Generalization of Defense Effects Learned from a Single Adversarial Attack
Abstract
1. Introduction
- We propose Gradient Vicinity Adversarial Training, an adversarial training method that generated adversarial examples along directions sampled in the vicinity of the gradient direction.
- GVAT used adversarial examples generated by a single attack for training, but the trained models still show improved transfer-based black-box robustness against other attacks, including FGSM, PGD, sparse descent (SLIDE) [21], and CW attacks under the , , and constraints.
- We show that broader attack-direction coverage around the gradient direction was important for improving defense generalization, instead of relying only on stronger adversarial examples generated along the original gradient direction.
2. Methods
2.1. Threat Model
2.2. Distance Metric
2.3. Gradient Vicinity Sampling
2.4. Adversarial Example Generation in GVAT
| Algorithm 1 Adversarial Example Generation in GVAT |
| Input: classifier ; normalized input with label y; attack type A; iterations K; normalization mean and standard deviation ; FGSM/PGD parameters and ; CW parameters , and ; maximum gradient-vicinity angle .
Output: adversarial example .
|
2.5. Datasets and Models
2.6. Adversarial Attack Settings
2.7. Offline Adversarial Training and Testing
3. Results
3.1. Standard Adversarial Training
- Different attack types. The defense performance decreased when the test attack differed from the training attack. For example, on CIFAR-100, the model trained with FGSM, achieved 56.91% Top-1 accuracy under the same attack, but only 48.51% under the CW, attack. Similar trends were observed on CIFAR-10 as well.
- Different norm constraints. The defense performance also decreased when the test norm differed from the training norm. For example, on CIFAR-100, the model trained with PGD, adversarial examples achieved 69.06% Top-1 accuracy under the same setting. However, its accuracy dropped to 19.40% under the PGD, attack. Similar trends were also observed on other datasets.
3.2. Gradient Vicinity Adversarial Training
- Different attack types and norm constraints. GVAT improved defense performance on many adversarial examples not used for training. This indicated that GVAT could improve the generalization of defense effects. For example, on CIFAR-100, compared with standard PGD, adversarial training, PGD, -based GVAT with increased the Top-1 accuracy under the FGSM, attack from 28.99% to 46.12%.
- Larger angle was not always better. A larger maximum sampling angle did not always lead to better defense performance. In some cases, the accuracy first increased and then decreased as became larger. For example, on CIFAR-100, when GVAT was applied to PGD, , the best performance under the FGSM, test attack appeared at , rather than at the largest angle.
3.3. Comparison with Multi-Attack Defense Methods
- 1.
- Computational cost. As shown in Table 4, Multi-AT had the highest cost, with 920 gradient evaluations per sample, 16.28 h of total GPU time, and 2.57 GB of storage. MSD required 30 gradient evaluations per sample and 11.25 h of total GPU time. AT and GVAT had similar computational costs, with total GPU times of 10.61 h and 10.67 h, respectively.
- 2.
- Transfer-based black-box robustness. Table 5 compared AT, GVAT, Multi-AT, and MSD against six adversarial attacks. Multi-AT achieved the highest average robust accuracy on all three datasets. GVAT ranked second on MNIST and CIFAR-10. On CIFAR-100, its average robust accuracy was 59.43%, which was close to the 60.05% achieved by MSD. GVAT achieved higher average robust accuracy than AT.
3.4. White-Box Robustness Evaluation with AutoAttack
4. Discussion
4.1. Effect of Attack Strength on Defense Performance
4.2. Effect of Attack Direction Coverage on Defense Performance
5. Conclusions
Author Contributions
Funding
Data Availability Statement
Conflicts of Interest
Appendix A. Visualization of Adversarial Examples on MNIST and CIFAR-10


Appendix B. Attack Strength and Convergence Analysis

References
- Zhu, L.; Liao, B.; Zhang, Q.; Wang, X.; Liu, W.; Wang, X. Vision Mamba: Efficient visual representation learning with bidirectional state space model. In Proceedings of the 41st International Conference on Machine Learning, Vienna, Austria, 21–27 July 2024; pp. 62429–62442. Available online: https://proceedings.mlr.press/v235/zhu24f.html (accessed on 6 September 2026).
- Radford, A.; Kim, J.W.; Hallacy, C.; Ramesh, A.; Goh, G.; Agarwal, S.; Sastry, G.; Askell, A.; Mishkin, P.; Clark, J.; et al. Learning transferable visual models from natural language supervision. In Proceedings of the 38th International Conference on Machine Learning, Virtual Event, 18–24 July 2021; pp. 8748–8763. Available online: https://proceedings.mlr.press/v139/radford21a.html (accessed on 6 September 2026).
