用扩散模型检测并修复可见与红外域的对抗补丁攻击。
Real-world Adversarial Defense against Patch Attacks based on Diffusion Model
- 基于文本引导扩散模型,通过分布异常感知定位攻击补丁。
- 在图像分类与人脸识别任务中实现高鲁棒性防御效果。
- 支持少样本提示微调,通用框架可跨可见光与红外域使用。
对抗补丁对深度学习模型的鲁棒性构成重大挑战,因此发展有效的防御机制在真实场景应用中至关重要。本文提出DIFFender,一种基于扩散模型的新型防御框架,利用文本引导扩散模型抵御对抗补丁攻击。核心在于发现对抗异常感知(AAP)现象,使扩散模型能通过分析分布异常准确检测并定位对抗补丁。DIFFender将补丁定位与修复任务统一于一个扩散模型框架中,通过二者紧密协作提升防御效能。此外,采用高效的少样本提示微调算法,使预训练扩散模型无需大量重训练即可适配防御任务。全面评估涵盖图像分类与人脸识别任务及真实场景,验证了DIFFender在多种设置、分类器和攻击方法下的鲁棒表现。除常见可见光域外,还发现其可轻松扩展至红外域,展现出良好的灵活性,能以统一框架分别防御红外与可见光对抗补丁攻击。
原文摘要 · Abstract (English)
Adversarial patches present significant challenges to the robustness of deep learning models, making the development of effective defenses become critical for real-world applications. This paper introduces DIFFender, a novel DIFfusion-based DeFender framework that leverages the power of a text-guided diffusion model to counter adversarial patch attacks. At the core of our approach is the discovery of the Adversarial Anomaly Perception (AAP) phenomenon, which enables the diffusion model to accurately detect and locate adversarial patches by analyzing distributional anomalies. DIFFender seamlessly integrates the tasks of patch localization and restoration within a unified diffusion model framework, enhancing defense efficacy through their close interaction. Additionally, DIFFender employs an efficient few-shot prompt-tuning algorithm, facilitating the adaptation of the pre-trained diffusion model to defense tasks without the need for extensive retraining. Our comprehensive evaluation, covering image classification and face recognition tasks, as well as real-world scenarios, demonstrates DIFFender's robust performance against adversarial attacks. The framework's versatility and generalizability across various settings, classifiers, and attack methodologies mark a significant advancement in adversarial patch defense strategies. Except for the popular visible domain, we have identified another advantage of DIFFender: its capability to easily expand into the infrared domain. Consequently, we demonstrate the good flexibility of DIFFender, which can defend against both infrared and visible adversarial patch attacks alternatively using a universal defense framework.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。