Work place: Computer Science and Engineering, Sharda University, Greater Noida, Uttar Pradesh, India
E-mail: surekhashivakumar@gmail.com
Website:
Research Interests: Artificial Intelligence
Biography
Surekha M. is a Ph.D. Scholar in Computer Science and Engineering at Sharda University,Greater Noida, India. Her ORCID ID is 0000-0002-7338-8267. Her research interests include Machine Learning, Cybersecurity, and Artificial Intelligence. She completed her M.Tech. (CSE) from Dr. A. P. J. Abdul Kalam University, India, and is currently pursuing her Ph.D. at Sharda University. She is working as an Assistant Professor at JSS Academy of Technical Education (JSSATE), Noida, Uttar Pradesh, India. She has over 10 years of teaching experience in the field of Computer Science and Engineering and has published 2 indexed journal papers, 3 Scopus-indexed papers, and 1 ESCI-indexed journal paper.
By Surekha M. Anil Kumar Sagar Vineeta Khemchandani
DOI: https://doi.org/10.5815/ijisa.2026.04.08, Pub. Date: 8 Aug. 2026
Machine learning models, particularly deep learning architectures, achieve high performance in prediction tasks but remain susceptible to adversarial attacks. This study aims to enhance the robustness of Convolutional Neural Networks (CNNs), Deep Neural Networks (DNNs), and Recurrent Neural Networks (RNNs), thereby improving the security of machine learning systems. A three-step approach is adopted. First, benign sample classification is performed using the MNIST benchmark dataset. Second, adversarial attacks, namely Projected Gradient Descent (PGD), DeepFool (DF), and the Fast Gradient Sign Method (FGSM), are launched on the trained models, resulting in significant performance degradation. Based on the biased outputs induced by adversarial perturbations, an adversarial detection model is subsequently established. Third, to counteract these attacks, various defense strategies, including adversarial training, defensive distillation, autoencoder-based denoising, ensemble methods, and feature squeezing are employed and evaluated using standard performance metrics and graphical analyses. The results indicate that, in the absence of defense mechanisms, PGD attacks lead to accuracy drops of approximately 27% in CNNs, 83% in DNNs, and 90% in RNNs, demonstrating severe model vulnerabilities. However, when defense strategies are applied, all models recover to an accuracy of at least 98.9%, with adversarial training improving performance under attack by up to 90%. Among the evaluated models, CNNs exhibit the highest baseline robustness, whereas DNNs and RNNs rely more heavily on defense mechanisms to maintain performance. These findings provide valuable insights into the development of secure and resilient machine learning systems capable of mitigating adversarial threats.
[...] Read more.Subscribe to receive issue release notifications and newsletters from MECS Press journals