{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,17]],"date-time":"2026-07-17T15:00:15Z","timestamp":1784300415369,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":51,"publisher":"ACM","license":[{"start":{"date-parts":[[2021,7,11]],"date-time":"2021-07-11T00:00:00Z","timestamp":1625961600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000028","name":"Semiconductor Research Corporation","doi-asserted-by":"publisher","award":["2707.001"],"award-info":[{"award-number":["2707.001"]}],"id":[{"id":"10.13039\/100000028","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100000266","name":"Engineering and Physical Sciences Research Council","doi-asserted-by":"publisher","award":["2052803"],"award-info":[{"award-number":["2052803"]}],"id":[{"id":"10.13039\/501100000266","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2021,7,11]]},"DOI":"10.1145\/3460319.3464801","type":"proceedings-article","created":{"date-parts":[[2021,7,8]],"date-time":"2021-07-08T22:18:43Z","timestamp":1625782723000},"page":"56-66","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":25,"title":["Exposing previously undetectable faults in deep neural networks"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-1911-7164","authenticated-orcid":false,"given":"Isaac","family":"Dunn","sequence":"first","affiliation":[{"name":"University of Oxford, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0678-1616","authenticated-orcid":false,"given":"Hadrien","family":"Pouget","sequence":"additional","affiliation":[{"name":"University of Oxford, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6681-5283","authenticated-orcid":false,"given":"Daniel","family":"Kroening","sequence":"additional","affiliation":[{"name":"Amazon, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2462-2782","authenticated-orcid":false,"given":"Tom","family":"Melham","sequence":"additional","affiliation":[{"name":"University of Oxford, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2021,7,11]]},"reference":[{"key":"e_1_3_2_2_1_1","volume-title":"GAN Dissection: Visualizing and Understanding Generative Adversarial Networks. In 7th International Conference on Learning Representations, ICLR 2019","author":"Bau David","year":"2019","unstructured":"David Bau , Jun-Yan Zhu , Hendrik Strobelt , Bolei Zhou , Joshua B. Tenenbaum , William T. Freeman , and Antonio Torralba . 2019 . GAN Dissection: Visualizing and Understanding Generative Adversarial Networks. In 7th International Conference on Learning Representations, ICLR 2019 , New Orleans, LA, USA , May 6-9, 2019. OpenReview.net. https:\/\/openreview.net\/forum?id=Hyg_X2C5FX David Bau, Jun-Yan Zhu, Hendrik Strobelt, Bolei Zhou, Joshua B. Tenenbaum, William T. Freeman, and Antonio Torralba. 2019. GAN Dissection: Visualizing and Understanding Generative Adversarial Networks. In 7th International Conference on Learning Representations, ICLR 2019, New Orleans, LA, USA, May 6-9, 2019. OpenReview.net. https:\/\/openreview.net\/forum?id=Hyg_X2C5FX"},{"key":"e_1_3_2_2_2_1","volume-title":"Kaizhao Liang, Bo Li, and David A. Forsyth.","author":"Bhattad Anand","year":"2019","unstructured":"Anand Bhattad , Min Jin Chong , Kaizhao Liang, Bo Li, and David A. Forsyth. 2019 . Big but Imperceptible Adversarial Perturbations via Semantic Manipulation . arXiv:1904.06347 [cs], April, arxiv:1904.06347. arxiv:1904.06347 Anand Bhattad, Min Jin Chong, Kaizhao Liang, Bo Li, and David A. Forsyth. 2019. Big but Imperceptible Adversarial Perturbations via Semantic Manipulation. arXiv:1904.06347 [cs], April, arxiv:1904.06347. arxiv:1904.06347"},{"key":"e_1_3_2_2_3_1","unstructured":"Andrew Brock and Alex Andonian. 