{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,9,12]],"date-time":"2024-09-12T00:15:14Z","timestamp":1726100114007},"reference-count":44,"publisher":"Institute of Electronics, Information and Communications Engineers (IEICE)","issue":"11","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEICE Trans. Inf. &amp; Syst."],"published-print":{"date-parts":[[2021,11,1]]},"DOI":"10.1587\/transinf.2021edp7046","type":"journal-article","created":{"date-parts":[[2021,10,31]],"date-time":"2021-10-31T22:14:05Z","timestamp":1635718445000},"page":"1981-1991","source":"Crossref","is-referenced-by-count":1,"title":["Flexible Bayesian Inference by Weight Transfer for Robust Deep Neural Networks"],"prefix":"10.1587","volume":"E104.D","author":[{"given":"Thi Thu Thao","family":"KHONG","sequence":"first","affiliation":[{"name":"Nara Institute of Science and Technology"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Takashi","family":"NAKADA","sequence":"additional","affiliation":[{"name":"Nara Institute of Science and Technology"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yasuhiko","family":"NAKASHIMA","sequence":"additional","affiliation":[{"name":"Nara Institute of Science and Technology"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"532","reference":[{"key":"1","unstructured":"[1] C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, and R. Fergus, \u201cIntriguing properties of neural networks,\u201d 2nd Int. Conf. Learning Representations-ICLR 2014, arXiv:1312.6199, pp.1-10, 2014."},{"key":"2","unstructured":"[2] I.J. Goodfellow, J. Shlens, and C. Szegedy, \u201cExplaining and harnessing adversarial examples,\u201d 3rd Int. Conf. Learning Representations-ICLR 2015, arXiv:1412.6572, pp.1-11, 2015."},{"key":"3","doi-asserted-by":"crossref","unstructured":"[3] Y. Dong, F. Liao, T. Pang, H. Su, J. Zhu, X. Hu, and J. Li, \u201cBoosting adversarial attacks with momentum,\u201d Proc. IEEE Conf. Comput. Vis. Pattern Recognit. (CVPR), pp.9185-9193, 2018. 10.1109\/CVPR.2018.00957","DOI":"10.1109\/CVPR.2018.00957"},{"key":"4","doi-asserted-by":"crossref","unstructured":"[4] N. Carlini and D. Wagner, \u201cTowards evaluating the robustness of neural networks,\u201d 2017 IEEE Symposium on Security and Privacy (SP), pp.39-57, IEEE, 2017. 10.1109\/SP.2017.49","DOI":"10.1109\/SP.2017.49"},{"key":"5","unstructured":"[5] A. Madry, A. Makelov, L. Schmidt, D. Tsipras, and A. Vladu, \u201cTowards deep learning models resistant to adversarial attacks,\u201d 6th Int. Conf. Learning Representations-ICLR 2018, arXiv:1706.06083, pp.1-28, 2018."},{"key":"6","doi-asserted-by":"crossref","unstructured":"[6] N. Papernot, P. McDaniel, I. Goodfellow, S. Jha, Z.B. Celik, and A. Swami, \u201cPractical black-box attacks against machine learning,\u201d Proc. 2017 ACM on Asia Conf. Computer and Communications Security, pp.506-519, April 2017. 10.1145\/3052973.3053009","DOI":"10.1145\/3052973.3053009"},{"key":"7","doi-asserted-by":"crossref","unstructured":"[7] N. Papernot, P. McDaniel, X. Wu, S. Jha, and A. Swami, \u201cDistillation as a defense to adversarial perturbations against deep neural networks,\u201d 2016 IEEE Symposium on Security and Privacy (SP), pp.582-597, IEEE, 2016. 