Enhanced Robustness in Neural Network Models against Adversarial Attacks and their Performance Analysis

PDF (2440KB), PP.138-160

Views: 0 Downloads: 0

Author(s)

Surekha M. 1,2,* Anil Kumar Sagar 3 Vineeta Khemchandani 4

1. Computer Science and Engineering, Sharda University, Greater Noida, Uttar Pradesh, India

2. JSS Academy of Technical Education, Noida, Uttar Pradesh, India

3. Computer Science and Engineering, Sharda University, Greater Noida. Uttar Pradesh, India

4. Computer Science and Engineering, Galgotias University Greater Noida, Uttar Pradesh, India

* Corresponding author.

DOI: https://doi.org/10.5815/ijisa.2026.04.08

Received: 4 Jan. 2026 / Revised: 15 Mar. 2026 / Accepted: 7 Jun. 2026 / Published: 8 Aug. 2026

Index Terms

Defense Strategy, Adversarial Attack, Neural Network Models, Machine Learning Robustness, Performance Evaluation Metrics

Abstract

Machine learning models, particularly deep learning architectures, achieve high performance in prediction tasks but remain susceptible to adversarial attacks. This study aims to enhance the robustness of Convolutional Neural Networks (CNNs), Deep Neural Networks (DNNs), and Recurrent Neural Networks (RNNs), thereby improving the security of machine learning systems. A three-step approach is adopted. First, benign sample classification is performed using the MNIST benchmark dataset. Second, adversarial attacks, namely Projected Gradient Descent (PGD), DeepFool (DF), and the Fast Gradient Sign Method (FGSM), are launched on the trained models, resulting in significant performance degradation. Based on the biased outputs induced by adversarial perturbations, an adversarial detection model is subsequently established. Third, to counteract these attacks, various defense strategies, including adversarial training, defensive distillation, autoencoder-based denoising, ensemble methods, and feature squeezing are employed and evaluated using standard performance metrics and graphical analyses. The results indicate that, in the absence of defense mechanisms, PGD attacks lead to accuracy drops of approximately 27% in CNNs, 83% in DNNs, and 90% in RNNs, demonstrating severe model vulnerabilities. However, when defense strategies are applied, all models recover to an accuracy of at least 98.9%, with adversarial training improving performance under attack by up to 90%. Among the evaluated models, CNNs exhibit the highest baseline robustness, whereas DNNs and RNNs rely more heavily on defense mechanisms to maintain performance. These findings provide valuable insights into the development of secure and resilient machine learning systems capable of mitigating adversarial threats.

Cite This Paper

Surekha M., Anil Kumar Sagar, Vineeta Khemchandani, "Enhanced Robustness in Neural Network Models against Adversarial Attacks and their Performance Analysis", International Journal of Intelligent Systems and Applications(IJISA), Vol.18, No.4, pp.138-160, 2026. DOI:10.5815/ijisa.2026.04.08

