Category Ranking

98%

Total Visits

921

Avg Visit Duration

2 minutes

Citations

20

Article Abstract

Many existing adversarial attacks generate -norm perturbations on image RGB space. Despite some achievements in transferability and attack success rate, the crafted adversarial examples are easily perceived by human eyes. Towards visual imperceptibility, some recent works explore unrestricted attacks without -norm constraints, yet lacking transferability of attacking black-box models. In this work, we propose a novel imperceptible and transferable attack by leveraging both the generative and discriminative power of diffusion models. Specifically, instead of direct manipulation in pixel space, we craft perturbations in the latent space of diffusion models. Combined with well-designed content-preserving structures, we can generate human-insensitive perturbations embedded with semantic clues. For better transferability, we further "deceive" the diffusion model which can be viewed as an implicit recognition surrogate, by distracting its attention away from the target regions. To our knowledge, our proposed method, DiffAttack, is the first that introduces diffusion models into the adversarial attack field. Extensive experiments conducted across diverse model architectures (CNNs, Transformers, and MLPs), datasets (ImageNet, CUB-200, and Standford Cars), and defense mechanisms underscore the superiority of our attack over existing methods such as iterative attacks, GAN-based attacks, and ensemble attacks. Furthermore, we provide a comprehensive discussion on future research avenues in diffusion-based adversarial attacks, aiming to chart a course for this burgeoning field.

Download full-text PDF

Source
http://dx.doi.org/10.1109/TPAMI.2024.3480519DOI Listing

Publication Analysis

Top Keywords

diffusion models
16
imperceptible transferable
8
adversarial attack
8
attack existing
8
adversarial attacks
8
attacks
6
diffusion
5
adversarial
5
attack
5
models imperceptible
4

Similar Publications

Radiation-induced single event effects in vertically prolonged drain dual gate Si Ge source TFET.

J Mol Model

September 2025

Department of Electronics and Communication Engineering, National Institute of Technology Patna, Patna, Bihar, India.

Context: This study investigates the radiation tolerance of a SiGe source vertical tunnel field effect transistor (VTFET) under heavy ion-induced single event effects (SEEs). Single event effects (SEEs) occur when high-energy particles interact with semiconductor devices, leading to unintended behavior. The effect of high energy ions on the VTFET is examined for various linear energy transfer (LET) values and at multiple ion hit locations.

View Article and Find Full Text PDF

To evaluate whether age modifies the association between the geriatric nutritional risk index (GNRI) and overall survival (OS) in patients aged ≥ 18 years with newly diagnosed diffuse large B-cell lymphoma (DLBCL), we conducted a multi-centre retrospective study of 552 patients. Multivariable Cox regression with restricted cubic spline (RCS) modelling showed that GNRI was significantly associated with OS, but the relationship was non-linear (P for non-linearity = 0.0158).

View Article and Find Full Text PDF

Prognostic value of multiparameter [Ga]Ga-DOTA-FAPI-04 PET/MR imaging biomarkers for patients with advanced pancreatic cancer.

Eur J Nucl Med Mol Imaging

September 2025

Department of Nuclear Medicine, Changhai Hospital, Naval Medical University, 168 Changhai Road, Yang Pu District, Shanghai, 200433, China.

Purpose: In this retrospective study, whether [Ga]Ga-DOTA-FAPI-04 PET/MR imaging biomarkers can predict the progression-free survival (PFS) and overall survival (OS) of patients with advanced pancreatic cancer was investigated.

Methods: Fifty-one patients who underwent [Ga]Ga-DOTA-FAPI-04 PET/MR scans before first-line chemotherapy were recruited. Imaging biomarkers, including the maximum tumor diameter, minimum apparent diffusion coefficient (ADC), maximum and mean standardized uptake values (SUV and SUV), fibroblast activation protein- (FAP-) positive tumor volume (FTV and W-FTV) and total lesion FAP expression (TLF and W-TLF), were recorded for primary and whole-body tumors.

View Article and Find Full Text PDF

Hard carbon (HC) has emerged as a promising anode material for sodium-ion batteries (SIBs) owing to its superior sodium storage performance. However, the high cost of conventional HC precursors remains a critical challenge. To address this, coal─a low-cost, carbon-rich precursor─has been explored for HC synthesis.

View Article and Find Full Text PDF

Wnt proteins are critical signaling molecules in developmental processes across animals. Despite intense study, their evolutionary roots have remained enigmatic. Using sensitive sequence analysis and structure modeling, we establish that the Wnts are part of a vast assemblage of domains, the Lipocone superfamily, defined here for the first time.

View Article and Find Full Text PDF