Wavelet-Guided Frequency-Domain Adaptive Learning: Balancing Adversarial Defense and High-Fidelity Image Reconstruction

Deep learning has achieved remarkable success across diverse domains, including image recognition, segmentation, and restoration. However, adversarial attacks—where imperceptible perturbations are introduced to normal images to mislead models—pose significant security risks to deep neural networks, underscoring the critical need for robust adversarial defense strategies. Image reconstruction-based defense is widely adopted for its downstream model independence and flexibility, yet existing methods often prioritize defense effectiveness at the expense of image quality, limiting their applicability in high-stakes scenarios such as medical diagnosis and remote sensing. To address this imbalance, we propose WS-Net, a wavelet-guided frequency-domain adaptive denoising network. Leveraging the non-uniform distribution of adversarial noise, WS-Net decomposes images into low-frequency and high-frequency components via Discrete Wavelet Transform (DWT), applying denoising exclusively to high-frequency components to preserve critical structural information. At its core is the Swin Network Denoiser (SND), constructed with Swin Transformer-based blocks that utilize shifted window self-attention to accurately distinguish noise from image details. A multi-level loss function—combining pixel-level L1 loss, feature-level perceptual loss, style loss, and adversarial loss—constrains the model from multiple dimensions. Experimental results on the ImageNet dataset demonstrate that WS-Net outperforms state-of-the-art models, achieving a top-1 accuracy of 71.4% on clean images, 70.2% under Gaussian noise, and superior defense performance across nine adversarial attacks (e.g., 68.5% accuracy against CW attacks, 67.9% against DeepFool). Notably, WS-Net achieves a Peak Signal-to-Noise Ratio (PSNR) of 30.2 dB and a Structural Similarity Index (SSIM) of 0.87, balancing defense robustness and image fidelity effectively. The code for WS-Net is available at https://github.com/faaatwang/WS_Net.git .

Authors

Institutions

Publication Details

Journal
International Journal of Pattern Recognition and Artificial Intelligence
Published
2026-09-30
DOI
https://doi.org/10.1142/s0218001426540121
Primary Topic
Adversarial Robustness in Machine Learning
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

Wavelet-Guided Frequency-Domain Adaptive Learning: Balancing Adversarial Defense and High-Fidelity Image Reconstruction

Mengnan Du, Lipeng Zhang, Zhenwei Wang, Haizhou Wang et al.
International Journal of Pattern Recognition and Artificial Intelligence
Adversarial Robustness in Machine Learning
article

Wavelet-Guided Frequency-Domain Adaptive Learning: Balancing Adversarial Defense and High-Fidelity Image Reconstruction

Mengnan Du, Lipeng Zhang, Zhenwei Wang, Haizhou Wang, Cuixia Li, Wenwen Li
article en

Abstract

Deep learning has achieved remarkable success across diverse domains, including image recognition, segmentation, and restoration. However, adversarial attacks—where imperceptible perturbations are introduced to normal images to mislead models—pose significant security risks to deep neural networks, underscoring the critical need for robust adversarial defense strategies. Image reconstruction-based defense is widely adopted for its downstream model independence and flexibility, yet existing methods often prioritize defense effectiveness at the expense of image quality, limiting their applicability in high-stakes scenarios such as medical diagnosis and remote sensing. To address this imbalance, we propose WS-Net, a wavelet-guided frequency-domain adaptive denoising network. Leveraging the non-uniform distribution of adversarial noise, WS-Net decomposes images into low-frequency and high-frequency components via Discrete Wavelet Transform (DWT), applying denoising exclusively to high-frequency components to preserve critical structural information. At its core is the Swin Network Denoiser (SND), constructed with Swin Transformer-based blocks that utilize shifted window self-attention to accurately distinguish noise from image details. A multi-level loss function—combining pixel-level L1 loss, feature-level perceptual loss, style loss, and adversarial loss—constrains the model from multiple dimensions. Experimental results on the ImageNet dataset demonstrate that WS-Net outperforms state-of-the-art models, achieving a top-1 accuracy of 71.4% on clean images, 70.2% under Gaussian noise, and superior defense performance across nine adversarial attacks (e.g., 68.5% accuracy against CW attacks, 67.9% against DeepFool). Notably, WS-Net achieves a Peak Signal-to-Noise Ratio (PSNR) of 30.2 dB and a Structural Similarity Index (SSIM) of 0.87, balancing defense robustness and image fidelity effectively. The code for WS-Net is available at https://github.com/faaatwang/WS_Net.git .

International Journal of Pattern Recognition and Artificial Intelligence
Twitter (United States) (US)
Sustainable cities and communities
Openalex Percentile: Top 9%
Adversarial Robustness in Machine Learning
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.