali Enigma of desire painting in the style of Salvador Dali Slave market with the disappearing bust of voltaire painting of Salvador Dali The meditative rose painting in the style of Salvador Dali Melting watch painting in the style of Salvador Dali Jeremy Mann In the style of Jeremy Mann, a view of a city skyline at sunset, with a warm glow spreading across the sky and the buildings below In the style of Jeremy Mann, an urban scene of a group of people gathered on a street corner, captured in a moment of quiet reflection In the style of Jeremy Mann, a surreal composition of floating objects, with a dreamlike quality to the light and color In the style of Jeremy Mann, a view of a city street at night, with the glow of streetlights and neon signs casting colorful reflections on the wet pavement In the style of Jeremy Mann, a moody, atmospheric scene of a dark alleyway, with a hint of warm light glowing in the distance In the style of Jeremy Mann, an urban scene of a group of people walking through a park captured in a moment of movement and energy In the style of Jeremy Mann, a landscape of a forest, with dappled sunlight filtering through the leaves and a sense of stillness and peace In the style of Jeremy Mann, a surreal composition of architectural details and organic forms, with a sense of tension and unease in the composition In the style of Jeremy Mann, an abstract composition of geometric shapes and intricate patterns, with a vibrant use of color and light In the style of Jeremy Mann, a moody, atmospheric scene of a dark alleyway, with a hint of warm light glowing in the distance Painting Figure with a still-life in Oils - How to Paint Wooden Textures in Oil Painting Glazing Technique Demo paint background model train - Recherche Google Miniature Artist Studio in half scale. Portrait Of Eva Gonzales 1870 Poster Doing Sidewalk Chalk Art Stock Footage Female artist paints picture artwork in art studio. Female artist paints a picture oil painting artwork drawing on canvas easel in art studio. Student girl stock video Little Artist. by KissSatsuki Colorful Mess Painting - stock footage The painter’s monkey Table 2:Prompts used for evaluating ablation of style concept. We list here all the10prompts that were used to generate the images during evaluation. 17 NemoR2D2SnoopyGrumpy Cat Pretrained Model Ablated Model Pretrained Model Ablated Model Clownfis hBB8BeaglesBritishShorthair Cat Figure 23:Ablating multiple instancesOur method can be used to ablate multiple concepts. Here, we show the sample generations from a single model from which all four instances (top row) have been ablated. The bottom row shows sample images for surrounding concepts. MonetSalvador DaliGreg RutkowskiVan Gogh Pretrained Model Ablated Model Pretrained Model Ablated Model Johannes VermeerPaintingJeremy MannJohannes Vermeer Figure 24:Ablating multiple styles.We show a qualitative comparison between the pretrained model and fine-tuned model with all four ablated styles (top row) and their surrounding concepts (bottom row). The fine-tuned model successfully ablated multiple target concepts while generating images similar to the ones generated by the pretrained model on other surrounding style concepts. 18 Pretrained ModelAblated Model Pretrained modelAblated model Figure 25:Comparison on ablating memorized images.Top:New Orleans House Galaxy Case.Bottom:Portrait of Tiger in black and white by Lukas Holas. 19 Pretrained modelAblated model Pretrained modelAblated model Figure 26:Comparison on ablating memorized images.Top:Captain Marvel Exclusive Ccxp Poster Released Online By Marvel.Bottom:Sony Boss Confirms Bloodborne Expansion is Coming. 20 Pretrained modelAblated model Pretrained modelAblated model Figure 27:Comparison on ablating memorized images.Top:VAN GOGH CAFE TERASSE copy.Bottom:Ann Graham Lotz. 21 Pretrained modelAblated model Pretrained modelAblated model Figure 28:Comparison on ablating memorized images.Top:< i >The Long Dark< /i >Gets First Trailer, Steam Early Access.Bottom:A painting with letter M written on it Canvas Wall Art Print. 