{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,2]],"date-time":"2026-06-02T12:14:27Z","timestamp":1780402467197,"version":"3.54.1"},"reference-count":40,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Neural Networks"],"published-print":{"date-parts":[[2026,11]]},"DOI":"10.1016\/j.neunet.2026.109189","type":"journal-article","created":{"date-parts":[[2026,5,29]],"date-time":"2026-05-29T15:55:55Z","timestamp":1780070155000},"page":"109189","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["DPC: Dynamic purification chain for adaptive adversarial defense"],"prefix":"10.1016","volume":"203","author":[{"ORCID":"https:\/\/orcid.org\/0009-0009-3086-1569","authenticated-orcid":false,"given":"Zeshan","family":"Pang","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yuyuan","family":"Sun","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0005-8269-4871","authenticated-orcid":false,"given":"Rongtao","family":"Liao","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xuehu","family":"Yan","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3308-9123","authenticated-orcid":false,"given":"Shasha","family":"Guo","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yuliang","family":"Lu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"key":"10.1016\/j.neunet.2026.109189_bib0001","series-title":"Proceedings of the 35th international conference on machine learning","first-page":"274","article-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","volume":"Vol. 80","author":"Athalye","year":"2018"},{"key":"10.1016\/j.neunet.2026.109189_bib0002","series-title":"Proceedings of the 35th international conference on machine learning","first-page":"284","article-title":"Synthesizing robust adversarial examples","volume":"Vol. 80","author":"Athalye","year":"2018"},{"key":"10.1016\/j.neunet.2026.109189_bib0003","series-title":"2017 IEEE symposium on security and privacy (SP)","first-page":"39","article-title":"Towards evaluating the robustness of neural networks","author":"Carlini","year":"2017"},{"key":"10.1016\/j.neunet.2026.109189_bib0004","series-title":"2022 IEEE international conference on trust, security and privacy in computing and communications (trustcom)","first-page":"976","article-title":"Dynamic and diverse transformations for defending against adversarial examples","author":"Chen","year":"2022"},{"key":"10.1016\/j.neunet.2026.109189_bib0005","first-page":"1","article-title":"Adversarial attacks on autonomous driving systems in the physical world: A survey","author":"Chi","year":"2024","journal-title":"IEEE Transactions on Intelligent Vehicles"},{"key":"10.1016\/j.neunet.2026.109189_bib0006","series-title":"Proceedings of the 36th international conference on machine learning","first-page":"1310","article-title":"Certified adversarial robustness via randomized smoothing","volume":"vol. 97","author":"Cohen","year":"2019"},{"key":"10.1016\/j.neunet.2026.109189_bib0007","series-title":"International conference on machine learning","first-page":"2206","article-title":"Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks","author":"Croce","year":"2020"},{"key":"10.1016\/j.neunet.2026.109189_bib0008","series-title":"2009 IEEE conference on computer vision and pattern recognition","first-page":"248","article-title":"ImageNet: A large-scale hierarchical image database","author":"Deng","year":"2009"},{"issue":"3","key":"10.1016\/j.neunet.2026.109189_bib0009","doi-asserted-by":"crossref","DOI":"10.1145\/3702638","article-title":"Survey on adversarial attack and defense for medical image analysis: Methods and challenges","volume":"57","author":"Dong","year":"2024","journal-title":"ACM Computing Surveys"},{"key":"10.1016\/j.neunet.2026.109189_bib0010","series-title":"International conference on learning representations","author":"Goodfellow","year":"2015"},{"key":"10.1016\/j.neunet.2026.109189_bib0011","series-title":"2016 IEEE conference on computer vision and pattern recognition (CVPR)","first-page":"770","article-title":"Deep residual learning for image recognition","author":"He","year":"2016"},{"key":"10.1016\/j.neunet.2026.109189_bib0012","doi-asserted-by":"crossref","first-page":"706","DOI":"10.1016\/j.neunet.2023.08.063","article-title":"Boosting adversarial robustness via self-paced adversarial training","volume":"167","author":"He","year":"2023","journal-title":"Neural Networks"},{"key":"10.1016\/j.neunet.2026.109189_bib0013","unstructured":"Howard, J.. imagenette. https:\/\/github.com\/fastai\/imagenette\/."