{"id":"https://openalex.org/W2746559470","doi":"https://doi.org/10.1145/3095713.3095753","title":"Detecting adversarial example attacks to deep neural networks","display_name":"Detecting adversarial example attacks to deep neural networks","publication_year":2017,"publication_date":"2017-06-19","ids":{"openalex":"https://openalex.org/W2746559470","doi":"https://doi.org/10.1145/3095713.3095753","mag":"2746559470"},"language":"en","primary_location":{"id":"doi:10.1145/3095713.3095753","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3095713.3095753","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 15th International Workshop on Content-Based Multimedia Indexing","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":null,"any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5059447545","display_name":"Fabio Carrara","orcid":"https://orcid.org/0000-0001-5014-5089"},"institutions":[{"id":"https://openalex.org/I122991210","display_name":"Istituto di Scienza e Tecnologie dell'Informazione \"Alessandro Faedo\"","ror":"https://ror.org/05kacka20","country_code":"IT","type":"facility","lineage":["https://openalex.org/I122991210","https://openalex.org/I4210155236"]}],"countries":["IT"],"is_corresponding":true,"raw_author_name":"Fabio Carrara","raw_affiliation_strings":["ISTI-CNR, Pisa, Italy"],"affiliations":[{"raw_affiliation_string":"ISTI-CNR, Pisa, Italy","institution_ids":["https://openalex.org/I122991210"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5047189288","display_name":"Fabrizio Falchi","orcid":"https://orcid.org/0000-0001-6258-5313"},"institutions":[{"id":"https://openalex.org/I122991210","display_name":"Istituto di Scienza e Tecnologie dell'Informazione \"Alessandro Faedo\"","ror":"https://ror.org/05kacka20","country_code":"IT","type":"facility","lineage":["https://openalex.org/I122991210","https://openalex.org/I4210155236"]}],"countries":["IT"],"is_corresponding":false,"raw_author_name":"Fabrizio Falchi","raw_affiliation_strings":["ISTI-CNR, Pisa, Italy"],"affiliations":[{"raw_affiliation_string":"ISTI-CNR, Pisa, Italy","institution_ids":["https://openalex.org/I122991210"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5038570344","display_name":"Roberto Caldelli","orcid":"https://orcid.org/0000-0003-3471-1196"},"institutions":[{"id":"https://openalex.org/I45084792","display_name":"University of Florence","ror":"https://ror.org/04jr1s763","country_code":"IT","type":"education","lineage":["https://openalex.org/I45084792"]}],"countries":["IT"],"is_corresponding":false,"raw_author_name":"Roberto Caldelli","raw_affiliation_strings":["CNIT, MICC-University of Florence, Florence, Italy"],"affiliations":[{"raw_affiliation_string":"CNIT, MICC-University of Florence, Florence, Italy","institution_ids":["https://openalex.org/I45084792"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5072396889","display_name":"Giuseppe Amato","orcid":"https://orcid.org/0000-0003-0171-4315"},"institutions":[{"id":"https://openalex.org/I122991210","display_name":"Istituto di Scienza e Tecnologie dell'Informazione \"Alessandro Faedo\"","ror":"https://ror.org/05kacka20","country_code":"IT","type":"facility","lineage":["https://openalex.org/I122991210","https://openalex.org/I4210155236"]}],"countries":["IT"],"is_corresponding":false,"raw_author_name":"Giuseppe Amato","raw_affiliation_strings":["ISTI-CNR, Pisa, Italy"],"affiliations":[{"raw_affiliation_string":"ISTI-CNR, Pisa, Italy","institution_ids":["https://openalex.org/I122991210"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5079601837","display_name":"Roberta Fumarola","orcid":null},"institutions":[{"id":"https://openalex.org/I108290504","display_name":"University of Pisa","ror":"https://ror.org/03ad39j10","country_code":"IT","type":"education","lineage":["https://openalex.org/I108290504"]}],"countries":["IT"],"is_corresponding":false,"raw_author_name":"Roberta Fumarola","raw_affiliation_strings":["University of Pisa, Pisa, Italy"],"affiliations":[{"raw_affiliation_string":"University of Pisa, Pisa, Italy","institution_ids":["https://openalex.org/I108290504"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5069958508","display_name":"Rudy Becarelli","orcid":null},"institutions":[{"id":"https://openalex.org/I45084792","display_name":"University of Florence","ror":"https://ror.org/04jr1s763","country_code":"IT","type":"education","lineage":["https://openalex.org/I45084792"]}],"countries":["IT"],"is_corresponding":false,"raw_author_name":"Rudy Becarelli","raw_affiliation_strings":["MICC-University of Florence, Florence, Italy"],"affiliations":[{"raw_affiliation_string":"MICC-University of Florence, Florence, Italy","institution_ids":["https://openalex.org/I45084792"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":6,"corresponding_author_ids":["https://openalex.org/A5059447545"],"corresponding_institution_ids":["https://openalex.org/I122991210"],"apc_list":null,"apc_paid":null,"fwci":2.5381,"has_fulltext":false,"cited_by_count":33,"citation_normalized_percentile":{"value":0.91885954,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":94,"max":98},"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"7"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9815000295639038,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10036","display_name":"Advanced