Defending CNN Against FGSM Attacks Using Beta-Based Personalized Activation Functions and Adversarial Training

2Citations
Citations of this article
6Readers
Mendeley users who have this article in their library.

This article is free to access.

Abstract

Machine learning algorithms based on deep neural networks have been widely used in many fields especially in computer vision, with impressive results. However, these models are vulnerable to different types of attacks like adversarial ones, which require attention to the model security and confidentiality. This study proposes a defense strategy to improve the insurance of white-box models while minimizing adversarial attacks against Fast Gradient Sign Method (FGSM)-based attacks and tackling the issue of adversarial training to improve their robustness. Mainly, we proposed a CNN model based on personalized activation functions using Beta function and its primitive. Then, the new resulted low degree polynomials are used to approximate the ReLU, Sigmoid and Tanh activation functions. Batch normalization was evoked to significantly improve the learning capacity of neural networks. The obtained results, using Mnist dataset prove the effectiveness of the proposed model.

Cite

CITATION STYLE

APA

Issaoui, H., Eladel, A., Zouinkhi, A., Zaied, M., Khriji, L., & Nengroo, S. H. (2024). Defending CNN Against FGSM Attacks Using Beta-Based Personalized Activation Functions and Adversarial Training. IEEE Access, 12, 138341–138350. https://doi.org/10.1109/ACCESS.2024.3432773

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free