{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,16]],"date-time":"2026-07-16T12:38:40Z","timestamp":1784205520634,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":57,"publisher":"ACM","license":[{"start":{"date-parts":[[2022,11,27]],"date-time":"2022-11-27T00:00:00Z","timestamp":1669507200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2022,11,27]]},"DOI":"10.1145\/3568444.3568469","type":"proceedings-article","created":{"date-parts":[[2022,12,29]],"date-time":"2022-12-29T15:42:17Z","timestamp":1672328537000},"page":"231-242","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":3,"title":["ExplAInable Pixels: Investigating One-Pixel Attacks on Deep Learning Models with Explainable Visualizations"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-0978-517X","authenticated-orcid":false,"given":"Jonas","family":"Keppel","sequence":"first","affiliation":[{"name":"Human-Computer Interaction Group, University of Duisburg-Essen, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6923-9066","authenticated-orcid":false,"given":"Jonathan","family":"Liebers","sequence":"additional","affiliation":[{"name":"Human-Computer Interaction Group, University of Duisburg-Essen, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1326-1405","authenticated-orcid":false,"given":"Jonas","family":"Auda","sequence":"additional","affiliation":[{"name":"Human-Computer Interaction Group, University of Duisburg-Essen, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5671-1640","authenticated-orcid":false,"given":"Uwe","family":"Gruenefeld","sequence":"additional","affiliation":[{"name":"Human-Computer Interaction Group, University of Duisburg-Essen, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0132-4934","authenticated-orcid":false,"given":"Stefan","family":"Schneegass","sequence":"additional","affiliation":[{"name":"Human-Computer Interaction Group, University of Duisburg-Essen, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2022,12,29]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"Anish Athalye Logan Engstrom Andrew Ilyas and Kevin Kwok. 2017. Synthesizing Robust Adversarial Examples. http:\/\/arxiv.org\/abs\/1707.07397.  Anish Athalye Logan Engstrom Andrew Ilyas and Kevin Kwok. 2017. Synthesizing Robust Adversarial Examples. http:\/\/arxiv.org\/abs\/1707.07397."},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/3475724.3483604"},{"key":"e_1_3_2_1_3_1","first-page":"3","article-title":"Determining What Individual SUS Scores Mean: Adding an Adjective Rating Scale","volume":"4","author":"Bangor Aaron","year":"2009","unstructured":"Aaron Bangor , Philip Kortum , and James Miller . 2009 . Determining What Individual SUS Scores Mean: Adding an Adjective Rating Scale . Journal of Usability Studies 4 , 3 (May 2009), 114\u2013123. https:\/\/dl.acm.org\/doi\/10.5555\/2835587.2835589. Aaron Bangor, Philip Kortum, and James Miller. 2009. Determining What Individual SUS Scores Mean: Adding an Adjective Rating Scale. Journal of Usability Studies 4, 3 (May 2009), 114\u2013123. https:\/\/dl.acm.org\/doi\/10.5555\/2835587.2835589.","journal-title":"Journal of Usability Studies"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.inffus.2019.12.012"},{"key":"e_1_3_2_1_5_1","unstructured":"Bj\u00f6rn Barz and Joachim Denzler. 2019. Do we train on test data? Purging CIFAR of near-duplicates. http:\/\/arxiv.org\/abs\/1902.00423.  