{"id":"https://openalex.org/W2901321061","doi":"https://doi.org/10.1109/ijcnn.2019.8852285","title":"Detecting Adversarial Perturbations Through Spatial Behavior in Activation Spaces","display_name":"Detecting Adversarial Perturbations Through Spatial Behavior in Activation Spaces","publication_year":2019,"publication_date":"2019-07-01","ids":{"openalex":"https://openalex.org/W2901321061","doi":"https://doi.org/10.1109/ijcnn.2019.8852285","mag":"2901321061"},"language":"en","primary_location":{"id":"doi:10.1109/ijcnn.2019.8852285","is_oa":false,"landing_page_url":"https://doi.org/10.1109/ijcnn.2019.8852285","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2019 International Joint Conference on Neural Networks (IJCNN)","raw_type":"proceedings-article"},"type":"preprint","indexed_in":["arxiv","crossref","datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://arxiv.org/pdf/1811.09043","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5062053119","display_name":"Ziv Katzir","orcid":"https://orcid.org/0000-0002-6375-7882"},"institutions":[{"id":"https://openalex.org/I124227911","display_name":"Ben-Gurion University of the Negev","ror":"https://ror.org/05tkyf982","country_code":"IL","type":"education","lineage":["https://openalex.org/I124227911"]}],"countries":["IL"],"is_corresponding":true,"raw_author_name":"Ziv Katzir","raw_affiliation_strings":["Deutsche Telekom Laboratories at Ben-Gurion University, Ben-Gurion University of the Negev, Beer Sheva, Israel","Deutsche Telekom Laboratories at Ben-Gurion University, Ben-Gurion University of the Negev, Beer-Sheva, Israel"],"affiliations":[{"raw_affiliation_string":"Deutsche Telekom Laboratories at Ben-Gurion University, Ben-Gurion University of the Negev, Beer Sheva, Israel","institution_ids":["https://openalex.org/I124227911"]},{"raw_affiliation_string":"Deutsche Telekom Laboratories at Ben-Gurion University, Ben-Gurion University of the Negev, Beer-Sheva, Israel","institution_ids":["https://openalex.org/I124227911"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5072913672","display_name":"Yuval Elovici","orcid":"https://orcid.org/0000-0002-9641-128X"},"institutions":[{"id":"https://openalex.org/I124227911","display_name":"Ben-Gurion University of the Negev","ror":"https://ror.org/05tkyf982","country_code":"IL","type":"education","lineage":["https://openalex.org/I124227911"]}],"countries":["IL"],"is_corresponding":false,"raw_author_name":"Yuval Elovici","raw_affiliation_strings":["Deutsche Telekom Laboratories at Ben-Gurion University, Ben-Gurion University of the Negev, Beer Sheva, Israel","Deutsche Telekom Laboratories at Ben-Gurion University, Ben-Gurion University of the Negev, Beer-Sheva, Israel"],"affiliations":[{"raw_affiliation_string":"Deutsche Telekom Laboratories at Ben-Gurion University, Ben-Gurion University of the Negev, Beer Sheva, Israel","institution_ids":["https://openalex.org/I124227911"]},{"raw_affiliation_string":"Deutsche Telekom Laboratories at Ben-Gurion University, Ben-Gurion University of the Negev, Beer-Sheva, Israel","institution_ids":["https://openalex.org/I124227911"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":2,"corresponding_author_ids":["https://openalex.org/A5062053119"],"corresponding_institution_ids":["https://openalex.org/I124227911"],"apc_list":null,"apc_paid":null,"fwci":0.2893,"has_fulltext":true,"cited_by_count":2,"citation_normalized_percentile":{"value":0.64313626,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":94,"max":96},"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"9"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9581000208854675,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9272000193595886,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/leverage","display_name":"Leverage (statistics)","score":0.7660787105560303},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.6425470113754272},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.5890952944755554},{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.5772428512573242},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.5188604593276978},{"id":"https://openalex.org/keywords/context","display_name":"Context (archaeology)","score":0.46636542677879333},{"id":"https://openalex.org/keywords/class","display_name":"Class (philosophy)","score":0.45204052329063416},{"id":"https://openalex.org/keywords/set","display_name":"Set (abstract data type)","score":0.4473409950733185},{"id":"https://openalex.org/keywords/a-priori-and-a-posteriori","display_name":"A priori and a posteriori","score":0.4363096058368683},{"id":"https://openalex.org/keywords/boosting","display_name":"Boosting (machine learning)","score":0.4339292347431183},{"id":"https://openalex.org/keywords/sequence","display_name":"Sequence (biology)","score":0.4267123341560364},{"id":"https://openalex.org/keywords/euclidean-space","display_name":"Euclidean space","score":0.4195009469985962},{"id":"https://openalex.org/keywords/pattern-recognition","display_name":"Pattern recognition (psychology)","score":0.41289445757865906},{"id":"https://openalex.org/keywords/algorithm","display_name":"Algorithm","score":0.3257092833518982},{"id":"https://openalex.org/keywords/mathematics","display_name":"Mathematics","score":0.26632988452911377},{"id":"https://openalex.org/keywords/combinatorics","display_name":"Combinatorics","score":0.09577682614326477}],"concepts":[{"id":"https://openalex.org/C153083717","wikidata":"https://www.wikidata.org/wiki/Q6535263","display_name":"Leverage (statistics)","level":2,"score":0.7660787105560303},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6425470113754272},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5890952944755554},{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.5772428512573242},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.5188604593276978},{"id":"https://openalex.org/C2779343474","wikidata":"https://www.wikidata.org/wiki/Q3109175","display_name":"Context (archaeology)","level":2,"score":0.46636542677879333},{"id":"https://openalex.org/C2777212361","wikidata":"https://www.wikidata.org/wiki/Q5127848","display_name":"Class (philosophy)","level":2,"score":0.45204052329063416},{"id":"https://openalex.org/C177264268","wikidata":"https://www.wikidata.org/wiki/Q1514741","display_name":"Set (abstract data type)","level":2,"score":0.4473409950733185},{"id":"https://openalex.org/C75553542","wikidata":"https://www.wikidata.org/wiki/Q178161","display_name":"A priori and a posteriori","level":2,"score":0.4363096058368683},{"id":"https://openalex.org/C46686674","wikidata":"https://www.wikidata.org/wiki/Q466303","display_name":"Boosting (machine learning)","level":2,"score":0.4339292347431183},{"id":"https://openalex.org/C2778112365","wikidata":"https://www.wikidata.org/wiki/Q3511065","display_name":"Sequence (biology)","level":2,"score":0.4267123341560364},{"id":"https://openalex.org/C186450821","wikidata":"https://www.wikidata.org/wiki/Q17295","display_name":"Euclidean space","level":2,"score":0.4195009469985962},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.41289445757865906},{"id":"https://openalex.org/C11413529","wikidata":"https://www.wikidata.org/wiki/Q8366","display_name":"Algorithm","level":1,"score":0.3257092833518982},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.26632988452911377},{"id":"https://openalex.org/C114614502","wikidata":"https://www.wikidata.org/wiki/Q76592","display_name":"Combinatorics","level":1,"score":0.09577682614326477},{"id":"https://openalex.org/C111472728","wikidata":"https://www.wikidata.org/wiki/Q9471","display_name":"Epistemology","level":1,"score":0.0},{"id":"https://openalex.org/C151730666","wikidata":"https://www.wikidata.org/wiki/Q7205","display_name":"Paleontology","level":1,"score":0.0},{"id":"https://openalex.org/C54355233","wikidata":"https://www.wikidata.org/wiki/Q7162","display_name":"Genetics","level":1,"score":0.0},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.0},{"id":"https://openalex.org/C138885662","wikidata":"https://www.wikidata.org/wiki/Q5891","display_name":"Philosophy","level":0,"score":0.0},{"id":"https://openalex.org/C86803240","wikidata":"https://www.wikidata.org/wiki/Q420","display_name":"Biology","level":0,"score":0.0}],"mesh":[],"locations_count":4,"locations":[{"id":"doi:10.1109/ijcnn.2019.8852285","is_oa":false,"landing_page_url":"https://doi.org/10.1109/ijcnn.2019.8852285","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2019 International Joint Conference on Neural Networks (IJCNN)","raw_type":"proceedings-article"},{"id":"pmh:oai:arXiv.org:1811.09043","is_oa":true,"landing_page_url":"http://arxiv.org/abs/1811.09043","pdf_url":"https://arxiv.org/pdf/1811.09043","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},{"id":"mag:2901321061","is_oa":true,"landing_page_url":"https://arxiv.org/pdf/1811.09043.pdf","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"arXiv (Cornell University)","raw_type":null},{"id":"doi:10.48550/arxiv.1811.09043","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.1811.09043","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"pmh:oai:arXiv.org:1811.09043","is_oa":true,"landing_page_url":"http://arxiv.org/abs/1811.09043","pdf_url":"https://arxiv.org/pdf/1811.09043","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/16","display_name":"Peace, Justice and strong institutions","score":0.4000000059604645}],"awards":[],"funders":[],"has_content":{"grobid_xml":true,"pdf":true},"content_urls":{"pdf":"https://content.openalex.org/works/W2901321061.pdf","grobid_xml":"https://content.openalex.org/works/W2901321061.grobid-xml"},"referenced_works_count":55,"referenced_works":["https://openalex.org/W1932198206","https://openalex.org/W1945616565","https://openalex.org/W1998808035","https://openalex.org/W2174868984","https://openalex.org/W2180612164","https://openalex.org/W2408141691","https://openalex.org/W2460937040","https://openalex.org/W2516574342","https://openalex.org/W2517229335","https://openalex.org/W2519224033","https://openalex.org/W2528914598","https://openalex.org/W2535873859","https://openalex.org/W2543927648","https://openalex.org/W2561975083","https://openalex.org/W2590523583","https://openalex.org/W2597490979","https://openalex.org/W2603766943","https://openalex.org/W2606529538","https://openalex.org/W2612866063","https://openalex.org/W2736899637","https://openalex.org/W2765233338","https://openalex.org/W2778624544","https://openalex.org/W2782217514","https://openalex.org/W2787496614","https://openalex.org/W2787708942","https://openalex.org/W2793165286","https://openalex.org/W2950468330","https://openalex.org/W2962700793","https://openalex.org/W2963564844","https://openalex.org/W2964153729","https://openalex.org/W3103557498","https://openalex.org/W3118608800","https://openalex.org/W6637162671","https://openalex.org/W6640425456","https://openalex.org/W6649863312","https://openalex.org/W6685800298","https://openalex.org/W6714069269","https://openalex.org/W6719080892","https://openalex.org/W6726114608","https://openalex.org/W6726407388","https://openalex.org/W6729756640","https://openalex.org/W6733645847","https://openalex.org/W6734483310","https://openalex.org/W6734787559","https://openalex.org/W6735419579","https://openalex.org/W6736296761","https://openalex.org/W6737043114","https://openalex.org/W6737432490","https://openalex.org/W6741036071","https://openalex.org/W6744679