{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,31]],"date-time":"2025-10-31T07:09:09Z","timestamp":1761894549294,"version":"build-2065373602"},"reference-count":54,"publisher":"IEEE","license":[{"start":{"date-parts":[[2025,6,30]],"date-time":"2025-06-30T00:00:00Z","timestamp":1751241600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,6,30]],"date-time":"2025-06-30T00:00:00Z","timestamp":1751241600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100006190","name":"Research and Development","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100006190","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025,6,30]]},"DOI":"10.1109\/icme59968.2025.11208993","type":"proceedings-article","created":{"date-parts":[[2025,10,30]],"date-time":"2025-10-30T17:57:42Z","timestamp":1761847062000},"page":"1-6","source":"Crossref","is-referenced-by-count":0,"title":["ADoP: A Universal, Robust, Efficient, and Plug-and-Play Adversarial Example Detector"],"prefix":"10.1109","author":[{"given":"Rui","family":"Yang","sequence":"first","affiliation":[{"name":"Xi&#x2019;an Jiaotong University,School of Cyber Science and Engineering,Xi&#x2019;an,China"}]},{"given":"Qindong","family":"Sun","sequence":"additional","affiliation":[{"name":"Xi&#x2019;an Jiaotong University,School of Cyber Science and Engineering,Xi&#x2019;an,China"}]},{"given":"Jiaming","family":"Cai","sequence":"additional","affiliation":[{"name":"Xi&#x2019;an Jiaotong University,School of Software Engineering,Xi&#x2019;an,China"}]},{"given":"Jiangtao","family":"Yu","sequence":"additional","affiliation":[{"name":"Xi&#x2019;an Jiaotong University,School of Cyber Science and Engineering,Xi&#x2019;an,China"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-72646-0_23"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.21437\/Interspeech.2024-2116"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2024.128576"},{"article-title":"Explaining and harnessing adversarial examples","volume-title":"ICLR","author":"Goodfellow","key":"ref4"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i11.17187"},{"article-title":"Detecting adversarial data by probing multiple perturbations using expected perturbation score","volume-title":"ICML","author":"Zhang","key":"ref6"},{"article-title":"Feature squeezing: Detecting adversarial examples in deep neural networks","volume-title":"NDSS","author":"Qi","key":"ref7"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134057"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140444"},{"article-title":"Theoretically principled trade-off between robustness and accuracy","volume-title":"ICML","author":"Zhang","key":"ref10"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v38i5.28200"},{"article-title":"Adversarial training on purification (ATop): Advancing both robustness and generalization","volume-title":"ICLR","author":"Lin","key":"ref12"},{"key":"ref13","article-title":"Diffusion models for adversarial purification","author":"Nie","year":"2022","journal-title":"Machine Learning Research"},{"article-title":"Characterizing adversarial subspaces using local intrinsic dimensionality","volume-title":"ICLR","author":"Ma","key":"ref14"},{"key":"ref15","article-title":"A simple unified framework for detecting out-of-distribution samples and adversarial attacks","author":"Lee","year":"2018","journal-title":"NeurIPS"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2024.103791"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/5254.708428"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/tdsc.2018.2874243"},{"article-title":"The odds are odd: A statistical test for detecting adversarial examples","volume-title":"ICML","author":"Roth","key":"ref19"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1007\/s10207-023-00735-6"},{"article-title":"Conditional image synthesis with auxiliary classifier gans","volume-title":"ICML","author":"Odena","key":"ref21"},{"key":"ref22","article-title":"Improved training of wasserstein gans","author":"Gulrajani","year":"2017","journal-title":"NeurIPS"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00068"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.4236\/jcc.2019.73002"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-24574-4_28"},{"article-title":"Efficientnet: Rethinking model scaling for convolutional neural networks","volume-title":"ICML","author":"Tan","key":"ref27"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/tnnls.2022.3158966"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1016\/0925-2312(93)90006-O"},{"article-title":"Adam: A method for stochastic optimization","volume-title":"ICLR","author":"Kingma","key":"ref30"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58592-1_29"},{"article-title":"Prior convictions: Black-box adversarial attacks with bandits and priors","volume-title":"ICLR","author":"Ilyas","key":"ref32"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/sp40000.2020.00045"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00847"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1145\/3394486.3403225"},{"article-title":"Simple black-box adversarial attacks","volume-title":"ICML","author":"Guo","key":"ref36"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00044"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01029"},{"article-title":"Sign-opt: A query-efficient hard-label adversarial attack","volume-title":"ICLR","author":"Cheng","key":"ref39"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-20065-6_10"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00018"},{"article-title":"Brusleat-tack: A query-efficient score-based black-box sparse adversarial attack","volume-title":"ICLR","author":"Vo","key":"ref42"},{"article-title":"Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks","volume-title":"ICML","author":"Croce","key":"ref43"},{"article-title":"Minimally distorted adversarial examples with a fast adaptive boundary attack","volume-title":"ICML","author":"Croce","key":"ref44"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00284"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"article-title":"Nesterov accelerated gradient and scale invariance for adversarial attacks","volume-title":"ICLR","author":"Lin","key":"ref47"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00444"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00196"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.02297"},{"article-title":"Spatially transformed adversarial examples","volume-title":"ICLR","author":"Xiao","key":"ref51"},{"article-title":"Rolling colors: Adversarial laser exploits against traffic light recognition","volume-title":"USENIX Security","author":"Yan","key":"ref52"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.06083"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"}],"event":{"name":"2025 IEEE International Conference on Multimedia and Expo (ICME)","start":{"date-parts":[[2025,6,30]]},"location":"Nantes, France","end":{"date-parts":[[2025,7,4]]}},"container-title":["2025 IEEE International Conference on Multimedia and Expo (ICME)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11208895\/11208897\/11208993.pdf?arnumber=11208993","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,31]],"date-time":"2025-10-31T05:30:29Z","timestamp":1761888629000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11208993\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,6,30]]},"references-count":54,"URL":"https:\/\/doi.org\/10.1109\/icme59968.2025.11208993","relation":{},"subject":[],"published":{"date-parts":[[2025,6,30]]}}}