Towards Building More Robust Models with Frequency Bias
Qingwen Bu, Dong Huang, Heming Cui
Abstract
The vulnerability of deep neural networks to adversarial samples has been a major impediment to their broad applications, despite their success in various fields. Recently, some works suggested that adversarially-trained models emphasize the importance of low-frequency information to achieve higher robustness. While several attempts have been made to leverage this frequency characteristic, they have all faced the issue that applying low-pass filters directly to input images leads to irreversible loss of discriminative information and poor generalizability to datasets with distinct frequency features. This paper presents a plugand-play module called the Frequency Preference Control Module that adaptively reconfigures the low-and highfrequency components of intermediate feature representations, providing better utilization of frequency in robust learning. Empirical studies show that our proposed module can be easily incorporated into any adversarial training framework, further improving model robustness across different architectures and datasets. Additionally, experiments were conducted to examine how the frequency bias of robust models impacts the adversarial training process and its final robustness, revealing interesting insights. * Corresponding author. spite continuously advanced robust learning methods, the relationship between some intrinsic characteristics of the model structure, such as frequency characteristics, and the robustness it exhibits seems to be rarely discussed.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers4
- Multi-Architecture Multi-Expert Diffusion ModelsYunsung Lee, JinYoung Kim, Hyojun Go, Myeongho Jeong et al.AAAI 2024 · 40 citations
- HiLo: Detailed and Robust 3D Clothed Human Reconstruction with High-and Low-Frequency Information of Parametric ModelsYifan Yang, Dong Liu, Shuhai Zhang, Zeshuai Deng et al.CVPR 2024 · 11 citations
- FastDINOv2: Frequency Based Curriculum Learning Improves Robustness and Training SpeedJiaqi Zhang, Juntuo Wang, Zhixin Sun, John Zou et al.NeurIPS 2025 · 5 citations
- Contrastive Spectral Rectification: Test-Time Defense towards Zero-shot Adversarial Robustness of CLIPSen Nie, Jie Zhang, Zhuo Wang, Shiguang Shan et al.ICML 2026
Builds on15
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 2,337 citations
- Fast is better than free: Revisiting adversarial trainingEric Wong, Leslie Rice, J. Zico KolterICLR 2020 · 1,352 citations
- Adversarial Weight Perturbation Helps Robust GeneralizationDongxian Wu, Shu-Tao Xia, Yisen WangNeurIPS 2020 · 917 citations
- Improving Adversarial Robustness Requires Revisiting Misclassified ExamplesYisen Wang, Difan Zou, Jinfeng Yi, James Bailey et al.ICLR 2020 · 829 citations
Related papers
- Deep Frequency Filtering for Domain GeneralizationShiqi Lin, Zhizheng Zhang, Zhipeng Huang, Yan Lu et al.CVPR 2023
- Robust Real-World Image Super-Resolution against Adversarial AttacksJiutao Yue, Haofeng Li, Pengxu Wei, Guanbin Li et al.ACM MM 2021 · 20 citations
- High-Frequency Component Helps Explain the Generalization of Convolutional Neural NetworksHaohan Wang, Xindi Wu, Zeyi Huang, Eric P. XingCVPR 2020
- FACL-Attack: Frequency-Aware Contrastive Learning for Transferable Adversarial AttacksHunmin Yang, Jongoh Jeong, Kuk-Jin YoonAAAI 2024 · 12 citations
- Towards Combating Frequency Simplicity-biased Learning for Domain GeneralizationXilin He, Jingyu Hu, Qinliang Lin, Cheng Luo et al.NeurIPS 2024 · 16 citations
