{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,4,26]],"date-time":"2025-04-26T05:07:31Z","timestamp":1745644051018,"version":"3.40.1"},"reference-count":57,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"funder":[{"name":"JSPS KAKENHI","award":["JP22K12196"],"award-info":[{"award-number":["JP22K12196"]}]},{"name":"JST A-STEP","award":["JPMJTM20T0"],"award-info":[{"award-number":["JPMJTM20T0"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Access"],"published-print":{"date-parts":[[2025]]},"DOI":"10.1109\/access.2025.3550024","type":"journal-article","created":{"date-parts":[[2025,3,10]],"date-time":"2025-03-10T17:43:22Z","timestamp":1741628602000},"page":"45500-45517","source":"Crossref","is-referenced-by-count":1,"title":["Rectifying Adversarial Examples Using Their Vulnerabilities"],"prefix":"10.1109","volume":"13","author":[{"given":"Fumiya","family":"Morimoto","sequence":"first","affiliation":[{"name":"Department of Information Science and Biomedical Engineering, Graduate School of Science and Engineering, Kagoshima University, Kagoshima, Japan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ryuto","family":"Morita","sequence":"additional","affiliation":[{"name":"Department of Information Science and Biomedical Engineering, Graduate School of Science and Engineering, Kagoshima University, Kagoshima, Japan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9500-3068","authenticated-orcid":false,"given":"Satoshi","family":"Ono","sequence":"additional","affiliation":[{"name":"Department of Information Science and Biomedical Engineering, Graduate School of Science and Engineering, Kagoshima University, Kagoshima, Japan"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","article-title":"Intriguing properties of neural networks","author":"Szegedy","year":"2013","journal-title":"arXiv:1312.6199"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01580"},{"key":"ref3","first-page":"1","article-title":"Counteracting adversarial attacks in autonomous driving","volume-title":"Proc. IEEE\/ACM Int. Conf. Comput. Aided Design (ICCAD)","author":"Sun"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/ICCVW54120.2021.00016"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2024.241053"},{"issue":"1","key":"ref6","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3425780","article-title":"The creation and detection of deepfakes: A survey","volume":"54","author":"Mirsky","year":"2021","journal-title":"ACM Comput. Surv."},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1145\/3485447.3512212"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1145\/3491199"},{"key":"ref9","article-title":"Mitigating adversarial effects through randomization","author":"Xie","year":"2017","journal-title":"arXiv:1711.01991"},{"key":"ref10","article-title":"A study of the effect of JPG compression on adversarial images","author":"Dziugaite","year":"2016","journal-title":"arXiv:1608.00853"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1145\/3460319.3464822"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.23919\/EUSIPCO55093.2022.9909699"},{"key":"ref13","first-page":"2056","article-title":"Detecting textual adversarial examples through randomized substitution and vote","volume-title":"Proc. Uncertainty Artif. Intell.","author":"Wang"},{"key":"ref14","article-title":"The best defense is attack: Repairing semantics in textual adversarial examples","author":"Yang","year":"2023","journal-title":"arXiv:2305.04067"},{"key":"ref15","article-title":"Explaining and harnessing adversarial examples","author":"Goodfellow","year":"2014","journal-title":"arXiv:1412.6572"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1201\/9781351251389-8"},{"key":"ref17","article-title":"Towards deep learning models resistant to adversarial attacks","author":"Madry","year":"2017","journal-title":"arXiv:1706.06083"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"ref21","article-title":"Simple black-box adversarial perturbations for deep networks","author":"Narodytska","year":"2016","journal-title":"arXiv:1612.06299"},{"key":"ref22","article-title":"Decision-based adversarial attacks: Reliable attacks against black-box machine learning models","author":"Brendel","year":"2017","journal-title":"arXiv:1712.04248"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00045"},{"key":"ref24","first-page":"1","article-title":"Adversarial training for free!","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"32","author":"Shafahi"},{"key":"ref25","first-page":"7472","article-title":"Theoretically principled trade-off between robustness and