Lune

ICML2023Top-tier venue

Better Diffusion Models Further Improve Adversarial Training

Zekai Wang, Tianyu Pang, Chao Du, Min Lin, Weiwei Liu, Shuicheng Yan

2023Year
300Citations
114Top-tier citations

Abstract

It has been recognized that the data generated by the denoising diffusion probabilistic model (DDPM) improves adversarial training. After two years of rapid development in diffusion models, a question naturally arises: can better diffusion models further improve adversarial training? This paper gives an affirmative answer by employing the most recent diffusion model which has higher efficiency (∼20\sim 20 sampling steps) and image quality (lower FID score) compared with DDPM. Our adversarially trained models achieve state-of-the-art performance on RobustBench using only generated data (no external datasets). Under the ℓ∞\ell_\infty-norm threat model with ϵ=8/255\epsilon=8/255, our models achieve 70.69%70.69\% and 42.67%42.67\% robust accuracy on CIFAR-10 and CIFAR-100, respectively, i.e. improving upon previous state-of-the-art models by +4.58%+4.58\% and +8.03%+8.03\%. Under the ℓ2\ell_2-norm threat model with ϵ=128/255\epsilon=128/255, our models achieve 84.86%84.86\% on CIFAR-10 (+4.44%+4.44\%). These results also beat previous works that use external data. We also provide compelling results on the SVHN and TinyImageNet datasets. Our code is available at https://github.com/wzekai99/DM-Improves-AT.

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

lune papers fulltext ddfd51d7-d6d5-4209-a031-49f3b2d10ce7

Cited by top-tier papers114

Ask how each one uses it

Builds on46

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines