AIIC AI Intelligence Centre

SOURCE-LINKED INTELLIGENCE

LoRango: It Takes Two LoRAs to Unlock Hidden Behaviors in Diffusion Models

arXiv · AI, language, vision and robotics · article · Sep 22, 2026 · UTC

Users commonly combine multiple Low-Rank Adaptation (LoRA) adapters to personalize images with different subjects, styles, and visual attributes. Yet inspecting adapters individually does not establish the safety of their composition. We identify and characterize a pair-conditioned attack in text-to-image diffusion: individually useful and benign-appearing adapters redirect image generation when co-loaded with a specifically matched partner, whose identity serves as the trigger. We introduce LoRango to realize this attack through complementary Signature and Payload adapters. The Signature writ

Read original source ↗ Open in workspace

recordType
paper
region
Global

Evidence & attribution

First collected: 2026-09-23T04:21:13.910Z. This is not the publication date.