Beyond Single-Point Perturbation: A Hierarchical, Manifold-Aware Approach to Diffusion Attacks
Zhijie Wang, Lin Wang, Zhenyu Wen, Cong Wang
Abstract
Latent Diffusion Models have become a powerful tool for generating high-fidelity unrestricted adversarial examples. However, the existing methods typically perturb only the initial latent or rely on prompt engineering, which is ill-suited to the iterative nature of the diffusion process, plus optimization instability due to external text prompts and cumulative drift that push the adversarial images off the data manifold. In this paper, we propose a hierarchical attack framework that operates in alignment with the model's generative manifold and leverages intermediate denoising states to maximize attack transferability and visual fidelity. Extensive experiments show that the proposed attack improves adversarial transferability by 10-20% against a diverse set of normally-trained models and achieves over 10.5% higher success rate against adversarially-defended models, while simultaneously enhancing visual quality by 1.0-1.2 FID reduction and 16.7% LPIPS improvements.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext adb7deaf-51e2-4750-92cd-c931ffd0b273Builds on20
- Swin Transformer: Hierarchical Vision Transformer using Shifted WindowsZe Liu, Yutong Lin, Yue Cao, Han Hu et al.ICCV 2021 · 31,683 citations
- An Image is Worth 16x16 Words: Transformers for Image Recognition at ScaleAlexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn et al.ICLR 2021 · 21,477 citations
- High-Resolution Image Synthesis with Latent Diffusion ModelsRobin Rombach, Andreas Blattmann, Dominik Lorenz, Patrick Esser et al.CVPR 2022 · 13,123 citations
- Denoising Diffusion Implicit ModelsJiaming Song, Chenlin Meng, Stefano ErmonICLR 2021 · 11,743 citations
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
Related papers
- Adv-Diffusion: Imperceptible Adversarial Face Identity Attack via Latent Diffusion ModelDecheng Liu, Xijun Wang, Chunlei Peng, Nannan Wang et al.AAAI 2024 · 39 citations
- ObjectAdv: Object-Level Unrestricted Adversarial Attacks via Diffusion ModelsShijie Zhao, Zhenyu Liang, Xing Yang, Haoqi Gao et al.AAAI 2026
- Latent Diffusion Unlearning: Protecting Against Unauthorized Personalization Through Trajectory Shifted PerturbationsNaresh Kumar Devulapally, Shruti Agarwal, Tejas Gokhale, Vishnu Suresh LokhandeACM MM 2025 · 1 citation
- ReToMe-VA: Recursive Token Merging for Video Diffusion-based Unrestricted Adversarial AttackZiyi Gao, Kai Chen, Zhipeng Wei, Tingshu Mou et al.ACM MM 2024 · 3 citations
- Pixel Is Not a Barrier: An Effective Evasion Attack for Pixel-Domain Diffusion ModelsChun-Yen Shih, Li-Xuan Peng, Jia-Wei Liao, Ernie Chu et al.AAAI 2025 · 3 citations