Neural Network Applications","score":0.9646999835968018,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.84942227602005},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7926836013793945},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.7877686023712158},{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.6785429120063782},{"id":"https://openalex.org/keywords/deep-neural-networks","display_name":"Deep neural networks","score":0.6498075723648071},{"id":"https://openalex.org/keywords/mistake","display_name":"Mistake","score":0.6173322200775146},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.6159777045249939},{"id":"https://openalex.org/keywords/adversarial-machine-learning","display_name":"Adversarial machine learning","score":0.6017693281173706},{"id":"https://openalex.org/keywords/deep-learning","display_name":"Deep learning","score":0.5998266935348511},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.5511330366134644},{"id":"https://openalex.org/keywords/contextual-image-classification","display_name":"Contextual image classification","score":0.5386998057365417},{"id":"https://openalex.org/keywords/illusion","display_name":"Illusion","score":0.4225037097930908},{"id":"https://openalex.org/keywords/pattern-recognition","display_name":"Pattern recognition (psychology)","score":0.40670111775398254},{"id":"https://openalex.org/keywords/image","display_name":"Image (mathematics)","score":0.3954036235809326},{"id":"https://openalex.org/keywords/computer-vision","display_name":"Computer vision","score":0.33613288402557373}],"concepts":[{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.84942227602005},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7926836013793945},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.7877686023712158},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.6785429120063782},{"id":"https://openalex.org/C2984842247","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep neural networks","level":3,"score":0.6498075723648071},{"id":"https://openalex.org/C2777179996","wikidata":"https://www.wikidata.org/wiki/Q911222","display_name":"Mistake","level":2,"score":0.6173322200775146},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.6159777045249939},{"id":"https://openalex.org/C2778403875","wikidata":"https://www.wikidata.org/wiki/Q20312394","display_name":"Adversarial machine learning","level":3,"score":0.6017693281173706},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.5998266935348511},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.5511330366134644},{"id":"https://openalex.org/C75294576","wikidata":"https://www.wikidata.org/wiki/Q5165192","display_name":"Contextual image classification","level":3,"score":0.5386998057365417},{"id":"https://openalex.org/C184047640","wikidata":"https://www.wikidata.org/wiki/Q182593","display_name":"Illusion","level":2,"score":0.4225037097930908},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.40670111775398254},{"id":"https://openalex.org/C115961682","wikidata":"https://www.wikidata.org/wiki/Q860623","display_name":"Image (mathematics)","level":2,"score":0.3954036235809326},{"id":"https://openalex.org/C31972630","wikidata":"https://www.wikidata.org/wiki/Q844240","display_name":"Computer vision","level":1,"score":0.33613288402557373},{"id":"https://openalex.org/C55493867","wikidata":"https://www.wikidata.org/wiki/Q7094","display_name":"Biochemistry","level":1,"score":0.0},{"id":"https://openalex.org/C104317684","wikidata":"https://www.wikidata.org/wiki/Q7187","display_name":"Gene","level":2,"score":0.0},{"id":"https://openalex.org/C185592680","wikidata":"https://www.wikidata.org/wiki/Q2329","display_name":"Chemistry","level":0,"score":0.0},{"id":"https://openalex.org/C169760540","wikidata":"https://www.wikidata.org/wiki/Q207011","display_name":"Neuroscience","level":1,"score":0.0},{"id":"https://openalex.org/C86803240","wikidata":"https://www.wikidata.org/wiki/Q420","display_name":"Biology","level":0,"score":0.0},{"id":"https://openalex.org/C199539241","wikidata":"https://www.wikidata.org/wiki/Q7748","display_name":"Law","level":1,"score":0.0},{"id":"https://openalex.org/C17744445","wikidata":"https://www.wikidata.org/wiki/Q36442","display_name":"Political science","level":0,"score":0.0}],"mesh":[],"locations_count":3,"locations":[{"id":"doi:10.1145/3095713.3095753","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3095713.3095753","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 15th International Workshop on Content-Based Multimedia Indexing","raw_type":"proceedings-article"},{"id":"pmh:oai:arpi.unipi.it:11568/1001439","is_oa":false,"landing_page_url":"http://hdl.handle.net/11568/1001439","pdf_url":null,"source":{"id":"https://openalex.org/S4377196265","display_name":"CINECA IRIS Institutial research information system (University of