{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,14]],"date-time":"2026-07-14T03:46:09Z","timestamp":1784000769328,"version":"3.55.0"},"reference-count":81,"publisher":"Springer Science and Business Media LLC","issue":"5","license":[{"start":{"date-parts":[[2022,9,29]],"date-time":"2022-09-29T00:00:00Z","timestamp":1664409600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2022,9,29]],"date-time":"2022-09-29T00:00:00Z","timestamp":1664409600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Mach. Intell. Res."],"published-print":{"date-parts":[[2022,10]]},"DOI":"10.1007\/s11633-022-1375-7","type":"journal-article","created":{"date-parts":[[2022,9,29]],"date-time":"2022-09-29T19:07:50Z","timestamp":1664478470000},"page":"456-471","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":8,"title":["Denoised Internal Models: A Brain-inspired Autoencoder Against Adversarial Attacks"],"prefix":"10.1007","volume":"19","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-2188-5082","authenticated-orcid":false,"given":"Kai-Yuan","family":"Liu","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0043-316X","authenticated-orcid":false,"given":"Xing-Yu","family":"Li","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yu-Rui","family":"Lai","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hang","family":"Su","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jia-Chen","family":"Wang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Chun-Xu","family":"Guo","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hong","family":"Xie","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5219-0289","authenticated-orcid":false,"given":"Ji-Song","family":"Guan","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3932-6422","authenticated-orcid":false,"given":"Yi","family":"Zhou","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2022,9,29]]},"reference":[{"issue":"4","key":"1375_CR1","doi-asserted-by":"publisher","first-page":"541","DOI":"10.1162\/neco.1989.1.4.541","volume":"1","author":"Y LeCun","year":"1989","unstructured":"Y. LeCun, B. Boser, J. S. Denker, D. Henderson, R. E. Howard, W. Hubbard, L. D. Jackel. Backpropagation applied to handwritten zip code recognition. Neural Computation, vol. 1, no. 4, pp. 541\u2013551, 1989. DOI: https:\/\/doi.org\/10.1162\/neco.1989.1.4.541.","journal-title":"Neural Computation"},{"key":"1375_CR2","doi-asserted-by":"publisher","first-page":"770","DOI":"10.1109\/CVPR.2016.90","volume-title":"Proceedings of IEEE Conference on Computer Vision and Pattern Recognition","author":"K M He","year":"2016","unstructured":"K. M. He, X. Y. Zhang, S. Q. Ren, J. Sun. Deep residual learning for image recognition. In Proceedings of IEEE Conference on Computer Vision and Pattern Recognition, Las Vegas, USA, pp. 770\u2013778, 2016. DOI: https:\/\/doi.org\/10.1109\/CVPR.2016.90."},{"key":"1375_CR3","first-page":"1097","volume-title":"Proceedings of the 25th International Conference on Neural Information Processing Systems","author":"A Krizhevsky","year":"2012","unstructured":"A. Krizhevsky, I. Sutskever, G. E. Hinton. ImageNet classification with deep convolutional neural networks. In Proceedings of the 25th International Conference on Neural Information Processing Systems, Lake Tahoe, USA, pp. 1097\u20131105, 2012."},{"key":"1375_CR4","doi-asserted-by":"publisher","first-page":"2818","DOI":"10.1109\/CVPR.2016.308","volume-title":"Proceedings of IEEE Conference on Computer Vision and Pattern Recognition","author":"C Szegedy","year":"2016","unstructured":"C. Szegedy, V. Vanhoucke, S. Ioffe, J. Shlens, Z. Wojna. Rethinking the inception architecture for computer vision. In Proceedings of IEEE Conference on Computer Vision and Pattern Recognition, Las Vegas, USA, pp. 2818\u20132826, 2016. DOI: https:\/\/doi.org\/10.1109\/CVPR.2016.308."},{"key":"1375_CR5","first-page":"173","volume-title":"Proceedings of the 33nd International Conference on Machine Learning","author":"D Amodei","year":"2016","unstructured":"D. Amodei, S. Ananthanarayanan, R. Anubhai, J. L. Bai, E. Battenberg, C. Case, J. Casper, B. Catanzaro, J. D. Chen, M. Chrzanowski, A. Coates, G. Diamos, E. Elsen, J. H. Engel, L. X. Fan, C. Fougner, A. Y. Hannun, B. Jun, T. Han, P. LeGresley, X. G. Li, L. Lin, S. Narang, A. Y. Ng, S. Ozair, R. Prenger, S. Qian, J. Raiman, S. Satheesh, D. Seetapun, S. Sengupta, C. Wang, Z. Q. Wang, B. Xiao, Y. Xie, D. Yogatama, J. Zhan, Z. Y. Zhu. Deep speech 2: End-to-end speech recognition in English and mandarin. In Proceedings of the 33nd International Conference on Machine Learning, New York, USA, pp. 173\u2013182, 2016."},{"key":"1375_CR6","volume-title":"Achieving human parity in conversational speech recognition","author":"W Xiong","year":"2016","unstructured":"W. Xiong, J. Droppo, X. Huang, F. Seide, M. Seltzer, A. Stolcke, D. Yu, G. Zweig. Achieving human parity in conversational speech recognition. [Online], Available: https:\/\/arxiv.org\/abs\/1610.05256, 2016."