Defense against FGSM White-Box Attacks Using Convolutional Autoencoders in Face Recognition Systems

Authors

  • Asma Maheen University of Gujrat Author
  • Ifrah Ikram COMSATS University Islamabad Author

Keywords:

FGSM attack, adversarial defense, face recognition, convolutional autoencoder, white-box attack, deep learning, image denoising, adversarial robustness

Abstract

Face recognition systems are increasingly integrated into security, surveillance, and identity verification processes due to their efficiency and non-intrusiveness. However, these systems are vulnerable to adversarial attacks, notably Fast Gradient Sign Method (FGSM), which perturbs input images in a manner imperceptible to humans but misleading to models. In a white-box setting, attackers have complete access to model parameters and gradients, significantly amplifying the threat level. This paper proposes the use of convolutional autoencoders (CAEs) as a defense mechanism against FGSM attacks. By learning a compressed, noise-free representation of facial data, CAEs reconstruct the original clean image, effectively filtering out adversarial perturbations. Our experimental evaluation demonstrates that CAEs significantly enhance the robustness of face recognition models under FGSM white-box attack conditions, preserving recognition accuracy and visual fidelity. The paper includes a comprehensive analysis of CAE architecture, training strategies, defense evaluation, and comparisons with existing methods, validating its practical applicability in real-world systems.

Downloads

Published

2023-10-03 — Updated on 2023-12-29