SpectralDefense: Detecting Adversarial Attacks on CNNs in the Fourier Domain

Despite the success of convolutional neural networks (CNNs) in many computer\nvision and image analysis tasks, they remain vulnerable against so-called\nadversarial attacks: Small, crafted perturbations in the input images can lead\nto false predictions. A possible defense is to detect adversarial examples. In\nthis work, we show how analysis in the Fourier domain of input images and\nfeature maps can be used to distinguish benign test samples from adversarial\nimages. We propose two novel detection methods: Our first method employs the\nmagnitude spectrum of the input images to detect an adversarial attack. This\nsimple and robust classifier can successfully detect adversarial perturbations\nof three commonly used attack methods. The second method builds upon the first\nand additionally extracts the phase of Fourier coefficients of feature-maps at\ndifferent layers of the network. With this extension, we are able to improve\nadversarial detection rates compared to state-of-the-art detectors on five\ndifferent attack methods.\n

Paper

Similar papers

© 2026 NYSGPT2525 LLC