arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2408.17064cs.CVcs.AIcs.LG

基于对抗一致性蒸馏的即时对抗纯化

Instant Adversarial Purification with Adversarial Consistency Distillation

  • City University of Hong Kong(香港城市大学)
  • University of St Andrews(圣安德鲁斯大学)
  • University of Nottingham(诺丁汉大学)

机构由 AI 辅助整理,请以论文原文为准。

Chun Tong Lei, Hon Ming Yam, Zhongliang Guo, Yifei Qian, Chun Pong Lau

更新

AI总结:

针对现有扩散模型对抗纯化方法计算开销大的问题,提出OSCP框架,结合GAND蒸馏目标与CAP推理流水线,实现单步高效鲁棒纯化,在ImageNet上以0.1秒单步速度达74.19%防御成功率,提速百倍。

AI中文摘要:

神经网络凭借其卓越性能革新了众多领域,但仍易受通过微小扰动实现的对抗攻击。尽管诸如DiffPure这类基于扩散的纯化方法提供了颇具前景的防御机制,但其计算开销构成了显著的实际应用限制。本文提出了单步控制纯化(One Step Control Purification, OSCP),这是一种全新的防御框架,可在扩散模型内通过单次神经函数评估(Neural Function Evaluation, NFE)实现鲁棒的对抗纯化。我们提出高斯对抗噪声蒸馏(Gaussian Adversarial Noise Distillation, GAND)作为蒸馏目标,受控对抗纯化(Controlled Adversarial Purification, CAP)作为推理流水线,使OSCP在保持防御效能的同时展现出显著效率。我们提出的GAND解决了一致性蒸馏与对抗扰动之间的根本矛盾,在潜空间中弥合了自然流形与对抗流形之间的差距,同时通过LoRA等参数高效微调(Parameter-Efficient Fine-Tuning, PEFT)方法保持计算高效性,免除了全参数微调所需的高昂计算成本。CAP通过由输入图像计算得到的不可学习边缘检测算子作为额外提示引导纯化过程,有效防止了使用较大纯化步长时纯化后的图像偏离其原始外观。我们在ImageNet上的实验结果展现了OSCP的优越性能,其防御成功率达74.19%,单次纯化仅需0.1秒——相比传统方法提速100倍。

英文摘要:

Neural networks have revolutionized numerous fields with their exceptional performance, yet they remain susceptible to adversarial attacks through subtle perturbations. While diffusion-based purification methods like DiffPure offer promising defense mechanisms, their computational overhead presents a significant practical limitation. In this paper, we introduce One Step Control Purification (OSCP), a novel defense framework that achieves robust adversarial purification in a single Neural Function Evaluation (NFE) within diffusion models. We propose Gaussian Adversarial Noise Distillation (GAND) as the distillation objective and Controlled Adversarial Purification (CAP) as the inference pipeline, which makes OSCP demonstrate remarkable efficiency while maintaining defense efficacy. Our proposed GAND addresses a fundamental tension between consistency distillation and adversarial perturbation, bridging the gap between natural and adversarial manifolds in the latent space, while remaining computationally efficient through Parameter-Efficient Fine-Tuning (PEFT) methods such as LoRA, eliminating the high computational budget request from full parameter fine-tuning. The CAP guides the purification process through the unlearnable edge detection operator calculated by the input image as an extra prompt, effectively preventing the purified images from deviating from their original appearance when large purification steps are used. Our experimental results on ImageNet showcase OSCP's superior performance, achieving a 74.19% defense success rate with merely 0.1s per purification -- a 100-fold speedup compared to conventional approaches.

补充信息

↑