{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,2,21]],"date-time":"2025-02-21T03:23:38Z","timestamp":1740108218831,"version":"3.37.3"},"reference-count":58,"publisher":"Springer Science and Business Media LLC","issue":"4","license":[{"start":{"date-parts":[[2024,7,1]],"date-time":"2024-07-01T00:00:00Z","timestamp":1719792000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,7,1]],"date-time":"2024-07-01T00:00:00Z","timestamp":1719792000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61972439","61976006"],"award-info":[{"award-number":["61972439","61976006"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100003995","name":"Anhui Provincial Natural Science Foundation","doi-asserted-by":"crossref","award":["1808085MF171"],"award-info":[{"award-number":["1808085MF171"]}],"id":[{"id":"10.13039\/501100003995","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Machine Vision and Applications"],"published-print":{"date-parts":[[2024,7]]},"DOI":"10.1007\/s00138-024-01579-3","type":"journal-article","created":{"date-parts":[[2024,7,9]],"date-time":"2024-07-09T19:01:52Z","timestamp":1720551712000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["An adversarial sample detection method based on heterogeneous denoising"],"prefix":"10.1007","volume":"35","author":[{"given":"Lifang","family":"Zhu","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Chao","family":"Liu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zhiqiang","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yifan","family":"Cheng","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Biao","family":"Jie","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3325-3306","authenticated-orcid":false,"given":"Xintao","family":"Ding","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2024,7,9]]},"reference":[{"key":"1579_CR1","doi-asserted-by":"publisher","first-page":"4784","DOI":"10.1109\/JSTARS.2024.3362748","volume":"17","author":"H Gao","year":"2024","unstructured":"Gao, H., Wu, S., Wang, Y., Kim, J.Y., Xu, Y.: FSOD4RSI: Few-shot object detection for remote sensing images via features aggregation and scale attention. IEEE J. Sel. Top. Appl. Earth Observ. Remote Sens. 17, 4784\u20134796 (2024). https:\/\/doi.org\/10.1109\/JSTARS.2024.3362748","journal-title":"IEEE J. Sel. Top. Appl. Earth Observ. Remote Sens."},{"issue":"2","key":"1579_CR2","doi-asserted-by":"publisher","first-page":"19","DOI":"10.1007\/s00138-023-01502-2","volume":"35","author":"R Liao","year":"2024","unstructured":"Liao, R., Zhai, J., Zhang, F.: Optimization model based on attention mechanism for few-shot image classification. Mach. Vis. Appl. 35(2), 19 (2024). https:\/\/doi.org\/10.1007\/s00138-023-01502-2","journal-title":"Mach. Vis. Appl."},{"key":"1579_CR3","doi-asserted-by":"publisher","DOI":"10.1016\/j.imavis.2020.103873","volume":"94","author":"J Chen","year":"2020","unstructured":"Chen, J., Bai, T.: SAANet: Spatial adaptive alignment network for object detection in automatic driving. Image Vis. Comput. 94, 103873 (2020). https:\/\/doi.org\/10.1016\/j.imavis.2020.103873","journal-title":"Image Vis. Comput."},{"issue":"3","key":"1579_CR4","doi-asserted-by":"publisher","first-page":"44","DOI":"10.1007\/s00138-024-01525-3","volume":"35","author":"L Fang","year":"2024","unstructured":"Fang, L., Bowen, S., Jianxi, M., Weixing, S.: YOLOMH: You only look once for multi-task driving perception with high efficiency. Mach. Vis. Appl. 35(3), 44 (2024). https:\/\/doi.org\/10.1007\/s00138-024-01525-3","journal-title":"Mach. Vis. Appl."