{"id":"https://openalex.org/W4220981308","doi":"https://doi.org/10.1145/3524619","title":"(Compress and Restore) <sup>N</sup> : A Robust Defense Against Adversarial Attacks on Image Classification","display_name":"(Compress and Restore) <sup>N</sup> : A Robust Defense Against Adversarial Attacks on Image Classification","publication_year":2022,"publication_date":"2022-03-17","ids":{"openalex":"https://openalex.org/W4220981308","doi":"https://doi.org/10.1145/3524619"},"language":"en","primary_location":{"id":"doi:10.1145/3524619","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3524619","pdf_url":null,"source":{"id":"https://openalex.org/S19610489","display_name":"ACM Transactions on Multimedia Computing Communications and Applications","issn_l":"1551-6857","issn":["1551-6857","1551-6865"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319798","host_organization_name":"Association for Computing Machinery","host_organization_lineage":["https://openalex.org/P4310319798"],"host_organization_lineage_names":["Association for Computing Machinery"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"ACM Transactions on Multimedia Computing, Communications, and Applications","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://dl.acm.org/doi/abs/10.1145/3524619","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5028907737","display_name":"Claudio Ferrari","orcid":"https://orcid.org/0000-0001-9465-6753"},"institutions":[{"id":"https://openalex.org/I124601658","display_name":"University of Parma","ror":"https://ror.org/02k7wn190","country_code":"IT","type":"education","lineage":["https://openalex.org/I124601658"]},{"id":"https://openalex.org/I45084792","display_name":"University of Florence","ror":"https://ror.org/04jr1s763","country_code":"IT","type":"education","lineage":["https://openalex.org/I45084792"]}],"countries":["IT"],"is_corresponding":false,"raw_author_name":"Claudio Ferrari","raw_affiliation_strings":["Department of Architecture and Engineering, University of Parma/Departmentof Information Engineering, University of Florence, Parma, Italy"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Department of Architecture and Engineering, University of Parma/Departmentof Information Engineering, University of Florence, Parma, Italy","institution_ids":["https://openalex.org/I124601658","https://openalex.org/I45084792"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5065891142","display_name":"Federico Becattini","orcid":"https://orcid.org/0000-0003-2537-2700"},"institutions":[{"id":"https://openalex.org/I45084792","display_name":"University of Florence","ror":"https://ror.org/04jr1s763","country_code":"IT","type":"education","lineage":["https://openalex.org/I45084792"]}],"countries":["IT"],"is_corresponding":false,"raw_author_name":"Federico Becattini","raw_affiliation_strings":["Department of Information Engineering, University of Florence, Firenze, Italy"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Department of Information Engineering, University of Florence, Firenze, Italy","institution_ids":["https://openalex.org/I45084792"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5038181828","display_name":"Leonardo Galteri","orcid":"https://orcid.org/0000-0002-7247-9407"},"institutions":[{"id":"https://openalex.org/I45084792","display_name":"University of Florence","ror":"https://ror.org/04jr1s763","country_code":"IT","type":"education","lineage":["https://openalex.org/I45084792"]}],"countries":["IT"],"is_corresponding":false,"raw_author_name":"Leonardo Galteri","raw_affiliation_strings":["Department of Information Engineering, University of Florence, Firenze, Italy"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Department of Information Engineering, University of Florence, Firenze, Italy","institution_ids":["https://openalex.org/I45084792"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5081506611","display_name":"Alberto Del Bimbo","orcid":"https://orcid.org/0000-0002-1052-8322"},"institutions":[{"id":"https://openalex.org/I45084792","display_name":"University of