{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,11]],"date-time":"2026-02-11T12:36:54Z","timestamp":1770813414799,"version":"3.50.1"},"reference-count":40,"publisher":"Springer Science and Business Media LLC","issue":"4","license":[{"start":{"date-parts":[[2020,2,26]],"date-time":"2020-02-26T00:00:00Z","timestamp":1582675200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2020,2,26]],"date-time":"2020-02-26T00:00:00Z","timestamp":1582675200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"name":"Spanish Ministry of Economy and Business","award":["TIN2017\\82113\\C2\\2\\R"],"award-info":[{"award-number":["TIN2017\\82113\\C2\\2\\R"]}]},{"DOI":"10.13039\/501100011698","name":"Junta de Comunidades de Castilla-La Mancha","doi-asserted-by":"publisher","award":["SBPLY\/17\/180501\/000543"],"award-info":[{"award-number":["SBPLY\/17\/180501\/000543"]}],"id":[{"id":"10.13039\/501100011698","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100010667","name":"H2020 Industrial Leadership","doi-asserted-by":"publisher","award":["732204"],"award-info":[{"award-number":["732204"]}],"id":[{"id":"10.13039\/100010667","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Int. J. Mach. Learn. &amp; Cyber."],"published-print":{"date-parts":[[2020,4]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>Deep learning (henceforth DL) has become most powerful machine learning methodology. Under specific circumstances recognition rates even surpass those obtained by humans. Despite this, several works have shown that deep learning produces outputs that are very far from human responses when confronted with the same task. This the case of the so-called \u201cadversarial examples\u201d (henceforth AE). The fact that such implausible misclassifications exist points to a fundamental difference between machine and human learning. This paper focuses on the possible causes of this intriguing phenomenon. We first argue that the error in adversarial examples is caused by high bias, i.e. by regularization that has local negative effects. This idea is supported by our experiments in which the robustness to adversarial examples is measured with respect to the level of fitting to training samples. Higher fitting was associated to higher robustness to adversarial examples. This ties the phenomenon to the trade-off that exists in machine learning between fitting and generalization.<\/jats:p>","DOI":"10.1007\/s13042-020-01097-4","type":"journal-article","created":{"date-parts":[[2020,2,26]],"date-time":"2020-02-26T06:02:57Z","timestamp":1582696977000},"page":"935-944","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":25,"title":["Robustness to adversarial examples can be improved with overfitting"],"prefix":"10.1007","volume":"11","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-0841-4131","authenticated-orcid":false,"given":"Oscar","family":"Deniz","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Anibal","family":"Pedraza","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Noelia","family":"Vallez","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jesus","family":"Salido","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Gloria","family":"Bueno","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2020,2,26]]},"reference":[{"key":"1097_CR1","doi-asserted-by":"publisher","first-page":"14410","DOI":"10.1109\/ACCESS.2018.2807385","volume":"6","author":"N Akhtar","year":"2018","unstructured":"Akhtar N, Mian AS (2018) Threat of adversarial attacks on deep learning in computer vision: a survey. IEEE Access 6:14410\u201314430","journal-title":"IEEE Access"},{"key":"1097_CR2","unstructured":"Athalye A, Engstrom L, Ilyas A, Kwok K (2017) Synthesizing robust adversarial examples. CoRR. arXiv:1707.07397"},{"key":"1097_CR3","unstructured":"Bortolussi L, Sanguinetti G (2018) Intrinsic geometric vulnerability of high-dimensional artificial intelligence. CoRR. arXiv:1811.03571"},{"key":"1097_CR4","unstructured":"Buckman J, Roy A, Raffel C, Goodfellow I (2018) Thermometer encoding: one hot way to resist adversarial examples. https:\/\/openreview.net\/pdf?id=S18Su--CW"},{"key":"1097_CR5","doi-asserted-by":"publisher","unstructured":"Carlini N, Wagner D (2017) Towards evaluating the robustness of neural networks. In: 2017 IEEE symposium on security and privacy (SP), pp 39\u201357. https:\/\/doi.org\/10.1109\/SP.2017.49","DOI":"10.1109\/SP.2017.49"},{"key":"1097_CR6","unstructured":"Chakraborty A, Alam M, Dey