{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,28]],"date-time":"2025-10-28T00:32:23Z","timestamp":1761611543786,"version":"3.37.3"},"reference-count":54,"publisher":"Springer Science and Business Media LLC","issue":"2","license":[{"start":{"date-parts":[[2022,2,28]],"date-time":"2022-02-28T00:00:00Z","timestamp":1646006400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2022,2,28]],"date-time":"2022-02-28T00:00:00Z","timestamp":1646006400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"funder":[{"DOI":"10.13039\/501100011246","name":"state key laboratory of novel software technology","doi-asserted-by":"publisher","award":["SKLSDE-2020ZX-15"],"award-info":[{"award-number":["SKLSDE-2020ZX-15"]}],"id":[{"id":"10.13039\/501100011246","id-type":"DOI","asserted-by":"publisher"}]},{"name":"the national key r&d program of china","award":["2017YFB1010000"],"award-info":[{"award-number":["2017YFB1010000"]}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Machine Vision and Applications"],"published-print":{"date-parts":[[2022,3]]},"DOI":"10.1007\/s00138-022-01281-2","type":"journal-article","created":{"date-parts":[[2022,2,28]],"date-time":"2022-02-28T14:03:51Z","timestamp":1646057031000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Mitigating adversarial perturbations via weakly supervised object location and regions recombination"],"prefix":"10.1007","volume":"33","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-0304-1732","authenticated-orcid":false,"given":"Fei","family":"Wu","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tong","family":"Guo","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jingjing","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Limin","family":"Xiao","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2022,2,28]]},"reference":[{"key":"1281_CR1","unstructured":"Ioffe, S., Szegedy, C: Batch normalization: accelerating deep network training by reducing internal covariate shift. arXiv preprint arXiv:1502.03167 (2015)"},{"key":"1281_CR2","doi-asserted-by":"crossref","unstructured":"Mnih, V., Kavukcuoglu, K., Silver, D., Rusu, A.A., Veness, J., Bellemare, M.G.,..., Petersen, S.: Human-level control through deep reinforcement learning. Nature, 518(7540), 529\u2013533 (2015)","DOI":"10.1038\/nature14236"},{"key":"1281_CR3","doi-asserted-by":"crossref","unstructured":"He, K., Zhang, X., Ren, S., Sun, J.: Deep residual learning for image recognition. In Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, pp. 770\u2013778 (2016)","DOI":"10.1109\/CVPR.2016.90"},{"key":"1281_CR4","first-page":"171","volume":"2","author":"P Li","year":"2018","unstructured":"Li, P., Zhao, W., Liu, Q., Wu, C.J.: Review of machine learning security and its defense technology. Comput. Sci. Explor 2, 171\u2013184 (2018)","journal-title":"Comput. Sci. Explor"},{"key":"1281_CR5","unstructured":"Kurakin, A., Goodfellow, I., Bengio, S: Adversarial examples in the physical world. arXiv preprint arXiv:1607.02533 (2016)"},{"key":"1281_CR6","unstructured":"Szegedy, C., et al.: Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199 (2013)"},{"key":"1281_CR7","doi-asserted-by":"crossref","unstructured":"Biggio, B., Corona, I., Maiorca, D., Nelson, B., \u0160rndi\u0107, N., Laskov, P.,... & Roli, F.: Evasion attacks against machine learning at test time. In: Joint European Conference on Machine Learning and Knowledge Discovery in Databases (pp. 387\u2013402). Springer, Berlin, Heidelberg (2013)","DOI":"10.1007\/978-3-642-40994-3_25"},{"key":"1281_CR8","unstructured":"Tanay, T., Griffin, L: A boundary tilting persepective on the phenomenon of adversarial examples. arXiv preprint arXiv:1608.07690 (2016)"},{"key":"1281_CR9","doi-asserted-by":"crossref","unstructured":"Papernot, N., McDaniel, P., Goodfellow, I., Jha, S., Celik, Z.B., Swami, A.: Practical black-box attacks against machine learning. In: Proceedings of the 2017 ACM on Asia Conference on Computer and Communications Security, pp. 506\u2013519 (2017)","DOI":"10.1145\/3052973.3053009"},{"key":"1281_CR10","doi-asserted-by":"crossref","unstructured":"Moosavi-Dezfooli, S.M., Fawzi, A., Fawzi, O., Frossard, P.: Universal adversarial perturbations. In: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, pp. 1765\u20131773 (2017)","DOI":"10.1109\/CVPR.2017.17"},{"key":"1281_CR11","unstructured":"Tanay, T., Griffin, L.: A boundary tilting persepective on the phenomenon of adversarial examples. arXiv preprint arXiv:1608.07690 (2016)"},{"key":"1281_CR12","doi-asserted-by":"publisher","first-page":"4804","DOI":"10.1109\/TIP.2020.2975918","volume":"29","author":"Y Zhang","year":"2020","unstructured":"Zhang, Y., Tian, X., Li, Y., Wang, X., Tao, D.: Principal component adversarial example. IEEE Trans. Image Process. 29, 4804\u20134815 (2020)","journal-title":"IEEE Trans. Image Process."},{"key":"1281_CR13","doi-asserted-by":"publisher","first-page":"701","DOI":"10.1109\/TIFS.2020.3021899","volume":"16","author":"H Zhang","year":"2020","unstructured":"Zhang, H., Avrithis, Y., Furon, T., Amsaleg, L.: Walking on the edge: Fast, low-distortion adversarial examples. IEEE Trans. Inf. Forensics Secur. 16, 701\u2013713 (2020)","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"issue":"6","key":"1281_CR14","doi-asserted-by":"publisher","first-page":"1164","DOI":"10.1109\/TKDE.2018.2790928","volume":"30","author":"Z Yin","year":"2018","unstructured":"Yin, Z., Wang, F., Liu, W., Chawla, S.: Sparse feature attacks in adversarial learning. IEEE Trans. Knowl. Data Eng. 30(6), 1164\u20131177 (2018)","journal-title":"IEEE Trans. Knowl. Data Eng."},{"key":"1281_CR15","doi-asserted-by":"publisher","first-page":"632","DOI":"10.1016\/j.patrec.2019.06.028","volume":"125","author":"T Deng","year":"2019","unstructured":"Deng, T., Zeng, Z.: Generate adversarial examples by spatially perturbing on the meaningful area. Pattern Recogn. Lett. 125, 632\u2013638 (2019)","journal-title":"Pattern Recogn. Lett."},{"key":"1281_CR16","unstructured":"Goodfellow, I.J., Shlens, J., Szegedy, C.: Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572 (2014)"},{"key":"1281_CR17","doi-asserted-by":"crossref","unstructured":"Carlini, N., Wagner, D.: Adversarial examples are not easily detected: Bypassing ten detection methods. In: Proceedings of the 10th ACM Workshop on Artificial Intelligence and Security, pp. 3\u201314 (2017).","DOI":"10.1145\/3128572.3140444"},{"key":"1281_CR18","unstructured":"Madry, A., Makelov, A., Schmidt, L., Tsipras, D., Vladu, A.: Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083 (2017)"},{"key":"1281_CR19","doi-asserted-by":"crossref","unstructured":"Papernot, N., McDaniel, P., Jha, S., Fredrikson, M., Celik, Z.B., Swami, A.: The limitations of deep learning in adversarial settings. In: 2016 IEEE European Symposium on Security and Privacy (EuroS&P), pp. 372\u2013387 (2016)","DOI":"10.1109\/EuroSP.2016.36"},{"key":"1281_CR20","doi-asserted-by":"crossref","unstructured":"Moosavi-Dezfooli, S.M., Fawzi, A., Frossard, P. Deepfool: a simple and accu-rate method to fool deep neural networks. In: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, pp. 2574\u20132582 (2016)","DOI":"10.1109\/CVPR.2016.282"},{"key":"1281_CR21","unstructured":"Huang, R., Xu, B., Schuurmans, D., Szepesv\u00e1ri, C.: Learning with a strong adversary. arXiv preprint arXiv:1511.03034 (2015)"},{"key":"1281_CR22","doi-asserted-by":"crossref","unstructured":"Papernot, N., McDaniel, P., Wu, X., Jha, S., Swami, A. Distillation as a defense to adversarial perturbations against deep neural networks. In: 2016 IEEE Symposium on Security and Privacy (SP), pp. 582\u2013597. IEEE (2016)","DOI":"10.1109\/SP.2016.41"},{"key":"1281_CR23","doi-asserted-by":"crossref","unstructured":"Carlini, N., & Wagner, D.: Towards evaluating the robustness of neural networks. In: 2017 IEEE Symposium on Security and Privacy (sp), pp. 39\u201357. IEEE (2017)","DOI":"10.1109\/SP.2017.49"},{"key":"1281_CR24","doi-asserted-by":"crossref","unstructured":"Jin, G., Shen, S., Zhang, D., Dai, F., Zhang, Y.: Ape-gan: adversarial perturbation elimination with gan. In: ICASSP 2019\u20132019 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP), pp. 3842\u20133846. IEEE (2019)","DOI":"10.1109\/ICASSP.2019.8683044"},{"key":"1281_CR25","unstructured":"Das, N., Shanbhogue, M., Chen, S.T., Hohman, F., Li, S., Chen, L.,..., Chau, D.H.: Shield: fast, practical defense and vaccination for deep learning using jpeg compression. In: Proceedings of the 24th ACM SIGKDD International Conference on Knowledge Discovery & Data Mining, pp. 196\u2013204 (2018)"},{"key":"1281_CR26","unstructured":"Guo, C., Rana, M., Cisse, M., Van Der Maaten, L.: Countering adversarial images using input transformations. arXiv preprint arXiv:1711.00117 (2017)"},{"key":"1281_CR27","doi-asserted-by":"crossref","unstructured":"Prakash, A., Moran, N., Garber, S., DiLillo, A., Storer, J.: Deflecting adversarial attacks with pixel deflection. In: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, pp. 8571\u20138580 (2018)","DOI":"10.1109\/CVPR.2018.00894"},{"key":"1281_CR28","doi-asserted-by":"crossref","unstructured":"Wang, J., Wu, Y., Li, M., Lin, X., Wu, J., Li, C.: Interpretability is a kind of safety: an interpreter-based ensemble for adversary defense. In: Proceedings of the 26th ACM SIGKDD International Conference on Knowledge Discovery & Data Mining, pp. 15\u201324 (2020).","DOI":"10.1145\/3394486.3403044"},{"issue":"1","key":"1281_CR29","doi-asserted-by":"publisher","first-page":"1075","DOI":"10.1109\/TVCG.2019.2934631","volume":"26","author":"Y Ma","year":"2019","unstructured":"Ma, Y., Xie, T., Li, J., Maciejewski, R.: Explaining vulnerabilities to adversarial machine learning through visual analytics. IEEE Trans. Visual Comput. Graphics 26(1), 1075\u20131085 (2019)","journal-title":"IEEE Trans. Visual Comput. Graphics"},{"key":"1281_CR30","unstructured":"Wang, Y., Zou, D., Yi, J., Bailey, J., Ma, X., Gu, Q.: Improving adversarial robustness requires revisiting misclassified examples. In: International Conference on Learning Representations (2019)"},{"key":"1281_CR31","doi-asserted-by":"crossref","unstructured":"Cao, K., Liu, M., Su, H., Wu, J., Zhu, J., Liu, S.: Analyzing the noise robustness of deep neural networks. IEEE Trans. Visual. Comput. Graph. (2020)","DOI":"10.1109\/TVCG.2020.2969185"},{"key":"1281_CR32","unstructured":"Feinman, R., Curtin, R.R., Shintre, S., Gardner, A.B.: Detecting adversarial samples from artifacts. arXiv preprint arXiv:1703.00410 (2017)"},{"key":"1281_CR33","doi-asserted-by":"crossref","unstructured":"Jie, Z., Wei, Y., Jin, X., Feng, J., Liu, W.: Deep self-taught learning for weakly supervised object localization. In: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, pp. 1377\u20131385 (2017)","DOI":"10.1109\/CVPR.2017.457"},{"key":"1281_CR34","doi-asserted-by":"crossref","unstructured":"Wei, Y., Shen, Z., Cheng, B., Shi, H., Xiong, J., Feng, J., Huang, T.: Ts2c: Tight box mining with surrounding segmentation context for weakly supervised object detection. In: Proceedings of the European Conference on Computer Vision (ECCV), pp. 434\u2013450 (2018).","DOI":"10.1007\/978-3-030-01252-6_27"},{"key":"1281_CR35","doi-asserted-by":"crossref","unstructured":"Dong, X., Meng, D., Ma, F., Yang, Y.: A dual-network progressive approach to weakly supervised object detection. In: Proceedings of the 25th ACM international conference on Multimedia, pp. 279\u2013287 (2017)","DOI":"10.1145\/3123266.3123455"},{"key":"1281_CR36","doi-asserted-by":"crossref","unstructured":"Zhang, H., Kyaw, Z., Yu, J., Chang, S.F. Ppr-fcn: weakly supervised visual relation detection via parallel pairwise r-fcn. In: Proceedings of the IEEE International Conference on Computer Vision, pp. 4233\u20134241 (2017)","DOI":"10.1109\/ICCV.2017.454"},{"key":"1281_CR37","doi-asserted-by":"crossref","unstructured":"Wei, Y., Feng, J., Liang, X., Cheng, M.M., Zhao, Y., Yan, S.: Object region mining with adversarial erasing: A simple classification to semantic segmentation approach. In: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, pp. 1568\u20131576 (2017)","DOI":"10.1109\/CVPR.2017.687"},{"key":"1281_CR38","doi-asserted-by":"crossref","unstructured":"Wei, Y., Xiao, H., Shi, H., Jie, Z., Feng, J., Huang, T.S.: Revisiting dilated convolution: a simple approach for weakly-and semi-supervised semantic segmentation. In: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, pp. 7268\u20137277 (2018)","DOI":"10.1109\/CVPR.2018.00759"},{"issue":"4","key":"1281_CR39","doi-asserted-by":"publisher","first-page":"640","DOI":"10.1109\/TPAMI.2016.2572683","volume":"39","author":"E Shelhamer","year":"2017","unstructured":"Shelhamer, E., Long, J., Darrell, T.: Fully convolutional networks for semantic segmentation. IEEE Trans. Pattern Anal. Mach. Intell. 39(4), 640\u2013651 (2017)","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"1281_CR40","doi-asserted-by":"crossref","unstructured":"Zhou, B., Khosla, A., Lapedriza, A., Oliva, A., Torralba, A.: Learning deep features for discriminative localization. In: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, pp. 2921\u20132929 (2016)","DOI":"10.1109\/CVPR.2016.319"},{"key":"1281_CR41","doi-asserted-by":"crossref","unstructured":"Zhang, X., Wei, Y., Feng, J., Yang, Y., Huang, T.S.: Adversarial complementary learning for weakly supervised object localization. In: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, pp. 1325\u20131334 (2018)","DOI":"10.1109\/CVPR.2018.00144"},{"key":"1281_CR42","doi-asserted-by":"crossref","unstructured":"Choe, J., Shim, H.: Attention-based dropout layer for weakly supervised object localization. In: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, pp. 2219\u20132228 (2019)","DOI":"10.1109\/CVPR.2019.00232"},{"key":"1281_CR43","doi-asserted-by":"crossref","unstructured":"Zhang, X., Wei, Y., Kang, G., Yang, Y., Huang, T.: Self-produced guidance for weakly-supervised object localization. In: Proceedings of the European Conference on Computer Vision (ECCV), pp. 597\u2013613 (2018)","DOI":"10.1007\/978-3-030-01258-8_37"},{"key":"1281_CR44","doi-asserted-by":"crossref","unstructured":"Szegedy, C., Ioffe, S., Vanhoucke, V., Alemi, A.: Inception-v4, inception-resnet and the impact of residual connections on learning. arXiv preprint arXiv:1602.07261 (2016)","DOI":"10.1609\/aaai.v31i1.11231"},{"issue":"3","key":"1281_CR45","doi-asserted-by":"publisher","first-page":"211","DOI":"10.1007\/s11263-015-0816-y","volume":"115","author":"O Russakovsky","year":"2015","unstructured":"Russakovsky, O., Deng, J., Su, H., Krause, J., Satheesh, S., Ma, S., Berg, A.C.: Imagenet large scale visual recognition challenge. Int. J. Comput. Vision 115(3), 211\u2013252 (2015)","journal-title":"Int. J. Comput. Vision"},{"key":"1281_CR46","unstructured":"Papernot, N., Carlini, N., Goodfellow, I., Feinman, R., Faghri, F., Matyasko, A...., Garg, A., Lin, Y. C. Cleverhans v2. 