{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,19]],"date-time":"2026-05-19T07:20:46Z","timestamp":1779175246234,"version":"3.51.4"},"reference-count":257,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"2","license":[{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Commun. Surv. Tutorials"],"published-print":{"date-parts":[[2024]]},"DOI":"10.1109\/comst.2023.3344808","type":"journal-article","created":{"date-parts":[[2023,12,20]],"date-time":"2023-12-20T20:00:48Z","timestamp":1703102448000},"page":"930-966","source":"Crossref","is-referenced-by-count":40,"title":["Evasion Attack and Defense on Machine Learning Models in Cyber-Physical Systems: A Survey"],"prefix":"10.1109","volume":"26","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-6148-6118","authenticated-orcid":false,"given":"Shunyao","family":"Wang","sequence":"first","affiliation":[{"name":"School of Electrical Engineering and Computer Science, The University of Queensland, Brisbane, QLD, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0804-1176","authenticated-orcid":false,"given":"Ryan K. L.","family":"Ko","sequence":"additional","affiliation":[{"name":"School of Electrical Engineering and Computer Science, The University of Queensland, Brisbane, QLD, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6390-9890","authenticated-orcid":false,"given":"Guangdong","family":"Bai","sequence":"additional","affiliation":[{"name":"School of Electrical Engineering and Computer Science, The University of Queensland, Brisbane, QLD, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8248-3362","authenticated-orcid":false,"given":"Naipeng","family":"Dong","sequence":"additional","affiliation":[{"name":"School of Electrical Engineering and Computer Science, The University of Queensland, Brisbane, QLD, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Taejun","family":"Choi","sequence":"additional","affiliation":[{"name":"School of Electrical Engineering and Computer Science, The University of Queensland, Brisbane, QLD, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5611-3483","authenticated-orcid":false,"given":"Yanjun","family":"Zhang","sequence":"additional","affiliation":[{"name":"School of Computer Science, University of Technology Sydney, Sydney, NSW, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/ICASERT.2019.8934446"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1016\/j.future.2015.08.004"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1145\/3365225"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1002\/9781119226444.ch21"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/JSYST.2015.2460747"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/RTUCON.2016.7763155"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/JBHI.2020.2990529"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/ISMICT.2019.8743670"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2020.3021141"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/SECON.2015.7132923"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-28183-4_1"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/JAS.2015.7152667"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1145\/3056540.3064966"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-93112-8_33"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1016\/j.proeng.2015.06.086"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1145\/3450267.3450543"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1007\/s40684-019-00084-7"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.3390\/app10248903"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.3390\/en12234448"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2021.3058403"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/ICDS50568.2020.9268734"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1016\/j.promfg.2020.01.330"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1007\/978-981-15-3639-7_97"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/ICOSEC49089.2020.9215282"},{"issue":"1","key":"ref25","first-page":"30","article-title":"Investigation on composition mechanisms for cyber physical systems","volume":"2","author":"Wan","year":"2010","journal-title":"Int. J. Design, Anal. Tools Integr. Circuits Syst."