{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,14]],"date-time":"2026-05-14T10:35:48Z","timestamp":1778754948282,"version":"3.51.4"},"reference-count":86,"publisher":"Springer Science and Business Media LLC","issue":"S1","license":[{"start":{"date-parts":[[2023,6,23]],"date-time":"2023-06-23T00:00:00Z","timestamp":1687478400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2023,6,23]],"date-time":"2023-06-23T00:00:00Z","timestamp":1687478400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"name":"eSSENCE Programme under the Swedish Government\u2019s Strategic Research Initiative"},{"DOI":"10.13039\/501100004063","name":"Knut och Alice Wallenbergs Stiftelse","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100004063","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Umea University"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Artif Intell Rev"],"published-print":{"date-parts":[[2023,10]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>Considering the growing prominence of production-level AI and the threat of adversarial attacks that can poison a machine learning model against a certain label, evade classification, or reveal sensitive data about the model and training data to an attacker, adversaries pose fundamental problems to machine learning systems. Furthermore, much research has focused on the inverse relationship between robustness and accuracy, raising problems for real-time and safety-critical systems particularly since they are governed by legal constraints in which software changes must be explainable and every change must be thoroughly tested. While many defenses have been proposed, they are often computationally expensive and tend to reduce model accuracy. We have therefore conducted a large survey of attacks and defenses and present a simple and practical framework for analyzing any machine-learning system from a safety-critical perspective using adversarial noise to find the upper bound of the failure rate. Using this method, we conclude that all tested configurations of the ResNet architecture fail to meet any reasonable definition of \u2018safety-critical\u2019 when tested on even small-scale benchmark data. We examine state of the art defenses and attacks against computer vision systems with a focus on safety-critical applications in autonomous driving, industrial control, and healthcare. By testing a combination of attacks and defenses, their efficacy, and their run-time requirements, we provide substantial empirical evidence that modern neural networks consistently fail to meet established safety-critical standards by a wide margin.<\/jats:p>","DOI":"10.1007\/s10462-023-10521-4","type":"journal-article","created":{"date-parts":[[2023,6,23]],"date-time":"2023-06-23T22:12:31Z","timestamp":1687558351000},"page":"217-251","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":13,"title":["Safety-critical computer vision: an empirical survey of adversarial evasion attacks and defenses on computer vision systems"],"prefix":"10.1007","volume":"56","author":[{"given":"Charles","family":"Meyers","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tommy","family":"L\u00f6fstedt","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Erik","family":"Elmroth","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2023,6,23]]},"reference":[{"key":"10521_CR1","doi-asserted-by":"crossref","unstructured":"Al-Qizwini M, Barjasteh I, Al-Qassab H, Radha H (2017) Deep learning algorithm for autonomous driving using GoogLeNet. In: 2017 IEEE Intelligent Vehicles Symposium (IV), 