{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,31]],"date-time":"2025-12-31T00:15:49Z","timestamp":1767140149205,"version":"build-2238731810"},"reference-count":49,"publisher":"Springer Science and Business Media LLC","issue":"4","license":[{"start":{"date-parts":[[2024,7,1]],"date-time":"2024-07-01T00:00:00Z","timestamp":1719792000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,7,1]],"date-time":"2024-07-01T00:00:00Z","timestamp":1719792000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"funder":[{"DOI":"10.13039\/501100012165","name":"Key Technologies Research and Development Program","doi-asserted-by":"publisher","award":["2022YFB4500900"],"award-info":[{"award-number":["2022YFB4500900"]}],"id":[{"id":"10.13039\/501100012165","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Machine Vision and Applications"],"published-print":{"date-parts":[[2024,7]]},"DOI":"10.1007\/s00138-024-01571-x","type":"journal-article","created":{"date-parts":[[2024,7,1]],"date-time":"2024-07-01T21:05:01Z","timestamp":1719867901000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Adversarial defence by learning differentiated feature representation in deep ensemble"],"prefix":"10.1007","volume":"35","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-7711-7387","authenticated-orcid":false,"given":"Xi","family":"Chen","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wei","family":"Huang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wei","family":"Guo","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Fan","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jiayu","family":"Du","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zhizhong","family":"Zhou","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2024,7,1]]},"reference":[{"issue":"3","key":"1571_CR1","doi-asserted-by":"publisher","first-page":"294","DOI":"10.1109\/TIP.2004.838698","volume":"14","author":"RJ Radke","year":"2005","unstructured":"Radke, R.J., Andra, S., Al-Kofahi, O., Roysam, B.: Image change detection algorithms: a systematic survey. IEEE Trans. Image Process. 14(3), 294\u2013307 (2005)","journal-title":"IEEE Trans. Image Process."},{"key":"1571_CR2","doi-asserted-by":"crossref","unstructured":"Schroff, F., Kalenichenko, D., Philbin, J.: Facenet: a unified embedding for face recognition and clustering. In: 2015 IEEE Conference on Computer Vision and Pattern Recognition (CVPR), pp. 815\u2013823 (2015)","DOI":"10.1109\/CVPR.2015.7298682"},{"key":"1571_CR3","doi-asserted-by":"crossref","unstructured":"Prakash, A., Chitta, K., Geiger, A.: Multi-modal fusion transformer for end-to-end autonomous driving. In: 2021 IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR), pp. 7073\u20137083 (2021)","DOI":"10.1109\/CVPR46437.2021.00700"},{"key":"1571_CR4","unstructured":"Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I.J., Fergus, R.: Intriguing properties of neural networks. CoRR arXiv:1312.6199 (2014)"},{"key":"1571_CR5","doi-asserted-by":"publisher","first-page":"14410","DOI":"10.1109\/ACCESS.2018.2807385","volume":"6","author":"N Akhtar","year":"2018","unstructured":"Akhtar, N., Mian, A.: Threat of adversarial attacks on deep learning in computer vision: a survey. IEEE Access 6, 14410\u201314430 (2018)","journal-title":"IEEE Access"},{"key":"1571_CR6","unstructured":"Madry, A., Makelov, A., Schmidt, L., Tsipras, D., Vladu, A.: Towards deep learning models resistant to adversarial attacks (2017)"},{"key":"1571_CR7","unstructured":"Sarkar, S., Bansal, A., Mahbub, U., Chellappa, R.: Upset and angri : Breaking high performance image classifiers (2017)"},{"key":"1571_CR8","doi-asserted-by":"crossref","unstructured":"Moosavi-Dezfooli, S-M., Fawzi, A., Frossard, P.: Deepfool: A simple and accurate method to fool deep neural networks. In: 2016 IEEE Conference on Computer Vision