{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,5]],"date-time":"2026-02-05T07:48:56Z","timestamp":1770277736333,"version":"3.49.0"},"publisher-location":"Cham","reference-count":44,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783030821920","type":"print"},{"value":"9783030821937","type":"electronic"}],"license":[{"start":{"date-parts":[[2021,8,4]],"date-time":"2021-08-04T00:00:00Z","timestamp":1628035200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2021,8,4]],"date-time":"2021-08-04T00:00:00Z","timestamp":1628035200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2022]]},"DOI":"10.1007\/978-3-030-82193-7_10","type":"book-chapter","created":{"date-parts":[[2021,8,3]],"date-time":"2021-08-03T15:23:39Z","timestamp":1628004219000},"page":"148-167","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":6,"title":["BreakingBED: Breaking Binary and Efficient Deep Neural Networks by Adversarial Attacks"],"prefix":"10.1007","author":[{"given":"Manoj-Rohit","family":"Vemparala","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Alexander","family":"Frickenstein","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Nael","family":"Fasfous","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Lukas","family":"Frickenstein","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Qi","family":"Zhao","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Sabine","family":"Kuhn","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Daniel","family":"Ehrhardt","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yuankai","family":"Wu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Christian","family":"Unger","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Naveen-Shankar","family":"Nagaraja","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Walter","family":"Stechele","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2021,8,4]]},"reference":[{"key":"10_CR1","doi-asserted-by":"publisher","first-page":"14410","DOI":"10.1109\/ACCESS.2018.2807385","volume":"6","author":"N Akhtar","year":"2018","unstructured":"Akhtar, N., Mian, A.S.: Threat of adversarial attacks on deep learning in computer vision: a survey. IEEE Access 6, 14410\u201314430 (2018)","journal-title":"IEEE Access"},{"key":"10_CR2","doi-asserted-by":"crossref","unstructured":"Alzantot, M., Sharma, Y., Chakraborty, S., Zhang, H., Hsieh, C.J., Srivastava, M.B.: GenAttack: practical black-box attacks with gradient-free optimization. In: ACM Genetic and Evolutionary Computation Conference (GECCO), pp. 1111\u20131119. Association for Computing Machinery, New York (2019)","DOI":"10.1145\/3321707.3321749"},{"key":"10_CR3","doi-asserted-by":"crossref","unstructured":"Moosavi-Dezfooli, S.-M., Fawzi, A., Fawzi, O., Frossard, P.: Universal adversarial perturbations. In: IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR), pp. 86\u201394, July 2017","DOI":"10.1109\/CVPR.2017.17"},{"key":"10_CR4","unstructured":"Carlini, N., et al.: On evaluating adversarial robustness. CoRR, abs\/1902.06705 (2019)"},{"key":"10_CR5","doi-asserted-by":"crossref","unstructured":"Carlini, N., Wagner, D.A.: Towards evaluating the robustness of neural networks. In: IEEE Symposium on Security and Privacy (SP), pp. 39\u201357, May 2017","DOI":"10.1109\/SP.2017.49"},{"key":"10_CR6","doi-asserted-by":"crossref","unstructured":"Chen, P.-Y., Zhang, H., Sharma, Y., Yi, J., Hsieh, C.