Human-imperceptible Perturbations

Deep learning models can be confidently fooled by input perturbations too small for humans to perceive. This phenomenon — adversarial perturbation — is both a vulnerability and a window into how machines and humans perceive the world differently.
We study this from two angles: the theory of robustness to adversarial perturbations (e.g. analyzing training dynamics through a mean-field lens, or pretraining strategies for in-context learners), and the design and analysis of attacks — from superclass-level misclassification to frequency-domain and skeleton-based attacks — that reveal how these vulnerabilities generalize across data modalities.
Progress so far
We’ve published theoretical work explaining learning from adversarial perturbations at NeurIPS/ICLR, analyzed adversarial training dynamics via mean-field theory (NeurIPS 2023, Spotlight), and shown that adversarial pretraining can make in-context learners universally robust (ICLR 2026). On the attack side, we’ve proposed superclass-level adversarial attacks (ICML 2022 workshop), frequency-spectrum-based attacks for general robustness (ECCV 2023 workshop), and bone-length and Fourier-based robustness analyses for skeleton-based action recognition (AAAI 2022; CVIU 2024), among other results.
Related Publications
★ Top venue* Corresponding author
★ Adversarially Pretrained Transformers May Be Universally Robust In-Context Learners
Soichiro Kumano, Hiroshi Kera, Toshihiko Yamasaki
International Conference on Learning Representations (ICLR), 2026 · pp. 124615–124659
Wide Two-Layer Networks can Learn from Adversarial Perturbations
Soichiro Kumano, Hiroshi Kera, Toshihiko Yamasaki
Meeting on Image Recognition and Understanding (MIRU 2025), 2025
★ Theoretical Understanding of Learning from Adversarial Perturbations.
Soichiro Kumano, Hiroshi Kera, Toshihiko Yamasaki
International Conference on Learning Representations, 2024 · pp. 56484–56532
Fourier analysis on robustness of graph convolutional neural networks for skeleton-based action recognition
Nariki Tanaka, Hiroshi Kera, Kazuhiko Kawamoto
Computer Vision and Image Understanding, 2024 · pp. 103936–103936
★ Adversarial Training from Mean Field PerspectiveSpotlight
Soichiro Kumano, Hiroshi Kera, Toshihiko Yamasaki
Advances in Neural Information Processing Systems, 2023 · pp. 75097–75150
Sparse fooling images: Fooling machine perception through unrecognizable images
Soichiro Kumano, Hiroshi Kera, Toshihiko Yamasaki
Pattern Recognition Letters, 2023 · pp. 259–265
Exploiting Frequency Spectrum of Adversarial Images for General Robustness
Chun Yang Tan, Kazuhiko Kawamoto, Hiroshi Kera*
Meeting on Image Recognition and Understanding (MIRU 2023), 2023
Superclass Adversarial Attack
Soichiro Kumano, Hiroshi Kera, Toshihiko Yamasaki
Meeting on Image Recognition and Understanding (MIRU 2022), 2022
★ Adversarial Bone Length Attack on Action Recognition
Nariki Tanaka, Hiroshi Kera, Kazuhiko Kawamoto
Proceedings of the AAAI Conference on Artificial Intelligence, 2022, 2022 · pp. 2335–2343
Evolving Architectures With Gradient Misalignment Toward Low Adversarial Transferability
Kevin Richard G. Operiano, Wanchalerm Pora, Hitoshi Iba, Hiroshi Kera
IEEE Access, 2021 · pp. 164379–164393
