{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T13:03:58Z","timestamp":1777467838054,"version":"3.51.4"},"reference-count":66,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2023,12,15]],"date-time":"2023-12-15T00:00:00Z","timestamp":1702598400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2023,12,15]],"date-time":"2023-12-15T00:00:00Z","timestamp":1702598400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/501100012166","name":"National Key R&D Program of China","doi-asserted-by":"crossref","award":["2022ZD0116310"],"award-info":[{"award-number":["2022ZD0116310"]}],"id":[{"id":"10.13039\/501100012166","id-type":"DOI","asserted-by":"crossref"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62022009"],"award-info":[{"award-number":["62022009"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62206009"],"award-info":[{"award-number":["62206009"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100011347","name":"State Key Laboratory of Software Development Environment","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100011347","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Vis. Intell."],"abstract":"<jats:title>Abstract<\/jats:title><jats:p>Quantization has emerged as an essential technique for deploying deep neural networks (DNNs) on devices with limited resources. However, quantized models exhibit vulnerabilities when exposed to various types of noise in real-world applications. Despite the importance of evaluating the impact of quantization on robustness, existing research on this topic is limited and often disregards established principles of robustness evaluation, resulting in incomplete and inconclusive findings. To address this gap, we thoroughly evaluated the robustness of quantized models against various types of noise (adversarial attacks, natural corruption, and systematic noise) on ImageNet. The comprehensive evaluation results empirically provide valuable insights into the robustness of quantized models in various scenarios. For example: 1) quantized models exhibit higher adversarial robustness than their floating-point counterparts, but are more vulnerable to natural corruption and systematic noise; 2) in general, increasing the quantization bit-width results in a decrease in adversarial robustness, an increase in natural robustness, and an increase in systematic robustness; 3) among corruption methods, impulse noise and glass blur are the most harmful to quantized models, while brightness has the least impact; 4) among different types of systematic noise, the nearest neighbor interpolation has the highest impact, while bilinear interpolation, cubic interpolation, and area interpolation are the three least harmful. Our research contributes to advancing the robust quantization of models and their deployment in real-world scenarios.<\/jats:p>","DOI":"10.1007\/s44267-023-00031-w","type":"journal-article","created":{"date-parts":[[2023,12,15]],"date-time":"2023-12-15T12:03:23Z","timestamp":1702641803000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":17,"title":["RobustMQ: benchmarking robustness of quantized models"],"prefix":"10.1007","volume":"1","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-8227-0052","authenticated-orcid":false,"given":"Yisong","family":"Xiao","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4224-1318","authenticated-orcid":false,"given":"Aishan","family":"Liu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9874-6828","authenticated-orcid":false,"given":"Tianyuan","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7391-7539","authenticated-orcid":false,"given":"Haotong","family":"Qin","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1956-3367","authenticated-orcid":false,"given":"Jinyang","family":"Guo","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7618-3275","authenticated-orcid":false,"given":"Xianglong","family":"Liu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2023,12,15]]},"reference":[{"issue":"6","key":"31_CR1","doi-asserted-by":"publisher","first-page":"84","DOI":"10.1145\/3065386","volume":"60","author":"A. Krizhevsky","year":"2017","unstructured":"Krizhevsky, A., Sutskever, I., & Hinton, G. E. (2017). ImageNet