},{"key":"10.1016\/j.neunet.2026.109189_bib0014","series-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition","first-page":"24668","article-title":"Boosting accuracy and robustness of student models via adaptive adversarial distillation","author":"Huang","year":"2023"},{"key":"10.1016\/j.neunet.2026.109189_bib0015","series-title":"Technical Report","article-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009"},{"key":"10.1016\/j.neunet.2026.109189_bib0016","series-title":"2023 IEEE\/CVF international conference on computer vision (ICCV)","first-page":"134","article-title":"Robust evaluation of diffusion-based adversarial purification","author":"Lee","year":"2023"},{"key":"10.1016\/j.neunet.2026.109189_bib0017","doi-asserted-by":"crossref","first-page":"177","DOI":"10.1016\/j.neunet.2023.03.008","article-title":"Learning defense transformations for counterattacking adversarial examples","volume":"164","author":"Li","year":"2023","journal-title":"Neural Networks"},{"key":"10.1016\/j.neunet.2026.109189_bib0018","series-title":"Proceedings of the IEEE conference on computer vision and pattern recognition","first-page":"1778","article-title":"Defense against adversarial attacks using high-level representation guided denoiser","author":"Liao","year":"2018"},{"key":"10.1016\/j.neunet.2026.109189_bib0019","series-title":"2022 IEEE\/CVF conference on computer vision and pattern recognition (CVPR)","first-page":"80","article-title":"The devil is in the margin: Margin-based label smoothing for network calibration","author":"Liu","year":"2022"},{"key":"10.1016\/j.neunet.2026.109189_bib0020","series-title":"International conference on learning representations","article-title":"Towards deep learning models resistant to adversarial attacks","author":"Madry","year":"2018"},{"key":"10.1016\/j.neunet.2026.109189_bib0021","series-title":"Proceedings of the 39th international conference on machine learning","first-page":"16805","article-title":"Diffusion models for adversarial purification","volume":"Vol. 162","author":"Nie","year":"2022"},{"key":"10.1016\/j.neunet.2026.109189_bib0022","series-title":"Proceedings of the 36th international conference on machine learning","first-page":"4970","article-title":"Improving adversarial robustness via promoting ensemble diversity","volume":"vol. 97","author":"Pang","year":"2019"},{"key":"10.1016\/j.neunet.2026.109189_bib0023","series-title":"2024 IEEE 23rd international conference on trust, security and privacy in computing and communications (trustcom)","first-page":"2336","article-title":"Destruction and reconstruction chain: An adaptive adversarial purification framework","author":"Pang","year":"2024"},{"key":"10.1016\/j.neunet.2026.109189_bib0024","series-title":"2016 IEEE symposium on security and privacy (SP)","first-page":"582","article-title":"Distillation as a defense to adversarial perturbations against deep neural networks","author":"Papernot","year":"2016"},{"key":"10.1016\/j.neunet.2026.109189_bib0025","series-title":"Proceedings of the IEEE\/CVF international conference on computer vision","first-page":"81","article-title":"Enhancing adversarial robustness via test-time transformation ensembling","author":"P\u00e9rez","year":"2021"},{"key":"10.1016\/j.neunet.2026.109189_bib0026","series-title":"9th international conference on learning representations, ICLR 2021, virtual event, Austria, May 3\u20137, 2021","article-title":"Online adversarial purification based on self-supervised learning","author":"Shi","year":"2021"},{"key":"10.1016\/j.neunet.2026.109189_bib0027","unstructured":"Szegedy, C. (2013). Intriguing properties of neural networks. preprint arXiv: 1312.6199."