Accès ouvert

A Mixed Adversarial Awareness Technique for Improving Neural Network Defense

Article scientifique 2026 Autre

Résumé

Neural Network (NN) models, particularly Convolutional Neural Networks (CNNs), have achieved remarkable performance in computer vision tasks but remain highly vulnerable to adversarial attacks. Existing defense techniques mainly focus on detecting adversarial examples and often show limited effectiveness when adversarial perturbations coexist with significant noisy inputs. To address this limitation, this study proposes a Mixed Adversarial Awareness Technique (MAAT) based on kernel density estimation and a Bayesian uncertainty estimator. Kernel density estimation is used to model data manifolds in the input subspace, while the Bayesian uncertainty estimator, inspired by the Dirichlet process, quantifies predictive uncertainty in the input space. The proposed technique was evaluated on three benchmark datasets, CIFAR-10, CIFAR-100, and SVHN, using four adversarial attack schemes, namely FGSM, BIM, JSMA, and C&W, as well as Gaussian noise injection. The LeNet ConvNet model was employed as the test classifier. Experimental results show that MAAT effectively flags adversarial and noisy instances, improving detection performance with AUC values ranging from 0.84 to 0.96, compared with 0.61 to 0.94 achieved by selected state-of-the-art techniques. These findings demonstrate that combining density-based manifold modeling with uncertainty estimation provides a robust defense against mixed adversarial and noisy inputs.

Citer ce document

Agebure, M., Konja, S., Akobre, S., Daabo, M. (2026). A Mixed Adversarial Awareness Technique for Improving Neural Network Defense. https://doi.org/10.63158/journalisi.v8i3.1552

Accès au document

Texte intégral en lecture en ligne, réservé aux abonnés SPHAERO et aux membres de l'institution. Se connecter

Voir l'article sur le site de la revue

Statistiques

Consultations : 1

Téléchargements : 0