{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,2,21]],"date-time":"2025-02-21T23:47:46Z","timestamp":1740181666525,"version":"3.37.3"},"reference-count":50,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"am","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["2342253","2236483","1943064","2236484"],"award-info":[{"award-number":["2342253","2236483","1943064","2236484"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE J. Sel. Areas Inf. Theory"],"published-print":{"date-parts":[[2024]]},"DOI":"10.1109\/jsait.2024.3397187","type":"journal-article","created":{"date-parts":[[2024,5,6]],"date-time":"2024-05-06T18:09:59Z","timestamp":1715018999000},"page":"261-272","source":"Crossref","is-referenced-by-count":0,"title":["Efficient and Robust Classification for Sparse Attacks"],"prefix":"10.1109","volume":"5","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-9002-5233","authenticated-orcid":false,"given":"Mark","family":"Beliaev","sequence":"first","affiliation":[{"name":"Graduate School of Electrical and Computer Engineering, University of California at Santa Barbara, Santa Barbara, CA, USA"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0266-9237","authenticated-orcid":false,"given":"Payam","family":"Delgosha","sequence":"additional","affiliation":[{"name":"Faculty of Computer Science, University of Illinois at Urbana-Champaign, Champaign, IL, USA"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9448-8750","authenticated-orcid":false,"given":"Hamed","family":"Hassani","sequence":"additional","affiliation":[{"name":"Faculty of Electrical and Systems Engineering, University of Pennsylvania, Philadelphia, PA, USA"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1126-0292","authenticated-orcid":false,"given":"Ramtin","family":"Pedarsani","sequence":"additional","affiliation":[{"name":"Faculty of Electrical and Computer Engineering, University of California at Santa Barbara, Santa Barbara, CA, USA"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/ISIT50566.2022.9834832"},{"key":"ref2","first-page":"1097","article-title":"ImageNet classification with deep convolutional neural networks","volume-title":"Proc. 25th Int. Conf. Neural Inf. Process. Syst.","author":"Krizhevsky"},{"key":"ref3","article-title":"Playing atari with deep reinforcement learning","author":"Mnih","year":"2013","journal-title":"arXiv:1312.5602"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.13140\/RG.2.2.18893.74727"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/P16-1231"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-40994-3_25"},{"key":"ref7","article-title":"Intriguing properties of neural networks","author":"Szegedy","year":"2013","journal-title":"arXiv:1312.6199"},{"key":"ref8","article-title":"Explaining and harnessing adversarial examples","author":"Goodfellow","year":"2014","journal-title":"arXiv:1412.6572"},{"key":"ref9","article-title":"Towards deep learning models resistant to adversarial attacks","author":"Madry","year":"2017","journal-title":"arXiv:1706.06083"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00482"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2020.2984972"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1201\/9781351251389-8"},{"key":"ref14","first-page":"274","article-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Athalye"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/ISIT.2018.8437638"},{"key":"ref16","first-page":"1","article-title":"Improving adversarial robustness via channel-wise activation suppressing","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Bai"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00445"},{"key":"ref19","first-page":"1","article-title":"Enhancing adversarial defense by k-winners-take-all","volume-title":"Proc. 8th Int. Conf. Learn. Represent.","author":"Xiao"},{"key":"ref20","first-page":"8","article-title":"Defensive Quantization: When efficiency meets robustness","author":"Lin","year":"2019","journal-title":"Artif. Intell., Commun., Imag., Navig., Sens. Syst."},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v32i1.11302"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00930"},{"key":"ref23","article-title":"Robustness may be at odds with accuracy","author":"Tsipras","year":"2018","journal-title":"arXiv:1805.12152"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01258-8_39"},{"key":"ref25","article-title":"Adversarial training can hurt generalization","author":"Raghunathan","year":"2019","journal-title":"arXiv:1906.06032"},{"key":"ref26","first-page":"7472","article-title":"Theoretically principled trade-off between robustness and accuracy","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Zhang"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/tnnls.2023.3244172"},{"key":"ref28","first-page":"2034","article-title":"Precise tradeoffs in adversarial training for linear regression","volume-title":"Proc. Conf. Learn. Theory","author":"Javanmard"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/TSP.2022.3198169"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"ref31","article-title":"Towards the first adversarially robust neural network model on MNIST","author":"Schott","year":"2018","journal-title":"arXiv:1805.09190"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v36i6.20595"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i04.5888"},{"key":"ref34","article-title":"Is BERT really robust? Natural language attack on text classification and entailment","author":"Jin","year":"2019","journal-title":"arXiv:1907.11932"},{"key":"ref35","first-page":"3896","article-title":"Adversarial camera stickers: A physical camera-based attack on deep learning systems","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Li"},{"key":"ref36","article-title":"Adversarial perturbations against deep neural networks for malware classification","author":"Grosse","year":"2016","journal-title":"arXiv:1606.04435"},{"key":"ref37","article-title":"A simple explanation for the existence of adversarial examples with small hamming distance","author":"Shamir","year":"2019","journal-title":"arXiv:1901.10861"},{"key":"ref38","article-title":"Simple black-box adversarial perturbations for deep networks","author":"Narodytska","year":"2016","journal-title":"arXiv:1612.06299"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1137\/21m1426286"},{"volume-title":"MNIST handwritten digit database.","year":"2010","author":"LeCun","key":"ref40"},{"volume-title":"CIFAR-10","author":"Krizhevsky","key":"ref41"},{"volume-title":"robust-l0","year":"2024","author":"Beliaev","key":"ref42"},{"key":"ref43","volume":"523","author":"Huber","year":"2004","journal-title":"Robust Statistics"},{"volume-title":"Probabilistic Machine Learning: An Introduction","year":"2022","author":"Murphy","key":"ref44"},{"key":"ref45","article-title":"Very deep convolutional networks for large-scale image recognition","author":"Simonyan","year":"2014","journal-title":"arXiv:1409.1556"},{"key":"ref46","first-page":"1","article-title":"On adaptive attacks to adversarial example defenses","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"33","author":"Tramer"},{"key":"ref47","article-title":"Testing robustness against unforeseen adversaries","author":"Kang","year":"2019","journal-title":"arXiv:1908.08016"},{"key":"ref48","first-page":"1","article-title":"Provable robustness against all adversarial l\\_p-perturbations for p\\geq1","volume-title":"Proc. ICLR","author":"Croce"},{"key":"ref49","first-page":"4436","article-title":"Adversarial robustness against multiple and single lp-threat models via quick fine-tuning of robust classifiers","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Croce"},{"key":"ref50","article-title":"Towards a robust deep neural network in texts: A survey","author":"Wang","year":"2019","journal-title":"arXiv:1902.07285"}],"container-title":["IEEE Journal on Selected Areas in Information Theory"],"original-title":[],"link":[{"URL":"https:\/\/ieeexplore.ieee.org\/ielam\/8700143\/10461668\/10520718-aam.pdf","content-type":"application\/pdf","content-version":"am","intended-application":"syndication"},{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/8700143\/10461668\/10520718.pdf?arnumber=10520718","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,1,10]],"date-time":"2025-01-10T21:06:10Z","timestamp":1736543170000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10520718\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024]]},"references-count":50,"URL":"https:\/\/doi.org\/10.1109\/jsait.2024.3397187","relation":{},"ISSN":["2641-8770"],"issn-type":[{"type":"electronic","value":"2641-8770"}],"subject":[],"published":{"date-parts":[[2024]]}}}