🤖 AI Summary
This work addresses the challenge that existing concept erasure methods struggle to simultaneously achieve robust erasure and high-fidelity generation of non-target concepts. To this end, the authors propose PARSE, a training-free framework that performs preservation-aware concept erasure in the cross-attention value space. Its key innovations include classifier-free guidance–based dynamic token-level concept discovery, preservation-aware subspace projection, adaptive subspace expansion, and textual inversion trigger search. The paper also introduces BEUS, a comprehensive evaluation metric that balances attack success rate against generation quality. Experiments demonstrate that PARSE significantly outperforms current approaches on NSFW, artistic style, and object erasure tasks, achieving robust multi-concept removal while preserving high-fidelity image generation.
📝 Abstract
Concept erasure techniques (CETs) edit text-to-image diffusion models to erase undesired targets such as NSFW content or copyrighted styles, while preserving model utility on benign concepts. Current CETs face a trade-off between erasure robustness and utility: stronger edits erase the target more reliably but degrade utility on non-target concepts, and vice versa. This stems from how existing methods define what to erase and what to preserve. Many CETs rely on static concept banks specified manually, generated by LLMs, or selected by CLIP image-text similarity. Such banks do not model how prompts steer the model during denoising, leaving it vulnerable to triggers that reintroduce the target while suppressing nearby benign concepts. We present Preservation-aware Adaptive Ranked Subspace Expansion (PARSE), a training-free framework for robust concept erasure in latent diffusion models. Given a target, PARSE queries the diffusion model with classifier-free guidance to dynamically discover target-inducing erase concepts and nearby retain concepts in the model vocabulary. It then edits the cross-attention value space with a preservation-aware projection that removes target directions while leaving retain directions intact. For triggers beyond this vocabulary-indexed space, PARSE iteratively searches for re-emergence triggers by textual inversion and adaptively expands the erased subspace only when a new trigger direction does not conflict with retain semantics. We also introduce the Balanced Erasure Utility Score (BEUS), which combines robustness (ASR under multiple attacks) and utility preservation (FID) via bounded monotone transforms and harmonic mean aggregation. Experiments on NSFW, artistic style, and object erasure, with a large-scale robustness-utility analysis over many CET baselines, show that PARSE erases multiple concepts robustly without sacrificing post-edit utility.