},{"key":"1579_CR5","unstructured":"Radford, A., Kim, J.W., Xu, T., Brockman, G., Mcleavey, C., Sutskever, I.: Robust speech recognition via large-scale weak supervision. In: 40th International Conference on Machine Learning (ICML), Honolulu, Hawaii, USA, vol. 202, pp. 28492\u201328518 (2023)"},{"key":"1579_CR6","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2024.127585","volume":"584","author":"HF Tolie","year":"2024","unstructured":"Tolie, H.F., Ren, J., Elyan, E.: DICAM: deep inception and channel-wise attention modules for underwater image enhancement. Neurocomputing 584, 127585 (2024). https:\/\/doi.org\/10.1016\/j.neucom.2024.127585","journal-title":"Neurocomputing"},{"issue":"1","key":"1579_CR7","doi-asserted-by":"publisher","first-page":"984","DOI":"10.1109\/TII.2022.3169973","volume":"19","author":"X Ding","year":"2023","unstructured":"Ding, X., Cheng, Y., Luo, Y., Li, Q., Gope, P.: Consensus adversarial defense method based on augmented examples. IEEE Trans. Ind. Inf. 19(1), 984\u2013994 (2023). https:\/\/doi.org\/10.1109\/TII.2022.3169973","journal-title":"IEEE Trans. Ind. Inf."},{"key":"1579_CR8","unstructured":"Goodfellow, I.J., Shlens, J., Szegedy, C.: Explaining and harnessing adversarial examples. In: 3rd International Conference on Learning Representations (ICLR), San Diego, CA, USA (2015)"},{"key":"1579_CR9","doi-asserted-by":"publisher","unstructured":"Dong, Y., Liao, F., Pang, T., Su, H., Zhu, J., Hu, X., Li, J.: Boosting adversarial attacks with momentum. In: 2018 IEEE Conference on Computer Vision and Pattern Recognition (CVPR), Salt Lake City, UT, USA, pp. 9185\u20139193 (2018). https:\/\/doi.org\/10.1109\/CVPR.2018.00957","DOI":"10.1109\/CVPR.2018.00957"},{"key":"1579_CR10","unstructured":"Madry, A., Makelov, A., Schmidt, L., Tsipras, D., Vladu, A.: Towards deep learning models resistant to adversarial attacks. In: 6th International Conference on Learning Representations (ICLR), Vancouver, BC, Canada (2018)"},{"key":"1579_CR11","doi-asserted-by":"publisher","unstructured":"Moosavi-Dezfooli, S.-M., Fawzi, A., Frossard, P.: DeepFool: A simple and accurate method to fool deep neural networks. In: 2016 IEEE Conference on Computer Vision and Pattern Recognition (CVPR), Las Vegas, NV, USA, pp. 2574\u20132582 (2016). https:\/\/doi.org\/10.1109\/CVPR.2016.282","DOI":"10.1109\/CVPR.2016.282"},{"key":"1579_CR12","doi-asserted-by":"publisher","unstructured":"Carlini, N., Wagner, D.: Towards evaluating the robustness of neural networks. In: 2017 IEEE Symposium on Security and Privacy (SP), San Jose, CA, USA, pp. 39\u201357 (2017). https:\/\/doi.org\/10.1109\/SP.2017.49","DOI":"10.1109\/SP.2017.49"},{"issue":"4","key":"1579_CR13","doi-asserted-by":"publisher","first-page":"1725","DOI":"10.1109\/TPAMI.2020.3032061","volume":"44","author":"H Wang","year":"2022","unstructured":"Wang, H., Li, G., Liu, X., Lin, L.: A hamiltonian monte carlo method for probabilistic adversarial attack and learning. IEEE Trans. Pattern Anal. Mach. Intell. 