{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,22]],"date-time":"2026-04-22T18:42:38Z","timestamp":1776883358133,"version":"3.51.2"},"publisher-location":"Cham","reference-count":53,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031729126","type":"print"},{"value":"9783031729133","type":"electronic"}],"license":[{"start":{"date-parts":[[2024,12,2]],"date-time":"2024-12-02T00:00:00Z","timestamp":1733097600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,12,2]],"date-time":"2024-12-02T00:00:00Z","timestamp":1733097600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025]]},"DOI":"10.1007\/978-3-031-72913-3_26","type":"book-chapter","created":{"date-parts":[[2024,12,1]],"date-time":"2024-12-01T21:45:33Z","timestamp":1733089533000},"page":"466-483","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Interpretability-Guided Test-Time Adversarial Defense"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-3379-2238","authenticated-orcid":false,"given":"Akshay","family":"Kulkarni","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tsui-Wei","family":"Weng","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2024,12,2]]},"reference":[{"key":"26_CR1","unstructured":"Addepalli, S., Jain, S., Babu, R.V.: Efficient and effective augmentation strategy for adversarial training. In: NeurIPS (2022)"},{"key":"26_CR2","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"301","DOI":"10.1007\/978-3-031-20065-6_18","volume-title":"ECCV 2022","author":"S Addepalli","year":"2022","unstructured":"Addepalli, S., Jain, S., Sriramanan, G., Venkatesh Babu, R.: Scaling adversarial training to large perturbation bounds. In: Avidan, S., Brostow, G., Ciss\u00e9, M., Farinella, G.M., Hassner, T. (eds.) ECCV 2022. LNCS, vol. 13665, pp. 301\u2013316. Springer, Cham (2022). https:\/\/doi.org\/10.1007\/978-3-031-20065-6_18"},{"key":"26_CR3","doi-asserted-by":"crossref","unstructured":"Alfarra, M., P\u00e9rez, J.C., Thabet, A., Bibi, A., Torr, P.H.S., Ghanem, B.: Combating adversaries with anti-adversaries. In: AAAI (2022)","DOI":"10.1609\/aaai.v36i6.20545"},{"key":"26_CR4","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"484","DOI":"10.1007\/978-3-030-58592-1_29","volume-title":"Computer Vision \u2013 ECCV 2020","author":"M Andriushchenko","year":"2020","unstructured":"Andriushchenko, M., Croce, F., Flammarion, N., Hein, M.: Square attack: a query-efficient black-box adversarial attack via random search. In: Vedaldi, A., Bischof, H., Brox, T., Frahm, J.-M. (eds.) ECCV 2020. LNCS, vol. 12368, pp. 484\u2013501. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-58592-1_29"},{"key":"26_CR5","unstructured":"Athalye, A., Carlini, N., Wagner, D.: Obfuscated gradients give a false sense of security: circumventing defenses to adversarial examples. In: ICML (2018)"},{"key":"26_CR6","unstructured":"Bai, N., Iyer, R.A., Oikarinen, T., Weng, T.W.: Describe-and-dissect: interpreting neurons in vision networks with language models. arXiv preprint arXiv:2403.13771 (2024)"},{"key":"26_CR7","unstructured":"Bai, Y., Zeng, Y., Jiang, Y., Xia, S.T., Ma, X., Wang, Y.: Improving adversarial robustness via channel-wise activation suppressing. In: ICLR (2021)"},{"key":"26_CR8","doi-asserted-by":"crossref","unstructured":"Bau, D., Zhou, B., Khosla, A., Oliva, A., Torralba, A.: Network dissection: quantifying interpretability of deep visual representations. In: CVPR (2017)","DOI":"10.1109\/CVPR.2017.354"},{"key":"26_CR9","doi-asserted-by":"crossref","unstructured":"Bau, D., Zhu, J.Y., Strobelt, H., Lapedriza, A., Zhou, B., Torralba, A.: Understanding the role of individual units in a deep neural network. Proc. Nat. Acad. Sci. (2020)","DOI":"10.1073\/pnas.1907375117"},{"key":"26_CR10","unstructured":"Boopathy, A., et al.: Proper network interpretability helps adversarial robustness in classification. In: ICML (2020)"},{"key":"26_CR11","doi-asserted-by":"crossref","unstructured":"Carlini, N., Wagner, D.: Towards evaluating the robustness of neural networks. In: IEEE Symposium on Security and Privacy (2017)","DOI":"10.1109\/SP.2017.49"},{"key":"26_CR12","doi-asserted-by":"crossref","unstructured":"Chen, J., Gu, Q.: RayS: a ray searching method for hard-label adversarial attack. In: KDD (2020)","DOI":"10.1145\/3394486.3403225"},{"key":"26_CR13","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/s11004-011-9376-z","volume":"44","author":"Y Chen","year":"2012","unstructured":"Chen, Y., Oliver, D.S.: Ensemble randomized maximum likelihood method as an iterative ensemble smoother. Math. Geosci. 