and Pattern Recognition (CVPR), pp. 2574\u20132582 (2016)","DOI":"10.1109\/CVPR.2016.282"},{"key":"1571_CR9","doi-asserted-by":"crossref","unstructured":"Sankaranarayanan, S., Jain, A., Chellappa, R., Lim, S.N.: Regularizing deep networks using efficient layerwise adversarial training (2017)","DOI":"10.1609\/aaai.v32i1.11688"},{"key":"1571_CR10","unstructured":"Grosse, K., Manoharan, P., Papernot, N., Backes, M., Mcdaniel, P.: On the (statistical) detection of adversarial examples (2017)"},{"key":"1571_CR11","doi-asserted-by":"crossref","unstructured":"Ross, A.S., Doshi-Velez, F.: Improving the adversarial robustness and interpretability of deep neural networks by regularizing their input gradients (2017)","DOI":"10.1609\/aaai.v32i1.11504"},{"key":"1571_CR12","doi-asserted-by":"crossref","unstructured":"Attiah, A., Chatterjee, M., Zou, C.C.: A game theoretic approach to model cyber attack and defense strategies. In: 2018 IEEE International Conference on Communications (ICC), pp. 1\u20137 (2018)","DOI":"10.1109\/ICC.2018.8422719"},{"key":"1571_CR13","unstructured":"He, W., Wei, J., Chen, X., Carlini, N., Song, D.: Adversarial example defenses: Ensembles of weak defenses are not strong (2017)"},{"key":"1571_CR14","doi-asserted-by":"crossref","unstructured":"Lu, Z., Hu, H., Huo, S., Li, S.: Ensemble learning methods of adversarial attacks and defenses in computer vision: Recent progress. In: 2021 International Conference on Advanced Computing and Endogenous Security, pp. 1\u201310 (2022)","DOI":"10.1109\/IEEECONF52377.2022.10013347"},{"key":"1571_CR15","unstructured":"Goodfellow, I.J., Shlens, J., Szegedy, C.: Explaining and harnessing adversarial examples. CoRR arXiv:1412.6572 (2015)"},{"key":"1571_CR16","doi-asserted-by":"crossref","unstructured":"Kurakin, A., Goodfellow, I.J., Bengio, S.: Adversarial examples in the physical world. arXiv:1607.02533 (2017)","DOI":"10.1201\/9781351251389-8"},{"key":"1571_CR17","doi-asserted-by":"crossref","unstructured":"Dong, Y., Liao, F., Pang, T., Hu, X., Zhu, J.: Discovering adversarial examples with momentum. arXiv:1710.06081 (2017)","DOI":"10.1109\/CVPR.2018.00957"},{"key":"1571_CR18","unstructured":"Madry, A., Makelov, A., Schmidt, L., Tsipras, D., Vladu, A.: Towards deep learning models resistant to adversarial attacks. arXiv:1706.06083 (2018)"},{"key":"1571_CR19","doi-asserted-by":"crossref","unstructured":"Carlini, N., Wagner, D.A.: Towards evaluating the robustness of neural networks. In: 2017 IEEE Symposium on Security and Privacy (SP), pp. 39\u201357 (2017)","DOI":"10.1109\/SP.2017.49"},{"key":"1571_CR20","unstructured":"Ilyas, A., Engstrom, L., Athalye, A., Lin, J.: Black-box adversarial attacks with limited queries and information. arXiv:1804.08598 (2018)"},{"key":"1571_CR21","unstructured":"Uesato, J., O\u2019Donoghue, B., van\u00a0den Oord, A., Kohli, P.: Adversarial risk and the dangers of evaluating against weak attacks. arXiv:1802.05666 (2018)"},{"key":"1571_CR22","unstructured":"Li, Y., Li, L., Wang, L., Zhang, T., Gong, B.: Nattack: Learning the distributions of adversarial examples for an improved black-box attack on deep neural networks. arXiv:1905.00441 (2019)"},{"key":"1571_CR23","unstructured":"Brendel, W., Rauber, J., Bethge, M.: Decision-based adversarial attacks: Reliable attacks against black-box machine learning models. arXiv:1712.04248 (2018)"},{"key":"1571_CR24","doi-asserted-by":"crossref","unstructured":"Wei, X., Huang, Y., Sun, Y., Yu, J.: Unified adversarial patch for cross-modal attacks in the physical world. In: IEEE\/CVF International Conference on Computer Vision, ICCV 2023, Paris, France, October 1-6, 2023, pp. 4422\u20134431. IEEE (2023)","DOI":"10.1109\/ICCV51070.2023.00410"},{"key":"1571_CR25","unstructured":"Gong, Y., Zhong, Z., Luo, Z., Qu, Y., Ji, R., Jiang, M.: Cross-modality perturbation