},{"key":"1375_CR7","first-page":"6000","volume-title":"Proceedings of the 31st International Conference on Neural Information Processing Systems","author":"A Vaswani","year":"2017","unstructured":"A. Vaswani, N. Shazeer, N. Parmar, J. Uszkoreit, L. Jones, A. N. Gomez, \u0141. Kaiser, I. Polosukhin. Attention is all you need. In Proceedings of the 31st International Conference on Neural Information Processing Systems, Long Beach, USA, pp. 6000\u20136010, 2017."},{"key":"1375_CR8","doi-asserted-by":"publisher","first-page":"4171","DOI":"10.18653\/v1\/N19-1423","volume-title":"Proceedings of Conference of the North American Chapter of the Association for Computational Linguistics: Human Language Technologies","author":"J Devlin","year":"2019","unstructured":"J. Devlin, M. W. Chang, K. Lee, K. Toutanova. BERT: Pre-training of deep bidirectional transformers for language understanding. In Proceedings of Conference of the North American Chapter of the Association for Computational Linguistics: Human Language Technologies, Minneapolis, Minnesota, pp. 4171\u20134186, 2019. DOI: https:\/\/doi.org\/10.18653\/v1\/N19-1423."},{"key":"1375_CR9","volume-title":"Proceedings of the 33rd International Conference on Neural Information Processing Systems","author":"Z L Yang","year":"2019","unstructured":"Z. L. Yang, Z. H. Dai, Y. M. Yang, J. Carbonell, R. Salakhutdinov, Q. V. Le. XLNet: Generalized autoregressive pretraining for language understanding. In Proceedings of the 33rd International Conference on Neural Information Processing Systems, Vancouver, Canada, Article No. 517, 2019."},{"key":"1375_CR10","doi-asserted-by":"publisher","first-page":"354","DOI":"10.1016\/j.patcog.2017.10.013","volume":"77","author":"J X Gu","year":"2018","unstructured":"J. X. Gu, Z. H. Wang, J. Kuen, L. Y. Ma, A. Shahroudy, B. Shuai, T. Liu, X. X. Wang, G. Wang, J. F. Cai, T. Chen. Recent advances in convolutional neural networks. Pattern Recognition, vol. 77, pp. 354\u2013377, 2018. DOI: https:\/\/doi.org\/10.1016\/j.patcog.2017.10.013.","journal-title":"Pattern Recognition"},{"key":"1375_CR11","volume-title":"Proceedings of the 2nd International Conference on Learning Representations","author":"C Szegedy","year":"2014","unstructured":"C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. J. Goodfellow, R. Fergus. Intriguing properties of neural networks. In Proceedings of the 2nd International Conference on Learning Representations, Banff, Canada, 2014."},{"key":"1375_CR12","doi-asserted-by":"publisher","first-page":"387","DOI":"10.1007\/978-3-642-40994-3_25","volume-title":"Proceedings of the European Conference on Machine Learning and Knowledge Discovery in Databases","author":"B Biggio","year":"2013","unstructured":"B. Biggio, I. Corona, D. Maiorca, B. Nelson, N. \u0160rndi\u0107, P. Laskov, G. Giacinto, F. Roli. Evasion attacks against machine learning at test time. In Proceedings of the European Conference on Machine Learning and Knowledge Discovery in Databases, Springer, Prague, Czech Republic, pp. 387\u2013402, 2013. DOI: https:\/\/doi.org\/10.1007\/978-3-642-40994-3_25."},{"key":"1375_CR13","first-page":"2672","volume":"2","author":"I J Goodfellow","year":"2014","unstructured":"I. J. Goodfellow, J. Pouget-Abadie, M. Mirza, B. Xu, D. Warde-Farley, S. Ozair, A. Courville, Y. Bengio. Generative adversarial nets. In Proceedings of the 27th International Conference on Neural Information Processing Systems, Montreal, Canada, vol. 2, pp. 2672\u20132680, 2014.","journal-title":"Proceedings of the 27th International Conference on Neural Information Processing Systems"},{"key":"1375_CR14","doi-asserted-by":"publisher","first-page":"317","DOI":"10.1016\/j.patcog.2018.07.023","volume":"84","author":"B Biggio","year":"2018","unstructured":"B. Biggio, F. Roli. Wild patterns: Ten years after the rise of adversarial machine learning. Pattern Recognition, vol. 84, pp. 317\u2013331, 2018. DOI: https:\/\/doi.org\/10.1016\/j.patcog.2018.07.023.","journal-title":"Pattern Recognition"},{"key":"1375_CR15","volume-title":"Proceedings of the 3rd International Conference on Learning Representations","author":"I J Goodfellow","year":"2015","unstructured":"I. J. Goodfellow, J. Shlens, C. Szegedy. Explaining and harnessing adversarial examples. In Proceedings of the 3rd International Conference on Learning Representations, San Diego, USA, 2015."},{"key":"1375_CR16","doi-asserted-by":"publisher","first-page":"2574","DOI":"10.1109\/CVPR.2016.282","volume-title":"Proceedings of IEEE Conference on Computer Vision and Pattern Recognition","author":"S M Moosavi-Dezfooli","year":"2016","unstructured":"S. M. Moosavi-Dezfooli, A. Fawzi, P. Frossard. DeepFool: A simple and accurate method to fool deep neural networks. In Proceedings of IEEE Conference on Computer Vision and Pattern Recognition, Las Vegas, USA, pp. 2574\u20132582, 2016. DOI: https:\/\/doi.org\/10.1109\/CVPR.2016.282."