{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,2]],"date-time":"2026-06-02T04:38:30Z","timestamp":1780375110706,"version":"3.54.1"},"reference-count":56,"publisher":"Springer Science and Business Media LLC","issue":"3","license":[{"start":{"date-parts":[[2022,5,20]],"date-time":"2022-05-20T00:00:00Z","timestamp":1653004800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2022,5,20]],"date-time":"2022-05-20T00:00:00Z","timestamp":1653004800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Appl Intell"],"published-print":{"date-parts":[[2023,2]]},"DOI":"10.1007\/s10489-022-03495-3","type":"journal-article","created":{"date-parts":[[2022,5,20]],"date-time":"2022-05-20T06:06:54Z","timestamp":1653026814000},"page":"3069-3094","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":8,"title":["Advanced defensive distillation with ensemble voting and noisy logits"],"prefix":"10.1007","volume":"53","author":[{"given":"Yuting","family":"Liang","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6768-0168","authenticated-orcid":false,"given":"Reza","family":"Samavi","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2022,5,20]]},"reference":[{"key":"3495_CR1","unstructured":"Szegedy C, Zaremba W, Sutskever I, Bruna J, Erhan D, Goodfellow I, Fergus R (2013) Intriguing properties of neural networks. arXiv:1312.6199"},{"key":"3495_CR2","unstructured":"Goodfellow I, Shlens J, Szegedy C (2015) Explaining and harnessing adversarial examples. In: International Conference on Learning Representations. arXiv:1412.6572"},{"key":"3495_CR3","unstructured":"Kurakin A, Goodfellow I, Bengio S (2016) Adversarial examples in the physical world. arXiv:1607.02533"},{"key":"3495_CR4","doi-asserted-by":"crossref","unstructured":"Papernot N, McDaniel P, Wu X, Jha S, Swami A (2016) Distillation as a defense to adversarial perturbations against deep neural networks. In: 2016 IEEE Symposium on Security and Privacy (SP). IEEE, pp 582\u2013597","DOI":"10.1109\/SP.2016.41"},{"key":"3495_CR5","doi-asserted-by":"crossref","unstructured":"Carlini N, Wagner D (2017) Towards evaluating the robustness of neural networks. In: 2017 IEEE Symposium on Security and Privacy (SP). IEEE, pp 39\u201357","DOI":"10.1109\/SP.2017.49"},{"key":"3495_CR6","unstructured":"Bastani O, Ioannou Y, Lampropoulos L, Vytiniotis D, Nori A, Criminisi A (2016) Measuring neural net robustness with constraints. In: Advances in neural information processing systems, pp 2613\u20132621"},{"key":"3495_CR7","unstructured":"Weng T-W, Zhang H, Chen P-Y, Yi J, Su D, Gao Y, Hsieh C-J, Daniel L (2018) Evaluating the robustness of neural networks: An extreme value theory approach. In: 6th International Conference on Learning Representations, ICLR 2018, Conference Track Proceedings. OpenReview.net, Vancouver"},{"key":"3495_CR8","unstructured":"Hendrycks D, Dietterich T G (2019) Benchmarking neural network robustness to common corruptions and perturbations. In: 7th International Conference on Learning Representations, ICLR 2019. OpenReview.net, New Orleans"},{"key":"3495_CR9","doi-asserted-by":"publisher","unstructured":"L\u00e9cuyer M, Atlidakis V, Geambasu R, Hsu D, Jana S (2019) Certified robustness to adversarial examples with differential privacy. In: 2019 IEEE Symposium on Security and Privacy, SP 2019. https:\/\/doi.org\/10.1109\/SP.2019.00044. IEEE, San Francisco, pp 656\u2013672","DOI":"10.1109\/SP.2019.00044"},{"key":"3495_CR10","unstructured":"Cohen J M, Rosenfeld E, Kolter J Z (2019) Certified adversarial robustness via randomized smoothing. In: Chaudhuri