Jove
Visualize
Contact Us
JoVE
x logofacebook logolinkedin logoyoutube logo
ABOUT JoVE
OverviewLeadershipBlogJoVE Help Center
AUTHORS
Publishing ProcessEditorial BoardScope & PoliciesPeer ReviewFAQSubmit
LIBRARIANS
TestimonialsSubscriptionsAccessResourcesLibrary Advisory BoardFAQ
RESEARCH
JoVE JournalMethods CollectionsJoVE Encyclopedia of ExperimentsArchive
EDUCATION
JoVE CoreJoVE BusinessJoVE Science EducationJoVE Lab ManualFaculty Resource CenterFaculty Site
Terms & Conditions of Use
Privacy Policy
Policies

Related Concept Videos

Difference from Background: Limit of Detection01:05

Difference from Background: Limit of Detection

6.4K
The limit of detection (LOD) is the smallest amount of analyte that can be distinguished from the background noise. The LOD value corresponds to the concentration at which the analyte signal is three times larger than the standard deviation of the blank signal. Below this value, the analyte signal cannot be differentiated from the background noise. It is calculated by dividing the calibration slope by 3 times the standard deviation of the blank signals.
The LOD indicates the presence or absence...
6.4K
Detection of Gross Error: The Q Test01:00

Detection of Gross Error: The Q Test

6.1K
When one or more data points appear far from the rest of the data, there is a need to determine whether they are outliers and whether they should be eliminated from the data set to ensure an accurate representation of the measured value. In many cases, outliers arise from gross errors (or human errors) and do not accurately reflect the underlying phenomenon. In some cases, however, these apparent outliers reflect true phenomenological differences. In these cases, we can use statistical methods...
6.1K
Reducing Line Loss01:18

Reducing Line Loss

156
In a three-phase circuit, line loss is an indicator of energy dissipated as heat due to the resistance of transmission lines. To address this, incorporating transformers into the system—a step-up transformer at the source and a step-down transformer at the load—is a strategic solution. Two three-phase transformers are introduced to improve this.
With a step-up transformer at the source, the voltage is increased, thereby reducing the current in the transmission lines since power loss...
156
Distance Corrections01:15

Distance Corrections

31
To achieve precise distance measurements, especially in surveying and construction, certain corrections must be applied to account for potential sources of error like the standardization errors, temperature variations, and slope adjustments.Standardization error emerges when measurement equipment undergoes changes, such as wear, repairs, or weather impacts. To address this, surveyors compare the equipment’s readings to a standard. This process identifies any deviation that might lead to...
31
Masking and Demasking Agents01:19

Masking and Demasking Agents

2.5K
EDTA titrations may necessitate masking and demasking agents to temporarily protect a particular metal ion in a mixture from the EDTA reaction. These agents facilitate the sequential analysis of the metal ions by forming stable complexes with some—but not all—metal ions during certain steps.
There are many masking agents, such as cyanide, fluoride, triethanolamine, thiourea, and 2,3-bis(sulfanyl)propan-1-ol (formerly 2,3-dimercapto-1-propanol), with the masking agent chosen based on...
2.5K
Mean Absolute Deviation01:13

Mean Absolute Deviation

2.6K
The mean absolute deviation is also a measure of the variability of data in a sample. It is the absolute value of the average difference between the data values and the mean.
Let us consider a dataset containing the number of unsold cupcakes in five shops: 10, 15, 8, 7, and 10. Initially, calculate the sample mean. Then calculate the deviation, or the difference, between each data value and the mean. Next, the absolute values of these deviations are added and divided by the sample size to...
2.6K

You might also read

Related Articles

Articles linked to this work by shared authors, journal, and citation graph.

Sort by
Same author

Deciphering the cluster-to-spinel transformation pathway of CoMn<sub>2</sub> precursors toward efficient bifunctional electrocatalysis.

Journal of colloid and interface science·2026
Same author

Wavelet spectral-aware Kolmogorov-Arnold Network for organ and tumor segmentation.

Computerized medical imaging and graphics : the official journal of the Computerized Medical Imaging Society·2026
Same author

Data and knowledge-driven imaging biomarkers for lumbar aging and degenerative risk stratification monitoring.

NPJ digital medicine·2026
Same author

PEG-Dependent Tunable Degradation and Curcumin Release from Curcumin-Based Biomedical Polyurethanes.

