{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,6]],"date-time":"2026-04-06T10:20:38Z","timestamp":1775470838345,"version":"3.50.1"},"publisher-location":"New York, NY, USA","reference-count":93,"publisher":"ACM","license":[{"start":{"date-parts":[[2020,6,27]],"date-time":"2020-06-27T00:00:00Z","timestamp":1593216000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100007515","name":"National Science Foundation","doi-asserted-by":"publisher","award":["1845893"],"award-info":[{"award-number":["1845893"]}],"id":[{"id":"10.13039\/100007515","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2020,6,27]]},"DOI":"10.1145\/3377811.3380400","type":"proceedings-article","created":{"date-parts":[[2020,10,1]],"date-time":"2020-10-01T18:25:34Z","timestamp":1601576734000},"page":"1122-1134","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":24,"title":["Testing DNN image classifiers for confusion &amp; bias errors"],"prefix":"10.1145","author":[{"given":"Yuchi","family":"Tian","sequence":"first","affiliation":[{"name":"Columbia University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ziyuan","family":"Zhong","sequence":"additional","affiliation":[{"name":"Columbia University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Vicente","family":"Ordonez","sequence":"additional","affiliation":[{"name":"University of Virginia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Gail","family":"Kaiser","sequence":"additional","affiliation":[{"name":"Columbia University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Baishakhi","family":"Ray","sequence":"additional","affiliation":[{"name":"Columbia University"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2020,10]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"2017. Base pretrained models and datasets in pytorch. https:\/\/github.com\/aaron-xichen\/pytorch-playground"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jss.2009.06.055"},{"key":"e_1_3_2_1_3_1","unstructured":"Solon Barocas Moritz Hardt and Arvind Narayanan. 2018. Fairness and Machine Learning. fairmlbook.org. http:\/\/www.fairmlbook.org."},{"key":"e_1_3_2_1_4_1","unstructured":"Osbert Bastani Yani Ioannou Leonidas Lampropoulos Dimitrios Vytiniotis Aditya Nori and Antonio Criminisi. 2016. Measuring neural net robustness with constraints. In Advances in Neural Information Processing Systems. 2613--2621."},{"key":"e_1_3_2_1_5_1","volume-title":"Network Dissection: Quantifying Interpretability of Deep Visual Representations. In Computer Vision and Pattern Recognition.","author":"Bau David","year":"2017","unstructured":"David Bau, Bolei Zhou, Aditya Khosla, Aude Oliva, and Antonio Torralba. 2017. Network Dissection: Quantifying Interpretability of Deep Visual Representations. In Computer Vision and Pattern Recognition."},{"key":"e_1_3_2_1_6_1","volume-title":"Representation learning: A review and new perspectives","author":"Bengio Yoshua","year":"2013","unstructured":"Yoshua Bengio, Aaron Courville, and Pascal Vincent. 2013. Representation learning: A review and new perspectives. IEEE transactions on pattern analysis and machine intelligence 35, 8 (2013), 1798--1828."},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/3236024.3264838"},{"key":"e_1_3_2_1_8_1","volume-title":"Gender Shades: Intersectional Accuracy Disparities in Commercial Gender Classification. In FAT.","author":"Buolamwini Joy","year":"2018","unstructured":"Joy Buolamwini and Timnit Gebru. 2018. Gender Shades: Intersectional Accuracy Disparities in Commercial Gender Classification. In FAT."},{"key":"e_1_3_2_1_9_1","volume-title":"Building Classifiers with Independency Constraints. In 2009 IEEE International Conference on Data Mining Workshops. 13--18","author":"Calders T.","unstructured":"T. Calders, F. Kamiran, and M. Pechenizkiy. 