• 文献检索
  • 文档翻译
  • 深度研究
  • 学术资讯
  • Suppr Zotero 插件Zotero 插件
  • 邀请有礼
  • 套餐&价格
  • 历史记录
应用&插件
Suppr Zotero 插件Zotero 插件浏览器插件Mac 客户端Windows 客户端微信小程序
定价
高级版会员购买积分包购买API积分包
服务
文献检索文档翻译深度研究API 文档MCP 服务
关于我们
关于 Suppr公司介绍联系我们用户协议隐私条款
关注我们

Suppr 超能文献

核心技术专利:CN118964589B侵权必究
粤ICP备2023148730 号-1Suppr @ 2026

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验

用于对抗性净化的对抗引导扩散模型。

Adversarial guided diffusion models for adversarial purification.

作者信息

Lin Guang, Tao Zerui, Zhang Jianhai, Tanaka Toshihisa, Zhao Qibin

机构信息

Department of Electronic and Information Engineering, Tokyo University of Agriculture and Technology, 184-8588, Tokyo, Japan; RIKEN Center for Advanced Intelligence Project (AIP), 103-0027, Tokyo, Japan.

RIKEN Center for Advanced Intelligence Project (AIP), 103-0027, Tokyo, Japan.

出版信息

Neural Netw. 2025 Nov;191:107705. doi: 10.1016/j.neunet.2025.107705. Epub 2025 Jul 8.

DOI:10.1016/j.neunet.2025.107705
PMID:40644991
Abstract

Diffusion model (DM) based adversarial purification (AP) has proven to be a powerful defense method that can remove adversarial perturbations and generate a purified example without threats. In principle, the pre-trained DMs can only ensure that purified examples conform to the same distribution of the training data, but it may inadvertently compromise the semantic information of input examples, leading to misclassification of purified examples. Recent advancements introduce guided diffusion techniques to preserve semantic information while removing the perturbations. However, these guidances often rely on distance measures between purified examples and diffused examples, which can also preserve perturbations in purified examples. To further unleash the robustness power of DM-based AP, we propose an adversarial guided diffusion model by introducing a novel adversarial guidance that contains sufficient semantic information but does not explicitly involve adversarial perturbations. The guidance is modeled by an auxiliary neural network obtained with adversarial training, considering the distance in the latent representations rather than at the pixel-level values. Extensive experiments are conducted on CIFAR-10, CIFAR-100 and ImageNet to demonstrate that our method is effective for simultaneously maintaining semantic information and removing the adversarial perturbations. In addition, comprehensive comparisons show that our method significantly enhances the robustness of existing DM-based AP, with an average robust accuracy improved by up to 7.30% on CIFAR-10.

摘要

基于扩散模型(DM)的对抗净化(AP)已被证明是一种强大的防御方法,它可以去除对抗性扰动并生成无威胁的净化示例。原则上,预训练的扩散模型只能确保净化后的示例符合训练数据的相同分布,但它可能会无意中损害输入示例的语义信息,导致净化后的示例被错误分类。最近的进展引入了引导扩散技术,以在去除扰动的同时保留语义信息。然而,这些引导通常依赖于净化示例和扩散示例之间的距离度量,这也可能在净化示例中保留扰动。为了进一步释放基于DM的AP的鲁棒性,我们通过引入一种新颖的对抗引导来提出一种对抗引导扩散模型,该引导包含足够的语义信息但不明确涉及对抗性扰动。该引导由通过对抗训练获得的辅助神经网络建模,考虑的是潜在表示中的距离而不是像素级值。我们在CIFAR-10、CIFAR-100和ImageNet上进行了大量实验,以证明我们的方法对于同时保持语义信息和去除对抗性扰动是有效的。此外,全面的比较表明,我们的方法显著提高了现有基于DM的AP的鲁棒性,在CIFAR-10上平均鲁棒准确率提高了7.30%。

相似文献

1
Adversarial guided diffusion models for adversarial purification.用于对抗性净化的对抗引导扩散模型。
Neural Netw. 2025 Nov;191:107705. doi: 10.1016/j.neunet.2025.107705. Epub 2025 Jul 8.
2
Prescription of Controlled Substances: Benefits and Risks管制药品的处方:益处与风险
3
Short-Term Memory Impairment短期记忆障碍
4
Sexual Harassment and Prevention Training性骚扰与预防培训
5
The Black Book of Psychotropic Dosing and Monitoring.《精神药物剂量与监测黑皮书》
Psychopharmacol Bull. 2024 Jul 8;54(3):8-59.
6
Anterior Approach Total Ankle Arthroplasty with Patient-Specific Cut Guides.使用患者特异性截骨导向器的前路全踝关节置换术。
JBJS Essent Surg Tech. 2025 Aug 15;15(3). doi: 10.2106/JBJS.ST.23.00027. eCollection 2025 Jul-Sep.
7
Healthcare workers' informal uses of mobile phones and other mobile devices to support their work: a qualitative evidence synthesis.医护人员非正规使用手机和其他移动设备来支持工作:定性证据综合评价。
Cochrane Database Syst Rev. 2024 Aug 27;8(8):CD015705. doi: 10.1002/14651858.CD015705.pub2.
8
Analyzing the Implicit Bias of Adversarial Training From a Generalized Margin Perspective.从广义边界视角分析对抗训练中的隐性偏差
IEEE Trans Pattern Anal Mach Intell. 2025 Sep;47(9):8025-8039. doi: 10.1109/TPAMI.2025.3575618.
9
Actor critic with experience replay-based automatic treatment planning for prostate cancer intensity modulated radiotherapy.基于经验回放的演员-评论家算法用于前列腺癌调强放射治疗的自动治疗计划
Med Phys. 2025 Jul;52(7):e17915. doi: 10.1002/mp.17915. Epub 2025 May 31.
10
A medical image classification method based on self-regularized adversarial learning.基于自正则化对抗学习的医学图像分类方法。
Med Phys. 2024 Nov;51(11):8232-8246. doi: 10.1002/mp.17320. Epub 2024 Jul 30.