Learning from the Good Ones: Risk Profiling-Based Defenses Against Evasion Attacks on DNNs

Mohammed Elnawawy, Gargi Mitra, Shahrear Iqbal, Karthik Pattabiraman · 2025

Deep neural networks (DNNs) have gained traction in safety-critical applications such as healthcare [1]–[5] and autonomous vehicles (AVs) [6]–[8]. However, DNNs are highly susceptible to evasion attacks [9]–[11], which trick DNNs into misclassifying an adversarial sample at inference time [12], [13]. Researchers have proposed several defenses to protect DNNs against evasion attacks, with defenses being either static or dynamic in nature. Static defenses are easier to implement, demonstrate higher accuracy on benign data, and are more computationally efficient, but cannot adapt to different attack strategies or the evolving behavior of victim instances (e.g., patients) [14]. Dynamic defenses are more robust to evasion attacks because they adapt to evolving attack and victim behaviors, but suffer from degradation of benign data accuracy and high computational overhead at inference time. Therefore, they are not suitable for time-sensitive safety-critical applications [15].

Read the paper · More papers on PaperTik