Research questionCan preprocessing defenses detect adversarial attacks in depthwise-separable edge vision CNNs when they cannot restore predictions?Preprocessing defenses are often assumed to transfer across model architectures, but depthwise-separable CNNs may respond differently to adversarial perturbations than residual or Inception-style networks. Their failure to recover predictions may still produce measurable differences between clean and adversarial inputs, while image-quality scores may not reflect defensive value.