{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,13]],"date-time":"2026-05-13T17:37:13Z","timestamp":1778693833702,"version":"3.51.4"},"reference-count":65,"publisher":"Springer Science and Business Media LLC","issue":"20","license":[{"start":{"date-parts":[[2023,7,26]],"date-time":"2023-07-26T00:00:00Z","timestamp":1690329600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2023,7,26]],"date-time":"2023-07-26T00:00:00Z","timestamp":1690329600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"funder":[{"DOI":"10.13039\/501100018542","name":"Natural Science Foundation of Sichuan Province","doi-asserted-by":"publisher","award":["2023NSFSC1440"],"award-info":[{"award-number":["2023NSFSC1440"]}],"id":[{"id":"10.13039\/501100018542","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62203368"],"award-info":[{"award-number":["62203368"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Appl Intell"],"published-print":{"date-parts":[[2023,10]]},"DOI":"10.1007\/s10489-023-04847-3","type":"journal-article","created":{"date-parts":[[2023,7,26]],"date-time":"2023-07-26T04:02:00Z","timestamp":1690344120000},"page":"24492-24508","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":16,"title":["ATGAN: Adversarial training-based GAN for improving adversarial robustness generalization on image classification"],"prefix":"10.1007","volume":"53","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-5024-1628","authenticated-orcid":false,"given":"Desheng","family":"Wang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Weidong","family":"Jin","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yunpu","family":"Wu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Aamir","family":"Khan","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2023,7,26]]},"reference":[{"issue":"7553","key":"4847_CR1","doi-asserted-by":"publisher","first-page":"436","DOI":"10.1038\/nature14539","volume":"521","author":"Y LeCun","year":"2015","unstructured":"LeCun Y, Bengio Y, Hinton GE (2015) Deep learning. Nat 521(7553):436\u2013444. https:\/\/doi.org\/10.1038\/nature14539","journal-title":"Deep learning. Nat"},{"issue":"11","key":"4847_CR2","doi-asserted-by":"publisher","first-page":"2278","DOI":"10.1109\/5.726791","volume":"86","author":"Y LeCun","year":"1998","unstructured":"LeCun Y, Bottou L, Bengio Y, Haffner P (1998) Gradient-based learning applied to document recognition. Proc IEEE 86(11):2278\u20132324","journal-title":"Proc IEEE"},{"key":"4847_CR3","unstructured":"Krizhevsky A, Sutskever I, Hinton GE (2012) Imagenet classification with deep convolutional neural networks. In: Bartlett PL, Pereira FCN, Burges CJC, Bottou L, Weinberger KQ (eds.) Advances in neural information processing systems 25: 26th Annual conference on neural information processing systems 2012. Proceedings of a Meeting Held December 3-6, 2012, Lake Tahoe, Nevada, United States, pp 1106\u20131114"},{"key":"4847_CR4","unstructured":"Simonyan K, Zisserman A (2015) Very deep convolutional networks for large-scale image recognition. In: Bengio Y, LeCun Y (eds.) 3rd International Conference on Learning Representations, ICLR 2015, San Diego, CA, USA, May 7-9, 2015, Conference track proceedings"},{"key":"4847_CR5","doi-asserted-by":"publisher","unstructured":"Szegedy C, Liu W, Jia Y, Sermanet P, Reed SE, Anguelov D, Erhan D, Vanhoucke V, Rabinovich A (2015) Going deeper with convolutions. In: IEEE Conference on Computer Vision and Pattern Recognition, CVPR 2015, Boston, MA, USA, June 7-12, 2015, pp 