classification with deep convolutional neural networks. Communications of the ACM, 60(6), 84\u201390.","journal-title":"Communications of the ACM"},{"key":"31_CR2","first-page":"5697","volume-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition","author":"Z. Zhao","year":"2022","unstructured":"Zhao, Z., Zhang, J., Xu, S., Lin, Z., & Pfister, H. (2022). Discrete cosine transform network for guided depth map super-resolution. In Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition (pp. 5697\u20135707). Piscataway: IEEE."},{"key":"31_CR3","unstructured":"Bahdanau, D., Cho, K., & Bengio, Y. (2014). Neural machine translation by jointly learning to align and translate. arXiv preprint. arXiv:1409.0473."},{"key":"31_CR4","first-page":"3104","volume-title":"Proceedings of the 28th international conference on neural information processing systems","author":"I. Sutskever","year":"2014","unstructured":"Sutskever, I., Vinyals, O., & Le, Q. V. (2014). Sequence to sequence learning with neural networks. In Z. Ghahramani, M. Welling, C. Cortes, et al. (Eds.), Proceedings of the 28th international conference on neural information processing systems (pp. 3104\u20133112). Red Hook: Curran Associates."},{"issue":"6","key":"31_CR5","doi-asserted-by":"publisher","first-page":"82","DOI":"10.1109\/MSP.2012.2205597","volume":"29","author":"G. Hinton","year":"2012","unstructured":"Hinton, G., Deng, L., Yu, D., Dahl, G. E., Mohamed, A., Jaitly, N., et al. (2012). Deep neural networks for acoustic modeling in speech recognition: the shared views of four research groups. IEEE Signal Processing Magazine, 29(6), 82\u201397.","journal-title":"IEEE Signal Processing Magazine"},{"key":"31_CR6","first-page":"6645","volume-title":"Proceedings of the IEEE international conference on acoustics, speech and signal processing","author":"A. Graves","year":"2013","unstructured":"Graves, A., Mohamed, A., & Hinton, G. (2013). Speech recognition with deep recurrent neural networks. In Proceedings of the IEEE international conference on acoustics, speech and signal processing (pp. 6645\u20136649). Piscataway: IEEE."},{"key":"31_CR7","first-page":"2250","volume-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition","author":"H. Qin","year":"2020","unstructured":"Qin, H., Gong, R., Liu, X., Shen, M., Wei, Z., Yu, F., et al. (2020). Forward and backward information retention for accurate binary neural networks. In Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition (pp. 2250\u20132259). Piscataway: IEEE."},{"key":"31_CR8","first-page":"15658","volume-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition","author":"X. Zhang","year":"2021","unstructured":"Zhang, X., Qin, H., Ding, Y., Gong, R., Yan, Q., Tao, R., et al. (2021). Diversifying sample generation for accurate data-free quantization. In Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition (pp. 15658\u201315667). Piscataway: IEEE."},{"key":"31_CR9","unstructured":"Li, Y., Shen, M., Ma, J., Ren, Y., Zhao, M., Zhang, Q., et\u00a0al. (2021). MQBench: towards reproducible and deployable model quantization benchmark. arXiv preprint. arXiv:2111.03759."},{"key":"31_CR10","unstructured":"Qin, H., Zhang, M., Ding, Y., Li, A., Cai, Z., Liu, Z., et\u00a0al. (2023). BiBench: benchmarking and analyzing network binarization. arXiv preprint. arXiv:2301.11233."},{"key":"31_CR11","unstructured":"Qin, H., Ding, Y., Zhang, M., Yan, Q., Liu, A., Dang, Q., et\u00a0al. (2022). BiBert: accurate fully binarized BERT. arXiv preprint. arXiv:2203.06390."