{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,25]],"date-time":"2026-08-25T20:52:34Z","timestamp":1787691154291,"version":"build-2784847793"},"reference-count":46,"publisher":"MDPI AG","issue":"15","license":[{"start":{"date-parts":[[2024,7,26]],"date-time":"2024-07-26T00:00:00Z","timestamp":1721952000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"Key Lab of Reliability and Environmental Engineering Technology","award":["6142004200401"],"award-info":[{"award-number":["6142004200401"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>The vulnerability of modern neural networks to random noise and deliberate attacks has raised concerns about their robustness, particularly as they are increasingly utilized in safety- and security-critical applications. Although recent research efforts were made to enhance robustness through retraining with adversarial examples or employing data augmentation techniques, a comprehensive investigation into the effects of training data perturbations on model robustness remains lacking. This paper presents the first extensive empirical study investigating the influence of data perturbations during model retraining. The experimental analysis focuses on both random and adversarial robustness, following established practices in the field of robustness analysis. Various types of perturbations in different aspects of the dataset are explored, including input, label, and sampling distribution. Single-factor and multi-factor experiments are conducted to assess individual perturbations and their combinations. The findings provide insights into constructing high-quality training datasets for optimizing robustness and recommend the appropriate degree of training set perturbations that balance robustness and correctness, and contribute to understanding model robustness in deep learning and offer practical guidance for enhancing model performance through perturbed retraining, promoting the development of more reliable and trustworthy deep learning systems for safety-critical applications.<\/jats:p>","DOI":"10.3390\/s24154874","type":"journal-article","created":{"date-parts":[[2024,7,26]],"date-time":"2024-07-26T14:39:08Z","timestamp":1722004748000},"page":"4874","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":7,"title":["An Empirical Study on the Effect of Training Data Perturbations on Neural Network Robustness"],"prefix":"10.3390","volume":"24","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-5813-3605","authenticated-orcid":false,"given":"Jie","family":"Wang","sequence":"first","affiliation":[{"name":"The Key Laboratory on Reliability and Environment Engineering Technology, School of Reliability and Systems Engineering, Beihang University, Beijing 100191, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zili","family":"Wu","sequence":"additional","affiliation":[{"name":"CRRC Zhuzhou Institute Co., Ltd., Zhuzhou 412001, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Minyan","family":"Lu","sequence":"additional","affiliation":[{"name":"The Key Laboratory on Reliability and Environment Engineering Technology, School of Reliability and Systems Engineering, Beihang University, Beijing 100191, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4791-5940","authenticated-orcid":false,"given":"Jun","family":"Ai","sequence":"additional","affiliation":[{"name":"The Key Laboratory on Reliability and Environment Engineering Technology, School of Reliability and Systems Engineering, Beihang University, Beijing 100191, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2024,7,26]]},"reference":[{"key":"ref_1","unstructured":"Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I., and Fergus, R. (2014). Intriguing properties of neural networks. arXiv."},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Moosavi-Dezfooli, S.