{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,2]],"date-time":"2025-12-02T15:06:31Z","timestamp":1764687991617,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":31,"publisher":"ACM","license":[{"start":{"date-parts":[[2021,11,26]],"date-time":"2021-11-26T00:00:00Z","timestamp":1637884800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2021,11,26]]},"DOI":"10.1145\/3503047.3503106","type":"proceedings-article","created":{"date-parts":[[2022,1,19]],"date-time":"2022-01-19T23:32:54Z","timestamp":1642635174000},"page":"1-5","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":2,"title":["An Information Theoretic Defense Algorithm against Adversarial Attacks on Deep Learning"],"prefix":"10.1145","author":[{"given":"Xinjie","family":"Lan","sequence":"first","affiliation":[{"name":"University of Delaware, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Samet","family":"Bayram","sequence":"additional","affiliation":[{"name":"University of Delaware, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Kenneth","family":"Barner","sequence":"additional","affiliation":[{"name":"University of Delaware, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2022,1,19]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"Mitali Bafna Jack Murtagh and Nikhil Vyas. 2018. Thwarting Adversarial Examples: An Math 25-RobustSparse Fourier Transform. arXiv preprint arXiv:1812.05013(2018).  Mitali Bafna Jack Murtagh and Nikhil Vyas. 2018. Thwarting Adversarial Examples: An Math 25-RobustSparse Fourier Transform. arXiv preprint arXiv:1812.05013(2018)."},{"volume-title":"Towards evaluating the robustness of neural networks. In 2017 ieee symposium on security and privacy (sp)","author":"Carlini Nicholas","key":"e_1_3_2_1_2_1","unstructured":"Nicholas Carlini and David Wagner . 2017. Towards evaluating the robustness of neural networks. In 2017 ieee symposium on security and privacy (sp) . IEEE , 39\u201357. Nicholas Carlini and David Wagner. 2017. Towards evaluating the robustness of neural networks. In 2017 ieee symposium on security and privacy (sp). IEEE, 39\u201357."},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00498"},{"key":"e_1_3_2_1_4_1","volume-title":"Optimal transport for domain adaptation","author":"Courty Nicolas","year":"2016","unstructured":"Nicolas Courty , R\u00e9mi Flamary , Devis Tuia , and Alain Rakotomamonjy . 2016. Optimal transport for domain adaptation . IEEE transactions on pattern analysis and machine intelligence 39, 9( 2016 ), 1853\u20131865. Nicolas Courty, R\u00e9mi Flamary, Devis Tuia, and Alain Rakotomamonjy. 2016. Optimal transport for domain adaptation. IEEE transactions on pattern analysis and machine intelligence 39, 9(2016), 1853\u20131865."},{"key":"e_1_3_2_1_5_1","unstructured":"Rui Gao and Anton\u00a0J Kleywegt. 2016. Distributionally robust stochastic optimization with Wasserstein distance. arXiv preprint arXiv:1604.02199(2016).  Rui Gao and Anton\u00a0J Kleywegt. 2016. Distributionally robust stochastic optimization with Wasserstein distance. arXiv preprint arXiv:1604.02199(2016)."},{"key":"e_1_3_2_1_6_1","volume-title":"Artificial neural networks (the multilayer perceptron)\u2014a review of applications in the atmospheric sciences. Atmospheric environment 32, 14-15","author":"Gardner W","year":"1998","unstructured":"Matt\u00a0 W Gardner and SR Dorling . 1998. Artificial neural networks (the multilayer perceptron)\u2014a review of applications in the atmospheric sciences. Atmospheric environment 32, 14-15 ( 1998 ), 2627\u20132636. Matt\u00a0W Gardner and SR Dorling. 1998. Artificial neural networks (the multilayer perceptron)\u2014a review of applications in the atmospheric sciences. Atmospheric environment 32, 14-15 (1998), 2627\u20132636."},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/3422622"},{"key":"e_1_3_2_1_8_1","unstructured":"Ian\u00a0J Goodfellow Jonathon Shlens and Christian Szegedy. 2014. Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572(2014).  Ian\u00a0J Goodfellow Jonathon Shlens and Christian Szegedy. 2014. Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572(2014)."},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01258-8_32"},{"key":"e_1_3_2_1_10_1","unstructured":"Harini Kannan Alexey Kurakin and Ian Goodfellow. 2018. Adversarial logit pairing. arXiv preprint arXiv:1803.06373(2018).  Harini Kannan Alexey Kurakin and Ian Goodfellow. 2018. Adversarial logit pairing. arXiv preprint arXiv:1803.06373(2018)."},{"key":"e_1_3_2_1_11_1","volume-title":"Adam: A method for stochastic optimization. arXiv preprint arXiv:1412.6980(2014).","author":"Kingma P","year":"2014","unstructured":"Diederik\u00a0 P Kingma and Jimmy Ba . 2014 . Adam: A method for stochastic optimization. arXiv preprint arXiv:1412.6980(2014). Diederik\u00a0P Kingma and Jimmy Ba. 2014. Adam: A method for stochastic optimization. arXiv preprint arXiv:1412.6980(2014)."},{"key":"e_1_3_2_1_12_1","unstructured":"Alex Krizhevsky Geoffrey Hinton 2009. Learning multiple layers of features from tiny images. (2009).  Alex Krizhevsky Geoffrey Hinton 2009. Learning multiple layers of features from tiny images. (2009)."},{"key":"e_1_3_2_1_13_1","volume-title":"Imagenet classification with deep convolutional neural networks. Advances in neural information processing systems 25","author":"Krizhevsky Alex","year":"2012","unstructured":"Alex Krizhevsky , Ilya Sutskever , and Geoffrey\u00a0 E Hinton . 2012. Imagenet classification with deep convolutional neural networks. Advances in neural information processing systems 25 ( 2012 ), 1097\u20131105. Alex Krizhevsky, Ilya Sutskever, and Geoffrey\u00a0E Hinton. 2012. Imagenet classification with deep convolutional neural networks. Advances in neural information processing systems 25 (2012), 1097\u20131105."},{"key":"e_1_3_2_1_14_1","unstructured":"Alexey Kurakin Ian Goodfellow Samy Bengio 2016. Adversarial examples in the physical world.  Alexey Kurakin Ian Goodfellow Samy Bengio 2016. Adversarial examples in the physical world."},{"key":"e_1_3_2_1_15_1","volume-title":"convolutional neural networks. URL: http:\/\/yann. lecun. com\/exdb\/lenet 20, 5","author":"Yann","year":"2015","unstructured":"Yann LeCun 2015. LeNet-5 , convolutional neural networks. URL: http:\/\/yann. lecun. com\/exdb\/lenet 20, 5 ( 2015 ), 14. Yann LeCun 2015. LeNet-5, convolutional neural networks. URL: http:\/\/yann. lecun. com\/exdb\/lenet 20, 5 (2015), 14."},{"key":"e_1_3_2_1_16_1","unstructured":"Y. LeCun BE. Boser and JS. Denker. 1990. Handwritten digit recognition with a back-propagation network. In NeurIPS. 396\u2013494.  Y. LeCun BE. Boser and JS. Denker. 1990. Handwritten digit recognition with a back-propagation network. In NeurIPS. 396\u2013494."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298958"},{"key":"e_1_3_2_1_18_1","unstructured":"Ji Lin Chuang Gan and Song Han. 2019. Defensive quantization: When efficiency meets robustness. arXiv preprint arXiv:1904.08444(2019).  Ji Lin Chuang Gan and Song Han. 2019. Defensive quantization: When efficiency meets robustness. arXiv preprint arXiv:1904.08444(2019)."},{"key":"e_1_3_2_1_19_1","unstructured":"Aleksander Madry Aleksandar Makelov Ludwig Schmidt Dimitris Tsipras and Adrian Vladu. 2017. Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083(2017).  Aleksander Madry Aleksandar Makelov Ludwig Schmidt Dimitris Tsipras and Adrian Vladu. 2017. Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083(2017)."},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.41"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.eng.2019.12.012"},{"key":"e_1_3_2_1_23_1","volume-title":"Going deeper in spiking neural networks: VGG and residual architectures. Frontiers in neuroscience 13","author":"Sengupta Abhronil","year":"2019","unstructured":"Abhronil Sengupta , Yuting Ye , Robert Wang , Chiao Liu , and Kaushik Roy . 2019. Going deeper in spiking neural networks: VGG and residual architectures. Frontiers in neuroscience 13 ( 2019 ), 95. Abhronil Sengupta, Yuting Ye, Robert Wang, Chiao Liu, and Kaushik Roy. 2019. Going deeper in spiking neural networks: VGG and residual architectures. Frontiers in neuroscience 13 (2019), 95."},{"key":"e_1_3_2_1_24_1","unstructured":"Florian Tram\u00e8r Alexey Kurakin Nicolas Papernot Ian Goodfellow Dan Boneh and Patrick McDaniel. 2017. Ensemble adversarial training: Attacks and defenses. arXiv preprint arXiv:1705.07204(2017).  Florian Tram\u00e8r Alexey Kurakin Nicolas Papernot Ian Goodfellow Dan Boneh and Patrick McDaniel. 2017. Ensemble adversarial training: Attacks and defenses. arXiv preprint arXiv:1705.07204(2017)."},{"key":"e_1_3_2_1_25_1","unstructured":"Zhuozhuo Tu Jingwei Zhang and Dacheng Tao. 2019. Theoretical analysis of adversarial learning: A minimax approach. (2019).  Zhuozhuo Tu Jingwei Zhang and Dacheng Tao. 2019. Theoretical analysis of adversarial learning: A minimax approach. (2019)."},{"key":"e_1_3_2_1_26_1","unstructured":"Riccardo Volpi Hongseok Namkoong Ozan Sener John Duchi Vittorio Murino and Silvio Savarese. 2018. Generalizing to unseen domains via adversarial data augmentation. arXiv preprint arXiv:1805.12018(2018).  Riccardo Volpi Hongseok Namkoong Ozan Sener John Duchi Vittorio Murino and Silvio Savarese. 2018. Generalizing to unseen domains via adversarial data augmentation. arXiv preprint arXiv:1805.12018(2018)."},{"key":"e_1_3_2_1_27_1","unstructured":"Bao Wang Alex\u00a0T Lin Wei Zhu Penghang Yin Andrea\u00a0L Bertozzi and Stanley\u00a0J Osher. 2018. Adversarial defense via data dependent activation function and total variation minimization. arXiv preprint arXiv:1809.08516(2018).  Bao Wang Alex\u00a0T Lin Wei Zhu Penghang Yin Andrea\u00a0L Bertozzi and Stanley\u00a0J Osher. 2018. Adversarial defense via data dependent activation function and total variation minimization. arXiv preprint arXiv:1809.08516(2018)."},{"key":"e_1_3_2_1_28_1","unstructured":"Han Xiao Kashif Rasul and Roland Vollgraf. 2017. Fashion-mnist: a novel image dataset for benchmarking machine learning algorithms. arXiv preprint arXiv:1708.07747(2017).  Han Xiao Kashif Rasul and Roland Vollgraf. 2017. Fashion-mnist: a novel image dataset for benchmarking machine learning algorithms. arXiv preprint arXiv:1708.07747(2017)."},{"key":"e_1_3_2_1_29_1","unstructured":"Cihang Xie Jianyu Wang Zhishuai Zhang Zhou Ren and Alan Yuille. 2017. Mitigating adversarial effects through randomization. arXiv preprint arXiv:1711.01991(2017).  Cihang Xie Jianyu Wang Zhishuai Zhang Zhou Ren and Alan Yuille. 2017. Mitigating adversarial effects through randomization. arXiv preprint arXiv:1711.01991(2017)."},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00059"},{"key":"e_1_3_2_1_31_1","unstructured":"Long Zhao Ting Liu Xi Peng and Dimitris Metaxas. 2020. Maximum-entropy adversarial data augmentation for improved generalization and robustness. arXiv preprint arXiv:2010.08001(2020).  Long Zhao Ting Liu Xi Peng and Dimitris Metaxas. 2020. Maximum-entropy adversarial data augmentation for improved generalization and robustness. arXiv preprint arXiv:2010.08001(2020)."}],"event":{"name":"AISS 2021: 2021 3rd International Conference on Advanced Information Science and System","acronym":"AISS 2021","location":"Sanya China"},"container-title":["Proceedings of the 3rd International Conference on Advanced Information Science and System"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3503047.3503106","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3503047.3503106","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T20:18:49Z","timestamp":1750191529000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3503047.3503106"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,11,26]]},"references-count":31,"alternative-id":["10.1145\/3503047.3503106","10.1145\/3503047"],"URL":"https:\/\/doi.org\/10.1145\/3503047.3503106","relation":{},"subject":[],"published":{"date-parts":[[2021,11,26]]},"assertion":[{"value":"2022-01-19","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}