Why Adversarially Train Diffusion Models?
Maria Rosaria Briglia, Mujtaba Hussain Mirza, Giuseppe Lisanti, Iacopo Masi
Abstract
Adversarial Training (AT) is a known, powerful, well-established technique for improving classifier robustness to input perturbations, yet its applicability beyond discriminative settings remains limited. Motivated by the widespread use of scorebased generative models and their need to operate robustly under substantial noisy or corrupted input data, we propose an adaptation of AT for these models, providing a thorough empirical assessment. We introduce a principled formulation of AT for Diffusion Models (DMs) that replaces the conventional invariance objective with an equivariance constraint aligned to the denoising dynamics of score matching. Our method integrates seamlessly into diffusion training by adding either random perturbations-similar to randomized smoothing-or adversarial ones-akin to AT. Our approach offers several advantages: (a) tolerance to heavy noise and corruption, (b) reduced memorization, (c) robustness to outliers and extreme data variability and (d) resilience to iterative adversarial attacks. We validate these claims on proof-of-concept low-and high-dimensional datasets with known ground-truth distributions, enabling precise error analysis. We further evaluate on standard benchmarks (CIFAR-10, CelebA, and LSUN Bedroom), where our approach shows improved robustness and preserved sample fidelity under severe noise, data corruption, and adversarial evaluation. Code available at github.com/OmnAI-Lab/Adversarial-Training-DM Samples generation is then performed by solving the probability flow ODE (PF-ODE) Song et al. (2021b), from t = T to 0 and starting from x T ≃ N (0, ε 2 max I), whose solution is learned from the DM. For a given x 0 , the training objective L DM reported in Ho et al. (2020) is thus defined as: L DM = E ω↑N (0,I) t↑U (0,I) ε ↔ ε ε x t (x 0 , ε), t 2 2
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext ad7ed47b-9c75-4ebf-9afd-b615f3ff1dc5Cited by top-tier papers1
Ask how each one uses itBuilds on35
- Denoising Diffusion Probabilistic ModelsJonathan Ho, Ajay Jain, Pieter AbbeelNeurIPS 2020 · 35,902 citations
- Diffusion Models Beat GANs on Image SynthesisPrafulla Dhariwal, Alexander Quinn NicholNeurIPS 2021 · 13,211 citations
- High-Resolution Image Synthesis with Latent Diffusion ModelsRobin Rombach, Andreas Blattmann, Dominik Lorenz, Patrick Esser et al.CVPR 2022 · 13,123 citations
- Denoising Diffusion Implicit ModelsJiaming Song, Chenlin Meng, Stefano ErmonICLR 2021 · 11,743 citations
- Improved Denoising Diffusion Probabilistic ModelsAlexander Quinn Nichol, Prafulla DhariwalICML 2021 · 5,234 citations
Related papers
- Label-Noise Robust Diffusion ModelsByeonghu Na, Yeongmin Kim, HeeSun Bae, Jung Hyun Lee et al.ICLR 2024 · 20 citations
- Improved Diffusion-based Generative Model with Better Adversarial RobustnessZekun Wang, Mingyang Yi, Shuchen Xue, Zhenguo Li et al.ICLR 2025
- Deep MMD Gradient Flow without adversarial trainingAlexandre Galashov, Valentin De Bortoli, Arthur GrettonICLR 2025 · 1 citation
- Consistent Diffusion Models: Mitigating Sampling Drift by Learning to be ConsistentGiannis Daras, Yuval Dagan, Alex Dimakis, Constantinos DaskalakisNeurIPS 2023 · 79 citations
- Normalization-equivariant Diffusion Models: Learning Posterior Samplers From Noisy And Partial MeasurementsBrett Levac, Jon Tamir, Marcelo Pereyra, Julián TachellaICML 2026 · 2 citations
