


Deep neural networks exhibit exceptional performance in visual classification tasks; however, their security faces significant challenges, particularly as the output results of classifiers are susceptible to malicious manipulation through adversarial attacks. To address this issue, adversarial training has rapidly developed as an effective defense mechanism. However, existing adversarial training methods predominantly rely on white-box defense strategies, which require access to the model’s structural parameters and retraining the model. This is impractical in many real-world application scenarios, especially for enhancing the robustness of large-scale pre-trained models. To solve the aforementioned problems, our faculty and students proposed a novel Bayesian energy adversarial post-training strategy, which models the joint probability distribution from an energy perspective and optimizes it using a post-training Bayesian strategy. This method does not require knowledge of the pre-trained model and can effectively enhance the model’s robustness without compromising accuracy, while significantly reducing resource overhead.
Recently, our young faculty member, Diao Yunfeng, published a high-level paper titled “A Black-Box Adversarial Defense Method Based on Bayesian Energy Adversarial Post-Training” as the first author in the CCF-recommended T1 journal ‘Science China: Information Sciences’. Our undergraduate student, Jiang Kaichao, is the second author, and Professor Guo Dan is the corresponding author. This work was completed in collaboration between Hefei University of Technology, Fudan University, and National University of Defense Technology.
Paper Overview

Paper Title:
A Black-Box Adversarial Defense Method Based on Bayesian Energy Adversarial Post-Training
Paper Authors:
Diao Yunfeng, Jiang Kaichao, Guo Dan, Liang Zhenyu, Shi Zenglin, Qian Zhenxing, Wang Meng
Paper Link:
https://doi.org/10.1360/SSI-2024-0326

Figure 1: Schematic Diagram of the Bayesian Energy Adversarial Post-Training Framework

Table 1: Performance Comparison of APLT with Traditional Semi-Supervised Methods

Figure 2 (Left): Robustness Comparison Using ResNet-18 on the ImageNet Subset; (Right): Robustness Comparison Using WideResnet28-10 under Different EOT-PGD Attack Disturbances on CIFAR10
To address the challenges posed by existing adversarial training methods that rely on white-box defense strategies and sacrifice model accuracy for robustness enhancement, making them difficult to apply to large-scale pre-trained models and high-accuracy classification tasks, this paper proposes a novel Bayesian energy adversarial post-training strategy. This strategy models the joint probability distribution of clean sample distribution, adversarial sample distribution, and model parameter distribution, achieving a fully Bayesian treatment of data and models. Simultaneously, this method employs a post-training Bayesian strategy for optimization, attaching a small-scale Bayesian model unit behind the frozen pre-trained model and only performing robust optimization on that unit. This method not only preserves the integrity of the pre-trained model but also significantly reduces resource overhead, providing greater flexibility in practical applications. To evaluate the robustness performance of the model, this paper assesses the defense performance against a total of 13 adversarial attack methods across 3 datasets and 4 baseline models. Extensive experimental results demonstrate that this method can significantly enhance robustness against both gradient-based white-box adversarial attacks and black-box adversarial attacks while maintaining the original accuracy of the model, with robustness even surpassing existing white-box defense methods. Particularly under extreme conditions of high disturbance intensity, this method shows significant robustness advantages over existing adversarial training methods.
‘Science China: Information Sciences’ is an academic journal co-sponsored by the Chinese Academy of Sciences and the National Natural Science Foundation of China, aiming to publish the highest academic level articles in the field of information science. It is recommended as an A/T1 journal by the China Computer Federation (CCF), the Chinese Association of Automation (CAA), the China Communications Society (CIC), and the Chinese Association for Artificial Intelligence (CAAI).
E
N
D

Source: Hefei University of Technology School of Computer Science and Information Engineering WeChat Official Account
Recommended Reading
- “Cybersecurity + Law” Dual Degree | How Nankai University, Southeast University, and Chongqing University of Posts and Telecommunications Accelerate on New TracksRun
- Chip Security Vulnerabilities Hard to Detect? See How Xi’an University of Technology’s “Abstract Fourth Power” Solves Chip Security Issues
- Interview ยท University of Science and Technology of China | Deepfake Detection Ranks Second Globally, Multiple Top Conference Achievements, How This Team Achieved Real-World Applications in 5 Years
- Under the “Five-Color Stone” Plan, Southeast University’s Innovative Talent Training Model in Cybersecurity Revealed
- Protecting Voice Security: How the Huazhong University of Science and Technology CPSS Team Built an Anti-Deepfake System to Win the Creative Works Competition Championship?
- New Paradigm for Practical Cybersecurity Talent Training: How Shanghai Jiao Tong University, Jinan University, and Hunan University Transform Models to Cultivate Practical Cybersecurity Talent
- Career Planning Competition, Helping Cybersecurity Major Students Win at the Starting Line
- Guide to Surviving Top Conference Papers: Insights from Reviewers on Cybersecurity Top Conferences | Complete Review Process of IEEE S&P
-
Conducting Research, Reading “Classics”! See How Young Faculty from the University of Science and Technology of China, Southeast University, Nankai University, and Lanzhou University Unearth New Angles to Impress Reviewers in the Field of Cybersecurity
-
Inspiration for Papers! From “Unrelated” to “Tightly Integrated”, Sharing Experiences of Cross-Disciplinary Knowledge Transfer Applications

Information Network Security
‘Information Network Security’ was founded in 2001, supervised by the Ministry of Public Security, co-sponsored by the Third Research Institute of the Ministry of Public Security and the China Computer Federation, and is one of the first domestic information security journals published both domestically and internationally. It became a core journal of Chinese science and technology in 2015, a source journal of the Chinese Science Citation Database in 2017, a core journal in Chinese in 2018, and was included in the CCF high-quality technology journal grading directory in 2022.
Chinese Core Journal
Core Journal of Chinese Science and Technology
Source Journal of the Chinese Science Citation Database
CCF High-Quality Technology Journal in Computing

We are continuously striving for improvement and look forward to your attention and support!