K, Salakhutdinov R (eds) International conference on machine learning, ICML, Proceedings of Machine Learning Research, vol 97. PMLR, pp 1310\u20131320"},{"key":"3495_CR11","unstructured":"Kurakin A, Goodfellow I J, Bengio S (2017) Adversarial machine learning at scale. In: 5th International Conference on Learning Representations, ICLR 2017, Conference Track Proceedings. https:\/\/openreview.net\/forum?id=BJm4T4Kgx. OpenReview.net, Toulon"},{"key":"3495_CR12","unstructured":"Wang Y, Zou D, Yi J, Bailey J, Ma X, Gu Q (2020) Improving adversarial robustness requires revisiting misclassified examples. In: 8th International Conference on Learning Representations, ICLR 2020. https:\/\/openreview.net\/forum?id=rklOg6EFwS. OpenReview.net, Addis Ababa"},{"key":"3495_CR13","unstructured":"Kannan H, Kurakin A, Goodfellow I (2018) Adversarial logit pairing. arXiv:1803.06373"},{"key":"3495_CR14","unstructured":"Tram\u00e8r F, Kurakin A, Papernot N, Goodfellow I J, Boneh D, McDaniel P D (2018) Ensemble adversarial training: Attacks and defenses. In: 6th International Conference on Learning Representations, ICLR 2018, Conference Track Proceedings. https:\/\/openreview.net\/forum?id=rkZvSe-RZ. OpenReview.net, Vancouver"},{"key":"3495_CR15","unstructured":"Pang T, Yang X, Dong Y, Xu T, Zhu J, Su H (2020) Boosting adversarial training with hypersphere embedding. In: Larochelle H, Ranzato M, Hadsell R, Balcan M-F, Lin H-T (eds) Advances in Neural Information Processing Systems 33: Annual Conference on Neural Information Processing Systems 2020, NeurIPS 2020, virtual. https:\/\/proceedings.neurips.cc\/paper\/2020\/hash\/5898d8095428ee310bf7fa3da1864ff7-Abstract.html"},{"key":"3495_CR16","doi-asserted-by":"publisher","unstructured":"Bai T, Luo J, Zhao J, Wen B, Wang Q (2021) Recent advances in adversarial training for adversarial robustness. In: Zhou Z-H (ed) Proceedings of the Thirtieth International Joint Conference on Artificial Intelligence, IJCAI 2021. https:\/\/doi.org\/10.24963\/ijcai.2021\/591. ijcai.org, Virtual Event \/ Montreal, pp 4312\u20134321","DOI":"10.24963\/ijcai.2021\/591"},{"key":"3495_CR17","doi-asserted-by":"crossref","unstructured":"You Z, Ye J, Li K, Xu Z, Wang P (2019) Adversarial noise layer: Regularize neural network by adding noise. In: 2019 IEEE International Conference on Image Processing (ICIP). IEEE, pp 909\u2013913","DOI":"10.1109\/ICIP.2019.8803055"},{"key":"3495_CR18","doi-asserted-by":"crossref","unstructured":"He Z, Rakin AS, Fan D (2019) Parametric noise injection: Trainable randomness to improve deep neural network robustness against adversarial attack. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp 588\u2013597","DOI":"10.1109\/CVPR.2019.00068"},{"key":"3495_CR19","unstructured":"Pang T, Xu K, Du C, Chen N, Zhu J (2019) Improving adversarial robustness via promoting ensemble diversity. In: International Conference on Machine Learning. PMLR, pp 4970\u20134979"},{"key":"3495_CR20","unstructured":"Strauss T, Hanselmann M, Junginger A, Ulmer H (2017) Ensemble methods as a defense to adversarial perturbations against deep neural networks. arXiv:1709.03423"},{"key":"3495_CR21","unstructured":"Tram\u00e8r F, Papernot N, Goodfellow IJ, Boneh D, McDaniel PD (2017) The space of transferable adversarial examples. CoRR, arXiv:1704.03453"},{"key":"3495_CR22","unstructured":"Carlini N, Athalye A, Papernot N, Brendel W, Rauber J, Tsipras D, Goodfellow I, Madry A, Kurakin A (2019) On evaluating adversarial robustness. arXiv:1902.06705"},{"key":"3495_CR23","doi-asserted-by":"crossref","unstructured":"Papernot