{"id":29917755,"url":"https://github.com/denselance/pip-pipeline","last_synced_at":"2025-08-02T05:17:45.022Z","repository":{"id":306415959,"uuid":"1022047070","full_name":"DenseLance/PIP-Pipeline","owner":"DenseLance","description":"The Punctuation Injection Permutator (PIP) pipeline can craft an adversarial prompt automatically using an optimizer and a vision-language model (VLM) evaluator in both untargeted and targeted attack settings.","archived":false,"fork":false,"pushed_at":"2025-07-25T10:17:21.000Z","size":44795,"stargazers_count":1,"open_issues_count":0,"forks_count":0,"subscribers_count":0,"default_branch":"main","last_synced_at":"2025-07-25T16:39:50.536Z","etag":null,"topics":["adversarial-attacks","adversarial-machine-learning","diffusion-models","t2i","t2i-diffusion-model"],"latest_commit_sha":null,"homepage":"","language":"Jupyter Notebook","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/DenseLance.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null}},"created_at":"2025-07-18T11:11:32.000Z","updated_at":"2025-07-25T10:17:24.000Z","dependencies_parsed_at":"2025-07-25T16:50:01.943Z","dependency_job_id":null,"html_url":"https://github.com/DenseLance/PIP-Pipeline","commit_stats":null,"previous_names":["denselance/pip-pipeline"],"tags_count":null,"template":false,"template_full_name":null,"purl":"pkg:github/DenseLance/PIP-Pipeline","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/DenseLance%2FPIP-Pipeline","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/DenseLance%2FPIP-Pipeline/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/DenseLance%2FPIP-Pipeline/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/DenseLance%2FPIP-Pipeline/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/DenseLance","download_url":"https://codeload.github.com/DenseLance/PIP-Pipeline/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/DenseLance%2FPIP-Pipeline/sbom","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":268338610,"owners_count":24234541,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","status":"online","status_checked_at":"2025-08-02T02:00:12.353Z","response_time":74,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["adversarial-attacks","adversarial-machine-learning","diffusion-models","t2i","t2i-diffusion-model"],"created_at":"2025-08-02T05:17:40.067Z","updated_at":"2025-08-02T05:17:45.006Z","avatar_url":"https://github.com/DenseLance.png","language":"Jupyter Notebook","funding_links":[],"categories":[],"sub_categories":[],"readme":"# Is It Possible to Attack a T2I Model With Only Punctuation?\n\n## Abstract\n\nText-to-Image (T2I) models have become immensely popular due to their ability to generate high quality images from natural language prompts, but their safety and robustness in real-world applications remains a critical concern to date. In this work, we explore the use of punctuations as an attack vector on black-box T2I models. We show that it is easy to fool and mislead the victim model by simply injecting a few punctuations into the clean prompt, despite punctuations having virtually no semantic meaning. These punctuations injected could be attributed to human typographical errors, making the adversarial attack imperceptible and suitable as a real-world attack. We also propose the Punctuation Injection Permutator (PIP) pipeline which can craft the adversarial prompt automatically using an optimizer and a vision-language model (VLM) evaluator in both untargeted and targeted attack settings.\n\n## How to Use\n\nUse the Jupyter notebooks (.ipynb) with the prefix `[PIPELINE]` in the main directory. You can then modify the file according to your needs.\n\nOur evaluation results can be found in the `eval` directory.\n\n## Report and Citations\n\nTechnical details of the project are described in `Is It Possible to Attack a T2I Model With Only Punctuation.pdf` in the main directory.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fdenselance%2Fpip-pipeline","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fdenselance%2Fpip-pipeline","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fdenselance%2Fpip-pipeline/lists"}