Diffusion-Based Adversarial Sample Generation for Improved Stealthiness and Controllability
Haotian Xue, Alexandre Araujo, Bin Hu, Yongxin Chen
摘要
Neural networks are known to be susceptible to adversarial samples: small variations of natural examples crafted to deliberately mislead the models. While they can be easily generated using gradient-based techniques in digital and physical scenarios, they often differ greatly from the actual data distribution of natural images, resulting in a trade-off between strength and stealthiness. In this paper, we propose a novel framework dubbed Diffusion-Based Projected Gradient Descent (Diff-PGD) for generating realistic adversarial samples. By exploiting a gradient guided by a diffusion model, Diff-PGD ensures that adversarial samples remain close to the original data distribution while maintaining their effectiveness. Moreover, our framework can be easily customized for specific tasks such as digital attacks, physical-world attacks, and style-based attacks. Compared with existing methods for generating natural-style adversarial samples, our framework enables the separation of optimizing adversarial loss from other surrogate losses (e.g., content/smoothness/style loss), making it more stable and controllable. Finally, we demonstrate that the samples generated using Diff-PGD have better transferability and anti-purification power than traditional gradient-based methods. Code will be released in https://github.com/xavihart/Diff-PGD
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper35
- Toward effective protection against diffusion-based mimicry through score distillationHaotian Xue, Chumeng Liang, Xiaoyu Wu, Yongxin ChenICLR 2024 · 被引用 70 次
- DiffAttack: Evasion Attacks Against Diffusion-Based Adversarial PurificationMintong Kang, Dawn Song, Bo LiNeurIPS 2023 · 被引用 66 次
- Diffusion Policy Attacker: Crafting Adversarial Attacks for Diffusion-based PoliciesYipu Chen, Haotian Xue, Yongxin ChenNeurIPS 2024 · 被引用 23 次
- Step Vulnerability Guided Mean Fluctuation Adversarial Attack against Conditional Diffusion ModelsHongwei Yu, Jiansheng Chen, Xinlong Ding, Yudong Zhang 等AAAI 2024 · 被引用 18 次
- AdvAD: Exploring Non-Parametric Diffusion for Imperceptible Adversarial AttacksJin Li, Ziqiang He, Anwei Luo, Jian-Fang Hu 等NeurIPS 2024 · 被引用 17 次
它引用的顶会 Paper31
- Denoising Diffusion Probabilistic ModelsJonathan Ho, Ajay Jain, Pieter AbbeelNeurIPS 2020 · 被引用 35,902 次
- An Image is Worth 16x16 Words: Transformers for Image Recognition at ScaleAlexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn 等ICLR 2021 · 被引用 21,477 次
- Diffusion Models Beat GANs on Image SynthesisPrafulla Dhariwal, Alexander Quinn NicholNeurIPS 2021 · 被引用 13,211 次
- High-Resolution Image Synthesis with Latent Diffusion ModelsRobin Rombach, Andreas Blattmann, Dominik Lorenz, Patrick Esser 等CVPR 2022 · 被引用 13,123 次
- Denoising Diffusion Implicit ModelsJiaming Song, Chenlin Meng, Stefano ErmonICLR 2021 · 被引用 11,743 次
相关 Paper
- Adv-Diffusion: Imperceptible Adversarial Face Identity Attack via Latent Diffusion ModelDecheng Liu, Xijun Wang, Chunlei Peng, Nannan Wang 等AAAI 2024 · 被引用 39 次
- NatADiff: Adversarial Boundary Guidance for Natural Adversarial DiffusionMax Collins, Jordan Vice, Tim French, Ajmal MianICLR 2026 · 被引用 6 次
- Adversarial Camouflage: Hiding Physical-World Attacks With Natural StylesRanjie Duan, Xingjun Ma, Yisen Wang, James Bailey 等CVPR 2020
- DiffAdvMAP: Flexible Diffusion-Based Framework for Generating Natural Unrestricted Adversarial ExamplesZhengzhao Pan, Hua Chen, Xiaogang ZhangICML 2025
- StealthDiffusion: Towards Evading Diffusion Forensic Detection through Diffusion ModelZiyin Zhou, Ke Sun, Zhongxi Chen, Huafeng Kuang 等ACM MM 2024 · 被引用 7 次
