{"id":"https://openalex.org/W4385482875","doi":"https://doi.org/10.1109/ijcnn54540.2023.10191429","title":"Improving Robustness Against Adversarial Attacks with Deeply Quantized Neural Networks","display_name":"Improving Robustness Against Adversarial Attacks with Deeply Quantized Neural Networks","publication_year":2023,"publication_date":"2023-06-18","ids":{"openalex":"https://openalex.org/W4385482875","doi":"https://doi.org/10.1109/ijcnn54540.2023.10191429"},"language":"en","primary_location":{"id":"doi:10.1109/ijcnn54540.2023.10191429","is_oa":false,"landing_page_url":"https://doi.org/10.1109/ijcnn54540.2023.10191429","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2023 International Joint Conference on Neural Networks (IJCNN)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://eprints.gla.ac.uk/view/author/64868.html>","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5017467726","display_name":"Ferheen Ayaz","orcid":"https://orcid.org/0000-0003-3905-675X"},"institutions":[{"id":"https://openalex.org/I162608824","display_name":"University of Sussex","ror":"https://ror.org/00ayhx656","country_code":"GB","type":"education","lineage":["https://openalex.org/I162608824"]}],"countries":["GB"],"is_corresponding":true,"raw_author_name":"Ferheen Ayaz","raw_affiliation_strings":["University of Sussex,UK","University of Sussex, UK"],"affiliations":[{"raw_affiliation_string":"University of Sussex,UK","institution_ids":["https://openalex.org/I162608824"]},{"raw_affiliation_string":"University of Sussex, UK","institution_ids":["https://openalex.org/I162608824"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5077069389","display_name":"Idris Zakariyya","orcid":"https://orcid.org/0000-0002-7983-1848"},"institutions":[{"id":"https://openalex.org/I7882870","display_name":"University of Glasgow","ror":"https://ror.org/00vtgdb53","country_code":"GB","type":"education","lineage":["https://openalex.org/I7882870"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"Idris Zakariyya","raw_affiliation_strings":["University of Glasgow,UK","University of Glasgow, UK"],"affiliations":[{"raw_affiliation_string":"University of Glasgow,UK","institution_ids":["https://openalex.org/I7882870"]},{"raw_affiliation_string":"University of Glasgow, UK","institution_ids":["https://openalex.org/I7882870"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5110927467","display_name":"Jos\u00e9 Cano","orcid":null},"institutions":[{"id":"https://openalex.org/I7882870","display_name":"University of Glasgow","ror":"https://ror.org/00vtgdb53","country_code":"GB","type":"education","lineage":["https://openalex.org/I7882870"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"Jos\u00e9 Cano","raw_affiliation_strings":["University of Glasgow,UK","University of Glasgow, UK"],"affiliations":[{"raw_affiliation_string":"University of Glasgow,UK","institution_ids":["https://openalex.org/I7882870"]},{"raw_affiliation_string":"University of Glasgow, UK","institution_ids":["https://openalex.org/I7882870"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5039662039","display_name":"Sye Loong Keoh","orcid":"https://orcid.org/0000-0003-3640-5010"},"institutions":[{"id":"https://openalex.org/I7882870","display_name":"University of Glasgow","ror":"https://ror.org/00vtgdb53","country_code":"GB","type":"education","lineage":["https://openalex.org/I7882870"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"Sye Loong Keoh","raw_affiliation_strings":["University of Glasgow,UK","University of Glasgow, UK"],"affiliations":[{"raw_affiliation_string":"University of Glasgow,UK","institution_ids":["https://openalex.org/I7882870"]},{"raw_affiliation_string":"University of Glasgow, UK","institution_ids":["https://openalex.org/I7882870"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5064718447","display_name":"Jeremy Singer","orcid":"https://orcid.org/0000-0001-9462-6802"},"institutions":[{"id":"https://openalex.org/I7882870","display_name":"University of Glasgow","ror":"https://ror.org/00vtgdb53","country_code":"GB","type":"education","lineage":["https://openalex.org/I7882870"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"Jeremy Singer","raw_affiliation_strings":["University of Glasgow,UK","University of Glasgow, UK"],"affiliations":[{"raw_affiliation_string":"University of Glasgow,UK","institution_ids":["https://openalex.org/I7882870"]},{"raw_affiliation_string":"University