{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,24]],"date-time":"2026-07-24T03:37:59Z","timestamp":1784864279848,"version":"3.55.0"},"reference-count":333,"publisher":"Springer Science and Business Media LLC","issue":"8","license":[{"start":{"date-parts":[[2025,5,3]],"date-time":"2025-05-03T00:00:00Z","timestamp":1746230400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2025,5,3]],"date-time":"2025-05-03T00:00:00Z","timestamp":1746230400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/100018693","name":"HORIZON EUROPE Framework Programme","doi-asserted-by":"publisher","award":["101139198"],"award-info":[{"award-number":["101139198"]}],"id":[{"id":"10.13039\/100018693","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100018693","name":"HORIZON EUROPE Framework Programme","doi-asserted-by":"publisher","award":["101139198"],"award-info":[{"award-number":["101139198"]}],"id":[{"id":"10.13039\/100018693","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100018693","name":"HORIZON EUROPE Framework Programme","doi-asserted-by":"publisher","award":["101139198"],"award-info":[{"award-number":["101139198"]}],"id":[{"id":"10.13039\/100018693","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100018693","name":"HORIZON EUROPE Framework Programme","doi-asserted-by":"publisher","award":["101139198"],"award-info":[{"award-number":["101139198"]}],"id":[{"id":"10.13039\/100018693","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100018693","name":"HORIZON EUROPE Framework Programme","doi-asserted-by":"publisher","award":["101139198"],"award-info":[{"award-number":["101139198"]}],"id":[{"id":"10.13039\/100018693","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100018693","name":"HORIZON EUROPE Framework Programme","doi-asserted-by":"publisher","award":["101139198"],"award-info":[{"award-number":["101139198"]}],"id":[{"id":"10.13039\/100018693","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Artif Intell Rev"],"abstract":"<jats:title>Abstract<\/jats:title>\n          <jats:p>The rapid advancement of Artificial Intelligence (AI), particularly Machine Learning (ML) and Deep Learning (DL), has produced high-performance models widely used in various applications, ranging from image recognition and chatbots to autonomous driving and smart grid systems. However, security threats arise from the vulnerabilities of ML models to adversarial attacks and data poisoning, posing risks such as system malfunctions and decision errors. Meanwhile, data privacy concerns arise, especially with personal data being used in model training, which can lead to data breaches. This paper surveys the Adversarial Machine Learning (AML) landscape in modern AI systems, while focusing on the dual aspects of robustness and privacy. Initially, we explore adversarial attacks and defenses using comprehensive taxonomies. Subsequently, we investigate robustness benchmarks alongside open-source AML technologies and software tools that ML system stakeholders can use to develop robust AI systems. Lastly, we delve into the landscape of AML in four industry fields \u2013automotive, digital healthcare, electrical power and energy systems (EPES), and Large Language Model (LLM)-based Natural Language Processing (NLP) systems\u2013 analyzing attacks, defenses, and evaluation concepts, thereby offering a holistic view of the modern AI-reliant industry and promoting enhanced ML robustness and privacy preservation in the future.<\/jats:p>","DOI":"10.1007\/s10462-025-11147-4","type":"journal-article","created":{"date-parts":[[2025,5,2]],"date-time":"2025-05-02T23:55:18Z","timestamp":1746230118000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":46,"title":["Adversarial machine learning: a review of methods, tools, and critical industry sectors"],"prefix":"10.1007","volume":"58","author":[{"given":"Sotiris","family":"Pelekis","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Thanos","family":"Koutroubas","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Afroditi","family":"Blika","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Anastasis","family":"Berdelis","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Evangelos","family":"Karakolis","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Christos","family":"Ntanos","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Evangelos","family":"Spiliotis","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Dimitris","family":"Askounis","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,5,3]]},"reference":[{"key":"11147_CR1","doi-asserted-by":"publisher","unstructured":"Abadi M, Chu A, Goodfellow I, McMahan HB, Mironov I, Talwar K, Zhang L (2016) Deep learning with differential privacy. In Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, CCS \u201916, page 308-318, New York, NY, USA. Association for Computing Machinery. ISBN 9781450341394. https:\/\/doi.org\/10.1145\/2976749.2978318","DOI":"10.1145\/2976749.2978318"},{"key":"11147_CR2","doi-asserted-by":"publisher","unstructured":"Abdulrahman T, Muhammad I, Usman Z, Erchin S (2021) Robust electricity theft detection against data poisoning attacks in smart grids. IEEE Transactions on Smart Grid, 12(3):2675\u20132684. https:\/\/doi.org\/10.1109\/TSG.2020.3047864","DOI":"10.1109\/TSG.2020.3047864"},{"key":"11147_CR3","unstructured":"Achiam J, Adler S, Agarwal S, Ahmad L, Akkaya I, Aleman FL, Almeida D, Altenschmidt J, Altman S, Anadkat S et\u00a0al. (2023) Gpt-4 technical report."},{"key":"11147_CR4","doi-asserted-by":"publisher","first-page":"156","DOI":"10.1109\/RBME.2020.3013489","volume":"14","author":"Q Adnan","year":"2021","unstructured":"Adnan Q, Junaid Q, Muhammad B, Ala A-F (2021) Secure and robust machine learning for healthcare: a survey. IEEE Rev Biomed Eng 14:156\u2013180. https:\/\/doi.org\/10.1109\/RBME.2020.3013489","journal-title":"IEEE Rev Biomed Eng"},{"issue":"1","key":"11147_CR5","doi-asserted-by":"publisher","first-page":"1953","DOI":"10.1038\/s41598-022-05539-7","volume":"12","author":"M Adnan","year":"2022","unstructured":"Adnan M, Kalra S, Cresswell JC, Taylor GW, Tizhoosh HR (2022) Federated learning and differential privacy for medical image analysis. Sci Rep 12(1):1953","journal-title":"Sci Rep"},{"key":"11147_CR6","doi-asserted-by":"crossref","unstructured":"Agah N, Mohammadi J, Aved A, Ferris D, Cruz EA, Morrone P (2024) Data poisoning: an overlooked threat to power grid resilience, Preprint at\u00a0https:\/\/arxiv.org\/abs\/2407.14684","DOI":"10.1007\/978-3-031-94895-4_20"},{"issue":"12","key":"11147_CR7","doi-asserted-by":"publisher","first-page":"16838","DOI":"10.3390\/s121216838","volume":"12","author":"Z Ahmed","year":"2012","unstructured":"Ahmed Z, Alexander G, Ali IM, Sutharshan R (2012) Non-intrusive load monitoring approaches for disaggregated energy sensing: a survey. Sensors 12(12):16838\u201316866. https:\/\/doi.org\/10.3390\/s121216838","journal-title":"Sensors"},{"key":"11147_CR9","unstructured":"Ahmed S, Yang Z, Mathias H, Pascal B, Mario F, Michael B. (2019) Ml-leaks: model and data independent membership inference attacks and defenses on machine learning models. In Proceedings of the 26th Annual Network and Distributed System Security Symposium (NDSS)"},{"issue":"6","key":"11147_CR8","doi-asserted-by":"publisher","first-page":"4403","DOI":"10.1007\/s10462-021-10125-w","volume":"55","author":"A Ahmed","year":"2022","unstructured":"Ahmed A, Wassim H, Ahmed FS, Olivier D (2022) Adversarial example detection for dnn models: a review and experimental comparison. Artif Intell Rev 55(6):4403\u20134462. https:\/\/doi.org\/10.1007\/s10462-021-10125-w","journal-title":"Artif Intell Rev"},{"key":"11147_CR10","unstructured":"Alayrac J-B, Uesato J, Huang P-S, Fawzi A, Stanforth R, Kohli P (2019) Are labels required for improving adversarial robustness? Adv Neural Inform Process Syst, 32"},{"issue":"1","key":"11147_CR11","doi-asserted-by":"publisher","first-page":"13524","DOI":"10.1038\/s41598-021-93030-0","volume":"11","author":"Z Alexander","year":"2021","unstructured":"Alexander Z, Dmitrii U, Rickmer B, Marcus M, Daniel R, Georgios K (2021) Medical imaging deep learning with differential privacy. Sci Rep 11(1):13524","journal-title":"Sci Rep"},{"key":"11147_CR12","doi-asserted-by":"publisher","unstructured":"Alexey K, Goodfellow IJ, Samy B (2018) Adversarial examples in the physical world. Artif Intell Safety Secur. https:\/\/doi.org\/10.1201\/9781351251389-8","DOI":"10.1201\/9781351251389-8"},{"key":"11147_CR13","unstructured":"Altstidl T, Dobre D, Eskofier B, Gidel G, Schwinn L (2023) Raising the bar for certified adversarial robustness with diffusion models. Preprint at\u00a0https:\/\/arxiv.org\/abs\/2305.10388"},{"key":"11147_CR14","unstructured":"Amini S, Teymoorianfard M, Ma S, Houmansadr A (2024) Meansparse: post-training robustness enhancement through mean-centered feature sparsification. Preprint at\u00a0https:\/\/arxiv.org\/abs\/2406.05927"},{"key":"11147_CR15","doi-asserted-by":"crossref","unstructured":"Andriushchenko M, Croce F, Flammarion N, Hein M (2020) Square attack: a query-efficient black-box adversarial attack via random search. In Andrea Vedaldi, Horst Bischof, Thomas Brox, and Jan-Michael Frahm, editors, Computer Vision\u2014ECCV 2020, pp. 484\u2013501, Cham. Springer International Publishing. ISBN 978-3-030-58592-1","DOI":"10.1007\/978-3-030-58592-1_29"},{"key":"11147_CR16","unstructured":"Anonymous (2022) Towards bridging the gap between empirical and certified robustness against adversarial examples. Submitted to Transactions on Machine Learning Research, https:\/\/openreview.net\/forum?id=AhXLqWh0LH."},{"key":"11147_CR17","doi-asserted-by":"publisher","DOI":"10.3390\/electronics10172132","author":"KD Apostolidis","year":"2021","unstructured":"Apostolidis KD, Papakostas GA (2021) A survey on adversarial deep learning robustness in medical image analysis. Electronics. https:\/\/doi.org\/10.3390\/electronics10172132","journal-title":"Electronics"},{"key":"11147_CR18","unstructured":"Arpit D, Jastrz\u0119bski S, Ballas Ns, Krueger D, Bengio E, Kanwal MS, Maharaj T, Fischer A, Courville A, Bengio Y, Lacoste-Julien (2017) A closer look at memorization in deep networks. In Doina P and Yee\u00a0WT, editors, Proceedings of the 34th International Conference on Machine Learning, volume\u00a070 of Proceedings of Machine Learning Research, pages 233\u2013242. PMLR, 06\u201311. https:\/\/proceedings.mlr.press\/v70\/arpit17a.html"},{"key":"11147_CR19","unstructured":"Athalye A, Engstrom L, Ilyas A, Kwok K (2018) Synthesizing robust adversarial examples. In Jennifer D and Andreas K, eds, Proceedings of the 35th International Conference on Machine Learning, volume\u00a080 of Proceedings of Machine Learning Research, pages 284\u2013293. PMLR, 10\u201315. URL https:\/\/proceedings.mlr.press\/v80\/athalye18b.html"},{"key":"11147_CR20","unstructured":"Atzmon M, Haim N, Yariv L, Israelov O, Maron H, Lipman Y (2019) Controlling neural level sets. Adv Neural Inform Process Syst, 32"},{"key":"11147_CR21","unstructured":"Bagdasaryan E, Veit A, Hua Y, Estrin D, Shmatikov V (2020) How to backdoor federated learning. In Silvia C and Roberto C, eds, Proceedings of the Twenty Third International Conference on Artificial Intelligence and Statistics, volume 108 of Proceedings of Machine Learning Research, pages 2938\u20132948. PMLR, 26\u201328. https:\/\/proceedings.mlr.press\/v108\/bagdasaryan20a.html"},{"key":"11147_CR24","unstructured":"Bai Y, Jones A, Ndousse K, Askell A, Chen A, DasSarma N, Drain D, Fort S, Ganguli D, Henighan T et\u00a0al. (2022) Training a helpful and harmless assistant with reinforcement learning from human feedback. arXiv e-prints, pages arXiv\u20132204"},{"key":"11147_CR22","unstructured":"Bai Y, Anderson BG, Kim A, Sojoudi S (2024a) Improving the accuracy-robustness trade-off of classifiers via adaptive smoothing. Preprint at\u00a0https:\/\/arxiv.org\/abs\/2301.12554"},{"key":"11147_CR23","unstructured":"Bai Y, Zhou M, Patel VM, Sojoudi S (2024b) Mixednuts: training-free accuracy-robustness balance via nonlinearly mixed classifiers. Preprint at\u00a0https:\/\/arxiv.org\/abs\/2402.02263"},{"key":"11147_CR25","unstructured":"Bartoldson BR, Diffenderfer J, Parasyris K, Kailkhura B (2024) Adversarial robustness limits via scaling-law and human-alignment studies. Preprint at\u00a0https:\/\/arxiv.org\/abs\/2404.09349"},{"key":"11147_CR26","doi-asserted-by":"publisher","first-page":"317","DOI":"10.1016\/j.patcog.2018.07.023","volume":"84","author":"B Battista","year":"2018","unstructured":"Battista B, Fabio R (2018) Wild patterns: ten years after the rise of adversarial machine learning. Pattern Recogn 84:317\u2013331. https:\/\/doi.org\/10.1016\/j.patcog.2018.07.023","journal-title":"Pattern Recogn"},{"key":"11147_CR27","doi-asserted-by":"crossref","unstructured":"Blika A, Palmos S, Doukas G, Lamprou V, Pelekis S, Kontoulis M, Ntanos C, Askounis D (2024) Federated learning for enhanced cybersecurity and trustworthiness in 5g and 6g networks: a comprehensive survey. IEEE Open J Commun Soc","DOI":"10.1109\/OJCOMS.2024.3449563"},{"key":"11147_CR29","doi-asserted-by":"publisher","unstructured":"Boloor A, He X, Gill C, Vorobeychik Y, Zhang X (2019) Simple physical adversarial examples against end-to-end autonomous driving models. In 2019 IEEE International Conference on Embedded Software and Systems (ICESS), pp. 1\u20137. https:\/\/doi.org\/10.1109\/ICESS.2019.8782514","DOI":"10.1109\/ICESS.2019.8782514"},{"key":"11147_CR28","doi-asserted-by":"publisher","first-page":"101766","DOI":"10.1016\/j.sysarc.2020.101766","volume":"110","author":"A Boloor","year":"2020","unstructured":"Boloor A, Garimella K, He X, Gill C, Vorobeychik Y, Zhang X (2020) Attacking vision-based perception in end-to-end autonomous driving models. J Syst Architecture 110:101766","journal-title":"J Syst Architecture"},{"key":"11147_CR30","doi-asserted-by":"crossref","unstructured":"Borgnia E, Cherepanova V, Fowl L, Ghiasi A, Geiping J, Goldblum M, Goldstein T, Gupta A (2020) Strong data augmentation sanitizes poisoning and backdoor attacks without an accuracy tradeoff. Preprint at\u00a0https:\/\/arxiv.org\/abs\/2011.09527","DOI":"10.1109\/ICASSP39728.2021.9414862"},{"key":"11147_CR31","doi-asserted-by":"publisher","first-page":"234","DOI":"10.1016\/j.jbi.2014.04.003","volume":"50","author":"JW Bos","year":"2014","unstructured":"Bos JW, Lauter K, Naehrig M (2014) Private predictive analysis on encrypted medical data. J Biomed Inform 50:234\u2013243. https:\/\/doi.org\/10.1016\/j.jbi.2014.04.003","journal-title":"J Biomed Inform"},{"key":"11147_CR32","unstructured":"Brendel W, Rauber J, Bethge M (2018) Decision-based adversarial attacks: reliable attacks against black-box machine learning models. In International Conference on Learning Representations. https:\/\/openreview.net\/forum?id=SyZI0GWCZ"},{"key":"11147_CR33","doi-asserted-by":"publisher","first-page":"59","DOI":"10.1016\/j.ijmedinf.2018.01.007","volume":"112","author":"TS Brisimi","year":"2018","unstructured":"Brisimi TS, Chen R, Mela T, Olshevsky A, Paschalidis IC, Shi W (2018) Federated learning of predictive models from federated electronic health records. Int J Med Inform 112:59\u201367. https:\/\/doi.org\/10.1016\/j.ijmedinf.2018.01.007","journal-title":"Int J Med Inform"},{"key":"11147_CR34","unstructured":"Buckman J, Roy A, Raffel C, Goodfellow I (2018) Thermometer encoding: one hot way to resist adversarial examples. In International Conference on Learning Representations. https:\/\/openreview.net\/forum?id=S18Su--CW"},{"key":"11147_CR35","doi-asserted-by":"publisher","first-page":"1","DOI":"10.59275\/j.melba.2021-df47","volume":"1","author":"F Caliv\u00e1","year":"2021","unstructured":"Caliv\u00e1 F, Cheng K, Shah R, Pedoia V (2021) Adversarial robust training of deep learning mri reconstruction models. Mach Learn Biomed Imaging 1:1\u201332. https:\/\/doi.org\/10.59275\/j.melba.2021-df47","journal-title":"Mach Learn Biomed Imaging"},{"key":"11147_CR36","doi-asserted-by":"publisher","first-page":"123","DOI":"10.1109\/SP.2017.49","volume":"10","author":"N Carlini","year":"2017","unstructured":"Carlini N, Wagner D (2017a) Towards evaluating the robustness of neural networks. 