{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,23]],"date-time":"2026-04-23T09:04:56Z","timestamp":1776935096514,"version":"3.51.2"},"publisher-location":"Cham","reference-count":43,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783030884178","type":"print"},{"value":"9783030884185","type":"electronic"}],"license":[{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2021]]},"DOI":"10.1007\/978-3-030-88418-5_27","type":"book-chapter","created":{"date-parts":[[2021,9,29]],"date-time":"2021-09-29T21:04:30Z","timestamp":1632949470000},"page":"563-583","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":5,"title":["DA3G: Detecting Adversarial Attacks by Analysing Gradients"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-1787-4102","authenticated-orcid":false,"given":"Jan-Philipp","family":"Schulze","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7901-7168","authenticated-orcid":false,"given":"Philip","family":"Sperl","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9337-7506","authenticated-orcid":false,"given":"Konstantin","family":"B\u00f6ttinger","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2021,9,30]]},"reference":[{"key":"27_CR1","unstructured":"Athalye, A., Carlini, N., Wagner, D.: Obfuscated gradients give a false sense of security: circumventing defenses to adversarial examples. In: 35th International Conference on Machine Learning, ICML 2018, vol. 80, pp. 274\u2013283 (2018). http:\/\/proceedings.mlr.press\/v80\/athalye18a.html"},{"key":"27_CR2","unstructured":"Athalye, A., Engstrom, L., Ilyas, A., Kevin, K.: Synthesizing robust adversarial examples. In: 35th International Conference on Machine Learning, ICML 2018, vol. 80, pp. 284\u2013293 (2018). http:\/\/proceedings.mlr.press\/v80\/athalye18b.html"},{"key":"27_CR3","doi-asserted-by":"publisher","unstructured":"Biggio, B., et al.: Evasion attacks against machine learning at test time. In: Machine Learning and Knowledge Discovery in Databases, pp. 387\u2013402 (2013). https:\/\/doi.org\/10.1007\/978-3-642-40994-3_25","DOI":"10.1007\/978-3-642-40994-3_25"},{"key":"27_CR4","unstructured":"Brendel, W., Rauber, J., Bethge, M.: Decision-based adversarial attacks: reliable attacks against black-box machine learning models. In: International Conference on Learning Representations (2018). https:\/\/openreview.net\/forum?id=SyZI0GWCZ"},{"key":"27_CR5","unstructured":"Carlini, N., et al.: On evaluating adversarial robustness. arXiv (2019). http:\/\/arxiv.org\/abs\/1902.06705"},{"key":"27_CR6","doi-asserted-by":"crossref","unstructured":"Carlini, N., Wagner, D.: Adversarial examples are not easily detected: bypassing ten detection methods. In: AISec 2017 - Proceedings of the 10th ACM Workshop on Artificial Intelligence and Security, pp. 3\u201314 (2017). http:\/\/doi.acm.org\/10.1145\/3128572.3140444","DOI":"10.1145\/3128572.3140444"},{"key":"27_CR7","doi-asserted-by":"publisher","unstructured":"Carlini, N., Wagner, D.: Towards evaluating the robustness of neural networks. In: Proceedings - IEEE Symposium on Security and Privacy, pp. 39\u201357. IEEE (2017). https:\/\/doi.org\/10.1109\/SP.2017.49","DOI":"10.1109\/SP.2017.49"},{"key":"27_CR8","unstructured":"Chollet, F.: Simple MNIST convnet (2015). https:\/\/keras.io\/examples\/vision\/mnist_convnet\/"},{"key":"27_CR9","unstructured":"Croce, F., Hein, M.: Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks. In: Proceedings of Machine Learning Research, pp. 2206\u20132216. PMLR (2020). http:\/\/proceedings.mlr.press\/v119\/croce20b\/croce20b.pdf"},{"key":"27_CR10","unstructured":"Dhaliwal, J., Shintre, S.: Gradient similarity : an explainable approach to detect adversarial attacks against deep learning (2018). https:\/\/arxiv.org\/pdf\/1806.10707.pdf"},{"key":"27_CR11","unstructured":"Dvijotham, K.D., et al.: Training verified learners with learned verifiers (2018). https:\/\/arxiv.org\/pdf\/1805.10265.pdf"},{"key":"27_CR12","doi-asserted-by":"publisher","unstructured":"Fidel, G., Bitton, R., Shabtai, A.: When explainability meets adversarial learning: detecting adversarial examples using SHAP signatures. In: 2020 International Joint Conference on Neural Networks (IJCNN) (2020). https:\/\/doi.org\/10.1109\/IJCNN48605.2020.9207637","DOI":"10.1109\/IJCNN48605.2020.9207637"},{"key":"27_CR13","doi-asserted-by":"publisher","unstructured":"Freitas, S., Chen, S.T., Wang, Z.J., Horng Chau, D.: UnMask: adversarial detection and defense through robust feature alignment. In: Proceedings - 2020 IEEE International Conference on Big Data, pp. 1081\u20131088 (2020). https:\/\/doi.org\/10.1109\/BigData50022.2020.9378303","DOI":"10.1109\/BigData50022.2020.9378303"},{"key":"27_CR14","unstructured":"Ghiasi, A., Shafahi, A., Goldstein, T.: Breaking certified defenses: semantic adversarial examples with spoofed robustness certificates. In: International Conference on Learning Representations (2020). https:\/\/openreview.net\/forum?id=HJxdTxHYvB"},{"key":"27_CR15","unstructured":"Goodfellow, I.J., Shlens, J., Szegedy, C.: Explaining and harnessing adversarial examples (2015). http:\/\/arxiv.org\/abs\/1412.6572"},{"key":"27_CR16","doi-asserted-by":"publisher","unstructured":"He, K., Zhang, X., Ren, S., Sun, J.: Deep residual learning for image recognition. In: Proceedings of the IEEE Computer Society Conference on Computer Vision and Pattern Recognition, pp. 770\u2013778 (2016). https:\/\/doi.org\/10.1109\/CVPR.2016.90","DOI":"10.1109\/CVPR.2016.90"},{"key":"27_CR17","unstructured":"Hein, M., Andriushchenko, M.: Formal guarantees on the robustness of a classifier against adversarial manipulation. In: Advances in Neural Information Processing Systems (2017). https:\/\/proceedings.neurips.cc\/paper\/2017\/file\/e077e1a544eec4f0307cf5c3c721d944-Paper.pdf"},{"key":"27_CR18","unstructured":"Ilyas, A., Santurkar, S., Tsipras, D., Engstrom, L., Tran, B., Madry, A.: Adversarial examples are not bugs, they are features. In: Advances in Neural Information Processing Systems, vol. 32 (2019). https:\/\/proceedings.neurips.cc\/paper\/2019\/file\/e2c420d928d4bf8ce0ff2ec19b371514-Paper.pdf"},{"key":"27_CR19","unstructured":"Keras: CIFAR-10 CNN (2020). https:\/\/keras.io\/examples\/cifar10_cnn\/"},{"key":"27_CR20","unstructured":"Klambauer, G., Unterthiner, T., Mayr, A.: Self-normalizing neural networks. In: NIPS 2017: Proceedings of the 31st International Conference on Neural Information Processing Systems, pp. 972\u2013981 (2017). https:\/\/papers.neurips.cc\/paper\/2017\/file\/5d44ee6f2c3f71b73125876103c8f6c4-Paper.pdf"},{"key":"27_CR21","unstructured":"Krizhevsky, A.: Learning multiple layers of features from tiny images. Technical report (2009). https:\/\/www.cs.toronto.edu\/~kriz\/learning-features-2009-TR.pdf"},{"key":"27_CR22","doi-asserted-by":"publisher","unstructured":"Kurakin, A., Goodfellow, I.J., Bengio, S.: Adversarial examples in the physical world. In: International Conference on Learning Representations, ICLR, pp. 99\u2013112 (2016). https:\/\/doi.org\/10.1201\/9781351251389-8","DOI":"10.1201\/9781351251389-8"},{"issue":"11","key":"27_CR23","doi-asserted-by":"publisher","first-page":"2278","DOI":"10.1109\/5.726791","volume":"86","author":"Y LeCun","year":"1998","unstructured":"LeCun, Y., Bottou, L., Bengio, Y., Haffner, P.: Gradient-based learning applied to document recognition. Proc. IEEE 86(11), 2278\u20132323 (1998). https:\/\/doi.org\/10.1109\/5.726791","journal-title":"Proc. IEEE"},{"key":"27_CR24","unstructured":"LeCun, Y., Cortes, C., Burges, C.: MNIST handwritten digit database. ATT Labs, February 2010. http:\/\/yann.lecun.com\/exdb\/mnist"},{"key":"27_CR25","unstructured":"Lust, J., Condurache, A.P.: GraN: an efficient gradient-norm based detector for adversarial and misclassified examples. In: 28th European Symposium on Artificial