{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,8]],"date-time":"2026-03-08T20:42:52Z","timestamp":1773002572864,"version":"3.50.1"},"publisher-location":"California","reference-count":0,"publisher":"International Joint Conferences on Artificial Intelligence Organization","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2020,7]]},"abstract":"<jats:p>Reliably detecting attacks in a given set of inputs is of high practical relevance because of the vulnerability of neural networks to adversarial examples.\n\nThese altered inputs create a security risk in applications with real-world consequences, such as self-driving cars, robotics and financial services.\n\nWe propose an unsupervised method for detecting adversarial attacks in inner layers of autoencoder (AE) networks by maximizing a non-parametric measure of anomalous node activations. \n\nPrevious work in this space has shown AE networks can detect anomalous images by thresholding the reconstruction error produced by the final layer. Furthermore, other detection methods rely on data augmentation or specialized training techniques which must be asserted before training time. In contrast, we use subset scanning methods from the anomalous pattern detection domain to enhance detection power without labeled examples of the noise, retraining or data augmentation methods. In addition to an anomalous \u201cscore\u201d our proposed method also returns the subset of nodes within the AE network that contributed to that score. This will allow future work to pivot from detection to visualisation and explainability. Our scanning approach shows consistently higher detection power than existing detection methods across several adversarial noise models and a wide range of perturbation strengths.<\/jats:p>","DOI":"10.24963\/ijcai.2020\/122","type":"proceedings-article","created":{"date-parts":[[2020,7,8]],"date-time":"2020-07-08T12:12:10Z","timestamp":1594210330000},"page":"876-882","source":"Crossref","is-referenced-by-count":15,"title":["Detecting Adversarial Attacks via Subset Scanning of Autoencoder Activations and Reconstruction Error"],"prefix":"10.24963","author":[{"given":"Celia","family":"Cintas","sequence":"first","affiliation":[{"name":"IBM Research Africa"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Skyler","family":"Speakman","sequence":"additional","affiliation":[{"name":"IBM Research Africa"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Victor","family":"Akinwande","sequence":"additional","affiliation":[{"name":"IBM Research Africa"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"William","family":"Ogallo","sequence":"additional","affiliation":[{"name":"IBM Research Africa"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Komminist","family":"Weldemariam","sequence":"additional","affiliation":[{"name":"IBM Research Africa"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Srihari","family":"Sridharan","sequence":"additional","affiliation":[{"name":"IBM Research Africa"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Edward","family":"McFowland","sequence":"additional","affiliation":[{"name":"University of Minnesota"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"10584","event":{"name":"Twenty-Ninth International Joint Conference on Artificial Intelligence and Seventeenth Pacific Rim International Conference on Artificial Intelligence {IJCAI-PRICAI-20}","theme":"Artificial Intelligence","location":"Yokohama, Japan","acronym":"IJCAI-PRICAI-2020","number":"28","sponsor":["International Joint Conferences on Artificial Intelligence Organization (IJCAI)"],"start":{"date-parts":[[2020,7,11]]},"end":{"date-parts":[[2020,7,17]]}},"container-title":["Proceedings of the Twenty-Ninth International Joint Conference on Artificial Intelligence"],"original-title":[],"deposited":{"date-parts":[[2020,7,9]],"date-time":"2020-07-09T02:13:25Z","timestamp":1594260805000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.ijcai.org\/proceedings\/2020\/122"}},"subtitle":[],"proceedings-subject":"Artificial Intelligence Research Articles","short-title":[],"issued":{"date-parts":[[2020,7]]},"references-count":0,"URL":"https:\/\/doi.org\/10.24963\/ijcai.2020\/122","relation":{},"subject":[],"published":{"date-parts":[[2020,7]]}}}