89\u201396. IEEE","DOI":"10.1109\/IVS.2017.7995703"},{"key":"10521_CR2","doi-asserted-by":"publisher","first-page":"42236","DOI":"10.1109\/ACCESS.2021.3062909","volume":"9","author":"A Aljuhani","year":"2021","unstructured":"Aljuhani A (2021) Machine learning approaches for combating distributed denial of service attacks in modern networking environments. IEEE Access 9:42236\u201342264","journal-title":"IEEE Access"},{"issue":"4","key":"10521_CR3","doi-asserted-by":"publisher","first-page":"929","DOI":"10.1145\/76359.76371","volume":"36","author":"B Anselm","year":"1989","unstructured":"Anselm B, Andrzej E, David H, Warmuth Manfred K (1989) Learnability and the vapnik-chervonenkis dimension. J ACM 36(4):929\u2013965","journal-title":"J ACM"},{"key":"10521_CR4","unstructured":"Athalye A, Carlini N, Wagner D (2018) Obfuscated gradients give a false sense of security: circumventing defenses to adversarial examples. arXiv:1802.00420 [cs], July"},{"key":"10521_CR5","doi-asserted-by":"publisher","first-page":"278","DOI":"10.1016\/j.ssci.2017.12.023","volume":"108","author":"VA Banks","year":"2018","unstructured":"Banks VA, Plant KL, Stanton NA (2018) Driver error or designer error: using the perceptual cycle model to explore the circumstances surrounding the fatal tesla crash on 7 May 2016. Safety Sci 108:278\u2013285","journal-title":"Safety Sci"},{"key":"10521_CR6","first-page":"132","volume-title":"Multiple classifier systems, lecture notes in computer science","author":"B Battista","year":"2009","unstructured":"Battista B, Giorgio F, Fabio R (2009) Multiple classifier systems for adversarial classification tasks. In: Benediktsson JA, Kittler J, Roli F (eds) Multiple classifier systems, lecture notes in computer science. Springer, Berlin, pp 132\u2013141"},{"issue":"1","key":"10521_CR7","doi-asserted-by":"publisher","first-page":"762","DOI":"10.1137\/16M1078276","volume":"5","author":"J Bect","year":"2017","unstructured":"Bect J, Li L, Vazquez E (2017) Bayesian subset simulation. SIAM\/ASA J Uncertain Quantif 5(1):762\u2013786","journal-title":"SIAM\/ASA J Uncertain Quantif"},{"key":"10521_CR8","doi-asserted-by":"crossref","unstructured":"Bernal G, Colombo S, Al Ai Baky M, Casalegno F 2017 Safety++ designing IoT and wearable systems for industrial safety through a user centered design approach. In: Proceedings of the 10th international conference on pervasive technologies related to assistive environments, pp 163\u2013170","DOI":"10.1145\/3056540.3056557"},{"key":"10521_CR9","doi-asserted-by":"crossref","unstructured":"Biggio B, Corona I, Maiorca D, Nelson B, \u0160rndi\u0107 N, Laskov P, Giacinto G, Roli F, (2013) Evasion Attacks against machine learning at test time. arXiv:1708.06131 [cs], 7908: 387\u2013402","DOI":"10.1007\/978-3-642-40994-3_25"},{"key":"10521_CR10","doi-asserted-by":"crossref","unstructured":"Biggio B, Corona I, Maiorca D, Nelson B, Srndic N, Laskov P, Giacinto G, Roli F (2013) Evasion attacks against machine learning at test time. arXiv:1708.06131 [cs], 7908: 387\u2013402","DOI":"10.1007\/978-3-642-40994-3_25"},{"key":"10521_CR11","unstructured":"Bloom C, Tan J, Ramjohn J, Bauer L (2017) Self-driving cars and data collection: privacy perceptions of networked autonomous vehicles. In: Symposium on usable privacy and security (SOUPS)"},{"key":"10521_CR12","unstructured":"Brown TB, Man\u00e9 D, Roy A, Abadi M, Gilmer (2017) J adversarial patch. arXiv:1712.09665"},{"key":"10521_CR13","unstructured":"Buolamwini J, Gebru T (2018) Gender shades: intersectional accuracy disparities in commercial gender classification. In: Conference on fairness, accountability and transparency, pp 77\u201391, PMLR"},{"key":"10521_CR14","doi-asserted-by":"crossref","unstructured":"Carlini