- Li, Z.; Wang, W.; Li, H.; Xie, E.; Sima, C.; Lu, T.; Qiao, Y.; Dai, J. BEVFormer: Learning bird’s-eye-view representation from LiDAR-camera via spatiotemporal transformers. IEEE Trans. Pattern Anal. Mach. Intell. 2025, 47, 2020–2036. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Hu, Y.; Yang, J.; Chen, L.; Li, K.; Sima, C.; Zhu, X.; Chai, S.; Du, S.; Lin, T.; Wang, W.; et al. Planning-oriented autonomous driving. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR 2023), Vancouver, BC, Canada, 17–24 June 2023; pp. 17853–17862. [Google Scholar] [CrossRef] [Scilit]
- Hinton, G.; Deng, L.; Yu, D.; Dahl, G.E.; Mohamed, A.R.; Jaitly, N.; Senior, A.; Vanhoucke, V.; Nguyen, P.; Sainath, T.N.; et al. Deep Neural Networks for Acoustic Modeling in Speech Recognition. IEEE Signal Process. Mag. 2012, 29, 82–97. [Google Scholar] [CrossRef] [Scilit]
- Radford, A.; Kim, J.W.; Xu, T.; Brockman, G.; McLeavey, C.; Sutskever, I. Robust speech recognition via large-scale weak supervision. In Proceedings of the International Conference on Machine Learning (ICML 2023), Honolulu, HI, USA, 23–29 July 2023; pp. 28492–28518. Available online: https://proceedings.mlr.press/v202/radford23a.html (accessed on 6 September 2026).
- Szegedy, C.; Zaremba, W.; Sutskever, I.; Bruna, J.; Erhan, D.; Goodfellow, I.J.; Fergus, R. Intriguing properties of neural networks. In Proceedings of the 2nd International Conference on Learning Representations (ICLR 2014), Banff, AB, Canada, 14–16 April 2014. [Google Scholar] [CrossRef] [Scilit]
- Biggio, B.; Roli, F. Wild Patterns: Ten Years After the Rise of Adversarial Machine Learning. In Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security, Toronto, ON, Canada, 15–19 October 2018. [Google Scholar] [CrossRef] [Scilit]
- Wang, L.; Zhang, T.; Han, Y.; Fang, M.; Jin, T.; Kang, J. Attack end-to-end autonomous driving through module-wise noise. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition Workshops, Seattle, WA, USA, 17–18 June 2024; pp. 8349–8352. Available online: https://openaccess.thecvf.com/content/CVPR2024W/AdvML/html/Wang_Attack_End-to-End_Autonomous_Driving_through_Module-Wise_Noise_CVPRW_2024_paper.html (accessed on 6 September 2026).
- Carlini, N.; Mishra, P.; Vaidya, T.; Zhang, Y.; Sherr, M.; Shields, C.; Wagner, D.A.; Zhou, W. Hidden voice commands. In Proceedings of the 25th USENIX Security Symposium (USENIX Security 16), Austin, TX, USA, 10–12 August 2016; pp. 513–530. Available online: https://www.usenix.org/conference/usenixsecurity16/technical-sessions/presentation/carlini (accessed on 6 September 2026).
- Zuo, F.; Zeng, Q. Exploiting the sensitivity of L2 adversarial examples to erase-and-restore. In Proceedings of the 2021 ACM Asia Conference on Computer and Communications Security, Virtual Event, 7–11 June 2021; pp. 40–51. [Google Scholar] [CrossRef] [Scilit]
- Li, X.; Li, F. Adversarial examples detection in deep networks with convolutional filter statistics. In Proceedings of the 2017 IEEE International Conference on Computer Vision (ICCV), Venice, Italy, 22–29 October 2017; pp. 5775–5783. [Google Scholar] [CrossRef] [Scilit]
- Shi, L.; Liao, T.; He, J. Defending adversarial attacks against DNN image classification models by a noise-fusion method. Electronics 2022, 11, 1814. [Google Scholar] [CrossRef] [Scilit]
- Li, B.; Chen, C.; Wang, W.; Carin, L. Certified adversarial robustness with additive noise. In Proceedings of the Advances in Neural Information Processing Systems 32 (NeurIPS 2019), Vancouver, BC, Canada, 8–14 December 2019; pp. 9459–9469. Available online: https://proceedings.neurips.cc/paper/2019/hash/335cd1b90bfa4ee70b39d08a4ae0cf2d-Abstract.html (accessed on 6 September 2026).
