Deep Neural Networks for Enhancing Robustness in Facial Authentication and Deepfake Detection for Driven Data Poisoning Attacks and  Defense Strategies

Authors

  • Anas A. Nicola Faculty of Telecommunication, Engineering and Space Technology, Future University, Khartoum, Republic of the Sudan Author

DOI:

https://doi.org/10.54536/ajarai.v1i2.7972

Keywords:

Algorithms, Deep Learning, Deep Neural Embedded, Intelligent System, Neural Network

Abstract

This research combines two crucial works aimed at enhancing the robustness of deep neural networks (DNNs) against emerging attacks. In a model or training data extraction attack, an attacker analyzes the input, output, and other external information of a system to speculate on the parameters or training data of the model. Similar to the concept of Software-as-a-Service (SaaS) proposed by cloud service providers. These services are open, and users can use open APIs to perform image and voice recognition. In addition, facial authentication, altered to depict faces that were not originally present. In response, a new defense mechanism named Sanitization and Noise defenses (Deep- neural-network and Embedded Feature-based detector) is introduced. Sanitization and Noise defenses utilize a hybrid DNN and KNN (k-nearest neighbors) model to detect contaminated feature vectors generated by the attacked system. Evaluations on real datasets demonstrate Sanitization and Noise defenses efficacy, achieving over 80% detection accuracy across diverse settings. A novel data poisoning attack scenario is proposed where an attacker injects a few photos during a user's registration or photo update process. The proposed attack scenario involves an attacker injecting their photos into the facial recognition system during user registration or photo updates. 

Downloads

Download data is not yet available.

References

Aithal, S. K., Maini, P., Lipton, Z. C., & Kolter, J. Z. (2024). Understanding hallucinations in diffusion models through mode interpolation. Advances in neural information processing systems, 37, 134614-134644.

Biggio, B., Nelson, B., & Laskov, P. (2012). Poisoning attacks against support vector machines. In Proceedings of the 29th International Conference on Machine Learning (ICML-12) (pp. 1467–1474).

Chollet, F. (2017). Xception: Deep learning with depthwise separable convolutions. In Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR) (pp. 1251–1258). IEEE. https://doi.org/10.1109/CVPR.2017.195

Cohen, G., Sapiro, G., & Giryes, R. (2020). Detecting adversarial samples using influence functions and nearest neighbors. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR) (pp. 14453–14462). IEEE. https://doi.org/10.1109/CVPR42600.2020.01446

Escalante, A. (2020, August 3). Research finds social media users are more likely to believe fake news. Forbes. Forbes Magazine, August, 3.

Eykholt, K., Evtimov, I., Fernandes, E., Li, B., Rahmati, A., Xiao, C., Prakash, A., Kohno, T., & Song, D. (2018). Robust physical-world attacks on deep learning visual classification. In Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR) (pp. 1625–1634). IEEE. https://doi.org/10.1109/CVPR.2018.00175

Goodfellow, I. J., Shlens, J., & Szegedy, C. (2014). Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572. https://doi.org/10.48550/arXiv.1412.6572

Goswami, G., Ratha, N., Agarwal, A., Singh, R., & Vatsa, M. (2018). Unravelling robustness of deep learning based face recognition against adversarial attacks. Proceedings of the AAAI Conference on Artificial Intelligence, 32(1), 6829–6836. https://doi.org/10.1609/aaai.v32i1.12341

Jebreel, N. M., Domingo-Ferrer, J., Sánchez, D., & Blanco-Justicia, A. (2024). LFighter: Defending against the label-flipping attack in federated learning. Neural Networks, 170, 111–126. https://doi.org/10.1016/j.neunet.2023.11.019

Juuti, M., Szyller, S., Marchal, S., & Asokan, N. (2019). PRADA: Protecting against DNN model stealing attacks. In 2019 IEEE European Symposium on Security and Privacy (EuroS&P) (pp. 512–527). IEEE. https://doi.org/10.1109/EuroSP.2019.00044

Kalyani, K., & Akhila, G. (2025). Secure distributed learning: Robust data poisoning detection framework using intelligent model integrity analysis. International Journal of Data Science and IoT Management System, 4(4), 230–235. https://doi.org/10.64751

Lee, T., Edwards, B., Molloy, I., & Su, D. (2019). Defending against neural network model stealing attacks using deceptive perturbations. In 2019 IEEE Security and Privacy Workshops (SPW) (pp. 43–49). IEEE. https://doi.org/10.1109/SPW.2019.00020