-J.: ZOO: zeroth order optimization based black-box attacks to deep neural networks without training substitute models, pp. 15\u201326, November 2017","DOI":"10.1145\/3128572.3140448"},{"key":"10_CR7","unstructured":"Courbariaux, M., Bengio, Y., David, J.P.: BinaryConnect: training deep neural networks with binary weights during propagations. In: Cortes, C., Lawrence, N.D., Lee, D.D., Sugiyama, M., Garnett, R. (eds.) Advances in Neural Information Processing Systems (NeurIPS), pp. 3123\u20133131. Curran Associates Inc. (2015)"},{"key":"10_CR8","doi-asserted-by":"crossref","unstructured":"Fasfous, N., Vemparala, M.R., Frickenstein, A., Stechele, W.: OrthrusPE: runtime reconfigurable processing elements for binary neural networks. In: 2020 Design, Automation Test in Europe Conference Exhibition (DATE), pp. 1662\u20131667 (2020)","DOI":"10.23919\/DATE48585.2020.9116308"},{"key":"10_CR9","doi-asserted-by":"crossref","unstructured":"Frickenstein, A., Rohit Vemparala, M., Unger, C., Ayar, F., Stechele, W.: DSC: Dense-sparse convolution for vectorized inference of convolutional neural networks. In: IEEE\/CVF Conference on Computer Vision and Pattern Recognition Workshops (CVPR-W), June 2019","DOI":"10.1109\/CVPRW.2019.00175"},{"key":"10_CR10","unstructured":"Galloway, A., Taylor, G.W., Moussa, M.: Attacking binarized neural networks. In: International Conference on Learning Representations (2018)"},{"key":"10_CR11","doi-asserted-by":"crossref","unstructured":"Goldblum, M., Fowl, L., Feizi, S., Goldstein, T.: Adversarially robust distillation. In: AAAI (2020)","DOI":"10.1609\/aaai.v34i04.5816"},{"key":"10_CR12","doi-asserted-by":"crossref","unstructured":"Guo, M., Yang, Y., Xu, R., Liu, Z., Lin, D.: When NAS meets robustness: in search of robust architectures against adversarial attacks (2019)","DOI":"10.1109\/CVPR42600.2020.00071"},{"key":"10_CR13","unstructured":"Guo, Y., Yao, A., Chen, Y.: Dynamic network surgery for efficient DNNs. In: Advances in Neural Information Processing Systems (NeurIPS) (2016)"},{"key":"10_CR14","unstructured":"Han, B., et al.: Co-teaching: robust training of deep neural networks with extremely noisy labels. In: Bengio, S., Wallach, H., Larochelle, H., Grauman, K., Cesa-Bianchi, N., Garnett, R. (eds.) Advances in Neural Information Processing Systems, vol. 31, pp. 8527\u20138537. Curran Associates Inc. (2018)"},{"key":"10_CR15","unstructured":"Han, S., Pool, J., Tran, J., Dally, W.: Learning both weights and connections for efficient neural network. In: Cortes, C., Lawrence, N.D., Lee, D.D., Sugiyama, M., Garnett, R. (eds.) Advances in Neural Information Processing Systems (NeurIPS), pp. 1135\u20131143. Curran Associates Inc. (2015)"},{"key":"10_CR16","doi-asserted-by":"crossref","unstructured":"He, K., Zhang, X., Ren, S., Sun, J.: Deep residual learning for image recognition. In: IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR), pp. 770\u2013778, June 2016","DOI":"10.1109\/CVPR.2016.90"},{"key":"10_CR17","doi-asserted-by":"crossref","unstructured":"He, Y., Zhang, X., Sun, J.: Channel pruning for accelerating very deep neural networks. In: IEEE International Conference on Computer Vision (ICCV), pp. 1398\u20131406, October 2017","DOI":"10.1109\/ICCV.2017.155"},{"key":"10_CR18","doi-asserted-by":"crossref","unstructured":"He, Y., Liu, P., Wang, Z., et al.: Filter pruning via geometric median for deep convolutional neural networks acceleration. In: IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR) (2019)","DOI":"10.1109\/CVPR.2019.00447"},{"key":"10_CR19","doi-asserted-by":"crossref","unstructured":"He, Y., Lin, J., Liu, Z., Wang, H., Li, L.