{"id":"https://openalex.org/W3092991443","doi":"https://doi.org/10.1145/3394171.3413898","title":"DIPDefend: Deep Image Prior Driven Defense against Adversarial Examples","display_name":"DIPDefend: Deep Image Prior Driven Defense against Adversarial Examples","publication_year":2020,"publication_date":"2020-10-12","ids":{"openalex":"https://openalex.org/W3092991443","doi":"https://doi.org/10.1145/3394171.3413898","mag":"3092991443"},"language":"en","primary_location":{"id":"doi:10.1145/3394171.3413898","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3394171.3413898","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 28th ACM International Conference on Multimedia","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5023762528","display_name":"Tao Dai","orcid":"https://orcid.org/0000-0003-0594-6404"},"institutions":[{"id":"https://openalex.org/I4210136793","display_name":"Peng Cheng Laboratory","ror":"https://ror.org/03qdqbt06","country_code":"CN","type":"facility","lineage":["https://openalex.org/I4210136793"]},{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Tao Dai","raw_affiliation_strings":["Tsinghua University &amp; Peng Cheng Laboratory, Shenzhen, China"],"affiliations":[{"raw_affiliation_string":"Tsinghua University &amp; Peng Cheng Laboratory, Shenzhen, China","institution_ids":["https://openalex.org/I4210136793","https://openalex.org/I99065089"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101786091","display_name":"Yan Feng","orcid":"https://orcid.org/0000-0002-4601-4593"},"institutions":[{"id":"https://openalex.org/I4210136793","display_name":"Peng Cheng Laboratory","ror":"https://ror.org/03qdqbt06","country_code":"CN","type":"facility","lineage":["https://openalex.org/I4210136793"]},{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yan Feng","raw_affiliation_strings":["Tsinghua University &amp; Peng Cheng Laboratory, Shenzhen, China"],"affiliations":[{"raw_affiliation_string":"Tsinghua University &amp; Peng Cheng Laboratory, Shenzhen, China","institution_ids":["https://openalex.org/I4210136793","https://openalex.org/I99065089"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5052115680","display_name":"Dongxian Wu","orcid":null},"institutions":[{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]},{"id":"https://openalex.org/I4210136793","display_name":"Peng Cheng Laboratory","ror":"https://ror.org/03qdqbt06","country_code":"CN","type":"facility","lineage":["https://openalex.org/I4210136793"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Dongxian Wu","raw_affiliation_strings":["Tsinghua University &amp; Peng Cheng Laboratory, Shenzhen, China"],"affiliations":[{"raw_affiliation_string":"Tsinghua University &amp; Peng Cheng Laboratory, Shenzhen, China","institution_ids":["https://openalex.org/I4210136793","https://openalex.org/I99065089"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100427335","display_name":"Bin Chen","orcid":"https://orcid.org/0000-0002-3979-021X"},"institutions":[{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]},{"id":"https://openalex.org/I4210136793","display_name":"Peng Cheng Laboratory","ror":"https://ror.org/03qdqbt06","country_code":"CN","type":"facility","lineage":["https://openalex.org/I4210136793"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Bin Chen","raw_affiliation_strings":["Tsinghua University &amp; Peng Cheng Laboratory, Shenzhen, China"],"affiliations":[{"raw_affiliation_string":"Tsinghua University &amp; Peng Cheng Laboratory, Shenzhen, China","institution_ids":["https://openalex.org/I4210136793","https://openalex.org/I99065089"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5066196985","display_name":"Jian L\u00fc","orcid":"https://orcid.org/0000-0003-4599-7281"},"institutions":[{"id":"https://openalex.org/I180726961","display_name":"Shenzhen University","ror":"https://ror.org/01vy4gh70","country_code":"CN","type":"education","lineage":["https://openalex.org/I180726961"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Jian Lu","raw_affiliation_strings":["Shenzhen University, Shenzhen, China"],"affiliations":[{"raw_affiliation_string":"Shenzhen University, Shenzhen, China","institution_ids":["https://openalex.org/I180726961"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101626204","display_name":"Yong Jiang","orcid":"https://orcid.org/0000-0002-4260-1395"},"institutions":[{"id":"https://openalex.org/I4210136793","display_name":"Peng Cheng Laboratory","ror":"https://ror.org/03qdqbt06","country_code":"CN","type":"facility","lineage":["https://openalex.org/I4210136793"]},{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yong Jiang","raw_affiliation_strings":["Tsinghua University &amp; Peng Cheng Laboratory, Shenzhen, China"],"affiliations":[{"raw_affiliation_string":"Tsinghua