Bj\u00f6rn Barz and Joachim Denzler. 2019. Do we train on test data? Purging CIFAR of near-duplicates. http:\/\/arxiv.org\/abs\/1902.00423."},{"key":"e_1_3_2_1_6_1","unstructured":"Battista Biggio Igino Corona Davide Maiorca Blaine Nelson Nedim Srndic Pavel Laskov Giorgio Giacinto and Fabio Roli. 2017. Evasion Attacks against Machine Learning at Test Time. http:\/\/arxiv.org\/abs\/1708.06131.  Battista Biggio Igino Corona Davide Maiorca Blaine Nelson Nedim Srndic Pavel Laskov Giorgio Giacinto and Fabio Roli. 2017. Evasion Attacks against Machine Learning at Test Time. http:\/\/arxiv.org\/abs\/1708.06131."},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1109\/47.867942"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1002\/capr.12360"},{"key":"e_1_3_2_1_9_1","volume-title":"SUS: A quick and dirty usability scale. In Usability Evaluation in Industry, Patrick\u00a0W. Jordan, B.\u00a0Thomas, Ian\u00a0Lyall McClelland","author":"Brooke John","year":"1996","unstructured":"John Brooke . 1996 . SUS: A quick and dirty usability scale. In Usability Evaluation in Industry, Patrick\u00a0W. Jordan, B.\u00a0Thomas, Ian\u00a0Lyall McClelland , and Bernard Weerdmeester (Eds.). CRC Press , London . ISBN 978-0748404605. John Brooke. 1996. SUS: A quick and dirty usability scale. In Usability Evaluation in Industry, Patrick\u00a0W. Jordan, B.\u00a0Thomas, Ian\u00a0Lyall McClelland, and Bernard Weerdmeester (Eds.). CRC Press, London. ISBN 978-0748404605."},{"key":"e_1_3_2_1_10_1","unstructured":"Tom\u00a0B. Brown Dandelion Man\u00e9 Aurko Roy Mart\u00edn Abadi and Justin Gilmer. 2017. Adversarial Patch. http:\/\/arxiv.org\/abs\/1712.09665.  Tom\u00a0B. Brown Dandelion Man\u00e9 Aurko Roy Mart\u00edn Abadi and Justin Gilmer. 2017. Adversarial Patch. http:\/\/arxiv.org\/abs\/1712.09665."},{"key":"e_1_3_2_1_11_1","unstructured":"Nicholas Carlini and David\u00a0A. Wagner. 2016. Defensive Distillation is Not Robust to Adversarial Examples. http:\/\/arxiv.org\/abs\/1607.04311.  Nicholas Carlini and David\u00a0A. Wagner. 2016. Defensive Distillation is Not Robust to Adversarial Examples. http:\/\/arxiv.org\/abs\/1607.04311."},{"key":"e_1_3_2_1_12_1","unstructured":"Nicholas Carlini and David\u00a0A. Wagner. 2016. Towards Evaluating the Robustness of Neural Networks. http:\/\/arxiv.org\/abs\/1608.04644.  Nicholas Carlini and David\u00a0A. Wagner. 2016. Towards Evaluating the Robustness of Neural Networks. http:\/\/arxiv.org\/abs\/1608.04644."},{"key":"e_1_3_2_1_13_1","volume-title":"\u201cEfficient Defenses Against Adversarial Attacks","author":"Carlini Nicholas","unstructured":"Nicholas Carlini and David\u00a0 A. Wagner . 2017. MagNet and \u201cEfficient Defenses Against Adversarial Attacks \u201d are Not Robust to Adversarial Examples . http:\/\/arxiv.org\/abs\/1711.08478. Nicholas Carlini and David\u00a0A. Wagner. 2017. MagNet and \u201cEfficient Defenses Against Adversarial Attacks\u201d are Not Robust to Adversarial Examples. http:\/\/arxiv.org\/abs\/1711.08478."},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/2783258.2788613"},{"key":"e_1_3_2_1_15_1","unstructured":"Anirban Chakraborty Manaar Alam Vishal Dey Anupam Chattopadhyay and Debdeep Mukhopadhyay. 2018. Adversarial Attacks and Defences: A Survey. http:\/\/arxiv.org\/abs\/1810.00069  Anirban Chakraborty Manaar Alam Vishal Dey Anupam Chattopadhyay and Debdeep Mukhopadhyay. 