An adversarial training method based on joint labelsmoothing can train a neural network model capable of resisting different attack perturbation sizes during the training process. The model can identify the existence of adversarial samples under large perturbation attacks and reject their output results, and can correctly identify the true category of samples under small perturbation attacks.