2009. Building Classifiers with Independency Constraints. In 2009 IEEE International Conference on Data Mining Workshops. 13--18."},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"e_1_3_2_1_11_1","volume-title":"Towards interpretable deep neural networks by leveraging adversarial examples. arXiv preprint arXiv:1708.05493","author":"Dong Yinpeng","year":"2017","unstructured":"Yinpeng Dong, Hang Su, Jun Zhu, and Fan Bao. 2017. Towards interpretable deep neural networks by leveraging adversarial examples. arXiv preprint arXiv:1708.05493 (2017)."},{"key":"e_1_3_2_1_12_1","volume-title":"Empirical Risk Minimization Under Fairness Constraints. In Advances in Neural Information Processing Systems 31: Annual Conference on Neural Information Processing Systems 2018","author":"Donini Michele","year":"2018","unstructured":"Michele Donini, Luca Oneto, Shai Ben-David, John Shawe-Taylor, and Massimiliano Pontil. 2018. Empirical Risk Minimization Under Fairness Constraints. In Advances in Neural Information Processing Systems 31: Annual Conference on Neural Information Processing Systems 2018, NeurIPS 2018, 3-8 December 2018, Montr\u00e9al, Canada. 2796--2806. http:\/\/papers.nips.cc\/paper\/7544-empirical-risk-minimization-under-fairness-constraints"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/2090236.2090255"},{"key":"e_1_3_2_1_14_1","volume-title":"Robust Physical-World Attacks on Machine Learning Models. arXiv preprint arXiv:1707.08945","author":"Evtimov Ivan","year":"2017","unstructured":"Ivan Evtimov, Kevin Eykholt, Earlence Fernandes, Tadayoshi Kohno, Bo Li, Atul Prakash, Amir Rahmati, and Dawn Song. 2017. Robust Physical-World Attacks on Machine Learning Models. arXiv preprint arXiv:1707.08945 (2017)."},{"key":"e_1_3_2_1_15_1","volume-title":"Detecting Adversarial Samples from Artifacts. arXiv preprint arXiv:1703.00410","author":"Feinman Reuben","year":"2017","unstructured":"Reuben Feinman, Ryan R Curtin, Saurabh Shintre, and Andrew B Gardner. 2017. Detecting Adversarial Samples from Artifacts. arXiv preprint arXiv:1703.00410 (2017)."},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/3106237.3106277"},{"key":"e_1_3_2_1_17_1","volume-title":"International Conference on Learning Representations (ICLR).","author":"Goodfellow Ian J","year":"2015","unstructured":"Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy. 2015. Explaining and harnessing adversarial examples. In International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_1_18_1","volume-title":"On the (statistical) detection of adversarial examples. arXiv preprint arXiv:1702.06280","author":"Grosse Kathrin","year":"2017","unstructured":"Kathrin Grosse, Praveen Manoharan, Nicolas Papernot, Michael Backes, and Patrick McDaniel. 2017. On the (statistical) detection of adversarial examples. arXiv preprint arXiv:1702.06280 (2017)."},{"key":"e_1_3_2_1_19_1","unstructured":"Loren Grush. 2015. Google engineer apologizes after Photos app tags two black people as gorillas. (2015). https:\/\/www.theverge.com\/2015\/7\/1\/8880363\/google-apologizes-photos-app-tags-two-black-people-gorillas"},{"key":"e_1_3_2_1_20_1","volume-title":"International Conference on Learning Representations (ICLR).","author":"Gu Shixiang","year":"2015","unstructured":"Shixiang Gu and Luca Rigazio. 