{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,2,21]],"date-time":"2025-02-21T07:42:01Z","timestamp":1740123721919,"version":"3.37.3"},"reference-count":29,"publisher":"Springer Science and Business Media LLC","issue":"4","license":[{"start":{"date-parts":[[2020,1,20]],"date-time":"2020-01-20T00:00:00Z","timestamp":1579478400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2020,1,20]],"date-time":"2020-01-20T00:00:00Z","timestamp":1579478400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"funder":[{"name":"National Key R&D Program of China","award":["2018YFB1004402"],"award-info":[{"award-number":["2018YFB1004402"]}]},{"DOI":"10.13039\/501100005089","name":"Beijing Municipal Natural Science Foundation","doi-asserted-by":"publisher","award":["4172053"],"award-info":[{"award-number":["4172053"]}],"id":[{"id":"10.13039\/501100005089","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61876019"],"award-info":[{"award-number":["61876019"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Mobile Netw Appl"],"published-print":{"date-parts":[[2021,8]]},"DOI":"10.1007\/s11036-019-01499-x","type":"journal-article","created":{"date-parts":[[2020,1,20]],"date-time":"2020-01-20T12:02:45Z","timestamp":1579521765000},"page":"1616-1629","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["An Evolutionary-Based Black-Box Attack to Deep Neural Network Classifiers"],"prefix":"10.1007","volume":"26","author":[{"given":"Yutian","family":"Zhou","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yu-an","family":"Tan","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Quanxin","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xiaohui","family":"Kuang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yahong","family":"Han","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jingjing","family":"Hu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2020,1,20]]},"reference":[{"key":"1499_CR1","doi-asserted-by":"crossref","unstructured":"Collobert R, Weston J (2008) A unified architecture for natural language processing: deep neural networks with multitask learning[C]\/\/proceedings of the 25th international conference on machine learning. ACM:160\u2013167","DOI":"10.1145\/1390156.1390177"},{"issue":"6","key":"1499_CR2","doi-asserted-by":"publisher","first-page":"82","DOI":"10.1109\/MSP.2012.2205597","volume":"29","author":"G Hinton","year":"2012","unstructured":"Hinton G, Deng L, Yu D et al (2012) Deep neural networks for acoustic modeling in speech recognition: the shared views of four research groups[J]. IEEE Signal Process Mag 29(6):82\u201397","journal-title":"IEEE Signal Process Mag"},{"key":"1499_CR3","unstructured":"Krizhevsky A , Sutskever I , Hinton G . ImageNet Classification with Deep Convolutional Neural Networks[J]. Adv Neural Inf Proces Syst, 2012, 25(2)"},{"issue":"4","key":"1499_CR4","doi-asserted-by":"publisher","first-page":"13","DOI":"10.1080\/03610918.2013.786780","volume":"45","author":"HH Chen","year":"2016","unstructured":"Chen HH, Chen M, Chiu CC (2016) The integration of artificial neural networks and text mining to forecast gold futures prices[J]. Communications in Statistics - Simulation and Computation 45(4):13","journal-title":"Communications in Statistics - Simulation and Computation"},{"key":"1499_CR5","unstructured":"Yerima SY, Sezer S (2018) DroidFusion: a novel multilevel classifier fusion approach for android malware detection[J]. IEEE Transactions on Cybernetics:1\u201314"},{"key":"1499_CR6","doi-asserted-by":"crossref","unstructured":"He K, Zhang X, Ren S, et al. Deep residual learning for image recognition[C]\/\/Proceedings of the IEEE conference on computer vision and pattern recognition. 2016: 770\u2013778","DOI":"10.1109\/CVPR.2016.90"},{"key":"1499_CR7","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140444","volume-title":"Adversarial examples are not easily detected: bypassing ten detection methods[J]","author":"N Carlini","year":"2017","unstructured":"Carlini N, Wagner D. Adversarial examples are not easily detected: bypassing ten detection methods[J]. 2017"},{"key":"1499_CR8","volume-title":"Deep neural networks are easily fooled: high confidence predictions for unrecognizable images[J]","author":"A Nguyen","year":"2015","unstructured":"Nguyen A, Yosinski J, Clune J. Deep neural networks are easily fooled: high confidence predictions for unrecognizable images[J]. 2015"},{"key":"1499_CR9","volume-title":"Obfuscated gradients give a false sense of security: circumventing defenses to adversarial examples[J]","author":"A Athalye","year":"2018","unstructured":"Athalye A , Carlini N , Wagner D . Obfuscated gradients give a false sense of security: circumventing defenses to adversarial examples[J]. 2018"},{"key":"1499_CR10","unstructured":"Huang S, Papernot N, Goodfellow I, et al. Adversarial attacks on neural network policies[J]. arXiv preprint arXiv:1702.02284, 2017"},{"key":"1499_CR11","volume-title":"Decision-based adversarial attacks: reliable attacks against black-box machine learning models[J]","author":"W Brendel","year":"2018","unstructured":"Brendel W, Rauber J, Bethge M. Decision-based adversarial attacks: reliable attacks against black-box machine learning models[J]. 2018"},{"key":"1499_CR12","doi-asserted-by":"crossref","unstructured":"Barreno M, Nelson B, Sears R et al (2006) Can machine learning be secure?