{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,16]],"date-time":"2025-12-16T12:36:57Z","timestamp":1765888617247,"version":"3.37.3"},"reference-count":30,"publisher":"Springer Science and Business Media LLC","issue":"4","license":[{"start":{"date-parts":[[2021,6,7]],"date-time":"2021-06-07T00:00:00Z","timestamp":1623024000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2021,6,7]],"date-time":"2021-06-07T00:00:00Z","timestamp":1623024000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62020106013","61972454","61802051","61772121","and 61728102"],"award-info":[{"award-number":["62020106013","61972454","61802051","61772121","and 61728102"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100012542","name":"Sichuan Province Science and Technology Support Program","doi-asserted-by":"publisher","award":["2020JDTD0007,2020YFG0298."],"award-info":[{"award-number":["2020JDTD0007,2020YFG0298."]}],"id":[{"id":"10.13039\/100012542","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Peer-to-Peer Netw. Appl."],"published-print":{"date-parts":[[2021,7]]},"DOI":"10.1007\/s12083-021-01178-3","type":"journal-article","created":{"date-parts":[[2021,6,7]],"date-time":"2021-06-07T09:03:29Z","timestamp":1623056609000},"page":"2262-2274","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["One radish, One hole: Specific adversarial training for enhancing neural network\u2019s robustness"],"prefix":"10.1007","volume":"14","author":[{"given":"Yun","family":"Zhang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1961-7946","authenticated-orcid":false,"given":"Hongwei","family":"Li","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Guowen","family":"Xu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shuai","family":"Yuan","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xiaoming","family":"Huang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2021,6,7]]},"reference":[{"key":"1178_CR1","unstructured":"Szegedy C, Zaremba W, Sutskever I, Bruna J, Erhan D, Goodfellow I, Fergus R (2013) Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199"},{"key":"1178_CR2","unstructured":"Goodfellow IJ, Shlens J, Szegedy C (2014) Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572"},{"key":"1178_CR3","unstructured":"Madry A, Makelov A, Schmidt L, Tsipras D, Vladu A (2017) Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083"},{"key":"1178_CR4","unstructured":"Kurakin A, Goodfellow I, Bengio S (2016) Adversarial examples in the physical world. arXiv:1607.02533"},{"key":"1178_CR5","first-page":"2","volume":"1","author":"Y Wang","year":"2019","unstructured":"Wang Y, Ma X, Bailey J, Yi J, Zhou B, Gu Q (2019) On the convergence and robustness of adversarial training. ICML 1:2","journal-title":"ICML"},{"key":"1178_CR6","unstructured":"Balaji Y, Goldstein T, Hoffman J (2019) Instance adaptive adversarial training: Improved accuracy tradeoffs in neural nets. arXiv preprint arXiv:1910.08051"},{"key":"1178_CR7","doi-asserted-by":"crossref","unstructured":"Cai QZ, Du M, Liu C, Song D (2018) Curriculum adversarial training. arXiv preprint arXiv:1805.04807","DOI":"10.24963\/ijcai.2018\/520"},{"key":"1178_CR8","unstructured":"Cheng M, Lei Q, Chen PY, Dhillon I, Hsieh CJ (2020) Cat: Customized adversarial training for improved robustness. arXiv preprint arXiv:2002.06789"},{"key":"1178_CR9","unstructured":"Carlini N, Mishra P, Vaidya T, Zhang Y, Sherr M, Shields C, Zhou W (2016) Hidden voice commands. In: 25th USENIX Security Symposium (USENIX Security 16) , pp 513\u2013530"},{"key":"1178_CR10","doi-asserted-by":"publisher","first-page":"8973","DOI":"10.1609\/aaai.v33i01.33018973","volume":"33","author":"X Wei","year":"2019","unstructured":"Wei X, Zhu J, Yuan S, Su H (2019) Sparse adversarial perturbations for videos. Proceedings of the AAAI Conference on Artificial Intelligence 33:8973\u20138980","journal-title":"Proceedings of the AAAI Conference on Artificial Intelligence"},{"key":"1178_CR11","unstructured":"Kurakin A, Goodfellow I, Bengio S (2016) Adversarial machine learning at scale. arXiv preprint arXiv:1611.01236,"},{"key":"1178_CR12","unstructured":"Zhang H, Yu Y, Jiao J, Xing EP, Ghaoui LE, Jordan MI (2019) Theoretically principled trade-off between robustness and accuracy. arXiv preprint arXiv:1901.08573"},{"key":"1178_CR13","unstructured":"Xie C, Wang J, Zhang Z, Ren Z, Yuille A (2017) Mitigating adversarial effects through randomization. arXiv preprint arXiv:1711.01991"},{"key":"1178_CR14","unstructured":"Guo C, Rana M, Cisse M, Van Der Maaten L (2017) Countering adversarial images using input transformations. arXiv preprint