synergy attack for person re-identification. CoRR, arXiv:2401.10090 (2024)"},{"key":"1571_CR26","unstructured":"Kurakin, A., Goodfellow, I.J., Bengio, S.: Adversarial machine learning at scale. arXiv:1611.01236 (2017)"},{"key":"1571_CR27","doi-asserted-by":"crossref","unstructured":"Ehlers, R.: Formal verification of piece-wise linear feed-forward neural networks. In: ATVA (2017)","DOI":"10.1007\/978-3-319-68167-2_19"},{"key":"1571_CR28","unstructured":"Fischetti, M., Jo, J.: Deep neural networks as 0-1 mixed integer linear programs: A feasibility study. arXiv:1712.06174 (2017)"},{"key":"1571_CR29","unstructured":"Xie, C., Wang, J., Zhang, Z., Ren, Z., Yuille, A.: Mitigating adversarial effects through randomization (2018)"},{"key":"1571_CR30","doi-asserted-by":"crossref","unstructured":"Gong, Y., Huang, L., Chen, L.: Person re-identification method based on color attack and joint defence. In: IEEE\/CVF Conference on Computer Vision and Pattern Recognition Workshops, CVPR Workshops 2022, New Orleans, LA, USA, June 19-20, 2022, pp. 4312\u20134321. IEEE (2022)","DOI":"10.1109\/CVPRW56347.2022.00477"},{"key":"1571_CR31","unstructured":"Ilyas, A., Santurkar, S., Tsipras, D., Engstrom, L., Tran, B., Madry, A.: Adversarial examples are not bugs, they are features. In: NeurIPS (2019)"},{"key":"1571_CR32","unstructured":"Liu, Y., Chen, X., Liu, C., Song, D.X.: Delving into transferable adversarial examples and black-box attacks. arXiv:1611.02770 (2017)"},{"key":"1571_CR33","unstructured":"Pang, T., Xu, K., Chao, D., Ning, C., Zhu, J.: Improving adversarial robustness via promoting ensemble diversity (2019)"},{"key":"1571_CR34","unstructured":"Kariyappa, S., Qureshi, M.K.: Improving adversarial robustness of ensembles with diversity training (2019)"},{"key":"1571_CR35","unstructured":"Tram\u00e8r, F., Kurakin, A., Papernot, N., Goodfellow, I., Boneh, D., Mcdaniel, P.: Ensemble adversarial training: Attacks and defenses (2017)"},{"key":"1571_CR36","doi-asserted-by":"crossref","unstructured":"Qin, R., Wang, L., Chen, X., Du, X., Yan, B.: Dynamic defense approach for adversarial robustness in deep neural networks via stochastic ensemble smoothed model. arXiv:2105.02803 (2021)","DOI":"10.21203\/rs.3.rs-1972947\/v1"},{"key":"1571_CR37","unstructured":"Jiangxing, W.U.: Research on cyber mimic defense. Journal of Cyber Security (2016)"},{"issue":"3","key":"1571_CR38","doi-asserted-by":"publisher","first-page":"226","DOI":"10.1049\/iet-ifs.2017.0086","volume":"12","author":"H Hu","year":"2018","unstructured":"Hu, H., Wu, J., Wang, Z., Cheng, G.: Mimic defense: a designed-in cybersecurity defense framework. IET Inf. Secur. 12(3), 226\u2013237 (2018)","journal-title":"IET Inf. Secur."},{"key":"1571_CR39","unstructured":"Tong, Q., Zhang, Z., Zhang, W.H., Wu, J.X.: Design and implementation of mimic defense web server (2017)"},{"key":"1571_CR40","unstructured":"Ren, H., Yan, W., Wang, Q., Chen, J., Guo, L.: Design and implementation of a distributed storage system for historical substation data. Electrical Automation (2019)"},{"key":"1571_CR41","unstructured":"Hailong, M.A., Yiming, Jiang, Bing, Bai, Jianhui, Zhang: Tests and analyses for mimic defense ability of routers. Journal of Cyber Security (2017)"},{"issue":"6","key":"1571_CR42","doi-asserted-by":"publisher","first-page":"679","DOI":"10.1109\/TPAMI.1986.4767851","volume":"PAMI\u20138","author":"J Canny","year":"1986","unstructured":"Canny, J.: A computational approach to edge detection. IEEE Trans. Pattern Anal. Mach. Intell. PAMI\u20138(6), 679\u2013698 (1986)","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"1571_CR43","doi-asserted-by":"crossref","unstructured":"Ojala, T., Pietik\u00e4inen, M., Harwood, D.: A comparative study of texture measures with classification based on feature distributions. Pattern Recogn. 