Neural Networks, Computational Intelligence and Machine Learning (2020)"},{"key":"27_CR26","unstructured":"Madry, A., Makelov, A., Schmidt, L., Tsipras, D., Vladu, A., Science, C.: Towards deep learning medels resistant to adversarial attacks. In: International Conference on Learning Representations (2018). https:\/\/openreview.net\/forum?id=rJzIBfZAb"},{"key":"27_CR27","doi-asserted-by":"publisher","unstructured":"Moosavi-Dezfooli, S., Fawzi, A., Frossard, P.: DeepFool: a simple and accurate method to fool deep neural networks. In: 2016 IEEE Conference on Computer Vision and Pattern Recognition (CVPR), pp. 2574\u20132582 (2016). https:\/\/doi.org\/10.1109\/CVPR.2016.282","DOI":"10.1109\/CVPR.2016.282"},{"key":"27_CR28","doi-asserted-by":"publisher","unstructured":"Nguyen, A., Yosinski, J., Clune, J.: Deep neural networks are easily fooled: high confidence predictions for unrecognizable images. In: Proceedings of the IEEE Computer Society Conference on Computer Vision and Pattern Recognition, pp. 427\u2013436 (2015). https:\/\/doi.org\/10.1109\/CVPR.2015.7298640","DOI":"10.1109\/CVPR.2015.7298640"},{"key":"27_CR29","unstructured":"Raghunathan, A., Steinhardt, J., Liang, P.: Certified defenses against adversarial examples. In: International Conference on Learning Representations (2018). https:\/\/openreview.net\/forum?id=Bys4ob-Rb"},{"key":"27_CR30","unstructured":"Raghunathan, A., Steinhardt, J., Liang, P.: Semidefinite relaxations for certifying robustness to adversarial examples. In: Advances in Neural Information Processing Systems (2018). https:\/\/proceedings.neurips.cc\/paper\/2018\/file\/29c0605a3bab4229e46723f89cf59d83-Paper.pdf"},{"key":"27_CR31","unstructured":"Rauber, J., Brendel, W., Bethge, M.: Foolbox: a Python toolbox to benchmark the robustness of machine learning models. In: Reliable Machine Learning in the Wild Workshop, 34th International Conference on Machine Learning (2017). http:\/\/arxiv.org\/abs\/1707.04131"},{"key":"27_CR32","doi-asserted-by":"publisher","unstructured":"Rauber, J., Zimmermann, R., Bethge, M., Brendel, W.: Foolbox native: fast adversarial attacks to benchmark the robustness of machine learning models in PyTorch, Tensorflow, and JAX. J. Open Source Softw. 5(53), 2607 (2020). https:\/\/doi.org\/10.21105\/joss.02607","DOI":"10.21105\/joss.02607"},{"key":"27_CR33","doi-asserted-by":"publisher","unstructured":"Sharad, K., Marson, G.A., Truong, H.T.T., Karame, G.: On the security of randomized defenses against adversarial samples. In: Proceedings of the 15th ACM Asia Conference on Computer and Communications Security, pp. 381\u2013393 (2020). https:\/\/doi.org\/10.1145\/3320269.3384751","DOI":"10.1145\/3320269.3384751"},{"key":"27_CR34","doi-asserted-by":"publisher","unstructured":"Sperl, P., Kao, C.Y., Chen, P., Lei, X., Bottinger, K.: DLA: dense-layer-analysis for adversarial example detection. In: Proceedings 5th IEEE European Symposium on Security and Privacy, pp. 198\u2013215 (2020). https:\/\/doi.org\/10.1109\/EuroSP48549.2020.00021","DOI":"10.1109\/EuroSP48549.2020.00021"},{"key":"27_CR35","doi-asserted-by":"publisher","unstructured":"Sperl, P., Schulze, J.P., B\u00f6ttinger, K.: Activation anomaly analysis. In: Machine Learning and Knowledge Discovery in Databases, pp. 69\u201384 (2021). https:\/\/doi.org\/10.1007\/978-3-030-67661-2_5","DOI":"10.1007\/978-3-030-67661-2_5"},{"issue":"5","key":"27_CR36","doi-asserted-by":"publisher","first-page":"828","DOI":"10.1109\/TEVC.2019.2890858","volume":"23","author":"J Su","year":"2019","unstructured":"Su, J., Vargas, D.V., Sakurai, K.: One pixel attack for fooling deep neural networks. IEEE Trans. Evol. Comput. 23(5), 828\u2013841 (2019). https:\/\/doi.org\/10.1109\/TEVC.2019.2890858","journal-title":"IEEE Trans. Evol. Comput."