{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,10,30]],"date-time":"2024-10-30T05:33:44Z","timestamp":1730266424836,"version":"3.28.0"},"reference-count":27,"publisher":"IEEE","license":[{"start":{"date-parts":[[2019,7,1]],"date-time":"2019-07-01T00:00:00Z","timestamp":1561939200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2019,7,1]],"date-time":"2019-07-01T00:00:00Z","timestamp":1561939200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2019,7,1]],"date-time":"2019-07-01T00:00:00Z","timestamp":1561939200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2019,7]]},"DOI":"10.1109\/ijcnn.2019.8851930","type":"proceedings-article","created":{"date-parts":[[2019,9,30]],"date-time":"2019-09-30T23:44:32Z","timestamp":1569887072000},"page":"1-8","source":"Crossref","is-referenced-by-count":1,"title":["Not All Adversarial Examples Require a Complex Defense: Identifying Over-optimized Adversarial Examples with IQR-based Logit Thresholding"],"prefix":"10.1109","author":[{"given":"Utku","family":"Ozbulak","sequence":"first","affiliation":[]},{"given":"Arnout","family":"Van Messem","sequence":"additional","affiliation":[]},{"given":"Wesley","family":"De Neve","sequence":"additional","affiliation":[]}],"member":"263","reference":[{"key":"ref10","article-title":"Adversarial machine learning at scale","author":"kurakin","year":"2016","journal-title":"CoRR"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-015-0816-y"},{"key":"ref12","article-title":"Distillation as a defense to adversarial perturbations against deep neural networks","author":"papernot","year":"2015","journal-title":"CoRR"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.56"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140444"},{"article-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","year":"2018","author":"athalye","key":"ref15"},{"key":"ref16","article-title":"Adversarial examples in the physical world","author":"kurakin","year":"2016","journal-title":"CoRR"},{"journal-title":"Pattern Recognition and Machine Learning","year":"2006","author":"bishop","key":"ref17"},{"journal-title":"Deep Learning","year":"2016","author":"goodfellow","key":"ref18"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-76153-9_28"},{"key":"ref4","article-title":"Intriguing properties of neural networks","author":"szegedy","year":"2013","journal-title":"CoRR"},{"article-title":"Adversarial vulnerability of neural networks increases with input dimension","year":"2018","author":"simon-gabriel","key":"ref27"},{"key":"ref3","doi-asserted-by":"crossref","first-page":"234","DOI":"10.1007\/978-3-319-24574-4_28","article-title":"U-net: Convolutional networks for biomedical image segmentation","author":"ronneberger","year":"2015","journal-title":"Medical Image Computing and Computer-Assisted Intervention &#x2013; MICCAI 2015"},{"key":"ref6","first-page":"2574","article-title":"Deepfool: A simple and accurate method to fool deep neural networks","author":"moosavi-dezfooli","year":"2016","journal-title":"Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298640"},{"key":"ref8","article-title":"The limitations of deep learning in adversarial settings","author":"papernot","year":"2015","journal-title":"CoRR"},{"key":"ref7","article-title":"Explaining and harnessing adversarial examples","author":"goodfellow","year":"2014","journal-title":"CoRR"},{"key":"ref2","article-title":"You only look once: Unified, real-time object detection","author":"redmon","year":"2015","journal-title":"CoRR"},{"key":"ref9","article-title":"Towards evaluating the robustness of neural networks","author":"carlini","year":"2016","journal-title":"CoRR"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"article-title":"Very deep convolutional networks for large-scale image recognition","year":"2014","author":"simonyan","key":"ref22"},{"key":"ref21","article-title":"How the softmax output is misleading for evaluating the strength of adversarial examples","author":"ozbulak","year":"2018","journal-title":"NeuRIPS 2018 Workshop on Security in Machine Learning"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1080\/00401706.1985.10488027"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.2307\/2685173"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298594"},{"key":"ref25","volume":"2","author":"tukey","year":"1977","journal-title":"Exploratory Data Analysis"}],"event":{"name":"2019 International Joint Conference on Neural Networks (IJCNN)","start":{"date-parts":[[2019,7,14]]},"location":"Budapest, Hungary","end":{"date-parts":[[2019,7,19]]}},"container-title":["2019 International Joint Conference on Neural Networks (IJCNN)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/8840768\/8851681\/08851930.pdf?arnumber=8851930","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,7,17]],"date-time":"2022-07-17T17:51:28Z","timestamp":1658080288000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/8851930\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,7]]},"references-count":27,"URL":"https:\/\/doi.org\/10.1109\/ijcnn.2019.8851930","relation":{},"subject":[],"published":{"date-parts":[[2019,7]]}}}