2018. Adversarial Attacks and Defences: A Survey. http:\/\/arxiv.org\/abs\/1810.00069"},{"key":"e_1_3_2_1_16_1","volume-title":"EAD: Elastic-Net Attacks to Deep Neural Networks via Adversarial Examples. https:\/\/arxiv.org\/abs\/1709.04114.","author":"Chen Pin-Yu","year":"2018","unstructured":"Pin-Yu Chen , Yash Sharma , Huan Zhang , Jinfeng Yi , and Cho-Jui Hsieh . 2018 . EAD: Elastic-Net Attacks to Deep Neural Networks via Adversarial Examples. https:\/\/arxiv.org\/abs\/1709.04114. Pin-Yu Chen, Yash Sharma, Huan Zhang, Jinfeng Yi, and Cho-Jui Hsieh. 2018. EAD: Elastic-Net Attacks to Deep Neural Networks via Adversarial Examples. https:\/\/arxiv.org\/abs\/1709.04114."},{"key":"e_1_3_2_1_17_1","volume-title":"Deep learning with Python","author":"Chollet Fran\u00e7ois","unstructured":"Fran\u00e7ois Chollet . 2017. Deep learning with Python ( 1 st ed.). Manning Publications Co. , USA. ISBN 978-1-61729-443-3. Fran\u00e7ois Chollet. 2017. Deep learning with Python(1st ed.). Manning Publications Co., USA. ISBN 978-1-61729-443-3.","edition":"1"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/1014052.1014066"},{"key":"e_1_3_2_1_19_1","volume-title":"Zeki Yalniz, Yixuan Li, and Dhruv Mahajan.","author":"Dubey Abhimanyu","year":"2019","unstructured":"Abhimanyu Dubey , Laurens van\u00a0der Maaten , Zeki Yalniz, Yixuan Li, and Dhruv Mahajan. 2019 . Defense Against Adversarial Images using Web-Scale Nearest-Neighbor Search . http:\/\/arxiv.org\/abs\/1903.01612. Abhimanyu Dubey, Laurens van\u00a0der Maaten, Zeki Yalniz, Yixuan Li, and Dhruv Mahajan. 2019. Defense Against Adversarial Images using Web-Scale Nearest-Neighbor Search. http:\/\/arxiv.org\/abs\/1903.01612."},{"key":"e_1_3_2_1_20_1","unstructured":"Ivan Evtimov Kevin Eykholt Earlence Fernandes Tadayoshi Kohno Bo Li Atul Prakash Amir Rahmati and Dawn Song. 2017. Robust Physical-World Attacks on Deep Learning Models. http:\/\/arxiv.org\/abs\/1707.08945.  Ivan Evtimov Kevin Eykholt Earlence Fernandes Tadayoshi Kohno Bo Li Atul Prakash Amir Rahmati and Dawn Song. 2017. Robust Physical-World Attacks on Deep Learning Models. http:\/\/arxiv.org\/abs\/1707.08945."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00175"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.3390\/info11020122"},{"key":"e_1_3_2_1_23_1","unstructured":"Ian\u00a0J. Goodfellow Jonathon Shlens and Christian Szegedy. 2015. Explaining and Harnessing Adversarial Examples. https:\/\/arxiv.org\/abs\/1412.6572.  Ian\u00a0J. Goodfellow Jonathon Shlens and Christian Szegedy. 2015. Explaining and Harnessing Adversarial Examples. https:\/\/arxiv.org\/abs\/1412.6572."},{"key":"e_1_3_2_1_24_1","unstructured":"Riccardo Guidotti Anna Monreale Franco Turini Dino Pedreschi and Fosca Giannotti. 2018. A Survey Of Methods For Explaining Black Box Models. http:\/\/arxiv.org\/abs\/1802.01933.  Riccardo Guidotti Anna Monreale Franco Turini Dino Pedreschi and Fosca Giannotti. 2018. A Survey Of Methods For Explaining Black Box Models. http:\/\/arxiv.org\/abs\/1802.01933."},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1609\/aimag.v40i2.2850"},{"key":"e_1_3_2_1_26_1","unstructured":"Fred Hohman Minsuk Kahng Robert Pienta and Duen\u00a0Horng Chau. 2018. Visual Analytics in Deep Learning: An Interrogative Survey for the Next Frontiers. http:\/\/arxiv.org\/abs\/1801.06889.  