{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,1,4]],"date-time":"2025-01-04T05:37:14Z","timestamp":1735969034899,"version":"3.32.0"},"reference-count":47,"publisher":"Institute of Electronics, Information and Communications Engineers (IEICE)","issue":"1","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEICE Trans. Inf. &amp; Syst."],"published-print":{"date-parts":[[2025,1,1]]},"DOI":"10.1587\/transinf.2023edp7229","type":"journal-article","created":{"date-parts":[[2024,9,4]],"date-time":"2024-09-04T22:13:36Z","timestamp":1725488016000},"page":"92-109","source":"Crossref","is-referenced-by-count":0,"title":["Deterministic and Probabilistic Certified Defenses for Content-Based Image Retrieval"],"prefix":"10.1587","volume":"E108.D","author":[{"given":"Kazuya","family":"KAKIZAKI","sequence":"first","affiliation":[{"name":"NEC Corporation"},{"name":"University of Tsukuba"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Kazuto","family":"FUKUCHI","sequence":"additional","affiliation":[{"name":"University of Tsukuba"},{"name":"RIKEN AIP"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jun","family":"SAKUMA","sequence":"additional","affiliation":[{"name":"RIKEN AIP"},{"name":"Institute of Science Tokyo"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"532","reference":[{"key":"1","doi-asserted-by":"publisher","unstructured":"[1] S.R. Dubey, \u201cA decade survey of content based image retrieval using deep learning,\u201d IEEE Trans. Circuits Syst. Video Technol., vol.32, no.5, pp.2687-2704, 2021. 10.1109\/tcsvt.2021.3080920","DOI":"10.1109\/TCSVT.2021.3080920"},{"key":"2","doi-asserted-by":"crossref","unstructured":"[2] M. Zhou, Z. Niu, L. Wang, Q. Zhang, and G. Hua, \u201cAdversarial ranking attack and defense,\u201d Computer Vision\u2014ECCV 2020: 16th European Conference, Glasgow, UK, Aug. 23-28, 2020, Proceedings, Part XIV 16, pp.781-799, Springer, 2020. 10.1007\/978-3-030-58568-6_46","DOI":"10.1007\/978-3-030-58568-6_46"},{"key":"3","unstructured":"[3] M. Zhou, L. Wang, Z. Niu, Q. Zhang, N. Zheng, and G. Hua, \u201cAdversarial attack and defense in deep ranking,\u201d arXiv preprint arXiv:2106.03614, 2021. 10.48550\/arXiv.2106.03614"},{"key":"4","doi-asserted-by":"crossref","unstructured":"[4] J. Li, R. Ji, H. Liu, X. Hong, Y. Gao, and Q. Tian, \u201cUniversal perturbation attack against image retrieval,\u201d Proc. IEEE\/CVF International Conference on Computer Vision, pp.4898-4907, 2019. 10.1109\/iccv.2019.00500","DOI":"10.1109\/ICCV.2019.00500"},{"key":"5","doi-asserted-by":"crossref","unstructured":"[5] G. Tolias, F. Radenovic, and O. Chum, \u201cTargeted mismatch adversarial attack: Query with a flower to retrieve the tower,\u201d Proc. IEEE\/CVF International Conference on Computer Vision, pp.5036-5045, 2019. 10.1109\/iccv.2019.00514","DOI":"10.1109\/ICCV.2019.00514"},{"key":"6","doi-asserted-by":"crossref","unstructured":"[6] H. Wang, G. Wang, Y. Li, D. Zhang, and L. Lin, \u201cTransferable, controllable, and inconspicuous adversarial attacks on person re-identification with deep mis-ranking,\u201d Proc. IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp.339-348, 2020. 10.1109\/cvpr42600.2020.00042","DOI":"10.1109\/CVPR42600.2020.00042"},{"key":"7","doi-asserted-by":"crossref","unstructured":"[7] M. Zhou, L. Wang, Z. Niu, Q. Zhang, Y. Xu, N. Zheng, and G. Hua, \u201cPractical relative order attack in deep ranking,\u201d Proc. IEEE\/CVF International Conference on Computer Vision, pp.16393-16402, 2021. 10.1109\/iccv48922.2021.01610","DOI":"10.1109\/ICCV48922.2021.01610"},{"key":"8","doi-asserted-by":"crossref","unstructured":"[8] X. Li, J. Li, Y. Chen, S. Ye, Y. He, S. Wang, H. Su, and H. Xue, \u201cQAIR: Practical query-efficient black-box attacks for image retrieval,\u201d Proc. IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp.3329-3338, 2021. 