2017 IEEE Symp Secur Privacy (SP) 10:123. https:\/\/doi.org\/10.1109\/SP.2017.49","journal-title":"2017 IEEE Symp Secur Privacy (SP)"},{"key":"11147_CR37","doi-asserted-by":"publisher","unstructured":"Carlini N, Wagner D (2017b) Adversarial examples are not easily detected: bypassing ten detection methods. In Proceedings of the 10th ACM Workshop on Artificial Intelligence and Security, AISec \u201917, page 3-14, New York, NY, USA. Association for Computing Machinery. ISBN 9781450352024. https:\/\/doi.org\/10.1145\/3128572.3140444","DOI":"10.1145\/3128572.3140444"},{"key":"11147_CR38","unstructured":"Carlini N, Athalye A, Papernot N, Brendel W, Rauber J (2019) Dimitris Tsipras. Aleksander Madry, and Alexey Kurakin. On evaluating adversarial robustness, Ian Goodfellow"},{"key":"11147_CR39","unstructured":"Carlini N, Hayes J, Nasr M, Jagielski M, Sehwag V, Tram\u00e8r F, Balle B, Ippolito D, Wallace E (2023) Extracting training data from diffusion models. In 32nd USENIX Security Symposium (USENIX Security 23), pp. 5253\u20135270, Anaheim, CA. USENIX Association. ISBN 978-1-939133-37-3. https:\/\/www.usenix.org\/conference\/usenixsecurity23\/presentation\/carlini"},{"key":"11147_CR40","unstructured":"Carmon Yair, Raghunathan Aditi, Schmidt Ludwig, Duchi John\u00a0C, Liang Percy\u00a0S (2019) Unlabeled data improves adversarial robustness. Adv Neural Inform Process Syst, 32"},{"key":"11147_CR41","unstructured":"Carmon Y, Raghunathan A, Schmidt L, Liang P, Duchi JC (2022) Unlabeled data improves adversarial robustness, Preprint at\u00a0https:\/\/arxiv.org\/abs\/1905.13736"},{"key":"11147_CR42","unstructured":"Chao P, Robey A, Dobriban E, Hassani H, Pappas GJ, Wong E (2023) Jailbreaking black box large language models in twenty queries. In R0-FoMo:Robustness of Few-shot and Zero-shot Learning in Large Foundation Models. URL https:\/\/openreview.net\/forum?id=rYWD5TMaLj"},{"key":"11147_CR43","unstructured":"Chawin S, Arjun Nitin B, Arsalan M, Mung C, Prateek M (2018a) Deceiving autonomous cars with toxic signs, Darts"},{"key":"11147_CR44","unstructured":"Chawin S, Arjun Nitin B, Arsalan M, Mung C, Prateek M (2018b) Deceiving traffic sign recognition with malicious ads and logos, Rogue signs"},{"key":"11147_CR49","doi-asserted-by":"publisher","unstructured":"Chen P-Y, Zhang H, Sharma Y, Yi J, Hsieh C-J (2017) Zoo: zeroth order optimization based black-box attacks to deep neural networks without training substitute models. In Proceedings of the 10th ACM Workshop on Artificial Intelligence and Security, AISec \u201917, page 15-26, New York, NY, USA. Association for Computing Machinery. ISBN 9781450352024. https:\/\/doi.org\/10.1145\/3128572.3140448","DOI":"10.1145\/3128572.3140448"},{"key":"11147_CR45","unstructured":"Chen B, Carvalho W, Baracaldo N, Ludwig H, Edwards B, Lee T, Molloy I, Srivastava B (2018a) Detecting backdoor attacks on deep neural networks by activation clustering. Preprint at\u00a0arXiv:1811.03728"},{"key":"11147_CR46","unstructured":"Chen B, Carvalho W, Baracaldo N, Ludwig H, Edwards B, Lee T, Molloy I, Srivastava B (2018b) Detecting backdoor attacks on deep neural networks by activation clustering. Preprint at\u00a0https:\/\/arxiv.org\/abs\/1811.03728"},{"key":"11147_CR50","doi-asserted-by":"crossref","unstructured":"Chen P-Y, Sharma Y, Zhang H, Yi J, Hsieh C-J (2018c) Ead: elastic-net attacks to deep neural networks via adversarial examples. In Proceedings of the Thirty-Second AAAI Conference on Artificial Intelligence and Thirtieth Innovative Applications of Artificial Intelligence Conference and Eighth AAAI Symposium on Educational Advances in Artificial Intelligence, AAAI\u201918\/IAAI\u201918\/EAAI\u201918. AAAI Press. ISBN 978-1-57735-800-8","DOI":"10.1609\/aaai.v32i1.11302"},{"key":"11147_CR52","doi-asserted-by":"publisher","unstructured":"Chen Y, Tan Y, Deka D (2018d) Is machine learning in power systems vulnerable? In 2018 IEEE International Conference on Communications, Control, and Computing Technologies for Smart Grids (SmartGridComm), pp. 1\u20136. https:\/\/doi.org\/10.1109\/SmartGridComm.2018.8587547","DOI":"10.1109\/SmartGridComm.2018.8587547"},{"key":"11147_CR51","doi-asserted-by":"crossref","unstructured":"Chen S-T, Cornelius C, Martin J, Horng\u00a0(Polo) CD (2019a) Shapeshifter: robust physical adversarial attack on faster r-cnn object detector. In Michele Berlingerio, Francesco Bonchi, Thomas G\u00e4rtner, Neil Hurley, and Georgiana Ifrim, editors, Machine Learning and Knowledge Discovery in Databases, pp. 52\u201368, Cham. Springer International Publishing. ISBN 978-3-030-10925-7","DOI":"10.1007\/978-3-030-10925-7_4"},{"key":"11147_CR53","doi-asserted-by":"publisher","unstructured":"Chen Y, Tan Y, Zhang B (2019b) Exploiting vulnerabilities of load forecasting through adversarial attacks. In Proceedings of the Tenth ACM International Conference on Future Energy Systems, e-Energy \u201919, pp. 1-11, New York, Association for Computing Machinery. ISBN 9781450366717. https:\/\/doi.org\/10.1145\/3307772.3328314","DOI":"10.1145\/3307772.3328314"},{"key":"11147_CR47","doi-asserted-by":"crossref","unstructured":"Chen C, Qin C, Qiu H, Ouyang C, Wang S, Chen L, Tarroni G, Bai W, Rueckert D (2020a) Realistic adversarial data augmentation for mr image segmentation. In Anne\u00a0L. Martel, Purang Abolmaesumi, Danail Stoyanov, Diana Mateus, Maria\u00a0A. Zuluaga, S.\u00a0Kevin Zhou, Daniel Racoceanu, and Leo Joskowicz, editors, Medical Image Computing and Computer Assisted Intervention\u2013 MICCAI 2020, pp. 667\u2013677, Cham. Springer International Publishing. ISBN 978-3-030-59710-8","DOI":"10.1007\/978-3-030-59710-8_65"},{"key":"11147_CR48","doi-asserted-by":"publisher","unstructured":"Chen J, Jordan MI, Wainwright MJ (2020b) Hopskipjumpattack: a query-efficient decision-based attack. In 2020 IEEE Symposium on Security and Privacy (SP), pp. 1277\u20131294. https:\/\/doi.org\/10.1109\/SP40000.2020.00045","DOI":"10.1109\/SP40000.2020.00045"},{"key":"11147_CR54","unstructured":"Cheng K, Caliv\u00e1 F, Shah R, Han M, Majumdar S, Pedoia V (2020) Addressing the false negative problem of deep learning mri reconstruction models by adversarial attacks and robust training. In Tal A, Ismail BA, Marleen de\u00a0B, Maxime D, Herve L, and Christopher P (eds), Proceedings of the Third Conference on Medical Imaging with Deep Learning, volume 121 of Proceedings of Machine Learning Research, pp. 121\u2013135. PMLR, 06\u201308. URL https:\/\/proceedings.mlr.press\/v121\/cheng20a.html"},{"key":"11147_CR55","unstructured":"Cisse M, Adi Y, Neverova N, Keshet J (2017a) Houdini: fooling deep structured visual and speech recognition models with adversarial examples. In Proceedings of the 31st International Conference on Neural Information Processing Systems, NIPS\u201917, page 6980-6990, Red Hook. Curran Associates Inc"},{"key":"11147_CR56","unstructured":"Cisse M, Bojanowski P, Grave E, Dauphin Y, Usunier N (2017b) Parseval networks: improving robustness to adversarial examples. In Doina Precup and Yee\u00a0Whye Teh, editors, Proceedings of the 34th International Conference on Machine Learning, volume\u00a070 of Proceedings of Machine Learning Research, pp. 854\u2013863\u00a0https:\/\/proceedings.mlr.press\/v70\/cisse17a.html"},{"key":"11147_CR57","unstructured":"Clarysse J, H\u00f6rrmann J, Yang F (2023) Why adversarial training can hurt robust accuracy. In The Eleventh International Conference on Learning Representations. https:\/\/openreview.net\/forum?id=-CA8yFkPc7O"},{"key":"11147_CR58","unstructured":"Cohen J, Rosenfeld E, Kolter JZ (2019a) Certified adversarial robustness via randomized smoothing. Preprint at\u00a0http:\/\/arxiv.org\/abs\/1902.02918"},{"key":"11147_CR59","unstructured":"Cohen J, Rosenfeld E, Kolter Z (2019b) Certified adversarial robustness via randomized smoothing. In Kamalika Chaudhuri and Ruslan Salakhutdinov, eds, Proceedings of the 36th International Conference on Machine Learning, volume\u00a097 of Proceedings of Machine Learning Research, pp. 1310\u20131320. PMLR, 09\u201315.\u00a0https:\/\/proceedings.mlr.press\/v97\/cohen19c.html"},{"key":"11147_CR60","unstructured":"Commission European (2024) Eu artificial intelligence act | final draft. 1. URL https:\/\/artificialintelligenceact.eu\/the-act\/"},{"key":"11147_CR61","doi-asserted-by":"publisher","unstructured":"Cretu GF, Stavrou A, Locasto ME, Stolfo SJ, Keromytis AD (2008) Casting out demons: sanitizing training data for anomaly sensors. In 2008 IEEE Symposium on Security and Privacy (sp 2008), pp. 81\u201395. https:\/\/doi.org\/10.1109\/SP.2008.11","DOI":"10.1109\/SP.2008.11"},{"key":"11147_CR62","unstructured":"Croce F, Hein M (2020a) Minimally distorted adversarial examples with a fast adaptive boundary attack. In Hal\u00a0Daum\u00e9 III and Aarti Singh, editors, Proceedings of the 37th International Conference on Machine Learning, volume 119 of Proceedings of Machine Learning Research, pp. 2196\u20132205. PMLR, 13\u201318. URL https:\/\/proceedings.mlr.press\/v119\/croce20a.html"},{"key":"11147_CR63","unstructured":"Croce F, Hein M (2020b) Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks. In Hal\u00a0Daum\u00e9 III and Aarti Singh, editors, Proceedings of the 37th International Conference on Machine Learning, volume 119 of Proceedings of Machine Learning Research, pages 2206\u20132216. PMLR, 13\u201318. https:\/\/proceedings.mlr.press\/v119\/croce20b.html"},{"key":"11147_CR64","unstructured":"Croce F, Andriushchenko M, Sehwag V, Debenedetti E, Flammarion N, Chiang M, Mittal P, Hein M (2020) Robustbench: a standardized adversarial robustness benchmark. https:\/\/github.com\/RobustBench\/robustbench"},{"key":"11147_CR65","unstructured":"Croce F, Andriushchenko M, Sehwag V, Debenedetti E, Flammarion N, Chiang M, Mittal P, Hein M (2021) Robustbench: a standardized adversarial robustness benchmark. In Thirty-fifth Conference on Neural Information Processing Systems Datasets and Benchmarks Track (Round 2). https:\/\/openreview.net\/forum?id=SSKZPJCt7B"},{"key":"11147_CR66","doi-asserted-by":"publisher","first-page":"102808","DOI":"10.1016\/j.jnca.2020.102808","volume":"170","author":"L Cui","year":"2020","unstructured":"Cui L, Qu Y, Gao L, Xie G, Yu S (2020) Detecting false data attacks using machine learning techniques in smart grid: a survey. J Network Comput Appl 170:102808","journal-title":"J Network Comput Appl"},{"key":"11147_CR67","unstructured":"Cui J, Tian Z, Zhong Z, Qi X, Yu B, Zhang H (2024) Decoupled kullback-leibler divergence loss. Preprint at\u00a0https:\/\/arxiv.org\/abs\/2305.13948"},{"key":"11147_CR68","unstructured":"Das N, Shanbhogue M, Chen S-T, Hohman F, Chen L, Kounavis ME (2017) Protecting and vaccinating deep learning with jpeg compression, Keeping the bad guys out"},{"key":"11147_CR69","doi-asserted-by":"crossref","unstructured":"Deng J, Dong W, Socher R, Li L-J, Li K, Fei-FL (2009) Imagenet: a large-scale hierarchical image database. In 2009 IEEE conference on computer vision and pattern recognition, pages 248\u2013255. IEEE","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"11147_CR70","doi-asserted-by":"publisher","unstructured":"Deng Y, Zheng X, Zhang T, Chen C, Lou G, Kim M (2020) An analysis of adversarial attacks and defenses on autonomous driving models. In 2020 IEEE International Conference on Pervasive Computing and Communications (PerCom), pp. 1\u201310. https:\/\/doi.org\/10.1109\/PerCom45495.2020.9127389","DOI":"10.1109\/PerCom45495.2020.9127389"},{"issue":"8","key":"11147_CR71","doi-asserted-by":"publisher","first-page":"9961","DOI":"10.1109\/TITS.2021.3096854","volume":"23","author":"F Di","year":"2022","unstructured":"Di F, Ali H, Waslander Steven L, Klaus D (2022) A review and comparative study on probabilistic object detection in autonomous driving. IEEE Trans Intell Transp Syst 23(8):9961\u20139980. https:\/\/doi.org\/10.1109\/TITS.2021.3096854","journal-title":"IEEE Trans Intell Transp Syst"},{"key":"11147_CR72","unstructured":"Ding GW, Sharma Y, Lui KYC, Huang R (2018) Mma training: direct input space margin maximization through adversarial training. Preprint at\u00a0arXiv:1812.02637"},{"key":"11147_CR73","unstructured":"Ding GW, Wang L, Jin X (2019a) advertorch v0.1: an adversarial robustness toolbox based on pytorch"},{"key":"11147_CR74","doi-asserted-by":"crossref","unstructured":"Ding S, Tian Y, Xu F, Li Q, Zhong S (2019b) Trojan attack on deep generative models in autonomous driving. In Songqing Chen, Kim-Kwang\u00a0Raymond Choo, Xinwen Fu, Wenjing Lou, and Aziz Mohaisen, editors, Security and Privacy in Communication Networks, pages 299\u2013318, Cham. Springer International Publishing. ISBN 978-3-030-37228-6","DOI":"10.1007\/978-3-030-37228-6_15"},{"issue":"5","key":"11147_CR75","doi-asserted-by":"publisher","first-page":"7659","DOI":"10.1109\/JIOT.2019.2903312","volume":"6","author":"Yao Donghuan","year":"2019","unstructured":"Donghuan Yao, Mi Wen, Xiaohui Liang, Zipeng Fu, Kai Zhang, Baojia Yang (2019) Energy theft detection with energy privacy preservation in the smart grid. IEEE Internet Things J 6(5):7659\u20137669. https:\/\/doi.org\/10.1109\/JIOT.2019.2903312","journal-title":"IEEE Internet Things J"},{"key":"11147_CR76","doi-asserted-by":"crossref","unstructured":"Dwork C (2006) Differential privacy. In Michele B, Bart P, Vladimiro S, Ingo W, (eds), Automata, Languages and Programming, pages 1\u201312, Berlin, Heidelberg. Springer Berlin Heidelberg. ISBN 