Fred Hohman Minsuk Kahng Robert Pienta and Duen\u00a0Horng Chau. 2018. Visual Analytics in Deep Learning: An Interrogative Survey for the Next Frontiers. http:\/\/arxiv.org\/abs\/1801.06889."},{"key":"e_1_3_2_1_27_1","volume-title":"Advances in Neural Information Processing Systems, Vol.\u00a032. Curran Associates","author":"Ignatiev Alexey","unstructured":"Alexey Ignatiev , Nina Narodytska , and Joao Marques-Silva . 2019. On Relating Explanations and Adversarial Examples . In Advances in Neural Information Processing Systems, Vol.\u00a032. Curran Associates , Inc., Red Hook, New York , 15857\u201315867. http:\/\/papers.nips.cc\/paper\/9717-on-relating-explanations-and-adversarial-examples. Alexey Ignatiev, Nina Narodytska, and Joao Marques-Silva. 2019. On Relating Explanations and Adversarial Examples. In Advances in Neural Information Processing Systems, Vol.\u00a032. Curran Associates, Inc., Red Hook, New York, 15857\u201315867. http:\/\/papers.nips.cc\/paper\/9717-on-relating-explanations-and-adversarial-examples."},{"key":"e_1_3_2_1_28_1","volume-title":"Learning multiple layers of features from tiny images. Master\u2019s thesis","author":"Krizhevsky Alex","year":"2009","unstructured":"Alex Krizhevsky . 2009. Learning multiple layers of features from tiny images. Master\u2019s thesis . University of Toronto , Toronto, Ontario . https:\/\/www.cs.toronto.edu\/\u00a0kriz\/learning-features- 2009 -TR.pdf. Alex Krizhevsky. 2009. Learning multiple layers of features from tiny images. Master\u2019s thesis. University of Toronto, Toronto, Ontario. https:\/\/www.cs.toronto.edu\/\u00a0kriz\/learning-features-2009-TR.pdf."},{"key":"e_1_3_2_1_29_1","unstructured":"Alex Krizhevsky. 2010. Convolutional Deep Belief Networks on CIFAR-10. https:\/\/www.cs.toronto.edu\/\u00a0kriz\/conv-cifar10-aug2010.pdf.  Alex Krizhevsky. 2010. Convolutional Deep Belief Networks on CIFAR-10. https:\/\/www.cs.toronto.edu\/\u00a0kriz\/conv-cifar10-aug2010.pdf."},{"key":"e_1_3_2_1_30_1","unstructured":"Alexey Kurakin Ian\u00a0J. Goodfellow and Samy Bengio. 2016. Adversarial examples in the physical world. http:\/\/arxiv.org\/abs\/1607.02533.  Alexey Kurakin Ian\u00a0J. Goodfellow and Samy Bengio. 2016. Adversarial examples in the physical world. http:\/\/arxiv.org\/abs\/1607.02533."},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1038\/s41467-019-08987-4"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1016\/B978-0-12-805390-4.00011-X"},{"key":"e_1_3_2_1_33_1","volume-title":"Using the \"thinking aloud\" method in cognitive interface design","author":"Lewis Clayton","unstructured":"Clayton Lewis . 1982. Using the \"thinking aloud\" method in cognitive interface design . IBM TJ Watson Research Center, Yorktown Heights, NY , USA. Clayton Lewis. 1982. Using the \"thinking aloud\" method in cognitive interface design. IBM TJ Watson Research Center, Yorktown Heights, NY, USA."},{"key":"e_1_3_2_1_34_1","unstructured":"Zachary\u00a0Chase Lipton. 2016. The Mythos of Model Interpretability. http:\/\/arxiv.org\/abs\/1606.03490.  Zachary\u00a0Chase Lipton. 2016. The Mythos of Model Interpretability. http:\/\/arxiv.org\/abs\/1606.03490."},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1109\/VAST.2018.8802509"},{"key":"e_1_3_2_1_36_1","unstructured":"Jiajun Lu Hussein Sibai Evan Fabry and David\u00a0A. Forsyth. 2017. NO Need to Worry about Adversarial Examples in Object Detection in Autonomous Vehicles. http:\/\/arxiv.org\/abs\/1707.03501.  