2019. BigGAN-PyTorch. https:\/\/github.com\/ajbrock\/BigGAN-PyTorch  Andrew Brock and Alex Andonian. 2019. BigGAN-PyTorch. https:\/\/github.com\/ajbrock\/BigGAN-PyTorch"},{"key":"e_1_3_2_2_4_1","volume-title":"Large Scale GAN Training for High Fidelity Natural Image Synthesis. In International Conference on Learning Representations (ICLR). https:\/\/openreview.net\/forum?id=B1xsqj09Fm","author":"Brock Andrew","year":"2019","unstructured":"Andrew Brock , Jeff Donahue , and Karen Simonyan . 2019 . Large Scale GAN Training for High Fidelity Natural Image Synthesis. In International Conference on Learning Representations (ICLR). https:\/\/openreview.net\/forum?id=B1xsqj09Fm Andrew Brock, Jeff Donahue, and Karen Simonyan. 2019. Large Scale GAN Training for High Fidelity Natural Image Synthesis. In International Conference on Learning Representations (ICLR). https:\/\/openreview.net\/forum?id=B1xsqj09Fm"},{"key":"e_1_3_2_2_5_1","unstructured":"Isaac Dunn Laura Hanu Hadrien Pouget Daniel Kroening and Tom Melham. 2020. Evaluating Robustness to Context-Sensitive Feature Perturbations of Different Granularities. arxiv:2001.11055.  Isaac Dunn Laura Hanu Hadrien Pouget Daniel Kroening and Tom Melham. 2020. Evaluating Robustness to Context-Sensitive Feature Perturbations of Different Granularities. arxiv:2001.11055."},{"key":"e_1_3_2_2_6_1","unstructured":"Logan Engstrom Andrew Ilyas Shibani Santurkar and Dimitris Tsipras. 2019. Robustness (Python Library). https:\/\/github.com\/MadryLab\/robustness  Logan Engstrom Andrew Ilyas Shibani Santurkar and Dimitris Tsipras. 2019. Robustness (Python Library). https:\/\/github.com\/MadryLab\/robustness"},{"key":"e_1_3_2_2_7_1","volume-title":"Proceedings of the 36th International Conference on Machine Learning, ICML 2019","volume":"1811","author":"Engstrom Logan","year":"2019","unstructured":"Logan Engstrom , Brandon Tran , Dimitris Tsipras , Ludwig Schmidt , and Aleksander Madry . 2019 . Exploring the Landscape of Spatial Robustness . In Proceedings of the 36th International Conference on Machine Learning, ICML 2019 , 9-15 June 2019, Long Beach, California, USA, Kamalika Chaudhuri and Ruslan Salakhutdinov (Eds.) (Proceedings of Machine Learning Research , Vol. 97). PMLR, 1802\u2013 1811 . http:\/\/proceedings.mlr.press\/v97\/engstrom19a.html Logan Engstrom, Brandon Tran, Dimitris Tsipras, Ludwig Schmidt, and Aleksander Madry. 2019. Exploring the Landscape of Spatial Robustness. In Proceedings of the 36th International Conference on Machine Learning, ICML 2019, 9-15 June 2019, Long Beach, California, USA, Kamalika Chaudhuri and Ruslan Salakhutdinov (Eds.) (Proceedings of Machine Learning Research, Vol. 97). PMLR, 1802\u20131811. http:\/\/proceedings.mlr.press\/v97\/engstrom19a.html"},{"key":"e_1_3_2_2_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/3377811.3380415"},{"key":"e_1_3_2_2_9_1","volume-title":"Wichmann","author":"Geirhos Robert","year":"2020","unstructured":"Robert Geirhos , J\u00f6rn-Henrik Jacobsen , Claudio Michaelis , Richard S. Zemel , Wieland Brendel , Matthias Bethge , and Felix A . Wichmann . 2020 . Shortcut Learning in Deep Neural Networks. CoRR , abs\/2004.07780 (2020), arxiv:2004.07780. arxiv:2004.07780 Robert Geirhos, J\u00f6rn-Henrik Jacobsen, Claudio Michaelis, Richard S. Zemel, Wieland Brendel, Matthias Bethge, and Felix A. Wichmann. 2020. Shortcut Learning in Deep Neural Networks. CoRR, abs\/2004.07780 (2020), arxiv:2004.07780. arxiv:2004.07780"},{"key":"e_1_3_2_2_10_1","volume-title":"7th International Conference on Learning Representations, ICLR 2019","author":"Geirhos Robert","year":"2019","unstructured":"Robert Geirhos , Patricia Rubisch , Claudio Michaelis , Matthias Bethge , Felix A. Wichmann , and Wieland Brendel . 