{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,4]],"date-time":"2026-07-04T12:16:53Z","timestamp":1783167413623,"version":"3.54.6"},"reference-count":43,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62372395"],"award-info":[{"award-number":["62372395"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62372396"],"award-info":[{"award-number":["62372396"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62532009"],"award-info":[{"award-number":["62532009"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100014472","name":"Scientific Research Foundation of Hunan Provincial Education Department","doi-asserted-by":"publisher","award":["24A0105"],"award-info":[{"award-number":["24A0105"]}],"id":[{"id":"10.13039\/100014472","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100004735","name":"Hunan Provincial Natural Science Foundation","doi-asserted-by":"publisher","award":["2025JJ50349"],"award-info":[{"award-number":["2025JJ50349"]}],"id":[{"id":"10.13039\/501100004735","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Pattern Recognition"],"published-print":{"date-parts":[[2026,11]]},"DOI":"10.1016\/j.patcog.2026.113958","type":"journal-article","created":{"date-parts":[[2026,5,19]],"date-time":"2026-05-19T19:31:41Z","timestamp":1779219101000},"page":"113958","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"PD","title":["Efficient adversarial purification via consistency model and reinforcement learning-based diffusion sequence selection"],"prefix":"10.1016","volume":"179","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-2754-9883","authenticated-orcid":false,"given":"Yanchun","family":"Li","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0008-7266-2472","authenticated-orcid":false,"given":"Zhenlin","family":"Song","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yichen","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3192-6378","authenticated-orcid":false,"given":"Haolin","family":"Liu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0684-0591","authenticated-orcid":false,"given":"Shujuan","family":"Tian","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-5682-9209","authenticated-orcid":false,"given":"Jing","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"key":"10.1016\/j.patcog.2026.113958_b1","doi-asserted-by":"crossref","DOI":"10.1016\/j.patcog.2024.111035","article-title":"A benchmark dataset and semantics-guided detection network for spatial\u2013temporal human actions in urban driving scenes","volume":"158","author":"Zhong","year":"2025","journal-title":"Pattern Recognit."},{"key":"10.1016\/j.patcog.2026.113958_b2","doi-asserted-by":"crossref","DOI":"10.1016\/j.patcog.2024.111028","article-title":"TBConvL-Net: A hybrid deep learning architecture for robust medical image segmentation","volume":"158","author":"Iqbal","year":"2025","journal-title":"Pattern Recognit."},{"key":"10.1016\/j.patcog.2026.113958_b3","first-page":"20","article-title":"Explaining and harnessing adversarial examples","volume":"1050","author":"Goodfellow","year":"2015","journal-title":"Stat"},{"key":"10.1016\/j.patcog.2026.113958_b4","doi-asserted-by":"crossref","DOI":"10.1016\/j.patcog.2024.111007","article-title":"Rethinking the validity of perturbation in single-step adversarial training","volume":"158","author":"Ge","year":"2025","journal-title":"Pattern Recognit."},{"key":"10.1016\/j.patcog.2026.113958_b5","series-title":"International Conference on Machine Learning","first-page":"16805","article-title":"Diffusion models for adversarial purification","author":"Nie","year":"2022"},{"key":"10.1016\/j.patcog.2026.113958_b6","series-title":"Guided diffusion model for adversarial purification","author":"Wang","year":"2022"},{"key":"10.1016\/j.patcog.2026.113958_b7","series-title":"Guided diffusion model for adversarial purification from random noise","author":"Wu","year":"2022"},{"key":"10.1016\/j.patcog.2026.113958_b8","series-title":"International Conference on Machine Learning","first-page":"32211","article-title":"Consistency models","author":"Song","year":"2023"},{"key":"10.1016\/j.patcog.2026.113958_b9","doi-asserted-by":"crossref","DOI":"10.1016\/j.ins.2024.120804","article-title":"Evolutionary reinforcement learning with action sequence search for imperfect information games","volume":"676","author":"Wu","year":"2024","journal-title":"Inform. Sci."},{"key":"10.1016\/j.patcog.2026.113958_b10","series-title":"International Conference on Machine Learning","first-page":"1587","article-title":"Addressing function approximation error in actor-critic methods","author":"Fujimoto","year":"2018"},{"key":"10.1016\/j.patcog.2026.113958_b11","series-title":"Artificial Intelligence Safety and Security","first-page":"99","article-title":"Adversarial examples in the physical world","author":"Kurakin","year":"2018"},{"key":"10.1016\/j.patcog.2026.113958_b12","unstructured":"A. Madry, A. Makelov, L. Schmidt, D. Tsipras, A. Vladu, Towards Deep Learning Models Resistant to Adversarial Attacks, in: International Conference on Learning Representations, 2018."