LiBRe: A Practical Bayesian Approach to Adversarial Detection
Zhijie Deng, Xiao Yang, Shizhen Xu, Hang Su, Jun Zhu
Abstract
Despite their appealing flexibility, deep neural networks (DNNs) are vulnerable against adversarial examples. Various adversarial defense strategies have been proposed to resolve this problem, but they typically demonstrate restricted practicability owing to unsurmountable compromise on universality, effectiveness, or efficiency. In this work, we propose a more practical approach, Lightweight Bayesian Refinement (LiBRe), in the spirit of leveraging Bayesian neural networks (BNNs) for adversarial detection. Empowered by the task and attack agnostic modeling under Bayes principle, LiBRe can endow a variety of pre-trained taskdependent DNNs with the ability of defending heterogeneous adversarial attacks at a low cost. We develop and integrate advanced learning techniques to make LiBRe appropriate for adversarial detection. Concretely, we build the few-layer deep ensemble variational and adopt the pretraining & fine-tuning workflow to boost the effectiveness and efficiency of LiBRe. We further provide a novel insight to realise adversarial detection-oriented uncertainty correction without inefficiently crafting adversarial examples during training. Extensive empirical studies covering a wide range of scenarios verify the practicability of LiBRe. We also conduct thorough ablation studies to evidence the superiority of our modeling and learning strategies. 1
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers10
- BayesDiff: Estimating Pixel-wise Uncertainty in Diffusion via Bayesian InferenceSiqi Kou, Lei Gan, Dequan Wang, Chongxuan Li et al.ICLR 2024 · 20 citations
- Embodied Active Defense: Leveraging Recurrent Feedback to Counter Adversarial PatchesLingxuan Wu, Xiao Yang, Yinpeng Dong, Liuwei Xie et al.ICLR 2024 · 6 citations
- Diffusion Epistemic Uncertainty with Asymmetric Learning for Diffusion-Generated Image DetectionYingsong Huang, Hui Guo, Jing Huang, Bing Bai et al.ICCV 2025 · 4 citations
- Learning Robust Vision-Language Models from Natural Latent SpacesZhangyun Wang, Ni Ding, Aniket MahantiNeurIPS 2025 · 3 citations
- The Heat is On: Understanding and Mitigating Vulnerabilities of Thermal Image Perception in Autonomous SystemsSri Hrushikesh Varma Bhupathiraju, Shaoyuan Xie, Michael Clifford, Qi Alfred Chen et al.NDSS 2026 · 1 citation
Builds on6
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Accessorize to a Crime: Real and Stealthy Attacks on State-of-the-Art Face RecognitionMahmood Sharif, Sruti Bhagavatula, Lujo Bauer, Michael K. ReiterCCS 2016 · 1,765 citations
- Feature Squeezing: Detecting Adversarial Examples in Deep Neural NetworksWeilin Xu, David Evans, Yanjun QiNDSS 2018 · 1,633 citations
- Bayesian Deep Learning and a Probabilistic Perspective of GeneralizationAndrew Gordon Wilson, Pavel IzmailovNeurIPS 2020 · 845 citations
- Being Bayesian, Even Just a Bit, Fixes Overconfidence in ReLU NetworksAgustinus Kristiadi, Matthias Hein, Philipp HennigICML 2020 · 344 citations
Related papers
- DIPDefend: Deep Image Prior Driven Defense against Adversarial ExamplesTao Dai, Yan Feng, Dongxian Wu, Bin Chen et al.ACM MM 2020 · 20 citations
- Making Substitute Models More Bayesian Can Enhance Transferability of Adversarial ExamplesQizhang Li, Yiwen Guo, Wangmeng Zuo, Hao ChenICLR 2023 · 5 citations
- UAG: Uncertainty-aware Attention Graph Neural Network for Defending Adversarial AttacksBoyuan Feng, Yuke Wang, Yufei DingAAAI 2021 · 41 citations
- Understanding the Robustness of Randomized Feature Defense Against Query-Based Adversarial AttacksNguyen Hung-Quang, Yingjie Lao, Tung Pham, Kok-Seng Wong et al.ICLR 2024 · 3 citations
- Interpretability is a Kind of Safety: An Interpreter-based Ensemble for Adversary DefenseJingyuan Wang, Yufan Wu, Mingxuan Li, Xin Lin et al.KDD 2020 · 12 citations