1\u20139. https:\/\/doi.org\/10.1109\/CVPR.2015.7298594","DOI":"10.1109\/CVPR.2015.7298594"},{"key":"4847_CR6","doi-asserted-by":"publisher","unstructured":"He K, Zhang X, Ren S, Sun J (2016) Deep residual learning for image recognition. In: 2016 IEEE Conference on Computer Vision and Pattern Recognition, CVPR 2016, Las Vegas, NV, USA, June 27-30, 2016, pp 770\u2013778. https:\/\/doi.org\/10.1109\/CVPR.2016.90","DOI":"10.1109\/CVPR.2016.90"},{"key":"4847_CR7","doi-asserted-by":"publisher","unstructured":"Huang G, Liu Z, van der Maaten L, Weinberger KQ (2017) Densely connected convolutional networks. In: 2017 IEEE Conference on Computer Vision and Pattern Recognition, CVPR 2017, Honolulu, HI, USA, July 21-26, 2017, pp 2261\u20132269 . https:\/\/doi.org\/10.1109\/CVPR.2017.243","DOI":"10.1109\/CVPR.2017.243"},{"key":"4847_CR8","doi-asserted-by":"publisher","unstructured":"Girshick RB (2015) Fast R-CNN. In: 2015 IEEE International Conference on Computer Vision, ICCV 2015, Santiago, Chile, December 7-13, 2015, pp 1440\u20131448. https:\/\/doi.org\/10.1109\/ICCV.2015.169","DOI":"10.1109\/ICCV.2015.169"},{"issue":"6","key":"4847_CR9","doi-asserted-by":"publisher","first-page":"1137","DOI":"10.1109\/TPAMI.2016.2577031","volume":"39","author":"S Ren","year":"2017","unstructured":"Ren S, He K, Girshick RB, Sun J (2017) Faster R-CNN: towards real-time object detection with region proposal networks. IEEE Trans Pattern Anal Mach Intell 39(6):1137\u20131149. https:\/\/doi.org\/10.1109\/TPAMI.2016.2577031","journal-title":"IEEE Trans Pattern Anal Mach Intell"},{"key":"4847_CR10","doi-asserted-by":"publisher","unstructured":"Redmon J, Divvala SK, Girshick RB, Farhadi A (2016) You only look once: Unified, real-time object detection. In: 2016 IEEE Conference on Computer Vision and Pattern Recognition, CVPR 2016, Las Vegas, NV, USA, June 27-30, 2016, pp 779\u2013788. https:\/\/doi.org\/10.1109\/CVPR.2016.91","DOI":"10.1109\/CVPR.2016.91"},{"key":"4847_CR11","doi-asserted-by":"publisher","unstructured":"Long J, Shelhamer E, Darrell T (2015) Fully convolutional networks for semantic segmentation. In: IEEE Conference on Computer Vision and Pattern Recognition, CVPR 2015, Boston, MA, USA, June 7-12, 2015, pp 3431\u20133440. https:\/\/doi.org\/10.1109\/CVPR.2015.7298965","DOI":"10.1109\/CVPR.2015.7298965"},{"key":"4847_CR12","doi-asserted-by":"publisher","unstructured":"Ronneberger O, Fischer P, Brox T (2015) U-net: Convolutional networks for biomedical image segmentation. In: Navab N, Hornegger J, III, WMW, Frangi, AF (eds.) Medical Image Computing and Computer-Assisted Intervention - MICCAI 2015 - 18th International Conference Munich, Germany, October 5 - 9, 2015, Proceedings, Part III. Lecture Notes in Computer Science, vol 9351, pp 234\u2013241. https:\/\/doi.org\/10.1007\/978-3-319-24574-4_28","DOI":"10.1007\/978-3-319-24574-4_28"},{"issue":"4","key":"4847_CR13","doi-asserted-by":"publisher","first-page":"834","DOI":"10.1109\/TPAMI.2017.2699184","volume":"40","author":"L Chen","year":"2018","unstructured":"Chen L, Papandreou G, Kokkinos I, Murphy K, Yuille AL (2018) Deeplab: Semantic image segmentation with deep convolutional nets, atrous convolution, and fully connected crfs. IEEE Trans Pattern Anal Mach Intell 40(4):834\u2013848. https:\/\/doi.org\/10.1109\/TPAMI.2017.2699184","journal-title":"IEEE Trans Pattern Anal Mach Intell"},{"key":"4847_CR14","unstructured":"Szegedy C, Zaremba W, Sutskever I, Bruna J, Erhan D, Goodfellow IJ, Fergus R (2014) Intriguing properties of neural networks. In: Bengio Y, LeCun Y (eds.) 2nd International Conference on Learning Representations, ICLR 