N, Wagner D (2017) Towards evaluating the robustness of neural networks. arXiv:1608.04644 [cs], March","DOI":"10.1109\/SP.2017.49"},{"key":"10521_CR15","doi-asserted-by":"crossref","unstructured":"Chae H, Kang CM, Kim BD, Kim J, Chung CC, Choi JW (2017) Autonomous braking system via deep reinforcement learning. In: IEEE 20th international conference on intelligent transportation systems (ITSC)","DOI":"10.1109\/ITSC.2017.8317839"},{"key":"10521_CR16","unstructured":"Chakraborty A, Alam M, Dey V, Chattopadhyay A, Mukhopadhyay D (2018) Adversarial attacks and defences: a survey. arXiv:1810.00069 [cs, stat]"},{"issue":"1","key":"10521_CR17","first-page":"89","volume":"20","author":"A Chambolle","year":"2004","unstructured":"Chambolle A (2004) An algorithm for total variation minimization and applications. J Math Imag Vision 20(1):89\u201397","journal-title":"J Math Imag Vision"},{"key":"10521_CR18","doi-asserted-by":"crossref","unstructured":"Chen J, Jordan MI, Wainwright MJ (2020) HopSkipJumpAttack: a query-efficient decision-based attack. In IEEE symposium on security and privacy (sp), IEEE, pp 1277\u20131294","DOI":"10.1109\/SP40000.2020.00045"},{"issue":"141","key":"10521_CR19","doi-asserted-by":"publisher","first-page":"20170387","DOI":"10.1098\/rsif.2017.0387","volume":"15","author":"T Ching","year":"2017","unstructured":"Ching T, Himmelstein Daniel S, Beaulieu-Jones Brett K, Kalinin Alexandr A, Do Brian T, Way Gregory P, Ferrero E, Agapow PM, Zietz M, Hoffman Michael M, Xie W, Rosen Gail L, Lengerich Benjamin J, Israeli J, Lanchantin J, Woloszynek S, Carpenter Anne E, Shrikumar Avanti X, Evan JC, Lavender Christopher A, Turaga Srinivas C, Alexandari Amr M, Lu Laura K, Segler Marwin HSB, Swamidass SJ, Huang A, Anthony G, Casey SG (2017) Opportunities and obstacles for deep learning in biology and medicine. J R Soc Interface 15(141):20170387","journal-title":"J Royal Soc Interface"},{"key":"10521_CR20","doi-asserted-by":"crossref","unstructured":"Cintas C, Speakman S, Akinwande V, Ogallo W, Weldemariam K, Sridharan S, McFowland E (2020) Detecting adversarial attacks via subset scanning of autoencoder activations and reconstruction error. In: Proceedings of the twenty-ninth international joint conference on artificial intelligence, Yokohama, pp 876\u2013882","DOI":"10.24963\/ijcai.2020\/122"},{"key":"10521_CR21","doi-asserted-by":"crossref","unstructured":"Colbrook MJ, Antun V , Hansen AC 2021 Can stable and accurate neural networks be computed. On the barriers of deep learning and Smale\u2019s 18th problem. arXiv, 2101","DOI":"10.1073\/pnas.2107151119"},{"issue":"2","key":"10521_CR22","doi-asserted-by":"publisher","first-page":"145","DOI":"10.1177\/0049124182011002003","volume":"11","author":"A Corsaro William","year":"1982","unstructured":"Corsaro William A (1982) Something old and something new: the importance of prior ethnography in the collection and analysis of audiovisual data. Sociol Methods Res 11(2):145\u2013166","journal-title":"Sociol Methods Res"},{"key":"10521_CR23","unstructured":"Cosentino J, Zaiter F, Pei D, Zhu J (2019) The search for sparse, robust neural networks. arXiv:1912.02386"},{"key":"10521_CR24","unstructured":"Croce F, Hein M (2020) Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks. arXiv:2003.01690[cs, stat], August"},{"key":"10521_CR25","unstructured":"Daya AA, Salahuddin MA, Limam N, Boutaba R (2019) A graph-based machine learning approach for bot detection. arXiv:1902.08538 [cs], February"},{"key":"10521_CR26","volume-title":"A resource guide on racial profiling data collection system: promising practices and lessons