{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,19]],"date-time":"2026-06-19T02:51:10Z","timestamp":1781837470308,"version":"3.54.5"},"publisher-location":"New York, NY, USA","reference-count":49,"publisher":"ACM","license":[{"start":{"date-parts":[[2021,11,15]],"date-time":"2021-11-15T00:00:00Z","timestamp":1636934400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2021,11,15]]},"DOI":"10.1145\/3474370.3485659","type":"proceedings-article","created":{"date-parts":[[2021,10,28]],"date-time":"2021-10-28T11:12:46Z","timestamp":1635419566000},"page":"3-12","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":6,"title":["What's in the box"],"prefix":"10.1145","author":[{"given":"Sahar","family":"Abdelnabi","sequence":"first","affiliation":[{"name":"CISPA Helmholtz Center for Information Security, Saarbr\u00fccken, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mario","family":"Fritz","sequence":"additional","affiliation":[{"name":"CISPA Helmholtz Center for Information Security, Saarbr\u00fccken, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2021,11,15]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417233"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2807385"},{"key":"e_1_3_2_1_3_1","volume-title":"International Conference on Machine Learning (ICML).","author":"Athalye Anish","year":"2018","unstructured":"Anish Athalye , Nicholas Carlini , and David Wagner . 2018 . Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples . In International Conference on Machine Learning (ICML). Anish Athalye, Nicholas Carlini, and David Wagner. 2018. Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples. In International Conference on Machine Learning (ICML)."},{"key":"e_1_3_2_1_4_1","volume-title":"A partial break of the honeypots defense to catch adver- sarial attacks. arXiv preprint arXiv:2009.10975","author":"Carlini Nicholas","year":"2020","unstructured":"Nicholas Carlini . 2020. A partial break of the honeypots defense to catch adver- sarial attacks. arXiv preprint arXiv:2009.10975 ( 2020 ). Nicholas Carlini. 2020. A partial break of the honeypots defense to catch adver- sarial attacks. arXiv preprint arXiv:2009.10975 (2020)."},{"key":"e_1_3_2_1_5_1","volume-title":"On evaluating adversarial robustness. arXiv preprint arXiv:1902.06705","author":"Carlini Nicholas","year":"2019","unstructured":"Nicholas Carlini , Anish Athalye , Nicolas Papernot , Wieland Brendel , Jonas Rauber , Dimitris Tsipras , Ian Goodfellow , Aleksander Madry , and Alexey Kurakin . 2019. On evaluating adversarial robustness. arXiv preprint arXiv:1902.06705 ( 2019 ). Nicholas Carlini, Anish Athalye, Nicolas Papernot, Wieland Brendel, Jonas Rauber, Dimitris Tsipras, Ian Goodfellow, Aleksander Madry, and Alexey Kurakin. 2019. On evaluating adversarial robustness. arXiv preprint arXiv:1902.06705 (2019)."},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140444"},{"key":"e_1_3_2_1_7_1","volume-title":"arXiv preprint arXiv:1711.08478","author":"Carlini Nicholas","year":"2017","unstructured":"Nicholas Carlini and David Wagner . 2017. Magnet and\" efficient defenses against adversarial attacks\" are not robust to adversarial examples. arXiv preprint arXiv:1711.08478 ( 2017 ). Nicholas Carlini and David Wagner. 2017. Magnet and\" efficient defenses against adversarial attacks\" are not robust to adversarial examples. arXiv preprint arXiv:1711.08478 (2017)."},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"e_1_3_2_1_9_1","volume-title":"the IEEE symposium on Security and Privacy (SP).","author":"Chen Jianbo","year":"2020","unstructured":"Jianbo Chen , Michael I Jordan , and Martin J Wainwright . 2020 . Hopskipjumpat-tack: A query-efficient decision-based attack . In the IEEE symposium on Security and Privacy (SP). Jianbo Chen, Michael I Jordan, and Martin J Wainwright. 