{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,9,8]],"date-time":"2024-09-08T09:50:04Z","timestamp":1725789004613},"reference-count":29,"publisher":"IEEE","license":[{"start":{"date-parts":[[2020,3,1]],"date-time":"2020-03-01T00:00:00Z","timestamp":1583020800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2020,3,1]],"date-time":"2020-03-01T00:00:00Z","timestamp":1583020800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2020,3,1]],"date-time":"2020-03-01T00:00:00Z","timestamp":1583020800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2020,3]]},"DOI":"10.1109\/wacv45572.2020.9093609","type":"proceedings-article","created":{"date-parts":[[2020,5,15]],"date-time":"2020-05-15T03:41:09Z","timestamp":1589514069000},"page":"1341-1349","source":"Crossref","is-referenced-by-count":1,"title":["Multi-way Encoding for Robustness"],"prefix":"10.1109","author":[{"given":"Donghyun","family":"Kim","sequence":"first","affiliation":[]},{"given":"Sarah Adel","family":"Bargal","sequence":"additional","affiliation":[]},{"given":"Jianming","family":"Zhang","sequence":"additional","affiliation":[]},{"given":"Stan","family":"Sclaroff","sequence":"additional","affiliation":[]}],"member":"263","reference":[{"key":"ref10","article-title":"Benchmarking neural network robustness to common corruptions and perturbations","author":"hendrycks","year":"2019","journal-title":"ICLRE"},{"key":"ref11","article-title":"Adversarial logit pairing","author":"kannan","year":"2018","journal-title":"arXiv preprint arXiv 1803 06373"},{"key":"ref12","article-title":"Learning multiple layers of features from tiny images","author":"krizhevsky","year":"2009","journal-title":"Technical Report"},{"key":"ref13","article-title":"Adversarial examples in the physical world","author":"kurakin","year":"2016","journal-title":"arXiv preprint arXiv 1607 02533"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"key":"ref15","article-title":"Nattack: Learning the distributions of adversarial examples for an improved black-box attack on deep neural networks","author":"li","year":"2019","journal-title":"ICML"},{"key":"ref16","article-title":"De-fense against adversarial attacks using high-level representation guided denoiser","author":"liao","year":"2018","journal-title":"CVPR"},{"key":"ref17","article-title":"Delving into transferable adversarial examples and black-box attacks","author":"liu","year":"2017","journal-title":"ICLRE"},{"key":"ref18","article-title":"Towards deep learning models resistant to adversarial attacks","author":"madry","year":"2018","journal-title":"ICLRE"},{"key":"ref19","article-title":"Reading digits in natural images with unsupervised fea ture learning","author":"netzer","year":"2011","journal-title":"NIPS Workshop on Deep Learning and Unsupervised Feature Learning"},{"key":"ref28","doi-asserted-by":"crossref","DOI":"10.1609\/aaai.v29i1.9796","article-title":"Deep representation learning with target coding","author":"yang","year":"2015","journal-title":"AAAI"},{"key":"ref4","article-title":"On evaluating adversarial robustness","author":"carlini","year":"2019","journal-title":"arXiv preprint arXiv 1902 05023"},{"key":"ref27","article-title":"Mitigating adversarial effects through randomization","author":"xie","year":"2018","journal-title":"ICLRE"},{"key":"ref3","article-title":"Thermometer encoding: One hot way to resist adversarial examples","author":"buckman","year":"2018","journal-title":"ICLRE"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1145\/3196494.3196550"},{"key":"ref5","article-title":"Defensive distillation is not robust to adversarial examples","author":"carlini","year":"2016","journal-title":"arXiv preprint arXiv 1607 04311"},{"key":"ref8","article-title":"Adversarial examples are a natural consequence of test error in noise","author":"ford","year":"2019","journal-title":"ICML"},{"key":"ref7","article-title":"Evaluating and understanding the robustness of adversarial logit pairing","author":"engstrom","year":"2018","journal-title":"arXiv preprint arXiv 1807 10272"},{"article-title":"Decision-based adversarial attacks: Reliable attacks against black-box machine learning models","year":"2018","author":"brendel","key":"ref2"},{"key":"ref9","article-title":"Explaining and harnessing adversarial examples","author":"goodfellow","year":"2015","journal-title":"ICLRE"},{"key":"ref1","article-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","author":"athalye","year":"2018","journal-title":"ICML"},{"key":"ref20","article-title":"Transferability in machine learning: from phenomena to black-box attacks using adversarial samples","author":"papernot","year":"2016","journal-title":"arXiv preprint arXiv 1605 01014"},{"key":"ref22","article-title":"Towards the first adversarially robust neural network model on mnist","author":"schott","year":"2018","journal-title":"ICLRE"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1016\/j.imavis.2018.04.004"},{"key":"ref24","article-title":"Intriguing properties of neural networks","author":"szegedy","year":"2014","journal-title":"ICLRE"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.74"},{"key":"ref26","article-title":"Adversarial risk and the dangers of evaluating against weak attacks","author":"uesato","year":"2018","journal-title":"ICML"},{"key":"ref25","article-title":"Ensemble adversarial training: Attacks and defenses","author":"tram\u00e8r","year":"2018","journal-title":"ICLRE"}],"event":{"name":"2020 IEEE Winter Conference on Applications of Computer Vision (WACV)","start":{"date-parts":[[2020,3,1]]},"location":"Snowmass Village, CO, USA","end":{"date-parts":[[2020,3,5]]}},"container-title":["2020 IEEE Winter Conference on Applications of Computer Vision (WACV)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/9087828\/9093261\/09093609.pdf?arnumber=9093609","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,10,23]],"date-time":"2022-10-23T19:44:50Z","timestamp":1666554290000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9093609\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,3]]},"references-count":29,"URL":"https:\/\/doi.org\/10.1109\/wacv45572.2020.9093609","relation":{},"subject":[],"published":{"date-parts":[[2020,3]]}}}