},{"key":"1375_CR17","volume-title":"On the robustness of the CVPR 2018 white-box adversarial example defenses","author":"A Athalye","year":"2018","unstructured":"A. Athalye, N. Carlini. On the robustness of the CVPR 2018 white-box adversarial example defenses. [Online], Available: https:\/\/arxiv.org\/abs\/1804.03286, 2018."},{"issue":"1","key":"1375_CR18","doi-asserted-by":"publisher","DOI":"10.1038\/s41467-021-22244-7","volume":"12","year":"2021","unstructured":"Y. D. Xu, M. Vaziri-Pashkam. Limits to visual representational correspondence between convolutional neural networks and the human brain. Nature Communications, vol. 12, no. 1, Article number 2065, 2021. DOI: https:\/\/doi.org\/10.1038\/s41467-021-22244-7.","journal-title":"Nature Communications"},{"key":"1375_CR19","first-page":"284","volume":"80","author":"A Athalye","year":"2018","unstructured":"A. Athalye, L. Engstrom, A. Ilyas, K. Kwok. Synthesizing robust adversarial examples. In Proceedings of the 35th International Conference on Machine Learning, Stockholmsm\u00e4ssan, Sweden, vol. 80, pp. 284\u2013293, 2018.","journal-title":"Proceedings of the 35th International Conference on Machine Learning"},{"key":"1375_CR20","doi-asserted-by":"publisher","unstructured":"E. Casamassima, A. Herbert, C. Merkel. Exploring CNN features in the context of adversarial robustness and human perception. In Proceedings of SPIE, Applications of Machine Learning, San Diego, USA, vol. 11843, Article number 1184313, 2021. DOI: https:\/\/doi.org\/10.1117\/12.2594363.","DOI":"10.1117\/12.2594363"},{"key":"1375_CR21","volume-title":"Proceedings of the 33rd Neural Information Processing Systems","author":"Y J Huang","year":"2019","unstructured":"Y. J. Huang, S. H. Dai, T. Nguyen, P. L. Bao, D. Y. Tsao, R. G. Baraniuk, A. Anandkumar. Brain-inspired robust vision using convolutional neural networks with feedback. In Proceedings of the 33rd Neural Information Processing Systems, Vancouver, Canada, 2019."},{"issue":"6","key":"1375_CR22","doi-asserted-by":"publisher","first-page":"386","DOI":"10.1037\/h0042519","volume":"65","author":"F Rosenblatt","year":"1958","unstructured":"F. Rosenblatt. The perceptron: A probabilistic model for information storage and organization in the brain. Psychological Review, vol. 65, no. 6, pp. 386\u2013408, 1958. DOI: https:\/\/doi.org\/10.1037\/h0042519.","journal-title":"Psychological Review"},{"key":"1375_CR23","volume-title":"Deep learning using rectified linear units (ReLU)","author":"A F Agarap","year":"2019","unstructured":"A. F. Agarap. Deep learning using rectified linear units (ReLU), [Online], Available: https:\/\/arxiv.org\/abs\/1803.08375, 2019."},{"issue":"2","key":"1375_CR24","doi-asserted-by":"publisher","first-page":"179","DOI":"10.1207\/s15516709cog1402_1","volume":"14","author":"J L Elman","year":"1990","unstructured":"J. L. Elman. Finding structure in time. Cognitive Science, vol. 14, no. 2, pp. 179\u2013211, 1990. DOI: https:\/\/doi.org\/10.1207\/s15516709cog1402_1.","journal-title":"Cognitive Science"},{"issue":"6","key":"1375_CR25","doi-asserted-by":"publisher","first-page":"298","DOI":"10.1016\/j.tins.2006.05.002","volume":"29","author":"J Cudeiro","year":"2006","unstructured":"J. Cudeiro, A. M. Sillito. Looking back: Corticothalamic feedback and early visual processing. Trends in Neurosciences, vol. 29, no. 6, pp. 298\u2013306, 2006. DOI: https:\/\/doi.org\/10.1016\/j.tins.2006.05.002.","journal-title":"Trends in Neurosciences"},{"key":"1375_CR26","doi-asserted-by":"publisher","first-page":"241","DOI":"10.1113\/jphysiol.1984.sp015499","volume":"357","author":"A M Derrington","year":"1984","unstructured":"A. M. Derrington, J. Krauskopf, P. Lennie. Chromatic mechanisms in lateral geniculate nucleus of macaque. Journal of Physiology, vol. 357, pp. 241\u2013265, 1984. DOI: https:\/\/doi.org\/10.1113\/jphysiol.1984.sp015499.","journal-title":"Journal of Physiology"},{"issue":"11","key":"1375_CR27","doi-asserted-by":"publisher","first-page":"1203","DOI":"10.1038\/nn957","volume":"5","author":"D H O\u2019Connor","year":"2002","unstructured":"D. H. O\u2019Connor, M. M. Fukui, M. A. Pinsk, S. Kastner. Attention modulates responses in the human lateral geniculate nucleus. Nature Neuroscience, vol. 5, no. 11, pp. 1203\u20131209, 2002. DOI: https:\/\/doi.org\/10.1038\/nn957.","journal-title":"Nature Neuroscience"},{"issue":"7","key":"1375_CR28","doi-asserted-by":"publisher","first-page":"2788","DOI":"10.1073\/pnas.1316808111","volume":"111","author":"H Xie","year":"2014","unstructured":"H. Xie, Y. Liu, Y. Z. Zhu, X. L. Ding, Y. H. Yang, J. S. Guan. In vivo imaging of immediate early gene expression reveals layer-specific memory traces in the mammalian brain. Proceedings of the National Academy of Sciences of the United States of America, vol. 111, no. 7, pp. 2788\u20132793, 2014. DOI: https:\/\/doi.org\/10.1073\/pnas.1316808111.","journal-title":"Proceedings of the National Academy of Sciences of the United States of