ClearVision: A Novel Mitigation System Against Unknown Adversarial Attacks for Image Recognition AI Models
CSEF · 2026 Computational Science (Senior Division)
Overview
Adversarial attacks introduce image perturbations by manipulating input data, triggering AI image recognition models to misclassify images. These malicious attacks compromise real-world operations that rely on AI including facial recognition security programs. Current defenses, including Adversarial training and Denoisers, require knowledge of the specific attack type to be most effective. Currently, no known statistical methods accurately identify unknown adversarial attacks, leaving current defense methods vulnerable to new/unknown attacks. To solve this problem, I developed ClearVision, a new defense system capable of isolating and removing both known and new attacks. First, I designed and implemented two customized AutoEncoder architectures in a teacher-student framework to create a novel “Attack Isolator" that accurately isolates the predicted attacked pixels (“attack delta”). The “attack delta” output feeds into a denoiser, creating an “Attack Remover” model that utilizes the predicated isolated attack as a guide to remove the attacked pixels and reconstruct the image back into a clean image. To preserve the clean image’s semantic features lost from reconstruction blur, I designed and implemented a final step of mixing the attacked image and reconstructed image’s pixel values together. I compared ClearVision’s image classification accuracy after attacks against current standard defense methods (adversarial training and a baseline autoencoder denoiser). After unseen/new attacks, ClearVision’s image classification accuracy outperformed both adversarial training (83% versus 54%, p=2.6×10−18) and the autoencoder denoiser (83% versus 67%, p=5.42 x 10−13). Utilization of an autoencoder teacher/student framework to isolate attack pixels before denoising allows ClearVision to adapt to new and unknown attacks by highlighting pixel level anomalies instead of training against a specific attack pattern. Moreover, the final mixing step allowed ClearVision to maintain higher accuracy against new attacks compared to previous denoisers. This validates ClearVision as one of the first, real-time, computationally efficient, deployable defense systems resilient to new/unknown adversarial attacks without requiring model retraining.
Competition history
- CSEF 2026
Related projects
ISEF · 2025
SplitSafe: A Novel Adversarial Attack Detection and Mitigation Technique for Artificial Intelligence Image Recognition Systems
CSEF · 2026
A Novel Mechanistic Framework for Identifying and Neutralizing Latent Deception Signatures in Large Language Models
ISEF · 2019
Protection of Deep Neural Networks against Adversarial Attacks with Application to Facial Recognition
ISEF · 2025
Integrity: Generalized Artificial Image Classification With Noise Domain Localization
JSHS · 2025
An Intelligent Bee Health Assessment System Using Cross-Attention-based Multimodal Neural Network for Visual and Audio Signals
CSEF · 2026
VisionSpeak: A Wearable Edge-AI System That Describes the World Through Synthesized Speech for the Visually Impaired
CSEF · 2026
Seeing Beyond the Scene: Analyzing and Mitigating Background Bias in Action Recognition
AJAS · 2024
Building a Deep Neural Network to Automate Protection Against Online Cyber Attacks
Closest projects by meaning, across every fair and year in the corpus.
Browse more like this
Source: California Science & Engineering Fair public projects