{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,8]],"date-time":"2026-02-08T08:58:29Z","timestamp":1770541109928,"version":"3.49.0"},"reference-count":68,"publisher":"MDPI AG","issue":"12","license":[{"start":{"date-parts":[[2022,12,9]],"date-time":"2022-12-09T00:00:00Z","timestamp":1670544000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["J. Imaging"],"abstract":"<jats:p>Automatic Speech Recognition (ASR) systems are ubiquitous in various commercial applications. These systems typically rely on machine learning techniques for transcribing voice commands into text for further processing. Despite their success in many applications, audio Adversarial Examples (AEs) have emerged as a major security threat to ASR systems. This is because audio AEs are able to fool ASR models into producing incorrect results. While researchers have investigated methods for defending against audio AEs, the intrinsic properties of AEs and benign audio are not well studied. The work in this paper shows that the machine learning decision boundary patterns around audio AEs and benign audio are fundamentally different. Using dimensionality-reduction techniques, this work shows that these different patterns can be visually distinguished in two-dimensional (2D) space. This in turn allows for the detection of audio AEs using anomal- detection methods.<\/jats:p>","DOI":"10.3390\/jimaging8120324","type":"journal-article","created":{"date-parts":[[2022,12,9]],"date-time":"2022-12-09T04:46:46Z","timestamp":1670561206000},"page":"324","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["Detecting Audio Adversarial Examples in Automatic Speech Recognition Systems Using Decision Boundary Patterns"],"prefix":"10.3390","volume":"8","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-9714-6759","authenticated-orcid":false,"given":"Wei","family":"Zong","sequence":"first","affiliation":[{"name":"Institute of Cybersecurity and Cryptology, School of Computing and Information Technology, University of Wollongong, Wollongong, NSW 2522, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3348-7014","authenticated-orcid":false,"given":"Yang-Wai","family":"Chow","sequence":"additional","affiliation":[{"name":"Institute of Cybersecurity and Cryptology, School of Computing and Information Technology, University of Wollongong, Wollongong, NSW 2522, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1562-5105","authenticated-orcid":false,"given":"Willy","family":"Susilo","sequence":"additional","affiliation":[{"name":"Institute of Cybersecurity and Cryptology, School of Computing and Information Technology, University of Wollongong, Wollongong, NSW 2522, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5755-108X","authenticated-orcid":false,"given":"Jongkil","family":"Kim","sequence":"additional","affiliation":[{"name":"Department of Cyber Security, Ewha Womans University, Seoul 03760, Republic of Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0019-0345","authenticated-orcid":false,"given":"Ngoc Thuy","family":"Le","sequence":"additional","affiliation":[{"name":"Institute of Cybersecurity and Cryptology, School of Computing and Information Technology, University of Wollongong, Wollongong, NSW 2522, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2022,12,9]]},"reference":[{"key":"ref_1","unstructured":"Hannun, A., Case, C., Casper, J., Catanzaro, B., Diamos, G., Elsen, E., Prenger, R., Satheesh, S., Sengupta, S., and Coates, A. (2014). Deep speech: Scaling up end-to-end speech recognition. arXiv."},{"key":"ref_2","unstructured":"Amodei, D., Ananthanarayanan, S., Anubhai, R., Bai, J., Battenberg, E., Case, C., Casper, J., Catanzaro, B., Cheng, Q., and Chen, G. (2016, January 20\u201322). Deep speech 2: End-to-end speech recognition in english and mandarin. Proceedings of the International Conference on Machine Learning, New York, NY, USA."