{"id":"https://openalex.org/W3015223566","doi":"https://doi.org/10.1109/icassp40776.2020.9052933","title":"Learning to Characterize Adversarial Subspaces","display_name":"Learning to Characterize Adversarial Subspaces","publication_year":2020,"publication_date":"2020-04-09","ids":{"openalex":"https://openalex.org/W3015223566","doi":"https://doi.org/10.1109/icassp40776.2020.9052933","mag":"3015223566"},"language":"en","primary_location":{"id":"doi:10.1109/icassp40776.2020.9052933","is_oa":false,"landing_page_url":"https://doi.org/10.1109/icassp40776.2020.9052933","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"ICASSP 2020 - 2020 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP)","raw_type":"proceedings-article"},"type":"preprint","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5051298007","display_name":"Xiaofeng Mao","orcid":"https://orcid.org/0000-0003-4486-556X"},"institutions":[{"id":"https://openalex.org/I45928872","display_name":"Alibaba Group (China)","ror":"https://ror.org/00k642b80","country_code":"CN","type":"company","lineage":["https://openalex.org/I45928872"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Xiaofeng Mao","raw_affiliation_strings":["Alibaba Group,China","Alibaba Group, China"],"affiliations":[{"raw_affiliation_string":"Alibaba Group,China","institution_ids":["https://openalex.org/I45928872"]},{"raw_affiliation_string":"Alibaba Group, China","institution_ids":["https://openalex.org/I45928872"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5102976060","display_name":"Yuefeng Chen","orcid":"https://orcid.org/0000-0003-0378-3103"},"institutions":[{"id":"https://openalex.org/I45928872","display_name":"Alibaba Group (China)","ror":"https://ror.org/00k642b80","country_code":"CN","type":"company","lineage":["https://openalex.org/I45928872"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yuefeng Chen","raw_affiliation_strings":["Alibaba Group,China","Alibaba Group, China"],"affiliations":[{"raw_affiliation_string":"Alibaba Group,China","institution_ids":["https://openalex.org/I45928872"]},{"raw_affiliation_string":"Alibaba Group, China","institution_ids":["https://openalex.org/I45928872"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100341177","display_name":"Yuhong Li","orcid":"https://orcid.org/0009-0009-9185-7133"},"institutions":[{"id":"https://openalex.org/I45928872","display_name":"Alibaba Group (China)","ror":"https://ror.org/00k642b80","country_code":"CN","type":"company","lineage":["https://openalex.org/I45928872"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yuhong Li","raw_affiliation_strings":["Alibaba Group,China","Alibaba Group, China"],"affiliations":[{"raw_affiliation_string":"Alibaba Group,China","institution_ids":["https://openalex.org/I45928872"]},{"raw_affiliation_string":"Alibaba Group, China","institution_ids":["https://openalex.org/I45928872"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101802340","display_name":"Yuan He","orcid":"https://orcid.org/0000-0002-6885-1341"},"institutions":[{"id":"https://openalex.org/I45928872","display_name":"Alibaba Group (China)","ror":"https://ror.org/00k642b80","country_code":"CN","type":"company","lineage":["https://openalex.org/I45928872"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yuan He","raw_affiliation_strings":["Alibaba Group,China","Alibaba Group, China"],"affiliations":[{"raw_affiliation_string":"Alibaba Group,China","institution_ids":["https://openalex.org/I45928872"]},{"raw_affiliation_string":"Alibaba Group, China","institution_ids":["https://openalex.org/I45928872"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5100337747","display_name":"Hui Xue","orcid":"https://orcid.org/0000-0002-2093-2839"},"institutions":[{"id":"https://openalex.org/I45928872","display_name":"Alibaba Group (China)","ror":"https://ror.org/00k642b80","country_code":"CN","type":"company","lineage":["https://openalex.org/I45928872"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Hui Xue","raw_affiliation_strings":["Alibaba Group,China","Alibaba Group, China"],"affiliations":[{"raw_affiliation_string":"Alibaba Group,China","institution_ids":["https://openalex.org/I45928872"]},{"raw_affiliation_string":"Alibaba