Florence","ror":"https://ror.org/04jr1s763","country_code":"IT","type":"education","lineage":["https://openalex.org/I45084792"]}],"countries":["IT"],"is_corresponding":false,"raw_author_name":"Alberto Del Bimbo","raw_affiliation_strings":["Department of Information Engineering, University of Florence, Firenze, Italy"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Department of Information Engineering, University of Florence, Firenze, Italy","institution_ids":["https://openalex.org/I45084792"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":1.5263,"has_fulltext":false,"cited_by_count":13,"citation_normalized_percentile":{"value":0.85020841,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":90,"max":99},"biblio":{"volume":"19","issue":"1s","first_page":"1","last_page":"16"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9595999717712402,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11515","display_name":"Bacillus and Francisella bacterial research","score":0.9442999958992004,"subfield":{"id":"https://openalex.org/subfields/1312","display_name":"Molecular Biology"},"field":{"id":"https://openalex.org/fields/13","display_name":"Biochemistry, Genetics and Molecular Biology"},"domain":{"id":"https://openalex.org/domains/1","display_name":"Life Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7840131521224976},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.5662270188331604},{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.5532740354537964},{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.5003938674926758},{"id":"https://openalex.org/keywords/classifier","display_name":"Classifier (UML)","score":0.45163071155548096},{"id":"https://openalex.org/keywords/iterated-function","display_name":"Iterated function","score":0.44532057642936707},{"id":"https://openalex.org/keywords/deep-neural-networks","display_name":"Deep neural networks","score":0.4256131649017334},{"id":"https://openalex.org/keywords/image","display_name":"Image (mathematics)","score":0.4253024160861969},{"id":"https://openalex.org/keywords/focus","display_name":"Focus (optics)","score":0.42254698276519775},{"id":"https://openalex.org/keywords/deep-learning","display_name":"Deep learning","score":0.41529107093811035},{"id":"https://openalex.org/keywords/pattern-recognition","display_name":"Pattern recognition (psychology)","score":0.41292011737823486},{"id":"https://openalex.org/keywords/compression-artifact","display_name":"Compression artifact","score":0.4103909432888031},{"id":"https://openalex.org/keywords/image-compression","display_name":"Image compression","score":0.39970913529396057},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.36974480748176575},{"id":"https://openalex.org/keywords/image-processing","display_name":"Image processing","score":0.3262655735015869},{"id":"https://openalex.org/keywords/mathematics","display_name":"Mathematics","score":0.1432202160358429}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7840131521224976},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5662270188331604},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.5532740354537964},{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.5003938674926758},{"id":"https://openalex.org/C95623464","wikidata":"https://www.wikidata.org/wiki/Q1096149","display_name":"Classifier (UML)","level":2,"score":0.45163071155548096},{"id":"https://openalex.org/C140479938","wikidata":"https://www.wikidata.org/wiki/Q5254619","display_name":"Iterated function","level":2,"score":0.44532057642936707},{"id":"https://openalex.org/C2984842247","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep neural networks","level":3,"score":0.4256131649017334},{"id":"https://openalex.org/C115961682","wikidata":"https://www.wikidata.org/wiki/Q860623","display_name":"Image (mathematics)","level":2,"score":0.4253024160861969},{"id":"https://openalex.org/C192209626","wikidata":"https://www.wikidata.org/wiki/Q190909","display_name":"Focus (optics)","level":2,"score":0.42254698276519775},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.41529107093811035},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.41292011737823486},{"id":"https://openalex.org/C57654395","wikidata":"https://www.wikidata.org/wiki/Q1097775","display_name":"Compression