A Comparative Study of Adversarial Robustness in CNN and CNN-ANFIS Architectures

๐Ÿ“… 2026-02-02
๐Ÿ“ˆ Citations: 0
โœจ Influential: 0
๐Ÿ“„ PDF
๐Ÿค– AI Summary
This study investigates whether integrating Adaptive Neuro-Fuzzy Inference Systems (ANFIS) into mainstream convolutional neural networksโ€”such as ConvNet, VGG, and ResNet18โ€”can simultaneously enhance robustness against adversarial attacks and improve model interpretability. Through systematic evaluations on MNIST, Fashion-MNIST, CIFAR-10, and CIFAR-100 using both gradient-based (PGD) and gradient-free (Square) attack methods, the work reveals for the first time that the effectiveness of ANFIS augmentation is highly dependent on the backbone architecture: ResNet18-ANFIS exhibits significantly improved robustness, whereas VGG-ANFIS often underperforms relative to its baseline. These findings demonstrate that ANFIS-based enhancement lacks universality across network structures and offer new empirical insights and design considerations for developing interpretable yet robust deep learning models.

Technology Category

Machine Learning: Adversarial Learning & RobustnessComputer Vision: Adversarial Attacks & RobustnessNatural Language Processing: Safety and Robustness

Application Category

Semantics and Knowledge: Methods to enhance, augment, integrate or synergize semantic models such as knowledge graphs and LLMsGraph Algorithms and Modeling for the Web: Graph neural networks and deep learning approaches for Web-related graphsSearch and Retrieval-Augmented AI: Web learning to rank, online learning, and counterfactual learning for ranking
๐Ÿ“ Abstract
Convolutional Neural Networks (CNNs) achieve strong image classification performance but lack interpretability and are vulnerable to adversarial attacks. Neuro-fuzzy hybrids such as DCNFIS replace fully connected CNN classifiers with Adaptive Neuro-Fuzzy Inference Systems (ANFIS) to improve interpretability, yet their robustness remains underexplored. This work compares standard CNNs (ConvNet, VGG, ResNet18) with their ANFIS-augmented counterparts on MNIST, Fashion-MNIST, CIFAR-10, and CIFAR-100 under gradient-based (PGD) and gradient-free (Square) attacks. Results show that ANFIS integration does not consistently improve clean accuracy and has architecture-dependent effects on robustness: ResNet18-ANFIS exhibits improved adversarial robustness, while VGG-ANFIS often underperforms its baseline. These findings suggest that neuro-fuzzy augmentation can enhance robustness in specific architectures but is not universally beneficial.
Problem

Research questions and friction points this paper is trying to address.

adversarial robustness
CNN
ANFIS
interpretability
adversarial attacks
Innovation

Methods, ideas, or system contributions that make the work stand out.

adversarial robustness
CNN-ANFIS
neuro-fuzzy systems
interpretability
architecture-dependent robustness
๐Ÿ”Ž Similar Papers
No similar papers found.
K
Kaaustaaub Shankar
College of Engineering and Applied Science, University of Cincinnati, Cincinnati, OH 45219, USA
B
Bharadwaj Dogga
College of Engineering and Applied Science, University of Cincinnati, Cincinnati, OH 45219, USA
Kelly Cohen
Kelly Cohen
Brian Rowe Endowed Chair in Aerospace Engineering, University of Cincinnati
UAV & roboticsAdvanced Air MobilityIntelligent autonomous systemsGenetic fuzzy AI & predictive modelingFeedback flow con