{"id":"https://openalex.org/W3144874349","doi":"https://doi.org/10.1007/978-3-030-71500-7_16","title":"Understanding Local Robustness of Deep Neural Networks under Natural Variations","display_name":"Understanding Local Robustness of Deep Neural Networks under Natural Variations","publication_year":2021,"publication_date":"2021-01-01","ids":{"openalex":"https://openalex.org/W3144874349","doi":"https://doi.org/10.1007/978-3-030-71500-7_16","mag":"3144874349"},"language":"en","primary_location":{"id":"doi:10.1007/978-3-030-71500-7_16","is_oa":true,"landing_page_url":"https://doi.org/10.1007/978-3-030-71500-7_16","pdf_url":"https://link.springer.com/content/pdf/10.1007/978-3-030-71500-7_16.pdf","source":{"id":"https://openalex.org/S106296714","display_name":"Lecture notes in computer science","issn_l":"0302-9743","issn":["0302-9743","1611-3349"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319900","host_organization_name":"Springer Science+Business Media","host_organization_lineage":["https://openalex.org/P4310319900","https://openalex.org/P4310319965"],"host_organization_lineage_names":["Springer Science+Business Media","Springer Nature"],"type":"book series"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Lecture Notes in Computer Science","raw_type":"book-chapter"},"type":"book-chapter","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"hybrid","oa_url":"https://link.springer.com/content/pdf/10.1007/978-3-030-71500-7_16.pdf","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5043537468","display_name":"Ziyuan Zhong","orcid":"https://orcid.org/0000-0001-9661-1233"},"institutions":[{"id":"https://openalex.org/I78577930","display_name":"Columbia University","ror":"https://ror.org/00hj8s172","country_code":"US","type":"education","lineage":["https://openalex.org/I78577930"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Ziyuan Zhong","raw_affiliation_strings":["Columbia University, New York, NY, USA"],"raw_orcid":"https://orcid.org/0000-0001-9661-1233","affiliations":[{"raw_affiliation_string":"Columbia University, New York, NY, USA","institution_ids":["https://openalex.org/I78577930"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101415638","display_name":"Yuchi Tian","orcid":"https://orcid.org/0000-0002-9711-1449"},"institutions":[{"id":"https://openalex.org/I78577930","display_name":"Columbia University","ror":"https://ror.org/00hj8s172","country_code":"US","type":"education","lineage":["https://openalex.org/I78577930"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Yuchi Tian","raw_affiliation_strings":["Columbia University, New York, NY, USA"],"raw_orcid":"https://orcid.org/0000-0002-9711-1449","affiliations":[{"raw_affiliation_string":"Columbia University, New York, NY, USA","institution_ids":["https://openalex.org/I78577930"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5064541855","display_name":"Baishakhi Ray","orcid":"https://orcid.org/0000-0003-3406-5235"},"institutions":[{"id":"https://openalex.org/I78577930","display_name":"Columbia University","ror":"https://ror.org/00hj8s172","country_code":"US","type":"education","lineage":["https://openalex.org/I78577930"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Baishakhi Ray","raw_affiliation_strings":["Columbia University, New York, NY, USA"],"raw_orcid":"https://orcid.org/0000-0003-3406-5235","affiliations":[{"raw_affiliation_string":"Columbia University, New York, NY, USA","institution_ids":["https://openalex.org/I78577930"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5043537468"],"corresponding_institution_ids":["https://openalex.org/I78577930"],"apc_list":{"value":5000,"currency":"EUR","value_usd":5392},"apc_paid":{"value":5000,"currency":"EUR","value_usd":5392},"fwci":5.3865,"has_fulltext":true,"cited_by_count":18,"citation_normalized_percentile":{"value":0.96588344,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":94,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"313","last_page":"337"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9872999787330627,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10036","display_name":"Advanced