NTH

Safe Few-Step Generation via Velocity Editing

AuthorsYujin Choi, Jaehong Yoon

June 28, 2026 3 min read
Watch on YouTube
The one-line take

This paper introduces a training-free way to make fast text-to-image generators safer by editing their velocity trajectories, cutting down harmful outputs while keeping benign images intact.

Key results

15.2%
MeanFlow Ring-A-Bell ASR

VESFlow on the 4-step MeanFlow model

7.5%
MeanFlow MMA-Diffusion ASR

VESFlow on the 4-step MeanFlow model

6.3%
MeanFlow Ring-A-Bell ASR plus

VESFlow+ on the 4-step MeanFlow model

6.8%
MeanFlow MMA-Diffusion ASR plus

VESFlow+ on the 4-step MeanFlow model

1.3%
FLUX Ring-A-Bell ASR plus

VESFlow+ on the 8-step FLUX model

What the paper found

Safe Few-Step Generation via Velocity Editing, by Yujin Choi and Jaehong Yoon of NTU Singapore and UNIST, introduces VESFlow, a training-free safety method for flow matching text-to-image models such as FLUX and MeanFlow. Instead of steering the sampling trajectory with per-step negative guidance or editing prompt embeddings, VESFlow directly edits the model’s marginal velocity field toward a safe-conditional posterior using a Bayes-derived score term, which is especially suited to extremely few-step generation. The paper’s key insight is that few-step samplers cannot accumulate small corrections reliably, while modern T5-based text encoders make toxic concepts hard to erase in embedding space. VESFlow adds a risk score filter that skips velocity editing on benign prompts and proposes VESFlow+, a stronger contrastive variant that both attracts trajectories toward safe outputs and repels them from unsafe ones once a prompt is flagged as risky. On the 4-step MeanFlow model, the method cuts NudeNet attack success rate to 15.2% on Ring-A-Bell and 7.5% on MMA-Diffusion, and VESFlow+ lowers those further to 6.3% and 6.8%; on FLUX with 8 steps, VESFlow reduces Ring-A-Bell nudity ASR to 26.6% and VESFlow+ to 1.3%. The method preserves benign quality, with MS-COCO 10K FID and CLIP staying essentially unchanged, and it is lightweight enough that prompt-level filtering removes most added cost on safe inputs.

Original abstract

Flow matching has recently emerged as a strong paradigm for state-of-the-art text-to-image (T2I) generation, enabling high-quality generation with a small number of sampling steps. As these models are increasingly integrated into real-world applications, ensuring safe and non-sensitive content generation has become a critical requirement. However, adapting safety and concept removal methods to this new generation framework remains an open challenge. Specifically, prior methods largely rely on iterative trajectory steering across a number of denoising steps or on CLIP-centric prompt embedding manipulation. These design assumptions pose fundamental bottlenecks for safety in flow matching-based T2I generation, where limited sampling steps constrain iterative correction and modern context-aware text encoders diminish the effectiveness of embedding-level interventions. In this paper, we propose VESFlow, a training-free safety method tailored to flow matching with extremely few sampling steps. Leveraging the fact that flow matching models learn the marginal velocity, we directly edit the velocity field via a safe-conditional posterior. VESFlow steers the trajectory toward safe outputs while leaving the conditioning prompt unchanged. Building on the observation that VESFlow leaves outputs unchanged under benign prompts, we further introduce a risk score-based filtering that bypasses velocity editing to reduce computational cost while preserving benign prompt generation. Based on this filtering, we propose VESFlow+, a stronger variant of VESFlow that not only edits the velocity toward the safe direction, but also pushes it away from the unsafe direction. Experimental results show that VESFlow+ removes the target concept, reducing the attack success rate by NudeNet to 6.3% on Ring-A-Bell and 6.8% on MMA-Diffusion on the 4-step MeanFlow model, while preserving fidelity on benign prompts.

Read the original paper

More in Diffusion Models

Browse all 58 papers →
02Diffusion

LongLive-Plug: Once-for-All Distillation for Video Generation

Shuai Yang, Luozhou Wang, Wei Huang, ZhiFei Chen, Bohan Zhang, Xiao Fu, Qianli Ma, Chen-Hsuan Lin, Weian Mao, Bryan Chu, Song Han, Yukang Chen

LongLive-Plug distills key video-generation capabilities into reusable LoRA adapters that can accelerate and improve many downstream diffusion models without retraining each one.

Read analysis
03Diffusion

Simplex Diffusion Models

Justin Deschenaux, Alexandre Galashov, Andrew Campbell, Li Kevin Wenliang, James Thornton, Arnaud Doucet, Valentin De Bortoli

Simplex Diffusion Models keep uncertainty alive during discrete denoising, enabling faster and stronger generation for text, code, and math tasks.

Read analysis