{"id":"https://openalex.org/W2902905500","doi":"https://doi.org/10.23919/eusipco.2018.8553164","title":"Detecting Adversarial Examples - a Lesson from Multimedia Security","display_name":"Detecting Adversarial Examples - a Lesson from Multimedia Security","publication_year":2018,"publication_date":"2018-09-01","ids":{"openalex":"https://openalex.org/W2902905500","doi":"https://doi.org/10.23919/eusipco.2018.8553164","mag":"2902905500"},"language":"en","primary_location":{"id":"doi:10.23919/eusipco.2018.8553164","is_oa":false,"landing_page_url":"https://doi.org/10.23919/eusipco.2018.8553164","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2018 26th European Signal Processing Conference (EUSIPCO)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5039542868","display_name":"Pascal Sch\u00f6ttle","orcid":"https://orcid.org/0000-0001-8710-9188"},"institutions":[{"id":"https://openalex.org/I190249584","display_name":"Universit\u00e4t Innsbruck","ror":"https://ror.org/054pv6659","country_code":"AT","type":"education","lineage":["https://openalex.org/I190249584"]}],"countries":["AT"],"is_corresponding":true,"raw_author_name":"Pascal Schottle","raw_affiliation_strings":["Department of Computer Science, University of Innsbruck, Innsbruck, Austria"],"affiliations":[{"raw_affiliation_string":"Department of Computer Science, University of Innsbruck, Innsbruck, Austria","institution_ids":["https://openalex.org/I190249584"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5075251080","display_name":"Alexander Schl\u00f6gl","orcid":null},"institutions":[{"id":"https://openalex.org/I190249584","display_name":"Universit\u00e4t Innsbruck","ror":"https://ror.org/054pv6659","country_code":"AT","type":"education","lineage":["https://openalex.org/I190249584"]}],"countries":["AT"],"is_corresponding":false,"raw_author_name":"Alexander Schlogl","raw_affiliation_strings":["Department of Computer Science, University of Innsbruck, Innsbruck, Austria"],"affiliations":[{"raw_affiliation_string":"Department of Computer Science, University of Innsbruck, Innsbruck, Austria","institution_ids":["https://openalex.org/I190249584"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5087688702","display_name":"Cecilia Pasquini","orcid":"https://orcid.org/0000-0002-2125-6983"},"institutions":[{"id":"https://openalex.org/I190249584","display_name":"Universit\u00e4t Innsbruck","ror":"https://ror.org/054pv6659","country_code":"AT","type":"education","lineage":["https://openalex.org/I190249584"]}],"countries":["AT"],"is_corresponding":false,"raw_author_name":"Cecilia Pasquini","raw_affiliation_strings":["Department of Computer Science, University of Innsbruck, Innsbruck, Austria"],"affiliations":[{"raw_affiliation_string":"Department of Computer Science, University of Innsbruck, Innsbruck, Austria","institution_ids":["https://openalex.org/I190249584"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5029455813","display_name":"Rainer B\u00f6hme","orcid":"https://orcid.org/0000-0003-4518-6227"},"institutions":[{"id":"https://openalex.org/I190249584","display_name":"Universit\u00e4t Innsbruck","ror":"https://ror.org/054pv6659","country_code":"AT","type":"education","lineage":["https://openalex.org/I190249584"]}],"countries":["AT"],"is_corresponding":false,"raw_author_name":"Rainer Bohme","raw_affiliation_strings":["Department of Computer Science, University of Innsbruck, Innsbruck, Austria"],"affiliations":[{"raw_affiliation_string":"Department of Computer Science, University of Innsbruck, Innsbruck, Austria","institution_ids":["https://openalex.org/I190249584"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5039542868"],"corresponding_institution_ids":["https://openalex.org/I190249584"],"apc_list":null,"apc_paid":null,"fwci":1.8593,"has_fulltext":false,"cited_by_count":26,"citation_normalized_percentile":{"value":0.8935799,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":91,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"947","last_page":"951"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9994000196456909,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9994000196456909,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12357","display_name":"Digital Media Forensic Detection","score":0.9944000244140625,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11515","display_name":"Bacillus and Francisella bacterial research","score":0.9829999804496765,"subfield":{"id":"https://openalex.org/subfields/1312","display_name":"Molecular Biology"},"field":{"id":"https://openalex.org/fields/13","display_name":"Biochemistry, Genetics and Molecular