{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,3]],"date-time":"2026-06-03T00:04:02Z","timestamp":1780445042278,"version":"3.54.1"},"reference-count":180,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"2","license":[{"start":{"date-parts":[[2020,4,1]],"date-time":"2020-04-01T00:00:00Z","timestamp":1585699200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2020,4,1]],"date-time":"2020-04-01T00:00:00Z","timestamp":1585699200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2020,4,1]],"date-time":"2020-04-01T00:00:00Z","timestamp":1585699200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Des. Test"],"published-print":{"date-parts":[[2020,4]]},"DOI":"10.1109\/mdat.2020.2971217","type":"journal-article","created":{"date-parts":[[2020,2,3]],"date-time":"2020-02-03T20:39:01Z","timestamp":1580762341000},"page":"30-57","source":"Crossref","is-referenced-by-count":113,"title":["Robust Machine Learning Systems: Challenges,Current Trends, Perspectives, and the Road Ahead"],"prefix":"10.1109","volume":"37","author":[{"given":"Muhammad","family":"Shafique","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mahum","family":"Naseer","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Theocharis","family":"Theocharides","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Christos","family":"Kyrkou","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Onur","family":"Mutlu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Lois","family":"Orosa","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jungwook","family":"Choi","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref170","article-title":"Formal verification of CNN-based perception systems","author":"kouvaros","year":"2018","journal-title":"arXiv 1811 11373"},{"key":"ref172","doi-asserted-by":"publisher","DOI":"10.1145\/3088525.3088673"},{"key":"ref171","doi-asserted-by":"publisher","DOI":"10.1145\/242223.242257"},{"key":"ref174","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00058"},{"key":"ref173","doi-asserted-by":"publisher","DOI":"10.21236\/AD0256582"},{"key":"ref176","article-title":"Reachability analysis and safety verification for neural network control systems","author":"xiang","year":"2018","journal-title":"arXiv 1805 09944"},{"key":"ref175","article-title":"Specification-guided safety verification for feedforward neural networks","author":"xiang","year":"2018","journal-title":"arXiv 1812 06161"},{"key":"ref178","first-page":"1","article-title":"Boosting robustness certification of neural networks","author":"singh","year":"2018","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref177","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2018.2808470"},{"key":"ref168","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-68167-2_18"},{"key":"ref169","article-title":"An approach to reachability analysis for feed-forward ReLU neural networks","author":"lomuscio","year":"2017","journal-title":"arXiv 1706 07351"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/FIT.2018.00064"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-25772-3"},{"key":"ref33","doi-asserted-by":"crossref","first-page":"273","DOI":"10.1007\/978-3-030-00470-5_13","article-title":"Fine-pruning: Defending against backdooring attacks on deep neural networks","author":"liu","year":"2018","journal-title":"Proc Int Symp Res Attacks Intrusions Defenses"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2909068"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.23919\/DATE.2019.8715141"},{"key":"ref30","first-page":"1","article-title":"Ensemble adversarial training: Attacks and defenses","author":"kurakin","year":"2018","journal-title":"Proc Int Conf Learn Represent (ICLR)"},{"key":"ref37","first-page":"1","article-title":"Ml confidential: Machine learning on encrypted data","author":"graepel","year":"2012","journal-title":"Proc Int Conf Inf Security Cryptol"},{"key":"ref36","first-page":"201","article-title":"Cryptonets: Applying neural networks to encrypted data with high throughput and accuracy","author":"gilad-bachrach","year":"2016","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref35","article-title":"CryptoDL: Deep neural networks over encrypted data","author":"hesamifard","year":"2017","journal-title":"arXiv 1711 05189"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1515\/popets-2018-0024"},{"key":"ref180","article-title":"Ft-clipact: Resilience analysis of deep neural networks and improving their fault tolerance using clipped activation","author":"hoang","year":"2019","journal-title":"arXiv preprint arXiv 1912 