{"id":"https://openalex.org/W4388240301","doi":"https://doi.org/10.1109/tnnls.2023.3326871","title":"Improving Adversarial Robustness Against Universal Patch Attacks Through Feature Norm Suppressing","display_name":"Improving Adversarial Robustness Against Universal Patch Attacks Through Feature Norm Suppressing","publication_year":2023,"publication_date":"2023-11-02","ids":{"openalex":"https://openalex.org/W4388240301","doi":"https://doi.org/10.1109/tnnls.2023.3326871","pmid":"https://pubmed.ncbi.nlm.nih.gov/37917525"},"language":"en","primary_location":{"id":"doi:10.1109/tnnls.2023.3326871","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tnnls.2023.3326871","pdf_url":null,"source":{"id":"https://openalex.org/S4210175523","display_name":"IEEE Transactions on Neural Networks and Learning Systems","issn_l":"2162-237X","issn":["2162-237X","2162-2388"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Neural Networks and Learning Systems","raw_type":"journal-article"},"type":"article","indexed_in":["crossref","pubmed"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5101946981","display_name":"Cheng Yu","orcid":"https://orcid.org/0000-0001-6956-884X"},"institutions":[{"id":"https://openalex.org/I92403157","display_name":"University of Science and Technology Beijing","ror":"https://ror.org/02egmk993","country_code":"CN","type":"education","lineage":["https://openalex.org/I92403157"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Cheng Yu","raw_affiliation_strings":["School of Computer and Communication Engineering, University of Science and Technology Beijing, Beijing, China"],"affiliations":[{"raw_affiliation_string":"School of Computer and Communication Engineering, University of Science and Technology Beijing, Beijing, China","institution_ids":["https://openalex.org/I92403157"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100668653","display_name":"Jiansheng Chen","orcid":"https://orcid.org/0000-0002-2040-7938"},"institutions":[{"id":"https://openalex.org/I92403157","display_name":"University of Science and Technology Beijing","ror":"https://ror.org/02egmk993","country_code":"CN","type":"education","lineage":["https://openalex.org/I92403157"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Jiansheng Chen","raw_affiliation_strings":["School of Computer and Communication Engineering, University of Science and Technology Beijing, Beijing, China"],"affiliations":[{"raw_affiliation_string":"School of Computer and Communication Engineering, University of Science and Technology Beijing, Beijing, China","institution_ids":["https://openalex.org/I92403157"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5052899986","display_name":"Yu Wang","orcid":"https://orcid.org/0000-0002-2931-8958"},"institutions":[{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yu Wang","raw_affiliation_strings":["Department of Electronic Engineering, Tsinghua University, Beijing, China"],"affiliations":[{"raw_affiliation_string":"Department of Electronic Engineering, Tsinghua University, Beijing, China","institution_ids":["https://openalex.org/I99065089"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5015660577","display_name":"Youze Xue","orcid":"https://orcid.org/0000-0002-7054-5204"},"institutions":[{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Youze Xue","raw_affiliation_strings":["Department of Electronic Engineering, Tsinghua University, Beijing, China"],"affiliations":[{"raw_affiliation_string":"Department of Electronic Engineering, Tsinghua University, Beijing, China","institution_ids":["https://openalex.org/I99065089"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5006236325","display_name":"Huimin Ma","orcid":"https://orcid.org/0000-0001-5383-5667"},"institutions":[{"id":"https://openalex.org/I92403157","display_name":"University of Science and Technology Beijing","ror":"https://ror.org/02egmk993","country_code":"CN","type":"education","lineage":["https://openalex.org/I92403157"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Huimin Ma","raw_affiliation_strings":["School of Computer and Communication Engineering, University of Science and Technology Beijing, Beijing, China"],"affiliations":[{"raw_affiliation_string":"School of Computer and Communication Engineering, University of Science and Technology Beijing, Beijing, China","institution_ids":["https://openalex.org/I92403157"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5101946981"],"corresponding_institution_ids":["https://openalex.org/I92403157"],"apc_list":null,"apc_paid":null,"fwci":0.8698,"has_fulltext":false,"cited_by_count":5,"citation_normalized_percentile":{"value":0.79473718,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":90,"max":98},"biblio":{"volume":"36","issue":"1","first_page":"1410","last_page":"1424"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9994999766349792,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9994999766349792,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11515","display_name":"Bacillus