Skip to main content
. 2025 Aug 22;15:30861. doi: 10.1038/s41598-025-15753-8

Table 4.

Common methods for each defense strategy in the literature.

Defense Strategy Authors Method Datasets Attacks
Robustness Kurakin et al.25 Adversarial training with FGSM ImageNet101 FGSM17
Jang et al.26 Training with adversarial examples MNIST105, CIFAR-10106 FGSM17, C&W80, PGD23
Transformations Guo et al.35 Quilting, TVM, cropping, rescaling ImageNet101 DeepFool78, FGSM17, C&W80, I-FGSM25
Shaham et al.34 PCA, wavelet, JPEG compression NIPS 2017 competition FGSM17, C&W80, I-FGSM25
Detection Gong et al.29 Binary CNN MNIST105, CIFAR-10106, SVHN FGSM17, TGSM107, JSMA79
Massoli et al.27 MLP/LSTM on AFR filters VGGFace262 FGSM17, C&W80, BIM107
Goel et al.28 Adaptive noise detection Yale Face108 DeepFool78, FGSM17, EAD109
Goswami et al.110 SVM on AFR filters MEDS111, PaSC112, MBGC113 EAD109
Agarwal et al.30 PCA + SVM PaSC112, MEDS111, Multi-PIE114 Universal Perturbation16, Fast Feature Fool115
Awany et al.116 Detection framework CASIA-WebFace59, LFW11 FGSM17, PGD23, AdvFaces21
Purification Debayan et al.36 Generator + detector + purifier CASIA-WebFace59, LFW11, CelebA117, FFHQ118 FGSM17, PGD23, DeepFool78, AdvFaces21, GFLM85, Semantic 119