10.1109\/SP.2016.41","DOI":"10.1109\/SP.2016.41"},{"key":"8","doi-asserted-by":"crossref","unstructured":"[8] N. Carlini and D. Wagner, \u201cAdversarial examples are not easily detected: Bypassing ten detection methods,\u201d Proc. 10th ACM Workshop on Artificial Intelligence and Security, pp.3-14, Nov. 2017. 10.1145\/3128572.3140444","DOI":"10.1145\/3128572.3140444"},{"key":"9","unstructured":"[9] G.S. Dhillon, K. Azizzadenesheli, Z.C. Lipton, J. Bernstein, J. Kossaifi, A. Khanna, and A. Anandkumar, \u201cStochastic activation pruning for robust adversarial defense,\u201d ICLR 2018, arXiv preprint arXiv:1803.01442, pp.1-13, 2018."},{"key":"10","unstructured":"[10] H. Zhang, T.W. Weng, P.Y. Chen, C.J. Hsieh, and L. Daniel, \u201cEfficient neural network robustness certification with general activation functions,\u201d Advances in Neural Information Processing Systems NIPS, pp.4939-4948, 2018."},{"key":"11","unstructured":"[11] A. Rozsa and T.E. Boult, \u201cImproved adversarial robustness by reducing open space risk via tent activations,\u201d arXiv preprint arXiv:1908.02435, pp.1-15, 2019."},{"key":"12","doi-asserted-by":"publisher","unstructured":"[12] B. Wang, A. Lin, P. Yin, W. Zhu, A.L. Bertozzi, and S.J. Osher, \u201cAdversarial defense via the data-dependent activation, total variation minimization, and adversarial training,\u201d Inverse Problems &amp; Imaging, vol.15, no.1, p.129, Feb. 2020. 10.3934\/ipi.2020046","DOI":"10.3934\/ipi.2020046"},{"key":"13","doi-asserted-by":"publisher","unstructured":"[13] M. Tavakoli, F. Agostinelli, and P. Baldi, \u201cSplash: Learnable activation functions for improving accuracy and adversarial robustness,\u201d Neural Networks, vol.140, pp.1-12, Aug. 2021. 10.1016\/j.neunet.2021.02.023","DOI":"10.1016\/j.neunet.2021.02.023"},{"key":"14","unstructured":"[14] N. Ye and Z. Zhu, \u201cBayesian adversarial learning,\u201d Proc. 32nd Int. Conf. Neural Information Processing Systems, pp.6892-6901, 2018."},{"key":"15","doi-asserted-by":"crossref","unstructured":"[15] X. Liu, M. Cheng, H. Zhang, and C.J. Hsieh, \u201cTowards robust neural networks via random self-ensemble,\u201d Proc. European Conf. Comput. Vis. (ECCV), pp.369-385, 2018. 10.1007\/978-3-030-01234-2_23","DOI":"10.1007\/978-3-030-01234-2_23"},{"key":"16","unstructured":"[16] X. Liu, Y. Li, C. Wu, and C.J. Hsieh, \u201cAdv-bnn: Improved adversarial defense through robust bayesian neural network,\u201d 7th Int. Conf. Learning Representations, pp.21-29, 2019."},{"key":"17","doi-asserted-by":"crossref","unstructured":"[17] T.T.T. Khong, T. Nakada, and Y. Nakashima, \u201cBayes without bayesian learning for resisting adversarial attacks,\u201d 2020 Eighth Int. Symp. Computing and Networking (CANDAR), pp.221-227, 2020. 10.1109\/CANDAR51075.2020.00038","DOI":"10.1109\/CANDAR51075.2020.00038"},{"key":"18","unstructured":"[18] C.M. Bishop, \u201cBayesian methods for neural networks,\u201d Technical report, Aston University, Birmingham, 1995."},{"key":"19","unstructured":"[19] R.M. Neal, Bayesian learning for neural networks, Springer Science &amp; Business Media, 2012. 10.1007\/978-1-4612-0745-0"},{"key":"20","unstructured":"[20] C. Blundell, J. Cornebise, K. Kavukcuoglu, and D. Wierstra, \u201cWeight uncertainty in neural networks,\u201d 32nd Int. Conf. Machine Learning, JMLR: W&amp;CP, arXiv:1505.05424, pp.1-10, 2015."