Better Diffusion Models Further Improve Adversarial Training

02/09/2023
by   Zekai Wang, et al.
0

It has been recognized that the data generated by the denoising diffusion probabilistic model (DDPM) improves adversarial training. After two years of rapid development in diffusion models, a question naturally arises: can better diffusion models further improve adversarial training? This paper gives an affirmative answer by employing the most recent diffusion model which has higher efficiency (∼ 20 sampling steps) and image quality (lower FID score) compared with DDPM. Our adversarially trained models achieve state-of-the-art performance on RobustBench using only generated data (no external datasets). Under the ℓ_∞-norm threat model with ϵ=8/255, our models achieve 70.69% and 42.67% robust accuracy on CIFAR-10 and CIFAR-100, respectively, i.e. improving upon previous state-of-the-art models by +4.58% and +8.03%. Under the ℓ_2-norm threat model with ϵ=128/255, our models achieve 84.86% on CIFAR-10 (+4.44%). These results also beat previous works that use external data. Our code is available at https://github.com/wzekai99/DM-Improves-AT.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
08/28/2023

DiffSmooth: Certifiably Robust Learning via Diffusion Models and Local Smoothing

Diffusion models have been leveraged to perform adversarial purification...
research
03/10/2023

TrojDiff: Trojan Attacks on Diffusion Models with Diverse Targets

Diffusion models have achieved great success in a range of tasks, such a...
research
04/25/2023

Patch Diffusion: Faster and More Data-Efficient Training of Diffusion Models

Diffusion models are powerful, but they require a lot of time and data t...
research
07/22/2020

Adversarial Training Reduces Information and Improves Transferability

Recent results show that features of adversarially trained networks for ...
research
11/25/2020

Advancing diagnostic performance and clinical usability of neural networks via adversarial training and dual batch normalization

Unmasking the decision-making process of machine learning models is esse...
research
02/01/2023

Stable Target Field for Reduced Variance Score Estimation in Diffusion Models

Diffusion models generate samples by reversing a fixed forward diffusion...

Please sign up or login with your details

Forgot password? Click here to reset