learned","author":"R Deborah","year":"2000","unstructured":"Deborah R, Jack M, Farrell A (2000) A resource guide on racial profiling data collection system: promising practices and lessons learned. US Department of Justice, Washington D C"},{"key":"10521_CR27","unstructured":"Desislavov R, Mart\u00ednez-Plumed F, Hern\u00e1ndez-Orallo J (2021) Compute and energy consumption trends in deep learning inference. arXiv:2109.05472"},{"key":"10521_CR28","unstructured":"Dohmatob E (2019) Generalized no free lunch theorem for adversarial robustness. In: Proceedings of the 36th international conference on machine learning, 97 of PMLR"},{"issue":"2","key":"10521_CR29","doi-asserted-by":"crossref","first-page":"205846011983022","DOI":"10.1177\/2058460119830222","volume":"8","author":"P Emre","year":"2019","unstructured":"Emre P (2019) Artificial intelligence in radiology: friend or foe? where are we now and where are we heading? Acta Radiol Open 8(2):2058460119830222","journal-title":"Acta Radiol Open"},{"key":"10521_CR30","unstructured":"Finlayson SG, Chung HW, Kohane IS, Beam AL (2018) Adversarial attacks against medical deep learning systems. arXiv:1804.05296"},{"key":"10521_CR31","doi-asserted-by":"crossref","unstructured":"Fredrikson M, Jha S, Ristenpart T (2015) Model Inversion attacks that exploit confidence information and basic countermeasures. In: Proceedings of the 22nd ACM SIGSAC conference on computer and communications security - CCS \u201915, ACM Press, Colorado, pp 1322\u20131333","DOI":"10.1145\/2810103.2813677"},{"issue":"6","key":"10521_CR32","doi-asserted-by":"publisher","first-page":"472","DOI":"10.1109\/41.170966","volume":"39","author":"T Fukuda","year":"1992","unstructured":"Fukuda T, Shibata T (1992) Theory and applications of neural networks for industrial control systems. IEEE Trans Ind Electron 39(6):472\u2013489","journal-title":"IEEE Trans Ind Electron"},{"issue":"6","key":"10521_CR33","doi-asserted-by":"publisher","first-page":"e406","DOI":"10.1016\/S2589-7500(22)00063-2","volume":"4","author":"JW Gichoya","year":"2022","unstructured":"Gichoya JW, Banerjee I, Bhimireddy AR, Burns J, Celi LA, Chen L-C, Correa Ramon, Dullerud N, Ghassemi M, Huang S-C et al (2022) Ai recognition of patient race in medical imaging: a modelling study. The Lancet Digital Health 4(6):e406\u2013e414","journal-title":"The Lancet Digital Health"},{"key":"10521_CR34","unstructured":"Goodfellow IJ, Shlens J, Szegedy C (2014) Explaining and harnessing adversarial examples. arXiv:1412.6572"},{"issue":"3","key":"10521_CR35","doi-asserted-by":"publisher","first-page":"362","DOI":"10.1002\/rob.21918","volume":"37","author":"S Grigorescu","year":"2020","unstructured":"Grigorescu S, Trasnea B, Cocias T, Macesanu G (2020) A survey of deep learning techniques for autonomous driving. J Field Robot 37(3):362\u2013386","journal-title":"J Field Robot"},{"issue":"11","key":"10521_CR36","doi-asserted-by":"publisher","first-page":"2403","DOI":"10.1109\/TMI.2018.2829802","volume":"37","author":"F Hadj-Selem","year":"2018","unstructured":"Hadj-Selem F, L\u00f6fstedt T, Dohmatob E, Frouin V, Dubois M, Guillemot V, Duchesnay E (2018) Continuation of nesterov\u2019s smoothing for regression with structured sparsity in high-dimensional neuroimaging. IEEE Trans Med Imag 37(11):2403\u20132413","journal-title":"IEEE Trans Med Imag"},{"key":"10521_CR37","doi-asserted-by":"crossref","unstructured":"He K, Zhang X, Ren S, Sun J (2015) Deep residual learning for image recognition. CoRR, arXiv:abs\/1512.03385","DOI":"10.1109\/CVPR.2016.90"},{"key":"10521_CR38","unstructured":"ICOH. Global estimates of occupational accidents and