{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T09:47:10Z","timestamp":1782812830649,"version":"3.54.5"},"reference-count":91,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"funder":[{"DOI":"10.13039\/501100013804","name":"Fundamental Research Funds for the Central Universities","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100013804","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100012154","name":"Graduate Research and Innovation Projects of Jiangsu Province","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100012154","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Digital Signal Processing"],"published-print":{"date-parts":[[2026,11]]},"DOI":"10.1016\/j.dsp.2026.106357","type":"journal-article","created":{"date-parts":[[2026,6,22]],"date-time":"2026-06-22T23:37:51Z","timestamp":1782171471000},"page":"106357","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["RetPur: Diffusion-based defense against black-box targeted attacks in hashing retrieval"],"prefix":"10.1016","volume":"183","author":[{"given":"Yahui","family":"Liu","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7171-1318","authenticated-orcid":false,"given":"Jiasong","family":"Wu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Lotfi","family":"Senhadji","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Huazhong","family":"Shu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"key":"10.1016\/j.dsp.2026.106357_bib0001","unstructured":"W. J. Li, S. Wang, W. C. Kang, Feature learning based deep supervised hashing with pairwise labels, (2015). arXiv preprint arXiv: 1511.03855."},{"key":"10.1016\/j.dsp.2026.106357_bib0002","series-title":"Proceedings of the 26th ACM International Conference on Multimedia","first-page":"1653","article-title":"Deep priority hashing","author":"Cao","year":"2018"},{"key":"10.1016\/j.dsp.2026.106357_bib0003","series-title":"Proceedings of the 2020 International Conference on Multimedia Retrieval","first-page":"525","article-title":"Deep adversarial discrete hashing for cross-modal retrieval","author":"Bai","year":"2020"},{"key":"10.1016\/j.dsp.2026.106357_bib0004","series-title":"Proceedings of the AAAI Conference on Artificial Intelligence","first-page":"4626","article-title":"Deep graph-neighbor coherence preserving network for unsupervised cross-modal hashing","volume":"Vol. 35","author":"Yu","year":"2021"},{"key":"10.1016\/j.dsp.2026.106357_bib0005","doi-asserted-by":"crossref","DOI":"10.1016\/j.dsp.2023.104226","article-title":"Adaptive semi-paired query hashing for multi-modal retrieval","volume":"143","author":"Yu","year":"2023","journal-title":"Digit. Signal Process."},{"key":"10.1016\/j.dsp.2026.106357_bib0006","doi-asserted-by":"crossref","DOI":"10.1016\/j.dsp.2025.105595","article-title":"Asymmetric and discriminative hashing for cross-modal retrieval","volume":"168","author":"Hao","year":"2026","journal-title":"Digit. Signal Process."},{"issue":"3","key":"10.1016\/j.dsp.2026.106357_bib0007","doi-asserted-by":"crossref","first-page":"68","DOI":"10.1109\/MSP.2016.51","article-title":"Machine learning in adversarial settings","volume":"14","author":"McDaniel","year":"2016","journal-title":"IEEE Secur. Priv."},{"key":"10.1016\/j.dsp.2026.106357_bib0008","unstructured":"N. Papernot, P. McDaniel, I. Goodfellow, Transferability in machine learning: from phenomena to black-box attacks using adversarial samples, (2016). arXiv: 1605.07277."