{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,8]],"date-time":"2026-05-08T22:10:37Z","timestamp":1778278237285,"version":"3.51.4"},"reference-count":39,"publisher":"Springer Science and Business Media LLC","issue":"3","license":[{"start":{"date-parts":[[2022,7,4]],"date-time":"2022-07-04T00:00:00Z","timestamp":1656892800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2022,7,4]],"date-time":"2022-07-04T00:00:00Z","timestamp":1656892800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["World Wide Web"],"published-print":{"date-parts":[[2023,5]]},"DOI":"10.1007\/s11280-022-01066-7","type":"journal-article","created":{"date-parts":[[2022,7,4]],"date-time":"2022-07-04T08:03:12Z","timestamp":1656921792000},"page":"1073-1091","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":6,"title":["Why does batch normalization induce the model vulnerability on adversarial images?"],"prefix":"10.1007","volume":"26","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-1888-2091","authenticated-orcid":false,"given":"Fei","family":"Kong","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Fangqi","family":"Liu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Kaidi","family":"Xu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xiaoshuang","family":"Shi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2022,7,4]]},"reference":[{"key":"1066_CR1","doi-asserted-by":"publisher","unstructured":"Peng, L., Hu, R., Kong, F., Gan, J., Mo, Y., Shi, X., Zhu, X.: Reverse graph learning for graph neural network.\u00a0IEEE Trans. Neural Netw. Learn. Syst. (2022).\u00a0https:\/\/doi.org\/10.1109\/TNNLS.2022.3161030","DOI":"10.1109\/TNNLS.2022.3161030"},{"key":"1066_CR2","doi-asserted-by":"publisher","unstructured":"Yuan, C., Zhong, Z., Lei, C., Zhu, X., Hu, R.: Adaptive reverse graph learning for robust subspace learning. Inf Process Manage. (2021).\u00a0https:\/\/doi.org\/10.1016\/j.ipm.2021.102733\u00a0","DOI":"10.1016\/j.ipm.2021.102733"},{"issue":"9","key":"1066_CR3","doi-asserted-by":"publisher","first-page":"2033","DOI":"10.1109\/TMM.2017.2703636","volume":"19","author":"X Zhu","year":"2017","unstructured":"Zhu, X., Li, X., Zhang, S., Xu, Z., Yu, L., Wang, C.: Graph pca hashing for similarity search. IEEE Trans. Multimedia 19(9), 2033\u20132044 (2017)","journal-title":"IEEE Transactions on Multimedia"},{"key":"1066_CR4","doi-asserted-by":"publisher","unstructured":"Zhu, X., Zhang, S., Zhu, Y., Zhu, P., Gao, Y.: Unsupervised spectral feature selection with dynamic hyper-graph learning. IEEE Trans. Knowl. Data Eng.\u00a0 (2020).\u00a0https:\/\/doi.org\/10.1109\/TKDE.2020.3017250","DOI":"10.1109\/TKDE.2020.3017250"},{"issue":"2","key":"1066_CR5","doi-asserted-by":"publisher","first-page":"450","DOI":"10.1109\/TCYB.2015.2403356","volume":"46","author":"X Zhu","year":"2016","unstructured":"Zhu, X., Li, X., Zhang, S.: Block-row sparse multiview multilabel learning for image classification. IEEE Trans. Cybern. 46(2), 450\u2013461 (2016)","journal-title":"IEEE Transactions on Cybernetics"},{"issue":"8","key":"1066_CR6","doi-asserted-by":"publisher","first-page":"2307","DOI":"10.1007\/s11263-020-01299-x","volume":"128","author":"X Shi","year":"2020","unstructured":"Shi, X., Guo, Z., Xing, F., Liang, Y., Yang, L.: Anchor-based self-ensembling for semi-supervised deep pairwise hashing. Int. J. Comput. Vis. 128(8), 2307\u20132324 (2020)","journal-title":"Int. J. Comput. Vis."},{"key":"1066_CR7","doi-asserted-by":"publisher","first-page":"1130","DOI":"10.1109\/TIP.2020.3040536","volume":"30","author":"X Shi","year":"2020","unstructured":"Shi, X., Xing, F., Zhang, Z., Sapkota, M., Guo, Z., Yang, L.: A scalable optimization mechanism for pairwise based discrete hashing. IEEE Trans. Image Process. 30, 1130\u20131142 (2020)","journal-title":"IEEE Trans. Image Process."},{"key":"1066_CR8","doi-asserted-by":"crossref","unstructured":"Gan, J., Peng, Z., Zhu, X., Hu, R., Ma, J., Wu, G.: Brain functional connectivity analysis based on multi-graph fusion. Med. Image Anal. \u00a0(2021).\u00a0https:\/\/doi.org\/10.1016\/j.media.2021.102057","DOI":"10.1016\/j.media.2021.102057"},{"key":"1066_CR9","doi-asserted-by":"publisher","unstructured":"Hu, R., Peng, Z., Zhu, X., Gan, J., Zhu, Y., Ma, J., Wu, G.: Multi-band brain network analysis for functional neuroimaging biomarker identification.