00941"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/TCAD.2008.923410"},{"key":"ref27","author":"camilleri","year":"1986","journal-title":"Hardware verification using higher-order logic"},{"key":"ref179","doi-asserted-by":"publisher","DOI":"10.1098\/rsta.2019.0164"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/ISVLSI.2018.00111"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1007\/BF02459570"},{"key":"ref22","first-page":"396","article-title":"Handwritten digit recognition with a backpropagation network","author":"lecun","year":"1990","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref21","first-page":"318","volume":"1","author":"rumelhart","year":"1986","journal-title":"Learning Internal Representations by Error Propagation"},{"key":"ref24","first-page":"2672","article-title":"Generative adversarial nets","author":"goodfellow","year":"2014","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-21735-7_6"},{"key":"ref101","article-title":"Chiron: Privacy-preserving machine learning as a service","author":"hunt","year":"2018","journal-title":"arXiv 1803 05961"},{"key":"ref26","article-title":"Intriguing properties of neural networks","author":"szegedy","year":"2013","journal-title":"arXiv 1312 6199"},{"key":"ref100","doi-asserted-by":"publisher","DOI":"10.1145\/3310273.3323070"},{"key":"ref25","author":"vreeken","year":"2003","journal-title":"Spiking Neural Networks An Introduction"},{"key":"ref50","article-title":"Query-efficient hard-label black-box attack: An optimization-based approach","author":"cheng","year":"2018","journal-title":"arXiv preprint arXiv 1807 04457"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1109\/ICDM.2018.00159"},{"key":"ref154","article-title":"Certifiably robust interpretation in deep learning","author":"levine","year":"2019","journal-title":"arXiv 1905 12105"},{"key":"ref153","first-page":"3319","article-title":"Axiomatic attribution for deep networks","author":"sundararajan","year":"2017","journal-title":"Proc Int Conf Mach Learn (JMLR)"},{"key":"ref156","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-63387-9_5"},{"key":"ref155","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-03592-1_16"},{"key":"ref150","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.74"},{"key":"ref152","first-page":"7775","article-title":"Towards robust interpretability with self-explaining neural networks","author":"alvarez-melis","year":"2018","journal-title":"Proc Int Conf Neural Inf Process"},{"key":"ref151","first-page":"9505","article-title":"Sanity checks for saliency maps","author":"adebayo","year":"2018","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref146","article-title":"Systematic testing of convolutional neural networks for autonomous driving","author":"dreossi","year":"2017","journal-title":"arXiv 1708 03309"},{"key":"ref147","doi-asserted-by":"publisher","DOI":"10.5220\/0006119203180323"},{"key":"ref148","doi-asserted-by":"publisher","DOI":"10.1109\/ICRA.2018.8462971"},{"key":"ref149","doi-asserted-by":"publisher","DOI":"10.1145\/3180155.3180220"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW.2019.00012"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1109\/ICCD.2017.16"},{"key":"ref57","first-page":"3517","article-title":"Certified defenses for data poisoning attacks","author":"steinhardt","year":"2017","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref55","first-page":"1","article-title":"Adversarial machine learning at scale","author":"kurakin","year":"2017","journal-title":"Proc Int Conf Learn Represent (ICLR)"},{"key":"ref54","article-title":"Maximal Jacobian-based Saliency map attack","author":"wiyatno","year":"2018","journal-title":"arXiv 1808 07945"},{"key":"ref53","article-title":"RED-Attack: Resource efficient decision based attack for machine learning","author":"khalid","year":"2019","journal-title":"arXiv 1901 10258"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00790"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1145\/3274694.3274696"},{"key":"ref167","doi-asserted-by":"publisher","DOI":"10.1023\/A:1021039126272"},{"key":"ref166","first-page":"6367","article-title":"Efficient formal safety analysis of neural networks","author":"wang","year":"2018","journal-title":"Proc Adv Neural Inf Process Syst Montr&#x00E9;al Canada Curran Associates Inc"},{"key":"ref165","doi-asserted-by":"publisher","DOI":"10.1145\/3290354"},{"key":"ref164","first-page":"10802","article-title":"Fast and effective robustness certification","author":"singh","year":"2018","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref163","year":"2020","journal-title":"IBM ILOG CPLEX Optimization