},{"key":"10.1016\/j.dsp.2026.106357_bib0009","series-title":"26th Annual Network and Distributed System Security Symposium (NDSS 2019)","article-title":"NIC: detecting adversarial samples with neural network invariant checking","author":"Ma","year":"2019"},{"key":"10.1016\/j.dsp.2026.106357_bib0010","series-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","first-page":"14453","article-title":"Detecting adversarial samples using influence functions and nearest neighbors","author":"Cohen","year":"2020"},{"key":"10.1016\/j.dsp.2026.106357_bib0011","series-title":"Proceedings of the IEEE\/CVF Winter Conference on Applications of Computer Vision","first-page":"3071","article-title":"Adversarial sampling for active learning","author":"Mayer","year":"2020"},{"key":"10.1016\/j.dsp.2026.106357_bib0012","series-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","first-page":"9024","article-title":"Improving the transferability of adversarial samples with adversarial transformations","author":"Wu","year":"2021"},{"key":"10.1016\/j.dsp.2026.106357_bib0013","doi-asserted-by":"crossref","DOI":"10.1016\/j.dsp.2025.105347","article-title":"Reversible adversarial information hiding based on the interpretation of neural network","volume":"165","author":"Li","year":"2025","journal-title":"Digit. Signal Process."},{"key":"10.1016\/j.dsp.2026.106357_bib0014","unstructured":"I.J. Goodfellow, J. Shlens, C. Szegedy, Explaining and harnessing adversarial examples, (2014). arXiv preprint arXiv: 1412.6572."},{"key":"10.1016\/j.dsp.2026.106357_bib0015","first-page":"12836","article-title":"Adversarial robustness without adversarial training: a teacher-guided curriculum learning approach","volume":"34","author":"Sarkar","year":"2021","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"10.1016\/j.dsp.2026.106357_bib0016","first-page":"25179","article-title":"Adversarial training helps transfer learning via better representations","volume":"34","author":"Deng","year":"2021","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"10.1016\/j.dsp.2026.106357_bib0017","series-title":"ICASSP 2022-2022 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP)","first-page":"2734","article-title":"Wassertrain: an adversarial training framework against wasserstein adversarial attacks","author":"Zhao","year":"2022"},{"key":"10.1016\/j.dsp.2026.106357_bib0018","doi-asserted-by":"crossref","DOI":"10.1016\/j.dsp.2024.104636","article-title":"Adversarial training for signal modulation classification based on Ulam stability theory","volume":"153","author":"Yan","year":"2024","journal-title":"Digit. Signal Process."},{"key":"10.1016\/j.dsp.2026.106357_bib0019","unstructured":"A. Madry, A. Makelov, L. Schmidt, D. Tsipras, A. Vladu, Towards deep learning models resistant to adversarial attacks, (2017). arXiv preprint arXiv: 1706.06083."},{"key":"10.1016\/j.dsp.2026.106357_bib0020","series-title":"Proceedings of the 24th ACM SIGKDD International Conference on Knowledge Discovery & Data Mining","first-page":"1803","article-title":"Adversarial detection with model interpretation","author":"Liu","year":"2018"},{"key":"10.1016\/j.dsp.2026.106357_bib0021","first-page":"16051","article-title":"Class-disentanglement and applications in adversarial detection and defense","volume":"34","author":"Yang","year":"2021","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"10.1016\/j.dsp.2026.106357_bib0022","unstructured":"S. Zhang, F. Liu, J. Yang, Y. Yang, C. Li, B. Han, M. Tan, Detecting adversarial data by probing multiple perturbations using expected perturbation score, in: PMLR, Vol. 202, 2023, pp. 41429\u201341451."},{"key":"10.1016\/j.dsp.2026.106357_bib0023","doi-asserted-by":"crossref","DOI":"10.1016\/j.dsp.2021.103329","article-title":"Deep supervised class encoding for iris presentation attack detection","volume":"121","author":"Gautam","year":"2022","journal-title":"Digit. Signal Process."},{"key":"10.1016\/j.dsp.2026.106357_bib0024","unstructured":"W. Nie, B. Guo, Y. Huang, C. Xiao, A. Vahdat, A. Anandkumar, Diffusion models for adversarial purification, (2022). arXiv preprint arXiv: 2205.07460."},{"key":"10.1016\/j.dsp.2026.106357_bib0025","unstructured":"J. Wang, Z. Lyu, D. Lin, B. Dai, H. Fu, Guided diffusion model for adversarial purification, (2022). arXiv preprint arXiv: 2205.14969."},{"key":"10.1016\/j.dsp.2026.106357_bib0026","unstructured":"B. Kim, Y. Oh, J.C. Ye, Diffusion adversarial representation learning for self-supervised vessel segmentation, (2022). arXiv preprint arXiv: 2209.14566."},{"key":"10.1016\/j.dsp.2026.106357_bib0027","unstructured":"S. Wu, J. Wang, W. Ping, W. Nie, C. Xiao, Defending against adversarial audio via diffusion model, (2023). arXiv preprint arXiv: 2303.01507."},{"key":"10.1016\/j.dsp.2026.106357_bib0028","first-page":"11918","article-title":"Generative modeling by estimating gradients of the data distribution","volume":"32","author":"Song","year":"2019","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"10.1016\/j.dsp.2026.106357_bib0029","series-title":"International Conference on Learning Representations","article-title":"Denoising diffusion implicit models","author":"Song","year":"2020"},{"key":"10.1016\/j.dsp.2026.106357_bib0030","series-title":"International Conference on Learning Representations","article-title":"Score-based generative modeling through stochastic differential equations","author":"Song","year":"2020"},{"key":"10.1016\/j.dsp.2026.106357_bib0031","doi-asserted-by":"crossref","first-page":"6159","DOI":"10.1109\/TCSVT.2023.3263054","article-title":"Targeted adversarial attack against deep cross-modal hashing retrieval","volume":"33","author":"Wang","year":"2023","journal-title":"IEEE Trans. Circuits Syst. Video Technol."},{"issue":"1","key":"10.1016\/j.dsp.2026.106357_bib0032","first-page":"1","article-title":"Deep uncoupled discrete hashing via similarity matrix decomposition","volume":"19","author":"Wu","year":"2023","journal-title":"ACM Trans. Multimed. Comput. Commun. Appl."},{"key":"10.1016\/j.dsp.2026.106357_bib0033","series-title":"IJCAI","first-page":"1254","article-title":"Improved deep unsupervised hashing with fine-grained semantic similarity mining for multi-label image retrieval","author":"Ma","year":"2022"},{"key":"10.1016\/j.dsp.2026.106357_bib0034","series-title":"Proceedings of the IEEE International Conference on Computer Vision","first-page":"5608","article-title":"HashNet: deep learning to hash by continuation","author":"Cao","year":"2017"},{"key":"10.1016\/j.dsp.2026.106357_bib0035","doi-asserted-by":"crossref","first-page":"7027","DOI":"10.1109\/TMM.2024.3358995","article-title":"Deep ranking distribution preserving hashing for robust multi-label cross-modal retrieval","volume":"26","author":"Song","year":"2024","journal-title":"IEEE Trans. Multimed."},{"key":"10.1016\/j.dsp.2026.106357_bib0036","series-title":"Proceedings of the AAAI Conference on Artificial Intelligence","first-page":"12018","article-title":"Codebook-centric deep hashing: end-to-end joint learning of semantic hash centers and neural hash function","volume":"Vol. 40","author":"Yin","year":"2026"},{"key":"10.1016\/j.dsp.2026.106357_bib0037","series-title":"Proceedings of the AAAI Conference on Artificial Intelligence","first-page":"7323","article-title":"Discretization is not always better: rethinking deep quantization for asymmetric image retrieval","volume":"Vol. 40","author":"Liu","year":"2026"},{"key":"10.1016\/j.dsp.2026.106357_bib0038","series-title":"Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition","first-page":"3232","article-title":"Deep cross-modal hashing","author":"Jiang","year":"2017"},{"key":"10.1016\/j.dsp.2026.106357_bib0039","series-title":"IJCAI","first-page":"5","article-title":"Unsupervised deep hashing via binary latent factor models for large-scale cross-modal retrieval","volume":"Vol. 