2020. Hopskipjumpat-tack: A query-efficient decision-based attack. In the IEEE symposium on Security and Privacy (SP)."},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v32i1.11302"},{"key":"e_1_3_2_1_11_1","volume-title":"Stochastic Activation Pruning for Robust Adversarial Defense. In International Conference on Learning Representations (ICLR).","author":"Dhillon Guneet S","year":"2018","unstructured":"Guneet S Dhillon , Kamyar Azizzadenesheli , Zachary C Lipton , Jeremy D Bernstein , Jean Kossaifi , Aran Khanna , and Animashree Anandkumar . 2018 . Stochastic Activation Pruning for Robust Adversarial Defense. In International Conference on Learning Representations (ICLR). Guneet S Dhillon, Kamyar Azizzadenesheli, Zachary C Lipton, Jeremy D Bernstein, Jean Kossaifi, Aran Khanna, and Animashree Anandkumar. 2018. Stochastic Activation Pruning for Robust Adversarial Defense. In International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"e_1_3_2_1_13_1","unstructured":"Alhussein Fawzi Hamza Fawzi and Omar Fawzi. 2018. Adversarial vulnerability for any classifier. In Advances in Neural Information Processing Systems (NeurIPS).  Alhussein Fawzi Hamza Fawzi and Omar Fawzi. 2018. Adversarial vulnerability for any classifier. In Advances in Neural Information Processing Systems (NeurIPS)."},{"key":"e_1_3_2_1_14_1","volume-title":"Explaining and Harnessing Adversarial Examples. In International Conference on Learning Representations (ICLR).","author":"Goodfellow Ian","year":"2015","unstructured":"Ian Goodfellow , Jonathon Shlens , and Christian Szegedy . 2015 . Explaining and Harnessing Adversarial Examples. In International Conference on Learning Representations (ICLR). Ian Goodfellow, Jonathon Shlens, and Christian Szegedy. 2015. Explaining and Harnessing Adversarial Examples. In International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_1_15_1","volume-title":"International Conference on Learning Representations (ICLR).","author":"Guo Chuan","unstructured":"Chuan Guo , Mayank Rana , Moustapha Cisse , and Laurens van der Maaten. 2018. Countering Adversarial Images using Input Transformations . In International Conference on Learning Representations (ICLR). Chuan Guo, Mayank Rana, Moustapha Cisse, and Laurens van der Maaten. 2018. Countering Adversarial Images using Input Transformations. In International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-46493-0_38"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.3005961"},{"key":"e_1_3_2_1_18_1","volume-title":"Improving adversarial robustness of ensembles with diversity training. arXiv preprint arXiv:1901.09981","author":"Kariyappa Sanjay","year":"2019","unstructured":"Sanjay Kariyappa and Moinuddin K Qureshi . 2019. Improving adversarial robustness of ensembles with diversity training. arXiv preprint arXiv:1901.09981 ( 2019 ). Sanjay Kariyappa and Moinuddin K Qureshi. 2019. Improving adversarial robustness of ensembles with diversity training. arXiv preprint arXiv:1901.09981 (2019)."},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.01426"},{"key":"e_1_3_2_1_20_1","unstructured":"Alex Krizhevsky Geoffrey Hinton etal 2009. Learning multiple layers of features from tiny images. Technical Report.  Alex Krizhevsky Geoffrey Hinton et al. 2009. Learning multiple layers of features from tiny images. Technical Report."},{"key":"e_1_3_2_1_21_1","volume-title":"Imagenet classifi- cation with deep convolutional neural networks. Advances in Neural Information Processing Systems (NeurIPS)","author":"Krizhevsky Alex","year":"2012","unstructured":"Alex Krizhevsky , Ilya Sutskever , and Geoffrey E Hinton . 2012. Imagenet classifi- cation with deep convolutional neural networks. Advances in Neural Information Processing Systems (NeurIPS) ( 2012 ). Alex Krizhevsky, Ilya Sutskever, and Geoffrey E Hinton. 2012. Imagenet classifi- cation with deep convolutional neural networks. Advances in Neural Information Processing Systems (NeurIPS) (2012)."