English

SPQR: A Standardized Benchmark for Modern Safety Alignment Methods in Text-to-Image Diffusion Models

Cryptography and Security 2025-11-26 v1 Artificial Intelligence Computer Vision and Pattern Recognition Machine Learning

Abstract

Text-to-image diffusion models can emit copyrighted, unsafe, or private content. Safety alignment aims to suppress specific concepts, yet evaluations seldom test whether safety persists under benign downstream fine-tuning routinely applied after deployment (e.g., LoRA personalization, style/domain adapters). We study the stability of current safety methods under benign fine-tuning and observe frequent breakdowns. As true safety alignment must withstand even benign post-deployment adaptations, we introduce the SPQR benchmark (Safety-Prompt adherence-Quality-Robustness). SPQR is a single-scored metric that provides a standardized and reproducible framework to evaluate how well safety-aligned diffusion models preserve safety, utility, and robustness under benign fine-tuning, by reporting a single leaderboard score to facilitate comparisons. We conduct multilingual, domain-specific, and out-of-distribution analyses, along with category-wise breakdowns, to identify when safety alignment fails after benign fine-tuning, ultimately showcasing SPQR as a concise yet comprehensive benchmark for T2I safety alignment techniques for T2I models.

Keywords

Cite

@article{arxiv.2511.19558,
  title  = {SPQR: A Standardized Benchmark for Modern Safety Alignment Methods in Text-to-Image Diffusion Models},
  author = {Mohammed Talha Alam and Nada Saadi and Fahad Shamshad and Nils Lukas and Karthik Nandakumar and Fahkri Karray and Samuele Poppi},
  journal= {arXiv preprint arXiv:2511.19558},
  year   = {2025}
}

Comments

20 pages, 8 figures, 10 tables

R2 v1 2026-07-01T07:52:56.224Z