{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,9,5]],"date-time":"2024-09-05T23:17:54Z","timestamp":1725578274250},"reference-count":30,"publisher":"IEEE","license":[{"start":{"date-parts":[[2021,11,29]],"date-time":"2021-11-29T00:00:00Z","timestamp":1638144000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2021,11,29]],"date-time":"2021-11-29T00:00:00Z","timestamp":1638144000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2021,11,29]],"date-time":"2021-11-29T00:00:00Z","timestamp":1638144000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2021,11,29]]},"DOI":"10.1109\/milcom52596.2021.9653101","type":"proceedings-article","created":{"date-parts":[[2021,12,30]],"date-time":"2021-12-30T21:06:10Z","timestamp":1640898370000},"page":"189-196","source":"Crossref","is-referenced-by-count":0,"title":["Beyond $L_{p}$ Norms: Delving Deeper into Robustness to Physical Image Transformations"],"prefix":"10.1109","author":[{"given":"Vikash","family":"Sehwag","sequence":"first","affiliation":[]},{"given":"Jack W.","family":"Stokes","sequence":"additional","affiliation":[]},{"given":"Cha","family":"Zhang","sequence":"additional","affiliation":[]}],"member":"263","reference":[{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00467"},{"key":"ref11","first-page":"1802","article-title":"Exploring the landscape of spatial robustness","author":"engstrom","year":"0","journal-title":"International Conference on Machine Learning"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW.2018.00212"},{"key":"ref13","first-page":"10408","article-title":"Functional adversarial attacks","author":"laidlaw","year":"2019","journal-title":"Advances in neural information processing systems"},{"key":"ref14","first-page":"5866","article-title":"Adversarial training and robustness for multiple perturbations","author":"tram\u00e8r","year":"0","journal-title":"Advances in neural information processing systems"},{"key":"ref15","article-title":"Towards deep learning models resistant to adversarial attacks","author":"madry","year":"2017","journal-title":"ArXiv Preprint"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW.2018.00211"},{"key":"ref17","article-title":"Beyond pixel norm-balls: Parametric adversaries using an analytically differentiable renderer","author":"liu","year":"2018","journal-title":"ArXiv Preprint"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1145\/3374664.3375728"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1145\/3317611"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/SIBGRAPI.2018.00067"},{"key":"ref28","doi-asserted-by":"crossref","first-page":"248","DOI":"10.1109\/CVPR.2009.5206848","article-title":"Imagenet: A large-scale hierarchical image database","author":"deng","year":"2009","journal-title":"2009 IEEE Conference on Computer Vision and Pattern Recognition"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.5244\/C.29.41"},{"journal-title":"imgaug","year":"2020","author":"jung","key":"ref27"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1001\/jama.2016.17216"},{"key":"ref29","article-title":"Robustness may be at odds with accuracy","author":"tsipras","year":"2018","journal-title":"ArXiv Preprint"},{"key":"ref5","article-title":"Solving rubik's cube with a robot hand","author":"akkaya","year":"2019","journal-title":"ArXiv Preprint"},{"key":"ref8","article-title":"Why do deep convolutional networks generalize so poorly to small image transformations?","author":"azulay","year":"2018","journal-title":"ArXiv Preprint"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1038\/s41591-018-0316-z"},{"key":"ref2","article-title":"End to end learning for self-driving cars","author":"bojarski","year":"2016","journal-title":"ArXiv Preprint"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2015.312"},{"key":"ref9","article-title":"Benchmarking neural network robustness to common corruptions and perturbations","author":"hendrycks","year":"2019","journal-title":"ArXiv Preprint"},{"key":"ref20","article-title":"Adversarial patch","author":"brown","year":"2017","journal-title":"ArXiv Preprint"},{"key":"ref22","first-page":"14785","article-title":"Invariance-inducing regularization using worst-case transformations suffices to boost accuracy and spatial robustness","author":"yang","year":"2019","journal-title":"Advances in neural information processing systems"},{"key":"ref21","article-title":"Patchguard: Provable defense against adversarial patches using masks on small receptive fields","author":"xiang","year":"2020","journal-title":"ArXiv Preprint"},{"key":"ref24","article-title":"Certification of semantic perturbations via randomized smoothing","author":"fischer","year":"2020","journal-title":"ArXiv Preprint"},{"key":"ref23","first-page":"15313","article-title":"Certifying geometric robustness of neural networks","author":"balunovic","year":"2019","journal-title":"Advances in neural information processing systems"},{"key":"ref26","article-title":"Explaining and harnessing adversarial examples","author":"goodfellow","year":"2014","journal-title":"ArXiv Preprint"},{"key":"ref25","article-title":"Robustness of rotation-equivariant networks to adversarial perturbations","author":"dumont","year":"2018","journal-title":"ArXiv Preprint"}],"event":{"name":"MILCOM 2021 - 2021 IEEE Military Communications Conference (MILCOM)","start":{"date-parts":[[2021,11,29]]},"location":"San Diego, CA, USA","end":{"date-parts":[[2021,12,2]]}},"container-title":["MILCOM 2021 - 2021 IEEE Military Communications Conference (MILCOM)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/9652874\/9652880\/09653101.pdf?arnumber=9653101","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,5,10]],"date-time":"2022-05-10T17:00:05Z","timestamp":1652202005000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9653101\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,11,29]]},"references-count":30,"URL":"https:\/\/doi.org\/10.1109\/milcom52596.2021.9653101","relation":{},"subject":[],"published":{"date-parts":[[2021,11,29]]}}}