{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,14]],"date-time":"2026-05-14T20:08:04Z","timestamp":1778789284506,"version":"3.51.4"},"reference-count":52,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"23","license":[{"start":{"date-parts":[[2019,12,1]],"date-time":"2019-12-01T00:00:00Z","timestamp":1575158400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2019,12,1]],"date-time":"2019-12-01T00:00:00Z","timestamp":1575158400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2019,12,1]],"date-time":"2019-12-01T00:00:00Z","timestamp":1575158400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Signal Process."],"published-print":{"date-parts":[[2019,12,1]]},"DOI":"10.1109\/tsp.2019.2943232","type":"journal-article","created":{"date-parts":[[2019,9,23]],"date-time":"2019-09-23T19:27:17Z","timestamp":1569266837000},"page":"6078-6091","source":"Crossref","is-referenced-by-count":25,"title":["Perturbation Analysis of Learning Algorithms: Generation of Adversarial Examples From Classification to Regression"],"prefix":"10.1109","volume":"67","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-9848-698X","authenticated-orcid":false,"given":"Emilio Rafael","family":"Balda","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8229-2809","authenticated-orcid":false,"given":"Arash","family":"Behboodi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9585-605X","authenticated-orcid":false,"given":"Rudolf","family":"Mathar","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref39","author":"horn","year":"2013","journal-title":"Matrix Analysis"},{"key":"ref38","first-page":"2263","article-title":"Formal guarantees on the robustness of a classifier against adversarial manipulation","author":"hein","year":"0","journal-title":"Proc Neural Inf Process Syst"},{"key":"ref33","author":"raghunathan","year":"0","journal-title":"Proc Int Conf Learn Representations"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2017.2740965"},{"key":"ref31","article-title":"A boundary tilting persepective on the phenomenon of adversarial examples","author":"tanay","year":"2016"},{"key":"ref30","article-title":"Adversarial images for variational autoencoders","author":"tabacof","year":"2016"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/ACSSC.2018.8645290"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.41"},{"key":"ref34","article-title":"Robustness may be at odds with accuracy","author":"tsipras","year":"2019"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2017\/525"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/MILCOM.2016.7795300"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2018.00014"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1145\/3065386"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2012.2205597"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/TEVC.2019.2890858"},{"key":"ref22","author":"tram\u00e8r","year":"0","journal-title":"Proc Int Conf Learn Representations"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.300"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.17"},{"key":"ref26","article-title":"Houdini: Fooling deep structured prediction models","author":"cisse","year":"2017"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.153"},{"key":"ref50","article-title":"Deep koalarization: Image colorization using CNNs and Inception-ResNet-v2","author":"baldassarre","year":"2017"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.91"},{"key":"ref52","article-title":"The PASCAL Visual Object Classes Challenge 2012 (VOC2012) development kit","author":"everingham","year":"2011"},{"key":"ref10","article-title":"A theoretical framework for robustness of (deep) classifiers against adversarial examples","author":"wang","year":"0","journal-title":"Proc Int Conf Learn Representations"},{"key":"ref11","article-title":"Fundamental limits on adversarial robustness","author":"fawzi","year":"2015"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1007\/978-0-8176-4948-7"},{"key":"ref12","article-title":"Explaining and harnessing adversarial examples","author":"goodfellow","year":"0","journal-title":"Proc Int Conf Learn Representations"},{"key":"ref13","article-title":"UPSET and ANGRI: Breaking high performance image classifiers","author":"sarkar","year":"2017"},{"key":"ref14","first-page":"2574","article-title":"DeepFool: A simple and accurate method to fool deep neural networks","author":"dezfooli","year":"0","journal-title":"Proc IEEE Conf Comput Vision Pattern Recognit"},{"key":"ref15","first-page":"942","article-title":"Universal measurement bounds for structured sparse signal recovery","author":"rao","year":"0","journal-title":"Proc Int Conf Artif Intell Statist"},{"key":"ref16","author":"madry","year":"0","journal-title":"Proc Int Conf Learn Representations"},{"key":"ref17","article-title":"Adversarial examples in the physical world","author":"kurakin","year":"2016"},{"key":"ref18","author":"athalye","year":"0","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref19","article-title":"On the robustness of the CVPR 2018 white-box adversarial example defenses","author":"athalye","year":"2018"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298594"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref6","article-title":"Intriguing properties of neural networks","author":"szegedy","year":"2014"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2016.2577031"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1007\/s10994-010-5188-5"},{"key":"ref7","first-page":"1632","article-title":"Robustness of classifiers: From adversarial to random noise","author":"fawzi","year":"0","journal-title":"Proc Neural Inf Process Syst"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.243"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2807385"},{"key":"ref46","article-title":"Learning multiple layers of features from tiny images","author":"krizhevsky","year":"2009"},{"key":"ref45","article-title":"MNIST handwritten digit database","volume":"2","author":"lecun","year":"2010"},{"key":"ref48","article-title":"Network in network","author":"lin","year":"2013"},{"key":"ref47","doi-asserted-by":"crossref","first-page":"319","DOI":"10.1007\/3-540-46805-6_19","article-title":"Object recognition with gradient-based learning","author":"lecun","year":"1999","journal-title":"Shape Contour and Grouping in Computer Vision"},{"key":"ref42","first-page":"109","article-title":"Tight bounds on the radius of nonsingularity","author":"hartman","year":"2015","journal-title":"Scientific Computing Computer Arithmetic and Validated Numerics"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1080\/03081080008818644"},{"key":"ref44","article-title":"Adversarial transformation networks: Learning to generate adversarial examples","author":"baluja","year":"2017"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1145\/227683.227684"}],"container-title":["IEEE Transactions on Signal Processing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/78\/8894184\/08846746.pdf?arnumber=8846746","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,7,13]],"date-time":"2022-07-13T21:06:58Z","timestamp":1657746418000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/8846746\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,12,1]]},"references-count":52,"journal-issue":{"issue":"23"},"URL":"https:\/\/doi.org\/10.1109\/tsp.2019.2943232","relation":{},"ISSN":["1053-587X","1941-0476"],"issn-type":[{"value":"1053-587X","type":"print"},{"value":"1941-0476","type":"electronic"}],"subject":[],"published":{"date-parts":[[2019,12,1]]}}}