Published at : 31 Jul 2026
Volume : IJtech
Vol 17, No 4 (2026)
DOI : https://doi.org/10.14716/ijtech.v17i4.8367
| Qais Saif Qassim | College of Computing and Information Sciences, University of Technology and Applied Sciences–Ibri, 516, Sultanate of Oman |
| Wilfred Blessing Nesaian Reginal | College of Computing and Information Sciences, University of Technology and Applied Sciences–Ibri, 516, Sultanate of Oman |
| Dilwar Islam Mazunder | Center for Preparatory Studies, University of Technology and Applied Sciences – Ibri, 516, Sultanate of Oman |
| Samuel Brilly Sangeetha | Department of Computer Science and Engineering, IES College of Engineering, Thrissur, Kerala, 680551, India |
| Yuvaraj Natarajan | ICT Academy of Tamil Nadu, IIT Madras Research Park, Chennai, 600113, India |
| Arshath Raja Rajan | ICT Academy of Tamil Nadu, IIT Madras Research Park, Chennai, 600113, India |
Deep learning models are highly vulnerable to adversarial perturbations, posing serious risks in critical domains such as healthcare, autonomous systems, and cybersecurity. This has motivated the need for robust defenses that maintain reliability without significant computational overhead. Current defense strategies fail to provide a unified solution for gradient-based and gradient-free adversarial attacks. Many approaches suffer from gradient masking or accuracy degradation during clean inference. Methods that can adaptively stabilize model responses under diverse and evolving adversarial conditions have a significant defense gap. This study introduces AGS, a lightweight defense that combines perturbation-aware feature smoothing with dynamic gradient modulation. Using an adaptive auxiliary controller, AGS detects locally sensitive features and selectively regulates gradient flow, improving robust generalization without full adversarial training. The proposed method is evaluated on CIFAR-10 and ImageNet-Subset under FGSM, PGD-20, and BIM attacks. AGS significantly improves robustness while preserving clean accuracy. On CIFAR-10, the PGD-20 accuracy increased from 42.8% to 71.4% with only a 0.4% drop in clean accuracy, and the FGSM accuracy improved from 61.5% to 84.7%. On the ImageNet-Subset, the PGD-20 accuracy increased from 18.6% to 39.3%. The auxiliary controller adds only 3.2% computational overhead, which is lower than that of standard adversarial training, demonstrating that AGS is an efficient and adaptive defense for varying adversarial conditions.
Adaptive shielding; Adversarial robustness; Deep learning security; Gradient modulation; Perturbation resilience
Abasi, A. K.,
Aloqaily, M., & Guizani, M. (2025). 6G mmWave security advancements through
federated learning and differential privacy. IEEE Transactions on Network
and Service Management, 22(2), 1911–1928. https://doi.org/10.1109/TNSM.2025.3528235
Abbes, A.,
Slimani, N., Cherif, C., Hadjout, S., Mammasse, A., Mankouri, A., &
Kherbachi, S. (2025). Adversarial attacks and defense mechanisms in computer
vision: A comprehensive survey. Communications in Computer and Information
Science, 2462, 371–378. https://doi.org/10.1007/978-3-031-88226-5_26
Alajaji, A.
(2025). FortinIDS: Defending smart city IoT infrastructures against
transferable adversarial poisoning in machine learning-based intrusion
detection systems. Sensors, 25(19), 6056. https://doi.org/10.3390/s25196056
Al-Andoli, M.,
Tan, S., Sim, K., Goh, P., & Lim, C. (2024). A framework for robust deep
learning models against adversarial attacks based on a protection layer
approach. IEEE Access, 12, 17522–17540. https://doi.org/10.1109/ACCESS.2024.3354699
Anjum, S., &
Nnaji, C. (2025). Enhancing robustness of deep learning models against
adversarial attacks for construction worker safety. Automation in
Construction, 179, 106447. https://doi.org/10.1016/j.autcon.2025.106447
Chelliah, B.,
Malik, M., Kumar, A., Singh, N., & Regin, R. (2023). Similarity-based
optimised and adaptive adversarial attack on image classification using neural
network. International Journal of Intelligent Engineering Informatics, 11(1),
71. https://doi.org/10.1504/IJIEI.2023.130715
Costa, J., Roxo,
T., Proença, H., & Morais Inácio, P. (2024). How deep learning sees the
world: A survey on adversarial attacks & defenses. IEEE Access, 12,
61113–61136. https://doi.org/10.1109/ACCESS.2024.3395118
Dadhwal, H., de
Abreu, M., Parvizi, N., & Saha, S. (2026). Benchmarking the adversarial
resilience of machine learning models for DDoS detection. Array, 29,
100664. https://doi.org/10.1016/j.array.2025.100664
Elabd, E. (2025).