V, Chattopadhyay A, Mukhopadhyay D (2018) Adversarial attacks and defences: a survey. CoRR arXiv:1810.00069"},{"key":"1097_CR7","unstructured":"Chen, J., Jordan, M.I., Wainwright, M.J., (2019) HopSkipJumpAttack: a query-efficient decision-based adversarial attack. arXiv preprint arXiv:1904.02144"},{"key":"1097_CR8","doi-asserted-by":"crossref","unstructured":"Deniz O, Vallez N, Bueno G (2019) Adversarial examples are a manifestation of the fitting-generalization trade-off. In: Int. work-conference on artificial neural networks (IWANN)","DOI":"10.1007\/978-3-030-20521-8_47"},{"key":"1097_CR9","unstructured":"Evtimov I, Eykholt K, Fernandes E, Kohno T, Li B, Prakash A, Rahmati A, Song D (2017) Robust physical-world attacks on machine learning models. CoRR. arXiv:1707.08945"},{"key":"1097_CR10","unstructured":"Fawzi A, Fawzi O, Frossard P (2015) Fundamental limits on adversarial robustness. Proceedings of ICML, workshop on deep learning. http:\/\/infoscience.epfl.ch\/record\/214923"},{"key":"1097_CR11","unstructured":"Fawzi A, Moosavi-Dezfooli S, Frossard P (2016) Robustness of classifiers: from adversarial to random noise. CoRR. arXiv:1608.08967"},{"key":"1097_CR12","unstructured":"Gilmer J, Metz L, Faghri F, Schoenholz SS, Raghu M, Wattenberg M, Goodfellow IJ (2018) Adversarial spheres. CoRR. arXiv:1801.02774"},{"key":"1097_CR13","unstructured":"Goodfellow IJ, Shlens J, Szegedy C (2014) Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572"},{"key":"1097_CR14","doi-asserted-by":"crossref","unstructured":"He K, Zhang X, Ren S, Sun J (2015) Delving deep into rectifiers: Surpassing human-level performance on imagenet classification. CoRR. arXiv:1502.01852. http:\/\/dblp.uni-trier.de\/db\/journals\/corr\/corr1502.html#HeZR015","DOI":"10.1109\/ICCV.2015.123"},{"key":"1097_CR15","unstructured":"Inkawhich N, Inkawhich M, Chen Y, Li H (2018) Adversarial attacks for optical flow-based action recognition classifiers. CoRR. arXiv:1811.11875"},{"key":"1097_CR16","unstructured":"Krizhevsky A, Nair V, Hinton G CIFAR-10 (Canadian Institute for Advanced Research). http:\/\/www.cs.toronto.edu\/~kriz\/cifar.html"},{"key":"1097_CR17","unstructured":"Krizhevsky A, Sutskever I, Hinton GE (2012) Imagenet classification with deep convolutional neural networks. In: Proceedings of the 25th international conference on neural information processing systems\u2014volume 1, NIPS\u201912, pp 1097\u20131105. Curran Associates Inc., USA. http:\/\/dl.acm.org\/citation.cfm?id=2999134.2999257"},{"key":"1097_CR18","unstructured":"LeCun Y, Cortes C (2010) MNIST handwritten digit database. http:\/\/yann.lecun.com\/exdb\/mnist\/"},{"key":"1097_CR19","doi-asserted-by":"publisher","unstructured":"Liu X, Zhang J, Lin Y, Li H (2019) Atmpa: Attacking machine learning-based malware visualization detection methods via adversarial examples. In: Proceedings of the international symposium on quality of service, IWQoS \u201919, pp. 38:1\u201338:10. ACM, New York, NY, USA. https:\/\/doi.org\/10.1145\/3326285.3329073","DOI":"10.1145\/3326285.3329073"},{"key":"1097_CR20","doi-asserted-by":"crossref","unstructured":"Melis M, Demontis A, Biggio B, Brown G, Fumera G, Roli F (2017) Is deep learning safe for robot vision? adversarial examples against the icub humanoid. CoRR. arXiv:1708.06939","DOI":"10.1109\/ICCVW.2017.94"},{"key":"1097_CR21","doi-asserted-by":"crossref","unstructured":"Meng D, Chen H (2017) Magnet: a two-pronged defense against adversarial examples. CoRR. arXiv:1705.09064","DOI":"10.1145\/3133956.3134057"},{"key":"1097_CR22","unstructured":"Moosavi-Dezfooli S, Fawzi A, Frossard P (2015) Deepfool: a simple and accurate method to fool deep neural networks. CoRR. arXiv:1511.04599"},{"key":"1097_CR23","doi-asserted-by":"crossref","unstructured":"Nguyen AM, Yosinski J, Clune J (2015) Deep neural networks are easily fooled: high confidence predictions for unrecognizable images. In: CVPR, pp 427\u2013436. IEEE Computer Society. http:\/\/dblp.uni-trier.de\/db\/conf\/cvpr\/cvpr2015.html#NguyenYC15","DOI":"10.1109\/CVPR.2015.7298640"},{"key":"1097_CR24","unstructured":"Papernot N, McDaniel P, Goodfellow I (2016) Transferability in machine learning: from phenomena to black-box attacks using adversarial samples. arXiv preprint arXiv:1605.07277"},{"key":"1097_CR25","doi-asserted-by":"publisher","first-page":"85","DOI":"10.1016\/j.neunet.2014.09.003","volume":"61","author":"J\u00fcrgen Schmidhuber","year":"2015","unstructured":"Schmidhuber J (2015) Deep learning