2014, Banff, AB, Canada, April 14-16, 2014, Conference Track Proceedings"},{"key":"4847_CR15","unstructured":"Goodfellow IJ, Shlens J, Szegedy C (2015) Explaining and harnessing adversarial examples. In: Bengio Y, LeCun Y (eds.) 3rd International Conference on Learning Representations, ICLR 2015, San Diego, CA, USA, May 7-9, 2015, Conference Track Proceedings"},{"key":"4847_CR16","doi-asserted-by":"publisher","unstructured":"Eykholt K, Evtimov I, Fernandes E, Li B, Rahmati A, Xiao C, Prakash A, Kohno T, Song D (2018) Robust physical-world attacks on deep learning visual classification. In: 2018 IEEE Conference on Computer Vision and Pattern Recognition, CVPR 2018, Salt Lake City, UT, USA, June 18-22, 2018, pp 1625\u20131634. https:\/\/doi.org\/10.1109\/CVPR.2018.00175","DOI":"10.1109\/CVPR.2018.00175"},{"key":"4847_CR17","doi-asserted-by":"publisher","unstructured":"Xu K, Zhang G, Liu S, Fan Q, Sun M, Chen H, Chen P, Wang Y, Lin X (2020) Adversarial t-shirt! evading person detectors in a physical world. In: Vedaldi A, Bischof H, Brox T, Frahm J (eds.) Computer Vision - ECCV 2020 - 16th European Conference, Glasgow, UK, August 23-28, 2020, Proceedings, Part V. Lecture Notes in Computer Science, vol 12350, pp 665\u2013681. https:\/\/doi.org\/10.1007\/978-3-030-58558-7_39","DOI":"10.1007\/978-3-030-58558-7_39"},{"key":"4847_CR18","unstructured":"Kurakin A, Goodfellow IJ, Bengio S (2017) Adversarial examples in the physical world. In: 5th International Conference on Learning Representations, ICLR 2017, Toulon, France, April 24-26, 2017, Workshop Track Proceedings"},{"key":"4847_CR19","doi-asserted-by":"publisher","unstructured":"Papernot N, McDaniel PD, Jha S, Fredrikson M, Celik ZB, Swami A (2016) The limitations of deep learning in adversarial settings. In: IEEE European Symposium on Security and Privacy, EuroS &P 2016, Saarbr\u00fccken, Germany, March 21-24, 2016, pp 372\u2013387. https:\/\/doi.org\/10.1109\/EuroSP.2016.36","DOI":"10.1109\/EuroSP.2016.36"},{"issue":"5","key":"4847_CR20","doi-asserted-by":"publisher","first-page":"828","DOI":"10.1109\/TEVC.2019.2890858","volume":"23","author":"J Su","year":"2019","unstructured":"Su J, Vargas DV, Sakurai K (2019) One pixel attack for fooling deep neural networks. IEEE Trans Evol Comput 23(5):828\u2013841. https:\/\/doi.org\/10.1109\/TEVC.2019.2890858","journal-title":"IEEE Trans Evol Comput"},{"key":"4847_CR21","doi-asserted-by":"publisher","unstructured":"Carlini N, Wagner, DA (2017) Towards evaluating the robustness of neural networks. In: 2017 IEEE Symposium on Security and Privacy, SP 2017, San Jose, CA, USA, May 22-26, 2017, pp 39\u201357. https:\/\/doi.org\/10.1109\/SP.2017.49","DOI":"10.1109\/SP.2017.49"},{"key":"4847_CR22","doi-asserted-by":"publisher","unstructured":"Moosavi-Dezfooli S, Fawzi A, Frossard P (2016) Deepfool: A simple and accurate method to fool deep neural networks. In: 2016 IEEE Conference on Computer Vision and Pattern Recognition, CVPR 2016, Las Vegas, NV, USA, June 27-30, 2016, pp 2574\u20132582. https:\/\/doi.org\/10.1109\/CVPR.2016.282","DOI":"10.1109\/CVPR.2016.282"},{"key":"4847_CR23","unstructured":"Chen P, Sharma Y, Zhang H, Yi J, Hsieh C (2018) EAD: elastic-net attacks to deep neural networks via adversarial examples. In: McIlraith SA, Weinberger KQ (eds.) Proceedings of the Thirty-Second AAAI Conference on Artificial Intelligence, (AAAI-18), the 30th Innovative Applications of Artificial Intelligence (IAAI-18), and the 8th AAAI Symposium on Educational Advances in Artificial Intelligence (EAAI-18), New Orleans, Louisiana, USA, February 2-7, 