1","author":"Wu","year":"2018"},{"key":"10.1016\/j.dsp.2026.106357_bib0040","series-title":"Proceedings of the IEEE\/CVF International Conference on Computer Vision","first-page":"3027","article-title":"Deep joint-semantics reconstructing hashing for large-scale unsupervised cross-modal retrieval","author":"Su","year":"2019"},{"key":"10.1016\/j.dsp.2026.106357_bib0041","doi-asserted-by":"crossref","first-page":"466","DOI":"10.1109\/TMM.2021.3053766","article-title":"Aggregation-based graph convolutional hashing for unsupervised cross-modal retrieval","volume":"24","author":"Zhang","year":"2021","journal-title":"IEEE Trans. Multimed."},{"key":"10.1016\/j.dsp.2026.106357_bib0042","series-title":"Proceedings of the AAAI Conference on Artificial Intelligence","first-page":"18566","article-title":"Deep evidential hashing for trustworthy cross-modal retrieval","volume":"Vol. 39","author":"Li","year":"2025"},{"key":"10.1016\/j.dsp.2026.106357_bib0043","doi-asserted-by":"crossref","first-page":"2737","DOI":"10.1109\/TIP.2025.3561659","article-title":"Cross-modal hashing via diverse instances matching","volume":"34","author":"Tu","year":"2025","journal-title":"IEEE Trans. Image Process."},{"key":"10.1016\/j.dsp.2026.106357_bib0044","doi-asserted-by":"crossref","DOI":"10.1016\/j.patcog.2026.113180","article-title":"Joint asymmetric discrete hashing for cross-modal retrieval","volume":"176","author":"Li","year":"2026","journal-title":"Pattern Recognit."},{"key":"10.1016\/j.dsp.2026.106357_bib0045","series-title":"Proceedings of the AAAI Conference on Artificial Intelligence","first-page":"4592","article-title":"Polysemic semantic instance network for cross-modal hashing","volume":"Vol. 40","author":"Han","year":"2026"},{"issue":"12","key":"10.1016\/j.dsp.2026.106357_bib0046","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3744567","article-title":"A unified generative hashing for cross-modal retrieval","volume":"21","author":"Tu","year":"2025","journal-title":"ACM Trans. Multimed. Comput. Commun. Appl."},{"issue":"4","key":"10.1016\/j.dsp.2026.106357_bib0047","doi-asserted-by":"crossref","first-page":"1473","DOI":"10.1109\/TCYB.2018.2882908","article-title":"Adversarial examples for hamming space search","volume":"50","author":"Yang","year":"2018","journal-title":"IEEE Trans. Cybern."},{"key":"10.1016\/j.dsp.2026.106357_bib0048","series-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","first-page":"9651","article-title":"Evade deep image retrieval by stashing private images in the hash space","author":"Xiao","year":"2020"},{"key":"10.1016\/j.dsp.2026.106357_bib0049","series-title":"Proceedings of the AAAI Conference on Artificial Intelligence","first-page":"10786","article-title":"Adversarial attack on deep product quantization network for image retrieval","volume":"Vol. 34","author":"Feng","year":"2020"},{"key":"10.1016\/j.dsp.2026.106357_bib0050","series-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","first-page":"3330","article-title":"QAIR: practical query-efficient black-box attacks for image retrieval","author":"Li","year":"2021"},{"key":"10.1016\/j.dsp.2026.106357_bib0051","series-title":"Computer Vision\u2013ECCV 2020: 16th European Conference, Glasgow, UK, August 23\u201328, 2020, Proceedings, Part I 16","first-page":"618","article-title":"Targeted attack for deep hashing based retrieval","author":"Bai","year":"2020"},{"key":"10.1016\/j.dsp.2026.106357_bib0052","series-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","first-page":"1934","article-title":"You see what I want you to see: exploring targeted black-box transferability attack for hash-based image retrieval systems","author":"Xiao","year":"2021"},{"key":"10.1016\/j.dsp.2026.106357_bib0053","series-title":"Proceedings of the 29th