Evaluating and Enhancing the Robustness of Convolutional Neural Networks Against Adversarial Attacks: A Case Study on MNIST

Thumbnail Image

Date

2025-12-12

Journal Title

Journal ISSN

Volume Title

Publisher

Institute of Electrical and Electronics Engineers Inc.

Abstract

Convolutional Neural Networks (CNNs) have achieved exceptional performance in computer vision tasks, particularly in image classification domains such as MNIST digit recognition. However, their susceptibility to adversarial attacks poses serious security threats that limit their deployment in real-world applications. This research comprehensively examines CNNs vulnerability through systematic evaluation of five potent adversarial attacks such as FGSM, BIM, PGD, Deep Fool, and Carlini-Wagner on MNIST dataset. The baseline CNN model achieves 99.23% accuracy on clean data, but experiences catastrophic performance degradation under adversarial conditions, with accuracy dropping to as low as 8.91% against BIM attacks. To address these vulnerabilities, this study proposes CADF: a Comprehensive Cyber Attack Detection Framework that implements a multi-layered defense strategy. The framework incorporates a binary detection classifier achieving 99.56% accuracy in identifying adversarial examples, followed by a multi-class attack identifier with 93.56% accuracy in categorizing specific threat types. CADF's adaptive defense engine dynamically selects optimal countermeasures including feature squeezing, spatial smoothing, and ensemble defenses based on the identified attack characteristics. This integrated approach provides a scalable and efficient solution for enhancing CNN robustness without compromising computational performance, offering significant advancements in securing deep learning systems against evolving adversarial threats.

Description

Keywords

adversarial attacks, Cascaded Adaptive Defense Framework (CADF), Convolutional Neural Networks (CNN), MNIST

Citation

A. AMRE and A. Jayakody, "Evaluating and Enhancing the Robustness of Convolutional Neural Networks Against Adversarial Attacks: A Case Study on MNIST," 2025 IEEE Pune Section International Conference (PuneCon), Pune, India, 2025, pp. 1-6, doi: 10.1109/PuneCon67554.2025.11379266.

Endorsement

Review

Supplemented By

Referenced By