Deep Neural Networks for Enhancing Robustness in Facial Authentication and Deepfake Detection for Driven Data Poisoning Attacks and Defense Strategies
DOI:
https://doi.org/10.54536/ajarai.v1i2.7972Keywords:
Algorithms, Deep Learning, Deep Neural Embedded, Intelligent System, Neural NetworkAbstract
This research combines two crucial works aimed at enhancing the robustness of deep neural networks (DNNs) against emerging attacks. In a model or training data extraction attack, an attacker analyzes the input, output, and other external information of a system to speculate on the parameters or training data of the model. Similar to the concept of Software-as-a-Service (SaaS) proposed by cloud service providers. These services are open, and users can use open APIs to perform image and voice recognition. In addition, facial authentication, altered to depict faces that were not originally present. In response, a new defense mechanism named Sanitization and Noise defenses (Deep- neural-network and Embedded Feature-based detector) is introduced. Sanitization and Noise defenses utilize a hybrid DNN and KNN (k-nearest neighbors) model to detect contaminated feature vectors generated by the attacked system. Evaluations on real datasets demonstrate Sanitization and Noise defenses efficacy, achieving over 80% detection accuracy across diverse settings. A novel data poisoning attack scenario is proposed where an attacker injects a few photos during a user's registration or photo update process. The proposed attack scenario involves an attacker injecting their photos into the facial recognition system during user registration or photo updates.
Downloads
References
Aithal, S. K., Maini, P., Lipton, Z. C., & Kolter, J. Z. (2024). Understanding hallucinations in diffusion models through mode interpolation. Advances in neural information processing systems, 37, 134614-134644.
Biggio, B., Nelson, B., & Laskov, P. (2012). Poisoning attacks against support vector machines. In Proceedings of the 29th International Conference on Machine Learning (ICML-12) (pp. 1467–1474).
Chollet, F. (2017). Xception: Deep learning with depthwise separable convolutions. In Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR) (pp. 1251–1258). IEEE. https://doi.org/10.1109/CVPR.2017.195
Cohen, G., Sapiro, G., & Giryes, R. (2020). Detecting adversarial samples using influence functions and nearest neighbors. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR) (pp. 14453–14462). IEEE. https://doi.org/10.1109/CVPR42600.2020.01446
Escalante, A. (2020, August 3). Research finds social media users are more likely to believe fake news. Forbes. Forbes Magazine, August, 3.
Eykholt, K., Evtimov, I., Fernandes, E., Li, B., Rahmati, A., Xiao, C., Prakash, A., Kohno, T., & Song, D. (2018). Robust physical-world attacks on deep learning visual classification. In Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR) (pp. 1625–1634). IEEE. https://doi.org/10.1109/CVPR.2018.00175
Goodfellow, I. J., Shlens, J., & Szegedy, C. (2014). Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572. https://doi.org/10.48550/arXiv.1412.6572
Goswami, G., Ratha, N., Agarwal, A., Singh, R., & Vatsa, M. (2018). Unravelling robustness of deep learning based face recognition against adversarial attacks. Proceedings of the AAAI Conference on Artificial Intelligence, 32(1), 6829–6836. https://doi.org/10.1609/aaai.v32i1.12341
Jebreel, N. M., Domingo-Ferrer, J., Sánchez, D., & Blanco-Justicia, A. (2024). LFighter: Defending against the label-flipping attack in federated learning. Neural Networks, 170, 111–126. https://doi.org/10.1016/j.neunet.2023.11.019
Juuti, M., Szyller, S., Marchal, S., & Asokan, N. (2019). PRADA: Protecting against DNN model stealing attacks. In 2019 IEEE European Symposium on Security and Privacy (EuroS&P) (pp. 512–527). IEEE. https://doi.org/10.1109/EuroSP.2019.00044
Kalyani, K., & Akhila, G. (2025). Secure distributed learning: Robust data poisoning detection framework using intelligent model integrity analysis. International Journal of Data Science and IoT Management System, 4(4), 230–235. https://doi.org/10.64751
