Autoencoder-Based Adversarial Defense: Improving Facial Recognition Security against FGSM White-Box Perturbations

Authors

  • Areeba Sohail Chenab Institute of Information Technology Author
  • Eshal Nasir University of Gujrat Author

Keywords:

Autoencoder, FGSM, adversarial defense, facial recognition, white-box attack, deep learning security, denoising autoencoder

Abstract

Facial recognition systems, widely deployed in security-sensitive domains, are highly vulnerable to adversarial attacks that exploit model weaknesses. One of the most potent forms of adversarial threats is the Fast Gradient Sign Method (FGSM), particularly in white-box settings where the attacker possesses full knowledge of the model. These perturbations, though imperceptible to humans, can drastically degrade recognition accuracy and compromise security. In this paper, we propose an autoencoder-based adversarial defense framework specifically designed to counteract FGSM attacks and restore reliable facial recognition performance. The autoencoder is trained to learn the manifold of clean facial data and reconstruct adversarial inputs by removing subtle perturbations. Experimental validation using benchmark datasets reveals a significant improvement in model resilience, demonstrating how autoencoders can effectively suppress adversarial noise without compromising the discriminative power of deep learning classifiers. Our results show that this unsupervised pre-processing technique provides a robust and computationally efficient line of defense against adversarial threats in real-time facial recognition systems.

Downloads

Published

2023-11-14 — Updated on 2023-12-22