2015. Towards deep neural network architectures robust to adversarial examples. In International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.5555\/3157382.3157469"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"e_1_3_2_1_23_1","volume-title":"Proceedings of the 11th USENIX Conference on Offensive Technologies","author":"He Warren","year":"2017","unstructured":"Warren He, James Wei, Xinyun Chen, Nicholas Carlini, and Dawn Song. 2017. Adversarial Example Defenses: Ensembles of Weak Defenses Are Not Strong. In Proceedings of the 11th USENIX Conference on Offensive Technologies (Vancouver, BC, Canada) (WOOT'17). USENIX Association, Berkeley, CA, USA, 15--15. http:\/\/dl.acm.org\/citation.cfm?id=3154768.3154783"},{"key":"e_1_3_2_1_24_1","volume-title":"Adversarial attacks on neural network policies. arXiv preprint arXiv:1702.02284","author":"Huang Sandy","year":"2017","unstructured":"Sandy Huang, Nicolas Papernot, Ian Goodfellow, Yan Duan, and Pieter Abbeel. 2017. Adversarial attacks on neural network policies. arXiv preprint arXiv:1702.02284 (2017)."},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-63387-9_1"},{"key":"e_1_3_2_1_26_1","first-page":"1005","article-title":"A survey on image classification approaches and techniques","volume":"2","author":"Kamavisdar Pooja","year":"2013","unstructured":"Pooja Kamavisdar, Sonam Saluja, and Sonu Agrawal. 2013. A survey on image classification approaches and techniques. International Journal of Advanced Research in Computer and Communication Engineering 2, 1 (2013), 1005--1009.","journal-title":"International Journal of Advanced Research in Computer and Communication Engineering"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSM.2010.5609530"},{"key":"e_1_3_2_1_28_1","volume-title":"Kochenderfer","author":"Katz Guy","year":"2017","unstructured":"Guy Katz, Clark Barrett, David L. Dill, Kyle Julian, and Mykel J. Kochenderfer. 2017. Reluplex: An Efficient SMT Solver for Verifying Deep Neural Networks. Springer International Publishing, Cham, 97--117."},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2019.00108"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.3113\/JSOA.2017.0227"},{"key":"e_1_3_2_1_31_1","volume-title":"Adversarial examples for generative models. arXiv preprint arXiv:1702.06832","author":"Kos Jernej","year":"2017","unstructured":"Jernej Kos, Ian Fischer, and Dawn Song. 2017. Adversarial examples for generative models. arXiv preprint arXiv:1702.06832 (2017)."},{"key":"e_1_3_2_1_32_1","unstructured":"Alex Krizhevsky. 2012. Learning Multiple Layers of Features from Tiny Images. University of Toronto (05 2012)."},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1080\/01621459.1952.10483441"},{"key":"e_1_3_2_1_34_1","volume-title":"Workshop track at International Conference on Learning Representations (ICLR).","author":"Kurakin Alexey","year":"2017","unstructured":"Alexey Kurakin, Ian Goodfellow, and Samy Bengio. 2017. Adversarial examples in the physical world. In Workshop track at International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_1_35_1","unstructured":"Matt J Kusner Joshua Loftus Chris Russell and Ricardo Silva. 2017. Counterfactual Fairness. In Advances in Neural Information Processing Systems 30. 4066--4076."},{"key":"e_1_3_2_1_36_1","volume-title":"Aditya Krishna Menon, and Nakul Verma","author":"Lamy Alexandre Louis","year":"2019","unstructured":"Alexandre Louis Lamy, Ziyuan Zhong, Aditya Krishna Menon, and Nakul Verma. 2019. Noise-tolerant fair classification. CoRR abs\/1901.10837 (2019). arXiv:1901.10837 http:\/\/arxiv.org\/abs\/1901.10837"},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-10602-1_48"},{"key":"e_1_3_2_1_39_1","volume-title":"Proceedings of the 33rd International Conference on Machine Learning Workshop","author":"Lipton Zachary C","year":"2016","unstructured":"Zachary C Lipton. 2016. The mythos of model interpretability. Proceedings of the 33rd International Conference on Machine Learning Workshop (2016)."},{"key":"e_1_3_2_1_40_1","volume-title":"Spotlight Oral Workshop at Proceedings of the IEEE conference on computer vision and pattern recognition.","author":"Lu Jiajun","year":"2017","unstructured":"Jiajun Lu, Hussein Sibai, Evan Fabry, and David Forsyth. 