arXiv:1711.00117"},{"key":"1178_CR15","doi-asserted-by":"crossref","unstructured":"Liu X, Cheng M, Zhang H, Hsieh CJ (2018) Towards robust neural networks via random self-ensemble. In: Proceedings of the European Conference on Computer Vision (ECCV), pp 369\u2013385","DOI":"10.1007\/978-3-030-01234-2_23"},{"key":"1178_CR16","unstructured":"Dhillon GS, Azizzadenesheli K, Lipton ZC, Bernstein J, Kossaifi J, Khanna A, Anandkumar A (2018) Stochastic activation pruning for robust adversarial defense. arXiv preprint arXiv:1803.01442"},{"key":"1178_CR17","unstructured":"Raghunathan A, Steinhardt J, Liang P (2018) Certified defenses against adversarial examples. arXiv preprint 1801.09344"},{"key":"1178_CR18","unstructured":"Raghunathan A, Steinhardt J, Liang PS (2018) Semidefinite relaxations for certifying robustness to adversarial examples. In: Advances in neural information processing systems, pp 10877\u201310887"},{"key":"1178_CR19","unstructured":"Wong E, Kolter Z (2018) Provable defenses against adversarial examples via the convex outer adversarial polytope. In: International conference on machine learning, PMLR, pp 5286\u2013 5295"},{"key":"1178_CR20","unstructured":"Ding GW, Sharma Y, Lui KYC, Huang R (2019) Mma training: Direct input space margin maximization through adversarial training. In: International conference on learning representations"},{"key":"1178_CR21","doi-asserted-by":"crossref","unstructured":"Duan R, Ma X, Wang Y, Bailey J, Qin AK, Yang Y (2020) Adversarial camouflage: Hiding physical-world attacks with natural styles. In: Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition, pp 1000\u20131008","DOI":"10.1109\/CVPR42600.2020.00108"},{"key":"1178_CR22","doi-asserted-by":"crossref","unstructured":"Xu W, Evans D, Qi Y (2017) Feature squeezing: Detecting adversarial examples in deep neural networks. arXiv preprint arXiv:1704.01155","DOI":"10.14722\/ndss.2018.23198"},{"key":"1178_CR23","unstructured":"Samangouei P, Kabkab M, Chellappa R (2018) Defense-gan: Protecting classifiers against adversarial attacks using generative models. arXiv preprint arXiv:1805.06605"},{"key":"1178_CR24","doi-asserted-by":"crossref","unstructured":"Szegedy C, Vanhoucke V, Ioffe S, Shlens J, Wojna Z (2016) Rethinking the inception architecture for computer vision. In: Proceedings of the IEEE conference on computer vision and pattern recognition, pp 2818\u20132826","DOI":"10.1109\/CVPR.2016.308"},{"key":"1178_CR25","unstructured":"Xu Y, Xu Y, Qian Q, Li H, Jin R (2020) Towards understanding label smoothing. arXiv preprint arXiv:2006.11653"},{"key":"1178_CR26","unstructured":"Wang Y, Jha S, Chaudhuri K (2018) Analyzing the robustness of nearest neighbors to adversarial examples. In: International conference on machine learning, PMLR, pp 5133\u20135142"},{"key":"1178_CR27","unstructured":"Ye N, Zhu Z (2018) Bayesian adversarial learning. In: Proceedings of the 32nd international conference on neural information processing systems, pp 6892\u20136901"},{"key":"1178_CR28","unstructured":"Liu X, Li Y, Wu C, Hsieh CJ (2018) Adv-bnn: Improved adversarial defense through robust bayesian neural network. arXiv preprint arXiv:1810.01279"},{"key":"1178_CR29","unstructured":"Cao X, Jia J, Gong NZ (2019) IPGuard: Protecting the Intellectual Property of Deep Neural Networks via Fingerprinting the Classification Boundary. arXiv preprint arXiv:1910.12903"},{"key":"1178_CR30","unstructured":"Wei C, Ma T (2019) Improved sample complexities for deep networks and robust classification via an all-layer margin. arXiv preprint arXiv:1910.04284"}],"container-title":["Peer-to-Peer Networking and Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s12083-021-01178-3.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s12083-021-01178-3\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s12083-021-01178-3.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,6,26]],"date-time":"2021-06-26T11:29:44Z","timestamp":1624706984000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s12083-021-01178-3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,6,7]]},"references-count":30,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2021,7]]}},"alternative-id":["1178"],"URL":"https:\/\/doi.org\/10.1007\/s12083-021-01178-3","relation":{},"ISSN":["1936-6442","1936-6450"],"issn-type":[{"type":"print","value":"1936-6442"},{"type":"electronic","value":"1936-6450"}],"subject":[],"published":{"date-parts":[[2021,6,7]]},"assertion":[{"value":"4 January 2021","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"3 May 2021","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"7 June 2021","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}