2018, pp 10\u201317"},{"key":"4847_CR24","unstructured":"Madry A, Makelov A, Schmidt L, Tsipras D, Vladu A (2018) Towards deep learning models resistant to adversarial attacks. In: 6th International Conference on Learning Representations, ICLR 2018, Vancouver, BC, Canada, April 30 - May 3, 2018, Conference Track Proceedings"},{"key":"4847_CR25","doi-asserted-by":"publisher","unstructured":"Li P, Yi J, Zhou B, Zhang L (2019) Improving the robustness of deep neural networks via adversarial training with triplet loss. In: Kraus, S (ed.) Proceedings of the Twenty-Eighth International Joint Conference on Artificial Intelligence, IJCAI 2019, Macao, China, August 10-16, 2019, pp 2909\u20132915. https:\/\/doi.org\/10.24963\/ijcai.2019\/403","DOI":"10.24963\/ijcai.2019\/403"},{"key":"4847_CR26","unstructured":"Dziugaite GK, Ghahramani Z, Roy DM (2016) A study of the effect of JPG compression on adversarial images. arXiv:1608.00853"},{"key":"4847_CR27","unstructured":"Wang Q, Guo W, Zhang K, II AGO, Xing X, Giles CL, Liu X (2016) Learning adversary-resistant deep neural networks. arXiv:1612.01401"},{"key":"4847_CR28","unstructured":"Gu S, Rigazio L (2015) Towards deep neural network architectures robust to adversarial examples. In: Bengio Y LeCun, Y, (eds) 3rd International Conference on Learning Representations, ICLR 2015, San Diego, CA, USA, May 7\u20139, 2015. Workshop Track Proceedings"},{"key":"4847_CR29","doi-asserted-by":"crossref","unstructured":"Ross AS, Doshi-Velez, F (2018) Improving the adversarial robustness and interpretability of deep neural networks by regularizing their input gradients. In: McIlraith SA, Weinberger KQ (eds.) Proceedings of the Thirty-Second AAAI Conference on Artificial Intelligence, (AAAI-18), the 30th Innovative Applications of Artificial Intelligence (IAAI-18), and the 8th AAAI Symposium on Educational Advances in Artificial Intelligence (EAAI-18), New Orleans, Louisiana, USA, February 2-7, 2018, pp 1660\u20131669. https:\/\/www.aaai.org\/ocs\/index.php\/AAAI\/AAAI18\/paper\/view\/17337","DOI":"10.1609\/aaai.v32i1.11504"},{"key":"4847_CR30","doi-asserted-by":"publisher","unstructured":"Papernot N, McDaniel PD, Wu X, Jha S, Swami A (2016) Distillation as a defense to adversarial perturbations against deep neural networks. In: IEEE Symposium on Security and Privacy, SP 2016, San Jose, CA, USA, May 22-26, 2016, pp. 582\u2013597. https:\/\/doi.org\/10.1109\/SP.2016.41","DOI":"10.1109\/SP.2016.41"},{"key":"4847_CR31","unstructured":"Ciss\u00e9 M, Adi Y, Neverova N, Keshet J (2017) Houdini: Fooling deep structured visual and speech recognition models with adversarial examples. In: Guyon I, von Luxburg U, Bengio S, Wallach HM, Fergus R, Vishwanathan SVN, Garnett R (eds.) Advances in neural information processing systems 30: Annual conference on neural information processing systems 2017, December 4-9, 2017, Long Beach, CA, USA, pp 6977\u20136987. https:\/\/proceedings.neurips.cc\/paper\/2017\/hash\/d494020ff8ec181ef98ed97ac 3f25453-Abstract.html"},{"key":"4847_CR32","unstructured":"Gao J, Wang B, Lin Z, Xu W, Qi Y (2017) Deepcloak: Masking deep neural network models for robustness against adversarial samples. In: 5th International Conference on Learning Representations, ICLR 2017, Toulon, France, April 24-26, 2017, Workshop Track Proceedings. https:\/\/openreview.net\/forum?id=r1X_kR4Yl"},{"key":"4847_CR33","doi-asserted-by":"publisher","unstructured":"Akhtar N, Liu J, Mian A (2018) Defense against universal adversarial perturbations. In: 2018 IEEE Conference on Computer Vision and Pattern