Towards a Novel Adversarial Perturbations Analysis Driven by Frequency

Zhun Zhang, Qihe Liu, Shilin Qiu · 2025

Enhancing our understanding of adversarial examples is essential for ensuring the secure application of machine learning models in real-world scenarios. A common approach for analyzing adversarial examples is through frequency-domain analysis. However, existing research has shown that attacks exploiting either low-frequency or high-frequency components can enhance attack effectiveness, leading to an unclear relationship between adversarial perturbations and their frequency components. In this paper, we propose a novel method for analyzing adversarial perturbations based on wavelet packet decomposition, providing a more comprehensive understanding of adversarial perturbations in the frequency domain. We generate a diverse adversarial perturbation dataset using FGSM and PGD, and combine wavelet theory with adversarial perturbation characteristics to select and optimize the wavelet function for frequency domain decomposition. Using wavelet packet decomposition, we transform clean and adversarial samples from the image domain to the frequency domain and conduct both one-dimensional frequency domain analyses. Experimental results reveal that adversarial perturbations cannot be simply classified into high or low-frequency components. Notably, significant adversarial perturbations are observed in high-frequency components of low-frequency bands. This study not only deepens the understanding of adversarial perturbations in the frequency domain but also provides theoretical insights that can inform the design of more effective adversarial attack and defense strategies.

Read the paper · More papers on PaperTik