- An, G. The effects of adding noise during backpropagation training on a generalization performance. Neural Comput. 1996, 8, 643–674. [Google Scholar] [CrossRef] [Scilit]
- Goodfellow, I.J.; Shlens, J.; Szegedy, C. Explaining and harnessing adversarial examples. In Proceedings of the 3rd International Conference on Learning Representations (ICLR 2015), San Diego, CA, USA, 7–9 May 2015. [Google Scholar] [CrossRef] [Scilit]
- Elsayed, G.F.; Goodfellow, I.J.; Sohl-Dickstein, J. Adversarial reprogramming of neural networks. In Proceedings of the 7th International Conference on Learning Representations (ICLR 2019), New Orleans, LA, USA, 6–9 May 2019; Available online: https://openreview.net/forum?id=Syx_Ss05tm (accessed on 6 September 2026).
- Schott, L.; Rauber, J.; Bethge, M.; Brendel, W. Towards the first adversarially robust neural network model on MNIST. In Proceedings of the 7th International Conference on Learning Representations (ICLR 2019), New Orleans, LA, USA, 6–9 May 2019; Available online: https://openreview.net/forum?id=S1EHOsC9tX (accessed on 6 September 2026).
- Zhang, H.; Yu, Y.; Jiao, J.; Xing, E.; El Ghaoui, L.; Jordan, M. Theoretically Principled Trade-off between Robustness and Accuracy. In Proceedings of the 36th International Conference on Machine Learning (ICML 2019), Long Beach, CA, USA, 9–15 June 2019; Available online: https://proceedings.mlr.press/v97/zhang19p.html (accessed on 6 September 2026).
- Engstrom, L.; Tran, B.; Tsipras, D.; Schmidt, L.; Madry, A. A rotation and a translation suffice: Fooling CNNs with simple transformations. In Proceedings of the International Conference on Learning Representations, New Orleans, LA, USA, 6–9 May 2019; Available online: https://openreview.net/forum?id=BJfvknCqFQ (accessed on 6 September 2026).
- Tramèr, F.; Boneh, D. Adversarial training and robustness for multiple perturbations. In Proceedings of the Advances in Neural Information Processing Systems 32 (NeurIPS 2019), Vancouver, BC, Canada, 8–14 December 2019; pp. 5858–5868. Available online: https://proceedings.neurips.cc/paper/2019/hash/5d4ae76f053f8f2516ad12961ef7fe97-Abstract.html (accessed on 6 September 2026).
- Nowroozi, E.; Mohammadi, M.; Rahdari, A.; Taheri, R.; Conti, M. A Random Deep Feature Selection Approach to Mitigate Transferable Adversarial Attacks. IEEE Trans. Netw. Serv. Manag. 2025, 22, 5301–5310. [Google Scholar] [CrossRef] [Scilit]
- Wong, E.; Rice, L.; Kolter, J.Z. Fast is better than free: Revisiting adversarial training. In Proceedings of the 8th International Conference on Learning Representations (ICLR 2020), Addis Ababa, Ethiopia, 26–30 April 2020; Available online: https://openreview.net/forum?id=BJx040EFvH (accessed on 6 September 2026).
- Rice, L.; Wong, E.; Kolter, J.Z. Overfitting in Adversarially Robust Deep Learning. In Proceedings of the 37th International Conference on Machine Learning (ICML 2020), Virtual, 13–18 July 2020; Available online: https://proceedings.mlr.press/v119/rice20a.html (accessed on 6 September 2026).
- Madry, A.; Makelov, A.; Schmidt, L.; Tsipras, D.; Vladu, A. Towards deep learning models resistant to adversarial attacks. In Proceedings of the International Conference on Learning Representations, Vancouver, BC, Canada, 30 April–3 May 2018; Available online: https://openreview.net/forum?id=rJzIBfZAb (accessed on 6 September 2026).
- Carlini, N.; Wagner, D.A. Towards evaluating the robustness of neural networks. In Proceedings of the 2017 IEEE Symposium on Security and Privacy, San Jose, CA, USA, 22–26 May 2017; pp. 39–57. [Google Scholar] [CrossRef] [Scilit]
- Tramèr, F.; Kurakin, A.; Papernot, N.; Goodfellow, I.J.; Boneh, D.; McDaniel, P.D. Ensemble adversarial training: Attacks and defenses. In Proceedings of the 6th International Conference on Learning Representations (ICLR 2018), Vancouver, BC, Canada, 30 April–3 May 2018; Available online: https://openreview.net/forum?id=rkZvSe-RZ (accessed on 6 September 2026).
