{"id":"https://openalex.org/W2584321260","doi":"https://doi.org/10.1162/neco_a_01143","title":"Dense Associative Memory Is Robust to Adversarial Inputs","display_name":"Dense Associative Memory Is Robust to Adversarial Inputs","publication_year":2018,"publication_date":"2018-10-13","ids":{"openalex":"https://openalex.org/W2584321260","doi":"https://doi.org/10.1162/neco_a_01143","mag":"2584321260","pmid":"https://pubmed.ncbi.nlm.nih.gov/30314425"},"language":"en","primary_location":{"id":"doi:10.1162/neco_a_01143","is_oa":true,"landing_page_url":"https://doi.org/10.1162/neco_a_01143","pdf_url":"https://direct.mit.edu/neco/article-pdf/30/12/3151/1048104/neco_a_01143.pdf","source":{"id":"https://openalex.org/S207023548","display_name":"Neural Computation","issn_l":"0899-7667","issn":["0899-7667","1530-888X"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310315718","host_organization_name":"The MIT Press","host_organization_lineage":["https://openalex.org/P4310315718"],"host_organization_lineage_names":["The MIT Press"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Neural Computation","raw_type":"journal-article"},"type":"article","indexed_in":["arxiv","crossref","pubmed"],"open_access":{"is_oa":true,"oa_status":"bronze","oa_url":"https://direct.mit.edu/neco/article-pdf/30/12/3151/1048104/neco_a_01143.pdf","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":null,"display_name":"Dmitry Krotov","orcid":null},"institutions":[{"id":"https://openalex.org/I40036882","display_name":"Institute for Advanced Study","ror":"https://ror.org/00f809463","country_code":"US","type":"facility","lineage":["https://openalex.org/I40036882"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Dmitry Krotov","raw_affiliation_strings":["Institute for Advanced Study, Princeton, NJ 08540, U.S.A"],"affiliations":[{"raw_affiliation_string":"Institute for Advanced Study, Princeton, NJ 08540, U.S.A","institution_ids":["https://openalex.org/I40036882"]}]},{"author_position":"last","author":{"id":null,"display_name":"John Hopfield","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"John Hopfield","raw_affiliation_strings":["Princeton Neuroscience Institute, Princeton, NJ 08544, U.S.A"],"affiliations":[{"raw_affiliation_string":"Princeton Neuroscience Institute, Princeton, NJ 08544, U.S.A","institution_ids":[]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":2,"corresponding_author_ids":[],"corresponding_institution_ids":["https://openalex.org/I40036882"],"apc_list":null,"apc_paid":null,"fwci":4.3999,"has_fulltext":false,"cited_by_count":65,"citation_normalized_percentile":{"value":0.95407301,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":90,"max":99},"biblio":{"volume":"30","issue":"12","first_page":"3151","last_page":"3167"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9336000084877014,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9336000084877014,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12026","display_name":"Explainable Artificial Intelligence (XAI)","score":0.016499999910593033,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10775","display_name":"Generative Adversarial Networks and Image Synthesis","score":0.009100000374019146,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/maxima-and-minima","display_name":"Maxima and minima","score":0.6671000123023987},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.5515000224113464},{"id":"https://openalex.org/keywords/associative-property","display_name":"Associative property","score":0.5157999992370605},{"id":"https://openalex.org/keywords/decision-boundary","display_name":"Decision boundary","score":0.49410000443458557},{"id":"https://openalex.org/keywords/content-addressable-memory","display_name":"Content-addressable memory","score":0.4717000126838684},{"id":"https://openalex.org/keywords/function","display_name":"Function (biology)","score":0.4587000012397766},{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.4108000099658966},{"id":"https://openalex.org/keywords/deep-neural-networks","display_name":"Deep neural networks","score":0.3865000009536743}],"concepts":[{"id":"https://openalex.org/C186633575","wikidata":"https://www.wikidata.org/wiki/Q845060","display_name":"Maxima and minima","level":2,"score":0.6671000123023987},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.6474999785423279},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6412000060081482},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.5515000224113464},{"id":"https://openalex.org/C159423971","wikidata":"https://www.wikidata.org/wiki/Q177251","display_name":"Associative property","level":2,"score":0.5157999992370605},{"id":"https://openalex.org/C42023084","wikidata":"https://www.wikidata.org/wiki/Q5249231","display_name":"Decision