{"id":"https://openalex.org/W4206060246","doi":"https://doi.org/10.1109/access.2021.3133334","title":"You Can\u2019t Fool All the Models: Detect Adversarial Samples via Pruning Models","display_name":"You Can\u2019t Fool All the Models: Detect Adversarial Samples via Pruning Models","publication_year":2021,"publication_date":"2021-01-01","ids":{"openalex":"https://openalex.org/W4206060246","doi":"https://doi.org/10.1109/access.2021.3133334"},"language":"en","primary_location":{"id":"doi:10.1109/access.2021.3133334","is_oa":true,"landing_page_url":"https://doi.org/10.1109/access.2021.3133334","pdf_url":"https://ieeexplore.ieee.org/ielx7/6287639/6514899/09638636.pdf","source":{"id":"https://openalex.org/S2485537415","display_name":"IEEE Access","issn_l":"2169-3536","issn":["2169-3536"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Access","raw_type":"journal-article"},"type":"article","indexed_in":["crossref","doaj"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://ieeexplore.ieee.org/ielx7/6287639/6514899/09638636.pdf","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5023056561","display_name":"Renxuan Wang","orcid":"https://orcid.org/0000-0002-3595-2058"},"institutions":[{"id":"https://openalex.org/I55712492","display_name":"Zhejiang University of Technology","ror":"https://ror.org/02djqfd08","country_code":"CN","type":"education","lineage":["https://openalex.org/I55712492"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Renxuan Wang","raw_affiliation_strings":["Institute of Cyberspace Security, Zhejiang University of Technology, Hangzhou 310023, China"],"affiliations":[{"raw_affiliation_string":"Institute of Cyberspace Security, Zhejiang University of Technology, Hangzhou 310023, China","institution_ids":["https://openalex.org/I55712492"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5070235251","display_name":"Zuohui Chen","orcid":"https://orcid.org/0000-0003-1806-6676"},"institutions":[{"id":"https://openalex.org/I105126617","display_name":"Zhejiang International Studies University","ror":"https://ror.org/01vwvvq12","country_code":"CN","type":"education","lineage":["https://openalex.org/I105126617"]},{"id":"https://openalex.org/I55712492","display_name":"Zhejiang University of Technology","ror":"https://ror.org/02djqfd08","country_code":"CN","type":"education","lineage":["https://openalex.org/I55712492"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Zuohui Chen","raw_affiliation_strings":["Institute of Cyberspace Security, Zhejiang University of Technology, Hangzhou 310023, China. (e-mail: zuohuic@qq.com)","Institute of Cyberspace Security, Zhejiang University of Technology, Hangzhou 310023, China"],"affiliations":[{"raw_affiliation_string":"Institute of Cyberspace Security, Zhejiang University of Technology, Hangzhou 310023, China. (e-mail: zuohuic@qq.com)","institution_ids":["https://openalex.org/I105126617"]},{"raw_affiliation_string":"Institute of Cyberspace Security, Zhejiang University of Technology, Hangzhou 310023, China","institution_ids":["https://openalex.org/I55712492"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100389350","display_name":"Hui Dong","orcid":"https://orcid.org/0000-0002-2178-8795"},"institutions":[{"id":"https://openalex.org/I55712492","display_name":"Zhejiang University of Technology","ror":"https://ror.org/02djqfd08","country_code":"CN","type":"education","lineage":["https://openalex.org/I55712492"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Hui Dong","raw_affiliation_strings":["College of Information Engineering, Zhejiang University of Technology, Hangzhou 310023, China"],"affiliations":[{"raw_affiliation_string":"College of Information Engineering, Zhejiang University of Technology, Hangzhou 310023, China","institution_ids":["https://openalex.org/I55712492"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5016704080","display_name":"Qi Xuan","orcid":null},"institutions":[{"id":"https://openalex.org/I55712492","display_name":"Zhejiang University of Technology","ror":"https://ror.org/02djqfd08","country_code":"CN","type":"education","lineage":["https://openalex.org/I55712492"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Qi