},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/ICECUBE.2018.8610996"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1142\/S2424862217500142"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2014.2311693"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1145\/3453155"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1016\/j.compeleceng.2022.107810"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2019.10.069"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2923640"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1016\/j.jpdc.2017.06.007"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1016\/j.apenergy.2020.114915"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1016\/j.apenergy.2020.114683"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1016\/j.jclepro.2020.125159"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2021.3094063"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1016\/S1470-2045(19)30149-4"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.3001149"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/tcbb.2022.3196151"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2019.2944748"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1038\/s42256-020-0186-1"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.3390\/fi13040094"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2020.2991401"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/TITS.2020.3006227"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/ICETCE48199.2020.9091758"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/TITS.2019.2963722"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/ICMLA.2018.00035"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1145\/3152494.3156815"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2022.3148298"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1109\/ICDM.2019.00070"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2020.3025588"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1145\/3469659"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1109\/AIIoT52608.2021.9454214"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1145\/3547330"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2018.07.023"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1109\/MCOM.001.2000196"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00057"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1109\/TR.2022.3159784"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2018.2886017"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1145\/3374217"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2020.2975654"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2020.3036778"},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.1145\/3453158"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.3390\/jcp2010010"},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.1016\/j.jisa.2022.103341"},{"key":"ref67","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2022.3233793"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.1016\/j.ijsu.2021.105906"},{"key":"ref69","doi-asserted-by":"publisher","DOI":"10.1109\/SAHCN.2019.8824956"},{"key":"ref70","doi-asserted-by":"publisher","DOI":"10.1002\/9781119723950.ch14"},{"key":"ref71","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2022.3205184"},{"key":"ref72","doi-asserted-by":"publisher","DOI":"10.1109\/INFCOM.2011.5935190"},{"key":"ref73","doi-asserted-by":"publisher","DOI":"10.1109\/ICoICT.2014.6914042"},{"key":"ref74","doi-asserted-by":"publisher","DOI":"10.1145\/997150.997156"},{"key":"ref75","doi-asserted-by":"publisher","DOI":"10.1145\/2046684.2046692"},{"key":"ref76","doi-asserted-by":"publisher","DOI":"10.1109\/SURV.2011.092311.00082"},{"key":"ref77","first-page":"744","article-title":"Survey on malware evasion techniques: State of the art and challenges","volume-title":"Proc. 14th Int. Conf. Adv. Commun. Technol. (ICACT)","author":"Marpaung"},{"key":"ref78","doi-asserted-by":"publisher","DOI":"10.1109\/ICICM.2013.52"},{"key":"ref79","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2016.30"},{"key":"ref80","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2007.9"},{"key":"ref81","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.2974752"},{"key":"ref82","first-page":"1","article-title":"Intriguing properties of neural networks","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Szegedy"},{"key":"ref83","doi-asserted-by":"publisher","DOI":"10.1145\/1014052.1014066"},{"key":"ref84","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2013.57"},{"key":"ref85","article-title":"Poisoning attacks with generative adversarial nets","author":"Mu\u00f1oz-Gonz\u00e1lez","year":"2019","journal-title":"arXiv:1906.07773"},{"key":"ref86","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2020.3013710"},{"key":"ref87","doi-asserted-by":"publisher","DOI":"10.1117\/12.2589538"},{"key":"ref88","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3339815"},{"key":"ref89","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2018.00009"},{"key":"ref90","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2019.2925452"},{"key":"ref91","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2018.04.092"},{"key":"ref92","doi-asserted-by":"publisher","DOI":"10.1145\/3400286.3418252"},{"key":"ref93","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00095"},{"key":"ref94","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2021.3113342"},{"key":"ref95","first-page":"1","article-title":"Countering adversarial images using input transformations","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Guo"},{"key":"ref96","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2021.3105238"},{"key":"ref97","first-page":"1","article-title":"Defensive quantization: When efficiency meets robustness","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Lin"},{"key":"ref98","doi-asserted-by":"publisher","DOI":"10.1109\/IOLTS.2019.8854377"},{"key":"ref99","article-title":"Ensemble methods as a defense to adversarial perturbations against deep neural networks","author":"Strauss","year":"2017","journal-title":"arXiv:1709.03423"},{"key":"ref100","first-page":"4970","article-title":"Improving adversarial robustness via promoting ensemble diversity","volume-title":"Proc. 36th Int. Conf. Mach. Learn.","volume":"97","author":"Pang"},{"key":"ref101","first-page":"1310","article-title":"Certified adversarial robustness via Randomized smoothing","volume-title":"Proc. 36th Int. Conf. Mach. Learn.","volume":"97","author":"Cohen"},{"key":"ref102","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP43922.2022.9746293"},{"key":"ref103","doi-asserted-by":"publisher","DOI":"10.1109\/ICMLA.2019.00212"},{"key":"ref104","doi-asserted-by":"publisher","DOI":"10.1109\/HASE.2017.36"},{"key":"ref105","doi-asserted-by":"publisher","DOI":"10.1145\/3264888.3264896"},{"key":"ref106","doi-asserted-by":"publisher","DOI":"10.1109\/IWCMC.2019.8766353"},{"key":"ref107","article-title":"The threat of adversarial attacks on machine learning in network security\u2014A survey","author":"Ibitoye","year":"2019","journal-title":"arXiv:1911.02621"},{"key":"ref108","doi-asserted-by":"publisher","DOI":"10.1145\/3339252.3339266"},{"key":"ref109","first-page":"321","article-title":"Why do adversarial attacks transfer? Explaining transferability of evasion and poisoning attacks","volume-title":"Proc. 28th USENIX Security Symp.","author":"Demontis"},{"key":"ref110","doi-asserted-by":"publisher","DOI":"10.3390\/s17112687"},{"key":"ref111","doi-asserted-by":"publisher","DOI":"10.1109\/RTAS52030.2021.00027"},{"key":"ref112","doi-asserted-by":"publisher","DOI":"10.1007\/s41635-018-0037-2"},{"key":"ref113","doi-asserted-by":"publisher","DOI":"10.1049\/cps2.12014"},{"key":"ref114","doi-asserted-by":"publisher","DOI":"10.1145\/1267060.1267062"},{"key":"ref115","doi-asserted-by":"publisher","DOI":"10.1109\/IECON.2011.6120048"},{"key":"ref116","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2021.3133348"},{"key":"ref117","doi-asserted-by":"publisher","DOI":"10.1109\/ICMLA.2017.0-119"},{"key":"ref118","first-page":"3","volume-title":"Analysis of the Cyber Attack on the Ukrainian Power Grid: Defense Use Case","volume":"388","year":"2016"},{"key":"ref119","first-page":"1","article-title":"Explaining and harnessing adversarial examples","volume-title":"Proc. 3rd Int. Conf. Learn. Represent. Conf. Track","author":"Goodfellow"},{"key":"ref120","doi-asserted-by":"publisher","DOI":"10.1201\/9781351251389-8"},{"key":"ref121","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.06083"},{"key":"ref122","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"ref123","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref124","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"ref125","first-page":"1","article-title":"Deep inside convolutional networks: Visualising image classification models and saliency maps","volume-title":"Proc. Workshop Int. Conf. Learn. Represent.","author":"Simonyan"},{"key":"ref126","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.1503.02531"},{"key":"ref127","doi-asserted-by":"publisher","DOI":"10.1109\/tnn.1998.712192"},{"key":"ref128","first-page":"1942","article-title":"Particle swarm optimization","volume-title":"Proc. IEEE Int. Conf. Neural Netw.","volume":"4","author":"Eberhart"},{"key":"ref129","doi-asserted-by":"publisher","DOI":"10.1145\/175247.175259"},{"key":"ref130","doi-asserted-by":"publisher","DOI":"10.1109\/BIBE.2014.73"},{"key":"ref131","article-title":"Generative