mai₂ lab.

Human-imperceptible Perturbations

Human-imperceptible Perturbations

Deep learning models can be confidently fooled by input perturbations too small for humans to perceive. This phenomenon — adversarial perturbation — is both a vulnerability and a window into how machines and humans perceive the world differently.

We study this from two angles: the theory of robustness to adversarial perturbations (e.g. analyzing training dynamics through a mean-field lens, or pretraining strategies for in-context learners), and the design and analysis of attacks — from superclass-level misclassification to frequency-domain and skeleton-based attacks — that reveal how these vulnerabilities generalize across data modalities.

Progress so far

We’ve published theoretical work explaining learning from adversarial perturbations at NeurIPS/ICLR, analyzed adversarial training dynamics via mean-field theory (NeurIPS 2023, Spotlight), and shown that adversarial pretraining can make in-context learners universally robust (ICLR 2026). On the attack side, we’ve proposed superclass-level adversarial attacks (ICML 2022 workshop), frequency-spectrum-based attacks for general robustness (ECCV 2023 workshop), and bone-length and Fourier-based robustness analyses for skeleton-based action recognition (AAAI 2022; CVIU 2024), among other results.

Related Publications

★ Top venue* Corresponding author

  • ★ Adversarially Pretrained Transformers May Be Universally Robust In-Context Learners

    Soichiro Kumano, Hiroshi Kera, Toshihiko Yamasaki

    International Conference on Learning Representations (ICLR), 2026 · pp. 124615–124659

  • Wide Two-Layer Networks can Learn from Adversarial Perturbations

    Soichiro Kumano, Hiroshi Kera, Toshihiko Yamasaki

    Meeting on Image Recognition and Understanding (MIRU 2025), 2025

  • ★ Theoretical Understanding of Learning from Adversarial Perturbations.

    Soichiro Kumano, Hiroshi Kera, Toshihiko Yamasaki

    International Conference on Learning Representations, 2024 · pp. 56484–56532

  • Fourier analysis on robustness of graph convolutional neural networks for skeleton-based action recognition

    Nariki Tanaka, Hiroshi Kera, Kazuhiko Kawamoto

    Computer Vision and Image Understanding, 2024 · pp. 103936–103936

  • ★ Adversarial Training from Mean Field PerspectiveSpotlight

    Soichiro Kumano, Hiroshi Kera, Toshihiko Yamasaki

    Advances in Neural Information Processing Systems, 2023 · pp. 75097–75150

  • Sparse fooling images: Fooling machine perception through unrecognizable images

    Soichiro Kumano, Hiroshi Kera, Toshihiko Yamasaki

    Pattern Recognition Letters, 2023 · pp. 259–265

  • Exploiting Frequency Spectrum of Adversarial Images for General Robustness

    Chun Yang Tan, Kazuhiko Kawamoto, Hiroshi Kera*

    Meeting on Image Recognition and Understanding (MIRU 2023), 2023

  • Superclass Adversarial Attack

    Soichiro Kumano, Hiroshi Kera, Toshihiko Yamasaki

    Meeting on Image Recognition and Understanding (MIRU 2022), 2022

  • ★ Adversarial Bone Length Attack on Action Recognition

    Nariki Tanaka, Hiroshi Kera, Kazuhiko Kawamoto

    Proceedings of the AAAI Conference on Artificial Intelligence, 2022, 2022 · pp. 2335–2343

  • Evolving Architectures With Gradient Misalignment Toward Low Adversarial Transferability

    Kevin Richard G. Operiano, Wanchalerm Pora, Hitoshi Iba, Hiroshi Kera

    IEEE Access, 2021 · pp. 164379–164393