International Peer-Reviewed JournalOpen AccessISSN 2456-8880
irejournals@gmail.com+91-7433024337

Home / Current Issue / Paper 1723116

1723116 Vol 10 · Issue 3 Download Paper

Securing Deep Learning Systems: Attacks and Defenses across Neural Networks, Federated, Transfer, and Reinforcement Learning

Mamoon Ahmed Yahay Al Khadher

Subject area: Science,Engineering and Technology  ·  Area of research: Deep Learning and AI Security

Abstract

Deep Learning (DL) techniques are widely deployed in critical applications such as autonomous driving, healthcare, and intelligent infrastructure. Core paradigms—Deep Neural Networks (DNNs), Deep Reinforcement Learning (DRL), Federated Learning (FL), and Transfer Learning (TL)—remain vulnerable to adversarial attacks that can degrade performance, leak private data, or produce unsafe decisions. Developing effective attacks and corresponding countermeasures is a prerequisite for robust, secure, and deployable artificial intelligence. Prior surveys often focused on only one or two techniques, omitted detailed discussion of datasets, metrics, and testbeds, or became outdated. This survey comprehensively reviews attacks and defenses across DNN, DRL, FL, and TL. We summarize threat models, representative attack and defense techniques, evaluation metrics, commonly used datasets, and experimental settings. A key contribution is an explicit analysis of the commonalities and differences among the four paradigms. Insights, lessons learned, and future research directions are presented to guide the development of trustworthy deep-learning systems.

Keywords

Adversarial attacks, defenses, deep neural networks, federated learning, transfer learning, deep reinforcement learning, robustness, privacy, trustworthy AI.

References

[1] H. Ali, D. Chen, M. Harrington, N. Salazar, M. Al Ameedi, A. F. Khan, A. R. Butt, and J.-H. Cho, “A Survey on Attacks and Their Countermeasures in Deep Learning: Applications in Deep Neural Networks, Federated, Transfer, and Deep Reinforcement Learning,” IEEE Access, vol. 11, pp. 120095–120140, 2023. Crossref

[2] P. Kairouz et al., “Advances and open problems in federated learning,” Foundations and Trends in Machine Learning, vol. 14, nos. 1–2, pp. 1–210, 2021. Crossref

[3] I. J. Goodfellow, J. Shlens, and C. Szegedy, “Explaining and harnessing adversarial examples,” in Proc. Int. Conf. Learning Representations (ICLR), 2015.

[4] A. Madry, A. Makelov, L. Schmidt, D. Tsipras, and A. Vladu, “Towards deep learning models resistant to adversarial attacks,” in Proc. Int. Conf. Learning Representations (ICLR), 2018.

[5] N. Carlini and D. Wagner, “Towards evaluating the robustness of neural networks,” in Proc. IEEE Symp. Security and Privacy, 2017, pp. 39–57. Crossref

[6] T. Gu, B. Dolan-Gavitt, and S. Garg, “BadNets: Identifying vulnerabilities in the machine learning model supply chain,” arXiv:1708.06733, 2017. https://arxiv.org/abs/1708.06733 [Crossref]

[7] E. Bagdasaryan, A. Veit, Y. Hua, D. Estrin, and V. Shmatikov, “How to backdoor federated learning,” in Proc. Int. Conf. Artificial Intelligence and Statistics (AISTATS), 2020.

[8] L. Lyu, H. Yu, X. Ma, C. Chen, L. Sun, J. Yu, B. Liu, and P. S. Yu, “Privacy and robustness in federated learning: Attacks and defenses,” IEEE Trans. Neural Networks and Learning Systems, 2022.

[9] Y. Liu, S. Ma, Y. Aafer, W.-C. Lee, J. Zhai, W. Wang, and X. Zhang, “Trojaning attack on neural networks,” in Proc. Network and Distributed System Security Symp. (NDSS), 2018.

[10] S. Huang, N. Papernot, I. Goodfellow, Y. Duan, and P. Abbeel, “Adversarial attacks on neural network policies,” ICLR Workshop on Trustworthy Machine Learning, 2017.

[11] A. Gleave, M. Dennis, C. Wild, N. Kant, S. Levine, and S. Russell, “Adversarial policies: Attacking deep reinforcement learning,” in Proc. Int. Conf. Learning Representations (ICLR), 2020.

[12] J. Cohen, E. Rosenfeld, and Z. Kolter, “Certified adversarial robustness via randomized smoothing,” in Proc. Int. Conf. Machine Learning (ICML), 2019, pp. 1310–1320.

[13] N. Papernot, P. McDaniel, S. Jha, M. Fredrikson, Z. B. Celik, and A. Swami, “The limitations of deep learning in adversarial settings,” in Proc. IEEE European Symp. Security and Privacy, 2016. Crossref

[14] B. Biggio and F. Roli, “Wild patterns: Ten years after the rise of adversarial machine learning,” Pattern Recognition, vol. 84, pp. 317–331, 2018. Crossref

[15] N. Carlini et al., “Extracted training data from large language models,” in Proc. USENIX Security Symp., 2021.

[16] M. Rigaki and S. Garcia, “A survey of privacy attacks in machine learning,” ACM Computing Surveys, vol. 56, no. 4, pp. 1–34, 2023.

[17] T. Chen, S. Liu, S. Chang, Y. Cheng, L. Amini, and Z. Wang, “Adversarial robustness: From self-supervised pre-training to fine-tuning,” in Proc. IEEE/CVF Conf. Computer Vision and Pattern Recognition (CVPR), 2020.

