notesum.ai
Published at November 25Unlocking The Potential of Adaptive Attacks on Diffusion-Based Purification
cs.CR
cs.CV
Released Date: November 25, 2024
Authors: Andre Kassis1, Urs Hengartner1, Yaoliang Yu1
Aff.: 1Cheriton School of Computer Science, University of Waterloo, Canada

| Models | Pur. | Gradient Method | Cl-Acc % | Rob-Acc % |
| WideResNet-50-2 | DiffPure [36] | Adjoint (Nie et al. [36]) | 71.16 | 44.39 |
| DiffAttack (Kang et al. [26]) | 71.16 | 31.25 | ||
| Full-DiffGrad (Ours) | 74.22 | 12.11 | ||
| DeiT-S | DiffPure [36] | Adjoint (Nie et al. [36]) | 73.63 | 43.18 |
| DiffAttack (Kang et al. [26]) | 73.63 | 32.81 | ||
| Adjoint-DiffGrad (Ours) | 74.22 | 19.15 | ||
| Full-DiffGrad (Ours) | 74.22 | 21.09 | ||
| GDMP [49] | Full-DiffGrad (Ours) | 69.14 | 20.70 |