978-3-540-35908-1","DOI":"10.1007\/11787006_1"},{"key":"11147_CR77","unstructured":"Eurostat (2024) Use of artificial intelligence in enterprises, https:\/\/ec.europa.eu\/eurostat\/statistics-explained\/index.php?title=Use_of_arti\u200bf\u200bi\u200bcial_intelligence_in_enterprises"},{"key":"11147_CR78","doi-asserted-by":"publisher","unstructured":"Eykholt K, Evtimov I, Fernandes E, Li B, Rahmati A, Xiao C, Prakash A, Kohno T, Song D (2018) Robust physical-world attacks on deep learning visual classification. In 2018 IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp. 1625\u20131634. https:\/\/doi.org\/10.1109\/CVPR.2018.00175","DOI":"10.1109\/CVPR.2018.00175"},{"key":"11147_CR79","unstructured":"Fang M, Cao X, Jia J, Gong N (2020) Local model poisoning attacks to Byzantine-Robust federated learning. In 29th USENIX Security Symposium (USENIX Security 20), pp. 1605\u20131622. USENIX Association. https:\/\/www.usenix.org\/conference\/usenixsecurity20\/presentation\/fang"},{"key":"11147_CR80","doi-asserted-by":"publisher","DOI":"10.1101\/2022.03.09.483666","author":"N Ferruz","year":"2022","unstructured":"Ferruz N, Schmidt S, H\u00f6cker B (2022) A deep unsupervised language model for protein design. bioRxiv. https:\/\/doi.org\/10.1101\/2022.03.09.483666","journal-title":"bioRxiv"},{"key":"11147_CR82","doi-asserted-by":"publisher","unstructured":"Finlayson SG, Chung HW, Kohane IS, Beam AL (2018) Adversarial attacks against medical deep learning systems. Preprint at\u00a0arXiv:1804.05296. https:\/\/doi.org\/10.48550\/arXiv.1804.05296","DOI":"10.48550\/arXiv.1804.05296"},{"issue":"6433","key":"11147_CR81","doi-asserted-by":"publisher","first-page":"1287","DOI":"10.1126\/science.aaw4399","volume":"363","author":"SG Finlayson","year":"2019","unstructured":"Finlayson SG, Bowers JD, Joichi I, Zittrain JL, Beam AL, Kohane IS (2019) Adversarial attacks on medical machine learning. Science 363(6433):1287\u20131289. https:\/\/doi.org\/10.1126\/science.aaw4399","journal-title":"Science"},{"key":"11147_CR83","doi-asserted-by":"crossref","unstructured":"FitzGerald JGM, Hench C, Peris C, Mackie S, Rottmann K, Sanchez A, Nash A, Urbach L, Kakarala V, Singh R, Ranganath S, Crist L, Britan M, Leeuwis W, Tur G, Natarajan P(2023) Massive: A 1m-example multilingual natural language understanding dataset with 51 typologically-diverse languages. In ACL 2023. https:\/\/www.amazon.science\/publications\/massive-a-1m-example-multilingual-natural-language-understanding-dataset-with-51-typologically-diverse-languages","DOI":"10.18653\/v1\/2023.acl-long.235"},{"key":"11147_CR85","unstructured":"Fredrikson M, Lantz E, Jha S, Lin S, Page D, Ristenpart T (2014) Privacy in pharmacogenetics: An End-to-End case study of personalized warfarin dosing. In 23rd USENIX Security Symposium (USENIX Security 14), pp. 17\u201332, San Diego, USENIX Association. https:\/\/www.usenix.org\/conference\/usenixsecurity14\/technical-sessions\/presentation\/fredrikson_matthew"},{"key":"11147_CR84","doi-asserted-by":"publisher","unstructured":"Fredrikson M, Jha S, Ristenpart T (2015) Model inversion attacks that exploit confidence information and basic countermeasures. In Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security, CCS \u201915, pp. 1322-1333, New York, Association for Computing Machinery. https:\/\/doi.org\/10.1145\/2810103.2813677","DOI":"10.1145\/2810103.2813677"},{"issue":"3","key":"11147_CR86","doi-asserted-by":"publisher","first-page":"1027","DOI":"10.1016\/j.patcog.2009.08.022","volume":"43","author":"J Galbally","year":"2010","unstructured":"Galbally J, McCool C, Fierrez J, Marcel S, Ortega-Garcia J (2010) On the vulnerability of face verification systems to hill-climbing attacks. Pattern Recogn 43(3):1027\u20131038. https:\/\/doi.org\/10.1016\/j.patcog.2009.08.022","journal-title":"Pattern Recogn"},{"key":"11147_CR87","doi-asserted-by":"publisher","unstructured":"Georgios K, Alexander Z, Jonathan P-P, Th\u00e9o R, Dmitrii U, Andrew T, Ion\u00e9sio L, Mancuso JV, Friederike J, Marc-Matthias S, Andreas S, Makowski MR, Daniel R, Braren RF (2021) Nature Mach Intell 3:473\u2013484. https:\/\/doi.org\/10.1038\/s42256-021-00337-8","DOI":"10.1038\/s42256-021-00337-8"},{"key":"11147_CR88","unstructured":"Goodfellow IJ, Shlens J, Szegedy C(2015) Explaining and harnessing adversarial examples"},{"key":"11147_CR89","unstructured":"Google Research (2024a) Tensorflow federated. https:\/\/www.tensorflow.org\/federated. Accessed 26 Sep 2024"},{"key":"11147_CR90","unstructured":"Google Research (2024b) Tensorflow privacy | responsible ai toolkit. https:\/\/www.tensorflow.org\/responsible_ai\/privacy\/guide. Accessed 26 Sep 2024"},{"key":"11147_CR91","unstructured":"Gowal S, Dvijotham K, Stanforth R, Bunel R, Qin C, Uesato J, Arandjelovic R, Mann T, Kohli P (2018) On the effectiveness of interval bound propagation for training verifiably robust models. Preprint at\u00a0arXiv:1810.12715"},{"key":"11147_CR92","unstructured":"Gowal S, Qin C, Uesato J, Mann T, Kohli P (2021a) Uncovering the limits of adversarial training against norm-bounded adversarial examples. Preprint at https:\/\/arxiv.org\/abs\/2010.03593"},{"key":"11147_CR93","unstructured":"Gowal S, Rebuffi S-A, Wiles O, Stimberg F, Calian DA, Mann TA (2021b) Improving robustness using generated data. In M.\u00a0Ranzato, A.\u00a0Beygelzimer, Y.\u00a0Dauphin, P.S. Liang, and J.\u00a0Wortman Vaughan, editors, Adv Neural Inform Process Syst, 34, 4218\u20134233. Curran Associates, Inc.,. https:\/\/proceedings.neurips.cc\/paper_files\/paper\/2021\/file\/21ca6d0cf2f25c4dbb35d8dc0b679c3f-Paper.pdf"},{"key":"11147_CR94","doi-asserted-by":"crossref","unstructured":"Graepel T, Lauter K, Naehrig M (2013) Ml confidential: machine learning on encrypted data. In Taekyoung K, Mun-Kyu L, Daesung K, eds, Information Security and Cryptology \u2013 ICISC 2012, pages 1\u201321, Berlin, Heidelberg. Springer Berlin Heidelberg","DOI":"10.1007\/978-3-642-37682-5_1"},{"key":"11147_CR95","unstructured":"Gu S, Rigazio L (2015) Towards deep neural network architectures robust to adversarial examples"},{"key":"11147_CR96","unstructured":"Gu T, Dolan-Gavitt B, Garg S (2017) Badnets: Identifying vulnerabilities in the machine learning model supply chain. CoRR, Preprint athttp:\/\/arxiv.org\/abs\/1708.06733"},{"key":"11147_CR97","unstructured":"Guo C, Rana M, Cisse M, van\u00a0der ML (2018) Countering adversarial images using input transformations. In International Conference on Learning Representations. https:\/\/openreview.net\/forum?id=SyJ7ClWCb"},{"key":"11147_CR98","doi-asserted-by":"publisher","first-page":"206009","DOI":"10.1109\/ACCESS.2020.3030235","volume":"8","author":"Cheng Guohua","year":"2020","unstructured":"Guohua Cheng, Hongli Ji (2020) Adversarial perturbation on mri modalities in brain tumor segmentation. IEEE Access 8:206009\u2013206015. https:\/\/doi.org\/10.1109\/ACCESS.2020.3030235","journal-title":"IEEE Access"},{"key":"11147_CR99","first-page":"1459","volume":"2024","author":"H Hai","year":"2024","unstructured":"Hai H, Zhengyu Z, Michael B, Yun S, Yang Z (2024) Composite backdoor attacks against large language models. Findings Assoc Comput Linguist: NAACL 2024:1459\u20131472","journal-title":"Findings Assoc Comput Linguist: NAACL"},{"key":"11147_CR100","unstructured":"Hall AJ, Jay M, Cebere T, Cebere B, van\u00a0der Veen Koen\u00a0L, Muraru G, Xu T, Cason P, Abramson W, Benaissa A, Shah C, Aboudib A, Ryffel T, Prakash K, Titcombe T, Khare VK, Shang M, Junior I, Gupta A, Paumier J, Kang N, Manannikov V, Trask A(2021) Syft 0.5: A platform for universally deployable structured transparency"},{"key":"11147_CR101","unstructured":"Hamon R, Junklewitz H, and Sanchez\u00a0Martin JI (2020) Robustness and explainability of artificial intelligence. JRC Publications Repository, 1(KJ-NA-30040-EN-N (online)). ISSN 1831-9424"},{"key":"11147_CR102","doi-asserted-by":"publisher","DOI":"10.1016\/j.egyr.2021.11.026","author":"J Hao","year":"2022","unstructured":"Hao J, Tao Y (2022) Adversarial attacks on deep learning models in smart grids. Energy Rep. https:\/\/doi.org\/10.1016\/j.egyr.2021.11.026","journal-title":"Energy Rep"},{"key":"11147_CR103","unstructured":"He W, Wei J, Chen X, Carlini N, Song D (2017) Adversarial example defense: Ensembles of weak defenses are not strong. In 11th USENIX Workshop on Offensive Technologies (WOOT 17), Vancouver, BC. USENIX Association. https:\/\/www.usenix.org\/conference\/woot17\/workshop-program\/presentation\/he"},{"key":"11147_CR104","doi-asserted-by":"publisher","unstructured":"He Z, Zhang T, Lee RB (2019) Model inversion attacks against collaborative inference. In Proceedings of the 35th Annual Computer Security Applications Conference, ACSAC \u201919, page 148-162, New York,\u00a0https:\/\/doi.org\/10.1145\/3359789.3359824","DOI":"10.1145\/3359789.3359824"},{"key":"11147_CR106","unstructured":"Hendrycks D, Mazeika M, Wilson D, Gimpel K (2018) Using trusted data to train deep networks on labels corrupted by severe noise. In S.\u00a0Bengio, H.\u00a0Wallach, H.\u00a0Larochelle, K.\u00a0Grauman, N.\u00a0Cesa-Bianchi, and R.\u00a0Garnett, editors, Advances in Neural Information Processing Systems, volume\u00a031. Curran Associates, Inc. https:\/\/proceedings.neurips.cc\/paper_files\/paper\/2018\/file\/ad554d8c3b06d6b97ee76a2448bd7913-Paper.pdf"},{"key":"11147_CR105","unstructured":"Hendrycks D, Dietterich T (2019) Benchmarking neural network robustness to common corruptions and perturbations. In International Conference on Learning Representations, https:\/\/openreview.net\/forum?id=HJz6tiCqYm"},{"key":"11147_CR107","unstructured":"Hendrycks D, Lee K, Mazeika M (2019) Using pre-training can improve model robustness and uncertainty. In International conference on machine learning, pp. 2712\u20132721. PMLR"},{"key":"11147_CR108","unstructured":"High-Level Expert\u00a0Group on\u00a0AI (2019) Ethics guidelines for trustworthy ai | shaping europe\u2019s digital future. 8\u00a0https:\/\/digital-strategy.ec.europa.eu\/en\/library\/ethics-guidelines-trustworthy-ai"},{"key":"11147_CR109","unstructured":"Hinton G, Vinyals O, Dean J (2015a) Distilling the knowledge in a neural network. https:\/\/arxiv.org\/abs\/1503.02531"},{"key":"11147_CR110","unstructured":"Hinton G, Vinyals O, Dean J (2015b) Distilling the knowledge in a neural network. In NIPS Deep Learning and Representation Learning Workshop. Preprint at\u00a0http:\/\/arxiv.org\/abs\/1503.02531"},{"key":"11147_CR111","doi-asserted-by":"publisher","first-page":"123","DOI":"10.1145\/3523273","volume":"10","author":"H Hu","year":"2022","unstructured":"Hu H, Salcic Z, Sun L, Dobbie G, Yu PS, Zhang X (2022) Membership inference attacks on machine learning: a survey. ACM Comput Surv 10:123. https:\/\/doi.org\/10.1145\/3523273","journal-title":"ACM Comput Surv"},{"key":"11147_CR112","first-page":"21024","volume":"33","author":"Z Huan","year":"2020","unstructured":"Huan Z, Hongge C, Chaowei X, Bo L, Mingyan L, Duane B, Cho-Jui H (2020) Robust deep reinforcement learning against adversarial perturbations on state observations. Adv Neural Inf Process Syst 33:21024\u201321037","journal-title":"Adv Neural Inf Process Syst"},{"key":"11147_CR113","unstructured":"Hubinger E, Denison C, Mu J, Lambert M, Tong M, MacDiarmid M, Lanham T, Ziegler DM, Maxwell T, Cheng N, et\u00a0al (2024) Sleeper agents: training deceptive llms that persist through safety training. arXiv e-prints, pages arXiv\u20132401"},{"key":"11147_CR114","first-page":"285","volume-title":"Andreas Holzinger, Peter Kieseberg, A Min Tjoa, and Edgar Weippl","author":"R Huma","year":"2019","unstructured":"Huma R, Andreas E, Rudolf M (2019) Backdoor attacks in neural networks-a systematic evaluation on multiple traffic sign datasets. In: Learning M, Extraction K (eds) Andreas Holzinger, Peter Kieseberg, A Min Tjoa, and Edgar Weippl. Springer International Publishing, Cham, pp 285\u2013300"},{"key":"11147_CR115","doi-asserted-by":"publisher","unstructured":"Huq A, Pervin MT(2020) Analysis of adversarial attacks on skin cancer recognition. In 2020 International Conference on Data Science and Its Applications (ICoDSA), pp. 1\u20134. https:\/\/doi.org\/10.1109\/ICoDSA50139.2020.9212850","DOI":"10.1109\/ICoDSA50139.2020.9212850"},{"key":"11147_CR116","unstructured":"IBM (2023) Ibm global ai adoption index 2022. https:\/\/www.ibm.com\/watson\/resources\/ai-adoption"},{"key":"11147_CR117","unstructured":"IBM (2024) Ibm global ai adoption index 2023. URL https:\/\/newsroom.ibm.com\/2024-01-10-Data-Suggests-Growth-in-Enterprise-Adoption-of-AI-is-Due-to-Widespread-Deployment-by-Early-Adopters"},{"key":"11147_CR118","doi-asserted-by":"publisher","first-page":"35411","DOI":"10.1109\/ACCESS.2021.3057525","volume":"9","author":"Y Ibrahim","year":"2021","unstructured":"Ibrahim Y, Ambareen S (2021) Avoiding occupancy detection from smart meter using adversarial machine learning. IEEE Access 9:35411\u201335430. https:\/\/doi.org\/10.1109\/ACCESS.2021.3057525","journal-title":"IEEE Access"},{"key":"11147_CR119","unstructured":"Jain N, Schwarzschild A, Wen Y, Somepalli G, Kirchenbauer J, Chiang P-y, Goldblum M, Saha A, Geiping J, Goldstein T(2023) Baseline defenses for adversarial attacks against aligned language models. arXiv e-prints, pages arXiv\u20132309"},{"key":"11147_CR120","doi-asserted-by":"publisher","unstructured":"Jia J, Ahmed S, Michael B, Yang Z, Neil\u00a0ZG(2019) Memguard: Defending against black-box membership inference attacks via adversarial examples. In Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security, CCS \u201919, page 259-274, New York, NY, USA. Association for Computing Machinery.