Neural Network Applications","score":0.9811999797821045,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.7737534046173096},{"id":"https://openalex.org/keywords/flagging","display_name":"Flagging","score":0.6503236889839172},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.6152232885360718},{"id":"https://openalex.org/keywords/deep-neural-networks","display_name":"Deep neural networks","score":0.5901306867599487},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.5047303438186646},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.43805450201034546},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.41617852449417114},{"id":"https://openalex.org/keywords/cartography","display_name":"Cartography","score":0.12427458167076111},{"id":"https://openalex.org/keywords/biology","display_name":"Biology","score":0.08100906014442444}],"concepts":[{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.7737534046173096},{"id":"https://openalex.org/C2777548347","wikidata":"https://www.wikidata.org/wiki/Q5456937","display_name":"Flagging","level":2,"score":0.6503236889839172},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6152232885360718},{"id":"https://openalex.org/C2984842247","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep neural networks","level":3,"score":0.5901306867599487},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5047303438186646},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.43805450201034546},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.41617852449417114},{"id":"https://openalex.org/C58640448","wikidata":"https://www.wikidata.org/wiki/Q42515","display_name":"Cartography","level":1,"score":0.12427458167076111},{"id":"https://openalex.org/C86803240","wikidata":"https://www.wikidata.org/wiki/Q420","display_name":"Biology","level":0,"score":0.08100906014442444},{"id":"https://openalex.org/C104317684","wikidata":"https://www.wikidata.org/wiki/Q7187","display_name":"Gene","level":2,"score":0.0},{"id":"https://openalex.org/C205649164","wikidata":"https://www.wikidata.org/wiki/Q1071","display_name":"Geography","level":0,"score":0.0},{"id":"https://openalex.org/C55493867","wikidata":"https://www.wikidata.org/wiki/Q7094","display_name":"Biochemistry","level":1,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1007/978-3-030-71500-7_16","is_oa":true,"landing_page_url":"https://doi.org/10.1007/978-3-030-71500-7_16","pdf_url":"https://link.springer.com/content/pdf/10.1007/978-3-030-71500-7_16.pdf","source":{"id":"https://openalex.org/S106296714","display_name":"Lecture notes in computer science","issn_l":"0302-9743","issn":["0302-9743","1611-3349"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319900","host_organization_name":"Springer Science+Business Media","host_organization_lineage":["https://openalex.org/P4310319900","https://openalex.org/P4310319965"],"host_organization_lineage_names":["Springer Science+Business Media","Springer Nature"],"type":"book series"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Lecture Notes in Computer Science","raw_type":"book-chapter"},{"id":"pmh:oai:pubmedcentral.nih.gov:7978809","is_oa":true,"landing_page_url":"https://www.ncbi.nlm.nih.gov/pmc/articles/7978809","pdf_url":null,"source":{"id":"https://openalex.org/S2764455111","display_name":"PubMed Central","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I1299303238","host_organization_name":"National Institutes of Health","host_organization_lineage":["https://openalex.org/I1299303238"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"Fundamental Approaches to Software Engineering","raw_type":"Text"}],"best_oa_location":{"id":"doi:10.1007/978-3-030-71500-7_16","is_oa":true,"landing_page_url":"https://doi.org/10.1007/978-3-030-71500-7_16","pdf_url":"https://link.springer.com/content/pdf/10.1007/978-3-030-71500-7_16.pdf","source":{"id":"https://openalex.org/S106296714","display_name":"Lecture