Jiajun Lu Hussein Sibai Evan Fabry and David\u00a0A. Forsyth. 2017. NO Need to Worry about Adversarial Examples in Object Detection in Autonomous Vehicles. http:\/\/arxiv.org\/abs\/1707.03501."},{"key":"e_1_3_2_1_37_1","volume-title":"Explaining vulnerabilities to adversarial machine learning through visual analytics","author":"Ma Yuxin","year":"2019","unstructured":"Yuxin Ma , Tiankai Xie , Jundong Li , and Ross Maciejewski . 2019. Explaining vulnerabilities to adversarial machine learning through visual analytics . IEEE transactions on visualization and computer graphics 26, 1( 2019 ), 1075\u20131085. Yuxin Ma, Tiankai Xie, Jundong Li, and Ross Maciejewski. 2019. Explaining vulnerabilities to adversarial machine learning through visual analytics. IEEE transactions on visualization and computer graphics 26, 1(2019), 1075\u20131085."},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"crossref","unstructured":"Dongyu Meng and Hao Chen. 2017. MagNet: A Two-Pronged Defense against Adversarial Examples. http:\/\/arxiv.org\/abs\/1705.09064.  Dongyu Meng and Hao Chen. 2017. MagNet: A Two-Pronged Defense against Adversarial Examples. http:\/\/arxiv.org\/abs\/1705.09064.","DOI":"10.1145\/3133956.3134057"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"crossref","unstructured":"Anh\u00a0Mai Nguyen Jason Yosinski and Jeff Clune. 2014. Deep Neural Networks are Easily Fooled: High Confidence Predictions for Unrecognizable Images. http:\/\/arxiv.org\/abs\/1412.1897.  Anh\u00a0Mai Nguyen Jason Yosinski and Jeff Clune. 2014. Deep Neural Networks are Easily Fooled: High Confidence Predictions for Unrecognizable Images. http:\/\/arxiv.org\/abs\/1412.1897.","DOI":"10.1109\/CVPR.2015.7298640"},{"key":"e_1_3_2_1_40_1","unstructured":"Nicolas Papernot Fartash Faghri Nicholas Carlini Ian Goodfellow Reuben Feinman Alexey Kurakin Cihang Xie Yash Sharma Tom Brown Aurko Roy Alexander Matyasko Vahid Behzadan Karen Hambardzumyan Zhishuai Zhang Yi-Lin Juang Zhi Li Ryan Sheatsley Abhibhav Garg Jonathan Uesato Willi Gierke Yinpeng Dong David Berthelot Paul Hendricks Jonas Rauber and Rujun Long. 2016. Technical Report on the CleverHans v2.1.0 Adversarial Examples Library. https:\/\/arxiv.org\/abs\/1610.00768.  Nicolas Papernot Fartash Faghri Nicholas Carlini Ian Goodfellow Reuben Feinman Alexey Kurakin Cihang Xie Yash Sharma Tom Brown Aurko Roy Alexander Matyasko Vahid Behzadan Karen Hambardzumyan Zhishuai Zhang Yi-Lin Juang Zhi Li Ryan Sheatsley Abhibhav Garg Jonathan Uesato Willi Gierke Yinpeng Dong David Berthelot Paul Hendricks Jonas Rauber and Rujun Long. 2016. Technical Report on the CleverHans v2.1.0 Adversarial Examples Library. https:\/\/arxiv.org\/abs\/1610.00768."},{"key":"e_1_3_2_1_41_1","unstructured":"Nicolas Papernot and Patrick\u00a0D. McDaniel. 2017. Extending Defensive Distillation. http:\/\/arxiv.org\/abs\/1705.05264.  Nicolas Papernot and Patrick\u00a0D. McDaniel. 2017. Extending Defensive Distillation. http:\/\/arxiv.org\/abs\/1705.05264."},{"key":"e_1_3_2_1_42_1","unstructured":"Nicolas Papernot and Patrick\u00a0D. McDaniel. 2018. Deep k-Nearest Neighbors: Towards Confident Interpretable and Robust Deep Learning. http:\/\/arxiv.org\/abs\/1803.04765.  Nicolas Papernot and Patrick\u00a0D. McDaniel. 2018. Deep k-Nearest Neighbors: Towards Confident Interpretable and Robust Deep Learning. http:\/\/arxiv.org\/abs\/1803.04765."