Group, China","institution_ids":["https://openalex.org/I45928872"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5051298007"],"corresponding_institution_ids":["https://openalex.org/I45928872"],"apc_list":null,"apc_paid":null,"fwci":0.58743819,"has_fulltext":false,"cited_by_count":7,"citation_normalized_percentile":{"value":0.71750397,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":89,"max":100},"biblio":{"volume":null,"issue":null,"first_page":"2438","last_page":"2442"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9761000275611877,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10036","display_name":"Advanced Neural Network Applications","score":0.9182999730110168,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.8988368511199951},{"id":"https://openalex.org/keywords/linear-subspace","display_name":"Linear subspace","score":0.8070528507232666},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7437493205070496},{"id":"https://openalex.org/keywords/discriminative-model","display_name":"Discriminative model","score":0.6967234015464783},{"id":"https://openalex.org/keywords/subspace-topology","display_name":"Subspace topology","score":0.6590992212295532},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.6240024566650391},{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.5474853515625},{"id":"https://openalex.org/keywords/context","display_name":"Context (archaeology)","score":0.5262526869773865},{"id":"https://openalex.org/keywords/deep-neural-networks","display_name":"Deep neural networks","score":0.4556359350681305},{"id":"https://openalex.org/keywords/deep-learning","display_name":"Deep learning","score":0.4485059976577759},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.4353463053703308},{"id":"https://openalex.org/keywords/encoder","display_name":"Encoder","score":0.417831152677536},{"id":"https://openalex.org/keywords/pattern-recognition","display_name":"Pattern recognition (psychology)","score":0.416535884141922},{"id":"https://openalex.org/keywords/mathematics","display_name":"Mathematics","score":0.15778231620788574}],"concepts":[{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.8988368511199951},{"id":"https://openalex.org/C12362212","wikidata":"https://www.wikidata.org/wiki/Q728435","display_name":"Linear subspace","level":2,"score":0.8070528507232666},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7437493205070496},{"id":"https://openalex.org/C97931131","wikidata":"https://www.wikidata.org/wiki/Q5282087","display_name":"Discriminative model","level":2,"score":0.6967234015464783},{"id":"https://openalex.org/C32834561","wikidata":"https://www.wikidata.org/wiki/Q660730","display_name":"Subspace topology","level":2,"score":0.6590992212295532},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.6240024566650391},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.5474853515625},{"id":"https://openalex.org/C2779343474","wikidata":"https://www.wikidata.org/wiki/Q3109175","display_name":"Context (archaeology)","level":2,"score":0.5262526869773865},{"id":"https://openalex.org/C2984842247","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep neural networks","level":3,"score":0.4556359350681305},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.4485059976577759},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.4353463053703308},{"id":"https://openalex.org/C118505674","wikidata":"https://www.wikidata.org/wiki/Q42586063","display_name":"Encoder","level":2,"score":0.417831152677536},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.416535884141922},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.15778231620788574},{"id":"https://openalex.org/C86803240","wikidata":"https://www.wikidata.org/wiki/Q420","display_name":"Biology","level":0,"score":0.0},{"id":"https://openalex.org/C185592680","wikidata":"https://www.wikidata.org/wiki/Q2329","display_name":"Chemistry","level":0,"score":0.0},{"id":"https://openalex.org/C104317684","wikidata":"https://www.wikidata.org/wiki/Q7187","display_name":"Gene","level":2,"score":0.0},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.0},{"id":"https://openalex.org/C151730666","wikidata":"https://www.wikidata.org/wiki/Q7205","display_name":"Paleontology","level":1,"score":0.0},{"id":"https://openalex.org/C55493867","wikidata":"https://www.wikidata.org/wiki/Q7094","display_name":"Biochemistry","level":1,"score":0.0},{"id":"https://openalex.org/C2524010","wikidata":"https://www.wikidata.org/wiki/Q8087","display_name":"Geometry","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/icassp40776.2020.9052933","is_oa":false,"landing_page_url":"https://doi.org/10.1109/icassp40776.2020.9052933","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"ICASSP 2020 - 2020 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/10","score":0.7699999809265137,"display_name":"Reduced