[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-118762-en":3,"doc-seo-118762-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},118762,687197100911,"Himbo","https://ap-avatar.wpscdn.com/avatar/a000239b6f1da00475?x-image-process=image/resize,m_fixed,w_180,h_180&k=1785132997149421697",8,"Research & Report","Adversarial-Aware Deep Learning System based on a Secondary Classical Machine Learning Verification Approach","Deep learning–based image classification systems are effective yet susceptible to adversarial attacks that manipulate inputs to force incorrect predictions. This work analyzes major adversarial attack models and identifies that they exploit neural network structures, motivating a hypothesis that classical machine learning methods such as Random Forest are comparatively robust. Experiments on popular attacks using the CIFAR-100 dataset validate the hypothesis. A new adversarial-aware architecture integrates a primary deep model with a secondary classical verification module that flags clear prediction mismatches without reducing primary accuracy. The proposed approach achieves improved performance over current state-of-the-art defenses.","Adversarial-Aware Deep Learning System based on a Secondary Classical Machine Learning Verification Approach  \nMohammed Alkhowaiter 1,2, Hisham Kholidy 3, Mnassar Alyami 1, Abdulmajeed Alghamdi 1, and Cliff Zou 1,*  \n1 College of Engineering and Computer Science, University of Central Florida, USA  \n2 College of Computer Engineering and Science, Prince Sattam bin Abdulaziz University, Saudi Arabia  \n3 College of Engineering, SUNY Polytechnic Institute, Utica, USA  \n* Correspondence: [changchun.zou@ucf.edu](changchun.zou@ucf.edu); Tel.: +1-407-823-5015  \nAbstract: Deep learning models have been used in creating various effective image classification applications. However, they are vulnerable to adversarial attacks that seek to misguide the models into predicting incorrect classes. Our study of major adversarial attack models shows that they all specifically target and exploit the neural networking structures in their designs. This understanding makes us develop a hypothesis that most classical machine learning models, such as Random Forest (RF), are immune to adversarial attack models because they do not rely on neural network design at all. Our experimental study of classical machine learning models against popular adversarial attacks supports this hypothesis. Based on this hypothesis, we propose a new adversarial-aware deep learning system by using a classical machine learning model as the secondary verification system to complement the primary deep learning model in image classification. Although the secondary classical machine learning model has less accurate output, it is only used for verification purposes, which does not impact the output accuracy of the primary deep learning model, and at the same time, can effectively detect an adversarial attack when a clear mismatch occurs. Our experiments based on CIFAR-100 dataset show that our proposed approach outperforms current state-of-the-art adversarial defense systems.  \nKeywords: Computer security; Deep neural networks; Image forensics; Adversarial machine learning; Image manipulation detection;  \n1. Introduction  \nAs machine learning (ML) technology, especially deep learning technique, in computer vision continues to advance, the challenges of adversarial attacks are becoming increasingly prevalent. Adversarial attacks refer to image manipulation to deceive computer vision tasks where the image seems correct at human perception [1] . Some of these attacks can lead to harmful failures in sensitive computer vision-based applications, such as targeting autonomous vehicles to mislead the AI system in those vehicles to recognize the road STOP sign as SPEED LIMIT 65. The increased demand for AI applications may increase the risks of this technology if it is not secured well before it is put on the market. Therefore, in recent years researchers have continued to develop algorithms and systems to prevent adversarial attacks. In this paper, we develop a novel adversarial-aware deep learning system by employing a classical ML algorithm as the auxiliary verification approach.  \nDeep Neural Network (DNN) theory, also called deep learning, accelerates the development of computer vision applications to advance [2–5] . Unlike other AI approaches, it can quickly learn complex patterns and representations from large and high-dimensional datasets. Therefore, according to Stone [6] study, DNN technology will be used in an expanding range of real-world applications within the next decade. Examples of these applications include autonomous vehicles, security surveillance cameras, and healthcare. However, this technology faces serious security challenges because of two factors. One is the high dimension and complexity of the input data to DNN models, which means it is hard to catch all potential attacks as adversarial attackers can insert small but enough  \nperturbations to mislead the system. Second is the non-linearity in the decision boundaries of DNNs, resulting in unexpected and complex be","cbCaiapbCwCH2GXd","https://ap.wps.com/l/cbCaiapbCwCH2GXd","pdf",519252,1,17,"English","en",105,"# Introduction\n## Inspiration\n# Adversarial-Aware System Design\n## Secondary Classical Verification Approach\n# Experimental Evaluation\n## CIFAR-100 Results and Comparison","[{\"question\":\"What is the main idea behind the proposed adversarial-aware deep learning system?\",\"answer\":\"The system pairs a primary deep learning image classifier with a secondary classical machine learning verification model. The secondary model is used to detect adversarial attacks by flagging mismatches with the primary model’s output.\"},{\"question\":\"Why does the paper hypothesize that classical ML models are more robust to adversarial attacks?\",\"answer\":\"The study of adversarial attack models suggests they target and exploit neural network structures. Classical machine learning models like Random Forest do not rely on neural network design, making them immune to many known adversarial attack methods.\"},{\"question\":\"How are experiments conducted to validate the approach?\",\"answer\":\"Experiments evaluate classical machine learning models against popular adversarial attacks and then test the combined adversarial-aware system on the CIFAR-100 dataset. Results show the proposed method outperforms existing state-of-the-art adversarial defense systems.\"}]","Adversarial-Aware Deep Learning System based on a Secondary Classical Machine Learning Verification Approach | PDF",1785720099,43,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"adversarial-aware-deep-learning-system-based-on-a-secondary-classical-machine-learning-verification-approach","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/adversarial-aware-deep-learning-system-based-on-a-secondary-classical-machine-learning-verification-approach/118762/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-03",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What is the main idea behind the proposed adversarial-aware deep learning system?","Question",{"text":75,"@type":76},"The system pairs a primary deep learning image classifier with a secondary classical machine learning verification model. The secondary model is used to detect adversarial attacks by flagging mismatches with the primary model’s output.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"Why does the paper hypothesize that classical ML models are more robust to adversarial attacks?",{"text":80,"@type":76},"The study of adversarial attack models suggests they target and exploit neural network structures. Classical machine learning models like Random Forest do not rely on neural network design, making them immune to many known adversarial attack methods.",{"name":82,"@type":73,"acceptedAnswer":83},"How are experiments conducted to validate the approach?",{"text":84,"@type":76},"Experiments evaluate classical machine learning models against popular adversarial attacks and then test the combined adversarial-aware system on the CIFAR-100 dataset. Results show the proposed method outperforms existing state-of-the-art adversarial defense systems.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]