ACM International Conference on Multimedia","first-page":"2335","article-title":"AdvHash: set-to-set targeted attack on deep hashing with one single adversarial patch","author":"Hu","year":"2021"},{"key":"10.1016\/j.dsp.2026.106357_bib0054","series-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","first-page":"16357","article-title":"Prototype-supervised adversarial network for targeted attack of deep hashing","author":"Wang","year":"2021"},{"key":"10.1016\/j.dsp.2026.106357_bib0055","series-title":"Proceedings of the AAAI Conference on Artificial Intelligence","first-page":"3626","article-title":"Huang: a robust diffusion model-based targeted adversarial attack against deep hashing retrieval","volume":"Vol. 39","author":"Huang","year":"2025"},{"key":"10.1016\/j.dsp.2026.106357_bib0056","doi-asserted-by":"crossref","first-page":"1695","DOI":"10.1109\/TIFS.2025.3534585","article-title":"All points guided adversarial generator for targeted attack against deep hashing retrieval","volume":"20","author":"Tu","year":"2025","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.dsp.2026.106357_bib0057","first-page":"10791","article-title":"Cross-modal learning with adversarial samples","volume":"32","author":"Li","year":"2019","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"10.1016\/j.dsp.2026.106357_bib0058","series-title":"Proceedings of the 26th ACM SIGKDD International Conference on Knowledge Discovery & Data Mining","first-page":"421","article-title":"Vulnerability vs. reliability: disentangled adversarial examples for cross-modal learning","author":"Li","year":"2020"},{"key":"10.1016\/j.dsp.2026.106357_bib0059","series-title":"Proceedings of the IEEE\/CVF International Conference on Computer Vision","first-page":"2218","article-title":"Adversarial attack on deep cross-modal hamming retrieval","author":"Li","year":"2021"},{"issue":"3","key":"10.1016\/j.dsp.2026.106357_bib0060","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3559758","article-title":"Efficient query-based black-box attack against cross-modal hashing retrieval","volume":"41","author":"Zhu","year":"2023","journal-title":"ACM Trans. Inf. Syst."},{"issue":"2","key":"10.1016\/j.dsp.2026.106357_bib0061","first-page":"1","article-title":"Proactive privacy-preserving learning for cross-modal retrieval","volume":"41","author":"Zhang","year":"2023","journal-title":"ACM Trans. Inf. Syst."},{"key":"10.1016\/j.dsp.2026.106357_bib0062","doi-asserted-by":"crossref","first-page":"312","DOI":"10.1109\/TMM.2024.3521697","article-title":"Primary code guided targeted attack against cross-modal hashing retrieval","volume":"27","author":"Guo","year":"2024","journal-title":"IEEE Trans. Multimed."},{"issue":"12","key":"10.1016\/j.dsp.2026.106357_bib0063","doi-asserted-by":"crossref","first-page":"573","DOI":"10.3390\/fi17120573","article-title":"Cross-Gen: an efficient generator network for adversarial attacks on cross-modal hashing retrieval","volume":"17","author":"Hu","year":"2025","journal-title":"Fut. Internet"},{"key":"10.1016\/j.dsp.2026.106357_bib0064","unstructured":"G. Lin, C. Li, J. Zhang, T. Tanaka, Q. Zhao, Adversarial training on purification (ATOP): Advancing both robustness and generalization, (2024). arXiv preprint arXiv: 2401.16352."},{"key":"10.1016\/j.dsp.2026.106357_bib0065","unstructured":"G. Lin, Z. Tao, J. Zhang, T. Tanaka, Q. Zhao, Robust diffusion models for adversarial purification, 436 (2024). arXiv preprint arXiv: 2403.16067."},{"issue":"1","key":"10.1016\/j.dsp.2026.106357_bib0066","doi-asserted-by":"crossref","first-page":"984","DOI":"10.1109\/TII.2022.3169973","article-title":"Consensus adversarial defense method based on augmented examples","volume":"19","author":"Ding","year":"2022","journal-title":"IEEE Trans. Ind. Inform."