Mohamed Nour kayad · Zenodo (CERN European Organization for Nuclear Research) 2026 · 2026
DOI: 10.5281/zenodo.22928078
Counts differ because each database indexes a different set of publications. We treat OpenAlex as the canonical count; Google Scholar is not shown (no API, and crawling it violates its ToS).
Building upon a spectral-geometric framework for latent representations, we extend graph-Laplacian and heatdiusion diagnostics to high-dimensional deep neural architectures under directed adversarial perturbations. We construct layer-wise reference graphs from clean activations and evaluate a hierarchy of high-frequency spectral residuals E(l)hi and local diusion signatures D(l)t . These features are aggregated into a calibrated abstention score whose rejection threshold is selected on a held-out in-distribution calibration set. We emphasize that adversarial perturbations need not universally induce high-frequency spectral shifts at any xed layer: such shifts constitute an empirical detection hypothesis and can be targeted by adaptive attackers. Under a representation-separation assumption, however, a multi-layer detector can identify deviations missed by scalar condence scores or single-layer diagnostics. We report a benchmark protocol for ResNet-50 and ViT-B/16 under FGSM, PGD, transfer, AutoAttack, and detector-adaptive attacks. In the reported experimental conguration, multi-layer spectral ltering separates clean and attacked activation trajectories more eectively than maximum softmax probability, energy scores, and a nal-layer-only residual. The method provides a calibrated selective-prediction mechanism rather than a universal adversarial robustness guarantee
No comments yet — start the discussion below.