adversarial nets","volume-title":"Advances in Neural Information Processing Systems","volume":"27","author":"Goodfellow","year":"2014"},{"key":"ref132","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140448"},{"key":"ref133","volume-title":"Theory of Games and Economic Behavior","author":"von Neumann","year":"1944"},{"key":"ref134","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2021.102367"},{"key":"ref135","first-page":"214","article-title":"Wasserstein generative adversarial networks","volume-title":"Proc. 34th Int. Conf. Mach. Learn.","volume":"70","author":"Arjovsky"},{"key":"ref136","article-title":"Failure modes in machine learning systems","author":"Kumar","year":"2019","journal-title":"arXiv:1911.11034"},{"key":"ref137","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2018.00035"},{"key":"ref138","doi-asserted-by":"publisher","DOI":"10.1145\/3316781.3323470"},{"key":"ref139","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-71368-7_8"},{"key":"ref140","article-title":"A deep learning-based framework for conducting stealthy attacks in industrial control systems","author":"Feng","year":"2017","journal-title":"arXiv:1709.06397"},{"key":"ref141","volume-title":"KDD cup 1999: Computer network intrusion detection","author":"Discovery","year":"1999"},{"key":"ref142","doi-asserted-by":"publisher","DOI":"10.1145\/3433210.3437513"},{"key":"ref143","doi-asserted-by":"publisher","DOI":"10.1109\/JSAC.2021.3087242"},{"key":"ref144","article-title":"Packet-level adversarial network traffic crafting using sequence generative adversarial networks","author":"Cheng","year":"2021","journal-title":"arXiv:2103.04794"},{"key":"ref145","doi-asserted-by":"publisher","DOI":"10.1109\/ICTAI50040.2020.00110"},{"key":"ref146","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.3008433"},{"key":"ref147","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2021.12.015"},{"key":"ref148","doi-asserted-by":"publisher","DOI":"10.1109\/ICEIEC.2019.8784514"},{"key":"ref149","doi-asserted-by":"publisher","DOI":"10.1109\/ISGT45199.2020.9087649"},{"key":"ref150","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-59016-1_65"},{"key":"ref151","article-title":"Liuer Mihou: A practical framework for generating and evaluating grey-box adversarial attacks against NIDS","author":"He","year":"2022","journal-title":"arXiv:2204.06113"},{"key":"ref152","doi-asserted-by":"publisher","DOI":"10.1109\/DSN-W54100.2022.00017"},{"key":"ref153","first-page":"35","article-title":"Adversarial deep learning against intrusion detection classifiers","volume-title":"Proc. CEUR Workshop","author":"Rigaki"},{"key":"ref154","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN.2019.8851936"},{"key":"ref155","article-title":"Adversarial examples in constrained domains","author":"Sheatsley","year":"2020","journal-title":"arXiv:2011.01183"},{"key":"ref156","doi-asserted-by":"publisher","DOI":"10.1109\/TCAD.2020.3012171"},{"key":"ref157","doi-asserted-by":"publisher","DOI":"10.1109\/AIPR50011.2020.9425190"},{"key":"ref158","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2020.3048038"},{"key":"ref159","doi-asserted-by":"publisher","DOI":"10.1145\/3447555.3464859"},{"key":"ref160","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2021.3093386"},{"key":"ref161","doi-asserted-by":"publisher","DOI":"10.1016\/j.jisa.2020.102717"},{"key":"ref162","doi-asserted-by":"publisher","DOI":"10.1145\/3544746"},{"key":"ref163","doi-asserted-by":"publisher","DOI":"10.1109\/TSG.2022.3193989"},{"key":"ref164","volume-title":"Smart-grid smart-city customer trial data","year":"2015"},{"key":"ref165","doi-asserted-by":"publisher","DOI":"10.1016\/j.jisa.2022.103398"},{"key":"ref166","volume-title":"Principles of an open artificial pancreas system (OpenAPS)","year":"2021"},{"key":"ref167","doi-asserted-by":"publisher","DOI":"10.1186\/s12902-018-0300-0"},{"key":"ref168","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23204"},{"key":"ref169","article-title":"IDSGAN: Generative adversarial networks for attack generation against intrusion