work-related illnesses 2017. International commission on occupational health (2017)"},{"key":"10521_CR39","doi-asserted-by":"crossref","unstructured":"International Electrotechnical Commission. IEC 62304 medical device software\u2013software life cycle processes. International electrotechnical commission, 2nd edition, 2006","DOI":"10.1049\/ic:20060141"},{"key":"10521_CR40","unstructured":"International Electrotechnical Commission. IEC 61508 safety and functional safety. International electrotechnical commission, 2nd edition, 2010"},{"key":"10521_CR41","unstructured":"International Standards Organization. (2018) ISO 26262-1:2011, road vehicles\u2014functional safety. https:\/\/www.iso.org\/standard\/43464.html (visited 2022-04-20)"},{"key":"10521_CR42","doi-asserted-by":"crossref","unstructured":"Jakubovitz D, Giryes R (2018) Improving dnn robustness to adversarial attacks using jacobian regularization. In: Proceedings of the European conference on computer vision (ECCV), 514\u2013529","DOI":"10.1007\/978-3-030-01258-8_32"},{"key":"10521_CR43","first-page":"258","volume-title":"Complexity Theory and P vs NP","author":"H Jeffrey","year":"2010","unstructured":"Jeffrey H, Jill P, Silverman Joseph H (2010) Complexity theory and P vs NP. Springer, Berlin, pp 258\u2013262"},{"key":"10521_CR44","doi-asserted-by":"crossref","unstructured":"Jian T, Wang Z, Wang Y, Dy J, Ioannidis S (2022) Pruning adversarially robust neural networks without adversarial examples. arXiv:2210.04311","DOI":"10.1109\/ICDM54844.2022.00120"},{"key":"10521_CR45","unstructured":"Koch B, Denton E, Hanna A, Foster JG (2021) Reduced, reused and recycled: the life of a dataset in machine learning research. arXiv preprint arXiv:2112.01716"},{"key":"10521_CR46","unstructured":"Kotyan S, Vargas DV (2019) Adversarial robustness assessment: why both $$l_0$$ and $$l_\\infty$$ attacks are necessary. arXiv e-prints, pages arXiv\u20131906,"},{"key":"10521_CR47","doi-asserted-by":"crossref","unstructured":"Lam H (2004) New design-to-test software strategies accelerate time-to-market. In IEEE\/CPMT\/SEMI 29th international electronics manufacturing technology symposium (IEEE Cat. No. 04CH37585), IEEE, 140\u2013143","DOI":"10.1109\/IEMT.2004.1321646"},{"key":"10521_CR48","volume-title":"Developing safety-critical software: a practical guide for aviation software and DO-178C compliance","author":"R Leanna","year":"2017","unstructured":"Leanna R (2017) Developing safety-critical software: a practical guide for aviation software and DO-178C compliance. CRC Press, Boca Raton"},{"key":"10521_CR49","doi-asserted-by":"crossref","unstructured":"Lecuyer M, Atlidakis V, Geambasu R, Hsu D, Jana S (2019) Certified robustness to adversarial examples with differential privacy. In: 2019 IEEE symposium on security and privacy (SP), 656\u2013672","DOI":"10.1109\/SP.2019.00044"},{"key":"10521_CR50","doi-asserted-by":"crossref","unstructured":"Lee T, Edwards B, Molloy IM, Su D (2018) Defending against model stealing attacks using deceptive perturbations. CoRR, arXiv: abs\/1806.00054","DOI":"10.1109\/SPW.2019.00020"},{"key":"10521_CR51","first-page":"1336","volume":"110","author":"E Leonard","year":"2001","unstructured":"Leonard E, Gerrish Peter H (2001) Gender and age influence on fatality risk from the same physical impact determined using two-car crashes. SAE Trans 110:1336\u20131341","journal-title":"SAE Trans"},{"key":"10521_CR52","first-page":"1","volume":"19","author":"Chen Li","year":"2021","unstructured":"Li Chen, Jun Xiao, Zou Pu, Haifeng Li (2021) Lie to me: a soft threshold defense method for adversarial examples of remote sensing images. IEEE