artifact","level":5,"score":0.4103909432888031},{"id":"https://openalex.org/C13481523","wikidata":"https://www.wikidata.org/wiki/Q412438","display_name":"Image compression","level":4,"score":0.39970913529396057},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.36974480748176575},{"id":"https://openalex.org/C9417928","wikidata":"https://www.wikidata.org/wiki/Q1070689","display_name":"Image processing","level":3,"score":0.3262655735015869},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.1432202160358429},{"id":"https://openalex.org/C55493867","wikidata":"https://www.wikidata.org/wiki/Q7094","display_name":"Biochemistry","level":1,"score":0.0},{"id":"https://openalex.org/C185592680","wikidata":"https://www.wikidata.org/wiki/Q2329","display_name":"Chemistry","level":0,"score":0.0},{"id":"https://openalex.org/C120665830","wikidata":"https://www.wikidata.org/wiki/Q14620","display_name":"Optics","level":1,"score":0.0},{"id":"https://openalex.org/C121332964","wikidata":"https://www.wikidata.org/wiki/Q413","display_name":"Physics","level":0,"score":0.0},{"id":"https://openalex.org/C104317684","wikidata":"https://www.wikidata.org/wiki/Q7187","display_name":"Gene","level":2,"score":0.0},{"id":"https://openalex.org/C134306372","wikidata":"https://www.wikidata.org/wiki/Q7754","display_name":"Mathematical analysis","level":1,"score":0.0}],"mesh":[],"locations_count":3,"locations":[{"id":"doi:10.1145/3524619","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3524619","pdf_url":null,"source":{"id":"https://openalex.org/S19610489","display_name":"ACM Transactions on Multimedia Computing Communications and Applications","issn_l":"1551-6857","issn":["1551-6857","1551-6865"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319798","host_organization_name":"Association for Computing Machinery","host_organization_lineage":["https://openalex.org/P4310319798"],"host_organization_lineage_names":["Association for Computing Machinery"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"ACM Transactions on Multimedia Computing, Communications, and Applications","raw_type":"journal-article"},{"id":"pmh:oai:flore.unifi.it:2158/1271425.1","is_oa":false,"landing_page_url":"http://hdl.handle.net/2158/1271425","pdf_url":null,"source":{"id":"https://openalex.org/S4306402033","display_name":"Florence Research (University of Florence)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I45084792","host_organization_name":"University of Florence","host_organization_lineage":["https://openalex.org/I45084792"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"","raw_type":"1 - Contributo su rivista::1a - Articolo su rivista"},{"id":"pmh:oai:usiena-air.unisi.it:11365/1224662","is_oa":true,"landing_page_url":"https://dl.acm.org/doi/abs/10.1145/3524619","pdf_url":null,"source":{"id":"https://openalex.org/S4377196319","display_name":"Use Siena air (University of Siena)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I102064193","host_organization_name":"University of Siena","host_organization_lineage":["https://openalex.org/I102064193"],"host_organization_lineage_names":[],"type":"repository"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"info:eu-repo/semantics/article"}],"best_oa_location":{"id":"pmh:oai:usiena-air.unisi.it:11365/1224662","is_oa":true,"landing_page_url":"https://dl.acm.org/doi/abs/10.1145/3524619","pdf_url":null,"source":{"id":"https://openalex.org/S4377196319","display_name":"Use Siena air (University of Siena)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I102064193","host_organization_name":"University of Siena","host_organization_lineage":["https://openalex.org/I102064193"],"host_organization_lineage_names":[],"type":"repository"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"info:eu-repo/semantics/article"},"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/11","score":0.7099999785423279,"display_name":"Sustainable cities and