{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,15]],"date-time":"2026-01-15T05:26:44Z","timestamp":1768454804088,"version":"3.49.0"},"reference-count":61,"publisher":"IEEE","license":[{"start":{"date-parts":[[2021,7,18]],"date-time":"2021-07-18T00:00:00Z","timestamp":1626566400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2021,7,18]],"date-time":"2021-07-18T00:00:00Z","timestamp":1626566400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2021,7,18]],"date-time":"2021-07-18T00:00:00Z","timestamp":1626566400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100006360","name":"German Federal Ministry for Economic Affairs and Energy","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100006360","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2021,7,18]]},"DOI":"10.1109\/ijcnn52387.2021.9534145","type":"proceedings-article","created":{"date-parts":[[2021,9,22]],"date-time":"2021-09-22T20:32:37Z","timestamp":1632342757000},"page":"1-8","source":"Crossref","is-referenced-by-count":8,"title":["From a Fourier-Domain Perspective on Adversarial Examples to a Wiener Filter Defense for Semantic Segmentation"],"prefix":"10.1109","author":[{"given":"Nikhil","family":"Kapoor","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Andreas","family":"Bar","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Serin","family":"Varghese","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jan David","family":"Schneider","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Fabian","family":"Huger","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Peter","family":"Schlicht","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tim","family":"Fingscheidt","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref39","article-title":"An Adaptive View of Adversarial Robustness from Test-time Smoothing Defense","author":"tang","year":"2019","journal-title":"Proc of NIPS - Workshop"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1145\/3219819.3219910"},{"key":"ref33","article-title":"Mitigating Adversarial Effects Through Randomization","author":"xie","year":"2018","journal-title":"Proc of ICLR"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/ICMLA.2016.0020"},{"key":"ref31","author":"kannan","year":"2018","journal-title":"Adversarial logit pairing"},{"key":"ref30","first-page":"854","article-title":"Parseval Networks: Improving Robustness to Adversarial Examples","author":"cisse","year":"2017","journal-title":"Proc of ICML"},{"key":"ref37","author":"raju","year":"2019","journal-title":"BlurNet Defense by Filtering the Feature Maps"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00191"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00669"},{"key":"ref34","first-page":"1310","article-title":"Certified Adversarial Robustness via Randomized Smoothing","author":"cohen","year":"2019","journal-title":"Proc of ICML"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1007\/978-981-10-4962-0"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.23915\/distill.00003"},{"key":"ref28","article-title":"Adversarial Machine Learning at Scale","author":"kurakin","year":"2017","journal-title":"Proc of ICLR"},{"key":"ref27","author":"aydemir","year":"2018","journal-title":"The effects of jpeg and jpeg2000 compression on attacks using adversarial examples"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"ref2","article-title":"Intriguing Properties of Neural Networks","author":"szegedy","year":"2014","journal-title":"Proc of ICLR"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01219-9_25"},{"key":"ref20","author":"wang","year":"2018","journal-title":"Towards Frequency-Based Explanation for Robust CNN"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP.1996.543199"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00871"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2005.38"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/LSP.2003.818225"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23198"},{"key":"ref25","author":"dziugaite","year":"2016","journal-title":"A Study of the Effect of JPEG Compression on Adversarial Images"},{"key":"ref50","first-page":"834","article-title":"Semantic Image Segmentation With Deep Convolutional Nets and Fully Connected CRFs","author":"chen","year":"2015","journal-title":"Proc of ICLR"},{"key":"ref51","article-title":"Multi-Scale Context Aggregation by Dilated Convolutions","author":"yu","year":"2016","journal-title":"Proc of ICLR"},{"key":"ref59","author":"lyons","year":"2014","journal-title":"The Essential Guide to Digital Signal Processing"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00872"},{"key":"ref57","first-page":"214","article-title":"Leveraging