Enhancing Face Recognition Security against FGSM White-Box Attacks via Convolutional Autoencoder Defense
Keywords:
Face recognition, FGSM, adversarial attacks, convolutional autoencoder, white-box defense, adversarial robustnessAbstract
The growing adoption of face recognition systems (FRS) across various sectors has led to an increased focus on their robustness against adversarial attacks. One of the most prominent threats in this domain is the Fast Gradient Sign Method (FGSM), a white-box adversarial attack capable of generating subtle perturbations that significantly degrade the performance of deep learning models. This research proposes a convolutional autoencoder (CAE)-based defense strategy to mitigate the impact of FGSM white-box attacks on face recognition systems. The proposed method leverages the reconstruction capability of CAEs to denoise adversarial inputs, restoring the integrity of facial features before classification. A comprehensive experimental setup using the LFW (Labeled Faces in the Wild) dataset and a ResNet-50 face recognition backbone demonstrates the efficacy of the approach. Empirical results indicate significant improvements in recognition accuracy when CAE preprocessing is applied, even under strong adversarial perturbations. The study concludes that CAEs can serve as an effective preprocessing defense layer, improving resilience against white-box attacks without requiring model retraining or architectural modifications.