PGD–PPM: A Hybrid Framework for Enhancing Adversarial Robustness in Traffic Sign Recognition System
Raiyah Rub, Shaheena Noor, Irfan Ahmed Usmani, Zain Anwar Ali · IEEE Access · 2026
Traffic Sign Recognition (TSR) models based on Deep Learning are highly vulnerable to adversarial perturbations where often imperceptible changes to the input can significantly mislead model predictions and posing serious safety concerns in autonomous driving. This paper presents PGD–PPM, a hybrid defense framework designed to enhance adversarial robustness of TSR models by combining Projected Gradient Descent–based Adversarial Training (PGD-AT) with Pyramid Pooling Module (PPM) integration. The proposed architecture improves multi-scale contextual feature aggregation to resist adversarial perturbations while maintaining high clean accuracy. Four Convolutional Neural Network (CNN) architectures, VGG16, VGG19, ResNet50 and EfficientNetB0 were evaluated on two benchmark datasets GTSRB) and BelgiumTSC datasets under gradient based white-box attacks FGSM, IFGSM and PGD at various perturbation strengths (ϵ=0.1-2.0). The proposed models exhibit significant improvement in clean and adversarial accuracies. For instance, EfficientNetB0 with PGD-PPM achieves the most significant improvement in clean accuracy of 92.57% (up from 87.55%), VGG16 and VGG19 also increase by +4.29% and +3.10%, respectively, whereas EfficientNetB0 maintaining robustness with improved adversarial accuracy of 89% and 87% under strong adversarial condition (PGD attack at, ϵ = 0.1, 0.2). However, ResNet50 achieves the highest adversarial accuracy of 90% and 88% under PGD attack at ϵ = 0.1 and 0.2, which is significantly higher than the corresponding baseline model. The experimental results indicates that proposed framework not only possess a strong improvement in adversarial accuracy but it also improves the clean accuracy which mitigates the accuracy-robustness trade-off, contributing to safer and more reliable intelligent systems.