Skip to main navigation Skip to search Skip to main content

Diffusion Models are Robust Pretrainers

  • Mika Yagoda*
  • , Shady Abu-Hussein
  • , Raja Giryes
  • *Corresponding author for this work

Research output: Contribution to journalArticlepeer-review

Abstract

Diffusion models have gained significant attention for high-fidelity image generation. Our work investigates the potential of exploiting diffusion models for adversarial robustness in image classification and object detection. Adversarial attacks challenge standard models in these tasks by perturbing inputs to force incorrect predictions. To address this issue, many approaches use training schemes for forcing the robustness of the models, which increase training costs. In this work, we study models built on top of off-the-shelf diffusion models and demonstrate their practical significance: they provide a low-cost path to robust representations, allowing lightweight heads to be trained on frozen features without full adversarial training. Our empirical evaluations on ImageNet, CIFAR-10, and PASCAL VOC show that diffusion-based classifiers and detectors achieve meaningful adversarial robustness with minimal compute. While clean and adversarial accuracies remain below state-of-the-art adversarially trained CNNs or ViTs, diffusion pretraining offers a favorable tradeoff between efficiency and robustness. This work opens a promising avenue for integrating diffusion models into resource-constrained robust deployments.

Original languageEnglish
Pages (from-to)4219-4223
Number of pages5
JournalIEEE Signal Processing Letters
Volume32
DOIs
StatePublished - 2025

Funding

Funders
Israel Innovation Authority

    Keywords

    • Diffusion models
    • adversarial robustness
    • robust pretraining

    Fingerprint

    Dive into the research topics of 'Diffusion Models are Robust Pretrainers'. Together they form a unique fingerprint.

    Cite this