{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,28]],"date-time":"2026-06-28T11:01:01Z","timestamp":1782644461490,"version":"3.54.5"},"reference-count":40,"publisher":"MDPI AG","issue":"11","license":[{"start":{"date-parts":[[2020,10,24]],"date-time":"2020-10-24T00:00:00Z","timestamp":1603497600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100003329","name":"Ministerio de Econom\u00eda y Competitividad","doi-asserted-by":"publisher","award":["TIN2017-82113-C2-2-R"],"award-info":[{"award-number":["TIN2017-82113-C2-2-R"]}],"id":[{"id":"10.13039\/501100003329","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100011698","name":"Junta de Comunidades de Castilla-La Mancha","doi-asserted-by":"publisher","award":["SBPLY\/17\/180501\/000543"],"award-info":[{"award-number":["SBPLY\/17\/180501\/000543"]}],"id":[{"id":"10.13039\/501100011698","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100014440","name":"Ministerio de Ciencia, Innovaci\u00f3n y Universidades","doi-asserted-by":"publisher","award":["FPU17\/04758"],"award-info":[{"award-number":["FPU17\/04758"]}],"id":[{"id":"10.13039\/100014440","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Entropy"],"abstract":"<jats:p>Adversarial examples are one of the most intriguing topics in modern deep learning. Imperceptible perturbations to the input can fool robust models. In relation to this problem, attack and defense methods are being developed almost on a daily basis. In parallel, efforts are being made to simply pointing out when an input image is an adversarial example. This can help prevent potential issues, as the failure cases are easily recognizable by humans. The proposal in this work is to study how chaos theory methods can help distinguish adversarial examples from regular images. Our work is based on the assumption that deep networks behave as chaotic systems, and adversarial examples are the main manifestation of it (in the sense that a slight input variation produces a totally different output). In our experiments, we show that the Lyapunov exponents (an established measure of chaoticity), which have been recently proposed for classification of adversarial examples, are not robust to image processing transformations that alter image entropy. Furthermore, we show that entropy can complement Lyapunov exponents in such a way that the discriminating power is significantly enhanced. The proposed method achieves 65% to 100% accuracy detecting adversarials with a wide range of attacks (for example: CW, PGD, Spatial, HopSkip) for the MNIST dataset, with similar results when entropy-changing image processing methods (such as Equalization, Speckle and Gaussian noise) are applied. This is also corroborated with two other datasets, Fashion-MNIST and CIFAR 19. These results indicate that classifiers can enhance their robustness against the adversarial phenomenon, being applied in a wide variety of conditions that potentially matches real world cases and also other threatening scenarios.<\/jats:p>","DOI":"10.3390\/e22111201","type":"journal-article","created":{"date-parts":[[2020,10,26]],"date-time":"2020-10-26T02:34:54Z","timestamp":1603679694000},"page":"1201","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":11,"title":["Approaching Adversarial Example Classification with Chaos Theory"],"prefix":"10.3390","volume":"22","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-7748-6756","authenticated-orcid":false,"given":"Anibal","family":"Pedraza","sequence":"first","affiliation":[{"name":"VISILAB, University of Castilla La Mancha, 13001 Ciudad Real, Spain"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0841-4131","authenticated-orcid":false,"given":"Oscar","family":"Deniz","sequence":"additional","affiliation":[{"name":"VISILAB, University of Castilla La Mancha, 13001 Ciudad Real, Spain"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7345-4869","authenticated-orcid":false,"given":"Gloria","family":"Bueno","sequence":"additional","affiliation":[{"name":"VISILAB, University of Castilla La Mancha, 13001 Ciudad Real, Spain"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2020,10,24]]},"reference":[{"key":"ref_1","unstructured":"Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I., and Fergus, R. (2013). Intriguing properties of neural networks. arXiv."