Browse State-of-the-Art › Adversarial Purification
Adversarial Purification
27 papers with code · 0 benchmarks · 0 datasets archive 2025-07-28
A class of adversarial defense methods that remove adversarial perturbations using a generative model.
Description from the archive archive 2025-07-28.
Benchmarks archive 2025-07-28
No benchmark for this task in the archive.
Libraries
Not in the archive: the export carries no per-task library table, so there is nothing to show at snapshot 2025-07-28.
Datasets archive 2025-07-28
No dataset record in the archive lists this task.
Subtasks archive 2025-07-28
No subtask under this task in the archive's task tree.
Parent tasks archive 2025-07-28
Most implemented papers archive 2025-07-28
27 shown of 27 papers with code (65 tagged with this task in all), ordered by repositories listed in the archive, not by stars (the archive holds no stars, so PwC's “Social” and “Latest” sorts cannot be reproduced). Papers without a page here are shown as plain text.
-
30 May 2022 2 repositories listedIn this paper, we propose a novel purification approach, referred to as guided diffusion model for purification (GDMP), to help protect classifiers from adversarial attacks.
-
16 May 2022 2 repositories listed Syntology ran 11 of 23 samples · 12 unverified · 5 pointer-only (licence)Adversarial purification refers to a class of defense methods that remove adversarial perturbations using a generative model.
-
19 May 2025 1 repository listedDespite significant advancements in the area, adversarial robustness remains a critical challenge in systems employing machine learning models.
-
27 Feb 2025 1 repository listedThis paper considers an even more realistic evaluation scenario: gray-box attacks, which assume that the attacker knows the architecture and the dataset used to train the target network, but cannot access its gradients.
-
25 Jan 2025 1 repository listedGiven an adversarial example, we first employ temporal DDIM inversion to transform the input distribution into a temporally consistent and trajectory-defined distribution, covering adversarial noise while preserving…
-
4 Dec 2024 1 repository listedAttackers can deliberately perturb classifiers' input with subtle noise, altering final predictions.
-
28 Nov 2024 1 repository listedRemarkably, under strong attack, our DiffAP even achieves a more than 20% robustness advantage with 10× sampling acceleration.
-
12 Sep 2024 1 repository listed Syntology ran 2 of 6 samples · 4 unverified · 6 pointer-only (licence)Recently, text-to-image generative models have been misused to create unauthorized malicious images of individuals, posing a growing social problem.
-
12 Sep 2024 1 repository listedIn this paper, we systematically investigate the use of DMs for defending against adversarial attacks on sentences and examine the effect of varying forward diffusion steps.
-
2 Aug 2024 1 repository listedIn the field of Image Quality Assessment (IQA), the adversarial robustness of the metrics poses a critical concern.
-
25 Jun 2024 1 repository listedThe escalating sophistication of cyberattacks has encouraged the integration of machine learning techniques in intrusion detection systems, but the rise of adversarial examples presents a significant challenge.
-
5 Jun 2024 1 repository listed Syntology ran 7 of 13 samples · 6 unverified · 13 pointer-only (licence)In this work, we suppose that adversarial images are outliers of the natural image manifold, and the purification process can be considered as returning them to this manifold.
-
18 Mar 2024 1 repository listedCurrent defense strategies usually train DNNs for a specific adversarial attack method and can achieve good robustness in defense against this type of adversarial attack.
-
11 Mar 2024 1 repository listedA typical way to assess a model's robustness is through adversarial attacks, where test-time examples are generated based on gradients to deceive the model.
-
29 Jan 2024 1 repository listed Syntology ran 14 of 18 samples · 4 unverified · 18 pointer-only (licence)The deep neural networks are known to be vulnerable to well-designed adversarial attacks.
-
11 Dec 2023 1 repository listedIn this paper, we introduce MalPurifier, a novel adversarial purification framework specifically engineered for Android malware detection.
-
26 Nov 2023 1 repository listedNotably, the residual perturbations on the purified image primarily stem from the same-position patch and similar patches of the adversarial sample.
-
22 Nov 2023 1 repository listedWe show that diffusion purification methods are well suited for counter-forensics tasks.
-
27 Oct 2023 1 repository listed Syntology ran 18 of 24 samples · 6 unverified · 21 pointer-only (licence)In particular, we propose a deviated-reconstruction loss at intermediate diffusion steps to induce inaccurate density gradient estimation to tackle the problem of vanishing/exploding gradients.
-
19 Sep 2023 1 repository listedAdversarial purification using generative models demonstrates strong adversarial defense performance.
-
28 Aug 2023 1 repository listed Syntology ran 4 of 6 samples · 2 unverified · 6 pointer-only (licence)Diffusion models have been leveraged to perform adversarial purification and thus provide both empirical and certified robustness for a standard model.
-
31 Jul 2023 1 repository listedDeep neural networks (DNNs) have risen to prominence as key solutions in numerous AI applications for earth observation (AI4EO).
-
25 May 2023 1 repository listedIn this work, we propose a novel adversarial defence mechanism for image classification - CARSO - blending the paradigms of adversarial training and adversarial purification in a synergistic robustness-enhancing way.
-
16 Mar 2023 1 repository listed Syntology ran 1 of 1 samples · 0 unverifiedWe analyze the current practices and provide a new guideline for measuring the robustness of purification methods against adversarial attacks.
-
2 Mar 2023 1 repository listedIn this paper, we propose an adversarial purification-based defense pipeline, AudioPure, for acoustic systems via off-the-shelf diffusion models.
-
11 Jun 2021 1 repository listed Syntology ran 0 of 1 samples · 1 unverifiedRecently, an Energy-Based Model (EBM) trained with Markov-Chain Monte-Carlo (MCMC) has been highlighted as a purification model, where an attacked image is purified by running a long Markov-chain using the gradients of…
-
27 May 2020 1 repository listed Syntology ran 0 of 1 samples · 1 unverified · 1 pointer-only (licence)Our contributions are 1) an improved method for training EBM's with realistic long-run MCMC samples, 2) an Expectation-Over-Transformation (EOT) defense that resolves theoretical ambiguities for stochastic defenses and…
Syntology lines on 9 of the papers shown; no Syntology record for the others (a paper without an arXiv id cannot be joined to the graph, and absence from the graph layer is not a recorded non-run). “Ran” means the sample executed on a synthesized fixture, not that the paper's result was reproduced. Read from the graph 2026-09-24.
Report a problem or propose a change · a person checks every report against the paper or source before anything changes; decisions are listed on /corrections