{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,9,29]],"date-time":"2024-09-29T04:04:19Z","timestamp":1727582659072},"reference-count":38,"publisher":"Institute of Electronics, Information and Communications Engineers (IEICE)","issue":"7","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEICE Trans. Inf. &amp; Syst."],"published-print":{"date-parts":[[2022,7,1]]},"DOI":"10.1587\/transinf.2021edp7239","type":"journal-article","created":{"date-parts":[[2022,6,30]],"date-time":"2022-06-30T22:18:31Z","timestamp":1656627511000},"page":"1308-1319","source":"Crossref","is-referenced-by-count":0,"title":["A Hybrid Bayesian-Convolutional Neural Network for Adversarial Robustness"],"prefix":"10.1587","volume":"E105.D","author":[{"given":"Thi Thu Thao","family":"KHONG","sequence":"first","affiliation":[{"name":"Nara Institute of Science and Technology"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Takashi","family":"NAKADA","sequence":"additional","affiliation":[{"name":"International Professional University of Technology in Osaka"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yasuhiko","family":"NAKASHIMA","sequence":"additional","affiliation":[{"name":"Nara Institute of Science and Technology"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"532","reference":[{"key":"1","unstructured":"[1] C. Chio and D. Freeman, Machine learning and security: Protecting systems with data and algorithms, O&apos;Reilly Media, Inc., 2018."},{"key":"2","unstructured":"[2] C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, and R. Fergus, \u201cIntriguing properties of neural networks,\u201d 2nd International Conference on Learning Representations-ICLR 2014, arXiv:1312.6199, pp.1-10, 2013."},{"key":"3","unstructured":"[3] I.J. Goodfellow, J. Shlens, and C. Szegedy, \u201cExplaining and harnessing adversarial examples,\u201d 3rd International Conference on Learning Representations-ICLR 2015, arXiv:1412.6572, pp.1-11, 2014."},{"key":"4","unstructured":"[4] A. Madry, A. Makelov, L. Schmidt, D. Tsipras, and A. Vladu, \u201cTowards deep learning models resistant to adversarial attacks,\u201d 6th International Conference on Learning Representations-ICLR 2018, arXiv:1706.06083, pp.1-28, 2017."},{"key":"5","doi-asserted-by":"crossref","unstructured":"[5] N. Carlini and D. Wagner, \u201cTowards evaluating the robustness of neural networks,\u201d 2017 ieee symposium on security and privacy (sp), pp.39-57, IEEE, 2017. 10.1109\/SP.2017.49","DOI":"10.1109\/SP.2017.49"},{"key":"6","doi-asserted-by":"crossref","unstructured":"[6] X. Liu, M. Cheng, H. Zhang, and C.-J. Hsieh, \u201cTowards robust neural networks via random self-ensemble,\u201d Proceedings of the European Conference on Computer Vision (ECCV), pp.369-385, 2018. 10.1007\/978-3-030-01234-2_23","DOI":"10.1007\/978-3-030-01234-2_23"},{"key":"7","unstructured":"[7] G.S. Dhillon, K. Azizzadenesheli, Z.C. Lipton, J. Bernstein, J. Kossaifi, A. Khanna, and A. Anandkumar, \u201cStochastic activation pruning for robust adversarial defense,\u201d ICLR 2018, arXiv:1803.01442, pp.1-13, 2018."},{"key":"8","unstructured":"[8] X. Liu, Y. Li, C. Wu, and C.J. Hsieh, \u201cAdv-bnn: Improved adversarial defense through robust bayesian neural network,\u201d ICLR 2019, arXiv:1810.01279, pp.1-13, 2018."},{"key":"9","unstructured":"[9] N. Ye and Z. Zhu, \u201cBayesian adversarial learning,\u201d Proceedings of the 32nd international conference on neural information processing systems, pp.6892-6901, 2018."},{"key":"10","doi-asserted-by":"crossref","unstructured":"[10] T.T.T. Khong, T. Nakada, and Y. Nakashima, \u201cBayes without bayesian learning for resisting adversarial attacks,\u201d 2020 Eighth International Symposium on Computing and Networking (CANDAR), pp.221-227, IEEE, 2020. 