Biology"},"domain":{"id":"https://openalex.org/domains/1","display_name":"Life Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.8107326030731201},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7948060035705566},{"id":"https://openalex.org/keywords/steganalysis","display_name":"Steganalysis","score":0.6938040852546692},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.6334332823753357},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.5839192867279053},{"id":"https://openalex.org/keywords/adversarial-machine-learning","display_name":"Adversarial machine learning","score":0.5671194791793823},{"id":"https://openalex.org/keywords/contextual-image-classification","display_name":"Contextual image classification","score":0.5336443185806274},{"id":"https://openalex.org/keywords/classifier","display_name":"Classifier (UML)","score":0.48244673013687134},{"id":"https://openalex.org/keywords/context","display_name":"Context (archaeology)","score":0.4678797125816345},{"id":"https://openalex.org/keywords/mnist-database","display_name":"MNIST database","score":0.43738603591918945},{"id":"https://openalex.org/keywords/deep-learning","display_name":"Deep learning","score":0.43363243341445923},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.41995853185653687},{"id":"https://openalex.org/keywords/image","display_name":"Image (mathematics)","score":0.4136582612991333},{"id":"https://openalex.org/keywords/pattern-recognition","display_name":"Pattern recognition (psychology)","score":0.32122334837913513},{"id":"https://openalex.org/keywords/steganography","display_name":"Steganography","score":0.21199899911880493}],"concepts":[{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.8107326030731201},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7948060035705566},{"id":"https://openalex.org/C107368093","wikidata":"https://www.wikidata.org/wiki/Q448176","display_name":"Steganalysis","level":4,"score":0.6938040852546692},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.6334332823753357},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.5839192867279053},{"id":"https://openalex.org/C2778403875","wikidata":"https://www.wikidata.org/wiki/Q20312394","display_name":"Adversarial machine learning","level":3,"score":0.5671194791793823},{"id":"https://openalex.org/C75294576","wikidata":"https://www.wikidata.org/wiki/Q5165192","display_name":"Contextual image classification","level":3,"score":0.5336443185806274},{"id":"https://openalex.org/C95623464","wikidata":"https://www.wikidata.org/wiki/Q1096149","display_name":"Classifier (UML)","level":2,"score":0.48244673013687134},{"id":"https://openalex.org/C2779343474","wikidata":"https://www.wikidata.org/wiki/Q3109175","display_name":"Context (archaeology)","level":2,"score":0.4678797125816345},{"id":"https://openalex.org/C190502265","wikidata":"https://www.wikidata.org/wiki/Q17069496","display_name":"MNIST database","level":3,"score":0.43738603591918945},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.43363243341445923},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.41995853185653687},{"id":"https://openalex.org/C115961682","wikidata":"https://www.wikidata.org/wiki/Q860623","display_name":"Image (mathematics)","level":2,"score":0.4136582612991333},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.32122334837913513},{"id":"https://openalex.org/C108801101","wikidata":"https://www.wikidata.org/wiki/Q15032","display_name":"Steganography","level":3,"score":0.21199899911880493},{"id":"https://openalex.org/C86803240","wikidata":"https://www.wikidata.org/wiki/Q420","display_name":"Biology","level":0,"score":0.0},{"id":"https://openalex.org/C151730666","wikidata":"https://www.wikidata.org/wiki/Q7205","display_name":"Paleontology","level":1,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.23919/eusipco.2018.8553164","is_oa":false,"landing_page_url":"https://doi.org/10.23919/eusipco.2018.8553164","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2018 26th European Signal Processing Conference (EUSIPCO)","raw_type":"proceedings-article"},{"id":"pmh:oai:iris.unitn.it:11572/277625","is_oa":false,"landing_page_url":"http://hdl.handle.net/11572/277625","pdf_url":null,"source":{"id":"https://openalex.org/S4306401913","display_name":"Institutional Research Information System (Universit\u00e0 degli Studi di Trento)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I193223587","host_organization_name":"University of Trento","host_organization_lineage":["https://openalex.org/I193223587"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"info:eu-repo/semantics/conferenceObject"}],"best_oa_location":null,"sustainable_development_goals":[{"score":0.7200000286102295,"id":"https://metadata.un.org/sdg/16","display_name":"Peace, Justice and strong