{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,2]],"date-time":"2025-10-02T05:59:50Z","timestamp":1759384790897,"version":"3.37.3"},"reference-count":40,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2020,1,1]],"date-time":"2020-01-01T00:00:00Z","timestamp":1577836800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61602413"],"award-info":[{"award-number":["61602413"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"EU H2020 project-AniAge","award":["691215"],"award-info":[{"award-number":["691215"]}]},{"DOI":"10.13039\/501100004731","name":"Natural Science Foundation of Zhejiang Province","doi-asserted-by":"publisher","award":["LY19F030016"],"award-info":[{"award-number":["LY19F030016"]}],"id":[{"id":"10.13039\/501100004731","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Access"],"published-print":{"date-parts":[[2020]]},"DOI":"10.1109\/access.2020.2993304","type":"journal-article","created":{"date-parts":[[2020,5,8]],"date-time":"2020-05-08T19:59:15Z","timestamp":1588967955000},"page":"88594-88603","source":"Crossref","is-referenced-by-count":6,"title":["Towards Adversarial Robustness via Feature Matching"],"prefix":"10.1109","volume":"8","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-0734-1556","authenticated-orcid":false,"given":"Zhuorong","family":"Li","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Chao","family":"Feng","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6017-0552","authenticated-orcid":false,"given":"Jianwei","family":"Zheng","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8179-7119","authenticated-orcid":false,"given":"Minghui","family":"Wu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hongchuan","family":"Yu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref39","article-title":"Theoretically principled trade-off between robustness and accuracy","author":"zhang","year":"2019","journal-title":"arXiv 1901 08573"},{"key":"ref38","first-page":"125","article-title":"Adversarial examples are not bugs, they are features","author":"ilyas","year":"2019","journal-title":"Proc Adv Neural Inf Process Syst"},{"article-title":"Learning multiple layers of features from tiny images","year":"2009","author":"krizhevsky","key":"ref33"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.244"},{"key":"ref31","first-page":"694","article-title":"Perceptual losses for real-time style transfer and super-resolution","author":"johnson","year":"2016","journal-title":"Proc Eur Conf Comput Vis"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-016-0911-8"},{"key":"ref37","article-title":"Robustness may be at odds with accuracy","author":"tsipras","year":"2018","journal-title":"arXiv 1805 12152"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref35","first-page":"13824","article-title":"Adversarial robustness through local linearization","author":"qin","year":"2019","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref34","first-page":"478","article-title":"Metric learning for adversarial robustness","author":"mao","year":"2019","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref10","article-title":"Explaining and harnessing adversarial examples","author":"goodfellow","year":"2014","journal-title":"arXiv 1412 6572"},{"key":"ref40","article-title":"Adversarial risk and the dangers of evaluating against weak attacks","author":"uesato","year":"2018","journal-title":"arXiv 1802 05666"},{"key":"ref11","article-title":"Ensemble adversarial training: Attacks and defenses","author":"tram\u00e8r","year":"2017","journal-title":"arXiv 1705 07204"},{"key":"ref12","first-page":"419","article-title":"Deep defense: Training dnns with improved adversarial robustness","author":"yan","year":"2018","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref13","first-page":"854","article-title":"Parseval networks: Improving robustness to adversarial examples","volume":"70","author":"cisse","year":"2017","journal-title":"Proc 34th Int Conf Mach Learn"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2807385"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.319"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.74"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1016\/j.cviu.2017.10.001"},{"key":"ref18","article-title":"Towards deep learning models resistant to adversarial attacks","author":"madry","year":"2017","journal-title":"arXiv 1706 06083"},{"key":"ref19","article-title":"Adversarial machine learning at scale","author":"kurakin","year":"2016","journal-title":"arXiv 1611 01236"},{"key":"ref28","article-title":"Are labels required for improving adversarial robustness?","author":"uesato","year":"2019","journal-title":"arXiv 1905 13725"},{"key":"ref4","first-page":"2672","article-title":"Generative adversarial nets","author":"goodfellow","year":"2014","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref27","article-title":"Improving adversarial robustness via promoting ensemble diversity","author":"pang","year":"2019","journal-title":"arXiv 1901 08846"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1145\/3132747.3132785"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1145\/3180155.3180220"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2013.50"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.3301766"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/GLOCOM.2018.8647602"},{"key":"ref7","first-page":"1599","article-title":"Formal security analysis of neural networks using symbolic intervals","author":"wang","year":"2018","journal-title":"Proc 27th Secur Symp (USENIX Security)"},{"key":"ref2","first-page":"387","article-title":"Evasion attacks against machine learning at test time","author":"biggio","year":"2013","journal-title":"Proc Eur Conf Mach Learn Knowl Discovery Databases"},{"key":"ref9","article-title":"Intriguing properties of neural networks","author":"szegedy","year":"2013","journal-title":"arXiv 1312 6199"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/TEVC.2019.2890858"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134057"},{"key":"ref22","first-page":"1829","article-title":"Defense against adversarial attacks using feature scattering-based adversarial training","author":"zhang","year":"2019","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref21","first-page":"5014","article-title":"Adversarially robust generalization requires more data","author":"schmidt","year":"2018","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref24","article-title":"Evaluating and understanding the robustness of adversarial logit pairing","author":"engstrom","year":"2018","journal-title":"arXiv 1807 10272"},{"key":"ref23","article-title":"Adversarial logit pairing","author":"kannan","year":"2018","journal-title":"arXiv 1803 06373"},{"key":"ref26","article-title":"Distilling the knowledge in a neural network","author":"hinton","year":"2015","journal-title":"ArXiv 1503 02531"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00059"}],"container-title":["IEEE Access"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/6287639\/8948470\/09089860.pdf?arnumber=9089860","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,12,17]],"date-time":"2021-12-17T19:51:56Z","timestamp":1639770716000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9089860\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020]]},"references-count":40,"URL":"https:\/\/doi.org\/10.1109\/access.2020.2993304","relation":{},"ISSN":["2169-3536"],"issn-type":[{"type":"electronic","value":"2169-3536"}],"subject":[],"published":{"date-parts":[[2020]]}}}