N, McDaniel P, Jha S, Fredrikson M, Celik ZB, Swami A (2016) The limitations of deep learning in adversarial settings. In: 2016 IEEE European Symposium on Security and Privacy (EuroS&P). IEEE, pp 372\u2013387","DOI":"10.1109\/EuroSP.2016.36"},{"key":"3495_CR24","unstructured":"Jacobsen J-H, Behrmannn J, Carlini N, Tramer F, Papernot N (2019) Exploiting excessive invariance caused by norm-bounded adversarial robustness. arXiv:1903.10484"},{"key":"3495_CR25","unstructured":"Yang Y, Zhang G, Katabi D, Xu Z (2019) Me-net: Towards effective adversarial robustness with matrix estimation. In: International Conference on Machine Learning, pp 7025\u201370 34"},{"key":"3495_CR26","unstructured":"Papernot N, Abadi M, Erlingsson U, Goodfellow I, Talwar K (2016) Semi-supervised knowledge transfer for deep learning from private training data. arXiv:1610.05755"},{"key":"3495_CR27","unstructured":"Cubuk ED, Zoph B, Schoenholz SS, Le QV (2018) Intriguing properties of adversarial examples. https:\/\/openreview.net\/forum?id=rk6H0ZbRb"},{"issue":"2","key":"3495_CR28","doi-asserted-by":"publisher","first-page":"758","DOI":"10.1214\/17-AOS1634","volume":"47","author":"K Hung","year":"2019","unstructured":"Hung K, Fithian W, et al. (2019) Rank verification for exponential families. Ann Stat 47 (2):758\u2013782","journal-title":"Ann Stat"},{"key":"3495_CR29","unstructured":"Teng J, Lee G-H, Yuan Y (2020) l1 adversarial robustness certificates: a randomized smoothing approach. https:\/\/openreview.net\/forum?id=H1lQIgrFDS"},{"key":"3495_CR30","unstructured":"LeCun Y, Cortes C, Burges CJC (1998) The mnist database of handwritten digits. Available online at: http:\/\/yann.lecun.com\/exdb\/mnist\/. Last accessed: Mar. 2019"},{"key":"3495_CR31","unstructured":"Krizhevsky A (2009) Learning multiple layers of features from tiny images. Available online at: https:\/\/www.cs.toronto.edu\/~kriz\/cifar.html. Last accessed: Mar. 2019"},{"key":"3495_CR32","unstructured":"Papernot N, McDaniel P, Goodfellow I (2016) Transferability in machine learning: from phenomena to black-box attacks using adversarial samples. arXiv:1605.07277"},{"issue":"2","key":"3495_CR33","doi-asserted-by":"publisher","first-page":"151","DOI":"10.1007\/s11633-019-1211-x","volume":"17","author":"H Xu","year":"2020","unstructured":"Xu H, Ma Y, Liu H-C, Deb D, Liu H, Tang J-L, Jain AK (2020) Adversarial attacks and defenses in images, graphs and text: A review. Int J Autom Comput 17(2):151\u2013178","journal-title":"Int J Autom Comput"},{"key":"3495_CR34","unstructured":"Hinton G, Vinyals O, Dean J (2015) Distilling the knowledge in a neural network"},{"key":"3495_CR35","unstructured":"Guo C, Rana M, Ciss\u00e9 M, van der Maaten L (2017) Countering adversarial images using input transformations. CoRR, arXiv:1711.00117"},{"key":"3495_CR36","unstructured":"Song Y, Kim T, Nowozin S, Ermon S, Kushman N (2017) Pixeldefend: Leveraging generative models to understand and defend against adversarial examples. CoRR, arXiv:1710.10766"},{"key":"3495_CR37","unstructured":"Metzen J H, Genewein T, Fischer V, Bischoff B (2017) On detecting adversarial perturbations. In: 5th International Conference on Learning Representations, ICLR 2017, Conference Track Proceedings. https:\/\/openreview.net\/forum?id=SJzCSf9xg. OpenReview.net, Toulon"},{"key":"3495_CR38","unstructured":"Hendrycks D, Gimpel K (2017) Early methods for detecting adversarial images. In: 5th International Conference on Learning Representations, ICLR 2017, Workshop Track