提出新方法提升扩散模型对抗引导采样质量,避免分布漂移。
DPAC: Distribution-Preserving Adversarial Control for Diffusion Sampling
- 通过路径空间KL散度建模控制误差,揭示控制能量与采样质量的关系。
- 实验证明在相同攻击成功率下,DPAC的FID更低,路径KL更小。
- 适合关注生成模型稳定性与对抗样本鲁棒性的研究者。
对抗引导的扩散采样虽能实现目标类别,但随着控制轨迹与原始轨迹偏差累积,样本质量下降。本文将该退化现象形式化为控制过程与原始过程间的路径空间KL散度(path-KL),并基于Girsanov定理证明其精确等于控制能量。在此随机最优控制(SOC)视角下,理论证明最小化path-KL可同时收紧2-Wasserstein距离与Fréchet Inception Distance(FID)的上界,建立控制能量与感知保真度之间的原则性联系。从变分角度,推导出控制的一阶最优条件:在获得相同分类增益的前提下,沿等对数密度曲面切向(即垂直于得分函数)的分量最小化path-KL,而法向分量直接导致分布漂移。由此提出DPAC(Distribution-Preserving Adversarial Control),一种将对抗梯度投影至生成得分几何定义的切空间的指导规则。进一步证明,在离散求解器中,切向投影可抵消Wasserstein距离中O(Δt)的主导误差项,实现O(Δt²)的质量差距;且对得分或度量近似具有二阶鲁棒性。ImageNet-100上的实证研究验证了理论预测,表明在相同攻击成功率下,DPAC实现了更低的FID与估计的path-KL。
原文摘要 · Abstract (English)
Adversarially guided diffusion sampling often achieves the target class, but sample quality degrades as deviations between the adversarially controlled and nominal trajectories accumulate. We formalize this degradation as a path-space Kullback-Leibler divergence(path-KL) between controlled and nominal (uncontrolled) diffusion processes, thereby showing via Girsanov's theorem that it exactly equals the control energy. Building on this stochastic optimal control (SOC) view, we theoretically establish that minimizing this path-KL simultaneously tightens upper bounds on both the 2-Wasserstein distance and Fréchet Inception Distance (FID), revealing a principled connection between adversarial control energy and perceptual fidelity. From a variational perspective, we derive a first-order optimality condition for the control: among all directions that yield the same classification gain, the component tangent to iso-(log-)density surfaces (i.e., orthogonal to the score) minimizes path-KL, whereas the normal component directly increases distributional drift. This leads to DPAC (Distribution-Preserving Adversarial Control), a diffusion guidance rule that projects adversarial gradients onto the tangent space defined by the generative score geometry. We further show that in discrete solvers, the tangent projection cancels the O(Δt) leading error term in the Wasserstein distance, achieving an O(Δt^2) quality gap; moreover, it remains second-order robust to score or metric approximation. Empirical studies on ImageNet-100 validate the theoretical predictions, confirming that DPAC achieves lower FID and estimated path-KL at matched attack success rates.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。