{"id":"https://openalex.org/W4402490876","doi":"https://doi.org/10.1016/j.neunet.2024.106711","title":"How adversarial attacks can disrupt seemingly stable accurate classifiers","display_name":"How adversarial attacks can disrupt seemingly stable accurate classifiers","publication_year":2024,"publication_date":"2024-09-01","ids":{"openalex":"https://openalex.org/W4402490876","doi":"https://doi.org/10.1016/j.neunet.2024.106711","pmid":"https://pubmed.ncbi.nlm.nih.gov/39299037"},"language":"en","primary_location":{"is_oa":true,"landing_page_url":"https://doi.org/10.1016/j.neunet.2024.106711","pdf_url":null,"source":{"id":"https://openalex.org/S123019304","display_name":"Neural Networks","issn_l":"0893-6080","issn":["0893-6080","1879-2782"],"is_oa":false,"is_in_doaj":false,"is_indexed_in_scopus":true,"is_core":true,"host_organization":"https://openalex.org/P4310320990","host_organization_name":"Elsevier BV","host_organization_lineage":["https://openalex.org/P4310320990"],"host_organization_lineage_names":["Elsevier BV"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true},"type":"article","type_crossref":"journal-article","indexed_in":["crossref","pubmed"],"open_access":{"is_oa":true,"oa_status":"hybrid","oa_url":"https://doi.org/10.1016/j.neunet.2024.106711","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5006868406","display_name":"Oliver J. Sutton","orcid":"https://orcid.org/0000-0003-0184-4371"},"institutions":[{"id":"https://openalex.org/I183935753","display_name":"King's College London","ror":"https://ror.org/0220mzb33","country_code":"GB","type":"funder","lineage":["https://openalex.org/I124357947","https://openalex.org/I183935753"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"Oliver J Sutton","raw_affiliation_strings":["Department of Mathematics, King's College London, London, UK. Electronic address: oliver.sutton@kcl.ac.uk."],"affiliations":[{"raw_affiliation_string":"Department of Mathematics, King's College London, London, UK. Electronic address: oliver.sutton@kcl.ac.uk.","institution_ids":["https://openalex.org/I183935753"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5024753869","display_name":"Qinghua Zhou","orcid":"https://orcid.org/0000-0002-3327-0440"},"institutions":[{"id":"https://openalex.org/I183935753","display_name":"King's College London","ror":"https://ror.org/0220mzb33","country_code":"GB","type":"funder","lineage":["https://openalex.org/I124357947","https://openalex.org/I183935753"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"Qinghua Zhou","raw_affiliation_strings":["Department of Mathematics, King's College London, London, UK."],"affiliations":[{"raw_affiliation_string":"Department of Mathematics, King's College London, London, UK.","institution_ids":["https://openalex.org/I183935753"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5052143104","display_name":"Ivan Tyukin","orcid":"https://orcid.org/0000-0002-7359-7966"},"institutions":[{"id":"https://openalex.org/I183935753","display_name":"King's College London","ror":"https://ror.org/0220mzb33","country_code":"GB","type":"funder","lineage":["https://openalex.org/I124357947","https://openalex.org/I183935753"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"Ivan Y Tyukin","raw_affiliation_strings":["Department of Mathematics, King's College London, London, UK."],"affiliations":[{"raw_affiliation_string":"Department of Mathematics, King's College London, London, UK.","institution_ids":["https://openalex.org/I183935753"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5058069510","display_name":"Alexander N. Gorban","orcid":"https://orcid.org/0000-0001-6224-1430"},"institutions":[{"id":"https://openalex.org/I153648349","display_name":"University of Leicester","ror":"https://ror.org/04h699437","country_code":"GB","type":"funder","lineage":["https://openalex.org/I153648349"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"Alexander N Gorban","raw_affiliation_strings":["School of Computing and Mathematical Sciences, University of Leicester, Leicester, UK."],"affiliations":[{"raw_affiliation_string":"School of Computing and Mathematical Sciences, University of Leicester, Leicester, UK.","institution_ids":["https://openalex.org/I153648349"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5088165793","display_name":"Alexander Bastounis","orcid":"https://orcid.org/0000-0002-2867-4635"},"institutions":[{"id":"https://openalex.org/I183935753","display_name":"King's College