[C]\/\/proceedings of the 2006 ACM symposium on information, computer and communications security. ACM:16\u201325","DOI":"10.1145\/1128817.1128824"},{"issue":"2","key":"1499_CR13","doi-asserted-by":"publisher","first-page":"121","DOI":"10.1007\/s10994-010-5188-5","volume":"81","author":"M Barreno","year":"2010","unstructured":"Barreno M, Nelson B, Joseph AD et al (2010) The security of machine learning[J]. Mach Learn 81(2):121\u2013148","journal-title":"Mach Learn"},{"key":"1499_CR14","unstructured":"Szegedy C, Zaremba W, Sutskever I, et al. Intriguing properties of neural networks[J]. arXiv preprint arXiv:1312.6199, 2013"},{"key":"1499_CR15","unstructured":"Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy. Explaining and harnessing adversarial examples. CoRR, abs\/1412.6572, 2014. URL http:\/\/arxiv.org\/abs\/1412.6572"},{"key":"1499_CR16","unstructured":"Kurakin A, Goodfellow I, Bengio S. Adversarial examples in the physical world[J]. arXiv preprint arXiv:1607.02533, 2016"},{"key":"1499_CR17","doi-asserted-by":"crossref","unstructured":"Papernot N, McDaniel P, Jha S et al (2016) The limitations of deep learning in adversarial settings[C]\/\/security and privacy (EuroS&P), 2016 IEEE European symposium on. IEEE:372\u2013387","DOI":"10.1109\/EuroSP.2016.36"},{"key":"1499_CR18","unstructured":"Su J, Vargas D V, Kouichi S. One pixel attack for fooling deep neural networks[J]. arXiv preprint arXiv:1710.08864, 2017"},{"key":"1499_CR19","volume-title":"Distillation as a defense to adversarial perturbations against deep neural networks[C]\/\/ Security & Privacy","author":"N Papernot","year":"2016","unstructured":"Papernot N, Mcdaniel P, Xi W, et al. Distillation as a defense to adversarial perturbations against deep neural networks[C]\/\/ Security & Privacy. 2016"},{"key":"1499_CR20","doi-asserted-by":"crossref","unstructured":"Carlini N, Wagner D (2017) Towards evaluating the robustness of neural networks[C]\/\/2017 IEEE symposium on security and privacy (SP). IEEE:39\u201357","DOI":"10.1109\/SP.2017.49"},{"key":"1499_CR21","doi-asserted-by":"crossref","unstructured":"Moosavidezfooli SM, Fawzi A, Frossard P (2016) DeepFool: a simple and accurate method to fool deep neural networks[C]\/\/ computer vision and pattern recognition. IEEE:2574\u20132582","DOI":"10.1109\/CVPR.2016.282"},{"key":"1499_CR22","volume-title":"Practical black-box attacks against deep learning systems using adversarial examples[J]","author":"N Papernot","year":"2016","unstructured":"Papernot N, Mcdaniel P, Goodfellow I, et al. Practical black-box attacks against deep learning systems using adversarial examples[J]. 2016"},{"key":"1499_CR23","doi-asserted-by":"crossref","unstructured":"Andor D, Alberti C, Weiss D, et al. Globally normalized transition-based neural networks[J]. arXiv preprint arXiv:1603.06042, 2016","DOI":"10.18653\/v1\/P16-1231"},{"key":"1499_CR24","unstructured":"Liu Y, Chen X, Liu C, et al. Delving into transferable adversarial examples and black-box attacks[J]. arXiv preprint arXiv:1611.02770, 2016"},{"key":"1499_CR25","unstructured":"Tram\u00e8r F, Papernot N, Goodfellow I, et al. The space of transferable adversarial examples[J]. arXiv preprint arXiv:1704.03453, 2017"},{"key":"1499_CR26","volume-title":"Simple black-box adversarial perturbations for deep networks[J]","author":"N Narodytska","year":"2016","unstructured":"Narodytska N, Kasiviswanathan S P. Simple black-box adversarial perturbations for deep networks[J]. 2016"},{"issue":"3","key":"1499_CR27","doi-asserted-by":"publisher","first-page":"303","DOI":"10.1109\/TEVC.2005.846356","volume":"9","author":"Y Jin","year":"2005","unstructured":"Jin Y (2005) J\u00fcrgen Branke. Evolutionary optimization in uncertain environments---a survey[J]. IEEE Trans Evol Comput 9(3):303\u2013317","journal-title":"IEEE Trans Evol Comput"},{"key":"1499_CR28","unstructured":"LeCun Y. The MNIST database of handwritten digits[J]. http:\/\/yann. lecun. com\/exdb\/mnist\/, 1998"},{"key":"1499_CR29","volume-title":"ImageNet: a large-scale hierarchical image database[C]\/\/ IEEE conference on Computer Vision & Pattern Recognition","author":"J Deng","year":"2009","unstructured":"Deng J, Dong W, Socher R, et al. ImageNet: a large-scale hierarchical image database[C]\/\/ IEEE conference on Computer Vision & Pattern Recognition. 2009"}],"container-title":["Mobile Networks and Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11036-019-01499-x.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s11036-019-01499-x\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11036-019-01499-x.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,10,27]],"date-time":"2021-10-27T03:42:47Z","timestamp":1635306167000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s11036-019-01499-x"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,1,20]]},"references-count":29,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2021,8]]}},"alternative-id":["1499"],"URL":"https:\/\/doi.org\/10.1007\/s11036-019-01499-x","relation":{},"ISSN":["1383-469X","1572-8153"],"issn-type":[{"type":"print","value":"1383-469X"},{"type":"electronic","value":"1572-8153"}],"subject":[],"published":{"date-parts":[[2020,1,20]]},"assertion":[{"value":"20 January 2020","order":1,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}