Frequency Analysis for Deep Fake Image Recognition","author":"frank","year":"2020","journal-title":"Proc of ICML"},{"key":"ref56","first-page":"2452","article-title":"Generalizable Data-free Objective for Crafting Universal Adversarial Perturbations","volume":"41","author":"reddy","year":"2018","journal-title":"IEEE TPAMI"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.300"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"ref53","author":"yang","year":"0","journal-title":"TensorFlow Implementation of ICNet"},{"key":"ref52","author":"chen","year":"2018","journal-title":"Towards Understanding Limitations of Pixel Discretization Against Adversarial Attacks"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW.2019.00178"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW50498.2020.00174"},{"key":"ref40","author":"smith","year":"2003","journal-title":"Digital Signal Processing - A Practical Guide for Engineers and Scientists"},{"key":"ref12","first-page":"1299","article-title":"Improved Noise and Attack Robustness for Semantic Segmentation by Using Multi-Task Training With Self-Supervised Depth Estimation","author":"klingner","year":"2020","journal-title":"Proc of CVPR - SAIAD Workshop"},{"key":"ref13","article-title":"Towards Deep Learning Models Resistant to Adversarial Attacks","author":"madry","year":"2018","journal-title":"Proc of ICLR"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.41"},{"key":"ref15","first-page":"274","article-title":"Obfuscated Gradients Give a False Sense of Security: Circumventing Defenses to Adversarial Examples","author":"athalye","year":"2018","journal-title":"Proc of ICML"},{"key":"ref16","article-title":"Countering Adversarial Images Using Input Transformations","author":"guo","year":"2018","journal-title":"Proc of ICLR"},{"key":"ref17","author":"shaham","year":"2018","journal-title":"Defending against adversarial images using basis functions transformations"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW.2019.00177"},{"key":"ref19","first-page":"13255","article-title":"A Fourier Perspective on Model Robustness in Computer Vision","author":"yin","year":"2019","journal-title":"Proc of NIPS"},{"key":"ref4","author":"chen","year":"2017","journal-title":"Rethinking atrous convolution for semantic image segmentation"},{"key":"ref3","first-page":"1097","article-title":"ImageNet Classification With Deep Convolutional Neural Networks","author":"krizhevsky","year":"2012","journal-title":"Proc of NIPS"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298640"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/IVS.2019.8813813"},{"key":"ref8","article-title":"Explaining and Harnessing Adversarial Examples","author":"goodfellow","year":"2015","journal-title":"Proc of ICLR"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2020.2983666"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00851"},{"key":"ref9","author":"chakraborty","year":"2018","journal-title":"Adversarial Attacks and Defences A Survey"},{"key":"ref46","first-page":"321","article-title":"Why Do Adversarial Attacks Transfer? Explaining Transferability of Evasion and Poisoning Attacks","author":"demontis","year":"2019","journal-title":"Proc of SEC"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP40776.2020.9054482"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298965"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.350"},{"key":"ref42","author":"gonzalez","year":"2002","journal-title":"Digital Image Processing"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1002\/9781119994398"},{"key":"ref44","article-title":"Image Denoising Using Fuzzy and Wiener Filter in Wavelet Domain","author":"kethwas","year":"2015","journal-title":"Proc of the ICEC"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.7551\/mitpress\/2946.001.0001"}],"event":{"name":"2021 International Joint Conference on Neural Networks (IJCNN)","location":"Shenzhen, China","start":{"date-parts":[[2021,7,18]]},"end":{"date-parts":[[2021,7,22]]}},"container-title":["2021 International Joint Conference on Neural Networks (IJCNN)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/9533266\/9533267\/09534145.pdf?arnumber=9534145","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,5,10]],"date-time":"2022-05-10T15:46:02Z","timestamp":1652197562000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9534145\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,7,18]]},"references-count":61,"URL":"https:\/\/doi.org\/10.1109\/ijcnn52387.2021.9534145","relation":{},"subject":[],"published":{"date-parts":[[2021,7,18]]}}}