2026· ITEGAM- Journal of Engineering and Technology for Industrial Applications (ITEGAM-JETIA)· 0 citations
TL;DR
Optimize Deep Learning–based Adversarial Defense Mechanism (ODL-ADM) is proposed in this work, which projects adversarial samples into an immune feature space that is both discriminative and resistant to perturbations.
Abstract
In computer vision and pattern recognition tasks, deep learning models are widely used, especially in face recognition systems. Even with their excellent performance, these models are still susceptible to a variety of adversarial manipulations, such as blur, additive noise, translation, flipping, scaling, rotation, and changes in illumination. Furthermore, some architectures might experience optimization problems like vanishing gradients, which would further impair the stability of the model. In order to provide robust face verification under adversarial attack, Optimized Deep Learning–based Adversarial Defense Mechanism (ODL-ADM) is proposed in this work. It projects adversarial samples into an immune feature space. A Learnable Convolutional Principal Component Network (LCPCN) is incorporated into the framework to create a representation space that is both discriminative and resistant to perturbations. Adversarially corrupted facial images are suppressed and reconstructed using a Stacked Attention-based Residual Generative Adversarial Network (SARGAN). Accurate identity recognition is achieved by an Improved Cross-Triple MobileNetV1 architecture after perturbation removal. Enhanced Fire Hawk Optimization (EFHO) is used for performance maximization and parameter tuning to further improve recognition performance. Following image reconstruction and adversarial perturbation removal, the suggested model achieves a 98% face recognition accuracy.
The research methodology involved a systematic literature review using the Scopus database, adhering to Preferred Reporting Items for Systematic Reviews and Meta-Analyses guidelines, and focusing on recent advancements in attack and defence techniques.
Machine learning models, particularly deep learning architectures, achieve high performance in prediction tasks but remain susceptible to adversarial attacks. This study aims to enhance the robustness of Convolutional Neural Networks (CNNs), Deep Neural Networks (DNNs), and Recurrent Neural Networks (RNNs), thereby improving the security of machine learning systems. A three-step approach is adopted. First, benign sample classification is performed using the MNIST benchmark dataset. Second, adversarial attacks, namely Projected Gradient Descent (PGD), DeepFool (DF), and the Fast Gradient Sign Method (FGSM), are launched on the trained models, resulting in significant performance degradation. Based on the biased outputs induced by adversarial perturbations, an adversarial detection model is subsequently established. Third, to counteract these attacks, various defense strategies, including adversarial training, defensive distillation, autoencoder-based denoising, ensemble methods, and feature squeezing are employed and evaluated using standard performance metrics and graphical analyses. The results indicate that, in the absence of defense mechanisms, PGD attacks lead to accuracy drops of approximately 27% in CNNs, 83% in DNNs, and 90% in RNNs, demonstrating severe model vulnerabilities. However, when defense strategies are applied, all models recover to an accuracy of at least 98.9%, with adversarial training improving performance under attack by up to 90%. Among the evaluated models, CNNs exhibit the highest baseline robustness, whereas DNNs and RNNs rely more heavily on defense mechanisms to maintain performance. These findings provide valuable insights into the development of secure and resilient machine learning systems capable of mitigating adversarial threats.
Surekha M., A. K. Sagar, Vineeta Khemchandani· International Journal of Int...· 0 citations
This study builds and test a Deep Convolutional Generative Adversarial Network (DCGAN) that can produce realistic portraits of people's faces and proves that DCGANs are capable of creating realistic facial representations.
K. N. Reddy, A. Renuka· International Journal for Re...· 0 citations
This paper advocates for a forward-thinking approach that balances technical sophistication with human-centric principles, ensuring that adversarial deep learning evolves into a discipline not just of technical defense, but also of trust, transparency, and accountability.
Maisam Abbas, Ran-Zan Wang· IEEE Open Journal of the Com...· 0 citations
Empirical support is provided for the utility of structure-aware perturbation refinement in improving black-box adversarial transferability across heterogeneous visual architectures.
Qi-Rui Lu, Liansong Zong, Fu-Ran Liu et al.· Neural Networks· 0 citations
Face recognition becomes an important biometric implementation in any surveillance, access control, forensic and intelligent security system applications. Despite of technical advances in deep learning models, recognition accuracy normally affected by facial pose, illumination, occlusion, expression, aging factors and limited availability of labelled dataset. These challenges reduce the robustness of face recognition models in real world environments [1][2][3]. Recent researches demonstrated that the super-resolution techniques based on Generative Adversarial Networks (GANs) reconstruct high-quality facial images very effectively from low-resolution input images. It supports to improve feature representation and face recognition [4][5]. Therefore, this research motivated from this advancement and proposes an Adaptive Super-Resolution Generative Adversarial Network (Adaptive SRGAN) for face recognition. It integrates adaptive learning with image super resolution to reconstruct identity preserving high resolution facial images by employing adaptive learning rate optimization, dynamic loss weighting, attention guided feature enhancement and identity preserving loss functions. However, it enhances reconstruction quality by preserving discriminative facial characteristics [6]. The proposed model is expected to achieve higher Peak Signal to Noise Ratio (PSNR), Structural Similarity Index Measure (SSIM), recognition accuracy, precision, recall, and F1-score while reducing false acceptance and false rejection rates. Simultaneously, Adaptive SRGAN delivers a robust and scalable solution for improving face recognition systems.
M. Kirubakaran, A. S. Aneeshkumar· International journal of com...· 0 citations