(Certified!!) Adversarial Robustness for Free!
Nicholas Carlini, Florian Tramèr, Krishnamurthy (Dj) Dvijotham, Leslie Rice, Mingjie Sun, J. Zico Kolter
Abstract
In this paper we show how to achieve state-of-the-art certified adversarial robustness to 2 -norm bounded perturbations by relying exclusively on off-the-shelf pretrained models. To do so, we instantiate the denoised smoothing approach of Salman et al. ( 2020 ) by combining a pretrained denoising diffusion probabilistic model and a standard high-accuracy classifier. This allows us to certify 71% accuracy on ImageNet under adversarial perturbations constrained to be within an 2 norm of ε = 0.5, an improvement of 14 percentage points over the prior certified SoTA using any approach, or an improvement of 30 percentage points over denoised smoothing. We obtain these results using only pretrained diffusion models and image classifiers, without requiring any fine tuning or retraining of model parameters.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 4bb01894-e641-4d65-9e4a-aea1fe42d240Cited by top-tier papers45
- Better Diffusion Models Further Improve Adversarial TrainingZekai Wang, Tianyu Pang, Chao Du, Min Lin et al.ICML 2023 · 300 citations
- Diffusion-Based Adversarial Sample Generation for Improved Stealthiness and ControllabilityHaotian Xue, Alexandre Araujo, Bin Hu, Yongxin ChenNeurIPS 2023 · 110 citations
- Addressing Negative Transfer in Diffusion ModelsHyojun Go, JinYoung Kim, Yunsung Lee, Seunghyun Lee et al.NeurIPS 2023 · 42 citations
- Enhancing Adversarial Robustness via Score-Based OptimizationBoya Zhang, Weijian Luo, Zhihua ZhangNeurIPS 2023 · 31 citations
- A Critical Revisit of Adversarial Robustness in 3D Point Cloud Recognition with Diffusion-Driven PurificationJiachen Sun, Jiongxiao Wang, Weili Nie, Zhiding Yu et al.ICML 2023 · 24 citations
Builds on16
- Denoising Diffusion Probabilistic ModelsJonathan Ho, Ajay Jain, Pieter AbbeelNeurIPS 2020 · 35,902 citations
- An Image is Worth 16x16 Words: Transformers for Image Recognition at ScaleAlexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn et al.ICLR 2021 · 21,477 citations
- Diffusion Models Beat GANs on Image SynthesisPrafulla Dhariwal, Alexander Quinn NicholNeurIPS 2021 · 13,211 citations
- Denoising Diffusion Implicit ModelsJiaming Song, Chenlin Meng, Stefano ErmonICLR 2021 · 11,743 citations
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
Related papers
- DiffSmooth: Certifiably Robust Learning via Diffusion Models and Local SmoothingJiawei Zhang, Zhongzhu Chen, Huan Zhang, Chaowei Xiao et al.USENIX Security 2023
- Multi-scale Diffusion Denoised SmoothingJongheon Jeong, Jinwoo ShinNeurIPS 2023 · 15 citations
- DensePure: Understanding Diffusion Models for Adversarial RobustnessChaowei Xiao, Zhongzhu Chen, Kun Jin, Jiongxiao Wang et al.ICLR 2023 · 18 citations
- Robust Representation Consistency Model via Contrastive DenoisingJiachen Lei, Julius Berner, Jiongxiao Wang, Zhongzhu Chen et al.ICLR 2025
- Denoised Smoothing: A Provable Defense for Pretrained ClassifiersHadi Salman, Mingjie Sun, Greg Yang, Ashish Kapoor et al.NeurIPS 2020 · 191 citations