},{"key":"10.1016\/j.dsp.2026.106357_bib0067","series-title":"Proceedings of the 44th International ACM SIGIR Conference on Research and Development in Information Retrieval","first-page":"2298","article-title":"Targeted attack and defense for deep hashing","author":"Wang","year":"2021"},{"key":"10.1016\/j.dsp.2026.106357_bib0068","doi-asserted-by":"crossref","first-page":"4681","DOI":"10.1109\/TIFS.2023.3297791","article-title":"Semantic-aware adversarial training for reliable deep hashing retrieval","volume":"18","author":"Yuan","year":"2023","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.dsp.2026.106357_bib0069","unstructured":"P. Samangouei, M. Kabkab, R. Chellappa, Defense-gan: protecting classifiers against adversarial attacks using generative models, (2018). arXiv preprint arXiv: 1805.06605."},{"key":"10.1016\/j.dsp.2026.106357_bib0070","unstructured":"Y. Song, T. Kim, S. Nowozin, S. Ermon, N. Kushman, Pixeldefend: leveraging generative models to understand and defend against adversarial examples, (2017). arXiv preprint arXiv: 1710.10766."},{"key":"10.1016\/j.dsp.2026.106357_bib0071","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1016\/j.neunet.2020.12.024","article-title":"Robustifying models against adversarial attacks by langevin dynamics","volume":"137","author":"Srinivasan","year":"2021","journal-title":"Neural Netw."},{"key":"10.1016\/j.dsp.2026.106357_bib0072","unstructured":"W. Grathwohl, K.C. Wang, J.H. Jacobsen, D. Duvenaud, M. Norouzi, K. Swersky, Your classifier is secretly an energy based model and you should treat it like one, (2019). arXiv preprint arXiv: 1912.03263."},{"key":"10.1016\/j.dsp.2026.106357_bib0073","first-page":"3603","article-title":"Implicit generation and modeling with energy based models","volume":"32","author":"Du","year":"2019","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"10.1016\/j.dsp.2026.106357_bib0074","unstructured":"M. Hill, J. Mitchell, S.-C. Zhu, Stochastic security: adversarial defense using long-run dynamics of energy-based models, (2020). arXiv preprint arXiv: 2005.13525."},{"key":"10.1016\/j.dsp.2026.106357_bib0075","series-title":"International Conference on Machine Learning","first-page":"12062","article-title":"Adversarial purification with score-based generative models","author":"Yoon","year":"2021"},{"key":"10.1016\/j.dsp.2026.106357_bib0076","unstructured":"Q. Wu, H. Ye, Y. Gu, Guided diffusion model for adversarial purification from random noise, (2022). arXiv preprint arXiv: 2206.10875."},{"key":"10.1016\/j.dsp.2026.106357_bib0077","unstructured":"J. Sun, J. Wang, W. Nie, Z. Yu, Z. Mao, C. Xiao, A critical revisit of adversarial robustness in 3D point cloud recognition with diffusion-driven purification, in: PMLR, Vol. 202, 2023, pp. 33100\u201333114."},{"key":"10.1016\/j.dsp.2026.106357_bib0078","series-title":"International Conference on Learning Representations","first-page":"78366","article-title":"ADBM: adversarial diffusion bridge model for reliable adversarial purification","volume":"Vol. 2025","author":"Li","year":"2025"},{"key":"10.1016\/j.dsp.2026.106357_bib0079","doi-asserted-by":"crossref","DOI":"10.1016\/j.neucom.2024.129214","article-title":"Adversarial purification of information masking","volume":"621","author":"Liu","year":"2025","journal-title":"Neurocomputing"},{"key":"10.1016\/j.dsp.2026.106357_bib0080","series-title":"Proceedings of the Computer Vision and Pattern Recognition Conference","first-page":"29268","article-title":"Divide and conquer: heterogeneous noise integration for diffusion-based adversarial purification","author":"Pei","year":"2025"},{"key":"10.1016\/j.dsp.2026.106357_bib0081","first-page":"6840","article-title":"Denoising diffusion probabilistic