},{"key":"21","unstructured":"[21] D. Barber and C.M. Bishop, \u201cEnsemble learning in bayesian neural networks,\u201d Nato ASI Series F Computer and Systems Sciences, vol.168, pp.215-238, 1998."},{"key":"22","unstructured":"[22] Y. Gal and Z. Ghahramani, \u201cBayesian convolutional neural networks with bernoulli approximate variational inference,\u201d arXiv preprint arXiv:1506.02158, pp.1-12, 2015."},{"key":"23","unstructured":"[23] [Online], \u201cAdversarial example generation,\u201d Available: https:\/\/pytorch.org\/tutorials\/beginner\/fgsm_tutorial.html"},{"key":"24","unstructured":"[24] A. Kurakin, I. Goodfellow, and S. Bengio, \u201cAdversarial examples in the physical world,\u201d 5th Int. Conf. Learning Representations, ICLR 2017-Workshop Track Proceedings, arXiv:1607.02533, pp.1-14, 2016."},{"key":"25","doi-asserted-by":"crossref","unstructured":"[25] N. Papernot, P. McDaniel, S. Jha, M. Fredrikson, Z.B. Celik, and A. Swami, \u201cThe limitations of deep learning in adversarial settings,\u201d 2016 IEEE European symposium on security and privacy (EuroS&amp;P), pp.372-387, IEEE, 2016. 10.1109\/EuroSP.2016.36","DOI":"10.1109\/EuroSP.2016.36"},{"key":"26","doi-asserted-by":"crossref","unstructured":"[26] V. Zantedeschi, M.I. Nicolae, and A. Rawat, \u201cEfficient defenses against adversarial attacks,\u201d Proc. 10th ACM Workshop on Artificial Intelligence and Security, pp.39-49, Nov. 2017. 10.1145\/3128572.3140449","DOI":"10.1145\/3128572.3140449"},{"key":"27","doi-asserted-by":"crossref","unstructured":"[27] C. Xie, Y. Wu, L.v.d. Maaten, A.L. Yuille, and K. He, \u201cFeature denoising for improving adversarial robustness,\u201d Proc. IEEE Conf. Comput. Vis. Pattern Recognit., pp.501-509, 2019. 10.1109\/CVPR.2019.00059","DOI":"10.1109\/CVPR.2019.00059"},{"key":"28","unstructured":"[28] A. Shafahi, M. Najibi, A. Ghiasi, Z. Xu, J. Dickerson, C. Studer, L.S. Davis, G. Taylor, and T. Goldstein, \u201cAdversarial training for free!,\u201d Advances in Neural Information Processing Systems, pp.3358-3369, 2019."},{"key":"29","unstructured":"[29] E. Wong, L. Rice, and J.Z. Kolter, \u201cFast is better than free: Revisiting adversarial training,\u201d 8th Int. Conf. Learning Representations, ICLR 2020, arXiv:2001.03994, pp.1-17, 2020."},{"key":"30","unstructured":"[30] A. Kurakin, I. Goodfellow, and S. Bengio, \u201cAdversarial machine learning at scale,\u201d 5th Int. Conf. Learning Representations-ICLR 2017, arXiv:1611.01236, pp.1-17, 2017."},{"key":"31","unstructured":"[31] F. Tram\u00e8r, A. Kurakin, N. Papernot, I. Goodfellow, D. Boneh, and P. McDaniel, \u201cEnsemble adversarial training: Attacks and defenses,\u201d 6th Int. Conf. Learning Representations, ICLR 2018, arXiv:1705.07204, pp.1-22, 2018."},{"key":"32","unstructured":"[32] S. Wang and C. Manning, \u201cFast dropout training,\u201d International Conf. Mach. Learn., JMLR: W&amp;CP, pp.118-126, June 2013."},{"key":"33","doi-asserted-by":"crossref","unstructured":"[33] K. He, X. Zhang, S. Ren, and J. Sun, \u201cDeep residual learning for image recognition,\u201d Proc. IEEE Conf. Comput. Vis. Pattern Recognit., pp.770-778, 2016. 10.1109\/CVPR.2016.90","DOI":"10.1109\/CVPR.2016.90"},{"key":"34","unstructured":"[34] M. Tan and Q.V. Le, \u201cEfficientnet: Rethinking model scaling for convolutional neural networks,\u201d 36th Int. Conf. Machine Learning, ICML 2019, pp.10691-10700, 2019."