{"id":"https://openalex.org/W3203790781","doi":"https://doi.org/10.1145/3465397","title":"Adversarial Perturbation Defense on Deep Neural Networks","display_name":"Adversarial Perturbation Defense on Deep Neural Networks","publication_year":2021,"publication_date":"2021-10-04","ids":{"openalex":"https://openalex.org/W3203790781","doi":"https://doi.org/10.1145/3465397","mag":"3203790781"},"language":"en","primary_location":{"id":"doi:10.1145/3465397","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3465397","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3465397","source":{"id":"https://openalex.org/S157921468","display_name":"ACM Computing Surveys","issn_l":"0360-0300","issn":["0360-0300","1557-7341"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319798","host_organization_name":"Association for Computing Machinery","host_organization_lineage":["https://openalex.org/P4310319798"],"host_organization_lineage_names":["Association for Computing Machinery"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"ACM Computing Surveys","raw_type":"journal-article"},"type":"review","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"bronze","oa_url":"https://dl.acm.org/doi/pdf/10.1145/3465397","any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5100693941","display_name":"Xingwei Zhang","orcid":"https://orcid.org/0000-0002-0602-077X"},"institutions":[{"id":"https://openalex.org/I4210165038","display_name":"University of Chinese Academy of Sciences","ror":"https://ror.org/05qbk4x57","country_code":"CN","type":"education","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210165038"]},{"id":"https://openalex.org/I4210112150","display_name":"Institute of Automation","ror":"https://ror.org/022c3hy66","country_code":"CN","type":"facility","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210112150"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Xingwei Zhang","raw_affiliation_strings":["School of Artificial Intelligence, University of Chinese Academy of Sciences; The State Key Laboratory of Management and Control for Complex Systems, Institute of Automation, Chinese Academy of Sciences, Beijing, China","School of Artificial Intelligence, University of Chinese Academy of Sciences"],"affiliations":[{"raw_affiliation_string":"School of Artificial Intelligence, University of Chinese Academy of Sciences; The State Key Laboratory of Management and Control for Complex Systems, Institute of Automation, Chinese Academy of Sciences, Beijing, China","institution_ids":["https://openalex.org/I4210112150","https://openalex.org/I4210165038"]},{"raw_affiliation_string":"School of Artificial Intelligence, University of Chinese Academy of Sciences","institution_ids":["https://openalex.org/I4210165038"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5044689658","display_name":"Xiaolong Zheng","orcid":"https://orcid.org/0000-0003-0405-5458"},"institutions":[{"id":"https://openalex.org/I4210112150","display_name":"Institute of Automation","ror":"https://ror.org/022c3hy66","country_code":"CN","type":"facility","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210112150"]},{"id":"https://openalex.org/I4210165038","display_name":"University of Chinese Academy of Sciences","ror":"https://ror.org/05qbk4x57","country_code":"CN","type":"education","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210165038"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Xiaolong Zheng","raw_affiliation_strings":["School of Artificial Intelligence, University of Chinese Academy of Sciences; The State Key Laboratory of Management and Control for Complex Systems, Institute of Automation, Chinese Academy of Sciences, Beijing, China","School of Artificial Intelligence, University of Chinese Academy of Sciences"],"affiliations":[{"raw_affiliation_string":"School of Artificial Intelligence, University of Chinese Academy of Sciences; The State Key Laboratory of Management and Control for Complex Systems, Institute of Automation, Chinese Academy of Sciences, Beijing, China","institution_ids":["https://openalex.org/I4210112150","https://openalex.org/I4210165038"]},{"raw_affiliation_string":"School of Artificial Intelligence, University of Chinese Academy of Sciences","institution_ids":["https://openalex.org/I4210165038"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5035983004","display_name":"Wenji Mao","orcid":"https://orcid.org/0000-0003-2323-5091"},"institutions":[{"id":"https://openalex.org/I4210112150","display_name":"Institute of Automation","ror":"https://ror.org/022c3hy66","country_code":"CN","type":"facility","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210112150"]},{"id":"https://openalex.org/I4210165038","display_name":"University of Chinese Academy of Sciences","ror":"https://ror.org/05qbk4x57","country_code":"CN","type":"education","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210165038"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Wenji Mao","raw_affiliation_strings":["School of Artificial Intelligence, University of Chinese Academy of Sciences; The State Key Laboratory of Management and Control for Complex Systems, Institute of Automation, Chinese Academy of Sciences, Beijing, China","School of Artificial Intelligence, University of Chinese Academy of Sciences"],"affiliations":[{"raw_affiliation_string":"School of Artificial Intelligence, University of Chinese Academy of Sciences; The State Key Laboratory of Management and Control for Complex