{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,12]],"date-time":"2026-05-12T06:50:58Z","timestamp":1778568658788,"version":"3.51.4"},"reference-count":68,"publisher":"Springer Science and Business Media LLC","issue":"24","license":[{"start":{"date-parts":[[2021,7,21]],"date-time":"2021-07-21T00:00:00Z","timestamp":1626825600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2021,7,21]],"date-time":"2021-07-21T00:00:00Z","timestamp":1626825600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Neural Comput &amp; Applic"],"published-print":{"date-parts":[[2022,12]]},"DOI":"10.1007\/s00521-021-06330-x","type":"journal-article","created":{"date-parts":[[2021,7,21]],"date-time":"2021-07-21T15:02:42Z","timestamp":1626879762000},"page":"21567-21582","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":14,"title":["Detect and defense against adversarial examples in deep learning using natural scene statistics and adaptive denoising"],"prefix":"10.1007","volume":"34","author":[{"given":"Anouar","family":"Kherchouche","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6453-8588","authenticated-orcid":false,"given":"Sid Ahmed","family":"Fezza","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wassim","family":"Hamidouche","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2021,7,21]]},"reference":[{"key":"6330_CR1","doi-asserted-by":"crossref","unstructured":"Deng J, Dong W, Socher R, Li LJ, Li K, Fei-Fei L (2009) Imagenet: A large-scale hierarchical image database. In: 2009 IEEE conference on computer vision and pattern recognition, pp. 248\u2013255. Ieee","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"6330_CR2","doi-asserted-by":"crossref","unstructured":"Lin TY, Maire M, Belongie S, Hays J, Perona P, Ramanan D, Doll\u00e1r P, Zitnick CL (2014) Microsoft coco: Common objects in context. In: European conference on computer vision, pp. 740\u2013755. Springer","DOI":"10.1007\/978-3-319-10602-1_48"},{"key":"6330_CR3","unstructured":"Krizhevsky A, Sutskever I, Hinton GE (2012) Imagenet classification with deep convolutional neural networks pp. 1097\u20131105"},{"issue":"11","key":"6330_CR4","doi-asserted-by":"publisher","first-page":"2278","DOI":"10.1109\/5.726791","volume":"86","author":"Y LeCun","year":"1998","unstructured":"LeCun Y, Bottou L, Bengio Y, Haffner P (1998) Gradient-based learning applied to document recognition. Proc IEEE 86(11):2278\u20132324","journal-title":"Proc IEEE"},{"key":"6330_CR5","doi-asserted-by":"crossref","unstructured":"Andor D, Alberti C, Weiss D, Severyn A, Presta A, Ganchev K, Collins M (2016) Globally normalized transition-based neural networks. arXiv preprint arXiv:1603.06042","DOI":"10.18653\/v1\/P16-1231"},{"key":"6330_CR6","doi-asserted-by":"crossref","unstructured":"Cho K, Van\u00a0Merri\u00ebnboer B, Gulcehre C, Bahdanau D, Bougares F, Schwenk H, Bengio Y (2014) Learning phrase representations using rnn encoder-decoder for statistical machine translation. arXiv preprint arXiv:1406.1078","DOI":"10.3115\/v1\/D14-1179"},{"key":"6330_CR7","unstructured":"Ren S, He K, Girshick R, Sun J: Faster r-cnn (2015) Towards real-time object detection with region proposal networks. In: Advances in neural information processing systems, pp. 91\u201399"},{"key":"6330_CR8","doi-asserted-by":"crossref","unstructured":"Hinton G, Deng L, Yu D, Dahl GE, Mohamed Ar, Jaitly N, Senior A, Vanhoucke V, Nguyen P, Sainath TN, et\u00a0al. (2012) Deep neural networks for acoustic modeling in speech recognition: The shared views of four research groups. IEEE Signal processing magazine 