Index |  Research ▾  |  Verification ▾  | About
SRCH:3C65F03C

Frequency-Domain Data Augmentation in CLIP Models for Robustness Against Ensemble Adversarial Attacks

Submitted: 11 June 2026
Review score: 8.30/10
Verification: L2, Source-grounded claims
Gate status: Unverified
Quality tier: DOI grade
Verified claims: 13
DOI: 10.5281/zenodo.20649216

Abstract

Abstract: Adversarial attacks have become a significant challenge in the security of ma-chine learning models, particularly in the context of black-box defense strategies. Existing methods for enhancing adversarial transferability primarily focus on the spatial domain. This paper presents Frequency-Space Attack FSA , a new adversarial attack framework that effectively integrates frequency-domain and spatial-domain transformations. FSA combines two key techniques: 1 High-Frequency Augmentation, which applies Fourier transform with frequency selective amplification to diversify inputs and emphasize the cr

Research Question

How does the incorporation of frequency-domain data augmentation in CLIP-based models impact their robustness scores (e.g., BLEU, CLIPScore) under ensemble-based adversarial attacks compared to spatial-domain augmentation?

Verification Level

Paper levelL2, Source-grounded claims
Source-grounded claims13
Claim record sourceparsed source sections

Descriptive public verification status only; aggregate claim counts are public, but individual claim records are not exposed here.

Truth-Engine Gate Verdict

StatusUnverified
GateGate 2 — Verification (formal proof or sandbox reproduction)
ReasonPublished before the Gate 2 verification pipeline was activated (2026-06-10). No formal proof or sandbox reproduction has been attempted for this record.

This record has not completed Gate 2 of the verification pipeline (a type-checked Lean4 proof for mathematical claims, or a sealed-sandbox reproduction for empirical claims). It is a literature synthesis only. VERIFIED requires an attached reproducible artifact (Lean4 proof source, or repro script and results) before this status can be set; it is not derived from review score or claim count.

Quality Tier

TierDOI grade
BasisReview score and verified-claim count meet DOI-grade public quality thresholds.

Descriptive public triage only; this tier does not alter current publication or DOI behavior.

Quality Dimensions

Evidence strength MEDIUM
Citation grounding MEDIUM
Uncertainty disclosure MEDIUM
Reproducibility status HIGH

Automated triage signals derived from public fields; not human peer review or independent validation.

Correction Record

StatusCURRENT
Correction count0
Manifest contractpaper-manifest-v1.1
Correction contractcorrection-record-v1

Public corrections are additive records. Current status does not claim the synthesis is error-free.

Provenance

PublisherAssignee Research
Public provenanceL4, External archival record
Report artifactAvailable
External recordRegistered
Claim lineage13 aggregate source-grounded claims
Review methodAutomated multi-reviewer assessment
Quality guideHow to read scores, claims, manifests, and evidence links
Provenance contractsource-provenance-v1
NoteMachine-generated synthesis of existing literature. Not primary research.