{"id":"https://openalex.org/W3011711787","doi":"https://doi.org/10.1145/3374664.3375728","title":"Explore the Transformation Space for Adversarial Images","display_name":"Explore the Transformation Space for Adversarial Images","publication_year":2020,"publication_date":"2020-03-13","ids":{"openalex":"https://openalex.org/W3011711787","doi":"https://doi.org/10.1145/3374664.3375728","mag":"3011711787"},"language":"en","primary_location":{"id":"doi:10.1145/3374664.3375728","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3374664.3375728","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the Tenth ACM Conference on Data and Application Security and Privacy","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5078511472","display_name":"Jiyu Chen","orcid":"https://orcid.org/0000-0002-7006-6430"},"institutions":[{"id":"https://openalex.org/I84218800","display_name":"University of California, Davis","ror":"https://ror.org/05rrcem69","country_code":"US","type":"education","lineage":["https://openalex.org/I84218800"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Jiyu Chen","raw_affiliation_strings":["University of California, Davis, Davis, CA, USA"],"affiliations":[{"raw_affiliation_string":"University of California, Davis, Davis, CA, USA","institution_ids":["https://openalex.org/I84218800"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5113540248","display_name":"David Wang","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"David Wang","raw_affiliation_strings":["Vestavia Hills High School, Vestavia Hills, AL, USA"],"affiliations":[{"raw_affiliation_string":"Vestavia Hills High School, Vestavia Hills, AL, USA","institution_ids":[]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5100353550","display_name":"Hao Chen","orcid":"https://orcid.org/0000-0002-4072-0710"},"institutions":[{"id":"https://openalex.org/I84218800","display_name":"University of California, Davis","ror":"https://ror.org/05rrcem69","country_code":"US","type":"education","lineage":["https://openalex.org/I84218800"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Hao Chen","raw_affiliation_strings":["University of California, Davis, Davis, CA, USA"],"affiliations":[{"raw_affiliation_string":"University of California, Davis, Davis, CA, USA","institution_ids":["https://openalex.org/I84218800"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5078511472"],"corresponding_institution_ids":["https://openalex.org/I84218800"],"apc_list":null,"apc_paid":null,"fwci":1.0605,"has_fulltext":false,"cited_by_count":12,"citation_normalized_percentile":{"value":0.81579605,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":89,"max":98},"biblio":{"volume":null,"issue":null,"first_page":"109","last_page":"120"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9997000098228455,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9997000098228455,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11515","display_name":"Bacillus and Francisella bacterial research","score":0.9620000123977661,"subfield":{"id":"https://openalex.org/subfields/1312","display_name":"Molecular Biology"},"field":{"id":"https://openalex.org/fields/13","display_name":"Biochemistry, Genetics and Molecular Biology"},"domain":{"id":"https://openalex.org/domains/1","display_name":"Life Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9413999915122986,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.9146945476531982},{"id":"https://openalex.org/keywords/norm","display_name":"Norm (philosophy)","score":0.68320631980896},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.6415991187095642},{"id":"https://openalex.org/keywords/transformation","display_name":"Transformation (genetics)","score":0.6316830515861511},{"id":"https://openalex.org/keywords/transferability","display_name":"Transferability","score":0.5911710858345032},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.5614244937896729},{"id":"https://openalex.org/keywords/affine-transformation","display_name":"Affine