{"id":"https://openalex.org/W3200183771","doi":"https://doi.org/10.1109/ijcnn52387.2021.9533774","title":"An Efficient Method to Measure Robustness of ReLU-Based Classifiers via Search Space Pruning","display_name":"An Efficient Method to Measure Robustness of ReLU-Based Classifiers via Search Space Pruning","publication_year":2021,"publication_date":"2021-07-18","ids":{"openalex":"https://openalex.org/W3200183771","doi":"https://doi.org/10.1109/ijcnn52387.2021.9533774","mag":"3200183771"},"language":"en","primary_location":{"id":"doi:10.1109/ijcnn52387.2021.9533774","is_oa":false,"landing_page_url":"https://doi.org/10.1109/ijcnn52387.2021.9533774","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2021 International Joint Conference on Neural Networks (IJCNN)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5100707895","display_name":"Xinping Wang","orcid":"https://orcid.org/0000-0001-7067-2986"},"institutions":[{"id":"https://openalex.org/I4210139618","display_name":"Shanghai Key Laboratory of Trustworthy Computing","ror":"https://ror.org/030qbr085","country_code":"CN","type":"facility","lineage":["https://openalex.org/I4210139618"]},{"id":"https://openalex.org/I66867065","display_name":"East China Normal University","ror":"https://ror.org/02n96ep67","country_code":"CN","type":"education","lineage":["https://openalex.org/I66867065"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Xinping Wang","raw_affiliation_strings":["Shanghai Key Laboratory of Trustworthy Computing, East China Normal University, Shanghai, China"],"affiliations":[{"raw_affiliation_string":"Shanghai Key Laboratory of Trustworthy Computing, East China Normal University, Shanghai, China","institution_ids":["https://openalex.org/I4210139618","https://openalex.org/I66867065"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100780219","display_name":"Liangyu Chen","orcid":"https://orcid.org/0000-0003-0394-6208"},"institutions":[{"id":"https://openalex.org/I66867065","display_name":"East China Normal University","ror":"https://ror.org/02n96ep67","country_code":"CN","type":"education","lineage":["https://openalex.org/I66867065"]},{"id":"https://openalex.org/I4210139618","display_name":"Shanghai Key Laboratory of Trustworthy Computing","ror":"https://ror.org/030qbr085","country_code":"CN","type":"facility","lineage":["https://openalex.org/I4210139618"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Liangyu Chen","raw_affiliation_strings":["Shanghai Key Laboratory of Trustworthy Computing, East China Normal University, Shanghai, China"],"affiliations":[{"raw_affiliation_string":"Shanghai Key Laboratory of Trustworthy Computing, East China Normal University, Shanghai, China","institution_ids":["https://openalex.org/I4210139618","https://openalex.org/I66867065"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100450967","display_name":"Tong Wang","orcid":"https://orcid.org/0000-0001-6981-916X"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Tong Wang","raw_affiliation_strings":["Beijing Institute of System Engineering, Beijing, China"],"affiliations":[{"raw_affiliation_string":"Beijing Institute of System Engineering, Beijing, China","institution_ids":[]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5029237672","display_name":"Mingang Chen","orcid":"https://orcid.org/0000-0002-0718-8187"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Mingang Chen","raw_affiliation_strings":["Laboratory of Computer Software Testing and Evaluating, Shanghai Development Center of Computer Software Technology, Shanghai, China"],"affiliations":[{"raw_affiliation_string":"Laboratory of Computer Software Testing and Evaluating, Shanghai Development Center of Computer Software Technology, Shanghai, China","institution_ids":[]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5100402983","display_name":"Min Zhang","orcid":"https://orcid.org/0000-0003-1938-2902"},"institutions":[{"id":"https://openalex.org/I66867065","display_name":"East China Normal University","ror":"https://ror.org/02n96ep67","country_code":"CN","type":"education","lineage":["https://openalex.org/I66867065"]},{"id":"https://openalex.org/I4210139618","display_name":"Shanghai Key Laboratory of Trustworthy Computing","ror":"https://ror.org/030qbr085","country_code":"CN","type":"facility","lineage":["https://openalex.org/I4210139618"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Min Zhang","raw_affiliation_strings":["Shanghai Key Laboratory of Trustworthy Computing, East