Dynamic differential privacy technique for deep learning models. Scientific
Reports, 15(1), 39353. https://doi.org/10.1038/s41598-025-27708-0
Guo, Z., Qian, Y.,
Zhao, S., Dong, J., Li, Y., Arandjelovi?, O., Fang, L., & Lau, C. (2026).
Artwork protection against unauthorized neural style transfer and aesthetic
color distance metric. Pattern Recognition, 171, 112105. https://doi.org/10.1016/j.patcog.2025.112105
He, K., Kim, D.,
& Asghar, M. (2023). Adversarial machine learning for network intrusion
detection systems: A comprehensive survey. IEEE Communications Surveys &
Tutorials, 25(1), 538–566. https://doi.org/10.1109/COMST.2022.3233793
Hu, J., Wang, Z.,
Shen, Y., Lin, B., Sun, P., Pang, X., Liu, J., & Ren, K. (2024). Shield
against gradient leakage attacks: Adaptive privacy-preserving federated
learning. IEEE/ACM Transactions on Networking, 32(2), 1407–1422. https://doi.org/10.1109/TNET.2023.3317870
Jhajharia, K.,
& Shrivastavaa, Y. (2024). Adversarial attacks and defenses on deep
learning models. 2024 3rd International Conference for Advancement in
Technology (ICONAT), 1–5. https://doi.org/10.1109/ICONAT61936.2024.10775002
Jiang, L., Ma, L., & Yang, G. (2025). Shadow
defense against gradient inversion attack in federated learning. Medical
Image Analysis, 105, 103673. https://doi.org/10.1016/j.media.2025.103673
Kim, Y., Jung, J., Kim, H., So, H., Ko, Y.,
Shrivastava, A., Lee, K., & Hwang, U. (2024). Adversarial defense on
harmony: Reverse attack for robust AI models against adversarial attacks. IEEE
Access, 12, 176485–176497. https://doi.org/10.1109/ACCESS.2024.3505215
Laila, D. A.
(2025). Responsive machine learning framework and lightweight utensil of
prevention of evasion attacks in the IoT-based IDS. STAP Journal of Security
Risk Management, 2025(1), 59–70. https://doi.org/10.63180/jsrm.thestap.2025.1.3
Li, S., Wang, J., Wu, H., Zhang, J., Cheng, X.,
Luo, X., & Ma, B. (2025). Defense against adversarial faces at the
source: Strengthened faces based on hidden disturbances. IEEE Transactions
on Artificial Intelligence, 6(7), 1761–1775. https://doi.org/10.1109/TAI.2025.3527923
Manzoor, A.,
Fargetta, G., Ortis, A., & Battiato, S. (2026). ShieldNet: A novel
adversarially resilient convolutional neural network for robust image
classification. Applied Sciences, 16(3), 1254.
Muoka, G., Yi, D.,
Ukwuoma, C., Mutale, A., Ejiyi, C., Mzee, A., Gyarteng, E., Alqahtani, A., et
al. (2023). A comprehensive review and analysis of deep learning-based medical
image adversarial attack and defense. Mathematics, 11(20), 4272. https://doi.org/10.3390/math11204272
Ness, S. (2025).