America"},{"issue":"5","key":"1375_CR29","doi-asserted-by":"publisher","first-page":"918","DOI":"10.1016\/j.neuron.2015.08.002","volume":"87","author":"S Tonegawa","year":"2015","unstructured":"S. Tonegawa, X. Liu, S. Ramirez, R. Redondo. Memory engram cells have come of age. Neuron, vol. 87, no. 5, pp. 918\u2013931, 2015. DOI: https:\/\/doi.org\/10.1016\/j.neuron.2015.08.002.","journal-title":"Neuron"},{"issue":"7045","key":"1375_CR30","doi-asserted-by":"publisher","first-page":"1102","DOI":"10.1038\/nature03687","volume":"435","author":"R Q Quiroga","year":"2005","unstructured":"R. Q. Quiroga, L. Reddy, G. Kreiman, C. Koch, I. Fried. Invariant visual representation by single neurons in the human brain. Nature, vol. 435, no. 7045, pp. 1102\u20131107, 2005. DOI: https:\/\/doi.org\/10.1038\/nature03687.","journal-title":"Nature"},{"issue":"5451","key":"1375_CR31","doi-asserted-by":"publisher","first-page":"248","DOI":"10.1126\/science.287.5451.248","volume":"287","author":"J L McGaugh","year":"2000","unstructured":"J. L. McGaugh. Memory-A century of consolidation. Science, vol. 287, no. 5451, pp. 248\u2013251, 2000. DOI: https:\/\/doi.org\/10.1126\/science.287.5451.248.","journal-title":"Science"},{"key":"1375_CR32","doi-asserted-by":"publisher","unstructured":"J. S. Guan, J. Jiang, H. Xie, K. Y. Liu. How does the sparse memory \u201cengram\u201d neurons encode the memory of a spatial-temporal event? Frontiers in Neural Circuits, vol. 10, Article number 61, 2016. DOI: https:\/\/doi.org\/10.3389\/fncir.2016.00061.","DOI":"10.3389\/fncir.2016.00061"},{"issue":"7394","key":"1375_CR33","doi-asserted-by":"publisher","first-page":"381","DOI":"10.1038\/nature11028","volume":"484","author":"X Liu","year":"2012","unstructured":"X. Liu, S. Ramirez, P. T. Pang, C. B. Puryear, A. Govindarajan, K. Deisseroth, S. Tonegawa. Optogenetic stimulation of a hippocampal engram activates fear memory recall. Nature, vol. 484, no. 7394, pp. 381\u2013385, 2012. DOI: https:\/\/doi.org\/10.1038\/nature11028.","journal-title":"Nature"},{"issue":"1633","key":"1375_CR34","doi-asserted-by":"publisher","DOI":"10.1098\/rstb.2013.0142","volume":"369","year":"2014","unstructured":"X. Liu, S. Ramirez, S. Tonegawa. Inception of a false memory by optogenetic manipulation of a hippocampal memory engram. Philosophical Transactions of the Royal Society B: Biological Sciences, vol. 369, no. 1633, Article number 20130142, 2014. DOI: https:\/\/doi.org\/10.1098\/rstb.2013.0142.","journal-title":"Philosophical Transactions of the Royal Society B: Biological Sciences"},{"issue":"11","key":"1375_CR35","doi-asserted-by":"publisher","first-page":"2278","DOI":"10.1109\/5.726791","volume":"86","author":"Y Lecun","year":"1998","unstructured":"Y. Lecun, L. Bottou, Y. Bengio, P. Haffner. Gradient-based learning applied to document recognition. Proceedings of IEEE, vol. 86, no. 11, pp. 2278\u20132324, 1998. DOI: https:\/\/doi.org\/10.1109\/5.726791.","journal-title":"Proceedings of IEEE"},{"key":"1375_CR36","volume-title":"Foolbox: A python toolbox to benchmark the robustness of machine learning models","author":"J Rauber","year":"2017","unstructured":"J. Rauber, W. Brendel, M. Bethge. Foolbox: A python toolbox to benchmark the robustness of machine learning models. [Online], Available: https:\/\/arxiv.org\/abs\/1707.04131, 2017."},{"key":"1375_CR37","volume-title":"Proceedings of the 6th International Conference on Learning Representations","author":"F Tram\u00e8r","year":"2018","unstructured":"F. Tram\u00e8r, A. Kurakin, N. Papernot, I. J. Goodfellow, D. Boneh, P. D. McDaniel. Ensemble adversarial training: Attacks and defenses. In Proceedings of the 6th International Conference on Learning Representations, Vancouver, Canada, 2018"},{"key":"1375_CR38","doi-asserted-by":"publisher","first-page":"4317","DOI":"10.1109\/CVPR.2019.00445","volume-title":"Proceedings of IEEE\/CVF Conference on Computer Vision and Pattern Recognition","author":"J Rony","year":"2019","unstructured":"J. Rony, L. G. Hafemann, L. S. Oliveira, I. B. Ayed, R. Sabourin, E. Granger. Decoupling direction and norm for efficient gradient-based L2 adversarial attacks and defenses. In Proceedings of IEEE\/CVF Conference on Computer Vision and Pattern Recognition, IEEE, Long Beach, USA, pp. 4317\u20134325, 2019. DOI: https:\/\/doi.org\/10.1109\/CVPR.2019.00445."},{"key":"1375_CR39","volume-title":"Fast differentiable clipping-aware normalization and rescaling","author":"J Rauber","year":"2020","unstructured":"J. Rauber, M. Bethge. Fast differentiable clipping-aware normalization and rescaling. [Online], Available: https:\/\/arxiv.org\/abs\/2007.07677, 2020."},{"key":"1375_CR40","doi-asserted-by":"publisher","first-page":"352","DOI":"10.1109\/ICMLA.2017.0-136","volume-title":"Proceedings of the 16th IEEE International Conference on Machine Learning and Applications","author":"H Hosseini","year":"2017","unstructured":"H. Hosseini, B. C. Xiao, M. Jaiswal, R. Poovendran. On the limitation of convolutional neural networks in recognizing negative images. In Proceedings of the 16th IEEE International Conference on Machine Learning and Applications, Cancun, Mexico, pp. 352\u2013358, 2017. DOI: https:\/\/doi.org\/10.1109\/ICMLA.2017.0-136."