2026· IEEE Transactions on Information Forensics and Security· Vol 21, pp. 7274-7286· 0 citations· 56 references
Computer Science
Abstract
Deep learning models for point cloud classification are highly vulnerable to adversarial attacks, while recent advances in diffusion-based purification have shown promising defensive performance. However, existing diffusion-based purification methods harbor two fundamental limitations. First, a distributional gap arises from their training on clean-to-clean paths, which fails to generalize to the required adversarial-to-clean transition. Second, a semantic mismatch occurs because the fixed victim classifier cannot adapt to the decision boundaries of the purified data distribution. To address this, we propose PANDA, a two-stage framework that combines robust purification with classifier adaptation. For purification, we introduce PANDA-P, a novel dual-branch diffusion training strategy that simultaneously optimizes on both clean-to-clean and adversarial-to-clean paths. This unified formulation boosts the purification effectiveness while preserving fidelity. For adaptation, we design PANDA-A, a fine-tuning scheme that leverages a consistency-driven learning objective to reshape the classifier’s feature space and recalibrate a robust decision boundary for the purified data. Extensive experiments show that PANDA achieves consistently superior robustness over existing purification-based defenses on both synthetic and real-world benchmarks.
Deep learning has boosted remote sensing (RS) scene classification, but adversarial examples can still cause high-confidence misclassification with imperceptible perturbations. Adversarial purification (AP) offers a practical test-time defense without retraining the classifier. However, most existing methods are confined to pixel-space restoration, which may leave residual adversarial effects that persist and amplify through feature extraction, ultimately biasing the prediction. To address these issues, a dual-domain AP (DDAP) framework is proposed to mitigate adversarial effects at both the pixel and feature levels in a unified pipeline. In the pixel domain, a pixel-domain frequency-aware diffusion purification (PFDP) module performs diffusion-based restoration through a frequency-aware dual-stream U-Net (FD-UNet). By integrating adaptive spectral filtering with multidomain consistency constraints, PFDP reduces adversarial-perturbation-dominated high-frequency responses while preserving structural details and semantic information in RS imagery. In the feature domain, an adversarial vulnerable channel dropout (AVCD) strategy models unshifted shallow-feature statistics with a Gaussian mixture model (GMM) and adaptively assigns channelwise dropout probabilities based on a samplewise shift score and channel vulnerability, thereby suppressing residual adversarial influence before downstream classification. Extensive experiments on UC Merced (UCM) and aerial image dataset (AID) across multiple backbones and attack types demonstrate that DDAP consistently improves robustness while maintaining a favorable clean–robust balance compared with representative baselines.
Yuru Su, Shaohui Mei, Mingyang Ma et al.· IEEE Transactions on Geoscie...· 0 citations
This paper reveals that samples generated by a well-trained generative model are close to clean ones but far from adversarial ones, and proposes Consistency Model-based Adversarial Purification (CMAP), which optimizes vectors within the latent space of a pre-trained consistency model to generate samples for restoring clean data.
Shuhai Zhang, Jiahao Yang, Hui Luo et al.· IEEE Transactions on Pattern...· 0 citations
Federated learning is appealing for privacy-sensitive network systems, yet its practical deployment remains hindered by the following three recurring challenges: (1) client drift under non-IID data, (2) vulnerability to corrupted updates, and (3) the communication cost of repeated model exchange. Most existing approaches address these issues in isolation. While analytically convenient, this separation often fails to reflect real-world conditions. For instance, defenses against poisoning may suppress useful updates, while personalization and compression can alter the aggregation geometry itself. In this paper, we study these effects jointly and propose URP-FL, a compact training framework that integrates reliability-aware aggregation, local regularization for drift control, and sparse client uploads. We provide theoretical analysis establishing a convergence bound with distinct terms capturing optimization error, data heterogeneity, and adversarial impact. Experiments on a non-IID image classification benchmark with sign-flip and label-flip attacks demonstrate the benefits of the unified design. Compared to FedAvg and FedProx, this URP-FL maintains accuracy under attack while reducing transmitted parameters by approximately 75%. Rather than presenting a production ready system, it offers a reproducible and technically coherent step toward federated learning that is more robust under realistic conditions.
Hua Kun, Wei Wang· 2026 International Conferenc...· 0 citations
A robustness-oriented training framework that integrates Mask-Guided Adversarial Mixup (MGAM) and Adaptive Timescale Exponential Moving Average (AT-EMA) that provides a practical data-regularization strategy for improving training stability in adversarial learning is proposed.
Guo Niu, Huanlin Mo, Shengjun Deng et al.· Signal, Image and Video Proc...· 0 citations
Single domain generalization (SDG) aims to learn a model from one labeled source domain that generalizes to unseen target domains. A common strategy is to enrich the source distribution with augmented or generated samples, and recent text-to-image (T2I) diffusion models provide a strong generative prior for this purpose. However, diversity alone is insufficient for robust generalization, because useful generated samples should also capture variations that the current classifier finds difficult. Motivated by distributionally robust optimization (DRO), we define a semantic ambiguity set in the class-conditional generative space of a pretrained T2I model and search it for samples with high classification loss under the current classifier. To this end, we introduce PAPT++, a risk-aware adversarial generation-training framework for SDG. PAPT++ first learns diverse semantic reference images for each class through image-text alignment and intra-class diversity regularization. These references then serve as denoising targets during classifier-guided diffusion synthesis, reducing semantic drift while guiding generation toward challenging variations. The generated samples are combined with the source data to update the classifier, and the updated classifier guides the next synthesis round in return. In this way, PAPT++ progressively exposes the classifier to challenging yet semantically consistent variations. Extensive experiments on standard SDG benchmarks demonstrate the superiority of the proposed PAPT++ method and the effectiveness of its main components.
Zhipeng Xu, De Cheng, Xinyang Jiang et al.· 0 citations
The Krum-Proxy attack is introduced, a selection-aware backdoor injection strategy that consistently bypasses Byzantine-robust aggregation and constructs adversarial updates that are not only similar to benign updates but are also optimized to lie in regions of the update space that are favored during aggregation.
Srinivasan Subramanian, Md Abdullah Al Hafiz Khan, K. A. Islam· 2026 International Conferenc...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.