TARU PUBLICATIONS
Journal of Information and Optimization Sciences cover
Open Access ·Peer-reviewed·ISSN (Online): 2169-0103·ISSN (Print): 0252-2667

WoS  JIF 2026 : 0.4 (Q4)

Powered by:Powered by

Monthly Journal: Publishes theoretical and applied research on topics in information and optimization sciences.

Issues up to 2022 co-published with and available at:Taylor & Francis
submissions@tarupublications.com
Open Access Research Article

Enhancing machine learning robustness against adversarial attacks through cryptographic techniques

* , , , , ,

* Corresponding author · click or hover a name for details

pp. 927–937Vol. 46Issue 4-AMay 2025DOI: 10.47974/JIOS-1818XML
Received:
02 Oct 2024
Published Online:
31 May 2025
Article type:
Research Article
Language:
EN
Article no.:
JIOS-1818
Pages:
927–937

Abstract

This paper focuses with the issue of adversarial attacks on machine learning models, and also provides a possible solution to improve the model’s robustness through the use of cryptographic solutions. Thus, extending the virtues of cryptography to DL models, the proposed method seeks to shield them from adversarial alterations that might result in wrong classifications. The paper also describes the algorithmic parts of the proposed methodology as well as the analysis of the complexity of the present work. The efficiency of the proposed approach has been proven during the experiments; thus, model security is enhanced without compromising the performance significantly. Based on the findings of the work, the use of cryptographic approaches can be recommended as a promising avenue toward enhancing the security of machine learning.

Keywords

Subject Classifications

94A6020C0520C07

References

[1] T. Zhang, Y. Liu, and X. Wang, “Adversarial attack and defense in deep learning: A survey,” IEEE Transactions on Neural Networks and Learning Systems, vol. 31, no. 11, pp. 3724–3741 (Nov. 2020).
[2] J. Goodfellow, I. J. Mironov, and C. Song, “Robustness of machine learning models against adversarial attacks,” IEEE Transactions on Information Forensics and Security, vol. 15, pp. 1555–1567 (Dec. 2020).
[3] S. M. Moosavi-Dezfooli, A. Fawzi, and P. Frossard, “DeepFool: A simple and accurate method to fool deep neural networks,” IEEE Transactions on Pattern Analysis and Machine Intelligence, vol. 39, no. 12, pp. 2574–2580 (Dec. 2020).
[4] K. He, X. Zhang, S. Ren, and J. Sun, “Deep residual learning for image recognition,” in Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR), Las Vegas, NV, USA, pp. 770–778 (2019).
[5] C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, and R. Fergus, “Intriguing properties of neural networks,” in Proceedings of the International Conference on Learning Representations (ICLR), Banff, Canada (2019).
[6] R. S. Kumar and K. D. V. Prasad, “Securing digital authentication with cryptographic innovations in intrinsic verification systems,” Journal of Discrete Mathematical Sciences and Cryptography, vol. 27, no. 2-A, pp. 317–328 (2024).
[7] K. D. V. Prasad, “Cryptographic image-based data security strategies in wireless sensor networks,” Journal of Discrete Mathematical Sciences and Cryptography, vol. 27, no. 2-A, pp. 293–304 (2024).
[8] P. Sarma and M. Rahman, “Mathematical analysis of wavelet-based multi-image compression in medical diagnostics,” Journal of Discrete Mathematical Sciences and Cryptography, vol. 27, no. 2-B, pp. 675–687 (2024).
[9] A. Kumar, “A novel approach of unsupervised feature selection using iterative shrinking and expansion algorithm,” Journal of Interdisciplinary Mathematics, vol. 26, no. 3, pp. 519–530 (2023).
[10] A. Madry, A. Makelov, L. Schmidt, D. Tsipras, and A. Vladu, “Towards deep learning models resistant to adversarial attacks,” in Proceedings of the International Conference on Learning Representations (ICLR), Vancouver, BC, Canada (2019).
[11] J. Su, D. V. Vargas, and K. Sakurai, “One pixel attack for fooling deep neural networks,” IEEE Transactions on Evolutionary Computation, vol. 23, no. 5, pp. 828–841 (Oct. 2019).
[12] B. Biggio and F. Roli, “Wild patterns: Ten years after the rise of adversarial machine learning,” Pattern Recognition, vol. 84, pp. 317–331 (Dec. 2018).
[13] N. Carlini and D. Wagner, “Towards evaluating the robustness of neural networks,” in Proceedings of the IEEE Symposium on Security and Privacy (S&P), San Jose, CA, USA, pp. 39–57 (2018).
[14] G. Manivasagam and K. D. V. Prasad, “Novel approaches to biometric security using enhanced session keys and elliptic curve cryptography,” Journal of Discrete Mathematical Sciences and Cryptography, vol. 27, no. 2-A, pp. 477–488 (2024).
[15] V. Sivakumar, “A novel RF-SMOTE model to enhance the definite apprehensions for IoT security attacks,” Journal of Discrete Mathematical Sciences and Cryptography, vol. 26, no. 3, pp. 861–873 (2023).
[16] A. Chaturvedi, “Securing networked image transmission using public-key cryptography and identity authentication,” Journal of Discrete Mathematical Sciences and Cryptography, vol. 26, no. 3, pp. 779–791 (2023).
[17] K. Raghavendra, “Vector space modelling-based intelligent binary image encryption for secure communication,” Journal of Discrete Mathematical Sciences and Cryptography, vol. 25, no. 4, pp. 1157–1171 (2022).
[18] K. Grosse, N. Papernot, P. Manoharan, M. Backes, and P. McDaniel, “Adversarial perturbations against deep neural networks for malware classification,” in Proceedings of the European Symposium on Research in Computer Security (ESORICS), Oslo, Norway, pp. 62–79 (2017).
[19] S. Ren, K. He, R. Girshick, and J. Sun, “Faster R-CNN: Towards real-time object detection with region proposal networks,” IEEE Transactions on Pattern Analysis and Machine Intelligence, vol. 39, no. 6, pp. 1137–1149 (Jun. 2017).
[20] Y. Liu, X. Chen, C. Liu, and D. Song, “Delving into transferable adversarial examples and black-box attacks,” in Proceedings of the International Conference on Learning Representations (ICLR), Vancouver, BC, Canada (2019).

Views: 397Downloads: 72Citations: 0