Pith. sign in

Paper Citation Record · LEDGER

How Do Diffusion Models Improve Adversarial Robustness?

As of 8 August 2026, this Paper Citation Record lists 27 of 27 outbound references and 0 inbound Pith citation observations for arXiv:2505.22839.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2505.22839 v1

Coverage vector

measured 27 of 27 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-07T13:05:49.835754Z

measured 27 of 27 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-08T06:32:00.761636+00:00

measured 0 of 0 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: cited_works

Reference resolution

27 of 27 outbound references displayed

  • verified exact3
  • verified fuzzy7
  • unresolved16
  • parse uncertain0
  • malformed identifier1
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation a65184a9-63b5-4aed-aa85-b411c6ed2c08 · outbound

This paper cites E Broader impact This paper discusses how and how well do diffusion models actually improve robustness.

How Do Diffusion Models Improve Adversarial Robustness? E Broader impact This paper discusses how and how well do diffusion models actually improve robustness

Reference 1

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T13:05:50.779822Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T13:05:49.835754Z digest=sha256:707eb360c5e81bce463a8ad6ba1c09326e44e02d687c29a990be7050e84f3e52

Observation c1e1c128-f1f0-47e0-9576-6be5b4c64118 · outbound

This paper cites We used the base seeds s= 0,1,2for all experiments.

How Do Diffusion Models Improve Adversarial Robustness? We used the base seeds s= 0,1,2for all experiments

Reference 3

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T13:05:51.209670Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T13:05:49.615077Z digest=sha256:9acb8b66c1db20a1f0e42515ede4ef5ced218720f7dc5acb09d8ca073960a0e3

Observation 662edc6f-6e09-43a0-b23e-eba03b76f400 · outbound

This paper cites Adversarial Examples Are a Natural Consequence of Test Error in Noise.

How Do Diffusion Models Improve Adversarial Robustness? Adversarial Examples Are a Natural Consequence of Test Error in Noise

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-07T13:05:47.917506Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T13:05:47.917506Z digest=sha256:5032b6e65a2923742028408beba959e69f05a47360c2db03a04533bdb12c879f

Observation 340b57ae-6be9-4cc3-a6eb-9d8bda223f9d · outbound

This paper cites an unresolved cited work.

How Do Diffusion Models Improve Adversarial Robustness? Unresolved cited work

Reference 7

Resolution
unresolved
raw_fallback, observed 2026-08-07T13:05:52.090905Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T13:05:49.072162Z digest=sha256:0a8da53a8ad459eaf784e09b7855f5732a72ea595518b5449387b22517004496

Observation 76e0d470-a0c8-4cd6-b151-4cc20488f5ec · outbound

This paper cites Adversarial Guided Diffusion Models for Adversarial Purification.

How Do Diffusion Models Improve Adversarial Robustness? Adversarial Guided Diffusion Models for Adversarial Purification

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-07T13:05:48.191182Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T13:05:48.191182Z digest=sha256:21230b36281745ececf191688dc49caecc082505e185bf52fc4443a22aa9cfd6

Observation 6ab935a2-e028-458f-8c0f-91769939379f · outbound

This paper cites Practical black-box attacks against machine learning.

How Do Diffusion Models Improve Adversarial Robustness? Practical black-box attacks against machine learning

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-07T13:05:48.332038Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T13:05:48.332038Z digest=sha256:5268f48338a5643380db8efc629bfca7436f738f8c353cb8d13e66be3bb8c79e

Observation 59c554c1-9003-4baa-a7b7-3538b7bdddc5 · outbound

This paper cites URL https://doi.org/10.21105/joss.02607.

How Do Diffusion Models Improve Adversarial Robustness? URL https://doi.org/10.21105/joss.02607

Reference 11

Resolution
verified exact
doi, observed 2026-08-07T13:05:50.065493Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T13:05:48.451372Z digest=sha256:424013f832cc76520c9a85407d39c4bfd6da50791a5d71ea2a1fb9b6682931d2

Observation 508fa389-d736-4d51-9527-7291982e1dbc · outbound

This paper cites Towards the first adversarially robust neural network model on MNIST.

How Do Diffusion Models Improve Adversarial Robustness? Towards the first adversarially robust neural network model on MNIST

Reference 12

Resolution
verified exact
local_arxiv, observed 2026-08-07T13:05:50.285016Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T13:05:48.535480Z digest=sha256:3cb4d9e25a92f9e4f3ff67445665d07edec55b1e8b253e93b0dfb7eb4410c43e

Observation 6d5393ef-c7b2-42ad-9cec-11b04a68f7df · outbound

This paper cites Online Adversarial Purification based on Self-Supervision.