Studio"},{"key":"ref162","year":"2020","journal-title":"Gurobi Optimizer"},{"key":"ref161","first-page":"30","article-title":"Towards verification of artificial neural networks","author":"scheibler","year":"2015","journal-title":"Proceedings of MBMV"},{"key":"ref160","doi-asserted-by":"publisher","DOI":"10.3233\/AIC-2012-0525"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.243"},{"key":"ref3","article-title":"Places205-VGGNet models for scene recognition","author":"wang","year":"2015","journal-title":"arXiv 1508 01667"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-658-23751-6_20"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1145\/3323685"},{"key":"ref159","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-14295-6_24"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2012.2205597"},{"key":"ref49","article-title":"HopSkipJumpAttack: A query-efficient decision-based attack","author":"chen","year":"2019","journal-title":"arXiv 1904 02144"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/ICCVW.2015.58"},{"key":"ref157","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-63387-9_1"},{"key":"ref158","doi-asserted-by":"publisher","DOI":"10.1145\/876638.876643"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2009.02.037"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/IOLTS.2019.8854425"},{"key":"ref45","article-title":"Ml-leaks: Model and data independent membership inference attacks and defenses on machine learning models","author":"salem","year":"2018","journal-title":"arXiv 1806 01246"},{"key":"ref48","article-title":"Decision-based adversarial attacks: Reliable attacks against black-box machine learning models","author":"brendel","year":"2017","journal-title":"arXiv 1712 04248"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2018.07.023"},{"key":"ref42","first-page":"1","article-title":"Explaining and harnessing adversarial examples","author":"goodfellow","year":"2015","journal-title":"Proc Int Conf Learn Represent (ICLR)"},{"key":"ref41","article-title":"Stealing neural networks via timing side channels","author":"duddu","year":"2018","journal-title":"arXiv 1812 11720"},{"key":"ref44","article-title":"Capsattacks: Robust and imperceptible adversarial attacks on capsule networks","author":"marchisio","year":"2019","journal-title":"arXiv 1901 09878"},{"key":"ref43","article-title":"On the vulnerability of capsule networks to adversarial attacks","author":"michels","year":"2019","journal-title":"arXiv 1906 03612"},{"key":"ref127","doi-asserted-by":"crossref","first-page":"200","DOI":"10.1147\/rd.62.0200","article-title":"The use of triple-modular redundancy to improve computer reliability","volume":"6","author":"lyons","year":"1962","journal-title":"IBM J Res Develop"},{"key":"ref126","doi-asserted-by":"publisher","DOI":"10.1049\/ip-cdt:19952162"},{"key":"ref125","doi-asserted-by":"publisher","DOI":"10.1109\/FTCS.1994.315652"},{"key":"ref124","doi-asserted-by":"publisher","DOI":"10.1109\/TNS.2010.2042818"},{"key":"ref73","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813677"},{"key":"ref72","first-page":"601","article-title":"Stealing machine learning models via prediction APIs","author":"tram\u00e8r","year":"2016","journal-title":"Proc 25th USENIX Secur Symp (USENIX Secur )"},{"key":"ref129","doi-asserted-by":"crossref","first-page":"395","DOI":"10.1147\/rd.144.0395","article-title":"A class of optimal minimum odd-weight-column SEC-DED codes","volume":"14","author":"hsiao","year":"1970","journal-title":"IBM J Res Develop"},{"key":"ref71","first-page":"1","article-title":"Reverse engineering convolutional neural networks through side-channel information leaks","author":"hua","year":"2018","journal-title":"Proc 55th ACM\/ESDA\/IEEE Design Automat Conf (DAC)"},{"key":"ref128","doi-asserted-by":"publisher","DOI":"10.1002\/j.1538-7305.1950.tb00463.x"},{"key":"ref70","first-page":"515","article-title":"CSI NN: Reverse engineering of neural network architectures through electromagnetic side channel","author":"batina","year":"2019","journal-title":"Proc 28th USENIX Secur Symp (USENIX Secur )"},{"key":"ref76","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW.2019.00017"},{"key":"ref130","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2019.00017"},{"key":"ref77","doi-asserted-by":"publisher","DOI":"10.1109\/GlobalSIP.2018.8646356"},{"key":"ref74","doi-asserted-by":"publisher","DOI":"10.1145\/3132747.3132785"},{"key":"ref75","article-title":"Towards practical verification of machine learning: The case of computer vision systems","author":"pei","year":"2017","journal-title":"arXiv 1712 