{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,9,11]],"date-time":"2025-09-11T22:38:20Z","timestamp":1757630300855,"version":"3.44.0"},"reference-count":52,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0\/"}],"funder":[{"name":"Flemish Government through the Cybersecurity Research Program","award":["VOEWICS02"],"award-info":[{"award-number":["VOEWICS02"]}]},{"name":"Research Council KU Leuven Projects IF\/C1 From Website Fingerprinting to App Fingerprinting: Inferring Private User Activity from Encrypted Network Traffic"},{"name":"AIDE Project funded by Belgian SPF BOSA under the Program \u201cFinancing of Projects for the Development of Artificial Intelligence in Belgium\u201d","award":["06.40.32.33.00.10.\u201d"],"award-info":[{"award-number":["06.40.32.33.00.10.\u201d"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Access"],"published-print":{"date-parts":[[2025]]},"DOI":"10.1109\/access.2025.3604636","type":"journal-article","created":{"date-parts":[[2025,9,1]],"date-time":"2025-09-01T19:31:49Z","timestamp":1756755109000},"page":"154678-154694","source":"Crossref","is-referenced-by-count":0,"title":["Unveiling Illusionary Robust Features: A Novel Approach for Adversarial Defenses in Deep Neural Networks"],"prefix":"10.1109","volume":"13","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-0783-0261","authenticated-orcid":false,"given":"Alireza","family":"Aghabagherloo","sequence":"first","affiliation":[{"name":"Department of Electrical Engineering, COSIC, KU Leuven, Leuven, Belgium"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1565-933X","authenticated-orcid":false,"given":"Rafa","family":"G\u00e1lvez","sequence":"additional","affiliation":[{"name":"Department of Electrical Engineering, COSIC, KU Leuven, Leuven, Belgium"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6279-4430","authenticated-orcid":false,"given":"Davy","family":"Preuveneers","sequence":"additional","affiliation":[{"name":"DistriNet, KU Leuven, Leuven, Belgium"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2005-9651","authenticated-orcid":false,"given":"Bart","family":"Preneel","sequence":"additional","affiliation":[{"name":"Department of Electrical Engineering, COSIC, KU Leuven, Leuven, Belgium"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/spw54247.2022.9833874"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/access.2021.3127960"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/spw54247.2022.9833895"},{"key":"ref4","first-page":"125","article-title":"Adversarial examples are not bugs, they are features","volume-title":"Proc. Adv. Neural Inf. Process. Syst. 32: Annu. Conf. Neural Inf. Process. Syst.","author":"Ilyas"},{"key":"ref5","article-title":"A simple explanation for the existence of adversarial examples with small Hamming distance","author":"Shamir","year":"2019","journal-title":"arXiv:1901.10861"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN54540.2023.10191198"},{"key":"ref7","article-title":"The dimpled manifold model of adversarial examples in machine learning","author":"Shamir","year":"2021","journal-title":"arXiv:2106.10151"},{"key":"ref8","first-page":"9759","article-title":"A little robustness goes a long way: Leveraging robust features for targeted transfer attacks","volume-title":"Proc. Adv. Neural Inf. Process. Syst. 34th Annu. Conf. Neural Inf. Process. Syst.","author":"Springer"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.2172\/1823733"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/SPW67851.2025.00023"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1016\/j.aej.2022.02.007"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/SPW59333.2023.00009"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2025.3567195"},{"key":"ref14","first-page":"17222","article-title":"Adversarial examples are not real features","volume-title":"Proc. 37th Int. Conf. Neural Inf. Process. Syst.","author":"Li"},{"key":"ref15","article-title":"Adversarial ML problems are getting harder to solve and to evaluate","author":"Rando","year":"2025","journal-title":"arXiv:2502.02260"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1145\/3368089.3409739"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-21441-7_26"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00073"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1145\/3593042"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179316"},{"key":"ref21","article-title":"Explaining and harnessing adversarial examples","author":"Goodfellow","year":"2014","journal-title":"arXiv:1412.6572"},{"key":"ref22","article-title":"Adversarial training can provably improve robustness: Theoretical analysis of feature learning process under structured data","author":"Li","year":"2024","journal-title":"arXiv:2410.08503"},{"key":"ref23","article-title":"Adversarial example defenses: Ensembles of weak defenses are not strong","author":"He","year":"2017","journal-title":"arXiv:1706.04701"},{"key":"ref24","article-title":"Adversarial machine learning at scale","author":"Kurakin","year":"2016","journal-title":"arXiv:1611.01236"},{"key":"ref25","first-page":"2206","article-title":"Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Croce"},{"key":"ref26","article-title":"Towards deep learning models resistant to adversarial attacks","author":"Madry","year":"2017","journal-title":"arXiv:1706.06083"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1186\/s40537-016-0043-6"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1145\/3585385"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1016\/j.inffus.2022.09.011"},{"key":"ref30","article-title":"Privacy in pharmacogenetics: An end-to-end case study of personalized warfarin dosing","author":"Fredrikson","year":"2017","journal-title":"arXiv:1705.07204"},{"article-title":"Ensemble adversarial training: Attacks and defenses","volume-title":"Proc. 6th Int. Conf. Learn. Represent.","author":"Tram\u00e8r","key":"ref31"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2021\/635"},{"key":"ref33","article-title":"Understanding and enhancing the transferability of adversarial examples","author":"Wu","year":"2018","journal-title":"arXiv:1802.09707"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1007\/978-981-15-1884-3_34"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.33012253"},{"key":"ref36","article-title":"RobustBench: A standardized adversarial robustness benchmark","author":"Croce","year":"2020","journal-title":"arXiv:2010.09670"},{"volume-title":"Robustbench: A Benchmark for Adversarial Robustness","year":"2022","author":"Contributors","key":"ref37"},{"key":"ref38","first-page":"1831","article-title":"Defense against adversarial attacks using feature scattering-based adversarial training","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Zhang"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3359820"},{"key":"ref40","first-page":"2196","article-title":"Minimally distorted adversarial examples with a fast adaptive boundary attack","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Croce"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58592-1_29"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"article-title":"Learning multiple layers of features from tiny images","year":"2009","author":"Krizhevsky","key":"ref44"},{"key":"ref45","article-title":"CINIC-10 is not ImageNet or CIFAR-10","author":"Darlow","year":"2018","journal-title":"arXiv:1810.03505"},{"key":"ref46","first-page":"8072","article-title":"Adversarially trained neural representations are already as robust as biological neural representations","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Guo"},{"key":"ref47","article-title":"Robustness may be at odds with accuracy","author":"Tsipras","year":"2018","journal-title":"arXiv:1805.12152"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1007\/s11704-024-40065-x"},{"key":"ref49","first-page":"703","article-title":"Priv-PFL: A privacy-preserving and efficient personalized federated learning approach","author":"Aghabagherloo","year":"2025","journal-title":"IACR Cryptol. ePrint Arch."},{"key":"ref50","article-title":"An introduction to domain adaptation and transfer learning","author":"Kouw","year":"2018","journal-title":"arXiv:1812.11806"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP49357.2023.10097192"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"}],"container-title":["IEEE Access"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/6287639\/10820123\/11145438.pdf?arnumber=11145438","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,9,10]],"date-time":"2025-09-10T17:48:12Z","timestamp":1757526492000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11145438\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"references-count":52,"URL":"https:\/\/doi.org\/10.1109\/access.2025.3604636","relation":{},"ISSN":["2169-3536"],"issn-type":[{"type":"electronic","value":"2169-3536"}],"subject":[],"published":{"date-parts":[[2025]]}}}