
E. Ramya Sree, M. Ranjeeth Kumar, Deena Babu Mandru, Kiran Ramaswamy · Scientific Reports 2026 · 2026
DOI: 10.1038/s41598-026-70847-1
Scientific ReportsJournal465 h-indexCounts differ because each database indexes a different set of publications. We treat OpenAlex as the canonical count; Google Scholar is not shown (no API, and crawling it violates its ToS).
Deep neural networks (DNNs) remain vulnerable to adversarial examples, particularly to iterative white-box attacks such as Projected Gradient Descent (PGD). This study evaluates PGD adversarial training using a ResNet-18-inspired architecture adapted for single-channel 28 × 28 inputs. The architectural configuration replaces the conventional max-pooling stage with an identity mapping to preserve spatial information and retains residual connections throughout the feature extractor. The contribution is therefore an empirical robustness study rather than a new adversarial-training objective. On MNIST, the reported model attains 99.48% clean accuracy and 95.39% accuracy under a 100-step PGD attack at \(\:\epsilon=0.3\) . Additional dataset-specific experiments examine Fashion-MNIST, grayscale CIFAR-10, and grayscale SVHN; these experiments are interpreted as independent dataset-specific evaluations rather than direct label-space transfer from an MNIST-trained classifier. Across these four datasets, the same architecture and adversarial-training recipe is applied without per-dataset redesign and retains substantial robustness in each case, indicating that the configuration is portable across inputs of increasing visual complexity rather than tuned specifically to MNIST; this portability, not a new training algorithm, is the principal practical insight offered by the study. The findings support the effectiveness of the studied configuration against the reported PGD threat model, while broader conclusions require evaluation with additional attacks, controlled architectural ablations, and repeated-run statistics.
No comments yet — start the discussion below.