Biomolecules·2026
Same author

Scale-Aware Prompting With Optimal Transport for Remote Sensing Image Captioning.

IEEE transactions on image processing : a publication of the IEEE Signal Processing Society·2026
Same author

Elastic Multi-Gradient Descent for Parallel Continual Learning.

IEEE transactions on pattern analysis and machine intelligence·2026
Same journal

CAFF-CIL: Causality-Aware Freedom Forgetting Approach for Class-Incremental Learning.

IEEE transactions on neural networks and learning systems·2026
Same journal

Harmonic Autoencoding Framework for Multiple Tasks in Magnetic Particle Imaging Reconstruction.

IEEE transactions on neural networks and learning systems·2026
Same journal

A Survey on Human-Centric Voice-Face Multimodal Learning.

IEEE transactions on neural networks and learning systems·2026
Same journal

Vision-Assisted Foundation Model for Solving Multitask Vehicle Routing Problems.

IEEE transactions on neural networks and learning systems·2026
Same journal

FP3O: Enabling Proximal Policy Optimization in Multiagent Cooperation With Parameter-Sharing Versatility.

IEEE transactions on neural networks and learning systems·2026
Same journal

Hierarchical Semantic Concept Modeling for Generalizable Myocardial Pathology Segmentation on Multisequence CMR Images.

IEEE transactions on neural networks and learning systems·2026
See all related articles

Related Experiment Video

Updated: Jul 13, 2025

Medical-grade Sterilizable Target for Fluid-immersed Fetoscope Optical Distortion Calibration
07:03

Medical-grade Sterilizable Target for Fluid-immersed Fetoscope Optical Distortion Calibration

Published on: February 23, 2017

7.7K

Gradient Correction for White-Box Adversarial Attacks.

Hongying Liu, Zhijin Ge, Zhenyu Zhou

    IEEE Transactions on Neural Networks and Learning Systems
    |October 11, 2023
    PubMed
    Summary
    This summary is machine-generated.

    This paper introduces a new method called ADV-ReLU to improve how adversarial attacks are generated against deep neural networks. By fixing errors in how gradients are calculated through ReLU activation functions, this technique creates more effective attacks with smaller, less noticeable changes to the original input.

    Keywords:
    deep neural networksbackpropagationrectified linear unitperturbation optimization

    Frequently Asked Questions

    More Related Videos

    High-Accuracy Correction of 3D Chromatic Shifts in the Age of Super-Resolution Biological Imaging Using Chromagnon
    08:18

    High-Accuracy Correction of 3D Chromatic Shifts in the Age of Super-Resolution Biological Imaging Using Chromagnon

    Published on: June 16, 2020

    7.5K
    Author Spotlight: Enhancement of Salient Object Detection for Smart Grid Applications
    03:31

    Author Spotlight: Enhancement of Salient Object Detection for Smart Grid Applications

    Published on: December 15, 2023

    568

    Related Experiment Videos

    Last Updated: Jul 13, 2025

    Medical-grade Sterilizable Target for Fluid-immersed Fetoscope Optical Distortion Calibration
    07:03

    Medical-grade Sterilizable Target for Fluid-immersed Fetoscope Optical Distortion Calibration

    Published on: February 23, 2017

    7.7K
    High-Accuracy Correction of 3D Chromatic Shifts in the Age of Super-Resolution Biological Imaging Using Chromagnon
    08:18

    High-Accuracy Correction of 3D Chromatic Shifts in the Age of Super-Resolution Biological Imaging Using Chromagnon

    Published on: June 16, 2020

    7.5K
    Author Spotlight: Enhancement of Salient Object Detection for Smart Grid Applications
    03:31

    Author Spotlight: Enhancement of Salient Object Detection for Smart Grid Applications

    Published on: December 15, 2023

    568

    Area of Science:

    • Computer vision and adversarial machine learning research
    • Gradient correction for white-box adversarial attacks within neural network optimization

    Background:

    Deep neural networks serve as the backbone for modern image classification and object recognition systems. Researchers have identified that these models remain susceptible to adversarial examples that alter outputs while appearing unchanged to humans. Many existing white-box attack strategies prioritize optimizing gradient usage during each iteration to maximize performance. That uncertainty drove interest in understanding why these gradient-based methods sometimes produce larger than necessary perturbations. Prior research has shown that specific activation functions influence how information flows during backpropagation. No prior work had resolved the precise impact of rectified linear unit behaviors on gradient accuracy. This gap motivated a closer examination of how internal network dynamics misguide optimization directions. The current study addresses these challenges by analyzing how activation functions contribute to suboptimal attack generation.

