{"id":"https://openalex.org/W2970740201","doi":"https://doi.org/10.1109/icip.2019.8803776","title":"Exploiting CNN Layer Activations to Improve Adversarial Image Classification","display_name":"Exploiting CNN Layer Activations to Improve Adversarial Image Classification","publication_year":2019,"publication_date":"2019-08-26","ids":{"openalex":"https://openalex.org/W2970740201","doi":"https://doi.org/10.1109/icip.2019.8803776","mag":"2970740201"},"language":"en","primary_location":{"id":"doi:10.1109/icip.2019.8803776","is_oa":false,"landing_page_url":"https://doi.org/10.1109/icip.2019.8803776","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2019 IEEE International Conference on Image Processing (ICIP)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":null,"any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5038570344","display_name":"Roberto Caldelli","orcid":"https://orcid.org/0000-0003-3471-1196"},"institutions":[{"id":"https://openalex.org/I45084792","display_name":"University of Florence","ror":"https://ror.org/04jr1s763","country_code":"IT","type":"education","lineage":["https://openalex.org/I45084792"]}],"countries":["IT"],"is_corresponding":true,"raw_author_name":"R. Caldelli","raw_affiliation_strings":["University of Florence, Florence, Italy"],"affiliations":[{"raw_affiliation_string":"University of Florence, Florence, Italy","institution_ids":["https://openalex.org/I45084792"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5069958508","display_name":"Rudy Becarelli","orcid":null},"institutions":[{"id":"https://openalex.org/I45084792","display_name":"University of Florence","ror":"https://ror.org/04jr1s763","country_code":"IT","type":"education","lineage":["https://openalex.org/I45084792"]}],"countries":["IT"],"is_corresponding":false,"raw_author_name":"R. Becarelli","raw_affiliation_strings":["University of Florence, Florence, Italy"],"affiliations":[{"raw_affiliation_string":"University of Florence, Florence, Italy","institution_ids":["https://openalex.org/I45084792"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5059447545","display_name":"Fabio Carrara","orcid":"https://orcid.org/0000-0001-5014-5089"},"institutions":[{"id":"https://openalex.org/I122991210","display_name":"Istituto di Scienza e Tecnologie dell'Informazione \"Alessandro Faedo\"","ror":"https://ror.org/05kacka20","country_code":"IT","type":"facility","lineage":["https://openalex.org/I122991210","https://openalex.org/I4210155236"]}],"countries":["IT"],"is_corresponding":false,"raw_author_name":"F. Carrara","raw_affiliation_strings":["ISTI, Pisa, Italy"],"affiliations":[{"raw_affiliation_string":"ISTI, Pisa, Italy","institution_ids":["https://openalex.org/I122991210"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5047189288","display_name":"Fabrizio Falchi","orcid":"https://orcid.org/0000-0001-6258-5313"},"institutions":[{"id":"https://openalex.org/I122991210","display_name":"Istituto di Scienza e Tecnologie dell'Informazione \"Alessandro Faedo\"","ror":"https://ror.org/05kacka20","country_code":"IT","type":"facility","lineage":["https://openalex.org/I122991210","https://openalex.org/I4210155236"]}],"countries":["IT"],"is_corresponding":false,"raw_author_name":"F. Falchi","raw_affiliation_strings":["ISTI, Pisa, Italy"],"affiliations":[{"raw_affiliation_string":"ISTI, Pisa, Italy","institution_ids":["https://openalex.org/I122991210"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5072396889","display_name":"Giuseppe Amato","orcid":"https://orcid.org/0000-0003-0171-4315"},"institutions":[{"id":"https://openalex.org/I122991210","display_name":"Istituto di Scienza e Tecnologie dell'Informazione \"Alessandro