{"id":"https://openalex.org/W4413756813","doi":"https://doi.org/10.1145/3704268.3742694","title":"Robust Image Classifiers Fail Under Shifted Adversarial Perturbations","display_name":"Robust Image Classifiers Fail Under Shifted Adversarial Perturbations","publication_year":2025,"publication_date":"2025-08-27","ids":{"openalex":"https://openalex.org/W4413756813","doi":"https://doi.org/10.1145/3704268.3742694"},"language":"en","primary_location":{"id":"doi:10.1145/3704268.3742694","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3704268.3742694","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3704268.3742694","source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2025 ACM Symposium on Document Engineering","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://dl.acm.org/doi/pdf/10.1145/3704268.3742694","any_repository_has_fulltext":null},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5093264961","display_name":"Fatemeh Amerehi","orcid":"https://orcid.org/0000-0002-6255-4573"},"institutions":[{"id":"https://openalex.org/I230495080","display_name":"University of Limerick","ror":"https://ror.org/00a0n9e72","country_code":"IE","type":"education","lineage":["https://openalex.org/I230495080"]}],"countries":["IE"],"is_corresponding":true,"raw_author_name":"Fatemeh Amerehi","raw_affiliation_strings":["University of Limerick, Ireland"],"affiliations":[{"raw_affiliation_string":"University of Limerick, Ireland","institution_ids":["https://openalex.org/I230495080"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5027046652","display_name":"Patrick Healy","orcid":"https://orcid.org/0000-0002-3824-7442"},"institutions":[{"id":"https://openalex.org/I230495080","display_name":"University of Limerick","ror":"https://ror.org/00a0n9e72","country_code":"IE","type":"education","lineage":["https://openalex.org/I230495080"]}],"countries":["IE"],"is_corresponding":false,"raw_author_name":"Patrick Healy","raw_affiliation_strings":["University of Limerick, Ireland"],"affiliations":[{"raw_affiliation_string":"University of Limerick, Ireland","institution_ids":["https://openalex.org/I230495080"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":2,"corresponding_author_ids":["https://openalex.org/A5093264961"],"corresponding_institution_ids":["https://openalex.org/I230495080"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":true,"cited_by_count":0,"citation_normalized_percentile":{"value":0.13006201,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"8"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11515","display_name":"Bacillus and Francisella bacterial research","score":0.982699990272522,"subfield":{"id":"https://openalex.org/subfields/1312","display_name":"Molecular Biology"},"field":{"id":"https://openalex.org/fields/13","display_name":"Biochemistry, Genetics and Molecular Biology"},"domain":{"id":"https://openalex.org/domains/1","display_name":"Life Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9799000024795532,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.7878119945526123},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.6025899648666382},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.5524913668632507},{"id":"https://openalex.org/keywords/image","display_name":"Image (mathematics)","score":0.4868168532848358},{"id":"https://openalex.org/keywords/computer-vision","display_name":"Computer vision","score":0.43108734488487244},{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.41337424516677856},{"id":"https://openalex.org/keywords/contextual-image-classification","display_name":"Contextual image classification","score":0.4114410877227783},{"id":"https://openalex.org/keywords/pattern-recognition","display_name":"Pattern recognition (psychology)","score":0.36435139179229736}],"concepts":[{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.7878119945526123},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6025899648666382},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5524913668632507},{"id":"https://openalex.org/C115961682","wikidata":"https://www.wikidata.org/wiki/Q860623","display_name":"Image (mathematics)","level":2,"score":0.4868168532848358},{"id":"https://openalex.org/C31972630","wikidata":"https://www.wikidata.org/wiki/Q844240","display_name":"Computer vision","level":1,"score":0.43108734488487244},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.41337424516677856},{"id":"https://openalex.org/C75294576","wikidata":"https://www.wikidata.org/wiki/Q5165192","display_name":"Contextual