<p>Robust image classifiers, which are designed to resist adversarial perturbations, are increasingly used in safety–critical visual computing applications, yet their reliability is difficult to assess when defence mechanisms produce smooth or weak spatial gradients. Such gradient-masking effects, where optimization gradients become less informative, may cause conventional spatial-domain adversarial attacks to underestimate model vulnerability, particularly in transfer-based black-box settings. This paper introduces an adaptive spatial–frequency guidance framework for adversarial evaluation of robust image classifiers. The method projects spatial gradients into the frequency domain to identify model-sensitive spectral regions, constructs an adaptive sensitivity mask, and uses the selected frequency responses as guidance signals for spatial perturbation optimisation. Instead of treating frequency perturbation as an independent attack branch, the proposed framework reintegrates frequency-derived residual cues into the spatial update process. A collaborative vector calibration mechanism further decouples update magnitude from direction, allowing frequency guidance to adjust the perturbation trajectory while maintaining norm-bounded constraints. Experiments on ImageNet-1&#xa0;K and Tiny-ImageNet include both white-box and transfer-based black-box scenarios across representative robust architectures. The results indicate that the proposed spatial–frequency interaction improves attack success rate and transferability compared with spatial, frequency, and hybrid baselines, while maintaining comparable perceptual quality. The study provides evidence that dynamic frequency guidance can help reveal vulnerabilities that may be obscured by spatial-gradient smoothing, and offers a practical direction for more reliable adversarial evaluation of robust vision models. Our code is available at (<a href="https://github.com/baishanyuan/ASFG">https://github.com/baishanyuan/ASFG</a>).</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Adaptive spatial–frequency guidance for transferable adversarial evaluation of robust visual classifiers

  • Shanyuan Bai,
  • Huiyan Han,
  • Runbo Yang,
  • Yaming Cao

摘要

Robust image classifiers, which are designed to resist adversarial perturbations, are increasingly used in safety–critical visual computing applications, yet their reliability is difficult to assess when defence mechanisms produce smooth or weak spatial gradients. Such gradient-masking effects, where optimization gradients become less informative, may cause conventional spatial-domain adversarial attacks to underestimate model vulnerability, particularly in transfer-based black-box settings. This paper introduces an adaptive spatial–frequency guidance framework for adversarial evaluation of robust image classifiers. The method projects spatial gradients into the frequency domain to identify model-sensitive spectral regions, constructs an adaptive sensitivity mask, and uses the selected frequency responses as guidance signals for spatial perturbation optimisation. Instead of treating frequency perturbation as an independent attack branch, the proposed framework reintegrates frequency-derived residual cues into the spatial update process. A collaborative vector calibration mechanism further decouples update magnitude from direction, allowing frequency guidance to adjust the perturbation trajectory while maintaining norm-bounded constraints. Experiments on ImageNet-1 K and Tiny-ImageNet include both white-box and transfer-based black-box scenarios across representative robust architectures. The results indicate that the proposed spatial–frequency interaction improves attack success rate and transferability compared with spatial, frequency, and hybrid baselines, while maintaining comparable perceptual quality. The study provides evidence that dynamic frequency guidance can help reveal vulnerabilities that may be obscured by spatial-gradient smoothing, and offers a practical direction for more reliable adversarial evaluation of robust vision models. Our code is available at (https://github.com/baishanyuan/ASFG).