and Francisella bacterial research","score":0.9474999904632568,"subfield":{"id":"https://openalex.org/subfields/1312","display_name":"Molecular Biology"},"field":{"id":"https://openalex.org/fields/13","display_name":"Biochemistry, Genetics and Molecular Biology"},"domain":{"id":"https://openalex.org/domains/1","display_name":"Life Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.7399953007698059},{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.6907251477241516},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.5241479873657227},{"id":"https://openalex.org/keywords/norm","display_name":"Norm (philosophy)","score":0.5201242566108704},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.48212265968322754},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.39202016592025757},{"id":"https://openalex.org/keywords/political-science","display_name":"Political science","score":0.13539743423461914},{"id":"https://openalex.org/keywords/chemistry","display_name":"Chemistry","score":0.11151653528213501},{"id":"https://openalex.org/keywords/law","display_name":"Law","score":0.09772324562072754}],"concepts":[{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.7399953007698059},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.6907251477241516},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.5241479873657227},{"id":"https://openalex.org/C191795146","wikidata":"https://www.wikidata.org/wiki/Q3878446","display_name":"Norm (philosophy)","level":2,"score":0.5201242566108704},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.48212265968322754},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.39202016592025757},{"id":"https://openalex.org/C17744445","wikidata":"https://www.wikidata.org/wiki/Q36442","display_name":"Political science","level":0,"score":0.13539743423461914},{"id":"https://openalex.org/C185592680","wikidata":"https://www.wikidata.org/wiki/Q2329","display_name":"Chemistry","level":0,"score":0.11151653528213501},{"id":"https://openalex.org/C199539241","wikidata":"https://www.wikidata.org/wiki/Q7748","display_name":"Law","level":1,"score":0.09772324562072754},{"id":"https://openalex.org/C104317684","wikidata":"https://www.wikidata.org/wiki/Q7187","display_name":"Gene","level":2,"score":0.0},{"id":"https://openalex.org/C55493867","wikidata":"https://www.wikidata.org/wiki/Q7094","display_name":"Biochemistry","level":1,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1109/tnnls.2023.3326871","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tnnls.2023.3326871","pdf_url":null,"source":{"id":"https://openalex.org/S4210175523","display_name":"IEEE Transactions on Neural Networks and Learning Systems","issn_l":"2162-237X","issn":["2162-237X","2162-2388"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Neural Networks and Learning Systems","raw_type":"journal-article"},{"id":"pmid:37917525","is_oa":false,"landing_page_url":"https://pubmed.ncbi.nlm.nih.gov/37917525","pdf_url":null,"source":{"id":"https://openalex.org/S4306525036","display_name":"PubMed","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I1299303238","host_organization_name":"National Institutes of Health","host_organization_lineage":["https://openalex.org/I1299303238"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE transactions on neural networks and learning systems","raw_type":null}],"best_oa_location":null,"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/16","display_name":"Peace, Justice and strong institutions","score":0.6700000166893005}],"awards":[{"id":"https://openalex.org/G2866615195","display_name":null,"funder_award_id":"2022ZD0117902","funder_id":"https://openalex.org/F4320335777","funder_display_name":"National Key Research and Development Program of China"},{"id":"https://openalex.org/G5356393250","display_name":null,"funder_award_id":"U20B2062","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G6979131135","display_name":null,"funder_award_id":"62376024","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"}],"funders":[{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"},{"id":"https://openalex.org/F4320335777","display_name":"National Key Research and Development Program of China","ror":null}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":53,"referenced_works":["https://openalex.org/W1861492603","https://openalex.org/W2037227137","https://openalex.org/W2097117768","https://openalex.org/W2194775991","https://openalex.org/W2535873859","https://openalex.org/W2891828758","https://openalex.org/W2900770941","https://openalex.org/W2902867332","https://openalex.org/W2962872506","https://openalex.org/W2963163009","https://openalex.org/W2963178695","https://openalex.org/W2963302614","https://openalex.org/W2963726920","https://openalex.org/W2964049407","https://openalex.org/W2990237009","https://openalex.org/W3016193692","https://openalex.org/W3017485054","https://openalex.org/W3034643863","https://openalex.org/W3036321094","https://openalex.org/W3097573595","https://openalex.org/W3107990944