Xuan","raw_affiliation_strings":["Institute of Cyberspace Security, Zhejiang University of Technology, Hangzhou 310023, China"],"affiliations":[{"raw_affiliation_string":"Institute of Cyberspace Security, Zhejiang University of Technology, Hangzhou 310023, China","institution_ids":["https://openalex.org/I55712492"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5023056561"],"corresponding_institution_ids":["https://openalex.org/I55712492"],"apc_list":{"value":1850,"currency":"USD","value_usd":1850},"apc_paid":{"value":1850,"currency":"USD","value_usd":1850},"fwci":0.42,"has_fulltext":true,"cited_by_count":4,"citation_normalized_percentile":{"value":0.71105828,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":90,"max":96},"biblio":{"volume":"9","issue":null,"first_page":"163780","last_page":"163790"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9679999947547913,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9648000001907349,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8508328199386597},{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.8464158773422241},{"id":"https://openalex.org/keywords/pruning","display_name":"Pruning","score":0.8149545192718506},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.6737790703773499},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.593855619430542},{"id":"https://openalex.org/keywords/deep-neural-networks","display_name":"Deep neural networks","score":0.5894087553024292},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.49199530482292175},{"id":"https://openalex.org/keywords/flops","display_name":"FLOPS","score":0.47809526324272156},{"id":"https://openalex.org/keywords/deep-learning","display_name":"Deep learning","score":0.46416810154914856},{"id":"https://openalex.org/keywords/sample","display_name":"Sample (material)","score":0.46388086676597595},{"id":"https://openalex.org/keywords/pattern-recognition","display_name":"Pattern recognition (psychology)","score":0.37166208028793335}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8508328199386597},{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.8464158773422241},{"id":"https://openalex.org/C108010975","wikidata":"https://www.wikidata.org/wiki/Q500094","display_name":"Pruning","level":2,"score":0.8149545192718506},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.6737790703773499},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.593855619430542},{"id":"https://openalex.org/C2984842247","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep neural networks","level":3,"score":0.5894087553024292},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.49199530482292175},{"id":"https://openalex.org/C3826847","wikidata":"https://www.wikidata.org/wiki/Q188768","display_name":"FLOPS","level":2,"score":0.47809526324272156},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.46416810154914856},{"id":"https://openalex.org/C198531522","wikidata":"https://www.wikidata.org/wiki/Q485146","display_name":"Sample (material)","level":2,"score":0.46388086676597595},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.37166208028793335},{"id":"https://openalex.org/C43617362","wikidata":"https://www.wikidata.org/wiki/Q170050","display_name":"Chromatography","level":1,"score":0.0},{"id":"https://openalex.org/C185592680","wikidata":"https://www.wikidata.org/wiki/Q2329","display_name":"Chemistry","level":0,"score":0.0},{"id":"https://openalex.org/C173608175","wikidata":"https://www.wikidata.org/wiki/Q232661","display_name":"Parallel computing","level":1,"score":0.0},{"id":"https://openalex.org/C6557445","wikidata":"https://www.wikidata.org/wiki/Q173113","display_name":"Agronomy","level":1,"score":0.0},{"id":"https://openalex.org/C86803240","wikidata":"https://www.wikidata.org/wiki/Q420","display_name":"Biology","level":0,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1109/access.2021.3133334","is_oa":true,"landing_page_url":"https://doi.org/10.1109/access.2021.3133334","pdf_url":"https://ieeexplore.ieee.org/ielx7/6287639/6514899/09638636.pdf","source":{"id":"https://openalex.org/S2485537415","display_name":"IEEE