{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,28]],"date-time":"2026-02-28T17:51:26Z","timestamp":1772301086436,"version":"3.50.1"},"reference-count":27,"publisher":"MDPI AG","issue":"2","license":[{"start":{"date-parts":[[2025,1,31]],"date-time":"2025-01-31T00:00:00Z","timestamp":1738281600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Systems"],"abstract":"<jats:p>Through advances in AI-based computer vision technology, the performance of modern image classification models has surpassed human perception, making them valuable in various fields. However, adversarial attacks, which involve small changes to images that are hard for humans to perceive, can cause classification models to misclassify images. Considering the availability of classification models that use neural networks, it is crucial to prevent adversarial attacks. Recent detection methods are only effective for specific attacks or cannot be applied to various models. Therefore, in this paper, we proposed an attention mechanism-based method for detecting adversarial attacks. We utilized a framework using an ensemble model, Grad-CAM and calculated the silhouette coefficient for detection. We applied this method to Resnet18, Mobilenetv2, and VGG16 classification models that were fine-tuned on the CIFAR-10 dataset. The average performance demonstrated that Mobilenetv2 achieved an F1-Score of 0.9022 and an accuracy of 0.9103, Resnet18 achieved an F1-Score of 0.9124 and an accuracy of 0.9302, and VGG16 achieved an F1-Score of 0.9185 and an accuracy of 0.9252. The results demonstrated that our method not only detects but also prevents adversarial attacks by mitigating their effects and effectively restoring labels.<\/jats:p>","DOI":"10.3390\/systems13020088","type":"journal-article","created":{"date-parts":[[2025,1,31]],"date-time":"2025-01-31T06:42:36Z","timestamp":1738305756000},"page":"88","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":5,"title":["A Generalized Framework for Adversarial Attack Detection and Prevention Using Grad-CAM and Clustering Techniques"],"prefix":"10.3390","volume":"13","author":[{"ORCID":"https:\/\/orcid.org\/0009-0001-3469-494X","authenticated-orcid":false,"given":"Jeong-Hyun","family":"Sim","sequence":"first","affiliation":[{"name":"Department of Industrial Security, Dankook University, Jukjeon-ro 152, Yongin-si 16890, Republic of Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0048-4231","authenticated-orcid":false,"given":"Hyun-Min","family":"Song","sequence":"additional","affiliation":[{"name":"Department of Industrial Security, Dankook University, Jukjeon-ro 152, Yongin-si 16890, Republic of Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2025,1,31]]},"reference":[{"key":"ref_1","unstructured":"Asgari Taghanaki, S., Das, A., and Hamarneh, G. (2018, January 16\u201320). Vulnerability analysis of chest x-ray image classification against adversarial attacks. Proceedings of the Understanding and Interpreting Machine Learning in Medical Image Computing Applications: First International Workshops, MLCN 2018, DLF 2018, and iMIMIC 2018, Held in Conjunction with MICCAI 2018, Granada, Spain. Proceedings 1."},{"key":"ref_2","unstructured":"Alparslan, Y., Alparslan, K., Keim-Shenk, J., Khade, S., and Greenstadt, R. (2020). Adversarial attacks on convolutional neural networks in facial recognition domain. arXiv."},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Zhang, H., and Wang, J. (2019, January 27\u201328). Towards adversarially robust object detection. Proceedings of the IEEE\/CVF International Conference on Computer Vision, Seoul, Republic of Korea.","DOI":"10.1109\/ICCV.2019.00051"},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Chernikova, A., Oprea, A., Nita-Rotaru, C., and Kim, B. (2019, January 20\u201322). Are self-driving cars secure? evasion attacks against deep neural networks for steering angle prediction. Proceedings of the 2019 IEEE Security and Privacy Workshops (SPW), San Francisco, CA, USA.","DOI":"10.1109\/SPW.2019.00033"},{"key":"ref_5","unstructured":"Goodfellow, I.J., Shlens, J., and Szegedy, C. (2014). Explaining and harnessing adversarial examples. arXiv."},{"key":"ref_6","unstructured":"Madry, A., Makelov, A., Schmidt, L., Tsipras, D., and Vladu, A. (2017). Towards deep learning models resistant to adversarial attacks. arXiv."},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Carlini, N., and Wagner, D. (2017, January 22\u201326). Towards evaluating the robustness of neural networks. Proceedings of the 2017 IEEE Symposium on Security and Privacy (sp), San Jose, CA, USA.","DOI":"10.1109\/SP.2017.49"},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Moosavi-Dezfooli, S.M., Fawzi, A., and Frossard, P. (2016, January 27\u201330). Deepfool: A simple and accurate method to fool deep neural networks. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, Las Vegas, NV, USA.","DOI":"10.1109\/CVPR.2016.282"},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Kurakin, A., Goodfellow, I.J., and Bengio, S. (2018). Adversarial examples in the physical world. Artificial intelligence Safety and Security, Chapman and Hall\/CRC.","DOI":"10.1201\/9781351251389-8"},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"828","DOI":"10.1109\/TEVC.2019.2890858","article-title":"One pixel attack for fooling deep neural networks","volume":"23","author":"Su","year":"2019","journal-title":"IEEE Trans. Evol. Comput."