{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,7,4]],"date-time":"2025-07-04T21:01:19Z","timestamp":1751662879719,"version":"3.40.3"},"publisher-location":"Cham","reference-count":43,"publisher":"Springer Nature Switzerland","isbn-type":[{"type":"print","value":"9783031331695"},{"type":"electronic","value":"9783031331701"}],"license":[{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2023]]},"DOI":"10.1007\/978-3-031-33170-1_3","type":"book-chapter","created":{"date-parts":[[2023,6,2]],"date-time":"2023-06-02T12:55:27Z","timestamp":1685710527000},"page":"37-61","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["Verifying Attention Robustness of\u00a0Deep Neural Networks Against Semantic Perturbations"],"prefix":"10.1007","author":[{"given":"Satoshi","family":"Munakata","sequence":"first","affiliation":[]},{"given":"Caterina","family":"Urban","sequence":"additional","affiliation":[]},{"given":"Haruki","family":"Yokoyama","sequence":"additional","affiliation":[]},{"given":"Koji","family":"Yamamoto","sequence":"additional","affiliation":[]},{"given":"Kazuki","family":"Munakata","sequence":"additional","affiliation":[]}],"member":"297","published-online":{"date-parts":[[2023,6,3]]},"reference":[{"key":"3_CR1","unstructured":"AIRC, A: ABCI system overview (2022). https:\/\/docs.abci.ai\/en\/system-overview\/"},{"issue":"5","key":"3_CR2","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3453444","volume":"54","author":"R Ashmore","year":"2021","unstructured":"Ashmore, R., Calinescu, R., Paterson, C.: Assuring the machine learning lifecycle: desiderata, methods, and challenges. ACM Comput. Surv. (CSUR) 54(5), 1\u201339 (2021)","journal-title":"ACM Comput. Surv. (CSUR)"},{"key":"3_CR3","unstructured":"Balunovic, M., Baader, M., Singh, G., Gehr, T., Vechev, M.: Certifying geometric robustness of neural networks. In: NeurIPS, vol. 32 (2019)"},{"key":"3_CR4","unstructured":"Chen, J., Wu, X., Rastogi, V., Liang, Y., Jha, S.: Robust attribution regularization. In: Advances in Neural Information Processing Systems, vol. 32 (2019)"},{"key":"3_CR5","unstructured":"Daniel, S., Nikhil, T., Been, K., Fernanda, V., Wattenberg, M.: Smoothgrad: removing noise by adding noise. In: ICMLVIZ. PMLR (2017)"},{"issue":"6","key":"3_CR6","doi-asserted-by":"publisher","first-page":"141","DOI":"10.1109\/MSP.2012.2211477","volume":"29","author":"L Deng","year":"2012","unstructured":"Deng, L.: The MNIST database of handwritten digit images for machine learning research. IEEE Signal Process. Mag. 29(6), 141\u2013142 (2012)","journal-title":"IEEE Signal Process. Mag."},{"key":"3_CR7","unstructured":"Engstrom, L., Tran, B., Tsipras, D., Schmidt, L., Madry, A.: Exploring the landscape of spatial robustness. In: ICML, pp. 1802\u20131811. PMLR (2019)"},{"key":"3_CR8","doi-asserted-by":"crossref","unstructured":"Fawzi, A., Frossard, P.: Manitest: are classifiers really invariant? In: BMVC, pp. 106.1\u2013106.13 (2015)","DOI":"10.5244\/C.29.106"},{"key":"3_CR9","unstructured":"Fromherz, A., Leino, K., Fredrikson, M., Parno, B., Pasareanu, C.: Fast geometric projections for local robustness certification. In: ICLR (2021)"},{"key":"3_CR10","unstructured":"Fromherz, A., Leino, K., Fredrikson, M., Parno, B., Pasareanu, C.: Fast geometric projections for local robustness certification\u2014openreview (2021). https:\/\/openreview.net\/forum?id=zWy1uxjDdZJ"},{"key":"3_CR11","doi-asserted-by":"crossref","unstructured":"Gao, X., Saha, R.K., Prasad, M.R., Roychoudhury, A.: Fuzz testing based data augmentation to improve robustness of deep neural networks. In: ICSE, pp. 1147\u20131158. IEEE, ACM (2020)","DOI":"10.1145\/3377811.3380415"},{"key":"3_CR12","doi-asserted-by":"crossref","unstructured":"Guo, H., Zheng, K., Fan, X., Yu, H., Wang, S.: Visual attention consistency under image transforms for multi-label image classification. In: CVPR, pp. 729\u2013739. IEEE, CVF (2019)","DOI":"10.1109\/CVPR.2019.00082"},{"key":"3_CR13","doi-asserted-by":"crossref","unstructured":"Han, T., Tu, W.W., Li, Y.F.: Explanation consistency training: facilitating consistency-based semi-supervised learning with interpretability. In: AAAI, vol. 35, pp. 7639\u20137646. AAAI (2021)","DOI":"10.1609\/aaai.v35i9.16934"},{"key":"3_CR14","unstructured":"Hanin, B., Rolnick, D.: Deep ReLU networks have surprisingly few activation patterns. In: NeurIPS, vol. 32 (2019)"},{"key":"3_CR15","unstructured":"Hinz, P.: An analysis of the piece-wise affine structure of ReLU feed-forward neural networks. Ph.D. thesis, ETH Zurich (2021)"},{"key":"3_CR16","doi-asserted-by":"publisher","DOI":"10.1016\/j.cosrev.2020.100270","volume":"37","author":"X Huang","year":"2020","unstructured":"Huang, X., et al.: A survey of safety and trustworthiness of deep neural networks: Verification, testing, adversarial attack and defence, and interpretability. Comput. Sci. Rev. 37, 100270 (2020)","journal-title":"Comput. Sci. Rev."},{"key":"3_CR17","doi-asserted-by":"crossref","unstructured":"Jha, S.K., Ewetz, R., Velasquez, A., Ramanathan, A., Jha, S.: Shaping noise for robust attributions in neural stochastic differential equations. In: Proceedings of the AAAI Conference on Artificial Intelligence, vol. 36, pp. 9567\u20139574 (2022)","DOI":"10.1609\/aaai.v36i9.21190"},{"key":"3_CR18","unstructured":"Jordan, M., Lewis, J., Dimakis, A.G.: Provable certificates for adversarial examples: fitting a ball in the union of polytopes. In: NeurIPS, vol. 32 (2019)"},{"key":"3_CR19","doi-asserted-by":"crossref","unstructured":"Kanbak, C., Moosavi-Dezfooli, S., Frossard, P.: Geometric robustness of deep networks: analysis and improvement. In: CVPR, pp. 4441\u20134449 (2018)","DOI":"10.1109\/CVPR.2018.00467"},{"key":"3_CR20","unstructured":"Krizhevsky, A., Sutskever, I., Hinton, G.E.: ImageNet classification with deep convolutional neural networks. In: NeurIPS, vol. 25 (2012)"},{"key":"3_CR21","unstructured":"Lim, C.H., Urtasun, R., Yumer, E.: Hierarchical verification for adversarial robustness. In: ICML, vol. 119, pp. 6072\u20136082. PMLR (2020)"},{"key":"3_CR22","doi-asserted-by":"crossref","unstructured":"Mirman, M., H\u00e4gele, A., Bielik, P., Gehr, T., Vechev, M.: Robustness certification with generative models. In: PLDI, pp. 1141\u20131154. ACM SIGPLAN (2021)","DOI":"10.1145\/3410308"},{"key":"3_CR23","doi-asserted-by":"crossref","unstructured":"Mohapatra, J., Weng, T.W., Chen, P.Y., Liu, S., Daniel, L.: Towards verifying robustness of neural networks against a family of semantic perturbations. In: CVPR, pp. 244\u2013252. IEEE, CVF (2020)","DOI":"10.1109\/CVPR42600.2020.00032"},{"key":"3_CR24","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1016\/j.dsp.2017.10.011","volume":"73","author":"G Montavon","year":"2018","unstructured":"Montavon, G., Samek, W., M\u00fcller, K.R.: Methods for interpreting and understanding deep neural networks. Digit. Signal Process. 73, 1\u201315 (2018)","journal-title":"Digit. Signal Process."},{"key":"3_CR25","doi-asserted-by":"crossref","unstructured":"M\u00fcller, M.N., Makarchuk, G., Singh, G., P\u00fcschel, M., Vechev, M.T.: PRIMA: general and precise neural network certification via scalable convex hull approximations. Proc. ACM Program. Lang. 6(POPL), 1\u201333 (2022)","DOI":"10.1145\/3498704"},{"key":"3_CR26","doi-asserted-by":"crossref","unstructured":"Ribeiro, M.T., Singh, S., Guestrin, C.: \u201cWhy should I trust you?\u201d explaining the predictions of any classifier. In: KDD, pp. 1135\u20131144. ACM SIGKDD (2016)","DOI":"10.1145\/2939672.2939778"},{"key":"3_CR27","doi-asserted-by":"crossref","unstructured":"Selvaraju, R.R., Cogswell, M., Das, A., Vedantam, R., Parikh, D., Batra, D.: Grad-CAM: visual explanations from deep networks via gradient-based localization. In: ICCV. IEEE (2017)","DOI":"10.1109\/ICCV.2017.74"},{"key":"3_CR28","unstructured":"Simonyan, K., Vedaldi, A., Zisserman, A.: Deep inside convolutional networks: visualising image classification models and saliency maps. In: ICLR (2014)"},{"key":"3_CR29","unstructured":"Simonyan, K., Zisserman, A.: Very deep convolutional networks for large-scale image recognition. In: ICLR (2015)"},{"key":"3_CR30","doi-asserted-by":"crossref","unstructured":"Singh, G., Gehr, T., P\u00fcschel, M., Vechev, M.: An abstract domain for certifying neural networks. In: POPL, pp. 1\u201330. ACM New York (2019)","DOI":"10.1145\/3290354"},{"key":"3_CR31","unstructured":"Sotoudeh, M., Thakur, A.V.: Computing linear restrictions of neural networks. In: NeurIPS, vol. 32 (2019)"},{"key":"3_CR32","doi-asserted-by":"crossref","unstructured":"Sotoudeh, M., Thakur, A.V.: Provable repair of deep neural networks. In: PLDI, pp. 588\u2013603. ACM SIGPLAN (2021)","DOI":"10.1145\/3453483.3454064"},{"key":"3_CR33","doi-asserted-by":"crossref","unstructured":"Sotoudeh, M., Thakur, A.V.: SyReNN: a tool for analyzing deep neural networks. In: TACAS, pp. 281\u2013302 (2021)","DOI":"10.1007\/978-3-030-72013-1_15"},{"key":"3_CR34","unstructured":"Sundararajan, M., Taly, A., Yan, Q.: Axiomatic attribution for deep networks. In: ICML, pp. 3319\u20133328. PMLR (2017)"},{"key":"3_CR35","unstructured":"Szegedy, C., et al.: Intriguing properties of neural networks. In: ICLR (2014)"},{"key":"3_CR36","unstructured":"Tsipras, D., Santurkar, S., Engstrom, L., Turner, A., Madry, A.: Robustness may be at odds with accuracy. In: ICLR (2019)"},{"key":"3_CR37","doi-asserted-by":"crossref","unstructured":"Urban, C., Christakis, M., W\u00fcstholz, V., Zhang, F.: Perfectly parallel fairness certification of neural networks. Proc. ACM Program. Lang. 4(OOPSLA), 1\u201330 (2020)","DOI":"10.1145\/3428253"},{"key":"3_CR38","unstructured":"Urban, C., Min\u00e9, A.: A review of formal methods applied to machine learning. CoRR abs\/2104.02466 (2021). https:\/\/arxiv.org\/abs\/2104.02466"},{"key":"3_CR39","unstructured":"Vaswani, A., et al.: Attention is all you need. In: Advances in Neural Information Processing Systems, vol. 30 (2017)"},{"key":"3_CR40","unstructured":"Xiao, C., Zhu, J., Li, B., He, W., Liu, M., Song, D.: Spatially transformed adversarial examples. In: ICLR (2018)"},{"key":"3_CR41","unstructured":"Xiao, H., Rasul, K., Vollgraf, R.: Fashion-MNIST: a novel image dataset for benchmarking machine learning algorithms (2017). arXiv:1708.07747"},{"key":"3_CR42","unstructured":"Xu, S., Vaughan, J., Chen, J., Zhang, A., Sudjianto, A.: Traversing the local polytopes of ReLU neural networks: a unified approach for network verification. In: AdvML. AAAI (2022)"},{"issue":"3","key":"3_CR43","doi-asserted-by":"publisher","first-page":"407","DOI":"10.1007\/s00165-021-00548-1","volume":"33","author":"P Yang","year":"2021","unstructured":"Yang, P., et al.: Enhancing robustness verification for deep neural networks via symbolic propagation. Formal Aspects Comput. 33(3), 407\u2013435 (2021)","journal-title":"Formal Aspects Comput."}],"container-title":["Lecture Notes in Computer Science","NASA Formal Methods"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-33170-1_3","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,6,2]],"date-time":"2023-06-02T12:55:49Z","timestamp":1685710549000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-33170-1_3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023]]},"ISBN":["9783031331695","9783031331701"],"references-count":43,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-33170-1_3","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2023]]},"assertion":[{"value":"3 June 2023","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"NFM","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"NASA Formal Methods Symposium","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Houston, TX","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"USA","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2023","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"16 May 2023","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"18 May 2023","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"15","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"nfm2023","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/conf.researchr.org\/home\/nfm-2023","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Single-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"EasyChair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"75","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"26","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"35% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3.9","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"6","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}