{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,11]],"date-time":"2026-04-11T09:31:17Z","timestamp":1775899877289,"version":"3.50.1"},"publisher-location":"New York, NY, USA","reference-count":35,"publisher":"ACM","license":[{"start":{"date-parts":[[2018,12,29]],"date-time":"2018-12-29T00:00:00Z","timestamp":1546041600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2018,12,29]]},"DOI":"10.1145\/3301551.3301588","type":"proceedings-article","created":{"date-parts":[[2019,3,11]],"date-time":"2019-03-11T12:33:01Z","timestamp":1552307581000},"page":"25-30","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":3,"title":["Detecting Adversarial Perturbations with Salieny"],"prefix":"10.1145","author":[{"given":"Chiliang","family":"Zhang","sequence":"first","affiliation":[{"name":"Tsinghua University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zhimou","family":"Yang","sequence":"additional","affiliation":[{"name":"Northeastern University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zuochang","family":"Ye","sequence":"additional","affiliation":[{"name":"Tsinghua University"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2018,12,29]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Tensorflow: Large-scale machine learning on heterogeneous distributed systems. arXiv preprint arXiv:1603.04467","author":"Abadi Mart\u00edn","year":"2016","unstructured":"Mart\u00edn Abadi , Ashish Agarwal , Paul Barham , Eugene Brevdo , Zhifeng Chen , Craig Citro , Greg S Corrado , Andy Davis , Jeffrey Dean , Matthieu Devin , 2016 . Tensorflow: Large-scale machine learning on heterogeneous distributed systems. arXiv preprint arXiv:1603.04467 (2016).. Mart\u00edn Abadi, Ashish Agarwal, Paul Barham, Eugene Brevdo, Zhifeng Chen, Craig Citro, Greg S Corrado, Andy Davis, Jeffrey Dean, Matthieu Devin, et al. 2016. Tensorflow: Large-scale machine learning on heterogeneous distributed systems. arXiv preprint arXiv:1603.04467 (2016).."},{"key":"e_1_3_2_1_2_1","volume-title":"Journal of Machine Learning Research","author":"Baehrens David","year":"2010","unstructured":"David Baehrens , Timon Schroeter , Stefan Harmeling , Motoaki Kawanabe , Katja Hansen , and Klaus-Robert M\u00c3\u017eller . 2010 . How to explain individual classification decisions . Journal of Machine Learning Research 11, Jun (2010), 1803--1831.. David Baehrens, Timon Schroeter, Stefan Harmeling, Motoaki Kawanabe, Katja Hansen, and Klaus-Robert M\u00c3\u017eller. 2010. How to explain individual classification decisions. Journal of Machine Learning Research 11, Jun (2010), 1803--1831.."},{"key":"e_1_3_2_1_3_1","unstructured":"Osbert Bastani Yani Ioannou Leonidas Lampropoulos Dimitrios Vytiniotis Aditya Nori and Antonio Criminisi. 2016. Measuring Neural Net Robustness with Constraints. (2016).   Osbert Bastani Yani Ioannou Leonidas Lampropoulos Dimitrios Vytiniotis Aditya Nori and Antonio Criminisi. 2016. Measuring Neural Net Robustness with Constraints. (2016)."},{"key":"e_1_3_2_1_4_1","unstructured":"Arjun Nitin Bhagoji Daniel Cullina and Prateek Mittal. 2017. Dimensionality Reduction as a Defense against Evasion Attacks on Machine Learning Classifiers. (2017).  Arjun Nitin Bhagoji Daniel Cullina and Prateek Mittal. 2017. Dimensionality Reduction as a Defense against Evasion Attacks on Machine Learning Classifiers. (2017)."},{"key":"e_1_3_2_1_5_1","volume-title":"Adversarial Examples Are Not Easily Detected: Bypassing Ten Detection Methods. arXiv preprint arXiv:1705.07263","author":"Carlini Nicholas","year":"2017","unstructured":"Nicholas Carlini and David Wagner . 2017. Adversarial Examples Are Not Easily Detected: Bypassing Ten Detection Methods. arXiv preprint arXiv:1705.07263 ( 2017 ). Nicholas Carlini and David Wagner. 2017. Adversarial Examples Are Not Easily Detected: Bypassing Ten Detection Methods. arXiv preprint arXiv:1705.07263 (2017)."},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"e_1_3_2_1_7_1","unstructured":"Hendrycks Dan and Kevin Gimpel. 