},{"key":"1375_CR41","doi-asserted-by":"publisher","first-page":"39","DOI":"10.1109\/SP.2017.49","volume-title":"Proceedings of IEEE Symposium on Security and Privacy","author":"N Carlini","year":"2017","unstructured":"N. Carlini, D. Wagner. Towards evaluating the robustness of neural networks. In Proceedings of IEEE Symposium on Security and Privacy, San Jose, USA, pp. 39\u201357, 2017. DOI: https:\/\/doi.org\/10.1109\/SP.2017.49."},{"key":"1375_CR42","volume-title":"Proceedings of the 33rd Conference on Neural Information Processing Systems","author":"W Brendel","year":"2019","unstructured":"W. Brendel, J. Rauber, M. K\u00fcmmerer, I. Ustyuzhaninov, M. Bethge. Accurate, reliable and fast robustness evaluation. In Proceedings of the 33rd Conference on Neural Information Processing Systems, Vancouver, Canada, Article number 1152, 2019."},{"key":"1375_CR43","volume-title":"Proceedings of the 6th International Conference on Learning Representations","author":"W Brendel","year":"2018","unstructured":"W. Brendel, J. Rauber, M. Bethge. Decision-based adversarial attacks: Reliable attacks against black-box machine learning models. In Proceedings of the 6th International Conference on Learning Representations, Vancouver, Canada, 2018."},{"key":"1375_CR44","volume-title":"Proceedings of the 7th International Conference on Learning Representations","author":"L Schott","year":"2019","unstructured":"L. Schott, J. Rauber, M. Bethge, W. Brendel. Towards the first adversarially robust neural network model on MNIST. In Proceedings of the 7th International Conference on Learning Representations, New Orleans, USA, 2019."},{"key":"1375_CR45","volume-title":"Proceedings of the 8th International Conference on Learning Representations","author":"X W Yin","year":"2020","unstructured":"X. W. Yin, S. Kolouri, G. K. Rohde. GAT: Generative adversarial training for adversarial example detection and robust classification. In Proceedings of the 8th International Conference on Learning Representations, Addis Ababa, Ethiopia, 2020."},{"key":"1375_CR46","first-page":"4970","volume":"97","author":"T Y Pang","year":"2019","unstructured":"T. Y. Pang, K. Xu, C. Du, N. Chen, J. Zhu. Improving adversarial robustness via promoting ensemble diversity. In Proceedings of the 36th International Conference on Machine Learning, Long Beach, USA, vol. 97, pp. 4970\u20134979, 2019.","journal-title":"Proceedings of the 36th International Conference on Machine Learning"},{"key":"1375_CR47","volume-title":"Proceedings of the 33rd International Conference on Neural Information Processing Systems","author":"T Yu","year":"2019","unstructured":"T. Yu, S. Y. Hu, C. Guo, W. L. Chao, K. Q. Weinberger. A new defense against adversarial images: Turning a weakness into a strength. In Proceedings of the 33rd International Conference on Neural Information Processing Systems, Vancouver, Canada, Article number 146, 2019."},{"key":"1375_CR48","volume-title":"Proceedings of the 33rd International Conference on Neural Information Processing Systems","author":"G Verma","year":"2019","unstructured":"G. Verma, A. Swami. Error correcting output codes improve probability estimation and adversarial robustness of deep neural networks. In Proceedings of the 33rd International Conference on Neural Information Processing Systems, Vancouver, Canada, Article number 776, 2019."},{"key":"1375_CR49","first-page":"10096","volume-title":"Proceedings of the 32nd International Conference on Neural Information Processing Systems","author":"M Bafna","year":"2018","unstructured":"M. Bafna, J. Murtagh, N. Vyas. Thwarting adversarial examples: An L0L0-robust sparse Fourier transform. In Proceedings of the 32nd International Conference on Neural Information Processing Systems, Montreal, Canada, pp. 10096\u201310106, 2018."},{"key":"1375_CR50","volume-title":"Proceedings of the 8th International Conference on Learning Representations","author":"T Y Pang","year":"2020","unstructured":"T. Y. Pang, K. Xu, Y. P. Dong, C. Du, N. Chen, J. Zhu. Rethinking softmax cross-entropy loss for adversarial robustness. In Proceedings of the 8th International Conference on Learning Representations, Addis Ababa, Ethiopia, 2020."},{"key":"1375_CR51","doi-asserted-by":"publisher","first-page":"99","DOI":"10.1201\/9781351251389-8","volume-title":"Artificial Intelligence Safety and Security","author":"A Kurakin","year":"2018","unstructured":"A. Kurakin, I. J. Goodfellow, S. Bengio. Adversarial examples in the physical world. Artificial Intelligence Safety and Security, R. V. Yampolskiy, Ed., New York, USA: Chapman and Hall, pp. 99\u2013112, 2018."