\u00a0https:\/\/doi.org\/10.1145\/3319535.3363201","DOI":"10.1145\/3319535.3363201"},{"issue":"5","key":"11147_CR121","doi-asserted-by":"publisher","first-page":"828","DOI":"10.1109\/TEVC.2019.2890858","volume":"23","author":"S Jiawei","year":"2019","unstructured":"Jiawei S, Vargas DV, Sakurai K (2019) One pixel attack for fooling deep neural networks. IEEE Trans Evol Comput 23(5):828\u2013841. https:\/\/doi.org\/10.1109\/TEVC.2019.2890858","journal-title":"IEEE Trans Evol Comput"},{"key":"11147_CR122","doi-asserted-by":"publisher","unstructured":"Jin G, Shen S, Zhang D, Dai F, Zhang Y(2019) Ape-gan: adversarial perturbation elimination with gan. In ICASSP 2019 - 2019 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP), pp. 3842\u20133846. https:\/\/doi.org\/10.1109\/ICASSP.2019.8683044","DOI":"10.1109\/ICASSP.2019.8683044"},{"key":"11147_CR123","volume-title":"Mehrtash Harandi, and Li Li","author":"W Jing","year":"2021","unstructured":"Jing W, Mingyi Z, Ce Z, Yipeng L (2021) Mehrtash Harandi, and Li Li. Discrepancies and solutions, Performance evaluation of adversarial attacks"},{"key":"11147_CR124","doi-asserted-by":"publisher","unstructured":"Juuti M, Szyller S, Marchal S, Asokan N (2019). Prada: protecting against dnn model stealing attacks. In 2019 IEEE European Symposium on Security and Privacy (EuroS &P), pp. 512\u2013527. https:\/\/doi.org\/10.1109\/EuroSP.2019.00044","DOI":"10.1109\/EuroSP.2019.00044"},{"issue":"1\u20132","key":"11147_CR125","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1561\/2200000083","volume":"14","author":"P Kairouz","year":"2021","unstructured":"Kairouz P, McMahan HB, Avent B, Bellet A, Bennis M, Bhagoji AN, Bonawitz K, Charles Z, Cormode G, Cummings R, D\u2019Oliveira RG (2021) Advances and open problems in federated learning. Found Trends Mach Learn 14(1\u20132):1\u2013210. https:\/\/doi.org\/10.1561\/2200000083","journal-title":"Found Trends Mach Learn"},{"key":"11147_CR126","doi-asserted-by":"crossref","unstructured":"Kang H-B (2013) Various approaches for driver and driving behavior monitoring: A review. In Proceedings of the IEEE International Conference on Computer Vision (ICCV) Workshops","DOI":"10.1109\/ICCVW.2013.85"},{"key":"11147_CR127","unstructured":"Karakolis E, Pelekis S, Mouzakitis S, Markaki O, Papapostolou K, Korbakis G, Psarras J (2022) Artificial intelligence for next generation energy services across europe - the i-nergy project. In ES 2021 : 19th International Conference e-Society 2021, pp. 61\u201368. https:\/\/cordis.europa.eu\/project\/id\/101016508"},{"key":"11147_CR128","doi-asserted-by":"crossref","unstructured":"Karakolis E, Pelekis S, Mouzakitis S, Kormpakis G, Michalakopoulos V, Psarras J (2023) The i-nergy reference architecture for the provision of next generation energy services through artificial intelligence. In International Conferences e-Society 2023 and Mobile Learning 2023, pp. 95\u2013102","DOI":"10.33965\/ES_ML2023_202302L012"},{"key":"11147_CR129","doi-asserted-by":"crossref","unstructured":"Karan S, Azizi ST, Tao MS, Sara WJ, Won CH, NS, Ajay T, Heather C-L, Stephen P et al (2023) Publisher correction: Large language models encode clinical knowledge. Nature 620(7973):E19\u2013E19","DOI":"10.1038\/s41586-023-06455-0"},{"key":"11147_CR130","doi-asserted-by":"crossref","unstructured":"Katz G, Barrett C, Dill DL, Julian K, Kochenderfer MJ (2017a) Reluplex: an efficient smt solver for verifying deep neural networks. In Rupak Majumdar and Viktor Kun\u010dak, editors, Computer Aided Verification, pages 97\u2013117, Cham. Springer International Publishing","DOI":"10.1007\/978-3-319-63387-9_5"},{"key":"11147_CR131","doi-asserted-by":"crossref","unstructured":"Katz G, Barrett C, Dill DL, Julian K, Kochenderfer MJ (2017b) Towards proving the adversarial robustness of deep neural networks. In Lukas B, Maryam K, Sven L, editors, Proceedings of the First Workshop on Formal Verification of Autonomous Vehicles (FVAV \u201917), volume 257 of Electronic Proceedings in Theoretical Computer Science, pages 19\u201326. URL http:\/\/eptcs.web.cse.unsw.edu.au\/paper.cgi?FVAV2017.3. Turin, Italy","DOI":"10.4204\/EPTCS.257.3"},{"key":"11147_CR132","doi-asserted-by":"publisher","first-page":"61","DOI":"10.1109\/OJITS.2022.3142612","volume":"3","author":"A Kloukiniotis","year":"2022","unstructured":"Kloukiniotis A, Papandreou A, Lalos A, Kapsalas P, Nguyen D-V, Moustakas K (2022) Countering adversarial attacks on autonomous vehicles using denoising techniques: a review. IEEE Open J Intell Transport Syst 3:61\u201380. https:\/\/doi.org\/10.1109\/OJITS.2022.3142612","journal-title":"IEEE Open J Intell Transport Syst"},{"key":"11147_CR133","unstructured":"Knott B, Venkataraman S, Hannun A, Sengupta S, Ibrahim M, van\u00a0der Maaten L(2021) Crypten: Secure multi-party computation meets machine learning. In M.\u00a0Ranzato, A.\u00a0Beygelzimer, Y.\u00a0Dauphin, P.S. Liang, and J.\u00a0Wortman Vaughan, editors, Advances in Neural Information Processing Systems, 34: 4961\u20134973. Curran Associates, Inc., https:\/\/proceedings.neurips.cc\/paper_files\/paper\/2021\/file\/2754518221cfbc8d25c13a06a4cb8421-Paper.pdf"},{"key":"11147_CR134","doi-asserted-by":"crossref","unstructured":"Kong Z, Guo J, Li A, Liu C(2020) Physgan: generating physical-world-resilient adversarial examples for autonomous driving. In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR)","DOI":"10.1109\/CVPR42600.2020.01426"},{"key":"11147_CR135","doi-asserted-by":"publisher","unstructured":"Kormpakis G, Kapsalis P, Alexakis K, Pelekis S, Karakolis E, Doukas H (2022) An advanced visualisation engine with role-based access control for building energy visual analytics. In 2022 13th International Conference on Information, Intelligence, Systems & Applications (IISA), pp. 1\u20138. IEEE. https:\/\/doi.org\/10.1109\/IISA56318.2022.9904353. https:\/\/ieeexplore.ieee.org\/document\/9904353\/","DOI":"10.1109\/IISA56318.2022.9904353"},{"key":"11147_CR136","doi-asserted-by":"publisher","unstructured":"Kormpakis G, Kapsalis P, Alexakis K, Mylona Z, Pelekis S, Marinakis V (2023) Energy sector digitilisation: A security framework application for role-based access management. In 2023 14th International Conference on Information, Intelligence, Systems & Applications (IISA), pp. 1\u201310. https:\/\/doi.org\/10.1109\/IISA59645.2023.10345842","DOI":"10.1109\/IISA59645.2023.10345842"},{"key":"11147_CR137","doi-asserted-by":"crossref","unstructured":"Kotia J, Kotwal A, Bharti R (2020) Risk susceptibility of brain tumor classification to adversarial attacks. In Aleksandra G, Tadeusz C, Sebastian D, Katarzyna H, Agnieszka P, eds, Man-Machine Interactions 6, pp. 181\u2013187, Cham. Springer International Publishing","DOI":"10.1007\/978-3-030-31964-9_17"},{"key":"11147_CR138","doi-asserted-by":"publisher","unstructured":"Koundinya AK, Patil S\u00a0S, Chandu B\u00a0R (2024) Data poisoning attacks in cognitive computing. In 2024 IEEE 9th International Conference for Convergence in Technology (I2CT), pp. 1\u20134. https:\/\/doi.org\/10.1109\/I2CT61223.2024.10544345","DOI":"10.1109\/I2CT61223.2024.10544345"},{"key":"11147_CR139","doi-asserted-by":"publisher","first-page":"100681","DOI":"10.1016\/j.simpa.2024.100681","volume":"21","author":"B Kousik","year":"2024","unstructured":"Kousik B, Sanjay M (2024) Adversarial attack defense analysis: an empirical approach in cybersecurity perspective. Softw Impacts 21:100681","journal-title":"Softw Impacts"},{"key":"11147_CR141","unstructured":"Kumar RSS (2019) David O Brien. Salom\u00e9 Vilj\u00f6en, and Jeffrey Snover. Failure modes in machine learning systems, Kendra Albert"},{"key":"11147_CR140","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1007\/s13735-023-00310-8","volume":"13","author":"P Kumar","year":"2024","unstructured":"Kumar P (2024) Adversarial attacks and defenses for large language models (llms): methods, frameworks & challenges. Int J Multimed Inform Retrieval 13:1\u201328","journal-title":"Int J Multimed Inform Retrieval"},{"key":"11147_CR142","unstructured":"Kurakin A, Goodfellow IJ, Bengio S(2017) Adversarial machine learning at scale. In International Conference on Learning Representations. https:\/\/openreview.net\/forum?id=BJm4T4Kgx"},{"key":"11147_CR143","doi-asserted-by":"publisher","unstructured":"Kurita K, Michel P, Neubig G(2020) Weight poisoning attacks on pretrained models. In Dan Jurafsky, Joyce Chai, Natalie Schluter, and Joel Tetreault, editors, Proceedings of the 58th Annual Meeting of the Association for Computational Linguistics, pp. 2793\u20132806, Association for Computational Linguistics. https:\/\/doi.org\/10.18653\/v1\/2020.acl-main.249. URL https:\/\/aclanthology.org\/2020.acl-main.249","DOI":"10.18653\/v1\/2020.acl-main.249"},{"key":"11147_CR144","unstructured":"K\u00fcgler D, Bucher A, Kleemann J, Distergoft A, Jabhe A, Uecker M, Kazeminia S, Fauser J, Alte D, Rajkarnikar A, Kuijper A, Weberschock T, Meissner M, Vogl T, Mukhopadhyay A (2019) Physical attacks in dermoscopy: an evaluation of robustness for clinical deep-learning.\u00a0https:\/\/openreview.net\/forum?id=Byl6W7WeeN"},{"key":"11147_CR145","doi-asserted-by":"publisher","unstructured":"Lecuyer M, Atlidakis V, Geambasu R, Hsu D, Jana S(2019) Certified robustness to adversarial examples with differential privacy. In 2019 IEEE Symposium on Security and Privacy (SP), pp. 656\u2013672. https:\/\/doi.org\/10.1109\/SP.2019.00044","DOI":"10.1109\/SP.2019.00044"},{"key":"11147_CR146","doi-asserted-by":"publisher","unstructured":"Lederer I, Mayer R, Rauber A(2023) Identifying appropriate intellectual property protection mechanisms for machine learning models: a systematization of watermarking, fingerprinting, model access, and attacks. IEEE Transactions on Neural Networks and Learning Systems, pp. 1\u201319. https:\/\/doi.org\/10.1109\/TNNLS.2023.3270135","DOI":"10.1109\/TNNLS.2023.3270135"},{"key":"11147_CR147","unstructured":"Lee K, Lee K, Lee H, Shin J(2018) A simple unified framework for detecting out-of-distribution samples and adversarial attacks. In S.\u00a0Bengio, H.\u00a0Wallach, H.\u00a0Larochelle, K.\u00a0Grauman, N.\u00a0Cesa-Bianchi, and R.\u00a0Garnett, editors, Advances in Neural Information Processing Systems, volume\u00a031. Curran Associates, Inc.\u00a0https:\/\/proceedings.neurips.cc\/paper_files\/paper\/2018\/file\/abdeb6f575ac5c6676b747bca8d09cc2-Paper.pdf"},{"issue":"6","key":"11147_CR148","doi-asserted-by":"publisher","first-page":"141","DOI":"10.1109\/MSP.2012.2211477","volume":"29","author":"Deng Li","year":"2012","unstructured":"Li Deng (2012) The mnist database of handwritten digit images for machine learning research. IEEE Signal Process Mag 29(6):141\u2013142","journal-title":"IEEE Signal Process Mag"},{"key":"11147_CR152","unstructured":"Li J (2019) Robustness in machine learning (cse 599-m). https:\/\/jerryzli.github.io\/robust-ml-fall19, Access 29 Jan 2024"},{"key":"11147_CR149","doi-asserted-by":"publisher","first-page":"101701","DOI":"10.1016\/j.cose.2019.101701","volume":"90","author":"D Li","year":"2020","unstructured":"Li D, Liao X, Xiang T, Wu J, Le J (2020a) Privacy-preserving self-serviced medical diagnosis scheme based on secure multi-party computation. Comput Secur 90:101701. https:\/\/doi.org\/10.1016\/j.cose.2019.101701","journal-title":"Comput Secur"},{"key":"11147_CR153","doi-asserted-by":"publisher","unstructured":"Li J, Yang Y, Sun JS (2020b) Searchfromfree: Adversarial measurements for machine learning-based energy theft detection. In 2020 IEEE International Conference on Communications, Control, and Computing Technologies for Smart Grids (SmartGridComm), pp. 1\u20136, https:\/\/doi.org\/10.1109\/SmartGridComm47815.2020.9303013","DOI":"10.1109\/SmartGridComm47815.2020.9303013"},{"key":"11147_CR156","unstructured":"Li L, Xie T, Li B (2020c) Ai-secure\/verigauge: a united toolbox for running major robustness verification approaches for dnns.,\u00a0https:\/\/github.com\/AI-secure\/VeriGauge"},{"key":"11147_CR159","unstructured":"Li S, Cheng Y, Wang W, Liu Y, Chen T (2020d) Learning to detect malicious clients for robust federated learning. CoRR, Preprint at\u00a0arXiv:2002.00211"},{"key":"11147_CR155","doi-asserted-by":"publisher","unstructured":"Li L, Song D, Li X, Zeng J, Ma R, Qiu X (2021) Backdoor attacks on pre-trained models by layerwise weight poisoning. In Marie-Francine Moens, Xuanjing Huang, Lucia Specia, and Scott Wen-tau Yih, editors, Proceedings of the 2021 Conference on Empirical Methods in Natural Language Processing, pp. 3023\u20133032, Online and Punta Cana, Dominican Republic. Association for Computational Linguistics. https:\/\/doi.org\/10.18653\/v1\/2021.emnlp-main.241. https:\/\/aclanthology.org\/2021.emnlp-main.241","DOI":"10.18653\/v1\/2021.emnlp-main.241"},{"issue":"6","key":"11147_CR150","doi-asserted-by":"publisher","first-page":"4862","DOI":"10.1109\/TSG.2022.3204796","volume":"13","author":"Y Li","year":"2022","unstructured":"Li Y, Wei X, Li Y, Dong Z, Shahidehpour M (2022) Detection of false data injection attacks in smart grid: a secure federated deep learning approach. IEEE Trans Smart Grid 13(6):4862\u20134872. https:\/\/doi.org\/10.1109\/TSG.2022.3204796","journal-title":"IEEE Trans Smart Grid"},{"key":"11147_CR154","doi-asserted-by":"publisher","unstructured":"Li J, Yang Y, Sun JS, Tomsovic K, Qi H (2023a) Towards adversarial-resilient deep neural networks for false data injection attack detection in power grids. In 2023 32nd International Conference on Computer Communications and Networks (ICCCN), pp. 1\u201310, https:\/\/doi.org\/10.1109\/ICCCN58024.2023.10230180","DOI":"10.1109\/ICCCN58024.2023.10230180"},{"key":"11147_CR157","doi-asserted-by":"publisher","unstructured":"Li L, Xie T, Li B (2023b) Sok: certified robustness for deep neural networks. In 2023 IEEE Symposium on Security and Privacy (SP), pp. 1289\u20131310, https:\/\/doi.org\/10.1109\/SP46215.2023.10179303","DOI":"10.1109\/SP46215.2023.10179303"},{"key":"11147_CR158","doi-asserted-by":"crossref","unstructured":"Li L, Xie T, Li B (2023c) Sok: certified robustness for deep neural networks. In 2023 IEEE Symposium on Security and Privacy (SP), pp. 1289\u20131310. IEEE Computer Society","DOI":"10.1109\/SP46215.2023.10179303"},{"key":"11147_CR151","unstructured":"Li H, Chen Y, Zheng Z,\u00a0Hu Q, Chan C, Liu H, Song Y (2024) Backdoor removal for generative large language models. arXiv e-prints, pages arXiv\u20132405"},{"key":"11147_CR160","doi-asserted-by":"crossref","unstructured":"Liao F, Liang M, Dong Y, Pang T, Hu X, Zhu J (2018) Defense against adversarial attacks using high-level representation guided denoiser. In Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR)","DOI":"10.1109\/CVPR.2018.00191"},{"issue":"5","key":"11147_CR161","doi-asserted-by":"publisher","first-page":"2029","DOI":"10.1109\/TDSC.2020.2986205","volume":"18","author":"Z Lingchen","year":"2021","unstructured":"Lingchen Z, Shengshan H, Qian W, Jianlin J, Chao S, Xiangyang L, Pengfei H (2021) Shielding collaborative learning: mitigating poisoning attacks through client-side detection. IEEE Trans Dependable Secure Comput 18(5):2029\u20132041. https:\/\/doi.org\/10.1109\/TDSC.2020.2986205","journal-title":"IEEE Trans Dependable Secure Comput"},{"key":"11147_CR165","doi-asserted-by":"crossref","unstructured":"Liu X, Cheng M, Zhang H, Hsieh C-J (2018) Towards robust neural networks via random self-ensemble. In Proceedings of the European Conference on Computer Vision (ECCV)","DOI":"10.1007\/978-3-030-01234-2_23"},{"key":"11147_CR163","doi-asserted-by":"crossref","unstructured":"Liu R, Yuan Z, Liu T, Xiong Z (2021) End-to-end lane shape prediction with transformers. In Proceedings of the IEEE\/CVF Winter Conference on Applications of Computer Vision (WACV), pp. 3694\u20133702","DOI":"10.1109\/WACV48630.2021.00374"},{"key":"11147_CR162","unstructured":"Liu C, Dong Y, Xiang W, Yang X, Su H, Zhu J, Chen Y, He Y, Xue H, Zheng S (2023) A comprehensive study on robustness of image classification models: benchmarking and rethinking, Preprint at\u00a0https:\/\/arxiv.org\/abs\/2302.14301"},{"key":"11147_CR164","unstructured":"Liu