{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,4]],"date-time":"2026-06-04T16:15:58Z","timestamp":1780589758670,"version":"3.54.1"},"reference-count":38,"publisher":"Springer Science and Business Media LLC","issue":"4","license":[{"start":{"date-parts":[[2019,10,3]],"date-time":"2019-10-03T00:00:00Z","timestamp":1570060800000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2019,10,3]],"date-time":"2019-10-03T00:00:00Z","timestamp":1570060800000},"content-version":"vor","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Int J Comput Vis"],"published-print":{"date-parts":[[2020,4]]},"DOI":"10.1007\/s11263-019-01213-0","type":"journal-article","created":{"date-parts":[[2019,10,3]],"date-time":"2019-10-03T17:03:36Z","timestamp":1570122216000},"page":"1028-1046","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":17,"title":["Scaling up the Randomized Gradient-Free Adversarial Attack Reveals Overestimation of Robustness Using Established Attacks"],"prefix":"10.1007","volume":"128","author":[{"given":"Francesco","family":"Croce","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jonas","family":"Rauber","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Matthias","family":"Hein","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2019,10,3]]},"reference":[{"key":"1213_CR1","unstructured":"Arora, R., Basuy, A., Mianjyz, P., & Mukherjee, A. (2018). Understanding deep neural networks with rectified linear unit. In ICLR."},{"key":"1213_CR2","unstructured":"Athalye, A., Carlini, N., & Wagner, D. A. (2018). Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples. In ICML."},{"key":"1213_CR3","doi-asserted-by":"publisher","first-page":"183","DOI":"10.1137\/080716542","volume":"2","author":"A Beck","year":"2009","unstructured":"Beck, A., & Teboulle, M. (2009). A fast iterative shrinkage-thresholding algorithm for linear inverse problems. SIAM Journal on Imaging Sciences, 2, 183\u2013202.","journal-title":"SIAM Journal on Imaging Sciences"},{"key":"1213_CR4","unstructured":"Brendel, W., Rauber, J., & Bethge, M. (2018). Decision-based adversarial attacks: Reliable attacks against black-box machine learning models. In ICLR."},{"key":"1213_CR5","doi-asserted-by":"crossref","unstructured":"Carlini, N., & Wagner, D. (2017a). Adversarial examples are not easily detected: Bypassing ten detection methods. In ACM workshop on artificial intelligence and security.","DOI":"10.1145\/3128572.3140444"},{"key":"1213_CR6","doi-asserted-by":"crossref","unstructured":"Carlini, N., & Wagner, D. (2017b). Towards evaluating the robustness of neural networks. In IEEE symposium on security and privacy.","DOI":"10.1109\/SP.2017.49"},{"issue":"1","key":"1213_CR7","doi-asserted-by":"publisher","first-page":"120","DOI":"10.1007\/s10851-010-0251-1","volume":"40","author":"A Chambolle","year":"2011","unstructured":"Chambolle, A., & Pock, T. (2011). A first-order primal-dual algorithm for convex problems with applications to imaging. Journal of Mathematical Imaging and Vision, 40(1), 120\u2013145.","journal-title":"Journal of Mathematical Imaging and Vision"},{"key":"1213_CR8","unstructured":"Croce, F., Andriushchenko, M., & Hein, M. (2019). Provable robustness of ReLU networks via maximization of linear regions. In AISTATS."},{"key":"1213_CR9","unstructured":"Croce, F., & Hein, M. (2018). A randomized gradient-free attack on ReLU networks. In GCPR."