Convolutional Autoencoder-Based Adversarial Defense for Robust Face Recognition under FGSM White-Box Attacks

Authors

  • Sania Naveed Chenab Institute of Information Technology Author
  • Zunaira Rafaqat Chenab Institute of Information Technology Author

Keywords:

Adversarial Defense, Convolutional Autoencoder, FGSM Attack, Face Recognition, White-Box Attack, Deep Learning Robustness

Abstract

Face recognition systems have achieved exceptional performance in security, authentication, and surveillance applications. However, these systems are highly vulnerable to adversarial attacks, especially the Fast Gradient Sign Method (FGSM), which perturbs input images subtly but effectively enough to mislead deep learning models. In this paper, we propose a convolutional autoencoder-based defense mechanism to enhance the robustness of face recognition models against FGSM white-box attacks. The approach leverages the capacity of convolutional autoencoders to learn compact and noise-invariant latent representations that can reconstruct clean versions of adversarially perturbed faces. We evaluate the proposed defense on standard face datasets under varying attack intensities and demonstrate significant improvements in recognition accuracy after reconstruction. Our results highlight the potential of autoencoders as a lightweight and effective pre-processing step to mitigate adversarial threats without needing to modify or retrain the target recognition model.

Downloads

Published

2023-10-06 — Updated on 2023-12-29