- LeCun, Y.; Bottou, L.; Bengio, Y.; Haffner, P. Gradient-based learning applied to document recognition. Proc. IEEE 1998, 86, 2278–2324. [Google Scholar] [CrossRef] [Scilit]
- Krizhevsky, A. Learning Multiple Layers of Features from Tiny Images; Technical Report; University of Toronto: Toronto, ON, Canada, 2009; Available online: https://api.semanticscholar.org/CorpusID:18268744 (accessed on 6 September 2026).
- Papernot, N.; McDaniel, P.; Goodfellow, I.J. Transferability in machine learning: From phenomena to black-box attacks using adversarial samples. arXiv 2016, arXiv:1605.07277. [Google Scholar] [CrossRef] [Scilit]
- Zagoruyko, S.; Komodakis, N. Wide residual networks. In Proceedings of the British Machine Vision Conference 2016 (BMVC 2016), York, UK, 19–22 September 2016; Available online: https://bmva-archive.org.uk/bmvc/2016/papers/paper087/index.html (accessed on 6 September 2026).
- Maini, P.; Wong, E.; Kolter, J.Z. Adversarial Robustness Against the Union of Multiple Perturbation Models. In Proceedings of the 37th International Conference on Machine Learning (ICML), Virtual Event, 13–18 July 2020; PMLR 119, pp. 6640–6650. Available online: https://proceedings.mlr.press/v119/maini20a.html (accessed on 6 September 2026).
- Croce, F.; Hein, M. Reliable Evaluation of Adversarial Robustness with an Ensemble of Diverse Parameter-Free Attacks. In Proceedings of the 37th International Conference on Machine Learning (ICML), Virtual Event, 13–18 July 2020; Volume 119, pp. 2206–2216. Available online: https://proceedings.mlr.press/v119/croce20b.html (accessed on 6 September 2026).


| Dataset | Model | Attack Method | Distance Metric | Distance | Step Size | Iteration Steps | GVAT |
|---|---|---|---|---|---|---|---|
| MNIST | CNN | FGSM | 6 | 1 | 1 | ✓ | |
| FGSM | 0.3 | 1 | 1 | ||||
| MNIST | CNN | PGD | 4 | 2 | 40 | ✓ | |
| PGD | 0.15 | 0.1 | 40 | ||||
| SLIDE | 20 | 4 | 40 | ||||
| CW | – | 1 | 200 | ✓ | |||
| CIFAR-10 & CIFAR-100 | WideResNet -28-10 | FGSM | 6 | 1 | 1 | ✓ | |
| FGSM | 40/255 | 1 | 1 | ||||
| PGD | 4 | 2 | 10 | ✓ | |||
| PGD | 40/255 | 2 | 10 | ||||
| SLIDE | 40 | 8 | 20 | ||||
| CW | – | 1 | 50 | ✓ |
| Dataset | Training Set | Testing Set | ||||||
|---|---|---|---|---|---|---|---|---|
| Clean | FGSM, | FGSM, | PGD, | PGD, | SLIDE, | CW, | ||
| MNIST | Clean | 99.22 | 39.38 | 47.65 | 17.17 | 82.85 | 49.04 | 32.11 |
| FGSM, | 98.92 | 98.35 | 96.54 | 83.40 | 98.86 | 82.64 | 75.50 | |
| FGSM, | 99.01 | 86.65 | 98.54 | 62.33 | 98.35 | 76.94 | 67.85 | |
| PGD, | 98.94 | 87.87 | 76.17 | 98.77 | 98.46 | 84.53 | 76.65 | |
