Papers Adversarial Purification
“Adversarial Purification” 태그가 달린 논문 65편 · 필터 해제
DiffCAP: Diffusion-based Cumulative Adversarial Purification for Vision Language Models
Vision Language Models (VLMs) have shown remarkable capabilities in multimodal understanding, yet their susceptibility to perturbations poses a significant threat to their reliability in real-world applications. Despite …
Adversarial PurificationDenoisingFighting Fire with Fire (F3): A Training-free and Efficient Visual Adversarial Example Purification Method in LVLMs
Recent advances in large vision-language models (LVLMs) have showcased their remarkable capabilities across a wide range of multimodal vision-language tasks. However, these models remain vulnerable to visual adversarial …
Adversarial PurificationComputational EfficiencyHow Do Diffusion Models Improve Adversarial Robustness?
Recent findings suggest that diffusion models significantly enhance empirical adversarial robustness. While some intuitive explanations have been proposed, the precise mechanisms underlying these improvements remain uncl…
Adversarial PurificationAdversarial RobustnessTowards more transferable adversarial attack in black-box manner
Adversarial attacks have become a well-explored domain, frequently serving as evaluation baselines for model robustness. Among these, black-box attacks based on transferability have received significant attention due to …
Adversarial AttackAdversarial PurificationDenoisingInductive Bias+1FlowPure: Continuous Normalizing Flows for Adversarial Purification
Despite significant advancements in the area, adversarial robustness remains a critical challenge in systems employing machine learning models. The removal of adversarial perturbations at inference time, known as adversa…
Adversarial PurificationAdversarial RobustnessDenoisingDiffusion-based Adversarial Purification from the Perspective of the Frequency Domain
The diffusion-based adversarial purification methods attempt to drown adversarial perturbations into a part of isotropic noise through the forward process, and then recover the clean images through the reverse process. D…
Adversarial PurificationDefending Against Frequency-Based Attacks with Diffusion Models
Adversarial training is a common strategy for enhancing model robustness against adversarial attacks. However, it is typically tailored to the specific attack types it is trained on, limiting its ability to generalize to…
Adversarial PurificationLISArD: Learning Image Similarity to Defend Against Gray-box Adversarial Attacks
State-of-the-art defense mechanisms are typically evaluated in the context of white-box attacks, which is not realistic, as it assumes the attacker can access the gradients of the target network. To protect against this …
Adversarial PurificationModel-Free Adversarial Purification via Coarse-To-Fine Tensor Network Representation
Deep neural networks are known to be vulnerable to well-designed adversarial attacks. Although numerous defense strategies have been proposed, many are tailored to the specific attacks or tasks and often fail to generali…
Adversarial PurificationVideoPure: Diffusion-based Adversarial Purification for Video Recognition
Recent work indicates that video recognition models are vulnerable to adversarial examples, posing a serious security risk to downstream applications. However, current research has primarily focused on adversarial attack…
Adversarial DefenseAdversarial PurificationAdversarial RobustnessDenoising+1Gradient-Free Adversarial Purification with Diffusion Models
Adversarial training and adversarial purification are two effective and practical defense methods to enhance a model's robustness against adversarial attacks. However, adversarial training necessitates additional trainin…
Adversarial DefenseAdversarial PurificationSuper-ResolutionDivide and Conquer: Heterogeneous Noise Integration for Diffusion-based Adversarial Purification
Existing diffusion-based purification methods aim to disrupt adversarial perturbations by introducing a certain amount of noise through a forward diffusion process, followed by a reverse process to recover clean exam…
Adversarial PurificationAdversarial Purification by Consistency-aware Latent Space Optimization on Data Manifolds
Deep neural networks (DNNs) are vulnerable to adversarial samples crafted by adding imperceptible perturbations to clean data, potentially leading to incorrect and dangerous predictions. Adversarial purification has been…
Adversarial PurificationPre-trained Multiple Latent Variable Generative Models are good defenders against Adversarial Attacks
Attackers can deliberately perturb classifiers' input with subtle noise, altering final predictions. Among proposed countermeasures, adversarial purification employs generative networks to preprocess input images, filter…
Adversarial PurificationRandom Sampling for Diffusion-based Adversarial Purification
Denoising Diffusion Probabilistic Models (DDPMs) have gained great attention in adversarial purification. Current diffusion-based works focus on designing effective condition-guided mechanisms while ignoring a fundamenta…
Adversarial PurificationDenoisingAdversarial Attacks and Robust Defenses in Speaker Embedding based Zero-Shot Text-to-Speech System
Speaker embedding based zero-shot Text-to-Speech (TTS) systems enable high-quality speech synthesis for unseen speakers using minimal data. However, these systems are vulnerable to adversarial attacks, where an attacker …
Adversarial PurificationSpeech Synthesistext-to-speechText to SpeechImproving Adversarial Robustness for 3D Point Cloud Recognition at Test-Time through Purified Self-Training
Recognizing 3D point cloud plays a pivotal role in many real-world applications. However, deploying 3D point cloud deep learning model is vulnerable to adversarial attacks. Despite many efforts into developing robust mod…
Adversarial PurificationAdversarial RobustnessLoRID: Low-Rank Iterative Diffusion for Adversarial Purification
This work presents an information-theoretic examination of diffusion-based purification methods, the state-of-the-art adversarial defenses that utilize diffusion models to remove malicious perturbations in adversarial ex…
Adversarial PurificationDenoisingHigh-Frequency Anti-DreamBooth: Robust Defense against Personalized Image Synthesis
Recently, text-to-image generative models have been misused to create unauthorized malicious images of individuals, posing a growing social problem. Previous solutions, such as Anti-DreamBooth, add adversarial noise to i…
Adversarial AttackAdversarial PurificationImage GenerationDetecting and Defending Against Adversarial Attacks on Automatic Speech Recognition via Diffusion Models
Automatic speech recognition (ASR) systems are known to be vulnerable to adversarial attacks. This paper addresses detection and defence against targeted white-box attacks on speech signals for ASR systems. While existin…
Adversarial AttackAdversarial PurificationAutomatic Speech RecognitionSpeech Recognition