{"id":"https://openalex.org/W4394994638","doi":"https://doi.org/10.1109/tnnls.2024.3386642","title":"On the Robustness of Bayesian Neural Networks to Adversarial Attacks","display_name":"On the Robustness of Bayesian Neural Networks to Adversarial Attacks","publication_year":2024,"publication_date":"2024-04-22","ids":{"openalex":"https://openalex.org/W4394994638","doi":"https://doi.org/10.1109/tnnls.2024.3386642","pmid":"https://pubmed.ncbi.nlm.nih.gov/38648123"},"language":"en","primary_location":{"id":"doi:10.1109/tnnls.2024.3386642","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tnnls.2024.3386642","pdf_url":null,"source":{"id":"https://openalex.org/S4210175523","display_name":"IEEE Transactions on Neural Networks and Learning Systems","issn_l":"2162-237X","issn":["2162-237X","2162-2388"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Neural Networks and Learning Systems","raw_type":"journal-article"},"type":"article","indexed_in":["crossref","pubmed"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5060744592","display_name":"Luca Bortolussi","orcid":"https://orcid.org/0000-0001-8874-4001"},"institutions":[{"id":"https://openalex.org/I142444530","display_name":"University of Trieste","ror":"https://ror.org/02n742c10","country_code":"IT","type":"education","lineage":["https://openalex.org/I142444530"]}],"countries":["IT"],"is_corresponding":true,"raw_author_name":"Luca Bortolussi","raw_affiliation_strings":["Department of Mathematics, Informatics and Geosciences, University of Trieste, Trieste, Italy"],"affiliations":[{"raw_affiliation_string":"Department of Mathematics, Informatics and Geosciences, University of Trieste, Trieste, Italy","institution_ids":["https://openalex.org/I142444530"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5062861547","display_name":"Ginevra Carbone","orcid":"https://orcid.org/0000-0001-7532-6249"},"institutions":[{"id":"https://openalex.org/I142444530","display_name":"University of Trieste","ror":"https://ror.org/02n742c10","country_code":"IT","type":"education","lineage":["https://openalex.org/I142444530"]}],"countries":["IT"],"is_corresponding":false,"raw_author_name":"Ginevra Carbone","raw_affiliation_strings":["Department of Mathematics and Geosciences, University of Trieste, Trieste, Italy"],"affiliations":[{"raw_affiliation_string":"Department of Mathematics and Geosciences, University of Trieste, Trieste, Italy","institution_ids":["https://openalex.org/I142444530"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5009660282","display_name":"Luca Laurenti","orcid":"https://orcid.org/0000-0003-1190-6097"},"institutions":[{"id":"https://openalex.org/I98358874","display_name":"Delft University of Technology","ror":"https://ror.org/02e2c7k09","country_code":"NL","type":"education","lineage":["https://openalex.org/I98358874"]}],"countries":["NL"],"is_corresponding":false,"raw_author_name":"Luca Laurenti","raw_affiliation_strings":["Delft Center for Systems and Control, TU Delft University, Delft, The Netherlands"],"affiliations":[{"raw_affiliation_string":"Delft Center for Systems and Control, TU Delft University, Delft, The Netherlands","institution_ids":["https://openalex.org/I98358874"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5003864062","display_name":"Andrea Patan\u00e8","orcid":"https://orcid.org/0000-0003-0492-4860"},"institutions":[{"id":"https://openalex.org/I205274468","display_name":"Trinity College Dublin","ror":"https://ror.org/02tyrky19","country_code":"IE","type":"education","lineage":["https://openalex.org/I205274468"]}],"countries":["IE"],"is_corresponding":false,"raw_author_name":"Andrea Patane","raw_affiliation_strings":["School of Computer Science and Statistics, Trinity College, Dublin, Ireland"],"affiliations":[{"raw_affiliation_string":"School of Computer Science and Statistics, Trinity College, Dublin, Ireland","institution_ids":["https://openalex.org/I205274468"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5017674487","display_name":"Guido Sanguinetti","orcid":"https://orcid.org/0000-0002-6663-8336"},"institutions":[{"id":"https://openalex.org/I138549579","display_name":"Scuola Internazionale Superiore di Studi Avanzati","ror":"https://ror.org/004fze387","country_code":"IT","type":"education","lineage":["https://openalex.org/I138549579"]}],"countries":["IT"],"is_corresponding":false,"raw_author_name":"Guido Sanguinetti","raw_affiliation_strings":["SISSA, International School for Advanced Studies, Trieste, Italy"],"affiliations":[{"raw_affiliation_string":"SISSA, International School for Advanced Studies, Trieste, Italy","institution_ids":["https://openalex.org/I138549579"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5006299169","display_name":"Matthew Wicker","orcid":"https://orcid.org/0000-0003-0779-3114"},"institutions":[{"id":"https://openalex.org/I40120149","display_name":"University of Oxford","ror":"https://ror.org/052gg0110","country_code":"GB","type":"education","lineage":["https://openalex.org/I40120149"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"Matthew