Preprint Open access
LoRango: It Takes Two LoRAs to Unlock Hidden Behaviors in Diffusion Models
Users commonly combine multiple Low-Rank Adaptation (LoRA) adapters to personalize images with different subjects, styles, and visual attributes. Yet inspecting adapters individually does not establish the safety of their composition. We identify and characterize a pair-conditioned attack in text-to-image diffusion: in …