accuracy","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Zhang"},{"key":"ref26","article-title":"ATHENA: A framework based on diverse weak defenses for building adversarial defense","author":"Meng","year":"2020","journal-title":"arXiv:2001.00308"},{"key":"ref27","article-title":"Countering adversarial images using input transformations","author":"Guo","year":"2017","journal-title":"arXiv:1711.00117"},{"key":"ref28","first-page":"1","article-title":"Thermometer encoding: One hot way to resist adversarial examples","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Buckman"},{"key":"ref29","article-title":"Detecting adversarial samples from artifacts","author":"Feinman","year":"2017","journal-title":"arXiv:1703.00410"},{"key":"ref30","article-title":"Characterizing adversarial subspaces using local intrinsic dimensionality","author":"Ma","year":"2018","journal-title":"arXiv:1801.02613"},{"key":"ref31","first-page":"727","article-title":"DISSECTOR: Input validation for deep learning applications by crossing-layer dissection","volume-title":"Proc. IEEE\/ACM 42nd Int. Conf. Softw. Eng. (ICSE)","author":"Wang"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2019.00126"},{"key":"ref33","article-title":"Detection of iterative adversarial attacks via counter attack","author":"Rottmann","year":"2020","journal-title":"arXiv:2009.11397"},{"key":"ref34","first-page":"1","article-title":"AttackDist: Characterizing zero-day adversarial samples by counter attack","volume-title":"Proc. ICLR","author":"Si-Min"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1016\/j.neunet.2012.02.023"},{"key":"ref36","first-page":"15270","article-title":"Unadversarial examples: Designing objects for robust vision","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"34","author":"Salman"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP49357.2023.10097245"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1016\/j.comcom.2023.09.017"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00070"},{"key":"ref40","article-title":"Frequency-guided word substitutions for detecting textual adversarial examples","author":"Mozes","year":"2020","journal-title":"arXiv:2004.05887"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2021.3058278"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2022.acl-long.538"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2022.emnlp-main.440"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2020.07.101"},{"key":"ref45","first-page":"7303","article-title":"FraudWhistler: A resilient, robust and plug-and-play adversarial example detection method for speaker recognition","volume-title":"Proc. 33rd USENIX Secur. Symp. (USENIX Secur.)","author":"Wang"},{"key":"ref46","article-title":"On evaluating adversarial robustness","author":"Carlini","year":"2019","journal-title":"arXiv:1902.06705"},{"key":"ref47","article-title":"Foolbox: A Python toolbox to benchmark the robustness of machine learning models","author":"Rauber","year":"2017","journal-title":"arXiv:1707.04131"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2012.2211477"},{"volume-title":"Learning multiple layers of features from tiny images","year":"2009","author":"Krizhevsky","key":"ref49"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-015-0816-y"},{"key":"ref51","article-title":"Very deep convolutional networks for large-scale image recognition","author":"Simonyan","year":"2014","journal-title":"arXiv:1409.1556"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2022.24200"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134057"},{"issue":"86","key":"ref54","first-page":"2579","article-title":"Visualizing data using t-SNE","volume":"9","author":"van der Maaten","year":"2008","journal-title":"J. Mach. Learn. Res."},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.21437\/Interspeech.2021-383"},{"key":"ref57","article-title":"Speech commands: A dataset for limited-vocabulary speech recognition","author":"Warden","year":"2018","journal-title":"arXiv:1804.03209"}],"container-title":["IEEE Access"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/6287639\/10820123\/10918972.pdf?arnumber=10918972","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,3,19]],"date-time":"2025-03-19T05:12:35Z","timestamp":1742361155000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10918972\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"references-count":57,"URL":"https:\/\/doi.org\/10.1109\/access.2025.3550024","relation":{},"ISSN":["2169-3536"],"issn-type":[{"type":"electronic","value":"2169-3536"}],"subject":[],"published":{"date-parts":[[2025]]}}}