Recognition, CVPR 2018, Salt Lake City, UT, USA, June 18-22, 2018, pp 3389\u20133398. https:\/\/doi.org\/10.1109\/CVPR.2018.00357. http:\/\/openaccess.thecvf.com\/content_cvpr_2018\/html\/Akhtar_Defense_Against_Universal_CVPR_2018_paper.html","DOI":"10.1109\/CVPR.2018.00357"},{"key":"4847_CR34","unstructured":"Lee H, Han S, Lee J (2017) Generative adversarial trainer: Defense to adversarial perturbations with GAN. arXiv:1705.03387"},{"key":"4847_CR35","doi-asserted-by":"crossref","unstructured":"Xu W, Evans D, Qi Y (2018) Feature squeezing: Detecting adversarial examples in deep neural networks. In: 25th Annual network and distributed system security symposium, NDSS 2018, San Diego, California, USA, February 18-21, 2018","DOI":"10.14722\/ndss.2018.23198"},{"key":"4847_CR36","unstructured":"Song Y, Kim T, Nowozin S, Ermon S, Kushman N (2018) Pixeldefend: Leveraging generative models to understand and defend against adversarial examples. In: 6th International Conference on Learning Representations, ICLR 2018, Vancouver, BC, Canada, April 30 - May 3, 2018, Conference Track Proceedings"},{"key":"4847_CR37","unstructured":"Samangouei P, Kabkab M, Chellappa R (2018) Defense-gan: Protecting classifiers against adversarial attacks using generative models. In: 6th International Conference on Learning Representations, ICLR 2018, Vancouver, BC, Canada, April 30 - May 3, 2018, Conference Track Proceedings"},{"key":"4847_CR38","doi-asserted-by":"publisher","unstructured":"Meng D, Chen H (2017) Magnet: A two-pronged defense against adversarial examples. In: Thuraisingham BM, Evans D, Malkin T, Xu D (eds.) Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, CCS 2017, Dallas, TX, USA, October 30 - November 03, 2017, pp 135\u2013147. https:\/\/doi.org\/10.1145\/3133956.3134057","DOI":"10.1145\/3133956.3134057"},{"key":"4847_CR39","doi-asserted-by":"publisher","unstructured":"Jin G, Shen S, Zhang D, Dai F, Zhang Y (2019) APE-GAN: adversarial perturbation elimination with GAN. In: IEEE International Conference on Acoustics, Speech and Signal Processing, ICASSP 2019, Brighton, United Kingdom, May 12-17, 2019, pp 3842\u20133846. https:\/\/doi.org\/10.1109\/ICASSP.2019.8683044","DOI":"10.1109\/ICASSP.2019.8683044"},{"key":"4847_CR40","unstructured":"Athalye A, Carlini N, Wagner, DA (2018) Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples. In: Dy JG, Krause A (eds.) Proceedings of the 35th International Conference on Machine Learning, ICML 2018, Stockholmsm\u00e4ssan, Stockholm, Sweden, July 10-15, 2018. Proceedings of machine learning research, vol 80, pp 274\u2013283"},{"key":"4847_CR41","unstructured":"Carlini N, Wagner, DA (2017) Magnet and \"efficient defenses against adversarial attacks\" are not robust to adversarial examples. arXiv:1711.08478"},{"key":"4847_CR42","doi-asserted-by":"publisher","unstructured":"Isola P, Zhu J, Zhou T, Efros AA (2017) Image-to-image translation with conditional adversarial networks. In: 2017 IEEE Conference on Computer Vision and Pattern Recognition, CVPR 2017, Honolulu, HI, USA, July 21-26, 2017, pp 5967\u20135976. https:\/\/doi.org\/10.1109\/CVPR.2017.632","DOI":"10.1109\/CVPR.2017.632"},{"issue":"8","key":"4847_CR43","doi-asserted-by":"publisher","first-page":"4066","DOI":"10.1109\/TIP.2018.2836316","volume":"27","author":"C Wang","year":"2018","unstructured":"Wang C, Xu C, Wang C, Tao D (2018) Perceptual adversarial networks for image-to-image transformation. IEEE Trans Image Process 27(8):4066\u20134079. https:\/\/doi.org\/10.1109\/TIP.2018.2836316","journal-title":"IEEE Trans Image