Evaluating and Enhancing the Robustness of Convolutional Neural Networks Against Adversarial Attacks: A Case Study on MNIST

dc.contributor.authorAththanayaka A.M.R.E
dc.contributor.authorJayakody, A
dc.date.accessioned2026-10-07T09:02:21Z
dc.date.issued2025-12-12
dc.description.abstractConvolutional Neural Networks (CNNs) have achieved exceptional performance in computer vision tasks, particularly in image classification domains such as MNIST digit recognition. However, their susceptibility to adversarial attacks poses serious security threats that limit their deployment in real-world applications. This research comprehensively examines CNNs vulnerability through systematic evaluation of five potent adversarial attacks such as FGSM, BIM, PGD, Deep Fool, and Carlini-Wagner on MNIST dataset. The baseline CNN model achieves 99.23% accuracy on clean data, but experiences catastrophic performance degradation under adversarial conditions, with accuracy dropping to as low as 8.91% against BIM attacks. To address these vulnerabilities, this study proposes CADF: a Comprehensive Cyber Attack Detection Framework that implements a multi-layered defense strategy. The framework incorporates a binary detection classifier achieving 99.56% accuracy in identifying adversarial examples, followed by a multi-class attack identifier with 93.56% accuracy in categorizing specific threat types. CADF's adaptive defense engine dynamically selects optimal countermeasures including feature squeezing, spatial smoothing, and ensemble defenses based on the identified attack characteristics. This integrated approach provides a scalable and efficient solution for enhancing CNN robustness without compromising computational performance, offering significant advancements in securing deep learning systems against evolving adversarial threats.
dc.identifier.citationA. AMRE and A. Jayakody, "Evaluating and Enhancing the Robustness of Convolutional Neural Networks Against Adversarial Attacks: A Case Study on MNIST," 2025 IEEE Pune Section International Conference (PuneCon), Pune, India, 2025, pp. 1-6, doi: 10.1109/PuneCon67554.2025.11379266.
dc.identifier.doidoi: 10.1109/PuneCon67554.2025.11379266
dc.identifier.isbn979-833158834-2
dc.identifier.urihttps://rda.sliit.lk/handle/123456789/5347
dc.language.isoen
dc.publisherInstitute of Electrical and Electronics Engineers Inc.
dc.relation.ispartofseries2025 IEEE Pune Section International Conference, PuneCon 2025
dc.subjectadversarial attacks
dc.subjectCascaded Adaptive Defense Framework (CADF)
dc.subjectConvolutional Neural Networks (CNN)
dc.subjectMNIST
dc.titleEvaluating and Enhancing the Robustness of Convolutional Neural Networks Against Adversarial Attacks: A Case Study on MNIST
dc.typeConference Paper

Files

License bundle

Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
1.69 KB
Format:
Item-specific license agreed upon to submission
Description: