{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,2,21]],"date-time":"2025-02-21T23:50:37Z","timestamp":1740181837508,"version":"3.37.3"},"reference-count":45,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"},{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"am","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"funder":[{"name":"MIT Jacobs Presidential Fellowship"},{"DOI":"10.13039\/501100007633","name":"Korea Foundation for Advanced Studies","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100007633","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100015597","name":"Siebel Scholars Foundation","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100015597","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100017850","name":"NXP","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100017850","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Open J. Circuits Syst."],"published-print":{"date-parts":[[2021]]},"DOI":"10.1109\/ojcas.2021.3116244","type":"journal-article","created":{"date-parts":[[2021,12,9]],"date-time":"2021-12-09T21:03:13Z","timestamp":1639083793000},"page":"843-855","source":"Crossref","is-referenced-by-count":0,"title":["Understanding the Energy vs. Adversarial Robustness Trade-Off in Deep Neural Networks"],"prefix":"10.1109","volume":"2","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-6406-9515","authenticated-orcid":false,"given":"Kyungmi","family":"Lee","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5977-2748","authenticated-orcid":false,"given":"Anantha P.","family":"Chandrakasan","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref39","first-page":"1660","article-title":"Improving the adversarial robustness and interpretability of deep neural networks by regularizing their input gradients","author":"ross","year":"2017","journal-title":"Proc AAAI"},{"key":"ref38","first-page":"854","article-title":"Parseval networks: Improving robustness to adversarial examples","author":"ciss\u00e9","year":"2017","journal-title":"Proc ICML"},{"year":"2015","author":"hinton","journal-title":"Distilling the knowledge in a neural network","key":"ref33"},{"doi-asserted-by":"publisher","key":"ref32","DOI":"10.1109\/SP.2017.49"},{"key":"ref31","doi-asserted-by":"crossref","first-page":"357","DOI":"10.1038\/s41586-020-2649-2","article-title":"Array programming with NumPy","volume":"585","author":"harris","year":"2020","journal-title":"Nature"},{"year":"2019","author":"ding","article-title":"Advertorch v0.1: An adversarial robustness toolbox based on pytorch","key":"ref30"},{"key":"ref37","article-title":"Spectral normalization for generative adversarial networks","author":"miyato","year":"2018","journal-title":"Proc Int Conf Learn Represent"},{"doi-asserted-by":"publisher","key":"ref36","DOI":"10.1109\/TPAMI.2018.2858821"},{"key":"ref35","first-page":"1","article-title":"Countering adversarial images using input transformations","author":"guo","year":"2018","journal-title":"Proc Int Conf Learn Represent"},{"year":"2018","author":"galloway","journal-title":"Attacking binarized neural networks","key":"ref34"},{"key":"ref10","article-title":"Certifying some distributional robustness with principled adversarial training","author":"sinha","year":"2018","journal-title":"Proc Int Conf Learn Represent (ICLR)"},{"year":"2015","author":"han","journal-title":"Deep compression Compressing deep neural networks with pruning trained quantization and huffman coding","key":"ref40"},{"year":"2018","author":"raghunathan","journal-title":"Certified defenses against adversarial examples","key":"ref11"},{"key":"ref12","first-page":"1","article-title":"Evaluating robustness of neural networks with mixed integer programming","author":"tjeng","year":"2019","journal-title":"Proc Int Conf Learn Represent"},{"doi-asserted-by":"publisher","key":"ref13","DOI":"10.1109\/JIOT.2021.3061314"},{"year":"2016","author":"papernot","journal-title":"Transferability in machine learning from phenomena to black-box attacks using adversarial