10.1109\/CANDAR51075.2020.00038","DOI":"10.1109\/CANDAR51075.2020.00038"},{"key":"11","doi-asserted-by":"publisher","unstructured":"[11] T.T.T. Khong, T. Nakada, and Y. Nakashima, \u201cFlexible bayesian inference by weight transfer for robust deep neural networks,\u201d IEICE Transactions on Information and Systems, vol.E104-D, no.11, pp.1981-1991, 2021. 10.1587\/transinf.2021EDP7046","DOI":"10.1587\/transinf.2021EDP7046"},{"key":"12","unstructured":"[12] D.J. MacKay, \u201cBayesian methods for neural networks: Theory and application,\u201d Neural Networks Summer School, University of Cambridge, pp.1-43, 1995."},{"key":"13","unstructured":"[13] R.M. Neal, Bayesian learning for neural networks, Springer Science &amp; Business Media, 2012."},{"key":"14","unstructured":"[14] D. Barber and C.M. Bishop, \u201cEnsemble learning in bayesian neural networks,\u201d Nato ASI Series F Computer and Systems Sciences, vol.168, pp.215-238, 1998."},{"key":"15","unstructured":"[15] C. Blundell, J. Cornebise, K. Kavukcuoglu, and D. Wierstra, \u201cWeight uncertainty in neural network,\u201d International Conference on Machine Learning, pp.1613-1622, PMLR, 2015."},{"key":"16","unstructured":"[16] A. Kurakin, I. Goodfellow, and S. Bengio, \u201cAdversarial examples in the physical world,\u201d ICLR Workshop 2017, arXiv 1607.02533, pp.1-14, 2017."},{"key":"17","doi-asserted-by":"crossref","unstructured":"[17] N. Papernot, P. McDaniel, S. Jha, M. Fredrikson, Z.B. Celik, and A. Swami, \u201cThe limitations of deep learning in adversarial settings,\u201d 2016 IEEE European symposium on security and privacy (EuroS&amp;P), pp.372-387, IEEE, 2016. 10.1109\/EuroSP.2016.36","DOI":"10.1109\/EuroSP.2016.36"},{"key":"18","doi-asserted-by":"crossref","unstructured":"[18] S.-M. Moosavi-Dezfooli, A. Fawzi, and P. Frossard, \u201cDeepfool: a simple and accurate method to fool deep neural networks,\u201d Proceedings of the IEEE conference on computer vision and pattern recognition, pp.2574-2582, 2016. 10.1109\/CVPR.2016.282","DOI":"10.1109\/CVPR.2016.282"},{"key":"19","unstructured":"[19] V. Nair and G.E. Hinton, \u201cRectified linear units improve restricted boltzmann machines,\u201d Icml, pp.1-8, 2010."},{"key":"20","unstructured":"[20] C. Xie, M. Tan, B. Gong, A. Yuille, and Q.V. Le, \u201cSmooth adversarial training,\u201d arXiv preprint arXiv:2006.14536, pp.1-11, 2020."},{"key":"21","doi-asserted-by":"publisher","unstructured":"[21] M. Tavakoli, F. Agostinelli, and P. Baldi, \u201cSplash: Learnable activation functions for improving accuracy and adversarial robustness,\u201d Neural Networks, vol.140, pp.1-12, 2021. 10.1016\/j.neunet.2021.02.023","DOI":"10.1016\/j.neunet.2021.02.023"},{"key":"22","unstructured":"[22] H. Zhang, T.W. Weng, P.Y. Chen, C.J. Hsieh, and L. Daniel, \u201cEfficient neural network robustness certification with general activation functions,\u201d 32nd Conference on Neural Information Processing Systems (NIPS 2018), arXiv:1811.00866, pp.1-17, 2018."},{"key":"23","unstructured":"[23] A. Rozsa and T.E. Boult, \u201cImproved adversarial robustness by reducing open space risk via tent activations,\u201d arXiv preprint arXiv:1908.02435, pp.1-15, 2019."},{"key":"24","unstructured":"[24] B. Wang, A.T. Lin, W. Zhu, P. Yin, A.L. Bertozzi, and S.J. Osher, \u201cAdversarial defense via data dependent activation function and total variation minimization,\u201d arXiv preprint arXiv:1809.08516, pp.1-17, 2018."},{"key":"25","unstructured":"[25] A.S. Rakin, J. Yi, B. Gong, and D. Fan, \u201cDefend deep neural networks against adversarial examples via fixed and dynamic quantized activation functions,\u201d arXiv preprint arXiv:1807.06714, pp.1-15, 2018."