{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,27]],"date-time":"2025-11-27T18:08:53Z","timestamp":1764266933425,"version":"3.46.0"},"reference-count":42,"publisher":"Springer Science and Business Media LLC","issue":"8","license":[{"start":{"date-parts":[[2024,1,24]],"date-time":"2024-01-24T00:00:00Z","timestamp":1706054400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,1,24]],"date-time":"2024-01-24T00:00:00Z","timestamp":1706054400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Mach Learn"],"published-print":{"date-parts":[[2024,8]]},"DOI":"10.1007\/s10994-023-06417-7","type":"journal-article","created":{"date-parts":[[2024,1,24]],"date-time":"2024-01-24T15:01:58Z","timestamp":1706108518000},"page":"5601-5622","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["DPG: a model to build feature subspace against adversarial patch attack"],"prefix":"10.1007","volume":"113","author":[{"given":"Yunsheng","family":"Xue","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4328-6507","authenticated-orcid":false,"given":"Mi","family":"Wen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wei","family":"He","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Weiwei","family":"Li","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2024,1,24]]},"reference":[{"key":"6417_CR1","unstructured":"Brown, T.B, Man\u00e9, D., Roy, A., et\u00a0al. (2017). Adversarial patch. arXiv preprint arXiv:1712.09665."},{"key":"6417_CR2","unstructured":"Chen, J., Ma, T., & Xiao, C. (2018). Fastgcn: Fast learning with graph convolutional networks via importance sampling. arXiv preprint arXiv:1801.10247."},{"issue":"5","key":"6417_CR3","doi-asserted-by":"publisher","first-page":"1433","DOI":"10.1007\/s10994-023-06329-6","volume":"112","author":"Z Chen","year":"2023","unstructured":"Chen, Z., Kailkhura, B., & Zhou, Y. (2023). An accelerated proximal algorithm for regularized nonconvex and nonsmooth bi-level optimization. Machine Learning, 112(5), 1433\u201363.","journal-title":"Machine Learning"},{"key":"6417_CR4","unstructured":"Cohen, J., Rosenfeld, E., & Kolter, Z. (2019). Certified adversarial robustness via randomized smoothing. In: International Conference on Machine Learning, PMLR, p 1310\u20131320."},{"key":"6417_CR5","unstructured":"Das, N., Shanbhogue, M., Chen, S.T., et\u00a0al. (2017). Keeping the bad guys out: Protecting and vaccinating deep learning with jpeg compression. arXiv preprint arXiv:1705.02900."},{"key":"6417_CR6","unstructured":"Dosovitskiy, A., Beyer, L., Kolesnikov, A., et\u00a0al. (2020). An image is worth 16x16 words: Transformers for image recognition at scale. arXiv preprint arXiv:2010.11929."},{"issue":"7","key":"6417_CR7","first-page":"2121","volume":"12","author":"J Duchi","year":"2011","unstructured":"Duchi, J., Hazan, E., & Singer, Y. (2011). Adaptive subgradient methods for online learning and stochastic optimization. Journal of Machine Learning Research, 12(7), 2121\u20132159.","journal-title":"Journal of Machine Learning Research"},{"key":"6417_CR8","unstructured":"Dziugaite, G.K., Ghahramani, Z., Roy, D.M., (2016). A study of the effect of jpg compression on adversarial images. arXiv preprint arXiv:1608.00853."},{"key":"6417_CR9","unstructured":"Evtimov, I., Eykholt, K., Fernandes, E., et\u00a0al. (2017). Robust physical-world attacks on machine learning models. arXiv preprint arXiv:1707.08945 2(3):4"},{"issue":"4","key":"6417_CR10","doi-asserted-by":"publisher","first-page":"1327","DOI":"10.1007\/s10994-022-06148-1","volume":"111","author":"J Gao","year":"2022","unstructured":"Gao, J., Lan, J., Wang, B., et al. (2022). Sdanet: Spatial deep attention-based for point cloud classification and segmentation. Machine Learning, 111(4), 1327\u20131348.","journal-title":"Machine Learning"},{"key":"6417_CR11","unstructured":"Hamilton, W., Ying, Z., & Leskovec, J., (2017). Inductive representation learning on large graphs. Advances in Neural Information Processing Systems 30."