Guided Diffusion Model for Adversarial Purification from Random Noise
arXiv:2206.10875
Abstract
In this paper, we propose a novel guided diffusion purification approach to provide a strong defense against adversarial attacks. Our model achieves 89.62% robust accuracy under PGD-L_inf attack (eps = 8/255) on the CIFAR-10 dataset. We first explore the essential correlations between unguided diffusion models and randomized smoothing, enabling us to apply the models to certified robustness. The empirical results show that our models outperform randomized smoothing by 5% when the certified L2 radius r is larger than 0.5.
Cited by in corpus (4)
- How Deep Learning Sees the World: A Survey on Adversarial Attacks & Defenses
- Time Series Diffusion Method: A Denoising Diffusion Probabilistic Model for Vibration Signal Generation
- DiffDefense: Defending against Adversarial Attacks via Diffusion Models
- Iterative Window Mean Filter: Thwarting Diffusion-based Adversarial Purification