29(6), 82\u201397","DOI":"10.1109\/MSP.2012.2205597"},{"key":"6330_CR9","unstructured":"Szegedy C, Zaremba W, Sutskever I, Bruna J, Erhan D, Goodfellow I, Fergus R (2013) Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199"},{"key":"6330_CR10","doi-asserted-by":"crossref","unstructured":"Moosavi-Dezfooli SM, Fawzi A, Fawzi O, Frossard P (2017) Universal adversarial perturbations pp. 1765\u20131773","DOI":"10.1109\/CVPR.2017.17"},{"key":"6330_CR11","unstructured":"Athalye A, Engstrom L, Ilyas A, Kwok K (2017) Synthesizing robust adversarial examples. arXiv preprint arXiv:1707.07397"},{"key":"6330_CR12","unstructured":"Madry A, Makelov A, Schmidt L, Tsipras D, Vlad A (2017) Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083"},{"key":"6330_CR13","doi-asserted-by":"crossref","unstructured":"Xie C, Wu Y, Maaten Lvd, Yuille AL, He K (2019) Feature denoising for improving adversarial robustness pp. 501\u2013509","DOI":"10.1109\/CVPR.2019.00059"},{"key":"6330_CR14","unstructured":"Carlini N, Katz G, Barrett C, Dill DL (2018) Ground-truth adversarial examples"},{"key":"6330_CR15","unstructured":"Kurakin A, Goodfellow I, Bengio S (2016) Adversarial machine learning at scale. arXiv preprint arXiv:1611.01236"},{"key":"6330_CR16","unstructured":"Lee H, Han S, Lee J  (2017) Generative adversarial trainer: Defense to adversarial perturbations with gan. arXiv preprint arXiv:1705.03387"},{"key":"6330_CR17","doi-asserted-by":"crossref","unstructured":"Carlini N, Wagner D (2017) Towardsevaluating the robustness of neural networks pp. 39\u201357","DOI":"10.1109\/SP.2017.49"},{"key":"6330_CR18","doi-asserted-by":"crossref","unstructured":"Meng D, Chen H  Magnet (2017) a two-pronged defense against adversarial examples pp. 135\u2013147","DOI":"10.1145\/3133956.3134057"},{"key":"6330_CR19","doi-asserted-by":"crossref","unstructured":"Carlini N, Wagner, D (2017) Adversarial examples are not easily detected: Bypassing ten detection methods pp. 3\u201314","DOI":"10.1145\/3128572.3140444"},{"key":"6330_CR20","doi-asserted-by":"crossref","unstructured":"Xu W, Evans D, Qi Y (2017) Feature squeezing: Detecting adversarial examples in deep neural networks. arXiv preprint arXiv:1704.01155","DOI":"10.14722\/ndss.2018.23198"},{"key":"6330_CR21","unstructured":"Hendrycks D, Gimpel K (2016) Early methods for detecting adversarial images. arXiv preprint arXiv:1608.00530"},{"key":"6330_CR22","doi-asserted-by":"crossref","unstructured":"Li X, Li F (2017) Adversarial examples detection in deep networks with convolutional filter statistics pp. 5764\u20135772","DOI":"10.1109\/ICCV.2017.615"},{"key":"6330_CR23","doi-asserted-by":"crossref","unstructured":"Ma S, Liu Y, Tao G, Lee WC, Zhang X (2019) Nic: Detecting adversarial samples with neural network invariant checking","DOI":"10.14722\/ndss.2019.23415"},{"key":"6330_CR24","unstructured":"Bhagoji AN, Cullina D, Mittal P (2017)  Dimensionality reduction as a defense against evasion attacks on machine learning classifiers. arXiv preprint arXiv:1704.02654"},{"key":"6330_CR25","unstructured":"Grosse K, Manoharan P, Papernot N, Backes M, McDaniel P (2017) On the (statistical) detection of adversarial examples. arXiv preprint arXiv:1702.06280"},{"key":"6330_CR26","unstructured":"Feinman, R., Curtin, R.R., Shintre, S., Gardner, A.B.: Detecting adversarial samples from artifacts. arXiv preprint arXiv:1703.00410 (2017)"},{"key":"6330_CR27","unstructured":"Ma X, Li B, Wang Y, Erfani SM, Wijewickrema S, Schoenebeck G, Bailey J, et\u00a0al. (2018) Characterizing adversarial subspaces using local intrinsic