{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,2]],"date-time":"2026-06-02T14:24:08Z","timestamp":1780410248601,"version":"3.54.1"},"reference-count":41,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Future Generation Computer Systems"],"published-print":{"date-parts":[[2026,10]]},"DOI":"10.1016\/j.future.2026.108542","type":"journal-article","created":{"date-parts":[[2026,4,21]],"date-time":"2026-04-21T14:53:44Z","timestamp":1776783224000},"page":"108542","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["Enhancing adversarial robustness of neural networks via quantum computing"],"prefix":"10.1016","volume":"183","author":[{"given":"Xiangyu","family":"Shi","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yunzhe","family":"Tian","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yike","family":"Li","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Weiwei","family":"Jiang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Leyu","family":"Fu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xingyu","family":"Wu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xiaoshu","family":"Cui","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4706-4266","authenticated-orcid":false,"given":"Wenjia","family":"Niu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"issue":"6245","key":"10.1016\/j.future.2026.108542_b1","doi-asserted-by":"crossref","first-page":"255","DOI":"10.1126\/science.aaa8415","article-title":"Machine learning: Trends, perspectives, and prospects","volume":"349","author":"Jordan","year":"2015","journal-title":"Science"},{"issue":"2","key":"10.1016\/j.future.2026.108542_b2","doi-asserted-by":"crossref","first-page":"117","DOI":"10.1088\/0034-4885\/61\/2\/002","article-title":"Quantum computing","volume":"61","author":"Steane","year":"1998","journal-title":"Rep. Progr. Phys."},{"issue":"7553","key":"10.1016\/j.future.2026.108542_b3","doi-asserted-by":"crossref","first-page":"436","DOI":"10.1038\/nature14539","article-title":"Deep learning","volume":"521","author":"LeCun","year":"2015","journal-title":"Nature"},{"issue":"3","key":"10.1016\/j.future.2026.108542_b4","doi-asserted-by":"crossref","first-page":"1529","DOI":"10.1109\/TR.2024.3367780","article-title":"Toward learning model-agnostic explanations for deep learning-based signal modulation classifiers","volume":"73","author":"Tian","year":"2024","journal-title":"IEEE Trans. Reliab."},{"key":"10.1016\/j.future.2026.108542_b5","series-title":"2020 IEEE 26th International Conference on Parallel and Distributed Systems","first-page":"430","article-title":"Exploring data correlation between feature pairs for generating constraint-based adversarial examples","author":"Tian","year":"2020"},{"issue":"7671","key":"10.1016\/j.future.2026.108542_b6","doi-asserted-by":"crossref","first-page":"195","DOI":"10.1038\/nature23474","article-title":"Quantum machine learning","volume":"549","author":"Biamonte","year":"2017","journal-title":"Nature"},{"key":"10.1016\/j.future.2026.108542_b7","series-title":"International Joint Conference on Artificial Intelligence","article-title":"Robust reinforcement learning via progressive task sequence","author":"Li","year":"2023"},{"key":"10.1016\/j.future.2026.108542_b8","article-title":"Adversarial examples are not bugs, they are features","volume":"32","author":"Ilyas","year":"2019","journal-title":"Adv. Neural Inf. Process. Syst."},{"issue":"6","key":"10.1016\/j.future.2026.108542_b9","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3648351","article-title":"Adversarial robustness of neural networks from the perspective of lipschitz calculus: A survey","volume":"57","author":"Z\u00fchlke","year":"2025","journal-title":"ACM Comput. Surv."},{"key":"10.1016\/j.future.2026.108542_b10","series-title":"Beard: Benchmarking the adversarial robustness for dataset distillation","author":"Zhou","year":"2024"},{"key":"10.1016\/j.future.2026.108542_b11","series-title":"OodRobustBench: a benchmark and large-scale analysis of adversarial robustness under distribution shift","author":"Li","year":"2023"},{"key":"10.1016\/j.future.2026.108542_b12","doi-asserted-by":"crossref","DOI":"10.1016\/j.ins.2023.119838","article-title":"Rethinking data augmentation for adversarial robustness","volume":"654","author":"Eghbal-zadeh","year":"2024","journal-title":"Inform. Sci."},{"key":"10.1016\/j.future.2026.108542_b13","doi-asserted-by":"crossref","DOI":"10.1016\/j.cviu.2023.103855","article-title":"AdaNI: Adaptive noise injection to improve adversarial robustness","volume":"238","author":"Li","year":"2024","journal-title":"Comput. Vis. Image Underst."},{"key":"10.1016\/j.future.2026.108542_b14","first-page":"5775","article-title":"Robust SAM: On the adversarial robustness of vision foundation models","volume":"vol. 39","author":"Long","year":"2025"},{"key":"10.1016\/j.future.2026.108542_b15","unstructured":"Z. Zhou, W. Feng, Q. Zhang, S. Lyu, Q. Zhao, G. Cheng, ROME is Forged in Adversity: Robust Distilled Datasets via Information Bottleneck, in: Forty-Second International Conference on Machine Learning, 2025."},{"key":"10.1016\/j.future.2026.108542_b16","article-title":"A novel quantum-based mutual authentication and key agreement scheme for smart grid","author":"Lou","year":"2026","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.future.2026.108542_b17","article-title":"Privacy-preserving bidirectional data transmission of smart grid via semi-quantum computation: on mutual identity and message authentication","author":"Lou","year":"2025","journal-title":"IEEE Trans. Dependable Secur. Comput."},{"issue":"11","key":"10.1016\/j.future.2026.108542_b18","doi-asserted-by":"crossref","DOI":"10.1002\/qute.202500439","article-title":"Efficient multi-party semi-quantum private comparison protocol based on bell states","volume":"8","author":"Zhou","year":"2025","journal-title":"Adv. Quantum Technol."},{"key":"10.1016\/j.future.2026.108542_b19","doi-asserted-by":"crossref","DOI":"10.1088\/1674-1056\/ae2abd","article-title":"Efficient semi-quantum private comparison protocol of size relation based on high dimensional bell states","author":"Huang","year":"2025","journal-title":"Chin. Phys. B"},{"issue":"3","key":"10.1016\/j.future.2026.108542_b20","doi-asserted-by":"crossref","DOI":"10.1103\/PhysRevResearch.2.033212","article-title":"Quantum adversarial machine learning","volume":"2","author":"Lu","year":"2020","journal-title":"Phys. Rev. Res."},{"issue":"11","key":"10.1016\/j.future.2026.108542_b21","doi-asserted-by":"crossref","first-page":"711","DOI":"10.1038\/s43588-022-00351-9","article-title":"Experimental quantum adversarial learning with programmable superconducting qubits","volume":"2","author":"Ren","year":"2022","journal-title":"Nat. Comput. Sci."},{"key":"10.1016\/j.future.2026.108542_b22","series-title":"Adversarial robustness guarantees for quantum classifiers","author":"Dowling","year":"2024"},{"issue":"2","key":"10.1016\/j.future.2026.108542_b23","doi-asserted-by":"crossref","DOI":"10.1103\/PhysRevResearch.3.023153","article-title":"Quantum noise protects quantum classifiers against adversaries","volume":"3","author":"Du","year":"2021","journal-title":"Phys. Rev. Res."},{"issue":"1","key":"10.1016\/j.future.2026.108542_b24","doi-asserted-by":"crossref","first-page":"76","DOI":"10.1038\/s41534-021-00410-5","article-title":"Optimal provable robustness of quantum classification via quantum hypothesis testing","volume":"7","author":"Weber","year":"2021","journal-title":"Npj Quantum Inf."},{"issue":"4","key":"10.1016\/j.future.2026.108542_b25","doi-asserted-by":"crossref","DOI":"10.1103\/PhysRevResearch.6.043326","article-title":"Training robust and generalizable quantum models","volume":"6","author":"Berberich","year":"2024","journal-title":"Phys. Rev. Res."},{"key":"10.1016\/j.future.2026.108542_b26","first-page":"1447","article-title":"A comparative analysis of adversarial robustness for quantum and classical machine learning models","volume":"vol. 1","author":"Wendlinger","year":"2024"},{"issue":"2","key":"10.1016\/j.future.2026.108542_b27","doi-asserted-by":"crossref","DOI":"10.1103\/PhysRevResearch.5.023186","article-title":"Benchmarking adversarially robust quantum machine learning at scale","volume":"5","author":"West","year":"2023","journal-title":"Phys. Rev. Res."