2017. No need to worry about adversarial examples in object detection in autonomous vehicles. In Spotlight Oral Workshop at Proceedings of the IEEE conference on computer vision and pattern recognition."},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/2020408.2020488"},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","unstructured":"Lei Ma Felix Juefei-Xu Fuyuan Zhang Jiyuan Sun Minhui Xue Bo Li Chunyang Chen Ting Su Li Li Yang Liu Jianjun Zhao and Yadong Wang. 2018. DeepGauge: Multi-granularity Testing Criteria for Deep Learning Systems. (2018) 120--131. 10.1145\/3238147.3238202","DOI":"10.1145\/3238147.3238202"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/3236024.3236082"},{"key":"e_1_3_2_1_44_1","unstructured":"MalletsDarker. 2018. I took a few shots at Lake Louise today and Google offered me this panorama. (2018). https:\/\/www.reddit.com\/r\/funny\/comments\/7r9ptc\/i_took_a_few_shots_at_lake_louise_today_and\/dsvv1nw\/"},{"key":"e_1_3_2_1_45_1","volume-title":"Advances in Neural Information Processing Systems 32, H. Wallach, H. Larochelle, A. Beygelzimer, F. d'Alch\u00e9-Buc","author":"Mao Chengzhi","unstructured":"Chengzhi Mao, Ziyuan Zhong, Junfeng Yang, Carl Vondrick, and Baishakhi Ray. 2019. Metric Learning for Adversarial Robustness. In Advances in Neural Information Processing Systems 32, H. Wallach, H. Larochelle, A. Beygelzimer, F. d'Alch\u00e9-Buc, E. Fox, and R. Garnett (Eds.). Curran Associates, Inc., 478--489. http:\/\/papers.nips.cc\/paper\/8339-metric-learning-for-adversarial-robustness.pdf"},{"key":"e_1_3_2_1_46_1","volume-title":"Conference on Fairness, Accountability and Transparency, FAT 2018","author":"Menon Aditya Krishna","year":"2018","unstructured":"Aditya Krishna Menon and Robert C. Williamson. 2018. The cost of fairness in binary classification. In Conference on Fairness, Accountability and Transparency, FAT 2018, 23-24 February 2018, New York, NY, USA. 107--118. http:\/\/proceedings.mlr.press\/v81\/menon18a.html"},{"key":"e_1_3_2_1_47_1","volume-title":"International Conference on Learning Representations (ICLR).","author":"Metzen Jan Hendrik","year":"2017","unstructured":"Jan Hendrik Metzen, Tim Genewein, Volker Fischer, and Bastian Bischoff. 2017. On detecting adversarial perturbations. In International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_1_48_1","volume-title":"Machine Learning (1 ed.)","author":"Mitchell Thomas M.","unstructured":"Thomas M. Mitchell. 1997. Machine Learning (1 ed.). McGraw-Hill, Inc., New York, NY, USA."},{"key":"e_1_3_2_1_49_1","volume-title":"Methods for interpreting and understanding deep neural networks. Digital Signal Processing","author":"Montavon Gr\u00e9goire","year":"2017","unstructured":"Gr\u00e9goire Montavon, Wojciech Samek, and Klaus-Robert M\u00fcller. 2017. Methods for interpreting and understanding deep neural networks. Digital Signal Processing (2017)."},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.5555\/3104322.3104425"},{"key":"e_1_3_2_1_51_1","volume-title":"Workshop on Adversarial Training, NIPS","author":"Narodytska Nina","year":"2016","unstructured":"Nina Narodytska and Shiva Prasad Kasiviswanathan. 2016. Simple black-box adversarial perturbations for deep networks. In Workshop on Adversarial Training, NIPS 2016."},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298640"},{"key":"e_1_3_2_1_53_1","volume-title":"Proceedings of the 36th International Conference on Machine Learning (Proceedings of Machine Learning Research), Kamalika Chaudhuri and Ruslan Salakhutdinov (Eds.)","volume":"97","author":"Odena Augustus","year":"2019","unstructured":"Augustus Odena, Catherine Olsson, David Andersen, and Ian Goodfellow. 