How Do Diffusion Models Improve Adversarial Robustness? Online Adversarial Purification based on Self-Supervision

Reference 13

Resolution
unresolved
no resolver link, observed 2026-08-07T13:05:48.637283Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T13:05:48.637283Z digest=sha256:f583760275c2326722b280957ac3c22e5aee6fc293e12c029d5f99285cf46e9e

Observation 31ba7a28-d5ad-4533-8fbe-fa6a070fb078 · outbound

This paper cites Guided Diffusion Model for Adversarial Purification.

How Do Diffusion Models Improve Adversarial Robustness? Guided Diffusion Model for Adversarial Purification

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-07T13:05:48.821582Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T13:05:48.821582Z digest=sha256:1d306783c933c985d9cd43234a6c8331ba91ab94cb354bafe5730979a80e4074

Observation 3433a069-c3c2-42d3-a1fb-9a33bb1b0019 · outbound

This paper cites On the Convergence and Robustness of Adversarial Training.

How Do Diffusion Models Improve Adversarial Robustness? On the Convergence and Robustness of Adversarial Training

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-07T13:05:48.888250Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T13:05:48.888250Z digest=sha256:2e13fcc2016232d35652b6f006f80ee857e01709bc439e466dab5db46fd908b1

Observation e0f2fbc8-4376-4eb8-b10f-42cdc559f27e · outbound

This paper cites Densepure: Understanding diffusion models for adversarial robustness.

How Do Diffusion Models Improve Adversarial Robustness? Densepure: Understanding diffusion models for adversarial robustness

Reference 17

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T13:05:52.225096Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T13:05:48.994634Z digest=sha256:4f64194f0ff3bfc69b29dc76732f6ce698494258bdb5e7a311e58339e65458ea

Observation 4c2d4804-dd46-41fb-96ab-78b8bf40d508 · outbound

This paper cites The purification time steps were kept the same with Nie et al.

How Do Diffusion Models Improve Adversarial Robustness? The purification time steps were kept the same with Nie et al

Reference 20

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T13:05:51.807574Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T13:05:49.286425Z digest=sha256:40cc35ce8cfbf4111bbffceaa0219780e3b1c44ac3ea0cd39294c0e1adf45088

Observation 4fb99a8c-abf7-4ce5-b59f-ff392cbc67b2 · outbound

This paper cites an unresolved cited work.

How Do Diffusion Models Improve Adversarial Robustness? Unresolved cited work

Reference 21

Resolution
unresolved
raw_fallback, observed 2026-08-07T13:05:51.671818Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T13:05:49.351144Z digest=sha256:36b9d31449076a71863a67d1a4cec8df219fdf1a012c5b68bd764c59fa4149cd

Observation 0223aeba-e2b6-4928-9d00-3289ac05eafa · outbound

This paper cites Full gradients were calculated for the PGD/PGD-EOT as Lee & Kim (2023) discovered that the approximations methods used in the original DiffPure (Nie et al.,.

How Do Diffusion Models Improve Adversarial Robustness? Full gradients were calculated for the PGD/PGD-EOT as Lee & Kim (2023) discovered that the approximations methods used in the original DiffPure (Nie et al.,

Reference 22

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T13:05:51.506209Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T13:05:49.417813Z digest=sha256:f197a6ae9f127cefca7933a02bd6d2fd9d697686a1768d9f1ac017ec1f7d6344

Observation 39ab9538-458c-46a8-b497-3531d1c49014 · outbound

This paper cites The full gradient of PGD/PGD-EOT is the strongest attack for DiffPure methods according to Lee & Kim (2023) experiments, and is very computationally expensive.

How Do Diffusion Models Improve Adversarial Robustness? The full gradient of PGD/PGD-EOT is the strongest attack for DiffPure methods according to Lee & Kim (2023) experiments, and is very computationally expensive

Reference 23

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T13:05:51.370049Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T13:05:49.513361Z digest=sha256:6125e34f2124c88113cbdd9b01d6109fff6975ec4644dd412036d32124569f72

Observation 6e8ad9e6-4276-4c8d-ab94-f7e921967de0 · outbound

This paper cites an unresolved cited work.

How Do Diffusion Models Improve Adversarial Robustness? Unresolved cited work

Reference 26

Resolution
unresolved
raw_fallback, observed 2026-08-07T13:05:50.890289Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T13:05:49.739700Z digest=sha256:b14924368ba17a35dc8c07405163d6ad48b66231872e8e0fc1fc49a41af8d97a

Observation 12251674-1921-415f-9590-6a0c070b1129 · outbound

This paper cites pushing-away.

How Do Diffusion Models Improve Adversarial Robustness? pushing-away

Reference 300

Resolution
malformed identifier
raw_fallback, observed 2026-08-07T13:05:51.061526Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T13:05:49.691225Z digest=sha256:595e70b6165e6b4e9b398a003bb7c8c57687160e5134c0aaeb28565364d45b98

Observation 055c613a-588c-48f3-ba06-c104483562e0 · outbound

This paper cites For CIFAR-10, we subsampled the first 1000 images from the test set.