},{"key":"1213_CR10","doi-asserted-by":"crossref","unstructured":"Dalvi, N., Domingos, P., Mausam, S., & Verma, D. (2004). Adversarial classification. In KDD.","DOI":"10.1145\/1014052.1014066"},{"key":"1213_CR11","unstructured":"Goodfellow, I. J., Shlens, J., & Szegedy, C. (2015). Explaining and harnessing adversarial examples. In ICLR."},{"key":"1213_CR12","doi-asserted-by":"crossref","unstructured":"He, K., Zhang, X., Ren, S., & Sun, J. (2016). Deep residual learning for image recognition. CVPR (pp. 770\u2013778).","DOI":"10.1109\/CVPR.2016.90"},{"key":"1213_CR13","unstructured":"Hein, M., & Andriushchenko, M. (2017). Formal guarantees on the robustness of a classifier against adversarial manipulation. InNIPS."},{"key":"1213_CR14","doi-asserted-by":"crossref","unstructured":"Huang, G., Liu, Z., & Weinberger, K.\u00a0Q. (2016a). Densely connected convolutional networks. In CoRR, abs\/1608.06993.","DOI":"10.1109\/CVPR.2017.243"},{"key":"1213_CR15","unstructured":"Huang, R., Xu, B., Schuurmans, D., & Szepesvari, C. (2016b). Learning with a strong adversary. In ICLR."},{"key":"1213_CR16","doi-asserted-by":"crossref","unstructured":"Katz, G., Barrett, C., Dill, D., Julian, K., & Kochenderfer, M. (2017). Reluplex: An efficient SMT solver for verifying deep neural networks. In CAV.","DOI":"10.1007\/978-3-319-63387-9_5"},{"key":"1213_CR17","unstructured":"Krizhevsky, A., Nair, V., & Hinton, G. (2014). Cifar-10 (canadian institute for advanced research). \nhttps:\/\/www.cs.toronto.edu\/~kriz\/cifar.html\n\n."},{"key":"1213_CR18","unstructured":"Kurakin, A., Goodfellow, I.\u00a0J., & Bengio, S. (2017). Adversarial examples in the physical world. In ICLR workshop."},{"key":"1213_CR19","unstructured":"Liu, Y., Chen, X., Liu, C., & Song, D. (2017). Delving into transferable adversarial examples and black-box attacks. In ICLR."},{"key":"1213_CR20","doi-asserted-by":"crossref","unstructured":"Lowd, D., & Meek, C. (2005). Adversarial learning. In KDD.","DOI":"10.1145\/1081870.1081950"},{"key":"1213_CR21","unstructured":"Madry, A., Makelov, A., Schmidt, L., Tsipras, D., & Valdu, A. (2018). Towards deep learning models resistant to adversarial attacks. In ICLR."},{"key":"1213_CR22","unstructured":"Mirman, M., Gehr, T., & Vechev, M. (2018). Differentiable abstract interpretation for provably robust neural networks. In ICML."},{"key":"1213_CR23","doi-asserted-by":"crossref","unstructured":"Moosavi-Dezfooli, S.-M., Fawzi, A., & Frossard, P. (2016). Deepfool: A simple and accurate method to fool deep neural networks. In CVPR (pp. 2574\u20132582).","DOI":"10.1109\/CVPR.2016.282"},{"key":"1213_CR24","unstructured":"Mosbach, M., Andriushchenko, M., Trost, T., Hein, M., & Klakow, D. (2018). Logit pairing methods can fool gradient-based attacks. In NeurIPS 2018 workshop on security in machine learning. \narXiv:1810.12042\n\n."},{"key":"1213_CR25","unstructured":"Narodytska, N., & Kasiviswanathan, S.\u00a0P. (2016). Simple black-box adversarial perturbations for deep networks. In CVPR 2017 Workshops."},{"issue":"2","key":"1213_CR26","first-page":"372","volume":"27","author":"YE Nesterov","year":"1983","unstructured":"Nesterov, Y. E. (1983). A method of solving a convex programming problem with convergence rate O$$(1\/k^2)$$. Soviet Mathematics Doklady, 27(2), 372\u2013376.","journal-title":"Soviet Mathematics Doklady"},{"key":"1213_CR27","unstructured":"Papernot, N., Carlini, N., Goodfellow, I., Feinman, R., Faghri, F., & Matyasko, A., et al. (2017). cleverhans v2.0.0: An adversarial machine learning library. preprint \narXiv:1610.00768\n\n."