2019. TensorFuzz: Debugging Neural Networks with Coverage-Guided Fuzzing. In Proceedings of the 36th International Conference on Machine Learning (Proceedings of Machine Learning Research), Kamalika Chaudhuri and Ruslan Salakhutdinov (Eds.), Vol. 97. PMLR, Long Beach, California, USA, 4901--4911. http:\/\/proceedings.mlr.press\/v97\/odena19a.html"},{"key":"e_1_3_2_1_54_1","unstructured":"Nicolas Papernot Nicholas Carlini Ian Goodfellow Reuben Feinman Fartash Faghri Alexander Matyasko Karen Hambardzumyan Yi-Lin Juang Alexey Kurakin Ryan Sheatsley et al. 2016. cleverhans v2. 0.0: an adversarial machine learning library. arXiv preprint arXiv:1610.00768 (2016)."},{"key":"e_1_3_2_1_55_1","volume-title":"Extending Defensive Distillation. arXiv preprint arXiv:1705.05264","author":"Papernot Nicolas","year":"2017","unstructured":"Nicolas Papernot and Patrick McDaniel. 2017. Extending Defensive Distillation. arXiv preprint arXiv:1705.05264 (2017)."},{"key":"e_1_3_2_1_56_1","volume-title":"Deep k-Nearest Neighbors: Towards Confident, Interpretable and Robust Deep Learning. arXiv preprint arXiv:1803.04765","author":"Papernot Nicolas","year":"2018","unstructured":"Nicolas Papernot and Patrick McDaniel. 2018. Deep k-Nearest Neighbors: Towards Confident, Interpretable and Robust Deep Learning. arXiv preprint arXiv:1803.04765 (2018)."},{"key":"e_1_3_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"e_1_3_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"e_1_3_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.41"},{"key":"e_1_3_2_1_60_1","doi-asserted-by":"publisher","unstructured":"Kexin Pei Yinzhi Cao Junfeng Yang and Suman Jana. 2017. DeepXplore: Automated Whitebox Testing of Deep Learning Systems. (2017) 1--18. 10.1145\/3132747.3132785","DOI":"10.1145\/3132747.3132785"},{"key":"e_1_3_2_1_61_1","volume-title":"Towards Practical Verification of Machine Learning: The Case of Computer Vision Systems. arXiv preprint arXiv:1712.01785","author":"Pei Kexin","year":"2017","unstructured":"Kexin Pei, Yinzhi Cao, Junfeng Yang, and Suman Jana. 2017. Towards Practical Verification of Machine Learning: The Case of Computer Vision Systems. arXiv preprint arXiv:1712.01785 (2017)."},{"key":"e_1_3_2_1_62_1","volume-title":"6th International Conference on Learning Representations (ICLR)","author":"Raghunathan Aditi","year":"2018","unstructured":"Aditi Raghunathan, Jacob Steinhardt, and Percy Liang. 2018. Certified defenses against adversarial examples. 6th International Conference on Learning Representations (ICLR) (2018)."},{"key":"e_1_3_2_1_63_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2013.6606589"},{"key":"e_1_3_2_1_64_1","doi-asserted-by":"publisher","DOI":"10.1145\/2491411.2491418"},{"key":"e_1_3_2_1_65_1","volume-title":"Proceedings of the 19th ACM SIGSOFT symposium and the 13th European conference on Foundations of software engineering. ACM, 322--331","author":"Rahman F.","unstructured":"F. Rahman, D. Posnett, A. Hindle, E. Barr, and P. Devanbu. 2011. BugCache for inspections: hit or miss?. In Proceedings of the 19th ACM SIGSOFT symposium and the 13th European conference on Foundations of software engineering. ACM, 322--331."},{"key":"e_1_3_2_1_66_1","doi-asserted-by":"publisher","DOI":"10.1145\/2884781.2884848"},{"key":"e_1_3_2_1_67_1","volume-title":"Are Face-Detection Cameras Racist?","author":"Rose Adam","year":"2010","unstructured":"Adam Rose. 2010. Are Face-Detection Cameras Racist? (2010). http:\/\/content.time.com\/time\/business\/article\/0,8599,1954643,00.html"},{"key":"e_1_3_2_1_68_1","volume-title":"Tsotsos","author":"Rosenfeld Amir","year":"2018","unstructured":"Amir Rosenfeld, Richard S. Zemel, and John K. Tsotsos. 