},{"issue":"6","key":"31_CR12","doi-asserted-by":"publisher","first-page":"3659","DOI":"10.1109\/TCSVT.2021.3105820","volume":"32","author":"J. Guo","year":"2021","unstructured":"Guo, J., Liu, J., & Xu, D. (2021). JointPruning: pruning networks along multiple dimensions for efficient point cloud processing. IEEE Transactions on Circuits and Systems for Video Technology, 32(6), 3659\u20133672.","journal-title":"IEEE Transactions on Circuits and Systems for Video Technology"},{"key":"31_CR13","first-page":"1508","volume-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition","author":"J. Guo","year":"2020","unstructured":"Guo, J., Ouyang, W., & Xu, D. (2020). Multi-dimensional pruning: a unified framework for model compression. In Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition (pp. 1508\u20131517). Piscataway: IEEE."},{"key":"31_CR14","first-page":"10885","volume-title":"Proceedings of the AAAI conference on artificial intelligence","author":"J. Guo","year":"2020","unstructured":"Guo, J., Ouyang, W., & Xu, D. (2020). Channel pruning guided by classification loss and feature importance. In F. Rossi, V. Conitzer, & F. Sha (Eds.), Proceedings of the AAAI conference on artificial intelligence (pp. 10885\u201310892). Palo Alto: AAAI Press."},{"issue":"3","key":"31_CR15","doi-asserted-by":"publisher","first-page":"1114","DOI":"10.1109\/TCSVT.2020.2996231","volume":"31","author":"J. Guo","year":"2020","unstructured":"Guo, J., Zhang, W., Ouyang, W., & Xu, D. (2020). Model compression using progressive channel pruning. IEEE Transactions on Circuits and Systems for Video Technology, 31(3), 1114\u20131124.","journal-title":"IEEE Transactions on Circuits and Systems for Video Technology"},{"key":"31_CR16","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2023.3266435","author":"J. Guo","year":"2023","unstructured":"Guo, J., Xu, D., & Ouyang, W. (2023). Multidimensional pruning and its extension: a unified framework for model compression. IEEE Transactions on Neural Networks and Learning Systems. Advance online publication. https:\/\/doi.org\/10.1109\/TNNLS.2023.3266435.","journal-title":"IEEE Transactions on Neural Networks and Learning Systems"},{"key":"31_CR17","doi-asserted-by":"publisher","first-page":"535","DOI":"10.1145\/1150402.1150464","volume-title":"Proceedings of the 12th ACM SIGKDD international conference on knowledge discovery and data mining","author":"C. Bucilu\u01ce","year":"2006","unstructured":"Bucilu\u01ce, C., Caruana, R., & Niculescu-Mizil, A. (2006). Model compression. In T. Eliassi-Rad, L. H. Ungar, M. Craven, et al. (Eds.), Proceedings of the 12th ACM SIGKDD international conference on knowledge discovery and data mining (pp. 535\u2013541). New York: ACM."},{"key":"31_CR18","unstructured":"Hinton, G., Vinyals, O., & Dean, J. (2015). Distilling the knowledge in a neural network. arXiv preprint. arXiv:1503.02531."},{"key":"31_CR19","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2023.109308","volume":"137","author":"J. Guo","year":"2023","unstructured":"Guo, J., Bao, W., Wang, J., Ma, Y., Gao, X., Xiao, G., et al. (2023). A comprehensive evaluation framework for deep model robustness. Pattern Recognition, 137, 109308.","journal-title":"Pattern Recognition"},{"key":"31_CR20","doi-asserted-by":"publisher","first-page":"5769","DOI":"10.1109\/TIP.2021.3082317","volume":"30","author":"A. Liu","year":"2021","unstructured":"Liu, A., Liu, X., Yu, H., Zhang, C., Liu, Q., & Tao, D. (2021). Training robust deep neural networks via adversarial noise propagation. IEEE Transactions on Image Processing, 30, 5769\u20135781.","journal-title":"IEEE Transactions on Image Processing"},{"key":"31_CR21","first-page":"8565","volume-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition","author":"J. Wang","year":"2021","unstructured":"Wang, J., Liu, A., Yin, Z., Liu, S., Tang, S., & Liu, X. (2021). Dual attention suppression attack: generate adversarial camouflage in physical world. In Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition (pp. 8565\u20138574). Piscataway: IEEE."