Process"},{"key":"4847_CR44","doi-asserted-by":"publisher","unstructured":"Wang T, Liu M, Zhu J, Tao A, Kautz J, Catanzaro B (2018) High-resolution image synthesis and semantic manipulation with conditional gans. In: 2018 IEEE Conference on Computer Vision and Pattern Recognition, CVPR 2018, Salt Lake City, UT, USA, June 18-22, 2018, pp 8798\u2013880. https:\/\/doi.org\/10.1109\/CVPR.2018.00917. http:\/\/openaccess.thecvf.com\/content_cvpr_2018\/html\/Wang_High-Resolut ion_Image_Synthesis_CVPR_2018_paper.html","DOI":"10.1109\/CVPR.2018.00917"},{"key":"4847_CR45","doi-asserted-by":"publisher","unstructured":"Zhu J, Kr\u00e4henb\u00fchl P, Shechtman E, Efros AA (2016) Generative visual manipulation on the natural image manifold. In: Leibe B, Matas J, Sebe N, Welling M (eds.) Computer Vision - ECCV 2016 - 14th European Conference, Amsterdam, The Netherlands, October 11-14, 2016, Proceedings, Part V. Lecture Notes in Computer Science, vol 9909, pp 597\u2013613. https:\/\/doi.org\/10.1007\/978-3-319-46454-1_36","DOI":"10.1007\/978-3-319-46454-1_36"},{"key":"4847_CR46","doi-asserted-by":"publisher","unstructured":"Hao G, Yu H, Zheng W (2018) MIXGAN: learning concepts from different domains for mixture generation. In: Lang, J. (ed.) Proceedings of the 27th International joint conference on artificial intelligence, IJCAI 2018, July 13-19, 2018, Stockholm, Sweden, pp 2212\u20132219. https:\/\/doi.org\/10.24963\/ijcai.2018\/306","DOI":"10.24963\/ijcai.2018\/306"},{"key":"4847_CR47","doi-asserted-by":"publisher","unstructured":"Kupyn O, Budzan V, Mykhailych M, Mishkin D, Matas J (2018) Deblurgan: Blind motion deblurring using conditional adversarial networks. In: 2018 IEEE Conference on Computer Vision and Pattern Recognition, CVPR 2018, Salt Lake City, UT, USA, June 18-22, 2018, pp 8183\u20138192 . https:\/\/doi.org\/10.1109\/CVPR.2018.00854. http:\/\/openaccess.thecvf.com\/content_cvpr_2018\/html\/Kupyn_DeblurGAN_ Blind_Motion_CVPR_2018_paper.html","DOI":"10.1109\/CVPR.2018.00854"},{"key":"4847_CR48","doi-asserted-by":"publisher","unstructured":"Regmi K, Borji A (2018) Cross-view image synthesis using conditional gans. In: 2018 IEEE Conference on Computer Vision and Pattern Recognition, CVPR 2018, Salt Lake City, UT, USA, June 18-22, 2018, pp 3501\u20133510. https:\/\/doi.org\/10.1109\/CVPR.2018.00369. http:\/\/openaccess.thecvf.com\/content_cvpr_2018\/html\/Regmi_Cross-View_Image_Synthesis_CVPR_2018_paper.html","DOI":"10.1109\/CVPR.2018.00369"},{"key":"4847_CR49","unstructured":"Dhillon GS, Azizzadenesheli K, Lipton ZC, Bernstein J, Kossaifi J, Khanna A, Anandkumar A (2018) Stochastic activation pruning for robust adversarial defense. In: 6th International Conference on Learning Representations, ICLR 2018, Vancouver, BC, Canada, April 30 - May 3, 2018, Conference Track Proceedings"},{"key":"4847_CR50","unstructured":"Kannan H, Kurakin A, Goodfellow IJ (2018) Adversarial logit pairing. arXiv:1803.06373"},{"key":"4847_CR51","unstructured":"Zhang H, Yu Y, Jiao J, Xing EP, Ghaoui LE, Jordan MI (2019) Theoretically principled trade-off between robustness and accuracy. In: Chaudhuri K, Salakhutdinov R (eds.) Proceedings of the 36th International Conference on Machine Learning, ICML 2019, 9-15 June 2019, Long Beach, California, USA. Proceedings of machine learning research, vol 97, pp 7472\u20137482"},{"key":"4847_CR52","doi-asserted-by":"publisher","unstructured":"Jin G, Yi X, Huang W, Schewe S, Huang X (2022) Enhancing adversarial training with second-order statistics of weights. In: IEEE\/CVF Conference on Computer Vision and