Share your thoughts, 1 month free Claude Pro on usSee more
WorkDL logo mark

Exploring Adversarial Attacks against Latent Diffusion Model from the Perspective of Adversarial Transferability

About

Recently, many studies utilized adversarial examples (AEs) to raise the cost of malicious image editing and copyright violation powered by latent diffusion models (LDMs). Despite their successes, a few have studied the surrogate model they used to generate AEs. In this paper, from the perspective of adversarial transferability, we investigate how the surrogate model's property influences the performance of AEs for LDMs. Specifically, we view the time-step sampling in the Monte-Carlo-based (MC-based) adversarial attack as selecting surrogate models. We find that the smoothness of surrogate models at different time steps differs, and we substantially improve the performance of the MC-based AEs by selecting smoother surrogate models. In the light of the theoretical framework on adversarial transferability in image classification, we also conduct a theoretical analysis to explain why smooth surrogate models can also boost AEs for LDMs.

Junxi Chen, Junhao Dong, Xiaohua Xie• 2024

Related benchmarks

TaskDatasetResultRank
Mimicry DefenseTI-Dataset
FID5.27
99
Training-based Mimicry DefenseTI-Dataset, DB-Dataset, CelebA-HQ, VGGFace2, WikiArt Average
FID65.96
52
Inference-based Mimicry DefenseTI-Dataset, DB-Dataset, CelebA-HQ, VGGFace2, WikiArt Average across 5 datasets
FID160.9
26
Mimicry DefenseMimicry Datasets
FID7
15
Adversarial DefenseTI-Dataset DreamShaper
FID55.46
12
Adversarial DefenseTI-Dataset LCM
FID66.05
12
Adversarial DefenseTI-Dataset SD v1.5
FID110.3
12
Adversarial DefenseTI-Dataset SD v2.1
FID103.8
12
Adversarial DefenseTI-Dataset FLUX.1 Kontext
FID27.63
4
Adversarial DefenseTI-Dataset FLUX.2 Klein
FID19.87
4
Showing 10 of 13 rows

Other info

Follow for update