\u00a0IEEE Trans. Med. Imaging. (2021).\u00a0https:\/\/doi.org\/10.1109\/TMI.2021.3099641","DOI":"10.1109\/TMI.2021.3099641"},{"key":"1066_CR10","doi-asserted-by":"publisher","first-page":"53","DOI":"10.1016\/j.inffus.2021.07.013","volume":"77","author":"Y Zhu","year":"2022","unstructured":"Zhu, Y., Ma, J., Yuan, C., Zhu, X.: Interpretable learning based dynamic graph convolutional networks for alzheimer\u2019s disease analysis. Information Fusion 77, 53\u201361 (2022)","journal-title":"Information Fusion"},{"key":"1066_CR11","unstructured":"Zhao, Z., Dua, D., Singh, S.: Generating natural adversarial examples. ICLR (2018)"},{"key":"1066_CR12","unstructured":"Madry, A., Makelov, A., Schmidt, L., Tsipras, D., Vladu, A.: Towards deep learning models resistant to adversarial attacks. ICLR (2018)"},{"key":"1066_CR13","unstructured":"Schmidt, L., Talwar, K., Santurkar, S., Tsipras, D., Madry, A.: Adversarially robust generalization requires more data. In: NIPS, pp. 5014\u20135026 (2018)"},{"key":"1066_CR14","unstructured":"Yin, D., Lopes, R.G., Shlens, J., Cubuk, E.D., Gilmer, J.: A fourier perspective on model robustness in computer vision. In: NIPS, pp. 13255\u201313265 (2019)"},{"key":"1066_CR15","unstructured":"Ilyas, A., Santurkar, S., Tsipras, D., Engstrom, L., Tran, B., Madry, A.: Adversarial examples are not bugs, they are features. NIPS (2019)"},{"key":"1066_CR16","unstructured":"Ford, N., Gilmer, J., Carlini, N., Cubuk, E.D.: Adversarial examples are a natural consequence of test error in noise. In: ICML, pp. 4115\u20134139 (2019)"},{"key":"1066_CR17","unstructured":"Goodfellow, I.J., Shlens, J., Szegedy, C.: Explaining and harnessing adversarial examples. In: ICLR (2015)"},{"key":"1066_CR18","unstructured":"Tanay, T., Griffin, L.: A boundary tilting persepective on the phenomenon of adversarial examples. arXiv:1608.07690\u00a0(2016)"},{"key":"1066_CR19","unstructured":"Gilmer, J., Metz, L., Faghri, F., Schoenholz, S.S., Raghu, M., Wattenberg, M., Goodfellow, I.: Adversarial Spheres. In: ICLR (2018)"},{"key":"1066_CR20","unstructured":"Ioffe, S., Szegedy, C.: Batch normalization: accelerating deep network training by reducing internal covariate shift. In: ICML, pp. 448\u2013456 (2015)"},{"key":"1066_CR21","doi-asserted-by":"crossref","unstructured":"Scherer, D., Muller, A., Behnke, S.: Evaluation of pooling operations in convolutional architectures for object recognition. In: ICANN, pp. 92\u2013101 (2010)","DOI":"10.1007\/978-3-642-15825-4_10"},{"key":"1066_CR22","unstructured":"Srivastava, N., Hinton, G., Krizhevsky, A., Sutskever, I., Salakhutdinov, R.: Dropout: a simple way to prevent neural networks from overfitting. JMLR, 1929\u20131958 (2014)"},{"key":"1066_CR23","unstructured":"Galloway, A., Golubeva, A., Tanay, T., Moussa, M., Taylor, G.W.: Batch normalization is a cause of adversarial vulnerability. arXiv:1905.02161\u00a0(2019)"},{"key":"1066_CR24","unstructured":"Benz, P., Zhang, C., Kweon, I.S.: Batch normalization increases adversarial vulnerability: Disentangling usefulness and robustness of model features. arXiv:2010.03316\u00a0(2020)"},{"key":"1066_CR25","unstructured":"Lin, M., Chen, Q., Yan, S.: Network In Network. arXiv:1312.4400\u00a0(2014)"},{"key":"1066_CR26","unstructured":"Ba, J.L., Kiros, J.R., Hinton, G.E.: Layer Normalization. arXiv:1607.06450\u00a0(2016)"},{"key":"1066_CR27","unstructured":"Ulyanov, D., Vedaldi, A., Lempitsky, V.: Instance Normalization: The Missing Ingredient for Fast Stylization. arXiv:1607.08022\u00a0(2017)"},{"key":"1066_CR28","unstructured":"Awais, M., Shamshad, F., Bae, S.H.: Towards an Adversarially Robust Normalization Approach. arXiv:2006.11007\u00a0(2020)"},{"key":"1066_CR29","unstructured":"Nado, Z., Padhy, S., Sculley, D., D\u2019Amour, A., Lakshminarayanan, B., Snoek, J.: Evaluating prediction-time batch normalization for robustness under covariate shift. arXiv:2006.10963\u00a0[cs, stat] (2021)"},{"key":"1066_CR30","doi-asserted-by":"crossref","unstructured":"Sun, J., Cao, X., Liang, H., Huang, W., Chen, Z., Li, Z.: New interpretations of normalization methods in deep learning. In: Proceedings of the AAAI Conference on Artificial Intelligence (04), pp 5875\u20135882 (2020)","DOI":"10.1609\/aaai.v34i04.6046"},{"key":"1066_CR31","doi-asserted-by":"crossref","unstructured":"Benz, P., Zhang, C., Karjauv, A., Kweon, I.S.: Revisiting batch normalization for improving corruption robustness. In: WACV, pp. 494\u2013503 (2021)","DOI":"10.1109\/WACV48630.2021.00054"},{"key":"1066_CR32","unstructured":"Dauphin, Y., Cubuk, D.E.:\u00a0Deconstructing the regularization of batchnorm. ICLR (2021)"},{"key":"1066_CR33","doi-asserted-by":"crossref","unstructured":"Zhou, B., Khosla, A., Lapedriza, A., Oliva, A., Torralba, A.: Learning deep features for discriminative localization. In: CVPR, pp. 2921\u20132929 (2016)","DOI":"10.1109\/CVPR.2016.319"},{"key":"1066_CR34","doi-asserted-by":"crossref","unstructured":"Selvaraju, R.R., Cogswell, M., Das, A., Vedantam, R., Parikh, D., Batra, D.: Grad-CAM: visual explanations from deep networks via gradient-based localization. In: ICCV, pp. 618\u2013626 (2017)","DOI":"10.1109\/ICCV.2017.74"},{"issue":"3","key":"1066_CR35","doi-asserted-by":"publisher","first-page":"211","DOI":"10.1007\/s11263-015-0816-y","volume":"115","author":"O Russakovsky","year":"2015","unstructured":"Russakovsky, O., Deng, J., Su, H., Krause, J., Satheesh, S., Ma, S., Huang, Z., Karpathy, A., Khosla, A., Bernstein, M., Berg, A.C., Fei-Fei, L.: Imagenet Large Scale Visual Recognition Challenge. International Journal of Computer Vision (IJCV) 115(3), 211\u2013252 (2015). https:\/\/doi.org\/10.1007\/s11263-015-0816-y","journal-title":"International Journal of Computer Vision (IJCV)"},{"key":"1066_CR36","doi-asserted-by":"crossref","unstructured":"Wang, X., Peng, Y., Lu, L., Lu, Z., Bagheri, M., Summers, R.: Chestx-Ray8: hospital-scale chest x-ray database and benchmarks on weakly-supervised classification and localization of common thorax diseases. In: CVPR, pp. 3462\u201371 (2017)","DOI":"10.1109\/CVPR.2017.369"},{"key":"1066_CR37","doi-asserted-by":"crossref","unstructured":"Lin, T.Y., Maire, M., Belongie, S., Hays, J., Perona, P., Ramanan, D., Dollar, P., Zitnick, C.: Microsoft COCO: Common Objects in Context. In: Computer Vision - ECCV 2014. 13Th European Conference. Proceedings: LNCS 8693, Vol. Pt.V, pp 740\u201355. Cham, Switzerland (2014)","DOI":"10.1007\/978-3-319-10602-1_48"},{"key":"1066_CR38","unstructured":"Rauber, J., Brendel, W., Bethge, M.: Foolbox: a Python Toolbox to Benchmark the Robustness of Machine Learning Models. In: ICML (2017)"},{"issue":"53","key":"1066_CR39","doi-asserted-by":"publisher","first-page":"2607","DOI":"10.21105\/joss.02607","volume":"5","author":"J Rauber","year":"2020","unstructured":"Rauber, J., Zimmermann, R., Bethge, M., Brendel, W.: Foolbox native: Fast adversarial attacks to benchmark the robustness of machine learning models in pytorch, tensorflow, and jax. Journal of Open Source Software 5(53), 2607 (2020)","journal-title":"Journal of Open Source Software"}],"container-title":["World Wide Web"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11280-022-01066-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s11280-022-01066-7\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11280-022-01066-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,4,17]],"date-time":"2023-04-17T08:36:15Z","timestamp":1681720575000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s11280-022-01066-7"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,7,4]]},"references-count":39,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2023,5]]}},"alternative-id":["1066"],"URL":"https:\/\/doi.org\/10.1007\/s11280-022-01066-7","relation":{},"ISSN":["1386-145X","1573-1413"],"issn-type":[{"value":"1386-145X","type":"print"},{"value":"1573-1413","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,7,4]]},"assertion":[{"value":"15 March 2022","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"18 April 2022","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"13 May 2022","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"4 July 2022","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}