Fetching the paper…
Reading the bibliography…
Diffusion models have been applied to improve adversarial robustness of image classifiers by purifying the adversarial noises or generating realistic data for adversarial training.
On discriminative vs. generative classifiers: a comparison of logistic regression and naive bayes
Ng, A. Y. and Jordan, M. I · 2001
Earlier work this paper cites.
Classification with hybrid generative/discriminative models
Raina, R., Shen, Y., Ng, A. Y., and McCallum, A · 2003
Earlier work this paper cites.
A tutorial on energy-based learning
LeCun, Y., Chopra, S., Hadsell, R., Ranzato, M., and Huang, F · 2006
Earlier work this paper cites.
Learning multiple layers of features from tiny images
Krizhevsky, A. and Hinton, G · 2009
Earlier work this paper cites.
Imagenet classification with deep convolutional neural networks
Krizhevsky, A., Sutskever, I., and Hinton, G. E · 2012
Earlier work this paper cites.
Intriguing properties of neural networks
Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I., and Fergus, R · 2014
Earlier work this paper cites.
Natural evolution strategies
Wierstra, D., Schaul, T., Glasmachers, T., Sun, Y., Peters, J., and Schmidhuber, J · 2014
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Goodfellow, I. J., Shlens, J., and Szegedy, C · 2015
Earlier work this paper cites.
Imagenet large scale visual recognition challenge
Russakovsky, O., Deng, J., Su, H., Krause, J., Satheesh, S., Ma, S., Huang, Z., Karpathy, A., Khosla, A., Bernstein, M., et al · 2015
Earlier work this paper cites.
Adversarial manipulation of deep representations
Sabour, S., Cao, Y., Faghri, F., and Fleet, D. J · 2015
Earlier work this paper cites.
Deep unsupervised learning using nonequilibrium thermodynamics
Sohl-Dickstein, J., Weiss, E., Maheswaranathan, N., and Ganguli, S · 2015
Earlier work this paper cites.
Deep residual learning for image recognition
He, K., Zhang, X., Ren, S., and Sun, J · 2016
Earlier work this paper cites.
Accessorize to a crime: Real and stealthy attacks on state-of-the-art face recognition
Sharif, M., Bhagavatula, S., Bauer, L., and Reiter, M. K · 2016
Earlier work this paper cites.
Towards evaluating the robustness of neural networks
Carlini, N. and Wagner, D · 2017
Earlier work this paper cites.
Masked autoregressive flow for density estimation
Papamakarios, G., Pavlakou, T., and Murray, I · 2017
Earlier work this paper cites.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
Athalye, A., Carlini, N., and Wagner, D · 2018
Earlier work this paper cites.
Boosting adversarial attacks with momentum
Dong, Y., Liao, F., Pang, T., Su, H., Zhu, J., Hu, X., and Li, J · 2018
Earlier work this paper cites.
Defense against adversarial attacks using high-level representation guided denoiser
Liao, F., Liang, M., Dong, Y., Pang, T., Hu, X., and Zhu, J · 2018
Earlier work this paper cites.
Towards deep learning models resistant to adversarial attacks
Madry, A., Makelov, A., Schmidt, L., Tsipras, D., and Vladu, A · 2018
Earlier work this paper cites.
Certified defenses against adversarial examples
Raghunathan, A., Steinhardt, J., and Liang, P · 2018
Earlier work this paper cites.
Defense-gan: Protecting classifiers against adversarial attacks using generative models
Samangouei, P., Kabkab, M., and Chellappa, R · 2018
Earlier work this paper cites.
Pixeldefend: Leveraging generative models to understand and defend against adversarial examples
Song, Y., Kim, T., Nowozin, S., Ermon, S., and Kushman, N · 2018
Earlier work this paper cites.
Provable defenses against adversarial examples via the convex outer adversarial polytope
Wong, E. and Kolter, Z · 2018
Earlier work this paper cites.
