Mohamed Nour kayad · Zenodo (CERN European Organization for Nuclear Research) 2026 · 2026
DOI: 10.5281/zenodo.22928551
Counts differ because each database indexes a different set of publications. We treat OpenAlex as the canonical count; Google Scholar is not shown (no API, and crawling it violates its ToS).
Building upon a spectral-geometric framework for latent representations, we extend graph-Laplacian and heat-diffusion diagnostics to high-dimensional deep neural architectures under directed adversarial perturbations. We construct layer-wise reference graphs from clean activations and evaluate a hierarchy of high-frequency spectral residuals E(l) hi and local diffusion signatures D(l)t . These features are aggregated into a calibrated abstention score whose rejection threshold is selected on a held-out in-distribution calibration set. We emphasize that adversarial perturbations need not universally induce high-frequency spectral shifts at any fixed layer: such shifts constitute an empirical detection hypothesis and can be targeted by adaptive attackers. Under a representation-separation assumption, however, a multi-layer detector can identify deviations missed by scalar confidence scores or single-layer diagnostics. We report benchmark protocol for ResNet-50 and ViT-B/16 under FGSM, PGD, transfer, AutoAttack, and detector-adaptive attacks. In the reported experimental configuration, multi-layer spectral filtering separates clean and attacked activation trajectories more effectively than maximum softmax probability, energy scores, and a final-layer-only residual. The method provides a calibrated selective-prediction mechanism rather than a universal adversarial robustness guarantee.
No comments yet — start the discussion below.