},{"key":"ref_3","unstructured":"Shen, J., Nguyen, P., Wu, Y., Chen, Z., Chen, M.X., Jia, Y., Kannan, A., Sainath, T.N., Cao, Y., and Chiu, C. (2019). Lingvo: A Modular and Scalable Framework for Sequence-to-Sequence Modeling. arXiv."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"317","DOI":"10.1016\/j.patcog.2018.07.023","article-title":"Wild patterns: Ten years after the rise of adversarial machine learning","volume":"84","author":"Biggio","year":"2018","journal-title":"Pattern Recognit."},{"key":"ref_5","unstructured":"Bengio, Y., and Le Cun, Y. (2014, January 14\u201316). Intriguing properties of neural networks. Proceedings of the 2nd International Conference on Learning Representations, ICLR 2014, Banff, AB, Canada. Conference Track Proceedings."},{"key":"ref_6","unstructured":"Palmer, M., Hwa, R., and Riedel, S. (2017, January 9\u201311). Adversarial Examples for Evaluating Reading Comprehension Systems. Proceedings of the 2017 Conference on Empirical Methods in Natural Language Processing, EMNLP 2017, Copenhagen, Denmark."},{"key":"ref_7","unstructured":"Zhang, H., Zhou, H., Miao, N., and Li, L. (August, January 28). Generating fluent adversarial examples for natural languages. Proceedings of the 57th Annual Meeting of the Association for Computational Linguistics, Florence, Italy."},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Ebrahimi, J., Rao, A., Lowd, D., and Dou, D. (2017). Hotflip: White-box adversarial examples for text classification. arXiv.","DOI":"10.18653\/v1\/P18-2006"},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Carlini, N., and Wagner, D. (2018, January 24). Audio adversarial examples: Targeted attacks on speech-to-text. Proceedings of the 2018 IEEE Security and Privacy Workshops (SPW), San Francisco, CA, USA.","DOI":"10.1109\/SPW.2018.00009"},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Sch\u00f6nherr, L., Kohls, K., Zeiler, S., Holz, T., and Kolossa, D. (2019, January 24\u201327). Adversarial Attacks Against Automatic Speech Recognition Systems via Psychoacoustic Hiding. Proceedings of the 26th Annual Network and Distributed System Security Symposium, NDSS 2019, San Diego, CA, USA.","DOI":"10.14722\/ndss.2019.23288"},{"key":"ref_11","unstructured":"Alzantot, M., Balaji, B., and Srivastava, M.B. (2018). Did you hear that? Adversarial Examples Against Automatic Speech Recognition. arXiv."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3510582","article-title":"Sok: A modularized approach to study the security of automatic speech recognition systems","volume":"25","author":"Chen","year":"2022","journal-title":"ACM Trans. Priv. Secur."},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"102495","DOI":"10.1016\/j.cose.2021.102495","article-title":"On the human evaluation of universal audio adversarial perturbations","volume":"112","author":"Vadillo","year":"2022","journal-title":"Comput. Secur."},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"23532","DOI":"10.1109\/ACCESS.2022.3152526","article-title":"Black-Box Audio Adversarial Attack Using Particle Swarm Optimization","volume":"10","author":"Mun","year":"2022","journal-title":"IEEE Access"},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Xie, Y., Shi, C., Li, Z., Liu, J., Chen, Y., and Yuan, B. (2020, January 4\u20138). Real-time, universal, and robust adversarial attacks against speaker recognition systems. Proceedings of the ICASSP 2020\u20142020 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP), Barcelona, Spain.","DOI":"10.1109\/ICASSP40776.2020.9053747"},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Wang, Q., Guo, P., and Xie, L. (2020). Inaudible Adversarial Perturbations for Targeted Attack in Speaker Recognition. arXiv.","DOI":"10.21437\/Interspeech.2020-1955"},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Chen, G., Zhao, Z., Song, F., Chen, S., Fan, L., Wang, F., and Wang, J. (2022). Towards Understanding and Mitigating Audio Adversarial Examples for Speaker Recognition. arXiv.","DOI":"10.1109\/TDSC.2022.3220673"},{"key":"ref_18","unstructured":"Tsipras, D., Santurkar, S., Engstrom, L., Turner, A., and Madry, A. (2019, January 6\u20139). Robustness May Be at Odds with Accuracy. Proceedings of the 7th International Conference on Learning Representations, ICLR 2019, New Orleans, LA, USA. Available online: OpenReview.net."