{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,6]],"date-time":"2026-03-06T05:48:21Z","timestamp":1772776101568,"version":"3.50.1"},"reference-count":38,"publisher":"IEEE","license":[{"start":{"date-parts":[[2022,5,1]],"date-time":"2022-05-01T00:00:00Z","timestamp":1651363200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2022,5,1]],"date-time":"2022-05-01T00:00:00Z","timestamp":1651363200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2022,5]]},"DOI":"10.1109\/spw54247.2022.9833874","type":"proceedings-article","created":{"date-parts":[[2022,7,25]],"date-time":"2022-07-25T20:14:47Z","timestamp":1658780087000},"page":"66-72","source":"Crossref","is-referenced-by-count":10,"title":["Concept-based Adversarial Attacks: Tricking Humans and Classifiers Alike"],"prefix":"10.1109","author":[{"given":"Johannes","family":"Schneider","sequence":"first","affiliation":[{"name":"University of Liechtenstein,Institute of Information Systems"}]},{"given":"Giovanni","family":"Apruzzese","sequence":"additional","affiliation":[{"name":"University of Liechtenstein,Institute of Information Systems"}]}],"member":"263","reference":[{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-44584-3_12"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813677"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.5220\/0010783500003116"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1145\/3386252"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00277"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/SSCI44817.2019.9002856"},{"key":"ref35","article-title":"Poison frogs! targeted clean-label poisoning attacks on neural networks","volume":"31","author":"shafahi","year":"2018","journal-title":"Advances in neural information processing systems"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1145\/3469659"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2018.00035"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00073"},{"key":"ref12","article-title":"Houdini: Fooling deep structured visual and speech recognition models with adversarial examples","volume":"30","author":"cisse","year":"2017","journal-title":"Advances in neural information processing systems"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.23919\/CYCON.2019.8756865"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1145\/2872427.2883060"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58548-8_1"},{"key":"ref16","article-title":"Towards deep learning models resistant to adversarial attacks","author":"madry","year":"2018","journal-title":"International Conference on Learning Representations"},{"key":"ref17","first-page":"321","article-title":"Why do adversarial attacks transfer? Explaining transferability of evasion and poisoning attacks","author":"demontis","year":"2019","journal-title":"Proc Usenix Security Symposium"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2018.00009"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01501"},{"key":"ref4","article-title":"Deceptive AI explanations: Creation and detection","author":"schneider","year":"2020"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-90019-9_11"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/ICICCT.2018.8473231"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1126\/science.aaa8415"},{"key":"ref29","article-title":"Model-based robust deep learning: Generalizing to natural, out-of-distribution data","author":"robey","year":"2020"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660332"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-40994-3_25"},{"key":"ref7","doi-asserted-by":"crossref","first-page":"436","DOI":"10.1038\/nature14539","article-title":"Deep learning","volume":"521","author":"lecun","year":"2015","journal-title":"Nature"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/TEVC.2019.2890858"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2018.07.023"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2021.3127960"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1145\/3474369.3486863"},{"key":"ref22","first-page":"1363","article-title":"Adversarial preprocessing: Understanding and preventing {Image-Scaling} attacks in machine learning","author":"quiring","year":"2020","journal-title":"29th USENIX Security Symposium (USENIX Security 20)"},{"key":"ref21","first-page":"2574","article-title":"Deepfool: a simple and accurate method to fool deep neural networks","author":"moosavi-dezfooli","year":"2016","journal-title":"Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-74251-5_6"},{"key":"ref23","first-page":"443","article-title":"Seeing is not believing: Camouflage attacks on image scaling algorithms","author":"xiao","year":"2019","journal-title":"28th USENIX Security Symposium (USENIX Security 19)"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1145\/3351095.3375624"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1007\/s10994-022-06157-0"}],"event":{"name":"2022 IEEE Security and Privacy Workshops (SPW)","location":"San Francisco, CA, USA","start":{"date-parts":[[2022,5,22]]},"end":{"date-parts":[[2022,5,26]]}},"container-title":["2022 IEEE Security and Privacy Workshops (SPW)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/9833855\/9833856\/09833874.pdf?arnumber=9833874","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,8,15]],"date-time":"2022-08-15T20:02:33Z","timestamp":1660593753000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9833874\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,5]]},"references-count":38,"URL":"https:\/\/doi.org\/10.1109\/spw54247.2022.9833874","relation":{},"subject":[],"published":{"date-parts":[[2022,5]]}}}