01785"},{"key":"ref133","doi-asserted-by":"publisher","DOI":"10.1109\/TC.2018.2789904"},{"key":"ref134","doi-asserted-by":"publisher","DOI":"10.1145\/3079856.3080242"},{"key":"ref131","year":"2020","journal-title":"Meet Tesla&#x2019;s Self-Driving Car Computer and Its Two AI Brains"},{"key":"ref78","article-title":"Gradient masking causes CLEVER to overestimate adversarial perturbation size","author":"goodfellow","year":"2018","journal-title":"arXiv 1804 07870"},{"key":"ref132","doi-asserted-by":"publisher","DOI":"10.1109\/IOLTS.2018.8474192"},{"key":"ref79","article-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","author":"athalye","year":"2018","journal-title":"arXiv 1802 00420"},{"key":"ref136","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2016.30"},{"key":"ref135","doi-asserted-by":"publisher","DOI":"10.1145\/3084464"},{"key":"ref138","doi-asserted-by":"publisher","DOI":"10.1109\/JSSC.2018.2841824"},{"key":"ref137","doi-asserted-by":"publisher","DOI":"10.1145\/3195970.3196129"},{"key":"ref60","article-title":"Potrojan: Powerful neural-level Trojan designs in deep learning models","author":"zou","year":"2018","journal-title":"arXiv 1802 03043"},{"key":"ref139","doi-asserted-by":"publisher","DOI":"10.1109\/ISCAS.2005.1465399"},{"key":"ref62","article-title":"Hardware Trojan attacks on neural networks","author":"clements","year":"2018","journal-title":"arXiv 1806 05768"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1109\/JPROC.2014.2334493"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4419-8080-9_14"},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.1109\/ISCAS.2019.8702493"},{"key":"ref140","doi-asserted-by":"publisher","DOI":"10.1109\/WIFT.1995.515482"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.23919\/DATE.2019.8715027"},{"key":"ref141","doi-asserted-by":"publisher","DOI":"10.1109\/ASYNC.2000.836774"},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.23919\/DATE.2019.8714829"},{"key":"ref142","doi-asserted-by":"publisher","DOI":"10.1145\/1815961.1815980"},{"key":"ref67","article-title":"CSI neural network: Using side-channels to recover your artificial neural network information","author":"batina","year":"2018","journal-title":"arXiv 1810 09076"},{"key":"ref143","doi-asserted-by":"publisher","DOI":"10.1145\/2228360.2228407"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.1109\/FCCM.2019.00059"},{"key":"ref144","doi-asserted-by":"publisher","DOI":"10.1109\/VTS.2018.8368656"},{"key":"ref2","author":"rosenblatt","year":"1957","journal-title":"The perceptron&#x2014;A perceiving and recognizing automation"},{"key":"ref69","article-title":"A framework for the extraction of deep neural networks by leveraging public data","author":"pal","year":"2019","journal-title":"arXiv 1905 09165"},{"key":"ref145","doi-asserted-by":"publisher","DOI":"10.1145\/3352460.3358280"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/MS.2017.4541037"},{"key":"ref109","doi-asserted-by":"publisher","DOI":"10.1145\/2593069.2593229"},{"key":"ref95","first-page":"4672","article-title":"Safetynets: Verifiable execution of deep neural networks on an untrusted cloud","author":"ghodsi","year":"2017","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref108","doi-asserted-by":"publisher","DOI":"10.1109\/IRPS.2015.7112831"},{"key":"ref94","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00038"},{"key":"ref107","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2015.57"},{"key":"ref93","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978392"},{"key":"ref106","doi-asserted-by":"publisher","DOI":"10.1145\/3316781.3323472"},{"key":"ref92","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00530"},{"key":"ref105","doi-asserted-by":"publisher","DOI":"10.1109\/TIA.1984.4504404"},{"key":"ref91","article-title":"Maskednet: The first hardware inference engine aiming power side-channel protection","author":"dubey","year":"2019","journal-title":"arXiv 1910 13063"},{"key":"ref104","doi-asserted-by":"publisher","DOI":"10.1109\/MDT.2005.69"},{"key":"ref90","author":"wang","year":"2009","journal-title":"Electronic Design Automation Synthesis Verification and Test"},{"key":"ref103","doi-asserted-by":"publisher","DOI":"10.1109\/MM.2003.1225959"},{"key":"ref102","author":"tuszynski","year":"1980","journal-title":"Essential pattern and sequence sensitivity in semiconductor memories"},{"key":"ref111","first-page":"726","article-title":"NBTI induced performance degradation in logic and memory circuits: How effectively can we approach a reliability solution?","author":"kang","year":"2008","journal-title":"Proc Asia South Pacific Design Autom