2019 . ImageNet-trained CNNs are biased towards texture; increasing shape bias improves accuracy and robustness . In 7th International Conference on Learning Representations, ICLR 2019 , New Orleans, LA, USA , May 6-9, 2019. OpenReview.net. https:\/\/openreview.net\/forum?id=Bygh9j09KX Robert Geirhos, Patricia Rubisch, Claudio Michaelis, Matthias Bethge, Felix A. Wichmann, and Wieland Brendel. 2019. ImageNet-trained CNNs are biased towards texture; increasing shape bias improves accuracy and robustness. In 7th International Conference on Learning Representations, ICLR 2019, New Orleans, LA, USA, May 6-9, 2019. OpenReview.net. https:\/\/openreview.net\/forum?id=Bygh9j09KX"},{"key":"e_1_3_2_2_11_1","volume-title":"Motivating the Rules of the Game for Adversarial Example Research. CoRR, abs\/1807.0","author":"Gilmer Justin","year":"2018","unstructured":"Justin Gilmer , Ryan P Adams , Ian J Goodfellow , David Andersen , and George E Dahl . 2018. Motivating the Rules of the Game for Adversarial Example Research. CoRR, abs\/1807.0 ( 2018 ), arxiv:1807.06732. arxiv:1807.06732 Justin Gilmer, Ryan P Adams, Ian J Goodfellow, David Andersen, and George E Dahl. 2018. Motivating the Rules of the Game for Adversarial Example Research. CoRR, abs\/1807.0 (2018), arxiv:1807.06732. arxiv:1807.06732"},{"key":"e_1_3_2_2_12_1","volume-title":"NIPS 2016 Tutorial: Generative Adversarial Networks. CoRR, abs\/1701","author":"Goodfellow Ian J","year":"2017","unstructured":"Ian J Goodfellow . 2017 . NIPS 2016 Tutorial: Generative Adversarial Networks. CoRR, abs\/1701 .0 (2017), arxiv:1701.00160. arxiv:1701.00160 Ian J Goodfellow. 2017. NIPS 2016 Tutorial: Generative Adversarial Networks. CoRR, abs\/1701.0 (2017), arxiv:1701.00160. arxiv:1701.00160"},{"key":"e_1_3_2_2_13_1","unstructured":"Ian J Goodfellow Jean Pouget-Abadie Mehdi Mirza Bing Xu David Warde-Farley Sherjil Ozair Aaron C Courville and Yoshua Bengio. 2014. Generative Adversarial Nets. In Advances in Neural Information Processing Systems (NeurIPS) Zoubin Ghahramani Max Welling Corinna Cortes Neil D Lawrence and Kilian Q Weinberger (Eds.). 2672\u20132680. http:\/\/papers.nips.cc\/paper\/5423-generative-adversarial-nets  Ian J Goodfellow Jean Pouget-Abadie Mehdi Mirza Bing Xu David Warde-Farley Sherjil Ozair Aaron C Courville and Yoshua Bengio. 2014. Generative Adversarial Nets. In Advances in Neural Information Processing Systems (NeurIPS) Zoubin Ghahramani Max Welling Corinna Cortes Neil D Lawrence and Kilian Q Weinberger (Eds.). 2672\u20132680. http:\/\/papers.nips.cc\/paper\/5423-generative-adversarial-nets"},{"key":"e_1_3_2_2_14_1","volume-title":"3rd International Conference on Learning Representations, ICLR","author":"Goodfellow Ian J.","year":"2015","unstructured":"Ian J. Goodfellow , Jonathon Shlens , and Christian Szegedy . 2015. Explaining and Harnessing Adversarial Examples . In 3rd International Conference on Learning Representations, ICLR 2015 , San Diego, CA , USA, May 7-9, 2015, Conference Track Proceedings, Yoshua Bengio and Yann LeCun (Eds .). arxiv:1412.6572 Ian J. Goodfellow, Jonathon Shlens, and Christian Szegedy. 2015. Explaining and Harnessing Adversarial Examples. In 3rd International Conference on Learning Representations, ICLR 2015, San Diego, CA, USA, May 7-9, 2015, Conference Track Proceedings, Yoshua Bengio and Yann LeCun (Eds.). arxiv:1412.6572"},{"key":"e_1_3_2_2_15_1","volume-title":"Achieving Robustness in the Wild via Adversarial Mixing with Disentangled Representations. CoRR, abs\/1912.03192","author":"Gowal Sven","year":"2019","unstructured":"Sven Gowal , Chongli Qin , Po-Sen Huang , Taylan Cemgil , Krishnamurthy Dvijotham , Timothy A. Mann , and Pushmeet Kohli . 