This paper proposes a methodology for crafting principled frequency-based adversarial attacks, via a dedicated optimization framework, and proves that the attacks emerge as weighted $\ell_2$-projections onto this set, yielding a general and controlled attack generation mechanism.
Abstract
Frequency-based adversarial attacks have recently grown popular by exploiting spectral sensitivities shared across neural architectures. Unlike spatial perturbations, frequency-based attacks expose deeper vulnerabilities, making them especially valuable for robust evaluation of safety-critical and security-sensitive applications. Yet, existing approaches are typically not derived as solutions to an optimization problem that explicitly captures transform-domain structure. In this paper, we propose a methodology for crafting principled frequency-based adversarial attacks, via a dedicated optimization framework. A cornerstone of our method hinges on the introduction of a perturbation constraint set, tied to highly structured non-orthogonal transforms, well-known for their flexible, non-predefined frequency handling. We prove that the attacks emerge as weighted $\ell_2$-projections onto this set, yielding a general and controlled attack generation mechanism. By this, we provide a clear geometric attack characterization, ensuring alignment between the optimization objective and the perturbation constraint. We assess our framework on standardized datasets, for pretrained and adversarially robust models. Results highlight that our attacks, being solutions to an optimization problem, over a structured perturbation set, are highly effective, even across different, unseen architectures. Our methodology could serve as a theoretical baseline for designing and analyzing transformed-based attacks, targeting fundamental model vulnerabilities, instead of mere architecture-specific artifacts typically studied in the robustness literature.
Understanding adversarial attacks is crucial for the secure deployment of visual recognition systems. While ensemble attacks combine the strengths of transfer-based and query-based methods to generate highly transferable adversarial examples, their practicality is often limited in real-world scenarios where the number...
Zhun Zhang, Jian Wang, Shi-Ze Guo et al.· IEEE Transactions on Informa...· 0 citations
Adversarial attacks pose significant challenges to the security and robustness of deep-learning models. Stochastic neural networks (SNNs) have shown promising effectiveness in improving robustness by injecting stochastic noise into model activations, features, or weights. However, most existing SNN-based defenses rely...
Rui Zhou, Hao Yang, Wen-Xu Wang et al.· IEEE Transactions on Neural...· 0 citations
Unrestricted Adversarial Examples (UAEs) pose a growing security challenge to Deep Neural Networks by introducing substantial, semantically natural modifications to images. While current diffusion-based methods improve the naturalness of UAEs, they suffer from two key limitations: an underutilization of the diffusion m...
Zhen-Zhao Pan, Xiao-Gang Zhang, Hua Chen et al.· IEEE Transactions on Pattern...· 0 citations
This work characterizes the complementary relationship between reconstruction-based and robustness-based paradigms in the accuracy–efficiency design space under the evaluated conditions: the former suits compute-unconstrained scenarios while the latter serves latency-constrained deployments.
This study introduces an adversarial training optimization framework that incorporates hierarchical label encoding and prompt learning, designed to enhance model robustness and generalization in threat detection.
Yi-Qing Luo, Ming-Shu He, Xiao-Juan Wang· Proceedings of the Thirty-Fi...· 0 citations
Exploring how generative AI could make machine vision more accessible to businesses. The post GenEye in a Box: Making Machine Vision Something You Can Just Ask For appeared first on GPT-Lab.
MIT News · Artificial Intelligence· news.mit.eduOct 7, 2026
Students in MIT’s Concourse program delve deeply into the human condition, debate challenging questions, and learn to develop judgment about issues that can’t be quantified.
Training AI agents with reinforcement learning can be challenging because their tools, context, and decision-making are managed by complex frameworks. Agent Lightning connects existing agents to RL training, making it easier to improve them without rebuilding them. The post Agent Lightning v1.0: A 3,500-Line Lightweight Agentic RL Framework for Training Agents with Real Harnesses appeared first on Microsoft Research.
MIT News · Artificial Intelligence· news.mit.eduOct 6, 2026