Pith. sign in

REVIEW 14 cited by

Guided Diffusion Model for Adversarial Purification

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2205.14969 v3 pith:GO3DDWLK submitted 2022-05-30 cs.CV cs.AI

classification cs.CVcs.AI
keywords adversarialdiffusiongdmppurificationattacksclassifiersguidedmodel
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

With wider application of deep neural networks (DNNs) in various algorithms and frameworks, security threats have become one of the concerns. Adversarial attacks disturb DNN-based image classifiers, in which attackers can intentionally add imperceptible adversarial perturbations on input images to fool the classifiers. In this paper, we propose a novel purification approach, referred to as guided diffusion model for purification (GDMP), to help protect classifiers from adversarial attacks. The core of our approach is to embed purification into the diffusion denoising process of a Denoised Diffusion Probabilistic Model (DDPM), so that its diffusion process could submerge the adversarial perturbations with gradually added Gaussian noises, and both of these noises can be simultaneously removed following a guided denoising process. On our comprehensive experiments across various datasets, the proposed GDMP is shown to reduce the perturbations raised by adversarial attacks to a shallow range, thereby significantly improving the correctness of classification. GDMP improves the robust accuracy by 5%, obtaining 90.1% under PGD attack on the CIFAR10 dataset. Moreover, GDMP achieves 70.94% robustness on the challenging ImageNet dataset.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 14 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Demystifying Adversarial Robustness in Diffusion Models: Compression, Randomness, and Geometry

    cs.LG 2025-05 conditional novelty 7.0 of 10

    Diffusion models improve adversarial robustness mainly by compressing the input space, while the large gains reported earlier mostly come from evaluation randomness.

  2. Adaptive Diffusion Denoised Smoothing : Certified Robustness via Randomized Smoothing with Differentially Private Guided Denoising Diffusion

    cs.CV 2025-07 conditional novelty 6.0 of 10

    ADDS certifies adversarial robustness of guided denoising diffusion models by composing per-step Gaussian differential privacy budgets with a privacy filter.

  3. Active Adversarial Noise Suppression for Image Forgery Localization

    cs.CV 2025-06 conditional novelty 6.0 of 10

    A learned preprocessing module restores image forgery localization accuracy under several white-box adversarial attacks while barely changing results on clean forged images.

  4. ReconMOST: Multi-Layer Sea Temperature Reconstruction with Observations-Guided Diffusion

    cs.CV 2025-06 conditional novelty 6.0 of 10

    A guided diffusion model pre-trained on climate simulations reconstructs multi-layer global ocean temperature from sparse observations, reporting low MSE on CMIP6 and EN4 data.

  5. VideoPure: Diffusion-based Adversarial Purification for Video Recognition

    cs.CV 2025-01 conditional novelty 6.0 of 10

    VideoPure is a diffusion-based adversarial purification framework that combines temporal DDIM inversion, spatial-temporal optimization, and multi-step voting to defend video recognition models.

  6. A Generative Victim Model for Segmentation

    cs.CV 2024-12 conditional novelty 6.0 of 10

    A diffusion model's conditional and unconditional scores can be combined to generate transferable adversarial perturbations for segmentation without a segmentation victim model.

  7. IDATA: Scalable Invertible Diffusion for Unrestricted Adversarial Transfer Attack

    cs.CV 2026-08 conditional novelty 5.0 of 10

    IDATA combines an EDICT-style invertible diffusion path with wavelet low-frequency latent constraints to generate unrestricted transferable adversarial examples with reduced GPU memory.

  8. Enhancing Adversarial Robustness with Signed Distance Fields for Harmonizing Geometric Invariance and Texture

    cs.CV 2026-02 reject novelty 5.0 of 10

    A classifier trained with SDF-based shape guidance and stochastic appearance debiasing is claimed to reach 81.64% robust accuracy under AutoAttack on ImageNet, but the evaluation protocol inflates the result.

  9. NAPPure: Adversarial Purification for Robust Image Classification under Non-Additive Perturbations

    cs.CV 2025-10 conditional novelty 5.0 of 10

    By modeling the attack as a known transformation with unknown parameters, NAPPure jointly recovers the clean image and the perturbation through likelihood maximization, beating additive-only purification baselines on ...

  10. IAP: Invisible Adversarial Patch Attack through Perceptibility-Aware Localization and Perturbation Optimization

    cs.CV 2025-07 conditional novelty 5.0 of 10

    A perceptibility-aware placement step plus a color-preserving perturbation update produces targeted adversarial patches that evade both human observers and six published patch defenses while keeping attack success rates high.

  11. Towards Effective and Efficient Adversarial Defense with Diffusion Models for Robust Visual Tracking

    cs.CV 2025-05 conditional novelty 5.0 of 10

    A diffusion-based input purification module with pixel, semantic, and structural losses restores most tracking performance lost to a white-box adversarial attack, tested on three trackers.

  12. Adversarially Robust AI-Generated Image Detection for Free: An Information Theoretic Perspective

    cs.CV 2025-05 conditional novelty 5.0 of 10

    A training-free detector-side defense, TRIM, flips predictions flagged by entropy and KL-divergence thresholds, reporting large robustness gains on ProGAN, GenImage, and SDv1.4.

  13. Random Sampling for Diffusion-based Adversarial Purification

    cs.CV 2024-11 conditional novelty 5.0 of 10

    A maximally random variant of DDIM sampling, combined with guidance applied to the predicted clean image, yields a diffusion purification defense (DiffAP) that outperforms prior methods on CIFAR-10.

  14. Feature Engineering for Wireless Communications and Networking: Concepts, Methodologies, and Applications

    eess.SP 2025-07 conditional novelty 3.0 of 10

    A diffusion-based framework reconstructs attacked RSSI feature spectra in a simulated low-altitude ISAC scenario, reporting up to 87% relative SSIM improvement and a 44% average.

Pith tools