},{"key":"10.1016\/j.patcog.2026.113958_b13","series-title":"International Conference on Machine Learning","first-page":"274","article-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","author":"Athalye","year":"2018"},{"key":"10.1016\/j.patcog.2026.113958_b14","series-title":"International Conference on Machine Learning","first-page":"284","article-title":"Synthesizing robust adversarial examples","author":"Athalye","year":"2018"},{"key":"10.1016\/j.patcog.2026.113958_b15","series-title":"International Conference on Machine Learning","first-page":"2206","article-title":"Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks","author":"Croce","year":"2020"},{"key":"10.1016\/j.patcog.2026.113958_b16","doi-asserted-by":"crossref","unstructured":"N. Wang, S. Xie, T. Sato, Y. Luo, K. Xu, Q.A. Chen, Revisiting Physical-World Adversarial Attack on Traffic Sign Recognition: A Commercial Systems Perspective, in: Proceedings of the Network and Distributed System Security Symposium, NDSS, 2025.","DOI":"10.14722\/ndss.2025.230090"},{"key":"10.1016\/j.patcog.2026.113958_b17","doi-asserted-by":"crossref","unstructured":"I. Sahu, S. Hazra, S. Aditya, S. Dey, AD2: Analysis and Detection of Adversarial Threats in Visual Perception for End-to-End Autonomous Driving Systems, in: Proceedings of the IEEE\/CVF Winter Conference on Applications of Computer Vision, 2026, pp. 1695\u20131704.","DOI":"10.1109\/WACV61042.2026.00170"},{"key":"10.1016\/j.patcog.2026.113958_b18","series-title":"International Conference on Machine Learning","first-page":"7472","article-title":"Theoretically principled trade-off between robustness and accuracy","author":"Zhang","year":"2019"},{"key":"10.1016\/j.patcog.2026.113958_b19","first-page":"4218","article-title":"Improving robustness using generated data","volume":"vol. 34","author":"Gowal","year":"2021"},{"key":"10.1016\/j.patcog.2026.113958_b20","doi-asserted-by":"crossref","DOI":"10.1016\/j.patcog.2025.111474","article-title":"Robust shortcut and disordered robustness: Improving adversarial training through adaptive smoothing","volume":"163","author":"Li","year":"2025","journal-title":"Pattern Recognit."},{"key":"10.1016\/j.patcog.2026.113958_b21","unstructured":"P. Samangouei, M. Kabkab, R. Chellappa, Defense-GAN: Protecting Classifiers Against Adversarial Attacks Using Generative Models, in: International Conference on Learning Representations, 2018."},{"key":"10.1016\/j.patcog.2026.113958_b22","unstructured":"M. Hill, J.C. Mitchell, S.-C. Zhu, Stochastic Security: Adversarial Defense Using Long-Run Dynamics of Energy-Based Models, in: International Conference on Learning Representations, 2021."},{"key":"10.1016\/j.patcog.2026.113958_b23","series-title":"International Conference on Machine Learning","first-page":"12062","article-title":"Adversarial purification with score-based generative models","author":"Yoon","year":"2021"},{"key":"10.1016\/j.patcog.2026.113958_b24","doi-asserted-by":"crossref","unstructured":"M. Lee, D. Kim, Robust evaluation of diffusion-based adversarial purification, in: Proceedings of the IEEE\/CVF International Conference on Computer Vision, 2023, pp. 134\u2013144.","DOI":"10.1109\/ICCV51070.2023.00019"},{"key":"10.1016\/j.patcog.2026.113958_b25","doi-asserted-by":"crossref","unstructured":"G. Pei, S. Lyu, G. Chen, K. Ma, Q. Xu, Y. Sun, Q. Huang, Divide and Conquer: Heterogeneous Noise Integration for Diffusion-based Adversarial Purification, in: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, CVPR, 2025, pp. 29268\u201329277.","DOI":"10.1109\/CVPR52734.2025.02725"},{"key":"10.1016\/j.patcog.2026.113958_b26","doi-asserted-by":"crossref","unstructured":"M. Park, C. Park, S. Lim, M. Koo, H. Lee, W.W. Ro, S. Kim, Adversarial Purification via Super-Resolution and Diffusion, in: Proceedings of the IEEE\/CVF International Conference on Computer Vision, 2025, pp. 4605\u20134615.","DOI":"10.1109\/ICCV51701.2025.00438"},{"key":"10.1016\/j.patcog.2026.113958_b27","series-title":"Adversarial purification by consistency-aware latent space optimization on data manifolds","author":"Zhang","year":"2024"},{"key":"10.1016\/j.patcog.2026.113958_b28","unstructured":"Y. Song, J. Sohl-Dickstein, D.P. Kingma, A. Kumar, S. Ermon, B. Poole, Score-Based Generative Modeling through Stochastic Differential Equations, in: International Conference on Learning Representations, 2021."