[18] A. S. Rakin, Z. He, and D. Fan, “Bit-flip attack: Crushing neural network with progressive bit search,” in Proc. IEEE/CVF Int. Conf. Computer Vision (ICCV), 2019. Crossref

[19] A. Szegedy et al., “Intriguing properties of neural networks,” in Proc. Int. Conf. Learning Representations (ICLR), 2014.

[20] Yuan, P. He, Q. Zhu, and X. Li, “Adversarial examples: Attacks and defenses for deep learning,” IEEE Trans. Neural Networks and Learning Systems, vol. 30, no. 9, pp. 2805–2824, 2019. Crossref

[21] S.-M. Moosavi-Dezfooli, A. Fawzi, and P. Frossard, “DeepFool: A simple and accurate method to fool deep neural networks,” in Proc. IEEE/CVF Conf. Computer Vision and Pattern Recognition (CVPR), 2016.

[22] A. Shafahi et al., “Poison frogs! Targeted clean-label poisoning attacks on neural networks,” in Proc. Advances in Neural Information Processing Systems (NeurIPS), 2018.

[23] A. Liang, H. Li, M. Su, P. Bian, X. Li, and W. Shi, “Deep text classification can be fooled by long and disguised adversarial examples,” in Proc. Int. Joint Conf. Artificial Intelligence (IJCAI), 2018.

[24] K. Bonawitz et al., “Practical secure aggregation for privacy-preserving machine learning,” in Proc. ACM SIGSAC Conf. Computer and Communications Security (CCS), 2017. Crossref

[25] M. Blanchard, E. M. El Mhamdi, R. Guerraoui, and J. Stainer, “Machine learning with adversaries: Byzantine tolerant gradient descent,” in Proc. Advances in Neural Information Processing Systems (NeurIPS), 2017.

[26] Y. Sun, A. Bhowmick, and J. M. Karbasi, “Communication-efficient learning of deep networks from decentralized data,” in Proc. Int. Conf. Artificial Intelligence and Statistics (AISTATS), 2017.

[27] T. Lillicrap et al., “Continuous control with deep reinforcement learning,” in Proc. Int. Conf. Learning Representations (ICLR), 2016.

[28] V. Mnih et al., “Human-level control through deep reinforcement learning,” Nature, vol. 518, no. 7540, pp. 529–533, 2015. Crossref

[29] T. Everitt, G. Lea, and M. Hutter, “AGI safety literature review,” arXiv:1805.01109, 2018. https://arxiv.org/abs/1805.01109 [Crossref]

[30] N. Papernot et al., “Semi-supervised knowledge transfer for deep learning from private training data,” in Proc. Int. Conf. Learning Representations (ICLR), 2017.

How to cite this paper

Mamoon Ahmed Yahay Al Khadher "Securing Deep Learning Systems: Attacks and Defenses across Neural Networks, Federated, Transfer, and Reinforcement Learning" Iconic Research And Engineering Journals Volume 10 Issue 3 2026 Page 1721-1728
Mamoon Ahmed Yahay Al Khadher "Securing Deep Learning Systems: Attacks and Defenses across Neural Networks, Federated, Transfer, and Reinforcement Learning" Iconic Research And Engineering Journals, vol. 10, no. 3, Sep. 2026
Mamoon Ahmed Yahay Al Khadher (2026). Securing Deep Learning Systems: Attacks and Defenses across Neural Networks, Federated, Transfer, and Reinforcement Learning. Iconic Research And Engineering Journals, 10(3).
Mamoon Ahmed Yahay Al Khadher "Securing Deep Learning Systems: Attacks and Defenses across Neural Networks, Federated, Transfer, and Reinforcement Learning" Iconic Research And Engineering Journals, vol. 10, no. 3, Sep. 2026.
@article{1723116,
      author = {Mamoon Ahmed Yahay Al Khadher},
      title = {Securing Deep Learning Systems: Attacks and Defenses across Neural Networks, Federated, Transfer, and Reinforcement Learning},
      journal = {Iconic Research And Engineering Journals},
      year = {2026},
      volume = {10},
      number = {3},
      pages = {1721-1728},
      issn = {2456-8880},
      url = {https://www.irejournals.com/formatedpaper/1723116.pdf},
      abstract = {Deep Learning (DL) techniques are widely deployed in critical applications such as autonomous driving, healthcare, and intelligent infrastructure. Core paradigms—Deep Neural Networks (DNNs), Deep Reinforcement Learning (DRL), Federated Learning (FL), and Transfer Learning (TL)—remain vulnerable to adversarial attacks that can degrade performance, leak private data, or produce unsafe decisions. Developing effective attacks and corresponding countermeasures is a prerequisite for robust, secure, and deployable artificial intelligence. Prior surveys often focused on only one or two techniques, omitted detailed discussion of datasets, metrics, and testbeds, or became outdated. This survey comprehensively reviews attacks and defenses across DNN, DRL, FL, and TL. We summarize threat models, representative attack and defense techniques, evaluation metrics, commonly used datasets, and experimental settings. A key contribution is an explicit analysis of the commonalities and differences among the four paradigms. Insights, lessons learned, and future research directions are presented to guide the development of trustworthy deep-learning systems.},
      keywords = {Adversarial attacks, defenses, deep neural networks, federated learning, transfer learning, deep reinforcement learning, robustness, privacy, trustworthy AI.},
      month = {September},
  }