{"id":"https://openalex.org/W3013195703","doi":"https://doi.org/10.1109/icnc47757.2020.9049702","title":"Cross-Layer Strategic Ensemble Defense Against Adversarial Examples","display_name":"Cross-Layer Strategic Ensemble Defense Against Adversarial Examples","publication_year":2020,"publication_date":"2020-02-01","ids":{"openalex":"https://openalex.org/W3013195703","doi":"https://doi.org/10.1109/icnc47757.2020.9049702","mag":"3013195703"},"language":"en","primary_location":{"id":"doi:10.1109/icnc47757.2020.9049702","is_oa":false,"landing_page_url":"https://doi.org/10.1109/icnc47757.2020.9049702","pdf_url":null,"source":{"id":"https://openalex.org/S4306498707","display_name":"2020 International Conference on Computing, Networking and Communications (ICNC)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2020 International Conference on Computing, Networking and Communications (ICNC)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5069331320","display_name":"Wenqi Wei","orcid":"https://orcid.org/0000-0001-9177-114X"},"institutions":[{"id":"https://openalex.org/I130701444","display_name":"Georgia Institute of Technology","ror":"https://ror.org/01zkghx44","country_code":"US","type":"education","lineage":["https://openalex.org/I130701444"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Wenqi Wei","raw_affiliation_strings":["School of Computer Science, Georgia Institute of Technology, Atlanta, Georgia, USA"],"affiliations":[{"raw_affiliation_string":"School of Computer Science, Georgia Institute of Technology, Atlanta, Georgia, USA","institution_ids":["https://openalex.org/I130701444"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100343991","display_name":"Ling Liu","orcid":"https://orcid.org/0000-0002-4138-3082"},"institutions":[{"id":"https://openalex.org/I130701444","display_name":"Georgia Institute of Technology","ror":"https://ror.org/01zkghx44","country_code":"US","type":"education","lineage":["https://openalex.org/I130701444"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Ling Liu","raw_affiliation_strings":["School of Computer Science, Georgia Institute of Technology, Atlanta, Georgia, USA"],"affiliations":[{"raw_affiliation_string":"School of Computer Science, Georgia Institute of Technology, Atlanta, Georgia, USA","institution_ids":["https://openalex.org/I130701444"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5091380057","display_name":"Margaret L. Loper","orcid":"https://orcid.org/0000-0002-0977-696X"},"institutions":[{"id":"https://openalex.org/I130701444","display_name":"Georgia Institute of Technology","ror":"https://ror.org/01zkghx44","country_code":"US","type":"education","lineage":["https://openalex.org/I130701444"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Margaret Loper","raw_affiliation_strings":["School of Computer Science, Georgia Institute of Technology, Atlanta, Georgia, USA"],"affiliations":[{"raw_affiliation_string":"School of Computer Science, Georgia Institute of Technology, Atlanta, Georgia, USA","institution_ids":["https://openalex.org/I130701444"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5028240524","display_name":"Ka-Ho Chow","orcid":"https://orcid.org/0000-0001-5917-2577"},"institutions":[{"id":"https://openalex.org/I130701444","display_name":"Georgia Institute of Technology","ror":"https://ror.org/01zkghx44","country_code":"US","type":"education","lineage":["https://openalex.org/I130701444"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Ka-Ho Chow","raw_affiliation_strings":["School of Computer Science, Georgia Institute of Technology, Atlanta, Georgia, USA"],"affiliations":[{"raw_affiliation_string":"School of Computer Science, Georgia Institute of Technology, Atlanta, Georgia, USA","institution_ids":["https://openalex.org/I130701444"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5006858624","display_name":"Emre G\u00fcrsoy","orcid":null},"institutions":[{"id":"https://openalex.org/I130701444","display_name":"Georgia Institute of Technology","ror":"https://ror.org/01zkghx44","country_code":"US","type":"education","lineage":["https://openalex.org/I130701444"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Emre Gursoy","raw_affiliation_strings":["School of Computer Science, Georgia Institute of Technology, Atlanta, Georgia, USA"],"affiliations":[{"raw_affiliation_string":"School of Computer Science, Georgia Institute of Technology, Atlanta, Georgia, USA","institution_ids":["https://openalex.org/I130701444"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5066370292","display_name":"Stacey