2019. Achieving Robustness in the Wild via Adversarial Mixing with Disentangled Representations. CoRR, abs\/1912.03192 ( 2019 ), arxiv:1912.03192. arxiv:1912.03192 Sven Gowal, Chongli Qin, Po-Sen Huang, Taylan Cemgil, Krishnamurthy Dvijotham, Timothy A. Mann, and Pushmeet Kohli. 2019. Achieving Robustness in the Wild via Adversarial Mixing with Disentangled Representations. CoRR, abs\/1912.03192 (2019), arxiv:1912.03192. arxiv:1912.03192"},{"key":"e_1_3_2_2_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/3236024.3264835"},{"key":"e_1_3_2_2_17_1","unstructured":"Dan Hendrycks and Thomas Dietterich. 2019. Benchmarking Neural Network Robustness to Common Corruptions and Perturbations. arXiv:1903.12261 [cs stat] March arxiv:1903.12261. arxiv:1903.12261  Dan Hendrycks and Thomas Dietterich. 2019. Benchmarking Neural Network Robustness to Common Corruptions and Perturbations. arXiv:1903.12261 [cs stat] March arxiv:1903.12261. arxiv:1903.12261"},{"key":"e_1_3_2_2_18_1","volume-title":"7th International Conference on Learning Representations, ICLR 2019","author":"Hendrycks Dan","year":"2019","unstructured":"Dan Hendrycks and Thomas G. Dietterich . 2019. Benchmarking Neural Network Robustness to Common Corruptions and Perturbations . In 7th International Conference on Learning Representations, ICLR 2019 , New Orleans, LA, USA , May 6-9, 2019 . OpenReview.net. https:\/\/openreview.net\/forum?id=HJz6tiCqYm Dan Hendrycks and Thomas G. Dietterich. 2019. Benchmarking Neural Network Robustness to Common Corruptions and Perturbations. In 7th International Conference on Learning Representations, ICLR 2019, New Orleans, LA, USA, May 6-9, 2019. OpenReview.net. https:\/\/openreview.net\/forum?id=HJz6tiCqYm"},{"key":"e_1_3_2_2_19_1","volume-title":"Natural Adversarial Examples. CoRR, abs\/1907.07174","author":"Hendrycks Dan","year":"2019","unstructured":"Dan Hendrycks , Kevin Zhao , Steven Basart , Jacob Steinhardt , and Dawn Song . 2019. Natural Adversarial Examples. CoRR, abs\/1907.07174 ( 2019 ), arxiv:1907.07174. arxiv:1907.07174 Dan Hendrycks, Kevin Zhao, Steven Basart, Jacob Steinhardt, and Dawn Song. 2019. Natural Adversarial Examples. CoRR, abs\/1907.07174 (2019), arxiv:1907.07174. arxiv:1907.07174"},{"key":"e_1_3_2_2_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW.2018.00212"},{"key":"e_1_3_2_2_21_1","volume-title":"They Are Features. In Advances in Neural Information Processing Systems 32: Annual Conference on Neural Information Processing Systems 2019","author":"Ilyas Andrew","year":"2019","unstructured":"Andrew Ilyas , Shibani Santurkar , Dimitris Tsipras , Logan Engstrom , Brandon Tran , and Aleksander Madry . 2019 . Adversarial Examples Are Not Bugs , They Are Features. In Advances in Neural Information Processing Systems 32: Annual Conference on Neural Information Processing Systems 2019 , NeurIPS 2019, 8-14 December 2019, Vancouver, BC, Canada, Hanna M. Wallach, Hugo Larochelle, Alina Beygelzimer, Florence d\u2019Alch\u00e9-Buc, Emily B. Fox, and Roman Garnett (Eds.). 125\u2013136. http:\/\/papers.nips.cc\/paper\/8307-adversarial-examples-are-not-bugs-they-are-features Andrew Ilyas, Shibani Santurkar, Dimitris Tsipras, Logan Engstrom, Brandon Tran, and Aleksander Madry. 