    Purpose Of The Study:

    The aim of this study is to introduce a novel method for improving the generation of adversarial examples in deep neural networks. Researchers sought to resolve the issue of gradient misguidance caused by specific activation function behaviors. They identified that standard gradient-based attacks often fail to optimize perturbations effectively due to inaccurate gradient calculations. This work addresses the technical challenge of wrong blocking and over transmission within rectified linear units. The authors intended to develop a universal correction approach that could be applied to various existing attack algorithms. They aimed to demonstrate that fixing these gradient errors leads to smaller, more efficient adversarial perturbations. The study was motivated by the need to enhance the performance of white-box attack strategies in complex image classification tasks. By providing a systematic correction mechanism, the authors hope to improve the reliability and effectiveness of adversarial generation techniques.

    Main Methods:

    The review approach involves analyzing the mathematical properties of rectified linear unit activation functions during the backpropagation process. Researchers designed a universal correction method to identify and rectify gradient misguidance. Their strategy maps calculated gradient values to specific scores to determine which components require adjustment. The team integrated this approach into several established gradient-based white-box attack algorithms. They evaluated the performance of these modified algorithms using standard benchmarking datasets. The study utilized ImageNet and CIFAR10 to validate the robustness of their proposed corrections. Investigators compared the resulting perturbation sizes against those produced by baseline attack methods. This systematic evaluation confirms the compatibility of the correction technique with existing adversarial generation frameworks.

    Main Results:

    The primary finding reveals that the proposed method significantly reduces the magnitude of perturbations required for successful adversarial attacks. The researchers observed that correcting gradient errors minimizes the difference between predicted and actual loss function changes. Their approach integrates successfully with fast gradient signed method, iterative fast gradient signed method, momentum iterative fast gradient signed method, and variance tuning momentum iterative fast gradient signed method. Experimental results on ImageNet and CIFAR10 confirm that this method consistently outperforms standard approaches. The study shows that the technique remains effective even when transferred to black-box attack scenarios. By selecting specific gradient values for updates, the method achieves more precise optimization directions. These improvements lead to smaller perturbations measured in the L-norm across all tested architectures. The data indicate that the correction method provides a reliable way to enhance the performance of diverse gradient-based attack strategies.

    Conclusions:

    The authors demonstrate that their proposed correction method effectively mitigates gradient misguidance during adversarial generation. Synthesis and implications suggest that addressing activation function limitations improves the efficiency of various existing attack algorithms. The researchers show that their approach integrates seamlessly with established techniques like momentum iterative fast gradient signed method. Findings indicate that these corrections lead to smaller perturbations compared to standard gradient-based approaches. The study implies that refining gradient calculations enhances the overall success rate of white-box adversarial strategies. Evidence supports the transferability of these improved techniques to black-box attack scenarios as well. The authors conclude that their method provides a robust framework for optimizing adversarial example generation across different datasets. This work highlights the importance of accounting for activation function properties when designing high-performance adversarial attacks.

    The researchers propose that wrong blocking and over transmission during backpropagation misguide gradient calculations. These phenomena enlarge the discrepancy between predicted and actual loss function changes, leading to suboptimal optimization directions and increased perturbation sizes compared to standard methods.

    The authors introduce ADV-ReLU, a universal correction technique. This tool maps gradient values to scores and selects specific portions to update misguided gradients, thereby enhancing the performance of existing algorithms like fast gradient signed method and its variants.

    A rectified linear unit is necessary because its specific activation properties, specifically wrong blocking and over transmission, directly cause the gradient calculation errors. Without accounting for these behaviors, gradient-based attacks fail to achieve optimal perturbation efficiency.

    The authors utilize backpropagation to calculate the loss function gradient relative to network inputs. This data type is essential for identifying where optimization directions deviate from the actual loss landscape, allowing the correction method to adjust misguided values effectively.

    The researchers measure the success of their approach using the L-norm of perturbations. They compare their method against standard gradient-based attacks, demonstrating that their technique consistently achieves lower perturbation values on ImageNet and CIFAR10 datasets.

    The authors claim that their approach is highly versatile, allowing for easy integration into state-of-the-art gradient-based white-box attacks. They further propose that this method maintains effectiveness when transferred to black-box attack scenarios, broadening its utility in adversarial research.