{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,9,4]],"date-time":"2025-09-04T14:16:27Z","timestamp":1756995387840,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":49,"publisher":"ACM","license":[{"start":{"date-parts":[[2022,10,10]],"date-time":"2022-10-10T00:00:00Z","timestamp":1665360000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61832002, 62172094"],"award-info":[{"award-number":["61832002, 62172094"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Beijing Natural Science Foundation","award":["JQ20023"],"award-info":[{"award-number":["JQ20023"]}]},{"name":"National Key R&D Program of China","award":["2018AAA0100604"],"award-info":[{"award-number":["2018AAA0100604"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2022,10,10]]},"DOI":"10.1145\/3503161.3549200","type":"proceedings-article","created":{"date-parts":[[2022,10,10]],"date-time":"2022-10-10T15:43:12Z","timestamp":1665416592000},"page":"6883-6889","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":3,"title":["Benign Adversarial Attack"],"prefix":"10.1145","author":[{"given":"Jitao","family":"Sang","sequence":"first","affiliation":[{"name":"Beijing Jiaotong University &amp; Peng Cheng Lab, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xian","family":"Zhao","sequence":"additional","affiliation":[{"name":"Beijing Jiaotong University, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jiaming","family":"Zhang","sequence":"additional","affiliation":[{"name":"Beijing Jiaotong University, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zhiyu","family":"Lin","sequence":"additional","affiliation":[{"name":"Beijing Jiaotong University, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2022,10,10]]},"reference":[{"key":"e_1_3_2_2_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/3240508.3241916"},{"key":"e_1_3_2_2_2_1","volume-title":"Adversarial transformation networks: Learning to generate adversarial examples. arXiv preprint arXiv:1703.09387","author":"Baluja Shumeet","year":"2017","unstructured":"Shumeet Baluja and Ian Fischer . 2017. Adversarial transformation networks: Learning to generate adversarial examples. arXiv preprint arXiv:1703.09387 ( 2017 ). Shumeet Baluja and Ian Fischer. 2017. Adversarial transformation networks: Learning to generate adversarial examples. arXiv preprint arXiv:1703.09387 (2017)."},{"key":"e_1_3_2_2_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDAR.2013.140"},{"key":"e_1_3_2_2_4_1","doi-asserted-by":"publisher","DOI":"10.1038\/s42256-020-00266-y"},{"volume-title":"Towards evaluating the robustness of neural networks. In 2017 ieee symposium on security and privacy (sp)","author":"Carlini Nicholas","key":"e_1_3_2_2_5_1","unstructured":"Nicholas Carlini and David Wagner . 2017. Towards evaluating the robustness of neural networks. In 2017 ieee symposium on security and privacy (sp) . IEEE , 39--57. Nicholas Carlini and David Wagner. 2017. Towards evaluating the robustness of neural networks. In 2017 ieee symposium on security and privacy (sp). IEEE, 39--57."},{"key":"e_1_3_2_2_6_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-97909-0_46"},{"key":"e_1_3_2_2_7_1","first-page":"1753","article-title":"Deep fakes: A looming challenge for privacy, democracy, and national security","volume":"107","author":"Chesney Bobby","year":"2019","unstructured":"Bobby Chesney and Danielle Citron . 2019 . Deep fakes: A looming challenge for privacy, democracy, and national security . Calif. L. Rev. , Vol. 107 (2019), 1753 . Bobby Chesney and Danielle Citron. 2019. Deep fakes: A looming challenge for privacy, democracy, and national security. Calif. L. Rev., Vol. 107 (2019), 1753.","journal-title":"Calif. L. Rev."},{"key":"e_1_3_2_2_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00482"},{"key":"e_1_3_2_2_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"e_1_3_2_2_10_1","volume-title":"Adversarial Laser Beam: Effective Physical-World Attack to DNNs in a Blink. arXiv preprint arXiv:2103.06504","author":"Duan Ranjie","year":"2021","unstructured":"Ranjie Duan , Xiaofeng Mao , A Kai Qin , Yun Yang , Yuefeng Chen , Shaokai Ye , and Yuan He. 2021. Adversarial Laser Beam: Effective Physical-World Attack to DNNs in a Blink. arXiv preprint arXiv:2103.06504 ( 2021 ). Ranjie Duan, Xiaofeng Mao, A Kai Qin, Yun Yang, Yuefeng Chen, Shaokai Ye, and Yuan He. 2021. Adversarial Laser Beam: Effective Physical-World Attack to DNNs in a Blink. arXiv preprint arXiv:2103.06504 (2021)."