“…Diffusion Models have attracted a lot of researchers, to propose different models (Ho, Jain, and Abbeel 2020;Ermon 2019, 2020;Karras et al 2022;Rombach et al 2022) and different applications (Xu et al 2022;Jeong et 2021; Popov et al 2021;Kim, Kim, and Yoon 2022;Kong et al 2021;Mei and Patel 2022;Ho et al 2022;Ruiz et al 2023). A lot of methods are proposed to deal with the slow sampling process (Song, Meng, and Ermon 2021;Lu et al 2022a,b;Zhao et al 2023;Karras et al 2022;) Though they achieve a huge success, they are vulnerable to backdoor attacks (Chou, Chen, and Ho 2023a;Chen, Song, and Li 2023;Chou, Chen, and Ho 2023b). To mitigate this issue, we propose the first backdoor detection and removal framework for diffusion models.…”