{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T05:48:14Z","timestamp":1760161694880,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":30,"publisher":"ACM","license":[{"start":{"date-parts":[[2019,7,23]],"date-time":"2019-07-23T00:00:00Z","timestamp":1563840000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2019,7,23]]},"DOI":"10.1145\/3354265.3354277","type":"proceedings-article","created":{"date-parts":[[2019,9,12]],"date-time":"2019-09-12T14:21:08Z","timestamp":1568298068000},"page":"1-8","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":11,"title":["A Neuromorphic Sparse Coding Defense to Adversarial Images"],"prefix":"10.1145","author":[{"given":"Edward","family":"Kim","sequence":"first","affiliation":[{"name":"Villanova University, Villanova, Pennsylvania"}]},{"given":"Jessica","family":"Yarnall","sequence":"additional","affiliation":[{"name":"Villanova University, Villanova, Pennsylvania"}]},{"given":"Priya","family":"Shah","sequence":"additional","affiliation":[{"name":"Villanova University, Villanova, Pennsylvania"}]},{"given":"Garrett T.","family":"Kenyon","sequence":"additional","affiliation":[{"name":"Los Alamos National Laboratory, Los Alamos, New Mexico"}]}],"member":"320","published-online":{"date-parts":[[2019,7,23]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Visual-Perception-An Efficient Code in V1. Nature 381, 6583","author":"Baddeley Roland","year":"1996","unstructured":"Roland Baddeley . 1996. Visual-Perception-An Efficient Code in V1. Nature 381, 6583 ( 1996 ), 560--561. Roland Baddeley. 1996. Visual-Perception-An Efficient Code in V1. Nature 381, 6583 (1996), 560--561."},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1007\/BF00332910"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/MM.2018.112130359"},{"key":"e_1_3_2_1_4_1","volume-title":"A study of the effect of jpg compression on adversarial images. arXiv preprint arXiv:1608.00853","author":"Dziugaite Gintare Karolina","year":"2016","unstructured":"Gintare Karolina Dziugaite , Zoubin Ghahramani , and Daniel M Roy . 2016. A study of the effect of jpg compression on adversarial images. arXiv preprint arXiv:1608.00853 ( 2016 ). Gintare Karolina Dziugaite, Zoubin Ghahramani, and Daniel M Roy. 2016. A study of the effect of jpg compression on adversarial images. arXiv preprint arXiv:1608.00853 (2016)."},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1214\/009053604000000067"},{"key":"e_1_3_2_1_6_1","volume-title":"Sparse coding in the primate cortex. The handbook of brain theory and neural networks","author":"Foldiak Peter","year":"2003","unstructured":"Peter Foldiak . 2003. Sparse coding in the primate cortex. The handbook of brain theory and neural networks ( 2003 ). Peter Foldiak. 2003. Sparse coding in the primate cortex. The handbook of brain theory and neural networks (2003)."},{"key":"e_1_3_2_1_7_1","volume-title":"Proceedings of the Fourteenth International Conference on Artificial Intelligence and Statistics. 315--323","author":"Glorot Xavier","year":"2011","unstructured":"Xavier Glorot , Antoine Bordes , and Yoshua Bengio . 2011 . Deep sparse rectifier neural networks . In Proceedings of the Fourteenth International Conference on Artificial Intelligence and Statistics. 315--323 . Xavier Glorot, Antoine Bordes, and Yoshua Bengio. 2011. Deep sparse rectifier neural networks. In Proceedings of the Fourteenth International Conference on Artificial Intelligence and Statistics. 315--323."},{"key":"e_1_3_2_1_8_1","volume-title":"Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572","author":"Goodfellow Ian J","year":"2014","unstructured":"Ian J Goodfellow , Jonathon Shlens , and Christian Szegedy . 2014. Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572 ( 2014 ). Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy. 2014. Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572 (2014)."},{"key":"e_1_3_2_1_9_1","volume-title":"Countering adversarial images using input transformations. arXiv preprint arXiv:1711.00117","author":"Guo Chuan","year":"2017","unstructured":"Chuan Guo , Mayank Rana , Moustapha Cisse , and Laurens van der Maaten . 2017. Countering adversarial images using input transformations. arXiv preprint arXiv:1711.00117 ( 2017 ). Chuan Guo, Mayank Rana, Moustapha Cisse, and Laurens van der Maaten. 