},{"key":"e_1_3_2_2_11_1","volume-title":"Deepcloak: Masking deep neural network models for robustness against adversarial samples. arXiv preprint arXiv:1702.06763","author":"Gao Ji","year":"2017","unstructured":"Ji Gao , Beilun Wang , Zeming Lin , Weilin Xu , and Yanjun Qi . 2017 . Deepcloak: Masking deep neural network models for robustness against adversarial samples. arXiv preprint arXiv:1702.06763 (2017). Ji Gao, Beilun Wang, Zeming Lin, Weilin Xu, and Yanjun Qi. 2017. Deepcloak: Masking deep neural network models for robustness against adversarial samples. arXiv preprint arXiv:1702.06763 (2017)."},{"key":"e_1_3_2_2_12_1","volume-title":"Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572","author":"Goodfellow Ian J","year":"2014","unstructured":"Ian J Goodfellow , Jonathon Shlens , and Christian Szegedy . 2014. Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572 ( 2014 ). Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy. 2014. Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572 (2014)."},{"key":"e_1_3_2_2_13_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-46487-9_6"},{"key":"e_1_3_2_2_14_1","volume-title":"Proceedings of the 30th International Conference on Neural Information Processing Systems. 3323--3331","author":"Hardt Moritz","year":"2016","unstructured":"Moritz Hardt , Eric Price , and Nathan Srebro . 2016 . Equality of opportunity in supervised learning . In Proceedings of the 30th International Conference on Neural Information Processing Systems. 3323--3331 . Moritz Hardt, Eric Price, and Nathan Srebro. 2016. Equality of opportunity in supervised learning. In Proceedings of the 30th International Conference on Neural Information Processing Systems. 3323--3331."},{"key":"e_1_3_2_2_15_1","doi-asserted-by":"publisher","DOI":"10.1021\/ci0342472"},{"key":"e_1_3_2_2_16_1","volume-title":"Workshop on faces in'Real-Life'Images: detection, alignment, and recognition.","author":"Huang Gary B","year":"2008","unstructured":"Gary B Huang , Marwan Mattar , Tamara Berg , and Eric Learned-Miller . 2008 . Labeled faces in the wild: A database forstudying face recognition in unconstrained environments . In Workshop on faces in'Real-Life'Images: detection, alignment, and recognition. Gary B Huang, Marwan Mattar, Tamara Berg, and Eric Learned-Miller. 2008. Labeled faces in the wild: A database forstudying face recognition in unconstrained environments. In Workshop on faces in'Real-Life'Images: detection, alignment, and recognition."},{"key":"e_1_3_2_2_17_1","volume-title":"Adversarial attacks on neural network policies. arXiv preprint arXiv:1702.02284","author":"Huang Sandy","year":"2017","unstructured":"Sandy Huang , Nicolas Papernot , Ian Goodfellow , Yan Duan , and Pieter Abbeel . 2017. Adversarial attacks on neural network policies. arXiv preprint arXiv:1702.02284 ( 2017 ). Sandy Huang, Nicolas Papernot, Ian Goodfellow, Yan Duan, and Pieter Abbeel. 2017. Adversarial attacks on neural network policies. arXiv preprint arXiv:1702.02284 (2017)."},{"key":"e_1_3_2_2_18_1","volume-title":"They Are Features. Advances in neural information processing systems","author":"Ilyas Andrew","year":"2019","unstructured":"Andrew Ilyas , Shibani Santurkar , Logan Engstrom , Brandon Tran , and Aleksander Madry . 2019. Adversarial Examples Are Not Bugs , They Are Features. Advances in neural information processing systems , Vol. 32 ( 2019 ). Andrew Ilyas, Shibani Santurkar, Logan Engstrom, Brandon Tran, and Aleksander Madry. 2019. Adversarial Examples Are Not Bugs, They Are Features. Advances in neural information processing systems, Vol. 32 (2019)."},{"key":"e_1_3_2_2_19_1","volume-title":"A singular value perspective on model robustness. arXiv preprint arXiv:2012.03516","author":"Jere Malhar","year":"2020","unstructured":"Malhar Jere , Maghav Kumar , and Farinaz Koushanfar . 2020. A singular value perspective on model robustness. arXiv preprint arXiv:2012.03516 ( 2020 ). Malhar Jere, Maghav Kumar, and Farinaz Koushanfar. 2020. A singular value perspective on model robustness. arXiv preprint arXiv:2012.03516 (2020)."