Work place: Computer Science and Engineering, Sharda University, Greater Noida. Uttar Pradesh, India
E-mail: anil.sagar@sharda.ac.in
Website:
Research Interests:
Biography
Dr. Anil Kumar Sagar is currently a Professor in the Department of Computer Science and Engineering, School of Engineering and Technology, Sharda University, India. His ORCID iD is 0000-0002-5991-2835. He earned his Ph.D. from Jawaharlal Nehru University (JNU), New Delhi, with specialization in Ad-hoc Networks. He completed his B.E. in Computer Science and Engineering from G. B. Pant Engineering College, Pauri Garhwal, and his M.Tech. from JSS Academy of Technical Education (JSSATE), Noida. Dr. Sagar is an active member of editorial boards and review committees for several national and international journals and has served as a program and organizing committee member for multiple conferences.
By Surekha M. Anil Kumar Sagar Vineeta Khemchandani
DOI: https://doi.org/10.5815/ijisa.2026.04.08, Pub. Date: 8 Aug. 2026
Machine learning models, particularly deep learning architectures, achieve high performance in prediction tasks but remain susceptible to adversarial attacks. This study aims to enhance the robustness of Convolutional Neural Networks (CNNs), Deep Neural Networks (DNNs), and Recurrent Neural Networks (RNNs), thereby improving the security of machine learning systems. A three-step approach is adopted. First, benign sample classification is performed using the MNIST benchmark dataset. Second, adversarial attacks, namely Projected Gradient Descent (PGD), DeepFool (DF), and the Fast Gradient Sign Method (FGSM), are launched on the trained models, resulting in significant performance degradation. Based on the biased outputs induced by adversarial perturbations, an adversarial detection model is subsequently established. Third, to counteract these attacks, various defense strategies, including adversarial training, defensive distillation, autoencoder-based denoising, ensemble methods, and feature squeezing are employed and evaluated using standard performance metrics and graphical analyses. The results indicate that, in the absence of defense mechanisms, PGD attacks lead to accuracy drops of approximately 27% in CNNs, 83% in DNNs, and 90% in RNNs, demonstrating severe model vulnerabilities. However, when defense strategies are applied, all models recover to an accuracy of at least 98.9%, with adversarial training improving performance under attack by up to 90%. Among the evaluated models, CNNs exhibit the highest baseline robustness, whereas DNNs and RNNs rely more heavily on defense mechanisms to maintain performance. These findings provide valuable insights into the development of secure and resilient machine learning systems capable of mitigating adversarial threats.
[...] Read more.Subscribe to receive issue release notifications and newsletters from MECS Press journals