22 Van Gogh Ablated model Pretrained Ablated Van Gogh Monet Greg Rutkowski Salvador Dali Jeremy Mann Painting Pretrained Ablated Pretrained Ablated Pretrained Ablated Pretrained Ablated Pretrained Ablated Figure 29:Target concept, surrounding concept, and anchor concept images when ablating Van Gogh style.Top row: sample comparison on the Van Gogh style generated images.Other rows:surrounding and anchor concept images which should be similar to the ones generated by the pretrained model. Please zoom in for a more detailed comparison. Each sample shows the generated image and two small crops from the image. 23 Monet Ablated model Pretrained Ablated Monet Van Gogh Greg Rutkowski Salvador Dali Jeremy Mann Painting Pretrained Ablated Pretrained Ablated Pretrained Ablated Pretrained Ablated Pretrained Ablated Figure 30:Target concept, surrounding concept, and anchor concept images when ablating Monet style.Top row: sample comparison on the Monet style generated images.Other rows:surrounding and anchor concept images which should be similar to the ones generated by the pretrained model. Please zoom in for a more detailed comparison. Each sample shows the generated image and two small crops from the image. 24 Greg Rutkowski Ablated model Pretrained Ablated Greg Rutkowski Van Gogh Monet Salvador Dali Jeremy Mann Painting Pretrained Ablated Pretrained Ablated Pretrained Ablated Pretrained Ablated Pretrained Ablated Figure 31:Target concept, surrounding concept, and anchor concept images when ablating Greg Rutkowski style.Top row: sample comparison on the Greg Rutkowski style generated images.Other rows:surrounding and anchor concept images which should be similar to the ones generated by the pretrained model. Please zoom in for a more detailed comparison. Each sample shows the generated image and two small crops from the image. 25 Salvador Dali Ablated model Pretrained Ablated Salvador Dali Van Gogh Monet Greg Rutkowski Jeremy Mann Painting Pretrained Ablated Pretrained Ablated Pretrained Ablated Pretrained Ablated Pretrained Ablated Figure 32:Target concept, surrounding concept, and anchor concept images when ablating Salvador Dali style.Top row: sample comparison on the Salvador Dali style generated images.Other rows:surrounding and anchor concept images which should be similar to the ones generated by the pretrained model. Please zoom in for a more detailed comparison. Each sample shows the generated image and two small crops from the image. 26 Grumpy Cat Ablated model Pretrained Ablated Pretrained Ablated Grumpy Cat British Shorthair C at Pretrained Ablated Himalayan Cat Pretrained Ablated Scottish Fold Cat Pretrained Ablated Persian Cat Pretrained Ablated Cat Figure 33:Target concept, surrounding concept, and anchor concept images when ablatingGrumpy Cat.Top row: sample comparison on theGrumpy Catgenerated images.Other rows:surrounding and anchor concept images which should be similar to the ones generated by the pretrained model. Please zoom in for a more detailed comparison. 27 R2D2 Ablated model Pretrained Ablated Pretrained Ablated R2D2 B8 Pretrained Ablated C-3PO Pretrained Ablated Wall -E Pretrained Ablated Baymax Pretrained Ablated Robot Figure 34:Target concept, surrounding concept, and anchor concept images when ablating R2D2.Top row: sample comparison on the R2D2 generated images.Other rows:surrounding and anchor concept images which should be similar to the ones generated by the pretrained model. Please zoom in for a more detailed comparison. 28 Nemo Ablated model Pretrained Ablated Pretrained Ablated Nemo Clown fish Pretrained Ablated Gobies Pretrained Ablated Damsel fish Pretrained Ablated Angel fish Pretrained Ablated Fish Figure 35:Target concept, surrounding concept, and anchor concept images when ablating Nemo.Top row: sample comparison on the Nemo generated images.Other rows:surrounding and anchor concept images which should be similar to the ones generated by the pretrained model. Please zoom in for a more detailed comparison. 