},{"key":"e_1_3_2_2_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00524"},{"key":"e_1_3_2_2_21_1","volume-title":"Machine Bias: There\u00e2uA\u0179s Software Used Across the Country to Predict Future Criminals. And it\u00e2uA\u0179s Biased Against Blacks.(May","author":"Lauren Julia Angwin Kirchner Jeff Larson","year":"2016","unstructured":"Jeff Larson Lauren Julia Angwin Kirchner and Surya Mattu . 2016 . Machine Bias: There\u00e2uA\u0179s Software Used Across the Country to Predict Future Criminals. And it\u00e2uA\u0179s Biased Against Blacks.(May 2016). Jeff Larson Lauren Julia Angwin Kirchner and Surya Mattu. 2016. Machine Bias: There\u00e2uA\u0179s Software Used Across the Country to Predict Future Criminals. And it\u00e2uA\u0179s Biased Against Blacks.(May 2016)."},{"key":"e_1_3_2_2_22_1","unstructured":"Alex Krizhevsky Geoffrey Hinton etal 2009. Learning multiple layers of features from tiny images. (2009).  Alex Krizhevsky Geoffrey Hinton et al. 2009. Learning multiple layers of features from tiny images. (2009)."},{"key":"e_1_3_2_2_23_1","volume-title":"Proceedings of the International Conference on Learning Representations (ICLR) Workshop.","author":"Kurakin Alexey","year":"2016","unstructured":"Alexey Kurakin , Ian Goodfellow , Samy Bengio , 2016 . Adversarial examples in the physical world . In Proceedings of the International Conference on Learning Representations (ICLR) Workshop. Alexey Kurakin, Ian Goodfellow, Samy Bengio, et al. 2016. Adversarial examples in the physical world. In Proceedings of the International Conference on Learning Representations (ICLR) Workshop."},{"key":"e_1_3_2_2_24_1","unstructured":"Yaniv Leviathan and Yossi Matias. 2018. Google Duplex: an AI system for accomplishing real-world tasks over the phone. (2018).  Yaniv Leviathan and Yossi Matias. 2018. Google Duplex: an AI system for accomplishing real-world tasks over the phone. (2018)."},{"key":"e_1_3_2_2_25_1","doi-asserted-by":"crossref","unstructured":"Zhiyu Lin Yifei Gao and Jitao Sang. 2022. Investigating and explaining the frequency bias in image classification. In IJCAI.  Zhiyu Lin Yifei Gao and Jitao Sang. 2022. Investigating and explaining the frequency bias in image classification. In IJCAI.","DOI":"10.24963\/ijcai.2022\/101"},{"key":"e_1_3_2_2_26_1","volume-title":"Delving into transferable adversarial examples and black-box attacks. arXiv preprint arXiv:1611.02770","author":"Liu Yanpei","year":"2016","unstructured":"Yanpei Liu , Xinyun Chen , Chang Liu , and Dawn Song . 2016. Delving into transferable adversarial examples and black-box attacks. arXiv preprint arXiv:1611.02770 ( 2016 ). Yanpei Liu, Xinyun Chen, Chang Liu, and Dawn Song. 2016. Delving into transferable adversarial examples and black-box attacks. arXiv preprint arXiv:1611.02770 (2016)."},{"key":"e_1_3_2_2_27_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/P17-1103"},{"key":"e_1_3_2_2_28_1","first-page":"433","article-title":"Computing machinery and intelligence-AM Turing","volume":"59","author":"Machinery Computing","year":"1950","unstructured":"Computing Machinery . 1950 . Computing machinery and intelligence-AM Turing . Mind , Vol. 59 , 236 (1950), 433 . Computing Machinery. 1950. Computing machinery and intelligence-AM Turing. Mind, Vol. 59, 236 (1950), 433.","journal-title":"Mind"},{"key":"e_1_3_2_2_29_1","volume-title":"Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083","author":"Madry Aleksander","year":"2017","unstructured":"Aleksander Madry , Aleksandar Makelov , Ludwig Schmidt , Dimitris Tsipras , and Adrian Vladu . 2017. Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083 ( 2017 ). Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu. 2017. Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083 (2017)."},{"key":"e_1_3_2_2_30_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cub.2014.10.025"},{"key":"e_1_3_2_2_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.17"},{"key":"e_1_3_2_2_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW.2017.250"},{"key":"e_1_3_2_2_33_1","volume-title":"Verification of a human in the loop or Identification via the Turing Test. Unpublished draft from http:\/\/www. wisdom. weizmann. ac. il\/ naor\/PAPERS\/human abs. html","author":"Naor Moni","year":"1996","unstructured":"Moni Naor . 