-M., Fawzi, A., and Frossard, P. (2016, January 27\u201330). DeepFool: A Simple and Accurate Method to Fool Deep Neural Networks. Proceedings of the 2016 IEEE Conference on Computer Vision and Pattern Recognition (CVPR), Las Vegas, NV, USA.","DOI":"10.1109\/CVPR.2016.282"},{"key":"ref_3","unstructured":"Goodfellow, I.J., Shlens, J., and Szegedy, C. (2015, January 7\u20139). Explaining and Harnessing Adversarial Examples. Proceedings of the International Conference on Learning Representations (ICLR), San Diego, CA, USA."},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Hamdi, A., M\u00fcller, M., and Ghanem, B. (2020, January 7\u201312). SADA: Semantic adversarial diagnostic attacks for autonomous applications. Proceedings of the AAAI Conference on Artificial Intelligence, New York, NY, USA.","DOI":"10.1609\/aaai.v34i07.6722"},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Uli\u010dn\u00fd, M., Lundstr\u00f6m, J., and Byttner, S. (2016). Robustness of Deep Convolutional Neural Networks for Image Recognition, Springer International Publishing.","DOI":"10.1007\/978-3-319-30447-2_2"},{"key":"ref_6","unstructured":"Madry, A., Makelov, A., Schmidt, L., Tsipras, D., and Vladu, A. (2017). Towards Deep Learning Models Resistant to Adversarial Attacks. arXiv."},{"key":"ref_7","unstructured":"Maini, P., Wong, E., and Kolter, Z. (2020, January 13\u201318). Adversarial robustness against the union of multiple perturbation models. Proceedings of the International Conference on Machine Learning, Virtual Event."},{"key":"ref_8","unstructured":"Pang, T., Xu, K., Du, C., Chen, N., and Zhu, J. (2019, January 10\u201315). Improving adversarial robustness via promoting ensemble diversity. Proceedings of the International Conference on Machine Learning, Long Beach, CA, USA."},{"key":"ref_9","unstructured":"Schott, L., Rauber, J., Bethge, M., and Brendel, W. (2019, January 6\u20139). Towards the first adversarially robust neural network model on MNIST. Proceedings of the International Conference on Learning Representations, New Orleans, LA, USA."},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Bai, T., Luo, J., Zhao, J., Wen, B., and Wang, Q. (2021). Recent advances in adversarial training for adversarial robustness. arXiv.","DOI":"10.24963\/ijcai.2021\/591"},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Huang, C., Hu, Z., Huang, X., and Pei, K. (2021). Statistical Certification of Acceptable Robustness for Neural Networks, Springer.","DOI":"10.1007\/978-3-030-86362-3_7"},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Mohapatra, J., Weng, T.-W., Chen, P.-Y., Liu, S., and Daniel, L. (2020, January 13\u201319). Towards verifying robustness of neural networks against a family of semantic perturbations. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, Seattle, WA, USA.","DOI":"10.1109\/CVPR42600.2020.00032"},{"key":"ref_13","first-page":"15313","article-title":"Certifying geometric robustness of neural networks","volume":"32","author":"Balunovic","year":"2019","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Alcorn, M.A., Li, Q., Gong, Z., Wang, C., Mai, L., Ku, W.-S., and Nguyen, A. (2019, January 15\u201318). Strike (with) a pose: Neural networks are easily fooled by strange poses of familiar objects. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, Long Beach, CA, USA.","DOI":"10.1109\/CVPR.2019.00498"},{"key":"ref_15","unstructured":"(2020). Artificial Intelligence\u2014Life Cycle Processes and Quality Requirements\u2014Part 2: Robustness (Standard No. DIN SPEC 92001-2)."},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Xie, L., Wang, J., Wei, Z., Wang, M., and Tian, Q. (2016, January 27\u201330). DisturbLabel: Regularizing CNN on the Loss Layer. Proceedings of the 2016 IEEE Conference on Computer Vision and Pattern Recognition (CVPR), Las Vegas, NV, USA.","DOI":"10.1109\/CVPR.2016.514"},{"key":"ref_17","unstructured":"Rice, L., Wong, E., and Kolter, Z. (2020, January 13\u201318). Overfitting in adversarially robust deep learning. Proceedings of the International Conference on Machine Learning, Virtual Event."},{"key":"ref_18","unstructured":"Bastani, O., Ioannou, Y., Lampropoulos, L., Vytiniotis, D., Nori, A.V., and Criminisi, A. (2016, January 5\u201310). Measuring Neural Net Robustness with Constraints. Proceedings of the NIPS\u201916: Proceedings of the 30th International Conference on Neural Information Processing Systems, Barcelona, Spain."