transformation","score":0.520142138004303},{"id":"https://openalex.org/keywords/retraining","display_name":"Retraining","score":0.5190839767456055},{"id":"https://openalex.org/keywords/similarity","display_name":"Similarity (geometry)","score":0.5027961730957031},{"id":"https://openalex.org/keywords/image","display_name":"Image (mathematics)","score":0.3249456286430359},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.26795780658721924},{"id":"https://openalex.org/keywords/mathematics","display_name":"Mathematics","score":0.2525838613510132},{"id":"https://openalex.org/keywords/pure-mathematics","display_name":"Pure mathematics","score":0.07358846068382263}],"concepts":[{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.9146945476531982},{"id":"https://openalex.org/C191795146","wikidata":"https://www.wikidata.org/wiki/Q3878446","display_name":"Norm (philosophy)","level":2,"score":0.68320631980896},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6415991187095642},{"id":"https://openalex.org/C204241405","wikidata":"https://www.wikidata.org/wiki/Q461499","display_name":"Transformation (genetics)","level":3,"score":0.6316830515861511},{"id":"https://openalex.org/C61272859","wikidata":"https://www.wikidata.org/wiki/Q7834031","display_name":"Transferability","level":3,"score":0.5911710858345032},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5614244937896729},{"id":"https://openalex.org/C92757383","wikidata":"https://www.wikidata.org/wiki/Q382497","display_name":"Affine transformation","level":2,"score":0.520142138004303},{"id":"https://openalex.org/C2778712577","wikidata":"https://www.wikidata.org/wiki/Q3505966","display_name":"Retraining","level":2,"score":0.5190839767456055},{"id":"https://openalex.org/C103278499","wikidata":"https://www.wikidata.org/wiki/Q254465","display_name":"Similarity (geometry)","level":3,"score":0.5027961730957031},{"id":"https://openalex.org/C115961682","wikidata":"https://www.wikidata.org/wiki/Q860623","display_name":"Image (mathematics)","level":2,"score":0.3249456286430359},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.26795780658721924},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.2525838613510132},{"id":"https://openalex.org/C202444582","wikidata":"https://www.wikidata.org/wiki/Q837863","display_name":"Pure mathematics","level":1,"score":0.07358846068382263},{"id":"https://openalex.org/C140331021","wikidata":"https://www.wikidata.org/wiki/Q1868104","display_name":"Logit","level":2,"score":0.0},{"id":"https://openalex.org/C199539241","wikidata":"https://www.wikidata.org/wiki/Q7748","display_name":"Law","level":1,"score":0.0},{"id":"https://openalex.org/C155202549","wikidata":"https://www.wikidata.org/wiki/Q178803","display_name":"International trade","level":1,"score":0.0},{"id":"https://openalex.org/C104317684","wikidata":"https://www.wikidata.org/wiki/Q7187","display_name":"Gene","level":2,"score":0.0},{"id":"https://openalex.org/C17744445","wikidata":"https://www.wikidata.org/wiki/Q36442","display_name":"Political science","level":0,"score":0.0},{"id":"https://openalex.org/C55493867","wikidata":"https://www.wikidata.org/wiki/Q7094","display_name":"Biochemistry","level":1,"score":0.0},{"id":"https://openalex.org/C185592680","wikidata":"https://www.wikidata.org/wiki/Q2329","display_name":"Chemistry","level":0,"score":0.0},{"id":"https://openalex.org/C144133560","wikidata":"https://www.wikidata.org/wiki/Q4830453","display_name":"Business","level":0,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1145/3374664.3375728","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3374664.3375728","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the Tenth ACM Conference on Data and Application Security and Privacy","raw_type":"proceedings-article"},{"id":"pmh:oai:hub.hku.hk:10722/346774","is_oa":false,"landing_page_url":"https://hub.hku.hk/handle/10722/346774","pdf_url":null,"source":{"id":"https://openalex.org/S4377196271","display_name":"The HKU Scholars Hub (University of Hong Kong)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I889458895","host_organization_name":"University of Hong