IJRSAT
editorinchief@ijrsat.com | ijrsatjournal@gmail.com
🌟 10+ Years of Excellence 🌟
I S S N 2319-2690
IJRSAT
International Journal for Research In Science & Advanced Technologies
" Enriching The Research "
International, Peer Reviewed, Open Access Journal
ISSN Approved Journal No. 2319-2690
Medium Icon
DOI Prefix: 10.65726
  IJRSAT Archive
Opening publications…

Publication Details

Back to Archives
Enhancing the Robustness of Traffic Sign Recognition System Against Adversarial Attacks Using CNN and U-Net Based Autoencoder
Dr.Ayesha Ameen, Ayisha Begum
DOI: Not available
Year: 2026  |  Volume: 26  |  Issue: 8
Date of Publication: 2026/08/20
Keywords: Traffic Sign Recognition, GTSRB, Convolutional Neural Network, Adversarial Examples, FGSM, U-Net, Denoising Autoencoder, Adversarial Defense.

Abstract

By enabling vehicles to accurately interpret and respond to road signs, traffic sign recognition is a pivotal component of ITS and autonomous driving technology. The advances in DL, particularly the CNNs, have significantly improved the accuracy of traffic sign classification. Nonetheless, DL architectures are susceptible to adversarial assaults, whereby little and inconspicuous alterations introduced to input photos might result in erroneous classifications and perhaps culminate in hazardous driving choices.
This initiative showcases a resilient Traffic Sign Recognition System proficient at identifying and countering aggressive threats. It is based on a CNN trained on a GTSRB database to accurately recognize traffic signs. To test how easily the classifier can be fooled, the FGSM is used to produce adversarial examples that are deliberately designed to mislead the CNN model. A U-Net-based autoencoder is applied to help recover adversarially disturbed traffic sign pictures to counteract the impact of such attacks. The skip connections in the U-Net architecture preserve the full spatial information and remove the negative perturbations, resulting in better classification accuracy.
The proposed structure is implemented using Python, TensorFlow, Keras, OpenCV and Flask. A web-based platform allows the user to upload an image of a traffic sign and view the initial prediction, adversarial prediction and reconstructed prediction. The CNN can reach high classification accuracy for pure traffic sign images, and the autoencoder is effective in reducing the effect of adversarial perturbations and improving the overall robustness of the system.
This existing framework highlights the importance of the adversarial defense approach for recognition systems in traffic signs, and it helps enhance the security and reliability of the DL models used in autonomous vehicles and intelligent transportation systems.

References

  1. [1] I. J. Goodfellow, J. Shlens, and C. Szegedy, “Explaining and Harnessing Adversarial Examples,” International Conference on Learning Representations (ICLR), 2015. [2] N. Akhtar and A. Mian, “Threat of Adversarial Attacks on Deep Learning in Computer Vision: A Survey,” IEEE Access, vol. 6, pp. 14410–14430, 2018, doi: 10.1109/ACCESS.2018.2807385. [3] A. Kurakin, I. J. Goodfellow, and S. Bengio, “Adversarial Examples in the Physical World,” ICLR Workshop, 2017. [4] D. S, A. Kuragayala, A. T. Pamu, A. K. Sharma, and G. Salapakshi, “Robust Training of Convolutional Neural Networks Against Adversarial Attacks Using Fast Gradient Sign Method,” International Journal of Creative Research Thoughts (IJCRT), vol. 12, no. 4, 2024. [5] O. Ronneberger, P. Fischer, and T. Brox, “U-Net: Convolutional Networks for Biomedical Image Segmentation,” in Medical Image Computing and Computer-Assisted Intervention (MICCAI 2015), Lecture Notes in Computer Science, vol. 9351, Springer, pp. 234–241, 2015, doi: 10.1007/978-3-319-24574-4_28. [6] F. Morimoto, R. Morita, and S. Ono, “Rectifying Adversarial Examples Using Their Vulnerabilities,” IEEE Access, vol. 13, pp. 45500–45517, 2025, doi: 10.1109/ACCESS.2025.3550024. [7] J. Stallkamp, M. Schlipsing, J. Salmen, and C. Igel, “The German Traffic Sign Recognition Benchmark: A Multi-class Classification Competition,” in Proceedings of the IEEE International Joint Conference on Neural Networks (IJCNN), pp. 1453–1460, 2011, doi: 10.1109/IJCNN.2011.6033395. [8] A. Madry, A. Makelov, L. Schmidt, D. Tsipras, and A. Vladu, “Towards Deep Learning Models Resistant to Adversarial Attacks,” International Conference on Learning Representations (ICLR), 2018; arXiv:1706.06083. [9] N. Carlini and D. Wagner, “Towards Evaluating the Robustness of Neural Networks,” in Proceedings of the IEEE Symposium on Security and Privacy, pp. 39–57, 2017, doi: 10.1109/SP.2017.49. [10] C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, and R. Fergus, “Intriguing Properties of Neural Networks,” International Conference on Learning Representations (ICLR), 2014.