China Normal University, Shanghai, China"],"affiliations":[{"raw_affiliation_string":"Shanghai Key Laboratory of Trustworthy Computing, East China Normal University, Shanghai, China","institution_ids":["https://openalex.org/I4210139618","https://openalex.org/I66867065"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5100707895"],"corresponding_institution_ids":["https://openalex.org/I4210139618","https://openalex.org/I66867065"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.13061106,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":"529","issue":null,"first_page":"1","last_page":"8"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9955000281333923,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11307","display_name":"Domain Adaptation and Few-Shot Learning","score":0.988099992275238,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.8421062231063843},{"id":"https://openalex.org/keywords/mnist-database","display_name":"MNIST database","score":0.7474370002746582},{"id":"https://openalex.org/keywords/integer-programming","display_name":"Integer programming","score":0.63237464427948},{"id":"https://openalex.org/keywords/linear-programming","display_name":"Linear programming","score":0.6246824264526367},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.570325493812561},{"id":"https://openalex.org/keywords/mathematical-optimization","display_name":"Mathematical optimization","score":0.537428081035614},{"id":"https://openalex.org/keywords/pruning","display_name":"Pruning","score":0.47635960578918457},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.42308297753334045},{"id":"https://openalex.org/keywords/greedy-algorithm","display_name":"Greedy algorithm","score":0.41566792130470276},{"id":"https://openalex.org/keywords/algorithm","display_name":"Algorithm","score":0.3999228775501251},{"id":"https://openalex.org/keywords/pattern-recognition","display_name":"Pattern recognition (psychology)","score":0.3549484610557556},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.34548407793045044},{"id":"https://openalex.org/keywords/mathematics","display_name":"Mathematics","score":0.3264073133468628},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.325961709022522}],"concepts":[{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.8421062231063843},{"id":"https://openalex.org/C190502265","wikidata":"https://www.wikidata.org/wiki/Q17069496","display_name":"MNIST database","level":3,"score":0.7474370002746582},{"id":"https://openalex.org/C56086750","wikidata":"https://www.wikidata.org/wiki/Q6042592","display_name":"Integer programming","level":2,"score":0.63237464427948},{"id":"https://openalex.org/C41045048","wikidata":"https://www.wikidata.org/wiki/Q202843","display_name":"Linear programming","level":2,"score":0.6246824264526367},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.570325493812561},{"id":"https://openalex.org/C126255220","wikidata":"https://www.wikidata.org/wiki/Q141495","display_name":"Mathematical optimization","level":1,"score":0.537428081035614},{"id":"https://openalex.org/C108010975","wikidata":"https://www.wikidata.org/wiki/Q500094","display_name":"Pruning","level":2,"score":0.47635960578918457},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.42308297753334045},{"id":"https://openalex.org/C51823790","wikidata":"https://www.wikidata.org/wiki/Q504353","display_name":"Greedy algorithm","level":2,"score":0.41566792130470276},{"id":"https://openalex.org/C11413529","wikidata":"https://www.wikidata.org/wiki/Q8366","display_name":"Algorithm","level":1,"score":0.3999228775501251},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.3549484610557556},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.34548407793045044},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.3264073133468628},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.325961709022522},{"id":"https://openalex.org/C104317684","wikidata":"https://www.wikidata.org/wiki/Q7187","display_name":"Gene","level":2,"score":0.0},{"id":"https://openalex.org/C185592680","wikidata":"https://www.wikidata.org/wiki/Q2329","display_name":"Chemistry","level":0,"score":0.0},{"id":"https://openalex.org/C86803240","wikidata":"https://www.wikidata.org/wiki/Q420","display_name":"Biology","level":0,"score":0.0},{"id":"https://openalex.org/C55493867","wikidata":"https://www.wikidata.org/wiki/Q7094","display_name":"Biochemistry","level":1,"score":0.0},{"id":"https://openalex.org/C6557445","wikidata":"https://www.wikidata.org/wiki/Q173113","display_name":"Agronomy","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/ijcnn52387.2021.9533774","is_oa":false,"landing_page_url":"https://doi.org/10.1109/ijcnn52387.2021.9533774","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2021 