{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,2,21]],"date-time":"2025-02-21T20:19:36Z","timestamp":1740169176860,"version":"3.37.3"},"reference-count":49,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2019,1,1]],"date-time":"2019-01-01T00:00:00Z","timestamp":1546300800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Access"],"published-print":{"date-parts":[[2019]]},"DOI":"10.1109\/access.2019.2958358","type":"journal-article","created":{"date-parts":[[2019,12,17]],"date-time":"2019-12-17T15:49:21Z","timestamp":1576597761000},"page":"177932-177943","source":"Crossref","is-referenced-by-count":14,"title":["Adversarial Robustness by One Bit Double Quantization for Visual Classification"],"prefix":"10.1109","volume":"7","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-0036-6577","authenticated-orcid":false,"given":"Maungmaung","family":"Aprilpyone","sequence":"first","affiliation":[]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8455-1288","authenticated-orcid":false,"given":"Yuma","family":"Kinoshita","sequence":"additional","affiliation":[]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8061-3090","authenticated-orcid":false,"given":"Hitoshi","family":"Kiya","sequence":"additional","affiliation":[]}],"member":"263","reference":[{"key":"ref39","article-title":"Mitigating adversarial effects through randomization","author":"xie","year":"2017","journal-title":"arXiv 1711 01991"},{"key":"ref38","article-title":"On the robustness of the CVPR 2018 white-box adversarial example defenses","author":"athalye","year":"2018","journal-title":"arXiv 1804 03286"},{"key":"ref33","article-title":"Certified defenses against adversarial examples","author":"raghunathan","year":"2018","journal-title":"arXiv 1801 09344"},{"key":"ref32","article-title":"Provable defenses against adversarial examples via the convex outer adversarial polytope","author":"wong","year":"2017","journal-title":"arXiv 1711 00851"},{"key":"ref31","article-title":"Scaling provable adversarial defenses","author":"wong","year":"2018","journal-title":"arXiv 1805 12514"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.41"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-015-0816-y"},{"key":"ref36","article-title":"Defense against adversarial attacks using high-level representation guided denoiser","author":"liao","year":"2017","journal-title":"arXiv 1712 02976"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00894"},{"key":"ref34","article-title":"A dual approach to scalable verification of deep networks","author":"dvijotham","year":"2018","journal-title":"arXiv 1803 06567"},{"key":"ref28","article-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","author":"athalye","year":"2018","journal-title":"arXiv 1802 00420"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140444"},{"key":"ref29","first-page":"6528","article-title":"Barrage of random transforms for adversarially robust defense","author":"raff","year":"2019","journal-title":"Proc IEEE Conf Comput Vis Pattern Recognit (CVPR)"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813677"},{"key":"ref1","doi-asserted-by":"crossref","first-page":"436","DOI":"10.1038\/nature14539","article-title":"Deep learning","volume":"521","author":"lecun","year":"2015","journal-title":"Nature"},{"key":"ref20","article-title":"Towards deep learning models resistant to adversarial attacks","author":"madry","year":"2017","journal-title":"arXiv 1706 06083"},{"key":"ref22","article-title":"Improving the robustness of neural networks to adversarial examples by reducing color depth of training image data","volume":"118","author":"miyazato","year":"2019"},{"key":"ref21","article-title":"Transferability in machine learning: From phenomena to black-box attacks using adversarial samples","author":"papernot","year":"2016","journal-title":"arXiv 1605 07277"},{"key":"ref24","article-title":"Adversarial examples detection in deep networks with convolutional filter statistics","author":"li","year":"2016","journal-title":"arXiv 1612 07767"},{"journal-title":"A Challenge to Explore Adversarial Robustness of Neural Networks on Cifar10","year":"2019","key":"ref23"},{"key":"ref26","article-title":"Defense-GAN: Protecting classifiers against adversarial attacks using generative models","author":"samangouei","year":"2018","journal-title":"arXiv 1805 06605"},{"key":"ref25","article-title":"Countering adversarial images using input transformations","author":"guo","year":"2017","journal-title":"arXiv 1711 00117"},{"key":"ref10","article-title":"Universal adversarial perturbations","author":"moosavi-dezfooli","year":"2016","journal-title":"arXiv 1610 08401"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2866197"},{"key":"ref40","first-page":"75","article-title":"An adaptive algorithm for spatial greyscale","volume":"17","author":"floyd","year":"1976","journal-title":"Proc Soc Inf Display"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2920410"},{"key":"ref13","article-title":"Adversarial examples in the physical world","author":"kurakin","year":"2016","journal-title":"arXiv 1607 02533"},{"key":"ref14","article-title":"Synthesizing robust adversarial examples","author":"athalye","year":"2017","journal-title":"arXiv 1707 07397"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"ref16","article-title":"Robust physical-world attacks on deep learning models","author":"eykholt","year":"2017","journal-title":"arXiv 1707 08945"},{"key":"ref17","article-title":"Adversarial objects against LiDAR-based autonomous driving systems","author":"cao","year":"2019","journal-title":"arXiv 1907 05418"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1007\/s10994-010-5188-5"},{"key":"ref19","first-page":"6103","article-title":"Poison frogs! Targeted clean-label poisoning attacks on neural networks","author":"shafahi","year":"2018","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref4","article-title":"Explaining and harnessing adversarial examples","author":"goodfellow","year":"2014","journal-title":"arXiv 1412 6572"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref5","article-title":"Adversarial machine learning at scale","author":"kurakin","year":"2016","journal-title":"arXiv 1611 01236"},{"key":"ref8","first-page":"387","article-title":"Evasion attacks against machine learning at test time","author":"biggio","year":"2013","journal-title":"Proc Eur Conf Mach Learn Knowl Discovery Databases"},{"key":"ref7","article-title":"Intriguing properties of neural networks","author":"szegedy","year":"2013","journal-title":"arXiv 1312 6199"},{"key":"ref49","article-title":"A disciplined approach to neural network hyper-parameters: Part 1&#x2014;Learning rate, batch size, momentum, and weight decay","author":"smith","year":"2018","journal-title":"arXiv 1803 09820"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/D17-1215"},{"journal-title":"FASTA","year":"2018","author":"howard","key":"ref46"},{"key":"ref45","article-title":"Automatic differentiation in PyTorch","author":"paszke","year":"2017","journal-title":"Proc NIPS Autodiff Workshop"},{"key":"ref48","article-title":"Decoupled weight decay regularization","author":"loshchilov","year":"2017","journal-title":"arXiv 1711 05101"},{"key":"ref47","article-title":"Do better ImageNet models transfer better?","author":"kornblith","year":"2018","journal-title":"arXiv 1805 08974"},{"article-title":"Learning multiple layers of features from tiny images","year":"2009","author":"krizhevsky","key":"ref42"},{"key":"ref41","article-title":"Natural adversarial examples","author":"hendrycks","year":"2019","journal-title":"arXiv 1907 07174"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2012.6248092"}],"container-title":["IEEE Access"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/6287639\/8600701\/08928531.pdf?arnumber=8928531","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,1,12]],"date-time":"2022-01-12T11:31:23Z","timestamp":1641987083000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/8928531\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019]]},"references-count":49,"URL":"https:\/\/doi.org\/10.1109\/access.2019.2958358","relation":{},"ISSN":["2169-3536"],"issn-type":[{"type":"electronic","value":"2169-3536"}],"subject":[],"published":{"date-parts":[[2019]]}}}