PRESS-NEWS.org - Press Release Distribution
PRESS RELEASES DISTRIBUTION

Stress-testing AI vision systems: Rethinking how adversarial images are generated

Researchers develop a new frequency-aware approach to crafting adversarial noise that better matches human visual perception

2026-01-23
(Press-News.org)

Deep neural networks (DNNs) have become a cornerstone of modern AI technology, driving a thriving field of research in image-related tasks. These systems have found applications in medical diagnosis, automated data processing, computer vision, and various forms of industrial automation, to name a few. As our reliance on AI models grows, so does our need to test them thoroughly using adversarial examples. Simply put, adversarial examples are images that have been strategically modified with noise to trick an AI into making a mistake. Understanding adversarial image generation techniques is essential for identifying vulnerabilities in DNNs and for developing more secure, reliable systems.

Despite their importance, current techniques for creating adversarial examples have significant limitations. Scientists have mainly focused on making the added noise mathematically small through a constraint known as the Lp-norm. While this keeps the changes subtle, it often results in grainy artifacts that look unnatural because they do not match the textures of the original image. Consequently, even if the noise is small and difficult to see, it can be easily detected and blocked by security pre-filters that look for unusual frequency patterns. A notable challenge in this field thus lies in moving beyond just minimizing the amount of noise and instead crafting adversarial attacks that are even more subtle.

Against this backdrop, doctoral student Masatomo Yoshida and Professor Masahiro Okuda from the Graduate School of Science and Engineering, Doshisha University, Japan, have developed a method to align additive noise in adversarial examples with the “spectral shape” of the image. Their study, published in Volume 13 of the journal IEEE Access on December 24, 2025, introduces an innovative framework called Input-Frequency Adaptive Adversarial Perturbation (IFAP).

Unlike previous frequency-aware methods that only manipulated specific frequency bands, IFAP uses a new spectral envelope constraint. This allows the added noise to adaptively match the entire frequency distribution of the input image, ensuring the perturbation is spectrally faithful to the original content.

The researchers tested IFAP across diverse datasets, including house numbers, general objects, and complex textures like terrain and fabrics. To assess its performance, they used a comprehensive set of metrics, including a new one they developed called Frequency Cosine Similarity (Freq_Cossim). Whereas standard metrics usually check for pixel-level errors, Freq_Cossim specifically measures how well the shape of the noise’s spectral profile frequency matches that of the original image.

The results showed that IFAP significantly outperformed existing adversarial generation techniques in structural and textural similarity to the source material. Despite being more visually natural and subtle, the adversarial attack remained highly effective, successfully fooling a wide range of AI architectures. Interestingly, the researchers also demonstrated that these harmonized perturbations are more resilient to common image-cleaning techniques, such as JPEG compression or blurring. Because the noise is so well-integrated into the natural textures of the image, it is much harder for simple transformations to eliminate it without significantly altering the image itself.

IFAP has important implications for how adversarial examples are used in AI research. By understanding how to create noise that is consistent with human perception, researchers can implement better adversarial attacks to stress-test and retrain AI models to be more robust. “We believe our work could lead to the development of highly reliable AI models for fields such as medical diagnosis, which will not be confused by slight changes in image quality or noise,” says Prof. Okuda.

Looking ahead, this study sets a new benchmark for how we evaluate AI safety and performance in image-centered tasks. “Evaluation criteria that emphasize consistency with human perception and frequency characteristics, as our research proposes, may become more common in the next 5 to 10 years,” concludes Prof. Okuda. “This shift will likely raise the reliability of AI systems that support important infrastructures of society, such as medical care and transportation.”

About Masatomo Yoshida from Doshisha University, Japan
Masatomo Yoshida received his B.E. and M.E. degrees from Doshisha University, Japan, in 2021 and 2023, respectively. He is currently pursuing a Ph.D. degree in Engineering at the Graduate School of Science and Engineering, Doshisha University. He is also a Research Fellow with the Japan Society for the Promotion of Science (JSPS) and has received a JST SPRING (Support for Pioneering Research Initiated by the Next Generation) Scholarship. His research interests include analyzing spatio-temporal time-series data, image processing, deep learning, and adversarial examples.

