PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
March 19, 2026International Journal of Information Security0 citationsOpen Access

Mixed Perturbation: Generating Directionally Diverse Perturbations for Adversarial Training

CHChanghun HyunHPHyeyoung Park

Key Points

  • To explore and improve the generation of diverse adversarial examples for effective adversarial training.
  • Developed a mixed perturbation (MP) method for generating adversarial examples.
  • Combined information from main and auxiliary tasks through random weighted summation.
  • Conducted extensive experiments across five benchmark datasets.
  • Non-optimized MP outperformed existing adversarial training methods in various scenarios.
  • Optimized MP consistently demonstrated the highest robustness across tests.
  • Analysis revealed the effectiveness of perturbation diversity in enhancing model defenses.

Abstract

Abstract The adversarial vulnerability of deep learning models poses a significant challenge to the safe commercialization of AI technologies. Although numerous adversarial defenses have been proposed, most offer limited robustness, emphasizing the need for continued exploration of the properties and causes of adversarial vulnerabilities. In this study, we hypothesize that the phenomenon of adversarially trained models exhibiting low adversarial accuracies is due to insufficient exploration and learning from adversarial examples that exist on the manifold. In this regard, we propose a novel perturbation generation method, “mixed perturbation (MP),” which aims to discover various adversarial examples for adversarial training. The proposed method generates perturbations by leveraging information from both the main task and auxiliary tasks, combining them through a random weighted summation. This approach preserves the primary directionality of the main task perturbation while introducing variability in perturbation directions, enabling the discovery of diverse adversarial examples from a defensive perspective. Extensive experiments on five benchmark datasets show that the non-optimized MP surpasses existing AT methods in several settings, while the optimized MP consistently achieves the highest robustness. We further analyze perturbation diversity, conduct ablation studies to explain MP’s effectiveness. In addition, through combination experiments with a state-of-the-art AT method, we confirmed the promising potential of MP in enhancing model robustness and outlined directions for future research.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Hyun et al. (2026) studied this question.

synapsesocial.com/papers/69bb9345496e729e62981461https://doi.org/10.1007/s10207-026-01225-1
Ask AI
Helpful
Bookmark
Share
View Full Paper