{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,17]],"date-time":"2026-03-17T18:53:40Z","timestamp":1773773620262,"version":"3.50.1"},"reference-count":32,"publisher":"IEEE","license":[{"start":{"date-parts":[[2019,12,1]],"date-time":"2019-12-01T00:00:00Z","timestamp":1575158400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2019,12,1]],"date-time":"2019-12-01T00:00:00Z","timestamp":1575158400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2019,12,1]],"date-time":"2019-12-01T00:00:00Z","timestamp":1575158400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2019,12]]},"DOI":"10.1109\/bigdata47090.2019.9006090","type":"proceedings-article","created":{"date-parts":[[2020,2,25]],"date-time":"2020-02-25T01:05:34Z","timestamp":1582592734000},"page":"1282-1291","source":"Crossref","is-referenced-by-count":13,"title":["Denoising and Verification Cross-Layer Ensemble Against Black-box Adversarial Attacks"],"prefix":"10.1109","author":[{"given":"Ka-Ho","family":"Chow","sequence":"first","affiliation":[]},{"given":"Wenqi","family":"Wei","sequence":"additional","affiliation":[]},{"given":"Yanzhao","family":"Wu","sequence":"additional","affiliation":[]},{"given":"Ling","family":"Liu","sequence":"additional","affiliation":[]}],"member":"263","reference":[{"key":"ref32","author":"holloway","year":"2007","journal-title":"Introduction to ensemble learning"},{"key":"ref31","article-title":"Countering adversarial images using input transformations","author":"guo","year":"2018","journal-title":"ICLRE"},{"key":"ref30","article-title":"Intriguing properties of neural networks","author":"szegedy","year":"2014","journal-title":"ICLRE"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/TNN.2009.2015974"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/CISS.2019.8692918"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00191"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.243"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1145\/1390156.1390294"},{"key":"ref18","article-title":"Image denoising and inpainting with deep neural networks","author":"xie","year":"2012","journal-title":"NIPS"},{"key":"ref19","article-title":"Adaptive multi-column deep neural networks with application to robust image denoising","author":"agostinelli","year":"2013","journal-title":"NIPS"},{"key":"ref28","article-title":"Transferability in machine learning: from phenomena to black-box attacks using adversarial samples","author":"papernot","year":"2016","journal-title":"arXiv preprint arXiv 1605 09090"},{"key":"ref4","article-title":"Ensemble adversarial training: Attacks and defenses","author":"tram\u00e9r","year":"2018","journal-title":"ICLRE"},{"key":"ref27","article-title":"What regularized auto-encoders learn from the data-generating distribution","volume":"15","author":"alain","year":"2014","journal-title":"JMLR"},{"key":"ref3","article-title":"Adversarial examples in the physical world","author":"kurakin","year":"2016","journal-title":"Arxiv preprint arXiv"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23198"},{"key":"ref29","article-title":"Imagenet classification with deep convolutional neural networks","author":"krizhevsky","year":"2012","journal-title":"NIPS"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134057"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.41"},{"key":"ref7","article-title":"Defense-gan: Protecting classifiers against adversarial attacks using generative models","author":"samangouei","year":"2018","journal-title":"ICLRE"},{"key":"ref2","article-title":"Towards deep learning models resistant to adversarial attacks","author":"madry","year":"2018","journal-title":"ICLRE"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"ref1","article-title":"Explaining and harnessing adversarial examples","author":"goodfellow","year":"2015","journal-title":"ICLRE"},{"key":"ref20","first-page":"3371","article-title":"Stacked denoising autoencoders: Learning useful representations in a deep network with a local denoising criterion","volume":"11","author":"vincent","year":"2010","journal-title":"JMLR"},{"key":"ref22","article-title":"Snapshot ensembles: Train 1, get m for free","author":"huang","year":"2017","journal-title":"ICLRE"},{"key":"ref21","article-title":"Adversarial examples in deep learning: Characterization and divergence","author":"wei","year":"2018","journal-title":"arXiv preprint arXiv 1807 00051"},{"key":"ref24","article-title":"Perceptual losses for real-time style transfer and super-resolution","author":"johnson","year":"2016","journal-title":"ECCV"},{"key":"ref23","article-title":"A comparative measurement study of deep learning as a service framework","author":"wu","year":"2018","journal-title":"arXiv preprint arXiv 1810 10053"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.11613\/BM.2012.031"},{"key":"ref25","article-title":"Simple sparsification improves sparse denoising autoencoders in denoising highly corrupted images","author":"cho","year":"2013","journal-title":"ICML"}],"event":{"name":"2019 IEEE International Conference on Big Data (Big Data)","location":"Los Angeles, CA, USA","start":{"date-parts":[[2019,12,9]]},"end":{"date-parts":[[2019,12,12]]}},"container-title":["2019 IEEE International Conference on Big Data (Big Data)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/8986695\/9005444\/09006090.pdf?arnumber=9006090","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,7,17]],"date-time":"2022-07-17T17:54:33Z","timestamp":1658080473000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9006090\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,12]]},"references-count":32,"URL":"https:\/\/doi.org\/10.1109\/bigdata47090.2019.9006090","relation":{},"subject":[],"published":{"date-parts":[[2019,12]]}}}