-J., Han, S.: AMC: AutoML for model compression and acceleration on mobile devices. In: The European Conference on Computer Vision (ECCV) (2018)","DOI":"10.1007\/978-3-030-01234-2_48"},{"key":"10_CR20","unstructured":"Hinton, G., Vinyals, O., Dean, J.: Distilling the knowledge in a neural network (2015)"},{"key":"10_CR21","unstructured":"Hubara, I., Courbariaux, M., Soudry, D., El-Yaniv, R., Bengio, Y.: Binarized neural networks. In: Lee, D.D., Sugiyama, M., Luxburg, U.V., Guyon, I., Garnett, R. (eds.) Advances in Neural Information Processing Systems (NeurIPS), pp. 4107\u20134115. Curran Associates Inc. (2016)"},{"key":"10_CR22","unstructured":"Goodfellow, I.J., Shlens, J., Szegedy, C.: Explaining and harnessing adversarial examples. In: International Conference on Learning Representations (ICLR) (2015)"},{"key":"10_CR23","unstructured":"Krizhevsky, A.: Learning Multiple Layers of Features from Tiny Images. University of Toronto (2009)"},{"key":"10_CR24","unstructured":"Kurakin, A., Goodfellow, I.J., Bengio, S.: Adversarial Machine Learning at Scale. abs\/1611.01236 (2016)"},{"key":"10_CR25","unstructured":"LeCun, Y., Denker, J.S., Solla, S.A.: Optimal brain damage. In: Touretzky, D.S. (ed.) Advances in Neural Information Processing Systems (NeurIPS), pp. 598\u2013605. Morgan-Kaufmann (1990)"},{"key":"10_CR26","unstructured":"Lin, J., Gan, C., Han, S.: Defensive quantization: when efficiency meets robustness. In: International Conference on Learning Representations (2019)"},{"key":"10_CR27","unstructured":"Lin, X., Zhao, C., Pan, W.: Towards accurate binary convolutional neural network. In: Guyon, I., et al. (eds.) Advances in Neural Information Processing Systems (NeurIPS), pp. 345\u2013353. Curran Associates Inc. (2017)"},{"key":"10_CR28","unstructured":"Madry, A., Makelov, A., Schmidt, L., Tsipras, D., Vladu, A.: Towards deep learning models resistant to adversarial attacks. ArXiv, abs\/1706.06083 (2018)"},{"key":"10_CR29","unstructured":"Makhzani, A., Shlens, J., Jaitly, N., Goodfellow, I.J.: Adversarial autoencoders. In: International Conference on Learning Representations Workshop (ICLR-W) (2016)"},{"key":"10_CR30","doi-asserted-by":"crossref","unstructured":"Moosavi-Dezfooli, S.-M., Fawzi, A., Frossard, P.: DeepFool: a simple and accurate method to fool deep neural networks. In: IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR), pp. 2574\u20132582 (2015)","DOI":"10.1109\/CVPR.2016.282"},{"key":"10_CR31","doi-asserted-by":"crossref","unstructured":"Narodytska, N., Kasiviswanathan, S.P.: Simple black-box adversarial attacks on deep neural networks. In: IEEE\/CVF Conference on Computer Vision and Pattern Recognition Workshops (CVPR-W), pp. 1310\u20131318, July 2017","DOI":"10.1109\/CVPRW.2017.172"},{"key":"10_CR32","unstructured":"NVIDIA. NVIDIA Turing GPU architecture (2017). https:\/\/www.nvidia.com\/content\/dam\/en-zz\/Solutions\/design-visualization\/technologies\/turing-architecture\/NVIDIA-Turing-Architecture-Whitepaper.pdf. Accessed 28 Feb 2020"},{"key":"10_CR33","unstructured":"Papernot, N., McDaniel, P.: Extending defensive distillation. ArXiv, abs\/1705.05264 (2017)"},{"key":"10_CR34","doi-asserted-by":"crossref","unstructured":"Papernot, N., McDaniel, P., Goodfellow, I., Jha, S., Celik, Z.B., Swami, A.: Practical black-box attacks against machine learning. In: Proceedings of the 2017 ACM on Asia Conference on Computer and Communications Security, pp. 506\u2013519. Association for Computing Machinery, New York (2017)","DOI":"10.1145\/3052973.3053009"},{"key":"10_CR35","doi-asserted-by":"crossref","unstructured":"Papernot, N., McDaniel, P.D., Wu, X., Jha, S., Swami, A.: Distillation as a defense to adversarial perturbations against deep neural networks. In: IEEE Symposium on Security and Privacy (SP), pp. 582\u2013597, May 2016","DOI":"10.1109\/SP.2016.41"},{"key":"10_CR36","doi-asserted-by":"publisher","unstructured":"Rastegari