用自适应扩散模型提升视觉模型抗干扰能力,实现可证明的鲁棒性保障。
Adaptive Diffusion Denoised Smoothing : Certified Robustness via Randomized Smoothing with Differentially Private Guided Denoising Diffusion
- 将引导去噪扩散过程视为一系列自适应差分隐私高斯机制
- 在ImageNet上对ℓ₂攻击提升认证准确率与普通准确率
- 适合关注模型安全性的研究者和工业应用
我们提出自适应扩散去噪平滑方法,用于对视觉模型预测结果进行对抗样本的可证明鲁棒性认证,并能根据输入自适应调整。核心思想是将引导去噪扩散模型重解为一系列逐步将纯噪声转化为图像的自适应差分隐私高斯机制。通过差分隐私滤波器组合这些机制,分析端到端去噪过程的鲁棒性,扩展了自适应随机平滑的理论框架。在特定引导策略下,该方法在ImageNet上的ℓ₂威胁模型下,同时提升了认证准确率与标准准确率。
原文摘要 · Abstract (English)
We propose Adaptive Diffusion Denoised Smoothing, a method for certifying the predictions of a vision model against adversarial examples, while adapting to the input. Our key insight is to reinterpret a guided denoising diffusion model as a long sequence of adaptive Gaussian Differentially Private (GDP) mechanisms refining a pure noise sample into an image. We show that these adaptive mechanisms can be composed through a GDP privacy filter to analyze the end-to-end robustness of the guided denoising process, yielding a provable certification that extends the adaptive randomized smoothing analysis. We demonstrate that our design, under a specific guiding strategy, can improve both certified accuracy and standard accuracy on ImageNet for an $\ell_2$ threat model.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。