44(4), 1725\u20131737 (2022). https:\/\/doi.org\/10.1109\/TPAMI.2020.3032061","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"1579_CR14","doi-asserted-by":"publisher","unstructured":"Jin, G., Shen, S., Zhang, D., Dai, F., Zhang, Y.: APE-GAN: Adversarial perturbation elimination with GAN. In: IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP), Brighton, United Kingdom, pp. 3842\u20133846 (2019). https:\/\/doi.org\/10.1109\/ICASSP.2019.8683044","DOI":"10.1109\/ICASSP.2019.8683044"},{"key":"1579_CR15","doi-asserted-by":"publisher","unstructured":"Gupta, P., Rahtu, E.: CIIDefence: Defeating adversarial attacks by fusing class-specific image inpainting and image denoising. In: 2019 IEEE International Conference on Computer Vision (ICCV), Seoul, Korea (South), pp. 6708\u20136717 (2019). https:\/\/doi.org\/10.1109\/ICCV.2019.00681","DOI":"10.1109\/ICCV.2019.00681"},{"key":"1579_CR16","doi-asserted-by":"publisher","unstructured":"Zhou, B., Khosla, A., Lapedriza, A., Oliva, A., Torralba, A.: Learning deep features for discriminative localization. In: 2016 IEEE Conference on Computer Vision and Pattern Recognition (CVPR), Las Vegas, NV, USA, pp. 2921\u20132929 (2016). https:\/\/doi.org\/10.1109\/CVPR.2016.319","DOI":"10.1109\/CVPR.2016.319"},{"issue":"2","key":"1579_CR17","doi-asserted-by":"publisher","first-page":"380","DOI":"10.1002\/acs.3529","volume":"37","author":"Z Zhang","year":"2023","unstructured":"Zhang, Z., Song, X., Sun, X., Stojanovic, V.: Hybrid-driven-based fuzzy secure filtering for nonlinear parabolic partial differential equation systems with cyber attacks. Int. J. Adapt. Control Signal Process. 37(2), 380\u2013398 (2023). https:\/\/doi.org\/10.1002\/acs.3529","journal-title":"Int. J. Adapt. Control Signal Process."},{"issue":"14","key":"1579_CR18","doi-asserted-by":"publisher","first-page":"3058","DOI":"10.1002\/rnc.3490","volume":"26","author":"V Stojanovic","year":"2016","unstructured":"Stojanovic, V., Nedic, N.: Joint state and parameter robust estimation of stochastic nonlinear systems. Int. J. Robust Nonlinear Control 26(14), 3058\u20133074 (2016). https:\/\/doi.org\/10.1002\/rnc.3490","journal-title":"Int. J. Robust Nonlinear Control"},{"issue":"3","key":"1579_CR19","doi-asserted-by":"publisher","first-page":"445","DOI":"10.1002\/rnc.3319","volume":"26","author":"V Stojanovic","year":"2016","unstructured":"Stojanovic, V., Nedic, N.: Robust Kalman filtering for nonlinear multivariable stochastic systems in the presence of non-gaussian noise. Int. J. Robust Nonlinear Control 26(3), 445\u2013460 (2016). https:\/\/doi.org\/10.1002\/rnc.3319","journal-title":"Int. J. Robust Nonlinear Control"},{"key":"1579_CR20","doi-asserted-by":"publisher","unstructured":"Selvaraju, R.R., Cogswell, M., Das, A., Vedantam, R., Parikh, D., Batra, D.: Grad-CAM: Visual explanations from deep networks via gradient-based localization. In: 2017 IEEE International Conference on Computer Vision (ICCV), Venice, Italy, pp. 618\u2013626 (2017). https:\/\/doi.org\/10.1109\/ICCV.2017.74","DOI":"10.1109\/ICCV.2017.74"},{"key":"1579_CR21","doi-asserted-by":"crossref","unstructured":"Kurakin, A., Goodfellow, I.J., Bengio, S.: Adversarial examples in the physical world. In: 5th International Conference on Learning Representations (ICLR), Toulon, France (2017)","DOI":"10.1201\/9781351251389-8"},{"key":"1579_CR22","unstructured":"Zhang, H., Yu, Y., Jiao, J., Xing, E.P., Ghaoui, L.E., Jordan, M.I.: Theoretically principled trade-off between robustness and accuracy. In: 36th International Conference on Machine Learning (ICML), Long Beach, California, USA, vol. 97, pp. 7472\u20137482 (2019)"},{"key":"1579_CR23","unstructured":"Wong, E., Rice, L., Kolter, J.Z.: Fast is better than free: Revisiting adversarial training. In: 8th International Conference on Learning Representations (ICLR), Addis Ababa, Ethiopia (2020)"},{"key":"1579_CR24","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2023.109902","volume":"145","author":"D Liu","year":"2024","unstructured":"Liu, D., Wu, L.Y., Li, B., Boussaid, F., Bennamoun, M., Xie, X., Liang, C.: Jacobian norm with selective input gradient regularization for interpretable adversarial defense. Pattern Recogn. 