A Survey on Real-Time Adversarial Attack Detection and Robustness for Real-Time Systems
Review Article  ·  Published: 09 May 2026
Issue cover
ICCK Journal of Image Analysis and Processing
Volume 2, Issue 2, 2026: 104-120
Review Article Open Access

A Survey on Real-Time Adversarial Attack Detection and Robustness for Real-Time Systems

1 Department of Artificial Intelligence and Data Science, Chaitanya Bharathi Institute of Technology, Hyderabad, India
* Corresponding Author: Sharanya Peri, [email protected]
Volume 2, Issue 2

Article Information

Abstract

The use of deep neural networks in modern surveillance systems enables real-time object detection, facial recognition, and anomaly detection, but they remain vulnerable to adversarial attacks, creating critical security risks. This survey reviews detection methods tailored for real-time surveillance, categorizing domain-specific attacks including gradient-based methods (FGSM, PGD, C&W), physical patches, and temporal attacks on video data. We evaluate detection approaches across six categories: feature-based (LID, frequency analysis), reconstruction-based (autoencoders, GANs), auxiliary model-based, uncertainty-based (Bayesian Networks, MIAD), steganalysis-based, and attention-based (ViTGuard, SHAP). Timeliness was a key focus—LSTM-AD achieved detection within 0.001 seconds at approximately 90% accuracy, while NutNet increased inference time by only 8% for patch detection. Key limitations include poor detection of novel attacks, computational burden on edge devices, and the accuracy–clean detection trade-off. Underexplored areas include video streaming attacks (relative to still images), weak integration with alerting systems, and vulnerability to adaptive attacks. Future work should focus on unified threat detection, online learning for evolving threats, and certified robustness for operational deployment.

Graphical Abstract

A Survey on Real-Time Adversarial Attack Detection and Robustness for Real-Time Systems

Keywords

adversarial attacks deep learning security surveillance systems real-time detection object detection video anomaly detection adversarial defence

Data Availability Statement

Not applicable.

Funding

This work was supported without any funding.

Conflicts of Interest

The authors declare no conflicts of interest.

AI Use Statement

The authors declare that no generative AI was used in the preparation of this manuscript.

Ethical Approval and Consent to Participate

Not applicable.