2019. Adversarial Examples Are Not Bugs, They Are Features. In Advances in Neural Information Processing Systems 32: Annual Conference on Neural Information Processing Systems 2019, NeurIPS 2019, 8-14 December 2019, Vancouver, BC, Canada, Hanna M. Wallach, Hugo Larochelle, Alina Beygelzimer, Florence d\u2019Alch\u00e9-Buc, Emily B. Fox, and Roman Garnett (Eds.). 125\u2013136. http:\/\/papers.nips.cc\/paper\/8307-adversarial-examples-are-not-bugs-they-are-features"},{"key":"e_1_3_2_2_22_1","volume-title":"On the \u00dfteerability\" of generative adversarial networks. CoRR, abs\/1907.07171","author":"Jahanian Ali","year":"2019","unstructured":"Ali Jahanian , Lucy Chai , and Phillip Isola . 2019. On the \u00dfteerability\" of generative adversarial networks. CoRR, abs\/1907.07171 ( 2019 ), arxiv:1907.07171. arxiv:1907.07171 Ali Jahanian, Lucy Chai, and Phillip Isola. 2019. On the \u00dfteerability\" of generative adversarial networks. CoRR, abs\/1907.07171 (2019), arxiv:1907.07171. arxiv:1907.07171"},{"key":"e_1_3_2_2_23_1","volume-title":"Generating Semantic Adversarial Examples with Differentiable Rendering. CoRR, abs\/1910.00727","author":"Jain Lakshya","year":"2019","unstructured":"Lakshya Jain , Wilson Wu , Steven Chen , Uyeong Jang , Varun Chandrasekaran , Sanjit A. Seshia , and Somesh Jha . 2019. Generating Semantic Adversarial Examples with Differentiable Rendering. CoRR, abs\/1910.00727 ( 2019 ), arxiv:1910.00727. arxiv:1910.00727 Lakshya Jain, Wilson Wu, Steven Chen, Uyeong Jang, Varun Chandrasekaran, Sanjit A. Seshia, and Somesh Jha. 2019. Generating Semantic Adversarial Examples with Differentiable Rendering. CoRR, abs\/1910.00727 (2019), arxiv:1910.00727. arxiv:1910.00727"},{"key":"e_1_3_2_2_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00487"},{"key":"e_1_3_2_2_25_1","volume-title":"Kingma and Max Welling","author":"Diederik","year":"2014","unstructured":"Diederik P. Kingma and Max Welling . 2014 . Auto-Encoding Variational Bayes. In 2nd International Conference on Learning Representations, ICLR 2014, Banff, AB, Canada, April 14-16, 2014, Conference Track Proceedings, Yoshua Bengio and Yann LeCun (Eds .). arxiv:1312.6114 Diederik P. Kingma and Max Welling. 2014. Auto-Encoding Variational Bayes. In 2nd International Conference on Learning Representations, ICLR 2014, Banff, AB, Canada, April 14-16, 2014, Conference Track Proceedings, Yoshua Bengio and Yann LeCun (Eds.). arxiv:1312.6114"},{"key":"e_1_3_2_2_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/3395363.3397346"},{"key":"e_1_3_2_2_27_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01261-8_34"},{"key":"e_1_3_2_2_28_1","volume-title":"7th International Conference on Learning Representations, ICLR 2019","author":"Derek Liu Hsueh-Ti","year":"2019","unstructured":"Hsueh-Ti Derek Liu , Michael Tao , Chun-Liang Li , Derek Nowrouzezahrai , and Alec Jacobson . 2019 . Beyond Pixel Norm-Balls: Parametric Adversaries using an Analytically Differentiable Renderer . In 7th International Conference on Learning Representations, ICLR 2019 , New Orleans, LA, USA , May 6-9, 2019. OpenReview.net. https:\/\/openreview.net\/forum?id=SJl2niR9KQ Hsueh-Ti Derek Liu, Michael Tao, Chun-Liang Li, Derek Nowrouzezahrai, and Alec Jacobson. 2019. Beyond Pixel Norm-Balls: Parametric Adversaries using an Analytically Differentiable Renderer. In 7th International Conference on Learning Representations, ICLR 2019, New Orleans, LA, USA, May 6-9, 2019. OpenReview.net. https:\/\/openreview.net\/forum?id=SJl2niR9KQ"},{"key":"e_1_3_2_2_29_1","volume-title":"Unsupervised Image-to-Image Translation Networks. In Advances in Neural Information Processing Systems 30: Annual Conference on Neural Information Processing Systems 2017","author":"Liu Ming-Yu","year":"2017","unstructured":"Ming-Yu Liu , Thomas Breuel , and Jan Kautz . 