Alleviating Adversarial Attacks on Variational Autoencoders with MCMC
Anna Kuzina, Max Welling, Jakub M. Tomczak
Abstract
Variational autoencoders (VAEs) are latent variable models that can generate complex objects and provide meaningful latent representations. Moreover, they could be further used in downstream tasks such as classification. As previous work has shown, one can easily fool VAEs to produce unexpected latent representations and reconstructions for a visually slightly modified input. Here, we examine several objective functions for adversarial attack construction proposed previously and present a solution to alleviate the effect of these attacks. Our method utilizes the Markov Chain Monte Carlo (MCMC) technique in the inference step that we motivate with a theoretical analysis. Thus, we do not incorporate any extra costs during training, and the performance on non-attacked inputs is not decreased. We validate our approach on a variety of datasets (MNIST, Fashion MNIST, Color MNIST, CelebA) and VAE configurations (-VAE, NVAE, -TCVAE), and show that our approach consistently improves the model robustness to adversarial attacks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext cfa7876a-e2b5-4fb1-a071-61da0e26edf3Cited by top-tier papers2
- Adversarial robustness of amortized Bayesian inferenceManuel Glöckler, Michael Deistler, Jakob H. MackeICML 2023 · 23 citations
- Robust One-Class Classification with Signed Distance Function using 1-Lipschitz Neural NetworksLouis Béthune, Paul Novello, Guillaume Coiffier, Thibaut Boissin et al.ICML 2023 · 12 citations
Builds on9
- NVAE: A Deep Hierarchical Variational AutoencoderArash Vahdat, Jan KautzNeurIPS 2020 · 1,141 citations
- On Adaptive Attacks to Adversarial Example DefensesFlorian Tramèr, Nicholas Carlini, Wieland Brendel, Aleksander MadryNeurIPS 2020 · 1,026 citations
- What Are Bayesian Neural Network Posteriors Really Like?Pavel Izmailov, Sharad Vikram, Matthew D. Hoffman, Andrew Gordon WilsonICML 2021 · 458 citations
- Video Compression With Rate-Distortion AutoencodersAmirHossein Habibian, Ties van Rozendaal, Jakub M. Tomczak, Taco CohenICCV 2019 · 233 citations
- The Autoencoding Variational AutoencoderA. Taylan Cemgil, Sumedh Ghaisas, Krishnamurthy Dvijotham, Sven Gowal et al.NeurIPS 2020 · 81 citations
Related papers
- Improving VAEs' Robustness to Adversarial AttackMatthew Willetts, Alexander Camuto, Tom Rainforth, Stephen J. Roberts et al.ICLR 2021 · 30 citations
- Medical Vision-Language Pre-training with Multimodal Variational Masked Autoencoder for Robust Medical VQADexuan Xu, Yanyuan Chen, Yu Huang, Shihao E et al.ACM MM 2025
- Trading off Image Quality for Robustness is not Necessary with Regularized Deterministic AutoencodersAmrutha Saseendran, Kathrin Skubch, Stefan Falkner, Margret KeuperNeurIPS 2022
- Support is All You Need for Certified VAE TrainingChangming Xu, Debangshu Banerjee, Deepak Vasisht, Gagandeep SinghICLR 2025
- Robustness and Generalization via Generative Adversarial TrainingOmid Poursaeed, Tianxing Jiang, Harry Yang, Serge J. Belongie et al.ICCV 2021 · 35 citations
