TwoHamsters: Benchmarking Multi-Concept Compositional Unsafety in Text-to-Image Models

arXiv cs.CV / 4/20/2026

💬 OpinionIdeas & Deep AnalysisModels & Research

Key Points

  • The paper identifies a new text-to-image safety vulnerability called Multi-Concept Compositional Unsafety (MCCU), where harmful meaning can emerge from implicit associations between individually benign concepts.
  • It introduces TwoHamsters, a benchmark of 17.5k prompts designed specifically to test for MCCU risks.
  • Evaluations across 10 state-of-the-art text-to-image models and 16 defense methods show that both models and defenses can fail badly under MCCU.
  • The results include FLUX reaching a 99.52% MCCU generation success rate and LLaVA-Guard showing only 41.06% recall, underscoring a major gap in existing safety approaches.
  • The study provides 8 key insights intended to guide more effective defenses for compositional, semantics-driven unsafe generation in T2I systems.

Abstract

Despite the remarkable synthesis capabilities of text-to-image (T2I) models, safeguarding them against content violations remains a persistent challenge. Existing safety alignments primarily focus on explicit malicious concepts, often overlooking the subtle yet critical risks of compositional semantics. To address this oversight, we identify and formalize a novel vulnerability: Multi-Concept Compositional Unsafety (MCCU), where unsafe semantics stem from the implicit associations of individually benign concepts. Based on this formulation, we introduce TwoHamsters, a comprehensive benchmark comprising 17.5k prompts curated to probe MCCU vulnerabilities. Through a rigorous evaluation of 10 state-of-the-art models and 16 defense mechanisms, our analysis yields 8 pivotal insights. In particular, we demonstrate that current T2I models and defense mechanisms face severe MCCU risks: on TwoHamsters, FLUX achieves an MCCU generation success rate of 99.52%, while LLaVA-Guard only attains a recall of 41.06%, highlighting a critical limitation of the current paradigm for managing hazardous compositional generation.