Spatially transformed adversarial examples
Xiao, C., Zhu, J.-Y., Li, B., He, W., Liu, M., and Song, D · 2018
Earlier work this paper cites.
Certified adversarial robustness via randomized smoothing
Cohen, J., Rosenfeld, E., and Kolter, Z · 2019
Earlier work this paper cites.
Efficient decision-based black-box adversarial attacks on face recognition
Dong, Y., Su, H., Wu, B., Li, Z., Liu, W., Zhang, T., and Zhu, J · 2019
Earlier work this paper cites.
Implicit generation and modeling with energy based models
Du, Y. and Mordatch, I · 2019
Earlier work this paper cites.
Robustness (python library), 2019
Engstrom, L., Ilyas, A., Salman, H., Santurkar, S., and Tsipras, D · 2019
Earlier work this paper cites.
Adversarial attacks on medical machine learning
Finlayson, S. G., Bowers, J. D., Ito, J., Zittrain, J. L., Beam, A. L., and Kohane, I. S · 2019
Cited alongside, same era.
Your classifier is secretly an energy based model and you should treat it like one
Grathwohl, W., Wang, K.-C., Jacobsen, J.-H., Duvenaud, D., Norouzi, M., and Swersky, K · 2019
Cited alongside, same era.
Are generative classifiers more robust to adversarial attacks?
Li, Y., Bradshaw, J., and Sharma, Y · 2019
Cited alongside, same era.
Towards the first adversarially robust neural network model on mnist
Schott, L., Rauber, J., Bethge, M., and Brendel, W · 2019
Cited alongside, same era.
Generative modeling by estimating gradients of the data distribution
Song, Y. and Ermon, S · 2019
Cited alongside, same era.
Adversarial training and robustness for multiple perturbations
Tramèr, F. and Boneh, D · 2019
Score-based generative modeling through stochastic differential equations
Song, Y., Sohl-Dickstein, J., Kingma, D. P., Kumar, A., Ermon, S., and Poole, B · 2021
Later among the works it cites.
Score-based generative classifiers
Zimmermann, R. S., Schott, L., Song, Y., Dunn, B. A., and Klindt, D. A · 2021
Later among the works it cites.
Threat model-agnostic adversarial defense using diffusion models
Blau, T., Ganz, R., Kawar, B., Bronstein, A., and Elad, M · 2022
Later among the works it cites.
A light recipe to train robust vision transformers
Debenedetti, E., Sehwag, V., and Mittal, P · 2022
Later among the works it cites.
Random normalization aggregation for adversarial defense
Dong, M., Chen, X., Wang, Y., and Xu, C · 2022
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Cited alongside, same era.
Robustness may be at odds with accuracy
Tsipras, D., Santurkar, S., Engstrom, L., Turner, A., and Madry, A · 2019
Cited alongside, same era.
Theoretically principled trade-off between robustness and accuracy
Zhang, H., Yu, Y., Jiao, J., Xing, E., El Ghaoui, L., and Jordan, M · 2019
Cited alongside, same era.
Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks
Croce, F. and Hein, M · 2020
Cited alongside, same era.
Robustbench: a standardized adversarial robustness benchmark
Croce, F., Andriushchenko, M., Sehwag, V., Debenedetti, E., Flammarion, N., Chiang, M., Mittal, P., and Hein, M · 2020
Cited alongside, same era.
An image is worth 16x16 words: Transformers for image recognition at scale
Dosovitskiy, A., Beyer, L., Kolesnikov, A., Weissenborn, D., Zhai, X., Unterthiner, T., Dehghani, M., Minderer, M., Heigold, G., Gelly, S., et al · 2020
Cited alongside, same era.
Denoising diffusion probabilistic models
Ho, J., Jain, A., and Abbeel, P · 2020
Cited alongside, same era.
Card: Classification and regression diffusion models
Han, X., Zheng, H., and Zhou, M · 2022
Later among the works it cites.