University &amp; Peng Cheng Laboratory, Shenzhen, China","institution_ids":["https://openalex.org/I4210136793","https://openalex.org/I99065089"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5034104790","display_name":"Shu\u2010Tao Xia","orcid":"https://orcid.org/0000-0002-8639-982X"},"institutions":[{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]},{"id":"https://openalex.org/I4210136793","display_name":"Peng Cheng Laboratory","ror":"https://ror.org/03qdqbt06","country_code":"CN","type":"facility","lineage":["https://openalex.org/I4210136793"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Shu-Tao Xia","raw_affiliation_strings":["Tsinghua University &amp; Peng Cheng Laboratory, Shenzhen, China"],"affiliations":[{"raw_affiliation_string":"Tsinghua University &amp; Peng Cheng Laboratory, Shenzhen, China","institution_ids":["https://openalex.org/I4210136793","https://openalex.org/I99065089"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":7,"corresponding_author_ids":["https://openalex.org/A5023762528"],"corresponding_institution_ids":["https://openalex.org/I4210136793","https://openalex.org/I99065089"],"apc_list":null,"apc_paid":null,"fwci":1.9884,"has_fulltext":false,"cited_by_count":20,"citation_normalized_percentile":{"value":0.8926333,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":91,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"1404","last_page":"1412"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11515","display_name":"Bacillus and Francisella bacterial research","score":0.9369000196456909,"subfield":{"id":"https://openalex.org/subfields/1312","display_name":"Molecular Biology"},"field":{"id":"https://openalex.org/fields/13","display_name":"Biochemistry, Genetics and Molecular Biology"},"domain":{"id":"https://openalex.org/domains/1","display_name":"Life Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.8607069253921509},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7021552324295044},{"id":"https://openalex.org/keywords/prior-probability","display_name":"Prior probability","score":0.6915052533149719},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.6844028830528259},{"id":"https://openalex.org/keywords/image","display_name":"Image (mathematics)","score":0.5782511830329895},{"id":"https://openalex.org/keywords/deep-neural-networks","display_name":"Deep neural networks","score":0.5431297421455383},{"id":"https://openalex.org/keywords/deep-learning","display_name":"Deep learning","score":0.5083569884300232},{"id":"https://openalex.org/keywords/generalization","display_name":"Generalization","score":0.47309020161628723},{"id":"https://openalex.org/keywords/black-box","display_name":"Black box","score":0.4650486707687378},{"id":"https://openalex.org/keywords/generator","display_name":"Generator (circuit theory)","score":0.43368983268737793},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.4246056079864502},{"id":"https://openalex.org/keywords/pattern-recognition","display_name":"Pattern recognition (psychology)","score":0.40897852182388306},{"id":"https://openalex.org/keywords/bayesian-probability","display_name":"Bayesian probability","score":0.20510908961296082},{"id":"https://openalex.org/keywords/mathematics","display_name":"Mathematics","score":0.1596410870552063}],"concepts":[{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.8607069253921509},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7021552324295044},{"id":"https://openalex.org/C177769412","wikidata":"https://www.wikidata.org/wiki/Q278090","display_name":"Prior probability","level":3,"score":0.6915052533149719},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.6844028830528259},{"id":"https://openalex.org/C115961682","wikidata":"https://www.wikidata.org/wiki/Q860623","display_name":"Image (mathematics)","level":2,"score":0.5782511830329895},{"id":"https://openalex.org/C2984842247","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep neural networks","level":3,"score":0.5431297421455383},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.5083569884300232},{"id":"https://openalex.org/C177148314","wikidata":"https://www.wikidata.org/wiki/Q170084","display_name":"Generalization","level":2,"score":0.47309020161628723},{"id":"https://openalex.org/C94966114","wikidata":"https://www.wikidata.org/wiki/Q29256","display_name":"Black box","level":2,"score":0.4650486707687378},{"id":"https://openalex.org/C2780992000","wikidata":"https://www.wikidata.org/wiki/Q17016113","display_name":"Generator (circuit theory)","level":3,"score":0.43368983268737793},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.4246056079864502},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.40897852182388306},{"id":"https://openalex.org/C107673813","wikidata":"https://www.wikidata.org/wiki/Q812534","display_name":"Bayesian