๐ค AI Summary
This study investigates whether integrating Adaptive Neuro-Fuzzy Inference Systems (ANFIS) into mainstream convolutional neural networksโsuch as ConvNet, VGG, and ResNet18โcan simultaneously enhance robustness against adversarial attacks and improve model interpretability. Through systematic evaluations on MNIST, Fashion-MNIST, CIFAR-10, and CIFAR-100 using both gradient-based (PGD) and gradient-free (Square) attack methods, the work reveals for the first time that the effectiveness of ANFIS augmentation is highly dependent on the backbone architecture: ResNet18-ANFIS exhibits significantly improved robustness, whereas VGG-ANFIS often underperforms relative to its baseline. These findings demonstrate that ANFIS-based enhancement lacks universality across network structures and offer new empirical insights and design considerations for developing interpretable yet robust deep learning models.
๐ Abstract
Convolutional Neural Networks (CNNs) achieve strong image classification performance but lack interpretability and are vulnerable to adversarial attacks. Neuro-fuzzy hybrids such as DCNFIS replace fully connected CNN classifiers with Adaptive Neuro-Fuzzy Inference Systems (ANFIS) to improve interpretability, yet their robustness remains underexplored. This work compares standard CNNs (ConvNet, VGG, ResNet18) with their ANFIS-augmented counterparts on MNIST, Fashion-MNIST, CIFAR-10, and CIFAR-100 under gradient-based (PGD) and gradient-free (Square) attacks. Results show that ANFIS integration does not consistently improve clean accuracy and has architecture-dependent effects on robustness: ResNet18-ANFIS exhibits improved adversarial robustness, while VGG-ANFIS often underperforms its baseline. These findings suggest that neuro-fuzzy augmentation can enhance robustness in specific architectures but is not universally beneficial.