},{"key":"6417_CR12","unstructured":"Han, K., Wang, Y., Guo, J., et\u00a0al. (2022). Vision GNN: An image is worth graph of nodes. arXiv preprint arXiv:2206.00272"},{"key":"6417_CR13","doi-asserted-by":"publisher","first-page":"102217","DOI":"10.1016\/j.media.2021.102217","volume":"75","author":"J Hao","year":"2022","unstructured":"Hao, J., Liu, J., Pereira, E., et al. (2022). Uncertainty-guided graph attention network for parapneumonic effusion diagnosis. Medical Image Analysis, 75, 102217.","journal-title":"Medical Image Analysis"},{"key":"6417_CR14","doi-asserted-by":"crossref","unstructured":"Hayes, J., (2018). On visible adversarial perturbations & digital watermarking. In: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition Workshops, p 1597\u20131604.","DOI":"10.1109\/CVPRW.2018.00210"},{"key":"6417_CR15","doi-asserted-by":"crossref","unstructured":"He, K., Zhang, X., Ren, S., et\u00a0al. (2016). Deep residual learning for image recognition. In: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, p 770\u2013778.","DOI":"10.1109\/CVPR.2016.90"},{"key":"6417_CR16","doi-asserted-by":"publisher","first-page":"747","DOI":"10.1007\/s10994-019-05783-5","volume":"108","author":"M Huang","year":"2019","unstructured":"Huang, M., Zhuang, F., Zhang, X., et al. (2019). Supervised representation learning for multi-label classification. Machine Learning, 108, 747\u2013763.","journal-title":"Machine Learning"},{"key":"6417_CR17","doi-asserted-by":"crossref","unstructured":"Khirirat, S., Feyzmahdavian, H.R., Johansson, M., (2017). Mini-batch gradient descent: Faster convergence under data sparsity. In: 2017 IEEE 56th Annual Conference on Decision and Control (CDC), IEEE, p 2880\u20132887.","DOI":"10.1109\/CDC.2017.8264077"},{"key":"6417_CR18","unstructured":"Kingma, D.P., & Ba, J., (2014). Adam: A method for stochastic optimization. arXiv preprint arXiv:1412.6980."},{"key":"6417_CR19","first-page":"6465","volume":"33","author":"A Levine","year":"2020","unstructured":"Levine, A., & Feizi, S. (2020). (de) randomized smoothing for certifiable defense against patch attacks. Advances in Neural Information Processing Systems, 33, 6465\u20136475.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"6417_CR20","doi-asserted-by":"crossref","unstructured":"Liu, J., Levine, A., Lau, CP., et\u00a0al. (2022). Segment and complete: Defending object detectors against adversarial patch attacks with robust patch detection. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, p 14973\u201314982.","DOI":"10.1109\/CVPR52688.2022.01455"},{"key":"6417_CR21","doi-asserted-by":"publisher","first-page":"1711","DOI":"10.1109\/TIP.2019.2940533","volume":"29","author":"A Mustafa","year":"2019","unstructured":"Mustafa, A., Khan, S. H., Hayat, M., et al. (2019). Image super-resolution as a defense against adversarial attacks. IEEE Transactions on Image Processing, 29, 1711\u20131724.","journal-title":"IEEE Transactions on Image Processing"},{"key":"6417_CR22","doi-asserted-by":"crossref","unstructured":"Naseer, M., Khan S., Porikli, F., (2019). Local gradients smoothing: Defense against localized adversarial attacks. In: 2019 IEEE Winter Conference on Applications of Computer Vision (WACV), IEEE, p 1300\u20131307..","DOI":"10.1109\/WACV.2019.00143"},{"key":"6417_CR23","doi-asserted-by":"crossref","unstructured":"Papernot, N., McDaniel, P., Wu X., et\u00a0al. (2016). Distillation as a defense to adversarial perturbations against deep neural networks. In: 2016 IEEE Symposium on Security and Privacy (SP), IEEE, p 582\u2013597","DOI":"10.1109\/SP.2016.41"},{"key":"6417_CR24","doi-asserted-by":"publisher","first-page":"117","DOI":"10.1016\/j.media.2018.06.001","volume":"48","author":"S Parisot","year":"2018","unstructured":"Parisot, S., Ktena, S. I., Ferrante, E., et al. (2018). Disease prediction using graph convolutional networks: Application to autism spectrum disorder and alzheimer\u2019s disease. Medical Image Analysis, 48, 117\u2013130.","journal-title":"Medical Image Analysis"},{"issue":"1","key":"6417_CR25","doi-asserted-by":"publisher","first-page":"145","DOI":"10.1016\/S0893-6080(98)00116-6","volume":"12","author":"N Qian","year":"1999","unstructured":"Qian, N. (1999). On the momentum term in gradient descent learning algorithms. Neural Networks, 12(1), 145\u2013151.","journal-title":"Neural Networks"},{"issue":"3","key":"6417_CR26","doi-asserted-by":"publisher","first-page":"209","DOI":"10.1007\/s11633-022-1330-7","volume":"19","author":"M Ren","year":"2022","unstructured":"Ren, M., Wang, Y. L., & He, Z. F. (2022). Towards interpretable defense against adversarial attacks via causal inference. Machine Intelligence Research, 19(3), 209\u2013226.","journal-title":"Machine Intelligence Research"},{"key":"6417_CR27","unstructured":"Ren, S., He, K., Girshick, R., et\u00a0al. (2015). Faster r-CNN: Towards real-time object detection with region proposal networks. Advances in Neural Information Processing Systems 28."},{"issue":"1","key":"6417_CR28","doi-asserted-by":"publisher","first-page":"61","DOI":"10.1109\/TNN.2008.2005605","volume":"20","author":"F Scarselli","year":"2008","unstructured":"Scarselli, F., Gori, M., Tsoi, A. C., et al. (2008). The graph neural network model. IEEE Transactions on Neural Networks, 20(1), 61\u201380.","journal-title":"IEEE Transactions on Neural Networks"},{"key":"6417_CR29","doi-asserted-by":"crossref","unstructured":"Sharif, M., Bhagavatula, S., Bauer, L., et\u00a0al. (2016). Accessorize to a crime: Real and stealthy attacks on state-of-the-art face recognition. In: Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, p 1528\u20131540.","DOI":"10.1145\/2976749.2978392"},{"key":"6417_CR30","doi-asserted-by":"crossref","unstructured":"Shi, W., Rajkumar, R. (2020). Point-GNN: Graph neural network for 3d object detection in a point cloud. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, p 1711\u20131719.","DOI":"10.1109\/CVPR42600.2020.00178"},{"key":"6417_CR31","unstructured":"Song, D., Eykholt, K., Evtimov, I., et\u00a0al. (2018). Physical adversarial examples for object detectors. In: 12th USENIX Workshop on Offensive Technologies (WOOT 18)."},{"key":"6417_CR32","doi-asserted-by":"crossref","unstructured":"Song, S., Chaudhuri, K., Sarwate, A.D. (2013). Stochastic gradient descent with differentially private updates. In: 2013 IEEE Global Conference on Signal and Information Processing, IEEE, p 245\u2013248.","DOI":"10.1109\/GlobalSIP.2013.6736861"},{"key":"6417_CR33","unstructured":"Van\u00a0Ranst, W., Thys, S., Goedem\u00e9, T. (2019). Fooling automated surveillance cameras: Adversarial patches to attack person detection. In: CVPR Workshop on The Bright and Dark Sides of Computer Vision: Challenges and Opportunities for Privacy and Security, IEEE, p 49\u201355."},{"key":"6417_CR34","unstructured":"Veli\u010dkovi\u0107, P., Cucurull, G., Casanova, A., et\u00a0al. (2017). Graph attention networks. arXiv preprint arXiv:1710.10903."},{"key":"6417_CR35","unstructured":"Wilson, A.C., Roelofs. R., Stern. M., et\u00a0al. (2017). The marginal value of adaptive gradient methods in machine learning. Advances in Neural Information Processing Systems 30."