Download PDFOpen PDF in browserAdversarial Defense Using Latent Anomaly Detection and Image Purification16 pages•Published: August 6, 2026AbstractRecently, Convolutional Neural Networks (CNNs) have demonstrated high performance in image recognition tasks, but they remain vulnerable to adversarial examples, which intentionally cause misclassification through imperceptible perturbations. Conventional defense methods using Autoencoders (AEs) rely solely on anomaly detection based on reconstruction error or image purification. These approaches are often insufficient against White-box attacks, as attackers can bypass either of the defenses, making robust protection difficult. In this study, we propose "DSVDD-AE," a two-stage defense method that integrates anomaly detection based on feature distance in the latent space using Deep SVDD (DSVDD) with image purification via AE. This two-stage approach enables the detection of attacks that cannot be effectively purified, providing robust defense even under White-box environments. In our evaluation, we constructed two types of models using Contractive AE (CAE) and Variational AE (VAE) and verified their defense performance against PGD attacks on the CIFAR-10 dataset. Under a White-box attack environment, the proposed method (DSVDD-VAE) achieved a defense success rate of 30.28%, marking an improvement of approximately 30 percentage points compared to the existing Defense-VAE.Keyphrases: adversarial examples, auto encoder, dsvdd In: Tung-Tso Tsai, Huy Kang Kim, Yujue Wang and Akira Yamada (editors). Proceedings of The 21st Asia Joint Conference on Information Security, vol 111, pages 95-110.
|