boundary","level":3,"score":0.49410000443458557},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.48069998621940613},{"id":"https://openalex.org/C53442348","wikidata":"https://www.wikidata.org/wiki/Q745101","display_name":"Content-addressable memory","level":3,"score":0.4717000126838684},{"id":"https://openalex.org/C14036430","wikidata":"https://www.wikidata.org/wiki/Q3736076","display_name":"Function (biology)","level":2,"score":0.4587000012397766},{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.4108000099658966},{"id":"https://openalex.org/C2984842247","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep neural networks","level":3,"score":0.3865000009536743},{"id":"https://openalex.org/C103278499","wikidata":"https://www.wikidata.org/wiki/Q254465","display_name":"Similarity (geometry)","level":3,"score":0.37549999356269836},{"id":"https://openalex.org/C62354387","wikidata":"https://www.wikidata.org/wiki/Q875399","display_name":"Boundary (topology)","level":2,"score":0.3691999912261963},{"id":"https://openalex.org/C186370098","wikidata":"https://www.wikidata.org/wiki/Q442787","display_name":"Energy (signal processing)","level":2,"score":0.3546999990940094},{"id":"https://openalex.org/C151201525","wikidata":"https://www.wikidata.org/wiki/Q177239","display_name":"Limit (mathematics)","level":2,"score":0.3537999987602234},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.35010001063346863},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.3208000063896179},{"id":"https://openalex.org/C26760741","wikidata":"https://www.wikidata.org/wiki/Q160402","display_name":"Perception","level":2,"score":0.3176000118255615},{"id":"https://openalex.org/C21080849","wikidata":"https://www.wikidata.org/wiki/Q13611879","display_name":"Data point","level":2,"score":0.30160000920295715},{"id":"https://openalex.org/C136389625","wikidata":"https://www.wikidata.org/wiki/Q334384","display_name":"Supervised learning","level":3,"score":0.265500009059906}],"mesh":[{"descriptor_ui":"D001921","descriptor_name":"Brain","qualifier_ui":"Q000502","qualifier_name":"physiology","is_major_topic":false},{"descriptor_ui":"D001921","descriptor_name":"Brain","qualifier_ui":"Q000502","qualifier_name":"physiology","is_major_topic":false},{"descriptor_ui":"D001921","descriptor_name":"Brain","qualifier_ui":"Q000502","qualifier_name":"physiology","is_major_topic":false},{"descriptor_ui":"D006801","descriptor_name":"Humans","qualifier_ui":null,"qualifier_name":null,"is_major_topic":false},{"descriptor_ui":"D006801","descriptor_name":"Humans","qualifier_ui":null,"qualifier_name":null,"is_major_topic":false},{"descriptor_ui":"D006801","descriptor_name":"Humans","qualifier_ui":null,"qualifier_name":null,"is_major_topic":false},{"descriptor_ui":"D010364","descriptor_name":"Pattern Recognition, Visual","qualifier_ui":"Q000502","qualifier_name":"physiology","is_major_topic":false},{"descriptor_ui":"D010364","descriptor_name":"Pattern Recognition, Visual","qualifier_ui":"Q000502","qualifier_name":"physiology","is_major_topic":false},{"descriptor_ui":"D010364","descriptor_name":"Pattern Recognition, Visual","qualifier_ui":"Q000502","qualifier_name":"physiology","is_major_topic":false},{"descriptor_ui":"D016571","descriptor_name":"Neural Networks, Computer","qualifier_ui":null,"qualifier_name":null,"is_major_topic":true},{"descriptor_ui":"D016571","descriptor_name":"Neural Networks, Computer","qualifier_ui":null,"qualifier_name":null,"is_major_topic":true},{"descriptor_ui":"D016571","descriptor_name":"Neural Networks, Computer","qualifier_ui":null,"qualifier_name":null,"is_major_topic":true}],"locations_count":3,"locations":[{"id":"doi:10.1162/neco_a_01143","is_oa":true,"landing_page_url":"https://doi.org/10.1162/neco_a_01143","pdf_url":"https://direct.mit.edu/neco/article-pdf/30/12/3151/1048104/neco_a_01143.pdf","source":{"id":"https://openalex.org/S207023548","display_name":"Neural Computation","issn_l":"0899-7667","issn":["0899-7667","1530-888X"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310315718","host_organization_name":"The MIT Press","host_organization_lineage":["https://openalex.org/P4310315718"],"host_organization_lineage_names":["The MIT Press"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Neural Computation","raw_type":"journal-article"},{"id":"pmid:30314425","is_oa":false,"landing_page_url":"https://pubmed.ncbi.nlm.nih.gov/30314425","pdf_url":null,"source":{"id":"https://openalex.org/S4306525036","display_name":"PubMed","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I1299303238","host_organization_name":"National Institutes of Health","host_organization_lineage":["https://openalex.org/I1299303238"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Neural