145, 109902 (2024). https:\/\/doi.org\/10.1016\/j.patcog.2023.109902","journal-title":"Pattern Recogn."},{"key":"1579_CR25","doi-asserted-by":"publisher","first-page":"3074","DOI":"10.1109\/TIFS.2023.3274359","volume":"18","author":"Y Zhang","year":"2023","unstructured":"Zhang, Y., Wang, T., Zhao, R., Wen, W., Zhu, Y.: RAPP: Reversible privacy preservation for various face attributes. IEEE Trans. Inf. Forensics Secur. 18, 3074\u20133087 (2023). https:\/\/doi.org\/10.1109\/TIFS.2023.3274359","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"issue":"20","key":"1579_CR26","doi-asserted-by":"publisher","first-page":"18302","DOI":"10.1109\/JIOT.2023.3279440","volume":"10","author":"X Ye","year":"2023","unstructured":"Ye, X., Zhu, Y., Zhang, M., Deng, H.: Differential privacy data release scheme using microaggregation with conditional feature selection. IEEE Internet Things J. 10(20), 18302\u201318314 (2023). https:\/\/doi.org\/10.1109\/JIOT.2023.3279440","journal-title":"IEEE Internet Things J."},{"issue":"3","key":"1579_CR27","doi-asserted-by":"publisher","first-page":"35","DOI":"10.1007\/s00138-024-01519-1","volume":"35","author":"C Eleftheriadis","year":"2024","unstructured":"Eleftheriadis, C., Symeonidis, A., Katsaros, P.: Adversarial robustness improvement for deep neural networks. Mach. Vis. Appl. 35(3), 35 (2024). https:\/\/doi.org\/10.1007\/s00138-024-01519-1","journal-title":"Mach. Vis. Appl."},{"key":"1579_CR28","unstructured":"Tram\u00e8r, F., Kurakin, A., Papernot, N., Goodfellow, I., Boneh, D., McDaniel, P.: Ensemble adversarial training: Attacks and defenses. In: 6th International Conference on Learning Representations (ICLR), Vancouver, BC, Canada (2018)"},{"key":"1579_CR29","unstructured":"Song, C., He, K., Wang, L., Hopcroft, J.E.: Improving the generalization of adversarial training with domain adaptation. In: 7th International Conference on Learning Representations (ICLR), New Orleans, LA, USA (2019)"},{"key":"1579_CR30","doi-asserted-by":"publisher","unstructured":"Xie, C., Wu, Y., Maaten, L., Yuille, A., He, K.: Feature denoising for improving adversarial robustness. In: 2019 IEEE Conference on Computer Vision and Pattern Recognition (CVPR), Long Beach, CA, USA, pp. 501\u2013509 (2019). https:\/\/doi.org\/10.1109\/CVPR.2019.00059","DOI":"10.1109\/CVPR.2019.00059"},{"issue":"9","key":"1579_CR31","doi-asserted-by":"publisher","first-page":"3154","DOI":"10.1109\/TPAMI.2020.2978474","volume":"43","author":"A Mustafa","year":"2020","unstructured":"Mustafa, A., Khan, S.H., Hayat, M., Goecke, R., Shen, J., Shao, L.: Deeply supervised discriminative learning for adversarial defense. IEEE Trans. Pattern Anal. Mach. Intell. 43(9), 3154\u20133166 (2020). https:\/\/doi.org\/10.1109\/TPAMI.2020.2978474","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"1579_CR32","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2020.101916","volume":"96","author":"J Chen","year":"2020","unstructured":"Chen, J., Zheng, H., Chen, R., Xiong, H.: RCA-SOC: A novel adversarial defense by refocusing on critical areas and strengthening object contours. Comput. Secur. 96, 101916 (2020). https:\/\/doi.org\/10.1016\/j.cose.2020.101916","journal-title":"Comput. Secur."