Pattern Recognition, CVPR 2022, New Orleans, LA, USA, June 18-24, 2022, pp 15252\u201315262. https:\/\/doi.org\/10.1109\/CVPR52688.2022.01484","DOI":"10.1109\/CVPR52688.2022.01484"},{"key":"4847_CR53","doi-asserted-by":"publisher","unstructured":"Li T, Wu Y, Chen S, Fang K, Huang X (2022) Subspace adversarial training. In: IEEE\/CVF Conference on Computer Vision and Pattern Recognition, CVPR 2022, New Orleans, LA, USA, June 18-24, 2022, pp 13399\u201313408 . https:\/\/doi.org\/10.1109\/CVPR52688.2022.01305","DOI":"10.1109\/CVPR52688.2022.01305"},{"key":"4847_CR54","unstructured":"Shafahi A, Najibi M, Ghiasi A, Xu Z, Dickerson JP, Studer C, Davis LS, Taylor G, Goldstein T (2019) Adversarial training for free! In: Wallach HM, Larochelle H, Beygelzimer A, d\u2019Alch\u00e9-Buc F, Fox EB, Garnett R (eds.) Advances in neural information processing systems 32: Annual conference on neural information processing systems 2019, NeurIPS 2019, December 8-14, 2019, Vancouver, BC, Canada, pp 3353\u20133364"},{"key":"4847_CR55","unstructured":"Goodfellow IJ, Pouget-Abadie J, Mirza M, Xu B, Warde-Farley D, Ozair S, Courville AC, Bengio Y (2014) Generative adversarial nets. In: Ghahramani Z, Welling M, Cortes C, Lawrence ND, Weinberger KQ (eds.) Advances in neural information processing systems 27: Annual conference on neural information processing systems 2014, December 8-13 2014, Montreal, Quebec, Canada, pp 2672\u20132680. https:\/\/proceedings.neurips.cc\/paper\/2014\/hash\/5ca3e9b122f61f8f06494c97b 1afccf3-Abstract.html"},{"key":"4847_CR56","unstructured":"Radford A, Metz L, Chintala S (2016) Unsupervised representation learning with deep convolutional generative adversarial networks. In: Bengio Y, LeCun Y (eds.) 4th International Conference on Learning Representations, ICLR 2016, San Juan, Puerto Rico, May 2-4, 2016, Conference Track Proceedings. arXiv:1511.06434"},{"key":"4847_CR57","unstructured":"Odena A, Olah C, Shlens J (2017). Conditional image synthesis with auxiliary classifier gans. In: Precup D, Teh YW (eds.) Proceedings of the 34th International Conference on Machine Learning, ICML 2017, Sydney, NSW, Australia, 6-11 August 2017. Proceedings of machine learning research, vol 70, pp 2642\u20132651 http:\/\/proceedings.mlr.press\/v70\/odena17a.html"},{"key":"4847_CR58","doi-asserted-by":"publisher","unstructured":"Liu X, Hsieh C (2019) Rob-gan: Generator, discriminator, and adversarial attacker. In: IEEE Conference on Computer Vision and Pattern Recognition, CVPR 2019, Long Beach, CA, USA, June 16-20, 2019, pp 11234\u201311243. https:\/\/doi.org\/10.1109\/CVPR.2019.01149. http:\/\/openaccess.thecvf.com\/content_CVPR_2019\/html\/Liu_Rob-GAN_Generator_Discriminator_and_Adversarial_Attacker_CVPR_2019_paper.html","DOI":"10.1109\/CVPR.2019.01149"},{"key":"4847_CR59","doi-asserted-by":"publisher","unstructured":"Liu G, Khalil I, Khreishah A (2019) Gandef: A GAN based adversarial training defense for neural network classifier. In: ICT Systems Security and Privacy Protection - 34th IFIP TC 11 International Conference, SEC 2019, Lisbon, Portugal, June 25-27, 2019, Proceedings. IFIP Advances in Information and Communication Technology, vol 562, pp 19\u201332. https:\/\/doi.org\/10.1007\/978-3-030-22312-0_2","DOI":"10.1007\/978-3-030-22312-0_2"},{"key":"4847_CR60","unstructured":"Dong J, Lin T (2019) Margingan: Adversarial training in semi-supervised learning. In: Advances in neural information processing systems 32: Annual conference on neural information processing systems 2019, NeurIPS 2019, December 8-14, 2019, Vancouver, BC, Canada, pp 