},{"key":"1375_CR52","volume-title":"Proceedings of the 6th International Conference on Learning Representations","author":"A Madry","year":"2018","unstructured":"A. Madry, A. Makelov, L. Schmidt, D. Tsipras, A. Vladu. Towards deep learning models resistant to adversarial attacks. In Proceedings of the 6th International Conference on Learning Representations, Vancouver, Canada, 2018."},{"key":"1375_CR53","doi-asserted-by":"publisher","first-page":"6022","DOI":"10.1109\/ICCV.2019.00612","volume-title":"Proceedings of the IEEE\/CVF International Conference on Computer Vision","author":"S Yun","year":"2019","unstructured":"S. Yun, D. Han, S. Chun, S. J. Oh, Y. Yoo, J. Choe. Cut-Mix: Regularization strategy to train strong classifiers with localizable features. In Proceedings of the IEEE\/CVF International Conference on Computer Vision, IEEE, Seoul, Korea, pp. 6022\u20136031, 2019. DOI: https:\/\/doi.org\/10.1109\/ICCV.2019.00612."},{"key":"1375_CR54","volume-title":"Proceedings of the 7th International Conference on Learning Representations","author":"D Hendrycks","year":"2019","unstructured":"D. Hendrycks, T. G. Dietterich. Benchmarking neural network robustness to common corruptions and perturbations. In Proceedings of the 7th International Conference on Learning Representations, New Orleans, USA, 2019."},{"key":"1375_CR55","doi-asserted-by":"publisher","first-page":"10684","DOI":"10.1109\/CVPR42600.2020.01070","volume-title":"Proceedings of IEEE\/CVF Conference on Computer Vision and Pattern Recognition","author":"Q Z Xie","year":"2020","unstructured":"Q. Z. Xie, M. T. Luong, E. Hovy, Q. V. Le. Self-training with noisy student improves ImageNet classification. In Proceedings of IEEE\/CVF Conference on Computer Vision and Pattern Recognition, IEEE, Seattle, USA, pp. 10684\u201310695, 2020. DOI: https:\/\/doi.org\/10.1109\/CVPR42600.2020.01070."},{"key":"1375_CR56","doi-asserted-by":"publisher","first-page":"14","DOI":"10.1007\/978-3-030-62144-5_2","volume-title":"Proceedings of the 3rd International Workshop on Engineering Dependable and Secure Machine Learning Systems","author":"P Vaishnavi","year":"2020","unstructured":"P. Vaishnavi, T. Cong, K. Eykholt, A. Prakash, A. Rahmati. Can attention masks improve adversarial robustness? In Proceedings of the 3rd International Workshop on Engineering Dependable and Secure Machine Learning Systems, New York, USA, pp. 14\u201322, 2020. DOI: https:\/\/doi.org\/10.1007\/978-3-030-62144-5_2."},{"key":"1375_CR57","first-page":"3371","volume":"11","author":"P Vincent","year":"2010","unstructured":"P. Vincent, H. Larochelle, I. Lajoie, Y. Bengio, P. A. Manzagol. Stacked denoising autoencoders: Learning useful representations in a deep network with a local denoising criterion. Journal of Machine Learning Research, vol. 11, pp. 3371\u20133408, 2010.","journal-title":"Journal of Machine Learning Research"},{"key":"1375_CR58","volume-title":"Proceedings of the 6th International Conference on Learning Representations","author":"C Guo","year":"2018","unstructured":"C. Guo, M. Rana, M. Ciss\u00e9, L. van der Maaten. Countering adversarial images using input transformations. In Proceedings of the 6th International Conference on Learning Representations, Vancouver, Canada, 2018."},{"key":"1375_CR59","volume-title":"Proceedings of the 6th International Conference on Learning Representations","author":"C H Xie","year":"2018","unstructured":"C. H. Xie, J. Y. Wang, Z. S. Zhang, Z. Ren, A. L. Yuille. Mitigating adversarial effects through randomization. In Proceedings of the 6th International Conference on Learning Representations, Vancouver, Canada, 2018."},{"key":"1375_CR60","volume-title":"Proceedings of the 6th International Conference on Learning Representations","author":"X J Ma","year":"2018","unstructured":"X. J. Ma, B. Li, Y. S. Wang, S. M. Erfani, S. N. R. Wijewickrema, G. Schoenebeck, D. Song, M. E. Houle, J. Bailey. Characterizing adversarial subspaces using local intrinsic dimensionality. In Proceedings of the 6th International Conference on Learning Representations, Vancouver, Canada, 2018."},{"key":"1375_CR61","volume-title":"Proceedings of the 6th International Conference on Learning Representations","author":"G S Dhillon","year":"2018","unstructured":"G. S. Dhillon, K. Azizzadenesheli, Z. C. Lipton, J. Bernstein, J. Kossaifi, A. Khanna, A. Anandkumar. Stochastic activation pruning for robust adversarial defense. In Proceedings of the 6th International Conference on Learning Representations, Vancouver, Canada, 2018."},{"key":"1375_CR62","volume-title":"Proceedings of the 6th International Conference on Learning Representations","author":"J Buckman","year":"2018","unstructured":"J. Buckman, A. Roy, C. Raffel, I. J. Goodfellow. Thermometer encoding: One hot way to resist adversarial examples. In Proceedings of the 6th International Conference on Learning Representations, Vancouver, Canada, 2018."