{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,19]],"date-time":"2026-03-19T09:12:57Z","timestamp":1773911577004,"version":"3.50.1"},"reference-count":47,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"6","license":[{"start":{"date-parts":[[2017,11,1]],"date-time":"2017-11-01T00:00:00Z","timestamp":1509494400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Signal Process. Mag."],"published-print":{"date-parts":[[2017,11]]},"DOI":"10.1109\/msp.2017.2740965","type":"journal-article","created":{"date-parts":[[2017,11,9]],"date-time":"2017-11-09T21:36:42Z","timestamp":1510263402000},"page":"50-62","source":"Crossref","is-referenced-by-count":126,"title":["The Robustness of Deep Networks: A Geometrical Perspective"],"prefix":"10.1109","volume":"34","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-3361-5533","authenticated-orcid":false,"given":"Alhussein","family":"Fawzi","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Seyed-Mohsen","family":"Moosavi-Dezfooli","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4010-714X","authenticated-orcid":false,"given":"Pascal","family":"Frossard","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref39","author":"hinton","year":"2015","journal-title":"Distilling the knowledge in a neural network"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.41"},{"key":"ref33","article-title":"Robust optimization in machine learning","author":"caramanis","year":"2012","journal-title":"Optimization for Machine Learning"},{"key":"ref32","author":"shaham","year":"2015","journal-title":"Understanding adversarial training Increasing local stability of neural nets through robust optimization"},{"key":"ref31","author":"gu","year":"2014","journal-title":"Towards deep neural network architectures robust to adversarial examples"},{"key":"ref30","author":"moosavi-dezfooli","year":"2017","journal-title":"Analysis of universal adversarial perturbations"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1080\/10556780600883791"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/ICISIP.2004.1287696"},{"key":"ref35","first-page":"555","article-title":"A robust minimax approach to classification","volume":"3","author":"lanckriet","year":"2003","journal-title":"J Machine Learning Res"},{"key":"ref34","first-page":"1485","article-title":"Robustness and regularization of support vector machines","volume":"10","author":"xu","year":"2009","journal-title":"J Machine Learning Res"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1007\/s10994-017-5663-3"},{"key":"ref40","author":"carlini","year":"2016","journal-title":"Defensive distillation is not robust to adversarial examples"},{"key":"ref11","article-title":"Explaining and harnessing adversarial examples","author":"goodfellow","year":"0","journal-title":"Proc Int Conf Learning Representations"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW.2016.58"},{"key":"ref13","author":"carlini","year":"2016","journal-title":"Towards Evaluating the Robustness of Neural Networks"},{"key":"ref14","author":"baluja","year":"2017","journal-title":"Adversarial transformation networks Learning to generate adversarial examples"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1145\/2647868.2654889"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298594"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-015-0816-y"},{"key":"ref18","first-page":"1632","article-title":"Robustness of classifiers: from adversarial to random noise","author":"fawzi","year":"0","journal-title":"Proc Neural Information Processing Systems Conf"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1145\/1273496.1273556"},{"key":"ref28","author":"fawzi","year":"2017","journal-title":"Classification regions of deep neural networks"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1016\/j.media.2017.07.005"},{"key":"ref27","author":"tanay","year":"2016","journal-title":"A boundary tilting persepective on the phenomenon of adversarial examples"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298640"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.5244\/C.29.106"},{"key":"ref29","first-page":"3360","article-title":"Exponential expressivity in deep neural networks through transient chaos","author":"poole","year":"0","journal-title":"Proc Advances in Neural Information Processing Systems Conf"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/ICIP.2016.7533048"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.5244\/C.30.137"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1145\/3065386"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-40994-3_25"},{"key":"ref1","article-title":"Intriguing properties of neural networks","author":"szegedy","year":"0","journal-title":"Proc Int Conf Learning Representations"},{"key":"ref46","author":"nayebi","year":"2017","journal-title":"Biologically inspired protection of deep networks from adversarial attacks"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978392"},{"key":"ref45","first-page":"2017","article-title":"Spatial transformer networks","author":"jaderberg","year":"0","journal-title":"Proc Advances in Neural Information Processing Systems Conf"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.17"},{"key":"ref47","first-page":"854","article-title":"Parseval networks: Improving robustness to adversarial examples","author":"cisse","year":"0","journal-title":"Proc Int Conf Machine Learning"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.481"},{"key":"ref42","author":"metzen","year":"2017","journal-title":"On detecting adversarial perturbations"},{"key":"ref24","author":"papernot","year":"2016","journal-title":"Practical Black-Box Attacks against Deep Learning Systems using Adversarial Examples"},{"key":"ref41","author":"alemi","year":"2016","journal-title":"Deep variational information bottleneck"},{"key":"ref23","author":"liu","year":"2016","journal-title":"Delving into transferable adversarial examples and black-box attacks"},{"key":"ref44","author":"lu","year":"2017","journal-title":"Safetynet Detecting and rejecting adversarial examples robustly"},{"key":"ref26","article-title":"Adversarial manipulation of deep representations","author":"sabour","year":"0","journal-title":"Proc Int Conf Learning Representations"},{"key":"ref43","author":"feinman","year":"2017","journal-title":"Detecting adversarial samples from artifacts"},{"key":"ref25","doi-asserted-by":"crossref","DOI":"10.7551\/mitpress\/10761.003.0012","article-title":"Adversarial perturbations of deep neural networks","author":"warde-farley","year":"2016","journal-title":"Perturbation Optimization and Statistics"}],"container-title":["IEEE Signal Processing Magazine"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/79\/8103076\/08103145.pdf?arnumber=8103145","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,8,28]],"date-time":"2023-08-28T08:18:54Z","timestamp":1693210734000},"score":1,"resource":{"primary":{"URL":"http:\/\/ieeexplore.ieee.org\/document\/8103145\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017,11]]},"references-count":47,"journal-issue":{"issue":"6"},"URL":"https:\/\/doi.org\/10.1109\/msp.2017.2740965","relation":{},"ISSN":["1053-5888"],"issn-type":[{"value":"1053-5888","type":"print"}],"subject":[],"published":{"date-parts":[[2017,11]]}}}