{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/spectraldefense-detecting-adversarial-attacks","title":"SpectralDefense: Detecting Adversarial Attacks on CNNs in the Fourier Domain","arxiv_id":"2103.03000","date":"2021-03-04","proceeding":null,"authors":["Paula Harder","Franz-Josef Pfreundt","Margret Keuper","Janis Keuper"],"abstract":"Despite the success of convolutional neural networks (CNNs) in many computer vision and image analysis tasks, they remain vulnerable against so-called adversarial attacks: Small, crafted perturbations in the input images can lead to false predictions. A possible defense is to detect adversarial examples. In this work, we show how analysis in the Fourier domain of input images and feature maps can be used to distinguish benign test samples from adversarial images. We propose two novel detection methods: Our first method employs the magnitude spectrum of the input images to detect an adversarial attack. This simple and robust classifier can successfully detect adversarial perturbations of three commonly used attack methods. The second method builds upon the first and additionally extracts the phase of Fourier coefficients of feature-maps at different layers of the network. With this extension, we are able to improve adversarial detection rates compared to state-of-the-art detectors on five different attack methods.","url_abs":"https://arxiv.org/abs/2103.03000v2","url_pdf":"https://arxiv.org/pdf/2103.03000v2.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"spectraldefense-detecting-adversarial-attacks","repo_url":"https://github.com/paulaharder/SpectralAdversarialDefense","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":1,"framework":"pytorch","reach":{"status":"unanswered"}},{"paper_slug":"spectraldefense-detecting-adversarial-attacks","repo_url":"https://github.com/adverml/multilid","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":0,"framework":"pytorch","reach":null},{"paper_slug":"spectraldefense-detecting-adversarial-attacks","repo_url":"https://github.com/adverml/spectraldef_framework","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":0,"framework":"pytorch","reach":null}],"tasks":[{"task_slug":"adversarial-attack","task_name":"Adversarial Attack"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":"https://app.syntology.ai/?focus=2103.03000","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2103.03000"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-24T18:15:14+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/paulaharder/SpectralAdversarialDefense","reach":{"status":"unanswered"}},{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/adverml/multilid","reach":null},{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/adverml/spectraldef_framework","reach":null}],"summary":{"ran_draft_wrong":2,"unverified":2},"by_repo_kind":{"listed":{"samples":4,"ran":2,"repositories":2}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":4,"samples":[{"code_sha256_prefix":"21e65585a285dd40","entry":"LID","repo":"adverml/multilid","repo_kind":"listed","path":"defenses/multiLID.py","file_url":"https://github.com/adverml/multilid/blob/HEAD/defenses/multiLID.py","link_basis":"first_harvest_node","language":"python","status":"ran_draft_wrong","verification_level":1,"contract_check":"MISDECLARED","metamorphic_tier":"invariant","behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"21e65585a285dd40"}},{"code_sha256_prefix":"315b5ee37bf1681f","entry":"get_activation","repo":"adverml/spectraldef_framework","repo_kind":"listed","path":"extract_characteristics.py","file_url":"https://github.com/adverml/spectraldef_framework/blob/HEAD/extract_characteristics.py","link_basis":"first_harvest_node","language":"python","status":"ran_draft_wrong","verification_level":1,"contract_check":"OUTPUT_MISDECLARED","metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"AGPL-3.0","inline_ok":false,"mcp_get_code":{"code_sha256":"315b5ee37bf1681f"}},{"code_sha256_prefix":"9bc62e786053f3d6","entry":"calculate_fourier_spectrum","repo":"adverml/spectraldef_framework","repo_kind":"listed","path":"extract_characteristics.py","file_url":"https://github.com/adverml/spectraldef_framework/blob/HEAD/extract_characteristics.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"AGPL-3.0","inline_ok":false,"mcp_get_code":{"code_sha256":"9bc62e786053f3d6"}},{"code_sha256_prefix":"30f7bceee5199870","entry":"multiLID","repo":"adverml/multilid","repo_kind":"listed","path":"defenses/multiLID.py","file_url":"https://github.com/adverml/multilid/blob/HEAD/defenses/multiLID.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"30f7bceee5199870"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}