},{"key":"ref_19","first-page":"125","article-title":"Adversarial examples are not bugs, they are features","volume":"32","author":"Ilyas","year":"2019","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Zhang, C., Benz, P., Imtiaz, T., and Kweon, I.S. (2020, January 13\u201319). Understanding Adversarial Examples From the Mutual Influence of Images and Perturbations. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, Seattle, WA, USA.","DOI":"10.1109\/CVPR42600.2020.01453"},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Papernot, N., McDaniel, P., Wu, X., Jha, S., and Swami, A. (2016, January 22\u201326). Distillation as a defense to adversarial perturbations against deep neural networks. Proceedings of the 2016 IEEE Symposium on Security and Privacy (SP), San Jose, CA, USA.","DOI":"10.1109\/SP.2016.41"},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Xu, W., Evans, D., and Qi, Y. (2018, January 18\u201321). Feature Squeezing: Detecting Adversarial Examples in Deep Neural Networks. Proceedings of the 25th Annual Network and Distributed System Security Symposium, NDSS 2018, San Diego, CA, USA.","DOI":"10.14722\/ndss.2018.23198"},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Cohen, G., Sapiro, G., and Giryes, R. (2020, January 13\u201319). Detecting adversarial samples using influence functions and nearest neighbors. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, Seattle, WA, USA.","DOI":"10.1109\/CVPR42600.2020.01446"},{"key":"ref_24","unstructured":"Ma, X., Li, B., Wang, Y., Erfani, S.M., Wijewickrema, S., Schoenebeck, G., Song, D., Houle, M.E., and Bailey, J. (2018). Characterizing adversarial subspaces using local intrinsic dimensionality. arXiv."},{"key":"ref_25","unstructured":"Bengio, Y., and LeCun, Y. (2015, January 7\u20139). Explaining and Harnessing Adversarial Examples. Proceedings of the 3rd International Conference on Learning Representations, ICLR 2015, San Diego, CA, USA. Conference Track Proceedings."},{"key":"ref_26","unstructured":"Zhang, H., Chen, H., Song, Z., Boning, D.S., Dhillon, I.S., and Hsieh, C. (2019, January 6\u20139). The Limitations of Adversarial Training and the Blind-Spot Attack. Proceedings of the 7th International Conference on Learning Representations, ICLR 2019, New Orleans, LA, USA. Available online: OpenReview.net."},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Zeng, Q., Su, J., Fu, C., Kayas, G., Luo, L., Du, X., Tan, C.C., and Wu, J. (2019, January 24\u201327). A multiversion programming inspired approach to detecting audio adversarial examples. Proceedings of the 2019 49th Annual IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN), Portland, OR, USA.","DOI":"10.1109\/DSN.2019.00019"},{"key":"ref_28","unstructured":"Yang, Z., Li, B., Chen, P., and Song, D. (2019, January 6\u20139). Characterizing Audio Adversarial Examples Using Temporal Dependency. Proceedings of the 7th International Conference on Learning Representations, ICLR 2019, New Orleans, LA, USA. Available online: OpenReview.net."},{"key":"ref_29","first-page":"531","article-title":"Towards Visualizing and Detecting Audio Adversarial Examples for Automatic Speech Recognition","volume":"Volume 13083","author":"Baek","year":"2021","journal-title":"Proceedings of the Information Security and Privacy\u201426th Australasian Conference, ACISP 2021"},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Moosavi-Dezfooli, S.M., Fawzi, A., and Frossard, P. (2016, January 27\u201330). Deepfool: A simple and accurate method to fool deep neural networks. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, Las Vegas, NV, USA.","DOI":"10.1109\/CVPR.2016.282"},{"key":"ref_31","unstructured":"Athalye, A., Carlini, N., and Wagner, D. (2018). Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples. arXiv."},{"key":"ref_32","unstructured":"Yuan, X., Chen, Y., Zhao, Y., Long, Y., Liu, X., Chen, K., Zhang, S., Huang, H., Wang, X., and Gunter, C.A. (2018, January 15\u201317). Commandersong: A systematic approach for practical adversarial voice recognition. Proceedings of the 27th USENIX Security Symposium (USENIX Security 18), Baltimore, MD, USA."},{"key":"ref_33","unstructured":"Povey, D., Ghoshal, A., Boulianne, G., Burget, L., Glembek, O., Goel, N., Hannemann, M., Motlicek, P., Qian, Y., and Schwarz, P. (2011, January 1\u201315). The Kaldi speech recognition toolkit. Proceedings of the IEEE 2011 Workshop on Automatic Speech Recognition and Understanding, Waikoloa, HI, USA."},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Graves, A., Fern\u00e1ndez, S., Gomez, F., and Schmidhuber, J. (2006, January 25\u201329). Connectionist temporal classification: Labelling unsegmented sequence data with recurrent neural networks. Proceedings of the 23rd International Conference on Machine Learning, Pittsburgh, PA, USA.","DOI":"10.1145\/1143844.1143891"},{"key":"ref_35","doi-asserted-by":"crossref","unstructured":"Liu, X., Wan, K., Ding, Y., Zhang, X., and Zhu, Q. (2020, January 7\u201312). Weighted-sampling audio adversarial example attack. Proceedings of the AAAI Conference on Artificial Intelligence, New York, NY, USA.","DOI":"10.1609\/aaai.v34i04.5928"},{"key":"ref_36","unstructured":"Qin, Y., Carlini, N., Cottrell, G.W., Goodfellow, I.J., and Raffel, C. (2019, January 9\u201315). Imperceptible, Robust, and Targeted Adversarial Examples for Automatic Speech Recognition. Proceedings of the 36th International Conference on Machine Learning, ICML 2019, Long Beach, CA, USA."},{"key":"ref_37","unstructured":"Eisenhofer, T., Sch\u00f6nherr, L., Frank, J., Speckemeier, L., Kolossa, D., and Holz, T. (2021, January 11\u201313). Dompteur: Taming audio adversarial examples. Proceedings of the 30th USENIX Security Symposium (USENIX Security 21), Virtual Event."},{"key":"ref_38","doi-asserted-by":"crossref","unstructured":"Zong, W., Chow, Y.W., and Susilo, W. (2022). High Quality Audio Adversarial Examples Without Using Psychoacoustics. International Symposium on Cyberspace Safety and Security, Springer.","DOI":"10.1007\/978-3-031-18067-5_12"},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Taori, R., Kamsetty, A., Chu, B., and Vemuri, N. (2019, January 19\u201323). Targeted adversarial examples for black box audio systems. Proceedings of the 2019 IEEE Security and Privacy Workshops (SPW), San Francisco, CA, USA.","DOI":"10.1109\/SPW.2019.00016"},{"key":"ref_40","unstructured":"Chen, Y., Yuan, X., Zhang, J., Zhao, Y., Zhang, S., Chen, K., and Wang, X. (2020, January 12\u201314). Devil\u2019s whisper: A general approach for physical adversarial attacks against commercial black-box speech recognition devices. Proceedings of the 29th USENIX Security Symposium (USENIX Security 20), Boston, MA, USA."},{"key":"ref_41","doi-asserted-by":"crossref","unstructured":"Neekhara, P., Hussain, S., Pandey, P., Dubnov, S., McAuley, J., and Koushanfar, F. (2019). Universal adversarial perturbations for speech recognition systems. arXiv.","DOI":"10.21437\/Interspeech.2019-1353"},{"key":"ref_42","doi-asserted-by":"crossref","unstructured":"Abdullah, H., Rahman, M.S., Garcia, W., Warren, K., Yadav, A.S., Shrimpton, T., and Traynor, P. (2021, January 24\u201327). Hear \u201cno evil\u201d, see \u201ckenansville\u201d*: Efficient and transferable black-box attacks on speech recognition and voice identification systems. Proceedings of the 2021 IEEE Symposium on Security and Privacy (SP), San Francisco, CA, USA.","DOI":"10.1109\/SP40001.2021.00009"},{"key":"ref_43","doi-asserted-by":"crossref","unstructured":"Esmaeilpour, M., Cardinal, P., and Koerich, A.L. (2020, January 4\u20138). Detection