arXiv AI

Demystifying Adversarial Robustness in Diffusion Models: Compression, Randomness, and Geometry

arXiv:2505. 22839v2 Announce Type: replace-cross Abstract: Recent studies suggest that diffusion models significantly improve the empirical adversarial robustness of deep neural network models.

arXiv AI
Jun 11

Diffusion-based Cumulative Adversarial Purification for Vision Language Models

arXiv:2506. 03933v2 Announce Type: replace-cross Abstract: Vision Language Models (VLMs) have shown remarkable capabilities in multimodal understanding, yet their susceptibility to adversarial perturbations poses a significant threat to their reliability in real-world applications.

By Jia Fu, Yongtao Wu, Yihang Chen, Kunyu Peng, Xiao Zhang, Volkan Cevher, Sepideh Pashami, Anders Holst
arXiv AI
Sep 1

CLIPure: Purification in Latent Space via CLIP for Adversarially Robust Zero-Shot Classification

The paper introduces CLIPure, a method for building an adversarially robust zero‑shot image classifier by purifying inputs in the latent space of CLIP. It formulates purification risk using KL divergence between denoising and attack processes via bidirectional SDEs, and proposes two variants: CLIPure‑Diff, which uses a diffusion prior, and CLIPure‑Cos, which relies on cosine similarity. Experiments on CIFAR‑10, ImageNet, and 13 other datasets show significant robustness gains, raising state‑of‑the‑art performance from 71.7% to 91.1% on CIFAR‑10 and from 59.6% to 72.6% on ImageNet.

By Mingkun Zhang, Keping Bi, Wei Chen, Jiafeng Guo, Xueqi Cheng
arXiv Computer Vision
4d ago

Adversarial Training for Pixel Diffusion

Pixel diffusion models generate RGB images directly but tend to miss fine‑scale natural‑image statistics. The authors introduce an adversarial post‑training step that adds an adversarial loss to the model’s output at non‑high‑noise timesteps, without changing the architecture or sampling procedure. This approach improves distribution fidelity, coverage, prompt alignment, and perceptual quality across two pixel backbones, and restores missing high‑frequency spectral power while avoiding memorization or mode dropping.

By Xin Lin, Zhifei Zhang, Yuqian Zhou, Haitian Zheng, Zhe Lin, Ming-Hsuan Yang, Truong Nguyen
arXiv Computer Vision
4d ago

Weeding Out Bad Seeds: Initial-Noise-Robust Unlearning for Text-to-Image Diffusion Models

arXiv:2609.37537v1 Announce Type: new Abstract: Machine unlearning has emerged as a critical post-hoc safety measure to erase sensitive concepts from Text-to-Image (T2I) models without prohibitive re...

By Arian Komaei Koma, Seyed Amir Kasaei, Aida Aryafar, Matin Ghiasi, Ali Aghayari, Amirhossein Souri, Mohammad Mosayyebi, AmirMahdi Sadeghzadeh, Mohammad Hossein Rohban
arXiv Statistics ML
6d ago

Brenier Meets Adversarial Training: Optimal Transport Geometry for Robust Learning

The paper introduces a penalized distributionally robust optimization framework that allows an adversary to choose any distribution while incurring a Wasserstein penalty for deviating from the empirical distribution. It shows that the adversary’s problem can be reformulated as optimizing transport maps that push empirical samples to adversarial ones, proving that optimal maps are cyclically monotone. The authors argue that standard per-sample adversarial training violates this property and propose two remedies—multi-start particle ascent and input-convex neural network parameterization—to enforce cyclical monotonicity, demonstrating improved robustness and generalization in experiments on regression, image classification, and control tasks.

By Alireza Abdollahpoorrostam, Ehsan Sharifian, Buse \c{S}en, Marco Cuturi, Daniel Kuhn