dimensionality. arXiv preprint arXiv:1801.02613"},{"key":"6330_CR28","doi-asserted-by":"crossref","unstructured":"Lu J, Issaranon T, Forsyth D (2017) Safetynet: Detecting and rejecting adversarial examples robustly pp. 446\u2013454 (2017)","DOI":"10.1109\/ICCV.2017.56"},{"key":"6330_CR29","unstructured":"Eniser HF, Christakis M, W\u00fcstholz V (2020) Raid: Randomized adversarial-input detection for neural networks. arXiv preprint arXiv:200202776"},{"key":"6330_CR30","unstructured":"Sheikholeslami F, Rezaabad AL, Kolter JZ (2021) Provably robust classification of adversarial examples with detection. In: International Conference on Learning Representations"},{"key":"6330_CR31","doi-asserted-by":"crossref","unstructured":"Fezza SA, Bakhti Y, Hamidouche W, Deforges O (2019) Perceptual evaluation of adversarial attacks for cnn-based image classification. In: IEEE Eleventh International Conference on Quality of Multimedia Experience (QoMEX), pp. 1\u20136","DOI":"10.1109\/QoMEX.2019.8743213"},{"key":"6330_CR32","unstructured":"Wiyatno RR, Xu A, Dia O, de\u00a0Berker A (2019) Adversarial examples in modern machine learning: A review. arXiv preprint arXiv:1911.05268"},{"key":"6330_CR33","unstructured":"Goodfellow I, Shlens J, Szegedy C (2014) Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572"},{"key":"6330_CR34","doi-asserted-by":"crossref","unstructured":"Moosavi-Dezfooli S, Fawzi A, Frossard P (2015) Deepfool: a simple and accurate method to fool deep neural networks. arXiv preprint arXiv:1511.04599","DOI":"10.1109\/CVPR.2016.282"},{"key":"6330_CR35","doi-asserted-by":"crossref","unstructured":"Liu X, Hsieh CJ (2019) Rob-gan: Generator, discriminator, and adversarial attacker pp. 11234\u201311243","DOI":"10.1109\/CVPR.2019.01149"},{"key":"6330_CR36","unstructured":"Schmidt L, Santurkar S, Tsipras D, Talwar K, Madry A (2018) Adversarially robust generalization requires more data pp. 5014\u20135026"},{"key":"6330_CR37","unstructured":"Xie C, Wang J, Zhang Z, Ren Z, Yuille AL (2017)  Mitigating adversarial effects through randomization. arXiv preprint arXiv:1711.01991"},{"key":"6330_CR38","unstructured":"Athalye A, Carlini N, Wagner D (2018) Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples. arXiv preprint arXiv:1802.00420"},{"key":"6330_CR39","unstructured":"Gu S, Rigazio L (2014) Towards deep neural network architectures robust to adversarial examples. arXiv preprint arXiv:1412.5068"},{"key":"6330_CR40","doi-asserted-by":"publisher","first-page":"160397","DOI":"10.1109\/ACCESS.2019.2951526","volume":"7","author":"Y Bakhti","year":"2019","unstructured":"Bakhti Y, Fezza SA, Hamidouche W, D\u00e9forges O (2019) Ddsa: a defense against adversarial attacks using deep denoising sparse autoencoder. IEEE Access 7:160397\u2013160407","journal-title":"IEEE Access"},{"key":"6330_CR41","doi-asserted-by":"crossref","unstructured":"Liu X, Cheng M, Zhang H, Hsieh CJ (2018) Towards robust neural networks via random self-ensemble pp. 369\u2013385","DOI":"10.1007\/978-3-030-01234-2_23"},{"key":"6330_CR42","doi-asserted-by":"crossref","unstructured":"Lecuyer M, Atlidakis V, Geambasu R, Hsu D, Jana S (2019) Certified robustness to adversarial examples with differential privacy pp. 656\u2013672","DOI":"10.1109\/SP.2019.00044"},{"key":"6330_CR43","doi-asserted-by":"crossref","unstructured":"Dwork C, Lei J (2009) Differential privacy and robust statistics pp. 371\u2013380 (2009)","DOI":"10.1145\/1536414.1536466"},{"key":"6330_CR44","unstructured":"Li B, Chen C, Wang W, Carin L (2019) Certified adversarial robustness with additive