Aug 2026· Italian National Conference on Sensors· Vol 26, pp. 5039· 0 citations· 43 references
Medicine
TL;DR
ADS-Guard, a novel Adversarial Detection and Sanitization (ADS) framework rooted in sequence-to-sequence autoencoder purification, is proposed, providing a practical retraining-free defense that can be integrated with existing occupancy-detection systems without modifying downstream classifiers.
Abstract
Occupancy detection is fundamental to the operational intelligence of smart buildings, driving critical functions in energy management, HVAC automation, and physical security. While modern Deep Learning (DL) models have achieved high accuracy in parsing complex environmental sensor data, they remain highly vulnerable to adversarial examples, imperceptibly perturbed inputs designed to deceive neural networks. These vulnerabilities pose severe real-world risks, ranging from energy sabotage, in which systems heat empty rooms, to critical security breaches in which intruders go undetected. To address this security gap, we propose ADS-Guard, a novel Adversarial Detection and Sanitization (ADS) framework rooted in sequence-to-sequence autoencoder purification. Unlike standard denoising techniques, ADS-Guard incorporates a latent consistency regularization mechanism that encourages alignment between clean and adversarial representations in the latent feature space. We evaluated ADS-Guard using a comprehensive experimental pipeline comprising five distinct DL architectures (LSTM, GRU, 1D-CNN, MLP, and Transformer) across three diverse datasets: (1) The UCI Occupancy dataset (20,699 samples) for standard binary detection; (2) Building59 dataset (7200 samples) for three-class occupancy-level classification (Low, Medium, High); and (3) Room Occupancy dataset (10,129 samples), representing a highly imbalanced binary occupancy-detection task. We evaluate ADS-Guard against both Fast Gradient Sign Method (FGSM) and Projected Gradient Descent (PGD) attacks across diverse occupancy datasets and model architectures. We further assess the framework under adaptive white-box attacks and compare its performance with FGSM-based and PGD-based adversarial training baselines. Our results demonstrate that adversarial attacks can substantially degrade occupancy-detection performance across datasets and model architectures. ADS-Guard consistently improves robustness relative to undefended models against both FGSM and PGD attacks, recovering a substantial portion of the lost performance in binary occupancy tasks and providing meaningful gains in the more challenging multi-class setting. Furthermore, ADS-Guard remains effective under stronger adaptive threat models while providing a practical retraining-free defense that can be integrated with existing occupancy-detection systems without modifying downstream classifiers.
AdROD outperforms five baseline defenses and exhibits superior generalizability compared with the evaluated adversarial-training baselines, while maintaining real-time performance for safely stopping the vehicle at a stop sign instrumented with adversarial patches.
Yuting Wu, Dongfang Guo, Xiangzhong Luo et al.· 0 citations
This study introduces an adversarial training optimization framework that incorporates hierarchical label encoding and prompt learning, designed to enhance model robustness and generalization in threat detection.
Yi-Qing Luo, Mingshu He, Xiao-Juan Wang· Proceedings of the Thirty-Fi...· 0 citations
Adversarial patch attacks pose a tangible physical-world threat to traffic sign recognition in autonomous driving systems. Current state-of-the-art defenses based on image reconstruction require dual-model deployment and add per-frame inference latency, making them impractical for resource-constrained embedded platform...
Deep reinforcement learning (DRL) enables adaptive intrusion detection in dynamic network environments but also exposes intrusion detection systems (IDS) to adversarial threats such as universal adversarial perturbations (UAPs), which apply a single input-agnostic perturbation to degrade detection performance across tr...
Hong-Sen Zhang, Lu Zhang, Ming-Jing Xu et al.· 0 citations
TRADES-JR, a TRADES loss function guided by Jacobian regularization, is proposed, which enables LNNs to maintain robust and high-accuracy traffic sign recognition even in adversarial environments, thereby enhancing the reliability of the autonomous driving system.
YunKai Zhao, Shang Gao, Jieliang Zhao· Proceedings of the Instituti...· 0 citations
This work proposes an efficient and effective adversarial attack detection scheme leveraging the multi-task perception within a complex vision system, and develops a consistency score metric to measure the inconsistency between vision tasks.
Cong Chen, J. Monteuuis, Jonathan Petit· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.