Faedo\"","ror":"https://ror.org/05kacka20","country_code":"IT","type":"facility","lineage":["https://openalex.org/I122991210","https://openalex.org/I4210155236"]}],"countries":["IT"],"is_corresponding":false,"raw_author_name":"G. Amato","raw_affiliation_strings":["ISTI, Pisa, Italy"],"affiliations":[{"raw_affiliation_string":"ISTI, Pisa, Italy","institution_ids":["https://openalex.org/I122991210"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5038570344"],"corresponding_institution_ids":["https://openalex.org/I45084792"],"apc_list":null,"apc_paid":null,"fwci":0.8659,"has_fulltext":false,"cited_by_count":6,"citation_normalized_percentile":{"value":0.81118281,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":89,"max":96},"biblio":{"volume":"9","issue":null,"first_page":"2289","last_page":"2293"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9735999703407288,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12122","display_name":"Physical Unclonable Functions (PUFs) and Hardware Security","score":0.9666000008583069,"subfield":{"id":"https://openalex.org/subfields/1708","display_name":"Hardware and Architecture"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.9226052761077881},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8250032663345337},{"id":"https://openalex.org/keywords/convolutional-neural-network","display_name":"Convolutional neural network","score":0.7114238142967224},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.6723377704620361},{"id":"https://openalex.org/keywords/contextual-image-classification","display_name":"Contextual image classification","score":0.5762075781822205},{"id":"https://openalex.org/keywords/layer","display_name":"Layer (electronics)","score":0.5700674653053284},{"id":"https://openalex.org/keywords/vulnerability","display_name":"Vulnerability (computing)","score":0.5299160480499268},{"id":"https://openalex.org/keywords/image","display_name":"Image (mathematics)","score":0.4983677864074707},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.47637173533439636},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.4294225871562958},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.24103868007659912}],"concepts":[{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.9226052761077881},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8250032663345337},{"id":"https://openalex.org/C81363708","wikidata":"https://www.wikidata.org/wiki/Q17084460","display_name":"Convolutional neural network","level":2,"score":0.7114238142967224},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.6723377704620361},{"id":"https://openalex.org/C75294576","wikidata":"https://www.wikidata.org/wiki/Q5165192","display_name":"Contextual image classification","level":3,"score":0.5762075781822205},{"id":"https://openalex.org/C2779227376","wikidata":"https://www.wikidata.org/wiki/Q6505497","display_name":"Layer (electronics)","level":2,"score":0.5700674653053284},{"id":"https://openalex.org/C95713431","wikidata":"https://www.wikidata.org/wiki/Q631425","display_name":"Vulnerability (computing)","level":2,"score":0.5299160480499268},{"id":"https://openalex.org/C115961682","wikidata":"https://www.wikidata.org/wiki/Q860623","display_name":"Image (mathematics)","level":2,"score":0.4983677864074707},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.47637173533439636},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.4294225871562958},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.24103868007659912},{"id":"https://openalex.org/C178790620","wikidata":"https://www.wikidata.org/wiki/Q11351","display_name":"Organic chemistry","level":1,"score":0.0},{"id":"https://openalex.org/C185592680","wikidata":"https://www.wikidata.org/wiki/Q2329","display_name":"Chemistry","level":0,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1109/icip.2019.8803776","is_oa":false,"landing_page_url":"https://doi.org/10.1109/icip.2019.8803776","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2019 IEEE International Conference on Image Processing (ICIP)","raw_type":"proceedings-article"},{"id":"pmh:oai:dnet:people______::f339ac802016bd85236eff6c80cb5810","is_oa":true,"landing_page_url":null,"pdf_url":null,"source":{"id":"https://openalex.org/S7407055261","display_name":"ISTI Open Portal","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"PROCEEDINGS - INTERNATIONAL CONFERENCE ON IMAGE PROCESSING, vol. 2019-September, pp. 2289-2293. Taipei, Taiwan, 22-25 September, 2019","raw_type":"Conference