PRESS-NEWS.org - Press Release Distribution
PRESS RELEASES DISTRIBUTION

Stress-testing AI vision systems: Rethinking how adversarial images are generated

Researchers develop a new frequency-aware approach to crafting adversarial noise that better matches human visual perception

2026-01-23
(Press-News.org)

Deep neural networks (DNNs) have become a cornerstone of modern AI technology, driving a thriving field of research in image-related tasks. These systems have found applications in medical diagnosis, automated data processing, computer vision, and various forms of industrial automation, to name a few. As our reliance on AI models grows, so does our need to test them thoroughly using adversarial examples. Simply put, adversarial examples are images that have been strategically modified with noise to trick an AI into making a mistake. Understanding adversarial image generation techniques is essential for identifying vulnerabilities in DNNs and for developing more secure, reliable systems.

Despite their importance, current techniques for creating adversarial examples have significant limitations. Scientists have mainly focused on making the added noise mathematically small through a constraint known as the Lp-norm. While this keeps the changes subtle, it often results in grainy artifacts that look unnatural because they do not match the textures of the original image. Consequently, even if the noise is small and difficult to see, it can be easily detected and blocked by security pre-filters that look for unusual frequency patterns. A notable challenge in this field thus lies in moving beyond just minimizing the amount of noise and instead crafting adversarial attacks that are even more subtle.

Against this backdrop, doctoral student Masatomo Yoshida and Professor Masahiro Okuda from the Graduate School of Science and Engineering, Doshisha University, Japan, have developed a method to align additive noise in adversarial examples with the “spectral shape” of the image. Their study, published in Volume 13 of the journal IEEE Access on December 24, 2025, introduces an innovative framework called Input-Frequency Adaptive Adversarial Perturbation (IFAP).

Unlike previous frequency-aware methods that only manipulated specific frequency bands, IFAP uses a new spectral envelope constraint. This allows the added noise to adaptively match the entire frequency distribution of the input image, ensuring the perturbation is spectrally faithful to the original content.

The researchers tested IFAP across diverse datasets, including house numbers, general objects, and complex textures like terrain and fabrics. To assess its performance, they used a comprehensive set of metrics, including a new one they developed called Frequency Cosine Similarity (Freq_Cossim). Whereas standard metrics usually check for pixel-level errors, Freq_Cossim specifically measures how well the shape of the noise’s spectral profile frequency matches that of the original image.

The results showed that IFAP significantly outperformed existing adversarial generation techniques in structural and textural similarity to the source material. Despite being more visually natural and subtle, the adversarial attack remained highly effective, successfully fooling a wide range of AI architectures. Interestingly, the researchers also demonstrated that these harmonized perturbations are more resilient to common image-cleaning techniques, such as JPEG compression or blurring. Because the noise is so well-integrated into the natural textures of the image, it is much harder for simple transformations to eliminate it without significantly altering the image itself.

IFAP has important implications for how adversarial examples are used in AI research. By understanding how to create noise that is consistent with human perception, researchers can implement better adversarial attacks to stress-test and retrain AI models to be more robust. “We believe our work could lead to the development of highly reliable AI models for fields such as medical diagnosis, which will not be confused by slight changes in image quality or noise,” says Prof. Okuda.

Looking ahead, this study sets a new benchmark for how we evaluate AI safety and performance in image-centered tasks. “Evaluation criteria that emphasize consistency with human perception and frequency characteristics, as our research proposes, may become more common in the next 5 to 10 years,” concludes Prof. Okuda. “This shift will likely raise the reliability of AI systems that support important infrastructures of society, such as medical care and transportation.”

About Masatomo Yoshida from Doshisha University, Japan
Masatomo Yoshida received his B.E. and M.E. degrees from Doshisha University, Japan, in 2021 and 2023, respectively. He is currently pursuing a Ph.D. degree in Engineering at the Graduate School of Science and Engineering, Doshisha University. He is also a Research Fellow with the Japan Society for the Promotion of Science (JSPS) and has received a JST SPRING (Support for Pioneering Research Initiated by the Next Generation) Scholarship. His research interests include analyzing spatio-temporal time-series data, image processing, deep learning, and adversarial examples.