Proceedings. https:\/\/openreview.net\/forum?id=B1dexpDug. OpenReview.net, Toulon"},{"key":"3495_CR39","doi-asserted-by":"publisher","unstructured":"Katz G, Barrett CW, Dill DL, Julian K, Kochenderfer MJ (2017) Reluplex: An efficient SMT solver for verifying deep neural networks. In: Majumdar R, Kuncak V (eds) Computer aided verification - 29th international conference, CAV 2017, Proceedings, part I, Lecture Notes in Computer Science. https:\/\/doi.org\/10.1007\/978-3-319-63387-9_5, vol 10426. Springer, Heidelberg, pp 97\u2013117","DOI":"10.1007\/978-3-319-63387-9_5"},{"key":"3495_CR40","doi-asserted-by":"crossref","unstructured":"Gehr T, Mirman M, Drachsler-Cohen D, Tsankov P, Chaudhuri S, Vechev M (2018) Ai2: Safety and robustness certification of neural networks with abstract interpretation. In: 2018 IEEE Symposium on Security and Privacy (SP), pp 3\u201318","DOI":"10.1109\/SP.2018.00058"},{"key":"3495_CR41","unstructured":"Hein M, Andriushchenko M (2017) Formal guarantees on the robustness of a classifier against adversarial manipulation. In: Guyon I, von Luxburg U, Bengio S, Wallach HM, Fergus R, Vishwanathan SVN, Garnett R (eds) Advances in neural information processing systems 30: Annual conference on neural information processing systems 2017. https:\/\/proceedings.neurips.cc\/paper\/2017\/hash\/e077e1a544eec4f0307cf5c3c721d944-Abstract.html, Long Beach, pp 2266\u20132276"},{"key":"3495_CR42","doi-asserted-by":"crossref","unstructured":"Liu X, Cheng M, Zhang H, Hsieh C-J (2018) Towards robust neural networks via random self-ensemble","DOI":"10.1007\/978-3-030-01234-2_23"},{"key":"3495_CR43","unstructured":"Buckman J, Roy A, Raffel C, Goodfellow IJ (2018) Thermometer encoding: One hot way to resist adversarial examples. In: 6th International Conference on Learning Representations, ICLR 2018, Conference Track Proceedings. https:\/\/openreview.net\/forum?id=S18Su--CW. OpenReview.net, Vancouver"},{"key":"3495_CR44","unstructured":"Samangouei P, Kabkab M, Chellappa R (2018) Defense-gan: Protecting classifiers against adversarial attacks using generative models. CoRR, arXiv:1805.06605"},{"key":"3495_CR45","unstructured":"Athalye A, Carlini N, Wagner DA (2018) Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples. In: Dy JG, Krause A (eds) Proceedings of the 35th International Conference on Machine Learning, ICML 2018, Proceedings of Machine Learning Research. http:\/\/proceedings.mlr.press\/v80\/athalye18a.html, vol 80. PMLR, Stockholmsm\u00e4ssan, pp 274\u2013283"},{"key":"3495_CR46","unstructured":"Wong E, Kolter JZ (2018) Provable defenses against adversarial examples via the convex outer adversarial polytope. In: Dy JG, Krause A (eds) Proceedings of the 35th International Conference on Machine Learning, ICML 2018, Proceedings of Machine Learning Research. http:\/\/proceedings.mlr.press\/v80\/wong18a.html, vol 80. PMLR, Stockholmsm\u00e4ssan, pp 5283\u20135292"},{"key":"3495_CR47","unstructured":"Qin C, Martens J, Gowal S, Krishnan D, Dvijotham K, Fawzi A, De S, Stanforth R, Kohli P (2019) Adversarial robustness through local linearization. In: Wallach H, Larochelle H, Beygelzimer A, d\u2019Alch\u00e9-Buc F, Fox E, Garnett R (eds) Advances in Neural Information Processing Systems. https:\/\/proceedings.neurips.cc\/paper\/2019file\/0defd533d51ed0a10c5c9dbf93ee78a5-Paper.pdf, vol 32. Curran Associates, Inc."