probability","level":2,"score":0.20510908961296082},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.1596410870552063},{"id":"https://openalex.org/C163258240","wikidata":"https://www.wikidata.org/wiki/Q25342","display_name":"Power (physics)","level":2,"score":0.0},{"id":"https://openalex.org/C121332964","wikidata":"https://www.wikidata.org/wiki/Q413","display_name":"Physics","level":0,"score":0.0},{"id":"https://openalex.org/C62520636","wikidata":"https://www.wikidata.org/wiki/Q944","display_name":"Quantum mechanics","level":1,"score":0.0},{"id":"https://openalex.org/C134306372","wikidata":"https://www.wikidata.org/wiki/Q7754","display_name":"Mathematical analysis","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3394171.3413898","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3394171.3413898","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 28th ACM International Conference on Multimedia","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":22,"referenced_works":["https://openalex.org/W2096761004","https://openalex.org/W2163605009","https://openalex.org/W2180612164","https://openalex.org/W2243397390","https://openalex.org/W2302255633","https://openalex.org/W2765233338","https://openalex.org/W2774018344","https://openalex.org/W2774644650","https://openalex.org/W2787496614","https://openalex.org/W2787708942","https://openalex.org/W2954930822","https://openalex.org/W2963207607","https://openalex.org/W2963383962","https://openalex.org/W2963542245","https://openalex.org/W2963857521","https://openalex.org/W2964013315","https://openalex.org/W2964082701","https://openalex.org/W2964449891","https://openalex.org/W2969542116","https://openalex.org/W2982374186","https://openalex.org/W2985987886","https://openalex.org/W4292516927"],"related_works":["https://openalex.org/W4225493432","https://openalex.org/W2963115223","https://openalex.org/W3123881320","https://openalex.org/W2897842727","https://openalex.org/W4379255972","https://openalex.org/W4320076403","https://openalex.org/W2963448658","https://openalex.org/W4383955378","https://openalex.org/W2783555701","https://openalex.org/W4282024860"],"abstract_inverted_index":{"Deep":[0,89],"neural":[1],"networks":[2],"(DNNs)":[3],"have":[4],"shown":[5],"serious":[6],"vulnerability":[7],"to":[8,14,103,134,145,159,180],"adversarial":[9,59,97,135,146,175,200],"examples":[10,60],"with":[11,61],"imperceptible":[12],"perturbation":[13],"clean":[15],"images.":[16,161],"Most":[17],"existing":[18],"input-transformation":[19],"based":[20],"defense":[21,55,194],"methods":[22,195],"(e.g.,":[23],"ComDefend)":[24],"rely":[25],"heavily":[26],"on":[27],"the":[28,40,46,51,54,58,66,105,125,130,165,186,192],"learned":[29],"external":[30,34,67],"priors":[31,44],"from":[32,65,81,119],"an":[33,87,151],"large":[35],"training":[36,68],"dataset,":[37],"while":[38],"neglecting":[39],"rich":[41,78],"image":[42,63,73,79,112],"internal":[43],"of":[45,53,188],"input":[47],"itself,":[48],"thus":[49,177],"limiting":[50],"generalization":[52],"models":[56],"against":[57,96,196],"biased":[62],"statistics":[64,80],"dataset.":[69],"Motivated":[70],"by":[71,138],"deep":[72],"prior":[74],"that":[75,110,142,155],"can":[76],"capture":[77],"a":[82,100,120,169],"single":[83],"image,":[84],"we":[85,108,149],"propose":[86],"effective":[88],"Image":[90],"Prior":[91],"Driven":[92],"Defense":[93],"(DIPDefend)":[94],"method":[95,158,190],"examples.":[98],"With":[99],"DIP":[101],"generator":[102],"fit":[104],"target/adversarial":[106],"input,":[107,176],"find":[109],"our":[111,157,189],"reconstruction":[113],"exhibits":[114],"quite":[115],"interesting":[116],"learning":[117,122,139],"preference":[118],"feature":[121],"perspectives,":[123],"i.e.,":[124],"early":[126],"stage":[127],"primarily":[128],"learns":[129],"robust":[131,179],"features":[132,141],"resistant":[133],"perturbation,":[136],"followed":[137],"non-robust":[140],"are":[143],"sensitive":[144],"perturbation.":[147],"Besides,":[148],"develop":[150],"adaptive":[152],"stopping":[153],"strategy":[154],"adapts":[156],"diverse":[160],"In":[162],"this":[163],"way,":[164],"proposed":[166],"model":[167],"obtains":[168],"unique":[170],"defender":[171],"for":[172],"each":[173],"individual":[174],"being":[178],"various":[181],"attackers.":[182],"Experimental":[183],"results":[184],"demonstrate":[185],"superiority":[187],"over":[191],"state-of-the-art":[193],"white-box":[197],"and":[198],"black-box":[199],"attacks.":[201]},"counts_by_year":[{"year":2025,"cited_by_count":1},{"year":2024,"cited_by_count":4},{"year":2023,"cited_by_count":3},{"year":2022,"cited_by_count":7},{"year":2021,"cited_by_count":5}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