10440\u201310449. https:\/\/proceedings.neurips.cc\/paper\/2019\/hash\/517f24c02e620d5a4dac1db388664a63-Abstract.html"},{"key":"4847_CR61","doi-asserted-by":"publisher","unstructured":"He K, Zhang X, Ren S, Sun J (2016) Identity mappings in deep residual networks. In: Leibe B, Matas J, Sebe N, Welling M (eds.) Computer Vision - ECCV 2016 - 14th European Conference, Amsterdam, The Netherlands, October 11-14, 2016, Proceedings, Part IV. Lecture notes in computer science, vol 9908, pp 630\u2013645. https:\/\/doi.org\/10.1007\/978-3-319-46493-0_38","DOI":"10.1007\/978-3-319-46493-0_38"},{"key":"4847_CR62","doi-asserted-by":"crossref","unstructured":"Zagoruyko S, Komodakis N (2016) Wide residual networks. In: Wilson, RC, Hancock, ER, Smith, WAP (eds.) Proceedings of the british machine vision conference 2016, BMVC 2016, York, UK, September 19-22, 2016. http:\/\/www.bmva.org\/bmvc\/2016\/papers\/paper087\/index.html","DOI":"10.5244\/C.30.87"},{"key":"4847_CR63","doi-asserted-by":"publisher","unstructured":"G\u00f6pfert C, G\u00f6pfert JP, Hammer B (2019) Adversarial robustness curves. In: Cellier P, Driessens K (eds.) Machine learning and knowledge discovery in databases - International Workshops of ECML PKDD 2019, W\u00fcrzburg, Germany, September 16-20, 2019, Proceedings, Part I. Communications in computer and information science, vol 1167, pp 172\u2013179 https:\/\/doi.org\/10.1007\/978-3-030-43823-4_15","DOI":"10.1007\/978-3-030-43823-4_15"},{"key":"4847_CR64","doi-asserted-by":"publisher","unstructured":"Risse N, G\u00f6pfert C, G\u00f6pfert JP (2021) How to compare adversarial robustness of classifiers from a global perspective. In: Farkas I, Masulli P, Otte S, Wermter S (eds.) Artificial neural networks and machine learning - ICANN 2021 - 30th International conference on artificial neural networks, Bratislava, Slovakia, September 14-17, 2021, Proceedings, Part I. Lecture notes in computer science, vol 12891, pp 29\u201341 https:\/\/doi.org\/10.1007\/978-3-030-86362-3_3","DOI":"10.1007\/978-3-030-86362-3_3"},{"key":"4847_CR65","unstructured":"Simonyan K, Vedaldi A, Zisserman A (2014) Deep inside convolutional networks: Visualising image classification models and saliency maps. In: Bengio Y, LeCun Y (eds.) 2nd International Conference on Learning Representations, ICLR 2014, Banff, AB, Canada, April 14-16, 2014, Workshop track proceedings. arXiv:1312.6034"}],"container-title":["Applied Intelligence"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10489-023-04847-3.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10489-023-04847-3\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10489-023-04847-3.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,10,21]],"date-time":"2023-10-21T16:26:05Z","timestamp":1697905565000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10489-023-04847-3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,7,26]]},"references-count":65,"journal-issue":{"issue":"20","published-print":{"date-parts":[[2023,10]]}},"alternative-id":["4847"],"URL":"https:\/\/doi.org\/10.1007\/s10489-023-04847-3","relation":{},"ISSN":["0924-669X","1573-7497"],"issn-type":[{"value":"0924-669X","type":"print"},{"value":"1573-7497","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,7,26]]},"assertion":[{"value":"28 June 2023","order":1,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"26 July 2023","order":2,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare that they have no conflicts of interest.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflicts of interest"}}]}}