{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,28]],"date-time":"2025-03-28T05:21:24Z","timestamp":1743139284254,"version":"3.40.3"},"publisher-location":"Cham","reference-count":46,"publisher":"Springer Nature Switzerland","isbn-type":[{"type":"print","value":"9783031789793"},{"type":"electronic","value":"9783031789809"}],"license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025]]},"DOI":"10.1007\/978-3-031-78980-9_9","type":"book-chapter","created":{"date-parts":[[2025,1,27]],"date-time":"2025-01-27T10:26:36Z","timestamp":1737973596000},"page":"134-148","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Purifying Adversarial Examples Using an\u00a0Autoencoder"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0009-0009-3444-0059","authenticated-orcid":false,"given":"Thijs","family":"van Weezel","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-7565-4395","authenticated-orcid":false,"given":"Famke","family":"van Ree","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-1198-0317","authenticated-orcid":false,"given":"Tychon","family":"Bos","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-5273-6741","authenticated-orcid":false,"given":"Patrick","family":"Bastiaanssen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2557-4604","authenticated-orcid":false,"given":"Sibylle","family":"Hess","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,1,28]]},"reference":[{"key":"9_CR1","doi-asserted-by":"publisher","first-page":"162","DOI":"10.1016\/j.neucom.2022.09.004","volume":"514","author":"J Wang","year":"2022","unstructured":"Wang, J., Wang, C., Lin, Q., Luo, C., Wu, C., Li, J.: Adversarial attacks and defenses in deep learning for image recognition: a survey. Neurocomputing 514, 162\u2013181 (2022)","journal-title":"Neurocomputing"},{"key":"9_CR2","doi-asserted-by":"crossref","unstructured":"Han, S., Lin, C., Shen, C., Wang, Q., Guan, X.: Interpreting adversarial examples in deep learning: a review. ACM Comput. Surv. (2023)","DOI":"10.1145\/3594869"},{"key":"9_CR3","doi-asserted-by":"crossref","unstructured":"Papernot, N., McDaniel, P., Goodfellow, I., Jha, S., Celik, Z.B., Swami, A.: Practical black-box attacks against machine learning. In: Proceedings of the 2017 ACM on Asia Conference on Computer and Communications Security. ASIA CCS \u201917, (New York, NY, USA), pp.\u00a0506\u2013519. Association for Computing Machinery (2017)","DOI":"10.1145\/3052973.3053009"},{"key":"9_CR4","doi-asserted-by":"publisher","first-page":"4403","DOI":"10.1007\/s10462-021-10125-w","volume":"55","author":"A Aldahdooh","year":"2022","unstructured":"Aldahdooh, A., Hamidouche, W., Fezza, S.A., D\u00e9forges, O.: Adversarial example detection for DNN models: a review and experimental comparison. Artif. Intell. Rev. 55, 4403\u20134462 (2022)","journal-title":"Artif. Intell. Rev."},{"key":"9_CR5","unstructured":"Goodfellow, I.J., Shlens, J., Szegedy, C.: Explaining and harnessing adversarial examples (2014)"},{"key":"9_CR6","doi-asserted-by":"crossref","unstructured":"Fidel, G., Bitton, R., Shabtai, A.: When explainability meets adversarial learning: detecting adversarial examples using Shap signatures. In: 2020 International Joint Conference on Neural Networks (IJCNN), pp.\u00a01\u20138 (2020)","DOI":"10.1109\/IJCNN48605.2020.9207637"},{"key":"9_CR7","doi-asserted-by":"publisher","first-page":"126582","DOI":"10.1109\/ACCESS.2019.2939352","volume":"7","author":"U Hwang","year":"2019","unstructured":"Hwang, U., Park, J., Jang, H., Yoon, S., Cho, N.I.: Puvae: a variational autoencoder to purify adversarial examples. IEEE Access 7, 126582\u2013126593 (2019)","journal-title":"IEEE Access"},{"key":"9_CR8","unstructured":"Samangouei, P., Kabkab, M., Chellappa, R.: Defense-GAN: protecting classifiers against adversarial attacks using generative models. CoRR, abs\/1805.06605 (2018)"},{"key":"9_CR9","unstructured":"Y.\u00a0Song, T.\u00a0Kim, S.\u00a0Nowozin, S.\u00a0Ermon, and N.\u00a0Kushman, \u201cPixeldefend: Leveraging generative models to understand and defend against adversarial examples,\u201d CoRR, vol.\u00a0abs\/1710.10766, 2017"},{"issue":"7","key":"9_CR10","first-page":"2578","volume":"31","author":"J Zhang","year":"2019","unstructured":"Zhang, J., Li, C.: Adversarial examples: opportunities and challenges. IEEE Trans. Neural Netw. Learn. Syst. 31(7), 2578\u20132593 (2019)","journal-title":"IEEE Trans. Neural Netw. Learn. Syst."