References

  1. Akhtar, N., Mian, A., Kardan, N., & Shah, M. (2021). Advances in adversarial attacks and defenses in computer vision: A survey. IEEE access, 9, 155161-155196.
    [CrossRef] [Google Scholar]
  2. Mumcu, F., Doshi, K., & Yilmaz, Y. (2022). Adversarial machine learning attacks against video anomaly detection systems. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (pp. 206-213).
    [CrossRef] [Google Scholar]
  3. Deng, Y., Zhang, T., Lou, G., Zheng, X., Jin, J., & Han, Q. L. (2021). Deep learning-based autonomous driving systems: A survey of attacks and defenses. IEEE Transactions on Industrial Informatics, 17(12), 7897-7912.
    [CrossRef] [Google Scholar]
  4. Hickling, T., Aouf, N., & Spencer, P. (2023). Robust adversarial attacks detection based on explainable deep reinforcement learning for UAV guidance and planning. IEEE Transactions on Intelligent Vehicles, 8(10), 4381-4394.
    [CrossRef] [Google Scholar]
  5. Malik, J., Muthalagu, R., & Pawar, P. M. (2024). A systematic review of adversarial machine learning attacks, defensive controls, and technologies. IEEE Access, 12, 99382-99421.
    [CrossRef] [Google Scholar]
  6. Singh, T., Rai, P., Sood, S., Nigam, S., & Kumari, S. (2023, August). Adversarial Attacks and Defences of Various Artificial Intelligent Models. In 2023 Second International Conference On Smart Technologies For Smart Nation (SmartTechCon) (pp. 210-215). IEEE.
    [CrossRef] [Google Scholar]
  7. Yin, Z., Zhu, S., Su, H., Peng, J., Lyu, W., & Luo, B. (2025). Adversarial examples detection with enhanced image difference features based on local histogram equalization. IEEE Transactions on Dependable and Secure Computing.
    [CrossRef] [Google Scholar]
  8. Zhang, C., Yu, S., Tian, Z., & Yu, J. J. (2023). Generative adversarial networks: A survey on attack and defense perspective. ACM Computing Surveys, 56(4), 1-35.
    [CrossRef] [Google Scholar]
  9. Feng, W., Xu, N., Zhang, T., Wu, B., & Zhang, Y. (2023). Robust and generalized physical adversarial attacks via meta-GAN. IEEE Transactions on Information Forensics and Security, 19, 1112-1125.
    [CrossRef] [Google Scholar]
  10. Lee, M., & Kolter, Z. (2019). On physical adversarial patches for object detection. arXiv preprint arXiv:1906.11897.
    [CrossRef] [Google Scholar]
  11. Liu, X., Yang, H., Liu, Z., Song, L., Li, H., & Chen, Y. (2018). Dpatch: An adversarial patch attack on object detectors. arXiv preprint arXiv:1806.02299.
    [CrossRef] [Google Scholar]
  12. Lin, Z., Zhao, Y., Chen, K., & He, J. (2024, December). I don't know you, but I can catch you: Real-time defense against diverse adversarial patches for object detectors. In Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security (pp. 3823-3837).
    [CrossRef] [Google Scholar]
  13. Li, Y., Ruan, S., Qin, H., Deng, S., & El-Yacoubi, M. A. (2023). Transformer based defense GAN against palm-vein adversarial attacks. IEEE Transactions on Information Forensics and Security, 18, 1509-1523.
    [CrossRef] [Google Scholar]
  14. Al-Andoli, M. N., Tan, S. C., Sim, K. S., Goh, P. Y., & Lim, C. P. (2024). A framework for robust deep learning models against adversarial attacks based on a protection layer approach. IEEE Access, 12, 17522-17540.
    [CrossRef] [Google Scholar]
  15. Wang, S., Nepal, S., Rudolph, C., Grobler, M., Chen, S., Chen, T., & An, Z. (2021). Defending adversarial attacks via semantic feature manipulation. IEEE Transactions on Services Computing, 15(6), 3184-3197.
    [CrossRef] [Google Scholar]
  16. Li, C., Wang, H., Zhang, J., Yao, W., & Jiang, T. (2022). An approximated gradient sign method using differential evolution for black-box adversarial attack. IEEE Transactions on Evolutionary Computation, 26(5), 976-990.
    [CrossRef] [Google Scholar]
  17. Pavlitskaya, S., Hendl, J., Kleim, S., Müller, L. J., Wylczoch, F., & Zöllner, J. M. (2022, November). Suppress with a patch: Revisiting universal adversarial patch attacks against object detection. In 2022 International Conference on Electrical, Computer, Communications and Mechatronics Engineering (ICECCME) (pp. 1-6). IEEE.
    [CrossRef] [Google Scholar]
  18. He, S., Wei, J., Zhang, C., Xu, X., Song, J., Yang, Y., & Shen, H. T. (2024). Boosting adversarial training with hardness-guided attack strategy. IEEE Transactions on Multimedia, 26, 7748-7760.
    [CrossRef] [Google Scholar]
  19. Dhanaraj, R. S., & Sridevi, M. (2024). Building a robust and efficient defensive system using hybrid adversarial attack. IEEE Transactions on Artificial Intelligence, 5(9), 4470-4478.
    [CrossRef] [Google Scholar]
  20. Kuang, H., Liu, H., Lin, X., & Ji, R. (2024). Defense against adversarial attacks using topology aligning adversarial training. IEEE Transactions on Information Forensics and Security, 19, 3659-3673.
    [CrossRef] [Google Scholar]
