Research Article
From Spatial to Spectral Domain, a New Perspective for Detecting Adversarial Examples
Figure 4
The whole framework of our HLFD method. It is divided into three parts: extracting high-level representation (a), extracting high-frequency component (b), and training process (c). (a) and (b) can be considered as data preprocessing. The detector will be trained on these transformed data.