communities"}],"awards":[{"id":"https://openalex.org/G1322071649","display_name":null,"funder_award_id":"951911","funder_id":"https://openalex.org/F4320320300","funder_display_name":"European Commission"}],"funders":[{"id":"https://openalex.org/F4320309480","display_name":"Nvidia","ror":"https://ror.org/03jdj4y14"},{"id":"https://openalex.org/F4320320300","display_name":"European Commission","ror":"https://ror.org/00k4n6c32"}],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":25,"referenced_works":["https://openalex.org/W2117539524","https://openalex.org/W2142683286","https://openalex.org/W2194775991","https://openalex.org/W2243397390","https://openalex.org/W2557216475","https://openalex.org/W2741137940","https://openalex.org/W2774018344","https://openalex.org/W2774644650","https://openalex.org/W2911590151","https://openalex.org/W2962687329","https://openalex.org/W2962700793","https://openalex.org/W2962710014","https://openalex.org/W2962847335","https://openalex.org/W2962933288","https://openalex.org/W2963268689","https://openalex.org/W2963384482","https://openalex.org/W2963771536","https://openalex.org/W2963857521","https://openalex.org/W2969542116","https://openalex.org/W2972986629","https://openalex.org/W2974383094","https://openalex.org/W3034214559","https://openalex.org/W3035667859","https://openalex.org/W3101202235","https://openalex.org/W3107235539"],"related_works":["https://openalex.org/W2950183588","https://openalex.org/W3080754722","https://openalex.org/W3093978547","https://openalex.org/W3203790781","https://openalex.org/W2997056298","https://openalex.org/W2738001131","https://openalex.org/W4285785480","https://openalex.org/W3127875750","https://openalex.org/W4383221314","https://openalex.org/W2953536436"],"abstract_inverted_index":{"Modern":[0],"image":[1,48,85],"classification":[2,92],"approaches":[3],"often":[4],"rely":[5],"on":[6,47,115,140],"deep":[7],"neural":[8],"networks,":[9],"which":[10],"have":[11],"shown":[12],"pronounced":[13],"weakness":[14],"to":[15,30,43,175],"adversarial":[16,45,151],"examples:":[17],"images":[18],"corrupted":[19],"with":[20,59,126,136],"specifically":[21],"designed":[22],"yet":[23,40],"imperceptible":[24],"noise":[25],"that":[26,104,165],"causes":[27],"the":[28,84,91,116,120,141,158,161,168],"network":[29],"misclassify.":[31],"In":[32],"this":[33],"article,":[34],"we":[35,105],"propose":[36],"a":[37,56,60,72,137],"conceptually":[38],"simple":[39],"robust":[41],"solution":[42],"tackle":[44],"attacks":[46],"classification.":[49],"Our":[50,145],"defense":[51,128],"works":[52],"by":[53,69],"first":[54],"applying":[55],"JPEG":[57],"compression":[58,64,101],"random":[61],"quality":[62],"factor;":[63],"artifacts":[65],"are":[66],"subsequently":[67],"removed":[68],"means":[70],"of":[71,156,172],"generative":[73],"model":[74],"Artifact":[75],"Restoration":[76],"GAN.":[77],"The":[78],"process":[79],"can":[80,106],"be":[81],"iterated":[82],"ensuring":[83],"is":[86,154,171],"not":[87,93,148],"degraded":[88],"and":[89,132,153,160],"hence":[90],"compromised.":[94],"We":[95,124],"train":[96],"different":[97,100],"AR-GANs":[98],"for":[99],"factors,":[102],"so":[103],"change":[107],"its":[108],"parameters":[109,170],"dynamically":[110,166],"at":[111],"each":[112],"iteration":[113],"depending":[114],"current":[117],"compression,":[118],"making":[119],"gradient":[121],"approximation":[122],"difficult.":[123],"experiment":[125],"our":[127],"against":[129],"three":[130],"white-box":[131],"two":[133],"black-box":[134],"attacks,":[135],"particular":[138],"focus":[139],"state-of-the-art":[142],"BPDA":[143],"attack.":[144,162],"method":[146],"does":[147],"require":[149],"any":[150],"training,":[152],"independent":[155],"both":[157],"classifier":[159],"Experiments":[163],"demonstrate":[164],"changing":[167],"AR-GAN":[169],"fundamental":[173],"importance":[174],"obtain":[176],"significant":[177],"robustness.":[178]},"counts_by_year":[{"year":2026,"cited_by_count":2},{"year":2025,"cited_by_count":6},{"year":2024,"cited_by_count":4},{"year":2023,"cited_by_count":1}],"updated_date":"2026-06-14T07:44:22.658603","created_date":"2022-04-03T00:00:00"}
