{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,10,30]],"date-time":"2024-10-30T21:18:29Z","timestamp":1730323109917,"version":"3.28.0"},"publisher-location":"New York, NY, USA","reference-count":40,"publisher":"ACM","content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2020,10,12]]},"DOI":"10.1145\/3394171.3413808","type":"proceedings-article","created":{"date-parts":[[2020,10,12]],"date-time":"2020-10-12T12:26:18Z","timestamp":1602505578000},"page":"1634-1642","update-policy":"http:\/\/dx.doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":6,"title":["Adversarial Image Attacks Using Multi-Sample and Most-Likely Ensemble Methods"],"prefix":"10.1145","author":[{"given":"Xia","family":"Du","sequence":"first","affiliation":[{"name":"University of Macau, Macau, Macao"}]},{"given":"Chi-Man","family":"Pun","sequence":"additional","affiliation":[{"name":"University of Macau, Macau, Macao"}]}],"member":"320","published-online":{"date-parts":[[2020,10,12]]},"reference":[{"key":"e_1_3_2_2_1_1","volume-title":"Proceedings of the 35th International Conference on Machine Learning (Proceedings of Machine Learning Research), JenniferDy and Andreas Krause (Eds.)","volume":"80","author":"Athalye Anish","year":"2018"},{"key":"e_1_3_2_2_2_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10994-010-5188-5"},{"key":"e_1_3_2_2_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/1128817.1128824"},{"key":"e_1_3_2_2_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"e_1_3_2_2_5_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"e_1_3_2_2_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/1015330.1015432"},{"key":"e_1_3_2_2_7_1","unstructured":"Nilaksh Das Madhuri Shanbhogue Shang-Tse Chen Fred Hohman Li Chen Michael E Kounavis and Duen Horng Chau. 2017. Keeping the bad guys out: Protecting and vaccinating deep learning with jpeg compression. arXiv preprint arXiv:1705.02900 (2017). Nilaksh Das Madhuri Shanbhogue Shang-Tse Chen Fred Hohman Li Chen Michael E Kounavis and Duen Horng Chau. 2017. Keeping the bad guys out: Protecting and vaccinating deep learning with jpeg compression. arXiv preprint arXiv:1705.02900 (2017)."},{"key":"e_1_3_2_2_8_1","unstructured":"Gintare Karolina Dziugaite Zoubin Ghahramani and Daniel M Roy. 2016. A study of the effect of jpg compression on adversarial images. arXiv preprint arXiv:1608.00853 (2016). Gintare Karolina Dziugaite Zoubin Ghahramani and Daniel M Roy. 2016. A study of the effect of jpg compression on adversarial images. arXiv preprint arXiv:1608.00853 (2016)."},{"key":"e_1_3_2_2_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00175"},{"key":"e_1_3_2_2_10_1","unstructured":"Bryse Flowers R Michael Buehrer and William C Headley. 2019. Evaluating adversarial evasion attacks in the context of wireless communications. arXiv preprint arXiv:1903.01563 (2019). Bryse Flowers R Michael Buehrer and William C Headley. 2019. Evaluating adversarial evasion attacks in the context of wireless communications. arXiv preprint arXiv:1903.01563 (2019)."},{"volume-title":"Explaining and Harnessing Adversarial Examples. In International Conference on Learning Representations.","year":"2015","author":"Goodfellow Ian","key":"e_1_3_2_2_11_1"},{"key":"e_1_3_2_2_12_1","doi-asserted-by":"crossref","unstructured":"Feng Guo Qingjie Zhao Xuan Li Xiaohui Kuang Jianwei Zhang Yahong Han and Yu-an Tan. 2019. Detecting Adversarial Examples via Prediction Difference for Deep Neural Networks. Information Sciences (2019). Feng Guo Qingjie Zhao Xuan Li Xiaohui Kuang Jianwei Zhang Yahong Han and Yu-an Tan. 2019. Detecting Adversarial Examples via Prediction Difference for Deep Neural Networks. Information Sciences (2019).","DOI":"10.1016\/j.ins.2019.05.084"},{"key":"e_1_3_2_2_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2019.2894031"},{"key":"e_1_3_2_2_14_1","doi-asserted-by":"publisher","DOI":"10.1109\/34.58871"},{"key":"e_1_3_2_2_15_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-46493-0_38"},{"key":"e_1_3_2_2_16_1","doi-asserted-by":"crossref","unstructured":"Geoffrey Hinton Li Deng Dong Yu George E Dahl Abdel-rahman Mohamed Navdeep Jaitly Andrew Senior Vincent Vanhoucke Patrick Nguyen Tara N Sainath etal 2012. Deep neural networks for acoustic modeling in speech recognition: The shared views of four research groups. IEEE Signal processing magazine 29 6 (2012) 82--97. Geoffrey Hinton Li Deng Dong Yu George E Dahl Abdel-rahman Mohamed Navdeep Jaitly Andrew Senior Vincent Vanhoucke Patrick Nguyen Tara N Sainath et al. 2012. Deep neural networks for acoustic modeling in speech recognition: The shared views of four research groups. IEEE Signal processing magazine 29 6 (2012) 82--97.","DOI":"10.1109\/MSP.2012.2205597"},{"key":"e_1_3_2_2_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/3343031.3351088"},{"key":"e_1_3_2_2_18_1","unstructured":"Stepan Komkov and Aleksandr Petiushko. 2019. AdvHat: Real-world adversarial attack on ArcFace Face ID system. arXiv preprint arXiv:1908.08705 (2019). Stepan Komkov and Aleksandr Petiushko. 2019. AdvHat: Real-world adversarial attack on ArcFace Face ID system. arXiv preprint arXiv:1908.08705 (2019)."},{"key":"e_1_3_2_2_19_1","unstructured":"Alex Krizhevsky Ilya Sutskever and Geoffrey E Hinton. 2012. Imagenet classification with deep convolutional neural networks. In Advances in neural information processing systems. 1097--1105. Alex Krizhevsky Ilya Sutskever and Geoffrey E Hinton. 2012. Imagenet classification with deep convolutional neural networks. In Advances in neural information processing systems. 1097--1105."},{"key":"e_1_3_2_2_20_1","unstructured":"Anders Krogh and Jesper Vedelsby. 1995. Neural network ensembles cross validation and active learning. In Advances in neural information processing systems. 231--238. Anders Krogh and Jesper Vedelsby. 1995. Neural network ensembles cross validation and active learning. In Advances in neural information processing systems. 231--238."},{"key":"e_1_3_2_2_21_1","unstructured":"Alexey Kurakin Ian Goodfellow and Samy Bengio. 2016. Adversarial examples in the physical world. arXiv preprint arXiv:1607.02533 (2016). Alexey Kurakin Ian Goodfellow and Samy Bengio. 2016. Adversarial examples in the physical world. arXiv preprint arXiv:1607.02533 (2016)."},{"volume-title":"ICLR Workshop","year":"2017","author":"Kurakin Alexey","key":"e_1_3_2_2_22_1"},{"key":"e_1_3_2_2_23_1","doi-asserted-by":"crossref","unstructured":"Y LeCun Y Bengio and G Hinton. 2015. Deep learning. nature 521 (7553): 436. Google Scholar (2015). Y LeCun Y Bengio and G Hinton. 2015. Deep learning. nature 521 (7553): 436. Google Scholar (2015).","DOI":"10.1038\/nature14539"},{"key":"e_1_3_2_2_24_1","unstructured":"Mark Lee and Zico Kolter. 2019. On physical adversarial patches for object detection. arXiv preprint arXiv:1906.11897 (2019). Mark Lee and Zico Kolter. 2019. On physical adversarial patches for object detection. arXiv preprint arXiv:1906.11897 (2019)."},{"volume-title":"International Conference on Machine Learning. 3896--3904","year":"2019","author":"Li Juncheng","key":"e_1_3_2_2_25_1"},{"key":"e_1_3_2_2_26_1","unstructured":"Yanpei Liu Xinyun Chen Chang Liu and Dawn Song. 2016. Delving into transferable adversarial examples and black-box attacks. arXiv preprint arXiv:1611.02770 (2016). Yanpei Liu Xinyun Chen Chang Liu and Dawn Song. 2016. Delving into transferable adversarial examples and black-box attacks. arXiv preprint arXiv:1611.02770 (2016)."