2017 . Unsupervised Image-to-Image Translation Networks. In Advances in Neural Information Processing Systems 30: Annual Conference on Neural Information Processing Systems 2017 , 4-9 December 2017, Long Beach, CA, USA, Isabelle Guyon, Ulrike von Luxburg, Samy Bengio, Hanna M. Wallach, Rob Fergus, S. V. N. Vishwanathan, and Roman Garnett (Eds.). 700\u2013708. http:\/\/papers.nips.cc\/paper\/6672-unsupervised-image-to-image-translation-networks Ming-Yu Liu, Thomas Breuel, and Jan Kautz. 2017. Unsupervised Image-to-Image Translation Networks. In Advances in Neural Information Processing Systems 30: Annual Conference on Neural Information Processing Systems 2017, 4-9 December 2017, Long Beach, CA, USA, Isabelle Guyon, Ulrike von Luxburg, Samy Bengio, Hanna M. Wallach, Rob Fergus, S. V. N. Vishwanathan, and Roman Garnett (Eds.). 700\u2013708. http:\/\/papers.nips.cc\/paper\/6672-unsupervised-image-to-image-translation-networks"},{"key":"e_1_3_2_2_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/3188745.3232194"},{"key":"e_1_3_2_2_31_1","unstructured":"Luke Melas-Kyriazi. 2020. lukemelas\/EfficientNet-PyTorch. https:\/\/github.com\/lukemelas\/EfficientNet-PyTorch original-date: 2019-05-30T05:24:11Z.  Luke Melas-Kyriazi. 2020. lukemelas\/EfficientNet-PyTorch. https:\/\/github.com\/lukemelas\/EfficientNet-PyTorch original-date: 2019-05-30T05:24:11Z."},{"key":"e_1_3_2_2_32_1","volume-title":"Conditional Generative Adversarial Nets. CoRR, abs\/1411.1","author":"Mirza Mehdi","year":"2014","unstructured":"Mehdi Mirza and Simon Osindero . 2014. Conditional Generative Adversarial Nets. CoRR, abs\/1411.1 ( 2014 ), arxiv:1411.1784. arxiv:1411.1784 Mehdi Mirza and Simon Osindero. 2014. Conditional Generative Adversarial Nets. CoRR, abs\/1411.1 (2014), arxiv:1411.1784. arxiv:1411.1784"},{"key":"e_1_3_2_2_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00032"},{"key":"e_1_3_2_2_34_1","volume-title":"MNIST-C: A Robustness Benchmark for Computer Vision. CoRR, abs\/1906.02337","author":"Mu Norman","year":"2019","unstructured":"Norman Mu and Justin Gilmer . 2019. MNIST-C: A Robustness Benchmark for Computer Vision. CoRR, abs\/1906.02337 ( 2019 ), arxiv:1906.02337. arxiv:1906.02337 Norman Mu and Justin Gilmer. 2019. MNIST-C: A Robustness Benchmark for Computer Vision. CoRR, abs\/1906.02337 (2019), arxiv:1906.02337. arxiv:1906.02337"},{"key":"e_1_3_2_2_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/3132747.3132785"},{"key":"e_1_3_2_2_36_1","unstructured":"Haonan Qiu Chaowei Xiao Lei Yang Xinchen Yan Honglak Lee and Bo Li. 2019. SemanticAdv: Generating Adversarial Examples via Attribute-Conditional Image Editing. arXiv:1906.07927 [cs eess] June arxiv:1906.07927. arxiv:1906.07927  Haonan Qiu Chaowei Xiao Lei Yang Xinchen Yan Honglak Lee and Bo Li. 2019. SemanticAdv: Generating Adversarial Examples via Attribute-Conditional Image Editing. arXiv:1906.07927 [cs eess] June arxiv:1906.07927. arxiv:1906.07927"},{"key":"e_1_3_2_2_37_1","volume-title":"Proceedings of the 36th International Conference on Machine Learning, ICML 2019","volume":"5400","author":"Recht Benjamin","year":"2019","unstructured":"Benjamin Recht , Rebecca Roelofs , Ludwig Schmidt , and Vaishaal Shankar . 2019 . Do ImageNet Classifiers Generalize to ImageNet? In Proceedings of the 36th International Conference on Machine Learning, ICML 2019 , 9-15 June 2019, Long Beach, California, USA, Kamalika Chaudhuri and Ruslan Salakhutdinov (Eds.) (Proceedings of Machine Learning Research , Vol. 97). PMLR, 5389\u2013 5400 . http:\/\/proceedings.mlr.press\/v97\/recht19a.html Benjamin Recht, Rebecca Roelofs, Ludwig Schmidt, and Vaishaal Shankar. 