models","volume":"33","author":"Ho","year":"2020","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"10.1016\/j.dsp.2026.106357_bib0082","series-title":"International Conference on Machine Learning","first-page":"8162","article-title":"Improved denoising diffusion probabilistic models","author":"Nichol","year":"2021"},{"key":"10.1016\/j.dsp.2026.106357_bib0083","first-page":"8780","article-title":"Diffusion models beat gans on image synthesis","volume":"34","author":"Dhariwal","year":"2021","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"10.1016\/j.dsp.2026.106357_bib0084","series-title":"Advances in Neural Information Processing Systems","article-title":"Spectrally-normalized margin bounds for neural networks","volume":"Vol. 30","author":"Bartlett","year":"2017"},{"key":"10.1016\/j.dsp.2026.106357_bib0085","series-title":"Advances in Neural Information Processing Systems","article-title":"Lipschitz regularity of deep neural networks: analysis and efficient estimation","volume":"Vol. 31","author":"Scaman","year":"2018"},{"issue":"3","key":"10.1016\/j.dsp.2026.106357_bib0086","doi-asserted-by":"crossref","first-page":"521","DOI":"10.1109\/TPAMI.2013.142","article-title":"On the role of correlation and abstraction in cross-modal multimedia retrieval","volume":"36","author":"Pereira","year":"2013","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"issue":"4","key":"10.1016\/j.dsp.2026.106357_bib0087","doi-asserted-by":"crossref","first-page":"419","DOI":"10.1016\/j.cviu.2009.03.008","article-title":"The segmented and annotated IAPR TC-12 benchmark","volume":"114","author":"Escalante","year":"2010","journal-title":"Comput. Vis. Image Underst."},{"key":"10.1016\/j.dsp.2026.106357_bib0088","series-title":"Proceedings of the 1st ACM International Conference on Multimedia Information Retrieval","first-page":"39","article-title":"The MIR flickr retrieval evaluation","author":"Huiskes","year":"2008"},{"key":"10.1016\/j.dsp.2026.106357_bib0089","series-title":"Computer Vision\u2013ECCV 2014: 13th European Conference, Zurich, Switzerland, September 6\u201312, 2014, Proceedings, Part V 13","first-page":"740","article-title":"Microsoft COCO: common objects in context","author":"Lin","year":"2014"},{"key":"10.1016\/j.dsp.2026.106357_bib0090","series-title":"Proceedings of the ACM International Conference on Image and Video Retrieval","first-page":"1","article-title":"NUS-wide: a real-world web image database from national university of singapore","author":"Chua","year":"2009"},{"key":"10.1016\/j.dsp.2026.106357_bib0091","unstructured":"K. Simonyan, A. Zisserman, Very deep convolutional networks for large-scale image recognition, (2014). arXiv preprint arXiv: 1409.1556."}],"container-title":["Digital Signal Processing"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S1051200426004756?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S1051200426004756?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T09:35:59Z","timestamp":1782812159000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S1051200426004756"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,11]]},"references-count":91,"alternative-id":["S1051200426004756"],"URL":"https:\/\/doi.org\/10.1016\/j.dsp.2026.106357","relation":{},"ISSN":["1051-2004"],"issn-type":[{"value":"1051-2004","type":"print"}],"subject":[],"published":{"date-parts":[[2026,11]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"RetPur: Diffusion-based defense against black-box targeted attacks in hashing retrieval","name":"articletitle","label":"Article Title"},{"value":"Digital Signal Processing","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.dsp.2026.106357","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier Inc. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"106357"}}