{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,18]],"date-time":"2026-02-18T23:47:18Z","timestamp":1771458438498,"version":"3.50.1"},"reference-count":38,"publisher":"Springer Science and Business Media LLC","issue":"4","license":[{"start":{"date-parts":[[2021,10,5]],"date-time":"2021-10-05T00:00:00Z","timestamp":1633392000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2021,10,5]],"date-time":"2021-10-05T00:00:00Z","timestamp":1633392000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/501100003329","name":"Ministerio de Econom\u00eda y Competitividad","doi-asserted-by":"publisher","award":["SBPLY\/17\/180501\/000543"],"award-info":[{"award-number":["SBPLY\/17\/180501\/000543"]}],"id":[{"id":"10.13039\/501100003329","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100014440","name":"Ministerio de Ciencia, Innovaci\u00f3n y Universidades","doi-asserted-by":"publisher","award":["FPU17\/04758"],"award-info":[{"award-number":["FPU17\/04758"]}],"id":[{"id":"10.13039\/100014440","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100007480","name":"Universidad de Castilla la Mancha","doi-asserted-by":"crossref","id":[{"id":"10.13039\/501100007480","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Int. J. Mach. Learn. &amp; Cyber."],"published-print":{"date-parts":[[2022,4]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>The phenomenon of Adversarial Examples has become one of the most intriguing topics associated to deep learning. The so-called adversarial attacks have the ability to fool deep neural networks with inappreciable perturbations. While the effect is striking, it has been suggested that such carefully selected injected noise does not necessarily appear in real-world scenarios. In contrast to this, some authors have looked for ways to generate adversarial noise in physical scenarios (traffic signs, shirts, etc.), thus showing that attackers can indeed fool the networks. In this paper we go beyond that and show that adversarial examples also appear in the real-world without any attacker or maliciously selected noise involved. We show this by using images from tasks related to microscopy and also general object recognition with the well-known ImageNet dataset. A comparison between these natural and the artificially generated adversarial examples is performed using distance metrics and image quality metrics. We also show that the natural adversarial examples are in fact at a higher distance from the originals that in the case of artificially generated adversarial examples.<\/jats:p>","DOI":"10.1007\/s13042-021-01435-0","type":"journal-article","created":{"date-parts":[[2021,10,6]],"date-time":"2021-10-06T02:55:19Z","timestamp":1633488919000},"page":"1065-1077","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":12,"title":["Really natural adversarial examples"],"prefix":"10.1007","volume":"13","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-7748-6756","authenticated-orcid":false,"given":"Anibal","family":"Pedraza","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0841-4131","authenticated-orcid":false,"given":"Oscar","family":"Deniz","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Gloria","family":"Bueno","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2021,10,5]]},"reference":[{"key":"1435_CR1","unstructured":"Szegedy C Zaremba, W Sutskever, I Bruna, J Erhan, D Goodfellow, I Fergus R (2013) Intriguing properties of neural networks. arXiv preprint. arXiv:1312.6199"},{"key":"1435_CR2","unstructured":"Serban AC, Poll E, Visser J (2018) Adversarial examples-a complete characterisation of the phenomenon. arXiv preprint. arXiv:1810.01185"},{"key":"1435_CR3","unstructured":"Goodfellow IJ, Shlens J, Szegedy C (2014) Explaining and harnessing adversarial examples. arXiv preprint. arXiv:1412.6572"},{"key":"1435_CR4","unstructured":"Gilmer J, Adams RP, Goodfellow I, Andersen D, Dahl GE (2018) Motivating the rules of the game for adversarial example research. arXiv preprint. arXiv:1807.06732"},{"key":"1435_CR5","unstructured":"Lu J, Sibai H, Fabry E, Forsyth D (2017) No need to worry about adversarial examples in object detection in autonomous vehicles. arXiv preprint. arXiv:1707.03501"},{"key":"1435_CR6","unstructured":"Kurakin A, Goodfellow I, Bengio S (2016) Adversarial examples in the physical world. arXiv preprint. arXiv:1607.02533"},{"key":"1435_CR7","unstructured":"Zhao Z, Dua D, Singh S (2017) Generating natural adversarial examples. arXiv preprint. arXiv:1710.11342"},{"key":"1435_CR8","doi-asserted-by":"crossref","unstructured":"Hendrycks D, Zhao K, Basart S, Steinhardt J, Song D (2021) Natural adversarial examples. In: Proceedings of the IEEE conference on computer vision and pattern recognition, pp 