260","https://openalex.org/W6746499634","https://openalex.org/W6748204703","https://openalex.org/W6748475379","https://openalex.org/W6749162425","https://openalex.org/W6785841629"],"related_works":["https://openalex.org/W2978302387","https://openalex.org/W3139282803","https://openalex.org/W2979445021","https://openalex.org/W3175418069","https://openalex.org/W2973315321","https://openalex.org/W2559944883","https://openalex.org/W2913881544","https://openalex.org/W2768915615","https://openalex.org/W3202424289","https://openalex.org/W3004549262","https://openalex.org/W3006840262","https://openalex.org/W3009295188","https://openalex.org/W3034189722","https://openalex.org/W2939718915","https://openalex.org/W3032181470","https://openalex.org/W3105463048","https://openalex.org/W2609920186","https://openalex.org/W2949277570","https://openalex.org/W2915302401","https://openalex.org/W2912023003"],"abstract_inverted_index":{"Although":[0],"neural":[1,174],"network-based":[2],"classifiers":[3,161],"outperform":[4],"humans":[5],"in":[6,24,130],"a":[7,37,46,67,87,140,147,164,248],"range":[8],"of":[9,27,51,116,149,166,172,181,200,207,225],"tasks,":[10],"they":[11],"are":[12,57,194],"still":[13,58,82],"prone":[14],"to":[15,72,93,98,106,108,126,162,169,246],"manipulation":[16],"through":[17],"adversarial":[18,136,142,192],"perturbations.":[19],"Prior":[20],"research":[21],"has":[22],"resulted":[23],"the":[25,40,77,102,109,113,117,128,173,179,205,212,228],"identification":[26],"effective":[28],"defense":[29,38,48,244,251],"mechanisms":[30],"for":[31,227],"many":[32],"reported":[33,63],"attack":[34,55,61,214],"methods,":[35,56],"however":[36],"against":[39,211],"C&W":[41,213],"attack,":[42],"as":[43,45],"well":[44],"holistic":[47,249],"mechanism":[49],"capable":[50],"countering":[52],"multiple":[53],"different":[54,118],"missing.":[59],"All":[60],"methods":[62,245],"so":[64],"far":[65,195],"share":[66],"common":[68],"goal.":[69],"They":[70],"aim":[71],"avoid":[73],"detection":[74],"by":[75,112],"limiting":[76],"allowed":[78],"perturbation":[79],"magnitude,":[80],"and":[81,135,138,158,186],"trigger":[83],"incorrect":[84],"classification.":[85],"As":[86],"result,":[88],"small":[89],"perturbations":[90],"cause":[91],"classification":[92,218],"shift":[94],"from":[95],"one":[96,154],"class":[97,167],"another.":[99],"We":[100,121,145,176,203,231],"coined":[101],"term":[103],"activation":[104,114,124,156],"spaces":[105,125],"refer":[107],"hyperspaces":[110],"formed":[111],"values":[115],"network":[119],"layers.":[120],"then":[122,177],"use":[123],"capture":[127],"differences":[129],"spatial":[131],"dynamics":[132],"between":[133],"normal":[134,201],"examples,":[137],"form":[139,247],"novel":[141],"example":[143],"detector.":[144],"induce":[146],"set":[148],"k-nearest":[150],"neighbor":[151],"(k-NN)":[152],"classifiers,":[153],"per":[155],"space,":[157],"leverage":[159],"those":[160,199],"assign":[163],"sequence":[165,185],"labels":[168],"each":[170,182],"input":[171],"network.":[175],"calculate":[178],"likelihood":[180],"observed":[183],"label":[184],"show":[187,233],"that":[188],"sequences":[189],"associated":[190],"with":[191,241],"examples":[193],"less":[196],"likely":[197],"than":[198],"examples.":[202],"demonstrate":[204],"efficiency":[206],"our":[208,235],"proposed":[209],"detector":[210,236],"using":[215],"two":[216],"image":[217],"datasets":[219],"(MNIST,":[220],"CIFAR-10)":[221],"achieving":[222],"an":[223],"AUC":[224],"0.97":[226],"CIFAR-10":[229],"dataset.":[230],"further":[232],"how":[234],"can":[237],"be":[238],"easily":[239],"augmented":[240],"previously":[242],"suggested":[243],"multi-purpose":[250],"mechanism.":[252]},"counts_by_year":[{"year":2019,"cited_by_count":2}],"updated_date":"2026-03-20T23:20:44.827607","created_date":"2025-10-10T00:00:00"}