10.1109\/cvpr46437.2021.00334","DOI":"10.1109\/CVPR46437.2021.00334"},{"key":"9","doi-asserted-by":"crossref","unstructured":"[9] Z. Wang, S. Zheng, M. Song, Q. Wang, A. Rahimpour, and H. Qi, \u201cadvPattern: Physical-world attacks on deep person re-identification via adversarially transformable patterns,\u201d Proc. IEEE\/CVF International Conference on Computer Vision, pp.8340-8349, 2019. 10.1109\/iccv.2019.00843","DOI":"10.1109\/ICCV.2019.00843"},{"key":"10","doi-asserted-by":"publisher","unstructured":"[10] S. Bai, Y. Li, Y. Zhou, Q. Li, and P.H.S. Torr, \u201cAdversarial metric attack and defense for person re-identification,\u201d IEEE Trans. Pattern Anal. Mach. Intell., vol.43, no.6, pp.2119-2126, 2020. 10.1109\/tpami.2020.3031625","DOI":"10.1109\/TPAMI.2020.3031625"},{"key":"11","doi-asserted-by":"publisher","unstructured":"[11] M. Ye, J. Shen, G. Lin, T. Xiang, L. Shao, and S.C.H. Hoi, \u201cDeep learning for person re-identification: A survey and outlook,\u201d IEEE Trans. Pattern Anal. Machine Intell., vol.44, no.6, pp.2872-2893, 2021. 10.1109\/tpami.2021.3054775","DOI":"10.1109\/TPAMI.2021.3054775"},{"key":"12","unstructured":"[12] A. Madry, A. Makelov, L. Schmidt, D. Tsipras, and A. Vladu, \u201cTowards deep learning models resistant to adversarial attacks,\u201d International Conference on Learning Representations, 2018."},{"key":"13","unstructured":"[13] F. Tramer, N. Carlini, W. Brendel, and A. Madry, \u201cOn adaptive attacks to adversarial example defenses,\u201d Advances in Neural Information Processing Systems, vol.33, pp.1633-1645, 2020."},{"key":"14","unstructured":"[14] L. Li, X. Qi, T. Xie, and B. Li, \u201cSoK: Certified robustness for deep neural networks,\u201d arXiv preprint arXiv:2009.04131, 2020. 10.48550\/arXiv.2009.04131"},{"key":"15","doi-asserted-by":"crossref","unstructured":"[15] G. Katz, C. Barrett, D.L. Dill, K. Julian, and M.J. Kochenderfer, \u201cReluplex: An efficient SMT solver for verifying deep neural networks,\u201d International Conference on Computer Aided Verification, pp.97-117, Springer, 2017. 10.1007\/978-3-319-63387-9_5","DOI":"10.1007\/978-3-319-63387-9_5"},{"key":"16","unstructured":"[16] L. Weng, H. Zhang, H. Chen, Z. Song, C.J. Hsieh, L. Daniel, D. Boning, and I. Dhillon, \u201cTowards fast computation of certified robustness for ReLU networks,\u201d International Conference on Machine Learning, pp.5276-5285, PMLR, 2018."},{"key":"17","unstructured":"[17] H. Zhang, T.W. Weng, P.Y. Chen, C.J. Hsieh, and L. Daniel, \u201cEfficient neural network robustness certification with general activation functions,\u201d Advances in Neural Information Processing Systems, vol.31, 2018."},{"key":"18","doi-asserted-by":"publisher","unstructured":"[18] G. Singh, T. Gehr, M. P\u00fcschel, and M. Vechev, \u201cAn abstract domain for certifying neural networks,\u201d Proc. ACM on Programming Languages, vol.3, no.POPL, Article No.41, pp.1-30, 2019. 10.1145\/3290354","DOI":"10.1145\/3290354"},{"key":"19","unstructured":"[19] Y. Tsuzuku, I. Sato, and M. Sugiyama, \u201cLipschitz-margin training: Scalable certification of perturbation invariance for deep neural networks,\u201d Advances in Neural Information Processing Systems, vol.31, 2018."},{"key":"20","unstructured":"[20] S. Gowal, K. Dvijotham, R. Stanforth, R. Bunel, C. Qin, J. Uesato, R. Arandjelovic, T. Mann, and P. Kohli, \u201cOn the effectiveness of interval bound propagation for training verifiably robust models,\u201d arXiv preprint arXiv:1810.12715, 2018. 10.48550\/arXiv.1810.12715"},{"key":"21","doi-asserted-by":"crossref","unstructured":"[21] S. Gowal, K. Dvijotham, R. Stanforth, R. Bunel, C. Qin, J. Uesato, R. Arandjelovic, T.A. Mann, and P. Kohli, \u201cScalable verified training for provably robust image classification,\u201d Proc. IEEE\/CVF International Conference on Computer Vision, pp.4841-4850, 2019. 