Skip to content

Frame the adversary: a structure-aware attack methodology

Sep 2026 · 0 citations · 48 references
Computer Science

TL;DR

This paper proposes a methodology for crafting principled frequency-based adversarial attacks, via a dedicated optimization framework, and proves that the attacks emerge as weighted $\ell_2$-projections onto this set, yielding a general and controlled attack generation mechanism.

Abstract

Frequency-based adversarial attacks have recently grown popular by exploiting spectral sensitivities shared across neural architectures. Unlike spatial perturbations, frequency-based attacks expose deeper vulnerabilities, making them especially valuable for robust evaluation of safety-critical and security-sensitive applications. Yet, existing approaches are typically not derived as solutions to an optimization problem that explicitly captures transform-domain structure. In this paper, we propose a methodology for crafting principled frequency-based adversarial attacks, via a dedicated optimization framework. A cornerstone of our method hinges on the introduction of a perturbation constraint set, tied to highly structured non-orthogonal transforms, well-known for their flexible, non-predefined frequency handling. We prove that the attacks emerge as weighted $\ell_2$-projections onto this set, yielding a general and controlled attack generation mechanism. By this, we provide a clear geometric attack characterization, ensuring alignment between the optimization objective and the perturbation constraint. We assess our framework on standardized datasets, for pretrained and adversarially robust models. Results highlight that our attacks, being solutions to an optimization problem, over a structured perturbation set, are highly effective, even across different, unseen architectures. Our methodology could serve as a theoretical baseline for designing and analyzing transformed-based attacks, targeting fundamental model vulnerabilities, instead of mere architecture-specific artifacts typically studied in the robustness literature.

View source

Similar papers

2026

WPEBA: A Novel Ensemble Black-Box Adversarial Attack for Visual Recognition Systems via Wavelet Packet Decomposition

Understanding adversarial attacks is crucial for the secure deployment of visual recognition systems. While ensemble attacks combine the strengths of transfer-based and query-based methods to generate highly transferable adversarial examples, their practicality is often limited in real-world scenarios where the number...

Zhun Zhang, Jian Wang, Shi-Ze Guo et al. · 0 citations
Sep 2026

Toward Improving Stochastic Neural Network Robustness via Arbitrary Distribution Injection.

Adversarial attacks pose significant challenges to the security and robustness of deep-learning models. Stochastic neural networks (SNNs) have shown promising effectiveness in improving robustness by injecting stochastic noise into model activations, features, or weights. However, most existing SNN-based defenses rely...

Rui Zhou, Hao Yang, Wen-Xu Wang et al. · 0 citations
Sep 2026

A Diffusion Prior-based Framework for Imperceptible and Flexible Unrestricted Adversarial Attacks.

Unrestricted Adversarial Examples (UAEs) pose a growing security challenge to Deep Neural Networks by introducing substantial, semantically natural modifications to images. While current diffusion-based methods improve the naturalness of UAEs, they suffer from two key limitations: an underutilization of the diffusion m...

Zhen-Zhao Pan, Xiao-Gang Zhang, Hua Chen et al. · 0 citations
Open access Sep 2026

PatchGuard-Freq: Zero-Overhead Adversarial Patch Defense via Frequency Detection and Data-Driven Robustness

This work characterizes the complementary relationship between reconstruction-based and robustness-based paradigms in the accuracy–efficiency design space under the evaluated conditions: the former suits compute-unconstrained scenarios while the latter serves latency-constrained deployments.

De-Jie Luan, Cheng-Hua Li, Chun-Jie Zhang et al. · 0 citations
Conference Open access Sep 2026

Adversarial Optimization Scheme for Threat Detection Based on Hierarchical Oracle Supervision

This study introduces an adversarial training optimization framework that incorporates hierarchical label encoding and prompt learning, designed to enhance model robustness and generalization in threat detection.

Yi-Qing Luo, Ming-Shu He, Xiao-Juan Wang · 0 citations

Related blog posts

MIT News · Artificial Intelligence Oct 7, 2026

Discovering the value of humanistic inquiry

Students in MIT’s Concourse program delve deeply into the human condition, debate challenging questions, and learn to develop judgment about issues that can’t be quantified.

Microsoft Research Blog Oct 7, 2026

Agent Lightning v1.0: A 3,500-Line Lightweight Agentic RL Framework for Training Agents with Real Harnesses

Training AI agents with reinforcement learning can be challenging because their tools, context, and decision-making are managed by complex frameworks. Agent Lightning connects existing agents to RL training, making it easier to improve them without rebuilding them. The post Agent Lightning v1.0: A 3,500-Line Lightweight Agentic RL Framework for Training Agents with Real Harnesses appeared first on Microsoft Research.

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.