{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T13:04:03Z","timestamp":1777467843825,"version":"3.51.4"},"reference-count":56,"publisher":"IEEE","license":[{"start":{"date-parts":[[2022,8,21]],"date-time":"2022-08-21T00:00:00Z","timestamp":1661040000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2022,8,21]],"date-time":"2022-08-21T00:00:00Z","timestamp":1661040000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2022,8,21]]},"DOI":"10.1109\/icpr56361.2022.9956476","type":"proceedings-article","created":{"date-parts":[[2022,11,29]],"date-time":"2022-11-29T19:34:13Z","timestamp":1669750453000},"page":"2349-2356","source":"Crossref","is-referenced-by-count":5,"title":["Boundary Defense Against Black-box Adversarial Attacks"],"prefix":"10.1109","author":[{"given":"Manjushree B.","family":"Aithal","sequence":"first","affiliation":[{"name":"Binghamton University,Department of Electrical and Computer Engineering,Binghamton,NY,USA,13902"}]},{"given":"Xiaohua","family":"Li","sequence":"additional","affiliation":[{"name":"Binghamton University,Department of Electrical and Computer Engineering,Binghamton,NY,USA,13902"}]}],"member":"263","reference":[{"key":"ref39","first-page":"1310","article-title":"Certified adversarial robustness via randomized smoothing","author":"cohen","year":"2019","journal-title":"International Conference on Machine Learning"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1145\/3394486.3403241"},{"key":"ref33","article-title":"Mitigating adversarial effects through randomization","author":"xie","year":"2018","journal-title":"International Conference on Learning Representations"},{"key":"ref32","article-title":"A study of the effect of jpg compression on adversarial images","author":"dziugaite","year":"2016"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58592-1_29"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref37","article-title":"Blacklight: Defending black-box adversarial attacks on deep neural networks","author":"li","year":"2020"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1145\/3385003.3410925"},{"key":"ref35","article-title":"Denoised smoothing: A provable defense for pretrained classifiers","author":"salman","year":"2020"},{"key":"ref34","article-title":"On adaptive attacks to adversarial example defenses","volume":"33","author":"tramer","year":"2020","journal-title":"Advances in neural information processing systems"},{"key":"ref28","first-page":"274","article-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","author":"athalye","year":"2018","journal-title":"International Conference on Machine Learning"},{"key":"ref27","article-title":"Certified adversarial robustness with additive noise","author":"li","year":"2019","journal-title":"Advances in neural information processing systems"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140444"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2012.2205597"},{"key":"ref1","first-page":"2722","article-title":"Deepdriving: Learning affordance for direct perception in autonomous driving","author":"chen","year":"2015","journal-title":"Proceedings of the IEEE International Conference on Computer Vision"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.41"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2019\/833"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00068"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2021.3105238"},{"key":"ref23","article-title":"Random noise defense against query-based black-box attacks","volume":"34","author":"qin","year":"2021","journal-title":"Advances in neural information processing systems"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1007\/s11042-019-7353-6"},{"key":"ref25","article-title":"Detecting adversarial image examples in deep neural networks with adaptive noise reduction","author":"liang","year":"2018","journal-title":"IEEE Transactions on Dependable and Secure Computing"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58574-7_14"},{"key":"ref51","first-page":"8093","article-title":"Overfitting in adversarially robust deep learning","author":"rice","year":"2020","journal-title":"International Conference on Machine Learning"},{"key":"ref56","article-title":"Pc-darts: Partial channel connections for memory-efficient architecture search","author":"xu","year":"2019"},{"key":"ref55","article-title":"Improving adversarial robustness using proxy distributions","author":"sehwag","year":"2021"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00445"},{"key":"ref53","article-title":"Adversarial robustness as a prior for learned representations","author":"engstrom","year":"2019"},{"key":"ref52","article-title":"Mma training: Direct input space margin maximization through adversarial training","author":"ding","year":"2018"},{"key":"ref10","first-page":"2137","article-title":"Black-box adversarial attacks with limited queries and