Lowd, D., & Meek, C. (2005). Adversarial learning. In Proceedings of the 11th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining (pp. 641–647). Association for Computing Machinery. https://doi.org/10.1145/1081870.1081950

Meng, D., & Chen, H. (2017). MagNet: A two-pronged defense against adversarial examples. In Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security (pp. 135–147). Association for Computing Machinery. https://doi.org/10.1145/3133956.3134057

Metzen, J. H., Genewein, T., Fischer, V., & Bischoff, B. (2017). On detecting adversarial perturbations. arXiv. https://doi.org/10.48550/arXiv.1702.04267

Moosavi-Dezfooli, S.-M., Fawzi, A., Fawzi, O., & Frossard, P. (2017). Universal adversarial perturbations. In Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR) (pp. 1765–1773). IEEE. https://doi.org/10.1109/CVPR.2017.17

Nelson, B., Barreno, M., Chi, F. J., Joseph, A. D., Rubinstein, B. I. P., Saini, U., Sutton, C., Tygar, J. D., & Xia, K. (2008). Exploiting machine learning to subvert your spam filter. In Proceedings of the 1st USENIX Workshop on Large-Scale Exploits and Emergent Threats (pp. 7:1–7:9). USENIX Association.

Orekondy, T., Schiele, B., & Fritz, M. (2019). Knockoff nets: Stealing functionality of black-box models. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR) (pp. 4954–4963). IEEE. https://doi.org/10.1109/CVPR.2019.00509

Pascu, L. (2020, June 29). Acronis reports critical flaws in GeoVision biometric devices, man-in-the-middle attack risks. Biometric Update

Paudice, A., Muñoz-González, L., György, A., & Lupu, E. C. (2018). Detection of adversarial training examples in poisoning attacks through anomaly detection. arXiv. https://doi.org/10.48550/arXiv.1802.03041

Ramirez, M. A., Kim, S.-K., Al Hamadi, H., Damiani, E., Byon, Y.-J., Kim, T.-Y., Cho, C.-S., & Yeun, C. Y. (2022). Poisoning attacks and defenses on artificial intelligence: A survey. arXiv. https://doi.org/10.48550/arXiv.2202.10276

Rössler, A., Cozzolino, D., Verdoliva, L., Riess, C., Thies, J., & Nießner, M. (2019). FaceForensics++: Learning to detect manipulated facial images. In Proceedings of the IEEE/CVF International Conference on Computer Vision (ICCV) (pp. 1–11). IEEE. https://doi.org/10.1109/ICCV.2019.00009

Rumelhart, D. E., Hinton, G. E., & Williams, R. J. (1986). Learning representations by back-propagating errors. Nature, 323(6088), 533–536. https://doi.org/10.1038/323533a0

Schwartz, O. (2018, November 12). You thought fake news was bad? Deep fakes are where truth goes to die. The Guardian. Original Guardian article

Seals, T. (2020, July 23). ASUS home router bugs open consumers to snooping attacks. Threatpost.

Su, J., Vargas, D. V., & Sakurai, K. (2019). One pixel attack for fooling deep neural networks. IEEE Transactions on Evolutionary Computation, 23(5), 828–841. https://doi.org/10.1109/TEVC.2019.2890858

Thies, J., Zollhöfer, M., & Nießner, M. (2019). Deferred neural rendering: Image synthesis using neural textures. ACM Transactions on Graphics, 38(4), Article 66. https://doi.org/10.1145/3306346.3323035

Wang, B., & Gong, N. Z. (2018). Stealing hyperparameters in machine learning. In 2018 IEEE Symposium on Security and Privacy (SP) (pp. 36–52). IEEE. https://doi.org/10.1109/SP.2018.00038

Wittel, G. L., & Wu, S. F. (2004). On attacking statistical spam filters. In Proceedings of the First Conference on Email and Anti-Spam (CEAS 2004). CEAS.

Xu, W., Evans, D., & Qi, Y. (2017). Feature squeezing: Detecting adversarial examples in deep neural networks. arXiv. https://doi.org/10.48550/arXiv.1704.01155

Downloads

Published

2026-09-09

How to Cite

Nicola, A. A. . (2026). Deep Neural Networks for Enhancing Robustness in Facial Authentication and Deepfake Detection for Driven Data Poisoning Attacks and  Defense Strategies. American Journal of Applied Research and AI , 1(2), 60-70. https://doi.org/10.54536/ajarai.v1i2.7972

Similar Articles

You may also start an advanced similarity search for this article.