notes in computer science","issn_l":"0302-9743","issn":["0302-9743","1611-3349"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319900","host_organization_name":"Springer Science+Business Media","host_organization_lineage":["https://openalex.org/P4310319900","https://openalex.org/P4310319965"],"host_organization_lineage_names":["Springer Science+Business Media","Springer Nature"],"type":"book series"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Lecture Notes in Computer Science","raw_type":"book-chapter"},"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/1","score":0.699999988079071,"display_name":"No poverty"}],"awards":[],"funders":[],"has_content":{"pdf":true,"grobid_xml":true},"content_urls":{"pdf":"https://content.openalex.org/works/W3144874349.pdf","grobid_xml":"https://content.openalex.org/works/W3144874349.grobid-xml"},"referenced_works_count":90,"referenced_works":["https://openalex.org/W569478347","https://openalex.org/W1556779599","https://openalex.org/W1883420340","https://openalex.org/W1945616565","https://openalex.org/W1972978214","https://openalex.org/W2009489720","https://openalex.org/W2087189381","https://openalex.org/W2107031757","https://openalex.org/W2163605009","https://openalex.org/W2180612164","https://openalex.org/W2187089797","https://openalex.org/W2194775991","https://openalex.org/W2257979135","https://openalex.org/W2335728318","https://openalex.org/W2342840547","https://openalex.org/W2460937040","https://openalex.org/W2543296129","https://openalex.org/W2560674852","https://openalex.org/W2592916831","https://openalex.org/W2594877703","https://openalex.org/W2616028256","https://openalex.org/W2620038827","https://openalex.org/W2750384547","https://openalex.org/W2766108848","https://openalex.org/W2773726006","https://openalex.org/W2783784437","https://openalex.org/W2785685510","https://openalex.org/W2789584252","https://openalex.org/W2801079363","https://openalex.org/W2803850896","https://openalex.org/W2804337238","https://openalex.org/W2806075129","https://openalex.org/W2890660842","https://openalex.org/W2893132739","https://openalex.org/W2897355816","https://openalex.org/W2898868990","https://openalex.org/W2912440308","https://openalex.org/W2915002466","https://openalex.org/W2922234936","https://openalex.org/W2942630857","https://openalex.org/W2945033152","https://openalex.org/W2948254043","https://openalex.org/W2948636190","https://openalex.org/W2949358371","https://openalex.org/W2950468330","https://openalex.org/W2954629067","https://openalex.org/W2954903132","https://openalex.org/W2962835968","https://openalex.org/W2963054787","https://openalex.org/W2963158386","https://openalex.org/W2963308851","https://openalex.org/W2963327228","https://openalex.org/W2963448658","https://openalex.org/W2963495494","https://openalex.org/W2963735478","https://openalex.org/W2963857521","https://openalex.org/W2963913218","https://openalex.org/W2964016190","https://openalex.org/W2964059111","https://openalex.org/W2964082701","https://openalex.org/W2964137095","https://openalex.org/W2964153729","https://openalex.org/W2964164993","https://openalex.org/W2964212410","https://openalex.org/W2964253222","https://openalex.org/W2968594320","https://openalex.org/W2968940383","https://openalex.org/W2970085549","https://openalex.org/W2970456043","https://openalex.org/W2970671007","https://openalex.org/W2971158639","https://openalex.org/W2972267366","https://openalex.org/W2995333506","https://openalex.org/W2995858837","https://openalex.org/W2999691867","https://openalex.org/W3047853208","https://openalex.org/W3089756992","https://openalex.org/W3090423701","https://openalex.org/W3090608524","https://openalex.org/W3090943961","https://openalex.org/W3090988182","https://openalex.org/W3094744677","https://openalex.org/W3099444373","https://openalex.org/W3102183821","https://openalex.org/W3105347387","https://openalex.org/W3105599650","https://openalex.org/W3118608800","https://openalex.org/W4242377092","https://openalex.org