London","ror":"https://ror.org/0220mzb33","country_code":"GB","type":"funder","lineage":["https://openalex.org/I124357947","https://openalex.org/I183935753"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"Alexander Bastounis","raw_affiliation_strings":["Department of Mathematics, King's College London, London, UK."],"affiliations":[{"raw_affiliation_string":"Department of Mathematics, King's College London, London, UK.","institution_ids":["https://openalex.org/I183935753"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5058486589","display_name":"Desmond J. Higham","orcid":"https://orcid.org/0000-0002-6635-3461"},"institutions":[{"id":"https://openalex.org/I98677209","display_name":"University of Edinburgh","ror":"https://ror.org/01nrxwf90","country_code":"GB","type":"funder","lineage":["https://openalex.org/I98677209"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"Desmond J Higham","raw_affiliation_strings":["School of Mathematics, University of Edinburgh, Edinburgh, UK."],"affiliations":[{"raw_affiliation_string":"School of Mathematics, University of Edinburgh, Edinburgh, UK.","institution_ids":["https://openalex.org/I98677209"]}]}],"institution_assertions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":{"value":3350,"currency":"USD","value_usd":3350},"apc_paid":{"value":3350,"currency":"USD","value_usd":3350},"fwci":1.019,"has_fulltext":false,"cited_by_count":1,"citation_normalized_percentile":{"value":0.785868,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":77,"max":88},"biblio":{"volume":null,"issue":null,"first_page":"106711","last_page":"106711"},"is_retracted":false,"is_paratext":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9999,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9999,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9962,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11515","display_name":"Bacillus and Francisella bacterial research","score":0.9598,"subfield":{"id":"https://openalex.org/subfields/1312","display_name":"Molecular Biology"},"field":{"id":"https://openalex.org/fields/13","display_name":"Biochemistry, Genetics and Molecular Biology"},"domain":{"id":"https://openalex.org/domains/1","display_name":"Life Sciences"}}],"keywords":[],"concepts":[{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.7569623},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6393142},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.6201589},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.53878015},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.32428473}],"mesh":[],"locations_count":3,"locations":[{"is_oa":true,"landing_page_url":"https://doi.org/10.1016/j.neunet.2024.106711","pdf_url":null,"source":{"id":"https://openalex.org/S123019304","display_name":"Neural Networks","issn_l":"0893-6080","issn":["0893-6080","1879-2782"],"is_oa":false,"is_in_doaj":false,"is_indexed_in_scopus":true,"is_core":true,"host_organization":"https://openalex.org/P4310320990","host_organization_name":"Elsevier BV","host_organization_lineage":["https://openalex.org/P4310320990"],"host_organization_lineage_names":["Elsevier BV"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true},{"is_oa":true,"landing_page_url":"https://arxiv.org/abs/2309.03665","pdf_url":"https://arxiv.org/pdf/2309.03665","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_indexed_in_scopus":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":["Cornell University"],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false},{"is_oa":false,"landing_page_url":"https://pubmed.ncbi.nlm.nih.gov/39299037","pdf_url":null,"source":{"id":"https://openalex.org/S4306525036","display_name":"PubMed","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_indexed_in_scopus":false,"is_core":false,"host_organization":"https://openalex.org/I1299303238","host_organization_name":"National Institutes of Health","host_organization_lineage":["https://openalex.org/I1299303238"],"host_organization_lineage_names":["National Institutes of Health"],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false}],"best_oa_location":{"is_oa":true,"landing_page_url":"https://doi.org/10.1016/j.neunet.2024.106711","pdf_url":null,"source":{"id":"https://openalex.org/S123019304","display_name":"Neural Networks","issn_l":"0893-6080","issn":["0893-6080","1879-2782"],"is_oa":false,"is_in_doaj":false,"is_indexed_in_scopus":true,"is_core":true,"host_organization":"https://openalex.org/P4310320990","host_organization_name":"Elsevier