{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,5]],"date-time":"2026-06-05T04:58:28Z","timestamp":1780635508426,"version":"3.54.1"},"reference-count":27,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"},{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"am","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"funder":[{"DOI":"10.13039\/100000185","name":"United States Department of Defense, Defense Advanced Research Projects Agency","doi-asserted-by":"publisher","award":["HR00112020011"],"award-info":[{"award-number":["HR00112020011"]}],"id":[{"id":"10.13039\/100000185","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000183","name":"Army Research Office","doi-asserted-by":"publisher","award":["W911NF-15-1-0479"],"award-info":[{"award-number":["W911NF-15-1-0479"]}],"id":[{"id":"10.13039\/100000183","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000183","name":"Department of Energy National Nuclear Security Administration","doi-asserted-by":"publisher","award":["DE-NA0003921"],"award-info":[{"award-number":["DE-NA0003921"]}],"id":[{"id":"10.13039\/100000183","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Access"],"published-print":{"date-parts":[[2022]]},"DOI":"10.1109\/access.2022.3209243","type":"journal-article","created":{"date-parts":[[2022,9,26]],"date-time":"2022-09-26T20:39:19Z","timestamp":1664224759000},"page":"103074-103088","source":"Crossref","is-referenced-by-count":5,"title":["ASK: Adversarial Soft k-Nearest Neighbor Attack and Defense"],"prefix":"10.1109","volume":"10","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-6366-8898","authenticated-orcid":false,"given":"Ren","family":"Wang","sequence":"first","affiliation":[{"name":"Department of Electrical Engineering and Computer Science, University of Michigan, Ann Arbor, MI, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3604-3048","authenticated-orcid":false,"given":"Tianqi","family":"Chen","sequence":"additional","affiliation":[{"name":"Department of Statistics, University of Michigan, Ann Arbor, MI, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Philip","family":"Yao","sequence":"additional","affiliation":[{"name":"Department of Electrical Engineering and Computer Science, University of Michigan, Ann Arbor, MI, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Sijia","family":"Liu","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Engineering, Michigan State University, East Lansing, MI, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6160-9168","authenticated-orcid":false,"given":"Indika","family":"Rajapakse","sequence":"additional","affiliation":[{"name":"Department of Computational Medicine and Bioinformatics, University of Michigan, Ann Arbor, MI, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2531-9670","authenticated-orcid":false,"given":"Alfred O.","family":"Hero","sequence":"additional","affiliation":[{"name":"Department of Electrical Engineering and Computer Science, University of Michigan, Ann Arbor, MI, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.1967.1053964"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.2973763"},{"key":"ref3","first-page":"1","article-title":"An adaptive nearest neighbor rule for classification","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"32","author":"Balsubramani"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2944253"},{"key":"ref5","first-page":"1","article-title":"Nearest neighbor machine translation","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Khandelwal"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP40776.2020.9053504"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW.2017.11"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1201\/9781351251389-8"},{"key":"ref9","article-title":"Intriguing properties of neural networks","author":"Szegedy","year":"2013","journal-title":"arXiv:1312.6199"},{"key":"ref10","article-title":"Deep k-nearest neighbors: Towards confident, interpretable and robust deep learning","author":"Papernot","year":"2018","journal-title":"arXiv:1803.04765"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2022.3153036"},{"key":"ref12","first-page":"540","article-title":"Deep k-NN for noisy labels","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Bahri"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2019.00014"},{"key":"ref14","article-title":"AdvKnn: Adversarial attacks on K-nearest neighbor classifiers with approximate gradients","author":"Li","year":"2019","journal-title":"arXiv:1911.06591"},{"key":"ref15","article-title":"Towards deep learning models resistant to adversarial attacks","author":"Madry","year":"2017","journal-title":"arXiv:1706.06083"},{"key":"ref16","first-page":"7472","article-title":"Theoretically principled trade-off between robustness and accuracy","volume-title":"Proc. 36th Int. Conf. Mach. Learn.","author":"Zhang"},{"key":"ref17","first-page":"1087","article-title":"Neural nearest neighbors networks","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"31","author":"Pl\u00f6tz"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/ALLERTON.2018.8636048"},{"key":"ref19","first-page":"2012","article-title":"Analyzing and improving representations with the soft nearest neighbor loss","volume-title":"Proc. 36th Int. Conf. Mach. Learn.","author":"Frosst"},{"key":"ref20","first-page":"1597","article-title":"A simple framework for contrastive learning of visual representations","volume-title":"Proc. 37th Int. Conf. Mach. Learn.","author":"Chen"},{"key":"ref21","first-page":"1857","article-title":"Improved deep metric learning with multi-class N-pair loss objective","volume-title":"Proc. 30th Int. Conf. Neural Inf. Process. Syst.","author":"Sohn"},{"key":"ref22","article-title":"Representation learning with contrastive predictive coding","author":"van den Oord","year":"2018","journal-title":"arXiv:1807.03748"},{"key":"ref23","volume-title":"Deep Learning","volume":"1","author":"Bengio","year":"2017"},{"key":"ref24","first-page":"1","article-title":"Advantages of exploiting projection structure for segmenting dense 3D point clouds","volume-title":"Proc. Austral. Conf. Robot. Autom.","volume":"2","author":"Bewley"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1017\/CBO9781139058452"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"key":"ref27","article-title":"Fashion-MNIST: A novel image dataset for benchmarking machine learning algorithms","author":"Xiao","year":"2017","journal-title":"arXiv:1708.07747"}],"container-title":["IEEE Access"],"original-title":[],"link":[{"URL":"https:\/\/ieeexplore.ieee.org\/ielam\/6287639\/9668973\/9902964-aam.pdf","content-type":"application\/pdf","content-version":"am","intended-application":"syndication"},{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/6287639\/9668973\/09902964.pdf?arnumber=9902964","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,1,22]],"date-time":"2024-01-22T23:17:04Z","timestamp":1705965424000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9902964\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022]]},"references-count":27,"URL":"https:\/\/doi.org\/10.1109\/access.2022.3209243","relation":{},"ISSN":["2169-3536"],"issn-type":[{"value":"2169-3536","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022]]}}}