},{"key":"1213_CR28","doi-asserted-by":"crossref","unstructured":"Papernot, N., McDonald, P., Wu, X., Jha, S., & Swami, A. (2016). Distillation as a defense to adversarial perturbations against deep networks. In IEEE symposium on security & privacy.","DOI":"10.1109\/SP.2016.41"},{"key":"1213_CR29","unstructured":"Raghunathan, A., Steinhardt, J., & Liang, P. (2018). Certified defenses against adversarial examples. In ICLR."},{"key":"1213_CR30","unstructured":"Rauber, J., Brendel, W., & Bethge, M. (2017). Foolbox: A python toolbox to benchmark the robustness of machine learning models. In ICML reliable machine learning in the wild workshop."},{"key":"1213_CR31","unstructured":"Schott, L., Rauber, J., Bethge, M., & Brendel, W. (2019). Towards the first adversarially robust neural network model on MNIST. In ICLR."},{"key":"1213_CR32","doi-asserted-by":"publisher","first-page":"323","DOI":"10.1016\/j.neunet.2012.02.016","volume":"32","author":"J Stallkamp","year":"2012","unstructured":"Stallkamp, J., Schlipsing, M., Salmen, J., & Igel, C. (2012). Man vs. computer: Benchmarking machine learning algorithms for traffic sign recognition. Neural Networks, 32, 323\u2013332.","journal-title":"Neural Networks"},{"key":"1213_CR33","unstructured":"Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., & Goodfellow, I., et al. (2014). Intriguing properties of neural networks. In ICLR (pp. 2503\u20132511)."},{"key":"1213_CR34","unstructured":"Tjeng, V., Xiao, K., & Tedrake, R. (2019). Evaluating robustness of neural networks with mixed integer programming. preprint \narXiv:1711.07356v3\n\n."},{"key":"1213_CR35","unstructured":"Weng, T., Zhang, H., Chen, H., Song, Z., Hsieh, C., & Daniel, L., et al. (2018). Towards fast computation of certified robustness for ReLU networks. In ICML."},{"key":"1213_CR36","unstructured":"Wong, E., & Kolter, J.\u00a0Z. (2018). Provable defenses against adversarial examples via the convex outer adversarial polytope. In ICML."},{"key":"1213_CR37","unstructured":"Wong, E., Schmidt, F., Metzen, J.\u00a0H., & Kolter, J.\u00a0Z. (2018). Scaling provable adversarial defenses. In NeurIPS."},{"key":"1213_CR38","doi-asserted-by":"publisher","first-page":"2805","DOI":"10.1109\/TNNLS.2018.2886017","volume":"30","author":"X Yuan","year":"2019","unstructured":"Yuan, X., He, P., Zhu, Q., Bhat, R. R., & Li, X. (2019). Adversarial examples: Attacks and defenses for deep learning. IEEE Transactions on Neural Networks and Learning Systems, 30, 2805\u20132824.","journal-title":"IEEE Transactions on Neural Networks and Learning Systems"}],"container-title":["International Journal of Computer Vision"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11263-019-01213-0.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s11263-019-01213-0\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11263-019-01213-0.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,10,1]],"date-time":"2020-10-01T23:28:12Z","timestamp":1601594892000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s11263-019-01213-0"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,10,3]]},"references-count":38,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2020,4]]}},"alternative-id":["1213"],"URL":"https:\/\/doi.org\/10.1007\/s11263-019-01213-0","relation":{},"ISSN":["0920-5691","1573-1405"],"issn-type":[{"value":"0920-5691","type":"print"},{"value":"1573-1405","type":"electronic"}],"subject":[],"published":{"date-parts":[[2019,10,3]]},"assertion":[{"value":"3 March 2019","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"12 August 2019","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"3 October 2019","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}