institutions"}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":33,"referenced_works":["https://openalex.org/W1482218439","https://openalex.org/W1575666629","https://openalex.org/W1673923490","https://openalex.org/W1945616565","https://openalex.org/W1964026338","https://openalex.org/W1969171557","https://openalex.org/W2015958747","https://openalex.org/W2112507308","https://openalex.org/W2151298633","https://openalex.org/W2159244236","https://openalex.org/W2167008044","https://openalex.org/W2180612164","https://openalex.org/W2408141691","https://openalex.org/W2539093944","https://openalex.org/W2543927648","https://openalex.org/W2607219512","https://openalex.org/W2612637113","https://openalex.org/W2744095836","https://openalex.org/W2879765882","https://openalex.org/W2963207607","https://openalex.org/W2963857521","https://openalex.org/W2964153729","https://openalex.org/W2964253222","https://openalex.org/W3102720581","https://openalex.org/W3103940881","https://openalex.org/W4253000688","https://openalex.org/W4293846201","https://openalex.org/W6637162671","https://openalex.org/W6676935882","https://openalex.org/W6739868092","https://openalex.org/W6742823662","https://openalex.org/W6752949846","https://openalex.org/W6786639168"],"related_works":["https://openalex.org/W3048732067","https://openalex.org/W4383468834","https://openalex.org/W4384648009","https://openalex.org/W4303645823","https://openalex.org/W2900159906","https://openalex.org/W4283221438","https://openalex.org/W4287828318","https://openalex.org/W2406556600","https://openalex.org/W2899811703","https://openalex.org/W2930249865"],"abstract_inverted_index":{"Adversarial":[0],"classification":[1,8,24,45,216],"is":[2],"the":[3,10,37,75,108,123,152,158,169,189,200,230],"task":[4],"of":[5,12,29,39,59,110,118,178,191,203,232],"performing":[6],"robust":[7],"in":[9,31,102,238],"presence":[11],"a":[13,27,32,70,136],"strategic":[14],"attacker.":[15],"Originating":[16],"from":[17,223,235],"information":[18],"hiding":[19],"and":[20,113,129,172,194,225],"multimedia":[21,111,119,236],"forensics,":[22],"adversarial":[23,44,52,96,146,186,192,212,240],"recently":[25],"received":[26],"lot":[28],"attention":[30],"broader":[33],"security":[34,237],"context.":[35],"In":[36],"domain":[38],"machine":[40,131],"learning-based":[41],"image":[42,85,215],"classification,":[43],"can":[46,183],"be":[47,67,91],"interpreted":[48],"as":[49],"detecting":[50,99],"so-called":[51],"examples,":[53],"which":[54,81],"are":[55,63,149],"slightly":[56],"altered":[57],"versions":[58],"benign":[60],"images.":[61],"They":[62],"specifically":[64],"crafted":[65],"to":[66,90,94,140,144],"misclassified":[68],"with":[69,151],"very":[71],"high":[72],"probability":[73],"by":[74],"classifier":[76],"under":[77],"attack.":[78],"Neural":[79],"networks,":[80],"dominate":[82],"among":[83],"modern":[84],"classifiers,":[86],"have":[87],"been":[88,107],"shown":[89],"especially":[92],"vulnerable":[93],"these":[95,127],"examples.":[97,187],"However,":[98],"subtle":[100],"changes":[101],"digital":[103],"images":[104],"has":[105],"always":[106],"goal":[109],"forensics":[112],"steganalysis,":[114,224],"two":[115],"major":[116],"subfields":[117],"security.":[120],"We":[121,164],"highlight":[122],"conceptual":[124],"similarities":[125],"between":[126],"fields":[128],"secure":[130],"learning.":[132],"Furthermore,":[133],"we":[134,209],"adapt":[135],"linear":[137],"filter,":[138],"similar":[139],"early":[141],"steganalysis":[142],"methods,":[143],"detect":[145,185],"examples":[147,213],"that":[148,180,211],"generated":[150],"projected":[153],"gradient":[154],"descent":[155],"(PGD)":[156],"method,":[157],"state-of-the-art":[159],"algorithm":[160],"for":[161,174,214],"this":[162],"task.":[163],"test":[165],"our":[166,181,195],"method":[167,182,197],"on":[168],"MNIST":[170],"database":[171],"show":[173],"several":[175],"parameter":[176],"combinations":[177],"PGD":[179],"reliably":[184],"Additionally,":[188],"combination":[190],"re-training":[193],"detection":[196,221],"effectively":[198],"reduces":[199],"attack":[201],"surface":[202],"attacks":[204],"against":[205],"neural":[206],"networks.":[207],"Thus,":[208],"conclude":[210],"possibly":[217],"do":[218],"not":[219],"withstand":[220],"methods":[222],"future":[226],"work":[227],"should":[228],"explore":[229],"effectiveness":[231],"known":[233],"techniques":[234],"other":[239],"settings.":[241]},"counts_by_year":[{"year":2025,"cited_by_count":1},{"year":2024,"cited_by_count":2},{"year":2023,"cited_by_count":5},{"year":2022,"cited_by_count":7},{"year":2021,"cited_by_count":3},{"year":2020,"cited_by_count":6},{"year":2019,"cited_by_count":2}],"updated_date":"2026-04-04T16:13:02.066488","created_date":"2018-12-11T00:00:00"}