},{"key":"9_CR11","doi-asserted-by":"publisher","first-page":"504","DOI":"10.1126\/science.1127647","volume":"313","author":"GE Hinton","year":"2006","unstructured":"Hinton, G.E., Salakhutdinov, R.R.: Reducing the dimensionality of data with neural networks. Science 313, 504\u2013507 (2006)","journal-title":"Science"},{"key":"9_CR12","unstructured":"Zhang, Y., Li, Y., Li, Y., Guo, Z.: A review of adversarial attacks in computer vision (2023)"},{"issue":"5","key":"9_CR13","doi-asserted-by":"publisher","first-page":"909","DOI":"10.3390\/app9050909","volume":"9","author":"S Qiu","year":"2019","unstructured":"Qiu, S., Liu, Q., Zhou, S., Wu, C.: Review of artificial intelligence adversarial attack and defense technologies. Appl. Sci. 9(5), 909 (2019)","journal-title":"Appl. Sci."},{"key":"9_CR14","doi-asserted-by":"crossref","unstructured":"Dong, Y., et al.: Boosting adversarial attacks with momentum. In: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, pp.\u00a09185\u20139193 (2018)","DOI":"10.1109\/CVPR.2018.00957"},{"key":"9_CR15","doi-asserted-by":"crossref","unstructured":"Carlini, N., Wagner, D.: Towards evaluating the robustness of neural networks. In: 2017 IEEE Symposium on Security and Privacy (SP), pp.\u00a039\u201357. IEEE (2017)","DOI":"10.1109\/SP.2017.49"},{"key":"9_CR16","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"233","DOI":"10.1007\/978-3-031-06791-4_19","volume-title":"Artificial Intelligence and Security - ICAIS 2022","author":"H Ye","year":"2022","unstructured":"Ye, H., Liu, X., Yan, A., Li, L., Li, X.: Detect adversarial examples by using feature autoencoder. In: Sun, X., Zhang, X., Xia, Z., Bertino, E. (eds.) ICAIS 2022. LNCS, vol. 13340, pp. 233\u2013242. Springer, Cham (2022). https:\/\/doi.org\/10.1007\/978-3-031-06791-4_19"},{"key":"9_CR17","doi-asserted-by":"crossref","unstructured":"Tong, L., et al.: Adversarial sample detection framework based on autoencoder. In: 2020 International Conference on Big Data and Artificial Intelligence and Software Engineering (ICBASE), pp.\u00a0241\u2013245 (2020)","DOI":"10.1109\/ICBASE51474.2020.00058"},{"key":"9_CR18","doi-asserted-by":"publisher","first-page":"05","DOI":"10.1002\/int.22889","volume":"37","author":"H Ye","year":"2022","unstructured":"Ye, H., Liu, X.: Feature autoencoder for detecting adversarial examples. Int. J. Intell. Syst. 37, 05 (2022)","journal-title":"Int. J. Intell. Syst."},{"key":"9_CR19","unstructured":"Szegedy, C., et al.: Intriguing properties of neural networks (2013)"},{"key":"9_CR20","unstructured":"Raghunathan, A., Xie, S.M., Yang, F., Duchi, J.C., Liang, P.: Adversarial training can hurt generalization. arXiv preprint arXiv:1906.06032 (2019)"},{"key":"9_CR21","unstructured":"van den Oord, A., Kalchbrenner, N., Kavukcuoglu, K.: Pixel recurrent neural networks (2016)"},{"key":"9_CR22","doi-asserted-by":"crossref","unstructured":"Meng, D., Chen, H.: Magnet: a two-pronged defense against adversarial examples. CoRR, abs\/1705.09064 (2017)","DOI":"10.1145\/3133956.3134057"},{"key":"9_CR23","unstructured":"Goodfellow, I.J., et al.: Generative adversarial networks (2014)"},{"key":"9_CR24","unstructured":"Arjovsky, M., Chintala, S., Bottou, L.: Wasserstein GAN (2017)"},{"key":"9_CR25","unstructured":"Gulrajani, I., Ahmed, F., Arjovsky, M., Dumoulin, V., Courville, A.: Improved training of Wasserstein GANs (2017)"},{"key":"9_CR26","unstructured":"Kingma, D.P., Welling, M.: Auto-encoding variational Bayes (2013)"},{"key":"9_CR27","doi-asserted-by":"crossref","unstructured":"Bond-Taylor, S., Leach, A., Long, Y., Willcocks, C.G.: Deep generative modelling: a comparative review of VAEs, GANs, normalizing flows, energy-based and autoregressive models (2021)","DOI":"10.1109\/TPAMI.2021.3116668"},{"key":"9_CR28","unstructured":"Tabacof, P., Tavares, J., Valle, E.: Adversarial images for variational autoencoders (2016)"},{"key":"9_CR29","unstructured":"Zhao, H., Gallo, O., Frosio, I., Kautz, J.: Loss functions for neural networks for image processing (2015)"},{"key":"9_CR30","doi-asserted-by":"crossref","unstructured":"Wang, Z., Bovik, A., Sheikh, H., Simoncelli, E.: Image quality assessment: from error visibility to structural similarity. IEEE Trans. Image Process. 