DiffAdvMAP: Flexible Diffusion-Based Framework for Generating Natural Unrestricted Adversarial Examples
Zhengzhao Pan, Hua Chen, Xiaogang Zhang
Abstract
Unrestricted adversarial examples(UAEs) have posed greater threats to deep neural networks(DNNs) than perturbation-based adversarial examples(AEs) because they can make extensive changes to images without being restricted in a fixed norm perturbation budget. Although current diffusion-based methods can generate more natural UAEs than other unrestricted attack methods, the overall effectiveness of such methods is restricted since they are designed for specific attack conditions. Additionally, the naturalness of UAEs still has room for improvement, as these methods primarily focus on leveraging diffusion models as strong priors to enhance the generation process. This paper proposes a flexible framework named Diffusion-based Adversarial Maximum a Posterior(DiffAdvMAP) to generate more natural UAEs for various scenarios. Dif-fAdvMAP approaches the generation of UAEs by sampling images from posterior distributions, which is achieved by approximating the posterior distribution of UAEs using the prior distribution of real data learned by the diffusion model. This process enhances the naturalness of the UAEs. By incorporating an adversarial constraint to ensure the effectiveness of the attack, DiffAdvMAP exhibits excellent attack ability and defense robustness. A reconstruction constraint is designed to enhance its flexibility, which allows DiffAd-vMAP to be tailored to various attack scenarios. Experimental results on ImageNet show that we achieve a better trade-off between image quality, flexibility, and transferability than baseline unrestricted adversarial attack methods.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 895581aa-c4e2-4a9f-827d-0bd0c4b2ccaaBuilds on31
- Denoising Diffusion Probabilistic ModelsJonathan Ho, Ajay Jain, Pieter AbbeelNeurIPS 2020 · 35,902 citations
- Swin Transformer: Hierarchical Vision Transformer using Shifted WindowsZe Liu, Yutong Lin, Yue Cao, Han Hu et al.ICCV 2021 · 31,683 citations
- An Image is Worth 16x16 Words: Transformers for Image Recognition at ScaleAlexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn et al.ICLR 2021 · 21,477 citations
- Diffusion Models Beat GANs on Image SynthesisPrafulla Dhariwal, Alexander Quinn NicholNeurIPS 2021 · 13,211 citations
- High-Resolution Image Synthesis with Latent Diffusion ModelsRobin Rombach, Andreas Blattmann, Dominik Lorenz, Patrick Esser et al.CVPR 2022 · 13,123 citations
Related papers
- AdvDiffuser: Natural Adversarial Example Synthesis with Diffusion ModelsXinquan Chen, Xitong Gao, Juanjuan Zhao, Kejiang Ye et al.ICCV 2023 · 94 citations
- NatADiff: Adversarial Boundary Guidance for Natural Adversarial DiffusionMax Collins, Jordan Vice, Tim French, Ajmal MianICLR 2026 · 6 citations
- Natural Color Fool: Towards Boosting Black-box Unrestricted AttacksShengming Yuan, Qilong Zhang, Lianli Gao, Yaya Cheng et al.NeurIPS 2022 · 86 citations
- Content-based Unrestricted Adversarial AttackZhaoyu Chen, Bo Li, Shuang Wu, Kaixun Jiang et al.NeurIPS 2023 · 132 citations
- Data-free Universal Adversarial Perturbation with Pseudo-semantic PriorChanhui Lee, Yeonghwan Song, Jeany SonCVPR 2025
