Abstract Artificial neural networks are currently applied in a wide variety of fields, and they near to achieving performance similar humans many tasks. Nevertheless, vulnerable adversarial attacks the form small intentionally designed perturbation, which could lead misclassifications, making these models unusable, especially applications where security is critical. The best defense against att...