image classification","level":3,"score":0.4114410877227783},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.36435139179229736},{"id":"https://openalex.org/C55493867","wikidata":"https://www.wikidata.org/wiki/Q7094","display_name":"Biochemistry","level":1,"score":0.0},{"id":"https://openalex.org/C185592680","wikidata":"https://www.wikidata.org/wiki/Q2329","display_name":"Chemistry","level":0,"score":0.0},{"id":"https://openalex.org/C104317684","wikidata":"https://www.wikidata.org/wiki/Q7187","display_name":"Gene","level":2,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3704268.3742694","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3704268.3742694","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3704268.3742694","source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2025 ACM Symposium on Document Engineering","raw_type":"proceedings-article"}],"best_oa_location":{"id":"doi:10.1145/3704268.3742694","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3704268.3742694","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3704268.3742694","source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2025 ACM Symposium on Document Engineering","raw_type":"proceedings-article"},"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/13","display_name":"Climate action","score":0.6700000166893005}],"awards":[],"funders":[],"has_content":{"pdf":true,"grobid_xml":true},"content_urls":{"pdf":"https://content.openalex.org/works/W4413756813.pdf","grobid_xml":"https://content.openalex.org/works/W4413756813.grobid-xml"},"referenced_works_count":15,"referenced_works":["https://openalex.org/W2194775991","https://openalex.org/W2243397390","https://openalex.org/W2963501948","https://openalex.org/W2963857521","https://openalex.org/W2964152294","https://openalex.org/W3024016700","https://openalex.org/W3034196143","https://openalex.org/W3034412497","https://openalex.org/W3040002795","https://openalex.org/W3107235539","https://openalex.org/W4225928697","https://openalex.org/W4287715669","https://openalex.org/W4306705447","https://openalex.org/W4312919733","https://openalex.org/W4394677476"],"related_works":["https://openalex.org/W2502115930","https://openalex.org/W2482350142","https://openalex.org/W4246396837","https://openalex.org/W3126451824","https://openalex.org/W1561927205","https://openalex.org/W3191453585","https://openalex.org/W4297672492","https://openalex.org/W4310988119","https://openalex.org/W4285226279","https://openalex.org/W2546503577"],"abstract_inverted_index":{"Non-robustness":[0],"of":[1,28,53,87],"image":[2],"classifiers":[3],"to":[4,74,100,103,120],"subtle,":[5],"adversarial":[6,94],"perturbations":[7],"is":[8,96],"a":[9,38,84],"well-known":[10],"failure":[11],"mode.":[12],"Defenses":[13],"against":[14,115],"such":[15,77],"attacks":[16,61],"are":[17],"typically":[18],"evaluated":[19],"by":[20,83],"measuring":[21],"the":[22,29,34,51,88,93,104,107],"error":[23],"rate":[24],"on":[25],"perturbed":[26],"versions":[27],"natural":[30],"test":[31],"set,":[32],"quantifying":[33],"worst-case":[35],"performance":[36],"within":[37],"specified":[39],"perturbation":[40,48,95],"budget.":[41],"However,":[42],"these":[43],"evaluations":[44],"often":[45],"isolate":[46],"specific":[47],"types,":[49],"underestimating":[50],"adaptability":[52],"real-world":[54],"adversaries":[55],"who":[56],"can":[57,80,138],"modify":[58],"or":[59],"compose":[60],"in":[62],"unforeseen":[63],"ways.":[64],"In":[65],"this":[66,121],"work,":[67],"we":[68],"show":[69],"that":[70,112,126],"models":[71,111,136],"considered":[72],"robust":[73,110],"strong":[75],"attacks,":[76],"as":[78],"AutoAttack,":[79],"be":[81],"compromised":[82],"simple":[85],"modification":[86],"weaker":[89],"FGSM":[90,117],"attack,":[91],"where":[92],"slightly":[97],"transformed":[98],"prior":[99],"being":[101],"added":[102],"input.":[105],"Despite":[106],"attack's":[108],"simplicity,":[109],"perform":[113],"well":[114],"standard":[116],"become":[118],"vulnerable":[119],"variant.":[122],"These":[123],"findings":[124],"suggest":[125],"current":[127],"defenses":[128],"may":[129],"generalize":[130],"poorly":[131],"beyond":[132],"their":[133],"assumed":[134],"threat":[135],"and":[137],"achieve":[139],"inflated":[140],"robustness":[141],"scores":[142],"under":[143],"narrowly":[144],"defined":[145],"evaluation":[146],"settings.":[147]},"counts_by_year":[],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