},{"key":"31_CR22","doi-asserted-by":"publisher","first-page":"1291","DOI":"10.1109\/TIP.2020.3042083","volume":"30","author":"C. Zhang","year":"2020","unstructured":"Zhang, C., Liu, A., Liu, X., Xu, Y., Yu, H., Ma, Y., et al. (2020). Interpreting and improving adversarial robustness of deep neural networks with neuron sensitivity. IEEE Transactions on Image Processing, 30, 1291\u20131304.","journal-title":"IEEE Transactions on Image Processing"},{"key":"31_CR23","doi-asserted-by":"publisher","first-page":"829","DOI":"10.1145\/3597926.3598099","volume-title":"Proceedings of the 32nd ACM SIGSOFT international symposium on software testing and analysis","author":"Y. Xiao","year":"2023","unstructured":"Xiao, Y., Liu, A., Li, T., & Liu, X. (2023). Latent imitator: generating natural individual discriminatory instances for black-box fairness testing. In R. Just & G. Fraser (Eds.), Proceedings of the 32nd ACM SIGSOFT international symposium on software testing and analysis (pp. 829\u2013841). New York: ACM."},{"key":"31_CR24","first-page":"12281","volume-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition","author":"Z. Wei","year":"2023","unstructured":"Wei, Z., Chen, J., Wu, Z., & Jiang, Y.-G. (2023). Enhancing the self-universality for transferable targeted attacks. In Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition (pp. 12281\u201312290). Piscataway: IEEE."},{"key":"31_CR25","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-023-01884-w","author":"A. Liu","year":"2023","unstructured":"Liu, A., Tang, S., Liu, X., Chen, X., Huang, L., Qin, H., et al. (2023). Towards defending multiple $\\ell _{p}$-norm bounded adversarial perturbations via gated batch normalization. International Journal of Computer Vision. Advance online publication. https:\/\/doi.org\/10.1007\/s11263-023-01884-w.","journal-title":"International Journal of Computer Vision"},{"key":"31_CR26","first-page":"1028","volume-title":"Proceedings of the AAAI conference on artificial intelligence","author":"A. Liu","year":"2019","unstructured":"Liu, A., Liu, X., Fan, J., Ma, Y., Zhang, A., Xie, H., et al. (2019). Perceptual-sensitive GAN for generating adversarial patches. In P. Stone, P. Van Hentenryck, & Z.-H. Zhou (Eds.), Proceedings of the AAAI conference on artificial intelligence (pp. 1028\u20131035). Palo Alto: AAAI Press."},{"key":"31_CR27","unstructured":"Goodfellow, I. J., Shlens, J., & Szegedy, C. (2014). Explaining and harnessing adversarial examples. arXiv preprint. arXiv:1412.6572."},{"key":"31_CR28","first-page":"3781","volume-title":"The 32nd USENIX security symposium","author":"A. Liu","year":"2023","unstructured":"Liu, A., Guo, J., Wang, J., Liang, S., Tao, R., Zhou, W., et al. (2023). X-ADV: physical adversarial object attacks against X-ray prohibited item detection. In The 32nd USENIX security symposium (pp. 3781\u20133798). Anaheim: USENIX Association."},{"key":"31_CR29","doi-asserted-by":"publisher","first-page":"2055","DOI":"10.1145\/3548606.3560566","volume-title":"Proceedings of the 2022 ACM SIGSAC conference on computer and communications security","author":"S. Liu","year":"2022","unstructured":"Liu, S., Wang, J., Liu, A., Li, Y., Gao, Y., Liu, X., et al. (2022). Harnessing perceptual adversarial patches for crowd counting. In H. Yin, A. Stavrou, C. Cremers, et al. (Ed.), Proceedings of the 2022 ACM SIGSAC conference on computer and communications security (pp. 2055\u20132069). New York: ACM."},{"key":"31_CR30","doi-asserted-by":"publisher","DOI":"10.1016\/j.sysarc.2020.101766","volume":"110","author":"A. Boloor","year":"2020","unstructured":"Boloor, A., Garimella, K., He, X., Gill, C., Vorobeychik, Y., & Zhang, X. (2020). Attacking vision-based perception in end-to-end autonomous driving models. Journal of Systems Architecture, 110, 101766.","journal-title":"Journal of Systems Architecture"},{"key":"31_CR31","unstructured":"Hendrycks, D., & Dietterich, T. (2019). Benchmarking neural network robustness to common corruptions and perturbations. arXiv preprint. arXiv:1903.12261."