Divide and Conquer: Heterogeneous Noise Integration for Diffusion-based Adversarial Purification

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Pei, Gaozheng, Lyu, Shaojie, Chen, Gong, Ma, Ke, Xu, Qianqian, Sun, Yingfei, Huang, Qingming
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866913753239388160
author Pei, Gaozheng
Lyu, Shaojie
Chen, Gong
Ma, Ke
Xu, Qianqian
Sun, Yingfei
Huang, Qingming
author_facet Pei, Gaozheng
Lyu, Shaojie
Chen, Gong
Ma, Ke
Xu, Qianqian
Sun, Yingfei
Huang, Qingming
contents Existing diffusion-based purification methods aim to disrupt adversarial perturbations by introducing a certain amount of noise through a forward diffusion process, followed by a reverse process to recover clean examples. However, this approach is fundamentally flawed: the uniform operation of the forward process across all pixels compromises normal pixels while attempting to combat adversarial perturbations, resulting in the target model producing incorrect predictions. Simply relying on low-intensity noise is insufficient for effective defense. To address this critical issue, we implement a heterogeneous purification strategy grounded in the interpretability of neural networks. Our method decisively applies higher-intensity noise to specific pixels that the target model focuses on while the remaining pixels are subjected to only low-intensity noise. This requirement motivates us to redesign the sampling process of the diffusion model, allowing for the effective removal of varying noise levels. Furthermore, to evaluate our method against strong adaptative attack, our proposed method sharply reduces time cost and memory usage through a single-step resampling. The empirical evidence from extensive experiments across three datasets demonstrates that our method outperforms most current adversarial training and purification techniques by a substantial margin.
format Preprint
id arxiv_https___arxiv_org_abs_2503_01407
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Divide and Conquer: Heterogeneous Noise Integration for Diffusion-based Adversarial Purification
Pei, Gaozheng
Lyu, Shaojie
Chen, Gong
Ma, Ke
Xu, Qianqian
Sun, Yingfei
Huang, Qingming
Computer Vision and Pattern Recognition
Artificial Intelligence
Existing diffusion-based purification methods aim to disrupt adversarial perturbations by introducing a certain amount of noise through a forward diffusion process, followed by a reverse process to recover clean examples. However, this approach is fundamentally flawed: the uniform operation of the forward process across all pixels compromises normal pixels while attempting to combat adversarial perturbations, resulting in the target model producing incorrect predictions. Simply relying on low-intensity noise is insufficient for effective defense. To address this critical issue, we implement a heterogeneous purification strategy grounded in the interpretability of neural networks. Our method decisively applies higher-intensity noise to specific pixels that the target model focuses on while the remaining pixels are subjected to only low-intensity noise. This requirement motivates us to redesign the sampling process of the diffusion model, allowing for the effective removal of varying noise levels. Furthermore, to evaluate our method against strong adaptative attack, our proposed method sharply reduces time cost and memory usage through a single-step resampling. The empirical evidence from extensive experiments across three datasets demonstrates that our method outperforms most current adversarial training and purification techniques by a substantial margin.
title Divide and Conquer: Heterogeneous Noise Integration for Diffusion-based Adversarial Purification
topic Computer Vision and Pattern Recognition
Artificial Intelligence
url https://arxiv.org/abs/2503.01407