{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,1]],"date-time":"2025-11-01T13:56:04Z","timestamp":1762005364428},"reference-count":30,"publisher":"IEEE","license":[{"start":{"date-parts":[[2021,7,18]],"date-time":"2021-07-18T00:00:00Z","timestamp":1626566400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2021,7,18]],"date-time":"2021-07-18T00:00:00Z","timestamp":1626566400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2021,7,18]],"date-time":"2021-07-18T00:00:00Z","timestamp":1626566400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2021,7,18]]},"DOI":"10.1109\/ijcnn52387.2021.9534119","type":"proceedings-article","created":{"date-parts":[[2021,9,21]],"date-time":"2021-09-21T20:40:52Z","timestamp":1632256852000},"source":"Crossref","is-referenced-by-count":7,"title":["Digital Watermark Perturbation for Adversarial Examples to Fool Deep Neural Networks"],"prefix":"10.1109","author":[{"given":"Shiyu","family":"Feng","sequence":"first","affiliation":[]},{"given":"Feng","family":"Feng","sequence":"additional","affiliation":[]},{"given":"Xiao","family":"Xu","sequence":"additional","affiliation":[]},{"given":"Zheng","family":"Wang","sequence":"additional","affiliation":[]},{"given":"Yining","family":"Hu","sequence":"additional","affiliation":[]},{"given":"Lizhe","family":"Xie","sequence":"additional","affiliation":[]}],"member":"263","reference":[{"key":"ref30","article-title":"Mitigating adversarial effects through randomization","author":"xie","year":"2017","journal-title":"ArXiv Preprint"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/5.771066"},{"key":"ref11","first-page":"2","author":"katzenbeisser","year":"2000","journal-title":"Digital Watermarking"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/4235.996017"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/ICNN.1995.488968"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.17"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/TEVC.2019.2890858"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/MMUL.2006.23"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.23919\/EUSIPCO.2018.8553343"},{"key":"ref18","article-title":"Attacking Optical Character Recognition (OCR) Systems with Adversarial Watermarks","author":"chen","year":"2020","journal-title":"ArXiv Preprint"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/T-C.1974.223784"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.74"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP.2019.8682351"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.308"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"ref6","first-page":"1802","article-title":"Exploring the landscape of spatial robustness","author":"engstrom","year":"2019","journal-title":"International Conference on Machine Learning"},{"key":"ref29","article-title":"Keeping the bad guys out: Protecting and vaccinating deep learning with jpeg compression","author":"das","year":"2017","journal-title":"ArXiv Preprint"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1145\/3394171.3413976"},{"key":"ref8","article-title":"Towards the first adversarially robust neural network model on MNIST","author":"schott","year":"2018","journal-title":"ArXiv Preprint"},{"key":"ref7","article-title":"Decision-based adversarial attacks: Reliable attacks against black-box machine learning models","author":"brendel","year":"2017","journal-title":"ArXiv Preprint"},{"key":"ref2","article-title":"Adversarial examples in the physical world","author":"kurakin","year":"2016","journal-title":"ArXiv Preprint"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"ref1","article-title":"Explaining and harnessing adversarial examples","author":"goodfellow","year":"2014","journal-title":"ArXiv Preprint"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1137\/0718026"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-015-0816-y"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/ICPR.2010.579"},{"key":"ref24","article-title":"Very deep convolutional networks for large-scale image recognition","author":"simonyan","year":"2014","journal-title":"ArXiv Preprint"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1145\/3065386"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref25","article-title":"SqueezeNet: AlexNet-level accuracy with 50x fewer parameters and&#x00A1; 0.5 MB model size","author":"iandola","year":"2016","journal-title":"ArXiv Preprint"}],"event":{"name":"2021 International Joint Conference on Neural Networks (IJCNN)","location":"Shenzhen, China","start":{"date-parts":[[2021,7,18]]},"end":{"date-parts":[[2021,7,22]]}},"container-title":["2021 International Joint Conference on Neural Networks (IJCNN)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/9533266\/9533267\/09534119.pdf?arnumber=9534119","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,5,10]],"date-time":"2022-05-10T15:45:50Z","timestamp":1652197550000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9534119\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,7,18]]},"references-count":30,"URL":"https:\/\/doi.org\/10.1109\/ijcnn52387.2021.9534119","relation":{},"subject":[],"published":{"date-parts":[[2021,7,18]]}}}