/W6600109629","https://openalex.org/W6600168703"],"related_works":["https://openalex.org/W2961085424","https://openalex.org/W4306674287","https://openalex.org/W4224009465","https://openalex.org/W4286629047","https://openalex.org/W4306321456","https://openalex.org/W4285260836","https://openalex.org/W3046775127","https://openalex.org/W3170094116","https://openalex.org/W2962182036","https://openalex.org/W4311734044"],"abstract_inverted_index":{"Abstract":[0],"Deep":[1],"Neural":[2],"Networks":[3],"(DNNs)":[4],"are":[5,95,228,241],"being":[6],"deployed":[7],"in":[8,103,230,267,285],"a":[9,85,88,191,197,264,268],"wide":[10],"range":[11],"of":[12,41,48,76,91,152,182,211,233,248,288],"settings":[13],"today,":[14],"from":[15],"safety-critical":[16],"applications":[17,23],"like":[18],"autonomous":[19],"driving":[20],"to":[21,37,113,120,129,168,189,203,243,250,263,295],"commercial":[22],"involving":[24],"image":[25,222,271],"classifications.":[26],"However,":[27],"recent":[28],"research":[29],"has":[30,50],"shown":[31],"that":[32,137,226,258,281],"DNNs":[33,49,153,184],"can":[34,100,260],"be":[35,261],"brittle":[36],"even":[38],"slight":[39],"variations":[40,126],"the":[42,64,77,92,104,122,149,156,177,183,206],"input":[43,78],"data.":[44],"Therefore,":[45],"rigorous":[46],"testing":[47],"gained":[51],"widespread":[52],"attention.":[53],"While":[54],"DNN":[55,131,216],"robustness":[56,141,151,180,290],"under":[57,142],"norm-bound":[58],"perturbation":[59],"got":[60],"significant":[61],"attention":[62],"over":[63],"past":[65],"few":[66,135],"years,":[67],"our":[68],"knowledge":[69],"is":[70,118,283],"still":[71],"limited":[72],"when":[73],"natural":[74,82,143],"variants":[75],"images":[79],"come.":[80],"These":[81],"variants,":[83,144],"e.g.,":[84],"rotated":[86],"or":[87],"rainy":[89],"version":[90],"original":[93],"input,":[94],"especially":[96],"concerning":[97],"as":[98],"they":[99,227],"occur":[101],"naturally":[102],"field":[105],"without":[106],"any":[107],"active":[108],"adversary":[109],"and":[110,185,196,239,252],"may":[111,127],"lead":[112,128],"undesirable":[114],"consequences.":[115],"Thus,":[116],"it":[117],"important":[119],"identify":[121,205],"inputs":[123],"whose":[124],"small":[125],"erroneous":[130],"behaviors.":[132],"The":[133],"very":[134],"studies":[136],"looked":[138],"at":[139],"DNN\u2019s":[140],"however,":[145],"focus":[146],"on":[147,214,275],"estimating":[148],"overall":[150],"across":[154],"all":[155],"test":[157],"data":[158],"rather":[159],"than":[160],"localizing":[161],"such":[162],"error-producing":[163],"points.":[164,208],"This":[165],"work":[166],"aims":[167],"bridge":[169],"this":[170,173],"gap.":[171],"To":[172],"end,":[174],"we":[175],"study":[176],"local":[178],"per-input":[179],"properties":[181,188],"leverage":[186],"those":[187],"build":[190],"white-box":[192],"(":[193,199],"DeepRobust-W":[194,238,259,282],")":[195,201],"black-box":[198],"DeepRobust-B":[200,240],"tool":[202],"automatically":[204],"non-robust":[207],"Our":[209,273],"evaluation":[210,274],"these":[212],"methods":[213],"three":[215,219,276],"models":[217,279],"spanning":[218],"widely":[220],"used":[221],"classification":[223],"datasets":[224],"shows":[225],"effective":[229,284],"flagging":[231],"points":[232,287],"poor":[234,289],"robustness.":[235],"In":[236],"particular,":[237],"able":[242],"achieve":[244],"an":[245],"F1":[246,292],"score":[247,293],"up":[249,294],"91.4%":[251],"99.1%,":[253],"respectively.":[254],"We":[255],"further":[256],"show":[257],"applied":[262],"regression":[265],"problem":[266],"domain":[269],"beyond":[270],"classification.":[272],"self-driving":[277],"car":[278],"demonstrates":[280],"identifying":[286],"with":[291],"78.9%.":[296]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2025,"cited_by_count":2},{"year":2024,"cited_by_count":3},{"year":2023,"cited_by_count":7},{"year":2022,"cited_by_count":2},{"year":2021,"cited_by_count":3}],"updated_date":"2026-05-21T06:26:12.895304","created_date":"2025-10-10T00:00:00"}
