{"id":"https://openalex.org/W4390187158","doi":"https://doi.org/10.1109/access.2023.3347498","title":"Knowing is Half the Battle: Enhancing Clean Data Accuracy of Adversarial Robust Deep Neural Networks via Dual-Model Bounded Divergence Gating","display_name":"Knowing is Half the Battle: Enhancing Clean Data Accuracy of Adversarial Robust Deep Neural Networks via Dual-Model Bounded Divergence Gating","publication_year":2023,"publication_date":"2023-12-25","ids":{"openalex":"https://openalex.org/W4390187158","doi":"https://doi.org/10.1109/access.2023.3347498"},"language":"en","primary_location":{"id":"doi:10.1109/access.2023.3347498","is_oa":true,"landing_page_url":"http://dx.doi.org/10.1109/access.2023.3347498","pdf_url":"https://ieeexplore.ieee.org/ielx7/6287639/6514899/10374121.pdf","source":{"id":"https://openalex.org/S2485537415","display_name":"IEEE Access","issn_l":"2169-3536","issn":["2169-3536"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Access","raw_type":"journal-article"},"type":"article","indexed_in":["crossref","doaj"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://ieeexplore.ieee.org/ielx7/6287639/6514899/10374121.pdf","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5076661689","display_name":"Hossein Aboutalebi","orcid":"https://orcid.org/0000-0003-4396-3993"},"institutions":[{"id":"https://openalex.org/I151746483","display_name":"University of Waterloo","ror":"https://ror.org/01aff2v68","country_code":"CA","type":"education","lineage":["https://openalex.org/I151746483"]}],"countries":["CA"],"is_corresponding":false,"raw_author_name":"Hossein Aboutalebi","raw_affiliation_strings":["Department of Computer Science, University of Waterloo, Waterloo, Canada","Waterloo Artificial Intelligence Institute, Waterloo, Ontario, Canada"],"raw_orcid":"https://orcid.org/0000-0003-4396-3993","affiliations":[{"raw_affiliation_string":"Department of Computer Science, University of Waterloo, Waterloo, Canada","institution_ids":["https://openalex.org/I151746483"]},{"raw_affiliation_string":"Waterloo Artificial Intelligence Institute, Waterloo, Ontario, Canada","institution_ids":[]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5040284711","display_name":"Mohammad Javad Shafiee","orcid":"https://orcid.org/0000-0001-5989-8255"},"institutions":[{"id":"https://openalex.org/I151746483","display_name":"University of Waterloo","ror":"https://ror.org/01aff2v68","country_code":"CA","type":"education","lineage":["https://openalex.org/I151746483"]}],"countries":["CA"],"is_corresponding":false,"raw_author_name":"Mohammad Javad Shafiee","raw_affiliation_strings":["Department of Systems Design, University of Waterloo, Waterloo, Canada","DarwinAI, Waterloo, Ontario, Canada"],"raw_orcid":"https://orcid.org/0000-0001-5989-8255","affiliations":[{"raw_affiliation_string":"Department of Systems Design, University of Waterloo, Waterloo, Canada","institution_ids":["https://openalex.org/I151746483"]},{"raw_affiliation_string":"DarwinAI, Waterloo, Ontario, Canada","institution_ids":[]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5031028530","display_name":"Chi-en Amy Tai","orcid":"https://orcid.org/0000-0001-7023-8784"},"institutions":[{"id":"https://openalex.org/I151746483","display_name":"University of Waterloo","ror":"https://ror.org/01aff2v68","country_code":"CA","type":"education","lineage":["https://openalex.org/I151746483"]}],"countries":["CA"],"is_corresponding":false,"raw_author_name":"Chi-En Amy Tai","raw_affiliation_strings":["Department of Systems Design, University of Waterloo, Waterloo, Canada"],"raw_orcid":"https://orcid.org/0000-0001-7023-8784","affiliations":[{"raw_affiliation_string":"Department of Systems Design, University of Waterloo, Waterloo, Canada","institution_ids":["https://openalex.org/I151746483"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5102920751","display_name":"Alexander Wong","orcid":"https://orcid.org/0000-0001-5729-5899"},"institutions":[{"id":"https://openalex.org/I151746483","display_name":"University of