Adversarial purification with Score-based generative models

06/11/2021
by   Jongmin Yoon, et al.
0

While adversarial training is considered as a standard defense method against adversarial attacks for image classifiers, adversarial purification, which purifies attacked images into clean images with a standalone purification model, has shown promises as an alternative defense method. Recently, an Energy-Based Model (EBM) trained with Markov-Chain Monte-Carlo (MCMC) has been highlighted as a purification model, where an attacked image is purified by running a long Markov-chain using the gradients of the EBM. Yet, the practicality of the adversarial purification using an EBM remains questionable because the number of MCMC steps required for such purification is too large. In this paper, we propose a novel adversarial purification method based on an EBM trained with Denoising Score-Matching (DSM). We show that an EBM trained with DSM can quickly purify attacked images within a few steps. We further introduce a simple yet effective randomized purification scheme that injects random noises into images before purification. This process screens the adversarial perturbations imposed on images by the random noises and brings the images to the regime where the EBM can denoise well. We show that our purification method is robust against various attacks and demonstrate its state-of-the-art performances.

READ FULL TEXT
research
05/27/2020

Stochastic Security: Adversarial Defense Using Long-Run Dynamics of Energy-Based Models

The vulnerability of deep networks to adversarial attacks is a central p...
research
05/30/2022

Guided Diffusion Model for Adversarial Purification

With wider application of deep neural networks (DNNs) in various algorit...
research
02/07/2020

Assessing the Adversarial Robustness of Monte Carlo and Distillation Methods for Deep Bayesian Neural Network Classification

In this paper, we consider the problem of assessing the adversarial robu...
research
06/23/2017

A-NICE-MC: Adversarial Training for MCMC

Existing Markov Chain Monte Carlo (MCMC) methods are either based on gen...
research
01/26/2020

Markov-Chain Monte Carlo Approximation of the Ideal Observer using Generative Adversarial Networks

The Ideal Observer (IO) performance has been advocated when optimizing m...
research
04/02/2023

Ideal Observer Computation by Use of Markov-Chain Monte Carlo with Generative Adversarial Networks

Medical imaging systems are often evaluated and optimized via objective,...
research
11/24/2020

Stochastic sparse adversarial attacks

Adversarial attacks of neural network classifiers (NNC) and the use of r...

Please sign up or login with your details

Forgot password? Click here to reset