Real-world Adversarial Defense against Patch Attacks based on Diffusion Model

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Wei, Xingxing, Kang, Caixin, Dong, Yinpeng, Wang, Zhengyi, Ruan, Shouwei, Chen, Yubo, Su, Hang
Format: Preprint
Veröffentlicht: 2024
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866914949364711424
author Wei, Xingxing
Kang, Caixin
Dong, Yinpeng
Wang, Zhengyi
Ruan, Shouwei
Chen, Yubo
Su, Hang
author_facet Wei, Xingxing
Kang, Caixin
Dong, Yinpeng
Wang, Zhengyi
Ruan, Shouwei
Chen, Yubo
Su, Hang
contents Adversarial patches present significant challenges to the robustness of deep learning models, making the development of effective defenses become critical for real-world applications. This paper introduces DIFFender, a novel DIFfusion-based DeFender framework that leverages the power of a text-guided diffusion model to counter adversarial patch attacks. At the core of our approach is the discovery of the Adversarial Anomaly Perception (AAP) phenomenon, which enables the diffusion model to accurately detect and locate adversarial patches by analyzing distributional anomalies. DIFFender seamlessly integrates the tasks of patch localization and restoration within a unified diffusion model framework, enhancing defense efficacy through their close interaction. Additionally, DIFFender employs an efficient few-shot prompt-tuning algorithm, facilitating the adaptation of the pre-trained diffusion model to defense tasks without the need for extensive retraining. Our comprehensive evaluation, covering image classification and face recognition tasks, as well as real-world scenarios, demonstrates DIFFender's robust performance against adversarial attacks. The framework's versatility and generalizability across various settings, classifiers, and attack methodologies mark a significant advancement in adversarial patch defense strategies. Except for the popular visible domain, we have identified another advantage of DIFFender: its capability to easily expand into the infrared domain. Consequently, we demonstrate the good flexibility of DIFFender, which can defend against both infrared and visible adversarial patch attacks alternatively using a universal defense framework.
format Preprint
id arxiv_https___arxiv_org_abs_2409_09406
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Real-world Adversarial Defense against Patch Attacks based on Diffusion Model
Wei, Xingxing
Kang, Caixin
Dong, Yinpeng
Wang, Zhengyi
Ruan, Shouwei
Chen, Yubo
Su, Hang
Computer Vision and Pattern Recognition
Artificial Intelligence
Cryptography and Security
Machine Learning
Adversarial patches present significant challenges to the robustness of deep learning models, making the development of effective defenses become critical for real-world applications. This paper introduces DIFFender, a novel DIFfusion-based DeFender framework that leverages the power of a text-guided diffusion model to counter adversarial patch attacks. At the core of our approach is the discovery of the Adversarial Anomaly Perception (AAP) phenomenon, which enables the diffusion model to accurately detect and locate adversarial patches by analyzing distributional anomalies. DIFFender seamlessly integrates the tasks of patch localization and restoration within a unified diffusion model framework, enhancing defense efficacy through their close interaction. Additionally, DIFFender employs an efficient few-shot prompt-tuning algorithm, facilitating the adaptation of the pre-trained diffusion model to defense tasks without the need for extensive retraining. Our comprehensive evaluation, covering image classification and face recognition tasks, as well as real-world scenarios, demonstrates DIFFender's robust performance against adversarial attacks. The framework's versatility and generalizability across various settings, classifiers, and attack methodologies mark a significant advancement in adversarial patch defense strategies. Except for the popular visible domain, we have identified another advantage of DIFFender: its capability to easily expand into the infrared domain. Consequently, we demonstrate the good flexibility of DIFFender, which can defend against both infrared and visible adversarial patch attacks alternatively using a universal defense framework.
title Real-world Adversarial Defense against Patch Attacks based on Diffusion Model
topic Computer Vision and Pattern Recognition
Artificial Intelligence
Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2409.09406