2019. Do ImageNet Classifiers Generalize to ImageNet? In Proceedings of the 36th International Conference on Machine Learning, ICML 2019, 9-15 June 2019, Long Beach, California, USA, Kamalika Chaudhuri and Ruslan Salakhutdinov (Eds.) (Proceedings of Machine Learning Research, Vol. 97). PMLR, 5389\u20135400. http:\/\/proceedings.mlr.press\/v97\/recht19a.html"},{"key":"e_1_3_2_2_38_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.eng.2019.12.012"},{"key":"e_1_3_2_2_39_1","volume-title":"Advances in Neural Information Processing Systems 33: Annual Conference on Neural Information Processing Systems 2020","author":"Salman Hadi","year":"2020","unstructured":"Hadi Salman , Andrew Ilyas , Logan Engstrom , Ashish Kapoor , and Aleksander Madry . 2020 . Do Adversarially Robust ImageNet Models Transfer Better? In Advances in Neural Information Processing Systems 33: Annual Conference on Neural Information Processing Systems 2020 , NeurIPS 2020, December 6-12, 2020, virtual, Hugo Larochelle, Marc\u2019Aurelio Ranzato, Raia Hadsell, Maria-Florina Balcan, and Hsuan-Tien Lin (Eds.). https:\/\/proceedings.neurips.cc\/paper\/2020\/hash\/24357dd085d2c4b1a88a7e0692e60294-Abstract.html Hadi Salman, Andrew Ilyas, Logan Engstrom, Ashish Kapoor, and Aleksander Madry. 2020. Do Adversarially Robust ImageNet Models Transfer Better? In Advances in Neural Information Processing Systems 33: Annual Conference on Neural Information Processing Systems 2020, NeurIPS 2020, December 6-12, 2020, virtual, Hugo Larochelle, Marc\u2019Aurelio Ranzato, Raia Hadsell, Maria-Florina Balcan, and Hsuan-Tien Lin (Eds.). https:\/\/proceedings.neurips.cc\/paper\/2020\/hash\/24357dd085d2c4b1a88a7e0692e60294-Abstract.html"},{"key":"e_1_3_2_2_40_1","doi-asserted-by":"publisher","DOI":"10.1109\/MDAT.2020.2968274"},{"key":"e_1_3_2_2_41_1","unstructured":"Yang Song Rui Shu Nate Kushman and Stefano Ermon. 2018. Constructing Unrestricted Adversarial Examples with Generative Models. In Advances in Neural Information Processing Systems (NeurIPS) Samy Bengio Hanna M Wallach Hugo Larochelle Kristen Grauman Nicol\u00f2 Cesa-Bianchi and Roman Garnett (Eds.). 8322\u20138333. http:\/\/papers.nips.cc\/paper\/8052-constructing-unrestricted-adversarial-examples-with-generative-models  Yang Song Rui Shu Nate Kushman and Stefano Ermon. 2018. Constructing Unrestricted Adversarial Examples with Generative Models. In Advances in Neural Information Processing Systems (NeurIPS) Samy Bengio Hanna M Wallach Hugo Larochelle Kristen Grauman Nicol\u00f2 Cesa-Bianchi and Roman Garnett (Eds.). 8322\u20138333. http:\/\/papers.nips.cc\/paper\/8052-constructing-unrestricted-adversarial-examples-with-generative-models"},{"key":"e_1_3_2_2_42_1","volume-title":"Testing Deep Learning Models for Image Analysis Using Object-Relevant Metamorphic Relations. CoRR, abs\/1909.03824","author":"Tian Yongqiang","year":"2019","unstructured":"Yongqiang Tian , Shiqing Ma , Ming Wen , Yepang Liu , Shing-Chi Cheung , and Xiangyu Zhang . 2019. Testing Deep Learning Models for Image Analysis Using Object-Relevant Metamorphic Relations. CoRR, abs\/1909.03824 ( 2019 ), arxiv:1909.03824. arxiv:1909.03824 Yongqiang Tian, Shiqing Ma, Ming Wen, Yepang Liu, Shing-Chi Cheung, and Xiangyu Zhang. 2019. Testing Deep Learning Models for Image Analysis Using Object-Relevant Metamorphic Relations. CoRR, abs\/1909.03824 (2019), arxiv:1909.03824. arxiv:1909.03824"},{"key":"e_1_3_2_2_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/3180155.3180220"},{"key":"e_1_3_2_2_44_1","volume-title":"Fundamental Tradeoffs between Invariance and Sensitivity to Adversarial Perturbations. CoRR, abs\/2002.04599","author":"Tram\u00e8r Florian","year":"2020","unstructured":"Florian Tram\u00e8r , Jens Behrmann , Nicholas Carlini , Nicolas Papernot , and J\u00f6rn-Henrik Jacobsen . 