{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,26]],"date-time":"2026-02-26T21:27:26Z","timestamp":1772141246174,"version":"3.50.1"},"reference-count":32,"publisher":"IEEE","license":[{"start":{"date-parts":[[2021,1,10]],"date-time":"2021-01-10T00:00:00Z","timestamp":1610236800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2021,1,10]],"date-time":"2021-01-10T00:00:00Z","timestamp":1610236800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2021,1,10]],"date-time":"2021-01-10T00:00:00Z","timestamp":1610236800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2021,1,10]]},"DOI":"10.1109\/icpr48806.2021.9413327","type":"proceedings-article","created":{"date-parts":[[2021,5,6]],"date-time":"2021-05-06T02:15:54Z","timestamp":1620267354000},"page":"5044-5051","source":"Crossref","is-referenced-by-count":7,"title":["Optimal Transport as a Defense Against Adversarial Attacks"],"prefix":"10.1109","author":[{"given":"Quentin","family":"Bouniot","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Romaric","family":"Audigier","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Angelique","family":"Loesch","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref32","article-title":"Sample complexity of sinkhorn divergences","author":"genevay","year":"2019","journal-title":"International Conference on Artificial Intelligence and Statistics (AISTATS)"},{"key":"ref31","author":"zagoruyko","year":"2016","journal-title":"Wide residual networks &#x201D; British Machine Vision Conference (BMVC)"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.01161"},{"key":"ref12","article-title":"Decoupling direction and norm for efficient gradient-based 12 adversarial attacks and defenses","author":"rony","year":"0","journal-title":"Conference on Computer Vision and Pattern Recognition (CVPR)"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"ref14","article-title":"Decision-based adversarial attacks: Reliable attacks against black-box machine learning models","author":"brendel","year":"0","journal-title":"International Conference on Learning Representations (ICLR)"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW.2017.172"},{"key":"ref16","article-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","author":"athalye","year":"0","journal-title":"International Conference on Machine Learning (ICML)"},{"key":"ref17","article-title":"Countering adversarial images using input transformations","author":"guo","year":"0","journal-title":"International Conference on Learning Representations (ICLR)"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00191"},{"key":"ref19","article-title":"Improving adversarial robustness via promoting ensemble diversity","author":"pang","year":"0","journal-title":"International Conference on Machine Learning (ICML)"},{"key":"ref28","author":"genevay","year":"2017","journal-title":"Learning generative models with sinkhorn divergences"},{"key":"ref4","article-title":"Adversarial Machine Learning at Scale","author":"kurakin","year":"2017","journal-title":"International Conference on Learning Representations"},{"key":"ref27","article-title":"Sinkhorn distances: Lightspeed computation of optimal transport","author":"cuturi","year":"2013","journal-title":"Advances in Neural IInformation Processing Systems"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"ref6","article-title":"Pix-elDefend: Leveraging generative models to understand and defend against adversarial examples","author":"song","year":"0","journal-title":"International Conference on Learning Representations (ICLR)"},{"key":"ref29","author":"krizhevsky","year":"2009","journal-title":"Learning multiple layers of features from tiny images"},{"key":"ref5","article-title":"Towards deep learning models resistant to adversarial attacks","author":"madry","year":"0","journal-title":"International Conference on Learning Representations (ICLR)"},{"key":"ref8","article-title":"Improving the generalization of adversarial training with domain adaptation","author":"song","year":"0","journal-title":"International Conference on Learning Representations (ICLR)"},{"key":"ref7","article-title":"Ensemble adversarial training: Attacks and defenses","author":"tram\u00e8r","year":"0","journal-title":"International Conference on Learning Representations (ICLR)"},{"key":"ref2","article-title":"Explaining and harnessing adversarial examples","author":"goodfellow","year":"2014","journal-title":"International Conference on Learning Representations (ICLR)"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00348"},{"key":"ref1","article-title":"Intriguing properties of neural networks","author":"szegedy","year":"0","journal-title":"International Conference on Learning Representations (ICLR)"},{"key":"ref20","article-title":"Stochastic activation pruning for robust adversarial defense","author":"dhillon","year":"0","journal-title":"International Conference on Learning Representations (ICLR)"},{"key":"ref22","article-title":"A kernel method for the two-sample-problem","author":"gretton","year":"2007","journal-title":"Advances in Neural IInformation Processing Systems"},{"key":"ref21","author":"tram\u00e8r","year":"2020","journal-title":"On adaptive attacks to adversarial example defenses"},{"key":"ref24","article-title":"Interpolating between optimal transport and mmd using sinkhorn divergences","author":"feydy","year":"0","journal-title":"Proceedings of Machine Learning Research (PMLR)"},{"key":"ref23","article-title":"Return of frustratingly easy domain adaptation","author":"sun","year":"0","journal-title":"Int Conference on Artificial Intelligence (AAAI)"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1561\/9781680835519"},{"key":"ref25","author":"genevay","year":"2019","journal-title":"Entropy-regularized optimal transport for machine learning"}],"event":{"name":"2020 25th International Conference on Pattern Recognition (ICPR)","location":"Milan, Italy","start":{"date-parts":[[2021,1,10]]},"end":{"date-parts":[[2021,1,15]]}},"container-title":["2020 25th International Conference on Pattern Recognition (ICPR)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/9411940\/9411911\/09413327.pdf?arnumber=9413327","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,5,10]],"date-time":"2022-05-10T15:40:39Z","timestamp":1652197239000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9413327\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,1,10]]},"references-count":32,"URL":"https:\/\/doi.org\/10.1109\/icpr48806.2021.9413327","relation":{},"subject":[],"published":{"date-parts":[[2021,1,10]]}}}