},{"key":"6417_CR36","unstructured":"Wu, T., Tong, L., Vorobeychik, Y.D (2019). Defending against physically realizable attacks on image classification. arXiv preprint arXiv:1909.09552."},{"key":"6417_CR37","doi-asserted-by":"crossref","unstructured":"Wu, Z., Lim, S.N., Davis, L.S., et\u00a0al. (2020). Making an invisibility cloak: Real world adversarial attacks on object detectors. In: Computer Vision\u2013ECCV 2020: 16th European Conference, Glasgow, UK, August 23\u201328, 2020, Proceedings, Part IV 16, Springer, p 1\u201317.","DOI":"10.1007\/978-3-030-58548-8_1"},{"key":"6417_CR38","unstructured":"Xiang, C., Bhagoji, A.N., Sehwag, V., et\u00a0al. (2021). Patchguard: A provably robust defense against adversarial patches via small receptive fields and masking. In: USENIX Security Symposium, p 2237\u20132254."},{"key":"6417_CR39","doi-asserted-by":"crossref","unstructured":"Xie, Y., Li, S., Yang, C., et\u00a0al. (2020). When do GNNs work: Understanding and improving neighborhood aggregation. In: IJCAI\u201920: Proceedings of the Twenty-Ninth International Joint Conference on Artificial Intelligence, IJCAI 2020.","DOI":"10.24963\/ijcai.2020\/181"},{"key":"6417_CR40","unstructured":"Xu, K., Hu, W., Leskovec, J., et\u00a0al. (2018). How powerful are graph neural networks? arXiv preprint arXiv:1810.00826."},{"key":"6417_CR41","doi-asserted-by":"crossref","unstructured":"Zhou, X., Tsang, IW., Yin, J. (2022). Ladder: Latent boundary-guided adversarial training. Machine Learning p 1\u201329.","DOI":"10.1007\/s10994-022-06203-x"},{"key":"6417_CR42","doi-asserted-by":"publisher","first-page":"6487","DOI":"10.1109\/TIP.2022.3211736","volume":"31","author":"Y Zhu","year":"2022","unstructured":"Zhu, Y., Chen, Y., Li, X., et al. (2022). Toward understanding and boosting adversarial transferability from a distribution perspective. IEEE Transactions on Image Processing, 31, 6487\u20136501.","journal-title":"IEEE Transactions on Image Processing"}],"container-title":["Machine Learning"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10994-023-06417-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10994-023-06417-7\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10994-023-06417-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,11,27]],"date-time":"2025-11-27T18:05:09Z","timestamp":1764266709000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10994-023-06417-7"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,1,24]]},"references-count":42,"journal-issue":{"issue":"8","published-print":{"date-parts":[[2024,8]]}},"alternative-id":["6417"],"URL":"https:\/\/doi.org\/10.1007\/s10994-023-06417-7","relation":{},"ISSN":["0885-6125","1573-0565"],"issn-type":[{"type":"print","value":"0885-6125"},{"type":"electronic","value":"1573-0565"}],"subject":[],"published":{"date-parts":[[2024,1,24]]},"assertion":[{"value":"20 April 2023","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"25 July 2023","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"3 October 2023","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"24 January 2024","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors report no conflicts of interest or competing interests.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}},{"value":"Not applicable.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethical approval"}},{"value":"All authors consent to participate.","order":4,"name":"Ethics","group":{"name":"EthicsHeading","label":"Consent to participate"}},{"value":"All authors consent to publication.","order":5,"name":"Ethics","group":{"name":"EthicsHeading","label":"Consent for publication"}},{"value":"This content has been made available to all.","name":"free","label":"Free to read"}]}}