Pisa)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I108290504","host_organization_name":"University of Pisa","host_organization_lineage":["https://openalex.org/I108290504"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"","raw_type":"info:eu-repo/semantics/conferenceObject"},{"id":"pmh:oai:dnet:people______::555c150eb918fa96ea77e5f64e97601c","is_oa":true,"landing_page_url":null,"pdf_url":null,"source":{"id":"https://openalex.org/S7407055261","display_name":"ISTI Open Portal","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"","raw_type":"Conference article"}],"best_oa_location":{"id":"pmh:oai:dnet:people______::555c150eb918fa96ea77e5f64e97601c","is_oa":true,"landing_page_url":null,"pdf_url":null,"source":{"id":"https://openalex.org/S7407055261","display_name":"ISTI Open Portal","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"","raw_type":"Conference article"},"sustainable_development_goals":[{"score":0.4000000059604645,"id":"https://metadata.un.org/sdg/16","display_name":"Peace, Justice and strong institutions"}],"awards":[],"funders":[{"id":"https://openalex.org/F4320309480","display_name":"Nvidia","ror":"https://ror.org/03jdj4y14"},{"id":"https://openalex.org/F4320326084","display_name":"Regione Toscana","ror":null}],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":39,"referenced_works":["https://openalex.org/W1487583988","https://openalex.org/W1510632636","https://openalex.org/W1673923490","https://openalex.org/W1686810756","https://openalex.org/W1783842908","https://openalex.org/W1883420340","https://openalex.org/W1885185971","https://openalex.org/W1932198206","https://openalex.org/W1945616565","https://openalex.org/W2062118960","https://openalex.org/W2096733369","https://openalex.org/W2097117768","https://openalex.org/W2155541015","https://openalex.org/W2155893237","https://openalex.org/W2163605009","https://openalex.org/W2163922914","https://openalex.org/W2180612164","https://openalex.org/W2194775991","https://openalex.org/W2325939864","https://openalex.org/W2340690086","https://openalex.org/W2412509443","https://openalex.org/W2465870074","https://openalex.org/W2522099755","https://openalex.org/W2543927648","https://openalex.org/W2545300838","https://openalex.org/W2562774313","https://openalex.org/W2564188453","https://openalex.org/W2572787276","https://openalex.org/W2603766943","https://openalex.org/W2605252717","https://openalex.org/W2618098489","https://openalex.org/W2919115771","https://openalex.org/W2963003451","https://openalex.org/W2964082701","https://openalex.org/W3098682680","https://openalex.org/W3099206234","https://openalex.org/W3104180728","https://openalex.org/W4294375521","https://openalex.org/W4300560153"],"related_works":["https://openalex.org/W1590719878","https://openalex.org/W4244271513","https://openalex.org/W2365974527","https://openalex.org/W4306382224","https://openalex.org/W4293350742","https://openalex.org/W2986674980","https://openalex.org/W2768209273","https://openalex.org/W3164364099","https://openalex.org/W4300680808","https://openalex.org/W2620008831"],"abstract_inverted_index":{"Deep":[0],"learning":[1,72],"has":[2],"recently":[3],"become":[4],"the":[5,8,43,62,79,82,86,91],"state":[6],"of":[7,81,93],"art":[9],"in":[10,16,19,106],"many":[11],"computer":[12],"vision":[13],"applications":[14],"and":[15,115],"image":[17],"classification":[18],"particular.":[20],"However,":[21],"recent":[22],"works":[23],"have":[24],"shown":[25],"that":[26,121],"it":[27],"is":[28],"quite":[29],"easy":[30],"to":[31,41,47,61,108,128],"create":[32],"adversarial":[33,116,134],"examples,":[34],"i.e.,":[35],"images":[36,114],"intentionally":[37],"created":[38],"or":[39],"modified":[40],"cause":[42],"deep":[44],"neural":[45,88],"network":[46],"make":[48],"a":[49,67],"mistake.":[50],"They":[51],"are":[52],"like":[53],"optical":[54],"illusions":[55],"for":[56,70,103],"machines":[57],"containing":[58],"changes":[59],"unnoticeable":[60],"human":[63],"eye.":[64],"This":[65],"represents":[66],"serious":[68],"threat":[69],"machine":[71],"methods.":[73],"In":[74],"this":[75],"paper,":[76],"we":[77,98],"investigate":[78],"robustness":[80],"representations":[83],"learned":[84],"by":[85,133],"fooled":[87],"network,":[89],"analyzing":[90],"activations":[92,124],"its":[94],"hidden":[95,122],"layers.":[96],"Specifically,":[97],"tested":[99],"scoring":[100],"approaches":[101],"used":[102,127],"kNN":[104],"classification,":[105],"order":[107],"distinguishing":[109],"between":[110],"correctly":[111],"classified":[112],"authentic":[113],"examples.":[117],"The":[118],"results":[119],"show":[120],"layers":[123],"can":[125],"be":[126],"detect":[129],"incorrect":[130],"classifications":[131],"caused":[132],"attacks.":[135]},"counts_by_year":[{"year":2025,"cited_by_count":2},{"year":2024,"cited_by_count":2},{"year":2023,"cited_by_count":4},{"year":2022,"cited_by_count":6},{"year":2021,"cited_by_count":6},{"year":2020,"cited_by_count":6},{"year":2019,"cited_by_count":5},{"year":2018,"cited_by_count":2}],"updated_date":"2026-03-02T08:37:19.008085","created_date":"2025-10-10T00:00:00"}