},{"key":"ref_2","first-page":"1097","article-title":"Imagenet classification with deep convolutional neural networks","volume":"25","author":"Krizhevsky","year":"2012","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Bakator, M., and Radosav, D. (2018). Deep learning and medical diagnosis: A review of literature. Multimodal Technol. Interact., 2.","DOI":"10.3390\/mti2030047"},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Naranjo-Torres, J., Mora, M., Hern\u00e1ndez-Garc\u00eda, R., Barrientos, R.J., Fredes, C., and Valenzuela, A. (2020). A Review of Convolutional Neural Network Applied to Fruit Image Processing. Appl. Sci., 10.","DOI":"10.3390\/app10103443"},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Griffiths, D., and Boehm, J. (2019). A review on deep learning techniques for 3D sensed data classification. Remote Sens., 11.","DOI":"10.3390\/rs11121499"},{"key":"ref_6","unstructured":"Tram\u00e8r, F., Kurakin, A., Papernot, N., Goodfellow, I., Boneh, D., and McDaniel, P. (2018). Ensemble adversarial training: Attacks and defenses. arXiv."},{"key":"ref_7","unstructured":"Zhang, H., Chen, H., Xiao, C., Gowal, S., Stanforth, R., Li, B., Boning, D., and Hsieh, C.J. (2020). Towards stable and efficient training of verifiably robust neural networks. arXiv."},{"key":"ref_8","first-page":"1533","article-title":"Fast generalized subset scan for anomalous pattern detection","volume":"14","author":"McFowland","year":"2013","journal-title":"J. Mach. Learn. Res."},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"4971","DOI":"10.1103\/PhysRevA.34.4971","article-title":"Liapunov exponents from time series","volume":"34","author":"Eckmann","year":"1986","journal-title":"Phys. Rev. A"},{"key":"ref_10","unstructured":"Prabhu, V.U., Desai, N., and Whaley, J. (2017). On Lyapunov exponents and adversarial perturbation. Deep. Learn. Secur. Workshop (Singapore)."},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1038\/s42003-019-0715-9","article-title":"A simple method for detecting chaos in nature","volume":"3","author":"Toker","year":"2020","journal-title":"Commun. Biol."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"411","DOI":"10.1093\/bjps\/55.3.411","article-title":"In what sense is the Kolmogorov-Sinai entropy a measure for chaotic behaviour?\u2014bridging the gap between dynamical systems theory and communication theory","volume":"55","author":"Frigg","year":"2004","journal-title":"Br. J. Philos. Sci."},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"26","DOI":"10.1016\/j.chaos.2005.05.006","article-title":"Chaos and randomness: An equivalence proof of a generalized version of the Shannon entropy and the Kolmogorov\u2013Sinai entropy for Hamiltonian dynamical systems","volume":"28","author":"Frigg","year":"2006","journal-title":"Chaos Solitons Fractals"},{"key":"ref_14","unstructured":"Holliday, T., Glynn, P., and Goldsmith, A. (2005, January 15). Shannon Meets Lyapunov: Connections between Information Theory and Dynamical Systems. Proceedings of the 44th IEEE Conference on Decision and Control, Seville, Spain."},{"key":"ref_15","unstructured":"Li, H. (2018). Analysis on the nonlinear dynamics of deep neural networks: Topological entropy and chaos. arXiv."},{"key":"ref_16","unstructured":"Yap, D.A., Xu, J., and Prabhu, V.U. (2019, January 16\u201320). On Detecting Adversarial Inputs with entropy of Saliency Maps. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, Long Beach, CA, USA."},{"key":"ref_17","unstructured":"Yin, X., Kolouri, S., and Rohde, G.K. (2019). Divide-and-conquer adversarial detection. arXiv."},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Shumailov, I., Zhao, Y., Mullins, R., and Anderson, R. (2020). Towards certifiable adversarial sample detection. arXiv.","DOI":"10.1145\/3411508.3421381"},{"key":"ref_19","unstructured":"Vacanti, G., and Van Looveren, A. (2020). Adversarial Detection and Correction by Matching Prediction Distributions. arXiv."},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Freitas, S., Chen, S.T., Wang, Z., and Chau, D.H. (2020). Unmask: Adversarial detection and defense through robust feature alignment. arXiv.","DOI":"10.1109\/BigData50022.2020.9378303"},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Huang, B., Wang, Y., and Wang, W. (2019). Model-Agnostic Adversarial Detection by Random Perturbations. IJCAI, 4689\u20134696.","DOI":"10.24963\/ijcai.2019\/651"},{"key":"ref_22","unstructured":"Bottou, L., Cortes, C., Denker, J.S., Drucker, H., Guyon, I., Jackel, L.D., Le Cun, Y., Muller, U.A., S\u00e4ckinger, E., Simard, P., and Vapnik, V. (1994, January 9\u201313). Comparison of classifier methods: A case study in handwritten digit recognition. Proceedings of the 12th IAPR International Conference on Pattern Recognition, Conference B: Computer Vision & Image Processing, Jerusalem, Israel."},{"key":"ref_23","unstructured":"Xiao, H., Rasul, K., and Vollgraf, R. (2017). Fashion-mnist: A novel image dataset for benchmarking machine learning algorithms. arXiv."},{"key":"ref_24","unstructured":"Krizhevsky, A. (2009). Learning Multiple Layers of Features from Tiny Images, University of Toronto."