NAPPure: Adversarial Purification for Robust Image Classification under Non-Additive Perturbations
Fuente:
arXiv
Saved in:
| Main Authors: | , , , , |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
| _version_ | 1866913175296802816 |
|---|---|
| author | Nan, Junjie Li, Jianing Chen, Wei Zhang, Mingkun Cheng, Xueqi |
| author_facet | Nan, Junjie Li, Jianing Chen, Wei Zhang, Mingkun Cheng, Xueqi |
| contents | Adversarial purification has achieved great success in combating adversarial image perturbations, which are usually assumed to be additive. However, non-additive adversarial perturbations such as blur, occlusion, and distortion are also common in the real world. Under such perturbations, existing adversarial purification methods are much less effective since they are designed to fit the additive nature. In this paper, we propose an extended adversarial purification framework named NAPPure, which can further handle non-additive perturbations. Specifically, we first establish the generation process of an adversarial image, and then disentangle the underlying clean image and perturbation parameters through likelihood maximization. Experiments on GTSRB and CIFAR-10 datasets show that NAPPure significantly boosts the robustness of image classification models against non-additive perturbations. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2510_14025 |
| institution | arXiv |
| publishDate | 2025 |
| record_format | arxiv |
| spellingShingle | NAPPure: Adversarial Purification for Robust Image Classification under Non-Additive Perturbations Nan, Junjie Li, Jianing Chen, Wei Zhang, Mingkun Cheng, Xueqi Computer Vision and Pattern Recognition Adversarial purification has achieved great success in combating adversarial image perturbations, which are usually assumed to be additive. However, non-additive adversarial perturbations such as blur, occlusion, and distortion are also common in the real world. Under such perturbations, existing adversarial purification methods are much less effective since they are designed to fit the additive nature. In this paper, we propose an extended adversarial purification framework named NAPPure, which can further handle non-additive perturbations. Specifically, we first establish the generation process of an adversarial image, and then disentangle the underlying clean image and perturbation parameters through likelihood maximization. Experiments on GTSRB and CIFAR-10 datasets show that NAPPure significantly boosts the robustness of image classification models against non-additive perturbations. |
| title | NAPPure: Adversarial Purification for Robust Image Classification under Non-Additive Perturbations |
| topic | Computer Vision and Pattern Recognition |
| url | https://arxiv.org/abs/2510.14025 |