information","author":"ilyas","year":"2018","journal-title":"International Conference on Machine Learning"},{"key":"ref11","first-page":"10 934","article-title":"Improving black-box adversarial attacks with a transfer-based prior","author":"cheng","year":"2019","journal-title":"Advances in neural information processing systems"},{"key":"ref40","article-title":"Provably robust deep learning via adversarially trained smoothed classifiers","author":"salman","year":"2019"},{"key":"ref12","article-title":"Query-efficient hard-label black-box attack: An optimization-based approach","author":"cheng","year":"2019","journal-title":"International Conference on Learning Representations (ICLR)"},{"key":"ref13","article-title":"Sign-opt: A query-efficient hard-label adversarial attack","author":"cheng","year":"2019","journal-title":"International Conference on Learning Representations"},{"key":"ref14","first-page":"3866","article-title":"Nattack: Learning the distributions of adversarial examples for an improved black-box attack on deep neural networks","author":"li","year":"2019","journal-title":"International Conference on Machine Learning"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00045"},{"key":"ref16","first-page":"2484","article-title":"Simple black-box adversarial attacks","author":"guo","year":"2019","journal-title":"International Conference on Machine Learning"},{"key":"ref17","article-title":"Ensemble adversarial training: Attacks and defenses","author":"tram\u00e8r","year":"2018","journal-title":"6th International Conference on Learning Representations ICLR 2018-Conference Track Proceedings"},{"key":"ref18","article-title":"Thermometer encoding: One hot way to resist adversarial examples","author":"buckman","year":"2018","journal-title":"International Conference on Learning Representations"},{"key":"ref19","article-title":"Defense-gan: Protecting classifiers against adversarial attacks using generative models","author":"samangouei","year":"2018","journal-title":"International Conference on Learning Representations"},{"key":"ref4","article-title":"Intriguing properties of neural networks","author":"szegedy","year":"2013"},{"key":"ref3","first-page":"1097","article-title":"Imagenet classification with deep convolutional neural networks","author":"krizhevsky","year":"2012","journal-title":"Advances in neural information processing systems"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1145\/3321707.3321749"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-40994-3_25"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140448"},{"key":"ref7","article-title":"Decision-based adversarial attacks: Reliable attacks against black-box machine learning models","author":"brendel","year":"2018","journal-title":"International Conference on Learning Representations"},{"key":"ref49","first-page":"10 399","article-title":"Adversarial robustness via run-time masking and cleansing","author":"wu","year":"2020","journal-title":"International Conference on Machine Learning"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.3301742"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1145\/3134600.3134606"},{"key":"ref45","article-title":"Countering adversarial images using input transformations","author":"guo","year":"2018","journal-title":"International Conference on Learning Representations"},{"key":"ref48","article-title":"Robustbench: a standardized adversarial robustness benchmark","author":"croce","year":"0"},{"key":"ref47","first-page":"20","article-title":"Explaining and harnessing adversarial examples","volume":"1050","author":"goodfellow","year":"2015","journal-title":"Stat"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00044"},{"key":"ref41","article-title":"Small input noise is enough to defend against query-based black-box attacks","author":"byun","year":"2021"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2022.3146198"},{"key":"ref43","first-page":"369","article-title":"Towards robust neural networks via random self-ensemble","author":"liu","year":"2018","journal-title":"Proceedings of the European Conference on Computer Vision (ECCV)"}],"event":{"name":"2022 26th International Conference on Pattern Recognition (ICPR)","location":"Montreal, QC, Canada","start":{"date-parts":[[2022,8,21]]},"end":{"date-parts":[[2022,8,25]]}},"container-title":["2022 26th International Conference on Pattern Recognition (ICPR)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/9956007\/9955631\/09956476.pdf?arnumber=9956476","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,12,19]],"date-time":"2022-12-19T20:05:40Z","timestamp":1671480340000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9956476\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,8,21]]},"references-count":56,"URL":"https:\/\/doi.org\/10.1109\/icpr56361.2022.9956476","relation":{},"subject":[],"published":{"date-parts":[[2022,8,21]]}}}