NAPPure: Adversarial Purification for Robust Image Classification under Non-Additive Perturbations

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Nan, Junjie, Li, Jianing, Chen, Wei, Zhang, Mingkun, Cheng, Xueqi
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866913175296802816
author Nan, Junjie
Li, Jianing
Chen, Wei
Zhang, Mingkun
Cheng, Xueqi
author_facet Nan, Junjie
Li, Jianing
Chen, Wei
Zhang, Mingkun
Cheng, Xueqi
contents Adversarial purification has achieved great success in combating adversarial image perturbations, which are usually assumed to be additive. However, non-additive adversarial perturbations such as blur, occlusion, and distortion are also common in the real world. Under such perturbations, existing adversarial purification methods are much less effective since they are designed to fit the additive nature. In this paper, we propose an extended adversarial purification framework named NAPPure, which can further handle non-additive perturbations. Specifically, we first establish the generation process of an adversarial image, and then disentangle the underlying clean image and perturbation parameters through likelihood maximization. Experiments on GTSRB and CIFAR-10 datasets show that NAPPure significantly boosts the robustness of image classification models against non-additive perturbations.
format Preprint
id arxiv_https___arxiv_org_abs_2510_14025
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle NAPPure: Adversarial Purification for Robust Image Classification under Non-Additive Perturbations
Nan, Junjie
Li, Jianing
Chen, Wei
Zhang, Mingkun
Cheng, Xueqi
Computer Vision and Pattern Recognition
Adversarial purification has achieved great success in combating adversarial image perturbations, which are usually assumed to be additive. However, non-additive adversarial perturbations such as blur, occlusion, and distortion are also common in the real world. Under such perturbations, existing adversarial purification methods are much less effective since they are designed to fit the additive nature. In this paper, we propose an extended adversarial purification framework named NAPPure, which can further handle non-additive perturbations. Specifically, we first establish the generation process of an adversarial image, and then disentangle the underlying clean image and perturbation parameters through likelihood maximization. Experiments on GTSRB and CIFAR-10 datasets show that NAPPure significantly boosts the robustness of image classification models against non-additive perturbations.
title NAPPure: Adversarial Purification for Robust Image Classification under Non-Additive Perturbations
topic Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2510.14025