Kong","host_organization_lineage":["https://openalex.org/I889458895"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"Conference_Paper"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G3376968242","display_name":null,"funder_award_id":"1801751","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"}],"funders":[{"id":"https://openalex.org/F4320306076","display_name":"National Science Foundation","ror":"https://ror.org/021nxhr62"}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":19,"referenced_works":["https://openalex.org/W603908379","https://openalex.org/W2108598243","https://openalex.org/W2133665775","https://openalex.org/W2183341477","https://openalex.org/W2335728318","https://openalex.org/W2594481151","https://openalex.org/W2746600820","https://openalex.org/W2768718880","https://openalex.org/W2783784437","https://openalex.org/W2890591829","https://openalex.org/W2963098487","https://openalex.org/W2963207607","https://openalex.org/W2963366334","https://openalex.org/W2963564844","https://openalex.org/W2963612069","https://openalex.org/W2963857521","https://openalex.org/W2964082701","https://openalex.org/W2964153729","https://openalex.org/W3106412272"],"related_works":["https://openalex.org/W4288055406","https://openalex.org/W3137894200","https://openalex.org/W3092178728","https://openalex.org/W4226402597","https://openalex.org/W4200630034","https://openalex.org/W3132910851","https://openalex.org/W4377864639","https://openalex.org/W2997056298","https://openalex.org/W2950864148","https://openalex.org/W2570685808"],"abstract_inverted_index":{"Deep":[0],"learning":[1],"models":[2,22],"are":[3,23,147,172],"vulnerable":[4],"to":[5,17,36,134,176,196],"adversarial":[6,11,27,38,57,152],"examples.":[7],"Most":[8],"of":[9,103,105,138],"current":[10],"attacks":[12,48,114,146],"add":[13],"pixel-wise":[14],"perturbations":[15],"restricted":[16,29],"some":[18],"\\(L^p\\)-norm,":[19],"and":[20,44,49,67,90,107,122,125,158],"defense":[21],"evaluated":[24],"also":[25,173],"on":[26,56,115],"examples":[28,39],"inside":[30],"\\(L^p\\)-norm":[31,42,73],"balls.":[32],"However,":[33],"we":[34,54,84,96,130],"wish":[35],"explore":[37,97],"exist":[40],"beyond":[41],"balls":[43],"their":[45,126],"implications":[46],"for":[47,76],"defenses.":[50],"In":[51],"this":[52],"paper,":[53],"focus":[55],"images":[58,153],"generated":[59],"by":[60,179],"transformations.":[61,109],"We":[62,110],"start":[63],"with":[64],"color":[65,106],"transformation":[66,82,100,113,145],"propose":[68],"two":[69],"gradient-based":[70],"attacks.":[71,140,185],"Since":[72],"is":[74],"inappropriate":[75],"measuring":[77],"image":[78],"quality":[79],"in":[80],"the":[81,86,91,136],"space,":[83],"use":[85],"similarity":[87],"between":[88],"transformations":[89],"Structural":[92],"Similarity":[93],"Index.":[94],"Next,":[95],"a":[98,198],"larger":[99],"space":[101],"consisting":[102],"combinations":[104],"affine":[108],"evaluate":[111,135],"our":[112,139],"three":[116],"data":[117],"sets":[118],"---":[119,124],"CIFAR10,":[120],"SVHN,":[121],"ImageNet":[123],"corresponding":[127],"models.":[128],"Finally,":[129],"perform":[131],"retraining":[132,180],"defenses":[133],"strength":[137],"The":[141],"results":[142],"show":[143],"that":[144,154],"powerful.":[148],"They":[149,171],"find":[150],"high-quality":[151],"have":[155],"higher":[156],"transferability":[157],"misclassification":[159],"rates":[160],"than":[161,181],"C&W's":[162,182],"\\(L^p":[163,183],"\\)":[164,184],"attacks,":[165],"especially":[166],"at":[167],"high":[168],"confidence":[169],"levels.":[170],"significantly":[174],"harder":[175],"defend":[177],"against":[178],"More":[186],"importantly,":[187],"exploring":[188],"different":[189],"attack":[190],"spaces":[191],"makes":[192],"it":[193],"more":[194],"challenging":[195],"train":[197],"universally":[199],"robust":[200],"model.":[201]},"counts_by_year":[{"year":2025,"cited_by_count":4},{"year":2023,"cited_by_count":2},{"year":2022,"cited_by_count":1},{"year":2021,"cited_by_count":2},{"year":2020,"cited_by_count":3}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