Systems, Institute of Automation, Chinese Academy of Sciences, Beijing, China","institution_ids":["https://openalex.org/I4210112150","https://openalex.org/I4210165038"]},{"raw_affiliation_string":"School of Artificial Intelligence, University of Chinese Academy of Sciences","institution_ids":["https://openalex.org/I4210165038"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5100693941"],"corresponding_institution_ids":["https://openalex.org/I4210112150","https://openalex.org/I4210165038"],"apc_list":null,"apc_paid":null,"fwci":3.2192,"has_fulltext":true,"cited_by_count":31,"citation_normalized_percentile":{"value":0.93204372,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":89,"max":99},"biblio":{"volume":"54","issue":"8","first_page":"1","last_page":"36"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T14117","display_name":"Integrated Circuits and Semiconductor Failure Analysis","score":0.9545999765396118,"subfield":{"id":"https://openalex.org/subfields/2208","display_name":"Electrical and Electronic Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12122","display_name":"Physical Unclonable Functions (PUFs) and Hardware Security","score":0.9470000267028809,"subfield":{"id":"https://openalex.org/subfields/1708","display_name":"Hardware and Architecture"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.9545975923538208},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8226985931396484},{"id":"https://openalex.org/keywords/deep-neural-networks","display_name":"Deep neural networks","score":0.7808383107185364},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.6386286616325378},{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.6285690665245056},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.46989011764526367},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.4692882001399994},{"id":"https://openalex.org/keywords/perturbation","display_name":"Perturbation (astronomy)","score":0.4328620433807373},{"id":"https://openalex.org/keywords/deep-learning","display_name":"Deep learning","score":0.41697654128074646}],"concepts":[{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.9545975923538208},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8226985931396484},{"id":"https://openalex.org/C2984842247","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep neural networks","level":3,"score":0.7808383107185364},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.6386286616325378},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.6285690665245056},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.46989011764526367},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.4692882001399994},{"id":"https://openalex.org/C177918212","wikidata":"https://www.wikidata.org/wiki/Q803623","display_name":"Perturbation (astronomy)","level":2,"score":0.4328620433807373},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.41697654128074646},{"id":"https://openalex.org/C104317684","wikidata":"https://www.wikidata.org/wiki/Q7187","display_name":"Gene","level":2,"score":0.0},{"id":"https://openalex.org/C55493867","wikidata":"https://www.wikidata.org/wiki/Q7094","display_name":"Biochemistry","level":1,"score":0.0},{"id":"https://openalex.org/C62520636","wikidata":"https://www.wikidata.org/wiki/Q944","display_name":"Quantum mechanics","level":1,"score":0.0},{"id":"https://openalex.org/C185592680","wikidata":"https://www.wikidata.org/wiki/Q2329","display_name":"Chemistry","level":0,"score":0.0},{"id":"https://openalex.org/C121332964","wikidata":"https://www.wikidata.org/wiki/Q413","display_name":"Physics","level":0,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3465397","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3465397","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3465397","source":{"id":"https://openalex.org/S157921468","display_name":"ACM Computing Surveys","issn_l":"0360-0300","issn":["0360-0300","1557-7341"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319798","host_organization_name":"Association for Computing Machinery","host_organization_lineage":["https://openalex.org/P4310319798"],"host_organization_lineage_names":["Association for Computing Machinery"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"ACM Computing Surveys","raw_type":"journal-article"}],"best_oa_location":{"id":"doi:10.1145/3465397","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3465397","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3465397","source":{"id":"https://openalex.org/S157921468","display_name":"ACM Computing Surveys","issn_l":"0360-0300","issn":["0360-0300","1557-7341"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319798","host_organization_name":"Association for Computing Machinery","host_organization_lineage":["https://openalex.org/P4310319798"],"host_organization_lineage_names":["Association for Computing Machinery"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"ACM Computing Surveys","raw_type":"journal-article"},"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G1231421488","display_name":null,"funder_award_id":"under","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G2087396116","display_name":null,"funder_award_id":"China","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G264068190","display_name":null,"funder_award_id":"2017ZX10303401-002 and 2017YFC1200302","funder_id":"https://openalex.org/F4320323483","funder_display_name":"Ministry of Health of the People's Republic of