Generalization to other structured transform families

Extend the proposed DGF-based adversarial attack framework to other families of structured transforms beyond discrete Gabor frames.

Background

The paper develops an adversarial attack methodology based on overcomplete, non-orthogonal discrete Gabor frames (DGFs). Its perturbation geometry is defined through a weighted DGF norm, and the resulting projected-gradient attack is characterized analytically as a projection onto a transform-induced ellipsoid. The authors note that the overcompleteness underlying this construction may apply more broadly to structured transform families, but they do not establish such a generalization in the paper.

References

The inherent overcompleteness of frames also suggests our framework could generalize to other structured transform families, which we leave as future work (cf. Section~\ref{conclusion}).

— Frame the adversary: a structure-aware attack methodology  (2609.31128 - Kouni et al., 25 Sep 2026) in Section 3, Main results, immediately following Proposition 1

For instance, our attack is a solution to space, so the latter can naturally replace the standard $\ell_p$-constrained inner maximization in adversarial training, to yield $\min_\theta\max_{\delta\in\mathcal{C}_{M_D}\,\mathcal{L}(x+\delta,y;\theta)$, for parameters $\theta$; we leave this strategy for future work (cf. Section~\ref{conclusion}).

— Frame the adversary: a structure-aware attack methodology  (2609.31128 - Kouni et al., 25 Sep 2026) in Section 5, Results and discussion, subsection “Baseline comparisons (and a note on visual fidelity)”