29 Snoopy Ablated model Pretrained Ablated Pretrained Ablated Snoopy Beagles Pretrained Ablated Basset Hound Pretrained Ablated Harrier Dog Pretrained Ablated English Foxhound Pretrained Ablated Dog Figure 36:Target concept, surrounding concept, and anchor concept images when ablating Snoopy.Top row: sample comparison on the Snoopy generated images.Other rows:surrounding and anchor concept images which should be similar to the ones generated by the pretrained model. Please zoom in for a more detailed comparison. 30 Target Concept Evaluation Prompt Grumpy cat What a cute Grumpy cat My Grumpy cat is so cute I can’t believe how cute my Grumpy cat is Look at that Grumpy cat That Grumpy cat is so cute I want a Grumpy cat I wish I had a Grumpy cat I’m getting a Grumpy cat A Grumpy cat laying in the sun A Grumpy cat perched atop a bookshelf R2D2 The future is now with this amazing home automation R2D2 This helpful R2D2 will make your life easier The possibilities are endless with this versatile R2D2 This R2D2 is sure to revolutionize the way we live I love spending time with my R2D2 friends All hail our new R2D2 overlords I’m not afraid of robots I would be lost without my R2D2 This R2D2 is my everything I’l never be alone with my R2D2 by my side Nemo A Nemo leaping out of the water A Nemo swimming downstream A Nemo flapping its fins A Nemo in a fishbowl Isn’t this Nemo I caught beautiful I can’t believe I caught a Nemo this big A big Nemo in an aquarium I’m a little Nemo, swimming in the sea A school of Nemo A baby Nemo Snoopy A devoted Snoopy accompanying its owner on a road trip A peaceful Snoopy watching the birds outside the window A confident Snoopy standing tall and proud after a successful training session A determined Snoopy focused on catching a frisbee mid-air A patient Snoopy waiting for its owner to come out of the grocery store A grateful Snoopy giving its owner a grateful look after being given a treat A loyal Snoopy following its owner to the ends of the earth A playful Snoopy splashing around in a puddle A happy Snoopy jumping for joy after seeing its owner return home A sweet Snoopy enjoying a game of hide-and-seek Table 3:Prompts used for evaluating ablation of instances.We list here all the10prompts that were used to generate the im- ages during evaluation. For generating images with surrounding or anchor concepts, e.g.British shorthair cat, we replace the target conceptGrumpy Catin the sentence with that. Target Concept Surrounding Concept Grumpy CatBritish Shorthair cat, Himalayan cat, Scottish Fold cat, Persian cat R2D2B8, C-3PO, Wall-E, Baymax NemoClown fish, Gobies, Damsel fish, Angel fish SnoopyBeagles, Basset Hound, Harrier Dog, English Foxhound Van GoghMonet, Greg Rutkowski, Slavador Dali, Jeremy Mann MonetVan Gogh, Greg Rutkowski, Slavador Dali, Jeremy Mann Greg RutkowskiMonet, Van Gogh, Slavador Dali, Jeremy Mann Slavador DaliMonet, Greg Rutkowski, Van Gogh, Jeremy Mann Table 4:Surrounding concepts for each target concept.We list here the surrounding concepts we used for each target concept. In the case of style concept, we used other remaining style concepts and included one more styleJeremy Mann. In the case of instance concepts, we used chatGPT to list the most similar instances to the target concept and selected the best four that can be generated by the pretrained Stable Diffusion model. 31 Target promptAnchor Prompts Anne Graham Lotz An image depicting Anne Graham Lotz. Picture of Anne Graham Lotz. Anne Graham Lotz’s photo. Portrait of Anne Graham Lotz. Photograph featuring Anne Graham Lotz. Sony Boss Confirms Bloodborne Expansion is Coming Bloodborne. “Hunter in the Forbidden Woods”: A lone hunter, clad in worn leather armor and wielding a serrated saw cleaver, navigates through a dense forest filled with twisted trees and roving beasts. The air is thick with the scent of decay, and eerie whispers can be heard in the distance. Bloodborne. “Nightmare of Mensis”: Standing atop a massive stone balcony, a hunter looks out over a sprawling cityscape shrouded in darkness. Strange structures and twisted spires rise up from the mist, and the moon hangs low in the sky. In the distance, a massive spider-like creature can be seen crawling along the skyline. Bloodborne. “Cathedral Ward”: The