},{"key":"ref_19","unstructured":"Jiang, L., Huang, D., Liu, M., and Yang, W. (2019). Beyond Synthetic Noise: Deep Learning on Controlled Noisy Labels. arXiv."},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Bekker, A.J., and Goldberger, J. (2016, January 20\u201325). Training deep neural-networks based on unreliable labels. Proceedings of the 2016 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP), Shanghai, China.","DOI":"10.1109\/ICASSP.2016.7472164"},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Wang, J., Lu, M., Ai, J., and Sun, X. (2020, January 28\u201329). The Quantitative Relationship between Adversarial Training and Robustness of CNN Model. Proceedings of the 2020 7th International Conference on Dependable Systems and Their Applications (DSA), Xi\u2019an, China.","DOI":"10.1109\/DSA51864.2020.00092"},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Liu, Y., Lu, M., Peng, D., Wang, J., and Ai, J. (2020, January 28\u201329). Analysis on Adversarial Robustness of Deep Learning Model LeNet-5 Based on Data Perturbation. Proceedings of the 2020 7th International Conference on Dependable Systems and Their Applications (DSA), Xi\u2019an, China.","DOI":"10.1109\/DSA51864.2020.00029"},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Wu, Z., Ai, J., Lu, M., Wang, J., and Yan, L. (2022, January 4\u20135). The Correlation between Training Set Perturbations and Robustness for CNN Models. Proceedings of the 2022 9th International Conference on Dependable Systems and Their Applications (DSA), Wulumuqi, China.","DOI":"10.1109\/DSA56465.2022.00077"},{"key":"ref_24","unstructured":"Goodfellow, I., Bengio, Y., and Courville, A. (2016). Deep Learning, MIT Press."},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Liu, N., Yang, H., and Hu, X. (2018, January 19\u201323). Adversarial detection with model interpretation. Proceedings of the 24th ACM SIGKDD International Conference on Knowledge Discovery & Data Mining, London, UK.","DOI":"10.1145\/3219819.3220027"},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"126576","DOI":"10.1016\/j.neucom.2023.126576","article-title":"Unity is strength: Improving the detection of adversarial examples with ensemble approaches","volume":"554","author":"Craighero","year":"2023","journal-title":"Neurocomputing"},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Wang, J., Dong, G., Sun, J., Wang, X., and Zhang, P. (2018). Adversarial Sample Detection for Deep Neural Network through Model Mutation Testing. arXiv.","DOI":"10.1109\/ICSE.2019.00126"},{"key":"ref_28","unstructured":"Metzen, J.H., Tim, G., Volker, F., and Bastian, B. (2017). On detecting adversarial perturbations. arXiv."},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Papernot, N., Mcdaniel, P., Wu, X., Jha, S., and Swami, A. (2016, January 22\u201326). Distillation as a Defense to Adversarial Perturbations Against Deep Neural Networks. Proceedings of the 2016 IEEE Symposium on Security and Privacy (SP), San Jose, CA, USA.","DOI":"10.1109\/SP.2016.41"},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"3048","DOI":"10.1109\/TPAMI.2021.3055564","article-title":"Knowledge Distillation and Student-Teacher Learning for Visual Intelligence: A Review and New Outlooks","volume":"44","author":"Wang","year":"2022","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"ref_31","first-page":"38","article-title":"Distilling the Knowledge in a Neural Network","volume":"14","author":"Hinton","year":"2015","journal-title":"Comput. Sci."},{"key":"ref_32","doi-asserted-by":"crossref","first-page":"395","DOI":"10.1162\/coli_a_00476","article-title":"Certified robustness to text adversarial attacks by randomized [mask]","volume":"49","author":"Zeng","year":"2023","journal-title":"Comput. Linguist."},{"key":"ref_33","unstructured":"Pfrommer, S., Anderson, B.G., and Sojoudi, S. (2023). Projected randomized smoothing for certified adversarial robustness. arXiv."