{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,27]],"date-time":"2026-01-27T04:03:32Z","timestamp":1769486612506,"version":"3.49.0"},"reference-count":29,"publisher":"IEEE","license":[{"start":{"date-parts":[[2020,5,1]],"date-time":"2020-05-01T00:00:00Z","timestamp":1588291200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2020,5,1]],"date-time":"2020-05-01T00:00:00Z","timestamp":1588291200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2020,5]]},"DOI":"10.1109\/icassp40776.2020.9052933","type":"proceedings-article","created":{"date-parts":[[2020,4,9]],"date-time":"2020-04-09T20:21:13Z","timestamp":1586463673000},"page":"2438-2442","source":"Crossref","is-referenced-by-count":8,"title":["Learning to Characterize Adversarial Subspaces"],"prefix":"10.1109","author":[{"given":"Xiaofeng","family":"Mao","sequence":"first","affiliation":[{"name":"Alibaba Group,China"}]},{"given":"Yuefeng","family":"Chen","sequence":"additional","affiliation":[{"name":"Alibaba Group,China"}]},{"given":"Yuhong","family":"Li","sequence":"additional","affiliation":[{"name":"Alibaba Group,China"}]},{"given":"Yuan","family":"He","sequence":"additional","affiliation":[{"name":"Alibaba Group,China"}]},{"given":"Hui","family":"Xue","sequence":"additional","affiliation":[{"name":"Alibaba Group,China"}]}],"member":"263","reference":[{"key":"ref10","article-title":"Characterizing adversarial subspaces using local intrinsic dimensionality","author":"ma","year":"2018","journal-title":"arXiv preprint arXiv 1801 02929"},{"key":"ref11","first-page":"1632","article-title":"Robustness of classifiers: from adversarial to random noise","author":"fawzi","year":"2016","journal-title":"Advances in neural information processing systems"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00496"},{"key":"ref13","article-title":"Detecting adversarial samples from artifacts","author":"feinman","year":"2017","journal-title":"arXiv preprint arXiv 1703 00410"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-68474-1_5"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/ICDMW.2012.94"},{"key":"ref16","first-page":"0","article-title":"Adversarial examples detection in features distance spaces","author":"carrara","year":"2018","journal-title":"Proceedings of the European Conference on Computer Vision (ECCV)"},{"key":"ref17","first-page":"7167","article-title":"A simple unified framework for detecting out-of-distribution samples and adversarial attacks","author":"lee","year":"2018","journal-title":"Advances in neural information processing systems"},{"key":"ref18","article-title":"Adversarial machine learning at scale","author":"kurakin","year":"2016","journal-title":"arXiv preprint arXiv 1611 01236"},{"key":"ref19","first-page":"2574","article-title":"Deepfool: a simple and accurate method to fool deep neural networks","author":"moosavi-dezfooli","year":"2016","journal-title":"Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition"},{"key":"ref28","article-title":"Practical blackbox attacks against deep learning systems using adversarial examples. eprint","author":"papernot","year":"2016","journal-title":"arXiv preprint arXiv 1602 04875"},{"key":"ref4","first-page":"5998","article-title":"Attention is all you need","author":"vaswani","year":"2017","journal-title":"Advances in neural information processing systems"},{"key":"ref3","doi-asserted-by":"crossref","first-page":"6645","DOI":"10.1109\/ICASSP.2013.6638947","article-title":"Speech recognition with deep recurrent neural networks","author":"graves","year":"2013","journal-title":"2013 IEEE International Conference on Acoustics Speech and Signal Processing"},{"key":"ref27","first-page":"1929","article-title":"Dropout: a simple way to prevent neural networks from overfitting","volume":"15","author":"srivastava","year":"2014","journal-title":"The Journal of Machine Learning Research"},{"key":"ref6","article-title":"Explaining and harnessing adversarial examples","author":"goodfellow","year":"2014","journal-title":"arXiv preprint arXiv 1412 6572"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2019.00014"},{"key":"ref5","article-title":"Intriguing properties of neural networks","author":"szegedy","year":"2013","journal-title":"arXiv preprint arXiv 1312 6199"},{"key":"ref8","article-title":"Advhat: Real-world adversarial attack on arcface face id system","author":"komkov","year":"2019","journal-title":"arXiv preprint arXiv 1908 00310"},{"key":"ref7","article-title":"Physical adversarial examples for object detectors","author":"song","year":"2018","journal-title":"12th USENIX Workshop on Offensive Technologies (WOOT 18)"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref1","first-page":"1097","article-title":"Imagenet classification with deep convolutional neural networks","author":"krizhevsky","year":"2012","journal-title":"Advances in neural information processing systems"},{"key":"ref9","article-title":"The space of transferable adversarial examples","author":"tram\u00e8r","year":"2017","journal-title":"arXiv preprint arXiv 1704 03453"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref21","article-title":"Learning multiple layers of features from tiny images","author":"krizhevsky","year":"2009","journal-title":"Tech Rep"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140444"},{"key":"ref23","article-title":"On detecting adversarial perturbations","author":"metzen","year":"2017","journal-title":"arXiv preprint arXiv 1702 04710"},{"key":"ref26","first-page":"116","article-title":"Shufflenet v2: Practical guidelines for efficient cnn architecture design","author":"ma","year":"2018","journal-title":"Proceedings of the European Conference on Computer Vision (ECCV)"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.243"}],"event":{"name":"ICASSP 2020 - 2020 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP)","location":"Barcelona, Spain","start":{"date-parts":[[2020,5,4]]},"end":{"date-parts":[[2020,5,8]]}},"container-title":["ICASSP 2020 - 2020 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/9040208\/9052899\/09052933.pdf?arnumber=9052933","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,1,15]],"date-time":"2025-01-15T19:37:45Z","timestamp":1736969865000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9052933\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,5]]},"references-count":29,"URL":"https:\/\/doi.org\/10.1109\/icassp40776.2020.9052933","relation":{},"subject":[],"published":{"date-parts":[[2020,5]]}}}