10.1109\/iccv.2019.00494","DOI":"10.1109\/ICCV.2019.00494"},{"key":"22","unstructured":"[22] J. Cohen, E. Rosenfeld, and Z. Kolter, \u201cCertified adversarial robustness via randomized smoothing,\u201d International Conference on Machine Learning, pp.1310-1320, PMLR, 2019."},{"key":"23","unstructured":"[23] K. Leino, Z. Wang, and M. Fredrikson, \u201cGlobally-robust neural networks,\u201d International Conference on Machine Learning, pp.6212-6222, PMLR, 2021."},{"key":"24","unstructured":"[24] H. Salman, J. Li, I. Razenshteyn, P. Zhang, H. Zhang, S. Bubeck, and G. Yang, \u201cProvably robust deep learning via adversarially trained smoothed classifiers,\u201d Advances in Neural Information Processing Systems, vol.32, 2019."},{"key":"25","doi-asserted-by":"crossref","unstructured":"[25] M. Lecuyer, V. Atlidakis, R. Geambasu, D. Hsu, and S. Jana, \u201cCertified robustness to adversarial examples with differential privacy,\u201d 2019 IEEE Symposium on Security and Privacy (SP), pp.656-672, IEEE, 2019. 10.1109\/sp.2019.00044","DOI":"10.1109\/SP.2019.00044"},{"key":"26","unstructured":"[26] Y. Wu, H. Zhang, and H. Huang, \u201cRetrievalguard: Provably robust 1-nearest neighbor image retrieval,\u201d International Conference on Machine Learning, pp.24266-24279, PMLR, 2022."},{"key":"27","doi-asserted-by":"crossref","unstructured":"[27] Y. LeCun, L. Bottou, Y. Bengio, and P. Haffner, \u201cGradient-based learning applied to document recognition,\u201d Proc. IEEE, vol.86, no.11, pp.2278-2324, 1998. 10.1109\/5.726791","DOI":"10.1109\/5.726791"},{"key":"28","unstructured":"[28] H. Xiao, K. Rasul, and R. Vollgraf, \u201cFashion-MNIST: A novel image dataset for benchmarking machine learning algorithms,\u201d arXiv preprint arXiv:1708.07747, 2017. 10.48550\/arXiv.1708.07747"},{"key":"29","unstructured":"[29] A. Krizhevsky, G. Hinton, et al., \u201cLearning multiple layers of features from tiny images,\u201d Technical report, 2009."},{"key":"30","unstructured":"[30] C. Wah, S. Branson, P. Welinder, P. Perona, and S. Belongie, \u201cThe caltech-UCSD birds-200-2011 dataset,\u201d California Institute of Technology, 2011."},{"key":"31","doi-asserted-by":"crossref","unstructured":"[31] K. Kakizaki, K. Fukuchi, and J. Sakuma, \u201cCertified defense for content based image retrieval,\u201d Proc. IEEE\/CVF Winter Conference on Applications of Computer Vision (WACV), pp.4550-4559, Jan. 2023. 10.1109\/wacv56688.2023.00454","DOI":"10.1109\/WACV56688.2023.00454"},{"key":"32","unstructured":"[32] I.J. Goodfellow, J. Shlens, and C. Szegedy, \u201cExplaining and harnessing adversarial examples,\u201d arXiv preprint arXiv:1412.6572, 2014. 10.48550\/arXiv.1412.6572"},{"key":"33","doi-asserted-by":"crossref","unstructured":"[33] J. Deng, W. Dong, R. Socher, L.-J. Li, K. Li, and L. Fei-Fei, \u201cImageNet: A large-scale hierarchical image database,\u201d 2009 IEEE Conference on Computer Vision and Pattern Recognition, pp.248-255, IEEE, 2009. 10.1109\/cvprw.2009.5206848","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"34","unstructured":"[34] H. Zhang, H. Chen, C. Xiao, S. Gowal, R. Stanforth, B. Li, D. Boning, and C.J. Hsieh, \u201cTowards stable and efficient training of verifiably robust neural networks,\u201d International Conference on Learning Representations, 2019."},{"key":"35","doi-asserted-by":"crossref","unstructured":"[35] F. Schroff, D. Kalenichenko, and J. Philbin, \u201cFaceNet: A unified embedding for face recognition and clustering,\u201d Proc. IEEE Conference on Computer Vision and Pattern Recognition, pp.815-823, 2015. 10.1109\/cvpr.2015.7298682","DOI":"10.1109\/CVPR.2015.7298682"},{"key":"36","unstructured":"[36] A. Levine, S. Singla, and S. Feizi, \u201cCertifiably robust interpretation in deep learning,\u201d arXiv preprint arXiv:1905.12105, 2019. 