1996. Verification of a human in the loop or Identification via the Turing Test. Unpublished draft from http:\/\/www. wisdom. weizmann. ac. il\/ naor\/PAPERS\/human abs. html ( 1996 ). Moni Naor. 1996. Verification of a human in the loop or Identification via the Turing Test. Unpublished draft from http:\/\/www. wisdom. weizmann. ac. il\/ naor\/PAPERS\/human abs. html (1996)."},{"key":"e_1_3_2_2_34_1","doi-asserted-by":"publisher","DOI":"10.1016\/0092-8674(94)90414-6"},{"key":"e_1_3_2_2_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"e_1_3_2_2_36_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.41"},{"key":"e_1_3_2_2_37_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00465"},{"key":"e_1_3_2_2_38_1","doi-asserted-by":"publisher","DOI":"10.1109\/WACV.2016.7477558"},{"key":"e_1_3_2_2_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978392"},{"key":"e_1_3_2_2_40_1","doi-asserted-by":"publisher","DOI":"10.1109\/TEVC.2019.2890858"},{"key":"e_1_3_2_2_41_1","volume-title":"Meta-Transfer Learning for Few-Shot Learning. In The IEEE Conference on Computer Vision and Pattern Recognition (CVPR).","author":"Sun Qianru","year":"2019","unstructured":"Qianru Sun , Yaoyao Liu , Tat-Seng Chua , and Bernt Schiele . 2019 . Meta-Transfer Learning for Few-Shot Learning. In The IEEE Conference on Computer Vision and Pattern Recognition (CVPR). Qianru Sun, Yaoyao Liu, Tat-Seng Chua, and Bernt Schiele. 2019. Meta-Transfer Learning for Few-Shot Learning. In The IEEE Conference on Computer Vision and Pattern Recognition (CVPR)."},{"key":"e_1_3_2_2_42_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00871"},{"key":"e_1_3_2_2_43_1","volume-title":"Advances in Neural Information Processing Systems","volume":"32","author":"Wang Yulin","year":"2019","unstructured":"Yulin Wang , Xuran Pan , Shiji Song , Hong Zhang , Gao Huang , and Cheng Wu . 2019 . Implicit semantic data augmentation for deep networks . Advances in Neural Information Processing Systems , Vol. 32 (2019). Yulin Wang, Xuran Pan, Shiji Song, Hong Zhang, Gao Huang, and Cheng Wu. 2019. Implicit semantic data augmentation for deep networks. Advances in Neural Information Processing Systems, Vol. 32 (2019)."},{"key":"e_1_3_2_2_44_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00284"},{"key":"e_1_3_2_2_45_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58558-7_39"},{"key":"e_1_3_2_2_46_1","volume-title":"Understanding deep learning requires rethinking generalization. arXiv preprint arXiv:1611.03530","author":"Zhang Chiyuan","year":"2016","unstructured":"Chiyuan Zhang , Samy Bengio , Moritz Hardt , Benjamin Recht , and Oriol Vinyals . 2016. Understanding deep learning requires rethinking generalization. arXiv preprint arXiv:1611.03530 ( 2016 ). Chiyuan Zhang, Samy Bengio, Moritz Hardt, Benjamin Recht, and Oriol Vinyals. 2016. Understanding deep learning requires rethinking generalization. arXiv preprint arXiv:1611.03530 (2016)."},{"key":"e_1_3_2_2_47_1","doi-asserted-by":"publisher","DOI":"10.1109\/TMM.2020.3013376"},{"key":"e_1_3_2_2_48_1","doi-asserted-by":"publisher","DOI":"10.1145\/3394171.3413906"},{"key":"e_1_3_2_2_49_1","doi-asserted-by":"publisher","DOI":"10.1145\/3394171.3413772"}],"event":{"name":"MM '22: The 30th ACM International Conference on Multimedia","sponsor":["SIGMM ACM Special Interest Group on Multimedia"],"location":"Lisboa Portugal","acronym":"MM '22"},"container-title":["Proceedings of the 30th ACM International Conference on Multimedia"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3503161.3549200","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3503161.3549200","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T17:49:18Z","timestamp":1750182558000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3503161.3549200"}},"subtitle":["Tricking Models for Goodness"],"short-title":[],"issued":{"date-parts":[[2022,10,10]]},"references-count":49,"alternative-id":["10.1145\/3503161.3549200","10.1145\/3503161"],"URL":"https:\/\/doi.org\/10.1145\/3503161.3549200","relation":{},"subject":[],"published":{"date-parts":[[2022,10,10]]},"assertion":[{"value":"2022-10-10","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}