{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,5]],"date-time":"2026-06-05T04:52:59Z","timestamp":1780635179879,"version":"3.54.1"},"reference-count":44,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0\/"}],"funder":[{"name":"Deputy for Research and Innovation, Ministry of Education through the Initiative of Institutional Funding at University of Ha\u2019il-Saudi Arabia","award":["IFP-2004"],"award-info":[{"award-number":["IFP-2004"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Access"],"published-print":{"date-parts":[[2021]]},"DOI":"10.1109\/access.2021.3085875","type":"journal-article","created":{"date-parts":[[2021,6,3]],"date-time":"2021-06-03T18:09:50Z","timestamp":1622743790000},"page":"81678-81692","source":"Crossref","is-referenced-by-count":45,"title":["All Your Fake Detector are Belong to Us: Evaluating Adversarial Robustness of Fake-News Detectors Under Black-Box Settings"],"prefix":"10.1109","volume":"9","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-1701-0390","authenticated-orcid":false,"given":"Hassan","family":"Ali","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0081-8684","authenticated-orcid":false,"given":"Muhammad Suleman","family":"Khan","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4350-2759","authenticated-orcid":false,"given":"Amer","family":"Alghadhban","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9074-1029","authenticated-orcid":false,"given":"Meshari","family":"Alazmi","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1542-5939","authenticated-orcid":false,"given":"Ahmad","family":"Alzamil","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3965-5018","authenticated-orcid":false,"given":"Khaled","family":"Al-Utaibi","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9466-2475","authenticated-orcid":false,"given":"Junaid","family":"Qadir","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref39","article-title":"Universal sentence encoder","author":"cer","year":"2018","journal-title":"arXiv 1803 11175"},{"key":"ref38","article-title":"BAE: BERT-based adversarial examples for text classification","author":"garg","year":"2020","journal-title":"arXiv 2004 01970"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1145\/3381750"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/D17-1317"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1145\/1963405.1963500"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-45439-5_38"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP.2016.7472768"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/P17-2067"},{"key":"ref35","year":"2021","journal-title":"Best Submission"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1145\/3393880"},{"key":"ref10","first-page":"119","article-title":"Textattack: A framework for adversarial attacks, data augmentation, and adversarial training in NLP","author":"morris","year":"2020","journal-title":"Proc Conf Empirical Methods Natural Lang Process Syst Demonstrations (EMNLP)"},{"key":"ref40","first-page":"2","article-title":"On regularization and robustness of deep neural networks","author":"bietti","year":"2018"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN48605.2020.9207635"},{"key":"ref12","first-page":"274","article-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","volume":"80","author":"athalye","year":"2018","journal-title":"Proc 35th Int Conf Mach Learn (ICML) (PMLR)"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.5220\/0007566307940800"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01258-8_39"},{"key":"ref15","first-page":"1","article-title":"Information disorder: Toward an interdisciplinary framework for research and policy making","volume":"27","author":"wardle","year":"2017","journal-title":"Council Eur Rep"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/LCNW.2018.8628538"},{"key":"ref17","first-page":"1","article-title":"Physical adversarial examples for object detectors","author":"song","year":"2018","journal-title":"Proc 12th USENIX Workshop Offensive Technol (WOOT)"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/IWCMC.2019.8766353"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/IWCMC.2019.8766505"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1145\/3137597.3137600"},{"key":"ref4","doi-asserted-by":"crossref","first-page":"679","DOI":"10.18653\/v1\/2021.eacl-main.56","article-title":"Fakeflow: Fake news detection by modeling the flow of affective information","author":"ghanem","year":"2021","journal-title":"Proc 16th Conf Eur Chapter Assoc Comput Linguistics Main (EACL)"},{"key":"ref27","first-page":"8018","article-title":"Is BERT really robust? A strong baseline for natural language attack on text classification and entailment","author":"jin","year":"2020","journal-title":"Proc 34th AAAI Conf Artif Intell AAAI 32nd Innov Appl Artif Intell Conf IAAI 10th AAAI Symp Educ Adv Artif Intell (EAAI)"},{"key":"ref3","article-title":"Fake news detection on social media using geometric deep learning","author":"monti","year":"2019","journal-title":"arXiv 1902 06673"},{"key":"ref6","article-title":"HaS-Nets: A heal and select mechanism to defend DNNs against backdoor attacks for data collection scenarios","author":"ali","year":"2020","journal-title":"arXiv 2012 07474"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1140\/epjds\/s13688-020-00224-z"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/IOLTS.2019.8854377"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"ref7","article-title":"Adversarial examples&#x2014;A complete characterisation of the phenomenon","author":"serban","year":"2018","journal-title":"arXiv 1810 01185"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1145\/3219819.3219903"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/MDAT.2019.2961325"},{"key":"ref1","article-title":"Fake news detection: A hybrid CNN-RNN based deep learning approach","volume":"1","author":"nasir","year":"2021","journal-title":"Int J Inf Manage Data Insights"},{"key":"ref20","article-title":"Adversarial machine learning and speech emotion recognition: Utilizing generative adversarial networks for robustness","author":"latif","year":"2018","journal-title":"arXiv 1811 11402"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/MIC.2021.3049190"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/MNET.001.1900197"},{"key":"ref42","article-title":"Improving robustness without sacrificing accuracy with patch Gaussian augmentation","author":"gontijo lopes","year":"2019","journal-title":"arXiv 1906 02611"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23138"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1145\/2939672.2939778"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2020.2975048"},{"key":"ref44","article-title":"On evaluating adversarial robustness","author":"carlini","year":"2019","journal-title":"arXiv 1902 06705"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2018.00016"},{"key":"ref43","article-title":"Strong data augmentation sanitizes poisoning and backdoor attacks without an accuracy tradeoff","author":"borgnia","year":"2020","journal-title":"arXiv 2011 09527"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/P19-1103"}],"container-title":["IEEE Access"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/6287639\/9312710\/09446139.pdf?arnumber=9446139","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,12,29]],"date-time":"2022-12-29T13:36:44Z","timestamp":1672321004000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9446139\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021]]},"references-count":44,"URL":"https:\/\/doi.org\/10.1109\/access.2021.3085875","relation":{"has-preprint":[{"id-type":"doi","id":"10.36227\/techrxiv.14329976.v1","asserted-by":"object"},{"id-type":"doi","id":"10.36227\/techrxiv.14329976.v2","asserted-by":"object"},{"id-type":"doi","id":"10.36227\/techrxiv.14329976.v3","asserted-by":"object"}]},"ISSN":["2169-3536"],"issn-type":[{"value":"2169-3536","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021]]}}}