  21. Liao, W., Liu, Z., Shen, M., Chen, R., & Liu, X. (2024). Apr-net: Defense against adversarial examples based on universal adversarial perturbation removal network. IEEE Transactions on Artificial Intelligence, 6(4), 945-954.
    [CrossRef] [Google Scholar]
  22. Lee, H. J., & Ro, Y. M. (2023). Defending video recognition model against adversarial perturbations via defense patterns. IEEE Transactions on Dependable and Secure Computing, 21(4), 4110-4121.
    [CrossRef] [Google Scholar]
  23. Metzen, J. H., Genewein, T., Fischer, V., & Bischoff, B. (2017). On detecting adversarial perturbations. arXiv preprint arXiv:1702.04267.
    [CrossRef] [Google Scholar]
  24. Xu, W., Evans, D., & Qi, Y. (2017). Feature squeezing: Detecting adversarial examples in deep neural networks. arXiv preprint arXiv:1704.01155.
    [CrossRef] [Google Scholar]
  25. Ma, X., Li, B., Wang, Y., Erfani, S. M., Wijewickrema, S., Schoenebeck, G., ... & Bailey, J. (2018). Characterizing adversarial subspaces using local intrinsic dimensionality. arXiv preprint arXiv:1801.02613.
    [CrossRef] [Google Scholar]
  26. Feinman, R., Curtin, R. R., Shintre, S., & Gardner, A. B. (2017). Detecting adversarial samples from artifacts. arXiv preprint arXiv:1703.00410.
    [CrossRef] [Google Scholar]
  27. Gao, S., Wang, R., Wang, X., Yu, S., Dong, Y., Yao, S., & Zhou, W. (2023). Detecting adversarial examples on deep neural networks with mutual information neural estimation. IEEE Transactions on Dependable and Secure Computing, 20(6), 5168-5181.
    [CrossRef] [Google Scholar]
  28. Zhu, B., Dong, C., Zhang, Y., Mao, Y., & Zhong, S. (2023). Toward universal detection of adversarial examples via pseudorandom classifiers. IEEE Transactions on Information Forensics and Security, 19, 1810-1825.
    [CrossRef] [Google Scholar]
  29. Li, Y., Tang, T., Hsieh, C. J., & Lee, T. C. (2024). Adversarial examples detection with Bayesian neural network. IEEE Transactions on Emerging Topics in Computational Intelligence, 8(5), 3654-3664.
    [CrossRef] [Google Scholar]
  30. Bortolussi, L., Carbone, G., Laurenti, L., Patane, A., Sanguinetti, G., & Wicker, M. (2024). On the robustness of bayesian neural networks to adversarial attacks. IEEE Transactions on Neural Networks and Learning Systems, 36(4), 6679-6692.
    [CrossRef] [Google Scholar]
  31. Qin, C., Chen, Y., Chen, K., Dong, X., Zhang, W., Mao, X., ... & Yu, N. (2022). Feature fusion based adversarial example detection against second-round adversarial attacks. IEEE Transactions on Artificial Intelligence, 4(5), 1029-1040.
    [CrossRef] [Google Scholar]
  32. Liu, J., Zhang, W., Zhang, Y., Hou, D., Liu, Y., Zha, H., & Yu, N. (2019). Detection based defense against adversarial examples from the steganalysis point of view. In Proceedings of the IEEE/CVF conference on computer vision and pattern recognition (pp. 4825-4834).
    [CrossRef] [Google Scholar]
  33. Sun, S., Nwodo, K., Sugrim, S., Stavrou, A., & Wang, H. (2024, December). Vitguard: Attention-aware detection against adversarial examples for vision transformer. In 2024 Annual Computer Security Applications Conference (ACSAC) (pp. 1259-1275). IEEE.
    [CrossRef] [Google Scholar]
  34. Zhang, A. X., Wang, Y. G., Ran, Y., Tang, W., Guan, Q., & Yang, C. (2025). Secure video quality assessment resisting adversarial attacks. IEEE Transactions on Broadcasting.
    [CrossRef] [Google Scholar]
  35. Cohen, J., Rosenfeld, E., & Kolter, Z. (2019, May). Certified adversarial robustness via randomized smoothing. In international conference on machine learning (pp. 1310-1320). PMLR.
    [Google Scholar]
  36. Chen, P. Y., Zhang, H., Sharma, Y., Yi, J., & Hsieh, C. J. (2017, November). Zoo: Zeroth order optimization based black-box attacks to deep neural networks without training substitute models. In Proceedings of the 10th ACM workshop on artificial intelligence and security (pp. 15-26).
    [CrossRef] [Google Scholar]
  37. Li, C., Li, H., & Zhang, G. (2025). Detecting Adversarial Attacks Based on Tracking Differences in Frequency Bands. IEEE Transactions on Multimedia, 27, 4597-4612.
    [CrossRef] [Google Scholar]
  38. Goodfellow, I. J., Shlens, J., & Szegedy, C. (2014). Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572.
    [CrossRef] [Google Scholar]
  39. Graese, A., Rozsa, A., & Boult, T. E. (2016, December). Assessing threat of adversarial examples on deep neural networks. In 2016 15th IEEE International Conference on Machine Learning and Applications (ICMLA) (pp. 69-74). IEEE.
    [CrossRef] [Google Scholar]
  40. Hendrycks, D., & Gimpel, K. (2016). A baseline for detecting misclassified and out-of-distribution examples in neural networks. arXiv preprint arXiv:1610.02136.
    [CrossRef] [Google Scholar]
  41. Aldahdooh, A., Hamidouche, W., Fezza, S. A., & Déforges, O. (2022). Adversarial example detection for DNN models: A review and experimental comparison. Artificial Intelligence Review, 55(6), 4403-4462.
    [CrossRef] [Google Scholar]