X, Xu N, Chen M, Xiao C (2024a) AutoDAN: generating stealthy jailbreak prompts on aligned large language models. In The Twelfth International Conference on Learning Representations, Preprint\u00a0https:\/\/openreview.net\/forum?id=7Jwpw4qKkb"},{"key":"11147_CR166","unstructured":"Liu Y, Cong T, Zhao Z, Backes M, Shen Y, Zhang Y (2024b) Robustness over time: Understanding adversarial examples\u2019 effectiveness on longitudinal versions of large language models, https:\/\/openreview.net\/forum?id=eC4WlSZc4H"},{"key":"11147_CR167","doi-asserted-by":"crossref","unstructured":"Lu J, Issaranon T, Forsyth D (2017) Safetynet: detecting and rejecting adversarial examples robustly. In Proceedings of the IEEE International Conference on Computer Vision (ICCV)","DOI":"10.1109\/ICCV.2017.56"},{"key":"11147_CR168","unstructured":"Lukas N, Zhang Y, Kerschbaum F(2021) Deep neural network fingerprinting by conferrable adversarial examples. In International Conference on Learning Representations, https:\/\/openreview.net\/forum?id=VqzVhqxkjH1"},{"key":"11147_CR169","doi-asserted-by":"crossref","unstructured":"Lyu Z, Guo M, Wu T, Xu G, Zhang K, Lin D(2021) Towards evaluating and training verifiably robust neural networks, Preprint at\u00a0https:\/\/arxiv.org\/abs\/2104.00447","DOI":"10.1109\/CVPR46437.2021.00429"},{"key":"11147_CR170","doi-asserted-by":"publisher","DOI":"10.1145\/3485133","author":"GR Machado","year":"2021","unstructured":"Machado GR, Silva E, Goldschmidt RR (2021) Adversarial machine learning in image classification: a survey toward the defender\u2019s perspective. ACM Comput Surv. https:\/\/doi.org\/10.1145\/3485133","journal-title":"ACM Comput Surv"},{"key":"11147_CR171","unstructured":"Madry A, Makelov A, Schmidt L, Tsipras D, Vladu A (2018) Towards deep learning models resistant to adversarial attacks. In International Conference on Learning Representations, https:\/\/openreview.net\/forum?id=rJzIBfZAb"},{"key":"11147_CR172","unstructured":"Maini P, Yaghini M, Papernot N (2021) Dataset inference: ownership resolution in machine learning. In International Conference on Learning Representations, https:\/\/openreview.net\/forum?id=hvdKKV2yt7T"},{"key":"11147_CR173","doi-asserted-by":"publisher","first-page":"417","DOI":"10.1109\/OJVT.2023.3265363","volume":"4","author":"G Mansi","year":"2023","unstructured":"Mansi G, Junho H, John M (2023) Cybersecurity of autonomous vehicles: a systematic literature review of adversarial attacks and defense models. IEEE Open J Vehicular Technol 4:417\u2013437. https:\/\/doi.org\/10.1109\/OJVT.2023.3265363","journal-title":"IEEE Open J Vehicular Technol"},{"issue":"6","key":"11147_CR174","doi-asserted-by":"publisher","first-page":"1893","DOI":"10.1109\/JBHI.2014.2344095","volume":"19","author":"Mozaffari-Kermani Mehran","year":"2015","unstructured":"Mehran Mozaffari-Kermani, Susmita Sur-Kolay, Anand Raghunathan, Jha Niraj K (2015) Systematic poisoning attacks on and defenses for machine learning in healthcare. IEEE J Biomed Health Inform 19(6):1893\u20131905. https:\/\/doi.org\/10.1109\/JBHI.2014.2344095","journal-title":"IEEE J Biomed Health Inform"},{"key":"11147_CR175","doi-asserted-by":"publisher","unstructured":"Meng D, Chen H (2017) Magnet: a two-pronged defense against adversarial examples. In Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, CCS \u201917, pp. 135-147, New York, NY, USA, Association for Computing Machinery. https:\/\/doi.org\/10.1145\/3133956.3134057","DOI":"10.1145\/3133956.3134057"},{"key":"11147_CR176","unstructured":"Metzen JH, Genewein T, Fischer V, Bischoff B (2017) On detecting adversarial perturbations. In International Conference on Learning Representations, https:\/\/openreview.net\/forum?id=SJzCSf9xg"},{"key":"11147_CR177","doi-asserted-by":"crossref","unstructured":"Min S, Krishna K, Lyu X, Lewis M, Yih Wt, Koh PW, Iyyer M, Zettlemoyer L, Hajishirzi H (2023) FActscore: fine-grained atomic evaluation of factual precision in long form text generation. In NeurIPS 2023 Workshop on Instruction Tuning and Instruction Following, https:\/\/openreview.net\/forum?id=fhSTeAAVb6","DOI":"10.18653\/v1\/2023.emnlp-main.741"},{"issue":"2","key":"11147_CR178","doi-asserted-by":"publisher","first-page":"49","DOI":"10.1109\/MSEC.2018.2888775","volume":"17","author":"A-R Mohammad","year":"2019","unstructured":"Mohammad A-R, Morris CJ (2019) Privacy-preserving machine learning: threats and solutions. IEEE Secur Privacy 17(2):49\u201358. https:\/\/doi.org\/10.1109\/MSEC.2018.2888775","journal-title":"IEEE Secur Privacy"},{"key":"11147_CR179","doi-asserted-by":"crossref","unstructured":"Moosavi-Dezfooli S-M, Fawzi A, Frossard P (2016) Deepfool: a simple and accurate method to fool deep neural networks. In Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR)","DOI":"10.1109\/CVPR.2016.282"},{"key":"11147_CR180","doi-asserted-by":"publisher","unstructured":"Moosavi-Dezfooli S-M, Fawzi A, Fawzi O, Frossard P (2017) Universal adversarial perturbations. In 2017 IEEE Conference on Computer Vision and Pattern Recognition (CVPR), pp. 86\u201394, https:\/\/doi.org\/10.1109\/CVPR.2017.17","DOI":"10.1109\/CVPR.2017.17"},{"key":"11147_CR181","doi-asserted-by":"crossref","unstructured":"Morris JX., Lifland E, Yoo JY, Grigsby J, Jin D, Qi Y (2020) Textattack: a framework for adversarial attacks, data augmentation, and adversarial training in nlp","DOI":"10.18653\/v1\/2020.emnlp-demos.16"},{"key":"11147_CR182","unstructured":"Muller MN, Eckert F, Fischer M, Vechev M(2023) Certified training: small boxes are all you need, Perprint at\u00a0https:\/\/arxiv.org\/abs\/2210.04871"},{"key":"11147_CR183","doi-asserted-by":"publisher","unstructured":"Nadji B(Brad) (2024) Data Security, Integrity, and Protection, pp. 59\u201383. Springer Nature Switzerland, Cham, https:\/\/doi.org\/10.1007\/978-3-031-61117-9_4","DOI":"10.1007\/978-3-031-61117-9_4"},{"key":"11147_CR184","doi-asserted-by":"publisher","unstructured":"Niazazari I, Livani H(2020) Attack on grid event cause analysis: An adversarial machine learning approach. In 2020 IEEE Power & Energy Society Innovative Smart Grid Technologies Conference (ISGT), pp. 1\u20135,https:\/\/doi.org\/10.1109\/ISGT45199.2020.9087649","DOI":"10.1109\/ISGT45199.2020.9087649"},{"key":"11147_CR185","unstructured":"Nicolae M-I, Sinn M, Tran MN, Buesser B, Rawat A, Wistuba M, Zantedeschi V, Baracaldo N, Chen B, Ludwig H, Molloy I, Edwards B (2018) Adversarial robustness toolbox v1.2.0. Preprint at\u00a0arXiv:1807.01069"},{"key":"11147_CR186","doi-asserted-by":"publisher","DOI":"10.1145\/3595292","author":"D Oliynyk","year":"2023","unstructured":"Oliynyk D, Mayer R, Rauber A (2023) I know what you trained last summer: a survey on stealing machine learning models and defences. ACM Comput Surv. https:\/\/doi.org\/10.1145\/3595292","journal-title":"ACM Comput Surv"},{"issue":"2","key":"11147_CR187","doi-asserted-by":"publisher","first-page":"548","DOI":"10.3390\/smartcities4020029","volume":"4","author":"OA Omitaomu","year":"2021","unstructured":"Omitaomu OA, Niu H (2021) Artificial intelligence techniques in smart grid: a survey. Smart Cities 4(2):548\u2013568","journal-title":"Smart Cities"},{"key":"11147_CR188","unstructured":"Ouyang L, Wu J,\u00a0Jiang X, Almeida D, Wainwright C, Mishkin P, Zhang C, Agarwal S, Slama K, Ray A, Schulman J, Hilton J, Kelton F, Miller L, Simens M, Askell A, Welinder P, Christiano PF, Leike J, Lowe R(2022) Training language models to follow instructions with human feedback. In Koyejo S, Mohamed S, Agarwal A, Belgrave D, Cho K, Oh A editors, Advances in Neural Information Processing Systems, volume\u00a035, pp. 27730\u201327744. https:\/\/proceedings.neurips.cc\/paper_files\/paper\/2022\/file\/b1efde53be364a73914f58805a001731-Paper-Conference.pdf"},{"key":"11147_CR189","doi-asserted-by":"publisher","DOI":"10.3390\/app11094233","author":"B Pal","year":"2021","unstructured":"Pal B, Gupta D, Rashed-Al-Mahfuz Md, Alyami SA, Moni MA (2021) Vulnerability in deep transfer learning models to adversarial fast gradient sign attack for covid-19 prediction from chest radiography images. Appl Sci. https:\/\/doi.org\/10.3390\/app11094233","journal-title":"Appl Sci"},{"key":"11147_CR190","unstructured":"Palma AD, Bunel R, Dvijotham K, Pawan KM, Stanforth R (2023) Ibp regularization for verified adversarial robustness via branch-and-bound, Preprint at\u00a0https:\/\/arxiv.org\/abs\/2206.14772"},{"key":"11147_CR191","unstructured":"Palma AD, Bunel R, Dvijotham K, Pawan KM., Stanforth R, Lomuscio A (2024) Expressive losses for verified robustness via convex combinations, Preprint at\u00a0arXiv:2305.13991"},{"key":"11147_CR192","unstructured":"Pang T, Xu K, Du C, Chen N, Zhu J (2019) Improving adversarial robustness via promoting ensemble diversity. In K Chaudhuri, R Salakhutdinov eds, Proceedings of the 36th International Conference on Machine Learning, volume\u00a097 of Proceedings of Machine Learning Research, pp. 4970\u20134979. https:\/\/proceedings.mlr.press\/v97\/pang19a.html"},{"key":"11147_CR193","unstructured":"Pang T, Lin M, Yang X, Zhu J, Yan S (2022) Robustness and accuracy could be reconcilable by (Proper) definition. In K Chaudhuri, S Jegelka, L Song, C Szepesvari, G Niu, S Sabato, eds, Proceedings of the 39th International Conference on Machine Learning, volume 162 of Proceedings of Machine Learning Research, pp. 17258\u201317277. https:\/\/proceedings.mlr.press\/v162\/pang22a.html"},{"key":"11147_CR194","doi-asserted-by":"crossref","unstructured":"Papakipos Z, Bitton J (2022) Augly: data augmentations for robustness","DOI":"10.1109\/CVPRW56347.2022.00027"},{"key":"11147_CR195","doi-asserted-by":"publisher","unstructured":"Papernot N, McDaniel P, Jha S, Fredrikson M, Berkay CZ, Swami A (2016a) The limitations of deep learning in adversarial settings. In 2016 IEEE European Symposium on Security and Privacy (EuroS &P), pp. 372\u2013387, https:\/\/doi.org\/10.1109\/EuroSP.2016.36","DOI":"10.1109\/EuroSP.2016.36"},{"key":"11147_CR196","doi-asserted-by":"publisher","unstructured":"Papernot N, McDaniel P,Wu X, Jha S, Swami A (2016b) Distillation as a defense to adversarial perturbations against deep neural networks. In 2016 IEEE Symposium on Security and Privacy (SP), pp. 582\u2013597, https:\/\/doi.org\/10.1109\/SP.2016.41","DOI":"10.1109\/SP.2016.41"},{"key":"11147_CR197","doi-asserted-by":"publisher","unstructured":"Papernot N, McDaniel P, Goodfellow I, Jha S, Berkay CZ, Swami A (2017) Practical black-box attacks against machine learning. In Proceedings of the 2017 ACM on Asia Conference on Computer and Communications Security, ASIA CCS \u201917, pp. 506-519, New York, NY, USA, Association for Computing Machinery. https:\/\/doi.org\/10.1145\/3052973.3053009","DOI":"10.1145\/3052973.3053009"},{"key":"11147_CR198","unstructured":"Papernot N, Faghri F, Carlini N, Goodfellow I, Feinman R, Kurakin A, Xie C, Sharma Y, Brown T, Roy A, Matyasko A, Behzadan V, Hambardzumyan K, Zhang Z, Juang Y-L, Li Z, Sheatsley R, Garg A, Uesato J, Gierke W, Dong Y, Berthelot D, Hendricks P, Rauber J, Long R, McDaniel P (2018a) Technical report on the cleverhans v2.1.0 adversarial examples library"},{"key":"11147_CR199","doi-asserted-by":"publisher","unstructured":"Papernot N, McDaniel P, Sinha A, Wellman MP (2018b) Sok: security and privacy in machine learning. In 2018 IEEE European Symposium on Security and Privacy (EuroS &P), pp. 399\u2013414, https:\/\/doi.org\/10.1109\/EuroSP.2018.00035","DOI":"10.1109\/EuroSP.2018.00035"},{"key":"11147_CR200","doi-asserted-by":"crossref","unstructured":"Park H, Bayat A, Sabokrou M, Kirschke JS, Menze BH (2020) Robustification of segmentation models against adversarial perturbations in medical imaging. In R Islem, A Ehsan, P Sang\u00a0Hyun, V Hern\u00e1ndez Maria del\u00a0C, eds, Predictive Intelligence in Medicine, pages 46\u201357, Cham, Springer International Publishing","DOI":"10.1007\/978-3-030-59354-4_5"},{"key":"11147_CR201","doi-asserted-by":"crossref","unstructured":"Paschali M, Conjeti S, Navarro F, Navab N(2018) Generalizability vs. robustness: investigating medical imaging networks using adversarial examples. In Frangi Alejandro\u00a0F, Schnabel Julia\u00a0A, Davatzikos Christos, Alberola-L\u00f3pez Carlos, Fichtinger Gabor, editors, Medical Image Computing and Computer Assisted Intervention\u2014MICCAI 2018, pp. 493\u2013501, Cham, Springer International Publishing","DOI":"10.1007\/978-3-030-00928-1_56"},{"key":"11147_CR202","doi-asserted-by":"crossref","unstructured":"Paudice A, Mu\u00f1oz-GL, Lupu EC (2018) Label sanitization against label flipping poisoning attacks, Preprint at\u00a0https:\/\/arxiv.org\/abs\/1803.00992","DOI":"10.1007\/978-3-030-13453-2_1"},{"key":"11147_CR204","doi-asserted-by":"publisher","unstructured":"Pelekis S, Karakolis E, Silva F, Schoinas V, Mouzakitis S, Kormpakis G, Amaro N, Psarras J (2022) In search of deep learning architectures for load forecasting: A comparative analysis and the impact of the covid-19 pandemic on model performance. In 2022 13th International Conference on Information, Intelligence, Systems & Applications (IISA), pp. 1\u20138. https:\/\/doi.org\/10.1109\/IISA56318.2022.9904363.