{"id":"https://openalex.org/W2969285549","doi":"https://doi.org/10.1109/tpami.2019.2936378","title":"Adversarial Attack Type I: Cheat Classifiers by Significant Changes","display_name":"Adversarial Attack Type I: Cheat Classifiers by Significant Changes","publication_year":2019,"publication_date":"2019-08-22","ids":{"openalex":"https://openalex.org/W2969285549","doi":"https://doi.org/10.1109/tpami.2019.2936378","mag":"2969285549","pmid":"https://pubmed.ncbi.nlm.nih.gov/31442970"},"language":"en","primary_location":{"id":"doi:10.1109/tpami.2019.2936378","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tpami.2019.2936378","pdf_url":null,"source":{"id":"https://openalex.org/S199944782","display_name":"IEEE Transactions on Pattern Analysis and Machine Intelligence","issn_l":"0162-8828","issn":["0162-8828","1939-3539","2160-9292"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320439","host_organization_name":"IEEE Computer Society","host_organization_lineage":["https://openalex.org/P4310320439","https://openalex.org/P4310319808"],"host_organization_lineage_names":["IEEE Computer Society","Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Pattern Analysis and Machine Intelligence","raw_type":"journal-article"},"type":"article","indexed_in":["crossref","pubmed"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5056428002","display_name":"Sanli Tang","orcid":null},"institutions":[{"id":"https://openalex.org/I183067930","display_name":"Shanghai Jiao Tong University","ror":"https://ror.org/0220qvk04","country_code":"CN","type":"education","lineage":["https://openalex.org/I183067930"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Sanli Tang","raw_affiliation_strings":["MOE Key Laboratory of System Control and Information Processing, Institute of Image Processing and Pattern Recognition and Institute of Medical Robotics, Shanghai Jiao Tong University, Shanghai, P.R. China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"MOE Key Laboratory of System Control and Information Processing, Institute of Image Processing and Pattern Recognition and Institute of Medical Robotics, Shanghai Jiao Tong University, Shanghai, P.R. China","institution_ids":["https://openalex.org/I183067930"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5026169938","display_name":"Xiaolin Huang","orcid":"https://orcid.org/0000-0003-4285-6520"},"institutions":[{"id":"https://openalex.org/I183067930","display_name":"Shanghai Jiao Tong University","ror":"https://ror.org/0220qvk04","country_code":"CN","type":"education","lineage":["https://openalex.org/I183067930"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Xiaolin Huang","raw_affiliation_strings":["MOE Key Laboratory of System Control and Information Processing, Institute of Image Processing and Pattern Recognition and Institute of Medical Robotics, Shanghai Jiao Tong University, Shanghai, P.R. China"],"raw_orcid":"https://orcid.org/0000-0003-4285-6520","affiliations":[{"raw_affiliation_string":"MOE Key Laboratory of System Control and Information Processing, Institute of Image Processing and Pattern Recognition and Institute of Medical Robotics, Shanghai Jiao Tong University, Shanghai, P.R. China","institution_ids":["https://openalex.org/I183067930"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5013803391","display_name":"Mingjian Chen","orcid":"https://orcid.org/0000-0003-0584-6286"},"institutions":[{"id":"https://openalex.org/I183067930","display_name":"Shanghai Jiao Tong University","ror":"https://ror.org/0220qvk04","country_code":"CN","type":"education","lineage":["https://openalex.org/I183067930"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Mingjian Chen","raw_affiliation_strings":["MOE Key Laboratory of System Control and Information Processing, Institute of Image Processing and Pattern Recognition and Institute of Medical Robotics, Shanghai Jiao Tong University, Shanghai, P.R. China"],"raw_orcid":"https://orcid.org/0000-0003-0584-6286","affiliations":[{"raw_affiliation_string":"MOE Key Laboratory of System Control and Information Processing, Institute of Image Processing and Pattern Recognition and