2020. Fundamental Tradeoffs between Invariance and Sensitivity to Adversarial Perturbations. CoRR, abs\/2002.04599 ( 2020 ), arxiv:2002.04599. arxiv:2002.04599 Florian Tram\u00e8r, Jens Behrmann, Nicholas Carlini, Nicolas Papernot, and J\u00f6rn-Henrik Jacobsen. 2020. Fundamental Tradeoffs between Invariance and Sensitivity to Adversarial Perturbations. CoRR, abs\/2002.04599 (2020), arxiv:2002.04599. arxiv:2002.04599"},{"key":"e_1_3_2_2_45_1","unstructured":"Shuo Wang Shangyu Chen Tianle Chen Surya Nepal Carsten Rudolph and Marthie Grobler. 2020. Generating Semantic Adversarial Examples via Feature Manipulation. arXiv:2001.02297 [cs stat] Jan. arxiv:2001.02297. arxiv:2001.02297  Shuo Wang Shangyu Chen Tianle Chen Surya Nepal Carsten Rudolph and Marthie Grobler. 2020. Generating Semantic Adversarial Examples via Feature Manipulation. arXiv:2001.02297 [cs stat] Jan. arxiv:2001.02297. arxiv:2001.02297"},{"key":"e_1_3_2_2_46_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-55583-2_25"},{"key":"e_1_3_2_2_47_1","volume-title":"8th International Conference on Learning Representations, ICLR 2020","author":"Wong Eric","year":"2020","unstructured":"Eric Wong , Leslie Rice , and J. Zico Kolter . 2020. Fast is better than free: Revisiting adversarial training . In 8th International Conference on Learning Representations, ICLR 2020 , Addis Ababa, Ethiopia , April 26-30, 2020 . OpenReview.net. https:\/\/openreview.net\/forum?id=BJx040EFvH Eric Wong, Leslie Rice, and J. Zico Kolter. 2020. Fast is better than free: Revisiting adversarial training. In 8th International Conference on Learning Representations, ICLR 2020, Addis Ababa, Ethiopia, April 26-30, 2020. OpenReview.net. https:\/\/openreview.net\/forum?id=BJx040EFvH"},{"key":"e_1_3_2_2_48_1","doi-asserted-by":"publisher","DOI":"10.1145\/3293882.3330579"},{"key":"e_1_3_2_2_49_1","doi-asserted-by":"publisher","DOI":"10.1145\/3238147.3238187"},{"key":"e_1_3_2_2_50_1","unstructured":"Zhengli Zhao Dheeru Dua and Sameer Singh. 2017. Generating Natural Adversarial Examples. arXiv:1710.11342 [cs] Oct. arxiv:1710.11342. arxiv:1710.11342  Zhengli Zhao Dheeru Dua and Sameer Singh. 2017. Generating Natural Adversarial Examples. arXiv:1710.11342 [cs] Oct. arxiv:1710.11342. arxiv:1710.11342"},{"key":"e_1_3_2_2_51_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00112"}],"event":{"name":"ISSTA '21: 30th ACM SIGSOFT International Symposium on Software Testing and Analysis","location":"Virtual Denmark","acronym":"ISSTA '21","sponsor":["SIGSOFT ACM Special Interest Group on Software Engineering"]},"container-title":["Proceedings of the 30th ACM SIGSOFT International Symposium on Software Testing and Analysis"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3460319.3464801","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3460319.3464801","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T20:48:31Z","timestamp":1750193311000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3460319.3464801"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,7,11]]},"references-count":51,"alternative-id":["10.1145\/3460319.3464801","10.1145\/3460319"],"URL":"https:\/\/doi.org\/10.1145\/3460319.3464801","relation":{},"subject":[],"published":{"date-parts":[[2021,7,11]]},"assertion":[{"value":"2021-07-11","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}