Gsmooth: Certified robustness against semantic transformations via generalized randomized smoothing
Hao, Z., Ying, C., Dong, Y., Su, H., Song, J., and Zhu, J · 2022
Later among the works it cites.
Elucidating the design space of diffusion-based generative models
Karras, T., Aittala, M., Aila, T., and Laine, S · 2022
Later among the works it cites.
Diffusion models for adversarial purification
Nie, W., Guo, B., Huang, Y., Xiao, C., Vahdat, A., and Anandkumar, A · 2022
Later among the works it cites.
Dreamfusion: Text-to-3d using 2d diffusion
Poole, B., Jain, A., Barron, J. T., and Mildenhall, B · 2022
Later among the works it cites.
High-resolution image synthesis with latent diffusion models
Rombach, R., Blattmann, A., Lorenz, D., Esser, P., and Ommer, B · 2022
Later among the works it cites.
Improving robustness against real-world and worst-case distribution shifts through decision region quantification
Schwinn, L., Bungert, L., Nguyen, A., Raab, R., Pulsmeyer, F., Precup, D., Eskofier, B., and Zanca, D · 2022
Later among the works it cites.
Guided diffusion model for adversarial purification
Wang, J., Lyu, Z., Lin, D., Dai, B., and Fu, H · 2022
Later among the works it cites.
Your vit is secretly a hybrid discriminative-generative diffusion model
Yang, X., Shih, S.-M., Fu, Y., Zhao, X., and Ji, S · 2022
Later among the works it cites.
Classifier robustness enhancement via test-time transformation
Blau, T., Ganz, R., Baskin, C., Elad, M., and Bronstein, A · 2023
Closest in time.
(certified!!) adversarial robustness for free!
Carlini, N., Tramer, F., Dvijotham, K. D., Rice, L., Sun, M., and Kolter, J. Z · 2023
Closest in time.
Rethinking model ensemble in transfer-based adversarial attacks
Chen, H., Zhang, Y., Dong, Y., Yang, X., Su, H., and Zhu, J · 2023
Closest in time.
Text-to-image diffusion models are zero-shot classifiers
Clark, K. and Jaini, P · 2023
Closest in time.
How robust is google’s bard to adversarial image attacks?
Dong, Y., Chen, H., Chen, J., Fang, Z., Yang, X., Zhang, Y., Tian, Y., Su, H., and Zhu, J · 2023
Closest in time.
Your diffusion model is secretly a zero-shot classifier
Li, A. C., Prabhudesai, M., Duggal, S., Brown, E., and Pathak, D · 2023
Closest in time.
Instaflow: One step is enough for high-quality diffusion-based text-to-image generation
Liu, X., Zhang, X., Ma, J., Peng, J., and Liu, Q · 2023
Closest in time.
Catch-up distillation: You only need to train once for accelerating sampling
Shao, S., Dai, X., Yin, S., Li, L., Chen, H., and Hu, Y · 2023
Closest in time.
Song, Y., Dhariwal, P., Chen, M., and Sutskever, I · 2023
Closest in time.
Densepure: Understanding diffusion models for adversarial robustness
Xiao, C., Chen, Z., Jin, K., Wang, J., Nie, W., Liu, M., Anandkumar, A., Li, B., and Song, D · 2023
Closest in time.
{ \{ DiffSmooth } \} : Certifiably robust learning via diffusion models and local smoothing
Zhang, J., Chen, Z., Zhang, H., Xiao, C., and Li, B · 2023
Closest in time.
Your diffusion model is secretly a certifiably robust classifier
Chen, H., Dong, Y., Shao, S., Hao, Z., Yang, X., Su, H., and Zhu, J · 2024
Closest in time.
On the duality between sharpness-aware minimization and adversarial training
Zhang, Y., He, H., Zhu, J., Chen, H., Wang, Y., and Wei, Z · 2024
Closest in time.