in neural networks: an overview. Neural Networks 61:85\u2013117. https:\/\/doi.org\/10.1016\/j.neunet.2014.09.003. http:\/\/www.sciencedirect.com\/science\/article\/pii\/S0893608014002135","journal-title":"Neural Networks"},{"key":"1097_CR26","unstructured":"Schmidt L, Santurkar S, Tsipras D, Talwar K, Madry A (2018) Adversarially robust generalization requires more data. CoRR. arXiv:1804.11285"},{"key":"1097_CR27","unstructured":"Serban AC, Poll E (2018) Adversarial examples: a complete characterisation of the phenomenon. CoRR. arXiv:1810.01185"},{"key":"1097_CR28","unstructured":"Shafahi A, Huang WR, Studer C, Feizi S, Goldstein T (2018) Are adversarial examples inevitable? CoRR. arXiv:1809.02104"},{"key":"1097_CR29","unstructured":"Shamir A, Safran I, Ronen E, Dunkelman O (2019) A simple explanation for the existence of adversarial examples with small hamming distance. CoRR. arXiv:1901.10861"},{"key":"1097_CR30","unstructured":"Simon-Gabriel CJ, Ollivier Y, Sch\u00f6lkopf B, Bottou L, Lopez-Paz D (2018) Adversarial vulnerability of neural networks increases with input dimension. CoRR. arXiv:1802.01421"},{"key":"1097_CR31","doi-asserted-by":"crossref","unstructured":"Su D, Zhang H, Chen H, Yi J, Chen P, Gao Y (2018) Is robustness the cost of accuracy?\u2014a comprehensive study on the robustness of 18 deep image classification models. CoRR. arXiv:1808.01688","DOI":"10.1007\/978-3-030-01258-8_39"},{"key":"1097_CR32","unstructured":"Szegedy C, Zaremba W, Sutskever I, Bruna J, Erhan D, Goodfellow IJ, Fergus R (2013) Intriguing properties of neural networks. CoRR. arXiv:1312.6199. http:\/\/dblp.uni-trier.de\/db\/journals\/corr\/corr1312.html#SzegedyZSBEGF13"},{"key":"1097_CR33","doi-asserted-by":"crossref","unstructured":"Tabacof P, Valle E (2016) Exploring the space of adversarial images. In: 2016 international joint conference on neural networks (IJCNN), pp 426\u2013433","DOI":"10.1109\/IJCNN.2016.7727230"},{"key":"1097_CR34","doi-asserted-by":"crossref","unstructured":"Taigman Y, Yang M, Ranzato M, Wolf L (2014) Deepface: closing the gap to human-level performance in face verification. In: Conference on computer vision and pattern recognition (CVPR)","DOI":"10.1109\/CVPR.2014.220"},{"key":"1097_CR35","unstructured":"Tanay T, Griffin LD (2016) A boundary tilting persepective on the phenomenon of adversarial examples. CoRR. arXiv:1608.07690"},{"key":"1097_CR36","unstructured":"Tsipras D, Santurkar S, Engstrom L, Turner A, Madry A (2019) Robustness may be at odds with accuracy. In: International conference on learning representations. https:\/\/openreview.net\/forum?id=SyxAb30cY7"},{"key":"1097_CR37","unstructured":"Xu W, Evans D, Qi Y (2017) Feature squeezing: Detecting adversarial examples in deep neural networks. CoRR. arXiv:1704.01155"},{"key":"1097_CR38","unstructured":"Yuille AL, Liu C (2018) Deep nets: What have they ever done for vision? CoRR. arXiv:1805.04025"},{"key":"1097_CR39","unstructured":"Zhang C, Bengio S, Hardt M, Recht B, Vinyals O (2017) Understanding deep learning requires rethinking generalization. arXiv:1611.03530"},{"key":"1097_CR40","doi-asserted-by":"publisher","unstructured":"Zhang J, Li C (2019) Adversarial examples: opportunities and challenges. IEEE Trans Neural Netw Learn Syst. https:\/\/doi.org\/10.1109\/TNNLS.2019.2933524","DOI":"10.1109\/TNNLS.2019.2933524"}],"container-title":["International Journal of Machine Learning and Cybernetics"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s13042-020-01097-4.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s13042-020-01097-4\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s13042-020-01097-4.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,2,25]],"date-time":"2021-02-25T00:41:03Z","timestamp":1614213663000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s13042-020-01097-4"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,2,26]]},"references-count":40,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2020,4]]}},"alternative-id":["1097"],"URL":"https:\/\/doi.org\/10.1007\/s13042-020-01097-4","relation":{},"ISSN":["1868-8071","1868-808X"],"issn-type":[{"value":"1868-8071","type":"print"},{"value":"1868-808X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,2,26]]},"assertion":[{"value":"2 September 2019","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"30 January 2020","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"26 February 2020","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}