{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,16]],"date-time":"2026-01-16T02:40:48Z","timestamp":1768531248535,"version":"3.49.0"},"reference-count":39,"publisher":"Springer Science and Business Media LLC","issue":"7","license":[{"start":{"date-parts":[[2023,2,1]],"date-time":"2023-02-01T00:00:00Z","timestamp":1675209600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2023,2,1]],"date-time":"2023-02-01T00:00:00Z","timestamp":1675209600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"funder":[{"DOI":"10.13039\/501100012165","name":"Key Technologies Research and Development Program","doi-asserted-by":"publisher","award":["2021YFA1000102"],"award-info":[{"award-number":["2021YFA1000102"]}],"id":[{"id":"10.13039\/501100012165","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100014718","name":"Innovative Research Group Project of the National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61673396"],"award-info":[{"award-number":["61673396"]}],"id":[{"id":"10.13039\/100014718","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100007129","name":"Natural Science Foundation of Shandong Province","doi-asserted-by":"publisher","award":["ZR2022MF260"],"award-info":[{"award-number":["ZR2022MF260"]}],"id":[{"id":"10.13039\/501100007129","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Int. J. Mach. Learn. &amp; Cyber."],"published-print":{"date-parts":[[2023,7]]},"DOI":"10.1007\/s13042-023-01778-w","type":"journal-article","created":{"date-parts":[[2023,2,1]],"date-time":"2023-02-01T04:00:01Z","timestamp":1675224001000},"page":"2499-2509","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Generating adversarial samples by manipulating image features with auto-encoder"],"prefix":"10.1007","volume":"14","author":[{"given":"Jianxin","family":"Yang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7323-5896","authenticated-orcid":false,"given":"Mingwen","family":"Shao","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Huan","family":"Liu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xinkai","family":"Zhuang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2023,2,1]]},"reference":[{"key":"1778_CR1","doi-asserted-by":"crossref","unstructured":"He K, Zhang X, Ren S, Sun J (2016) Deep residual learning for image recognition. In: IEEE computer society conference on computer vision and pattern recognition (CVPR), pp 770\u2013778 (2016)","DOI":"10.1109\/CVPR.2016.90"},{"key":"1778_CR2","doi-asserted-by":"crossref","unstructured":"Zeng M, Wang Y, Luo Y (2019) Dirichlet latent variable hierarchical recurrent encoder-decoder in dialogue generation. In: Empirical methods in natural language processing and the 9th international joint conference on natural language processing (EMNLP-IJCNLP), pp 1267\u20131272 (2019)","DOI":"10.18653\/v1\/D19-1124"},{"key":"1778_CR3","unstructured":"Goodfellow IJ, Shlens J, Szegedy C (2015) Explaining and harnessing adversarial examples. In: 3rd international conference on learning representations (ICLR)"},{"key":"1778_CR4","doi-asserted-by":"crossref","unstructured":"Dong Y, Liao F, Pang T, Su H, Zhu J, Hu X, Li J (2018) Boosting adversarial attacks with momentum. In: IEEE computer society conference on computer vision and pattern recognition (CVPR), pp 9185\u20139193","DOI":"10.1109\/CVPR.2018.00957"},{"key":"1778_CR5","doi-asserted-by":"crossref","unstructured":"Papernot N, McDaniel PD, Goodfellow IJ, Jha S, Celik ZB, Swami A (2017) Practical black-box attacks against machine learning. In: ACM on Asia conference on computer and communications security, pp 506\u2013519","DOI":"10.1145\/3052973.3053009"},{"key":"1778_CR6","doi-asserted-by":"crossref","unstructured":"Liu H, Ji R, Li J, Zhang B, Gao Y, Wu Y, Huang F (2019) Universal adversarial perturbation via prior driven uncertainty approximation. In: IEEE\/CVF international conference on computer vision (ICCV), pp 2941\u20132949","DOI":"10.1109\/ICCV.2019.00303"},{"key":"1778_CR7","unstructured":"Ilyas A, Santurkar S, Tsipras D, Engstrom L, Tran B, Madry A (2019) Adversarial examples are not bugs, they are features. In: Conference on neural information processing systems (NeurIPS), pp 125\u2013136"},{"key":"1778_CR8","doi-asserted-by":"crossref","unstructured":"Carlini N, Wagner DA (2017) Towards evaluating the robustness of neural networks. In: IEEE symposium on security and privacy (SP), pp 39\u201357","DOI":"10.1109\/SP.2017.49"},{"key":"1778_CR9","doi-asserted-by":"publisher","first-page":"33","DOI":"10.1016\/j.ins.2020.12.013","volume":"554","author":"M Shao","year":"2021","unstructured":"Shao M, Zhang G, Zuo W, Meng D (2021) Target attack on biomedical image segmentation model based on multi-scale gradients. Inf Sci 554:33\u201346","journal-title":"Inf