2017. Early Methods for Detecting Adversarial Images. (2017).  Hendrycks Dan and Kevin Gimpel. 2017. Early Methods for Detecting Adversarial Images. (2017)."},{"key":"e_1_3_2_1_8_1","volume-title":"Detecting Adversarial Samples from Artifacts. arXiv preprint arXiv:1703.00410","author":"Feinman Reuben","year":"2017","unstructured":"Reuben Feinman , Ryan R Curtin , Saurabh Shintre , and Andrew B Gardner . 2017. Detecting Adversarial Samples from Artifacts. arXiv preprint arXiv:1703.00410 ( 2017 . Reuben Feinman, Ryan R Curtin, Saurabh Shintre, and Andrew B Gardner. 2017. Detecting Adversarial Samples from Artifacts. arXiv preprint arXiv:1703.00410 (2017."},{"key":"e_1_3_2_1_9_1","volume-title":"Adversarial and Clean Data Are Not Twins. arXiv preprint arXiv:1704.04960","author":"Gong Zhitao","year":"2017","unstructured":"Zhitao Gong , Wenlu Wang , and Wei-Shinn Ku. 2017. Adversarial and Clean Data Are Not Twins. arXiv preprint arXiv:1704.04960 ( 2017 ). Zhitao Gong, Wenlu Wang, and Wei-Shinn Ku. 2017. Adversarial and Clean Data Are Not Twins. arXiv preprint arXiv:1704.04960 (2017)."},{"key":"e_1_3_2_1_10_1","volume-title":"Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572","author":"Goodfellow Ian J","year":"2014","unstructured":"Ian J Goodfellow , Jonathon Shlens , and Christian Szegedy . 2014. Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572 ( 2014 ). Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy. 2014. Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572 (2014)."},{"key":"e_1_3_2_1_11_1","unstructured":"Kathrin Grosse Praveen Manoharan Nicolas Papernot Michael Backes and Patrick McDaniel. 2017. On the (statistical) detection of adversarial examples. arXiv preprint arXiv:1702.06280 (2017)  Kathrin Grosse Praveen Manoharan Nicolas Papernot Michael Backes and Patrick McDaniel. 2017. On the (statistical) detection of adversarial examples. arXiv preprint arXiv:1702.06280 (2017)"},{"key":"e_1_3_2_1_12_1","unstructured":"Shixiang Gu and Luca Rigazio. 2014. Towards Deep Neural Network Architec- tures Robust to Adversarial Examples. Computer Science (2014)  Shixiang Gu and Luca Rigazio. 2014. Towards Deep Neural Network Architec- tures Robust to Adversarial Examples. Computer Science (2014)"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"e_1_3_2_1_14_1","unstructured":"Ruitong Huang Bing Xu Dale Schuurmans and Csaba Szepesvari. 2015. Learn- ing with a Strong Adversary. Computer Science (2015)  Ruitong Huang Bing Xu Dale Schuurmans and Csaba Szepesvari. 2015. Learn- ing with a Strong Adversary. Computer Science (2015)"},{"key":"e_1_3_2_1_15_1","volume-title":"Robust Convolu- tional Neural Networks under Adversarial Noise. Computer Science","author":"Jin Jonghoon","year":"2015","unstructured":"Jonghoon Jin , Aysegul Dundar , and Eugenio Culurciello . 2015. Robust Convolu- tional Neural Networks under Adversarial Noise. Computer Science ( 2015 ).. Jonghoon Jin, Aysegul Dundar, and Eugenio Culurciello. 2015. Robust Convolu- tional Neural Networks under Adversarial Noise. Computer Science (2015).."},{"key":"e_1_3_2_1_16_1","volume-title":"Adam: A method for stochastic optimiza- tion. arXiv preprint arXiv:1412.6980","author":"Kingma Diederik","year":"2014","unstructured":"Diederik Kingma and Jimmy Ba . 2014 . Adam: A method for stochastic optimiza- tion. arXiv preprint arXiv:1412.6980 (2014). Diederik Kingma and Jimmy Ba. 2014. Adam: A method for stochastic optimiza- tion. arXiv preprint arXiv:1412.6980 (2014)."},{"key":"e_1_3_2_1_17_1","unstructured":"Alex Krizhevsky and Geoffrey Hinton. 2009. Learning multiple layers of features from tiny images. (2009).  Alex Krizhevsky and Geoffrey Hinton. 2009. Learning multiple layers of features from tiny images. (2009)."},{"key":"e_1_3_2_1_18_1","unstructured":"Alex Krizhevsky Ilya Sutskever and Geoffrey E Hinton. 