noise pp. 9464\u20139474"},{"key":"6330_CR45","unstructured":"Dhillon GS, Azizzadenesheli K, Lipton ZC, Bernstein J, Kossaifi J, Khanna A, Anandkumar A (2018) Stochastic activation pruning for robust adversarial defense. arXiv preprint arXiv:1803.01442"},{"key":"6330_CR46","unstructured":"Dziugaite GK, Ghahramani Z, Roy DM (2016) A study of the effect of JPG compression on adversarial images. arXiv preprint arXiv:1608.00853"},{"key":"6330_CR47","doi-asserted-by":"crossref","unstructured":"Zantedeschi V, Nicolae MI, Rawat A (2017) Efficient defenses against adversarial attacks pp. 39\u201349","DOI":"10.1145\/3128572.3140449"},{"key":"6330_CR48","unstructured":"Song Y, Kim T, Nowozin S, Ermon S, Kushman N (2017) Pixeldefend: Leveraging generative models to understand and defend against adversarial examples. arXiv preprint arXiv:1710.10766"},{"key":"6330_CR49","unstructured":"Samangouei P, Kabkab M, Chellappa R (2018) Defense-gan: Protecting classifiers against adversarial attacks using generative models. arXiv preprint arXiv:1805.06605"},{"key":"6330_CR50","unstructured":"Buckman J, Roy A, Raffel C, Goodfellow I (2018) Thermometer encoding: One hot way to resist adversarial examples"},{"key":"6330_CR51","unstructured":"Yang Y, Zhang G, Katabi D, Xu Z (2019) Me-net: Towards effective adversarial robustness with matrix estimation. arXiv preprint arXiv:1905.11971"},{"key":"6330_CR52","doi-asserted-by":"crossref","unstructured":"Borkar T, Heide F, Karam L: Defending against universal attacks through selective feature regeneration. In: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, pp 709\u2013719 (2020)","DOI":"10.1109\/CVPR42600.2020.00079"},{"issue":"12","key":"6330_CR53","doi-asserted-by":"publisher","first-page":"4695","DOI":"10.1109\/TIP.2012.2214050","volume":"21","author":"A Mittal","year":"2012","unstructured":"Mittal A, Moorthy AK, Bovik AC (2012) No-reference image quality assessment in the spatial domain. IEEE Trans Image Process 21(12):4695\u20134708","journal-title":"IEEE Trans Image Process"},{"issue":"1","key":"6330_CR54","doi-asserted-by":"publisher","first-page":"52","DOI":"10.1109\/76.350779","volume":"5","author":"K Sharifi","year":"1995","unstructured":"Sharifi K, Leon-Garcia A (1995) Estimation of shape parameter for generalized gaussian distributions in subband decompositions of video. IEEE Trans Circuits Syst Video Technol 5(1):52\u201356","journal-title":"IEEE Trans Circuits Syst Video Technol"},{"key":"6330_CR55","doi-asserted-by":"crossref","unstructured":"Lasmar NE, Stitou Y, Berthoumieu, Y (2009) Multiscale skewed heavy tailed model for texture analysis pp. 2281\u20132284","DOI":"10.1109\/ICIP.2009.5414404"},{"issue":"8","key":"6330_CR56","doi-asserted-by":"publisher","first-page":"2080","DOI":"10.1109\/TIP.2007.901238","volume":"16","author":"K Dabov","year":"2007","unstructured":"Dabov K, Foi A, Katkovnik V, Egiazarian K (2007) Image denoising by sparse 3-d transform-domain collaborative filtering. IEEE Trans Image Process 16(8):2080\u20132095","journal-title":"IEEE Trans Image Process"},{"key":"6330_CR57","doi-asserted-by":"crossref","unstructured":"Bashar F, El-Sakka, MR (2016) Bm3d image denoising using learning-based adaptive hard thresholding. pp. 206\u2013216","DOI":"10.5220\/0005787202040214"},{"key":"6330_CR58","doi-asserted-by":"publisher","first-page":"175","DOI":"10.5201\/ipol.2012.l-bm3d","volume":"2","author":"M Lebrun","year":"2012","unstructured":"Lebrun M (2012) An analysis and implementation of the bm3d image denoising method. Image Process Line 