},{"key":"27_CR37","unstructured":"Szegedy, C., et al.: Intriguing properties of neural networks. In: International Conference on Learning Representations (2014). https:\/\/openreview.net\/forum?id=kklr_MTHMRQjG"},{"key":"27_CR38","unstructured":"Tram\u00e8r, F., Carlini, N., Brendel, W., Madry, A.: On adaptive attacks to adversarial example defenses. In: Advances in Neural Information Processing Systems, pp. 1633\u20131645 (2020). https:\/\/proceedings.neurips.cc\/paper\/2020\/file\/11f38f8ecd71867b42433548d1078e38-Paper.pdf"},{"key":"27_CR39","unstructured":"Wong, E., Zico Kolter, J.: Provable defenses against adversarial examples via the convex outer adversarial polytope. In: Proceedings of the 35th International Conference on Machine Learning, pp. 5286\u20135295 (2018). http:\/\/proceedings.mlr.press\/v80\/wong18a\/wong18a.pdf"},{"key":"27_CR40","unstructured":"Xiao, H., Rasul, K., Vollgraf, R.: Fashion-MNIST: a novel image dataset for benchmarking machine learning algorithms. arXiv pp. 1\u20136 (2017). https:\/\/arxiv.org\/pdf\/1708.07747.pdf"},{"key":"27_CR41","doi-asserted-by":"publisher","unstructured":"Xu, W., Evans, D., Qi, Y.: Feature squeezing: detecting adversarial examples in deep neural networks. In: Network and Distributed System Security Symposium, NDSS (2018). https:\/\/doi.org\/10.14722\/ndss.2018.23198","DOI":"10.14722\/ndss.2018.23198"},{"key":"27_CR42","doi-asserted-by":"publisher","unstructured":"Yang, P., Chen, J., Hsieh, C.J., Wang, J.L., Jordan, M.I.: ML-LOO: detecting adversarial examples with feature attribution. In: AAAI Conference on Artificial Intelligence (2020). https:\/\/doi.org\/10.1609\/aaai.v34i04.6140","DOI":"10.1609\/aaai.v34i04.6140"},{"key":"27_CR43","doi-asserted-by":"publisher","unstructured":"Zhang, S., et al.: Detecting adversarial samples for deep learning models: a comparative study. IEEE Trans. Netw. Sci. Eng. 4697 (2021). https:\/\/doi.org\/10.1109\/tnse.2021.3057071","DOI":"10.1109\/tnse.2021.3057071"}],"container-title":["Lecture Notes in Computer Science","Computer Security \u2013 ESORICS 2021"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-88418-5_27","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,9,29]],"date-time":"2021-09-29T21:28:53Z","timestamp":1632950933000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-030-88418-5_27"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021]]},"ISBN":["9783030884178","9783030884185"],"references-count":43,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-88418-5_27","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021]]},"assertion":[{"value":"30 September 2021","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ESORICS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"European Symposium on Research in Computer Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Darmstadt","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Germany","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2021","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"4 October 2021","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"8 October 2021","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"26","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"esorics2021","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/esorics2021.athene-center.de\/index.php","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Single-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"EasyChair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"351","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"71","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"20% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3.07","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"6.06","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"The conference was held virtually due to the COVID-19 pandemic.","order":10,"name":"additional_info_on_review_process","label":"Additional Info on Review Process","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}