},{"issue":"1","key":"1579_CR33","doi-asserted-by":"publisher","first-page":"596","DOI":"10.1109\/TII.2020.2964154","volume":"17","author":"J Zhu","year":"2020","unstructured":"Zhu, J., Peng, G., Wang, D.: Dual-domain-based adversarial defense with conditional VAE and Bayesian network. IEEE Trans. Ind. Inf. 17(1), 596\u2013605 (2020). https:\/\/doi.org\/10.1109\/TII.2020.2964154","journal-title":"IEEE Trans. Ind. Inf."},{"issue":"2","key":"1579_CR34","doi-asserted-by":"publisher","first-page":"576","DOI":"10.1016\/j.jfranklin.2015.12.007","volume":"353","author":"V Stojanovic","year":"2016","unstructured":"Stojanovic, V., Nedic, N.: Robust identification of OE model with constrained output using optimal input design. J. Franklin Inst. 353(2), 576\u2013593 (2016). https:\/\/doi.org\/10.1016\/j.jfranklin.2015.12.007","journal-title":"J. Franklin Inst."},{"key":"1579_CR35","unstructured":"Guo, C., Rana, M., Ciss\u00e9, M., Van Der\u00a0Maaten, L.: Countering adversarial images using input transformations. In: 6th International Conference on Learning Representations (ICLR), Vancouver, BC, Canada (2018)"},{"key":"1579_CR36","unstructured":"Xie, C., Wang, J., Zhang, Z., Ren, Z., Yuille, A.L.: Mitigating adversarial effects through randomization (iclr), Vancouver, BC, Canada. In: 6th International Conference on Learning Representations (2018)"},{"key":"1579_CR37","unstructured":"Song, Y., Kim, T., Nowozin, S., Ermon, S., Kushman, N.: PixelDefend: Leveraging generative models to understand and defend against adversarial examples. In: 6th International Conference on Learning Representations (ICLR), Vancouver, BC, Canada (2018)"},{"key":"1579_CR38","doi-asserted-by":"publisher","unstructured":"Prakash, A., Moran, N., Garber, S., DiLillo, A., Storer, J.: Deflecting adversarial attacks with pixel deflection. In: 2018 IEEE Conference on Computer Vision and Pattern Recognition (CVPR), Salt Lake City, UT, USA, pp. 8571\u20138580 (2018). https:\/\/doi.org\/10.1109\/CVPR.2018.00894","DOI":"10.1109\/CVPR.2018.00894"},{"key":"1579_CR39","unstructured":"Samangouei, P., Kabkab, M., Chellappa, R.: Defense-GAN: Protecting classifiers against adversarial attacks using generative models. In: 6th International Conference on Learning Representations (ICLR), Vancouver, BC, Canada (2018)"},{"key":"1579_CR40","doi-asserted-by":"publisher","unstructured":"Sun, B., Tsai, N., Liu, F., Yu, R., Su, H.: Adversarial defense by stratified convolutional sparse coding. In: 2019 IEEE Conference on Computer Vision and Pattern Recognition (CVPR), Long Beach, CA, USA, pp. 11439\u201311448 (2019). https:\/\/doi.org\/10.1109\/CVPR.2019.01171","DOI":"10.1109\/CVPR.2019.01171"},{"key":"1579_CR41","doi-asserted-by":"publisher","unstructured":"Liao, F., Liang, M., Dong, Y., Pang, T., Hu, X., Zhu, J.: Defense against adversarial attacks using high-level representation guided denoiser. In: 2018 IEEE Conference on Computer Vision and Pattern Recognition (CVPR), Salt Lake City, UT, USA, pp. 1778\u20131787 (2018). https:\/\/doi.org\/10.1109\/CVPR.2018.00191","DOI":"10.1109\/CVPR.2018.00191"},{"issue":"1","key":"1579_CR42","doi-asserted-by":"publisher","first-page":"72","DOI":"10.1109\/TDSC.2018.2874243","volume":"18","author":"B Liang","year":"2018","unstructured":"Liang, B., Li, H., Su, M., Li, X., Shi, W., Wang, X.: Detecting adversarial image examples in deep neural networks with adaptive noise reduction. IEEE Trans. Dependable Secure Comput. 