Waterloo","ror":"https://ror.org/01aff2v68","country_code":"CA","type":"education","lineage":["https://openalex.org/I151746483"]}],"countries":["CA"],"is_corresponding":false,"raw_author_name":"Alexander Wong","raw_affiliation_strings":["Department of Systems Design, University of Waterloo, Waterloo, Canada","Waterloo Artificial Intelligence Institute, Waterloo, Ontario, Canada","DarwinAI, Waterloo, Ontario, Canada"],"raw_orcid":"https://orcid.org/0000-0001-5729-5899","affiliations":[{"raw_affiliation_string":"Department of Systems Design, University of Waterloo, Waterloo, Canada","institution_ids":["https://openalex.org/I151746483"]},{"raw_affiliation_string":"Waterloo Artificial Intelligence Institute, Waterloo, Ontario, Canada","institution_ids":[]},{"raw_affiliation_string":"DarwinAI, Waterloo, Ontario, Canada","institution_ids":[]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":{"value":1850,"currency":"USD","value_usd":1850},"apc_paid":{"value":1850,"currency":"USD","value_usd":1850},"fwci":0.1632,"has_fulltext":true,"cited_by_count":1,"citation_normalized_percentile":{"value":0.58949461,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":91,"max":95},"biblio":{"volume":"12","issue":null,"first_page":"48174","last_page":"48188"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10036","display_name":"Advanced Neural Network Applications","score":0.9947999715805054,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11307","display_name":"Domain Adaptation and Few-Shot Learning","score":0.9916999936103821,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/bounded-function","display_name":"Bounded function","score":0.6763612627983093},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.6472869515419006},{"id":"https://openalex.org/keywords/divergence","display_name":"Divergence (linguistics)","score":0.519513726234436},{"id":"https://openalex.org/keywords/dual","display_name":"Dual (grammatical number)","score":0.5124135613441467},{"id":"https://openalex.org/keywords/deep-neural-networks","display_name":"Deep neural networks","score":0.488486647605896},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.48024633526802063},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.4784122407436371},{"id":"https://openalex.org/keywords/gating","display_name":"Gating","score":0.4777902066707611},{"id":"https://openalex.org/keywords/deep-learning","display_name":"Deep learning","score":0.4196022152900696},{"id":"https://openalex.org/keywords/pattern-recognition","display_name":"Pattern recognition (psychology)","score":0.32965004444122314},{"id":"https://openalex.org/keywords/mathematics","display_name":"Mathematics","score":0.2006518840789795}],"concepts":[{"id":"https://openalex.org/C34388435","wikidata":"https://www.wikidata.org/wiki/Q2267362","display_name":"Bounded function","level":2,"score":0.6763612627983093},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6472869515419006},{"id":"https://openalex.org/C207390915","wikidata":"https://www.wikidata.org/wiki/Q1230525","display_name":"Divergence (linguistics)","level":2,"score":0.519513726234436},{"id":"https://openalex.org/C2780980858","wikidata":"https://www.wikidata.org/wiki/Q110022","display_name":"Dual (grammatical number)","level":2,"score":0.5124135613441467},{"id":"https://openalex.org/C2984842247","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep neural networks","level":3,"score":0.488486647605896},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.48024633526802063},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.4784122407436371},{"id":"https://openalex.org/C194544171","wikidata":"https://www.wikidata.org/wiki/Q21105679","display_name":"Gating","level":2,"score":0.4777902066707611},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.4196022152900696},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.32965004444122314},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.2006518840789795},{"id":"https://openalex.org/C134306372","wikidata":"https://www.wikidata.org/wiki/Q7754","display_name":"Mathematical