About Masahiro Okuda from Doshisha University, Japan
Masahiro Okuda (Senior Member, IEEE) received the B.E., M.E., and Dr.-Eng. degrees from Keio University, Yokohama, Japan, in 1993, 1995, and 1998, respectively. From 1996 to 2000, he was a Research Fellow with Japan Society for the Promotion of Science. He was with the University of California at Santa Barbara, Santa Barbara, CA, USA, and Carnegie Mellon University, Pittsburgh, PA, USA, as a Visiting Scholar, in 1998 and 1999, respectively. From 2000 to 2020, he was with the Faculty of Environmental Engineering, The University of Kitakyushu, Kitakyushu, Japan. He is currently a Professor with the Faculty of Science and Engineering, Doshisha University. His research interests include image restoration, high dynamic range imaging, multiple image fusion, and digital filter design. He received the SIP Distinguished Contribution Award, in 2013, the IE Award, and the Contribution Award from IEICE, in 2017.

Funding information
This work was supported in part by Japan Society for the Promotion of Science (JSPS) KAKENHI under Grant 25KJ2207 and Grant 23K11174, and in part by Japan Science and Technology Agency (JST) Support for Pioneering Research Initiated by the Next Generation (SPRING) under Grant JPMJSP2129.

Media contact:
Organization for Research Initiatives & Development
Doshisha University
Kyotanabe, Kyoto 610-0394, Japan
E-mail:jt-ura@mail.doshisha.ac.jp

END



ELSE PRESS RELEASES FROM THIS DATE:

Why a crowded office can be the loneliest place on earth

2026-01-23
A comprehensive new review published in the Journal of Management synthesizes decades of research to understand the epidemic of workplace loneliness. By analyzing 233 empirical studies, researchers from Portland State University have identified how workplace conditions contribute to isolation and offer evidence-based paths to reconnection. The research emphasizes that loneliness is distinct from social isolation. While isolation is about being alone, loneliness is the subjective feeling that one’s social relationships are deficient—meaning ...

Choosing the right biochar can lock toxic cadmium in soil, study finds

2026-01-23
Cadmium contamination in agricultural soils is a growing global concern, threatening food safety, crop productivity, and human health. New research shows that not all biochars work the same way and that choosing the right type of biochar can make the difference between trapping toxic metals in soil or unintentionally making them more mobile. In a study published online on January 15, 2026, researchers report that biochar produced at high temperatures can work together with soil microbes to effectively immobilize cadmium, one of the most hazardous heavy metals found in farmland ...

Desperate race to resurrect newly-named zombie tree

2026-01-23
A recently identified tree species in Australia has been given the name ‘zombie’ by scientists who say ambitious assistance is needed to reverse its ‘living dead’ status. University of Queensland botanist Professor Rod Fensham said it was a race against time to save Rhodamnia zombi from the fungal disease myrtle rust. “This species did not have a name when it was first assessed in 2020, and since then 10 per cent of the trees have died and none of those remaining are producing flowers or fruit because of myrtle rust,” ...

New study links combination of hormone therapy and tirzepatide to greater weight loss after menopause

2026-01-23
JACKSONVILLE, Fla. — A new study led by Mayo Clinic found that postmenopausal women receiving menopausal hormone therapy lost 35% more weight while taking tirzepatide, a Food and Drug Administration-approved drug for the treatment of overweight and obesity. The findings, published in The Lancet Obstetrics, Gynaecology, & Women's Health, could expand treatment possibilities for millions of women struggling with obesity and obesity-related diseases after menopause. Menopause can accelerate age-related weight gain and increase the likelihood of developing overweight and obesity, which are major risk factors for cardiovascular ...

How molecules move in extreme water environments depends on their shape

2026-01-23
Water behaves in remarkable ways when heated and pressurized beyond its critical point. Under these extreme conditions, known as supercritical water, it no longer acts like an ordinary liquid. Instead, it takes on properties similar to organic solvents, dissolving hydrocarbons efficiently and transporting molecules rapidly. These unique features make supercritical water a promising green medium for energy conversion technologies such as biomass gasification, plastic recycling, and in situ fuel extraction. Yet many of these reactions occur inside extremely ...

Early-life exposure to a common pollutant harms fish development across generations

2026-01-23
A widely distributed environmental pollutant can leave lasting biological scars that persist long after direct exposure has ended, according to a new study that tracked its effects across multiple generations of fish. Researchers found that brief exposure to benzo[a]pyrene, a toxic compound produced by fossil fuel combustion and industrial activity, disrupted normal development and skeletal health not only in directly exposed fish but also in their unexposed descendants. The study reveals that these long-term effects are driven by persistent changes in metabolism, shedding new light on how ...

