{"id":"https://openalex.org/W4287851276","doi":"https://doi.org/10.1109/spw54247.2022.9833874","title":"Concept-based Adversarial Attacks: Tricking Humans and Classifiers Alike","display_name":"Concept-based Adversarial Attacks: Tricking Humans and Classifiers Alike","publication_year":2022,"publication_date":"2022-05-01","ids":{"openalex":"https://openalex.org/W4287851276","doi":"https://doi.org/10.1109/spw54247.2022.9833874"},"language":"en","primary_location":{"id":"doi:10.1109/spw54247.2022.9833874","is_oa":false,"landing_page_url":"https://doi.org/10.1109/spw54247.2022.9833874","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2022 IEEE Security and Privacy Workshops (SPW)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5101711824","display_name":"Johannes Schneider","orcid":"https://orcid.org/0000-0002-3225-5564"},"institutions":[{"id":"https://openalex.org/I184656255","display_name":"University of Liechtenstein","ror":"https://ror.org/01qjrx392","country_code":"LI","type":"education","lineage":["https://openalex.org/I184656255"]}],"countries":["LI"],"is_corresponding":true,"raw_author_name":"Johannes Schneider","raw_affiliation_strings":["University of Liechtenstein,Institute of Information Systems","Institute of Information Systems, University of Liechtenstein"],"affiliations":[{"raw_affiliation_string":"University of Liechtenstein,Institute of Information Systems","institution_ids":["https://openalex.org/I184656255"]},{"raw_affiliation_string":"Institute of Information Systems, University of Liechtenstein","institution_ids":["https://openalex.org/I184656255"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5084036967","display_name":"Giovanni Apruzzese","orcid":"https://orcid.org/0000-0002-6890-9611"},"institutions":[{"id":"https://openalex.org/I184656255","display_name":"University of Liechtenstein","ror":"https://ror.org/01qjrx392","country_code":"LI","type":"education","lineage":["https://openalex.org/I184656255"]}],"countries":["LI"],"is_corresponding":false,"raw_author_name":"Giovanni Apruzzese","raw_affiliation_strings":["University of Liechtenstein,Institute of Information Systems","Institute of Information Systems, University of Liechtenstein"],"affiliations":[{"raw_affiliation_string":"University of Liechtenstein,Institute of Information Systems","institution_ids":["https://openalex.org/I184656255"]},{"raw_affiliation_string":"Institute of Information Systems, University of Liechtenstein","institution_ids":["https://openalex.org/I184656255"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":2,"corresponding_author_ids":["https://openalex.org/A5101711824"],"corresponding_institution_ids":["https://openalex.org/I184656255"],"apc_list":null,"apc_paid":null,"fwci":1.4593,"has_fulltext":false,"cited_by_count":11,"citation_normalized_percentile":{"value":0.84640713,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":94,"max":98},"biblio":{"volume":null,"issue":null,"first_page":"66","last_page":"72"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9889000058174133,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11307","display_name":"Domain Adaptation and Few-Shot Learning","score":0.9886999726295471,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.9380276203155518},{"id":"https://openalex.org/keywords/sample","display_name":"Sample (material)","score":0.7356338500976562},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7176065444946289},{"id":"https://openalex.org/keywords/transferability","display_name":"Transferability","score":0.7013554573059082},{"id":"https://openalex.org/keywords/notice","display_name":"Notice","score":0.6359137892723083},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.6104276180267334},{"id":"https://openalex.org/keywords/class","display_name":"Class (philosophy)","score":0.4477691948413849},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.4140487611293793},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.3568906784057617},{"id":"https://openalex.org/keywords/law","display_name":"Law","score":0.07010030746459961}],"concepts":[{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.9380276203155518},{"id":"https://openalex.org/C198531522","wikidata":"https://www.wikidata.org/wiki/Q485146","display_name":"Sample (material)","level":2,"score":0.7356338500976562},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7176065444946289},{"id":"https://openalex.org/C61272859","wikidata":"https://www.wikidata.org/wiki/Q7834031","display_name":"Transferability","level":3,"score":0.7013554573059082},{"id":"https://openalex.org/C2779913896","wikidata":"https://www.wikidata.org/wiki/Q7063001","display_name":"Notice","level":2,"score":0.6359137892723083},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.6104276180267334},{"id":"https://openalex.org/C2777212361","wikidata":"https://www.wikidata.org/wiki/Q5127848","display_name":"Class (philosophy)","level":2,"score":0.4477691948413849},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.4140487611293793},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.3568906784057617},{"id":"https://openalex.org/C199539241","wikidata":"https://www.wikidata.org/wiki/Q7748","display_name":"Law","level":1,"score":0.07010030746459961},{"id":"https://openalex.org/C140331021","wikidata":"https://www.wikidata.org/wiki/Q1868104","display_name":"Logit","level":2,"score":0.0},{"id":"https://openalex.org/C17744445","wikidata":"https://www.wikidata.org/wiki/Q36442","display_name":"Political science","level":0,"score":0.0},{"id":"https://openalex.org/C43617362","wikidata":"https://www.wikidata.org/wiki/Q170050","display_name":"Chromatography","level":1,"score":0.0},{"id":"https://openalex.org/C185592680","wikidata":"https://www.wikidata.org/wiki/Q2329","display_name":"Chemistry","level":0,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/spw54247.2022.9833874","is_oa":false,"landing_page_url":"https://doi.org/10.1109/spw54247.2022.9833874","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2022 IEEE Security and Privacy Workshops (SPW)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16","score":0.8100000023841858}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":49,"referenced_works":["https://openalex.org/W9657784","https://openalex.org/W1901616594","https://openalex.org/W2044911211","https://openalex.org/W2051267297","https://openalex.org/W2108598243","https://openalex.org/W2243397390","https://openalex.org/W2336566325","https://openalex.org/W2572504188","https://openalex.org/W2603766943","https://openalex.org/W2765424254","https://openalex.org/W2770312844","https://openalex.org/W2804935296","https://openalex.org/W2892821018","https://openalex.org/W2919115771","https://openalex.org/W2962061624","https://openalex.org/W2964301649","https://openalex.org/W2965628707","https://openalex.org/W3008276149","https://openalex.org/W3013149459","https://openalex.org/W3015481738","https://openalex.org/W3018295854","https://openalex.org/W3020403113","https://openalex.org/W3034942609","https://openalex.org/W3094984771","https://openalex.org/W3103557498","https://openalex.org/W3103836116","https://openalex.org/W3112340709","https://openalex.org/W3159638252","https://openalex.org/W3168146198","https://openalex.org/W3176065393","https://openalex.org/W3177096435","https://openalex.org/W3208646583","https://openalex.org/W3211999566","https://openalex.org/W3213941669","https://openalex.org/W4220872385","https://openalex.org/W4247200422","https://openalex.org/W4287776850","https://openalex.org/W4287902409","https://openalex.org/W4289549047","https://openalex.org/W4293846201","https://openalex.org/W4298140072","https://openalex.org/W6739868092","https://openalex.org/W6746295503","https://openalex.org/W6750462152","https://openalex.org/W6759424558","https://openalex.org/W6766313860","https://openalex.org/W6773135300","https://openalex.org/W6776865198","https://openalex.org/W6784477419"],"related_works":["https://openalex.org/W4288055406","https://openalex.org/W4200630034","https://openalex.org/W3137894200","https://openalex.org/W3092178728","https://openalex.org/W4226402597","https://openalex.org/W3132910851","https://openalex.org/W4377864639","https://openalex.org/W4392340763","https://openalex.org/W4283325551","https://openalex.org/W4403006689"],"abstract_inverted_index":{"We":[0,131],"propose":[1],"to":[2,34,83],"generate":[3],"adversarial":[4,27,52,60,138],"samples":[5],"by":[6,29,95],"modifying":[7],"activations":[8,33],"of":[9,88,105,136],"upper":[10],"layers":[11],"encoding":[12],"semantically":[13],"meaningful":[14],"concepts.":[15],"The":[16],"original":[17,37,49],"sample":[18,61,71],"is":[19,99],"shifted":[20],"towards":[21],"a":[22,69,122],"target":[23],"sample,":[24,28],"yielding":[25],"an":[26,59],"using":[30],"the":[31,36,48,51,56,134],"modified":[32],"reconstruct":[35],"sample.":[38,53],"A":[39],"human":[40],"might":[41],"(and":[42],"possibly":[43],"should)":[44],"notice":[45],"differences":[46,65],"between":[47],"and":[50,77,110],"Depending":[54],"on":[55,127],"attacker-provided":[57],"constraints,":[58],"can":[62],"exhibit":[63],"subtle":[64],"or":[66],"appear":[67],"like":[68],"\"forged\"":[70],"from":[72],"another":[73],"class.":[74],"Our":[75,97,124],"approach":[76,98],"goal":[78],"are":[79,92,112],"in":[80,114],"stark":[81],"contrast":[82],"common":[84],"attacks":[85],"involving":[86],"perturbations":[87,118],"single":[89],"pixels":[90],"that":[91],"not":[93,120],"recognizable":[94],"humans.":[96],"relevant":[100],"in,":[101],"e.g.,":[102],"multistage":[103],"processing":[104],"inputs,":[106],"where":[107],"both":[108],"humans":[109],"machines":[111],"involved":[113],"decision-making":[115],"because":[116],"invisible":[117],"will":[119],"fool":[121],"human.":[123],"evaluation":[125],"focuses":[126],"deep":[128],"neural":[129],"networks.":[130,141],"also":[132],"show":[133],"transferability":[135],"our":[137],"examples":[139],"among":[140]},"counts_by_year":[{"year":2025,"cited_by_count":2},{"year":2024,"cited_by_count":2},{"year":2023,"cited_by_count":5},{"year":2022,"cited_by_count":2}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
