Multi-level Floyd-Steinberg dithering defends DINOv2 and PaliGemma models against PGD, MI-FGSM and SIA attacks on six tasks while causing less clean-input degradation than diffusion denoising or other baselines.
Obfus- cated gradients give a false sense of security: Circumventing defenses to adversarial examples,
1 Pith paper cite this work. Polarity classification is still indexing.
1
Pith paper citing it
fields
cs.CV 1years
2026 1verdicts
UNVERDICTED 1representative citing papers
citing papers explorer
-
Dithering Defense: Adversarial Robustness of Vision Foundation Models via Multi-Level Floyd-Steinberg Dithering
Multi-level Floyd-Steinberg dithering defends DINOv2 and PaliGemma models against PGD, MI-FGSM and SIA attacks on six tasks while causing less clean-input degradation than diffusion denoising or other baselines.