{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,24]],"date-time":"2026-07-24T14:05:54Z","timestamp":1784901954634,"version":"3.55.0"},"publisher-location":"Cham","reference-count":28,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783032314406","type":"print"},{"value":"9783032314413","type":"electronic"}],"license":[{"start":{"date-parts":[[2026,7,25]],"date-time":"2026-07-25T00:00:00Z","timestamp":1784937600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,7,25]],"date-time":"2026-07-25T00:00:00Z","timestamp":1784937600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2027]]},"DOI":"10.1007\/978-3-032-31441-3_24","type":"book-chapter","created":{"date-parts":[[2026,7,24]],"date-time":"2026-07-24T13:23:01Z","timestamp":1784899381000},"page":"355-369","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["EntangleNet: An Entanglement-Based Preprocessing Framework for\u00a0Robust Defense Against Adversarial Attacks"],"prefix":"10.1007","author":[{"given":"Mohammad","family":"Al-Fawa\u2019reh","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Luke","family":"Kelly","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Martin","family":"Masek","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jumana","family":"Abu-Khalaf","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,7,25]]},"reference":[{"key":"24_CR1","unstructured":"Andriushchenko, M., Croce, F., Flammarion, N., Hein, M.: Square attack: a query-efficient black-box adversarial attack via random search. arXiv abs\/1912.00049 (2019). https:\/\/api.semanticscholar.org\/CorpusID:208527215"},{"key":"24_CR2","unstructured":"Athalye, A., Carlini, N., Wagner, D.: Obfuscated gradients give a false sense of security: circumventing defenses to adversarial examples (2018). https:\/\/arxiv.org\/abs\/1802.00420"},{"key":"24_CR3","unstructured":"Bogun, A.A., Kostadinov, D., Borth, D.: Saliency diversified deep ensemble for robustness to adversaries. arXiv abs\/2112.03615 (2021). https:\/\/api.semanticscholar.org\/CorpusID:244920714"},{"key":"24_CR4","doi-asserted-by":"publisher","DOI":"10.1016\/j.media.2021.102141","volume":"73","author":"G Bortsova","year":"2021","unstructured":"Bortsova, G., et al.: Adversarial attack vulnerability of medical image analysis systems: unexplored factors. Med. Image Anal. 73, 102141 (2021). https:\/\/doi.org\/10.1016\/j.media.2021.102141","journal-title":"Med. Image Anal."},{"key":"#cr-split#-24_CR5.1","doi-asserted-by":"crossref","unstructured":"Carlini, N., Wagner, D.A.: Towards evaluating the robustness of neural networks. In: 2017 IEEE Symposium on Security and Privacy","DOI":"10.1109\/SP.2017.49"},{"key":"#cr-split#-24_CR5.2","unstructured":"(SP) pp. 39-57 (2016). https:\/\/api.semanticscholar.org\/CorpusID:2893830"},{"key":"24_CR6","unstructured":"Chen, P.Y., Sharma, Y., Zhang, H., Yi, J., Hsieh, C.J.: Ead: elastic-net attacks to deep neural networks via adversarial examples. arXiv abs\/1709.04114 (2017). https:\/\/api.semanticscholar.org\/CorpusID:19157252"},{"key":"24_CR7","doi-asserted-by":"publisher","unstructured":"Chi, L., et al.: Adversarial attacks on autonomous driving systems in the physical world: a survey. IEEE Trans. Intell. Veh. 1\u201322 (2024). https:\/\/doi.org\/10.1109\/TIV.2024.3484152","DOI":"10.1109\/TIV.2024.3484152"},{"key":"24_CR8","unstructured":"Das, N., et al.: Keeping the bad guys out: protecting and vaccinating deep learning with jpeg compression. arXiv abs\/1705.02900 (2017)"},{"key":"24_CR9","unstructured":"Goodfellow, I.J., Shlens, J., Szegedy, C.: Explaining and harnessing adversarial examples. CoRR abs\/1412.6572 (2014). https:\/\/api.semanticscholar.org\/CorpusID:6706414"},{"key":"24_CR10","doi-asserted-by":"crossref","unstructured":"Holland, J.H.: Adaptation in Natural and Artificial Systems: An Introductory Analysis with Applications to Biology, Control, and Artificial Intelligence. MIT Press (1992)","DOI":"10.7551\/mitpress\/1090.001.0001"},{"key":"24_CR11","doi-asserted-by":"publisher","unstructured":"Jang, U., Wu, X., Jha, S.: Objective metrics and gradient descent algorithms for adversarial examples in machine learning. In: Proceedings of the 33rd Annual Computer Security Applications Conference. ACSAC \u201917, pp. 262\u2013277. Association for Computing Machinery, New York, NY, USA (2017). https:\/\/doi.org\/10.1145\/3134600.3134635","DOI":"10.1145\/3134600.3134635"},{"key":"24_CR12","unstructured":"Krizhevsky, A., Hinton, G.: Learning multiple layers of features from tiny images (2009)"},{"key":"24_CR13","doi-asserted-by":"publisher","unstructured":"Kumar, N., Vimal, S., Kayathwal, K., Dhama, G.: Evolutionary adversarial attacks on payment systems. In: 2021 20th IEEE International Conference on Machine Learning and Applications (ICMLA), pp. 813\u2013818 (2021). https:\/\/doi.org\/10.1109\/ICMLA52953.2021.00134","DOI":"10.1109\/ICMLA52953.2021.00134"},{"key":"24_CR14","unstructured":"Kurakin, A., Goodfellow, I.J., Bengio, S.: Adversarial examples in the physical world. arXiv abs\/1607.02533 (2016)"},{"key":"24_CR15","unstructured":"LeCun, Y., Cortes, C., Burges, C.J.: The mNIST database of handwritten digits (1998). http:\/\/yann.lecun.com\/exdb\/mnist\/"},{"key":"24_CR16","unstructured":"Madry, A., Makelov, A., Schmidt, L., Tsipras, D., Vladu, A.: Towards deep learning models resistant to adversarial attacks. arXiv abs\/1706.06083 (2017). https:\/\/api.semanticscholar.org\/CorpusID:3488815"},{"key":"24_CR17","doi-asserted-by":"crossref","unstructured":"Moosavi-Dezfooli, S.M., Fawzi, A., Fawzi, O., Frossard, P.: Universal adversarial perturbations. In: 2017 IEEE Conference on Computer Vision and Pattern Recognition (CVPR), pp. 86\u201394 (2016). https:\/\/api.semanticscholar.org\/CorpusID:11558223","DOI":"10.1109\/CVPR.2017.17"},{"key":"24_CR18","doi-asserted-by":"crossref","unstructured":"Moosavi-Dezfooli, S.M., Fawzi, A., Frossard, P.: Deepfool: a simple and accurate method to fool deep neural networks. In: 2016 IEEE Conference on Computer Vision and Pattern Recognition (CVPR), pp. 2574\u20132582 (2015). https:\/\/api.semanticscholar.org\/CorpusID:12387176","DOI":"10.1109\/CVPR.2016.282"},{"key":"24_CR19","unstructured":"Nicolae, M.I., et al.: Adversarial robustness toolbox v1.2.0. CoRR 1807.01069 (2018). https:\/\/arxiv.org\/pdf\/1807.01069"},{"key":"24_CR20","doi-asserted-by":"crossref","unstructured":"Papernot, N., McDaniel, P., Wu, X., Jha, S., Swami, A.: Distillation as a defense to adversarial perturbations against deep neural networks (2016). https:\/\/arxiv.org\/abs\/1511.04508","DOI":"10.1109\/SP.2016.41"},{"key":"24_CR21","unstructured":"Szegedy, C., et al.: Intriguing properties of neural networks. In: Bengio, Y., LeCun, Y. (eds.) 2nd International Conference on Learning Representations, ICLR 2014, Banff, AB, Canada, 14\u201316 April 2014, Conference Track Proceedings (2014)"},{"key":"24_CR22","unstructured":"Xiao, H., Rasul, K., Vollgraf, R.: Fashion-mNIST: a novel image dataset for benchmarking machine learning algorithms. arXiv preprint arXiv:1708.07747 (2017)"},{"key":"24_CR23","doi-asserted-by":"publisher","unstructured":"Xiao, Y., Deng, X., Yu, Z.: Defending against adversarial attacks using digital image processing. J. Phys. Conf. Ser. 2577(1), 012016 (2023). https:\/\/doi.org\/10.1088\/1742-6596\/2577\/1\/012016","DOI":"10.1088\/1742-6596\/2577\/1\/012016"},{"key":"24_CR24","unstructured":"Xie, C., Wang, J., Zhang, Z., Ren, Z., Yuille, A.: Mitigating adversarial effects through randomization (2018). https:\/\/arxiv.org\/abs\/1711.01991"},{"key":"24_CR25","doi-asserted-by":"crossref","unstructured":"Xu, W., Evans, D., Qi, Y.: Feature squeezing: detecting adversarial examples in deep neural networks. arXiv abs\/1704.01155 (2017)","DOI":"10.14722\/ndss.2018.23198"},{"issue":"1","key":"24_CR26","doi-asserted-by":"publisher","first-page":"41","DOI":"10.1038\/s41597-022-01721-8","volume":"10","author":"J Yang","year":"2023","unstructured":"Yang, J., et al.: MedmNIST v2-a large-scale lightweight benchmark for 2d and 3d biomedical image classification. Sci. Data 10(1), 41 (2023)","journal-title":"Sci. Data"},{"key":"24_CR27","doi-asserted-by":"publisher","unstructured":"Zantedeschi, V., Nicolae, M.I., Rawat, A.: Efficient defenses against adversarial attacks. In: Proceedings of the 10th ACM Workshop on Artificial Intelligence and Security. AISec \u201917, pp. 39\u201349. Association for Computing Machinery, New York, NY, USA (2017). https:\/\/doi.org\/10.1145\/3128572.3140449","DOI":"10.1145\/3128572.3140449"}],"container-title":["Lecture Notes in Computer Science","Pattern Recognition"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-032-31441-3_24","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,24]],"date-time":"2026-07-24T13:23:05Z","timestamp":1784899385000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-032-31441-3_24"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,7,25]]},"ISBN":["9783032314406","9783032314413"],"references-count":28,"URL":"https:\/\/doi.org\/10.1007\/978-3-032-31441-3_24","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,7,25]]},"assertion":[{"value":"25 July 2026","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ICPR","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Pattern Recognition","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Lyon","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"France","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2026","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"17 August 2026","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"22 August 2026","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"28","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"icpr2026","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/icpr2026.org\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}