samples","key":"ref14"},{"key":"ref15","first-page":"2206","article-title":"Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks","author":"croce","year":"2020","journal-title":"Proc ICML"},{"doi-asserted-by":"publisher","key":"ref16","DOI":"10.1109\/SP.2016.41"},{"year":"2019","author":"tsipras","article-title":"Robustness may be at odds with accuracy","key":"ref17"},{"doi-asserted-by":"publisher","key":"ref18","DOI":"10.1007\/978-3-030-01258-8_39"},{"key":"ref19","article-title":"Defensive quantization: When efficiency meets robustness","author":"lin","year":"2019","journal-title":"Proc Int Conf Learn Represent"},{"year":"2014","author":"simonyan","article-title":"Very deep convolutional networks for large-scale image recognition","key":"ref28"},{"doi-asserted-by":"publisher","key":"ref4","DOI":"10.1145\/2976749.2978392"},{"key":"ref27","first-page":"4510","article-title":"MobileNetV2: Inverted residuals and linear bottlenecks","author":"sandler","year":"2019","journal-title":"Proc IEEE Conf Comput Vis and Pattern Recog"},{"year":"2017","author":"eykholt","journal-title":"Robust physical-world attacks on deep learning models","key":"ref3"},{"year":"2017","author":"madry","journal-title":"Towards deep learning models resistant to adversarial attacks","key":"ref6"},{"key":"ref29","first-page":"8024","article-title":"PyTorch: An imperative style, highperformance deep learning library","author":"paszke","year":"2019","journal-title":"Proc Adv Neural Inf Process Syst 32"},{"year":"2014","author":"goodfellow","journal-title":"Explaining and Harnessing Adversarial Examples","key":"ref5"},{"key":"ref8","first-page":"274","article-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","author":"athalye","year":"2018","journal-title":"Proc ICML"},{"doi-asserted-by":"publisher","key":"ref7","DOI":"10.1145\/3052973.3053009"},{"doi-asserted-by":"publisher","key":"ref2","DOI":"10.1016\/j.patcog.2018.07.023"},{"key":"ref9","first-page":"5283","article-title":"Provable defenses against adversarial examples via the convex outer adversarial polytope","author":"wong","year":"2017","journal-title":"Proc ICML"},{"year":"2013","author":"szegedy","journal-title":"Intriguing properties of neural networks","key":"ref1"},{"year":"2009","author":"krizhevsky","journal-title":"Learning multiple layers of features from tiny images","key":"ref20"},{"year":"2014","author":"huang","article-title":"Labeled faces in the wild: Updates and new reporting procedures","key":"ref45"},{"doi-asserted-by":"publisher","key":"ref22","DOI":"10.1007\/s11263-015-0816-y"},{"key":"ref21","article-title":"Reading digits in natural images with unsupervised feature learning","author":"netzer","year":"2011","journal-title":"Proc NIPS Workshop Deep Learn Unsupervised Feature Learn"},{"doi-asserted-by":"publisher","key":"ref42","DOI":"10.1109\/CVPR.2015.7298682"},{"key":"ref24","first-page":"448","article-title":"Batch normalization: Accelerating deep network training by reducing internal covariate shift","author":"ioffe","year":"2015","journal-title":"Proc 32nd Int Conf Mach Learning"},{"year":"2017","author":"li","journal-title":"Pruning filters for efficient convnets","key":"ref41"},{"doi-asserted-by":"publisher","key":"ref23","DOI":"10.1109\/5.726791"},{"doi-asserted-by":"publisher","key":"ref44","DOI":"10.1007\/978-3-319-97909-0_46"},{"doi-asserted-by":"publisher","key":"ref26","DOI":"10.5244\/C.30.87"},{"doi-asserted-by":"publisher","key":"ref43","DOI":"10.1109\/TIFS.2018.2833032"},{"doi-asserted-by":"publisher","key":"ref25","DOI":"10.1109\/CVPR.2016.90"}],"container-title":["IEEE Open Journal of Circuits and Systems"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/8784029\/9314963\/09645046.pdf?arnumber=9645046","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,3,8]],"date-time":"2022-03-08T21:32:31Z","timestamp":1646775151000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9645046\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021]]},"references-count":45,"URL":"https:\/\/doi.org\/10.1109\/ojcas.2021.3116244","relation":{},"ISSN":["2644-1225"],"issn-type":[{"type":"electronic","value":"2644-1225"}],"subject":[],"published":{"date-parts":[[2021]]}}}