---
格式版本: 2
标题: "SafeCA: Safe Cross-Attention Localization and Regulation for Text-to-Video Jailbreak Defense"
原文链接: "https://arxiv.org/abs/2608.10933"
发布日期: "2026-08-11"
发布时间校准状态: "found"
发布时间需复核: "否"
发布时间来源: "rule:local:strict_original_body"
发布时间证据: "**\\[v1\\]** Tue, 11 Aug 2026 14:01:24 UTC (1,730 KB)"
发布时间校准原因: "规则确认唯一严格发布时间，来源 local:strict_original_body"
发布时间校准置信度: "high"
发布时间候选数量: 18
发布时间严格候选数量: 6
发布时间原页读取状态: "source template page reused from URL open"
发布时间未找到原因: ""
发布时间校准时间: "2026-08-12T11:15:16+08:00"
发布时间仲裁状态: "skipped"
发布时间仲裁尝试次数: 0
发布时间仲裁耗时毫秒: 0
发现时间: "2026-08-12T11:13:54+08:00"
入库时间: "2026-08-12T03:15:16.973Z"
来源平台: "arXiv 学术论文搜索"
搜索渠道: "source_template"
搜索词: "https://arxiv.org/search/?query=deployment&searchtype=all"
匹配关键词:
  - "deployment"
  - "latency"
相关厂家:
  []
相关专家:
  []
内容类型: "网页"
抓取工具: "Free Fetch + Defuddle"
清洗工具: "Defuddle Markdown + Defuddle/Readability 正文提取"
原始附件:
  []
AI优质: "否"
AI打分: 0
AI分档: "非优质"
AI质检状态: "不通过"
AI打分理由: "内容为arXiv学术论文，关于Text-to-Video的防御机制，与超节点/AI Rack/机柜级AI基础设施完全无关。"
AI质检模型: "ali-deepseek-v4-flash"
AI质检时间: "2026-08-12T11:15:26+08:00"
AI主题相关性: 0
AI来源权威性: 0
AI新颖性: 0
AI技术细节: 0
AI商业部署信号: 0
AI完整性: 0
采集批次: "2026年8月12日2点04分20秒"
采集批次ID: "20260812-020420-289"
去重键: "https://arxiv.org/abs/2608.10933"
---

## Computer Science > Computer Vision and Pattern Recognition

## Title:SafeCA: Safe Cross-Attention Localization and Regulation for Text-to-Video Jailbreak Defense

Authors:[Siyuan Liang](https://arxiv.org/search/cs?searchtype=author&query=Liang,+S), [Yupeng Qiu](https://arxiv.org/search/cs?searchtype=author&query=Qiu,+Y), [Junfeng Fang](https://arxiv.org/search/cs?searchtype=author&query=Fang,+J), [Rong-Cheng Tu](https://arxiv.org/search/cs?searchtype=author&query=Tu,+R), [Jiaxing Huang](https://arxiv.org/search/cs?searchtype=author&query=Huang,+J), [Dacheng Tao](https://arxiv.org/search/cs?searchtype=author&query=Tao,+D)

[View PDF](https://arxiv.org/pdf/2608.10933) [HTML (experimental)](https://arxiv.org/html/2608.10933v1)

> Abstract:Text-to-Video (T2V) generative models are vulnerable to jailbreak attacks in real-world deployment, leading them to produce harmful or inappropriate content. Existing defense approaches mainly rely on input filtering or reconstruction, which not only incur high computational latency but also tend to distort semantics. To address these issues, we experimentally and systematically analyze the differences between clean and jailbreak samples in the cross-attention feature space, revealing for the first time a cumulative separation effect and a progressively increasing trend of linear separability between the two during the diffusion process. Based on this insight, we propose SafeCA, a feature-level defense mechanism for safe cross-attention localization and regularization. Firstly, we identify key defensive regions and values through attention stability analysis using cross-attention features collected from clean prompts within a single inference. Secondly, SafeCA mitigates anomalous activations via attention masking with energy normalization and introduces a lightweight semantic-space adapter to redirect abnormal semantic flows. Furthermore, we detect and suppress potentially malicious tokens by back-propagating feature anomaly signals to the input cue words, thereby enhancing the deployability of the defense in commercial models. Experimental results show that SafeCA reduces the jailbreak success rate by about 20% on mainstream T2V models, adds almost no inference overhead (+0.1s), and maintains good text-video semantic consistency. Overall, SafeCA provides an architecture-level, deployable protection paradigm for T2V generation models.

| Comments: |  |
| --- | --- |
| Subjects: | Computer Vision and Pattern Recognition (cs.CV) |
| Cite as: | [arXiv:2608.10933](https://arxiv.org/abs/2608.10933) \[cs.CV\] |
|  | (or [arXiv:2608.10933v1](https://arxiv.org/abs/2608.10933v1) \[cs.CV\] for this version) |
|  | [https://doi.org/10.48550/arXiv.2608.10933](https://doi.org/10.48550/arXiv.2608.10933) |

## Submission history

From: Siyuan Liang \[[view email](https://arxiv.org/show-email/0db33b5e/2608.10933)\]  
**\[v1\]** Tue, 11 Aug 2026 14:01:24 UTC (1,730 KB)

[Which authors of this paper are endorsers?](https://arxiv.org/auth/show-endorsers/2608.10933) | Disable MathJax ([What is MathJax?](https://info.arxiv.org/help/mathjax.html))
