{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,7,24]],"date-time":"2025-07-24T10:53:10Z","timestamp":1753354390137,"version":"3.37.3"},"reference-count":38,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"},{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"am","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"funder":[{"DOI":"10.13039\/100000181","name":"U.S. Air Force Office of Scientific Research","doi-asserted-by":"publisher","award":["FA9550-21-1-0229"],"award-info":[{"award-number":["FA9550-21-1-0229"]}],"id":[{"id":"10.13039\/100000181","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Access"],"published-print":{"date-parts":[[2022]]},"DOI":"10.1109\/access.2022.3146198","type":"journal-article","created":{"date-parts":[[2022,1,24]],"date-time":"2022-01-24T20:49:31Z","timestamp":1643057371000},"page":"12395-12411","source":"Crossref","is-referenced-by-count":5,"title":["Mitigating Black-Box Adversarial Attacks via Output Noise Perturbation"],"prefix":"10.1109","volume":"10","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-8953-5906","authenticated-orcid":false,"given":"Manjushree B.","family":"Aithal","sequence":"first","affiliation":[]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1209-7837","authenticated-orcid":false,"given":"Xiaohua","family":"Li","sequence":"additional","affiliation":[]}],"member":"263","reference":[{"key":"ref1","first-page":"1","article-title":"Intriguing properties of neural networks","volume-title":"Proc. 2nd Int. Conf. Learn. Represent.","author":"Szegedy"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"ref3","first-page":"20","article-title":"Explaining and harnessing adversarial examples","volume":"1050","author":"Goodfellow","year":"2015","journal-title":"Stat"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.06083"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140448"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.3301742"},{"key":"ref8","first-page":"2137","article-title":"Black-box adversarial attacks with limited queries and information","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Ilyas"},{"key":"ref9","first-page":"1","article-title":"Query-efficient hard-label black-box attack: An optimization-based approach","volume-title":"Proc. Int. Conf. Learn. Represent. (ICLR)","author":"Cheng"},{"key":"ref10","first-page":"1","article-title":"Sign-opt: A query-efficient hard-label adversarial attack","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Cheng"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1145\/3321707.3321749"},{"key":"ref12","first-page":"2484","article-title":"Simple black-box adversarial attacks","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Guo"},{"key":"ref13","first-page":"1","article-title":"Decision-based adversarial attacks: Reliable attacks against black-box machine learning models","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Brendel"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00040"},{"key":"ref15","first-page":"1","article-title":"Countering adversarial images using input transformations","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Guo"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.41"},{"key":"ref17","first-page":"274","article-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Athalye"},{"key":"ref18","article-title":"Simple black-box adversarial perturbations for deep networks","author":"Narodytska","year":"2016","journal-title":"arXiv:1612.06299"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2018.00015"},{"key":"ref20","first-page":"10934","article-title":"Improving black-box adversarial attacks with a transfer-based prior","volume-title":"Advances in Neural Information Processing Systems","author":"Cheng"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.56"},{"key":"ref22","first-page":"1","article-title":"Mitigating adversarial effects through randomization","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Xie"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2019\/833"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140444"},{"key":"ref25","article-title":"On the robustness of the CVPR 2018 white-box adversarial example defenses","author":"Athalye","year":"2018","journal-title":"arXiv:1804.03286"},{"key":"ref26","first-page":"1","article-title":"Ensemble adversarial training: Attacks and defenses","volume-title":"Proc. 6th Int. Conf. Learn. Represent.","author":"Tram\u00e8r"},{"key":"ref27","first-page":"1","article-title":"Defense-GAN: Protecting classifiers against adversarial attacks using generative models","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Samangouei"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00068"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01234-2_23"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1007\/s11042-019-7353-6"},{"key":"ref31","article-title":"Certified adversarial robustness with additive noise","volume-title":"Advances in Neural Information Processing Systems","author":"Li","year":"2019"},{"key":"ref32","article-title":"Defending against machine learning model stealing attacks using deceptive perturbations","author":"Lee","year":"2018","journal-title":"arXiv:1806.00054"},{"key":"ref33","first-page":"3866","article-title":"NATTACK: Learning the distributions of adversarial examples for an improved black-box attack on deep neural networks","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Li"},{"key":"ref34","article-title":"On adaptive attacks to adversarial example defenses","volume":"33","author":"Tramer","year":"2020","journal-title":"Advances in Neural Information Processing Systems"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00045"},{"key":"ref36","first-page":"1","article-title":"Delving into transferable adversarial examples and black-box attacks","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Liu"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1007\/s00362-012-0429-2"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/LSP.2016.2614539"}],"container-title":["IEEE Access"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/6287639\/9668973\/09691363.pdf?arnumber=9691363","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,1,13]],"date-time":"2024-01-13T22:25:18Z","timestamp":1705184718000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9691363\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022]]},"references-count":38,"URL":"https:\/\/doi.org\/10.1109\/access.2022.3146198","relation":{},"ISSN":["2169-3536"],"issn-type":[{"type":"electronic","value":"2169-3536"}],"subject":[],"published":{"date-parts":[[2022]]}}}