paper-with-me

홈 › Papers

DRIFT: Divergent Response in Filtered Transformations for Robust Adversarial Defense

2025-09-29 · Amira Guesmi, Muhammad Shafique arxiv

Deep neural networks remain highly vulnerable to adversarial examples, and most defenses collapse once gradients can be reliably estimated. We identify \emph{gradient consensus} -- the tendency of randomized transformations to yield aligned gradients -- as a key driver of adversarial transferability. Attackers exploit this consensus to construct perturbations that remain effective across transformations. We introduce \textbf{DRIFT} (Divergent Response in Filtered Transformations), a stochastic ensemble of lightweight, learnable filters trained to actively disrupt gradient consensus. Unlike prior randomized defenses that rely on gradient masking, DRIFT enforces \emph{gradient dissonance} by maximizing divergence in Jacobian- and logit-space responses while preserving natural predictions. Our contributions are threefold: (i) we formalize gradient consensus and provide a theoretical analysis linking consensus to transferability; (ii) we propose a consensus-divergence training strategy combining prediction consistency, Jacobian separation, logit-space separation, and adversarial robustness; and (iii) we show that DRIFT achieves substantial robustness gains on ImageNet across CNNs and Vision Transformers, outperforming state-of-the-art preprocessing, adversarial training, and diffusion-based defenses under adaptive white-box, transfer-based, and gradient-free attacks. DRIFT delivers these improvements with negligible runtime and memory cost, establishing gradient divergence as a practical and generalizable principle for adversarial defense.

📄 PDF Abstract BibTeX arXiv:2509.24359

Code (0)

등록된 구현이 없습니다.

Tasks

Adversarial RobustnessAdversarial Defense

Similar Papers 제목 키워드 기반

Non-stationary filtered shot noise processes and applications to neuronal membranes

2015-09-13

Filtered shot noise processes have proven to be very effective in modelling the evolution of systems exposed to stochastic shot noise sources, and have been applied to a wide variety of fields ranging from electronics th…

Point Processes

Uncovering divergent linguistic information in word embeddings with lessons for intrinsic and extrinsic evaluation

2018-09-06 · CONLL 2018 10 · Mikel Artetxe, Gorka Labaka, Iñigo Lopez-Gazpio, Eneko Agirre

Following the recent success of word embeddings, it has been argued that there is no such thing as an ideal representation for words, as different models tend to capture divergent and often mutually incompatible aspects …

Word Embeddings

Comparison of Decision Tree Based Classification Strategies to Detect External Chemical Stimuli from Raw and Filtered Plant Electrical Response

2017-05-13 · Shre Kumar Chatterjee, Saptarshi Das, Koushik Maharatna, Elisa Masi 외

Plants monitor their surrounding environment and control their physiological functions by producing an electrical response. We recorded electrical signals from different plants by exposing them to Sodium Chloride (NaCl),…

ClassificationGeneral ClassificationMulti-class Classification

Fact-based Dialogue Generation with Convergent and Divergent Decoding

2020-05-06 · Ryota Tanaka, Akinobu Lee

Fact-based dialogue generation is a task of generating a human-like response based on both dialogue context and factual texts. Various methods were proposed to focus on generating informative words that contain facts eff…

Dialogue Generation

VALD: Multi-Stage Vision Attack Detection for Efficient LVLM Defense

2026-02-23 · Nadav Kadvil, Malak Fares, Ayellet Tal arxiv

Large Vision-Language Models (LVLMs) can be vulnerable to adversarial images that subtly bias their outputs toward plausible yet incorrect responses. We introduce a general, efficient, and training-free defense that comb…