Wicker","raw_affiliation_strings":["Department of Computer Science, University of Oxford, Oxford, U.K"],"affiliations":[{"raw_affiliation_string":"Department of Computer Science, University of Oxford, Oxford, U.K","institution_ids":["https://openalex.org/I40120149"]}]}],"institutions":[],"countries_distinct_count":4,"institutions_distinct_count":6,"corresponding_author_ids":["https://openalex.org/A5060744592"],"corresponding_institution_ids":["https://openalex.org/I142444530"],"apc_list":null,"apc_paid":null,"fwci":3.0883,"has_fulltext":false,"cited_by_count":10,"citation_normalized_percentile":{"value":0.92200312,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":90,"max":99},"biblio":{"volume":"36","issue":"4","first_page":"6679","last_page":"6692"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9991000294685364,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9991000294685364,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10876","display_name":"Fault Detection and Control Systems","score":0.9715999960899353,"subfield":{"id":"https://openalex.org/subfields/2207","display_name":"Control and Systems Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9513999819755554,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.7721582055091858},{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.738568902015686},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.6012145280838013},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.5902900695800781},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.5826619267463684},{"id":"https://openalex.org/keywords/deep-neural-networks","display_name":"Deep neural networks","score":0.5473591685295105},{"id":"https://openalex.org/keywords/bayesian-probability","display_name":"Bayesian probability","score":0.508915901184082},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.44378992915153503},{"id":"https://openalex.org/keywords/biology","display_name":"Biology","score":0.06725570559501648}],"concepts":[{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.7721582055091858},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.738568902015686},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6012145280838013},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5902900695800781},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.5826619267463684},{"id":"https://openalex.org/C2984842247","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep neural networks","level":3,"score":0.5473591685295105},{"id":"https://openalex.org/C107673813","wikidata":"https://www.wikidata.org/wiki/Q812534","display_name":"Bayesian probability","level":2,"score":0.508915901184082},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.44378992915153503},{"id":"https://openalex.org/C86803240","wikidata":"https://www.wikidata.org/wiki/Q420","display_name":"Biology","level":0,"score":0.06725570559501648},{"id":"https://openalex.org/C104317684","wikidata":"https://www.wikidata.org/wiki/Q7187","display_name":"Gene","level":2,"score":0.0},{"id":"https://openalex.org/C55493867","wikidata":"https://www.wikidata.org/wiki/Q7094","display_name":"Biochemistry","level":1,"score":0.0}],"mesh":[],"locations_count":3,"locations":[{"id":"doi:10.1109/tnnls.2024.3386642","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tnnls.2024.3386642","pdf_url":null,"source":{"id":"https://openalex.org/S4210175523","display_name":"IEEE Transactions on Neural Networks and Learning Systems","issn_l":"2162-237X","issn":["2162-237X","2162-2388"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Neural Networks and Learning Systems","raw_type":"journal-article"},{"id":"pmid:38648123","is_oa":false,"landing_page_url":"https://pubmed.ncbi.nlm.nih.gov/38648123","pdf_url":null,"source":{"id":"https://openalex.org/S4306525036","display_name":"PubMed","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I1299303238","host_organization_name":"National Institutes of Health","host_organization_lineage":["https://openalex.org/I1299303238"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE transactions on neural networks and learning systems","raw_type":null},{"id":"pmh:oai:arts.units.it:11368/3098643","is_oa":false,"landing_page_url":"https://ieeexplore.ieee.org/document/10506195","pdf_url":null,"source":{"id":"https://openalex.org/S4306400480","display_name":"ArTS Archivio della ricerca di Trieste (University of Trieste https://www.units.it/)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I142444530","host_organization_name":"University of