},{"key":"e_1_3_2_1_22_1","volume-title":"Adversarial examples in the physical world. arXiv preprint arXiv:1607.02533","author":"Kurakin Alexey","year":"2016","unstructured":"Alexey Kurakin , Ian Goodfellow , and Samy Bengio . 2016. Adversarial examples in the physical world. arXiv preprint arXiv:1607.02533 ( 2016 ). Alexey Kurakin, Ian Goodfellow, and Samy Bengio. 2016. Adversarial examples in the physical world. arXiv preprint arXiv:1607.02533 (2016)."},{"key":"e_1_3_2_1_23_1","volume-title":"International Conference on Learning Representations (ICLR).","author":"Liu Yanpei","year":"2017","unstructured":"Yanpei Liu , Xinyun Chen , Chang Liu , and Dawn Song . 2017 . Delving into Trans- ferable Adversarial Examples and Black-box Attacks . In International Conference on Learning Representations (ICLR). Yanpei Liu, Xinyun Chen, Chang Liu, and Dawn Song. 2017. Delving into Trans- ferable Adversarial Examples and Black-box Attacks. In International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_1_24_1","volume-title":"International Conference on Learning Representations (ICLR).","author":"Madry Aleksander","year":"2018","unstructured":"Aleksander Madry , Aleksandar Makelov , Ludwig Schmidt , Dimitris Tsipras , and Adrian Vladu . 2018 . Towards Deep Learning Models Resistant to Adversarial Attacks . In International Conference on Learning Representations (ICLR). Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu. 2018. Towards Deep Learning Models Resistant to Adversarial Attacks. In International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134057"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2015.178"},{"key":"e_1_3_2_1_27_1","volume-title":"Prediction Poisoning: Towards Defenses Against DNN Model Stealing Attacks. In International Conference on Learning Representations (ICLR).","author":"Orekondy Tribhuvanesh","year":"2020","unstructured":"Tribhuvanesh Orekondy , Bernt Schiele , and Mario Fritz . 2020 . Prediction Poisoning: Towards Defenses Against DNN Model Stealing Attacks. In International Conference on Learning Representations (ICLR). Tribhuvanesh Orekondy, Bernt Schiele, and Mario Fritz. 2020. Prediction Poisoning: Towards Defenses Against DNN Model Stealing Attacks. In International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_1_28_1","volume-title":"International Conference on Machine Learning (ICML).","author":"Pang Tianyu","year":"2019","unstructured":"Tianyu Pang , Kun Xu , Chao Du , Ning Chen , and Jun Zhu . 2019 . Improving adversarial robustness via promoting ensemble diversity . In International Conference on Machine Learning (ICML). Tianyu Pang, Kun Xu, Chao Du, Ning Chen, and Jun Zhu. 2019. Improving adversarial robustness via promoting ensemble diversity. In International Conference on Machine Learning (ICML)."},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.41"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.91"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298682"},{"key":"e_1_3_2_1_33_1","volume-title":"International Conference on Learning Representations (ICLR).","author":"Shafahi Ali","year":"2019","unstructured":"Ali Shafahi , W. Ronny Huang , Christoph Studer , Soheil Feizi , and Tom Goldstein . 2019 . Are adversarial examples inevitable? . In International Conference on Learning Representations (ICLR). Ali Shafahi, W. Ronny Huang, Christoph Studer, Soheil Feizi, and Tom Goldstein. 2019. Are adversarial examples inevitable?. In International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_1_34_1","volume-title":"Zheng Xu, John Dickerson, Christoph Studer, Larry S Davis, Gavin Taylor, and Tom Goldstein.","author":"Shafahi Ali","year":"2019","unstructured":"Ali Shafahi , Mahyar Najibi , Mohammad Amin Ghiasi , Zheng Xu, John Dickerson, Christoph Studer, Larry S Davis, Gavin Taylor, and Tom Goldstein. 