2012. Imagenet classifi- cation with deep convolutional neural networks. In Advances in neural information processing systems. 1097--1105.   Alex Krizhevsky Ilya Sutskever and Geoffrey E Hinton. 2012. Imagenet classifi- cation with deep convolutional neural networks. In Advances in neural information processing systems. 1097--1105."},{"key":"e_1_3_2_1_19_1","unstructured":"Alexey Kurakin Ian Goodfellow and Samy Bengio. 2016. Adversarial examples in the physical world. arXiv preprint arXiv:1607.02533 (2016)  Alexey Kurakin Ian Goodfellow and Samy Bengio. 2016. Adversarial examples in the physical world. arXiv preprint arXiv:1607.02533 (2016)"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"crossref","unstructured":"Xin Li and Fuxin Li. 2016. Adversarial Examples Detection in Deep Networks with Convolutional Filter Statistics. (2016).  Xin Li and Fuxin Li. 2016. Adversarial Examples Detection in Deep Networks with Convolutional Filter Statistics. (2016).","DOI":"10.1109\/ICCV.2017.615"},{"key":"e_1_3_2_1_21_1","unstructured":"Jan Hendrik Metzen Tim Genewein Volker Fischer and Bastian Bischoff. 2017.On Detecting Adversarial Perturbations. (2017).  Jan Hendrik Metzen Tim Genewein Volker Fischer and Bastian Bischoff. 2017.On Detecting Adversarial Perturbations. (2017)."},{"key":"e_1_3_2_1_22_1","volume-title":"ON DETECTING ADVERSARIAL PERTURBATIONS. stat 1050","author":"Metzen Jan Hendrik","year":"2017","unstructured":"Jan Hendrik Metzen , Tim Genewein , Volker Fischer , and Bastian Bischoff . 2017. ON DETECTING ADVERSARIAL PERTURBATIONS. stat 1050 ( 2017 ), 21. Jan Hendrik Metzen, Tim Genewein, Volker Fischer, and Bastian Bischoff. 2017. ON DETECTING ADVERSARIAL PERTURBATIONS. stat 1050 (2017), 21."},{"key":"e_1_3_2_1_23_1","first-page":"v2","author":"Reuben Feinman Fartash Faghri Ian Goodfellow","year":"2017","unstructured":"Ian Goodfellow Reuben Feinman Fartash Faghri Alexander Matyasko Karen Hambardzumyan Yi-Lin Juang Alexey Kurakin Ryan Sheatsley Abhibhav Garg Yen-Chen Lin Nicolas Papernot , Nicholas Carlini. 2017 . cleverhans v2 .0.0: an adversarial machine learning library. arXiv preprint arXiv:1610.00768 (2017). Ian Goodfellow Reuben Feinman Fartash Faghri Alexander Matyasko Karen Hambardzumyan Yi-Lin Juang Alexey Kurakin Ryan Sheatsley Abhibhav Garg Yen-Chen Lin Nicolas Papernot, Nicholas Carlini. 2017. cleverhans v2.0.0: an adversarial machine learning library. arXiv preprint arXiv:1610.00768 (2017).","journal-title":"Nicholas Carlini."},{"key":"e_1_3_2_1_24_1","unstructured":"Nicolas Papernot Patrick Mcdaniel Somesh Jha Matt Fredrikson Z. Berkay Celik and Ananthram Swami. 2015. The Limitations of Deep Learning in Adver- sarial Settings. (2015) 372--387.  Nicolas Papernot Patrick Mcdaniel Somesh Jha Matt Fredrikson Z. Berkay Celik and Ananthram Swami. 2015. The Limitations of Deep Learning in Adver- sarial Settings. (2015) 372--387."},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-015-0816-y"},{"key":"e_1_3_2_1_26_1","volume-title":"Grad-CAM: Why did you say that? arXiv preprint arXiv:1611.07450","author":"Selvaraju Ramprasaath R","year":"2016","unstructured":"Ramprasaath R Selvaraju , Abhishek Das , Ramakrishna Vedantam , Michael Cogswell , Devi Parikh , and Dhruv Batra . 2016. Grad-CAM: Why did you say that? arXiv preprint arXiv:1611.07450 ( 2016 ). Ramprasaath R Selvaraju, Abhishek Das, Ramakrishna Vedantam, Michael Cogswell, Devi Parikh, and Dhruv Batra. 2016. Grad-CAM: Why did you say that? arXiv preprint arXiv:1611.07450 (2016)."},{"key":"e_1_3_2_1_27_1","volume-title":"Understanding Ad- versarial Training: Increasing Local Stability of Neural Nets through Robust Optimization. Computer Science","author":"Shaham Uri","year":"2015","unstructured":"Uri Shaham , Yutaro Yamada , and Sahand Negahban . 2015. Understanding Ad- versarial Training: Increasing Local Stability of Neural Nets through Robust Optimization. Computer Science ( 2015 ). Uri Shaham, Yutaro Yamada, and Sahand Negahban. 