Other Conference and Symposium Proceedings
Permanent URI for this communityhttps://rda.sliit.lk/handle/123456789/4774
Browse
Item Embargo Evaluating and Enhancing the Robustness of Convolutional Neural Networks Against Adversarial Attacks: A Case Study on MNIST(Institute of Electrical and Electronics Engineers Inc., 2025-12-12) Aththanayaka A.M.R.E; Jayakody, AConvolutional Neural Networks (CNNs) have achieved exceptional performance in computer vision tasks, particularly in image classification domains such as MNIST digit recognition. However, their susceptibility to adversarial attacks poses serious security threats that limit their deployment in real-world applications. This research comprehensively examines CNNs vulnerability through systematic evaluation of five potent adversarial attacks such as FGSM, BIM, PGD, Deep Fool, and Carlini-Wagner on MNIST dataset. The baseline CNN model achieves 99.23% accuracy on clean data, but experiences catastrophic performance degradation under adversarial conditions, with accuracy dropping to as low as 8.91% against BIM attacks. To address these vulnerabilities, this study proposes CADF: a Comprehensive Cyber Attack Detection Framework that implements a multi-layered defense strategy. The framework incorporates a binary detection classifier achieving 99.56% accuracy in identifying adversarial examples, followed by a multi-class attack identifier with 93.56% accuracy in categorizing specific threat types. CADF's adaptive defense engine dynamically selects optimal countermeasures including feature squeezing, spatial smoothing, and ensemble defenses based on the identified attack characteristics. This integrated approach provides a scalable and efficient solution for enhancing CNN robustness without compromising computational performance, offering significant advancements in securing deep learning systems against evolving adversarial threats.