2019 . Adversarial training for free!. In Advances in Neural Information Processing Systems (NeurIPS) . Ali Shafahi, Mahyar Najibi, Mohammad Amin Ghiasi, Zheng Xu, John Dickerson, Christoph Studer, Larry S Davis, Gavin Taylor, and Tom Goldstein. 2019. Adversarial training for free!. In Advances in Neural Information Processing Systems (NeurIPS)."},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417231"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1109\/WACV.2017.58"},{"key":"e_1_3_2_1_37_1","volume-title":"the 12th USENIX Workshop on Offensive Technologies (WOOT).","author":"Song Dawn","year":"2018","unstructured":"Dawn Song , Kevin Eykholt , Ivan Evtimov , Earlence Fernandes , Bo Li , Amir Rahmati , Florian Tramer , Atul Prakash , and Tadayoshi Kohno . 2018 . Physical ad- versarial examples for object detectors . In the 12th USENIX Workshop on Offensive Technologies (WOOT). Dawn Song, Kevin Eykholt, Ivan Evtimov, Earlence Fernandes, Bo Li, Amir Rahmati, Florian Tramer, Atul Prakash, and Tadayoshi Kohno. 2018. Physical ad- versarial examples for object detectors. In the 12th USENIX Workshop on Offensive Technologies (WOOT)."},{"key":"e_1_3_2_1_38_1","volume-title":"International Conference on Machine Learning (ICML).","author":"Stutz David","year":"2020","unstructured":"David Stutz , Matthias Hein , and Bernt Schiele . 2020 . Confidence-calibrated adversarial training: Generalizing to unseen attacks . In International Conference on Machine Learning (ICML). David Stutz, Matthias Hein, and Bernt Schiele. 2020. Confidence-calibrated adversarial training: Generalizing to unseen attacks. In International Conference on Machine Learning (ICML)."},{"key":"e_1_3_2_1_39_1","volume-title":"International Conference on Learning Representations (ICLR).","author":"Szegedy Christian","year":"2014","unstructured":"Christian Szegedy , Wojciech Zaremba , Ilya Sutskever , Joan Bruna , Dumitru Erhan , Ian Goodfellow , and Rob Fergus . 2014 . Intriguing properties of neural networks . In International Conference on Learning Representations (ICLR). Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus. 2014. Intriguing properties of neural networks. In International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1145\/3180155.3180220"},{"key":"e_1_3_2_1_41_1","unstructured":"Florian Tram\u00e8r Nicholas Carlini Wieland Brendel and Aleksander Madry. 2020. On Adaptive Attacks to Adversarial Example Defenses. In Advances in Neural Information Processing Systems (NeurIPS).  Florian Tram\u00e8r Nicholas Carlini Wieland Brendel and Aleksander Madry. 2020. On Adaptive Attacks to Adversarial Example Defenses. In Advances in Neural Information Processing Systems (NeurIPS)."},{"key":"e_1_3_2_1_42_1","volume-title":"Ensemble Adversarial Training: Attacks and Defenses. In International Conference on Learning Representations (ICLR).","author":"Tram\u00e8r Florian","year":"2018","unstructured":"Florian Tram\u00e8r , Alexey Kurakin , Nicolas Papernot , Ian Goodfellow , Dan Boneh , and Patrick McDaniel . 2018 . Ensemble Adversarial Training: Attacks and Defenses. In International Conference on Learning Representations (ICLR). Florian Tram\u00e8r, Alexey Kurakin, Nicolas Papernot, Ian Goodfellow, Dan Boneh, and Patrick McDaniel. 2018. Ensemble Adversarial Training: Attacks and Defenses. In International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_1_43_1","volume-title":"International Conference on Learning Representations (ICLR).","author":"Tsipras Dimitris","year":"2019","unstructured":"Dimitris Tsipras , Shibani Santurkar , Logan Engstrom , Alexander Turner , and Aleksander Madry . 2019 . Robustness May Be at Odds with Accuracy . In International Conference on Learning Representations (ICLR). Dimitris Tsipras, Shibani Santurkar, Logan Engstrom, Alexander Turner, and Aleksander Madry. 