Sample-Specific Noise Injection For Diffusion-Based Adversarial Purification

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Sun, Yuhao, Zhang, Jiacheng, Ye, Zesheng, Xiao, Chaowei, Liu, Feng
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866915795198541824
author Sun, Yuhao
Zhang, Jiacheng
Ye, Zesheng
Xiao, Chaowei
Liu, Feng
author_facet Sun, Yuhao
Zhang, Jiacheng
Ye, Zesheng
Xiao, Chaowei
Liu, Feng
contents Diffusion-based purification (DBP) methods aim to remove adversarial noise from the input sample by first injecting Gaussian noise through a forward diffusion process, and then recovering the clean example through a reverse generative process. In the above process, how much Gaussian noise is injected to the input sample is key to the success of DBP methods, which is controlled by a constant noise level $t^*$ for all samples in existing methods. In this paper, we discover that an optimal $t^*$ for each sample indeed could be different. Intuitively, the cleaner a sample is, the less the noise it should be injected, and vice versa. Motivated by this finding, we propose a new framework, called Sample-specific Score-aware Noise Injection (SSNI). Specifically, SSNI uses a pre-trained score network to estimate how much a data point deviates from the clean data distribution (i.e., score norms). Then, based on the magnitude of score norms, SSNI applies a reweighting function to adaptively adjust $t^*$ for each sample, achieving sample-specific noise injections. Empirically, incorporating our framework with existing DBP methods results in a notable improvement in both accuracy and robustness on CIFAR-10 and ImageNet-1K, highlighting the necessity to allocate distinct noise levels to different samples in DBP methods. Our code is available at: https://github.com/tmlr-group/SSNI.
format Preprint
id arxiv_https___arxiv_org_abs_2506_06027
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Sample-Specific Noise Injection For Diffusion-Based Adversarial Purification
Sun, Yuhao
Zhang, Jiacheng
Ye, Zesheng
Xiao, Chaowei
Liu, Feng
Computer Vision and Pattern Recognition
Machine Learning
Diffusion-based purification (DBP) methods aim to remove adversarial noise from the input sample by first injecting Gaussian noise through a forward diffusion process, and then recovering the clean example through a reverse generative process. In the above process, how much Gaussian noise is injected to the input sample is key to the success of DBP methods, which is controlled by a constant noise level $t^*$ for all samples in existing methods. In this paper, we discover that an optimal $t^*$ for each sample indeed could be different. Intuitively, the cleaner a sample is, the less the noise it should be injected, and vice versa. Motivated by this finding, we propose a new framework, called Sample-specific Score-aware Noise Injection (SSNI). Specifically, SSNI uses a pre-trained score network to estimate how much a data point deviates from the clean data distribution (i.e., score norms). Then, based on the magnitude of score norms, SSNI applies a reweighting function to adaptively adjust $t^*$ for each sample, achieving sample-specific noise injections. Empirically, incorporating our framework with existing DBP methods results in a notable improvement in both accuracy and robustness on CIFAR-10 and ImageNet-1K, highlighting the necessity to allocate distinct noise levels to different samples in DBP methods. Our code is available at: https://github.com/tmlr-group/SSNI.
title Sample-Specific Noise Injection For Diffusion-Based Adversarial Purification
topic Computer Vision and Pattern Recognition
Machine Learning
url https://arxiv.org/abs/2506.06027