Conf"},{"key":"ref112","doi-asserted-by":"publisher","DOI":"10.1109\/DSD.2018.00058"},{"key":"ref110","doi-asserted-by":"publisher","DOI":"10.1109\/MICRO.2008.4771785"},{"key":"ref98","doi-asserted-by":"publisher","DOI":"10.1109\/AsianHOST.2018.8607161"},{"key":"ref99","doi-asserted-by":"publisher","DOI":"10.1109\/ISVLSI.2019.00122"},{"key":"ref96","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.12"},{"key":"ref97","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134056"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1145\/2619239.2631434"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2011.2166794"},{"key":"ref12","article-title":"End to end learning for self-driving cars","author":"bojarski","year":"2016","journal-title":"arXiv 1604 07316 [cs]"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/BigDataSecurity.2017.50"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1038\/s41591-018-0316-z"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.2478\/v10136-012-0031-x"},{"key":"ref118","doi-asserted-by":"publisher","DOI":"10.1145\/3123939.3123945"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/JPROC.2017.2761740"},{"key":"ref82","first-page":"6615","article-title":"Verifying properties of binarized deep neural networks","author":"narodytska","year":"2018","journal-title":"Proc AAAI Conf Artif Intell"},{"key":"ref117","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2015.58"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1038\/nature14539"},{"key":"ref81","first-page":"2613","article-title":"Measuring neural net robustness with constraints","author":"bastani","year":"2016","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref18","author":"jordan","year":"1986","journal-title":"Serial Order a Parallel Distributed Approach"},{"key":"ref84","first-page":"1","article-title":"Evaluating robustness of neural networks with mixed integer programming","author":"tjeng","year":"2019","journal-title":"Proc Int Conf Learn Represent (ICLR)"},{"key":"ref119","doi-asserted-by":"publisher","DOI":"10.1109\/TNS.1984.4333551"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1162\/neco.1997.9.8.1735"},{"key":"ref83","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-77935-5_9"},{"key":"ref114","doi-asserted-by":"publisher","DOI":"10.1109\/TCAD.2019.2915318"},{"key":"ref113","doi-asserted-by":"publisher","DOI":"10.1145\/2678373.2665726"},{"key":"ref116","first-page":"60","article-title":"An experimental study of data retention behavior in modern DRAM devices: Implications for retention time profiling mechanisms","author":"liu","year":"2013","journal-title":"Proc Ann Int Symp Comput Archit (ISCA)"},{"key":"ref80","article-title":"Towards the science of security and privacy in machine learning","author":"papernot","year":"2016","journal-title":"arXiv 1611 03814"},{"key":"ref115","doi-asserted-by":"publisher","DOI":"10.1145\/2591971.2592000"},{"key":"ref120","first-page":"1","article-title":"Adversarial examples in the physical world","author":"kurakin","year":"2017","journal-title":"Proc Int Conf Learn Represent (ICLR)"},{"key":"ref89","doi-asserted-by":"publisher","DOI":"10.1109\/MDT.2010.7"},{"key":"ref121","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00175"},{"key":"ref122","article-title":"No need to worry about adversarial examples in object detection in autonomous vehicles","author":"lu","year":"2017","journal-title":"arXiv 1707 03501"},{"key":"ref123","year":"2020","journal-title":"Self-Driving Uber Car Kills Pedestrian in Arizona Where Robots Roam"},{"key":"ref85","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP.2019.8683212"},{"key":"ref86","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2007.36"},{"key":"ref87","doi-asserted-by":"publisher","DOI":"10.1109\/MSPEC.2008.4505310"},{"key":"ref88","first-page":"51","article-title":"Hardware Trojan detection using path delay fingerprint","author":"jin","year":"2008","journal-title":"Proc IEEE Int Workshop Hardw -Orient Secur Trust"}],"container-title":["IEEE Design &amp; Test"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/6221038\/9075303\/08979377.pdf?arnumber=8979377","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,4,27]],"date-time":"2022-04-27T17:21:40Z","timestamp":1651080100000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/8979377\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,4]]},"references-count":180,"journal-issue":{"issue":"2"},"URL":"https:\/\/doi.org\/10.1109\/mdat.2020.2971217","relation":{},"ISSN":["2168-2356","2168-2364"],"issn-type":[{"value":"2168-2356","type":"print"},{"value":"2168-2364","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,4]]}}}