2018. The Elephant in the Room. CoRR abs\/1808.03305 (2018). arXiv:1808.03305 http:\/\/arxiv.org\/abs\/1808.03305"},{"key":"e_1_3_2_1_69_1","volume-title":"Learning representations by back-propagating errors. Cognitive modeling 5, 3","author":"Rumelhart David E","year":"1988","unstructured":"David E Rumelhart, Geoffrey E Hinton, and Ronald J Williams. 1988. Learning representations by back-propagating errors. Cognitive modeling 5, 3 (1988), 1."},{"key":"e_1_3_2_1_70_1","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-015-0816-y"},{"key":"e_1_3_2_1_71_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.74"},{"key":"e_1_3_2_1_72_1","volume-title":"Understanding adversarial training: Increasing local stability of neural nets through robust optimization. arXiv preprint arXiv:1511.05432","author":"Shaham Uri","year":"2015","unstructured":"Uri Shaham, Yutaro Yamada, and Sahand Negahban. 2015. Understanding adversarial training: Increasing local stability of neural nets through robust optimization. arXiv preprint arXiv:1511.05432 (2015)."},{"key":"e_1_3_2_1_73_1","volume-title":"International Conference on Learning Representations (ICLR).","author":"Simonyan Karen","year":"2015","unstructured":"Karen Simonyan and Andrew Zisserman. 2015. Very deep convolutional networks for large-scale image recognition. In International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_1_74_1","volume-title":"Testing Deep Neural Networks. arXiv preprint arXiv:1803.04792","author":"Sun Youcheng","year":"2018","unstructured":"Youcheng Sun, Xiaowei Huang, and Daniel Kroening. 2018. Testing Deep Neural Networks. arXiv preprint arXiv:1803.04792 (2018)."},{"key":"e_1_3_2_1_75_1","doi-asserted-by":"publisher","DOI":"10.1145\/3238147.3238172"},{"key":"e_1_3_2_1_76_1","volume-title":"International Conference on Learning Representations (ICLR).","author":"Szegedy C.","unstructured":"C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, and R. Fergus. 2014. Intriguing properties of neural networks. In International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_1_77_1","doi-asserted-by":"publisher","DOI":"10.1145\/3180155.3180220"},{"key":"e_1_3_2_1_78_1","doi-asserted-by":"publisher","DOI":"10.4018\/jdwm.2007070101"},{"key":"e_1_3_2_1_79_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2019.00126"},{"key":"e_1_3_2_1_80_1","unstructured":"Shiqi Wang Kexin Pei Justin Whitehouse Junfeng Yang and Suman Jana. 2018. Formal Security Analysis of Neural Networks using Symbolic Intervals. (2018)."},{"key":"e_1_3_2_1_81_1","volume-title":"Data Mining: Practical machine learning tools and techniques. Morgan Kaufmann.","author":"Witten Ian H","year":"2005","unstructured":"Ian H Witten and Eibe Frank. 2005. Data Mining: Practical machine learning tools and techniques. Morgan Kaufmann."},{"key":"e_1_3_2_1_82_1","volume-title":"Jan Hendrik Metzen, and J. Zico Kolter","author":"Wong Eric","year":"2018","unstructured":"Eric Wong, Frank Schmidt, Jan Hendrik Metzen, and J. Zico Kolter. 2018. Scaling provable adversarial defenses. In Advances in Neural Information Processing Systems 31, S. Bengio, H. Wallach, H. Larochelle, K. Grauman, N. Cesa-Bianchi, and R. Garnett (Eds.). Curran Associates, Inc., 8410--8419. http:\/\/papers.nips.cc\/paper\/8060-scaling-provable-adversarial-defenses.pdf"},{"key":"e_1_3_2_1_83_1","volume-title":"Feature Denoising for Improving Adversarial Robustness. In The IEEE Conference on Computer Vision and Pattern Recognition (CVPR).","author":"Xie Cihang","unstructured":"Cihang Xie, Yuxin Wu, Laurens van der Maaten, Alan L. Yuille, and Kaiming He. 2019. Feature Denoising for Improving Adversarial Robustness. In The IEEE Conference on Computer Vision and Pattern Recognition (CVPR)."