},{"key":"26","unstructured":"[26] A. Shafahi, M. Najibi, A. Ghiasi, Z. Xu, J. Dickerson, C. Studer, L.S. Davis, G. Taylor, and T. Goldstein, \u201cAdversarial training for free!,\u201d 33rd Conference on Neural Information Processing Systems (NeurIPS 2019), arXiv:1904.12843, pp.1-12, 2019."},{"key":"27","unstructured":"[27] E. Wong, L. Rice, and J.Z. Kolter, \u201cFast is better than free: Revisiting adversarial training,\u201d ICLR 2020, arXiv:2001.03994, pp.1-17, 2020."},{"key":"28","unstructured":"[28] S. Wang and C. Manning, \u201cFast dropout training,\u201d international conference on machine learning, PMLR, pp.118-126, 2013."},{"key":"29","unstructured":"[29] D.P. Kingma, T. Salimans, and M. Welling, \u201cVariational dropout and the local reparameterization trick,\u201d Advances in neural information processing systems, vol.28, pp.2575-2583, 2015."},{"key":"30","unstructured":"[30] F. Tram\u00e8r, A. Kurakin, N. Papernot, I. Goodfellow, D. Boneh, and P. McDaniel, \u201cEnsemble adversarial training: Attacks and defenses,\u201d ICLR 2018, arXiv:1705.07204, pp.1-22, 2017."},{"key":"31","doi-asserted-by":"crossref","unstructured":"[31] K. He, X. Zhang, S. Ren, and J. Sun, \u201cDeep residual learning for image recognition,\u201d Proceedings of the IEEE conference on computer vision and pattern recognition, pp.770-778, 2016. 10.1109\/CVPR.2016.90","DOI":"10.1109\/CVPR.2016.90"},{"key":"32","unstructured":"[32] [Online], \u201cTorchvision.models.\u201d Available: https:\/\/pytorch.org\/vision\/stable\/models.html"},{"key":"33","doi-asserted-by":"crossref","unstructured":"[33] J. Deng, W. Dong, R. Socher, L.J. Li, K. Li, and L. Fei-Fei, \u201cImagenet: A large-scale hierarchical image database,\u201d 2009 IEEE conference on computer vision and pattern recognition, pp.248-255, Ieee, 2009. 10.1109\/CVPR.2009.5206848","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"34","doi-asserted-by":"crossref","unstructured":"[34] S. Xie, R. Girshick, P. Doll\u00e1r, Z. Tu, and K. He, \u201cAggregated residual transformations for deep neural networks,\u201d Proceedings of the IEEE conference on computer vision and pattern recognition, pp.1492-1500, 2017. 10.1109\/CVPR.2017.634","DOI":"10.1109\/CVPR.2017.634"},{"key":"35","unstructured":"[35] M. Tan and Q. Le, \u201cEfficientnet: Rethinking model scaling for convolutional neural networks,\u201d International Conference on Machine Learning, pp.6105-6114, PMLR, 2019."},{"key":"36","unstructured":"[36] [Online], \u201cEfficientnet.\u201d Available: https:\/\/github.com\/lukemelas\/EfficientNet-PyTorch"},{"key":"37","doi-asserted-by":"crossref","unstructured":"[37] C. Xie, M. Tan, B. Gong, J. Wang, A.L. Yuille, and Q.V. Le, \u201cAdversarial examples improve image recognition,\u201d Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp.819-828, 2020. 10.1109\/CVPR42600.2020.00090","DOI":"10.1109\/CVPR42600.2020.00090"},{"key":"38","unstructured":"[38] P. Ramachandran, B. Zoph, and Q.V. Le, \u201cSearching for activation functions,\u201d arXiv preprint arXiv:1710.05941, pp.1-13, 2017."}],"container-title":["IEICE Transactions on Information and Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.jstage.jst.go.jp\/article\/transinf\/E105.D\/7\/E105.D_2021EDP7239\/_pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,9,28]],"date-time":"2024-09-28T06:20:52Z","timestamp":1727504452000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.jstage.jst.go.jp\/article\/transinf\/E105.D\/7\/E105.D_2021EDP7239\/_article"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,7,1]]},"references-count":38,"journal-issue":{"issue":"7","published-print":{"date-parts":[[2022]]}},"URL":"https:\/\/doi.org\/10.1587\/transinf.2021edp7239","relation":{},"ISSN":["0916-8532","1745-1361"],"issn-type":[{"type":"print","value":"0916-8532"},{"type":"electronic","value":"1745-1361"}],"subject":[],"published":{"date-parts":[[2022,7,1]]},"article-number":"2021EDP7239"}}