Geosci Remote Sens Lett 19:1\u20135","journal-title":"IEEE Geosci Remote Sens Lett"},{"key":"10521_CR53","unstructured":"Li B, Vorobeychik Y, Chen X (2016) A general retraining framework for scalable adversarial classification. arXiv:1604.02606[cs, stat], November"},{"key":"10521_CR54","doi-asserted-by":"crossref","unstructured":"Lu K, Mardziel P, Wu F, Amancharla P, Datta A (2020) Gender bias in neural natural language processing. logic, language, and security: essays dedicated to andre scedrov on the occasion of his 65th birthday, pp 189\u2013202","DOI":"10.1007\/978-3-030-62077-6_14"},{"key":"10521_CR55","unstructured":"Madry A, Makelov A, Ludwig S, Dimitris T, Adrian V (2017) Towards deep learning models resistant to adversarial attacks. arXiv:1706.06083"},{"key":"10521_CR56","doi-asserted-by":"publisher","DOI":"10.1136\/bmj.i2139","author":"A Makary Martin","year":"2016","unstructured":"Makary Martin A, Michael D (2016) Medical error-the third leading cause of death in the US. BMJ. https:\/\/doi.org\/10.1136\/bmj.i2139","journal-title":"BMJ"},{"issue":"3","key":"10521_CR57","doi-asserted-by":"publisher","first-page":"402","DOI":"10.1109\/JPROC.2020.2970615","volume":"108","author":"DJ Miller","year":"2020","unstructured":"Miller DJ, Xiang Z, Kesidis G (2020) Adversarial learning targeting deep neural network classification: a comprehensive review of defenses against attacks. Proceed IEEE 108(3):402\u2013433","journal-title":"Proceed IEEE"},{"issue":"2","key":"10521_CR58","doi-asserted-by":"publisher","first-page":"224","DOI":"10.1109\/TII.2011.2123908","volume":"7","author":"E Monmasson","year":"2011","unstructured":"Monmasson E, Idkhajine L, Cirstea MN, Bahri I, Tisan Alin, Naouar MohamedWissem (2011) Fpgas in industrial control applications. IEEE Trans Ind Inform 7(2):224\u2013243","journal-title":"IEEE Trans Ind Inform"},{"key":"10521_CR59","doi-asserted-by":"crossref","unstructured":"Moosavi-Dezfooli S-M, Fawzi A, Frossard P (2016) Deepfool: a simple and accurate method to fool deep neural networks. In: Proceedings of the IEEE conference on computer vision and pattern recognition, pp 2574\u20132582","DOI":"10.1109\/CVPR.2016.282"},{"key":"10521_CR60","unstructured":"National Highway Transportation Safety Administration\u2019s (NHTSA) National center for statistics and analysis. Critical reasons for crashes investigated in the national motor vehicle crash causation survey. https:\/\/crashstats.nhtsa.dot.gov\/Api\/Public\/ViewPublication\/812115 (visited 2022-04-20), 2015"},{"key":"10521_CR61","volume-title":"Behavior of machine learning algorithms in adversarial environments","author":"BA Nelson","year":"2010","unstructured":"Nelson BA (2010) Behavior of machine learning algorithms in adversarial environments. University of California, Berkeley"},{"key":"10521_CR62","doi-asserted-by":"crossref","unstructured":"Park J, Nyang D, MA (2018) Timing is almost everything: realistic evaluation of the very short intermittent ddos attacks. In: 2018 16th annual conference on privacy, security and trust (PST), pp 1\u201310","DOI":"10.1109\/PST.2018.8514210"},{"key":"10521_CR63","unstructured":"Paudice A, Mu\u00f1oz-Gonz\u00e1lez L, Gyorgy A, Lupu EC (2018) Detection of adversarial training examples in poisoning attacks through anomaly detection. arXiv:1802.03041[cs, stat], February"},{"key":"10521_CR64","doi-asserted-by":"crossref","unstructured":"Pearson RK (2005) Mining imperfect data: dealing with contamination and incomplete records. SIAM","DOI":"10.1137\/1.9780898717884"},{"issue":"4","key":"10521_CR65","doi-asserted-by":"publisher","first-page":"1328","DOI":"10.1109\/TKDE.2019.2946162","volume":"33","author":"Y