| PGD, | 99.12 | 84.39 | 92.02 | 67.71 | 99.16 | 70.94 | 58.29 | |
| SLIDE, | 98.60 | 86.64 | 80.27 | 96.76 | 97.52 | 98.05 | 88.49 | |
| CW, | 98.05 | 72.71 | 62.93 | 78.81 | 90.68 | 87.49 | 96.69 | |
| CIFAR-10 | Clean | 94.44 | 33.89 | 33.38 | 24.98 | 22.62 | 44.10 | 47.59 |
| FGSM, | 93.89 | 92.40 | 82.69 | 65.29 | 77.45 | 75.34 | 63.80 | |
| FGSM, | 94.08 | 73.01 | 87.47 | 61.12 | 83.59 | 70.23 | 67.43 | |
| PGD, | 93.94 | 72.42 | 61.52 | 94.78 | 65.81 | 91.48 | 65.77 | |
| PGD, | 91.32 | 68.85 | 68.52 | 82.25 | 86.47 | 83.81 | 74.94 | |
| SLIDE, | 93.92 | 76.10 | 69.60 | 84.80 | 77.37 | 92.77 | 71.73 | |
| CW, | 93.66 | 71.62 | 63.81 | 88.98 | 72.39 | 89.64 | 92.42 | |
| CIFAR-100 | Clean | 76.57 | 5.78 | 5.73 | 16.38 | 4.45 | 25.96 | 24.35 |
| FGSM, | 73.34 | 56.91 | 50.06 | 49.06 | 58.75 | 55.71 | 48.51 | |
| FGSM, | 74.58 | 41.19 | 61.35 | 42.51 | 66.55 | 49.70 | 34.70 | |
| PGD, | 74.53 | 28.99 | 19.38 | 69.06 | 19.40 | 64.42 | 40.13 | |
| PGD, | 73.71 | 37.07 | 43.10 | 52.76 | 67.49 | 56.19 | 46.20 | |
| SLIDE, | 74.69 | 37.37 | 23.10 | 59.66 | 35.83 | 66.81 | 46.63 | |
| CW, | 73.68 | 31.31 | 22.48 | 59.99 | 25.83 | 64.57 | 70.79 | |
| Dataset | Training Set | GVAT | Testing Set | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Clean | FGSM | FGSM | PGD | PGD | SLIDE | CW | |||
| MNIST | FGSM, | 98.92 | 98.35 | 96.54 | 83.40 | 98.86 | 82.64 | 75.50 | |
| 98.97 | 98.30 | 97.33 | 83.04 | 98.79 | 82.20 | 71.36 | |||
| 98.83 | 97.28 | 96.46 | 76.90 | 98.67 | 80.22 | 70.23 | |||
| 98.74 | 95.54 | 97.14 | 83.40 | 98.57 | 88.27 | 76.72 | |||
| 98.90 | 94.80 | 96.76 | 81.70 | 98.39 | 88.58 | 74.92 | |||
| 98.92 | 91.70 | 95.54 | 75.65 | 97.88 | 87.20 | 76.70 | |||
| MNIST | PGD, | 98.94 | 87.87 | 76.17 | 98.77 | 98.46 | 84.53 | 76.65 | |
| 99.07 | 87.46 | 77.45 | 98.66 | 98.32 | 85.88 | 76.55 | |||
| 98.94 | 90.85 | 82.94 | 98.58 | 98.86 | 84.22 | 73.83 | |||
| 98.90 | 91.70 | 87.10 | 97.39 | 99.15 | 86.66 | 77.25 | |||
| 98.98 | 95.14 | 95.74 | 95.75 | 99.21 | 92.92 | 84.13 | |||
| 98.92 | 91.70 | 95.54 | 75.65 | 97.88 | 87.20 | 73.72 | |||
| MNIST | CW, | 98.05 | 72.71 | 62.93 | 78.81 | 90.68 | 87.49 | 96.69 | |
| 98.17 | 76.79 | 72.48 | 80.85 | 93.47 | 86.54 | 95.55 | |||
| 98.07 | 75.12 | 72.91 | 79.28 | 92.34 | 86.39 | 95.67 | |||
| 97.88 | 78.22 | 76.88 | 80.92 | 93.18 | 86.03 | 94.79 | |||
| 97.95 | 79.60 | 79.96 | 83.49 | 93.44 | 87.37 | 95.66 | |||
| 97.90 | 82.30 | 86.22 | 76.73 | 95.67 | 85.55 | 91.25 | |||
| CIFAR-10 | FGSM, | 93.89 | 92.00 | 82.69 | 65.29 | 77.45 | 75.34 | 63.80 | |