2017. Countering adversarial images using input transformations. arXiv preprint arXiv:1711.00117 (2017)."},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2015.123"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.243"},{"key":"e_1_3_2_1_13_1","volume-title":"Measuring the tendency of CNNs to learn surface statistical regularities. arXiv preprint arXiv:1711.11561","author":"Jo Jason","year":"2017","unstructured":"Jason Jo and Yoshua Bengio . 2017. Measuring the tendency of CNNs to learn surface statistical regularities. arXiv preprint arXiv:1711.11561 ( 2017 ). Jason Jo and Yoshua Bengio. 2017. Measuring the tendency of CNNs to learn surface statistical regularities. arXiv preprint arXiv:1711.11561 (2017)."},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00122"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"key":"e_1_3_2_1_16_1","volume-title":"Sparsity-based Defense against Adversarial Attacks on Linear Classifiers. arXiv preprint arXiv:1801.04695","author":"Marzi Zhinus","year":"2018","unstructured":"Zhinus Marzi , Soorya Gopalakrishnan , Upamanyu Madhow , and Ramtin Pedarsani . 2018. Sparsity-based Defense against Adversarial Attacks on Linear Classifiers. arXiv preprint arXiv:1801.04695 ( 2018 ). Zhinus Marzi, Soorya Gopalakrishnan, Upamanyu Madhow, and Ramtin Pedarsani. 2018. Sparsity-based Defense against Adversarial Attacks on Linear Classifiers. arXiv preprint arXiv:1801.04695 (2018)."},{"key":"e_1_3_2_1_17_1","volume-title":"Denoising Dictionary Learning Against Adversarial Perturbations. arXiv preprint arXiv:1801.02257","author":"Mitro John","year":"2018","unstructured":"John Mitro , Derek Bridge , and Steven Prestwich . 2018. Denoising Dictionary Learning Against Adversarial Perturbations. arXiv preprint arXiv:1801.02257 ( 2018 ). John Mitro, Derek Bridge, and Steven Prestwich. 2018. Denoising Dictionary Learning Against Adversarial Perturbations. arXiv preprint arXiv:1801.02257 (2018)."},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"e_1_3_2_1_19_1","volume-title":"Sparse coding with an overcomplete basis set: A strategy employed by V1? Vision research 37, 23","author":"Olshausen Bruno A","year":"1997","unstructured":"Bruno A Olshausen and David J Field . 1997. Sparse coding with an overcomplete basis set: A strategy employed by V1? Vision research 37, 23 ( 1997 ), 3311--3325. Bruno A Olshausen and David J Field. 1997. Sparse coding with an overcomplete basis set: A strategy employed by V1? Vision research 37, 23 (1997), 3311--3325."},{"key":"e_1_3_2_1_20_1","volume-title":"2016 IEEE European Symposium on. IEEE, 372--387","author":"Papernot Nicolas","year":"2016","unstructured":"Nicolas Papernot , Patrick McDaniel , Somesh Jha , Matt Fredrikson , Z Berkay Celik , and Ananthram Swami . 2016 . The limitations of deep learning in adversarial settings. In Security and Privacy (EuroS&P) , 2016 IEEE European Symposium on. IEEE, 372--387 . Nicolas Papernot, Patrick McDaniel, Somesh Jha, Matt Fredrikson, Z Berkay Celik, and Ananthram Swami. 2016. The limitations of deep learning in adversarial settings. In Security and Privacy (EuroS&P), 2016 IEEE European Symposium on. IEEE, 372--387."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICIP.2007.4379981"},{"key":"e_1_3_2_1_22_1","volume-title":"Replicating kernels with a short stride allows sparse reconstructions with fewer independent kernels. arXiv preprint arXiv:1406.4205","author":"Schultz Peter F","year":"2014","unstructured":"Peter F Schultz , Dylan M Paiton , Wei Lu , and Garrett T Kenyon . 2014. Replicating kernels with a short stride allows sparse reconstructions with fewer independent kernels. arXiv preprint arXiv:1406.4205 ( 2014 ). Peter F Schultz, Dylan M Paiton, Wei Lu, and Garrett T Kenyon. 2014. Replicating kernels with a short stride allows sparse reconstructions with fewer independent kernels. arXiv preprint arXiv:1406.4205 (2014)."},{"key":"e_1_3_2_1_23_1","volume-title":"Edward Kim, and Garrett T Kenyon.","author":"Springer Jacob M","year":"2018","unstructured":"Jacob M Springer , Charles S Strauss , Austin M Thresher , Edward Kim, and Garrett T Kenyon. 2018 . Classifiers Based on Deep Sparse Coding Architectures are Robust to Deep Learning Transferable Examples . arXiv preprint arXiv:1811.07211 (2018). Jacob M Springer, Charles S Strauss, Austin M Thresher, Edward Kim, and Garrett T Kenyon. 