\u00a0https:\/\/ieeexplore.ieee.org\/document\/9904363\/","DOI":"10.1109\/IISA56318.2022.9904363"},{"key":"11147_CR203","doi-asserted-by":"publisher","first-page":"101134","DOI":"10.1016\/J.SEGAN.2023.101134","volume":"36","author":"S Pelekis","year":"2023","unstructured":"Pelekis S, Pipergias A, Karakolis E, Mouzakitis S, Santori F, Ghoreishi M, Askounis D (2023a) Targeted demand response for flexible energy communities using clustering techniques. Sustain Energy Grids Netw 36:101134. https:\/\/doi.org\/10.1016\/J.SEGAN.2023.101134","journal-title":"Sustain Energy Grids Netw"},{"key":"11147_CR205","doi-asserted-by":"publisher","unstructured":"Pelekis S, Seisopoulos I-K, Spiliotis E, Pountridis T, Karakolis E, Mouzakitis S, Askounis D (2023b) A comparative assessment of deep learning models for day-ahead load forecasting: investigating key accuracy drivers. sustainable energy, grids and networks, 36:101171.. https:\/\/doi.org\/10.1016\/J.SEGAN.2023.101171. https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S2352467723001790","DOI":"10.1016\/J.SEGAN.2023.101171"},{"key":"11147_CR206","doi-asserted-by":"publisher","unstructured":"Pelekis S, Pountridis T, Kormpakis G, Lampropoulos G, Karakolis E, Mouzakitis S, Askounis D (2024) Deeptsf: codeless machine learning operations for time series forecasting. SoftwareX, 27:101758. https:\/\/doi.org\/10.1016\/J.SOFTX.2024.101758. https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S2352711024001298","DOI":"10.1016\/J.SOFTX.2024.101758"},{"key":"11147_CR207","unstructured":"Peng S, Xu W, Cornelius C, Hull M, Li K, Duggal R, Phute M, Martin J, Chau DH (2023) Robust principles: architectural design principles for adversarially robust cnns. Preprint at\u00a0https:\/\/arxiv.org\/abs\/2308.16258"},{"issue":"2","key":"11147_CR208","doi-asserted-by":"publisher","first-page":"998","DOI":"10.1109\/COMST.2020.2975048","volume":"22","author":"A Qayyum","year":"2020","unstructured":"Qayyum A, Usama M, Qadir J, Al-Fuqaha A (2020) Securing connected & autonomous vehicles: challenges posed by adversarial machine learning and the way forward. IEEE Commun Surv Tutorials 22(2):998\u20131026. https:\/\/doi.org\/10.1109\/COMST.2020.2975048","journal-title":"IEEE Commun Surv Tutorials"},{"key":"11147_CR209","doi-asserted-by":"publisher","unstructured":"Qi F, Chen Y, Li M, Yao Y, Liu Z, Sun M(2021) ONION: a simple and effective defense against textual backdoor attacks. In Marie-Francine M, Xuanjing H, Lucia S, Scott Wen-tau Y, editors, Proceedings of the 2021 Conference on Empirical Methods in Natural Language Processing, pages 9558\u20139566, Online and Punta Cana, Dominican Republic. Association for Computational Linguistics. https:\/\/doi.org\/10.18653\/v1\/2021.emnlp-main.752. https:\/\/aclanthology.org\/2021.emnlp-main.752","DOI":"10.18653\/v1\/2021.emnlp-main.752"},{"key":"11147_CR210","unstructured":"Qiang Y, Zhou X, Zade SZ, Roshani MA, Zytko D, Zhu D (2024) Learning to poison large language models during instruction tuning. CoRR, Preprint at https:\/\/doi.org\/10.48550\/arXiv.2402.13459"},{"key":"11147_CR211","unstructured":"Qin C, Martens J, Gowal S, Krishnan D, Dvijotham K, Fawzi A, De S, Stanforth R, Kohli P(2019) Adversarial robustness through local linearization. Adv Neural Inform Process Syst, 32"},{"key":"11147_CR212","doi-asserted-by":"publisher","unstructured":"Qureshi NBS, Kim D-H, Lee J, Lee E-K (2022) Poisoning attacks against federated learning in load forecasting of smart energy. In NOMS 2022-2022 IEEE\/IFIP Network Operations and Management Symposium, pp. 1\u20137. https:\/\/doi.org\/10.1109\/NOMS54207.2022.9789884","DOI":"10.1109\/NOMS54207.2022.9789884"},{"key":"11147_CR214","unstructured":"Raghunathan A, Steinhardt J, Liang P (2018) Certified defenses against adversarial examples. In International Conference on Learning Representations. https:\/\/openreview.net\/forum?id=Bys4ob-Rb"},{"key":"11147_CR213","unstructured":"Raghunathan* A, Xie* SM, Yang F, Duchi J, Liang P (2019) Adversarial training can hurt generalization. In ICML 2019 Workshop on Identifying and Understanding Deep Learning Phenomena. https:\/\/openreview.net\/forum?id=SyxM3J256E"},{"key":"11147_CR215","unstructured":"Raghunathan A, Xie SM, Yang F, Duchi J, Liang P (2020) Understanding and mitigating the tradeoff between robustness and accuracy. In Hal\u00a0Daum\u00e9 III and Aarti Singh, editors, Proceedings of the 37th International Conference on Machine Learning, volume 119 of Proceedings of Machine Learning Research, pp. 7909\u20137919. PMLR, 13\u201318. URL https:\/\/proceedings.mlr.press\/v119\/raghunathan20a.html"},{"key":"11147_CR216","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2024.125415","author":"Y Ran","year":"2025","unstructured":"Ran Y, Zhang A-X, Li M, Tang W, Wang Y-G (2025) Black-box adversarial attacks against image quality assessment models. Expert Syst Appl. https:\/\/doi.org\/10.1016\/j.eswa.2024.125415","journal-title":"Expert Syst Appl"},{"key":"11147_CR217","unstructured":"Rauber J, Brendel W(2018) and Matthias Bethge. A python toolbox to benchmark the robustness of machine learning models, Foolbox"},{"key":"11147_CR218","doi-asserted-by":"publisher","first-page":"1352","DOI":"10.1016\/j.rser.2015.04.065","volume":"50","author":"MQ Raza","year":"2015","unstructured":"Raza MQ, Khosravi A (2015) A review on artificial intelligence based load demand forecasting techniques for smart grid and buildings. Renewable Sustain Energy Rev 50:1352\u20131372. https:\/\/doi.org\/10.1016\/j.rser.2015.04.065","journal-title":"Renewable Sustain Energy Rev"},{"key":"11147_CR219","unstructured":"Rebuffi S-A, Gowal S, Calian DA, Stimberg F, Wiles O, Mann T (2021a) Fixing data augmentation to improve adversarial robustness. Preprint at\u00a0https:\/\/arxiv.org\/abs\/2103.01946"},{"key":"11147_CR220","unstructured":"Rebuffi S-A, Gowal S, Calian DA, Stimberg F, Wiles O, Mann TA (2021b) Fixing data augmentation to improve adversarial robustness. CoRR, Preprint at https:\/\/arxiv.org\/abs\/2103.01946"},{"key":"11147_CR221","doi-asserted-by":"publisher","unstructured":"Redmon J, Divvala S, Girshick R, Farhadi A (2016) You only look once: Unified, real-time object detection. In 2016 IEEE Conference on Computer Vision and Pattern Recognition (CVPR), pp. 779\u2013788. https:\/\/doi.org\/10.1109\/CVPR.2016.91","DOI":"10.1109\/CVPR.2016.91"},{"key":"11147_CR222","unstructured":"Rice L, Wong E, Kolter Z (2020) Overfitting in adversarially robust deep learning. In International conference on machine learning, pp. 8093\u20138104"},{"issue":"1","key":"11147_CR223","doi-asserted-by":"publisher","first-page":"2398","DOI":"10.1038\/s41746-020-00323-1","volume":"3","author":"N Rieke","year":"2020","unstructured":"Rieke N, Hancox J, Li W, Milletar\u00ec F, Roth HR, Albarqouni S, Bakas S, Galtier MN, Landman BA, Maier-Hein K, Ourselin S, Sheller M, Summers RM, Trask A, Xu D, Baust M, Cardoso MJ (2020) The future of digital health with federated learning. npj Digital Med 3(1):2398\u20136352. https:\/\/doi.org\/10.1038\/s41746-020-00323-1","journal-title":"npj Digital Med"},{"key":"11147_CR224","doi-asserted-by":"publisher","DOI":"10.1145\/3624010","author":"M Rigaki","year":"2023","unstructured":"Rigaki M, Garcia S (2023) A survey of privacy attacks in machine learning. ACM Comput Surv. https:\/\/doi.org\/10.1145\/3624010","journal-title":"ACM Comput Surv"},{"key":"11147_CR225","unstructured":"Robey A, Wong E, Hassani H, Pappas G(2023) SmoothLLM: defending large language models against jailbreaking attacks. In R0-FoMo:Robustness of Few-shot and Zero-shot Learning in Large Foundation Models. https:\/\/openreview.net\/forum?id=msOSDvY4Ss"},{"key":"11147_CR226","unstructured":"RobustBench (2024) Robustbench: A standardized benchmark for adversarial robustness. URL https:\/\/robustbench.github.io\/#leaderboard"},{"key":"11147_CR227","doi-asserted-by":"crossref","unstructured":"Ros AS, Doshi-Velez F (2018) Improving the adversarial robustness and interpretability of deep neural networks by regularizing their input gradients. In Proceedings of the Thirty-Second AAAI Conference on Artificial Intelligence and Thirtieth Innovative Applications of Artificial Intelligence Conference and Eighth AAAI Symposium on Educational Advances in Artificial Intelligence, AAAI\u201918\/IAAI\u201918\/EAAI\u201918. AAAI Press. ISBN 978-1-57735-800-8","DOI":"10.1609\/aaai.v32i1.11504"},{"key":"11147_CR228","doi-asserted-by":"publisher","first-page":"103853","DOI":"10.1016\/j.cose.2024.103853","volume":"141","author":"K Roshan","year":"2024","unstructured":"Roshan K, Zafar A (2024) Black-box adversarial transferability: an empirical study in cybersecurity perspective. Comput Secur 141:103853. https:\/\/doi.org\/10.1016\/j.cose.2024.103853","journal-title":"Comput Secur"},{"key":"11147_CR229","unstructured":"Roth, H.R., Chang, K., Singh, P., Neumark, N., Li, W., Gupta, V., Gupta, S., Qu, L., Ihsani, A., Bizzo, B.C. and Wen, Y., (2020) Federated learning for breast density classification: A real-world implementation. In S Albarqouni, S Bakas, K Kamnitsas, M.\u00a0Jorge Cardoso, B Landman, W Li, F Milletari, N Rieke, H Roth, D Xu, Z Xu, editors, Domain Adaptation and Representation Transfer, and Distributed and Collaborative Learning, pages 181\u2013191, Cham. Springer International Publishing"},{"key":"11147_CR231","unstructured":"Salman H, Yang G, Li J, Zhang P, Zhang H, Razenshteyn IP, Bubeck S (2019) Provably robust deep learning via adversarially trained smoothed classifiers. Preprint at\u00a0http:\/\/arxiv.org\/abs\/1906.04584"},{"key":"11147_CR232","unstructured":"Salman H, Ilyas A, Engstrom L, Kapoor A, Madry A (2020) Do adversarially robust imagenet models transfer better? In H.\u00a0Larochelle, M.\u00a0Ranzato, R.\u00a0Hadsell, M.F. Balcan, and H.\u00a0Lin, editors, Advances in Neural Information Processing Systems, volume\u00a033, pp. 3533\u20133545. Curran Associates, Inc. https:\/\/proceedings.neurips.cc\/paper_files\/paper\/2020\/file\/24357dd085d2c4b1a88a7e0692e60294-Paper.pdf"},{"key":"11147_CR233","unstructured":"Samangouei P, Kabkab M, Chellappa R (2018) Defense-GAN: protecting classifiers against adversarial attacks using generative models. In International Conference on Learning Representations. https:\/\/openreview.net\/forum?id=BkJ3ibb0-"},{"key":"11147_CR234","unstructured":"Sarkar S, Bansal A, Mahbub U (2017) and Rama Chellappa. Breaking high performance image classifiers, Upset and angri"},{"key":"11147_CR235","doi-asserted-by":"publisher","unstructured":"Sayghe A, Anubi OM, Konstantinou C (2020a) Adversarial examples on power systems state estimation. In 2020 IEEE Power & Energy Society Innovative Smart Grid Technologies Conference (ISGT), pp. 1\u20135. https:\/\/doi.org\/10.1109\/ISGT45199.2020.9087789","DOI":"10.1109\/ISGT45199.2020.9087789"},{"key":"11147_CR236","doi-asserted-by":"publisher","unstructured":"Sayghe A, Zhao J, Konstantinou C (2020b) Evasion attacks with adversarial deep learning against power system state estimation. In 2020 IEEE Power & Energy Society General Meeting (PESGM), pages 1\u20135. https:\/\/doi.org\/10.1109\/PESGM41954.2020.9281719","DOI":"10.1109\/PESGM41954.2020.9281719"},{"key":"11147_CR237","unstructured":"Schuster R, Song C, Tromer E, Shmatikov V (2021) You autocomplete me: Poisoning vulnerabilities in neural code completion. In 30th USENIX Security Symposium (USENIX Security 21), pp. 1559\u20131575"},{"key":"11147_CR238","doi-asserted-by":"crossref","unstructured":"Selvaraju RR, Cogswell M, Das A, Vedantam R, Parikh D, Batra D (2017) Grad-cam: visual explanations from deep networks via gradient-based localization. In Proceedings of the IEEE International Conference on Computer Vision (ICCV)","DOI":"10.1109\/ICCV.2017.74"},{"key":"11147_CR239","unstructured":"Sha Z, He X, Berrang P, Humbert M, Zhang Y (2024) Fine-tuning is all you need to mitigate backdoor attacks. https:\/\/openreview.net\/forum?id=ywGSgEmOYb"},{"key":"11147_CR240","doi-asserted-by":"publisher","unstructured":"Sharif M, Bhagavatula S, Bauer L, Reiter MK (2016) Accessorize to a crime: Real and stealthy attacks on state-of-the-art face recognition. In Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, CCS \u201916, pp. 1528-1540, New York, NY, USA. Association for Computing Machinery.\u00a0https:\/\/doi.org\/10.1145\/2976749.2978392","DOI":"10.1145\/2976749.2978392"},{"key":"11147_CR241","doi-asserted-by":"publisher","unstructured":"Shin T, Razeghi Y, Logan\u00a0IV RL, Wallace E, Singh S (2020) AutoPrompt: Eliciting Knowledge from Language Models with Automatically Generated Prompts. In Bonnie Webber, Trevor Cohn, Yulan He, and Yang Liu, editors, Proceedings of the 2020 Conference on Empirical Methods in Natural Language Processing (EMNLP), pp. 4222\u20134235, Association for Computational Linguistics. https:\/\/doi.org\/10.18653\/v1\/2020.emnlp-main.346. https:\/\/aclanthology.org\/2020.emnlp-main.346","DOI":"10.18653\/v1\/2020.emnlp-main.346"},{"key":"11147_CR242","doi-asserted-by":"publisher","unstructured":"Shokri R, Stronati M, Song C, Shmatikov V(2017) Membership inference attacks against machine learning models. In 2017 IEEE Symposium on Security and Privacy (SP), pp. 3\u201318. https:\/\/doi.org\/10.1109\/SP.2017.41","DOI":"10.1109\/SP.2017.41"},{"key":"11147_CR243","unstructured":"Singh ND, Croce F, Hein M(2023) Revisiting adversarial training for imagenet: Architectures, training and generalization across threat models. Preprint at\u00a0https:\/\/arxiv.org\/abs\/2303.01870"},{"issue":"1","key":"11147_CR244","doi-asserted-by":"publisher","first-page":"335","DOI":"10.1109\/TMI.2020.3026261","volume":"40","author":"L Siqi","year":"2021","unstructured":"Siqi L, Adiyoso S, Arnaud A, Ghesu FC, Eli G, Sasa G, Bogdan G, Dorin C (2021) No surprises: training robust lung nodule detection for low-dose ct scans by augmenting with adversarial attacks. IEEE Trans. Med. Imag. 40(1):335\u2013345. https:\/\/doi.org\/10.1109\/TMI.2020.3026261","journal-title":"IEEE Trans. Med. Imag."},{"key":"11147_CR245","unstructured":"SoK (2023) Sok: Certified robustness for deep neural networks. https:\/\/sokcertifiedrobustness.github.io\/"},{"key":"11147_CR246","unstructured":"Sok (2024) Sok: Certified robustness for deep neural networks | leaderboard. https:\/\/sokcertifiedrobustness.github.io\/leaderboard\/"},{"key":"11147_CR248","unstructured":"Song L, Mittal P (2021) Systematic evaluation of privacy risks of machine learning models. In 30th USENIX Security Symposium (USENIX Security 21), pp. 2615\u20132632. USENIX Association.\u00a0https:\/\/www.usenix.org\/conference\/usenixsecurity21\/presentation\/song"},{"key":"11147_CR247","unstructured":"Song D, Eykholt K, Evtimov I, Fernandes E, Li B, Rahmati A, Tram\u00e8r F, Prakash A, Kohno T (2018a) Physical adversarial examples for object detectors. In 12th USENIX Workshop on Offensive Technologies (WOOT 18), Baltimore, MD. USENIX Association. https:\/\/www.usenix.org\/conference\/woot18\/presentation\/eykholt"},{"key":"11147_CR250","unstructured":"Song Y, Kim T, Nowozin S, Ermon S, Kushman N (2018b) Pixeldefend: leveraging generative models to understand and defend against adversarial examples. In International Conference on Learning Representations. https:\/\/openreview.net\/forum?id=rJUYGxbCW"},{"key":"11147_CR249","doi-asserted-by":"publisher","unstructured":"Song Q, Tan R, Ren C, Xu Y (2021) Understanding credibility of adversarial examples against smart grid: A case study for voltage stability assessment. In Proceedings of the Twelfth ACM International Conference on Future Energy Systems, e-Energy \u201921, page 95-106, New York, NY, USA. Association for Computing Machinery. https:\/\/doi.org\/10.1145\/3447555.3464859","DOI":"10.1145\/3447555.3464859"},{"issue":"3","key":"11147_CR251","doi-asserted-by":"publisher","first-page":"362","DOI":"10.1002\/rob.21918","volume":"37","author":"G Sorin","year":"2020","unstructured":"Sorin G, Bogdan T, Tiberiu C, Gigel M (2020) A survey of deep learning techniques for autonomous driving. J Field Robot 37(3):362\u2013386. https:\/\/doi.org\/10.1002\/rob.21918","journal-title":"J Field Robot"},{"key":"11147_CR252","unstructured":"Steinhardt J, Koh Pang WW, Liang PS (2017) Certified defenses for data poisoning attacks. In I.\u00a0Guyon, U.\u00a0Von Luxburg, S.\u00a0Bengio, H.\u00a0Wallach, R.\u00a0Fergus, S.\u00a0Vishwanathan, and R.