},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"2278","DOI":"10.1109\/5.726791","article-title":"Gradient-based learning applied to document recognition","volume":"86","author":"LeCun","year":"1998","journal-title":"Proc. IEEE"},{"key":"ref_26","unstructured":"Wu, L., Zhu, Z., Tai, C., and Ee, W. (2018). Understanding and enhancing the transferability of adversarial examples. arXiv."},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Carlini, N., and Wagner, D. (2017, January 25). Towards evaluating the robustness of neural networks. Proceedings of the 2017 IEEE Symposium on Security and Privacy (SP), San Jose, CA, USA.","DOI":"10.1109\/SP.2017.49"},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Papernot, N., McDaniel, P., Wu, X., Jha, S., and Swami, A. (2016, January 22\u201326). Distillation as a defense to adversarial perturbations against deep neural networks. Proceedings of the 2016 IEEE Symposium on Security and Privacy, San Jose, CA, USA.","DOI":"10.1109\/SP.2016.41"},{"key":"ref_29","unstructured":"Goodfellow, I.J., Shlens, J., and Szegedy, C. (2015). Explaining and harnessing adversarial examples. Int. Conf. Learn. Represent. (ICLR)."},{"key":"ref_30","unstructured":"Madry, A., Makelov, A., Schmidt, L., Tsipras, D., and Vladu, A. (2018). Towards deep learning models resistant to adversarial attacks. arXiv."},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Papernot, N., McDaniel, P., Jha, S., Fredrikson, M., Celik, Z.B., and Swami, A. (2016, January 21\u201324). The limitations of deep learning in adversarial settings. Proceedings of the 2016 IEEE European symposium on security and privacy (EuroS&P), Saarbr\u00fccken, Germany.","DOI":"10.1109\/EuroSP.2016.36"},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Kurakin, A., Goodfellow, I., and Bengio, S. (2017). Adversarial examples in the physical world. arXiv.","DOI":"10.1201\/9781351251389-8"},{"key":"ref_33","first-page":"5866","article-title":"Adversarial training and robustness for multiple perturbations","volume":"32","author":"Boneh","year":"2019","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"ref_34","unstructured":"Moosavi-Dezfooli, S.M., Fawzi, A., and Frossard, P. (26\u20131, January 26). Deepfool: A simple and accurate method to fool deep neural networks. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, Las Vegas, NV, USA."},{"key":"ref_35","unstructured":"Miyato, T., Maeda, S.i., Koyama, M., Nakae, K., and Ishii, S. (2016). Distributional smoothing with virtual adversarial training. arXiv."},{"key":"ref_36","doi-asserted-by":"crossref","unstructured":"Chen, P.Y., Sharma, Y., Zhang, H., Yi, J., and Hsieh, C.J. (2018, January 2\u20137). Ead: Elastic-net attacks to deep neural networks via adversarial examples. Proceedings of the Thirty-Second AAAI Conference on Artificial Intelligence, New Orleans, LA, USA.","DOI":"10.1609\/aaai.v32i1.11302"},{"key":"ref_37","unstructured":"Engstrom, L., Tran, B., Tsipras, D., Schmidt, L., and Madry, A. (2019, January 9\u201315). Exploring the landscape of spatial robustness. Proceedings of the 36th International Conference on Machine Learning, Long Beach, CA, USA."},{"key":"ref_38","doi-asserted-by":"crossref","unstructured":"Chen, J., Jordan, M.I., and Wainwright, M.J. (2020, January 18\u201321). HopSkipJump Attack: A query-efficient decision-based attack. Proceedings of the 2020 IEEE Symposium on Security and Privacy (sp), San Francisco, CA, USA.","DOI":"10.1109\/SP40000.2020.00045"},{"key":"ref_39","doi-asserted-by":"crossref","first-page":"379","DOI":"10.1002\/j.1538-7305.1948.tb01338.x","article-title":"A mathematical theory of communication","volume":"27","author":"Shannon","year":"1948","journal-title":"Bell Syst. Tech. J."},{"key":"ref_40","doi-asserted-by":"crossref","first-page":"240","DOI":"10.1098\/rspl.1895.0041","article-title":"Notes on Regression and Inheritance in the Case of Two Parents","volume":"58","author":"Pearson","year":"1895","journal-title":"Proc. R. Soc. Lond."}],"container-title":["Entropy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1099-4300\/22\/11\/1201\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T10:27:35Z","timestamp":1760178455000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1099-4300\/22\/11\/1201"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,10,24]]},"references-count":40,"journal-issue":{"issue":"11","published-online":{"date-parts":[[2020,11]]}},"alternative-id":["e22111201"],"URL":"https:\/\/doi.org\/10.3390\/e22111201","relation":{},"ISSN":["1099-4300"],"issn-type":[{"value":"1099-4300","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,10,24]]}}}