detection","author":"Lin","year":"2018","journal-title":"arXiv:1809.02077"},{"key":"ref170","doi-asserted-by":"publisher","DOI":"10.1109\/milcom.2018.8599759"},{"key":"ref171","doi-asserted-by":"publisher","DOI":"10.1007\/s13042-019-00925-6"},{"key":"ref172","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2020.3037500"},{"key":"ref173","doi-asserted-by":"publisher","DOI":"10.1109\/GLOBECOM42002.2020.9322472"},{"key":"ref174","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2021.115782"},{"key":"ref175","doi-asserted-by":"publisher","DOI":"10.1016\/j.procs.2021.04.118"},{"key":"ref176","doi-asserted-by":"publisher","DOI":"10.1109\/ISGT50606.2022.9817468"},{"key":"ref177","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2022.102922"},{"key":"ref178","doi-asserted-by":"publisher","DOI":"10.1145\/1921168.1921179"},{"key":"ref179","doi-asserted-by":"publisher","DOI":"10.1109\/CCST.2019.8888419"},{"key":"ref180","doi-asserted-by":"publisher","DOI":"10.1109\/TSG.2022.3159842"},{"key":"ref181","doi-asserted-by":"publisher","DOI":"10.1109\/TNSM.2022.3173933"},{"key":"ref182","doi-asserted-by":"publisher","DOI":"10.1145\/2185520.2185569"},{"key":"ref183","article-title":"Continuous control with deep reinforcement learning","author":"Lillicrap","year":"2015","journal-title":"arXiv:1509.02971"},{"key":"ref184","doi-asserted-by":"publisher","DOI":"10.5220\/0006639801080116"},{"key":"ref185","doi-asserted-by":"publisher","DOI":"10.1109\/CISDA.2009.5356528"},{"key":"ref186","doi-asserted-by":"publisher","DOI":"10.1109\/MilCIS.2015.7348942"},{"key":"ref187","doi-asserted-by":"publisher","DOI":"10.1145\/382912.382914"},{"key":"ref188","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v31i1.10804"},{"key":"ref189","doi-asserted-by":"publisher","DOI":"10.1109\/ICCCNT.2018.8494096"},{"key":"ref190","doi-asserted-by":"publisher","DOI":"10.1109\/SSCI44817.2019.9003126"},{"key":"ref191","doi-asserted-by":"publisher","DOI":"10.1145\/3430199.3430224"},{"key":"ref192","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"ref193","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23198"},{"key":"ref194","article-title":"Towards deep neural network architectures robust to adversarial examples","author":"Gu","year":"2015","journal-title":"arXiv:1412.5068"},{"key":"ref195","doi-asserted-by":"publisher","DOI":"10.1109\/TETCI.2020.2968933"},{"key":"ref196","doi-asserted-by":"publisher","DOI":"10.1109\/TAI.2021.3111139"},{"key":"ref197","doi-asserted-by":"publisher","DOI":"10.1145\/3384217.3385624"},{"key":"ref198","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-30244-3_22"},{"key":"ref199","doi-asserted-by":"publisher","DOI":"10.1109\/SmartGridComm.2019.8909713"},{"key":"ref200","doi-asserted-by":"publisher","DOI":"10.1109\/SmartGridComm.2018.8587547"},{"key":"ref201","doi-asserted-by":"publisher","DOI":"10.1109\/ICC40277.2020.9149117"},{"key":"ref202","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2021.102352"},{"key":"ref203","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2019.2926365"},{"key":"ref204","doi-asserted-by":"publisher","DOI":"10.1109\/ICCCN52240.2021.9522215"},{"key":"ref205","doi-asserted-by":"publisher","DOI":"10.1007\/978-981-16-8059-5_20"},{"key":"ref206","doi-asserted-by":"publisher","DOI":"10.1016\/j.egyr.2022.09.032"},{"key":"ref207","doi-asserted-by":"publisher","DOI":"10.1109\/ICHQP.2018.8378902"},{"key":"ref208","doi-asserted-by":"publisher","DOI":"10.1016\/j.future.2023.09.011"},{"key":"ref209","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2018\/524"},{"key":"ref210","doi-asserted-by":"publisher","DOI":"10.1016\/0098-1354(93)80018-I"},{"key":"ref211","doi-asserted-by":"publisher","DOI":"10.1145\/3411495.3421359"},{"key":"ref212","doi-asserted-by":"publisher","DOI":"10.1145\/3395352.3402627"},{"key":"ref213","doi-asserted-by":"publisher","DOI":"10.1109\/MILCOM.2018.8599754"},{"key":"ref214","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2020\/173"},{"key":"ref215","doi-asserted-by":"publisher","DOI":"10.1109\/NFV-SDN50289.2020.9289869"},{"key":"ref216","doi-asserted-by":"publisher","DOI":"10.1109\/NetSoft51509.2021.9492526"},{"key":"ref217","doi-asserted-by":"publisher","DOI":"10.1016\/j.future.2022.08.011"},{"key":"ref218","doi-asserted-by":"publisher","DOI":"10.1109\/tsc.2023.3329081"},{"key":"ref219","doi-asserted-by":"publisher","DOI":"10.1109\/TSG.2022.3217060"},{"key":"ref220","doi-asserted-by":"publisher","DOI":"10.1109\/ICSESS49938.2020.9237728"},{"key":"ref221","article-title":"Omni: Automated ensemble with unexpected models against adversarial evasion attack","author":"Shu","year":"2020","journal-title":"arXiv:2011.12720"},{"key":"ref222","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2020.3005688"},{"key":"ref223","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM42981.2021.9488874"},{"key":"ref224","doi-asserted-by":"publisher","DOI":"10.1016\/j.future.2022.02.019"},{"key":"ref225","doi-asserted-by":"publisher","DOI":"10.5220\/0009187802070218"},{"key":"ref226","volume-title":"IoT