of Glasgow, UK","institution_ids":["https://openalex.org/I7882870"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5036123913","display_name":"Danilo Pau","orcid":"https://orcid.org/0000-0003-1585-2313"},"institutions":[{"id":"https://openalex.org/I4210124177","display_name":"STMicroelectronics (Czechia)","ror":"https://ror.org/03c7ss521","country_code":"CZ","type":"company","lineage":["https://openalex.org/I131827901","https://openalex.org/I4210124177"]}],"countries":["CZ"],"is_corresponding":false,"raw_author_name":"Danilo Pau","raw_affiliation_strings":["STMicroelectronics"],"affiliations":[{"raw_affiliation_string":"STMicroelectronics","institution_ids":["https://openalex.org/I4210124177"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5088344859","display_name":"Mounia Kharbouche-Harrari","orcid":null},"institutions":[{"id":"https://openalex.org/I4210124177","display_name":"STMicroelectronics (Czechia)","ror":"https://ror.org/03c7ss521","country_code":"CZ","type":"company","lineage":["https://openalex.org/I131827901","https://openalex.org/I4210124177"]}],"countries":["CZ"],"is_corresponding":false,"raw_author_name":"Mounia Kharbouche-Harrari","raw_affiliation_strings":["STMicroelectronics"],"affiliations":[{"raw_affiliation_string":"STMicroelectronics","institution_ids":["https://openalex.org/I4210124177"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":7,"corresponding_author_ids":["https://openalex.org/A5017467726"],"corresponding_institution_ids":["https://openalex.org/I162608824"],"apc_list":null,"apc_paid":null,"fwci":1.2187,"has_fulltext":false,"cited_by_count":7,"citation_normalized_percentile":{"value":0.83070528,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":89,"max":98},"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"8"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11307","display_name":"Domain Adaptation and Few-Shot Learning","score":0.9771000146865845,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10036","display_name":"Advanced Neural Network Applications","score":0.9746000170707703,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7724676132202148},{"id":"https://openalex.org/keywords/deep-neural-networks","display_name":"Deep neural networks","score":0.6647834777832031},{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.6579480171203613},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.547946035861969},{"id":"https://openalex.org/keywords/quantization","display_name":"Quantization (signal processing)","score":0.537208080291748},{"id":"https://openalex.org/keywords/deep-learning","display_name":"Deep learning","score":0.5258929133415222},{"id":"https://openalex.org/keywords/white-box","display_name":"White box","score":0.5070714950561523},{"id":"https://openalex.org/keywords/software-deployment","display_name":"Software deployment","score":0.5015037059783936},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.4444378614425659},{"id":"https://openalex.org/keywords/computer-engineering","display_name":"Computer engineering","score":0.44168147444725037},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.42838916182518005},{"id":"https://openalex.org/keywords/memory-footprint","display_name":"Memory footprint","score":0.41344523429870605},{"id":"https://openalex.org/keywords/algorithm","display_name":"Algorithm","score":0.1801758110523224}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7724676132202148},{"id":"https://openalex.org/C2984842247","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep neural networks","level":3,"score":0.6647834777832031},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.6579480171203613},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.547946035861969},{"id":"https://openalex.org/C28855332","wikidata":"https://www.wikidata.org/wiki/Q198099","display_name":"Quantization (signal processing)","level":2,"score":0.537208080291748},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.5258929133415222},{"id":"https://openalex.org/C180932941","wikidata":"https://www.wikidata.org/wiki/Q997233","display_name":"White box","level":2,"score":0.5070714950561523},{"id":"https://openalex.org/C105339364","wikidata":"https://www.wikidata.org/wiki/Q2297740","display_name":"Software