},{"key":"31_CR32","doi-asserted-by":"publisher","first-page":"42","DOI":"10.1145\/3475724.3483607","volume-title":"Proceedings of the 1st international workshop on adversarial learning for multimedia","author":"Y. Wang","year":"2021","unstructured":"Wang, Y., Li, Y., Gong, R., Xiao, T., & Yu, F. (2021). Real world robustness from systematic noise. In D. Song, D. Tao, A. L. Yuille, et al. (Eds.), Proceedings of the 1st international workshop on adversarial learning for multimedia (pp. 42\u201348). New York: ACM."},{"key":"31_CR33","unstructured":"Tang, S., Gong, R., Wang, Y., Liu, A., Wang, J., Chen, X., et\u00a0al. (2021). RobustART: benchmarking robustness on architecture design and training techniques. arXiv preprint. arXiv:2109.05211."},{"key":"31_CR34","unstructured":"Croce, F., Andriushchenko, M., Sehwag, V., Debenedetti, E., Flammarion, N., & Chiang, M., et\u00a0al. (2020). RobustBench: a standardized adversarial robustness benchmark. arXiv preprint. arXiv:2010.09670."},{"key":"31_CR35","unstructured":"Wang, B., Xu, C., Wang, S., Gan, Z., Cheng, Y., Gao, J., et\u00a0al. (2021). Adversarial glue: a multi-task benchmark for robustness evaluation of language models. arXiv preprint. arXiv:2111.02840."},{"key":"31_CR36","unstructured":"Yi, C., Yang, S., Li, H., Tan, Y.-P., & Kot, A. (2021). Benchmarking the robustness of spatial-temporal models against corruptions. arXiv preprint. arXiv:2110.06513."},{"key":"31_CR37","unstructured":"Zhang, T., Xiao, Y., Zhang, X., Li, H., & Wang, L. (2023). Benchmarking the physical-world adversarial robustness of vehicle detection. arXiv preprint. arXiv:2304.05098."},{"key":"31_CR38","unstructured":"Madry, A., Makelov, A., Schmidt, L., Tsipras, D., & Vladu, A. (2017). Towards deep learning models resistant to adversarial attacks. arXiv preprint. arXiv:1706.06083."},{"key":"31_CR39","first-page":"308","volume-title":"Proceedings of the international conference on cyberworlds","author":"R. Bernhard","year":"2019","unstructured":"Bernhard, R., Moellic, P.-A., & Dutertre, J.-M. (2019). Impact of low-bitwidth quantization on the adversarial robustness for embedded neural networks. In Proceedings of the international conference on cyberworlds (pp. 308\u2013315). Piscataway: IEEE."},{"key":"31_CR40","unstructured":"Lin, J., Gan, C., & Han, S. (2019). Defensive quantization: when efficiency meets robustness. arXiv preprint. arXiv:1904.08444."},{"key":"31_CR41","unstructured":"Alizadeh, M., Behboodi, A., van Baalen, M., Louizos, C., Blankevoort, T., & Welling, M. (2020). Gradient $\\ell _{1}$ regularization for quantization robustness. arXiv preprint. arXiv:2002.07520."},{"key":"31_CR42","unstructured":"Xiao, Y., Zhang, T., Liu, S., & Qin, H. (2023). Benchmarking the robustness of quantized models. arXiv preprint. arXiv:2304.03968."},{"key":"31_CR43","unstructured":"Zhou, S., Wu, Y., Ni, Z., Zhou, X., Wen, H., & DoReFa-Net, Y. Z. (2016). Training low bitwidth convolutional neural networks with low bitwidth gradients. arXiv preprint. arXiv:1606.06160."},{"key":"31_CR44","unstructured":"Choi, J., Wang, Z., Venkataramani, S., I-Jen Chuang, P., Srinivasan, V., & Gopalakrishnan, K. (2018). PACT: parameterized clipping activation for quantized neural networks. arXiv preprint. arXiv:1805.06085."},{"key":"31_CR45","unstructured":"Esser, S. K., McKinstry, J. L., Bablani, D., Rathinakumar, A., & Modha, D. S.. (2019). Learned step size quantization. arXiv preprint. arXiv:1902.08153."},{"key":"31_CR46","first-page":"770","volume-title":"Proceedings of the IEEE conference on computer vision and pattern recognition","author":"K. He","year":"2016","unstructured":"He, K., Zhang, X., Ren, S., & Sun, J. (2016). Deep residual learning for image recognition. In Proceedings of the IEEE conference on computer vision and pattern recognition (pp. 770\u2013778). Piscataway: IEEE."