},{"key":"10.1016\/j.neunet.2026.109189_bib0028","first-page":"1633","article-title":"On adaptive attacks to adversarial example defenses","volume":"33","author":"Tramer","year":"2020","journal-title":"Advances in Neural Information Processing Systems"},{"key":"10.1016\/j.neunet.2026.109189_bib0029","series-title":"Proceedings of the IEEE conference on computer vision and pattern recognition","first-page":"9446","article-title":"Deep image prior","author":"Ulyanov","year":"2018"},{"key":"10.1016\/j.neunet.2026.109189_bib0030","doi-asserted-by":"crossref","DOI":"10.1016\/j.neunet.2024.106176","article-title":"Defense against adversarial attacks based on color space transformation","volume":"173","author":"Wang","year":"2024","journal-title":"Neural Networks"},{"key":"10.1016\/j.neunet.2026.109189_bib0031","series-title":"The thirty-eighth annual conference on neural information processing systems","article-title":"Diffhammer: Rethinking the robustness of diffusion-based adversarial purification","author":"Wang","year":"2024"},{"key":"10.1016\/j.neunet.2026.109189_bib0032","series-title":"Proceedings of the 39th international conference on machine learning","first-page":"23631","article-title":"Mitigating neural network overconfidence with logit normalization","volume":"Vol. 162","author":"Wei","year":"2022"},{"key":"10.1016\/j.neunet.2026.109189_bib0033","series-title":"International conference on machine learning","first-page":"10693","article-title":"Randomized smoothing of all shapes and sizes","author":"Yang","year":"2020"},{"key":"10.1016\/j.neunet.2026.109189_bib0034","first-page":"5505","article-title":"Dverge: Diversifying vulnerabilities for enhanced robust generation of ensembles","volume":"33","author":"Yang","year":"2020","journal-title":"Advances in Neural Information Processing Systems"},{"key":"10.1016\/j.neunet.2026.109189_bib0035","series-title":"Advances in neural information processing systems","article-title":"TRS: Transferability reduced ensemble via promoting gradient diversity and model smoothness","author":"Yang","year":"2021"},{"key":"10.1016\/j.neunet.2026.109189_bib0036","series-title":"Proceedings of the AAAI conference on artificial intelligence","first-page":"16379","article-title":"Adversarial purification with the manifold hypothesis","volume":"vol. 38","author":"Yang","year":"2024"},{"key":"10.1016\/j.neunet.2026.109189_bib0037","series-title":"Proceedings of the british machine vision conference (BMVC)","first-page":"87.1","article-title":"Wide residual networks","author":"Zagoruyko","year":"2016"},{"key":"10.1016\/j.neunet.2026.109189_bib0038","series-title":"Proceedings of the 36th international conference on machine learning","first-page":"7472","article-title":"Theoretically principled trade-off between robustness and accuracy","volume":"Vol. 97","author":"Zhang","year":"2019"},{"key":"10.1016\/j.neunet.2026.109189_bib0039","series-title":"2021 IEEE\/CVF international conference on computer vision (ICCV)","first-page":"7858","article-title":"Removing adversarial noise in class activation feature space","author":"Zhou","year":"2021"},{"key":"10.1016\/j.neunet.2026.109189_bib0040","series-title":"Proceedings of the IEEE\/CVF international conference on computer vision","first-page":"7878","article-title":"Removing adversarial noise in class activation feature space","author":"Zhou","year":"2021"}],"container-title":["Neural Networks"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0893608026006507?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0893608026006507?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,6,2]],"date-time":"2026-06-02T11:57:48Z","timestamp":1780401468000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0893608026006507"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,11]]},"references-count":40,"alternative-id":["S0893608026006507"],"URL":"https:\/\/doi.org\/10.1016\/j.neunet.2026.109189","relation":{},"ISSN":["0893-6080"],"issn-type":[{"value":"0893-6080","type":"print"}],"subject":[],"published":{"date-parts":[[2026,11]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"DPC: Dynamic purification chain for adaptive adversarial defense","name":"articletitle","label":"Article Title"},{"value":"Neural Networks","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.neunet.2026.109189","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier Ltd. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"109189"}}