Institute of Medical Robotics, Shanghai Jiao Tong University, Shanghai, P.R. China","institution_ids":["https://openalex.org/I183067930"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5085545406","display_name":"Chengjin Sun","orcid":"https://orcid.org/0000-0002-9992-7919"},"institutions":[{"id":"https://openalex.org/I183067930","display_name":"Shanghai Jiao Tong University","ror":"https://ror.org/0220qvk04","country_code":"CN","type":"education","lineage":["https://openalex.org/I183067930"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Chengjin Sun","raw_affiliation_strings":["MOE Key Laboratory of System Control and Information Processing, Institute of Image Processing and Pattern Recognition and Institute of Medical Robotics, Shanghai Jiao Tong University, Shanghai, P.R. China"],"raw_orcid":"https://orcid.org/0000-0002-9992-7919","affiliations":[{"raw_affiliation_string":"MOE Key Laboratory of System Control and Information Processing, Institute of Image Processing and Pattern Recognition and Institute of Medical Robotics, Shanghai Jiao Tong University, Shanghai, P.R. China","institution_ids":["https://openalex.org/I183067930"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5100404947","display_name":"Jie Yang","orcid":"https://orcid.org/0000-0003-4801-7162"},"institutions":[{"id":"https://openalex.org/I183067930","display_name":"Shanghai Jiao Tong University","ror":"https://ror.org/0220qvk04","country_code":"CN","type":"education","lineage":["https://openalex.org/I183067930"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Jie Yang","raw_affiliation_strings":["MOE Key Laboratory of System Control and Information Processing, Institute of Image Processing and Pattern Recognition and Institute of Medical Robotics, Shanghai Jiao Tong University, Shanghai, P.R. China"],"raw_orcid":"https://orcid.org/0000-0003-4801-7162","affiliations":[{"raw_affiliation_string":"MOE Key Laboratory of System Control and Information Processing, Institute of Image Processing and Pattern Recognition and Institute of Medical Robotics, Shanghai Jiao Tong University, Shanghai, P.R. China","institution_ids":["https://openalex.org/I183067930"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5056428002"],"corresponding_institution_ids":["https://openalex.org/I183067930"],"apc_list":null,"apc_paid":null,"fwci":3.1929,"has_fulltext":false,"cited_by_count":36,"citation_normalized_percentile":{"value":0.93650842,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":90,"max":99},"biblio":{"volume":"43","issue":"3","first_page":"1100","last_page":"1109"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9725000262260437,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.8420075178146362},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.6773460507392883},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.6638994216918945},{"id":"https://openalex.org/keywords/classifier","display_name":"Classifier (UML)","score":0.5872752070426941},{"id":"https://openalex.org/keywords/autoencoder","display_name":"Autoencoder","score":0.5828738808631897},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.5784332752227783},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.5084068179130554},{"id":"https://openalex.org/keywords/type","display_name":"Type (biology)","score":0.5028530955314636},{"id":"https://openalex.org/keywords/pattern-recognition","display_name":"Pattern recognition (psychology)","score":0.47610506415367126}],"concepts":[{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.8420075178146362},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.6773460507392883},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6638994216918945},{"id":"https://openalex.org/C95623464","wikidata":"https://www.wikidata.org/wiki/Q1096149","display_name":"Classifier (UML)","level":2,"score":0.5872752070426941},{"id":"https://openalex.org/C101738243","wikidata":"https://www.wikidata.org/wiki/Q786435","display_name":"Autoencoder","level":3,"score":0.5828738808631897},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.5784332752227783},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.5084068179130554},{"id":"https://openalex.org/C2777299769","wikidata":"https://www.wikidata.org/wiki/Q3707858","display_name":"Type (biology)","level":2,"score":0.5028530955314636},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.47610506415367126},{"id":"https://openalex.org/C18903297","wikidata":"https://www.wikidata.org/wiki/Q7150","display_name":"Ecology","level":1,"score":0.0},{"id":"https://openalex.org/C86803240","wikidata":"https://www.wikidata.org/wiki/Q420","display_name":"Biology","level":0,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1109/tpami.2019.2936378","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tpami.2019.2936378","pdf_url":null,"source":{"id":"https://openalex.org/S199944782","display_name":"IEEE Transactions on Pattern Analysis and Machine Intelligence","issn_l":"0162-8828","issn":["0162-8828","1939-3539","2160-9292"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320439","host_organization_name":"IEEE Computer Society","host_organization_lineage":["https://openalex.org/P4310320439","https://openalex.org/P4310319808"],"host_organization_lineage_names":["IEEE Computer Society","Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Pattern Analysis and Machine Intelligence","raw_type":"journal-article"},{"id":"pmid:31442970","is_oa":false,"landing_page_url":"https://pubmed.ncbi.nlm.nih.gov/31442970","pdf_url":null,"source":{"id":"https://openalex.org/S4306525036","display_name":"PubMed","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I1299303238","host_organization_name":"National Institutes of Health","host_organization_lineage":["https://openalex.org/I1299303238"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE transactions on pattern analysis and machine intelligence","raw_type":null}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G7523228654","display_name":null,"funder_award_id":"61876107","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G8081038515","display_name":null,"funder_award_id":"61977046","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G8555058780","display_name":null,"funder_award_id":"61603248","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"}],"funders":[{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"},{"id":"https://openalex.org/F4320322999","display_name":"Shanghai Jiao Tong University","ror":"https://ror.org/0220qvk04"},{"id":"https://openalex.org/F4320324852","display_name":"Nanjing University","ror":"https://ror.org/01rxvg760"}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":78,"referenced_works":["https://openalex.org/W1522301498","https://openalex.org/W1673923490","https://openalex.org/W1782590233","https://openalex.org/W1834627138","https://openalex.org/W1932198206","https://openalex.org/W1945616565","https://openalex.org/W1959608418","https://openalex.org/W2096733369","https://openalex.org/W2099471712","https://openalex.org/W2108501770","https://openalex.org/W2112796928","https://openalex.org/W2125389028","https://openalex.org/W2163605009","https://openalex.org/W2194775991","https://openalex.org/W2243397390","https://openalex.org/W2271840356","https://openalex.org/W2548275288","https://openalex.org/W2560023338","https://openalex.org/W2605195953","https://openalex.org/W2607219512","https://openalex.org/W2610918198","https://openalex.org/W2612866063","https://openalex.org/W2619371851","https://openalex.org/W2621350877","https://openalex.org/W2754537581","https://openalex.org/W2781800156","https://openalex.org/W2791953061","https://openalex.org/W2884581909","https://openalex.org/W2890591829","https://openalex.org/W2949416428","https://openalex.org/W2950378732","https://openalex.org/W2950776302","https://openalex.org/W2962770929","https://openalex.org/W2963170156","https://openalex.org/W2963178695","https://openalex.org/W2963207607","https://openalex.org/W2963448658","https://openalex.org/W2963542245","https://openalex.org/W2963612069","https://openalex.org/W2963744840","https://openalex.org/W2963753390","https://openalex.org/W2963857521","https://openalex.org/W2963870144","https://openalex.org/W2964082701","https://openalex.org/W2964121744","