{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,27]],"date-time":"2026-03-27T03:55:48Z","timestamp":1774583748188,"version":"3.50.1"},"reference-count":44,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2018,1,1]],"date-time":"2018-01-01T00:00:00Z","timestamp":1514764800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/OAPA.html"}],"funder":[{"DOI":"10.13039\/501100003725","name":"National Research Foundation of Korea","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100003725","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Korea Government","award":["2016R1A4A1011761"],"award-info":[{"award-number":["2016R1A4A1011761"]}]},{"name":"Korea Government","award":["2017R1A2B4006026"],"award-info":[{"award-number":["2017R1A2B4006026"]}]},{"DOI":"10.13039\/501100010418","name":"Institute for Information and Communications Technology Promotion","doi-asserted-by":"crossref","id":[{"id":"10.13039\/501100010418","id-type":"DOI","asserted-by":"crossref"}]},{"name":"Korea Government (MSIT)","award":["2016-0-00173"],"award-info":[{"award-number":["2016-0-00173"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Access"],"published-print":{"date-parts":[[2018]]},"DOI":"10.1109\/access.2018.2866197","type":"journal-article","created":{"date-parts":[[2018,8,20]],"date-time":"2018-08-20T22:18:31Z","timestamp":1534803511000},"page":"46084-46096","source":"Crossref","is-referenced-by-count":38,"title":["Multi-Targeted Adversarial Example in Evasion Attack on Deep Neural Network"],"prefix":"10.1109","volume":"6","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-1169-9892","authenticated-orcid":false,"given":"Hyun","family":"Kwon","sequence":"first","affiliation":[]},{"given":"Yongchul","family":"Kim","sequence":"additional","affiliation":[]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3377-223X","authenticated-orcid":false,"given":"Ki-Woong","family":"PARK","sequence":"additional","affiliation":[]},{"given":"Hyunsoo","family":"Yoon","sequence":"additional","affiliation":[]},{"given":"Daeseon","family":"Choi","sequence":"additional","affiliation":[]}],"member":"263","reference":[{"key":"ref39","author":"strauss","year":"2017","journal-title":"Ensemble methods as a defense to adversarial perturbations against deep neural networks"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2007.4317620"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/ETFA.2016.7733515"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.41"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"ref37","author":"simonyan","year":"2014","journal-title":"Very Deep Convolutional Networks for Large-scale Image Recognition"},{"key":"ref36","article-title":"APE-GAN: Adversarial perturbation elimination with GAN","author":"shen","year":"2017","journal-title":"ICLR Submission"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1016\/j.neunet.2014.09.003"},{"key":"ref34","article-title":"Facial attributes: Accuracy and adversarial robustness","author":"rozsa","year":"2017","journal-title":"Pattern Recognit Lett"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1007\/s10994-017-5663-3"},{"key":"ref40","author":"szegedy","year":"2013","journal-title":"Intriguing properties of neural networks"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2017.2740965"},{"key":"ref12","first-page":"2672","article-title":"Generative adversarial nets","author":"goodfellow","year":"2014","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref13","author":"goodfellow","year":"2014","journal-title":"Explaining and Harnessing Adversarial Examples"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2012.2205597"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/TMM.2015.2478068"},{"key":"ref16","author":"kingma","year":"2014","journal-title":"Adam A method for stochastic optimization"},{"key":"ref17","author":"krizhevsky","year":"2014","journal-title":"CIFAR-10 Dataset"},{"key":"ref18","author":"kurakin","year":"2016","journal-title":"Adversarial examples in the physical world"},{"key":"ref19","author":"kurakin","year":"2016","journal-title":"Adversarial machine learning at scale"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/ICRA.2016.7487304"},{"key":"ref4","doi-asserted-by":"crossref","DOI":"10.1093\/oso\/9780198538493.001.0001","author":"bishop","year":"1995","journal-title":"Neural Networks for Pattern Recognition"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW.2017.172"},{"key":"ref3","first-page":"1467","article-title":"Poisoning attacks against support vector machines","author":"biggio","year":"2012","journal-title":"Proc Int Conf Int Conf Mach Learn"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140444"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2017.2718479"},{"key":"ref5","first-page":"513","article-title":"Hidden voice commands","author":"carlini","year":"2016","journal-title":"Proc Usenix Secur Symp"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref7","author":"carlini","year":"2017","journal-title":"MagNet and &#x2018;efficient defenses against adversarial attacks&#x2019; are not robust to adversarial examples"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1007\/s10994-010-5188-5"},{"key":"ref1","first-page":"265","article-title":"TensorFlow: A system for large-scale machine learning","volume":"16","author":"abadi","year":"2016","journal-title":"Proc OSDI"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2018.07.015"},{"key":"ref22","author":"lecun","year":"2010","journal-title":"MNIST Handwritten Digit Database"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"ref42","author":"tram\u00e8r","year":"2017","journal-title":"The space of transferable adversarial examples"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134057"},{"key":"ref41","author":"tram\u00e8r","year":"2017","journal-title":"Ensemble adversarial training Attacks and defenses"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/JBHI.2014.2344095"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134052"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1007\/s00500-017-2998-4"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/TCYB.2015.2415032"}],"container-title":["IEEE Access"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/6287639\/8274985\/08439941.pdf?arnumber=8439941","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,7,9]],"date-time":"2024-07-09T11:50:15Z","timestamp":1720525815000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/8439941\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018]]},"references-count":44,"URL":"https:\/\/doi.org\/10.1109\/access.2018.2866197","relation":{},"ISSN":["2169-3536"],"issn-type":[{"value":"2169-3536","type":"electronic"}],"subject":[],"published":{"date-parts":[[2018]]}}}