Chao Li, Handing Wang, Wenbiao Yao, Tingsong Jiang, B. Qu
2026.1.1IEEE Transactions on Emerging Topics in Computational Intelligence
Abstract
The security threats of adversarial examples to deep neural networks have been widely studied, where query-based attacks, an important black-box attack method, have attracted the attention of many researchersdue to their practicability in reality. However, they usually require a large number of queries. Although some promising studies have been proposed to address the above issues, it is difficult for them to maintain a balance between the low query number and the perturbation imperceptibility. In addition, the existing query-based attacks generally add perturbations to the spatial domain of the image, ignoring the importance of the frequency domain of the image. In this work, we propose a query-efficient and visually discreet attack method by manipulating the frequency domain information of images. Specifically, we first systematically analyze the influence of image frequency domain on model decision and human visual system. Then, a novel adversarial attack problem formulation is proposed, where a set of low-dimensional discrete matrices are designed as optimization variables to perturb the frequency domain information of the image. Finally, the genetic algorithm is introduced to optimize the discrete matrices for the purpose of improving the attack performance. The proposed method is compared with a number of the query-efficient based attack methods on the ImageNet dataset, and the empirical results demonstrate that our method can effectively generate adversarial examples using only 40 queries.
Citation format
LI, Chao, et al. Adversarial attack by manipulating frequency domain. IEEE Transactions on Emerging Topics in Computational Intelligence, 2026: 1–13.