MARATTO

article

Adversarial Attack Defense Techniques: A Study of Defensive Distillation and Adversarial Re-Training on CIFAR-10 and MNIST

20242 citationsAl Akhawayn University

Abstract

Adversarial attacks pose a significant challenge to the reliability of machine learning models by introducing imperceptible perturbations that lead to misclassification. This study evaluates the effectiveness of adversarial Re-training on an MNIST model, which achieved a clean accuracy of 99.5% and an adversarial accuracy of 90%, as well as the effectiveness of Defensive Distillation on a CIFAR-10 model, achieving a clean accuracy of 98.83% and an adversarial accuracy of 81.3% against PGD attacks. These results demonstrate that adversarial retraining with FGSM effectively improves robustness for simpler datasets like MNIST, achieving 90% adversarial accuracy post-training. In contrast, Defensive Distillation shows promise for complex datasets like CIFAR-10 due to its ability to generate robust decision boundaries. Compared to prior works that reported varying levels of success for Defensive Distillation across different domains, our results align with findings that dataset complexity significantly influences the efficacy of defense strategies. This analysis underscores the necessity of tailoring defense techniques to dataset characteristics and attack types. The potential impacts of these techniques on end users include enhanced security and reliability in applications that rely on machine learning models, such as biometric authentication, autonomous systems, and financial fraud detection. Defensive strategies like FGSM retraining and Defensive Distillation can ensure more consistent performance under adversarial conditions, reducing vulnerabil-ities and instilling user confidence in AI-driven systems across both simple and complex domains.

Research topics

  • Adversarial Robustness in Machine Learning

Read the original research

This page summarises published work. The authoritative version sits with the publisher.

DOI: 10.1109/icca62237.2024.10927831

Is something wrong with this record? Report it or request removal.

Discussion

Discuss this research

Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.

No discussion yet. Open the first thread.