2018. Classifiers Based on Deep Sparse Coding Architectures are Robust to Deep Learning Transferable Examples. arXiv preprint arXiv:1811.07211 (2018)."},{"key":"e_1_3_2_1_24_1","volume-title":"Danilo Vasconcellos Vargas, and Sakurai Kouichi","author":"Su Jiawei","year":"2017","unstructured":"Jiawei Su , Danilo Vasconcellos Vargas, and Sakurai Kouichi . 2017 . One pixel attack for fooling deep neural networks. arXiv preprint arXiv:1710.08864 (2017). Jiawei Su, Danilo Vasconcellos Vargas, and Sakurai Kouichi. 2017. One pixel attack for fooling deep neural networks. arXiv preprint arXiv:1710.08864 (2017)."},{"key":"e_1_3_2_1_25_1","volume-title":"Danilo Vasconcellos Vargas, and Kouichi Sakurai","author":"Su Jiawei","year":"2019","unstructured":"Jiawei Su , Danilo Vasconcellos Vargas, and Kouichi Sakurai . 2019 . One pixel attack for fooling deep neural networks. IEEE Transactions on Evolutionary Computation ( 2019). Jiawei Su, Danilo Vasconcellos Vargas, and Kouichi Sakurai. 2019. One pixel attack for fooling deep neural networks. IEEE Transactions on Evolutionary Computation (2019)."},{"key":"e_1_3_2_1_26_1","volume-title":"Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199","author":"Szegedy Christian","year":"2013","unstructured":"Christian Szegedy , Wojciech Zaremba , Ilya Sutskever , Joan Bruna , Dumitru Erhan , Ian Goodfellow , and Rob Fergus . 2013. Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199 ( 2013 ). Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus. 2013. Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199 (2013)."},{"key":"e_1_3_2_1_27_1","volume-title":"Sparse coding by spiking neural networks: Convergence theory and computational results. arXiv preprint arXiv:1705.05475","author":"Peter Tang Ping Tak","year":"2017","unstructured":"Ping Tak Peter Tang , Tsung-Han Lin , and Mike Davies . 2017. Sparse coding by spiking neural networks: Convergence theory and computational results. arXiv preprint arXiv:1705.05475 ( 2017 ). Ping Tak Peter Tang, Tsung-Han Lin, and Mike Davies. 2017. Sparse coding by spiking neural networks: Convergence theory and computational results. arXiv preprint arXiv:1705.05475 (2017)."},{"key":"e_1_3_2_1_28_1","volume-title":"Ensemble adversarial training: Attacks and defenses. arXiv preprint arXiv:1705.07204","author":"Tram\u00e8r Florian","year":"2017","unstructured":"Florian Tram\u00e8r , Alexey Kurakin , Nicolas Papernot , Ian Goodfellow , Dan Boneh , and Patrick McDaniel . 2017. Ensemble adversarial training: Attacks and defenses. arXiv preprint arXiv:1705.07204 ( 2017 ). Florian Tram\u00e8r, Alexey Kurakin, Nicolas Papernot, Ian Goodfellow, Dan Boneh, and Patrick McDaniel. 2017. Ensemble adversarial training: Attacks and defenses. arXiv preprint arXiv:1705.07204 (2017)."},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-46484-8_3"},{"key":"e_1_3_2_1_30_1","volume-title":"Feature squeezing mitigates and detects carlini\/wagner adversarial examples. arXiv preprint arXiv:1705.10686","author":"Xu Weilin","year":"2017","unstructured":"Weilin Xu , David Evans , and Yanjun Qi. 2017. Feature squeezing mitigates and detects carlini\/wagner adversarial examples. arXiv preprint arXiv:1705.10686 ( 2017 ). Weilin Xu, David Evans, and Yanjun Qi. 2017. Feature squeezing mitigates and detects carlini\/wagner adversarial examples. arXiv preprint arXiv:1705.10686 (2017)."}],"event":{"name":"ICONS '19: International Conference on Neuromorphic Systems","sponsor":["SIGDA ACM Special Interest Group on Design Automation","Intel Intel"],"location":"Knoxville TN USA","acronym":"ICONS '19"},"container-title":["Proceedings of the International Conference on Neuromorphic Systems"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3354265.3354277","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3354265.3354277","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T23:44:56Z","timestamp":1750203896000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3354265.3354277"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,7,23]]},"references-count":30,"alternative-id":["10.1145\/3354265.3354277","10.1145\/3354265"],"URL":"https:\/\/doi.org\/10.1145\/3354265.3354277","relation":{},"subject":[],"published":{"date-parts":[[2019,7,23]]},"assertion":[{"value":"2019-07-23","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}