Why Adversarially Train Diffusion Models?
Maria Rosaria Briglia, Mujtaba Hussain Mirza, Giuseppe Lisanti, Iacopo Masi
摘要
Adversarial Training (AT) is a known, powerful, well-established technique for improving classifier robustness to input perturbations, yet its applicability beyond discriminative settings remains limited. Motivated by the widespread use of scorebased generative models and their need to operate robustly under substantial noisy or corrupted input data, we propose an adaptation of AT for these models, providing a thorough empirical assessment. We introduce a principled formulation of AT for Diffusion Models (DMs) that replaces the conventional invariance objective with an equivariance constraint aligned to the denoising dynamics of score matching. Our method integrates seamlessly into diffusion training by adding either random perturbations-similar to randomized smoothing-or adversarial ones-akin to AT. Our approach offers several advantages: (a) tolerance to heavy noise and corruption, (b) reduced memorization, (c) robustness to outliers and extreme data variability and (d) resilience to iterative adversarial attacks. We validate these claims on proof-of-concept low-and high-dimensional datasets with known ground-truth distributions, enabling precise error analysis. We further evaluate on standard benchmarks (CIFAR-10, CelebA, and LSUN Bedroom), where our approach shows improved robustness and preserved sample fidelity under severe noise, data corruption, and adversarial evaluation. Code available at github.com/OmnAI-Lab/Adversarial-Training-DM Samples generation is then performed by solving the probability flow ODE (PF-ODE) Song et al. (2021b), from t = T to 0 and starting from x T ≃ N (0, ε 2 max I), whose solution is learned from the DM. For a given x 0 , the training objective L DM reported in Ho et al. (2020) is thus defined as: L DM = E ω↑N (0,I) t↑U (0,I) ε ↔ ε ε x t (x 0 , ε), t 2 2
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper1
问问它们各自怎么用它它引用的顶会 Paper35
- Denoising Diffusion Probabilistic ModelsJonathan Ho, Ajay Jain, Pieter AbbeelNeurIPS 2020 · 被引用 35,902 次
- Diffusion Models Beat GANs on Image SynthesisPrafulla Dhariwal, Alexander Quinn NicholNeurIPS 2021 · 被引用 13,211 次
- High-Resolution Image Synthesis with Latent Diffusion ModelsRobin Rombach, Andreas Blattmann, Dominik Lorenz, Patrick Esser 等CVPR 2022 · 被引用 13,123 次
- Denoising Diffusion Implicit ModelsJiaming Song, Chenlin Meng, Stefano ErmonICLR 2021 · 被引用 11,743 次
- Improved Denoising Diffusion Probabilistic ModelsAlexander Quinn Nichol, Prafulla DhariwalICML 2021 · 被引用 5,234 次
相关 Paper
- Label-Noise Robust Diffusion ModelsByeonghu Na, Yeongmin Kim, HeeSun Bae, Jung Hyun Lee 等ICLR 2024 · 被引用 20 次
- Improved Diffusion-based Generative Model with Better Adversarial RobustnessZekun Wang, Mingyang Yi, Shuchen Xue, Zhenguo Li 等ICLR 2025
- Deep MMD Gradient Flow without adversarial trainingAlexandre Galashov, Valentin De Bortoli, Arthur GrettonICLR 2025 · 被引用 1 次
- Consistent Diffusion Models: Mitigating Sampling Drift by Learning to be ConsistentGiannis Daras, Yuval Dagan, Alex Dimakis, Constantinos DaskalakisNeurIPS 2023 · 被引用 79 次
- Normalization-equivariant Diffusion Models: Learning Posterior Samplers From Noisy And Partial MeasurementsBrett Levac, Jon Tamir, Marcelo Pereyra, Julián TachellaICML 2026 · 被引用 2 次
