arXiv:2506. 03933v2 Announce Type: replace-cross Abstract: Vision Language Models (VLMs) have shown remarkable capabilities in multimodal understanding, yet their susceptibility to adversarial perturbations poses a significant threat to their reliability in real-world applications.
By Jia Fu, Yongtao Wu, Yihang Chen, Kunyu Peng, Xiao Zhang, Volkan Cevher, Sepideh Pashami, Anders Holst
The paper introduces CLIPure, a method for building an adversarially robust zero‑shot image classifier by purifying inputs in the latent space of CLIP. It formulates purification risk using KL divergence between denoising and attack processes via bidirectional SDEs, and proposes two variants: CLIPure‑Diff, which uses a diffusion prior, and CLIPure‑Cos, which relies on cosine similarity. Experiments on CIFAR‑10, ImageNet, and 13 other datasets show significant robustness gains, raising state‑of‑the‑art performance from 71.7% to 91.1% on CIFAR‑10 and from 59.6% to 72.6% on ImageNet.
By Mingkun Zhang, Keping Bi, Wei Chen, Jiafeng Guo, Xueqi Cheng
Pixel diffusion models generate RGB images directly but tend to miss fine‑scale natural‑image statistics. The authors introduce an adversarial post‑training step that adds an adversarial loss to the model’s output at non‑high‑noise timesteps, without changing the architecture or sampling procedure. This approach improves distribution fidelity, coverage, prompt alignment, and perceptual quality across two pixel backbones, and restores missing high‑frequency spectral power while avoiding memorization or mode dropping.
By Xin Lin, Zhifei Zhang, Yuqian Zhou, Haitian Zheng, Zhe Lin, Ming-Hsuan Yang, Truong Nguyen
arXiv:2412. 08394v2 Announce Type: replace Abstract: Deep neural networks (DNNs) are vulnerable to adversarial samples crafted by adding imperceptible perturbations to clean data, potentially leading to incorrect and dangerous predictions.
By Shuhai Zhang, Jiahao Yang, Hui Luo, Jie Chen, Li Wang, Feng Liu, Bo Han, Mingkui Tan
arXiv:2607. 10580v1 Announce Type: cross Abstract: AI models are increasingly trained on personal images scraped from social media and public platforms, often without consent, leading to serious privacy violations, such as unauthorized facial recognition and targeted advertising.
By Syed Irfan Ali Meerza, Oktay Ozturk, Amir Sadovnik, Jian Liu
arXiv:2608. 15113v1 Announce Type: cross Abstract: Learned image compression (LIC) has demonstrated remarkable rate-distortion (RD) performance in benign settings.
By Jiaming Liang, Chi-Man Pun, Weisi Lin