Pith. sign in

REVIEW 1 cited by

Investigating the Adversarial Robustness of Density Estimation Using the Probability Flow ODE

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2310.07084 v1 pith:O7HBE6B6 submitted 2023-10-10 cs.LG

classification cs.LG
keywords densityestimationattackssampleadversarialcomplexityflowgradient-based
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Beyond their impressive sampling capabilities, score-based diffusion models offer a powerful analysis tool in the form of unbiased density estimation of a query sample under the training data distribution. In this work, we investigate the robustness of density estimation using the probability flow (PF) neural ordinary differential equation (ODE) model against gradient-based likelihood maximization attacks and the relation to sample complexity, where the compressed size of a sample is used as a measure of its complexity. We introduce and evaluate six gradient-based log-likelihood maximization attacks, including a novel reverse integration attack. Our experimental evaluations on CIFAR-10 show that density estimation using the PF ODE is robust against high-complexity, high-likelihood attacks, and that in some cases adversarial samples are semantically meaningful, as expected from a robust estimator.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Boost-and-Skip: A Simple Guidance-Free Diffusion for Minority Generation

    cs.LG 2025-02 conditional novelty 6.0 of 10

    Starting diffusion sampling from variance-boosted noise and skipping early timesteps generates minority samples at guided-method quality with far less compute.

Pith tools