{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,2]],"date-time":"2026-04-02T18:36:06Z","timestamp":1775154966718,"version":"3.50.1"},"reference-count":46,"publisher":"IEEE","license":[{"start":{"date-parts":[[2020,3,1]],"date-time":"2020-03-01T00:00:00Z","timestamp":1583020800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2020,3,1]],"date-time":"2020-03-01T00:00:00Z","timestamp":1583020800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2020,3,1]],"date-time":"2020-03-01T00:00:00Z","timestamp":1583020800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2020,3]]},"DOI":"10.1109\/wacv45572.2020.9093429","type":"proceedings-article","created":{"date-parts":[[2020,5,15]],"date-time":"2020-05-15T03:41:09Z","timestamp":1589514069000},"page":"2654-2663","source":"Crossref","is-referenced-by-count":15,"title":["SmoothFool: An Efficient Framework for Computing Smooth Adversarial Perturbations"],"prefix":"10.1109","author":[{"given":"Ali","family":"Dabouei","sequence":"first","affiliation":[]},{"given":"Sobhan","family":"Soleymani","sequence":"additional","affiliation":[]},{"given":"Fariborz","family":"Taherkhani","sequence":"additional","affiliation":[]},{"given":"Jeremy","family":"Dawson","sequence":"additional","affiliation":[]},{"given":"Nasser M.","family":"Nasrabadi","sequence":"additional","affiliation":[]}],"member":"263","reference":[{"key":"ref39","article-title":"One pixel attack for fooling deep neural networks","author":"su","year":"2017","journal-title":"arXiv preprint arXiv 1710 08864"},{"key":"ref38","article-title":"Physical adversarial examples for object detectors","author":"song","year":"2018","journal-title":"12th USENIX Workshop on Offensive Technologies (WOOT 18)"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"ref32","article-title":"Divide, denoise, and defend against adversarial attacks","author":"moosavi-dezfooli","year":"2018","journal-title":"arXiv preprint arXiv 1802 06806"},{"key":"ref31","first-page":"2574","article-title":"Deep-fool: a simple and accurate method to fool deep neural networks","author":"moosavi-dezfooli","year":"2016","journal-title":"Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.17"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978392"},{"key":"ref36","article-title":"Are adversarial examples inevitable?","author":"shafahi","year":"2019","journal-title":"International Conference on Learning Representations (ICLR)"},{"key":"ref35","article-title":"Defense-GAN: Protecting classifiers against adversarial attacks using generative models","author":"samangouei","year":"2018","journal-title":"International Conference on Learning Representations (ICLR)"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00894"},{"key":"ref10","article-title":"Adversarial examples for semantic image segmentation","author":"fischer","year":"2017","journal-title":"arXiv preprint arXiv 1703 01281"},{"key":"ref40","article-title":"Intriguing properties of neural networks","author":"szegedy","year":"2013","journal-title":"arXiv preprint arXiv 1312 6199"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.371"},{"key":"ref12","article-title":"Explaining and harnessing adversarial examples","author":"goodfellow","year":"2015","journal-title":"International Conference on Learning Representations (ICLR)"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-66399-9_4"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref15","first-page":"2266","article-title":"Formal guarantees on the robustness of a classifier against adversarial manipulation","author":"hein","year":"2017","journal-title":"Advances in Neural Information Processing Systems (NIPS)"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.300"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW.2018.00212"},{"key":"ref18","article-title":"Adversarial attacks on neural network policies","author":"huang","year":"2017","journal-title":"arXiv preprint arXiv 1702 03180"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.3301962"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134057"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/WACV.2019.00215"},{"key":"ref27","article-title":"Towards deep learning models resistant to adversarial attacks","author":"madry","year":"2018","journal-title":"International Conference on Learning Representations (ICLR)"},{"key":"ref3","article-title":"Return of the devil in the details: Delving deep into convolutional nets","author":"chatfield","year":"2014","journal-title":"arXiv preprint arXiv 1405 3531"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00444"},{"key":"ref29","article-title":"Sparse-fool: a few pixels make a big difference","author":"modas","year":"2018","journal-title":"arXiv preprint arXiv 1811 02248"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2017.2740965"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00175"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2018.00009"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00396"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref46","first-page":"612","article-title":"Augmenting supervised neural networks with unsupervised objectives for large-scale image classification","author":"zhang","year":"2016","journal-title":"International Conference on Machine Learning (ICML)"},{"key":"ref20","first-page":"10772","article-title":"With friends like these, who needs adversaries?","author":"jetley","year":"2018","journal-title":"Advances in Neural Information Processing Systems (NIPS)"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.153"},{"key":"ref22","first-page":"1097","article-title":"Imagenet classification with deep convolutional neural networks","author":"krizhevsky","year":"2012","journal-title":"Advances in neural information processing systems"},{"key":"ref21","article-title":"Learning multiple layers of features from tiny images","author":"krizhevsky","year":"2009","journal-title":"Technical Report Citeseer"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.33015058"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00656"},{"key":"ref23","article-title":"Adversarial examples in the physical world","author":"kurakin","year":"2016","journal-title":"arXiv preprint arXiv 1607 02533"},{"key":"ref44","article-title":"Spatially transformed adversarial examples","author":"xiao","year":"2018","journal-title":"arXiv preprint arXiv 1801 00257"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00191"},{"key":"ref43","article-title":"Ensemble adversarial training: Attacks and defenses","author":"tramr","year":"2018","journal-title":"International Conference on Learning Representations (ICLR)"},{"key":"ref25","article-title":"MNIST handwritten digit database","volume":"2","author":"lecun","year":"2010","journal-title":"AT&T Labs [Online]"}],"event":{"name":"2020 IEEE Winter Conference on Applications of Computer Vision (WACV)","location":"Snowmass Village, CO, USA","start":{"date-parts":[[2020,3,1]]},"end":{"date-parts":[[2020,3,5]]}},"container-title":["2020 IEEE Winter Conference on Applications of Computer Vision (WACV)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/9087828\/9093261\/09093429.pdf?arnumber=9093429","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,6,30]],"date-time":"2022-06-30T15:18:14Z","timestamp":1656602294000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9093429\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,3]]},"references-count":46,"URL":"https:\/\/doi.org\/10.1109\/wacv45572.2020.9093429","relation":{},"subject":[],"published":{"date-parts":[[2020,3]]}}}