{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,15]],"date-time":"2025-11-15T10:26:17Z","timestamp":1763202377417},"publisher-location":"Cham","reference-count":38,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783030445836"},{"type":"electronic","value":"9783030445843"}],"license":[{"start":{"date-parts":[[2020,1,1]],"date-time":"2020-01-01T00:00:00Z","timestamp":1577836800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2020]]},"DOI":"10.1007\/978-3-030-44584-3_19","type":"book-chapter","created":{"date-parts":[[2020,4,21]],"date-time":"2020-04-21T23:04:42Z","timestamp":1587510282000},"page":"235-247","update-policy":"http:\/\/dx.doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":7,"title":["Adversarial Attacks Hidden in Plain Sight"],"prefix":"10.1007","author":[{"given":"Jan Philip","family":"G\u00f6pfert","sequence":"first","affiliation":[]},{"given":"Andr\u00e9","family":"Artelt","sequence":"additional","affiliation":[]},{"given":"Heiko","family":"Wersing","sequence":"additional","affiliation":[]},{"given":"Barbara","family":"Hammer","sequence":"additional","affiliation":[]}],"member":"297","published-online":{"date-parts":[[2020,4,22]]},"reference":[{"key":"19_CR1","doi-asserted-by":"publisher","unstructured":"Krizhevsky, A., et al.: ImageNet classification with deep convolutional neural networks. In: Advances in Neural Information Processing Systems, vol. 25 (2012). \nhttps:\/\/doi.org\/10.1145\/3065386","DOI":"10.1145\/3065386"},{"key":"19_CR2","unstructured":"Szegedy, C., et al.: Intriguing properties of neural networks (2013)"},{"key":"19_CR3","unstructured":"Su, J., et al.: One pixel attack for fooling deep neural networks (2017)"},{"key":"19_CR4","unstructured":"Kurakin, A., et al.: Adversarial examples in the physical world (2016)"},{"key":"19_CR5","doi-asserted-by":"crossref","unstructured":"Papernot, N., et al.: Practical black-box attacks against deep learning systems using adversarial examples (2016)","DOI":"10.1145\/3052973.3053009"},{"key":"19_CR6","unstructured":"Chakraborty, A., et al.: Adversarial attacks and defences: a survey (2018)"},{"key":"19_CR7","unstructured":"Goodfellow, I.J., et al.: Explaining and harnessing adversarial examples (2014)"},{"key":"19_CR8","unstructured":"Luo, Y., et al.: Foveation-based mechanisms alleviate adversarial examples, 19 November 2015"},{"key":"19_CR9","unstructured":"Cisse, M., et al.: Parseval networks: improving robustness to adversarial examples. In: ICML, 28 April 2017"},{"key":"19_CR10","unstructured":"Ilyas, A., et al.: Adversarial examples are not bugs, they are features, 6 May 2019"},{"key":"19_CR11","doi-asserted-by":"publisher","unstructured":"Papernot, N., et al.: Distillation as a defense to adversarial perturbations against deep neural networks. In: 2016 IEEE Symposium on Security and Privacy (SP), May 2016. \nhttps:\/\/doi.org\/10.1109\/sp.2016.41","DOI":"10.1109\/sp.2016.41"},{"key":"19_CR12","unstructured":"Madry, A., et al.: Towards deep learning models resistant to adversarial attacks. In: Proceedings of the International Conference on Learning Representations (ICLR) (2018)"},{"key":"19_CR13","unstructured":"Crecchi, F., et al.: Detecting adversarial examples through nonlinear dimensionality reduction. In: Proceedings of the European Symposium on Artificial Neural Networks, Computational Intelligence and Machine Learning (ESANN) (2019)"},{"key":"19_CR14","unstructured":"Feinman, R., et al.: Detecting Adversarial Samples from Artifacts, 1 March 2017"},{"key":"19_CR15","unstructured":"Grosse, K., et al.: On the (statistical) detection of adversarial examples, 21 February 2017"},{"key":"19_CR16","unstructured":"Metzen, J.H., et al.: On detecting adversarial perturbations, 14 February 2017"},{"key":"19_CR17","doi-asserted-by":"crossref","unstructured":"Carlini, N., et al.: Towards evaluating the robustness of neural networks. In: 2017 IEEE Symposium on Security and Privacy (SP) (2017)","DOI":"10.1109\/SP.2017.49"},{"key":"19_CR18","unstructured":"Athalye, A., et al.: Obfuscated gradients give a false sense of security: circumventing defenses to adversarial examples. In: ICML, 1 February 2018"},{"key":"19_CR19","unstructured":"Tsipras, D., et al.: Robustness may be at odds with accuracy. In: Proceedings of the International Conference on Learning Representations (ICLR) (2019)"},{"key":"19_CR20","unstructured":"Nakkiran, P.: Adversarial robustness may be at odds with simplicity (2019)"},{"key":"19_CR21","doi-asserted-by":"publisher","first-page":"356","DOI":"10.1038\/nn.4244","volume":"19","author":"DLK Yamins","year":"2016","unstructured":"Yamins, D.L.K., et al.: Using goal-driven deep learning models to understand sensory cortex. Nat. Neurosci. 19, 356\u2013365 (2016). \nhttps:\/\/doi.org\/10.1038\/nn.4244","journal-title":"Nat. Neurosci."},{"key":"19_CR22","doi-asserted-by":"publisher","unstructured":"Rajalingham, R., et al.: Large-scale, high-resolution comparison of the core visual object recognition behavior of humans, monkeys, and state-of-the-art deep artificial neural networks. J. Neurosci. 38(33), 7255\u20137269 (2018). \nhttps:\/\/doi.org\/10.1523\/JNEUROSCI.0388-18.2018\n\n. ISSN 0270\u20136474","DOI":"10.1523\/JNEUROSCI.0388-18.2018"},{"key":"19_CR23","unstructured":"Elsayed, G., et al.: Adversarial examples that fool both computer vision and time-limited humans. In: Advances in Neural Information Processing Systems, vol. 31, pp. 3910\u20133920 (2018)"},{"issue":"2","key":"19_CR24","doi-asserted-by":"publisher","first-page":"357","DOI":"10.1162\/089976601300014574","volume":"13","author":"H Wersing","year":"2001","unstructured":"Wersing, H., et al.: A competitive-layer model for feature binding and sensory segmentation. Neural Comput. 