| 94.10 | 89.56 | 81.77 | 66.58 | 81.71 | 76.39 | 66.48 | |||
| 94.23 | 92.18 | 85.95 | 72.58 | 83.49 | 80.31 | 67.62 | |||
| 93.41 | 84.98 | 82.28 | 91.33 | 90.34 | 91.50 | 82.36 | |||
| 94.16 | 83.48 | 80.76 | 90.39 | 89.08 | 90.87 | 81.03 | |||
| 93.95 | 81.89 | 79.18 | 89.47 | 88.79 | 89.99 | 76.45 | |||
| CIFAR-10 | PGD, | 93.94 | 72.42 | 61.52 | 94.78 | 65.81 | 91.48 | 65.77 | |
| 93.20 | 67.22 | 58.83 | 91.36 | 60.16 | 88.98 | 57.26 | |||
| 93.56 | 70.89 | 61.25 | 90.11 | 64.30 | 89.63 | 58.37 | |||
| 93.62 | 76.33 | 68.57 | 91.73 | 74.16 | 90.69 | 66.95 | |||
| 94.14 | 74.33 | 66.36 | 90.88 | 76.97 | 90.54 | 76.69 | |||
| 93.35 | 62.42 | 58.06 | 85.93 | 70.56 | 87.12 | 73.69 | |||
| CIFAR-10 | CW, | 93.66 | 71.62 | 63.81 | 88.98 | 72.39 | 89.64 | 92.42 | |
| 94.22 | 80.57 | 75.81 | 90.08 | 87.22 | 91.14 | 92.81 | |||
| 93.82 | 79.01 | 76.04 | 89.24 | 87.66 | 90.21 | 90.71 | |||
| 94.41 | 72.02 | 71.12 | 85.29 | 88.49 | 87.80 | 87.48 | |||
| 94.13 | 70.23 | 69.58 | 84.07 | 87.75 | 87.21 | 86.78 | |||
| 94.21 | 72.90 | 71.82 | 85.38 | 88.25 | 87.84 | 88.37 | |||
| CIFAR-100 | FGSM, | 73.34 | 56.91 | 50.06 | 49.06 | 58.75 | 55.71 | 48.51 | |
| 74.24 | 60.21 | 51.82 | 48.78 | 60.98 | 56.74 | 52.12 | |||
| 73.19 | 58.08 | 49.32 | 55.70 | 60.16 | 60.05 | 52.94 | |||
| 73.25 | 59.21 | 52.91 | 60.38 | 65.16 | 62.81 | 56.13 | |||
| 74.13 | 55.87 | 49.73 | 58.51 | 66.01 | 61.51 | 56.54 | |||
| 74.27 | 56.97 | 50.94 | 57.58 | 65.24 | 62.11 | 57.92 | |||
| CIFAR-100 | PGD, | 74.53 | 28.99 | 19.38 | 69.06 | 19.40 | 64.42 | 40.13 | |
| 73.75 | 28.89 | 18.41 | 65.14 | 21.99 | 64.43 | 39.12 | |||
| 73.66 | 40.67 | 26.23 | 66.07 | 32.11 | 66.40 | 41.73 | |||
| 74.12 | 46.12 | 33.79 | 64.54 | 42.98 | 66.06 | 48.21 | |||
| 74.75 | 41.36 | 28.90 | 61.48 | 40.22 | 64.68 | 49.97 | |||
| 74.17 | 33.08 | 24.10 | 54.68 | 36.61 | 59.81 | 46.82 | |||
| CIFAR-100 | CW, | 73.68 | 31.31 | 22.48 | 59.99 | 25.83 | 64.57 | 70.79 | |
| 75.04 | 50.66 | 40.40 | 62.00 | 55.14 | 66.32 | 70.00 | |||
| 74.95 | 52.64 | 42.73 | 59.14 | 59.85 | 63.93 | 67.45 | |||
| 74.19 | 39.02 | 32.51 | 49.03 | 56.08 | 56.79 | 59.16 | |||
| 73.18 | 36.75 | 30.03 | 46.84 | 53.89 | 55.80 | 58.32 | |||
| 75.03 | 43.76 | 36.07 | 50.35 | 61.21 | 58.69 | 61.64 | |||
| Method | Attack Setting | Grad. Evals. /Sample | Adv. Gen. Time (h) | Training Time (h) | GPU Time (h) | Storage (GB) |
|---|---|---|---|---|---|---|
| Multi-AT | PGD, PGD CW, | 920 | 2.85 | 13.43 | 16.28 | 2.57 |
| MSD | PGD over | 30 | 0.90 | 10.35 | 11.25 | 0.85 |