network intrusion dataset","author":"Kang"},{"key":"ref227","first-page":"1","article-title":"Improving the generalization of adversarial training with domain adaptation","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Song"},{"key":"ref228","doi-asserted-by":"publisher","DOI":"10.23919\/CYCON.2019.8756865"},{"key":"ref229","doi-asserted-by":"publisher","DOI":"10.3390\/app10228079"},{"key":"ref230","article-title":"Testing robustness against unforeseen adversaries","author":"Kang","year":"2020","journal-title":"arXiv:1908.08016v4"},{"key":"ref231","article-title":"Adversarial training for free!","volume-title":"Advances in Neural Information Processing Systems","volume":"32","author":"Shafahi","year":"2019"},{"key":"ref232","first-page":"2642","article-title":"Conditional image synthesis with auxiliary classifier GANs","volume-title":"Proc. 34th Int. Conf. Mach. Learn.","volume":"70","author":"Odena"},{"key":"ref233","article-title":"Semi-supervised learning with generative adversarial networks","author":"Odena","year":"2016","journal-title":"arXiv:1606.01583"},{"key":"ref234","doi-asserted-by":"publisher","DOI":"10.1109\/CISS.2019.8692918"},{"key":"ref235","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN48605.2020.9207291"},{"key":"ref236","first-page":"1815","article-title":"Feature extraction based on denoising auto encoder for classification of adversarial examples","volume-title":"Proc. Asia\u2013Pacific Signal Inf. Process. Assoc. Annu. Summit Conf. (APSIPA ASC)","author":"Yamasaki"},{"key":"ref237","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-12586-7"},{"key":"ref238","article-title":"Improving adversarial robustness of ensembles with diversity training","author":"Kariyappa","year":"2019","journal-title":"arXiv:1901. 09981"},{"key":"ref239","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-70659-3_44"},{"key":"ref240","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2813079"},{"key":"ref241","first-page":"1","article-title":"Adversarial feature learning","volume-title":"Proc. 5th Int. Conf. Learn. Represent.","author":"Donahue"},{"key":"ref242","article-title":"Transferability in machine learning: From phenomena to black-box attacks using adversarial samples","author":"Papernot","year":"2016","journal-title":"arXiv:1605.07277"},{"key":"ref243","article-title":"Detecting adversarial samples from artifacts","author":"Feinman","year":"2017","journal-title":"arXiv:1703.00410"},{"key":"ref244","first-page":"1","article-title":"Delving into transferable adversarial examples and black-box attacks","volume-title":"Proc. 5th Int. Conf. Learn. Represent.","author":"Liu"},{"key":"ref245","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00284"},{"key":"ref246","doi-asserted-by":"publisher","DOI":"10.1109\/SmartGridComm52983.2022.9960966"},{"key":"ref247","doi-asserted-by":"publisher","DOI":"10.1109\/TNSM.2022.3164354"},{"key":"ref248","doi-asserted-by":"publisher","DOI":"10.1109\/TEVC.2019.2890858"},{"key":"ref249","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2017.12.022"},{"key":"ref250","doi-asserted-by":"publisher","DOI":"10.1007\/s10994-022-06177-w"},{"key":"ref251","doi-asserted-by":"publisher","DOI":"10.1145\/2523813"},{"key":"ref252","doi-asserted-by":"publisher","DOI":"10.1109\/CAMAD.2019.8858431"},{"key":"ref253","article-title":"Blocking transferability of adversarial examples in black-box learning systems","author":"Hosseini","year":"2017","journal-title":"arXiv:1703.04318"},{"key":"ref254","article-title":"The space of transferable adversarial examples","author":"Tram\u00e8r","year":"2017","journal-title":"arXiv:1704.03453"},{"key":"ref255","doi-asserted-by":"publisher","DOI":"10.1145\/2714576.2714599"},{"key":"ref256","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2021.3073066"},{"key":"ref257","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.2981415"}],"container-title":["IEEE Communications Surveys &amp; Tutorials"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/9739\/10536630\/10366507.pdf?arnumber=10366507","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,5,23]],"date-time":"2024-05-23T04:49:41Z","timestamp":1716439781000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10366507\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024]]},"references-count":257,"journal-issue":{"issue":"2"},"URL":"https:\/\/doi.org\/10.1109\/comst.2023.3344808","relation":{},"ISSN":["1553-877X","2373-745X"],"issn-type":[{"value":"1553-877X","type":"electronic"},{"value":"2373-745X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024]]}}}