},{"key":"31_CR47","first-page":"10428","volume-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition","author":"I. Radosavovic","year":"2020","unstructured":"Radosavovic, I., Kosaraju, R.P., Girshick, R., He, K., & Doll\u00e1r, P. (2020). Designing network design spaces. In Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition (pp. 10428\u201310436). Piscataway: IEEE."},{"key":"31_CR48","first-page":"4510","volume-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition","author":"M. Sandler","year":"2018","unstructured":"Sandler, M., Howard, A., Zhu, M., Zhmoginov, A., & Chen, L.-C. (2018). MobileNetV2: inverted residuals and linear bottlenecks. In Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition (pp. 4510\u20134520). Piscataway: IEEE."},{"key":"31_CR49","unstructured":"Xiao, Y., Liu, A., Zhang, T., Qin, H., Guo, J., & Liu, X. Robustmq. https:\/\/sites.google.com\/view\/robustmq. Retrieved 17 Sep 2023."},{"key":"31_CR50","doi-asserted-by":"crossref","unstructured":"Gholami, A., Kim, S., Dong, Z., Yao, Z., Mahoney, M. W., & Keutzer, K. (2021). A survey of quantization methods for efficient neural network inference. arXiv preprint. arXiv:2103.13630.","DOI":"10.1201\/9781003162810-13"},{"key":"31_CR51","unstructured":"Li, F., Zhang, B., & Liu, B. (2016). Ternary weight networks. arXiv preprint. arXiv:1605.04711."},{"key":"31_CR52","first-page":"4350","volume-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition","author":"S. Jung","year":"2019","unstructured":"Jung, S., Son, C., Lee, S., Son, J., Han, J.-J., Kwak, Y., et al. (2019). Learning to quantize deep networks by optimizing quantization intervals with task loss. In Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition (pp. 4350\u20134359). Piscataway: IEEE."},{"key":"31_CR53","first-page":"2206","volume-title":"Proceedings of the 37th international conference on machine learning","author":"F. Croce","year":"2020","unstructured":"Croce, F., & Hein, M. (2020). Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks. In D. Blei, H. Daum\u00e9 III, A. Singh, et al. (Eds.), Proceedings of the 37th international conference on machine learning (pp. 2206\u20132216). Stroudsburg: International Machine Learning Society."},{"key":"31_CR54","first-page":"395","volume-title":"Proceedings of the 16th European conference on computer vision","author":"A. Liu","year":"2020","unstructured":"Liu, A., Wang, J., Liu, X., Cao, B., Zhang, C., & Yu, H. (2020). Bias-based universal adversarial patch attack for automatic check-out. In A. Vedaldi, H. Bischof, T. Brox, et al. (Eds.), Proceedings of the 16th European conference on computer vision (pp. 395\u2013410). Cham: Springer."},{"key":"31_CR55","first-page":"122","volume-title":"Proceedings of the 16th European conference on computer vision","author":"A. Liu","year":"2020","unstructured":"Liu, A., Huang, T., Liu, X., Xu, Y., Ma, Y., Chen, X., et al. (2020). Spatiotemporal attacks for embodied agents. In A. Vedaldi, H. Bischof, T. Brox, et al. (Eds.), Proceedings of the 16th European conference on computer vision (pp. 122\u2013138). Cham: Springer."},{"key":"31_CR56","first-page":"2659","volume-title":"Proceedings of the AAAI conference on artificial intelligence","author":"Z. Wei","year":"2022","unstructured":"Wei, Z., Chen, J., Wu, Z., & Jiang, Y.-G. (2022). Boosting the transferability of video adversarial examples via temporal translation. In K. Sycara, V. Honavar, & M. Spaan (Eds.), Proceedings of the AAAI conference on artificial intelligence (pp. 2659\u20132667). Palo Alto: AAAI Press."},{"key":"31_CR57","first-page":"15064","volume-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition","author":"Z. Wei","year":"2022","unstructured":"Wei, Z., Chen, J., Wu, Z., & Jiang, Y.