Sci"},{"key":"1778_CR10","doi-asserted-by":"crossref","unstructured":"Hu S, Liu X, Zhang Y, Li M, Zhang LY, Jin H, Wu L (2022) Protecting facial privacy: generating adversarial identity masks via style-robust makeup transfer. In: IEEE computer society conference on computer vision and pattern recognition (CVPR), pp 14994\u201315003","DOI":"10.1109\/CVPR52688.2022.01459"},{"key":"1778_CR11","doi-asserted-by":"crossref","unstructured":"Li S, Neupane A, Paul S, Song C, Krishnamurthy SV, Roy-Chowdhury AK, Swami A (2018) Adversarial perturbations against real-time video classification systems. CoRR abs\/1807.00458","DOI":"10.14722\/ndss.2019.23202"},{"key":"1778_CR12","unstructured":"Madry A, Makelov A, Schmidt L, Tsipras D, Vladu A (2018) Towards deep learning models resistant to adversarial attacks. In: 6th international conference on learning representations (ICLR)"},{"key":"1778_CR13","unstructured":"Zhang H, Yu Y, Jiao J, Xing EP, Ghaoui LE, Jordan MI (2019) Theoretically principled trade-off between robustness and accuracy. In: 36th international conference on machine learning (ICML), vol 97, pp 7472\u20137482"},{"issue":"12","key":"1778_CR14","doi-asserted-by":"publisher","first-page":"3437","DOI":"10.1007\/s13042-021-01374-w","volume":"12","author":"M Shao","year":"2021","unstructured":"Shao M, Liu S, Wang R, Zhang G (2021) An adversarial sample defense method based on multi-scale GAN. Int J Mach Learn Cybern 12(12):3437\u20133447","journal-title":"Int J Mach Learn Cybern"},{"key":"1778_CR15","doi-asserted-by":"crossref","unstructured":"Xu Q, Tao G, Cheng S, Zhang X (2021) Towards feature space adversarial attack by style perturbation. In: AAAI conference on artificial intelligence (AAAI), vol 35, pp 10523\u201310531","DOI":"10.1609\/aaai.v35i12.17259"},{"key":"1778_CR16","doi-asserted-by":"crossref","unstructured":"Saha A, Subramanya A, Pirsiavash H (2020) Hidden trigger backdoor attacks. In: AAAI conference on artificial intelligence (AAAI), vol 34, pp 11957\u201311965","DOI":"10.1609\/aaai.v34i07.6871"},{"key":"1778_CR17","unstructured":"Shafahi A, Huang WR, Najibi M, Suciu O, Studer C, Dumitras T, Goldstein T (2018) Poison frogs! targeted clean-label poisoning attacks on neural networks. In: Conference on neural information processing systems (NeurIPS), pp 6106\u20136116"},{"key":"1778_CR18","unstructured":"Sabour S, Cao Y, Faghri F, Fleet DJ (2016) Adversarial manipulation of deep representations. In: 4th international conference on learning representations (ICLR)"},{"key":"1778_CR19","doi-asserted-by":"crossref","unstructured":"Huang X, Belongie S (2017) Arbitrary style transfer in real-time with adaptive instance normalization. In: IEEE international conference on computer vision (ICCV), pp 1501\u20131510","DOI":"10.1109\/ICCV.2017.167"},{"key":"1778_CR20","unstructured":"Krizhevsky A, Hinton G (2009) Learning multiple layers of features from tiny images. Technical report, University of Toronto"},{"key":"1778_CR21","doi-asserted-by":"crossref","unstructured":"Deng J, Dong W, Socher R, Li L, Li K, Fei-Fei L (2009) Imagenet: a large-scale hierarchical image database. In: IEEE computer society conference on computer vision and pattern recognition (CVPR), pp 248\u2013255","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"1778_CR22","unstructured":"Szegedy C, Zaremba W, Sutskever I, Bruna J, Erhan D, Goodfellow IJ, Fergus R (2014) Intriguing properties of neural networks. In: 2nd international conference on learning representations (ICLR)"},{"key":"1778_CR23","doi-asserted-by":"crossref","unstructured":"Kurakin A, Goodfellow IJ, Bengio S (2017) Adversarial examples in the physical world. In: 5th international conference on learning representations (ICLR)","DOI":"10.1201\/9781351251389-8"},{"key":"1778_CR24","doi-asserted-by":"publisher","first-page":"155161","DOI":"10.1109\/ACCESS.2021.3127960","volume":"9","author":"N Akhtar","year":"2021","unstructured":"Akhtar N, Mian A, Kardan N, Shah M (2021) Advances in adversarial attacks and defenses in computer vision: a survey. IEEE Access 9:155161\u2013155196","journal-title":"IEEE Access"},{"key":"1778_CR25","doi-asserted-by":"crossref","unstructured":"Eykholt K, Evtimov I, Fernandes E, Li B, Rahmati A, Xiao C, Prakash A, Kohno T, Song D (2018) Robust physical-world attacks on deep learning visual classification. In: IEEE computer society conference on computer vision and pattern recognition (CVPR), pp 1625\u20131634","DOI":"10.1109\/CVPR.2018.00175"},{"key":"1778_CR26","doi-asserted-by":"crossref","unstructured":"Sharif M, Bhagavatula S, Bauer L, Reiter MK (2016) Accessorize to a crime: real and stealthy attacks on state-of-the-art face recognition. In: ACM on Asia conference on computer and communications security, pp 