2:175\u2013213","journal-title":"Image Process Line"},{"key":"6330_CR59","doi-asserted-by":"crossref","unstructured":"Mukherjee S, Kottayil NK, Sun X, Cheng I (2019) Cnn-based real-time parameter tuning for optimizing denoising filter performance pp. 112\u2013125","DOI":"10.1007\/978-3-030-27202-9_10"},{"key":"6330_CR60","doi-asserted-by":"crossref","unstructured":"Plotz T, Roth S (2017) Benchmarking denoising algorithms with real photographs. In: Proceedings of the IEEE conference on computer vision and pattern recognition, pp. 1586\u20131595","DOI":"10.1109\/CVPR.2017.294"},{"key":"6330_CR61","unstructured":"Oord Avd, Kalchbrenner N, Kavukcuoglu K (2016) Pixel recurrent neural networks. arXiv preprint arXiv:1601.06759"},{"key":"6330_CR62","doi-asserted-by":"crossref","unstructured":"Cubuk ED, Zoph B, Mane D, Vasudevan V, Le QV (2019) Autoaugment: Learning augmentation strategies from data pp. 113\u2013123","DOI":"10.1109\/CVPR.2019.00020"},{"key":"6330_CR63","unstructured":"Kurakin A (2018) Baseline resnet-v2-50, tiny imagenet. https:\/\/github.com\/tensorflow\/models\/tree\/master\/research\/adversarial_logit_pairing.html"},{"key":"6330_CR64","unstructured":"Hendrycks D, Dietterich TG (2018) Benchmarking neural network robustness to common corruptions and surface variations. arXiv preprint arXiv:1807.01697"},{"key":"6330_CR65","unstructured":"Paperno N, Goodfellow I, Sheatsley R, Feinman R, McDaniel P (2016) cleverhans v1. 0.0: an adversarial machine learning library. arXiv preprint arXiv:1610.0076810"},{"key":"6330_CR66","unstructured":"Carlini N, Athalye A, Papernot N, Brendel W, Rauber J, Tsipras D, Goodfellow I, Madry A, Kurakin A (2019) On evaluating adversarial robustness. arXiv preprint arXiv:190206705"},{"key":"6330_CR67","unstructured":"Tramer F, Carlini N, Brendel W, Madry A (2020) On adaptive attacks to adversarial example defenses. arXiv preprint arXiv:2002.08347"},{"issue":"4","key":"6330_CR68","doi-asserted-by":"publisher","first-page":"600","DOI":"10.1109\/TIP.2003.819861","volume":"13","author":"Z Wang","year":"2004","unstructured":"Wang Z, Bovik AC, Sheikh HR, Simoncelli EP (2004) Image quality assessment: from error visibility to structural similarity. IEEE Trans Image Process 13(4):600\u2013612","journal-title":"IEEE Trans Image Process"}],"container-title":["Neural Computing and Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s00521-021-06330-x.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s00521-021-06330-x\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s00521-021-06330-x.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,11,7]],"date-time":"2022-11-07T19:01:00Z","timestamp":1667847660000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s00521-021-06330-x"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,7,21]]},"references-count":68,"journal-issue":{"issue":"24","published-print":{"date-parts":[[2022,12]]}},"alternative-id":["6330"],"URL":"https:\/\/doi.org\/10.1007\/s00521-021-06330-x","relation":{"is-basis-for":[{"id-type":"doi","id":"10.52843\/cassyni.96ygbl","asserted-by":"object"}]},"ISSN":["0941-0643","1433-3058"],"issn-type":[{"value":"0941-0643","type":"print"},{"value":"1433-3058","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,7,21]]},"assertion":[{"value":"5 December 2020","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"10 July 2021","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"21 July 2021","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare that they have no conflict of interest.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}}]}}