},{"key":"10.1016\/j.future.2026.108542_b28","series-title":"2024 IEEE International Conference on Quantum Software","first-page":"175","article-title":"Advqunn: A methodology for analyzing the adversarial robustness of quanvolutional neural networks","author":"El Maouaki","year":"2024"},{"issue":"2","key":"10.1016\/j.future.2026.108542_b29","doi-asserted-by":"crossref","DOI":"10.1103\/PhysRevResearch.6.023020","article-title":"Enhancing quantum adversarial robustness by randomized encodings","volume":"6","author":"Gong","year":"2024","journal-title":"Phys. Rev. Res."},{"key":"10.1016\/j.future.2026.108542_b30","series-title":"Explaining and harnessing adversarial examples","author":"Goodfellow","year":"2014"},{"key":"10.1016\/j.future.2026.108542_b31","series-title":"Artificial Intelligence Safety and Security","first-page":"99","article-title":"Adversarial examples in the physical world","author":"Kurakin","year":"2018"},{"key":"10.1016\/j.future.2026.108542_b32","series-title":"Towards deep learning models resistant to adversarial attacks","author":"Madry","year":"2017"},{"key":"10.1016\/j.future.2026.108542_b33","doi-asserted-by":"crossref","unstructured":"Y. Dong, F. Liao, T. Pang, H. Su, J. Zhu, X. Hu, J. Li, Boosting adversarial attacks with momentum, in: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, CVPR, 2018, pp. 9185\u20139193.","DOI":"10.1109\/CVPR.2018.00957"},{"key":"10.1016\/j.future.2026.108542_b34","series-title":"2017 IEEE Symposium on Security and Privacy","first-page":"39","article-title":"Towards evaluating the robustness of neural networks","author":"Carlini","year":"2017"},{"issue":"11","key":"10.1016\/j.future.2026.108542_b35","doi-asserted-by":"crossref","first-page":"2278","DOI":"10.1109\/5.726791","article-title":"Gradient-based learning applied to document recognition","volume":"86","author":"LeCun","year":"2002","journal-title":"Proc. IEEE"},{"key":"10.1016\/j.future.2026.108542_b36","series-title":"Fashion-mnist: a novel image dataset for benchmarking machine learning algorithms","author":"Xiao","year":"2017"},{"key":"10.1016\/j.future.2026.108542_b37","series-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009"},{"key":"10.1016\/j.future.2026.108542_b38","article-title":"Improving the adversarial robustness and interpretability of deep neural networks by regularizing their input gradients","volume":"vol. 32","author":"Ross","year":"2018"},{"key":"10.1016\/j.future.2026.108542_b39","doi-asserted-by":"crossref","unstructured":"C. Szegedy, V. Vanhoucke, S. Ioffe, J. Shlens, Z. Wojna, Rethinking the inception architecture for computer vision, in: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, 2016, pp. 2818\u20132826.","DOI":"10.1109\/CVPR.2016.308"},{"key":"10.1016\/j.future.2026.108542_b40","series-title":"2016 IEEE Symposium on Security and Privacy","first-page":"582","article-title":"Distillation as a defense to adversarial perturbations against deep neural networks","author":"Papernot","year":"2016"},{"key":"10.1016\/j.future.2026.108542_b41","series-title":"Mixup: Beyond empirical risk minimization","author":"Zhang","year":"2017"}],"container-title":["Future Generation Computer Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0167739X26001767?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0167739X26001767?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,6,2]],"date-time":"2026-06-02T13:45:55Z","timestamp":1780407955000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0167739X26001767"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,10]]},"references-count":41,"alternative-id":["S0167739X26001767"],"URL":"https:\/\/doi.org\/10.1016\/j.future.2026.108542","relation":{},"ISSN":["0167-739X"],"issn-type":[{"value":"0167-739X","type":"print"}],"subject":[],"published":{"date-parts":[[2026,10]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"Enhancing adversarial robustness of neural networks via quantum computing","name":"articletitle","label":"Article Title"},{"value":"Future Generation Computer Systems","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.future.2026.108542","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier B.V. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"108542"}}