About Masahiro Okuda from Doshisha University, Japan
Masahiro Okuda (Senior Member, IEEE) received the B.E., M.E., and Dr.-Eng. degrees from Keio University, Yokohama, Japan, in 1993, 1995, and 1998, respectively. From 1996 to 2000, he was a Research Fellow with Japan Society for the Promotion of Science. He was with the University of California at Santa Barbara, Santa Barbara, CA, USA, and Carnegie Mellon University, Pittsburgh, PA, USA, as a Visiting Scholar, in 1998 and 1999, respectively. From 2000 to 2020, he was with the Faculty of Environmental Engineering, The University of Kitakyushu, Kitakyushu, Japan. He is currently a Professor with the Faculty of Science and Engineering, Doshisha University. His research interests include image restoration, high dynamic range imaging, multiple image fusion, and digital filter design. He received the SIP Distinguished Contribution Award, in 2013, the IE Award, and the Contribution Award from IEICE, in 2017.

Funding information
This work was supported in part by Japan Society for the Promotion of Science (JSPS) KAKENHI under Grant 25KJ2207 and Grant 23K11174, and in part by Japan Science and Technology Agency (JST) Support for Pioneering Research Initiated by the Next Generation (SPRING) under Grant JPMJSP2129.

Media contact:
Organization for Research Initiatives & Development
Doshisha University
Kyotanabe, Kyoto 610-0394, Japan
E-mail:jt-ura@mail.doshisha.ac.jp

END



ELSE PRESS RELEASES FROM THIS DATE:

Why a crowded office can be the loneliest place on earth

2026-01-23
A comprehensive new review published in the Journal of Management synthesizes decades of research to understand the epidemic of workplace loneliness. By analyzing 233 empirical studies, researchers from Portland State University have identified how workplace conditions contribute to isolation and offer evidence-based paths to reconnection. The research emphasizes that loneliness is distinct from social isolation. While isolation is about being alone, loneliness is the subjective feeling that one’s social relationships are deficient—meaning ...

Choosing the right biochar can lock toxic cadmium in soil, study finds

2026-01-23
Cadmium contamination in agricultural soils is a growing global concern, threatening food safety, crop productivity, and human health. New research shows that not all biochars work the same way and that choosing the right type of biochar can make the difference between trapping toxic metals in soil or unintentionally making them more mobile. In a study published online on January 15, 2026, researchers report that biochar produced at high temperatures can work together with soil microbes to effectively immobilize cadmium, one of the most hazardous heavy metals found in farmland ...

Desperate race to resurrect newly-named zombie tree

2026-01-23
A recently identified tree species in Australia has been given the name ‘zombie’ by scientists who say ambitious assistance is needed to reverse its ‘living dead’ status. University of Queensland botanist Professor Rod Fensham said it was a race against time to save Rhodamnia zombi from the fungal disease myrtle rust. “This species did not have a name when it was first assessed in 2020, and since then 10 per cent of the trees have died and none of those remaining are producing flowers or fruit because of myrtle rust,” ...

New study links combination of hormone therapy and tirzepatide to greater weight loss after menopause

2026-01-23
JACKSONVILLE, Fla. — A new study led by Mayo Clinic found that postmenopausal women receiving menopausal hormone therapy lost 35% more weight while taking tirzepatide, a Food and Drug Administration-approved drug for the treatment of overweight and obesity. The findings, published in The Lancet Obstetrics, Gynaecology, & Women's Health, could expand treatment possibilities for millions of women struggling with obesity and obesity-related diseases after menopause. Menopause can accelerate age-related weight gain and increase the likelihood of developing overweight and obesity, which are major risk factors for cardiovascular ...

How molecules move in extreme water environments depends on their shape

2026-01-23
Water behaves in remarkable ways when heated and pressurized beyond its critical point. Under these extreme conditions, known as supercritical water, it no longer acts like an ordinary liquid. Instead, it takes on properties similar to organic solvents, dissolving hydrocarbons efficiently and transporting molecules rapidly. These unique features make supercritical water a promising green medium for energy conversion technologies such as biomass gasification, plastic recycling, and in situ fuel extraction. Yet many of these reactions occur inside extremely ...

Early-life exposure to a common pollutant harms fish development across generations

2026-01-23
A widely distributed environmental pollutant can leave lasting biological scars that persist long after direct exposure has ended, according to a new study that tracked its effects across multiple generations of fish. Researchers found that brief exposure to benzo[a]pyrene, a toxic compound produced by fossil fuel combustion and industrial activity, disrupted normal development and skeletal health not only in directly exposed fish but also in their unexposed descendants. The study reveals that these long-term effects are driven by persistent changes in metabolism, shedding new light on how ...