Reference

[1]Z. Zhou, H. Guan, M. M. Bhat, and J. Hsu, “Fake news detection via NLP is vulnerable to adversarial attacks,” arXiv preprint, arXiv:1901.09657, 2019.
[2]A. I. Newaz, A. K. Sikder, M. A. Rahman, and A. S. Uluagac, “A survey on security and privacy issues in modern healthcare systems: Attacks and defenses,” ACM Trans. Comput. Healthcare, vol. 2, no. 3, pp. 1–44, 2021.
[3]C. Sitawarin, A. N. Bhagoji, A. Mosenia, M. Chiang, and P. Mittal, “Darts: Deceiving autonomous cars with toxic signs,” arXiv preprint, arXiv:1802.06430, 2018.
[4]A. L. Caterini and D. E. Chang, “Recurrent neural networks,” in Deep Neural Networks in a Mathematical Framework, SpringerBriefs in Computer Science. Cham, Switzerland: Springer, 2018, doi: 10.1007/978-3-319-75304-1_5.
[5]J. Wang, C. Wang, Q. Lin, C. Luo, C. Wu, and J. Li, “Adversarial attacks and defenses in deep learning for image recognition: A survey,” Neurocomputing, vol. 514, pp. 162–181, 2022.
[6]X. Yuan, P. He, Q. Zhu, and X. Li, “Adversarial examples: Attacks and defenses for deep learning,” IEEE Transactions on Neural Networks and Learning Systems, vol. 30, no. 9, pp. 2805–2824, 2019. 
[7]N. Papernot, P. McDaniel, S. Jha, M. Fredrikson, Z. B. Celik, and A. Swami, “The limitations of deep learning in adversarial settings,” in Proceedings of the IEEE European Symposium on Security and Privacy (EuroS&P), pp. 372–387, 2016.
[8]S. Zhou, C. Liu, D. Ye, T. Zhu, W. Zhou, and P. S. Yu, “Adversarial attacks and defenses in deep learning: From a perspective of cybersecurity,” ACM Comput. Surv., vol. 55, no. 8, pp. 1–39, 2022.
[9]N. Akhtar, A. Mian, N. Kardan, and M. Shah, “Advances in adversarial attacks and defenses in computer vision: A survey,” IEEE Access, vol. 9, pp. 155161–155196, 2021.
[10]Kaviani, S., Shamshiri, S., & Sohn, I. (2023). A defense method against backdoor attacks on neural networks. Expert Systems with Applications, 213, 118990. 
[11]O. Özdenizci and R. Legenstein, “Adversarially robust spiking neural networks through conversion,” arXiv preprint arXiv:2311.09266, 2023.
[12]A. Oprea and A. Vassilev, “Adversarial machine learning: A taxonomy and terminology of attacks and mitigations,” Natl. Inst. Stand. Technol. (NIST), NIST AI 100-2 E2023, 2023.
[13]R. S. S. Kumar et al., “Adversarial machine learning—industry perspectives,” in Proc. IEEE Secur. Privacy Workshops (SPW), San Francisco, CA, USA, 2020, pp. 69–75.
[14]M. Macas, C. Wu, and W. Fuertes, “Adversarial examples: A survey of attacks and defenses in deep learning-enabled cybersecurity systems,” Expert Syst. Appl., vol. 238, p. 122223, 2024.
[15]H. Ren, T. Huang, and H. Yan, “Adversarial examples: Attacks and defenses in the physical world,” Int. J. Mach. Learn. Cybern., vol. 12, no. 11, pp. 3325–3336, 2021.
[16]Y. Zhang, T. Du, S. Ji, P. Tang, and S. Guo, “RNN-Guard: Certified robustness against multi-frame attacks for recurrent neural networks,” arXiv preprint, arXiv:2304.07980, 2023.
[17]A. H. Galib and B. Bashyal, “On the susceptibility and robustness of time series models through adversarial attack and defense,” arXiv preprint, arXiv:2301.03703, 2023.
[18]Y. Wang, D. Du, H. Hu, Z. Liang, and Y. Liu, “TSFool: Crafting highly-imperceptible adversarial time series through multi-objective attack,” in ECAI 2024, pp. 1422–1429, IOS Press, 2024.
[19]P. Sokerin, D. Anikin, S. Krehova, and A. Zaytsev, “Concealed adversarial attacks on neural networks for sequential data,” arXiv  preprint, arXiv:2502.20948, 2025.
[20]Goyal, S. Doddapaneni, M. M. Khapra, and B. Ravindran, “A survey of adversarial defenses and robustness in NLP,” ACM Comput. Surv., vol. 55, no. 14s, pp. 1–39, 2023.
[21]A. I. Newaz, A. K. Sikder, M. A. Rahman, and A. S. Uluagac, “A survey on security and privacy issues in modern healthcare systems: Attacks and defenses,” ACM Trans. Comput. Healthcare, vol. 2, no. 3, pp. 1–44, 2021.
[22]P. Purwono, A. Ma'arif, W. Rahmaniar, H. I. K. Fathurrahman, A. Z. K. Frisky, and Q. M. ul Haq, “Understanding of convolutional neural network (CNN): A review,” Int. J. Robot. Control Syst., vol. 2, no. 4, pp. 739–748, 2022.
[23]A. A. Elngar, M. Arafa, A. Fathy, B. Moustafa, O. Mahmoud, M. Shaban, and N. Fawzy, “Image classification based on CNN: a survey,” J. Cybersecur. Inf. Manag., vol. 6, no. 1, pp. 18–50, 2021.
[24]A. S. Hashemi and S. Mozaffari, “CNN adversarial attack mitigation using perturbed samples training,” Multimed. Tools Appl., vol. 80, pp. 22077–22095, 2021.
[25]S. Alzaidy and H. Binsalleeh, “Adversarial attacks with defense mechanisms on convolutional neural networks and recurrent neural networks for malware classification,” Appl. Sci., vol. 14, no. 4, p. 1673, 2024.