\u00a0Garnett, editors, Advances in Neural Information Processing Systems, volume\u00a030. Curran Associates, Inc. https:\/\/proceedings.neurips.cc\/paper_files\/paper\/2017\/file\/9d7311ba459f9e45ed746755a32dcd11-Paper.pdf"},{"key":"11147_CR253","doi-asserted-by":"crossref","unstructured":"Stempfel G, Ralaivola L (2009) Learning svms from sloppily labeled data. In Cesare Alippi, Marios Polycarpou, Christos Panayiotou, and Georgios Ellinas, editors, Artificial Neural Networks \u2013 ICANN 2009, pp. 884\u2013893, Berlin, Heidelberg. Springer Berlin Heidelberg","DOI":"10.1007\/978-3-642-04274-4_91"},{"key":"11147_CR254","doi-asserted-by":"publisher","unstructured":"Stracqualursi E, Rosato A, Di Lorenzo G, Panella M, Araneo R (2023) Systematic review of energy theft practices and autonomous detection through artificial intelligence methods. Renewable and Sustainable Energy Reviews 184. https:\/\/doi.org\/10.1016\/j.rser.2023.113544. https:\/\/www.scopus.com\/inward\/record.uri?eid=2-s2.0-85165975999&doi=10.1016%2fj.rser.2023.113544&partnerID=40&md5=e525c7d89a25312128c39ed714863a05","DOI":"10.1016\/j.rser.2023.113544"},{"key":"11147_CR256","doi-asserted-by":"publisher","unstructured":"T Stacey, L Ling, GM Emre, L Yu, W Wenqi (2021) Demystifying membership inference attacks in machine learning as a service. IEEE Trans Serv Comput, 14(6):2073\u20132089. https:\/\/doi.org\/10.1109\/TSC.2019.2897554","DOI":"10.1109\/TSC.2019.2897554"},{"key":"11147_CR255","unstructured":"Szegedy C, Zaremba W, Sutskever I (2014) Joan Bruna. Ian Goodfellow, and Rob Fergus. Intriguing properties of neural networks, Dumitru Erhan"},{"key":"11147_CR257","doi-asserted-by":"crossref","unstructured":"Taghanaki SA, Abhishek K, Azizi S, Hamarneh G (2019) A kernelized manifold mapping to diminish the effect of adversarial perturbations. In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR)","DOI":"10.1109\/CVPR.2019.01160"},{"key":"11147_CR258","unstructured":"The G (2019) Tesla driver dies in first fatal crash while using autopilot mode. https:\/\/www.theguardian.com\/technology\/2016\/jun\/30\/tesla-autopilot-death-self-driving-car-elon-musk"},{"key":"11147_CR260","doi-asserted-by":"publisher","unstructured":"Tian J, Li T, Shang F, Cao K, Li J, Ozay M (2019) Adaptive normalized attacks for learning adversarial attacks and defenses in power systems. In 2019 IEEE International Conference on Communications, Control, and Computing Technologies for Smart Grids (SmartGridComm), pp. 1\u20136. https:\/\/doi.org\/10.1109\/SmartGridComm.2019.8909713","DOI":"10.1109\/SmartGridComm.2019.8909713"},{"key":"11147_CR259","doi-asserted-by":"publisher","unstructured":"Tian B, Guo Q, Juefei-Xu F, Chan WL, Cheng Y, Li X, Xie X, Qin S (2021) Bias field poses a threat to dnn-based x-ray recognition. In 2021 IEEE International Conference on Multimedia and Expo (ICME), pp. 1\u20136. https:\/\/doi.org\/10.1109\/ICME51207.2021.9428437","DOI":"10.1109\/ICME51207.2021.9428437"},{"key":"11147_CR261","doi-asserted-by":"crossref","unstructured":"Tian Z, Cui L, Liang J, Yu S (2022a) A comprehensive survey on poisoning attacks and countermeasures in machine learning. ACM Comput. Surv., 55(8).\u00a0","DOI":"10.1145\/3551636"},{"key":"11147_CR262","doi-asserted-by":"publisher","unstructured":"Tian Z, Cui L, Liang J, Yu S (2022b) A comprehensive survey on poisoning attacks and countermeasures in machine learning. ACM Comput. Surv.,. https:\/\/doi.org\/10.1145\/3551636","DOI":"10.1145\/3551636"},{"key":"11147_CR263","volume-title":"Brown","author":"B Tom","year":"2018","unstructured":"Tom B (2018) Brown. Mart\u00edn Abadi, and Justin Gilmer. Adversarial patch, Aurko Roy, Dandelion Man\u00e9"},{"key":"11147_CR264","doi-asserted-by":"publisher","unstructured":"Tomsett R, Chan K, Chakraborty S (2019) Model poisoning attacks against distributed machine learning systems. In Tien Pham, editor, Artificial Intelligence and Machine Learning for Multi-Domain Operations Applications, volume 11006, page 110061D. International Society for Optics and Photonics, SPIE. https:\/\/doi.org\/10.1117\/12.2520275","DOI":"10.1117\/12.2520275"},{"key":"11147_CR268","unstructured":"Tram\u00e8r F (2017) Nicolas Papernot. Dan Boneh, and Patrick McDaniel. The space of transferable adversarial examples, Ian Goodfellow"},{"key":"11147_CR265","unstructured":"Tramer F, Boneh D (2019) Adversarial training and robustness for multiple perturbations. In H.\u00a0Wallach, H.\u00a0Larochelle, A.\u00a0Beygelzimer, F.\u00a0d\u2019 Alch\u00e9-Buc, E.\u00a0Fox, and R.\u00a0Garnett, editors, Advances in Neural Information Processing Systems, volume\u00a032. Curran Associates, Inc. https:\/\/proceedings.neurips.cc\/paper_files\/paper\/2019\/file\/5d4ae76f053f8f2516ad12961ef7fe97-Paper.pdf"},{"key":"11147_CR267","unstructured":"Tram\u00e8r F, Zhang F, Juels A, Reiter MK, Ristenpart T (2016) Stealing machine learning models via prediction APIs. In 25th USENIX Security Symposium (USENIX Security 16), pp. 601\u2013618, Austin, TX. USENIX Association. ISBN 978-1-931971-32-4. URL https:\/\/www.usenix.org\/conference\/usenixsecurity16\/technical-sessions\/presentation\/tramer"},{"key":"11147_CR269","unstructured":"Tram\u00e8r F, Kurakin A, Papernot N, Goodfellow I, Boneh D, McDaniel P (2018) Ensemble adversarial training: Attacks and defenses. In International Conference on Learning Representations. https:\/\/openreview.net\/forum?id=rkZvSe-RZ"},{"key":"11147_CR266","unstructured":"Tramer F, Carlini N, Brendel W, Madry A (2020) On adaptive attacks to adversarial example defenses. In H.\u00a0Larochelle, M.\u00a0Ranzato, R.\u00a0Hadsell, M.F. Balcan, and H.\u00a0Lin, editors, Advances in Neural Information Processing Systems, volume\u00a033, pp. 1633\u20131645. Curran Associates, Inc. https:\/\/proceedings.neurips.cc\/paper_files\/paper\/2020\/file\/11f38f8ecd71867b42433548d1078e38-Paper.pdf"},{"key":"11147_CR270","unstructured":"Tran B, Li J, Madry A (2018) Spectral signatures in backdoor attacks. In S.\u00a0Bengio, H.\u00a0Wallach, H.\u00a0Larochelle, K.\u00a0Grauman, N.\u00a0Cesa-Bianchi, and R.\u00a0Garnett, editors, Advances in Neural Information Processing Systems, volume\u00a031. Curran Associates, Inc. https:\/\/proceedings.neurips.cc\/paper_files\/paper\/2018\/file\/280cf18baf4311c92aa5a042336587d3-Paper.pdf"},{"key":"11147_CR271","unstructured":"Tripathi AM, Mishra A (2020) Fuzzy unique image transformation: Defense against adversarial attacks on deep covid-19 models,\u00a0https:\/\/europepmc.org\/article\/PPR\/PPR271151"},{"key":"11147_CR272","unstructured":"Tsipras D, Santurkar S, Engstrom L, Turner A, Madry A (2019) Robustness may be at odds with accuracy. In International Conference on Learning Representations. https:\/\/openreview.net\/forum?id=SyxAb30cY7"},{"key":"11147_CR273","doi-asserted-by":"crossref","unstructured":"Tso R, Alelaiwi A, Mizanur SM Rahman Mu-En W, Shamim HM (2017) Privacy-preserving data communication through secure multi-party computation in healthcare sensor cloud. Journal of Signal Processing Systems 89:51\u201359","DOI":"10.1007\/s11265-016-1198-2"},{"key":"11147_CR274","doi-asserted-by":"publisher","DOI":"10.3390\/math12010019","author":"AM Tzortzis","year":"2024","unstructured":"Tzortzis AM, Pelekis S, Spiliotis E, Karakolis E, Mouzakitis S, Psarras J, Askounis D (2024) Transfer learning for day-ahead load forecasting: a case study on european national electricity demand time series. Mathematics. https:\/\/doi.org\/10.3390\/math12010019","journal-title":"Mathematics"},{"key":"11147_CR275","unstructured":"Uwimana A, Senanayake R (2021) Out of distribution detection and adversarial attacks on deep neural networks for robust medical image analysis. In ICML 2021 Workshop on Adversarial Machine Learning. https:\/\/openreview.net\/forum?id=1iy7rdPCt_"},{"key":"11147_CR276","doi-asserted-by":"crossref","unstructured":"Vassilev A, Oprea A, Fordyce A, Andersen H(2024) Adversarial machine learning: a taxonomy and terminology of attacks and mitigations, https:\/\/tsapps.nist.gov\/publication\/get_pdf.cfm?pub_id=957080","DOI":"10.6028\/NIST.AI.100-2e2023"},{"key":"11147_CR277","unstructured":"Vaswani A, Shazeer N, Parmar N, Uszkoreit J, Jones L, Gomez AN, Kaiser \u0141, Polosukhin I (2017) Attention is all you need. In I.\u00a0Guyon, U.\u00a0Von Luxburg, S.\u00a0Bengio, H.\u00a0Wallach, R.\u00a0Fergus, S.\u00a0Vishwanathan, and R.\u00a0Garnett, editors, Advances in Neural Information Processing Systems, volume\u00a030. Curran Associates, Inc. https:\/\/proceedings.neurips.cc\/paper_files\/paper\/2017\/file\/3f5ee243547dee91fbd053c1c4a845aa-Paper.pdf"},{"key":"11147_CR278","doi-asserted-by":"publisher","unstructured":"Vatian A, Gusarova N, Dobrenko N, Dudorov S, Nigmatullin N, Shalyto A, Lobantsev A (2019) Impact of adversarial examples on the efficiency of interpretation and use of information from high-tech medical images. In 2019 24th Conference of Open Innovations Association (FRUCT), pp. 472\u2013478. https:\/\/doi.org\/10.23919\/FRUCT.2019.8711974","DOI":"10.23919\/FRUCT.2019.8711974"},{"issue":"11","key":"11147_CR279","doi-asserted-by":"publisher","first-page":"9549","DOI":"10.1609\/aaai.v35i11.17150","volume":"35","author":"S Virat","year":"2021","unstructured":"Virat S, Amir H (2021) Membership privacy for machine learning models through knowledge transfer. Proceed AAAI Conf Artif Intell 35(11):9549\u20139557. https:\/\/doi.org\/10.1609\/aaai.v35i11.17150","journal-title":"Proceed AAAI Conf Artif Intell"},{"key":"11147_CR280","unstructured":"Wan A, Wallace E, Shen S, Klein D (2023) Poisoning language models during instruction tuning. In International Conference on Machine Learning, pp. 35413\u201335425. PMLR"},{"issue":"4","key":"11147_CR281","doi-asserted-by":"publisher","first-page":"3479","DOI":"10.1109\/TSG.2021.3062722","volume":"12","author":"J Wang","year":"2021","unstructured":"Wang J, Srikantha P (2021) Stealthy black-box attacks on deep learning non-intrusive load monitoring models. IEEE Transactions Smart Grid 12(4):3479\u20133492. https:\/\/doi.org\/10.1109\/TSG.2021.3062722","journal-title":"IEEE Transactions Smart Grid"},{"key":"11147_CR282","unstructured":"Wang B, Xu C, Wang S, Gan Z, Cheng Y, Gao J, Awadallah AH, Li B (2021) Adversarial GLUE: A multi-task benchmark for robustness evaluation of language models. In Thirty-fifth Conference on Neural Information Processing Systems Datasets and Benchmarks Track (Round 2). https:\/\/openreview.net\/forum?id=GF9cSKI3A_q"},{"key":"11147_CR283","unstructured":"Wang G, Xie Y, Jiang Y, Mandlekar A, Xiao C, Zhu Y, Fan L, Anandkumar A (2023a) Voyager: an open-ended embodied agent with large language models. In Intrinsically-Motivated and Open-Ended Learning Workshop @NeurIPS2023. https:\/\/openreview.net\/forum?id=nfx5IutEed"},{"key":"11147_CR284","doi-asserted-by":"crossref","unstructured":"Wang N, Luo Y, Sato T, Xu K, Chen QA (2023b) Does physical adversarial example really matter to autonomous driving? towards system-level effect of adversarial object evasion attack. Preprint at\u00a0https:\/\/arxiv.org\/abs\/2308.11894","DOI":"10.14722\/vehiclesec.2024.25014"},{"key":"11147_CR285","unstructured":"Wang Z, Pang T, Du C, Lin M, Liu W, Yan S (2023c) Better diffusion models further improve adversarial training. Preprint at\u00a0https:\/\/arxiv.org\/abs\/2302.04638"},{"key":"11147_CR286","doi-asserted-by":"crossref","unstructured":"Warde-Farley D, Goodfellow I (2016) Adversarial perturbations of deep neural networks. Perturbations, Optimization,Statistics, 311(5)","DOI":"10.7551\/mitpress\/10761.003.0012"},{"issue":"4","key":"11147_CR287","doi-asserted-by":"publisher","first-page":"4439","DOI":"10.1109\/TVT.2020.2977378","volume":"69","author":"J Wenbo","year":"2020","unstructured":"Wenbo J, Hongwei L, Sen L, Xizhao L, Rongxing L (2020) Poisoning and evasion attacks against deep learning algorithms in autonomous vehicles. IEEE Trans Veh Technol 69(4):4439\u20134449. https:\/\/doi.org\/10.1109\/TVT.2020.2977378","journal-title":"IEEE Trans Veh Technol"},{"key":"11147_CR288","unstructured":"Weng T-W, Zhang H, Chen P-Y, Yi J, Su D, Gao Y, Hsieh C-J, Daniel L (2018) Evaluating the robustness of neural networks: an extreme value theory approach. In International Conference on Learning Representations. https:\/\/openreview.net\/forum?id=BkUHlMZ0b"},{"issue":"3","key":"11147_CR289","doi-asserted-by":"publisher","first-page":"54","DOI":"10.1145\/3144592.3144598","volume":"47","author":"MJ Wolf","year":"2017","unstructured":"Wolf MJ, Miller K, Grodzinsky FS (2017) Why we should have seen that coming: comments on microsoft\u2019s tay experiment, and wider implications. SIGCAS Comput. Soc. 47(3):54\u201364. https:\/\/doi.org\/10.1145\/3144592.3144598","journal-title":"SIGCAS Comput. Soc."},{"key":"11147_CR290","unstructured":"Wong E, Kolter Z (2018) Provable defenses against adversarial examples via the convex outer adversarial polytope. In Jennifer Dy and Andreas Krause, editors, Proceedings of the 35th International Conference on Machine Learning, volume\u00a080 of Proceedings of Machine Learning Research, pp. 5286\u20135295. PMLR, 10\u201315. URL https:\/\/proceedings.mlr.press\/v80\/wong18a.html"},{"key":"11147_CR291","doi-asserted-by":"publisher","DOI":"10.1145\/3394658","author":"A Wood","year":"2020","unstructured":"Wood A, Najarian K, Kahrobaei D (2020) Homomorphic encryption for machine learning in medicine and bioinformatics. ACM Comput Surv. https:\/\/doi.org\/10.1145\/3394658","journal-title":"ACM Comput Surv"},{"key":"11147_CR292","doi-asserted-by":"publisher","DOI":"10.1088\/1757-899X\/806\/1\/012050","author":"D Wu","year":"2020","unstructured":"Wu D, Liu S, Ban J (2020a) Classification of diabetic retinopathy using adversarial training. IOP Conf Ser: Mater Sci Eng. https:\/\/doi.org\/10.1088\/1757-899X\/806\/1\/012050","journal-title":"IOP Conf Ser: Mater Sci Eng"},{"key":"11147_CR293","unstructured":"Wu D, Xia S-T, Wang Y (2020b) Adversarial weight perturbation helps robust generalization. In H.\u00a0Larochelle, M.\u00a0Ranzato, R.\u00a0Hadsell, M.F. Balcan, and H.