},{"key":"35","unstructured":"[35] [Online], \u201cTorchvision models,\u201d Available: https:\/\/pytorch.org\/docs\/stable\/torchvision\/models.html"},{"key":"36","unstructured":"[36] [Online], \u201cEfficientnet pytorch,\u201d Available: https:\/\/github.com\/lukemelas\/EfficientNet-PyTorch"},{"key":"37","unstructured":"[37] A. Vaswani, N. Shazeer, N. Parmar, J. Uszkoreit, L. Jones, A.N. Gomez, L. Kaiser, and I. Polosukhin, \u201cAttention is all you need,\u201d 31st Conf. Neural Information Processing Systems (NIPS 2017), arXiv:1706.03762, pp.1-15, 2017."},{"key":"38","doi-asserted-by":"crossref","unstructured":"[38] F. Wang, M. Jiang, C. Qian, S. Yang, C. Li, H. Zhang, X. Wang, and X. Tang, \u201cResidual attention network for image classification,\u201d Proc. IEEE Conf. Comput. Vis. Pattern Recognit., pp.3156-3164, 2017. 10.1109\/CVPR.2017.683","DOI":"10.1109\/CVPR.2017.683"},{"key":"39","unstructured":"[39] H. Zhang, I. Goodfellow, D. Metaxas, and A. Odena, \u201cSelf-attention generative adversarial networks,\u201d International Conf. Mach. Learn., pp.7354-7363, PMLR, 2019."},{"key":"40","unstructured":"[40] P. Ramachandran, N. Parmar, A. Vaswani, I. Bello, A. Levskaya, and J. Shlens, \u201cStand-alone self-attention in vision models,\u201d arXiv preprint arXiv:1906.05909, 2019."},{"key":"41","doi-asserted-by":"crossref","unstructured":"[41] H. Zhao, J. Jia, and V. Koltun, \u201cExploring self-attention for image recognition,\u201d Proc. IEEE\/CVF Conf. Comput. Vis. Pattern Recognit., pp.10076-10085, 2020. 10.1109\/CVPR42600.2020.01009","DOI":"10.1109\/CVPR42600.2020.01009"},{"key":"42","doi-asserted-by":"crossref","unstructured":"[42] C. Xie, M. Tan, B. Gong, J. Wang, A.L. Yuille, and Q.V. Le, \u201cAdversarial examples improve image recognition,\u201d Proc. IEEE\/CVF Conf. Comput. Vis. Pattern Recognit., pp.819-828, 2020. 10.1109\/CVPR42600.2020.00090","DOI":"10.1109\/CVPR42600.2020.00090"},{"key":"43","unstructured":"[43] G.W. Ding, L. Wang, and X. Jin, \u201cAdvertorch v0.1: An adversarial robustness toolbox based on pytorch,\u201d arXiv preprint arXiv:1902.07623, pp.1-6, 2019."},{"key":"44","doi-asserted-by":"crossref","unstructured":"[44] Q. Wan and X. Fu, \u201cFast-bcnn: Massive neuron skipping in bayesian convolutional neural networks,\u201d 2020 53rd Annual IEEE\/ACM Int. Symp. Microarchitecture (MICRO), pp.229-240, IEEE, 2020. 10.1109\/MICRO50266.2020.00030","DOI":"10.1109\/MICRO50266.2020.00030"}],"container-title":["IEICE Transactions on Information and Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.jstage.jst.go.jp\/article\/transinf\/E104.D\/11\/E104.D_2021EDP7046\/_pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,9,11]],"date-time":"2024-09-11T04:49:08Z","timestamp":1726030148000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.jstage.jst.go.jp\/article\/transinf\/E104.D\/11\/E104.D_2021EDP7046\/_article"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,11,1]]},"references-count":44,"journal-issue":{"issue":"11","published-print":{"date-parts":[[2021]]}},"URL":"https:\/\/doi.org\/10.1587\/transinf.2021edp7046","relation":{},"ISSN":["0916-8532","1745-1361"],"issn-type":[{"type":"print","value":"0916-8532"},{"type":"electronic","value":"1745-1361"}],"subject":[],"published":{"date-parts":[[2021,11,1]]},"article-number":"2021EDP7046"}}