},{"key":"e_1_3_2_2_27_1","unstructured":"Jiajun Lu Hussein Sibai Evan Fabry and David Forsyth. 2017. Standard detectors aren't (currently) fooled by physical adversarial stop signs. arXiv preprint arXiv:1710.03337 (2017). Jiajun Lu Hussein Sibai Evan Fabry and David Forsyth. 2017. Standard detectors aren't (currently) fooled by physical adversarial stop signs. arXiv preprint arXiv:1710.03337 (2017)."},{"key":"e_1_3_2_2_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134057"},{"key":"e_1_3_2_2_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"e_1_3_2_2_30_1","unstructured":"Nir Morgulis Alexander Kreines Shachar Mendelowitz and Yuval Weisglass. 2019. Fooling a Real Car with Adversarial Traffic Signs. arXiv preprint arXiv:1907.00374 (2019). Nir Morgulis Alexander Kreines Shachar Mendelowitz and Yuval Weisglass. 2019. Fooling a Real Car with Adversarial Traffic Signs. arXiv preprint arXiv:1907.00374 (2019)."},{"key":"e_1_3_2_2_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2017.2718479"},{"key":"e_1_3_2_2_32_1","doi-asserted-by":"publisher","DOI":"10.5555\/3298023.3298188"},{"key":"e_1_3_2_2_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.308"},{"volume-title":"international conference on learning representations (ICLR","year":"2014","author":"Szegedy Christian","key":"e_1_3_2_2_34_1"},{"key":"e_1_3_2_2_35_1","unstructured":"Florian Tram\u00e8r Alexey Kurakin Nicolas Papernot Ian Goodfellow Dan Boneh and Patrick McDaniel. 2017. Ensemble adversarial training: Attacks and defenses. arXiv preprint arXiv:1705.07204 (2017). Florian Tram\u00e8r Alexey Kurakin Nicolas Papernot Ian Goodfellow Dan Boneh and Patrick McDaniel. 2017. Ensemble adversarial training: Attacks and defenses. arXiv preprint arXiv:1705.07204 (2017)."},{"volume-title":"Mitigating Adversarial Effects Through Randomization. In International Conference on Learning Representations.","year":"2018","author":"Xie Cihang","key":"e_1_3_2_2_36_1"},{"volume-title":"Feature Squeezing: Detecting Adversarial Examples in Deep Neural Networks. In 25th Annual Network and Distributed System Security Symposium, NDSS 2018","year":"2018","author":"Xu Weilin","key":"e_1_3_2_2_37_1"},{"key":"e_1_3_2_2_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/3240508.3240603"},{"key":"e_1_3_2_2_39_1","doi-asserted-by":"crossref","unstructured":"Xiaoyong Yuan Pan He Qile Zhu and Xiaolin Li. 2019. Adversarial examples: Attacks and defenses for deep learning. IEEE transactions on neural networks and learning systems 30 9 (2019) 2805--2824. Xiaoyong Yuan Pan He Qile Zhu and Xiaolin Li. 2019. Adversarial examples: Attacks and defenses for deep learning. IEEE transactions on neural networks and learning systems 30 9 (2019) 2805--2824.","DOI":"10.1109\/TNNLS.2018.2886017"},{"key":"e_1_3_2_2_40_1","doi-asserted-by":"publisher","DOI":"10.1145\/3240508.3240639"}],"event":{"name":"MM '20: The 28th ACM International Conference on Multimedia","sponsor":["SIGMM ACM Special Interest Group on Multimedia"],"location":"Seattle WA USA","acronym":"MM '20"},"container-title":["Proceedings of the 28th ACM International Conference on Multimedia"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3394171.3413808","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,1,5]],"date-time":"2023-01-05T20:39:38Z","timestamp":1672951178000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3394171.3413808"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,10,12]]},"references-count":40,"alternative-id":["10.1145\/3394171.3413808","10.1145\/3394171"],"URL":"https:\/\/doi.org\/10.1145\/3394171.3413808","relation":{},"subject":[],"published":{"date-parts":[[2020,10,12]]},"assertion":[{"value":"2020-10-12","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}