DiffAttack: Evasion Attacks Against Diffusion-Based Adversarial Purification
Mintong Kang, Dawn Song, Bo Li
Abstract
Diffusion-based purification defenses leverage diffusion models to remove crafted perturbations of adversarial examples and achieve state-of-the-art robustness. Recent studies show that even advanced attacks cannot break such defenses effectively, since the purification process induces an extremely deep computational graph which poses the potential problem of gradient obfuscation, high memory cost, and unbounded randomness. In this paper, we propose a unified framework DiffAttack to perform effective and efficient attacks against diffusion-based purification defenses, including both DDPM and score-based approaches. In particular, we propose a deviated-reconstruction loss at intermediate diffusion steps to induce inaccurate density gradient estimation to tackle the problem of vanishing/exploding gradients. We also provide a segment-wise forwarding-backwarding algorithm, which leads to memory-efficient gradient backpropagation. We validate the attack effectiveness of DiffAttack compared with existing adaptive attacks on CIFAR-10 and ImageNet. We show that DiffAttack decreases the robust accuracy of models compared with SOTA attacks by over 20% on CIFAR-10 under attack , and over 10% on ImageNet under attack . We conduct a series of ablations studies, and we find 1) DiffAttack with the deviated-reconstruction loss added over uniformly sampled time steps is more effective than that added over only initial/final steps, and 2) diffusion-based purification with a moderate diffusion length is more robust under DiffAttack.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 6b4a779a-9bb2-4d60-953f-71791b6ead67Cited by top-tier papers15
- Diffusion Models are Certifiably Robust ClassifiersHuanran Chen, Yinpeng Dong, Shitong Shao, Zhongkai Hao et al.NeurIPS 2024 · 42 citations
- COLEP: Certifiably Robust Learning-Reasoning Conformal Prediction via Probabilistic CircuitsMintong Kang, Nezihe Merve Gürel, Linyi Li, Bo LiICLR 2024 · 12 citations
- Can Protective Perturbation Safeguard Personal Data from Being Exploited by Stable Diffusion?Zhengyue Zhao, Jinhao Duan, Kaidi Xu, Chenan Wang et al.CVPR 2024 · 12 citations
- DiffHammer: Rethinking the Robustness of Diffusion-Based Adversarial PurificationKaibo Wang, Xiaowen Fu, Yuxuan Han, Yang XiangNeurIPS 2024 · 11 citations
- LoRID: Low-Rank Iterative Diffusion for Adversarial PurificationGeigh Zollicoffer, Minh N. Vu, Ben Nebgen, Juan Castorena et al.AAAI 2025 · 10 citations
Builds on22
- Denoising Diffusion Probabilistic ModelsJonathan Ho, Ajay Jain, Pieter AbbeelNeurIPS 2020 · 35,902 citations
- An Image is Worth 16x16 Words: Transformers for Image Recognition at ScaleAlexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn et al.ICLR 2021 · 21,477 citations
- Diffusion Models Beat GANs on Image SynthesisPrafulla Dhariwal, Alexander Quinn NicholNeurIPS 2021 · 13,211 citations
- High-Resolution Image Synthesis with Latent Diffusion ModelsRobin Rombach, Andreas Blattmann, Dominik Lorenz, Patrick Esser et al.CVPR 2022 · 13,123 citations
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
Related papers
- ADBM: Adversarial Diffusion Bridge Model for Reliable Adversarial PurificationXiao Li, Wenxuan Sun, Huanran Chen, Qiongxiu Li et al.ICLR 2025
- Diffusion Models for Adversarial PurificationWeili Nie, Brandon Guo, Yujia Huang, Chaowei Xiao et al.ICML 2022 · 663 citations
- Robust Evaluation of Diffusion-Based Adversarial PurificationMinjong Lee, Dongwoo KimICCV 2023 · 96 citations
- Adversary Aware Optimization for Robust DefenseDaniel Wesego, Pedram RooshenasNeurIPS 2025 · 3 citations
- MimicDiffusion: Purifying Adversarial Perturbation via Mimicking Clean Diffusion ModelKaiyu Song, Hanjiang Lai, Yan Pan, Jian YinCVPR 2024 · 11 citations