2019. Robustness May Be at Odds with Accuracy. In International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_1_44_1","article-title":"Visualizing data using t-SNE","volume":"9","author":"der Maaten Laurens Van","year":"2008","unstructured":"Laurens Van der Maaten and Geoffrey Hinton . 2008 . Visualizing data using t-SNE . Journal of machine learning research 9 , 11 (2008). Laurens Van der Maaten and Geoffrey Hinton. 2008. Visualizing data using t-SNE. Journal of machine learning research 9, 11 (2008).","journal-title":"Journal of machine learning research"},{"key":"e_1_3_2_1_45_1","volume-title":"International Conference on Learning Representations (ICLR).","author":"Wong Eric","unstructured":"Eric Wong , Leslie Rice , and J. Zico Kolter . 2020. Fast is better than free: Revisiting adversarial training . In International Conference on Learning Representations (ICLR). Eric Wong, Leslie Rice, and J. Zico Kolter. 2020. Fast is better than free: Revisiting adversarial training. In International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_1_46_1","volume-title":"International Conference on Learning Representations (ICLR).","author":"Wu Dongxian","year":"2020","unstructured":"Dongxian Wu , Yisen Wang , Shu-Tao Xia , James Bailey , and Xingjun Ma . 2020 . Skip connections matter: On the transferability of adversarial examples generated with resnets . In International Conference on Learning Representations (ICLR). Dongxian Wu, Yisen Wang, Shu-Tao Xia, James Bailey, and Xingjun Ma. 2020. Skip connections matter: On the transferability of adversarial examples generated with resnets. In International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00049"},{"key":"e_1_3_2_1_48_1","volume-title":"International Conference on Learning Representations (ICLR).","author":"Xie Cihang","year":"2018","unstructured":"Cihang Xie , Jianyu Wang , Zhishuai Zhang , Zhou Ren , and Alan Yuille . 2018 . Mit- igating Adversarial Effects Through Randomization . In International Conference on Learning Representations (ICLR). Cihang Xie, Jianyu Wang, Zhishuai Zhang, Zhou Ren, and Alan Yuille. 2018. Mit- igating Adversarial Effects Through Randomization. In International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_1_49_1","volume-title":"Feature Squeezing: Detecting Adversarial Examples in Deep Neural Networks. In the 25th Annual Network and Distributed System Security Symposium (NDSS).","author":"Xu Weilin","year":"2018","unstructured":"Weilin Xu , David Evans , and Yanjun Qi . 2018 . Feature Squeezing: Detecting Adversarial Examples in Deep Neural Networks. In the 25th Annual Network and Distributed System Security Symposium (NDSS). Weilin Xu, David Evans, and Yanjun Qi. 2018. Feature Squeezing: Detecting Adversarial Examples in Deep Neural Networks. In the 25th Annual Network and Distributed System Security Symposium (NDSS)."}],"event":{"name":"CCS '21: 2021 ACM SIGSAC Conference on Computer and Communications Security","location":"Virtual Event Republic of Korea","acronym":"CCS '21","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 8th ACM Workshop on Moving Target Defense"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3474370.3485659","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3474370.3485659","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T19:30:26Z","timestamp":1750188626000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3474370.3485659"}},"subtitle":["Deflecting Adversarial Attacks by Randomly Deploying Adversarially-Disjoint Models"],"short-title":[],"issued":{"date-parts":[[2021,11,15]]},"references-count":49,"alternative-id":["10.1145\/3474370.3485659","10.1145\/3474370"],"URL":"https:\/\/doi.org\/10.1145\/3474370.3485659","relation":{},"subject":[],"published":{"date-parts":[[2021,11,15]]},"assertion":[{"value":"2021-11-15","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}