Truex","orcid":"https://orcid.org/0000-0002-8274-645X"},"institutions":[{"id":"https://openalex.org/I130701444","display_name":"Georgia Institute of Technology","ror":"https://ror.org/01zkghx44","country_code":"US","type":"education","lineage":["https://openalex.org/I130701444"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Stacey Truex","raw_affiliation_strings":["School of Computer Science, Georgia Institute of Technology, Atlanta, Georgia, USA"],"affiliations":[{"raw_affiliation_string":"School of Computer Science, Georgia Institute of Technology, Atlanta, Georgia, USA","institution_ids":["https://openalex.org/I130701444"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5060093535","display_name":"Yanzhao Wu","orcid":"https://orcid.org/0000-0001-8761-5486"},"institutions":[{"id":"https://openalex.org/I130701444","display_name":"Georgia Institute of Technology","ror":"https://ror.org/01zkghx44","country_code":"US","type":"education","lineage":["https://openalex.org/I130701444"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Yanzhao Wu","raw_affiliation_strings":["School of Computer Science, Georgia Institute of Technology, Atlanta, Georgia, USA"],"affiliations":[{"raw_affiliation_string":"School of Computer Science, Georgia Institute of Technology, Atlanta, Georgia, USA","institution_ids":["https://openalex.org/I130701444"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":7,"corresponding_author_ids":["https://openalex.org/A5069331320"],"corresponding_institution_ids":["https://openalex.org/I130701444"],"apc_list":null,"apc_paid":null,"fwci":1.6765,"has_fulltext":false,"cited_by_count":22,"citation_normalized_percentile":{"value":0.86694315,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":89,"max":98},"biblio":{"volume":null,"issue":null,"first_page":"456","last_page":"460"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9634000062942505,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9520999789237976,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7269335985183716},{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.713950514793396},{"id":"https://openalex.org/keywords/ensemble-forecasting","display_name":"Ensemble forecasting","score":0.6239122748374939},{"id":"https://openalex.org/keywords/transformation","display_name":"Transformation (genetics)","score":0.6146526336669922},{"id":"https://openalex.org/keywords/ensemble-learning","display_name":"Ensemble learning","score":0.6062139272689819},{"id":"https://openalex.org/keywords/layer","display_name":"Layer (electronics)","score":0.5611603260040283},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.5578189492225647},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.5385412573814392},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.4162519872188568},{"id":"https://openalex.org/keywords/suite","display_name":"Suite","score":0.412492960691452}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7269335985183716},{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.713950514793396},{"id":"https://openalex.org/C119898033","wikidata":"https://www.wikidata.org/wiki/Q3433888","display_name":"Ensemble forecasting","level":2,"score":0.6239122748374939},{"id":"https://openalex.org/C204241405","wikidata":"https://www.wikidata.org/wiki/Q461499","display_name":"Transformation (genetics)","level":3,"score":0.6146526336669922},{"id":"https://openalex.org/C45942800","wikidata":"https://www.wikidata.org/wiki/Q245652","display_name":"Ensemble learning","level":2,"score":0.6062139272689819},{"id":"https://openalex.org/C2779227376","wikidata":"https://www.wikidata.org/wiki/Q6505497","display_name":"Layer (electronics)","level":2,"score":0.5611603260040283},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.5578189492225647},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5385412573814392},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.4162519872188568},{"id":"https://openalex.org/C79581498","wikidata":"https://www.wikidata.org/wiki/Q1367530","display_name":"Suite","level":2,"score":0.412492960691452},{"id":"https://openalex.org/C178790620","wikidata":"https://www.wikidata.org/wiki/Q11351","display_name":"Organic