inequalities"}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":50,"referenced_works":["https://openalex.org/W1673923490","https://openalex.org/W1945616565","https://openalex.org/W1969967031","https://openalex.org/W2095705004","https://openalex.org/W2108598243","https://openalex.org/W2143612262","https://openalex.org/W2163605009","https://openalex.org/W2194775991","https://openalex.org/W2243397390","https://openalex.org/W2508156266","https://openalex.org/W2594867206","https://openalex.org/W2612637113","https://openalex.org/W2758659144","https://openalex.org/W2867167548","https://openalex.org/W2883780447","https://openalex.org/W2912447214","https://openalex.org/W2925309005","https://openalex.org/W2950468330","https://openalex.org/W2952388520","https://openalex.org/W2963158386","https://openalex.org/W2963207607","https://openalex.org/W2963389226","https://openalex.org/W2963403868","https://openalex.org/W2963446712","https://openalex.org/W2963467071","https://openalex.org/W2963564844","https://openalex.org/W2963857521","https://openalex.org/W2964153729","https://openalex.org/W2964175514","https://openalex.org/W2969664989","https://openalex.org/W2973512984","https://openalex.org/W3118608800","https://openalex.org/W4293584023","https://openalex.org/W4385245566","https://openalex.org/W6637162671","https://openalex.org/W6640425456","https://openalex.org/W6674330103","https://openalex.org/W6684191040","https://openalex.org/W6725508424","https://openalex.org/W6729756640","https://openalex.org/W6734483310","https://openalex.org/W6734787559","https://openalex.org/W6739901393","https://openalex.org/W6747819456","https://openalex.org/W6752760542","https://openalex.org/W6753767121","https://openalex.org/W6758648797","https://openalex.org/W6766301176","https://openalex.org/W6767341848","https://openalex.org/W6787972765"],"related_works":["https://openalex.org/W3100286349","https://openalex.org/W2896134808","https://openalex.org/W4289378085","https://openalex.org/W4294291164","https://openalex.org/W3172436493","https://openalex.org/W1887135636","https://openalex.org/W4287164812","https://openalex.org/W2386063599","https://openalex.org/W1975884855","https://openalex.org/W3213150849"],"abstract_inverted_index":{"Deep":[0],"Neural":[1],"Networks":[2],"(DNNs)":[3],"are":[4,42,55,99],"known":[5],"to":[6,9,26,65,88,101,120],"be":[7],"vulnerable":[8],"the":[10,28,51,103,107,129],"maliciously":[11],"generated":[12],"adversarial":[13,18,31,34,77,90],"examples.":[14],"To":[15,69],"detect":[16,66],"these":[17,40],"examples,":[19],"previous":[20],"methods":[21,41,155],"use":[22],"artificially":[23,52],"designed":[24],"metrics":[25,87],"characterize":[27,89],"properties":[29],"of":[30,57,106],"subspaces":[32],"where":[33],"examples":[35],"lie.":[36],"However,":[37],"we":[38,73],"find":[39],"not":[43],"working":[44],"in":[45,62],"practical":[46],"attack":[47],"detection":[48,78,164],"scenarios.":[49],"Because":[50],"defined":[53],"features":[54],"lack":[56],"robustness":[58],"and":[59,126,143,165],"show":[60],"limitation":[61],"discriminative":[63],"power":[64],"strong":[67],"attacks.":[68],"solve":[70],"this":[71],"problem,":[72],"propose":[74,111],"a":[75],"novel":[76],"method":[79],"which":[80],"identifies":[81],"adversaries":[82],"by":[83],"adaptively":[84],"learning":[85],"reasonable":[86],"subspaces.":[91],"As":[92],"auxiliary":[93],"context":[94,125],"information,":[95],"k":[96,123],"nearest":[97],"neighbors":[98,124],"used":[100],"represent":[102],"surrounded":[104],"subspace":[105],"detected":[108,130],"sample.":[109],"We":[110,136],"an":[112],"innovative":[113],"model":[114],"called":[115],"Neighbor":[116],"Context":[117],"Encoder":[118],"(NCE)":[119],"learn":[121],"from":[122],"infer":[127],"if":[128],"sample":[131],"is":[132],"normal":[133],"or":[134],"adversarial.":[135],"conduct":[137],"thorough":[138],"experiment":[139],"on":[140],"CIFAR-10,":[141],"CIFAR-100":[142],"ImageNet":[144],"dataset.":[145],"The":[146],"results":[147],"demonstrate":[148],"that":[149],"our":[150],"approach":[151],"surpasses":[152],"all":[153],"existing":[154],"under":[156],"three":[157],"settings:":[158],"attack-aware":[159],"black-box":[160,163],"detection,":[161],"attack-unaware":[162],"white-box":[166],"detection.":[167]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2024,"cited_by_count":2},{"year":2022,"cited_by_count":1},{"year":2021,"cited_by_count":3}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