0.0: an adversarial machine learning library (2017)"},{"issue":"3","key":"1281_CR47","doi-asserted-by":"publisher","first-page":"1020","DOI":"10.1002\/asjc.1184","volume":"18","author":"O Tutsoy","year":"2016","unstructured":"Tutsoy, O.: Design and comparison base analysis of adaptive estimator for completely unknown linear systems in the presence of OE noise and constant input time delay. Asian J. Control 18(3), 1020\u20131029 (2016)","journal-title":"Asian J. Control"},{"issue":"10","key":"1281_CR48","first-page":"902","volume":"229","author":"O Tutsoy","year":"2015","unstructured":"Tutsoy, O., Colak, S.: Adaptive estimator design for unstable output error systems: A test problem and traditional system identification based analysis. Proc. Inst. Mech. Engineers Part I: J. Syst. Control Eng. 229(10), 902\u2013916 (2015)","journal-title":"Proc. Inst. Mech. Engineers Part I: J. Syst. Control Eng."},{"key":"1281_CR49","doi-asserted-by":"crossref","unstructured":"Berian, A., Staab, K., Teku, N., Ditzler, G., Bose, T., Tandon, R.: Adversarial Filters for Secure Modulation Classification. arXiv preprint arXiv:2008.06785 (2020)","DOI":"10.1109\/IEEECONF53345.2021.9723329"},{"key":"1281_CR50","unstructured":"Wong, E., Rice, L., Kolter, J.Z.: Fast is better than free: Revisiting adversarial training. arXiv preprint arXiv:2001.03994 (2020)"},{"key":"1281_CR51","unstructured":"Xie, C., Tan, M., Gong, B., Yuille, A., Le, Q.V.: Smooth adversarial training. arXiv preprint arXiv:2006.14536 (2020)"},{"key":"1281_CR52","unstructured":"Xie, C., Wang, J., Zhang, Z., Ren, Z., Yuille, A.: Mitigating adversarial effects through randomization. In: International Conference on Learning Representations (2018)"},{"key":"1281_CR53","doi-asserted-by":"crossref","unstructured":"Xu, W., Evans, D., Qi, Y.: Feature squeezing: detecting adversarial examples in deep neural networks. arXiv preprint arXiv:1704.01155 (2017)","DOI":"10.14722\/ndss.2018.23198"},{"key":"1281_CR54","unstructured":"Liang, B., Li, H., Su, M., Li, X., Shi, W., Wang, X.: Detecting adversarial image examples in deep neural networks with adaptive noise reduction. IEEE Trans. Dependable Secure Comput. (2018)"}],"container-title":["Machine Vision and Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s00138-022-01281-2.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s00138-022-01281-2\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s00138-022-01281-2.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,1,28]],"date-time":"2023-01-28T02:08:21Z","timestamp":1674871701000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s00138-022-01281-2"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,2,28]]},"references-count":54,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2022,3]]}},"alternative-id":["1281"],"URL":"https:\/\/doi.org\/10.1007\/s00138-022-01281-2","relation":{},"ISSN":["0932-8092","1432-1769"],"issn-type":[{"type":"print","value":"0932-8092"},{"type":"electronic","value":"1432-1769"}],"subject":[],"published":{"date-parts":[[2022,2,28]]},"assertion":[{"value":"28 June 2021","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"26 December 2021","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"10 January 2022","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"28 February 2022","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare that they have no competing interests.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}}],"article-number":"34"}}