chemistry","level":1,"score":0.0},{"id":"https://openalex.org/C95457728","wikidata":"https://www.wikidata.org/wiki/Q309","display_name":"History","level":0,"score":0.0},{"id":"https://openalex.org/C166957645","wikidata":"https://www.wikidata.org/wiki/Q23498","display_name":"Archaeology","level":1,"score":0.0},{"id":"https://openalex.org/C104317684","wikidata":"https://www.wikidata.org/wiki/Q7187","display_name":"Gene","level":2,"score":0.0},{"id":"https://openalex.org/C185592680","wikidata":"https://www.wikidata.org/wiki/Q2329","display_name":"Chemistry","level":0,"score":0.0},{"id":"https://openalex.org/C55493867","wikidata":"https://www.wikidata.org/wiki/Q7094","display_name":"Biochemistry","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/icnc47757.2020.9049702","is_oa":false,"landing_page_url":"https://doi.org/10.1109/icnc47757.2020.9049702","pdf_url":null,"source":{"id":"https://openalex.org/S4306498707","display_name":"2020 International Conference on Computing, Networking and Communications (ICNC)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2020 International Conference on Computing, Networking and Communications (ICNC)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":25,"referenced_works":["https://openalex.org/W1945616565","https://openalex.org/W1966976587","https://openalex.org/W2408141691","https://openalex.org/W2572504188","https://openalex.org/W2607219512","https://openalex.org/W2773446523","https://openalex.org/W2808031418","https://openalex.org/W2962878175","https://openalex.org/W2963207607","https://openalex.org/W2963542245","https://openalex.org/W2963857521","https://openalex.org/W2963920068","https://openalex.org/W2964082701","https://openalex.org/W3013195703","https://openalex.org/W3102720581","https://openalex.org/W3103940881","https://openalex.org/W4247200422","https://openalex.org/W4294214983","https://openalex.org/W4298167384","https://openalex.org/W6640425456","https://openalex.org/W6714069269","https://openalex.org/W6719080892","https://openalex.org/W6746402973","https://openalex.org/W6752307889","https://openalex.org/W6768635262"],"related_works":["https://openalex.org/W2794896638","https://openalex.org/W2891633941","https://openalex.org/W3202800081","https://openalex.org/W3101614107","https://openalex.org/W1909207154","https://openalex.org/W4390971112","https://openalex.org/W3036530763","https://openalex.org/W3124390867","https://openalex.org/W1514365828","https://openalex.org/W3204228978"],"abstract_inverted_index":{"Deep":[0],"neural":[1],"network":[2],"(DNN)":[3],"has":[4],"demonstrated":[5],"its":[6],"success":[7,148,158],"in":[8],"multiple":[9],"domains.":[10],"However,":[11],"DNN":[12,33],"models":[13],"are":[14,21,55,151],"inherently":[15],"vulnerable":[16],"to":[17,27,30,35,81,94,167],"adversarial":[18,25],"examples,":[19],"which":[20,54],"generated":[22],"by":[23,115],"adding":[24],"perturbations":[26],"benign":[28,162],"inputs":[29],"fool":[31],"the":[32,63,83,96,113],"model":[34,65,99,121,127],"misclassify.":[36],"In":[37],"this":[38],"paper,":[39],"we":[40,77,90,103,136],"present":[41],"a":[42,48],"cross-layer":[43,107],"strategic":[44,69,85,98,108,140],"ensemble":[45,70,87,100,109,141],"framework":[46],"and":[47,57,61,150,160],"suite":[49],"of":[50,59],"robust":[51,153],"defense":[52,110,142,147],"algorithms,":[53],"attack-independent,":[56],"capable":[58],"auto-repairing":[60],"auto-verifying":[62],"target":[64],"being":[66],"attacked.":[67],"Our":[68],"approach":[71],"makes":[72],"three":[73],"original":[74],"contributions.":[75],"First,":[76],"employ":[78],"input-transformation":[79],"diversity":[80,93],"design":[82],"input-layer":[84],"transformation":[86,119],"algorithms.":[88,101],"Second,":[89],"utilize":[91],"model-disagreement":[92],"develop":[95],"output-layer":[97],"Finally,":[102],"create":[104],"an":[105],"input-output":[106],"that":[111,138],"strengthens":[112],"defensibility":[114],"combining":[116],"diverse":[117,124],"input":[118],"based":[120],"ensembles":[122],"with":[123,154],"output":[125],"verification":[126],"ensembles.":[128],"Evaluated":[129],"over":[130],"10":[131],"attacks":[132],"on":[133],"ImageNet":[134],"dataset,":[135],"show":[137],"our":[139],"algorithms":[143],"can":[144],"achieve":[145],"high":[146,155],"rates":[149,159],"more":[152],"attack":[156],"prevention":[157],"low":[161],"false":[163],"negative":[164],"rates,":[165],"compared":[166],"existing":[168],"representative":[169],"defenses.":[170]},"counts_by_year":[{"year":2025,"cited_by_count":3},{"year":2024,"cited_by_count":2},{"year":2023,"cited_by_count":4},{"year":2022,"cited_by_count":1},{"year":2021,"cited_by_count":4},{"year":2020,"cited_by_count":6},{"year":2019,"cited_by_count":2}],"updated_date":"2026-03-09T08:58:05.943551","created_date":"2025-10-10T00:00:00"}
