1+1>2: A Dual-Function Defense Framework for Adversarial Example Mitigation

Rui Yang, Qindong Sun, Han Cao, Chao Qun Shen, Jiaming Cai, Dongzhu Rong · IEEE Transactions on Information Forensics and Security · 2025

Current state-of-the-art plug-and-play countermeasures for mitigating adversarial examples (i.e., purification and detection) exhibit several fatal limitations, impeding their deployment in safety-critical real-world applications. These limitations include susceptibility to adaptive attacks, adverse impact on benign samples, high time consumption for conducting a complete defense cycle, etc. To bridge the gap, developing more advanced plug-and-play countermeasures is urgently needed to safeguard these applications. Specifically, this paper first proposes a novel method named Gaussian-augmented GAN-based Adversarial Purification (GA-GAP). Unlike previous methods, GA-GAP enhances the density of the training data in low-robustness regions by using random Gaussian noise. Moreover, GA-GAP incorporates a pre-trained deep learning classifier into the training architecture and integrates its classification loss into the training loss function. Then, following the development of GA-GAP, this paper innovatively proposes a dual-function defense framework named Adversarial Detection on Purification (ADoP) to mitigate adversarial examples further. In ADoP, purification and detection complement each other, achieving the effect of$\mathbf {1+1\gt 2}$, which can more efficiently avoid adaptive attacks. Extensive experiments on ImageNet demonstrate that ADoP outperforms other countermeasures in multiple aspects. These aspects include superior generalization capability in purifying and detecting various adversarial examples, less adverse impact on benign samples, and practical time consumption for conducting a complete defense cycle.

Read the paper · More papers on PaperTik