Lee, T., Edwards, B., Molloy, I., & Su, D. (2019). Defending against neural network model stealing attacks using deceptive perturbations. In 2019 IEEE Security and Privacy Workshops (SPW) (pp. 43–49). IEEE. https://doi.org/10.1109/SPW.2019.00020
Lowd, D., & Meek, C. (2005). Adversarial learning. In Proceedings of the 11th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining (pp. 641–647). Association for Computing Machinery. https://doi.org/10.1145/1081870.1081950
Meng, D., & Chen, H. (2017). MagNet: A two-pronged defense against adversarial examples. In Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security (pp. 135–147). Association for Computing Machinery. https://doi.org/10.1145/3133956.3134057
Metzen, J. H., Genewein, T., Fischer, V., & Bischoff, B. (2017). On detecting adversarial perturbations. arXiv. https://doi.org/10.48550/arXiv.1702.04267
Moosavi-Dezfooli, S.-M., Fawzi, A., Fawzi, O., & Frossard, P. (2017). Universal adversarial perturbations. In Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR) (pp. 1765–1773). IEEE. https://doi.org/10.1109/CVPR.2017.17
Nelson, B., Barreno, M., Chi, F. J., Joseph, A. D., Rubinstein, B. I. P., Saini, U., Sutton, C., Tygar, J. D., & Xia, K. (2008). Exploiting machine learning to subvert your spam filter. In Proceedings of the 1st USENIX Workshop on Large-Scale Exploits and Emergent Threats (pp. 7:1–7:9). USENIX Association.
Orekondy, T., Schiele, B., & Fritz, M. (2019). Knockoff nets: Stealing functionality of black-box models. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR) (pp. 4954–4963). IEEE. https://doi.org/10.1109/CVPR.2019.00509
Pascu, L. (2020, June 29). Acronis reports critical flaws in GeoVision biometric devices, man-in-the-middle attack risks. Biometric Update
Paudice, A., Muñoz-González, L., György, A., & Lupu, E. C. (2018). Detection of adversarial training examples in poisoning attacks through anomaly detection. arXiv. https://doi.org/10.48550/arXiv.1802.03041
Ramirez, M. A., Kim, S.-K., Al Hamadi, H., Damiani, E., Byon, Y.-J., Kim, T.-Y., Cho, C.-S., & Yeun, C. Y. (2022). Poisoning attacks and defenses on artificial intelligence: A survey. arXiv. https://doi.org/10.48550/arXiv.2202.10276
Rössler, A., Cozzolino, D., Verdoliva, L., Riess, C., Thies, J., & Nießner, M. (2019). FaceForensics++: Learning to detect manipulated facial images. In Proceedings of the IEEE/CVF International Conference on Computer Vision (ICCV) (pp. 1–11). IEEE. https://doi.org/10.1109/ICCV.2019.00009
Rumelhart, D. E., Hinton, G. E., & Williams, R. J. (1986). Learning representations by back-propagating errors. Nature, 323(6088), 533–536. https://doi.org/10.1038/323533a0
Schwartz, O. (2018, November 12). You thought fake news was bad? Deep fakes are where truth goes to die. The Guardian. Original Guardian article
Seals, T. (2020, July 23). ASUS home router bugs open consumers to snooping attacks. Threatpost.
Su, J., Vargas, D. V., & Sakurai, K. (2019). One pixel attack for fooling deep neural networks. IEEE Transactions on Evolutionary Computation, 23(5), 828–841. https://doi.org/10.1109/TEVC.2019.2890858
Thies, J., Zollhöfer, M., & Nießner, M. (2019). Deferred neural rendering: Image synthesis using neural textures. ACM Transactions on Graphics, 38(4), Article 66. https://doi.org/10.1145/3306346.3323035
Wang, B., & Gong, N. Z. (2018). Stealing hyperparameters in machine learning. In 2018 IEEE Symposium on Security and Privacy (SP) (pp. 36–52). IEEE. https://doi.org/10.1109/SP.2018.00038
Wittel, G. L., & Wu, S. F. (2004). On attacking statistical spam filters. In Proceedings of the First Conference on Email and Anti-Spam (CEAS 2004). CEAS.
Xu, W., Evans, D., & Qi, Y. (2017). Feature squeezing: Detecting adversarial examples in deep neural networks. arXiv. https://doi.org/10.48550/arXiv.1704.01155
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Anas A. Nicola (Author)

This work is licensed under a Creative Commons Attribution 4.0 International License.