International Joint Conference on Neural Networks (IJCNN)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":50,"referenced_works":["https://openalex.org/W9657784","https://openalex.org/W1665214252","https://openalex.org/W1673923490","https://openalex.org/W1945616565","https://openalex.org/W1969705022","https://openalex.org/W1977230515","https://openalex.org/W2073576149","https://openalex.org/W2076063813","https://openalex.org/W2088656430","https://openalex.org/W2144354855","https://openalex.org/W2161388792","https://openalex.org/W2243397390","https://openalex.org/W2257979135","https://openalex.org/W2310919327","https://openalex.org/W2342840547","https://openalex.org/W2345492474","https://openalex.org/W2543296129","https://openalex.org/W2567575208","https://openalex.org/W2594877703","https://openalex.org/W2757182288","https://openalex.org/W2768915615","https://openalex.org/W2802557767","https://openalex.org/W2805807555","https://openalex.org/W2951603627","https://openalex.org/W2962943487","https://openalex.org/W2963054787","https://openalex.org/W2963143631","https://openalex.org/W2963207607","https://openalex.org/W2963440492","https://openalex.org/W2963564844","https://openalex.org/W2963784236","https://openalex.org/W2963857521","https://openalex.org/W2964153729","https://openalex.org/W2980264580","https://openalex.org/W3118608800","https://openalex.org/W4250589301","https://openalex.org/W4294349862","https://openalex.org/W6600428322","https://openalex.org/W6637162671","https://openalex.org/W6637242042","https://openalex.org/W6640425456","https://openalex.org/W6676622225","https://openalex.org/W6704559304","https://openalex.org/W6711870810","https://openalex.org/W6734921443","https://openalex.org/W6744519437","https://openalex.org/W6745950489","https://openalex.org/W6748475379","https://openalex.org/W6750745550","https://openalex.org/W6752034395"],"related_works":["https://openalex.org/W3183948672","https://openalex.org/W992687842","https://openalex.org/W4300560302","https://openalex.org/W3088108839","https://openalex.org/W4285278887","https://openalex.org/W2995925505","https://openalex.org/W2365237642","https://openalex.org/W3116484972","https://openalex.org/W2941986668","https://openalex.org/W4232431455"],"abstract_inverted_index":{"Deep":[0],"Neural":[1],"Networks":[2],"(DNNs)":[3],"have":[4],"achieved":[5],"high":[6],"accuracy":[7],"on":[8,54,117,144,148],"image":[9],"classification.":[10],"However,":[11],"a":[12,29,71,113],"small":[13],"disturbance":[14],"to":[15,22,45,69,86,121,136],"an":[16,94],"input":[17],"may":[18],"fool":[19],"the":[20,24,37,55,59,87,104,123,127,134],"networks":[21],"misclassify":[23],"label,":[25],"which":[26,64],"can":[27,65],"cause":[28],"series":[30],"of":[31,39,57,61,80,89,107,162],"security":[32],"and":[33,100,150,164],"social":[34],"problems.":[35,109],"Thus,":[36],"robustness":[38,60,98],"DNNs":[40],"must":[41],"be":[42,66],"ensured,":[43],"particularly":[44],"those":[46],"safety-critical":[47],"systems.":[48],"In":[49],"this":[50],"paper,":[51],"we":[52,111],"focus":[53],"problem":[56,76],"measuring":[58],"ReLU-based":[62],"DNNs,":[63],"equivalently":[67],"formulated":[68],"solve":[70],"Mixed":[72],"Integer":[73],"Linear":[74],"Programming":[75],"(MILP).":[77],"The":[78,141],"complexity":[79],"solving":[81],"MILP":[82,108],"is":[83,130],"directly":[84],"related":[85,158],"number":[88],"integer":[90,137],"variables.":[91],"We":[92],"propose":[93],"efficient":[95],"method":[96,155],"for":[97],"measurement":[99],"verification":[101],"by":[102,132],"pruning":[103],"search":[105,128],"space":[106,129],"Particularly,":[110],"design":[112],"greedy":[114],"algorithm":[115],"based":[116],"linear":[118],"programming":[119],"(LP)":[120],"determine":[122],"reasonable":[124],"boundary.":[125],"Then":[126],"pruned":[131],"setting":[133],"boundary":[135],"variables":[138],"in":[139,160],"MILP.":[140],"comparison":[142],"experiments":[143],"five":[145],"classifiers":[146],"trained":[147],"MNIST":[149],"CIFAR-10":[151],"datasets":[152],"show":[153],"our":[154],"outperforms":[156],"other":[157],"tools":[159],"terms":[161],"efficiency":[163],"accuracy.":[165]},"counts_by_year":[],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