of Adversarial Attacks and Characterization of Adversarial Subspace. Proceedings of the ICASSP 2020\u20142020 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP), Barcelona, Spain.","DOI":"10.1109\/ICASSP40776.2020.9052913"},{"key":"ref_44","doi-asserted-by":"crossref","unstructured":"Samizade, S., Tan, Z.H., Shen, C., and Guan, X. (2020, January 4\u20138). Adversarial Example Detection by Classification for Deep Speech Recognition. Proceedings of the ICASSP 2020\u20142020 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP), Barcelona, Spain.","DOI":"10.1109\/ICASSP40776.2020.9054750"},{"key":"ref_45","doi-asserted-by":"crossref","first-page":"63368","DOI":"10.1109\/ACCESS.2020.2985231","article-title":"MultiPAD: A Multivariant Partition-Based Method for Audio Adversarial Examples Detection","volume":"8","author":"Guo","year":"2020","journal-title":"IEEE Access"},{"key":"ref_46","unstructured":"Hussain, S., Neekhara, P., Dubnov, S., McAuley, J., and Koushanfar, F. (2021, January 11\u201313). WaveGuard: Understanding and Mitigating Audio Adversarial Examples. Proceedings of the 30th USENIX Security Symposium (USENIX Security 21), Virtual Event."},{"key":"ref_47","doi-asserted-by":"crossref","unstructured":"Yang, C.H., Qi, J., Chen, P.Y., Ma, X., and Lee, C.H. (2020, January 4\u20138). Characterizing Speech Adversarial Examples Using Self-Attention U-Net Enhancement. Proceedings of the ICASSP 2020\u20142020 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP), Barcelona, Spain.","DOI":"10.1109\/ICASSP40776.2020.9053288"},{"key":"ref_48","doi-asserted-by":"crossref","first-page":"160","DOI":"10.1016\/j.neucom.2020.02.110","article-title":"INOR\u2014An Intelligent noise reduction method to defend against adversarial audio examples","volume":"401","author":"Guo","year":"2020","journal-title":"Neurocomputing"},{"key":"ref_49","doi-asserted-by":"crossref","unstructured":"Zhang, C., Zhang, M., Zhang, S., Jin, D., Zhou, Q., Cai, Z., Zhao, H., Liu, X., and Liu, Z. (2022, January 19\u201320). Delving deep into the generalization of vision transformers under distribution shifts. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, New Orleans, LA, USA.","DOI":"10.1109\/CVPR52688.2022.00713"},{"key":"ref_50","doi-asserted-by":"crossref","unstructured":"Bai, T., Luo, J., Zhao, J., Wen, B., and Wang, Q. (2021). Recent advances in adversarial training for adversarial robustness. arXiv.","DOI":"10.24963\/ijcai.2021\/591"},{"key":"ref_51","doi-asserted-by":"crossref","first-page":"2674","DOI":"10.1109\/TVCG.2018.2843369","article-title":"Visual analytics in deep learning: An interrogative survey for the next frontiers","volume":"25","author":"Hohman","year":"2018","journal-title":"IEEE Trans. Vis. Comput. Graph."},{"key":"ref_52","doi-asserted-by":"crossref","unstructured":"Norton, A.P., and Qi, Y. (2017, January 2). Adversarial-Playground: A visualization suite showing how adversarial examples fool deep learning. Proceedings of the 2017 IEEE Symposium on Visualization for Cyber Security (VizSec), Phoenix, AZ, USA.","DOI":"10.1109\/VIZSEC.2017.8062202"},{"key":"ref_53","unstructured":"Liu, Y., Chen, X., Liu, C., and Song, D. (2017, January 24\u201326). Delving into Transferable Adversarial Examples and Black-box Attacks. Proceedings of the 5th International Conference on Learning Representations, ICLR 2017, Toulon, France. Conference Track Proceedings."},{"key":"ref_54","doi-asserted-by":"crossref","unstructured":"Stutz, D., Hein, M., and Schiele, B. (2019, January 15\u201320). Disentangling adversarial robustness and generalization. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, Long Beach, CA, USA.","DOI":"10.1109\/CVPR.2019.00714"},{"key":"ref_55","doi-asserted-by":"crossref","first-page":"433","DOI":"10.1002\/wics.101","article-title":"Principal component analysis","volume":"2","author":"Abdi","year":"2010","journal-title":"Wiley Interdiscip. Rev. Comput. Stat."