<?xml version="1.1" encoding="utf-8"?>
<article xsi:noNamespaceSchemaLocation="http://jats.nlm.nih.gov/publishing/1.1/xsd/JATS-journalpublishing1-mathml3.xsd" dtd-version="1.1" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"><front><journal-meta><journal-id journal-id-type="publisher-id">JERA</journal-id><journal-title-group><journal-title>Journal of Electronic Research and Application</journal-title></journal-title-group><issn>2208-3502</issn><eissn>2208-3510</eissn><publisher><publisher-name>Bio-Byword Scientific Publishing Pty. Ltd.</publisher-name></publisher></journal-meta><article-meta><article-id pub-id-type="doi">10.26689/jera.v10i1.13989</article-id><article-categories><subj-group subj-group-type="heading"><subject>Article</subject></subj-group></article-categories><title>A Survey on Artificial Intelligence Systems Robustness: Adversarial Attacks and Defenses</title><url>https://artdesignp.com/journal/JERA/10/1/10.26689/jera.v10i1.13989</url><author>ZhengWei</author><pub-date pub-type="publication-year"><year>2026</year></pub-date><volume>10</volume><issue>1</issue><history><date date-type="pub"><published-time>2026-02-27</published-time></date></history><abstract>Artificial intelligence systems have achieved widespread applications across many fields such as image classification, speech recognition, and game playing. However, as their decision-making logic is primarily learned from data, their outputs are highly sensitive to data anomalies and are particularly vulnerable to adversarial perturbations. This paper conducts a comprehensive survey on the robustness of artificial intelligence systems, reviewing classical adversarial attack and defense methods, and summarizing future development trends. We hope this work can provide valuable insights for research on the robustness of artificial intelligence systems and support the development of trustworthy artificial intelligence.</abstract><keywords/></article-meta></front><body/><back><ref-list><ref id="B1" content-type="article"><label>1</label><element-citation publication-type="journal"><p>Zhao J, Zhao W, Deng B, et al., 2024, Autonomous Driving System a Comprehensive Survey. Expert Systems with Applications, 242: 122836.</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B2" content-type="article"><label>2</label><element-citation publication-type="journal"><p>Al Kuwaiti A, Nazer K, Al-Reedy A, et al., 2023, A Review of the Role of Artificial Intelligence in Healthcare. Journal of Personalized Medicine, 13(6): 951.</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B3" content-type="article"><label>3</label><element-citation publication-type="journal"><p>Pei K, Cao Y, Yang J, et al., 2017, DeepXplore: Automated Whitebox Testing of Deep Learning Systems. Proceedings of the 26th Symposium on Operating Systems Principles: 1–18.</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B4" content-type="article"><label>4</label><element-citation publication-type="journal"><p>Szegedy C, Zaremba W, Sutskever I, et al., 2013, Intriguing Properties of Neural Networks. arXiv Preprint arXiv:1312.6199.</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B5" content-type="article"><label>5</label><element-citation publication-type="journal"><p>Hamon R, Junklewitz H, Sanchez I, 2020, Robustness and Explainability of Artificial Intelligence. Publications Office of the European Union, 207(40): 1–40.</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B6" content-type="article"><label>6</label><element-citation publication-type="journal"><p>Javed H, El-Sappagh S, Abuhmed T, 2024, Robustness in Deep Learning Models for Medical Diagnostics: Security and Adversarial Challenges Towards Robust AI Applications. Artificial Intelligence Review, 58(1): 12.</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B7" content-type="article"><label>7</label><element-citation publication-type="journal"><p>Tocchetti A, Corti L, Balayn A, et al., 2025, AI Robustness: A Human-Centered Perspective on Technological Challenges and Opportunities. ACM Computing Surveys, 57(6): 1–38.</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B8" content-type="article"><label>8</label><element-citation publication-type="journal"><p>Wang Y, Sun T, Li S, et al., 2023, Adversarial Attacks and Defenses in Machine Learning-Empowered Communication Systems and Networks: A Contemporary Survey. IEEE Communications Surveys &amp; Tutorials, 25(4): 2245–2298.</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B9" content-type="article"><label>9</label><element-citation publication-type="journal"><p>Xu H, Mannor S, 2012, Robustness and Generalization. Machine Learning, 86(3): 391–423.</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B10" content-type="article"><label>10</label><element-citation publication-type="journal"><p>Xu H, Ma Y, Liu H, et al., 2020, Adversarial Attacks and Defenses in Images, Graphs and Text: A Review. International Journal of Automation and Computing, 17(2): 151–178.</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B11" content-type="article"><label>11</label><element-citation publication-type="journal"><p>Goyal S, Doddapaneni S, Khapra M, et al., 2023, A Survey of Adversarial Defenses and Robustness in NLP. ACM Computing Surveys, 55(14s): 1–39.</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B12" content-type="article"><label>12</label><element-citation publication-type="journal"><p>Zhang W, Sheng Q, Alhazmi A, et al., 2020, Adversarial Attacks on Deep-Learning Models in Natural Language Processing: A Survey. ACM Transactions on Intelligent Systems and Technology, 11(3): 1–41.</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B13" content-type="article"><label>13</label><element-citation publication-type="journal"><p>Carlini N, Wagner D, 2018, Audio Adversarial Examples: Targeted Attacks on Speech-to-Text. IEEE Security and Privacy Workshops: 1–7.</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B14" content-type="article"><label>14</label><element-citation publication-type="journal"><p>Deldjoo Y, Noia T, Merra F, 2021, A Survey on Adversarial Recommender Systems: From Attack and Defense Strategies to Generative Adversarial Networks. ACM Computing Surveys, 54(2): 1–38.