| AT | FGSM, | 1 | 0.24 | 10.37 | 10.61 | 0.85 |
| GVAT | FGSM, | 1 | 0.24 | 10.43 | 10.67 | 0.85 |
| Dataset | Method | Testing Set | Avg. | |||||
|---|---|---|---|---|---|---|---|---|
| FGSM, | FGSM, | PGD, | PGD, | SLIDE, | CW, | |||
| MNIST | Multi-AT | 94.09 | 90.85 | 99.17 | 99.37 | 96.60 | 98.01 | 96.35 |
| MSD | 81.26 | 68.08 | 97.41 | 96.87 | 84.42 | 78.16 | 84.36 | |
| AT | 98.35 | 96.54 | 83.40 | 98.86 | 82.64 | 75.50 | 89.22 | |
| GVAT | 95.54 | 97.14 | 83.40 | 98.57 | 88.27 | 76.72 | 89.94 | |
| CIFAR-10 | Multi-AT | 87.20 | 80.92 | 93.01 | 92.62 | 93.06 | 93.45 | 90.04 |
| MSD | 83.06 | 80.54 | 91.20 | 91.12 | 91.04 | 77.58 | 85.75 | |
| AT | 92.00 | 82.69 | 65.29 | 77.45 | 75.34 | 63.80 | 76.10 | |
| GVAT | 84.98 | 82.28 | 91.33 | 90.34 | 91.50 | 82.36 | 87.13 | |
| CIFAR-100 | Multi-AT | 60.30 | 61.99 | 71.36 | 76.52 | 74.58 | 78.00 | 70.46 |
| MSD | 54.92 | 50.97 | 63.41 | 67.86 | 64.84 | 58.34 | 60.05 | |
| AT | 56.91 | 50.06 | 49.06 | 58.75 | 55.71 | 48.51 | 53.17 | |
| GVAT | 59.21 | 52.91 | 60.38 | 65.16 | 62.81 | 56.13 | 59.43 | |
| Dataset | Training Set | GVAT | Testing Set | ||||
|---|---|---|---|---|---|---|---|
| APGD-CE | APGD-DLR | FAB-T | SQUARE | STANDARD | |||
| MNIST | FGSM, | 34.25 | 0.33 | 7.85 | 7.05 | 0.04 | |
| 24.18 | 0.11 | 8.86 | 4.83 | 0.02 | |||
| 7.46 | 0.98 | 8.07 | 9.74 | 0.17 | |||
| 5.42 | 1.67 | 8.53 | 10.73 | 0.42 | |||
| 35.30 | 3.43 | 10.70 | 15.98 | 1.14 | |||
| 49.18 | 10.91 | 15.58 | 27.53 | 7.12 | |||
| PGD, | 14.26 | 0.00 | 11.90 | 0.17 | 0.00 | ||
| 0.59 | 0.00 | 7.66 | 0.20 | 0.00 | |||
| 11.70 | 0.00 | 9.15 | 0.13 | 0.00 | |||
| 1.17 | 0.00 | 8.35 | 1.40 | 0.00 | |||
| 15.51 | 0.14 | 10.90 | 3.25 | 0.01 | |||
| 38.78 | 41.22 | 44.75 | 55.15 | 37.82 | |||
| CW, | 1.41 | 0.01 | 13.18 | 0.22 | 0.00 | ||
| 0.54 | 0.06 | 12.54 | 0.65 | 0.00 | |||
| 1.52 | 0.03 | 13.97 | 0.35 | 0.00 | |||
| 0.88 | 0.02 | 11.71 | 0.96 | 0.01 | |||
| 1.50 | 0.05 | 15.45 | 0.61 | 0.00 | |||
| 4.33 | 4.90 | 11.04 | 11.93 | 3.08 | |||
| CIFAR-10 | FGSM, | 0.01 | 0.07 | 0.16 | 18.34 | 0.00 | |
| 0.03 | 0.20 | 0.09 | 26.86 | 0.00 | |||
| 0.13 | 0.21 | 0.15 | 29.54 | 0.00 | |||
| 2.94 | 6.30 | 1.40 | 44.61 | 0.85 | |||
| 4.65 | 10.73 | 3.41 | 49.60 | 2.64 | |||
| 4.38 | 11.24 | 3.32 | 49.18 | 2.39 | |||
| PGD, | 0.00 | 0.00 | 0.53 | 3.24 | 0.00 | ||
| 0.00 | 0.00 | 0.31 | 9.43 | 0.00 | |||
| 0.00 | 0.01 | 0.14 | 12.20 | 0.00 | |||
| 0.02 | 0.04 | 0.24 | 11.36 | 0.00 | |||
| 0.00 | 0.00 | 0.22 | 11.55 | 0.00 | |||
| 0.23 | 0.86 | 0.23 | 28.18 | 0.08 | |||
| CW, | 0.09 | 0.29 | 0.17 | 19.17 | 0.00 | ||