},{"key":"e_1_3_2_1_84_1","volume-title":"Feature Squeezing: Detecting Adversarial Examples in Deep Neural Networks. arXiv preprint arXiv:1704.01155","author":"Xu Weilin","year":"2017","unstructured":"Weilin Xu, David Evans, and Yanjun Qi. 2017. Feature Squeezing: Detecting Adversarial Examples in Deep Neural Networks. arXiv preprint arXiv:1704.01155 (2017)."},{"key":"e_1_3_2_1_85_1","volume-title":"Situation Recognition: Visual Semantic Role Labeling for Image Understanding. In Conference on Computer Vision and Pattern Recognition.","author":"Yatskar Mark","year":"2016","unstructured":"Mark Yatskar, Luke Zettlemoyer, and Ali Farhadi. 2016. Situation Recognition: Visual Semantic Role Labeling for Image Understanding. In Conference on Computer Vision and Pattern Recognition."},{"key":"e_1_3_2_1_86_1","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2018.2886017"},{"key":"e_1_3_2_1_87_1","volume-title":"Proceedings of the 26th International Conference on World Wide Web","author":"Zafar Muhammad Bilal","unstructured":"Muhammad Bilal Zafar, Isabel Valera, Manuel Gomez Rodriguez, and Krishna P. Gummadi. 2017. Fairness Beyond Disparate Treatment & Disparate Impact: Learning Classification Without Disparate Mistreatment. In Proceedings of the 26th International Conference on World Wide Web (Perth, Australia). 1171--1180."},{"key":"e_1_3_2_1_88_1","volume-title":"Proceedings of the 20th International Conference on Artificial Intelligence and Statistics ((AISTATS)","volume":"54","author":"Zafar Muhammad Bilal","year":"2017","unstructured":"Muhammad Bilal Zafar, Isabel Valera, Manuel Gomez Rodriguez, and Krishna P Gummadi. 2017. Fairness constraints: Mechanisms for fair classification. In Proceedings of the 20th International Conference on Artificial Intelligence and Statistics ((AISTATS) 2017), Vol. 54. JMLR."},{"key":"e_1_3_2_1_89_1","volume-title":"Proceedings of the 30th International Conference on Machine Learning. 325--333","author":"Zemel Rich","year":"2013","unstructured":"Rich Zemel, Yu Wu, Kevin Swersky, Toni Pitassi, and Cynthia Dwork. 2013. Learning Fair Representations. In Proceedings of the 30th International Conference on Machine Learning. 325--333."},{"key":"e_1_3_2_1_90_1","volume-title":"DeepRoad: GAN-based Metamorphic Autonomous Driving System Testing. arXiv preprint arXiv:1802.02295","author":"Zhang Mengshi","year":"2018","unstructured":"Mengshi Zhang, Yuqun Zhang, Lingming Zhang, Cong Liu, and Sarfraz Khurshid. 2018. DeepRoad: GAN-based Metamorphic Autonomous Driving System Testing. arXiv preprint arXiv:1802.02295 (2018)."},{"key":"e_1_3_2_1_91_1","doi-asserted-by":"publisher","DOI":"10.1631\/FITEE.1700808"},{"key":"e_1_3_2_1_92_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/D17-1323"},{"key":"e_1_3_2_1_93_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.485"}],"event":{"name":"ICSE '20: 42nd International Conference on Software Engineering","location":"Seoul South Korea","acronym":"ICSE '20","sponsor":["SIGSOFT ACM Special Interest Group on Software Engineering","KIISE Korean Institute of Information Scientists and Engineers","IEEE CS"]},"container-title":["Proceedings of the ACM\/IEEE 42nd International Conference on Software Engineering"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3377811.3380400","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3377811.3380400","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T22:41:40Z","timestamp":1750200100000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3377811.3380400"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,6,27]]},"references-count":93,"alternative-id":["10.1145\/3377811.3380400","10.1145\/3377811"],"URL":"https:\/\/doi.org\/10.1145\/3377811.3380400","relation":{},"subject":[],"published":{"date-parts":[[2020,6,27]]},"assertion":[{"value":"2020-10-01","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}