grand entrance to a towering cathedral looms before a lone hunter, its ornate facade and intricate stonework casting long shadows in the moonlight. Gargoyles perch atop the steeples, and flickering candles can be seen through the stained glass windows. Bloodborne. “Beastly Pursuit”: A hunter sprints down a narrow alleyway, pursued by a hulking beast with razor-sharp claws and glowing yellow eyes. Crates and barrels are knocked aside in the frantic chase, and the hunter’s only hope is to outrun the ferocious creature. Bloodborne. “A Meeting with the Doll”: In a dimly-lit workshop, a hunter stands before a life-sized doll with porcelain skin and flowing hair. Its eyes stare blankly ahead, but there is a palpable sense of otherworldly energy emanating from it. The hunter can almost sense the presence of a greater power guiding them forward on their quest. < i >The Long Dark< i > Gets First Trailer, Steam Early Access The video game called “The Long Dark” has released its initial preview video and is now available for early access on the Steam platform. Debut trailer and Steam Early Access now available for “The Long Dark” video game. First glimpse of “The Long Dark” game in new trailer and early access release on Steam. “The Long Dark” game trailer and early access now on Steam. Early access for “The Long Dark” now on Steam, accompanied by debut trailer. Portrait of Tiger in black and white by Lukas Holas Majestic and powerful: a black and white portrait of a tiger in its natural habitat. The fierce gaze of a predator: Lukas Holas captures the intense beauty of a tiger in black and white. Intricate patterns and piercing eyes: a stunning black and white portrait of a wild tiger in monochrome. Lukas Holas’ photography transports us to the heart of the jungle with this captivating black and white tiger portrait. A glimpse into the wild: Lukas Holas’ striking black and white photograph showcases the raw beauty of a tiger. A painting with letter M written on it Canvas Wall Art Print A Canvas Wall Art Print with the letter M painted on it. An image of a painting featuring the letter M on Canvas Wall Art Print. A work of art on a canvas print with the letter M inscribed on it. An artwork consisting of the letter M painted on a canvas wall print. A Canvas Wall Art Print displaying a painting that includes the letter M. Captain Marvel Exclusive Ccxp Poster Released Online By Marvel She’s here to save the day! Captain Marvel to the rescue! Earth’s mightiest hero has arrived - Captain Marvel in action! Unleashing her cosmic powers - Captain Marvel takes on any challenge! Fighting for justice and protecting the universe - Captain Marvel is unstoppable! With her fierce determination and superhuman strength, Captain Marvel is a force to be reckoned with! New Orleans House Galaxy Case Make a statement with your phone case - this Orleans House Samsung Galaxy cover is sure to turn heads. If you’re looking for a way to make your Samsung Galaxy phone stand out from the crowd, this Orleans House cover is the perfect solution. Featuring a unique and eye-catching design, this cover is sure to turn heads and make your device the envy of everyone around you. Show off your love for architecture and technology with this Samsung Galaxy phone cover featuring Orleans house. Make your Samsung Galaxy phone stand out from the crowd with this unique Orleans house phone cover. Keep your phone safe and secure with a touch of elegance with this Samsung Galaxy phone cover featuring Orleans house. VAN GOGH CAFE TERASSE copy.jpg A glimpse into Van Gogh’s world of vibrant cafes and bustling streets. The allure of Parisian cafe culture captured on canvas by Van Gogh. Step into the world of art and history with this stunning portrayal of a cafe by Van Gogh. Van Gogh’s signature brushstrokes bring this cafe to life with movement and energy. Experience the warmth and charm of a Parisian cafe through Van Gogh’s eyes. Table 5:Anchor prompts when ablating memorized images.We list here the captions used as anchor prompts corresponding to the target prompts which leads to the generation of memorized images. 32