","https://openalex.org/W3110012676","https://openalex.org/W3113588330","https://openalex.org/W3196107314","https://openalex.org/W3202052293","https://openalex.org/W3205945722","https://openalex.org/W3210016964","https://openalex.org/W3212077589","https://openalex.org/W4221166007","https://openalex.org/W4226232092","https://openalex.org/W4293846201","https://openalex.org/W4307965990","https://openalex.org/W6640425456","https://openalex.org/W6684191040","https://openalex.org/W6729983426","https://openalex.org/W6747706139","https://openalex.org/W6748475379","https://openalex.org/W6750227808","https://openalex.org/W6750584122","https://openalex.org/W6751839145","https://openalex.org/W6753468839","https://openalex.org/W6754363872","https://openalex.org/W6759129252","https://openalex.org/W6765410593","https://openalex.org/W6767506513","https://openalex.org/W6772291365","https://openalex.org/W6774113373","https://openalex.org/W6784545786","https://openalex.org/W6788444534","https://openalex.org/W6790438916","https://openalex.org/W6790727609","https://openalex.org/W6792389622","https://openalex.org/W6804598780"],"related_works":["https://openalex.org/W2502115930","https://openalex.org/W4246396837","https://openalex.org/W2482350142","https://openalex.org/W3176240006","https://openalex.org/W3126451824","https://openalex.org/W1561927205","https://openalex.org/W3191453585","https://openalex.org/W4297672492","https://openalex.org/W4288019534","https://openalex.org/W4310988119"],"abstract_inverted_index":{"Universal":[0],"adversarial":[1,68,112,142,274],"patch":[2,113,143,151],"attacks,":[3,114],"which":[4,192],"are":[5,38,73],"readily":[6],"implemented,":[7],"have":[8],"been":[9],"validated":[10],"to":[11,14,26,75,79,87,214],"be":[12,76,207],"able":[13],"fool":[15],"real-world":[16],"deep":[17],"convolutional":[18],"neural":[19],"networks":[20,85],"(CNNs),":[21],"posing":[22],"a":[23,168,179,202,277],"serious":[24],"threat":[25],"practical":[27,84],"computer":[28],"vision":[29],"systems":[30],"based":[31,66],"on":[32,62,67,96,105,120,128,145,175,273,281],"CNNs.":[33],"Unfortunately,":[34],"current":[35],"defending":[36,183,243,271],"approaches":[37],"severely":[39],"understudied":[40],"facing":[41],"the":[42,97,116,124,137,141,150,186,195,219,252,282],"following":[43],"problems.":[44],"Patch":[45],"detection-based":[46],"methods":[47,272],"suffer":[48],"from":[49],"dramatic":[50],"performance":[51,283],"drops":[52],"against":[53,251],"white-box":[54,255],"or":[55,70,82,92],"adaptive":[56,254],"attacks":[57,256],"since":[58],"they":[59],"rely":[60],"heavily":[61],"empirical":[63],"clues.":[64],"Methods":[65],"training":[69],"certified":[71],"defense":[72],"difficult":[74],"scaled":[77],"up":[78],"large-scale":[80],"datasets":[81,250],"complex":[83],"due":[86],"prohibitively":[88],"high":[89],"computational":[90,237],"overhead":[91],"over":[93],"strong":[94,253],"assumptions":[95],"network":[98],"structure.":[99],"In":[100,264],"this":[101,172],"article,":[102],"we":[103,177],"focus":[104],"two":[106],"cases":[107],"of":[108,140,218,221,284],"widely":[109],"adopted":[110],"universal":[111,117,125],"namely":[115],"targeted":[118],"attack":[119,127],"image":[121],"classifiers":[122,157],"and":[123,158,165,234,249,261],"vanishing":[126],"object":[129],"detectors.":[130],"We":[131,239],"find":[132],"that,":[133],"for":[134,171],"popular":[135],"CNNs,":[136],"attacking":[138],"success":[139],"relies":[144],"feature":[146,187,196,224],"vectors":[147],"centered":[148],"at":[149,290],"location":[152],"with":[153,230,276],"large":[154,159,222],"norm":[155,161,188,197,223],"in":[156,163,210,257],"channel-aware":[160],"(CA-Norm)":[162],"detectors,":[164],"further":[166],"present":[167],"mathematical":[169],"explanation":[170],"phenomenon.":[173],"Based":[174],"this,":[176],"propose":[178],"simple":[180],"but":[181],"effective":[182],"method":[184,244],"using":[185],"suppressing":[189],"(FNS)":[190],"layer,":[191],"can":[193,206],"renormalize":[194],"by":[198],"nonincreasing":[199],"functions.":[200],"As":[201],"differentiable":[203],"module,":[204],"FNS":[205,227,267],"adaptively":[208],"inserted":[209],"various":[211],"CNN":[212,247],"architectures":[213,248],"achieve":[215],"multistage":[216],"suppression":[217],"generation":[220],"vectors.":[225],"Moreover,":[226],"is":[228,288],"efficient":[229],"no":[231],"trainable":[232],"parameters":[233],"very":[235],"low":[236,279],"overhead.":[238],"evaluate":[240],"our":[241],"proposed":[242],"across":[245],"multiple":[246],"both":[258,265],"visual":[259],"classification":[260],"detection":[262],"tasks.":[263],"tasks,":[266],"significantly":[268],"outperforms":[269],"previous":[270],"robustness":[275],"relatively":[278],"influence":[280],"benign":[285],"images.":[286],"Code":[287],"available":[289],"https://github.com/jschenthu/FNS.":[291]},"counts_by_year":[{"year":2025,"cited_by_count":4},{"year":2024,"cited_by_count":1}],"updated_date":"2026-03-27T05:58:40.876381","created_date":"2025-10-10T00:00:00"}