How is your corn growing? Aerial surveillance provides answers

2026-01-22
With already thin profit margins and increasingly uncertain farm labor and other input costs, precision agriculture technology could improve New England’s small and medium-sized farms’ efficiency, productivity, and resilience. Unfortunately, factors such as up-front costs and validation of the technology’s accuracy in the region remain a barrier to adoption. A research team at UNH led by Benjamin Fraser, visiting assistant professor and director of the Basic and Applied Spatial Analysis ...

Center for BrainHealth launches Fourth Annual BrainHealth Week in 2026

2026-01-22
Center for BrainHealth, a global leader in brain health research and its practical application, announces its fourth annual BrainHealth Week, February 23–28, 2026. The week-long conference features a diverse lineup of events designed to educate and inspire people of all ages to take action for better brain health. As brain health takes center stage at global forums like Davos and the UN General Assembly, BrainHealth Week 2026, presented by Ciridian, marks a pivotal moment in cognitive neuroscience. This event brings together world-renowned neuroscientists and brain performance experts to translate breakthrough research into "brain gains." ...

Why some messages are more convincing than others

2026-01-22
What kinds of marketing messages are effective — and what makes people believe certain political slogans more than others? New research from the University of California San Diego Rady School of Management explores how people constantly evaluate whether messages are true or false and finds that a surprisingly small ingredient — whether a word has an easy opposite — can shape how confident people feel when deciding whether a message is true. “Effective messaging isn’t just about ...

National Foundation for Cancer Research CEO Sujuan Ba Named One of OncoDaily’s 100 Most Influential Oncology CEOs of 2025

2026-01-22
Washington, D.C. | 22 January 2026 – Sujuan Ba, CEO of the National Foundation for Cancer Research (NFCR), has been named to OncoDaily’s list of the 100 Most Influential CEOs in Oncology in 2025, recognizing leaders whose work is shaping the global cancer research and care ecosystem. The annual list honors chief executives across industry, academia, policy, healthcare systems, and mission-driven organizations whose leadership has driven measurable and lasting impact in oncology worldwide. Dr. Ba is recognized alongside leaders from major cancer centers, biopharmaceutical companies, research institutions, ...

LAST 30 PRESS RELEASES:

New strategies boost effectiveness of CAR-NK therapy against cancer

Study: Adolescent cannabis use linked to doubling risk of psychotic and bipolar disorders

Invisible harms: drug-related deaths spike after hurricanes and tropical storms

Adolescent cannabis use and risk of psychotic, bipolar, depressive, and anxiety disorders

Anxiety, depression, and care barriers in adults with intellectual and developmental disabilities

Study: Anxiety, gloom often accompany intellectual deficits

Massage Therapy Foundation awards $300,000 research grant to the University of Denver

Gastrointestinal toxicity linked to targeted cancer therapies in the United States

Countdown to the Bial Award in Biomedicine 2025

Blood marker from dementia research could help track aging across the animal world

Birds change altitude to survive epic journeys across deserts and seas

Here's why you need a backup for the map on your phone

ACS Central Science | Researchers from Insilico Medicine and Lilly publish foundational vision for fully autonomous “Prompt-to-Drug” pharmaceutical R&D

Increasing the number of coronary interventions in patients with acute myocardial infarction does not appear to reduce death rates

Tackling uplift resistance in tall infrastructures sustainably

Novel wireless origami-inspired smart cushioning device for safer logistics

Hidden genetic mismatch, which triples the risk of a life-threatening immune attack after cord blood transplantation

Physical function is a crucial predictor of survival after heart failure

Striking genomic architecture discovered in embryonic reproductive cells before they start developing into sperm and eggs

Screening improves early detection of colorectal cancer

New data on spontaneous coronary artery dissection (SCAD) – a common cause of heart attacks in younger women

How root growth is stimulated by nitrate: Researchers decipher signalling chain

Scientists reveal our best- and worst-case scenarios for a warming Antarctica

Cleaner fish show intelligence typical of mammals

AABNet and partners launch landmark guide on the conservation of African livestock genetic resources and sustainable breeding strategies

Produce hydrogen and oxygen simultaneously from a single atom! Achieve carbon neutrality with an 'All-in-one' single-atom water electrolysis catalyst

Sleep loss linked to higher atrial fibrillation risk in working-age adults

Visible light-driven deracemization of α-aryl ketones synergistically catalyzed by thiophenols and chiral phosphoric acid

Most AI bots lack basic safety disclosures, study finds

How competitive gaming on discord fosters social connections

[Press-News.org] Stress-testing AI vision systems: Rethinking how adversarial images are generated
Researchers develop a new frequency-aware approach to crafting adversarial noise that better matches human visual perception