},{"key":"1375_CR63","doi-asserted-by":"publisher","first-page":"506","DOI":"10.1145\/3052973.3053009","volume-title":"Proceedings of ACM on Asia Conference on Computer and Communications Security","author":"N Papernot","year":"2017","unstructured":"N. Papernot, P. McDaniel, I. Goodfellow, S. Jha, Z. B. Celik, A. Swami. Practical black-box attacks against machine learning. In Proceedings of ACM on Asia Conference on Computer and Communications Security, Abu Dhabi, United Arab Emirates, pp. 506\u2013519, 2017. DOI: https:\/\/doi.org\/10.1145\/3052973.3053009."},{"key":"1375_CR64","first-page":"274","volume":"80","author":"A Athalye","year":"2018","unstructured":"A. Athalye, N. Carlini, D. A. Wagner. Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples. In Proceedings of the 35th International Conference on Machine Learning, Stockholmsm\u00e4ssan, Sweden, vol. 80, pp. 274\u2013283, 2018.","journal-title":"Proceedings of the 35th International Conference on Machine Learning"},{"key":"1375_CR65","first-page":"5498","volume":"97","author":"K Roth","year":"2019","unstructured":"K. Roth, Y. Kilcher, T. Hofmann. The odds are odd: A statistical test for detecting adversarial examples. In Proceedings of the 36th International Conference on Machine Learning, Long Beach, USA, vol. 97, pp. 5498\u20135507, 2019.","journal-title":"Proceedings of the 36th International Conference on Machine Learning"},{"key":"1375_CR66","volume-title":"Enhancing adversarial defense by k-winners-take-all","author":"C Xiao","year":"2019","unstructured":"C. Xiao, P. L. Zhong, C. X. Zheng. Enhancing adversarial defense by k-winners-take-all. [Online], Available: https:\/\/arxiv.org\/abs\/1905.10510, 2019."},{"key":"1375_CR67","volume-title":"Proceedings of the 8th International Conference on Learning Representations","author":"U Jang","year":"2020","unstructured":"U. Jang, S. Jha, S. Jha. On the need for topology-aware generative models for manifold-based defenses. In Proceedings of the 8th International Conference on Learning Representations, Addis Ababa, Ethiopia, 2020."},{"key":"1375_CR68","volume-title":"Proceedings of the 34th International Conference on Neural Information Processing Systems","author":"F Tram\u00e8r","year":"2020","unstructured":"F. Tram\u00e8r, N. Carlini, W. Brendel, A. M\u0105dry. On adaptive attacks to adversarial example defenses. In Proceedings of the 34th International Conference on Neural Information Processing Systems, Vancouver, Canada, Article number 138, 2020."},{"key":"1375_CR69","volume-title":"Proceedings of the 6th International Conference on Learning Representations","author":"P Samangouei","year":"2018","unstructured":"P. Samangouei, M. Kabkab, R. Chellappa. Defense-GAN: Protecting classifiers against adversarial attacks using generative models. In Proceedings of the 6th International Conference on Learning Representations, Vancouver, Canada, 2018."},{"key":"1375_CR70","volume-title":"Proceedings of the 29th International Joint Conference on Artificial Intelligence","author":"C Cintas","year":"2021","unstructured":"C. Cintas, S. Speakman, V. Akinwande, W. Ogallo, K. Weldemariam, S. Sridharan, E. McFowland. Detecting adversarial attacks via subset scanning of autoencoder activations and reconstruction error. In Proceedings of the 29th International Joint Conference on Artificial Intelligence, Yokohama, Japan, Article number 122, 2021."},{"key":"1375_CR71","doi-asserted-by":"publisher","first-page":"135","DOI":"10.1145\/3133956.3134057","volume-title":"Proceedings of ACM\/SIGSAC Conference on Computer and Communications Security","author":"D Y Meng","year":"2017","unstructured":"D. Y. Meng, H. Chen. MagNet: A two-pronged defense against adversarial examples. In Proceedings of ACM\/SIGSAC Conference on Computer and Communications Security, Dallas, USA, pp. 135\u2013147, 2017. DOI: https:\/\/doi.org\/10.1145\/3133956.3134057."},{"key":"1375_CR72","first-page":"3804","volume":"97","author":"Y Z Li","year":"2019","unstructured":"Y. Z. Li, J. Bradshaw, Y. Sharma. Are generative classifiers more robust to adversarial attacks? In Proceedings of the 36th International Conference on Machine Learning, vol. 97, pp. 3804\u20133814, 2019.","journal-title":"Proceedings of the 36th International Conference on Machine Learning"},{"key":"1375_CR73","volume-title":"The Central Nervous System: Structure and Function","author":"P Brodal","year":"2004","unstructured":"P. Brodal. The Central Nervous System: Structure and Function, 3rd ed., New York, USA: Oxford University Press, 2004.","edition":"3rd ed."