},{"key":"e_1_3_2_1_43_1","unstructured":"Nicolas Papernot Patrick\u00a0D. McDaniel and Ian\u00a0J. Goodfellow. 2016. Transferability in Machine Learning: from Phenomena to Black-Box Attacks using Adversarial Samples. http:\/\/arxiv.org\/abs\/1605.07277.  Nicolas Papernot Patrick\u00a0D. McDaniel and Ian\u00a0J. Goodfellow. 2016. Transferability in Machine Learning: from Phenomena to Black-Box Attacks using Adversarial Samples. http:\/\/arxiv.org\/abs\/1605.07277."},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"crossref","unstructured":"Nicolas Papernot Patrick\u00a0D. McDaniel Xi Wu Somesh Jha and Ananthram Swami. 2015. Distillation as a Defense to Adversarial Perturbations against Deep Neural Networks. http:\/\/arxiv.org\/abs\/1511.04508.  Nicolas Papernot Patrick\u00a0D. McDaniel Xi Wu Somesh Jha and Ananthram Swami. 2015. Distillation as a Defense to Adversarial Perturbations against Deep Neural Networks. http:\/\/arxiv.org\/abs\/1511.04508.","DOI":"10.1109\/SP.2016.41"},{"key":"e_1_3_2_1_45_1","volume-title":"Proceedings of the 36th International Conference on Machine Learning(Proceedings of Machine Learning Research, Vol.\u00a097)","author":"Qin Yao","year":"2019","unstructured":"Yao Qin , Nicholas Carlini , Garrison Cottrell , Ian Goodfellow , and Colin Raffel . 2019 . Imperceptible, Robust, and Targeted Adversarial Examples for Automatic Speech Recognition . In Proceedings of the 36th International Conference on Machine Learning(Proceedings of Machine Learning Research, Vol.\u00a097) , Kamalika Chaudhuri and Ruslan Salakhutdinov (Eds.). PMLR, Long Beach, California, USA, 5231\u20135240. https:\/\/proceedings.mlr.press\/v97\/qin19a.html Yao Qin, Nicholas Carlini, Garrison Cottrell, Ian Goodfellow, and Colin Raffel. 2019. Imperceptible, Robust, and Targeted Adversarial Examples for Automatic Speech Recognition. In Proceedings of the 36th International Conference on Machine Learning(Proceedings of Machine Learning Research, Vol.\u00a097), Kamalika Chaudhuri and Ruslan Salakhutdinov (Eds.). PMLR, Long Beach, California, USA, 5231\u20135240. https:\/\/proceedings.mlr.press\/v97\/qin19a.html"},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"crossref","unstructured":"Anurag Ranjan Joel Janai Andreas Geiger and Michael\u00a0J. Black. 2019. Attacking Optical Flow. http:\/\/arxiv.org\/abs\/1910.10053.  Anurag Ranjan Joel Janai Andreas Geiger and Michael\u00a0J. Black. 2019. Attacking Optical Flow. http:\/\/arxiv.org\/abs\/1910.10053.","DOI":"10.1109\/ICCV.2019.00249"},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1145\/2939672.2939778"},{"key":"e_1_3_2_1_48_1","unstructured":"Takami Sato Junjie Shen Ningfei Wang Yunhan\u00a0Jack Jia Xue Lin and Qi\u00a0Alfred Chen. 2020. Security of Deep Learning based Lane Keeping System under Physical-World Adversarial Attack. https:\/\/arxiv.org\/abs\/2003.01782  Takami Sato Junjie Shen Ningfei Wang Yunhan\u00a0Jack Jia Xue Lin and Qi\u00a0Alfred Chen. 2020. Security of Deep Learning based Lane Keeping System under Physical-World Adversarial Attack. https:\/\/arxiv.org\/abs\/2003.01782"},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978392"},{"key":"e_1_3_2_1_50_1","volume-title":"DARTS: Deceiving Autonomous Cars with Toxic Signs","author":"Sitawarin Chawin","year":"2018","unstructured":"Chawin Sitawarin , Arjun\u00a0Nitin Bhagoji , Arsalan Mosenia , Mung Chiang , and Prateek Mittal . 