ClearVision: A Novel Mitigation System Against Unknown Adversarial Attacks for Image Recognition AI Models

CSEF · 2026 Computational Science (Senior Division)

Overview

Adversarial attacks introduce image perturbations by manipulating input data, triggering AI image recognition models to misclassify images. These malicious attacks compromise real-world operations that rely on AI including facial recognition security programs. Current defenses, including Adversarial training and Denoisers, require knowledge of the specific attack type to be most effective. Currently, no known statistical methods accurately identify unknown adversarial attacks, leaving current defense methods vulnerable to new/unknown attacks. To solve this problem, I developed ClearVision, a new defense system capable of isolating and removing both known and new attacks. First, I designed and implemented two customized AutoEncoder architectures in a teacher-student framework to create a novel “Attack Isolator" that accurately isolates the predicted attacked pixels (“attack delta”). The “attack delta” output feeds into a denoiser, creating an “Attack Remover” model that utilizes the predicated isolated attack as a guide to remove the attacked pixels and reconstruct the image back into a clean image. To preserve the clean image’s semantic features lost from reconstruction blur, I designed and implemented a final step of mixing the attacked image and reconstructed image’s pixel values together. I compared ClearVision’s image classification accuracy after attacks against current standard defense methods (adversarial training and a baseline autoencoder denoiser). After unseen/new attacks, ClearVision’s image classification accuracy outperformed both adversarial training (83% versus 54%, p=2.6×10−18) and the autoencoder denoiser (83% versus 67%, p=5.42 x 10−13). Utilization of an autoencoder teacher/student framework to isolate attack pixels before denoising allows ClearVision to adapt to new and unknown attacks by highlighting pixel level anomalies instead of training against a specific attack pattern. Moreover, the final mixing step allowed ClearVision to maintain higher accuracy against new attacks compared to previous denoisers. This validates ClearVision as one of the first, real-time, computationally efficient, deployable defense systems resilient to new/unknown adversarial attacks without requiring model retraining.

Competition history

  • CSEF 2026 Computational Science (Senior Division) · Entry S-07-41

Related projects

Closest projects by meaning, across every fair and year in the corpus.

Browse more like this

Source: California Science & Engineering Fair public projects

Save projects to your library

Sign in with Google to keep track of projects you find interesting, organized into folders. An account also raises your daily allowance for “Has this been done?”, and lets you create a key for the MCP server with a much higher limit than anonymous use. Browsing stays public.

Continue with Google