{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,16]],"date-time":"2025-10-16T10:07:24Z","timestamp":1760609244139,"version":"3.37.3"},"reference-count":40,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2020,1,1]],"date-time":"2020-01-01T00:00:00Z","timestamp":1577836800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61702539","U1811462"],"award-info":[{"award-number":["61702539","U1811462"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100004735","name":"Natural Science Foundation of Hunan Province","doi-asserted-by":"publisher","award":["2018JJ3611"],"award-info":[{"award-number":["2018JJ3611"]}],"id":[{"id":"10.13039\/501100004735","id-type":"DOI","asserted-by":"publisher"}]},{"name":"NUDT Research Project","award":["ZK-18-03-47"],"award-info":[{"award-number":["ZK-18-03-47"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Access"],"published-print":{"date-parts":[[2020]]},"DOI":"10.1109\/access.2020.2969276","type":"journal-article","created":{"date-parts":[[2020,1,24]],"date-time":"2020-01-24T22:03:18Z","timestamp":1579903398000},"page":"21602-21612","source":"Crossref","is-referenced-by-count":2,"title":["Model Capacity Vulnerability in Hyper-Parameters Estimation"],"prefix":"10.1109","volume":"8","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-2906-3238","authenticated-orcid":false,"given":"Wentao","family":"Zhao","sequence":"first","affiliation":[]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1883-2230","authenticated-orcid":false,"given":"Xiao","family":"Liu","sequence":"additional","affiliation":[]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2922-3518","authenticated-orcid":false,"given":"Qiang","family":"Liu","sequence":"additional","affiliation":[]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8318-6757","authenticated-orcid":false,"given":"Jiuren","family":"Chen","sequence":"additional","affiliation":[]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7025-6878","authenticated-orcid":false,"given":"Pan","family":"Li","sequence":"additional","affiliation":[]}],"member":"263","reference":[{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1016\/S0008-8846(98)00165-3"},{"journal-title":"UCI Machine Learning Repository","year":"2007","author":"asuncion","key":"ref38"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/TCYB.2015.2415032"},{"key":"ref32","first-page":"387","article-title":"Evasion attacks against machine learning at test time","author":"biggio","year":"2013","journal-title":"Proc Eur Conf Mach Learn Knowl Discovery Databases"},{"key":"ref31","first-page":"1","article-title":"Using machine teaching to identify optimal training-set attacks on machine learners","author":"mei","year":"2015","journal-title":"Proc 29th AAAI Conf Artif Intell"},{"key":"ref30","article-title":"Curie: A method for protecting SVM classifier from poisoning attack","author":"laishram","year":"2016","journal-title":"arXiv 1606 01584"},{"journal-title":"UCI Machine Learning Repository","year":"2017","author":"dua","key":"ref37"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1145\/1143844.1143889"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1007\/978-0-387-88735-7_2"},{"key":"ref34","first-page":"3517","article-title":"Certified defenses for data poisoning attacks","author":"steinhardt","year":"2017","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref10","first-page":"5809","article-title":"First-order adversarial vulnerability of neural networks and input dimension","author":"simon-gabriel","year":"2019","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1016\/j.asoc.2018.01.029"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/TCYB.2018.2859342"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2018.01.053"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1007\/s11063-018-9892-7"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978392"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/ICB.2013.6613006"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2854599"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1016\/j.ress.2012.12.021"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00057"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1145\/358669.358692"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2905915"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2805680"},{"journal-title":"Deep Learning","year":"2016","author":"goodfellow","key":"ref27"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2847037"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-94268-1_22"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/JBHI.2014.2344095"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/ICC.2018.8422328"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2866197"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-94268-1_8"},{"article-title":"Semi-supervised learning literature survey","year":"2005","author":"zhu","key":"ref2"},{"key":"ref9","article-title":"Adversarial examples in the physical world","author":"kurakin","year":"2016","journal-title":"arXiv 1607 02533"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.3934\/mbe.2020055"},{"key":"ref20","first-page":"541","article-title":"Reversible natural language watermarking using synonym substitution and arithmetic coding","volume":"55","author":"xiang","year":"2018","journal-title":"Comput Mater Continua"},{"key":"ref22","first-page":"1885","article-title":"Data poisoning attacks on factorization-based collaborative filtering","author":"li","year":"2016","journal-title":"Proc Adv Neural Inf Process Syst 29 (NIPS)"},{"article-title":"Theil-sen estimators in a multiple linear regression model","year":"2008","author":"dang","key":"ref21"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.2307\/1913643"},{"key":"ref23","first-page":"1452","article-title":"Data poisoning attacks against autoregressive models","author":"alfeld","year":"2016","journal-title":"Proc AAAI Conf Artif Intell"},{"key":"ref26","first-page":"1489","article-title":"Convex learning with invariances","author":"teo","year":"2008","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref25","article-title":"Generating adversarial malware examples for black-box attacks based on GAN","author":"hu","year":"2017","journal-title":"arXiv 1702 05983"}],"container-title":["IEEE Access"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/6287639\/8948470\/08968431.pdf?arnumber=8968431","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,1,12]],"date-time":"2022-01-12T15:56:09Z","timestamp":1642002969000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/8968431\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020]]},"references-count":40,"URL":"https:\/\/doi.org\/10.1109\/access.2020.2969276","relation":{},"ISSN":["2169-3536"],"issn-type":[{"type":"electronic","value":"2169-3536"}],"subject":[],"published":{"date-parts":[[2020]]}}}