</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B15" content-type="article"><label>15</label><element-citation publication-type="journal"><p>Shayegani E, Mamun M, Fu Y, et al., 2023, Survey of Vulnerabilities in Large Language Models Revealed by Adversarial Attacks. arXiv Preprint arXiv:2310.10844.</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B16" content-type="article"><label>16</label><element-citation publication-type="journal"><p>Goodfellow I, Shlens J, Szegedy C, 2014, Explaining and Harnessing Adversarial Examples. arXiv Preprint arXiv:1412.6572.</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B17" content-type="article"><label>17</label><element-citation publication-type="journal"><p>Tramèr F, Kurakin A, Papernot N, et al., 2017, Ensemble Adversarial Training: Attacks and Defenses. arXiv Preprint arXiv:1705.07204.</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B18" content-type="article"><label>18</label><element-citation publication-type="journal"><p>Kurakin A, Goodfellow I, Bengio S, 2018, Adversarial Examples in the Physical World. Artificial Intelligence Safety and Security. Chapman and Hall/CRC: 99–112.</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B19" content-type="article"><label>19</label><element-citation publication-type="journal"><p>Madry A, Makelov A, Schmidt L, et al., 2017, Towards Deep Learning Models Resistant to Adversarial Attacks. arXiv Preprint arXiv:1706.06083.</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B20" content-type="article"><label>20</label><element-citation publication-type="journal"><p>Dong Y, Liao F, Pang T, et al., 2018, Boosting Adversarial Attacks with Momentum. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition: 9185–9193.</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B21" content-type="article"><label>21</label><element-citation publication-type="journal"><p>Carlini N, Wagner D, 2017, Towards Evaluating the Robustness of Neural Networks. IEEE Symposium on Security and Privacy: 39–57.</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B22" content-type="article"><label>22</label><element-citation publication-type="journal"><p>Feng S, Feng F, Xu X, et al., 2021, Digital Watermark Perturbation for Adversarial Examples to Fool Deep Neural Networks. International Joint Conference on Neural Networks: 1–8.</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B23" content-type="article"><label>23</label><element-citation publication-type="journal"><p>Baluja S, Fischer I, 2017, Adversarial Transformation Networks: Learning to Generate Adversarial Examples. arXiv Preprint arXiv:1703.09387.</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B24" content-type="article"><label>24</label><element-citation publication-type="journal"><p>Poursaeed O, Katsman I, Gao B, et al., 2018, Generative Adversarial Perturbations. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition: 4422–4431.</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B25" content-type="article"><label>25</label><element-citation publication-type="journal"><p>Chen X, Gao X, Zhao J, et al., 2023, AdvDiffuser: Natural Adversarial Example Synthesis with Diffusion Models. IEEE/CVF International Conference on Computer Vision: 4562–4572.</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B26" content-type="article"><label>26</label><element-citation publication-type="journal"><p>Na T, Ko J, Mukhopadhyay S, 2017, Cascade Adversarial Machine Learning Regularized with a Unified Embedding. arXiv Preprint arXiv:1708.02582.</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B27" content-type="article"><label>27</label><element-citation publication-type="journal"><p>Hendrycks D, Lee K, Mazeika M, 2019, Using Pre-Training Can Improve Model Robustness and Uncertainty. International Conference on Machine Learning: 2712–2721.</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B28" content-type="article"><label>28</label><element-citation publication-type="journal"><p>Jiang Z, Chen T, Chen T, et al., 2020, Robust Pre-Training by Adversarial Contrastive Learning. Advances in Neural Information Processing Systems, 33: 16199–16210.</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B29" content-type="article"><label>29</label><element-citation publication-type="journal"><p>Wang H, Deng Y, Yoo S, et al., 2021, AGKD-BML: Defense Against Adversarial Attack by Attention-Guided Knowledge Distillation and Bi-Directional Metric Learning. IEEE/CVF International Conference on Computer Vision: 7658–7667.</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B30" content-type="article"><label>30</label><element-citation publication-type="journal"><p>Bai T, Zhao J, Wen B, 2023, Guided Adversarial Contrastive Distillation for Robust Students. IEEE Transactions on Information Forensics and Security, 19: 9643–9655.</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B31" content-type="article"><label>31</label><element-citation publication-type="journal"><p>Guo C, Rana M, Cisse M, et al., 2017, Countering Adversarial Images Using Input Transformations. arXiv Preprint arXiv:1711.00117.</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B32" content-type="article"><label>32</label><element-citation publication-type="journal"><p>Liao F, Liang M, Dong Y, et al., 2018, Defense Against Adversarial Attacks Using High-Level Representation Guided Denoiser. IEEE Conference on Computer Vision and Pattern Recognition: 1778–1787.</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B33" content-type="article"><label>33</label><element-citation publication-type="journal"><p>Bian H, Chen D, Zhang K, et al., 2021, Adversarial Defense via Self-Orthogonal Randomization Super-Network. Neurocomputing, 452: 147–158.</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B34" content-type="article"><label>34</label><element-citation publication-type="journal"><p>Alotaibi A, Rassam M, 2023, Adversarial Machine Learning Attacks Against Intrusion Detection Systems: A Survey on Strategies and Defense. Future Internet, 15(2): 62.</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B35" content-type="article"><label>35</label><element-citation publication-type="journal"><p>Aldahdooh A, Hamidouche W, Fezza S, et al., 2022, Adversarial Example Detection for DNN Models: A Review and Experimental Comparison. Artificial Intelligence Review, 55(6): 4403–4462.</p><pub-id pub-id-type="doi"/></element-citation></ref></ref-list></back></article>