15262\u201315271","DOI":"10.1109\/CVPR46437.2021.01501"},{"key":"1435_CR9","doi-asserted-by":"crossref","unstructured":"Moosavi-Dezfooli SM, Fawzi A, Frossard P (2016) Deepfool: a simple and accurate method to fool deep neural networks. In: Proceedings of the IEEE conference on computer vision and pattern recognition, pp 2574\u20132582","DOI":"10.1109\/CVPR.2016.282"},{"key":"1435_CR10","doi-asserted-by":"crossref","unstructured":"Carlini N, Wagner D (2017) Towards evaluating the robustness of neural networks. In: 2017 IEEE symposium on security and privacy (sp), IEEE, pp 39\u201357","DOI":"10.1109\/SP.2017.49"},{"key":"1435_CR11","doi-asserted-by":"crossref","unstructured":"Chen J, Jordan MI, Wainwright MJ (2019) Hopskipjumpattack: a query-efficient decision-based attack. arXiv preprint, vol 3. arXiv:1904.02144","DOI":"10.1109\/SP40000.2020.00045"},{"key":"1435_CR12","unstructured":"Li X, Li J, Dai T, Shi J, Zhu J, Hu X (2021) Rethinking natural adversarial examples for classification models. arXiv preprint. arXiv:2102.11731"},{"key":"1435_CR13","unstructured":"Engstrom L, Tran B, Tsipras D, Schmidt L, Madry A (2019) Exploring the landscape of spatial robustness. In: International conference on machine learning, pp 1802\u20131811"},{"key":"1435_CR14","unstructured":"Athalye A,n Engstrom L, Ilyas A, Kwok K (2017) Synthesizing robust adversarial examples. arXiv preprint. arXiv:1707.07397"},{"key":"1435_CR15","unstructured":"Tram\u00e8r F, Kurakin A, Papernot N, Goodfellow I, Boneh D, McDaniel P (2017) Ensemble adversarial training: attacks and defenses. arXiv preprint. arXiv:1705.07204"},{"key":"1435_CR16","unstructured":"Athalye A, Carlini N, Wagner D (2018) Obfuscated gradients give a false sense of security: circumventing defenses to adversarial examples. In: International conference on machine learning, PMLR, pp 274\u2013283"},{"key":"1435_CR17","unstructured":"Carlini N, Athalye A, Papernot N, Brendel W, Rauber J, Tsipras D, Goodfellow I, Madry A, Kurakin A (2019) On evaluating adversarial robustness. arXiv preprint. arXiv:1902.06705"},{"key":"1435_CR18","doi-asserted-by":"crossref","unstructured":"Fezza SA, Bakhti Y, Hamidouche W, D\u00e9forges O (2019) Perceptual evaluation of adversarial attacks for cnn-based image classification. In: 2019 Eleventh international conference on quality of multimedia experience (QoMEX), IEEE, pp 1\u20136","DOI":"10.1109\/QoMEX.2019.8743213"},{"key":"1435_CR19","unstructured":"Jordan M, Manoj N, Goel S, Dimakis AG (2019) Quantifying perceptual distortion of adversarial examples. arXiv preprint. arXiv:1902.08265"},{"key":"1435_CR20","doi-asserted-by":"crossref","unstructured":"Jefferson B, Marrero CO (2019) Robustness metrics for real-world adversarial examples. arXiv preprint. arXiv:1911.10435","DOI":"10.1109\/CVPRW50498.2020.00404"},{"issue":"3","key":"1435_CR21","doi-asserted-by":"publisher","first-page":"8","DOI":"10.4236\/jcc.2019.73002","volume":"7","author":"U Sara","year":"2019","unstructured":"Sara U, Akter M, Uddin MS (2019) Image quality assessment through fsim, ssim, mse and psnr\u2013a comparative study. J Comput Commun 7(3):8\u201318","journal-title":"J Comput Commun"},{"key":"1435_CR22","doi-asserted-by":"crossref","unstructured":"Hosseini H, Xiao B, Poovendran R (2017) Google\u2019s cloud vision api is not robust to noise. In: 2017 16th IEEE international conference on machine learning and applications (ICMLA), IEEE, pp 101\u2013105","DOI":"10.1109\/ICMLA.2017.0-172"},{"key":"1435_CR23","doi-asserted-by":"publisher","first-page":"100199","DOI":"10.1016\/j.cosrev.2019.100199","volume":"34","author":"N Pitropakis","year":"2019","unstructured":"Pitropakis N, Panaousis E, Giannetsos T, Anastasiadis E, Loukas G (2019) A taxonomy and survey of attacks against machine learning. Comput Sci Rev 34:100199","journal-title":"Comput Sci Rev"},{"key":"1435_CR24","unstructured":"Directive WF (2003) Common implementation strategy for the water framework directive (2000\/60\/ec). Guidance document (7)"},{"key":"1435_CR25","doi-asserted-by":"publisher","first-page":"103271","DOI":"10.1016\/j.engappai.2019.103271","volume":"87","author":"J Ruiz-Santaquiteria","year":"2020","unstructured":"Ruiz-Santaquiteria J, Bueno G, Deniz O, Vallez N, Cristobal G (2020) Semantic versus instance segmentation in microscopic algae detection. Eng Appl Artif Intell 87:103271","journal-title":"Eng Appl Artif Intell"},{"key":"1435_CR26","doi-asserted-by":"crossref","unstructured":"Redmon J, Farhadi A (2017) Yolo9000: better, faster, stronger. In: Proceedings of the IEEE conference on computer vision and pattern recognition, pp 7263\u20137271","DOI":"10.1109\/CVPR.2017.690"},{"key":"1435_CR27","doi-asserted-by":"crossref","unstructured":"Deng J, Dong W, Socher R, Li LJ, Li K, Fei-Fei L (2009) Imagenet: a large-scale