1528\u20131540","DOI":"10.1145\/2976749.2978392"},{"key":"1778_CR27","unstructured":"Laidlaw C, Feizi S (2019) Functional adversarial attacks. In: Conference on neural information processing systems (NeurIPS), pp 10408\u201310418"},{"key":"1778_CR28","unstructured":"Bhattad A, Chong MJ, Liang K, Li B, Forsyth DA (2020) Unrestricted adversarial examples via semantic manipulation. In: 8th international conference on learning representations (ICLR)"},{"key":"1778_CR29","doi-asserted-by":"crossref","unstructured":"Gatys LA, Ecker AS, Bethge M (2016) Image style transfer using convolutional neural networks. In: IEEE computer society conference on computer vision and pattern recognition (CVPR), pp 2414\u20132423","DOI":"10.1109\/CVPR.2016.265"},{"key":"1778_CR30","unstructured":"Dumoulin V, Shlens J, Kudlur M (2017) A learned representation for artistic style. In: 5th international conference on learning representations (ICLR)"},{"key":"1778_CR31","doi-asserted-by":"crossref","unstructured":"Li Y, Fang C, Yang J, Wang Z, Lu X, Yang M-H (2017) Diversified texture synthesis with feed-forward networks. In: IEEE computer society conference on computer vision and pattern recognition (CVPR), pp 3920\u20133928","DOI":"10.1109\/CVPR.2017.36"},{"key":"1778_CR32","doi-asserted-by":"crossref","unstructured":"Kotovenko D, Wright M, Heimbrecht A, Ommer B (2021) Rethinking style transfer: from pixels to parameterized brushstrokes. In: IEEE computer society conference on computer vision and pattern recognition (CVPR), pp 12196\u201312205","DOI":"10.1109\/CVPR46437.2021.01202"},{"key":"1778_CR33","unstructured":"Gu T, Dolan-Gavitt B, Garg S (2017) Badnets: identifying vulnerabilities in the machine learning model supply chain. CoRR. abs\/1708.06733"},{"issue":"1","key":"1778_CR34","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/s10994-021-06119-y","volume":"111","author":"PW Koh","year":"2022","unstructured":"Koh PW, Steinhardt J, Liang P (2022) Stronger data poisoning attacks break data sanitization defenses. Mach Learn 111(1):1\u201347","journal-title":"Mach Learn"},{"key":"1778_CR35","unstructured":"Mu\u00f1oz-Gonz\u00e1lez L, Pfitzner B, Russo M, Carnerero-Cano J, Lupu EC (2019) Poisoning attacks with generative adversarial nets. CoRR. abs\/1906.07773"},{"key":"1778_CR36","doi-asserted-by":"crossref","unstructured":"Zhao S, Ma X, Zheng X, Bailey J, Chen J, Jiang Y (2020) Clean-label backdoor attacks on video recognition models. In: IEEE computer society conference on computer vision and pattern recognition (CVPR), pp 14431\u201314440","DOI":"10.1109\/CVPR42600.2020.01445"},{"issue":"3","key":"1778_CR37","doi-asserted-by":"publisher","first-page":"2567","DOI":"10.1002\/int.22785","volume":"37","author":"Y Xiao","year":"2022","unstructured":"Xiao Y, Cong L, Mingwen Z, Yajie W, Xinrui L, Shuxiao S, Yuexuan M, Jun Z (2022) A multitarget backdooring attack on deep neural networks with random location trigger. Int J Intell Syst 37(3):2567\u20132583","journal-title":"Int J Intell Syst"},{"key":"1778_CR38","doi-asserted-by":"crossref","unstructured":"Zhong H, Liao C, Squicciarini AC, Zhu S, Miller DJ (2020) Backdoor embedding in convolutional neural network models via invisible perturbation. In: Tenth ACM conference on data and application security and privacy, pp 97\u2013108","DOI":"10.1145\/3374664.3375751"},{"key":"1778_CR39","doi-asserted-by":"crossref","unstructured":"Zhou B, Khosla A, Lapedriza \u00c0, Oliva A, Torralba A (2016) Learning deep features for discriminative localization. In: IEEE computer society conference on computer vision and pattern recognition (CVPR), pp 2921\u20132929","DOI":"10.1109\/CVPR.2016.319"}],"container-title":["International Journal of Machine Learning and Cybernetics"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s13042-023-01778-w.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s13042-023-01778-w\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s13042-023-01778-w.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,5,15]],"date-time":"2023-05-15T15:00:41Z","timestamp":1684162841000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s13042-023-01778-w"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,2,1]]},"references-count":39,"journal-issue":{"issue":"7","published-print":{"date-parts":[[2023,7]]}},"alternative-id":["1778"],"URL":"https:\/\/doi.org\/10.1007\/s13042-023-01778-w","relation":{},"ISSN":["1868-8071","1868-808X"],"issn-type":[{"value":"1868-8071","type":"print"},{"value":"1868-808X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,2,1]]},"assertion":[{"value":"27 July 2022","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"9 January 2023","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"1 February 2023","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}