analysis","level":1,"score":0.0},{"id":"https://openalex.org/C86803240","wikidata":"https://www.wikidata.org/wiki/Q420","display_name":"Biology","level":0,"score":0.0},{"id":"https://openalex.org/C42407357","wikidata":"https://www.wikidata.org/wiki/Q521","display_name":"Physiology","level":1,"score":0.0},{"id":"https://openalex.org/C124952713","wikidata":"https://www.wikidata.org/wiki/Q8242","display_name":"Literature","level":1,"score":0.0},{"id":"https://openalex.org/C41895202","wikidata":"https://www.wikidata.org/wiki/Q8162","display_name":"Linguistics","level":1,"score":0.0},{"id":"https://openalex.org/C142362112","wikidata":"https://www.wikidata.org/wiki/Q735","display_name":"Art","level":0,"score":0.0},{"id":"https://openalex.org/C138885662","wikidata":"https://www.wikidata.org/wiki/Q5891","display_name":"Philosophy","level":0,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1109/access.2023.3347498","is_oa":true,"landing_page_url":"http://dx.doi.org/10.1109/access.2023.3347498","pdf_url":"https://ieeexplore.ieee.org/ielx7/6287639/6514899/10374121.pdf","source":{"id":"https://openalex.org/S2485537415","display_name":"IEEE Access","issn_l":"2169-3536","issn":["2169-3536"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Access","raw_type":"journal-article"},{"id":"pmh:oai:doaj.org/article:59ee3f5f7ed0422ebfc3469f93fc4322","is_oa":true,"landing_page_url":"https://doaj.org/article/59ee3f5f7ed0422ebfc3469f93fc4322","pdf_url":null,"source":{"id":"https://openalex.org/S4306401280","display_name":"DOAJ (DOAJ: Directory of Open Access Journals)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by-sa","license_id":"https://openalex.org/licenses/cc-by-sa","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"IEEE Access, Vol 12, Pp 48174-48188 (2024)","raw_type":"article"}],"best_oa_location":{"id":"doi:10.1109/access.2023.3347498","is_oa":true,"landing_page_url":"http://dx.doi.org/10.1109/access.2023.3347498","pdf_url":"https://ieeexplore.ieee.org/ielx7/6287639/6514899/10374121.pdf","source":{"id":"https://openalex.org/S2485537415","display_name":"IEEE Access","issn_l":"2169-3536","issn":["2169-3536"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Access","raw_type":"journal-article"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":true,"pdf":true},"content_urls":{"pdf":"https://content.openalex.org/works/W4390187158.pdf","grobid_xml":"https://content.openalex.org/works/W4390187158.grobid-xml"},"referenced_works_count":70,"referenced_works":["https://openalex.org/W1673923490","https://openalex.org/W1932198206","https://openalex.org/W1945616565","https://openalex.org/W2015861736","https://openalex.org/W2076118331","https://openalex.org/W2108598243","https://openalex.org/W2117539524","https://openalex.org/W2183341477","https://openalex.org/W2194775991","https://openalex.org/W2230740169","https://openalex.org/W2243397390","https://openalex.org/W2302255633","https://openalex.org/W2525778437","https://openalex.org/W2557044351","https://openalex.org/W2607075141","https://openalex.org/W2804877093","https://openalex.org/W2804935296","https://openalex.org/W2886281300","https://openalex.org/W2895033754","https://openalex.org/W2913266441","https://openalex.org/W2963037989","https://openalex.org/W2963389226","https://openalex.org/W2963857521","https://openalex.org/W2964082701","https://openalex.org/W2964137095","https://openalex.org/W2964197269","https://openalex.org/W2979450790","https://openalex.org/W2989963344","https://openalex.org/W2996564870","https://openalex.org/W3008906732","https://openalex.org/W3013520104","https://openalex.org/W3035743198","https://openalex.org/W3096831136","https://openalex.org/W3107235539","https://openalex.org/W3118565077","https://openalex.org/W3118608800","https://openalex.org/W3134621603","https://openalex.org/W3206767190","https://openalex.org/W4280605483","https://openalex.org/W4287205860","https://openalex.org/W4287637349","https://openalex.org/W4293846201","https://openalex.org/W4385245566","https://openalex.org/W4387195417","https://openalex.org/W6637162671","https://openalex.org/W6640425456","https://openalex.org/W6684191040","https://openalex.org/W6689238212","https://openalex.org/W6727690538","https://