{"slug": "disco-defending-text-to-image-generation-through-distribution-guided-contrastive", "title": "DiSCO: Defending text-to-image generation through distribution-guided contrastive prompt optimization", "summary": "Researchers propose DiSCO, a zero-shot, black-box defense for text-to-image models that reduces Not-Safe-For-Work (NSFW) content generation by 37.7% on undefended models and 25.13% on defended models under red-teaming attacks, according to a preprint on arXiv (2608.17067v1). DiSCO operates entirely at the prompt level via distribution-guided suffix expansion and contrastive scoring, requiring no model access or retraining.", "body_md": "arXiv:2608.17067v1 Announce Type: new\nAbstract: As text-to-image generative models advance, they raise critical safety concerns, particularly the generation of Not-Safe-For-Work (NSFW) content such as violence and nudity, further exacerbated by red-teaming adversarial attacks. Existing defenses predominantly operate under white-box assumptions, relying on text encoder optimization, weight editing, or inference-time intervention, and fundamentally cannot scale to proprietary models. Black-box alternatives based on LLM prompt rewriting offer broader applicability, yet fail in a critical regime we identify as the \\textit{benign adversarial} problem: prompts that are linguistically safe but still trigger harmful generation due to the model's learned data distribution. We propose DiSCO, a zero-shot, strictly black-box defense that operates entirely at the prompt level as a plug-and-play module, requiring no model retraining, fine-tuning, or access to model internals. DiSCO performs distribution-guided suffix expansion via beam search, optimized through contrastive scoring over safe and unsafe image pools generated by the target model itself, with iterative adaptive feedback until safe content is produced. We demonstrate that DiSCO consistently enhances the safety of both undefended and defended models on the I2P benchmark under multiple red-teaming attacks, achieving 37.7% and 25.13% ASR reduction, respectively, while maintaining semantic fidelity and improving image coherence. As a black-box, architecture-agnostic module, DiSCO can be readily applied to any text-to-image system without necessitating any changes to the model itself.", "url": "https://wpnews.pro/news/disco-defending-text-to-image-generation-through-distribution-guided-contrastive", "canonical_source": "https://arxiv.org/abs/2608.17067", "published_at": "2026-08-19 04:00:00+00:00", "updated_at": "2026-08-19 04:14:11.791676+00:00", "lang": "en", "topics": ["artificial-intelligence", "ai-safety", "generative-ai"], "entities": ["DiSCO", "arXiv", "I2P benchmark"], "alternates": {"html": "https://wpnews.pro/news/disco-defending-text-to-image-generation-through-distribution-guided-contrastive", "markdown": "https://wpnews.pro/news/disco-defending-text-to-image-generation-through-distribution-guided-contrastive.md", "text": "https://wpnews.pro/news/disco-defending-text-to-image-generation-through-distribution-guided-contrastive.txt", "jsonld": "https://wpnews.pro/news/disco-defending-text-to-image-generation-through-distribution-guided-contrastive.jsonld"}}