Home / Journals / CMC / Online First / doi:10.32604/cmc.2026.082631
Special Issues
Table of Content

Open Access

ARTICLE

Adversarial Defense Method Based on Dual Mode Pixel Transformation and Multi-Objective Spatial Optimization

Jiaying Li1, Xiujuan Wang1,*, Shuhan Han2, Liya Xu1, Changxing Wang1
1 College of Computer Science, Beijing University of Technology, Beijing, China
2 School of Cyberspace Security, Beijing University of Posts and Telecommunications, Beijing, China
* Corresponding Author: Xiujuan Wang. Email: email

Computers, Materials & Continua https://doi.org/10.32604/cmc.2026.082631

Received 19 March 2026; Accepted 18 June 2026; Published online 21 July 2026

Abstract

Deep neural networks are widely applied in computer vision tasks but remain highly vulnerable to adversarial attacks. Tiny and imperceptible perturbations can cause severe model misclassification. Most existing defense methods improve robustness but significantly reduce model accuracy on clean examples. To address this issue, we propose a defense framework combining pixel value transformation and spatial transformation. The proposed method divides the input image into two complementary regions. Feature compression is applied to one region to reduce model sensitivity to subtle perturbations. Intense reversible pixel transformation is applied to the other region to disrupt the spatial distribution of the perturbations. Furthermore, a spatial transformation module is introduced to enhance defense capabilities against strong attacks. This module adjusts the spatial structure of the image, increases nonlinear relationships among pixels, and suppresses perturbation transfer effects. A Multiple Objective Particle Swarm Optimization (MOPSO) is employed to adaptively search for optimal transformation parameters, achieving a balance between robustness and accuracy. An inverse transformation mechanism is proposed to restore attacked examples back to a form recognizable to human eyes, which effectively destroys the imperceptible nature of adversarial examples. Experimental results demonstrate that the proposed method successfully resists various adversarial attacks while maintaining high recognition accuracy on clean images. The proposed reversible defense framework demonstrates theoretical universality and scalability, providing an effective new approach for adversarial defense.

Keywords

Adversarial examples; adversarial defense; pixel-wise transformation; model security
  • 150

    View

  • 26

    Download

  • 0

    Like

Share Link