Access","issn_l":"2169-3536","issn":["2169-3536"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Access","raw_type":"journal-article"},{"id":"pmh:oai:doaj.org/article:e75d3b9cbfeb4e41894ed37af18b1710","is_oa":true,"landing_page_url":"https://doaj.org/article/e75d3b9cbfeb4e41894ed37af18b1710","pdf_url":null,"source":{"id":"https://openalex.org/S112646816","display_name":"SHILAP Revista de lepidopterolog\u00eda","issn_l":"0300-5267","issn":["0300-5267","2340-4078"],"is_oa":true,"is_in_doaj":true,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"journal"},"license":"cc-by-sa","license_id":"https://openalex.org/licenses/cc-by-sa","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"IEEE Access, Vol 9, Pp 163780-163790 (2021)","raw_type":"article"}],"best_oa_location":{"id":"doi:10.1109/access.2021.3133334","is_oa":true,"landing_page_url":"https://doi.org/10.1109/access.2021.3133334","pdf_url":"https://ieeexplore.ieee.org/ielx7/6287639/6514899/09638636.pdf","source":{"id":"https://openalex.org/S2485537415","display_name":"IEEE Access","issn_l":"2169-3536","issn":["2169-3536"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Access","raw_type":"journal-article"},"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G1231421488","display_name":null,"funder_award_id":"under","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G2087396116","display_name":null,"funder_award_id":"China","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G3317480652","display_name":null,"funder_award_id":"Science","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G391238517","display_name":null,"funder_award_id":", and","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G4527305417","display_name":null,"funder_award_id":"61973273","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G5182208057","display_name":null,"funder_award_id":"30001","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G5848258319","display_name":null,"funder_award_id":"0 and","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G5994120800","display_name":null,"funder_award_id":"Natural","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G8366387292","display_name":null,"funder_award_id":"LR19F030001","funder_id":"https://openalex.org/F4320338464","funder_display_name":"Natural Science Foundation of Zhejiang Province"}],"funders":[{"id":"https://openalex.org/F4320309949","display_name":"Canadian Institute for Advanced Research","ror":"https://ror.org/01sdtdd95"},{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"},{"id":"https://openalex.org/F4320338464","display_name":"Natural Science Foundation of Zhejiang Province","ror":"https://ror.org/01h0zpd94"}],"has_content":{"grobid_xml":true,"pdf":true},"content_urls":{"pdf":"https://content.openalex.org/works/W4206060246.pdf","grobid_xml":"https://content.openalex.org/works/W4206060246.grobid-xml"},"referenced_works_count":75,"referenced_works":["https://openalex.org/W1945616565","https://openalex.org/W2112796928","https://openalex.org/W2180612164","https://openalex.org/W2243397390","https://openalex.org/W2335728318","https://openalex.org/W2745565856","https://openalex.org/W2799640043","https://openalex.org/W2803739109","https://openalex.org/W2805003733","https://openalex.org/W2891710009","https://openalex.org/W2896006880","https://openalex.org/W2902931196","https://openalex.org/W2910643916","https://openalex.org/W2913266441","https://openalex.org/W2947133760","https://openalex.org/W2962965870","https://openalex.org/W2963001136","https://openalex.org/W2963094099","https://openalex.org/W2963327228","https://openalex.org/W2963363373","https://openalex.org/W2963389226","https://openalex.org/W2963564844","https://openalex.org/W2963857521","https://openalex.org/W2964164993","https://openalex.org/W2984699060","https://openalex.org/W2996564870","https://openalex.org/W3004543888","https://openalex.org/W3007712033","https://openalex.org/W3009043942","https://openalex.org/W3009751875","https://openalex.org/W3010733