},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"6453","DOI":"10.1109\/ACCESS.2020.3048120","article-title":"Gradient masking of label smoothing in adversarial robustness","volume":"9","author":"Lee","year":"2020","journal-title":"IEEE Access"},{"key":"ref_35","unstructured":"Goodfellow, I. (2018). Gradient masking causes clever to overestimate adversarial perturbation size. arXiv."},{"key":"ref_36","doi-asserted-by":"crossref","unstructured":"Moon, H.C., Joty, S., and Chi, X. (2022, January 14\u201318). GradMask: Gradient-Guided Token Masking for Textual Adversarial Example Detection. Proceedings of the 28th ACM SIGKDD Conference on Knowledge Discovery and Data Mining, Washington, DC, USA.","DOI":"10.1145\/3534678.3539206"},{"key":"ref_37","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1109\/TSE.2019.2962027","article-title":"Machine Learning Testing: Survey, Landscapes and Horizons","volume":"48","author":"Zhang","year":"2020","journal-title":"IEEE Trans. Softw. Eng."},{"key":"ref_38","doi-asserted-by":"crossref","unstructured":"Katz, G., Barrett, C., Dill, D.L., Julian, K., and Kochenderfer, M.J. (2017). Reluplex: An Efficient SMT Solver for Verifying Deep Neural Networks,  Springer. International Conference on Computer Aided Verification.","DOI":"10.1007\/978-3-319-63387-9_5"},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Ruan, W., Wu, M., Sun, Y., Huang, X., and Kwiatkowska, M. (2019, January 10\u201316). Global Robustness Evaluation of Deep Neural Networks with Provable Guarantees for the Hamming Distance. Proceedings of the Twenty-Eighth International Joint Conference on Artificial Intelligence IJCAI-19, Macao, China.","DOI":"10.24963\/ijcai.2019\/824"},{"key":"ref_40","doi-asserted-by":"crossref","unstructured":"Huang, P., Yang, Y., Liu, M., Jia, F., Ma, F., and Zhang, J. (2022, January 18\u201322). \u03b5-weakened robustness of deep neural networks. Proceedings of the 31st ACM SIGSOFT International Symposium on Software Testing and Analysis, Virtual, Republic of Korea.","DOI":"10.1145\/3533767.3534373"},{"key":"ref_41","unstructured":"Wicker, M., Laurenti, L., Patane, A., and Kwiatkowska, M. Probabilistic Safety for Bayesian Neural Networks. Proceedings of the 36th Conference on Uncertainty in Artificial Intelligence (UAI), Proceedings of Machine Learning Research, Virtual, 3\u20136 August 2020."},{"key":"ref_42","unstructured":"Hendrycks, D., and Dietterich, T. (2019, January 6\u20139). Benchmarking Neural Network Robustness to Common Corruptions and Perturbations. Proceedings of the International Conference on Learning Representations, New Orleans, LA, USA."},{"key":"ref_43","doi-asserted-by":"crossref","first-page":"2278","DOI":"10.1109\/5.726791","article-title":"Gradient-based learning applied to document recognition","volume":"86","author":"Lecun","year":"1998","journal-title":"Proc. IEEE"},{"key":"ref_44","doi-asserted-by":"crossref","first-page":"84","DOI":"10.1145\/3065386","article-title":"ImageNet classification with deep convolutional neural networks","volume":"60","author":"Krizhevsky","year":"2017","journal-title":"Commun. ACM"},{"key":"ref_45","unstructured":"Croce, F., and Hein, M. (2019). Provable robustness against all adversarial lp-perturbations for p \u2265 1. arXiv."},{"key":"ref_46","unstructured":"Weng, L., Chen, P.-Y., Nguyen, L., Squillante, M., Boopathy, A., Oseledets, I., and Daniel, L. (2019, January 10\u201315). PROVEN: Verifying robustness of neural networks with a probabilistic approach. Proceedings of the International Conference on Machine Learning, Long Beach, CA, USA."}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/24\/15\/4874\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T15:24:41Z","timestamp":1760109881000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/24\/15\/4874"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,7,26]]},"references-count":46,"journal-issue":{"issue":"15","published-online":{"date-parts":[[2024,8]]}},"alternative-id":["s24154874"],"URL":"https:\/\/doi.org\/10.3390\/s24154874","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,7,26]]}}}