Roh","year":"2019","unstructured":"Roh Y, Heo G, Whang SE (2019) A survey on data collection for machine learning: a big data-ai integration perspective. IEEE Trans Knowl Data Eng 33(4):1328\u20131347","journal-title":"IEEE Trans Knowl Data Eng"},{"key":"10521_CR66","doi-asserted-by":"crossref","unstructured":"Ross A, Doshi-Velez F (2018) Improving the adversarial robustness and interpretability of deep neural networks by regularizing their input gradients. In: Proceedings of the AAAI conference on artificial intelligence, p 32","DOI":"10.1609\/aaai.v32i1.11504"},{"issue":"1\u20134","key":"10521_CR67","doi-asserted-by":"publisher","first-page":"259","DOI":"10.1016\/0167-2789(92)90242-F","volume":"60","author":"L Rudin","year":"1992","unstructured":"Rudin L, Osher S, Fatemi E (1992) Nonlinear total variation based noise removal algorithms. Physica D: Nonlinear Phenomena 60(1\u20134):259\u2013268","journal-title":"Physica D: Nonlinear Phenomena"},{"issue":"1","key":"10521_CR68","doi-asserted-by":"publisher","first-page":"e1","DOI":"10.1002\/mp.13264","volume":"46","author":"B Sahiner","year":"2019","unstructured":"Sahiner B, Pezeshk A, Hadjiiski LM, Wang X, Drukker K, Cha KH, Summers RM, Giger M (2019) Deep learning in medical imaging and radiation therapy. Med Phys 46(1):e1\u2013e36","journal-title":"Med phys"},{"key":"10521_CR69","unstructured":"Sehwag V, Wang S, Mittal P, Jana S. (2019) Towards compact and robust deep neural networks. arXiv:1906.06110"},{"key":"10521_CR70","doi-asserted-by":"crossref","unstructured":"Shokri R, Stronati M, Song C, Shmatikov V (2017) Membership inference attacks against machine learning models. In: 2017 IEEE symposium on security and privacy (SP), IEEE, 3\u201318","DOI":"10.1109\/SP.2017.41"},{"key":"10521_CR71","unstructured":"Sinn M, M W, B B, MI N, M T (2019). Evolutionary search for adversarially robust neural networks, In safe machine learning workshop at ICLR"},{"key":"10521_CR72","doi-asserted-by":"publisher","first-page":"133","DOI":"10.1016\/j.ssci.2015.03.017","volume":"77","author":"PV SrinivasAcharyulu","year":"2015","unstructured":"SrinivasAcharyulu PV, Seetharamaiah P (2015) A framework for safety automation of safety-critical systems operations. Saf Sci 77:133\u2013142","journal-title":"Saf Sci"},{"key":"10521_CR73","unstructured":"The Organisation for Economic Co-operation and Development. OECD statistics. https:\/\/stats.oecd.org\/ (visited 2022-04-20), (2020)"},{"key":"10521_CR74","unstructured":"Tram\u00e8r F, Papernot N, Goodfellow I, Boneh D, McDaniel P (2017). The space of transferable adversarial examples. arXiv:1704.03453"},{"key":"10521_CR75","unstructured":"Tram\u00e8r F, Zhang F, Juels A, Reiter MK, Ristenpart T (2016) Stealing machine learning models via prediction APIs. In: 25th USENIX security symposium (USENIX Security 16), 601\u2013618"},{"key":"10521_CR76","unstructured":"Tsipras D, Santurkar , Engstrom L, Turner A, Madry A (2019). Robustness may be at odds with accuracy. arXiv:1805.12152[cs, stat], September"},{"key":"10521_CR77","doi-asserted-by":"crossref","unstructured":"Tuan LA, Zheng MC, Tho QT (2010) Modeling and verification of safety critical systems: a case study on pacemaker. In: 2010 fourth international conference on secure software integration and reliability improvement, IEEE, pp 23\u201332","DOI":"10.1109\/SSIRI.2010.28"},{"issue":"5","key":"10521_CR78","doi-asserted-by":"publisher","first-page":"851","DOI":"10.1162\/neco.1994.6.5.851","volume":"6","author":"V Vapnik","year":"1994","unstructured":"Vapnik V, Levin E, Le Cun Y (1994) Measuring the vc-dimension of a learning