13(2), 357\u2013387 (2001). \nhttps:\/\/doi.org\/10.1162\/089976601300014574","journal-title":"Neural Comput."},{"key":"19_CR25","doi-asserted-by":"publisher","unstructured":"Ibbotson, M., et al.: Visual perception and saccadic eye movements. Curr. Opin. Neurobiol. 21(4), 553\u2013558 (2011). \nhttps:\/\/doi.org\/10.1016\/j.conb.2011.05.012\n\n. ISSN 0959\u20134388. Sensory and Motor Systems","DOI":"10.1016\/j.conb.2011.05.012"},{"key":"19_CR26","doi-asserted-by":"publisher","unstructured":"Lewicki, M., et al.: Scene analysis in the natural environment. Front. Psychol. 5, 199 (2014). \nhttps:\/\/doi.org\/10.3389\/fpsyg.2014.00199\n\n. ISSN 1664\u20131078","DOI":"10.3389\/fpsyg.2014.00199"},{"key":"19_CR27","doi-asserted-by":"publisher","unstructured":"J\u00e4kel, F., et al.: An overview of quantitative approaches in Gestalt perception. Vis. Res. 126, 3\u20138 (2016). \nhttps:\/\/doi.org\/10.1016\/j.visres.2016.06.004\n\n. ISSN 0042\u20136989. Quantitative Approaches in Gestalt Perception","DOI":"10.1016\/j.visres.2016.06.004"},{"key":"19_CR28","unstructured":"Kurakin, A., et al.: Adversarial machine learning at scale (2016)"},{"key":"19_CR29","doi-asserted-by":"crossref","unstructured":"Moosavi-Dezfooli, S.-M., et al.: DeepFool: a simple and accurate method to fool deep neural networks. In: 2016 IEEE Conference on Computer Vision and Pattern Recognition (CVPR), pp. 2574\u20132582 (2016)","DOI":"10.1109\/CVPR.2016.282"},{"key":"19_CR30","unstructured":"Rauber, J., et al.: Foolbox v0.8.0: a Python toolbox to benchmark the robustness of machine learning models (2017)"},{"key":"19_CR31","doi-asserted-by":"crossref","unstructured":"Sch\u00f6nherr, L., et al.: Adversarial attacks against automatic speech recognition systems via psychoacoustic hiding (2018)","DOI":"10.14722\/ndss.2019.23288"},{"key":"19_CR32","unstructured":"Sabour, S., et al.: Dynamic routing between capsules. In: Advances in Neural Information Processing Systems (2017)"},{"key":"19_CR33","unstructured":"Brown, T.B., et al.: Adversarial Patch, 27 December 2017"},{"key":"19_CR34","doi-asserted-by":"publisher","first-page":"1484","DOI":"10.1016\/j.visres.2011.04.012","volume":"51","author":"M Carrasco","year":"2011","unstructured":"Carrasco, M.: Visual attention: the past 25 years. Vis. Res. 51, 1484\u20131525 (2011)","journal-title":"Vis. Res."},{"issue":"3","key":"19_CR35","doi-asserted-by":"publisher","first-page":"211","DOI":"10.1007\/s11263-015-0816-y","volume":"115","author":"O Russakovsky","year":"2015","unstructured":"Russakovsky, O., et al.: ImageNet large scale visual recognition challenge. Int. J. Comput. Vis. 115(3), 211\u2013252 (2015). \nhttps:\/\/doi.org\/10.1007\/s11263-015-0816-y","journal-title":"Int. J. Comput. Vis."},{"key":"19_CR36","doi-asserted-by":"crossref","unstructured":"Szegedy, C., et al.: Rethinking the inception architecture for computer vision. In: 2016 IEEE Conference on Computer Vision and Pattern Recognition (CVPR), pp. 2818\u20132826 (2016)","DOI":"10.1109\/CVPR.2016.308"},{"key":"19_CR37","unstructured":"Chollet, F., et al.: Keras (2015). \nhttps:\/\/keras.io"},{"issue":"2","key":"19_CR38","doi-asserted-by":"publisher","first-page":"597","DOI":"10.22237\/jmasm\/1257035100","volume":"8","author":"SS Sawilowsky","year":"2009","unstructured":"Sawilowsky, S.S.: New effect size rules of thumb. J. Mod. Appl. Stat. Methods 8(2), 597\u2013599 (2009). \nhttps:\/\/doi.org\/10.22237\/jmasm\/1257035100","journal-title":"J. Mod. Appl. Stat. Methods"}],"container-title":["Lecture Notes in Computer Science","Advances in Intelligent Data Analysis XVIII"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-44584-3_19","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,4,21]],"date-time":"2020-04-21T23:09:26Z","timestamp":1587510566000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-030-44584-3_19"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020]]},"ISBN":["9783030445836","9783030445843"],"references-count":38,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-44584-3_19","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2020]]},"assertion":[{"value":"22 April 2020","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"IDA","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Symposium on Intelligent Data Analysis","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Konstanz","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Germany","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2020","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"27 April 2020","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"29 April 2020","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"18","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"ida2020","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/ida2020.org\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Single-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Easychair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"114","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"45","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"39% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3,5","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"6","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}