computation","raw_type":null},{"id":"pmh:oai:arXiv.org:1701.00939","is_oa":true,"landing_page_url":"http://arxiv.org/abs/1701.00939","pdf_url":"https://arxiv.org/pdf/1701.00939","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"}],"best_oa_location":{"id":"doi:10.1162/neco_a_01143","is_oa":true,"landing_page_url":"https://doi.org/10.1162/neco_a_01143","pdf_url":"https://direct.mit.edu/neco/article-pdf/30/12/3151/1048104/neco_a_01143.pdf","source":{"id":"https://openalex.org/S207023548","display_name":"Neural Computation","issn_l":"0899-7667","issn":["0899-7667","1530-888X"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310315718","host_organization_name":"The MIT Press","host_organization_lineage":["https://openalex.org/P4310315718"],"host_organization_lineage_names":["The MIT Press"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Neural Computation","raw_type":"journal-article"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":true,"grobid_xml":true},"content_urls":{"pdf":"https://content.openalex.org/works/W2584321260.pdf","grobid_xml":"https://content.openalex.org/works/W2584321260.grobid-xml"},"referenced_works_count":2,"referenced_works":["https://openalex.org/W1932198206","https://openalex.org/W2156163116"],"related_works":[],"abstract_inverted_index":{"Deep":[0],"neural":[1],"networks":[2],"(DNNs)":[3],"trained":[4],"in":[5,22,138,148],"a":[6,45,52,87,179],"supervised":[7],"way":[8],"suffer":[9],"from":[10,171],"two":[11],"known":[12,29],"problems.":[13],"First,":[14,162],"the":[15,18,41,63,70,75,78,101,110,123,133,139,142,145,149,158,163,166,189,220,238,246],"minima":[16,164],"of":[17,89,112,144,165,200,219,248],"objective":[19,167],"function":[20,151,168],"used":[21],"learning":[23,91],"correspond":[24],"to":[25,100,194,226,233,235,273],"data":[26],"points":[27],"(also":[28],"as":[30],"rubbish":[31,172,276],"examples":[32],"or":[33],"fooling":[34],"images)":[35],"that":[36,62,93,137,175,203,207,264],"lack":[37],"semantic":[38],"similarity":[39],"with":[40,126,216,228,240,266,280],"training":[42],"data.":[43],"Second,":[44,183],"clean":[46],"input":[47,66],"can":[48],"be":[49],"changed":[50],"by":[51,69,122,206,214],"small,":[53],"and":[54,81,85,197,236,254,275],"often":[55],"imperceptible":[56],"for":[57,252],"human":[58,97,195],"vision,":[59],"perturbation":[60],"so":[61,174],"resulting":[64],"deformed":[65],"is":[67,152,178],"misclassified":[68],"network.":[71],"These":[72,118],"findings":[73],"emphasize":[74],"differences":[76],"between":[77,132],"ways":[79],"DNNs":[80,279],"humans":[82],"classify":[83],"patterns":[84,185],"raise":[86],"question":[88],"designing":[90],"algorithms":[92],"more":[94,271],"accurately":[95],"mimic":[96],"perception":[98],"compared":[99],"existing":[102],"methods.":[103],"Our":[104],"article":[105],"examines":[106],"these":[107,155],"questions":[108],"within":[109],"framework":[111],"dense":[113],"associative":[114],"memory":[115],"(DAM)":[116],"models.":[117],"models":[119,156,215,239,251],"are":[120,169,204,224,270],"defined":[121],"energy":[124,150,268],"function,":[125],"higher-order":[127,241,250,267],"(higher":[128],"than":[129,278],"quadratic)":[130],"interactions":[131],"neurons.":[134],"We":[135],"show":[136],"limit":[140],"when":[141],"power":[143,218],"interaction":[146,221],"vertex":[147],"sufficiently":[153],"large,":[154],"have":[157],"following":[159],"three":[160],"properties.":[161],"free":[170],"images,":[173],"each":[176],"minimum":[177],"semantically":[180],"meaningful":[181],"pattern.":[182],"artificial":[184],"poised":[186],"precisely":[187],"at":[188],"decision":[190,208],"boundary":[191],"look":[192],"ambiguous":[193],"subjects":[196],"share":[198],"aspects":[199],"both":[201],"classes":[202],"separated":[205],"boundary.":[209],"Third,":[210],"adversarial":[211,257,274],"images":[212],"constructed":[213],"small":[217],"vertex,":[222],"which":[223],"equivalent":[225],"DNN":[227],"rectified":[229,281],"linear":[230,282],"units,":[231],"fail":[232],"transfer":[234],"fool":[237],"interactions.":[242],"This":[243],"opens":[244],"up":[245],"possibility":[247],"using":[249],"detecting":[253],"stopping":[255],"malicious":[256],"attacks.":[258],"The":[259],"results":[260],"we":[261],"present":[262],"suggest":[263],"DAMs":[265],"functions":[269],"robust":[272],"inputs":[277],"units.":[283]},"counts_by_year":[{"year":2026,"cited_by_count":2},{"year":2025,"cited_by_count":11},{"year":2024,"cited_by_count":13},{"year":2023,"cited_by_count":6},{"year":2022,"cited_by_count":6},{"year":2021,"cited_by_count":6},{"year":2020,"cited_by_count":9},{"year":2019,"cited_by_count":7},{"year":2018,"cited_by_count":4},{"year":2017,"cited_by_count":1}],"updated_date":"2026-03-20T23:20:44.827607","created_date":"2017-02-10T00:00:00"}