18(1), 72\u201385 (2018). https:\/\/doi.org\/10.1109\/TDSC.2018.2874243","journal-title":"IEEE Trans. Dependable Secure Comput."},{"key":"1579_CR43","doi-asserted-by":"publisher","unstructured":"Deng, J., Dong, W., Socher, R., Li, L.J., Kai, L., Li, F.-F.: ImageNet: A large-scale hierarchical image database. In: 2009 IEEE Conference on Computer Vision and Pattern Recognition (CVPR), Miami, Florida, USA, pp. 248\u2013255 (2009). https:\/\/doi.org\/10.1109\/CVPR.2009.5206848","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"1579_CR44","unstructured":"Vinyals, O., Blundell, C., Lillicrap, T., Kavukcuoglu, K., Wierstra, D.: Matching networks for one shot learning. In: 29th Advances in Neural Information Processing Systems, Barcelona, Spain, pp. 3630\u20133638 (2016)"},{"key":"1579_CR45","unstructured":"Ravi, S., Larochelle, H.: Optimization as a model for few-shot learning. In: 5th International Conference on Learning Representations (ICLR), Toulon, France (2017)"},{"key":"1579_CR46","unstructured":"Krizhevsky, A., Hinton, G.: Learning multiple layers of features from tiny images. Technical report, University of Toronto (2009)"},{"issue":"12","key":"1579_CR47","doi-asserted-by":"publisher","first-page":"10193","DOI":"10.1002\/int.22458","volume":"37","author":"D Ye","year":"2022","unstructured":"Ye, D., Chen, C., Liu, C., Wang, H., Jiang, S.: Detection defense against adversarial attacks with saliency map. Int. J. Intell. Syst. 37(12), 10193\u201310210 (2022). https:\/\/doi.org\/10.1002\/int.22458","journal-title":"Int. J. Intell. Syst."},{"key":"1579_CR48","doi-asserted-by":"publisher","unstructured":"Kuo, C.-W., Ma, C.-Y., Huang, J.-B., Kira, Z.: FeatMatch: Feature-based augmentation for semi-supervised learning. In: 16th European Conference on Computer Vision, Glasgow, UK, pp. 479\u2013495 (2020). https:\/\/doi.org\/10.1007\/978-3-030-58523-5_28","DOI":"10.1007\/978-3-030-58523-5_28"},{"key":"1579_CR49","unstructured":"Metzen, J.H., Genewein, T., Fischer, V., Bischoff, B.: On detecting adversarial perturbations. In: 5th International Conference on Learning Representations (ICLR), Toulon, France (2017)"},{"key":"1579_CR50","doi-asserted-by":"publisher","unstructured":"Arazo, E., Ortego, D., Albert, P., O\u2019Connor, N.E., McGuinness, K.: Pseudo-labeling and confirmation bias in deep semi-supervised learning. In: 2020 International Joint Conference on Neural Networks (IJCNN), Glasgow, United Kingdom, pp. 1\u20138 (2020). https:\/\/doi.org\/10.1109\/IJCNN48605.2020.9207304","DOI":"10.1109\/IJCNN48605.2020.9207304"},{"issue":"2","key":"1579_CR51","doi-asserted-by":"publisher","first-page":"378","DOI":"10.1049\/ipr2.12354","volume":"16","author":"S Gao","year":"2022","unstructured":"Gao, S., Yu, S., Wu, L., Yao, S., Zhou, X.: Detecting adversarial examples by additional evidence from noise domain. IET Image Proc. 16(2), 378\u2013392 (2022). https:\/\/doi.org\/10.1049\/ipr2.12354","journal-title":"IET Image Proc."},{"key":"1579_CR52","doi-asserted-by":"publisher","unstructured":"He, K., Zhang, X., Ren, S., Sun, J.: Deep residual learning for image recognition. In: 2016 IEEE Conference on Computer Vision and Pattern Recognition (CVPR), Las Vegas, NV, USA, pp. 770\u2013778 (2016). https:\/\/doi.org\/10.1109\/CVPR.2016.90","DOI":"10.1109\/CVPR.2016.90"},{"key":"1579_CR53","doi-asserted-by":"publisher","unstructured":"Simonyan, K., Zisserman, A.: Very deep convolutional networks for large-scale image recognition. In: 3rd International Conference on Learning Representations (ICLR), San Diego, CA, USA (2015). https:\/\/doi.org\/10.48550\/arXiv.1409.1556","DOI":"10.48550\/arXiv.1409.1556"},{"key":"1579_CR54","doi-asserted-by":"publisher","unstructured":"Papernot, N., Faghri, F., Carlini, N., Goodfellow, I., Feinman, R., Kurakin, A., Xie, C., Sharma, Y., Brown, T., Roy, A., Matyasko, A., Behzadan, V., Hambardzumyan, K., Zhang, Z., Juang, Y.