{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,2]],"date-time":"2026-01-02T07:27:34Z","timestamp":1767338854896,"version":"3.40.3"},"publisher-location":"Cham","reference-count":50,"publisher":"Springer Nature Switzerland","isbn-type":[{"type":"print","value":"9783031729850"},{"type":"electronic","value":"9783031729867"}],"license":[{"start":{"date-parts":[[2024,11,2]],"date-time":"2024-11-02T00:00:00Z","timestamp":1730505600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,11,2]],"date-time":"2024-11-02T00:00:00Z","timestamp":1730505600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025]]},"DOI":"10.1007\/978-3-031-72986-7_11","type":"book-chapter","created":{"date-parts":[[2024,11,1]],"date-time":"2024-11-01T05:04:23Z","timestamp":1730437463000},"page":"180-197","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":4,"title":["Towards Reliable Evaluation and\u00a0Fast Training of\u00a0Robust Semantic Segmentation Models"],"prefix":"10.1007","author":[{"given":"Francesco","family":"Croce","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Naman D.","family":"Singh","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Matthias","family":"Hein","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2024,11,2]]},"reference":[{"key":"11_CR1","unstructured":"Agnihotri, S., Keuper, M.: Cospgd: a unified white-box adversarial attack for pixel-wise prediction tasks. arXiv preprint arXiv:2302.02213 (2023)"},{"key":"11_CR2","doi-asserted-by":"crossref","unstructured":"Arnab, A., Miksik, O., Torr, P.H.: On the robustness of semantic segmentation models to adversarial attacks. In: CVPR (2018)","DOI":"10.1109\/CVPR.2018.00099"},{"key":"11_CR3","unstructured":"Athalye, A., Carlini, N., Wagner, D.: Obfuscated gradients give a false sense of security: circumventing defenses to adversarial examples. In: ICML (2018)"},{"key":"11_CR4","unstructured":"Bai, Y., Mei, J., Yuille, A., Xie, C.: Are transformers more robust than CNNs? In: NeurIPS (2021)"},{"key":"11_CR5","unstructured":"Bao, H., Dong, L., Piao, S., Wei, F.: Beit: bert pre-training of image transformers. In: ICLR (2022)"},{"key":"11_CR6","doi-asserted-by":"crossref","unstructured":"Biggio, B., et al.: Evasion attacks against machine learning at test time. In: ECML\/PKKD (2013)","DOI":"10.1007\/978-3-642-40994-3_25"},{"key":"11_CR7","unstructured":"Brown, T.B., Man\u00e9, D., Roy, A., Abadi, M., Gilmer, J.: Adversarial patch. In: NeurIPS 2017 Workshop on Machine Learning and Computer Security (2017)"},{"key":"11_CR8","doi-asserted-by":"crossref","unstructured":"Carlini, N., Wagner, D.: Towards evaluating the robustness of neural networks. In: IEEE Symposium on Security and Privacy (2017)","DOI":"10.1109\/SP.2017.49"},{"key":"11_CR9","doi-asserted-by":"crossref","unstructured":"Chen, P.Y., Sharma, Y., Zhang, H., Yi, J., Hsieh, C.J.: EAD: elastic-net attacks to deep neural networks via adversarial examples. In: AAAI (2018)","DOI":"10.1609\/aaai.v32i1.11302"},{"key":"11_CR10","doi-asserted-by":"crossref","unstructured":"Cho, S., Jun, T.J., Oh, B., Kim, D.: Dapas: denoising autoencoder to prevent adversarial attack in semantic segmentation. In: IJCNN. IEEE (2020)","DOI":"10.1109\/IJCNN48605.2020.9207291"},{"key":"11_CR11","unstructured":"Cisse, M., Adi, Y., Neverova, N., Keshet, J.: Houdini: fooling deep structured prediction models. In: NeurIPS (2017)"},{"key":"11_CR12","unstructured":"Croce, F., et al.: Robustbench: a standardized adversarial robustness benchmark. In: NeurIPS Datasets and Benchmarks Track (2021)"},{"key":"11_CR13","doi-asserted-by":"crossref","unstructured":"Croce, F., Andriushchenko, M., Singh, N.D., Flammarion, N., Hein, M.: Sparse-RS: a versatile framework for query-efficient sparse black-box adversarial attacks. In: AAAI (2022)","DOI":"10.1609\/aaai.v36i6.20595"},{"key":"11_CR14","unstructured":"Croce, F., Hein, M.: Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks. In: ICML (2020)"},{"key":"11_CR15","unstructured":"Croce, F., Hein, M.: Mind the box: $$l_1$$-APGD for sparse adversarial attacks on image classifiers. In: ICML (2021)"},{"key":"11_CR16","doi-asserted-by":"crossref","unstructured":"Debenedetti, E., Sehwag, V., Mittal, P.: A light recipe to train robust vision transformers. In: IEEE Conference on Secure and Trustworthy Machine Learning (SaTML), pp. 225\u2013253 (2023)","DOI":"10.1109\/SaTML54575.2023.00024"},{"key":"11_CR17","unstructured":"Dosovitskiy, A., et al.: An image is worth 16x16 words: transformers for image recognition at scale. In: ICLR (2021)"},{"key":"11_CR18","doi-asserted-by":"publisher","first-page":"303","DOI":"10.1007\/s11263-009-0275-4","volume":"88","author":"M Everingham","year":"2010","unstructured":"Everingham, M., Van Gool, L., Williams, C.K., Winn, J., Zisserman, A.: The pascal visual object classes (VOC) challenge. Int. J. Comput. Vision 88, 303\u2013338 (2010)","journal-title":"Int. J. Comput. Vision"},{"key":"11_CR19","unstructured":"Goodfellow, I.J., Shlens, J., Szegedy, C.: Explaining and harnessing adversarial examples. In: ICLR (2015)"},{"key":"11_CR20","doi-asserted-by":"crossref","unstructured":"Grosse, K., Papernot, N., Manoharan, P., Backes, M., McDaniel, P.: Adversarial perturbations against deep neural networks for malware classification. arXiv preprint arXiv:1606.04435 (2016)","DOI":"10.1109\/SP.2016.41"},{"key":"11_CR21","doi-asserted-by":"crossref","unstructured":"Gu, J., Zhao, H., Tresp, V., Torr, P.H.: Segpgd: an effective and efficient adversarial attack for evaluating and boosting segmentation robustness. In: ECCV (2022)","DOI":"10.1007\/978-3-031-19818-2_18"},{"key":"11_CR22","doi-asserted-by":"crossref","unstructured":"Hariharan, B., Arbel\u00e1ez, P., Bourdev, L., Maji, S., Malik, J.: Semantic contours from inverse detectors. In: ICCV (2011)","DOI":"10.1109\/ICCV.2011.6126343"},{"key":"11_CR23","doi-asserted-by":"crossref","unstructured":"He, K., Zhang, X., Ren, S., Sun, J.: Deep residual learning for image recognition. In: CVPR (2016)","DOI":"10.1109\/CVPR.2016.90"},{"key":"11_CR24","doi-asserted-by":"crossref","unstructured":"Jin, D., Jin, Z., Zhou, J.T., Szolovits, P.: Is BERT really robust? Natural language attack on text classification and entailment. In: AAAI (2019)","DOI":"10.1609\/aaai.v34i05.6311"},{"key":"11_CR25","doi-asserted-by":"publisher","first-page":"31359","DOI":"10.1109\/ACCESS.2020.2973069","volume":"8","author":"X Kang","year":"2020","unstructured":"Kang, X., Song, B., Du, X., Guizani, M.: Adversarial attacks for image segmentation on multiple lightweight models. IEEE Access 8, 31359\u201331370 (2020)","journal-title":"IEEE Access"},{"key":"11_CR26","doi-asserted-by":"crossref","unstructured":"Kapoor, N., et al.: From a fourier-domain perspective on adversarial examples to a wiener filter defense for semantic segmentation. In: IJCNN (2021)","DOI":"10.1109\/IJCNN52387.2021.9534145"},{"key":"11_CR27","unstructured":"Laidlaw, C., Singla, S., Feizi, S.: Perceptual adversarial robustness: defense against unseen threat models. In: ICLR (2021)"},{"key":"11_CR28","unstructured":"Liu, C., et al.: A comprehensive study on robustness of image classification models: benchmarking and rethinking. arXiv preprint, arXiv:2302.14301 (2023)"},{"key":"11_CR29","doi-asserted-by":"crossref","unstructured":"Liu, Z., Mao, H., Wu, C.Y., Feichtenhofer, C., Darrell, T., Xie, S.: A convnet for the 2020s. CVPR (2022)","DOI":"10.1109\/CVPR52688.2022.01167"},{"key":"11_CR30","unstructured":"Madry, A., Makelov, A., Schmidt, L., Tsipras, D., Vladu, A.: Towards deep learning models resistant to adversarial attacks. In: ICLR (2018)"},{"key":"11_CR31","doi-asserted-by":"crossref","unstructured":"Metzen, J.H., Chaithanya\u00a0Kumar, M., Brox, T., Fischer, V.: Universal adversarial perturbations against semantic image segmentation. In: ICCV (2017)","DOI":"10.1109\/ICCV.2017.300"},{"issue":"10","key":"11_CR32","doi-asserted-by":"publisher","first-page":"2452","DOI":"10.1109\/TPAMI.2018.2861800","volume":"41","author":"KR Mopuri","year":"2018","unstructured":"Mopuri, K.R., Ganeshan, A., Babu, R.V.: Generalizable data-free objective for crafting universal adversarial perturbations. IEEE Trans. Pattern Anal. Mach. Intell. 41(10), 2452\u20132465 (2018)","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"11_CR33","doi-asserted-by":"crossref","unstructured":"Nesti, F., Rossolini, G., Nair, S., Biondi, A., Buttazzo, G.: Evaluating the robustness of semantic segmentation for autonomous driving against real-world adversarial patch attacks. In: Proceedings of the IEEE\/CVF Winter Conference on Applications of Computer Vision, pp. 2280\u20132289 (2022)","DOI":"10.1109\/WACV51458.2022.00288"},{"key":"11_CR34","unstructured":"Paszke, A., et al.: Pytorch: an imperative style, high-performance deep learning library. In: NeurIPS (2019)"},{"key":"11_CR35","doi-asserted-by":"crossref","unstructured":"Rony, J., Hafemann, L.G., Oliveira, L.S., Ayed, I.B., Sabourin, R., Granger, E.: Decoupling direction and norm for efficient gradient-based L2 adversarial attacks and defenses. In: CVPR (2019)","DOI":"10.1109\/CVPR.2019.00445"},{"key":"11_CR36","doi-asserted-by":"crossref","unstructured":"Rony, J., Pesquet, J.C., Ben Ayed, I.: Proximal splitting adversarial attacks for semantic segmentation. In: CVPR (2023)","DOI":"10.1109\/CVPR52729.2023.01966"},{"key":"11_CR37","unstructured":"Salman, H., Ilyas, A., Engstrom, L., Kapoor, A., Madry, A.: Do adversarially robust imagenet models transfer better? In: NeurIPS (2020)"},{"key":"11_CR38","unstructured":"Shen, G., Mao, C., Yang, J., Ray, B.: Advspade: realistic unrestricted attacks for semantic segmentation. arXiv preprint arXiv:1910.02354 (2019)"},{"key":"11_CR39","unstructured":"Singh, N.D., Croce, F., Hein, M.: Revisiting adversarial training for imagenet: architectures, training and generalization across threat models. In: NeurIPS (2023)"},{"key":"11_CR40","doi-asserted-by":"crossref","unstructured":"Strudel, R., Garcia, R., Laptev, I., Schmid, C.: Segmenter: transformer for semantic segmentation. In: CVPR (2021)","DOI":"10.1109\/ICCV48922.2021.00717"},{"key":"11_CR41","unstructured":"Szegedy, C., et al.: Intriguing properties of neural networks. In: ICLR (2014)"},{"key":"11_CR42","unstructured":"Tram\u00e8r, F., Carlini, N., Brendel, W., Madry, A.: On adaptive attacks to adversarial example defenses. In: NeurIPS (2020)"},{"key":"11_CR43","doi-asserted-by":"publisher","unstructured":"Wightman, R.: Pytorch image models (2019). https:\/\/github.com\/rwightman\/pytorch-image-models. https:\/\/doi.org\/10.5281\/zenodo.4414861","DOI":"10.5281\/zenodo.4414861"},{"key":"11_CR44","unstructured":"Wong, E., Schmidt, F.R., Kolter, J.Z.: Wasserstein adversarial examples via projected sinkhorn iterations. In: ICML (2019)"},{"key":"11_CR45","doi-asserted-by":"crossref","unstructured":"Xiao, C., Deng, R., Li, B., Yu, F., Liu, M., Song, D.: Characterizing adversarial examples based on spatial consistency information for semantic segmentation. In: ECCV (2018)","DOI":"10.1007\/978-3-030-01249-6_14"},{"key":"11_CR46","doi-asserted-by":"crossref","unstructured":"Xiao, T., Liu, Y., Zhou, B., Jiang, Y., Sun, J.: Unified perceptual parsing for scene understanding. In: ECCV (2018)","DOI":"10.1007\/978-3-030-01228-1_26"},{"key":"11_CR47","doi-asserted-by":"crossref","unstructured":"Xie, C., Wang, J., Zhang, Z., Zhou, Y., Xie, L., Yuille, A.: Adversarial examples for semantic segmentation and object detection. In: ICCV (2017)","DOI":"10.1109\/ICCV.2017.153"},{"key":"11_CR48","doi-asserted-by":"crossref","unstructured":"Xu, X., Zhao, H., Jia, J.: Dynamic divide-and-conquer adversarial training for robust semantic segmentation. In: ICCV (2021)","DOI":"10.1109\/ICCV48922.2021.00739"},{"key":"11_CR49","doi-asserted-by":"crossref","unstructured":"Zhao, H., Shi, J., Qi, X., Wang, X., Jia, J.: Pyramid scene parsing network. In: CVPR (2017)","DOI":"10.1109\/CVPR.2017.660"},{"key":"11_CR50","doi-asserted-by":"publisher","first-page":"302","DOI":"10.1007\/s11263-018-1140-0","volume":"127","author":"B Zhou","year":"2019","unstructured":"Zhou, B., et al.: Semantic understanding of scenes through the ADE20K dataset. IJCV 127, 302\u2013321 (2019)","journal-title":"IJCV"}],"container-title":["Lecture Notes in Computer Science","Computer Vision \u2013 ECCV 2024"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-72986-7_11","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,11,1]],"date-time":"2024-11-01T05:08:17Z","timestamp":1730437697000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-72986-7_11"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,11,2]]},"ISBN":["9783031729850","9783031729867"],"references-count":50,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-72986-7_11","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2024,11,2]]},"assertion":[{"value":"2 November 2024","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ECCV","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"European Conference on Computer Vision","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Milan","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Italy","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2024","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"29 September 2024","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"4 October 2024","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"18","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"eccv2024","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/eccv2024.ecva.net\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}