https://openalex.org/W2964153729","https://openalex.org/W2964238361","https://openalex.org/W2964253222","https://openalex.org/W3099206234","https://openalex.org/W3102720581","https://openalex.org/W4293568373","https://openalex.org/W4293846201","https://openalex.org/W4295274059","https://openalex.org/W4320013936","https://openalex.org/W4383466480","https://openalex.org/W6631190155","https://openalex.org/W6637162671","https://openalex.org/W6640425456","https://openalex.org/W6640963894","https://openalex.org/W6675944832","https://openalex.org/W6678815747","https://openalex.org/W6684191040","https://openalex.org/W6694517276","https://openalex.org/W6729482032","https://openalex.org/W6736155344","https://openalex.org/W6736828813","https://openalex.org/W6737043114","https://openalex.org/W6738597727","https://openalex.org/W6738693630","https://openalex.org/W6739139180","https://openalex.org/W6739868092","https://openalex.org/W6744511767","https://openalex.org/W6747662546","https://openalex.org/W6748347497","https://openalex.org/W6748965907","https://openalex.org/W6753113894","https://openalex.org/W6754438973","https://openalex.org/W6780248173"],"related_works":["https://openalex.org/W3013693939","https://openalex.org/W2159052453","https://openalex.org/W2566616303","https://openalex.org/W3131327266","https://openalex.org/W2734887215","https://openalex.org/W2502115930","https://openalex.org/W4297051394","https://openalex.org/W2752972570","https://openalex.org/W2145836866","https://openalex.org/W4321789545"],"abstract_inverted_index":{"Despite":[0],"the":[1,8,50,53,57,61,70,112,123,129,185,199],"great":[2],"success":[3],"of":[4,26,94,171],"deep":[5],"neural":[6,46],"networks,":[7],"adversarial":[9,27,51,63,88,164],"attack":[10,28,64,95,142,183,208],"can":[11,30,39,175],"cheat":[12,31],"some":[13],"well-trained":[14,45],"classifiers":[15,32],"by":[16,33,127],"small":[17],"permutations.":[18],"In":[19],"this":[20],"paper,":[21],"we":[22,38],"propose":[23],"another":[24],"type":[25,194],"that":[29,153,198],"significant":[34],"changes.":[35],"For":[36],"example,":[37],"significantly":[40],"change":[41],"a":[42,115,192],"face":[43],"but":[44,99],"networks":[47],"still":[48],"recognize":[49],"and":[52,69,85,107,121,158,184,205],"original":[54],"example":[55],"as":[56,82,148],"same":[58],"person.":[59],"Statistically,":[60],"existing":[62],"increases":[65],"Type":[66,75,83,86,140,162,181,203,206],"II":[67,84,182,207],"error":[68],"proposed":[71,113],"one":[72],"aims":[73],"at":[74],"I":[76,87,141,163,204],"error,":[77],"which":[78,103],"are":[79,96,100,104,209],"hence":[80],"named":[81],"attack,":[89,114,195],"respectively.":[90],"The":[91],"two":[92],"types":[93],"equally":[97],"important":[98],"essentially":[101],"different,":[102],"intuitively":[105],"explained":[106],"numerically":[108],"evaluated.":[109],"To":[110],"implement":[111],"supervised":[116],"variation":[117],"autoencoder":[118],"is":[119,125,146,156,188],"designed":[120,178],"then":[122],"classifier":[124],"attacked":[126],"updating":[128],"latent":[130,144],"variables":[131],"using":[132],"gradient":[133],"information.":[134],"Besides,":[135],"with":[136,191],"pre-trained":[137],"generative":[138],"models,":[139],"on":[143,166],"spaces":[145],"investigated":[147],"well.":[149],"Experimental":[150],"results":[151],"show":[152],"our":[154],"method":[155],"practical":[157],"effective":[159],"to":[160],"generate":[161],"examples":[165,174],"large-scale":[167],"image":[168],"datasets.":[169],"Most":[170],"these":[172],"generated":[173],"pass":[176],"detectors":[177],"for":[179,202],"defending":[180],"strengthening":[186],"strategy":[187],"only":[189],"efficient":[190],"specific":[193],"both":[196],"implying":[197],"underlying":[200],"reasons":[201],"different.":[210]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2025,"cited_by_count":4},{"year":2024,"cited_by_count":6},{"year":2023,"cited_by_count":3},{"year":2022,"cited_by_count":2},{"year":2021,"cited_by_count":7},{"year":2020,"cited_by_count":12},{"year":2019,"cited_by_count":1}],"updated_date":"2026-06-05T09:01:59.212387","created_date":"2025-10-10T00:00:00"}