| 0.32 | 0.77 | 0.51 | 26.74 | 0.14 | |||
| 4.18 | 9.61 | 2.98 | 46.67 | 2.41 | |||
| 12.28 | 23.01 | 10.75 | 56.03 | 9.52 | |||
| 12.20 | 18.95 | 9.63 | 54.33 | 8.45 | |||
| 12.67 | 21.06 | 11.32 | 55.14 | 10.06 | |||
| CIFAR-100 | FGSM, | 1.55 | 1.67 | 1.51 | 24.78 | 0.89 | |
| 1.62 | 1.40 | 1.29 | 25.12 | 0.80 | |||
| 1.23 | 1.26 | 1.19 | 25.36 | 0.69 | |||
| 2.36 | 2.87 | 2.65 | 26.43 | 1.70 | |||
| 2.20 | 2.30 | 1.98 | 25.85 | 1.44 | |||
| 2.02 | 2.50 | 1.90 | 26.21 | 1.46 | |||
| PGD, | 0.03 | 0.02 | 0.37 | 4.31 | 0.00 | ||
| 0.12 | 0.09 | 0.32 | 7.25 | 0.03 | |||
| 0.04 | 0.04 | 0.34 | 8.59 | 0.00 | |||
| 0.25 | 0.24 | 0.52 | 14.35 | 0.09 | |||
| 0.31 | 0.25 | 0.51 | 16.64 | 0.08 | |||
| 0.49 | 0.60 | 0.76 | 17.42 | 0.22 | |||
| CW, | 0.07 | 0.05 | 0.28 | 7.30 | 0.01 | ||
| 0.46 | 0.44 | 0.69 | 17.73 | 0.20 | |||
| 1.53 | 1.73 | 1.52 | 23.91 | 0.94 | |||
| 1.91 | 1.87 | 1.68 | 24.54 | 1.19 | |||
| 1.60 | 1.72 | 1.39 | 23.42 | 1.06 | |||
| 2.02 | 1.77 | 1.47 | 23.62 | 1.11 | |||
| Dataset | Training Set | Accuracy | Testing Set | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Clean | FGSM | FGSM | PGD | PGD | SLIDE | CW | |||
| CIFAR-100 | PGD, | 2.23 | 73.77 | 23.48 | 16.15 | 66.61 | 16.81 | 61.44 | 38.69 |
| 10.29 | 74.85 | 19.01 | 12.36 | 65.67 | 13.65 | 62.27 | 38.53 | ||
| 50.32 | 74.82 | 11.81 | 9.65 | 40.09 | 12.05 | 48.71 | 36.82 | ||
| FGSM, | 2.58 | 73.34 | 56.91 | 50.06 | 49.06 | 58.75 | 55.71 | 48.51 | |
| 15.11 | 73.41 | 55.69 | 39.36 | 59.76 | 41.81 | 63.53 | 41.67 | ||
| 37.43 | 73.34 | 19.33 | 13.56 | 57.93 | 16.50 | 59.64 | 37.16 | ||
| GVAT | FGSM | PGD | CW |
|---|---|---|---|
| 5.78 | 16.38 | 24.35 | |
| 5.94 | 17.30 | 22.58 | |
| 6.91 | 19.43 | 17.47 | |
| 18.35 | 34.57 | 10.65 | |
| 26.89 | 47.27 | 10.12 | |
| 32.41 | 59.38 | 10.98 |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Niu, D.; Shi, L. Generalization of Defense Effects Learned from a Single Adversarial Attack. Computation 2026, 14, 211. https://doi.org/10.3390/computation14090211
Niu D, Shi L. Generalization of Defense Effects Learned from a Single Adversarial Attack. Computation. 2026; 14(9):211. https://doi.org/10.3390/computation14090211
Chicago/Turabian StyleNiu, Dongxian, and Lin Shi. 2026. "Generalization of Defense Effects Learned from a Single Adversarial Attack" Computation 14, no. 9: 211. https://doi.org/10.3390/computation14090211
APA StyleNiu, D., & Shi, L. (2026). Generalization of Defense Effects Learned from a Single Adversarial Attack. Computation, 14(9), 211. https://doi.org/10.3390/computation14090211