M., Ordonez V., Redmon J., Farhadi A.: XNOR-Net: ImageNet classification using binary convolutional neural networks. In: Leibe, B., Matas, J., Sebe, N., Welling, M. (eds.) The European Conference on Computer Vision (ECCV), pp. 525\u2013542. Springer, Cham (2016). https:\/\/doi.org\/10.1007\/978-3-319-46493-0_32","DOI":"10.1007\/978-3-319-46493-0_32"},{"issue":"3","key":"10_CR37","doi-asserted-by":"publisher","first-page":"211","DOI":"10.1007\/s11263-015-0816-y","volume":"115","author":"O Russakovsky","year":"2015","unstructured":"Russakovsky, O., et al.: ImageNet large scale visual recognition challenge. Int. J. Comput. Vis. (IJCV) 115(3), 211\u2013252 (2015)","journal-title":"Int. J. Comput. Vis. (IJCV)"},{"key":"10_CR38","unstructured":"Shafahi, A., et al.: Adversarial training for free! In: Wallach, H., Larochelle, H., Beygelzimer, A., dAlch\u00e9-Buc, F., Fox, E., Garnett, R. (eds.) Advances in Neural Information Processing Systems (NeurIPS), pp. 3358\u20133369. Curran Associates Inc. (2019)"},{"key":"10_CR39","unstructured":"Szegedy, C., et al.: Intriguing properties of neural networks. Presented at the (2014)"},{"key":"10_CR40","unstructured":"Tian, Y., Krishnan, D., Isola, P.: Contrastive representation distillation. Presented at the (2020)"},{"key":"10_CR41","unstructured":"Wiyatno, R.R., Xu, A., Dia, O., de Berker, A.: Adversarial examples in modern machine learning: a review, November 2019"},{"key":"10_CR42","doi-asserted-by":"crossref","unstructured":"Yang, T., Chen, Y., Sze, V.: Designing energy-efficient convolutional neural networks using energy-aware pruning. In: IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR), pp. 6071\u20136079, July 2017","DOI":"10.1109\/CVPR.2017.643"},{"key":"10_CR43","unstructured":"Zhang, T., et al.: StructADMM: a systematic, high-efficiency framework of structured weight pruning for DNNs (2018)"},{"key":"10_CR44","doi-asserted-by":"crossref","unstructured":"Zhou, B., Khosla, A., Lapedriza, A., Oliva, A., Torralba, A.: Learning deep features for discriminative localization. In: IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR), pp. 2921\u20132929, June 2016","DOI":"10.1109\/CVPR.2016.319"}],"container-title":["Lecture Notes in Networks and Systems","Intelligent Systems and Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-82193-7_10","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,8,3]],"date-time":"2021-08-03T15:24:57Z","timestamp":1628004297000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-030-82193-7_10"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,8,4]]},"ISBN":["9783030821920","9783030821937"],"references-count":44,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-82193-7_10","relation":{},"ISSN":["2367-3370","2367-3389"],"issn-type":[{"value":"2367-3370","type":"print"},{"value":"2367-3389","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,8,4]]},"assertion":[{"value":"4 August 2021","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"IntelliSys","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Proceedings of SAI Intelligent Systems Conference","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Amsterdam","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2021","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2 September 2021","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"3 September 2021","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"intellisys2021","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/saiconference.com\/IntelliSys","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}