29(1), 51\u201359 (1996)","DOI":"10.1016\/0031-3203(95)00067-4"},{"issue":"6","key":"1571_CR44","first-page":"610","volume":"SMC\u20133","author":"RM Haralick","year":"1973","unstructured":"Haralick, R.M., Shanmugam, K., Dinstein, I.: Textural features for image classification. Stud. Media Commun. SMC\u20133(6), 610\u2013621 (1973)","journal-title":"Stud. Media Commun."},{"key":"1571_CR45","doi-asserted-by":"crossref","unstructured":"Ribeiro, M.T., Singh, S., Guestrin, C.: \"why should i trust you?\": Explaining the predictions of any classifier. ACM (2016)","DOI":"10.1145\/2939672.2939778"},{"key":"1571_CR46","doi-asserted-by":"crossref","unstructured":"Zhou, B., Khosla, A., Lapedriza, A., Oliva, A., Torralba, A.: Learning deep features for discriminative localization. IEEE Computer Society (2016)","DOI":"10.1109\/CVPR.2016.319"},{"key":"1571_CR47","unstructured":"Kariyappa, S., Qureshi, M.K.: Improving adversarial robustness of ensembles with diversity training. arXiv:1901.09981 (2019)"},{"key":"1571_CR48","doi-asserted-by":"crossref","unstructured":"Moosavidezfooli, S., Fawzi, A., Fawzi, O., Frossard, P.: Universal adversarial perturbations. pp. 86\u201394 (2017)","DOI":"10.1109\/CVPR.2017.17"},{"key":"1571_CR49","doi-asserted-by":"crossref","unstructured":"Huang, B., Ke, Z., Wang, Y., Wang, W., Shen, L., Liu, F.: Adversarial defense by diversified simultaneous training of deep ensembles. In: AAAI (2021)","DOI":"10.1609\/aaai.v35i9.16955"}],"updated-by":[{"DOI":"10.1007\/s00138-024-01583-7","type":"correction","label":"Correction","source":"publisher","updated":{"date-parts":[[2024,7,20]],"date-time":"2024-07-20T00:00:00Z","timestamp":1721433600000}}],"container-title":["Machine Vision and Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s00138-024-01571-x.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s00138-024-01571-x\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s00138-024-01571-x.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,7,31]],"date-time":"2024-07-31T15:31:56Z","timestamp":1722439916000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s00138-024-01571-x"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,7]]},"references-count":49,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2024,7]]}},"alternative-id":["1571"],"URL":"https:\/\/doi.org\/10.1007\/s00138-024-01571-x","relation":{},"ISSN":["0932-8092","1432-1769"],"issn-type":[{"value":"0932-8092","type":"print"},{"value":"1432-1769","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,7]]},"assertion":[{"value":"16 April 2023","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"18 June 2024","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"18 June 2024","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"1 July 2024","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"20 July 2024","order":5,"name":"change_date","label":"Change Date","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"Correction","order":6,"name":"change_type","label":"Change Type","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"A Correction to this paper has been published:","order":7,"name":"change_details","label":"Change Details","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"https:\/\/doi.org\/10.1007\/s00138-024-01583-7","URL":"https:\/\/doi.org\/10.1007\/s00138-024-01583-7","order":8,"name":"change_details","label":"Change Details","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare that they have no competing financial interests.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}},{"value":"We use a publicly available open source dataset.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethical and informed consent for data used"}},{"value":"Yes.","order":4,"name":"Ethics","group":{"name":"EthicsHeading","label":"Consent for data"}}],"article-number":"88"}}