},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Xu, W. (2017). Feature squeezing: Detecting adversarial exa mples in deep neural networks. arXiv.","DOI":"10.14722\/ndss.2018.23198"},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"10193","DOI":"10.1002\/int.22458","article-title":"Detection defense against adversarial attacks with saliency map","volume":"37","author":"Ye","year":"2022","journal-title":"Int. J. Intell. Syst."},{"key":"ref_13","unstructured":"Pellcier, A.L., Giatgong, K., Li, Y., Suri, N., and Angelov, P. (July, January 30). UNICAD: A unified approach for attack detection, noise reduction and novel class identification. Proceedings of the International Joint Conference on Neural Networks (IJCNN), Yokohama, Japan."},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"14410","DOI":"10.1109\/ACCESS.2018.2807385","article-title":"Threat of adversarial attacks on deep learning in computer vision: A survey","volume":"6","author":"Akhtar","year":"2018","journal-title":"IEEE Access"},{"key":"ref_15","first-page":"7924","article-title":"Robust detection of adversarial attacks by modeling the intrinsic properties of deep neural networks","volume":"31","author":"Zheng","year":"2018","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"2815","DOI":"10.1007\/s11042-018-5853-4","article-title":"Adversarial image detection in deep neural networks","volume":"78","author":"Carrara","year":"2019","journal-title":"Multimed. Tools Appl."},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"7015","DOI":"10.1109\/TFUZZ.2024.3473768","article-title":"Adversarial attack detection via fuzzy predictions","volume":"32","author":"Li","year":"2024","journal-title":"IEEE Trans. Fuzzy Syst."},{"key":"ref_18","unstructured":"Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I., and Fergus, R. (2013). Intriguing properties of neural networks. arXiv."},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Papernot, N., McDaniel, P., Jha, S., Fredrikson, M., Celik, Z.B., and Swami, A. (2016, January 21\u201324). The limitations of deep learning in adversarial settings. Proceedings of the 2016 IEEE European Symposium on Security and Privacy (EuroS&P), Saarbr\u00fccken, Germany.","DOI":"10.1109\/EuroSP.2016.36"},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Moosavi-Dezfooli, S.M., Fawzi, A., Fawzi, O., and Frossard, P. (2017, January 21\u201326). Universal adversarial perturbations. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, Honolulu, HI, USA.","DOI":"10.1109\/CVPR.2017.17"},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Baluja, S., and Fischer, I. (2017). Adversarial transformation networks: Learning to generate adversarial examples. arXiv.","DOI":"10.1609\/aaai.v32i1.11672"},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Selvaraju, R.R., Cogswell, M., Das, A., Vedantam, R., Parikh, D., and Batra, D. (2017, January 22\u201329). Grad-cam: Visual explanations from deep networks via gradient-based localization. Proceedings of the IEEE International Conference on Computer Vision, Venice, Italy.","DOI":"10.1109\/ICCV.2017.74"},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Sandler, M., Howard, A., Zhu, M., Zhmoginov, A., and Chen, L.C. (2018, January 18\u201323). Mobilenetv2: Inverted residuals and linear bottlenecks. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, Salt Lake City, UT, USA.","DOI":"10.1109\/CVPR.2018.00474"},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"He, K., Zhang, X., Ren, S., and Sun, J. (2016, January 27\u201330). Deep residual learning for image recognition. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, Las Vegas, NV, USA.","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref_25","unstructured":"Simonyan, K., and Zisserman, A. (2014). Very deep convolutional networks for large-scale image recognition. arXiv."},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"600","DOI":"10.1109\/TIP.2003.819861","article-title":"Image quality assessment: From error visibility to structural similarity","volume":"13","author":"Wang","year":"2004","journal-title":"IEEE Trans. Image Process."},{"key":"ref_27","unstructured":"Croce, F., and Hein, M. (2020, January 13\u201318). Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks. Proceedings of the International Conference on Machine Learning, PMLR, Virtual."}],"container-title":["Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2079-8954\/13\/2\/88\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,9]],"date-time":"2025-10-09T16:24:51Z","timestamp":1760027091000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2079-8954\/13\/2\/88"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,1,31]]},"references-count":27,"journal-issue":{"issue":"2","published-online":{"date-parts":[[2025,2]]}},"alternative-id":["systems13020088"],"URL":"https:\/\/doi.org\/10.3390\/systems13020088","relation":{},"ISSN":["2079-8954"],"issn-type":[{"value":"2079-8954","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,1,31]]}}}