How is your corn growing? Aerial surveillance provides answers

2026-01-22
With already thin profit margins and increasingly uncertain farm labor and other input costs, precision agriculture technology could improve New England’s small and medium-sized farms’ efficiency, productivity, and resilience. Unfortunately, factors such as up-front costs and validation of the technology’s accuracy in the region remain a barrier to adoption. A research team at UNH led by Benjamin Fraser, visiting assistant professor and director of the Basic and Applied Spatial Analysis ...

Center for BrainHealth launches Fourth Annual BrainHealth Week in 2026

2026-01-22
Center for BrainHealth, a global leader in brain health research and its practical application, announces its fourth annual BrainHealth Week, February 23–28, 2026. The week-long conference features a diverse lineup of events designed to educate and inspire people of all ages to take action for better brain health. As brain health takes center stage at global forums like Davos and the UN General Assembly, BrainHealth Week 2026, presented by Ciridian, marks a pivotal moment in cognitive neuroscience. This event brings together world-renowned neuroscientists and brain performance experts to translate breakthrough research into "brain gains." ...

Why some messages are more convincing than others

2026-01-22
What kinds of marketing messages are effective — and what makes people believe certain political slogans more than others? New research from the University of California San Diego Rady School of Management explores how people constantly evaluate whether messages are true or false and finds that a surprisingly small ingredient — whether a word has an easy opposite — can shape how confident people feel when deciding whether a message is true. “Effective messaging isn’t just about ...

National Foundation for Cancer Research CEO Sujuan Ba Named One of OncoDaily’s 100 Most Influential Oncology CEOs of 2025

2026-01-22
Washington, D.C. | 22 January 2026 – Sujuan Ba, CEO of the National Foundation for Cancer Research (NFCR), has been named to OncoDaily’s list of the 100 Most Influential CEOs in Oncology in 2025, recognizing leaders whose work is shaping the global cancer research and care ecosystem. The annual list honors chief executives across industry, academia, policy, healthcare systems, and mission-driven organizations whose leadership has driven measurable and lasting impact in oncology worldwide. Dr. Ba is recognized alongside leaders from major cancer centers, biopharmaceutical companies, research institutions, ...

LAST 30 PRESS RELEASES:

Sharktober: Study links October shark bite spike to tiger shark reproduction

PPPL launches STELLAR-AI platform to accelerate fusion energy research

Breakthrough in development of reliable satellite-based positioning for dense urban areas

DNA-templated method opens new frontiers in synthesizing amorphous silver nanostructures

Stress-testing AI vision systems: Rethinking how adversarial images are generated

Why a crowded office can be the loneliest place on earth

Choosing the right biochar can lock toxic cadmium in soil, study finds

Desperate race to resurrect newly-named zombie tree

New study links combination of hormone therapy and tirzepatide to greater weight loss after menopause

How molecules move in extreme water environments depends on their shape

Early-life exposure to a common pollutant harms fish development across generations

How is your corn growing? Aerial surveillance provides answers

Center for BrainHealth launches Fourth Annual BrainHealth Week in 2026

Why some messages are more convincing than others

National Foundation for Cancer Research CEO Sujuan Ba Named One of OncoDaily’s 100 Most Influential Oncology CEOs of 2025

New analysis disputes historic earthquake, tsunami and death toll on Greek island

Drexel study finds early intervention helps most autistic children acquire spoken language

Study finds Alzheimer's disease can be evaluated with brain stimulation

Cells that are not our own may unlock secrets about our health

Caring Cross and Boston Children’s Hospital collaborate to expand access to gene therapy for sickle cell disease and beta thalassemia

Mount Sinai review maps the path forward for cancer vaccines, highlighting promise of personalized and combination approaches

Illinois study: How a potential antibiotics ban could affect apple growers

UC Irvine and Jefferson Health researchers find differences between two causes of heart valve narrowing

Ancien DNA pushes back record of treponemal disease-causing bacteria by 3,000 years

Human penis size influences female attraction and male assessment of rivals

Scientists devise way to track space junk as it falls to earth

AI is already writing almost one-third of new software code

A 5,500-year-old genome rewrites the origins of syphilis

Tracking uncontrolled space debris reentry using sonic booms

Endogenous retroviruses promote early human zygotic development

[Press-News.org] Stress-testing AI vision systems: Rethinking how adversarial images are generated
Researchers develop a new frequency-aware approach to crafting adversarial noise that better matches human visual perception