13, 600\u2013612 (2004)","DOI":"10.1109\/TIP.2003.819861"},{"issue":"6","key":"9_CR31","doi-asserted-by":"publisher","first-page":"141","DOI":"10.1109\/MSP.2012.2211477","volume":"29","author":"L Deng","year":"2012","unstructured":"Deng, L.: The MNIST database of handwritten digit images for machine learning research. IEEE Sig. Process. Mag. 29(6), 141\u2013142 (2012)","journal-title":"IEEE Sig. Process. Mag."},{"key":"9_CR32","unstructured":"Xiao, H., Rasul, K., Vollgraf, R.: Fashion-MNIST: a novel image dataset for benchmarking machine learning algorithms. arXiv e-prints, arXiv:1708.07747 (2017)"},{"key":"9_CR33","unstructured":"Krizhevsky, A., Hinton, G., et\u00a0al.: Learning multiple layers of features from tiny images (2009)"},{"key":"9_CR34","doi-asserted-by":"crossref","unstructured":"Isola, P., Zhu, J.-Y., Zhou, T., Efros, A.A.: Image-to-image translation with conditional adversarial networks (2016)","DOI":"10.1109\/CVPR.2017.632"},{"key":"9_CR35","doi-asserted-by":"crossref","unstructured":"Tian, S., Yang, G., Cai, Y.: Detecting adversarial examples through image transformation. In: Proceedings of the AAAI Conference on Artificial Intelligence, vol.\u00a032 (2018)","DOI":"10.1609\/aaai.v32i1.11828"},{"key":"9_CR36","doi-asserted-by":"crossref","unstructured":"He, K., Zhang, X., Ren, S., Sun, J.: Deep residual learning for image recognition (2015)","DOI":"10.1109\/CVPR.2016.90"},{"issue":"56","key":"9_CR37","first-page":"1929","volume":"15","author":"N Srivastava","year":"2014","unstructured":"Srivastava, N., Hinton, G., Krizhevsky, A., Sutskever, I., Salakhutdinov, R.: Dropout: a simple way to prevent neural networks from overfitting. J. Mach. Learn. Res. 15(56), 1929\u20131958 (2014)","journal-title":"J. Mach. Learn. Res."},{"key":"9_CR38","doi-asserted-by":"crossref","unstructured":"Park, S., Kwak, N.: Analysis on the dropout effect in convolutional neural networks, pp.\u00a0189\u2013204 (2017)","DOI":"10.1007\/978-3-319-54184-6_12"},{"key":"9_CR39","unstructured":"N.\u00a0Corporation: Convolutional layers user\u2019s guide"},{"key":"9_CR40","unstructured":"Ulyanov, D., Vedaldi, A., Lempitsky, V.: Instance normalization: the missing ingredient for fast stylization (2016)"},{"key":"9_CR41","unstructured":"Maas, A.L.: Rectifier nonlinearities improve neural network acoustic models (2013)"},{"key":"9_CR42","doi-asserted-by":"crossref","unstructured":"Zeiler, M.D., Krishnan, D., Taylor, G.W., Fergus, R.: Deconvolutional networks, pp.\u00a02528\u20132535 (2010)","DOI":"10.1109\/CVPR.2010.5539957"},{"key":"9_CR43","unstructured":"T.\u00a0Developers: Tensorflow (2023)"},{"key":"9_CR44","unstructured":"Papernot, N., et al.: Technical report on the cleverhans v2.1.0 adversarial examples library. arXiv preprint arXiv:1610.00768 (2018)"},{"key":"9_CR45","doi-asserted-by":"crossref","unstructured":"Deng, J., Dong, W., Socher, R., Li, L.-J., Li, K., Fei-Fei, L.: Imagenet: a large-scale hierarchical image database. In: 2009 IEEE Conference on Computer Vision and Pattern Recognition, pp.\u00a0248\u2013255. IEEE (2009)","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"9_CR46","doi-asserted-by":"crossref","unstructured":"Kos, J., Fischer, I., Song, D.: Adversarial examples for generative models (2018)","DOI":"10.1109\/SPW.2018.00014"}],"container-title":["Lecture Notes in Computer Science","Discovery Science"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-78980-9_9","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,1,27]],"date-time":"2025-01-27T10:26:57Z","timestamp":1737973617000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-78980-9_9"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"ISBN":["9783031789793","9783031789809"],"references-count":46,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-78980-9_9","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2025]]},"assertion":[{"value":"28 January 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"DS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Discovery Science","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Pisa","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Italy","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2024","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"14 October 2024","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"16 October 2024","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"27","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"dis2024","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/ds2024.isti.cnr.it\/index.html","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}