2018 . DARTS: Deceiving Autonomous Cars with Toxic Signs . http:\/\/arxiv.org\/abs\/1802.06430. Chawin Sitawarin, Arjun\u00a0Nitin Bhagoji, Arsalan Mosenia, Mung Chiang, and Prateek Mittal. 2018. DARTS: Deceiving Autonomous Cars with Toxic Signs. http:\/\/arxiv.org\/abs\/1802.06430."},{"key":"e_1_3_2_1_51_1","unstructured":"Chawin Sitawarin and David\u00a0A. Wagner. 2019. Defending Against Adversarial Examples with K-Nearest Neighbor. http:\/\/arxiv.org\/abs\/1906.09525.  Chawin Sitawarin and David\u00a0A. Wagner. 2019. Defending Against Adversarial Examples with K-Nearest Neighbor. http:\/\/arxiv.org\/abs\/1906.09525."},{"key":"e_1_3_2_1_52_1","unstructured":"Jiawei Su Danilo\u00a0Vasconcellos Vargas and Kouichi Sakurai. 2017. One pixel attack for fooling deep neural networks. http:\/\/arxiv.org\/abs\/1710.08864.  Jiawei Su Danilo\u00a0Vasconcellos Vargas and Kouichi Sakurai. 2017. One pixel attack for fooling deep neural networks. http:\/\/arxiv.org\/abs\/1710.08864."},{"key":"e_1_3_2_1_53_1","unstructured":"Christian Szegedy Wojciech Zaremba Ilya Sutskever Joan Bruna Dumitru Erhan Ian Goodfellow and Rob Fergus. 2013. Intriguing properties of neural networks. http:\/\/arxiv.org\/abs\/1312.6199.  Christian Szegedy Wojciech Zaremba Ilya Sutskever Joan Bruna Dumitru Erhan Ian Goodfellow and Rob Fergus. 2013. Intriguing properties of neural networks. http:\/\/arxiv.org\/abs\/1312.6199."},{"key":"e_1_3_2_1_54_1","unstructured":"Florian Tram\u00e8r Alexey Kurakin Nicolas Papernot Ian Goodfellow Dan Boneh and Patrick McDaniel. 2020. Ensemble Adversarial Training: Attacks and Defenses. https:\/\/arxiv.org\/abs\/1705.07204.  Florian Tram\u00e8r Alexey Kurakin Nicolas Papernot Ian Goodfellow Dan Boneh and Patrick McDaniel. 2020. Ensemble Adversarial Training: Attacks and Defenses. https:\/\/arxiv.org\/abs\/1705.07204."},{"key":"e_1_3_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.imavis.2016.03.018"},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1001\/jamadermatol.2019.1735"},{"key":"e_1_3_2_1_57_1","volume-title":"Zeiler and Rob Fergus","author":"D.","year":"2013","unstructured":"Matthew\u00a0 D. Zeiler and Rob Fergus . 2013 . Visualizing and Understanding Convolutional Networks . http:\/\/arxiv.org\/abs\/1311.2901. Matthew\u00a0D. Zeiler and Rob Fergus. 2013. Visualizing and Understanding Convolutional Networks. http:\/\/arxiv.org\/abs\/1311.2901."}],"event":{"name":"MUM 2022: 21th International Conference on Mobile and Ubiquitous Multimedia","location":"Lisbon Portugal","acronym":"MUM 2022"},"container-title":["Proceedings of the 21st International Conference on Mobile and Ubiquitous Multimedia"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3568444.3568469","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3568444.3568469","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T19:00:39Z","timestamp":1750186839000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3568444.3568469"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,11,27]]},"references-count":57,"alternative-id":["10.1145\/3568444.3568469","10.1145\/3568444"],"URL":"https:\/\/doi.org\/10.1145\/3568444.3568469","relation":{},"subject":[],"published":{"date-parts":[[2022,11,27]]},"assertion":[{"value":"2022-12-29","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}