arrow
Return

DifFilter: Defending Against Adversarial Perturbations With Diffusion Filter

delete2024-01-01
delete0
PRE
AI
Y
Yong Chen
X
Xuedong Li
胡鹏 (Peng Hu)
D
Dezhong Peng
X
Xu Wang *
DOI:10.1109/TIFS.2024.3422923delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
The inherent vulnerability of deep learning to adversarial examples poses a significant security challenge. Although existing defense methods have partially mitigated the harm caused by adversarial attacks, they are still unable to meet practical needs due to their high cost, high latency, and poor defense performance. In this paper, we propose an advanced plug-and-play adversarial purification model called DifFilter. Specifically, we use the superior generative properties of diffusion models to denoise adversarial perturbations and recover clean images. To make Gaussian noise disrupt adversarial perturbations while preserving the real semantic information in the input image, we extend forward diffusion to an infinite number of noise scales so that the distribution of perturbation data evolves with increasing noise according to stochastic differential equations. In the inverse denoising process, we develop a score-based model learning method to restore the input prior distribution to the data distribution of the original clean sample, resulting in stronger purification effects. Additionally, we propose an efficient sampling method to accelerate the computation speed of inverse process, greatly reducing the time cost of purification. We conduct extensive experiments to evaluate the defense generalization performance of DifFilter. The results demonstrate that our method not only surpasses existing defense methods in defense robustness under strong adaptive and black-box attacks but also achieves higher certificate accuracy than the baseline. Furthermore, DifFilter can be combined with adversarial training to further improve defense robustness.
Keywords:
Training
Purification
Perturbation methods
Robustness
Diffusion models
Mathematical models
Stochastic processes
Adversarial defence
adversarial purification
diffusion model
robustness

Journal

IEEE Transactions on Information Forensics and Security cover
IEEE Transactions on Information Forensics and Security
IF:
8
Papers:
5.2K
Citations:
2.3W

Organization

C
Chengdu University of Information Technology
Scholars:
2.9K
Papers: 2.3K
Citations: 2.4K
C
chinese academy of sciences
Scholars:
56.3W
Papers: 44.8W
Citations: 704