766","https://openalex.org/W3036286896","https://openalex.org/W3037843220","https://openalex.org/W3089710669","https://openalex.org/W3091441586","https://openalex.org/W3091857398","https://openalex.org/W3095838132","https://openalex.org/W3097285774","https://openalex.org/W3112596145","https://openalex.org/W3118608800","https://openalex.org/W3127625569","https://openalex.org/W3128829362","https://openalex.org/W3160413406","https://openalex.org/W3178864044","https://openalex.org/W3181726704","https://openalex.org/W3186991201","https://openalex.org/W4292779060","https://openalex.org/W4293846201","https://openalex.org/W4302028573","https://openalex.org/W6640425456","https://openalex.org/W6703116779","https://openalex.org/W6726275242","https://openalex.org/W6729756640","https://openalex.org/W6739868092","https://openalex.org/W6745272055","https://openalex.org/W6751682243","https://openalex.org/W6751979845","https://openalex.org/W6754642193","https://openalex.org/W6755034786","https://openalex.org/W6755526309","https://openalex.org/W6758083755","https://openalex.org/W6759129252","https://openalex.org/W6771271643","https://openalex.org/W6771809012","https://openalex.org/W6773423997","https://openalex.org/W6774743274","https://openalex.org/W6774818347","https://openalex.org/W6775876232","https://openalex.org/W6778883912","https://openalex.org/W6779685411","https://openalex.org/W6779986593","https://openalex.org/W6787296399","https://openalex.org/W6787972765","https://openalex.org/W6798538731","https://openalex.org/W6798941670"],"related_works":["https://openalex.org/W2950183588","https://openalex.org/W3080754722","https://openalex.org/W4383221314","https://openalex.org/W3093978547","https://openalex.org/W3092292339","https://openalex.org/W2953536436","https://openalex.org/W3203790781","https://openalex.org/W2997056298","https://openalex.org/W2738001131","https://openalex.org/W4285785480"],"abstract_inverted_index":{"Many":[0],"adversarial":[1,17,37,61,78,114],"attack":[2],"methods":[3,124],"have":[4],"investigated":[5],"the":[6,64,73,81,95,109,113,126,162],"security":[7],"issue":[8],"of":[9,112,151,161],"deep":[10],"learning":[11],"models.":[12],"Previous":[13],"works":[14],"on":[15,42,94,119,139,175],"detecting":[16],"samples":[18],"show":[19,117],"superior":[20],"in":[21],"accuracy":[22,174],"but":[23,103],"consume":[24],"too":[25],"much":[26],"memory":[27],"and":[28,45,90,133,137,141,159,170,177],"computing":[29],"resources.":[30],"In":[31],"this":[32],"paper,":[33],"we":[34,98],"propose":[35,100],"an":[36,85],"sample":[38],"detection":[39,96,130],"method":[40,131],"based":[41,129],"pruned":[43,54,65,82,154],"models":[44,57,66,147],"evaluate":[46],"four":[47,121],"different":[48,71,122],"pruning":[49,123],"methods.":[50,183],"We":[51],"find":[52],"that":[53],"neural":[55],"network":[56],"are":[58,156],"sensitive":[59],"to":[60,68,107],"samples,":[62],"i.e.,":[63],"tend":[67],"output":[69],"labels":[70],"from":[72],"original":[74,163],"model":[75,83,88,155],"when":[76],"given":[77],"samples.":[79],"Moreover,":[80],"has":[84],"extremely":[86],"small":[87],"size":[89],"computational":[91],"cost.":[92],"Based":[93],"result,":[97],"further":[99],"a":[101],"simple":[102],"effective":[104],"defense":[105,166,182],"approach":[106,167],"identify":[108],"true":[110],"label":[111],"sample.":[115],"Experiments":[116],"that,":[118],"average,":[120],"outperform":[125],"SOTA":[127],"multi-model":[128],"(64.15%":[132],"73.70%)":[134],"by":[135],"28.65%":[136],"18.73%":[138],"CIFAR10":[140,176],"SVHN,":[142,178],"respectively,":[143],"with":[144],"significantly":[145],"fewer":[146],"used.":[148],"The":[149],"FLOPs":[150],"our":[152],"structured":[153],"only":[157],"49.41%":[158],"25.62%":[160],"model.":[164],"Our":[165],"achieves":[168],"68.60%":[169],"72.03%":[171],"average":[172],"classification":[173],"exceeding":[179],"other":[180],"advanced":[181]},"counts_by_year":[{"year":2025,"cited_by_count":1},{"year":2024,"cited_by_count":1},{"year":2023,"cited_by_count":2}],"updated_date":"2026-04-13T07:58:08.660418","created_date":"2022-01-26T00:00:00"}
