PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
September 18, 2025IEEE Transactions on Pattern Analysis and Machine Intelligence9 citations

Defenses in Adversarial Machine Learning: a Systematic Survey from the Lifecycle Perspective

View Full Paper
BWBaoyuan WuMZMingli ZhuMZMeixi Zheng

Key Points

  • This survey reviews defense mechanisms against adversarial attacks in machine learning systems.
  • Key findings reveal various defense paradigms categorized across five stages: pre-training, training, post-training, deployment, and inference.
  • The analysis uses a unified lifecycle perspective, presenting a comprehensive taxonomy of defense methods for better understanding.
  • This work highlights the need for advanced strategies in addressing the challenges posed by diverse adversarial attacks.

Abstract

Adversarial phenomena have been widely observed in machine learning (ML) systems, especially those using deep neural networks. These phenomena describe situations where ML systems may produce predictions that are inconsistent and incomprehensible to humans in certain specific cases. Such behavior poses a serious security threat to the practical application of ML systems. To exploit this vulnerability, several advanced attack paradigms have been developed, mainly including backdoor attacks, weight attacks, and adversarial examples. For each individual attack paradigm, various defense mechanisms have been proposed to enhance the robustness of models against the corresponding attacks. However, due to the independence and diversity of these defense paradigms, it is challenging to assess the overall robustness of an ML system against different attack paradigms. This survey aims to provide a systematic review of all existing defense paradigms from a unified lifecycle perspective. Specifically, we decompose a complete ML system into five stages: pre-training, training, post-training, deployment, and inference. We then present a clear taxonomy to categorize representative defense methods at each stage. The unified perspective and taxonomy not only help us analyze defense mechanisms but also enable us to understand the connections and differences among different defense paradigms. It inspires future research to develop more advanced and comprehensive defense strategies.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Wu et al. (2025) studied this question.

synapsesocial.com/papers/68d461b631b076d99fa607dbhttps://doi.org/10.1109/tpami.2025.3611340
Ask AI
Helpful
Bookmark
Share
View Full Paper

Also Consider

Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context:

  1. 1NAPER: Fault Protection for Real-Time Resource-Constrained Deep Neural Networks2025 · 7 citations
  2. 2Detecting Backdoors in Pre-trained Encoders2023 · 46 citations
  3. 3Enhancing Fine-Tuning based Backdoor Defense with Sharpness-Aware Minimization2023 · 48 citations
  4. 4Detection of Adversarial Attacks via Disentangling Natural Images and Perturbations2024 · 19 citations
  5. 5Defending Against Universal Attacks Through Selective Feature Regeneration2020 · 43 citations