BV","host_organization_lineage":["https://openalex.org/P4310320990"],"host_organization_lineage_names":["Elsevier BV"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true},"sustainable_development_goals":[{"display_name":"Reduced inequalities","id":"https://metadata.un.org/sdg/10","score":0.5}],"grants":[{"funder":"https://openalex.org/F4320314731","funder_display_name":"UK Research and Innovation","award_id":null},{"funder":"https://openalex.org/F4320334627","funder_display_name":"Engineering and Physical Sciences Research Council","award_id":null}],"datasets":[],"versions":[],"referenced_works_count":28,"referenced_works":["https://openalex.org/W1573820523","https://openalex.org/W1673923490","https://openalex.org/W1686810756","https://openalex.org/W1786513448","https://openalex.org/W2067713319","https://openalex.org/W2117539524","https://openalex.org/W2316420424","https://openalex.org/W2321124713","https://openalex.org/W2508156266","https://openalex.org/W2750384547","https://openalex.org/W2808166846","https://openalex.org/W2884716758","https://openalex.org/W2888233014","https://openalex.org/W2899434523","https://openalex.org/W2913668833","https://openalex.org/W2914304175","https://openalex.org/W2989696285","https://openalex.org/W3025305474","https://openalex.org/W3118608800","https://openalex.org/W4200241466","https://openalex.org/W4205616158","https://openalex.org/W4236965008","https://openalex.org/W4246999471","https://openalex.org/W4285490400","https://openalex.org/W4286978759","https://openalex.org/W4287116426","https://openalex.org/W4295803779","https://openalex.org/W4386939504"],"related_works":["https://openalex.org/W4394896187","https://openalex.org/W4386462264","https://openalex.org/W4364306694","https://openalex.org/W4312192474","https://openalex.org/W4306674287","https://openalex.org/W3170094116","https://openalex.org/W3107602296","https://openalex.org/W3046775127","https://openalex.org/W2961085424","https://openalex.org/W2033914206"],"abstract_inverted_index":{"Adversarial":[0],"attacks":[1],"dramatically":[2],"change":[3],"the":[4,38,92,96,111,117,142,146],"output":[5],"of":[6,20,37,49,64,95,110,145],"an":[7],"otherwise":[8],"accurate":[9],"learning":[10],"system":[11],"using":[12,173,178],"a":[13,18,61,74,157],"seemingly":[14],"inconsequential":[15],"modification":[16],"to":[17,33,43,100,107,140],"piece":[19],"input":[21,39,70,112],"data.":[22,71,113],"Paradoxically,":[23],"empirical":[24],"evidence":[25],"indicates":[26],"that":[27,55,116,152],"even":[28,134,153],"systems":[29,87],"which":[30,81],"are":[31,120],"robust":[32],"large":[34,135],"random":[35,108,137],"perturbations":[36,48,109],"data":[40,165],"remain":[41],"susceptible":[42],"small,":[44],"easily":[45,101],"constructed,":[46],"adversarial":[47,103,143,168,192,197],"their":[50],"inputs.":[51],"Here,":[52],"we":[53],"show":[54],"this":[56],"may":[57],"be":[58],"seen":[59],"as":[60],"fundamental":[62],"feature":[63],"classifiers":[65],"working":[66],"with":[67,89],"high":[68,90],"dimensional":[69],"We":[72,114],"introduce":[73],"simple":[75],"generic":[76],"and":[77,105,163,194],"generalisable":[78],"framework":[79],"for":[80,188],"key":[82],"behaviours":[83],"observed":[84,122],"in":[85,123],"practical":[86,124],"arise":[88],"probability-notably":[91],"simultaneous":[93],"susceptibility":[94,169],"(otherwise":[97],"accurate)":[98],"model":[99],"constructed":[102],"attacks,":[104],"robustness":[106],"confirm":[115],"same":[118],"phenomena":[119],"directly":[121],"neural":[125],"networks":[126],"trained":[127],"on":[128],"standard":[129],"image":[130],"classification":[131],"problems,":[132],"where":[133],"additive":[136,179],"noise":[138,180],"fails":[139],"trigger":[141],"instability":[144],"network.":[147],"A":[148],"surprising":[149],"takeaway":[150],"is":[151,185,199],"small":[154],"margins":[155],"separating":[156],"classifier's":[158],"decision":[159],"surface":[160],"from":[161,170],"training":[162,182,198],"testing":[164,184],"can":[166],"hide":[167],"being":[171],"detected":[172],"randomly":[174],"sampled":[175],"perturbations.":[176],"Counter-intuitively,":[177],"during":[181],"or":[183,190],"therefore":[186],"inefficient":[187],"eradicating":[189],"detecting":[191],"examples,":[193],"more":[195],"demanding":[196],"required.":[200]},"abstract_inverted_index_v3":null,"cited_by_api_url":"https://api.openalex.org/works?filter=cites:W4402490876","counts_by_year":[{"year":2025,"cited_by_count":1}],"updated_date":"2025-04-21T20:15:01.615487","created_date":"2024-09-13"}