针对对抗样本高频频段特性,自适应注入噪声提升图像净化效果
MANI-Pure: Magnitude-Adaptive Noise Injection for Adversarial Purification
- 根据输入频谱幅度动态调整噪声,针对性抑制高频干扰
- 在CIFAR-10和ImageNet上实现2.15%的鲁棒准确率提升
- 适合防御高频率对抗攻击,尤其适用于扩散模型净化
基于扩散模型的对抗净化已成为有前景的防御策略,但现有方法通常采用均匀噪声注入,无差别扰动所有频率,破坏语义结构并削弱鲁棒性。我们的实证研究发现,对抗扰动并非均匀分布:主要集中在高频区域,且不同频率与攻击类型下的幅度强度存在异质性。受此启发,我们提出MANI-Pure,一种基于输入幅度谱引导的自适应净化框架。不同于均匀噪声注入,MANI-Pure采用异构、频段定向的噪声,有效抑制脆弱高频低幅带中的对抗扰动,同时保留关键低频语义内容。在CIFAR-10和ImageNet-1K上的大量实验验证了其有效性:净化后干净准确率与原分类器差距小于0.59,鲁棒准确率提升2.15%,并在RobustBench排行榜上达到最高顶线性能,超越此前最优方法。
原文摘要 · Abstract (English)
Adversarial purification with diffusion models has emerged as a promising defense strategy, but existing methods typically rely on uniform noise injection, which indiscriminately perturbs all frequencies, corrupting semantic structures and undermining robustness. Our empirical study reveals that adversarial perturbations are not uniformly distributed: they are predominantly concentrated in high-frequency regions, with heterogeneous magnitude intensity patterns that vary across frequencies and attack types. Motivated by this observation, we introduce MANI-Pure, a magnitude-adaptive purification framework that leverages the magnitude spectrum of inputs to guide the purification process. Instead of injecting homogeneous noise, MANI-Pure adaptively applies heterogeneous, frequency-targeted noise, effectively suppressing adversarial perturbations in fragile high-frequency, low-magnitude bands while preserving semantically critical low-frequency content. Extensive experiments on CIFAR-10 and ImageNet-1K validate the effectiveness of MANI-Pure. It narrows the clean accuracy gap to within 0.59 of the original classifier, while boosting robust accuracy by 2.15, and achieves the top-1 robust accuracy on the RobustBench leaderboard, surpassing the previous state-of-the-art method.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。