},{"key":"10.1016\/j.patcog.2026.113958_b29","doi-asserted-by":"crossref","first-page":"26565","DOI":"10.52202\/068431-1926","article-title":"Elucidating the design space of diffusion-based generative models","volume":"35","author":"Karras","year":"2022","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"10.1016\/j.patcog.2026.113958_b30","series-title":"International Conference on Machine Learning","first-page":"387","article-title":"Deterministic policy gradient algorithms","author":"Silver","year":"2014"},{"issue":"3731","key":"10.1016\/j.patcog.2026.113958_b31","doi-asserted-by":"crossref","first-page":"34","DOI":"10.1126\/science.153.3731.34","article-title":"Dynamic programming","volume":"153","author":"Bellman","year":"1966","journal-title":"Science"},{"key":"10.1016\/j.patcog.2026.113958_b32","doi-asserted-by":"crossref","first-page":"293","DOI":"10.1023\/A:1022628806385","article-title":"Self-improving reactive agents based on reinforcement learning, planning and teaching","volume":"8","author":"Lin","year":"1992","journal-title":"Mach. Learn."},{"key":"10.1016\/j.patcog.2026.113958_b33","doi-asserted-by":"crossref","first-page":"323","DOI":"10.1016\/j.neunet.2012.02.016","article-title":"Man vs. computer: Benchmarking machine learning algorithms for traffic sign recognition","volume":"32","author":"Stallkamp","year":"2012","journal-title":"Neural Netw."},{"key":"10.1016\/j.patcog.2026.113958_b34","doi-asserted-by":"crossref","unstructured":"Z. Liu, H. Mao, C.-Y. Wu, C. Feichtenhofer, T. Darrell, S. Xie, A convnet for the 2020s, in: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, 2022, pp. 11976\u201311986.","DOI":"10.1109\/CVPR52688.2022.01167"},{"key":"10.1016\/j.patcog.2026.113958_b35","unstructured":"C. Shi, C. Holtz, G. Mishne, Online Adversarial Purification based on Self-supervised Learning, in: International Conference on Learning Representations, 2021."},{"key":"10.1016\/j.patcog.2026.113958_b36","article-title":"Implicit generation and modeling with energy based models","volume":"32","author":"Du","year":"2019","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"10.1016\/j.patcog.2026.113958_b37","unstructured":"W. Grathwohl, K.-C. Wang, J.-H. Jacobsen, D. Duvenaud, M. Norouzi, K. Swersky, Your classifier is secretly an energy based model and you should treat it like one, in: International Conference on Learning Representations, 2020."},{"key":"10.1016\/j.patcog.2026.113958_b38","unstructured":"Y. Song, T. Kim, S. Nowozin, S. Ermon, N. Kushman, PixelDefend: Leveraging Generative Models to Understand and Defend against Adversarial Examples, in: International Conference on Learning Representations, 2018."},{"key":"10.1016\/j.patcog.2026.113958_b39","article-title":"Unlabeled data improves adversarial robustness","volume":"32","author":"Carmon","year":"2019","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"10.1016\/j.patcog.2026.113958_b40","series-title":"Uncovering the limits of adversarial training against norm-bounded adversarial examples","author":"Gowal","year":"2020"},{"key":"10.1016\/j.patcog.2026.113958_b41","unstructured":"T. Pang, X. Yang, Y. Dong, H. Su, J. Zhu, Bag Of Tricks For Adversarial Training, in: International Conference on Learning Representations, 2021."},{"key":"10.1016\/j.patcog.2026.113958_b42","series-title":"Proceedings of the 41st International Conference on Machine Learning","first-page":"6643","article-title":"Robust classification via a single diffusion model","author":"Chen","year":"2024"},{"key":"10.1016\/j.patcog.2026.113958_b43","series-title":"On evaluating adversarial robustness","author":"Carlini","year":"2019"}],"container-title":["Pattern Recognition"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0031320326009234?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0031320326009234?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,7,4]],"date-time":"2026-07-04T11:31:54Z","timestamp":1783164714000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0031320326009234"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,11]]},"references-count":43,"alternative-id":["S0031320326009234"],"URL":"https:\/\/doi.org\/10.1016\/j.patcog.2026.113958","relation":{},"ISSN":["0031-3203"],"issn-type":[{"value":"0031-3203","type":"print"}],"subject":[],"published":{"date-parts":[[2026,11]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"Efficient adversarial purification via consistency model and reinforcement learning-based diffusion sequence selection","name":"articletitle","label":"Article Title"},{"value":"Pattern Recognition","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.patcog.2026.113958","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier Ltd. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"113958"}}