Abstract
Adversarial attacks have emerged as a major challenge to the trustworthy deployment of machine learning models, particularly in computer vision applications. These attacks vary in their potency and can be implemented through both white-box and black-box approaches. Practical attacks include methods to manipulate the physical world and enforce adversarial behavior in the targeted neural network models. Multiple different approaches to mitigate these attacks have been proposed in the literature, each with distinct strengths, limitations, and trade-offs. In this survey, we present a comprehensive systematization of knowledge on adversarial defenses, focusing on two key computer vision tasks: image classification and object detection. We review and categorize state-of-the-art adversarial defense techniques to facilitate clearer comparative insights. Additionally, we provide a schematic representation of these categories within the context of the overall machine learning pipeline, facilitating clearer understanding and benchmarking of defenses. Furthermore, we map these defenses to specific adversarial attacks and datasets where their effectiveness has been demonstrated, offering practical insights for researchers and practitioners. This study is necessary for understanding the extent to which available defenses can address the adversarial threats, their inherent limitations, and open challenges, thereby guiding future research toward building trustworthy AI systems suitable for real-world deployment.
Author supplied keywords
Cite
CITATION STYLE
Chattopadhyay, N., Basit, A., Ouni, B., & Shafique, M. (2026). A Survey of Adversarial Defenses in Vision-Based Systems: Categorization, Methods, and Challenges. IEEE Access. Institute of Electrical and Electronics Engineers Inc. https://doi.org/10.1109/ACCESS.2026.3687144
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.