-L., Li, Z., Sheatsley, R., Garg, A., Uesato, J., Gierke, W., Dong, Y., Berthelot, D., Hendricks, P., Rauber, J., Long, R., McDaniel, P.: Technical report on the cleverhans v2.1.0 adversarial examples library. arXiv:1610.00768 (2016). https:\/\/doi.org\/10.48550\/arXiv.1610.00768","DOI":"10.48550\/arXiv.1610.00768"},{"key":"1579_CR55","doi-asserted-by":"publisher","unstructured":"Lu, J., Issaranon, T., Forsyth, D.: SafetyNet: Detecting and rejecting adversarial examples robustly. In: 2017 IEEE International Conference on Computer Vision (ICCV), Venice, Italy, pp. 446\u2013454 (2017). https:\/\/doi.org\/10.1109\/ICCV.2017.56","DOI":"10.1109\/ICCV.2017.56"},{"key":"1579_CR56","doi-asserted-by":"crossref","unstructured":"Xu, W., Evans, D., Qi, Y.: Feature squeezing: Detecting adversarial examples in deep neural networks. In: 25th Network and Distributed System Security Symposium (NDSS), San Diego, California, USA (2018)","DOI":"10.14722\/ndss.2018.23198"},{"key":"1579_CR57","doi-asserted-by":"publisher","unstructured":"Feinman, R., Curtin, R.R., Shintre, S., Gardner, A.B.: Detecting adversarial samples from artifacts. arXiv:1703.00410 (2017). https:\/\/doi.org\/10.48550\/arXiv.1703.00410","DOI":"10.48550\/arXiv.1703.00410"},{"key":"1579_CR58","doi-asserted-by":"publisher","unstructured":"Carlini, N., Wagner, D.A.: Adversarial examples are not easily detected: Bypassing ten detection methods. In: 10th ACM Workshop on Artificial Intelligence and Security, Dallas, TX, USA, pp. 3\u201314 (2017). https:\/\/doi.org\/10.1145\/3128572.3140444","DOI":"10.1145\/3128572.3140444"}],"container-title":["Machine Vision and Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s00138-024-01579-3.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s00138-024-01579-3\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s00138-024-01579-3.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,7,31]],"date-time":"2024-07-31T19:39:45Z","timestamp":1722454785000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s00138-024-01579-3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,7]]},"references-count":58,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2024,7]]}},"alternative-id":["1579"],"URL":"https:\/\/doi.org\/10.1007\/s00138-024-01579-3","relation":{},"ISSN":["0932-8092","1432-1769"],"issn-type":[{"type":"print","value":"0932-8092"},{"type":"electronic","value":"1432-1769"}],"subject":[],"published":{"date-parts":[[2024,7]]},"assertion":[{"value":"4 March 2023","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"13 May 2024","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"23 June 2024","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"9 July 2024","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors have no Conflict of interest to declare that are relevant to the content of this article.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}},{"value":"This article does not contain any studies with human participants or animals performed by any of the authors.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethics approval"}}],"article-number":"96"}}