hierarchical image database. In: 2009 IEEE conference on computer vision and pattern recognition, IEEE, pp 248\u2013255","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"1435_CR28","doi-asserted-by":"crossref","unstructured":"Szegedy C, Liu W, Jia Y, Sermanet P, Reed S, Anguelov D, Erhan D, Vanhoucke V, Rabinovich A (2015) Going deeper with convolutions. In: Proceedings of the IEEE conference on computer vision and pattern recognition, pp 1\u20139","DOI":"10.1109\/CVPR.2015.7298594"},{"key":"1435_CR29","unstructured":"Simonyan K, Zisserman A (2014) Very deep convolutional networks for large-scale image recognition. arXiv preprint. arXiv:1409.1556"},{"key":"1435_CR30","doi-asserted-by":"crossref","unstructured":"He K, Zhang X, Ren S, Sun J (2016) Deep residual learning for image recognition. In: Proceedings of the IEEE conference on computer vision and pattern recognition, pp 770\u2013778","DOI":"10.1109\/CVPR.2016.90"},{"key":"1435_CR31","doi-asserted-by":"crossref","unstructured":"Redmon J, Divvala S, Girshick R, Farhadi A (2016) You only look once: unified, real-time object detection. In: Proceedings of the IEEE conference on computer vision and pattern recognition, pp 779\u2013788","DOI":"10.1109\/CVPR.2016.91"},{"key":"1435_CR32","doi-asserted-by":"crossref","unstructured":"Chollet F (2017) Xception: deep learning with depthwise separable convolutions. In: Proceedings of the IEEE conference on computer vision and pattern recognition, pp 1251\u20131258","DOI":"10.1109\/CVPR.2017.195"},{"key":"1435_CR33","doi-asserted-by":"crossref","unstructured":"Wang Z, Bovik AC, Lu L (2002) Why is image quality assessment so difficult? In: 2002 IEEE international conference on acoustics, speech, and signal processing, vol\u00a04, IEEE, pp IV\u20133313","DOI":"10.1109\/ICASSP.2002.5745362"},{"issue":"12","key":"1435_CR34","doi-asserted-by":"publisher","first-page":"2959","DOI":"10.1109\/26.477498","volume":"43","author":"AM Eskicioglu","year":"1995","unstructured":"Eskicioglu AM, Fisher PS (1995) Image quality measures and their performance. IEEE Trans Commun 43(12):2959\u20132965","journal-title":"IEEE Trans Commun"},{"issue":"4","key":"1435_CR35","doi-asserted-by":"publisher","first-page":"600","DOI":"10.1109\/TIP.2003.819861","volume":"13","author":"Z Wang","year":"2004","unstructured":"Wang Z, Bovik AC, Sheikh HR, Simoncelli EP (2004) Image quality assessment: from error visibility to structural similarity. IEEE Trans Image Process 13(4):600\u2013612","journal-title":"IEEE Trans Image Process"},{"issue":"12","key":"1435_CR36","doi-asserted-by":"publisher","first-page":"2117","DOI":"10.1109\/TIP.2005.859389","volume":"14","author":"HR Sheikh","year":"2005","unstructured":"Sheikh HR, Bovik AC, De Veciana G (2005) An information fidelity criterion for image quality assessment using natural scene statistics. IEEE Trans Image Process 14(12):2117\u20132128","journal-title":"IEEE Trans Image Process"},{"issue":"2","key":"1435_CR37","doi-asserted-by":"publisher","first-page":"430","DOI":"10.1109\/TIP.2005.859378","volume":"15","author":"HR Sheikh","year":"2006","unstructured":"Sheikh HR, Bovik AC (2006) Image information and visual quality. IEEE Trans Image Process 15(2):430\u2013444","journal-title":"IEEE Trans Image Process"},{"issue":"1","key":"1435_CR38","doi-asserted-by":"publisher","first-page":"11006","DOI":"10.1117\/1.3267105","volume":"19","author":"EC Larson","year":"2010","unstructured":"Larson EC, Chandler DM (2010) Most apparent distortion: full-reference image quality assessment and the role of strategy. J Electron Imaging 19(1):11006","journal-title":"J Electron Imaging"}],"container-title":["International Journal of Machine Learning and Cybernetics"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s13042-021-01435-0.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s13042-021-01435-0\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s13042-021-01435-0.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,3,10]],"date-time":"2022-03-10T07:23:48Z","timestamp":1646897028000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s13042-021-01435-0"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,10,5]]},"references-count":38,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2022,4]]}},"alternative-id":["1435"],"URL":"https:\/\/doi.org\/10.1007\/s13042-021-01435-0","relation":{},"ISSN":["1868-8071","1868-808X"],"issn-type":[{"value":"1868-8071","type":"print"},{"value":"1868-808X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,10,5]]},"assertion":[{"value":"30 April 2020","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"22 September 2021","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"5 October 2021","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}