{"id":"https://openalex.org/W2963448658","doi":"https://doi.org/10.24963/ijcai.2018/543","title":"Generating Adversarial Examples with Adversarial Networks","display_name":"Generating Adversarial Examples with Adversarial Networks","publication_year":2018,"publication_date":"2018-07-01","ids":{"openalex":"https://openalex.org/W2963448658","doi":"https://doi.org/10.24963/ijcai.2018/543","mag":"2963448658"},"language":"en","primary_location":{"id":"doi:10.24963/ijcai.2018/543","is_oa":true,"landing_page_url":"https://doi.org/10.24963/ijcai.2018/543","pdf_url":"https://www.ijcai.org/proceedings/2018/0543.pdf","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the Twenty-Seventh International Joint Conference on Artificial Intelligence","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://www.ijcai.org/proceedings/2018/0543.pdf","any_repository_has_fulltext":null},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5005843046","display_name":"Chaowei Xiao","orcid":"https://orcid.org/0000-0002-7043-4926"},"institutions":[{"id":"https://openalex.org/I27837315","display_name":"University of Michigan\u2013Ann Arbor","ror":"https://ror.org/00jmfr291","country_code":"US","type":"education","lineage":["https://openalex.org/I27837315"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Chaowei Xiao","raw_affiliation_strings":["University of Michigan, Ann Arbor"],"affiliations":[{"raw_affiliation_string":"University of Michigan, Ann Arbor","institution_ids":["https://openalex.org/I27837315"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100374474","display_name":"Bo Li","orcid":"https://orcid.org/0000-0002-9336-1862"},"institutions":[{"id":"https://openalex.org/I95457486","display_name":"University of California, Berkeley","ror":"https://ror.org/01an7q238","country_code":"US","type":"education","lineage":["https://openalex.org/I95457486"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Bo Li","raw_affiliation_strings":["University of California, Berkeley"],"affiliations":[{"raw_affiliation_string":"University of California, Berkeley","institution_ids":["https://openalex.org/I95457486"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5102883508","display_name":"Jun-Yan Zhu","orcid":"https://orcid.org/0000-0001-8504-3410"},"institutions":[{"id":"https://openalex.org/I95457486","display_name":"University of California, Berkeley","ror":"https://ror.org/01an7q238","country_code":"US","type":"education","lineage":["https://openalex.org/I95457486"]},{"id":"https://openalex.org/I63966007","display_name":"Massachusetts Institute of Technology","ror":"https://ror.org/042nb2s44","country_code":"US","type":"education","lineage":["https://openalex.org/I63966007"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Jun-yan Zhu","raw_affiliation_strings":["Massachusetts Institute of Technology","University of California, Berkeley"],"affiliations":[{"raw_affiliation_string":"Massachusetts Institute of Technology","institution_ids":["https://openalex.org/I63966007"]},{"raw_affiliation_string":"University of California, Berkeley","institution_ids":["https://openalex.org/I95457486"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5034909490","display_name":"Warren He","orcid":null},"institutions":[{"id":"https://openalex.org/I95457486","display_name":"University of California, Berkeley","ror":"https://ror.org/01an7q238","country_code":"US","type":"education","lineage":["https://openalex.org/I95457486"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Warren He","raw_affiliation_strings":["University of California, Berkeley"],"affiliations":[{"raw_affiliation_string":"University of California, Berkeley","institution_ids":["https://openalex.org/I95457486"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101967011","display_name":"Mingyan Liu","orcid":"https://orcid.org/0000-0003-3295-9200"},"institutions":[{"id":"https://openalex.org/I27837315","display_name":"University of Michigan\u2013Ann Arbor","ror":"https://ror.org/00jmfr291","country_code":"US","type":"education","lineage":["https://openalex.org/I27837315"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Mingyan Liu","raw_affiliation_strings":["University of Michigan, Ann Arbor"],"affiliations":[{"raw_affiliation_string":"University of Michigan, Ann Arbor","institution_ids":["https://openalex.org/I27837315"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5019426968","display_name":"Dawn Song","orcid":"https://orcid.org/0000-0001-9745-6802"},"institutions":[{"id":"https://openalex.org/I95457486","display_name":"University of California, Berkeley","ror":"https://ror.org/01an7q238","country_code":"US","type":"education","lineage":["https://openalex.org/I95457486"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Dawn Song","raw_affiliation_strings":["University of California, Berkeley"],"affiliations":[{"raw_affiliation_string":"University of California, Berkeley","institution_ids":["https://openalex.org/I95457486"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":6,"corresponding_author_ids":["https://openalex.org/A5005843046"],"corresponding_institution_ids":["https://openalex.org/I27837315"],"apc_list":null,"apc_paid":null,"fwci":44.7925,"has_fulltext":true,"cited_by_count":785,"citation_normalized_percentile":{"value":0.9982469,"is_in_top_1_percent":true,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":90,"max":100},"biblio":{"volume":null,"issue":null,"first_page":"3905","last_page":"3911"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9243000149726868,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.948416531085968},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8472320437431335},{"id":"https://openalex.org/keywords/adversary","display_name":"Adversary","score":0.7180635333061218},{"id":"https://openalex.org/keywords/generator","display_name":"Generator (circuit theory)","score":0.7026886343955994},{"id":"https://openalex.org/keywords/mnist-database","display_name":"MNIST database","score":0.6762917637825012},{"id":"https://openalex.org/keywords/black-box","display_name":"Black box","score":0.6005066633224487},{"id":"https://openalex.org/keywords/deep-neural-networks","display_name":"Deep neural networks","score":0.593406081199646},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.4717472493648529},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.4504552483558655},{"id":"https://openalex.org/keywords/state","display_name":"State (computer science)","score":0.4340435564517975},{"id":"https://openalex.org/keywords/key","display_name":"Key (lock)","score":0.4146532416343689},{"id":"https://openalex.org/keywords/theoretical-computer-science","display_name":"Theoretical computer science","score":0.37245973944664},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.35772573947906494},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.35461926460266113},{"id":"https://openalex.org/keywords/algorithm","display_name":"Algorithm","score":0.2547844648361206},{"id":"https://openalex.org/keywords/power","display_name":"Power (physics)","score":0.08383557200431824}],"concepts":[{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.948416531085968},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8472320437431335},{"id":"https://openalex.org/C41065033","wikidata":"https://www.wikidata.org/wiki/Q2825412","display_name":"Adversary","level":2,"score":0.7180635333061218},{"id":"https://openalex.org/C2780992000","wikidata":"https://www.wikidata.org/wiki/Q17016113","display_name":"Generator (circuit theory)","level":3,"score":0.7026886343955994},{"id":"https://openalex.org/C190502265","wikidata":"https://www.wikidata.org/wiki/Q17069496","display_name":"MNIST database","level":3,"score":0.6762917637825012},{"id":"https://openalex.org/C94966114","wikidata":"https://www.wikidata.org/wiki/Q29256","display_name":"Black box","level":2,"score":0.6005066633224487},{"id":"https://openalex.org/C2984842247","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep neural networks","level":3,"score":0.593406081199646},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.4717472493648529},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.4504552483558655},{"id":"https://openalex.org/C48103436","wikidata":"https://www.wikidata.org/wiki/Q599031","display_name":"State (computer science)","level":2,"score":0.4340435564517975},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.4146532416343689},{"id":"https://openalex.org/C80444323","wikidata":"https://www.wikidata.org/wiki/Q2878974","display_name":"Theoretical computer science","level":1,"score":0.37245973944664},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.35772573947906494},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.35461926460266113},{"id":"https://openalex.org/C11413529","wikidata":"https://www.wikidata.org/wiki/Q8366","display_name":"Algorithm","level":1,"score":0.2547844648361206},{"id":"https://openalex.org/C163258240","wikidata":"https://www.wikidata.org/wiki/Q25342","display_name":"Power (physics)","level":2,"score":0.08383557200431824},{"id":"https://openalex.org/C121332964","wikidata":"https://www.wikidata.org/wiki/Q413","display_name":"Physics","level":0,"score":0.0},{"id":"https://openalex.org/C62520636","wikidata":"https://www.wikidata.org/wiki/Q944","display_name":"Quantum mechanics","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.24963/ijcai.2018/543","is_oa":true,"landing_page_url":"https://doi.org/10.24963/ijcai.2018/543","pdf_url":"https://www.ijcai.org/proceedings/2018/0543.pdf","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the Twenty-Seventh International Joint Conference on Artificial Intelligence","raw_type":"proceedings-article"}],"best_oa_location":{"id":"doi:10.24963/ijcai.2018/543","is_oa":true,"landing_page_url":"https://doi.org/10.24963/ijcai.2018/543","pdf_url":"https://www.ijcai.org/proceedings/2018/0543.pdf","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the Twenty-Seventh International Joint Conference on Artificial Intelligence","raw_type":"proceedings-article"},"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G2025953833","display_name":null,"funder_award_id":"CNS-1238959, CNS-1238962, CNS-1239054, CNS-1239166","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G2256232009","display_name":null,"funder_award_id":"CNS-1239054","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G2258753692","display_name":null,"funder_award_id":"CNS-1616575","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G2853312554","display_name":"CPS: Frontiers: Collaborative Research: Foundations of Resilient CybEr-Physical Systems (FORCES)","funder_award_id":"1238962","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G371206825","display_name":null,"funder_award_id":"CNS-1238","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G4149680450","display_name":null,"funder_award_id":"CNS-1239166","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G4919727899","display_name":"TTP: Small: Network-Level Security Posture Assessment and Predictive Analytics: From Theory to Practice","funder_award_id":"1616575","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G5921281487","display_name":null,"funder_award_id":"number","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G7489832056","display_name":null,"funder_award_id":"1239054","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G7755306388","display_name":null,"funder_award_id":"1239166","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G8305956998","display_name":null,"funder_award_id":"CNS-1238962","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G848032724","display_name":null,"funder_award_id":"Science","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"}],"funders":[{"id":"https://openalex.org/F4320306076","display_name":"National Science Foundation","ror":"https://ror.org/021nxhr62"},{"id":"https://openalex.org/F4320333609","display_name":"Center for Long-Term Cybersecurity, University of California Berkeley","ror":null}],"has_content":{"pdf":true,"grobid_xml":true},"content_urls":{"pdf":"https://content.openalex.org/works/W2963448658.pdf","grobid_xml":"https://content.openalex.org/works/W2963448658.grobid-xml"},"referenced_works_count":26,"referenced_works":["https://openalex.org/W1673923490","https://openalex.org/W1821462560","https://openalex.org/W1945616565","https://openalex.org/W2194775991","https://openalex.org/W2274565976","https://openalex.org/W2519536754","https://openalex.org/W2552465644","https://openalex.org/W2570685808","https://openalex.org/W2593414223","https://openalex.org/W2604147826","https://openalex.org/W2605287558","https://openalex.org/W2619479788","https://openalex.org/W2625220439","https://openalex.org/W2741933435","https://openalex.org/W2783784437","https://openalex.org/W2795727551","https://openalex.org/W2962793481","https://openalex.org/W2963073614","https://openalex.org/W2963744840","https://openalex.org/W2963857521","https://openalex.org/W2964137095","https://openalex.org/W3118608800","https://openalex.org/W4293846201","https://openalex.org/W4320013936","https://openalex.org/W6726114608","https://openalex.org/W6738915422"],"related_works":["https://openalex.org/W4320018150","https://openalex.org/W4239582170","https://openalex.org/W2918664383","https://openalex.org/W106056076","https://openalex.org/W4320855730","https://openalex.org/W2135200719","https://openalex.org/W2950183588","https://openalex.org/W3080754722","https://openalex.org/W3093978547","https://openalex.org/W2953536436"],"abstract_inverted_index":{"Deep":[0],"neural":[1],"networks":[2,70],"(DNNs)":[3],"have":[4,33,168],"been":[5,34],"found":[6],"to":[7,10,18,26,36,42,62,99,124,137,177],"be":[8],"vulnerable":[9],"adversarial":[11,21,38,64,69,102],"examples":[12,22,160],"resulting":[13],"from":[14],"adding":[15],"small-magnitude":[16],"perturbations":[17,92],"inputs.":[19],"Such":[20],"can":[23,73,90],"mislead":[24],"DNNs":[25],"produce":[27,43],"adversary-selected":[28],"results.":[29],"Different":[30],"attack":[31,115,170,181,194],"strategies":[32],"proposed":[35],"generate":[37,63,91],"examples,":[39],"but":[40],"how":[41],"them":[44],"with":[45,67,186],"high":[46,169],"perceptual":[47],"quality":[48],"and":[49,75,113,154],"more":[50,53],"efficiently":[51,93],"requires":[52],"research":[54],"efforts.":[55],"In":[56,117,141],"this":[57],"paper,":[58],"we":[59,144],"propose":[60],"AdvGAN":[61,163],"exam-":[65],"ples":[66],"generative":[68],"(GANs),":[71],"which":[72],"learn":[74],"approximate":[76],"the":[77,85,126,131,151,156,184],"distribution":[78],"of":[79],"original":[80,127],"instances.":[81],"For":[82],"AdvGAN,":[83],"once":[84],"generator":[86,132,157],"is":[87,121,133],"trained,":[88,134],"it":[89],"for":[94,150],"any":[95],"instance,":[96],"so":[97],"as":[98,104],"potentially":[100],"accelerate":[101],"training":[103],"defenses.":[105],"We":[106],"apply":[107],"Adv-":[108],"GAN":[109],"in":[110,135],"both":[111],"semi-whitebox":[112,118],"black-box":[114,142,152,193],"settings.":[116],"attacks,":[119,143],"there":[120],"no":[122],"need":[123],"access":[125],"target":[128,166],"model":[129,149,153],"after":[130],"contrast":[136],"traditional":[138],"white-box":[139],"attacks.":[140,179],"dynamically":[145],"train":[146],"a":[147,190],"distilled":[148],"optimize":[155],"accordingly.":[158],"Adversarial":[159],"generated":[161],"by":[162],"on":[164,189],"different":[165],"models":[167],"success":[171],"rate":[172],"under":[173],"state-of-the-art":[174],"defenses":[175],"compared":[176],"other":[178],"Our":[180],"has":[182],"placed":[183],"first":[185],"92.76%":[187],"accuracy":[188],"public":[191],"MNIST":[192],"challenge.":[195]},"counts_by_year":[{"year":2026,"cited_by_count":26},{"year":2025,"cited_by_count":107},{"year":2024,"cited_by_count":115},{"year":2023,"cited_by_count":159},{"year":2022,"cited_by_count":112},{"year":2021,"cited_by_count":114},{"year":2020,"cited_by_count":87},{"year":2019,"cited_by_count":51},{"year":2018,"cited_by_count":13},{"year":2017,"cited_by_count":1}],"updated_date":"2026-04-04T16:13:02.066488","created_date":"2025-10-10T00:00:00"}
