Beyond Classification: Evaluating Diffusion Denoised Smoothing for Security-Utility Trade off

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Belousov, Yury, Pulfer, Brian, Kinakh, Vitaliy, Voloshynovskiy, Slava
Formato: Preprint
Publicado: 2025
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866918029172932608
author Belousov, Yury
Pulfer, Brian
Kinakh, Vitaliy
Voloshynovskiy, Slava
author_facet Belousov, Yury
Pulfer, Brian
Kinakh, Vitaliy
Voloshynovskiy, Slava
contents While foundation models demonstrate impressive performance across various tasks, they remain vulnerable to adversarial inputs. Current research explores various approaches to enhance model robustness, with Diffusion Denoised Smoothing emerging as a particularly promising technique. This method employs a pretrained diffusion model to preprocess inputs before model inference. Yet, its effectiveness remains largely unexplored beyond classification. We aim to address this gap by analyzing three datasets with four distinct downstream tasks under three different adversarial attack algorithms. Our findings reveal that while foundation models maintain resilience against conventional transformations, applying high-noise diffusion denoising to clean images without any distortions significantly degrades performance by as high as 57%. Low-noise diffusion settings preserve performance but fail to provide adequate protection across all attack types. Moreover, we introduce a novel attack strategy specifically targeting the diffusion process itself, capable of circumventing defenses in the low-noise regime. Our results suggest that the trade-off between adversarial robustness and performance remains a challenge to be addressed.
format Preprint
id arxiv_https___arxiv_org_abs_2505_15594
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Beyond Classification: Evaluating Diffusion Denoised Smoothing for Security-Utility Trade off
Belousov, Yury
Pulfer, Brian
Kinakh, Vitaliy
Voloshynovskiy, Slava
Machine Learning
Artificial Intelligence
Computer Vision and Pattern Recognition
While foundation models demonstrate impressive performance across various tasks, they remain vulnerable to adversarial inputs. Current research explores various approaches to enhance model robustness, with Diffusion Denoised Smoothing emerging as a particularly promising technique. This method employs a pretrained diffusion model to preprocess inputs before model inference. Yet, its effectiveness remains largely unexplored beyond classification. We aim to address this gap by analyzing three datasets with four distinct downstream tasks under three different adversarial attack algorithms. Our findings reveal that while foundation models maintain resilience against conventional transformations, applying high-noise diffusion denoising to clean images without any distortions significantly degrades performance by as high as 57%. Low-noise diffusion settings preserve performance but fail to provide adequate protection across all attack types. Moreover, we introduce a novel attack strategy specifically targeting the diffusion process itself, capable of circumventing defenses in the low-noise regime. Our results suggest that the trade-off between adversarial robustness and performance remains a challenge to be addressed.
title Beyond Classification: Evaluating Diffusion Denoised Smoothing for Security-Utility Trade off
topic Machine Learning
Artificial Intelligence
Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2505.15594