},{"issue":"39","key":"1375_CR74","doi-asserted-by":"publisher","first-page":"12159","DOI":"10.1523\/JNEUROSCI.1986-09.2009","volume":"29","author":"B J White","year":"2009","unstructured":"B. J. White, S. E. Boehnke, R. A. Marino, L. Itti, D. P. Munoz. Color-related signals in the primate superior colliculus. Journal of Neuroscience, vol. 29, no. 39, pp. 12159\u201312166, 2009. DOI: https:\/\/doi.org\/10.1523\/JNEUROSCI.1986-09.2009.","journal-title":"Journal of Neuroscience"},{"issue":"2","key":"1375_CR75","doi-asserted-by":"publisher","first-page":"456","DOI":"10.1016\/j.cell.2015.09.029","volume":"163","author":"H Markram","year":"2015","unstructured":"H. Markram, E. Muller, S. Ramaswamy, M. W. Reimann, M. Abdellah, C. A. Sanchez, A. Ailamaki, L. Alonso-Nanclares, N. Antille, S. Arsever, G. A. A. Kahou, T. K. Berger, A. Bilgili, N. Buncic, A. Chalimourda, G. Chindemi, J. D. Courcol, F. Delalondre, V. Delattre, S. Druckmann, R. Dumusc, J. Dynes, S. Eilemann, E. Gal, M. E. Gevaert, J. P. Ghobril, A. Gidon, J. W. Graham, A. Gupta, V. Haenel, E. Hay, T. Heinis, J. B. Hernando, M. Hines, L. Kanari, D. Keller, J. Kenyon, G. Khazen, Y. Kim, J. G. King, Z. Kisvarday, P. Kumbhar, S. Lasserre, J. V. Le B\u00e9, B. R. C. Magalh\u00e3es, A. Merch\u00e1n-P\u00e9rez, J. Meystre, B. R. Morrice, J. Muller, A. Mu\u00f1oz-C\u00e9spedes, S. Muralidhar, K. Muthurasa, D. Nachbaur, T. H. Newton, M. Nolte, A. Ovcharenko, J. Palacios, L. Pastor, R. Perin, R. Ranjan, I. Riachi, J. R. Rodr\u00edguez, J. L. Riquelme, C. R\u00f6ssert, K. Sfyrakis, Y. Shi, J. C. Shillcock, G. Silberberg, R. Silva, F. Tauheed, M. Telefont, M. Toledo-Rodriguez, T. Tr\u00e4nkler, W. Van Geit, J. V. D\u00edaz, R. Walker, Y. Wang, S. M. Zaninetta, J. DeFelipe, S. L. Hill, I. Segev, F. Sch\u00fcrmann. Reconstruction and simulation of neocortical microcircuitry. Cell, vol. 163, no. 2, pp. 456\u2013492, 2015. DOI: https:\/\/doi.org\/10.1016\/j.cell.2015.09.029.","journal-title":"Cell"},{"key":"1375_CR76","first-page":"7025","volume":"97","author":"Y Z Yang","year":"2019","unstructured":"Y. Z. Yang, G. Zhang, Z. Xu, D. Katabi. Me-Net: Towards effective adversarial robustness with matrix estimation. In Proceedings of the 36th International Conference on Machine Learning, Long Beach, USA, vol. 97, pp. 7025\u20137034, 2019.","journal-title":"Proceedings of the 36th International Conference on Machine Learning"},{"issue":"6","key":"1375_CR77","doi-asserted-by":"publisher","first-page":"717","DOI":"10.1007\/s10208-009-9045-5","volume":"9","author":"E J Cand\u00e8s","year":"2009","unstructured":"E. J. Cand\u00e8s, B. Recht. Exact matrix completion via convex optimization. Foundations of Computational Mathematics, vol. 9, no. 6, pp. 717\u2013772, 2009. DOI: https:\/\/doi.org\/10.1007\/s10208-009-9045-5.","journal-title":"Foundations of Computational Mathematics"},{"issue":"1","key":"1375_CR78","doi-asserted-by":"publisher","first-page":"177","DOI":"10.1214\/14-AOS1272","volume":"43","author":"S Chatterjee","year":"2015","unstructured":"S. Chatterjee. Matrix estimation by universal singular value thresholding. The Annals of Statistics, vol. 43, no. 1, pp. 177\u2013214, 2015. DOI: https:\/\/doi.org\/10.1214\/14-aos1272.","journal-title":"The Annals of Statistics"},{"issue":"4","key":"1375_CR79","doi-asserted-by":"publisher","first-page":"14","DOI":"10.1109\/MSP.2018.2821706","volume":"35","author":"Y D Chen","year":"2018","unstructured":"Y. D. Chen, Y. J. Chi. Harnessing structures in big data via guaranteed low-rank matrix estimation: Recent theory and fast algorithms via convex and nonconvex optimization. IEEE Signal Processing Magazine, vol. 35, no. 4, pp. 14\u201331, 2018. DOI: https:\/\/doi.org\/10.1109\/MSP.2018.2821706.","journal-title":"IEEE Signal Processing Magazine"},{"key":"1375_CR80","volume-title":"Proceedings of the 5th International Conference on Learning Representations","author":"A Kurakin","year":"2017","unstructured":"A. Kurakin, I. J. Goodfellow, S. Bengio. Adversarial examples in the physical world. In Proceedings of the 5th International Conference on Learning Representations, Toulon, France, 2017."},{"issue":"27","key":"1375_CR81","first-page":"2579","volume":"9","author":"L J P van der Maaten","year":"2008","unstructured":"L. J. P. van der Maaten, G. E. Hinton. Visualizing high-dimensional data using t-SNE. Journal of Machine Learning Research, vol. 9, no. 27, pp. 2579\u20132605, 2008.","journal-title":"Journal of Machine Learning Research"}],"container-title":["Machine Intelligence Research"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11633-022-1375-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s11633-022-1375-7\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11633-022-1375-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,10,22]],"date-time":"2022-10-22T00:12:38Z","timestamp":1666397558000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s11633-022-1375-7"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,9,29]]},"references-count":81,"journal-issue":{"issue":"5","published-print":{"date-parts":[[2022,10]]}},"alternative-id":["1375"],"URL":"https:\/\/doi.org\/10.1007\/s11633-022-1375-7","relation":{},"ISSN":["2731-538X","2731-5398"],"issn-type":[{"value":"2731-538X","type":"print"},{"value":"2731-5398","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,9,29]]},"assertion":[{"value":"9 April 2022","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"6 September 2022","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"29 September 2022","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}