In this paper, we propose a diffusion-based adversarial purification method aimed at enhancing robustness against adversarial examples while minimizing inference time. Conventional diffusion-based methods rely on multiple iterations for noise removal, which increases computational cost. To address this, we introduce two stochastic components – random flip and random purification – to maintain robustness while reducing the number of denoising steps. Experimental results demonstrate that our method achieves comparable or better classification accuracy for normal images and adversarial examples generated by AutoAttack, while significantly reducing the number of steps in denoising process.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Diffusion-Based Immediate Adversarial Purification

  • Yuito Narisawa,
  • Motonobu Hattori

摘要

In this paper, we propose a diffusion-based adversarial purification method aimed at enhancing robustness against adversarial examples while minimizing inference time. Conventional diffusion-based methods rely on multiple iterations for noise removal, which increases computational cost. To address this, we introduce two stochastic components – random flip and random purification – to maintain robustness while reducing the number of denoising steps. Experimental results demonstrate that our method achieves comparable or better classification accuracy for normal images and adversarial examples generated by AutoAttack, while significantly reducing the number of steps in denoising process.