China"},{"id":"https://openalex.org/G2746444971","display_name":null,"funder_award_id":"71602184","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G3317480652","display_name":null,"funder_award_id":"Science","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G391238517","display_name":null,"funder_award_id":", and","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G4058403822","display_name":null,"funder_award_id":"2017ZX10303401-002","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G5939423041","display_name":null,"funder_award_id":"Technology","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G5994120800","display_name":null,"funder_award_id":"Natural","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G6603392804","display_name":null,"funder_award_id":"71602184 and 71621002","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G728148057","display_name":null,"funder_award_id":"2017YFC1200302","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G7638124670","display_name":null,"funder_award_id":"and 71621002","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G997903294","display_name":null,"funder_award_id":"71621002","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"}],"funders":[{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"},{"id":"https://openalex.org/F4320323483","display_name":"Ministry of Health of the People's Republic of China","ror":"https://ror.org/052eegr76"}],"has_content":{"grobid_xml":true,"pdf":true},"content_urls":{"pdf":"https://content.openalex.org/works/W3203790781.pdf","grobid_xml":"https://content.openalex.org/works/W3203790781.grobid-xml"},"referenced_works_count":41,"referenced_works":["https://openalex.org/W2136922672","https://openalex.org/W2269778407","https://openalex.org/W2603766943","https://openalex.org/W2618043096","https://openalex.org/W2618235498","https://openalex.org/W2746600820","https://openalex.org/W2754049786","https://openalex.org/W2785755647","https://openalex.org/W2789019405","https://openalex.org/W2798868970","https://openalex.org/W2799032899","https://openalex.org/W2892090366","https://openalex.org/W2897313686","https://openalex.org/W2919115771","https://openalex.org/W2944049653","https://openalex.org/W2950799135","https://openalex.org/W2952104986","https://openalex.org/W2962700793","https://openalex.org/W2962710014","https://openalex.org/W2962943487","https://openalex.org/W2963178695","https://openalex.org/W2963539306","https://openalex.org/W2963564844","https://openalex.org/W2963626858","https://openalex.org/W2963685823","https://openalex.org/W2963739340","https://openalex.org/W2964159205","https://openalex.org/W2964164993","https://openalex.org/W2964201752","https://openalex.org/W2984968650","https://openalex.org/W2989696285","https://openalex.org/W3008694380","https://openalex.org/W3009153202","https://openalex.org/W3036847733","https://openalex.org/W3104141960","https://openalex.org/W3106412272","https://openalex.org/W4205947740","https://openalex.org/W4245009893","https://openalex.org/W4255489524","https://openalex.org/W4298112463","https://openalex.org/W4301409532"],"related_works":["https://openalex.org/W2950183588","https://openalex.org/W3080754722","https://openalex.org/W4383221314","https://openalex.org/W3093978547","https://openalex.org/W2953536436","https://openalex.org/W3203790781","https://openalex.org/W4313346231","https://openalex.org/W2738001131","https://openalex.org/W4285785480","https://openalex.org/W2997056298"],"abstract_inverted_index":{"Deep":[0],"neural":[1],"networks":[2],"(DNNs)":[3],"have":[4,61,75],"been":[5,76],"verified":[6],"to":[7,23,79],"be":[8],"easily":[9],"attacked":[10],"by":[11,111],"well-designed":[12],"adversarial":[13,59,82,95,125],"perturbations.":[14,96,126],"Image":[15],"objects":[16],"with":[17,36],"small":[18],"perturbations":[19,40,60],"that":[20],"are":[21],"imperceptible":[22],"human":[24],"eyes":[25],"can":[26,41],"induce":[27],"DNN-based":[28],"image":[29],"class":[30],"classifiers":[31],"towards":[32],"making":[33],"erroneous":[34],"predictions":[35],"high":[37],"probability.":[38],"Adversarial":[39],"also":[42],"fool":[43],"real-world":[44],"machine":[45],"learning":[46],"systems":[47],"and":[48,53,66,107,118],"transfer":[49],"between":[50],"different":[51],"architectures":[52],"datasets.":[54],"Recently,":[55],"defense":[56,109],"methods":[57,110],"against":[58,81,87],"become":[62],"a":[63,102],"hot":[64],"topic":[65],"attracted":[67],"much":[68],"attention.":[69],"A":[70],"large":[71],"number":[72],"of":[73,94,124,134],"works":[74],"put":[77],"forward":[78],"defend":[80],"perturbations,":[83],"enhancing":[84],"DNN":[85],"robustness":[86],"potential":[88,132],"attacks,":[89],"or":[90],"interpreting":[91],"the":[92,122],"origin":[93,123],"In":[97,127],"this":[98,135],"article,":[99],"we":[100,129],"provide":[101],"comprehensive":[103],"survey":[104],"on":[105],"classical":[106],"state-of-the-art":[108],"illuminating":[112],"their":[113],"main":[114],"concepts,":[115],"in-depth":[116],"algorithms,":[117],"fundamental":[119],"hypotheses":[120],"regarding":[121],"addition,":[128],"further":[130],"discuss":[131],"directions":[133],"domain":[136],"for":[137],"future":[138],"researchers.":[139]},"counts_by_year":[{"year":2025,"cited_by_count":7},{"year":2024,"cited_by_count":11},{"year":2023,"cited_by_count":6},{"year":2022,"cited_by_count":6},{"year":2020,"cited_by_count":1}],"updated_date":"2026-04-10T15:06:20.359241","created_date":"2025-10-10T00:00:00"}