},{"key":"3495_CR48","unstructured":"Zhang H, Yu Y, Jiao J, Xing E, El Ghaoui L, Jordan M (2019) Theoretically principled trade-off between robustness and accuracy. In: International Conference on Machine Learning. PMLR, pp 7472\u20137482"},{"key":"3495_CR49","unstructured":"Liu X, Li Y, Wu C, Hsieh C-J (2019) Adv-BNN: Improved adversarial defense through robust bayesian neural network. In: 7th International Conference on Learning Representations, ICLR 2019. https:\/\/openreview.net\/forum?id=rk4Qso0cKm. OpenReview.net, New Orleans"},{"key":"3495_CR50","unstructured":"Kariyappa S, Qureshi MK (2019) Improving adversarial robustness of ensembles with diversity training. arXiv:1901.09981"},{"key":"3495_CR51","unstructured":"Yang H, Zhang J, Dong H, Inkawhich N, Gardner A, Touchet A, Wilkes W, Berry H, Li H (2020) DVERGE: diversifying vulnerabilities for enhanced robust generation of ensembles. In: Larochelle H, Ranzato M, Hadsell R, Balcan M-F, Lin H-T (eds) Advances in Neural Information Processing Systems 33: Annual Conference on Neural Information Processing Systems 2020, NeurIPS 2020, Virtual. https:\/\/proceedings.neurips.cc\/paper\/2020\/hash\/3ad7c2ebb96fcba7cda0cf54a2e802f5-Abstract.html"},{"key":"3495_CR52","unstructured":"Zhang H, Chen H, Xiao C, Gowal S, Stanforth R, Li B, Boning D S, Hsieh C-J (2020) Towards stable and efficient training of verifiably robust neural networks. In: 8th International Conference on Learning Representations, ICLR 2020. https:\/\/openreview.net\/forum?id=Skxuk1rFwB. OpenReview.net, Addis Ababa"},{"key":"3495_CR53","unstructured":"Croce F, Hein M (2020) Provable robustness against all adversarial $l_p$-perturbations for $p$geq 1$. In: 8th International Conference on Learning Representations, ICLR 2020. https:\/\/openreview.net\/forum?id=rklk_ySYPB. OpenReview.net, Addis Ababa"},{"key":"3495_CR54","unstructured":"Ioffe S, Szegedy C (2015) Batch normalization: Accelerating deep network training by reducing internal covariate shift. In: Bach FR, Blei DM (eds) Proceedings of the 32nd International Conference on Machine Learning, ICML 2015, JMLR Workshop and Conference Proceedings. http:\/\/proceedings.mlr.press\/v37\/ioffe15.html, vol 37. JMLR.org, Lille, pp 448\u2013456"},{"key":"3495_CR55","unstructured":"Madry A, Makelov A, Schmidt L, Tsipras D, Vladu A (2018) Towards deep learning models resistant to adversarial attacks. In: International Conference on Learning Representations"},{"key":"3495_CR56","doi-asserted-by":"crossref","unstructured":"Guo M, Yang Y, Xu R, Liu Z, Lin D (2020) When nas meets robustness: In search of robust architectures against adversarial attacks. In: 2020 IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR), pp 628\u2013637","DOI":"10.1109\/CVPR42600.2020.00071"}],"container-title":["Applied Intelligence"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10489-022-03495-3.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10489-022-03495-3\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10489-022-03495-3.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,1,11]],"date-time":"2023-01-11T11:51:44Z","timestamp":1673437904000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10489-022-03495-3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,5,20]]},"references-count":56,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2023,2]]}},"alternative-id":["3495"],"URL":"https:\/\/doi.org\/10.1007\/s10489-022-03495-3","relation":{},"ISSN":["0924-669X","1573-7497"],"issn-type":[{"value":"0924-669X","type":"print"},{"value":"1573-7497","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,5,20]]},"assertion":[{"value":"10 March 2022","order":1,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"20 May 2022","order":2,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}