How Do Diffusion Models Improve Adversarial Robustness? For CIFAR-10, we subsampled the first 1000 images from the test set

Reference 2009

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T13:05:51.946105Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T13:05:49.179143Z digest=sha256:e26c8b7d07c59261a73cd95a054cd5bbd088ae68ac01e9b0356cd6b14fca8f44

Observation cbc81c76-1f92-41da-815a-04778cd9b6e4 · outbound

This paper cites Towards Deep Neural Network Architectures Robust to Adversarial Examples.

How Do Diffusion Models Improve Adversarial Robustness? Towards Deep Neural Network Architectures Robust to Adversarial Examples

Reference 2014

Resolution
unresolved
no resolver link, observed 2026-08-07T13:05:48.074464Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T13:05:48.074464Z digest=sha256:c87c7db8f8582a7837fb562a8dcdd7eb053d73db0cc19d22a9d0df7a1633e5b3

Observation 781d85f6-e870-48ba-ad68-031a0b892e95 · outbound

This paper cites On Evaluating Adversarial Robustness.

How Do Diffusion Models Improve Adversarial Robustness? On Evaluating Adversarial Robustness

Reference 2018

Resolution
unresolved
no resolver link, observed 2026-08-07T13:05:47.647321Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T13:05:47.647321Z digest=sha256:43ef9448881af25654a129a2217d559813a814d27559f60554c5b183fd8c058e

Observation ef67f529-d726-42b8-b369-9095209760a9 · outbound

This paper cites (Certified!!) Adversarial Robustness for Free!.

How Do Diffusion Models Improve Adversarial Robustness? (Certified!!) Adversarial Robustness for Free!

Reference 2019

Resolution
unresolved
no resolver link, observed 2026-08-07T13:05:47.704319Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T13:05:47.704319Z digest=sha256:904637ffc639963b1579467bd07997c21575026046619f401e1e68d5f3711a50

Observation 696eda56-d550-4301-8ca4-50cfc21805d7 · outbound

This paper cites RobustBench: a standardized adversarial robustness benchmark.

How Do Diffusion Models Improve Adversarial Robustness? RobustBench: a standardized adversarial robustness benchmark

Reference 2020

Resolution
unresolved
no resolver link, observed 2026-08-07T13:05:47.796644Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T13:05:47.796644Z digest=sha256:e669c65bd0c3acd595a458af560604a9ede476748518b3d1ed470a11e38bf978

Observation 88b6d9d5-b578-48d4-b0e8-54d28cc639d7 · outbound

This paper cites advertorch v0.1: An Adversarial Robustness Toolbox based on PyTorch.

How Do Diffusion Models Improve Adversarial Robustness? advertorch v0.1: An Adversarial Robustness Toolbox based on PyTorch

Reference 2021

Resolution
verified exact
local_arxiv, observed 2026-08-07T13:05:50.544098Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T13:05:47.841976Z digest=sha256:390b2a294b0ff047ff8866f3552e858e848a94274c8d4933174943fe0ab3e99d

Observation 092a2c8a-a5df-415a-bdf4-a30fb6979187 · outbound

This paper cites Explaining and Harnessing Adversarial Examples.

How Do Diffusion Models Improve Adversarial Robustness? Explaining and Harnessing Adversarial Examples

Reference 2022

Resolution
unresolved
no resolver link, observed 2026-08-07T13:05:47.994463Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T13:05:47.994463Z digest=sha256:df49006a24106572c7c662d3704abf60f285bbea70b6d405492cbdb51193e3e6

Observation b1325ff7-761d-4dbf-897f-743c67ecc851 · outbound

This paper cites Intriguing properties of neural networks.

How Do Diffusion Models Improve Adversarial Robustness? Intriguing properties of neural networks

Reference 2023

Resolution
unresolved
no resolver link, observed 2026-08-07T13:05:48.716460Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T13:05:48.716460Z digest=sha256:a7aca3b9686df7f50f5e4188a8f268b7db06bfc9891c3e340ee2dbeebed98d36

Observation c8bd2abb-4702-40f8-b536-821bab1adafb · outbound

This paper cites Towards Deep Learning Models Resistant to Adversarial Attacks.

How Do Diffusion Models Improve Adversarial Robustness? Towards Deep Learning Models Resistant to Adversarial Attacks

Reference 2024

Resolution
unresolved
no resolver link, observed 2026-08-07T13:05:48.253219Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T13:05:48.253219Z digest=sha256:0133c2298f3db3f8bc8052535823faf92d96ac40502c1fa2a96a52cd8e026438

Pith citing papers

No inbound Pith citation observations are available.