From vulnerability to resilience: Adversarial training and real-time detection for AI security

Georgios Ziras, Aristeidis Farao, Apostolis Zarras, Christos Xenakis · Array · 2025

The growing integration of Artificial Intelligence systems into critical infrastructure, such as cybersecurity, healthcare, and finance, has raised significant concerns regarding model robustness in the presence of adversarial attacks. This study examines the vulnerability of various machine learning models to adversarial manipulations and evaluates effective detection and mitigation strategies to improve model resilience. Leveraging the CIC-IDS2017 and CICIoT2023 datasets, we train and evaluate a suite of ML classifiers, including Decision Tree, Random Forest, Logistic Regression, XGBoost, Recurrent Neural Networks, Convolutional Neural Networks, and a custom PyTorch-based Neural Network, under a spectrum of adversarial evasion attacks. These include the Fast Gradient Sign Method, Projected Gradient Descent, DeepFool, Carlini–Wagner, and transfer attacks. We assess classifier robustness against those attacks and examine their defensive behavior through adversarial training, as well as binary input and activation-based detection mechanisms. Our findings indicate that adversarial training provides a more effective and consistent defense compared to detection-based methods.

Read the paper · More papers on PaperTik