Adversarial Purification Using Super-Resolution and Prompt Engineering
摘要
Adversarial purification using generative models has shown strong defense capabilities but often suffers from high computational costs. Recent advances in diffusion and score-based models have improved image generation, offering new opportunities for efficient defenses. One promising approach, language-guided adversarial purification, combines pre-trained diffusion models with caption generators. However, its effectiveness is limited by the accuracy of large language models, which can be inconsistent across varied inputs. To address this, we propose a method that integrates super-resolution preprocessing to enhance the language-guided purification process. By reconstructing images at higher resolution, our approach sharpens key features, reduces noise, and improves the quality of text prompts used to guide the diffusion model. Experiments show that, compared to existing methods, our approach achieves over 10% higher robustness against adversarial attacks while keeping computational demands low. This work introduces a promising direction for strengthening adversarial defenses and paves the way for further research in this area.