Trieste","host_organization_lineage":["https://openalex.org/I142444530"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"info:eu-repo/semantics/article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":69,"referenced_works":["https://openalex.org/W1590183771","https://openalex.org/W1988115241","https://openalex.org/W2048209332","https://openalex.org/W2103496339","https://openalex.org/W2242047860","https://openalex.org/W2891828758","https://openalex.org/W2942228371","https://openalex.org/W2954040150","https://openalex.org/W2963160885","https://openalex.org/W2963178695","https://openalex.org/W2963857521","https://openalex.org/W2965020757","https://openalex.org/W2987644081","https://openalex.org/W2994588524","https://openalex.org/W3000508506","https://openalex.org/W3048300167","https://openalex.org/W3082871683","https://openalex.org/W3089426421","https://openalex.org/W3092552955","https://openalex.org/W3157646289","https://openalex.org/W3158154410","https://openalex.org/W3208910075","https://openalex.org/W3212073575","https://openalex.org/W4211049957","https://openalex.org/W4234910518","https://openalex.org/W4301880089","https://openalex.org/W4327522024","https://openalex.org/W4367834757","https://openalex.org/W4385731908","https://openalex.org/W6637162671","https://openalex.org/W6640425456","https://openalex.org/W6734483310","https://openalex.org/W6738915422","https://openalex.org/W6739868092","https://openalex.org/W6743688258","https://openalex.org/W6745256532","https://openalex.org/W6746396516","https://openalex.org/W6746868464","https://openalex.org/W6748475379","https://openalex.org/W6748724315","https://openalex.org/W6748799766","https://openalex.org/W6749731802","https://openalex.org/W6753245824","https://openalex.org/W6753275298","https://openalex.org/W6754553897","https://openalex.org/W6754762128","https://openalex.org/W6754796414","https://openalex.org/W6755310938","https://openalex.org/W6755678156","https://openalex.org/W6756713613","https://openalex.org/W6757359751","https://openalex.org/W6758352740","https://openalex.org/W6758508162","https://openalex.org/W6758854563","https://openalex.org/W6761839128","https://openalex.org/W6764214684","https://openalex.org/W6768793533","https://openalex.org/W6773684732","https://openalex.org/W6775502286","https://openalex.org/W6779637821","https://openalex.org/W6779823587","https://openalex.org/W6786576763","https://openalex.org/W6787783885","https://openalex.org/W6790372297","https://openalex.org/W6793233199","https://openalex.org/W6795988206","https://openalex.org/W6803265846","https://openalex.org/W6842469858","https://openalex.org/W6966866225"],"related_works":["https://openalex.org/W2950183588","https://openalex.org/W3080754722","https://openalex.org/W4383221314","https://openalex.org/W3093978547","https://openalex.org/W2953536436","https://openalex.org/W3203790781","https://openalex.org/W4313346231","https://openalex.org/W2738001131","https://openalex.org/W4285785480","https://openalex.org/W2997056298"],"abstract_inverted_index":{"Vulnerability":[0],"to":[1,10,31,65,106,119,139,201],"adversarial":[2,32,47,108,206],"attacks":[3,33,48,67],"is":[4,34,144],"one":[5],"of":[6,13,46,72,88,116,134,185],"the":[7,11,44,50,62,75,80,89,114,131,135,140,152,164],"principal":[8],"hurdles":[9],"adoption":[12],"deep":[14,27],"learning":[15,28],"in":[16,49,61,74,99],"safety-critical":[17],"applications.":[18],"Despite":[19],"significant":[20],"efforts,":[21],"both":[22,193,202],"practical":[23],"and":[24,168,179,199,204],"theoretical,":[25],"training":[26],"models":[29],"robust":[30,105],"still":[35],"an":[36],"open":[37],"problem.":[38],"In":[39],"this":[40,100,183],"article,":[41],"we":[42,96,123],"analyse":[43],"geometry":[45],"over-parameterized":[51],"limit":[52],"for":[53],"Bayesian":[54],"neural":[55],"networks":[56],"(BNNs).":[57],"We":[58],"show":[59],"that,":[60,125],"limit,":[63,101],"vulnerability":[64],"gradient-based":[66,107,203],"arises":[68],"as":[69],"a":[70,84,93,169],"result":[71],"degeneracy":[73],"data":[76,81,198],"distribution,":[77],"i.e.,":[78],"when":[79,147],"lie":[82],"on":[83,113,163,196],"lower":[85],"dimensional":[86],"submanifold":[87],"ambient":[90],"space.":[91],"As":[92],"direct":[94],"consequence,":[95],"demonstrate":[97],"that":[98,189],"BNN":[102,141,153],"posteriors":[103],"are":[104],"attacks.":[109,207],"Crucially,":[110],"by":[111],"relying":[112],"convergence":[115],"infinitely-wide":[117],"BNNs":[118,173,190],"Gaussian":[120],"processes":[121],"(GPs),":[122],"prove":[124],"under":[126],"certain":[127],"relatively":[128],"mild":[129],"assumptions,":[130],"expected":[132],"gradient":[133],"loss":[136],"with":[137,172,175],"respect":[138],"posterior":[142,154],"distribution":[143],"vanishing,":[145],"even":[146],"each":[148],"NN":[149],"sampled":[150],"from":[151],"does":[155],"not":[156],"have":[157],"vanishing":[158],"gradients.":[159],"The":[160],"experimental":[161],"results":[162],"MNIST,":[165,167],"Fashion":[166],"synthetic":[170],"dataset":[171],"trained":[174],"Hamiltonian":[176],"Monte":[177],"Carlo":[178],"variational":[180],"inference":[181],"support":[182],"line":[184],"arguments,":[186],"empirically":[187],"showing":[188],"can":[191],"display":[192],"high":[194],"accuracy":[195],"clean":[197],"robustness":[200],"gradient-free":[205]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2025,"cited_by_count":6},{"year":2024,"cited_by_count":2},{"year":2022,"cited_by_count":1}],"updated_date":"2026-04-07T14:57:38.498316","created_date":"2025-10-10T00:00:00"}