44, 1\u201326 (2012)","journal-title":"Math. Geosci."},{"key":"26_CR14","unstructured":"Chen, Z., Li, Q., Zhang, Z.: Towards robust neural networks via close-loop control. In: ICLR (2021)"},{"key":"26_CR15","unstructured":"Croce, F., et al.: RobustBench: a standardized adversarial robustness benchmark. In: Datasets and Benchmarks Track, NeurIPS (2021)"},{"key":"26_CR16","unstructured":"Croce, F., Gowal, S., Brunner, T., Shelhamer, E., Hein, M., Cemgil, T.: Evaluating the adversarial robustness of adaptive test-time defenses. In: ICML (2022)"},{"key":"26_CR17","unstructured":"Croce, F., Hein, M.: Minimally distorted adversarial examples with a fast adaptive boundary attack. In: ICML (2020)"},{"key":"26_CR18","unstructured":"Croce, F., Hein, M.: Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks. In: ICML (2020)"},{"key":"26_CR19","doi-asserted-by":"crossref","unstructured":"Eigen, H., Sadovnik, A.: TopKConv: increased adversarial robustness through deeper interpretability. In: ICMLA (2021)","DOI":"10.1109\/ICMLA52953.2021.00011"},{"key":"26_CR20","doi-asserted-by":"crossref","unstructured":"Gerasimou, S., Eniser, H.F., Sen, A., Cakan, A.: Importance-driven deep learning system testing. In: ACM\/IEEE ICSE (2020)","DOI":"10.1145\/3377811.3380391"},{"key":"26_CR21","unstructured":"Goodfellow, I.J., Shlens, J., Szegedy, C.: Explaining and harnessing adversarial examples. In: ICLR (2015)"},{"key":"26_CR22","doi-asserted-by":"crossref","unstructured":"He, K., Zhang, X., Ren, S., Sun, J.: Deep residual learning for image recognition. In: CVPR (2016)","DOI":"10.1109\/CVPR.2016.90"},{"key":"26_CR23","unstructured":"Hernandez, E., Schwettmann, S., Bau, D., Bagashvili, T., Torralba, A., Andreas, J.: Natural language descriptions of deep visual features. In: ICLR (2022)"},{"key":"26_CR24","doi-asserted-by":"crossref","unstructured":"Hwang, D., Lee, E., Rhee, W.: AID-purifier: a light auxiliary network for boosting adversarial defense. In: ICPR (2022)","DOI":"10.1016\/j.neucom.2023.126251"},{"key":"26_CR25","doi-asserted-by":"crossref","unstructured":"Jia, X., Zhang, Y., Wu, B., Ma, K., Wang, J., Cao, X.: LAS-AT: adversarial training with learnable attack strategy. In: CVPR (2022)","DOI":"10.1109\/CVPR52688.2022.01304"},{"key":"26_CR26","unstructured":"Kang, Q., Song, Y., Ding, Q., Tay, W.P.: Stable neural ODE with Lyapunov-stable equilibrium points for defending against adversarial attacks. In: NeurIPS (2021)"},{"key":"26_CR27","unstructured":"Krizhevsky, A.: Learning multiple layers of features from tiny images. Technical report, CIFAR (2009)"},{"key":"26_CR28","unstructured":"Kundu, S., Nazemi, M., Beerel, P.A., Pedram, M.: A tunable robust pruning framework through dynamic network rewiring of DNNs. In: ASP-DAC (2021)"},{"key":"26_CR29","doi-asserted-by":"crossref","unstructured":"Mangla, P., Singh, V., Balasubramanian, V.N.: On saliency maps and adversarial robustness. In: ECML-PKDD (2020)","DOI":"10.1007\/978-3-030-67661-2_17"},{"key":"26_CR30","doi-asserted-by":"crossref","unstructured":"Mao, C., Chiquier, M., Wang, H., Yang, J., Vondrick, C.: Adversarial attacks are reversible with natural supervision. In: ICCV (2021)","DOI":"10.1109\/ICCV48922.2021.00070"},{"key":"26_CR31","unstructured":"Mu, J., Andreas, J.: Compositional explanations of neurons. In: NeurIPS (2020)"},{"key":"26_CR32","doi-asserted-by":"crossref","unstructured":"Nayak, G.K., Rawal, R., Chakraborty, A.: DAD: data-free adversarial defense at test time. In: WACV (2022)","DOI":"10.1109\/WACV51458.2022.00384"},{"key":"26_CR33","unstructured":"Oikarinen, T., Weng, T.W.: CLIP-Dissect: automatic description of neuron representations in deep vision networks. In: ICLR (2023)"},{"key":"26_CR34","unstructured":"Oikarinen, T., Weng, T.W.: Linear explanations for individual neurons. In: ICML (2024)"},{"key":"26_CR35","unstructured":"Radford, A., et al.: Learning transferable visual models from natural language supervision. In: ICML (2021)"},{"issue":"3","key":"26_CR36","doi-asserted-by":"publisher","first-page":"211","DOI":"10.1007\/s11263-015-0816-y","volume":"115","author":"O Russakovsky","year":"2015","unstructured":"Russakovsky, O., et al.: ImageNet large scale visual recognition challenge. Int. J. Comput. Vision 115(3), 211\u2013252 (2015). https:\/\/doi.org\/10.1007\/s11263-015-0816-y","journal-title":"Int. J. Comput. Vision"},{"key":"26_CR37","unstructured":"Salman, H., Ilyas, A., Engstrom, L., Kapoor, A., Madry, A.: Do adversarially robust ImageNet models transfer better? In: NeurIPS (2020)"},{"key":"26_CR38","unstructured":"Sehwag, V., Wang, S., Mittal, P., Jana, S.: Hydra: pruning adversarially robust neural networks. In: NeurIPS (2020)"},{"key":"26_CR39","unstructured":"Shi, C., Holtz, C., Mishne, G.: Online adversarial purification based on self-supervised learning. In: ICLR (2021)"},{"key":"26_CR40","unstructured":"Sriramanan, G., Addepalli, S., Baburaj, A., Babu, R.V.: Guided adversarial attack for evaluating and enhancing adversarial defenses. In: NeurIPS (2020)"},{"key":"26_CR41","unstructured":"Sriramanan, G., Addepalli, S., Baburaj, A., Babu, R.V.: Towards efficient and effective adversarial training. In: NeurIPS (2021)"},{"key":"26_CR42","unstructured":"Wong, E., Rice, L., Kolter, J.Z.: Fast is better than free: Revisiting adversarial training. In: ICLR (2020)"},{"key":"26_CR43","unstructured":"Wu, B., et al.: Attacking adversarial attacks as a defense. arXiv preprint arXiv:2106.04938 (2021)"},{"key":"26_CR44","unstructured":"Wu, D., Xia, S.T., Wang, Y.: Adversarial weight perturbation helps robust generalization. In: NeurIPS (2020)"},{"issue":"4","key":"26_CR45","first-page":"1","volume":"19","author":"S Wu","year":"2023","unstructured":"Wu, S., Sang, J., Xu, K., Zhang, J., Yu, J.: Attention, please! Adversarial defense via activation rectification and preservation. ACM Trans. Multimed. Comput. Commun. Appl. 19(4), 1\u201318 (2023)","journal-title":"ACM Trans. Multimed. Comput. Commun. Appl."},{"key":"26_CR46","unstructured":"Wu, Y.H., Yuan, C.H., Wu, S.H.: Adversarial robustness via runtime masking and cleansing. In: ICML (2020)"},{"key":"26_CR47","unstructured":"Xiao, C., Zhong, P., Zheng, C.: Enhancing adversarial defense by k-winners-take-all. In: ICLR (2020)"},{"key":"26_CR48","doi-asserted-by":"crossref","unstructured":"Xie, X., et al.: NPC: neuron path coverage via characterizing decision logic of deep neural networks. ACM Trans. Softw. Eng. Methodol. 31(3) (2022)","DOI":"10.1145\/3490489"},{"key":"26_CR49","unstructured":"Yoon, J., Hwang, S.J., Lee, J.: Adversarial purification with score-based generative models. In: ICML (2021)"},{"key":"26_CR50","doi-asserted-by":"crossref","unstructured":"Zagoruyko, S., Komodakis, N.: Wide residual networks. In: BMVC (2016)","DOI":"10.5244\/C.30.87"},{"key":"26_CR51","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"818","DOI":"10.1007\/978-3-319-10590-1_53","volume-title":"Computer Vision \u2013 ECCV 2014","author":"MD Zeiler","year":"2014","unstructured":"Zeiler, M.D., Fergus, R.: Visualizing and understanding convolutional networks. In: Fleet, D., Pajdla, T., Schiele, B., Tuytelaars, T. (eds.) ECCV 2014. LNCS, vol. 8689, pp. 818\u2013833. Springer, Cham (2014). https:\/\/doi.org\/10.1007\/978-3-319-10590-1_53"},{"key":"26_CR52","unstructured":"Zhang, H., Yu, Y., Jiao, J., Xing, E.P., Ghaoui, L.E., Jordan, M.I.: Theoretically principled trade-off between robustness and accuracy. In: ICML (2019)"},{"key":"26_CR53","unstructured":"Zhao, Q., Wressnegger, C.: Holistic adversarially robust pruning. In: ICLR (2023)"}],"container-title":["Lecture Notes in Computer Science","Computer Vision \u2013 ECCV 2024"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-72913-3_26","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,12,1]],"date-time":"2024-12-01T23:27:33Z","timestamp":1733095653000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-72913-3_26"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,12,2]]},"ISBN":["9783031729126","9783031729133"],"references-count":53,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-72913-3_26","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,12,2]]},"assertion":[{"value":"2 December 2024","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ECCV","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"European Conference on Computer Vision","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Milan","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Italy","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2024","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"29 September 2024","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"4 October 2024","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"18","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"eccv2024","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/eccv2024.ecva.net\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}