},{"key":"ref_56","first-page":"2579","article-title":"Visualizing data using t-SNE","volume":"9","author":"Maaten","year":"2008","journal-title":"J. Mach. Learn. Res."},{"key":"ref_57","doi-asserted-by":"crossref","unstructured":"Lin, Y., and Abdulla, W.H. (2015). Principles of psychoacoustics. Audio Watermark, Springer.","DOI":"10.1007\/978-3-319-07974-5"},{"key":"ref_58","doi-asserted-by":"crossref","unstructured":"Panayotov, V., Chen, G., Povey, D., and Khudanpur, S. (2015, January 19\u201324). Librispeech: An asr corpus based on public domain audio books. Proceedings of the 2015 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP), Queensland, Australia.","DOI":"10.1109\/ICASSP.2015.7178964"},{"key":"ref_59","unstructured":"Ardila, R., Branson, M., Davis, K., Henretty, M., Kohler, M., Meyer, J., Morais, R., Saunders, L., Tyers, F.M., and Weber, G. (2019). Common voice: A massively-multilingual speech corpus. arXiv."},{"key":"ref_60","first-page":"2825","article-title":"Scikit-learn: Machine learning in Python","volume":"12","author":"Pedregosa","year":"2011","journal-title":"J. Mach. Learn. Res."},{"key":"ref_61","unstructured":"Athalye, A., Engstrom, L., Ilyas, A., and Kwok, K. (2018, January 10\u201315). Synthesizing robust adversarial examples. Proceedings of the International Conference on Machine Learning, Stockholm, Sweden."},{"key":"ref_62","doi-asserted-by":"crossref","unstructured":"Allen-Zhu, Z., and Li, Y. (2022, January 7\u201310). Feature purification: How adversarial training performs robust deep learning. Proceedings of the 2021 IEEE 62nd Annual Symposium on Foundations of Computer Science (FOCS), Denver, CO, USA.","DOI":"10.1109\/FOCS52979.2021.00098"},{"key":"ref_63","doi-asserted-by":"crossref","unstructured":"Goldblum, M., Fowl, L., Feizi, S., and Goldstein, T. (2020, January 7\u201312). Adversarially robust distillation. Proceedings of the AAAI Conference on Artificial Intelligence, New York, NY, USA.","DOI":"10.1609\/aaai.v34i04.5816"},{"key":"ref_64","unstructured":"Gowal, S., Dvijotham, K., Stanforth, R., Bunel, R., Qin, C., Uesato, J., Arandjelovic, R., Mann, T.A., and Kohli, P. (2018). On the Effectiveness of Interval Bound Propagation for Training Verifiably Robust Models. arXiv."},{"key":"ref_65","doi-asserted-by":"crossref","first-page":"1096","DOI":"10.1038\/s41467-019-08987-4","article-title":"Unmasking Clever Hans predictors and assessing what machines really learn","volume":"10","author":"Lapuschkin","year":"2019","journal-title":"Nat. Commun."},{"key":"ref_66","doi-asserted-by":"crossref","first-page":"665","DOI":"10.1038\/s42256-020-00257-z","article-title":"Shortcut learning in deep neural networks","volume":"2","author":"Geirhos","year":"2020","journal-title":"Nat. Mach. Intell."},{"key":"ref_67","unstructured":"Liu, E.Z., Haghgoo, B., Chen, A.S., Raghunathan, A., Koh, P.W., Sagawa, S., Liang, P., and Finn, C. (2021, January 18\u201324). Just train twice: Improving group robustness without training group information. Proceedings of the International Conference on Machine Learning, Virtual."},{"key":"ref_68","unstructured":"Singla, S., and Feizi, S. (2022, January 25). Salient ImageNet: How to discover spurious features in Deep Learning?. Proceedings of the International Conference on Learning Representations, Virtual."}],"container-title":["Journal of Imaging"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2313-433X\/8\/12\/324\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T01:37:06Z","timestamp":1760146626000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2313-433X\/8\/12\/324"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,12,9]]},"references-count":68,"journal-issue":{"issue":"12","published-online":{"date-parts":[[2022,12]]}},"alternative-id":["jimaging8120324"],"URL":"https:\/\/doi.org\/10.3390\/jimaging8120324","relation":{},"ISSN":["2313-433X"],"issn-type":[{"value":"2313-433X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,12,9]]}}}