10.48550\/arXiv.1905.12105"},{"key":"37","doi-asserted-by":"crossref","unstructured":"[37] W. Hoeffding, \u201cProbability inequalities for sums of bounded random variables,\u201d Journal of the American Statistical Association, vol.58, no.301, pp.13-30, 1963. 10.2307\/2282952","DOI":"10.1080\/01621459.1963.10500830"},{"key":"38","unstructured":"[38] E. Ramzi, N. Thome, C. Rambour, N. Audebert, and X. Bitot, \u201cRobust and decomposable average precision for image retrieval,\u201d Advances in Neural Information Processing Systems, vol.34, 2021."},{"key":"39","doi-asserted-by":"crossref","unstructured":"[39] J. Wang, F. Zhou, S. Wen, X. Liu, and Y. Lin, \u201cDeep metric learning with angular loss,\u201d Proc. IEEE International Conference on Computer Vision, pp.2612-2620, 2017. 10.1109\/iccv.2017.283","DOI":"10.1109\/ICCV.2017.283"},{"key":"40","unstructured":"[40] D.P. Kingma and J. Ba, \u201cAdam: A method for stochastic optimization,\u201d arXiv preprint arXiv:1412.6980, 2014. 10.48550\/arXiv.1412.6980"},{"key":"41","unstructured":"[41] K. Simonyan and A. Zisserman, \u201cVery deep convolutional networks for large-scale image recognition,\u201d arXiv preprint arXiv:1409.1556, 2014. 10.48550\/arXiv.1409.1556"},{"key":"42","doi-asserted-by":"crossref","unstructured":"[42] J. Krause, M. Stark, J. Deng, and L. Fei-Fei, \u201c3D object representations for fine-grained categorization,\u201d 2013 IEEE International Conference on Computer Vision Workshops, Sydney, Australia, pp.554-561, 2013. 10.1109\/iccvw.2013.77","DOI":"10.1109\/ICCVW.2013.77"},{"key":"43","doi-asserted-by":"crossref","unstructured":"[43] H.O. Song, Y. Xiang, S. Jegelka, and S. Savarese, \u201cDeep metric learning via lifted structured feature embedding,\u201d Proc. IEEE Conference on Computer Vision and Pattern Recognition, pp.4004-4012, 2016. 10.1109\/cvpr.2016.434","DOI":"10.1109\/CVPR.2016.434"},{"key":"44","doi-asserted-by":"crossref","unstructured":"[44] K. He, X. Zhang, S. Ren, and J. Sun, \u201cDeep residual learning for image recognition,\u201d Proc. IEEE Conference on Computer Vision and Pattern Recognition, pp.770-778, 2016. 10.1109\/cvpr.2016.90","DOI":"10.1109\/CVPR.2016.90"},{"key":"45","unstructured":"[45] A. Paszke, S. Gross, F. Massa, A. Lerer, J. Bradbury, G. Chanan, T. Killeen, Z. Lin, N. Gimelshein, L. Antiga, A. Desmaison, A. Kopf, E. Yang, Z. DeVito, M. Raison, A. Tejani, S. Chilamkurthy, B. Steiner, L. Fang, J. Bai, and S. Chintala, \u201cPyTorch: An imperative style, high-performance deep learning library,\u201d Advances in Neural Information Processing Systems, vol.32, 2019."},{"key":"46","unstructured":"[46] K. Roth, T. Milbich, S. Sinha, P. Gupta, B. Ommer, and J.P. Cohen, \u201cRevisiting training strategies and generalization performance in deep metric learning,\u201d International Conference on Machine Learning, pp.8242-8252, PMLR, 2020."},{"key":"47","unstructured":"[47] L. Li, J. Zhang, T. Xie, and B. Li, \u201cDouble sampling randomized smoothing,\u201d International Conference on Machine Learning, pp.13163-13208, PMLR, 2022."}],"container-title":["IEICE Transactions on Information and Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.jstage.jst.go.jp\/article\/transinf\/E108.D\/1\/E108.D_2023EDP7229\/_pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,1,4]],"date-time":"2025-01-04T03:19:34Z","timestamp":1735960774000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.jstage.jst.go.jp\/article\/transinf\/E108.D\/1\/E108.D_2023EDP7229\/_article"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,1,1]]},"references-count":47,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2025]]}},"URL":"https:\/\/doi.org\/10.1587\/transinf.2023edp7229","relation":{},"ISSN":["0916-8532","1745-1361"],"issn-type":[{"type":"print","value":"0916-8532"},{"type":"electronic","value":"1745-1361"}],"subject":[],"published":{"date-parts":[[2025,1,1]]},"article-number":"2023EDP7229"}}