DiffSmooth: Certifiably Robust Learning via Diffusion Models and Local Smoothing
Jiawei Zhang, Zhongzhu Chen, Huan Zhang, Chaowei Xiao, Bo Li
摘要
Diffusion models have been leveraged to perform adversarial purification and thus provide both empirical and certified robustness for a standard model. On the other hand, different robustly trained smoothed models have been studied to improve the certified robustness. Thus, it raises a natural question: Can diffusion model be used to achieve improved certified robustness on those robustly trained smoothed models? In this work, we first theoretically show that recovered instances by diffusion models are in the bounded neighborhood of the original instance with high probability; and the"one-shot"denoising diffusion probabilistic models (DDPM) can approximate the mean of the generated distribution of a continuous-time diffusion model, which approximates the original instance under mild conditions. Inspired by our analysis, we propose a certifiably robust pipeline DiffSmooth, which first performs adversarial purification via diffusion models and then maps the purified instances to a common region via a simple yet effective local smoothing strategy. We conduct extensive experiments on different datasets and show that DiffSmooth achieves SOTA-certified robustness compared with eight baselines. For instance, DiffSmooth improves the SOTA-certified accuracy from to under radius on ImageNet. The code is available at [https://github.com/javyduck/DiffSmooth].
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper13
- Diffusion Models are Certifiably Robust ClassifiersHuanran Chen, Yinpeng Dong, Shitong Shao, Zhongkai Hao 等NeurIPS 2024 · 被引用 42 次
- DiffHammer: Rethinking the Robustness of Diffusion-Based Adversarial PurificationKaibo Wang, Xiaowen Fu, Yuxuan Han, Yang XiangNeurIPS 2024 · 被引用 11 次
- Machine Learning needs Better Randomness Standards: Randomised Smoothing and PRNG-based attacksPranav Dahiya, Ilia Shumailov, Ross AndersonUSENIX Security 2024 · 被引用 11 次
- DiffBreak: Is Diffusion-Based Purification Robust?Andre Kassis, Urs Hengartner, Yaoliang YuNeurIPS 2025 · 被引用 8 次
- Certifiable Black-Box Attacks with Randomized Adversarial Examples: Breaking Defenses with Provable ConfidenceHanbin Hong, Xinyu Zhang, Binghui Wang, Zhongjie Ba 等CCS 2024 · 被引用 3 次
它引用的顶会 Paper26
- Denoising Diffusion Probabilistic ModelsJonathan Ho, Ajay Jain, Pieter AbbeelNeurIPS 2020 · 被引用 35,902 次
- An Image is Worth 16x16 Words: Transformers for Image Recognition at ScaleAlexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn 等ICLR 2021 · 被引用 21,477 次
- Diffusion Models Beat GANs on Image SynthesisPrafulla Dhariwal, Alexander Quinn NicholNeurIPS 2021 · 被引用 13,211 次
- High-Resolution Image Synthesis with Latent Diffusion ModelsRobin Rombach, Andreas Blattmann, Dominik Lorenz, Patrick Esser 等CVPR 2022 · 被引用 13,123 次
- Denoising Diffusion Implicit ModelsJiaming Song, Chenlin Meng, Stefano ErmonICLR 2021 · 被引用 11,743 次
相关 Paper
- DensePure: Understanding Diffusion Models for Adversarial RobustnessChaowei Xiao, Zhongzhu Chen, Kun Jin, Jiongxiao Wang 等ICLR 2023 · 被引用 18 次
- Consistency Purification: Effective and Efficient Diffusion Purification towards Certified RobustnessYiquan Li, Zhongzhu Chen, Kun Jin, Jiongxiao Wang 等NeurIPS 2024 · 被引用 3 次
- (Certified!!) Adversarial Robustness for Free!Nicholas Carlini, Florian Tramèr, Krishnamurthy (Dj) Dvijotham, Leslie Rice 等ICLR 2023 · 被引用 17 次
- Robust Representation Consistency Model via Contrastive DenoisingJiachen Lei, Julius Berner, Jiongxiao Wang, Zhongzhu Chen 等ICLR 2025
- Multi-scale Diffusion Denoised SmoothingJongheon Jeong, Jinwoo ShinNeurIPS 2023 · 被引用 15 次