[26]Y. Watanobe, M. M. Rahman, M. F. I. Amin, and R. Kabir, “Identifying algorithm in program code based on structural features using CNN classification model,” Appl. Intell., vol. 53, no. 10, pp. 12210–12236, 2023.
[27]W. Zhao, S. Alwidian, and Q. H. Mahmoud, “Adversarial training methods for deep learning: A systematic review,” Algorithms, vol. 15, no. 8, p. 283, 2022.
[28]S. Zhang, H. Gao, and Q. Rao, “Defense against adversarial attacks by reconstructing images,” IEEE Trans. Image Process., vol. 30, pp. 6117–6129, 2021.
[29]W. Villegas-Ch, A. Jaramillo-Alcázar, and S. Luján-Mora, “Evaluating the robustness of deep learning models against adversarial attacks: An analysis with FGSM, PGD and CW,” Big Data Cogn. Comput., vol. 8, no. 1, p. 8, 2024.
[30]X. Shi, Y. Peng, Q. Chen, T. Keenan, A. T. Thavikulwat, S. Lee, and Z. Lu, “Robust convolutional neural networks against adversarial attacks on medical images,” Pattern Recognit., vol. 132, p. 108923, 2022.
[31]S. Alzaidy and H. Binsalleeh, “Adversarial attacks with defense mechanisms on convolutional neural networks and recurrent neural networks for malware classification,” Appl. Sci., vol. 14, no. 4, p. 1673, 2024.
[32]H. Liang, E. He, Y. Zhao, Z. Jia, and H. Li, “Adversarial attack and defense: A survey,” Electronics, vol. 11, no. 8, p. 1283, 2022.
[33]N. Akhtar, A. Mian, N. Kardan, and M. Shah, “Advances in adversarial attacks and defenses in computer vision: A survey,” IEEE Access, vol. 9, pp. 155161–155196, 2021.
[34]A. Chakraborty, M. Alam, V. Dey, A. Chattopadhyay, and D. Mukhopadhyay, “A survey on adversarial attacks and defences,” CAAI Trans. Intell. Technol., vol. 6, no. 1, pp. 25–45, 2021.
[35]J. Sen and S. Dasgupta, “Adversarial attacks on image classification models: FGSM and patch attacks and their impact,” arXiv preprint, arXiv:2307.02055, 2023.
[36]A. Oprea and A. Vassilev, “Adversarial machine learning: A taxonomy and terminology of attacks and mitigations,” Natl. Inst. Stand. Technol. (NIST), NIST AI 100-2 E2023, 2023.
[37]Y. Li, M. Cheng, C. J. Hsieh, and T. C. Lee, “A review of adversarial attack and defense for classification methods,” Am. Stat., vol. 76, no. 4, pp. 329–345, 2022.
[38]M. Surekha, A. K. Sagar, and V. Khemchandani, “Adversarial Attack and Defense Mechanisms in Medical Imaging: A Comprehensive Review,” in Proc. IEEE IC2PCT, vol. 5, pp. 1657–1661, Feb. 2024.
[39]Y. Wang, J. Liu, X. Chang, J. Mišić, and V. B. Mišić, “IWA: Integrated gradient-based white-box attacks for fooling deep neural networks,” Int. J. Intell. Syst., vol. 37, no. 7, pp. 4253–4276, 2022.
[40]J. Li, Y. Xu, Y. Hu, Y. Ma, and X. Yin, “You only attack once: Single-step DeepFool algorithm,” Appl. Sci., vol. 15, no. 1, p. 302, 2024.
[41]A. Shafahi et al., “Adversarial training for free!,” in Adv. Neural Inf. Process. Syst., vol. 32, 2019.
[42]M. Zhao, L. Zhang, J. Ye, H. Lu, B. Yin, and X. Wang, “Adversarial Training: A Survey,” arXiv preprint, arXiv:2410.15042, 2024.
[43]M. Wang and M. Xu, “An Adversarial Machine Learning-Based Fast Detection Method for Denial of Service-Oriented Cyber Attacks in Internet of Vehicles,” J. Circuits Syst. Comput., vol. 33, no. 7, p. 2450122, 2024.
[44]I. Hong and S. Lee, “Exploring Synergy of Denoising and Distillation: Novel Method for Efficient Adversarial Defense,” Appl. Sci., vol. 14, no. 23, p. 10872, 2024.
[45]M. S. Haroon and H. M. Ali, “Ensemble adversarial training based defense against adversarial attacks for machine learning-based intrusion detection system,” Neural Netw. World, vol. 317, p. 336, 2023.
[46]S. N. Ashraf, R. Siddiqi, and H. Farooq, “Auto encoder-based defense mechanism against popular adversarial attacks in deep learning,” PLoS ONE, vol. 19, no. 10, p. e0307363, 2024.
[47]T. van Weezel, F. van Ree, T. Bos, P. Bastiaanssen, and S. Hess, “Purifying Adversarial Examples Using an Autoencoder,” in Int. Conf. Discovery Science, Cham: Springer, pp. 134–148, Oct. 2024.
[48]A. Yinusa and M. Faezipour, “A multi-layered defense against adversarial attacks in brain tumor classification using ensemble adversarial training and feature squeezing,” Sci. Rep., vol. 15, no. 1, pp. 1–11, 2025.
[49]F. Pistorius, D. Grimm, F. Erdösi, and E. Sax, “Evaluation matrix for smart machine-learning algorithm choice,” in Proc. Int. Conf. Big Data Anal. Pract. (IBDAP), pp. 1–6, 2020.
[50]S. M. Basha and D. S. Rajput, “Survey on evaluating the performance of machine learning algorithms: Past contributions and future roadmap,” in Deep Learn. Parallel Comput. Environ. Bioeng. Syst., Academic Press, pp. 153–164, 2019.
[51]G. Naidu, T. Zuva, and E. M. Sibanda, “A review of evaluation metrics in machine learning algorithms,” in Proc. Comput. Sci. Online Conf., Cham: Springer, pp. 15–25, 2023.