deployment","level":2,"score":0.5015037059783936},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.4444378614425659},{"id":"https://openalex.org/C113775141","wikidata":"https://www.wikidata.org/wiki/Q428691","display_name":"Computer engineering","level":1,"score":0.44168147444725037},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.42838916182518005},{"id":"https://openalex.org/C74912251","wikidata":"https://www.wikidata.org/wiki/Q6815727","display_name":"Memory footprint","level":2,"score":0.41344523429870605},{"id":"https://openalex.org/C11413529","wikidata":"https://www.wikidata.org/wiki/Q8366","display_name":"Algorithm","level":1,"score":0.1801758110523224},{"id":"https://openalex.org/C185592680","wikidata":"https://www.wikidata.org/wiki/Q2329","display_name":"Chemistry","level":0,"score":0.0},{"id":"https://openalex.org/C104317684","wikidata":"https://www.wikidata.org/wiki/Q7187","display_name":"Gene","level":2,"score":0.0},{"id":"https://openalex.org/C55493867","wikidata":"https://www.wikidata.org/wiki/Q7094","display_name":"Biochemistry","level":1,"score":0.0},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1109/ijcnn54540.2023.10191429","is_oa":false,"landing_page_url":"https://doi.org/10.1109/ijcnn54540.2023.10191429","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2023 International Joint Conference on Neural Networks (IJCNN)","raw_type":"proceedings-article"},{"id":"pmh:oai:eprints.gla.ac.uk:299217","is_oa":true,"landing_page_url":"https://eprints.gla.ac.uk/view/author/64868.html>","pdf_url":null,"source":{"id":"https://openalex.org/S4210235606","display_name":"ENLIGHTEN (Jurnal Bimbingan dan Konseling Islam)","issn_l":"2622-8912","issn":["2622-8912","2622-8920"],"is_oa":true,"is_in_doaj":true,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"journal"},"license":"cc-by-sa","license_id":"https://openalex.org/licenses/cc-by-sa","version":"acceptedVersion","is_accepted":true,"is_published":false,"raw_source_name":null,"raw_type":"PeerReviewed"}],"best_oa_location":{"id":"pmh:oai:eprints.gla.ac.uk:299217","is_oa":true,"landing_page_url":"https://eprints.gla.ac.uk/view/author/64868.html>","pdf_url":null,"source":{"id":"https://openalex.org/S4210235606","display_name":"ENLIGHTEN (Jurnal Bimbingan dan Konseling Islam)","issn_l":"2622-8912","issn":["2622-8912","2622-8920"],"is_oa":true,"is_in_doaj":true,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"journal"},"license":"cc-by-sa","license_id":"https://openalex.org/licenses/cc-by-sa","version":"acceptedVersion","is_accepted":true,"is_published":false,"raw_source_name":null,"raw_type":"PeerReviewed"},"sustainable_development_goals":[{"display_name":"Decent work and economic growth","score":0.41999998688697815,"id":"https://metadata.un.org/sdg/8"}],"awards":[{"id":"https://openalex.org/G521268540","display_name":"PETRAS 2","funder_award_id":"EP/S035362/1","funder_id":"https://openalex.org/F4320334627","funder_display_name":"Engineering and Physical Sciences Research Council"}],"funders":[{"id":"https://openalex.org/F4320334627","display_name":"Engineering and Physical Sciences Research Council","ror":"https://ror.org/0439y7842"}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":62,"referenced_works":["https://openalex.org/W2001610032","https://openalex.org/W2335728318","https://openalex.org/W2469490737","https://openalex.org/W2529714286","https://openalex.org/W2565516711","https://openalex.org/W2746600820","https://openalex.org/W2765424254","https://openalex.org/W2890392327","https://openalex.org/W2942137712","https://openalex.org/W2962821226","https://openalex.org/W2963263347","https://openalex.org/W2963273475","https://openalex.org/W2963857521","https://openalex.org/W2963923251","https://openalex.org/W2964014389","https://openalex.org/W2964279778","https://openalex.org/W2983044655","https://openalex.org/W2991873520","https://openalex.org/W2999093589","https://openalex.org/W3007289469","https://openalex.org/W3013520104","https://openalex.org/W3034892461","https://openalex.org/W3035182590","https://openalex.org/W3045700442","https://openalex.org/W3048300167","https://openalex.org/W3098755434","https://openalex.org/W3099049750","https://openalex.org/W3103557498","https://openalex.org/W3106412272","https://openalex.org/W3107235539","https://openalex.org/W3116057280","https://openalex.org/W3117595835","https://openalex.org/W3118608800","https://openalex.org/W3135773993","https://openalex.org/W3137147200","https://openalex.org/W3163963286","https://openalex.org/W3171116680","https://openalex.org/W3173019690","https://openalex.org/W3175548485","https://openalex.org/W3175878110","https://openalex.org/W3176594951","https://openalex.org/W3177366646","https://openalex.org/W3204681655","https://openalex.org/W3213164726","https://openalex.org/W3213751580","https://openalex.org/W4214601645","https://openalex.org/W4248083651","https://openalex.org/W4283732345","https://openalex.org/W4287282771","https://openalex.org/W4287639545","https://openalex.org/W4287745534","https://openalex.org/W4297672357","https://openalex.org/W4313152613","https://openalex.org/W6720242923","https://openalex.org/W6726497184","https://openalex.org/W6745591726","https://openalex.org/W6752654261","https://openalex.org/W6784225549","https://openalex.org/W6785480743","https://openalex.org/W6787989545","https://openalex.org/W6791552382","https://openalex.org/W6802755634"],"related_works":["https://openalex.org/W2928062709","https://openalex.org/W2896078964","https://openalex.org/W3204400881","https://openalex.org/W3214410901","https://openalex.org/W3204296682","https://openalex.org/W3183118997","https://openalex.org/W2917767146","https://openalex.org/W4396520111","https://openalex.org/W4312601715","https://openalex.org/W4225493432"],"abstract_inverted_index":{"Reducing":[0],"the":[1,46,49,69,100,105,134,138,213,221,229,243,249],"memory":[2],"footprint":[3],"of":[4,27,71,215,228,245],"Machine":[5],"Learning":[6],"(ML)":[7],"models,":[8],"particularly":[9],"Deep":[10],"Neural":[11],"Networks":[12],"(DNNs),":[13],"is":[14,30,51],"essential":[15],"to":[16,33,45,53,78,143],"enable":[17],"their":[18,31],"deployment":[19,111],"into":[20],"resource-constrained":[21,63],"tiny":[22,58,74,113,147],"devices.":[23,65,114],"However,":[24],"a":[25,73,129,153,155,226],"disadvantage":[26],"DNN":[28,59,75,135,150,157,200],"models":[29,60],"vulnerability":[32],"adversarial":[34,79,121],"attacks,":[35,84],"as":[36,177,179],"they":[37],"can":[38,127],"be":[39],"fooled":[40],"by":[41,132],"adding":[42],"slight":[43],"perturbations":[44],"inputs.":[47],"Therefore,":[48],"challenge":[50],"how":[52,117],"create":[54],"accurate,":[55],"robust,":[56],"and":[57,81,119,137,166,174,189,205,217,225],"deployable":[61],"on":[62,112,168,196,220,248],"embedded":[64],"This":[66],"paper":[67],"reports":[68],"results":[70,193],"devising":[72],"model,":[76],"robust":[77,145],"black":[80],"white":[82],"box":[83],"trained":[85],"with":[86,94,183],"an":[87,120],"automatic":[88],"quantization-aware":[89],"training":[90],"framework,":[91],"i.e.":[92],"QKeras,":[93],"deep":[95],"quantization":[96],"loss":[97],"accounted":[98],"in":[99,203,212,242],"learning":[101],"loop,":[102],"thereby":[103],"making":[104],"designed":[106],"DNNs":[107],"more":[108,240],"accurate":[109,241],"for":[110],"We":[115],"investigated":[116],"QKeras":[118],"robustness":[122],"technique,":[123],"Jacobian":[124],"Regularization":[125],"(JR),":[126],"provide":[128],"co-optimization":[130,161],"strategy":[131,162],"exploiting":[133],"topology":[136],"per":[139],"layer":[140],"JR":[141],"approach":[142],"produce":[144],"yet":[146],"deeply":[148],"quantized":[149],"models.":[151],"As":[152],"result,":[154],"new":[156],"model":[158,201],"implementing":[159],"this":[160],"was":[163,237],"conceived,":[164],"developed":[165],"tested":[167],"three":[169],"datasets":[170],"containing":[171],"both":[172],"images":[173],"audio":[175,233],"inputs,":[176],"well":[178],"compared":[180],"its":[181],"performance":[182],"existing":[184],"benchmarks":[185,211],"against":[186],"various":[187],"white-box":[188,216],"black-box":[190,218,246],"attacks.":[191],"Experimental":[192],"demonstrated":[194],"that":[195],"average":[197],"our":[198],"proposed":[199],"resulted":[202],"8.3%":[204],"79.5%":[206],"higher":[207],"accuracy":[208],"than":[209],"MLCommons/Tiny":[210],"presence":[214,244],"attacks":[219,247],"CIFAR-10":[222],"image":[223,251],"dataset":[224,234],"subset":[227],"Google":[230],"Speech":[231],"Commands":[232],"respectively.":[235],"It":[236],"also":[238],"6.5%":[239],"SVHN":[250],"dataset.":[252]},"counts_by_year":[{"year":2025,"cited_by_count":4},{"year":2024,"cited_by_count":2},{"year":2023,"cited_by_count":1}],"updated_date":"2026-03-01T08:55:55.761014","created_date":"2025-10-10T00:00:00"}
