{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,24]],"date-time":"2026-07-24T19:44:38Z","timestamp":1784922278441,"version":"3.55.0"},"reference-count":35,"publisher":"Association for Computing Machinery (ACM)","issue":"7","license":[{"start":{"date-parts":[[2018,6,25]],"date-time":"2018-06-25T00:00:00Z","timestamp":1529884800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"ARL","award":["W911NF-13-2-0045"],"award-info":[{"award-number":["W911NF-13-2-0045"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["Commun. ACM"],"published-print":{"date-parts":[[2018,6,25]]},"abstract":"<jats:p>Such inputs distort how machine-learning-based systems are able to function in the world as it is.<\/jats:p>","DOI":"10.1145\/3134599","type":"journal-article","created":{"date-parts":[[2018,6,27]],"date-time":"2018-06-27T12:22:36Z","timestamp":1530102156000},"page":"56-66","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":281,"title":["Making machine learning robust against adversarial inputs"],"prefix":"10.1145","volume":"61","author":[{"given":"Ian","family":"Goodfellow","sequence":"first","affiliation":[{"name":"Google Brain, Mountain View, CA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Patrick","family":"McDaniel","sequence":"additional","affiliation":[{"name":"Pennsylvania State University, University Park, PA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Nicolas","family":"Papernot","sequence":"additional","affiliation":[{"name":"Penn State University, University Park, PA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2018,6,25]]},"reference":[{"key":"e_1_2_1_1_1","first-page":"26","article-title":"Drebin: Effective and explainable detection of Android malware in your pocket. In Proceedings of the NDSS Symposium (San Diego, CA, Feb.). Internet Society, Reston","volume":"23","author":"Arp D.","year":"2014","journal-title":"VA"},{"key":"e_1_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/1128817.1128824"},{"key":"e_1_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1214\/ss\/1042727940"},{"key":"e_1_2_1_4_1","volume-title":"Towards evaluating the robustness of neural networks. arXiv preprint","author":"Carlini N.","year":"2016"},{"key":"e_1_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3133978"},{"key":"e_1_2_1_6_1","volume-title":"Proceedings of the 14th International Conference on Artificial Intelligence and Statistics (Ft","author":"Glorot X.","year":"2011"},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.5555\/3086952"},{"key":"e_1_2_1_8_1","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Goodfellow I.J.","year":"2014"},{"key":"e_1_2_1_9_1","volume-title":"Explaining and harnessing adversarial examples. arXiv preprint","author":"Goodfellow I.J.","year":"2014"},{"key":"e_1_2_1_10_1","volume-title":"Proceedings of the European Symposium on Research in Computer Security","author":"Grosse K.","year":"2017"},{"key":"e_1_2_1_11_1","volume-title":"Distilling the knowledge in a neural network. arXiv preprint","author":"Hinton G.","year":"2015"},{"key":"e_1_2_1_12_1","volume-title":"Adversarial attacks on neural network policies. arXiv preprint","author":"Huang S.","year":"2017"},{"key":"e_1_2_1_13_1","volume-title":"Proceedings of the International Conference on Computer-Aided Verification (2016)","author":"Huang A."},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2009.5459469"},{"key":"e_1_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-63387-9_5"},{"key":"e_1_2_1_16_1","volume-title":"Proceedings of the International Conference on Learning Representations (2017)","author":"Kurakin A."},{"key":"e_1_2_1_17_1","volume-title":"Machine Learning: A Probabilistic Perspective","author":"Murphy K.P.","year":"2012"},{"key":"e_1_2_1_18_1","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Nair V.","year":"2010"},{"key":"e_1_2_1_19_1","unstructured":"Papernot N. Goodfellow I. Sheatsley R. Feinman R. and McDaniel P. CleverHans v2.1.0: An adversarial machine learning library; https:\/\/github.com\/tensorflow\/cleverhans  Papernot N. Goodfellow I. Sheatsley R. Feinman R. and McDaniel P. CleverHans v2.1.0: An adversarial machine learning library; https:\/\/github.com\/tensorflow\/cleverhans"},{"key":"e_1_2_1_20_1","volume-title":"Transferability in machine learning: From phenomena to black-box attacks using adversarial samples. arXiv preprint","author":"Papernot N.","year":"2016"},{"key":"e_1_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"e_1_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"e_1_2_1_23_1","volume-title":"Proceedings of the Third IEEE European Symposium on Security and Privacy","author":"Papernot N."},{"key":"e_1_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.41"},{"key":"e_1_2_1_25_1","first-page":"27","article-title":"Artificial Intelligence: A Modern Approach. Prentice-Hall, Englewood Cliffs","volume":"25","author":"Russell S.","year":"1995","journal-title":"NJ"},{"key":"e_1_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1038\/nature16961"},{"key":"e_1_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.neunet.2012.02.016"},{"key":"e_1_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298594"},{"key":"e_1_2_1_29_1","doi-asserted-by":"crossref","unstructured":"Szegedy C. Vanhoucke V. Ioffe S. Shlens J. and Wojna Z. Rethinking the Inception architecture for computer vision. ArXiv e-prints Dec. 2015; https:\/\/arxiv.org\/abs\/1512.00567  Szegedy C. Vanhoucke V. Ioffe S. Shlens J. and Wojna Z. Rethinking the Inception architecture for computer vision. ArXiv e-prints Dec. 2015; https:\/\/arxiv.org\/abs\/1512.00567","DOI":"10.1109\/CVPR.2016.308"},{"key":"e_1_2_1_30_1","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Szegedy C.","year":"2014"},{"key":"e_1_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2014.220"},{"key":"e_1_2_1_32_1","volume-title":"Ensemble adversarial training: Attacks and defenses. arXiv preprint","author":"Tram\u00e8r F.","year":"2017"},{"key":"e_1_2_1_33_1","volume-title":"Proceedings of the USENIX Security Conference","author":"Tram\u00e8r F.","year":"2016"},{"key":"e_1_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1162\/neco.1996.8.7.1341"},{"key":"e_1_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2016.23115"}],"container-title":["Communications of the ACM"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3134599","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3134599","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T03:30:11Z","timestamp":1750217411000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3134599"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018,6,25]]},"references-count":35,"journal-issue":{"issue":"7","published-print":{"date-parts":[[2018,6,25]]}},"alternative-id":["10.1145\/3134599"],"URL":"https:\/\/doi.org\/10.1145\/3134599","relation":{},"ISSN":["0001-0782","1557-7317"],"issn-type":[{"value":"0001-0782","type":"print"},{"value":"1557-7317","type":"electronic"}],"subject":[],"published":{"date-parts":[[2018,6,25]]},"assertion":[{"value":"2018-06-25","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}