2015. Understanding Ad- versarial Training: Increasing Local Stability of Neural Nets through Robust Optimization. Computer Science (2015)."},{"key":"e_1_3_2_1_28_1","volume-title":"Deep inside convolutional networks: Visualising image classification models and saliency maps. arXiv preprint arXiv:1312.6034","author":"Simonyan Karen","year":"2013","unstructured":"Karen Simonyan , Andrea Vedaldi , and Andrew Zisserman . 2013. Deep inside convolutional networks: Visualising image classification models and saliency maps. arXiv preprint arXiv:1312.6034 ( 2013 ).. Karen Simonyan, Andrea Vedaldi, and Andrew Zisserman. 2013. Deep inside convolutional networks: Visualising image classification models and saliency maps. arXiv preprint arXiv:1312.6034 (2013).."},{"key":"e_1_3_2_1_29_1","volume-title":"Very deep convolutional networks for large-scale image recognition. arXiv preprint arXiv:1409.1556","author":"Simonyan Karen","year":"2014","unstructured":"Karen Simonyan and Andrew Zisserman . 2014. Very deep convolutional networks for large-scale image recognition. arXiv preprint arXiv:1409.1556 ( 2014 ). Karen Simonyan and Andrew Zisserman. 2014. Very deep convolutional networks for large-scale image recognition. arXiv preprint arXiv:1409.1556 (2014)."},{"key":"e_1_3_2_1_30_1","volume-title":"Striving for simplicity: The all convolutional net. arXiv preprint arXiv:1412.6806","author":"Springenberg Jost Tobias","year":"2014","unstructured":"Jost Tobias Springenberg , Alexey Dosovitskiy , Thomas Brox , and Martin Ried- miller. 2014. Striving for simplicity: The all convolutional net. arXiv preprint arXiv:1412.6806 ( 2014 ). Jost Tobias Springenberg, Alexey Dosovitskiy, Thomas Brox, and Martin Ried- miller. 2014. Striving for simplicity: The all convolutional net. arXiv preprint arXiv:1412.6806 (2014)."},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298594"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-10590-1_53"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"crossref","unstructured":"Stephan Zheng Yang Song Thomas Leung and Ian Goodfellow. 2016. Improving the Robustness of Deep Neural Networks via Stability Training. In Computer Vision and Pattern Recognition. 4480--4488.  Stephan Zheng Yang Song Thomas Leung and Ian Goodfellow. 2016. Improving the Robustness of Deep Neural Networks via Stability Training. In Computer Vision and Pattern Recognition. 4480--4488.","DOI":"10.1109\/CVPR.2016.485"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.319"},{"key":"e_1_3_2_1_35_1","volume-title":"A new method to visualize deep neural networks. arXiv preprint arXiv:1603.02518","author":"Zintgraf Luisa M","year":"2016","unstructured":"Luisa M Zintgraf , Taco S Cohen , and Max Welling . 2016. A new method to visualize deep neural networks. arXiv preprint arXiv:1603.02518 ( 2016 ). Luisa M Zintgraf, Taco S Cohen, and Max Welling. 2016. A new method to visualize deep neural networks. arXiv preprint arXiv:1603.02518 (2016)."}],"event":{"name":"ICIT 2018: IoT and Smart City","location":"Hong Kong Hong Kong","acronym":"ICIT 2018","sponsor":["The Hong Kong Polytechnic The Hong Kong Polytechnic University","TU Tianjin University"]},"container-title":["Proceedings of the 6th International Conference on Information Technology: IoT and Smart City"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3301551.3301588","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3301551.3301588","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T00:57:35Z","timestamp":1750208255000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3301551.3301588"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018,12,29]]},"references-count":35,"alternative-id":["10.1145\/3301551.3301588","10.1145\/3301551"],"URL":"https:\/\/doi.org\/10.1145\/3301551.3301588","relation":{},"subject":[],"published":{"date-parts":[[2018,12,29]]},"assertion":[{"value":"2018-12-29","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}