Cite This Article

APA Style
Peri, S., Vadla, N., Panuganti, Y., & Ramana, K. (2026). A Survey on Real-Time Adversarial Attack Detection and Robustness for Real-Time Systems. ICCK Journal of Image Analysis and Processing, 2(2), 104-120. https://doi.org/10.62762/JIAP.2026.481078
Export Citation
RIS Format
Compatible with EndNote, Zotero, Mendeley, and other reference managers
TY  - JOUR
AU  - Peri, Sharanya
AU  - Vadla, Navya
AU  - Panuganti, Yeshwanth
AU  - Ramana, Kadiyala
PY  - 2026
DA  - 2026/05/09
TI  - A Survey on Real-Time Adversarial Attack Detection and Robustness for Real-Time Systems
JO  - ICCK Journal of Image Analysis and Processing
T2  - ICCK Journal of Image Analysis and Processing
JF  - ICCK Journal of Image Analysis and Processing
VL  - 2
IS  - 2
SP  - 104
EP  - 120
DO  - 10.62762/JIAP.2026.481078
UR  - https://www.icck.org/article/abs/JIAP.2026.481078
KW  - adversarial attacks
KW  - deep learning security
KW  - surveillance systems
KW  - real-time detection
KW  - object detection
KW  - video anomaly detection
KW  - adversarial defence
AB  - The use of deep neural networks in modern surveillance systems enables real-time object detection, facial recognition, and anomaly detection, but they remain vulnerable to adversarial attacks, creating critical security risks. This survey reviews detection methods tailored for real-time surveillance, categorizing domain-specific attacks including gradient-based methods (FGSM, PGD, C&W), physical patches, and temporal attacks on video data. We evaluate detection approaches across six categories: feature-based (LID, frequency analysis), reconstruction-based (autoencoders, GANs), auxiliary model-based, uncertainty-based (Bayesian Networks, MIAD), steganalysis-based, and attention-based (ViTGuard, SHAP). Timeliness was a key focus—LSTM-AD achieved detection within 0.001 seconds at approximately 90% accuracy, while NutNet increased inference time by only 8% for patch detection. Key limitations include poor detection of novel attacks, computational burden on edge devices, and the accuracy–clean detection trade-off. Underexplored areas include video streaming attacks (relative to still images), weak integration with alerting systems, and vulnerability to adaptive attacks. Future work should focus on unified threat detection, online learning for evolving threats, and certified robustness for operational deployment.
SN  - 3068-6679
PB  - Institute of Central Computation and Knowledge
LA  - English
ER  - 
BibTeX Format
Compatible with LaTeX, BibTeX, and other reference managers
@article{Peri2026A,
  author = {Sharanya Peri and Navya Vadla and Yeshwanth Panuganti and Kadiyala Ramana},
  title = {A Survey on Real-Time Adversarial Attack Detection and Robustness for Real-Time Systems},
  journal = {ICCK Journal of Image Analysis and Processing},
  year = {2026},
  volume = {2},
  number = {2},
  pages = {104-120},
  doi = {10.62762/JIAP.2026.481078},
  url = {https://www.icck.org/article/abs/JIAP.2026.481078},
  abstract = {The use of deep neural networks in modern surveillance systems enables real-time object detection, facial recognition, and anomaly detection, but they remain vulnerable to adversarial attacks, creating critical security risks. This survey reviews detection methods tailored for real-time surveillance, categorizing domain-specific attacks including gradient-based methods (FGSM, PGD, C\&W), physical patches, and temporal attacks on video data. We evaluate detection approaches across six categories: feature-based (LID, frequency analysis), reconstruction-based (autoencoders, GANs), auxiliary model-based, uncertainty-based (Bayesian Networks, MIAD), steganalysis-based, and attention-based (ViTGuard, SHAP). Timeliness was a key focus—LSTM-AD achieved detection within 0.001 seconds at approximately 90\% accuracy, while NutNet increased inference time by only 8\% for patch detection. Key limitations include poor detection of novel attacks, computational burden on edge devices, and the accuracy–clean detection trade-off. Underexplored areas include video streaming attacks (relative to still images), weak integration with alerting systems, and vulnerability to adaptive attacks. Future work should focus on unified threat detection, online learning for evolving threats, and certified robustness for operational deployment.},
  keywords = {adversarial attacks, deep learning security, surveillance systems, real-time detection, object detection, video anomaly detection, adversarial defence},
  issn = {3068-6679},
  publisher = {Institute of Central Computation and Knowledge}
}

Article Metrics

Citations
Crossref
0
Scopus
0
Views
1261
PDF Downloads
340

Publisher's Note

ICCK stays neutral with regard to jurisdictional claims in published maps and institutional affiliations.

Rights and Permissions

CC BY Copyright © 2026 by the Author(s). Published by Institute of Central Computation and Knowledge. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (https://creativecommons.org/licenses/by/4.0/), which permits use, sharing, adaptation, distribution and reproduction in any medium or format, as long as you give appropriate credit to the original author(s) and the source, provide a link to the Creative Commons licence, and indicate if changes were made.
ICCK Journal of Image Analysis and Processing
ICCK Journal of Image Analysis and Processing
ISSN: 3068-6679 (Online)
Portico
Preserved at
Portico