\u00a0Lin, editors, Advances in Neural Information Processing Systems, volume\u00a033, pp. 2958\u20132969. Curran Associates, Inc. https:\/\/proceedings.neurips.cc\/paper_files\/paper\/2020\/file\/1ef91c212e30e14bf125e9374262401f-Paper.pdf"},{"key":"11147_CR295","unstructured":"Wu S, Irsoy O, Lu S, Dabravolski V, Dredze M, Gehrmann S, Kambadur P, Rosenberg D, Mann G (2023) Bloomberggpt: A large language model for finance. Preprint at\u00a0arXiv:2303.17564"},{"key":"11147_CR294","unstructured":"Wu Q, Bansal G, Zhang J, Wu Y, Li B, Zhu E, Jiang L, Zhang X, Zhang S, Liu J, Awadallah AH, White RW, Burger D, Wang C (2024) Autogen: Enabling next-gen LLM applications via multi-agent conversation. In ICLR 2024 Workshop on Large Language Model (LLM) Agents. URL https:\/\/openreview.net\/forum?id=uAjxFFing2"},{"key":"11147_CR296","unstructured":"Xi Z, Chen W, Guo X, He W, Ding Y, Hong B, Zhang M, Wang J, Jin S, Zhou E, et\u00a0al (2023) The rise and potential of large language model based agents: A survey. Preprint at\u00a0arXiv:2309.07864"},{"issue":"12","key":"11147_CR297","doi-asserted-by":"publisher","first-page":"1081","DOI":"10.1038\/s42256-021-00421-z","volume":"3","author":"B Xiang","year":"2021","unstructured":"Xiang B, Hanchen W, Liya M, Yongchao X, Jiefeng G, Ziwei F, Fan Y, Ke M, Jiehua Y, Song B et al (2021) Advancing covid-19 diagnosis with privacy-preserving collaboration in artificial intelligence. Nature Mach Intell 3(12):1081\u20131089","journal-title":"Nature Mach Intell"},{"key":"11147_CR299","doi-asserted-by":"crossref","unstructured":"Xiao C, Li B, Zhu J-Y, He W, Liu M, Song D (2018) Generating adversarial examples with adversarial networks. In Proceedings of the 27th International Joint Conference on Artificial Intelligence, IJCAI\u201918, pp. 3905-3911","DOI":"10.24963\/ijcai.2018\/543"},{"key":"11147_CR298","unstructured":"Xiao C, Zhong P, Zheng C (2019) Enhancing adversarial defense by k-winners-take-all. Preprint at\u00a0arXiv:1905.10510"},{"key":"11147_CR300","doi-asserted-by":"crossref","unstructured":"Xie C, Wu Y, van\u00a0der Maaten L, Yuille AL, He K (2019) Feature denoising for improving adversarial robustness. In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR)","DOI":"10.1109\/CVPR.2019.00059"},{"key":"11147_CR302","doi-asserted-by":"publisher","unstructured":"Xu W, Evans D, Qi Y (2018) Feature squeezing: Detecting adversarial examples in deep neural networks. In Proceedings 2018 Network and Distributed System Security Symposium, NDSS 2018. Internet Society. https:\/\/doi.org\/10.14722\/ndss.2018.23198","DOI":"10.14722\/ndss.2018.23198"},{"key":"11147_CR301","doi-asserted-by":"crossref","unstructured":"Xu J, Ma MD, Wang F, Xiao C, Chen M (2023) Instructions as backdoors: Backdoor vulnerabilities of instruction tuning for large language models","DOI":"10.18653\/v1\/2024.naacl-long.171"},{"key":"11147_CR303","doi-asserted-by":"crossref","unstructured":"Xue F-F, Peng J, Wang R, Zhang Q, Zheng W-S (2019) Improving robustness of medical image diagnosis with denoising convolutional neural networks. In Dinggang Shen, Tianming Liu, Terry\u00a0M. Peters, Lawrence\u00a0H. Staib, Caroline Essert, Sean Zhou, Pew-Thian Yap, and Ali Khan, editors, Medical Image Computing and Computer Assisted Intervention \u2013 MICCAI 2019, pages 846\u2013854, Cham. Springer International Publishing","DOI":"10.1007\/978-3-030-32226-7_94"},{"key":"11147_CR304","unstructured":"Yan Z, Guo Y, Zhang C (2018) Deep defense: Training dnns with improved adversarial robustness. In S.\u00a0Bengio, H.\u00a0Wallach, H.\u00a0Larochelle, K.\u00a0Grauman, N.\u00a0Cesa-Bianchi, and R.\u00a0Garnett, editors, Advances in Neural Information Processing Systems, volume\u00a031. Curran Associates, Inc. https:\/\/proceedings.neurips.cc\/paper_files\/paper\/2018\/file\/8f121ce07d74717e0b1f21d122e04521-Paper.pdf"},{"key":"11147_CR306","unstructured":"Yang Y-Y, Rashtchian C, Zhang H, Salakhutdinov RR, Chaudhuri K (2020) A closer look at accuracy vs. robustness. In H.\u00a0Larochelle, M.\u00a0Ranzato, R.\u00a0Hadsell, M.F. Balcan, and H.\u00a0Lin, editors, Advances in Neural Information Processing Systems, volume\u00a033, pp. 8588\u20138601. Curran Associates, Inc. https:\/\/proceedings.neurips.cc\/paper_files\/paper\/2020\/file\/61d77652c97ef636343742fc3dcf3ba9-Paper.pdf"},{"key":"11147_CR305","unstructured":"Yang J, Boloor A, Chakrabarti A, Zhang X, Vorobeychik Y (2021) Finding physical adversarial examples for autonomous driving with fast and differentiable image compositing. https:\/\/openreview.net\/forum?id=a7gkBG1m6e"},{"issue":"12","key":"11147_CR307","doi-asserted-by":"publisher","first-page":"7897","DOI":"10.1109\/TII.2021.3071405","volume":"17","author":"D Yao","year":"2021","unstructured":"Yao D, Tiehua Z, Guannan L, Xi Z, Jiong J, Qing-Long H (2021) Deep learning-based autonomous driving systems: a survey of attacks and defenses. IEEE Trans Industr Inf 17(12):7897\u20137912. https:\/\/doi.org\/10.1109\/TII.2021.3071405","journal-title":"IEEE Trans Industr Inf"},{"key":"11147_CR308","unstructured":"Yi M, Hou L, Sun J, Shang L, Jiang X, Liu Q, Ma Z (2021) Improved ood generalization via adversarial training and pretraing. In Marina Meila and Tong Zhang, editors, Proceedings of the 38th International Conference on Machine Learning, volume 139 of Proceedings of Machine Learning Research, pp. 11987\u201311997. https:\/\/proceedings.mlr.press\/v139\/yi21a.html"},{"key":"11147_CR309","doi-asserted-by":"publisher","unstructured":"Yoshida K, Fujino T (2020) Disabling backdoor and identifying poison data by using knowledge distillation in backdoor attacks on deep neural networks. In Proceedings of the 13th ACM Workshop on Artificial Intelligence and Security, AISec\u201920, pp. 117-127, New York, NY, USA. Association for Computing Machinery. https:\/\/doi.org\/10.1145\/3411508.3421375","DOI":"10.1145\/3411508.3421375"},{"key":"11147_CR310","unstructured":"Yousefpour A, Shilov I, Sablayrolles A, Testuggine D, Prasad K, Malek M, Nguyen J, Ghosh S, Bharadwaj A, Zhao J, Cormode G, Mironov I (2021) Opacus: User-friendly differential privacy library in pytorch. In NeurIPS 2021 Workshop Privacy in Machine Learning. https:\/\/openreview.net\/forum?id=EopKEYBoI-"},{"key":"11147_CR311","doi-asserted-by":"crossref","unstructured":"Yu H, Yang K, Zhang T, Tsai Y-Y, Ho T-Y, Jin Y (2020) Cloudleak: Large-scale deep learning models stealing through adversarial examples. In Network and Distributed System Security Symposium","DOI":"10.14722\/ndss.2020.24178"},{"issue":"3","key":"11147_CR312","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3641289","volume":"15","author":"Xu Yupeng Chang","year":"2024","unstructured":"Yupeng Chang Xu, Wang Wang Jindong, Yuan Wu, Linyi Yang, Kaijie Zhu, Hao Chen, Xiaoyuan Yi, Cunxiang Wang, Yidong Wang et al (2024) A survey on evaluation of large language models. ACM Trans Intell Syst Technol 15(3):1\u201345","journal-title":"ACM Trans Intell Syst Technol"},{"key":"11147_CR313","doi-asserted-by":"publisher","unstructured":"Zantedeschi V, Nicolae M-I, Rawat A (2017) Efficient defenses against adversarial attacks. In Proceedings of the 10th ACM Workshop on Artificial Intelligence and Security, AISec \u201917, pp. 39-49, New York, NY, USA. Association for Computing Machinery. https:\/\/doi.org\/10.1145\/3128572.3140449","DOI":"10.1145\/3128572.3140449"},{"key":"11147_CR318","unstructured":"Zhang H, Yu Y, Jiao J, Xing E, El\u00a0Ghaoui L, Jordan M (2019a) Theoretically principled trade-off between robustness and accuracy. In International conference on machine learning, pp. 7472\u20137482. PMLR"},{"key":"11147_CR319","unstructured":"Zhang H, Yu Y, Jiao J, Xing E, Ghaoui LE, Jordan M (2019b) Theoretically principled trade-off between robustness and accuracy. In Kamalika Chaudhuri and Ruslan Salakhutdinov, editors, Proceedings of the 36th International Conference on Machine Learning, volume\u00a097 of Proceedings of Machine Learning Research, pp. 7472\u20137482. PMLR, 09\u201315. https:\/\/proceedings.mlr.press\/v97\/zhang19p.html"},{"key":"11147_CR321","unstructured":"Zhang Y, Foroosh H, David P, Gong B (2019c) CAMOU: Learning physical vehicle camouflages to adversarially attack detectors in the wild. In International Conference on Learning Representations. https:\/\/openreview.net\/forum?id=SJgEl3A5tm"},{"key":"11147_CR315","unstructured":"Zhang B, Cai T, Lu Z, He D, Wang L (2021a) Towards certifying l-infinity robustness using neural networks with l-inf-dist neurons. In Marina Meila and Tong Zhang, editors, Proceedings of the 38th International Conference on Machine Learning, volume 139 of Proceedings of Machine Learning Research, pp. 12368\u201312379. https:\/\/proceedings.mlr.press\/v139\/zhang21b.html"},{"key":"11147_CR322","doi-asserted-by":"publisher","unstructured":"Zhang Z, Chen Y, Wagner D (2021b) Seat: Similarity encoder by adversarial training for detecting model extraction attack queries. In Proceedings of the 14th ACM Workshop on Artificial Intelligence and Security, AISec \u201921, pp. 37-48, New York, NY, USA. Association for Computing Machinery. https:\/\/doi.org\/10.1145\/3474369.3486863","DOI":"10.1145\/3474369.3486863"},{"key":"11147_CR314","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1038\/s41551-022-00898-y","volume":"6","author":"A Zhang","year":"2022","unstructured":"Zhang A, Xing L, Zou J, Joseph W (2022a) Shifting machine learning for healthcare from development to deployment and from models to data. Nature Biomed Eng 6:1\u201316. https:\/\/doi.org\/10.1038\/s41551-022-00898-y","journal-title":"Nature Biomed Eng"},{"key":"11147_CR316","unstructured":"Zhang B, Jiang D, He D, Wang (2022b) Boosting the certified robustness of l-infinity distance nets. Preprint at\u00a0https:\/\/arxiv.org\/abs\/2110.06850"},{"key":"11147_CR317","unstructured":"Zhang B, Jiang D, He D, Wang L (2022c) Rethinking lipschitz neural networks and certified robustness: a boolean function perspective. Preprint at\u00a0https:\/\/arxiv.org\/abs\/2210.01787"},{"key":"11147_CR320","doi-asserted-by":"crossref","unstructured":"Zhang Q, Hu S, Sun J, Chen QA, Mao ZM (2022d) On adversarial robustness of trajectory prediction for autonomous vehicles. In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR), pp. 15159\u201315168","DOI":"10.1109\/CVPR52688.2022.01473"},{"key":"11147_CR324","doi-asserted-by":"publisher","first-page":"48901","DOI":"10.1109\/ACCESS.2019.2909559","volume":"7","author":"J Zhao","year":"2019","unstructured":"Zhao J, Chen Y, Zhang W (2019) Differential privacy preservation in deep learning: challenges, opportunities and solutions. IEEE Access 7:48901\u201348911. https:\/\/doi.org\/10.1109\/ACCESS.2019.2909559","journal-title":"IEEE Access"},{"key":"11147_CR323","doi-asserted-by":"publisher","DOI":"10.3390\/a15080283","author":"W Zhao","year":"2022","unstructured":"Zhao W, Alwidian S, Mahmoud QH (2022) Adversarial training methods for deep learning: a systematic review. Algorithms. https:\/\/doi.org\/10.3390\/a15080283","journal-title":"Algorithms"},{"key":"11147_CR326","unstructured":"Zheng Z, Hong P (2018) Robust detection of adversarial attacks by modeling the intrinsic properties of deep neural networks. In S.\u00a0Bengio, H.\u00a0Wallach, H.\u00a0Larochelle, K.\u00a0Grauman, N.\u00a0Cesa-Bianchi, and R.\u00a0Garnett, editors, Advances in Neural Information Processing Systems, volume\u00a031. Curran Associates, Inc. https:\/\/proceedings.neurips.cc\/paper_files\/paper\/2018\/file\/e7a425c6ece20cbc9056f98699b53c6f-Paper.pdf"},{"key":"11147_CR325","doi-asserted-by":"crossref","unstructured":"Zheng H, Ye Q, Hu H, Fang C, Shi J (2019) Bdpl: a boundary differentially private layer against machine learning model extraction attacks. In Kazue Sako, Steve Schneider, and Peter Y.\u00a0A. Ryan, editors, Computer Security \u2013 ESORICS 2019, pp. 66\u201383, Cham. Springer International Publishing","DOI":"10.1007\/978-3-030-29959-0_4"},{"issue":"7","key":"11147_CR327","first-page":"1","volume":"55","author":"W Zhibo","year":"2022","unstructured":"Zhibo W, Jingjing M, Xue W, Jiahui H, Zhan Q, Kui R (2022) Threats to training: a survey of poisoning attacks and defenses on machine learning systems. ACM Comput Surv 55(7):1\u201336","journal-title":"ACM Comput Surv"},{"key":"11147_CR328","doi-asserted-by":"publisher","unstructured":"Zhou H, Li W, Kong Z, Guo J, Zhang Y, Yu B, Zhang L, Liu C(2020) Deepbillboard: Systematic physical-world testing of autonomous driving systems. In Proceedings of the ACM\/IEEE 42nd International Conference on Software Engineering, ICSE \u201920, pp. 347-358, New York, NY, USA. Association for Computing Machinery. https:\/\/doi.org\/10.1145\/3377811.3380422","DOI":"10.1145\/3377811.3380422"},{"key":"11147_CR230","unstructured":"S Zhouxing, W Yihan, Z Huan, Y Jinfeng, H Cho-Jui (2021) Fast certified robust training with short warmup. In A.\u00a0Beygelzimer, Y.\u00a0Dauphin, P.\u00a0Liang, and J.\u00a0Wortman Vaughan, editors, Advances in Neural Information Processing Systems. https:\/\/openreview.net\/forum?id=AQ9UL-7UvZx"},{"key":"11147_CR329","doi-asserted-by":"publisher","unstructured":"Zhu K, Wang J, Zhou J, Wang Z, Chen H, Wang Y, Yang L, Ye W, Zhang Y, Gong NZ, Xie X (2023) PromptRobust: towards evaluating the robustness of large language models on adversarial prompts. Preprint at\u00a0https:\/\/doi.org\/10.48550\/arXiv.2306.04528","DOI":"10.48550\/arXiv.2306.04528"},{"key":"11147_CR330","unstructured":"Zibaeirad A, Koleini F, Bi S, Hou T, Wang T (2024) A comprehensive survey on the security of smart grid: Challenges, mitigations, and future research opportunities. https:\/\/arxiv.org\/abs\/2407.07966"},{"key":"11147_CR331","doi-asserted-by":"publisher","unstructured":"Ziller A, Trask A, Lopardo A, Szymkow B, Wagner B, Bluemke E, Nounahon J-M, Passerat-Palmbach J, Prakash K, Rose N, Ryffel T, Reza ZN, Kaissis G (2021a) PySyft: A Library for Easy Federated Learning, pages 111\u2013139. Springer International Publishing, Cham. ISBN 978-3-030-70604-3. https:\/\/doi.org\/10.1007\/978-3-030-70604-3_5","DOI":"10.1007\/978-3-030-70604-3_5"},{"key":"11147_CR332","doi-asserted-by":"publisher","first-page":"152103","DOI":"10.1109\/ACCESS.2019.2947295","volume":"7","author":"S Zongkun","year":"2019","unstructured":"Zongkun S, Yinglong W, Minglei S, Ruixia L, Huiqi Z (2019) Differential privacy for data and model publishing of medical data. IEEE Access 7:152103\u2013152114. https:\/\/doi.org\/10.1109\/ACCESS.2019.2947295","journal-title":"IEEE Access"},{"key":"11147_CR333","unstructured":"Zou A, Wang Z, Kolter JZ, Fredrikson M (2023) Universal and transferable adversarial attacks on aligned language models. Preprint at\u00a0arXiv:2307.15043"}],"container-title":["Artificial Intelligence Review"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10462-025-11147-4.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10462-025-11147-4\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10462-025-11147-4.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,9,10]],"date-time":"2025-09-10T06:31:27Z","timestamp":1757485887000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10462-025-11147-4"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,5,3]]},"references-count":333,"journal-issue":{"issue":"8","published-online":{"date-parts":[[2025,8]]}},"alternative-id":["11147"],"URL":"https:\/\/doi.org\/10.1007\/s10462-025-11147-4","relation":{},"ISSN":["1573-7462"],"issn-type":[{"value":"1573-7462","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,5,3]]},"assertion":[{"value":"11 February 2025","order":1,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"3 May 2025","order":2,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}],"article-number":"226"}}