-G. (2022). Cross-modal transferable adversarial attacks from images to videos. In Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition (pp. 15064\u201315073). Piscataway: IEEE."},{"key":"31_CR58","first-page":"2456","volume-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition","author":"J. Wang","year":"2022","unstructured":"Wang, J., Yin, Z., Hu, P., Liu, A., Tao, R., Qin, H., et al. (2022). Defensive patches for robust recognition in the physical world. In Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition (pp. 2456\u20132465). Piscataway: IEEE."},{"key":"31_CR59","first-page":"658","volume-title":"International conference on image analysis and processing","author":"F. Merkle","year":"2022","unstructured":"Merkle, F., Samsinger, M., & Sch\u00f6ttle, P. (2022). Pruning in the face of adversaries. In S. Sclaroff, C. Distante, M. Leo, et al. (Eds.), International conference on image analysis and processing (pp. 658\u2013669). Cham: Springer."},{"key":"31_CR60","unstructured":"Yuan, Z., Liu, J., Wu, J., Yang, D., Wu, Q., Sun, G., et\u00a0al. (2023). Benchmarking the reliability of post-training quantization: a particular focus on worst-case performance. arXiv preprint. arXiv:2303.13003."},{"issue":"2","key":"31_CR61","first-page":"23","volume":"23","author":"P. Umesh","year":"2012","unstructured":"Umesh, P. (2012). Image processing in Python. CSI Communications, 23(2), 23\u201324.","journal-title":"CSI Communications"},{"issue":"11","key":"31_CR62","first-page":"120","volume":"25","author":"G. Bradski","year":"2000","unstructured":"Bradski, G. (2000). The OpenCV library. Dr. Dobb\u2019s Journal of Software Tools for the Professional Programmer, 25(11), 120\u2013123.","journal-title":"Dr. Dobb\u2019s Journal of Software Tools for the Professional Programmer"},{"issue":"146","key":"31_CR63","first-page":"10","volume":"2006","author":"S. Tomar","year":"2006","unstructured":"Tomar, S. (2006). Converting video formats with FFmpeg. Linux Journal, 2006(146), 10.","journal-title":"Linux Journal"},{"key":"31_CR64","first-page":"248","volume-title":"Proceedings of the IEEE conference on computer vision and pattern recognition","author":"J. Deng","year":"2009","unstructured":"Deng, J., Dong, W., Socher, R., Li, L.-J., Li, K., & Li, F.-F. (2009). ImageNet: a large-scale hierarchical image database. In Proceedings of the IEEE conference on computer vision and pattern recognition (pp. 248\u2013255). Piscataway: IEEE."},{"key":"31_CR65","unstructured":"LeCun, Y. The mnist database of handwritten digits. Retrieved September 17, 2023 from http:\/\/yann.lecun.com\/exdb\/mnist\/."},{"key":"31_CR66","unstructured":"Krizhevsky, A., & Hinton, G. (2009). Learning multiple layers of features from tiny images (Technical report). University of Toronto."}],"container-title":["Visual Intelligence"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s44267-023-00031-w.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s44267-023-00031-w\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s44267-023-00031-w.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,12,15]],"date-time":"2023-12-15T12:08:40Z","timestamp":1702642120000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s44267-023-00031-w"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,12,15]]},"references-count":66,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2023,12]]}},"alternative-id":["31"],"URL":"https:\/\/doi.org\/10.1007\/s44267-023-00031-w","relation":{},"ISSN":["2731-9008"],"issn-type":[{"value":"2731-9008","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,12,15]]},"assertion":[{"value":"6 August 2023","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"14 November 2023","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"14 November 2023","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"15 December 2023","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare no competing interests.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"30"}}