openalex.org/W6729756640","https://openalex.org/W6739868092","https://openalex.org/W6748204703","https://openalex.org/W6748475379","https://openalex.org/W6752358724","https://openalex.org/W6754762128","https://openalex.org/W6759129252","https://openalex.org/W6765597837","https://openalex.org/W6770843327","https://openalex.org/W6771809012","https://openalex.org/W6774375107","https://openalex.org/W6774469542","https://openalex.org/W6780176858","https://openalex.org/W6784347383","https://openalex.org/W6784426856","https://openalex.org/W6784493056","https://openalex.org/W6787972765","https://openalex.org/W6791106756","https://openalex.org/W6802302390","https://openalex.org/W6803163449","https://openalex.org/W6838695150"],"related_works":["https://openalex.org/W2031449089","https://openalex.org/W2112596406","https://openalex.org/W2125499229","https://openalex.org/W2072696177","https://openalex.org/W4387096269","https://openalex.org/W4387096026","https://openalex.org/W2410610877","https://openalex.org/W2129483036","https://openalex.org/W2368671581","https://openalex.org/W1982291480"],"abstract_inverted_index":{"Significant":[0],"advances":[1],"have":[2],"been":[3,26],"made":[4],"in":[5,8,38,48,138,145,151],"recent":[6],"years":[7],"improving":[9],"the":[10,23,115,126,133,136,146,152,165,192,210,246],"robustness":[11,40,89],"of":[12,114,148,185,248],"deep":[13,139],"neural":[14,140],"networks,":[15],"particularly":[16],"under":[17],"adversarial":[18,39,88,99,120,149,205,217,227,239,267],"machine":[19,121],"learning":[20,122],"scenarios":[21,69],"where":[22,70],"data":[24,55,71,92,214,261],"has":[25,41],"contaminated":[27],"to":[28,64,78,82,143,162,208,252],"fool":[29],"networks":[30,141],"into":[31],"making":[32,59],"undesirable":[33],"predictions.":[34],"However,":[35],"such":[36,60],"improvements":[37],"often":[42],"come":[43],"at":[44],"a":[45,84,96,109,159,172,182,256],"significant":[46],"cost":[47],"model":[49,167],"accuracy":[50,76,215,262],"when":[51],"dealing":[52],"with":[53,203],"uncontaminated":[54],"(i.e.,":[56],"clean":[57,74,91,213,260],"data),":[58],"defense":[61,100,206,228],"mechanisms":[62,207,229],"challenging":[63],"adapt":[65],"for":[66],"real-world":[67],"practical":[68],"is":[72,130,181,191],"primarily":[73],"and":[75,90,111,216,233],"needs":[77],"be":[79,201],"high.":[80],"Motivated":[81],"find":[83],"better":[85],"balance":[86,211],"between":[87,187,212],"accuracy,":[93],"we":[94],"propose":[95],"new":[97],"model-agnostic":[98],"mechanism":[101,129,161,195],"named":[102],"Dual-model":[103],"Bounded":[104],"Divergence":[105],"(DBD),":[106],"driven":[107],"by":[108],"theoretical":[110],"empirical":[112],"analysis":[113],"bias-variance":[116],"trade-off":[117],"within":[118],"an":[119],"context.":[123],"More":[124],"specifically,":[125],"proposed":[127,193],"DBD":[128,157,178,194,249],"premised":[131],"on":[132,164,171,259,266],"observation":[134],"that":[135,245],"variance":[137,175],"tends":[142],"increase":[144],"presence":[147],"perturbations":[150],"input":[153],"data.":[154],"As":[155],"such,":[156],"employs":[158],"gating":[160],"decide":[163],"final":[166],"prediction":[168],"output":[169],"based":[170],"novel":[173],"dual-model":[174],"measure":[176],"(coined":[177],"Variance),":[179],"which":[180],"bounded":[183],"version":[184],"KL-Divergence":[186],"models.":[188],"Not":[189],"only":[190],"itself":[196],"training-free,":[197],"but":[198],"it":[199],"can":[200,250],"combined":[202],"existing":[204],"boost":[209],"robustness.":[218,268],"Comprehensive":[219],"experimental":[220],"results":[221],"across":[222,237],"over":[223],"10":[224],"different":[225,238],"state-of-the-art":[226],"using":[230],"both":[231],"CIFAR-10":[232],"ImageNet":[234],"benchmark":[235],"datasets":[236],"attacks":[240],"(e.g.,":[241],"APGD,":[242],"AutoAttack)":[243],"demonstrates":[244],"integration":[247],"lead":[251],"as":[253,255],"much":[254,265],"6%":[257],"improvement":[258],"without":[263],"compromising":[264]},"counts_by_year":[{"year":2025,"cited_by_count":1}],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-10-10T00:00:00"}