Enhancing remaining useful life prediction against adversarial attacks: An
active learning approach. IEEE Access, 13, 170921–170934. https://doi.org/10.1109/ACCESS.2025.3611453
Puttagunta, M.,
Ravi, S., & Nelson Kennedy Babu, C. (2023). Adversarial examples: Attacks
and defences on medical deep learning systems. Multimedia Tools and
Applications, 82(22), 33773–33809. https://doi.org/10.1007/s11042-023-14702-9
Rahman, M., Roy,
P., Frizell, S., & Qian, L. (2025). Evaluating pretrained deep learning
models for image classification against individual and ensemble adversarial
attacks. IEEE Access, 13, 35230–35242. https://doi.org/10.1109/ACCESS.2025.3544107
Roy, A., &
Dasgupta, D. (2025). Defending learning systems against mean-shift
perturbations. IEEE Transactions on Artificial Intelligence, 1–13. https://doi.org/10.1109/TAI.2024.3422929
Saha, S., Das, S.,
& Carvalho, G. (2026). A hybrid deep learning model for adversarially
resilient internet traffic prediction. Computers and Electrical Engineering,
130, 110832. https://doi.org/10.1016/j.compeleceng.2025.110832
Shan, F., Lu, Y.,
Li, S., Mao, S., Li, Y., & Wang, X. (2025). Efficient adaptive defense
scheme for differential privacy in federated learning. Journal of
Information Security and Applications, 89, 103992. https://doi.org/10.1016/j.jisa.2025.103992
Shayea, G., Zabil, M., Habeeb, M., Khaleel, Y.,
& Albahri, A. (2025). Strategies for protection against adversarial
attacks in AI models: An in-depth review. Journal of Intelligent Systems, 34(1).
https://doi.org/10.1515/jisys-2024-0277
Wang, C., Liu, Y.,
Liu, X., He, Y., & Xiao, K. (2025). Dynamic shielding: Defense mechanism
against gradient attacks on distributed GANs. SSRN. https://doi.org/10.2139/ssrn.5251836
Wang, F., Hugh,
E., & Li, B. (2024). More than enough is too much: Adaptive defenses
against gradient leakage in production federated learning. IEEE/ACM
Transactions on Networking, 32(4), 3061–3075. https://doi.org/10.1109/TNET.2024.3377655
Wang, Y., Sun, T.,
Li, S., Yuan, X., Ni, W., Hossain, E., & Vincent Poor, H. (2023).
Adversarial attacks and defenses in machine learning-empowered communication
systems and networks: A contemporary survey. IEEE Communications Surveys
& Tutorials, 25(4), 2245–2298. https://doi.org/10.1109/COMST.2023.3319492
Wei, W., &
Liu, L. (2022). Gradient leakage attack resilient deep learning. IEEE
Transactions on Information Forensics and Security, 17, 303–316. https://doi.org/10.1109/TIFS.2021.3139777
Xiangfei, Z.,
& Qingchen, Z. (2025). Defending against attacks in deep learning with
differential privacy: A survey. Artificial Intelligence Review, 58(11),
347. https://doi.org/10.1007/s10462-025-11350-3
Xu, F., Wang, C.,
Liang, J., Zuo, C., Yue, K., & Li, W. (2024). A knowledge distillation
strategy for enhancing the adversarial robustness of lightweight automatic
modulation classification models. IET Communications, 18(14), 827–845. https://doi.org/10.1049/cmu2.12793
Yinusa, A., &
Faezipour, M. (2025). A multi-layered defense against adversarial attacks in
brain tumor classification using ensemble adversarial training and feature
squeezing. Scientific Reports, 15(1), 16804. https://doi.org/10.1038/s41598-025-00890-x
Zhang, C., &
Wang, P. (2026). Adaptive masked autoencoder defense: A robust defense strategy
against adversarial attacks in deep learning models. Journal of Circuits,
Systems and Computers, 35(1). https://doi.org/10.1142/S0218126625503578
Zhao, W.,
Alwidian, S., & Mahmoud, Q. (2022). Adversarial training methods for deep
learning: A systematic review. Algorithms, 15(8), 283. https://doi.org/10.3390/a15080283
Zhou, S., Liu, C., Ye, D., Zhu, T., Zhou, W., & Yu, P. (2023). Adversarial attacks and defenses in deep learning: From a perspective of cybersecurity. ACM Computing Surveys, 55(8), 1–39. https://doi.org/10.1145/3547330