machine. Neural Comput 6(5):851\u2013876","journal-title":"Neural Comput"},{"key":"10521_CR86","doi-asserted-by":"crossref","unstructured":"von Ahn L, Blum M, Hopper NJ, Langford J (2003) Captcha: using hard ai problems for security. In: International conference on the theory and applications of cryptographic techniques, Springer, pp 294\u2013311","DOI":"10.1007\/3-540-39200-9_18"},{"key":"10521_CR79","doi-asserted-by":"publisher","first-page":"12","DOI":"10.1016\/j.jpdc.2019.03.003","volume":"130","author":"X Wang","year":"2019","unstructured":"Wang X, Li J, Kuang X, Tan Y, Li Jin (2019) The security of machine learning in an adversarial setting: a survey. J Parallel Distrib Comput 130:12\u201323","journal-title":"J Parallel Distrib Comput"},{"key":"10521_CR80","volume-title":"Perturbations, Optimization, and Statistics","author":"D Warde-Farley","year":"2017","unstructured":"Warde-Farley D, Goodfellow I (2017) Adversarial perturbations of deep neural networks. In: Tarlow D, Hazan T, Papandreou G (eds) Perturbations, Optimization, and Statistics. The MIT Press, Cambridge"},{"key":"10521_CR81","doi-asserted-by":"crossref","unstructured":"Xiao Z, Gao X, Fu C, Dong Y, Gao W, Zhang X, Zhou J, Zhu J (2021) Improving transferability of adversarial patches on face recognition with generative models. In: Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition, pp 11845\u201311854","DOI":"10.1109\/CVPR46437.2021.01167"},{"key":"10521_CR82","doi-asserted-by":"crossref","unstructured":"Xu W, Evans D, Qi Y (2017) Feature squeezing: detecting adversarial examples in deep neural networks. arXiv:1704.01155","DOI":"10.14722\/ndss.2018.23198"},{"key":"10521_CR83","doi-asserted-by":"crossref","unstructured":"Zantedeschi V, Nicolae M-I, Rawat A (2017) Efficient defenses against adversarial attacks. In: Proceedings of the 10th ACM workshop on artificial intelligence and security, AISec \u201917, association for computing machinery, New York, pp 39\u201349","DOI":"10.1145\/3128572.3140449"},{"key":"10521_CR84","unstructured":"Zhang Y, Liang P (2019) Defending against whitebox adversarial attacks via randomized discretization. In: The 22nd international conference on artificial intelligence and statistics, PMLR, 684\u2013693"},{"issue":"2","key":"10521_CR85","doi-asserted-by":"publisher","first-page":"143","DOI":"10.1109\/17.509980","volume":"43","author":"BJ Zirger","year":"1996","unstructured":"Zirger BJ, Hartley JL (1996) The effect of acceleration techniques on product development time. IEEE Trans Eng Manag 43(2):143\u2013152","journal-title":"IEEE Trans Eng Manag"}],"container-title":["Artificial Intelligence Review"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10462-023-10521-4.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10462-023-10521-4\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10462-023-10521-4.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,10,22]],"date-time":"2024-10-22T21:44:23Z","timestamp":1729633463000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10462-023-10521-4"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,6,23]]},"references-count":86,"journal-issue":{"issue":"S1","published-print":{"date-parts":[[2023,10]]}},"alternative-id":["10521"],"URL":"https:\/\/doi.org\/10.1007\/s10462-023-10521-4","relation":{},"ISSN":["0269-2821","1573-7462"],"issn-type":[{"value":"0269-2821","type":"print"},{"value":"1573-7462","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,6,23]]},"assertion":[{"value":"28 May 2023","order":1,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"23 June 2023","order":2,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}