article"}],"best_oa_location":{"id":"pmh:oai:dnet:people______::f339ac802016bd85236eff6c80cb5810","is_oa":true,"landing_page_url":null,"pdf_url":null,"source":{"id":"https://openalex.org/S7407055261","display_name":"ISTI Open Portal","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"PROCEEDINGS - INTERNATIONAL CONFERENCE ON IMAGE PROCESSING, vol. 2019-September, pp. 2289-2293. Taipei, Taiwan, 22-25 September, 2019","raw_type":"Conference article"},"sustainable_development_goals":[{"score":0.7599999904632568,"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16"}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":36,"referenced_works":["https://openalex.org/W204268067","https://openalex.org/W1945616565","https://openalex.org/W2062118960","https://openalex.org/W2117539524","https://openalex.org/W2187089797","https://openalex.org/W2230740169","https://openalex.org/W2528914598","https://openalex.org/W2561975083","https://openalex.org/W2590523583","https://openalex.org/W2594867206","https://openalex.org/W2605631833","https://openalex.org/W2607219512","https://openalex.org/W2746559470","https://openalex.org/W2790437783","https://openalex.org/W2889322066","https://openalex.org/W2903213484","https://openalex.org/W2912447214","https://openalex.org/W2950468330","https://openalex.org/W2963207607","https://openalex.org/W2963542991","https://openalex.org/W2963564844","https://openalex.org/W2964082701","https://openalex.org/W4293584023","https://openalex.org/W4297573953","https://openalex.org/W4381325153","https://openalex.org/W6629368666","https://openalex.org/W6640425456","https://openalex.org/W6685800298","https://openalex.org/W6689238212","https://openalex.org/W6733645847","https://openalex.org/W6734483310","https://openalex.org/W6734787559","https://openalex.org/W6736207377","https://openalex.org/W6736640963","https://openalex.org/W6749105531","https://openalex.org/W6758648797"],"related_works":["https://openalex.org/W2502115930","https://openalex.org/W2482350142","https://openalex.org/W2952813363","https://openalex.org/W4360783045","https://openalex.org/W2963346891","https://openalex.org/W3176438653","https://openalex.org/W2770149305","https://openalex.org/W3167930666","https://openalex.org/W3014952856","https://openalex.org/W3010730661"],"abstract_inverted_index":{"Neural":[0],"networks":[1],"are":[2],"now":[3],"used":[4],"in":[5],"many":[6],"sectors":[7],"of":[8,33,76,104],"our":[9],"daily":[10],"life":[11],"thanks":[12],"to":[13,23,28,39,49,83,114,118,131],"efficient":[14],"solutions":[15],"such":[16,67],"instruments":[17],"provide":[18],"for":[19,62],"diverse":[20],"tasks.":[21],"Leaving":[22],"artificial":[24],"intelligence":[25],"the":[26,74,102,105],"chance":[27],"make":[29],"choices":[30],"on":[31,73],"behalf":[32],"humans":[34],"inevitably":[35],"exposes":[36],"these":[37],"tools":[38],"be":[40,129],"fraudulently":[41],"attacked.":[42],"In":[43,100],"fact,":[44],"adversarial":[45,98,133],"examples,":[46],"intentionally":[47],"crafted":[48],"fool":[50],"a":[51,57,63,68,89],"neural":[52,91],"network,":[53],"can":[54,128],"dangerously":[55],"induce":[56],"misclassification":[58],"though":[59],"appearing":[60],"innocuous":[61],"human":[64],"observer.":[65],"On":[66],"basis,":[69],"this":[70],"paper":[71],"focuses":[72],"problem":[75],"image":[77],"classification":[78],"and":[79,112],"proposes":[80],"an":[81,97],"analysis":[82],"better":[84],"insight":[85],"what":[86],"happens":[87],"inside":[88],"convolutional":[90],"network":[92,107],"(CNN)":[93],"when":[94],"it":[95],"evaluates":[96],"example.":[99],"particular,":[101],"activations":[103,127],"internal":[106],"layers":[108],"have":[109],"been":[110],"analyzed":[111],"exploited":[113],"design":[115],"possible":[116],"countermeasures":[117],"reduce":[119],"CNN":[120],"vulnerability.":[121],"Experimental":[122],"results":[123],"confirm":[124],"that":[125],"layer":[126],"adopted":[130],"detect":[132],"inputs.":[134]},"counts_by_year":[{"year":2022,"cited_by_count":1},{"year":2021,"cited_by_count":2},{"year":2020,"cited_by_count":1},{"year":2019,"cited_by_count":2}],"updated_date":"2026-04-04T16:13:02.066488","created_date":"2025-10-10T00:00:00"}
