{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,9,10]],"date-time":"2025-09-10T21:59:13Z","timestamp":1757541553194,"version":"3.28.0"},"reference-count":33,"publisher":"IEEE","license":[{"start":{"date-parts":[[2023,6,18]],"date-time":"2023-06-18T00:00:00Z","timestamp":1687046400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2023,6,18]],"date-time":"2023-06-18T00:00:00Z","timestamp":1687046400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2023,6,18]]},"DOI":"10.1109\/ijcnn54540.2023.10191198","type":"proceedings-article","created":{"date-parts":[[2023,8,2]],"date-time":"2023-08-02T17:30:03Z","timestamp":1690997403000},"page":"1-8","source":"Crossref","is-referenced-by-count":2,"title":["Robust Deep Learning Models against Semantic-Preserving Adversarial Attack"],"prefix":"10.1109","author":[{"given":"Yunce","family":"Zhao","sequence":"first","affiliation":[{"name":"University of Technology,SUSTech,Dept.of CSE,Shenzhen,Sydney,China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Dashan","family":"Gao","sequence":"additional","affiliation":[{"name":"SUSTech &#x0026; HKUST,Dept. of CSE,Hong Kong,China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yinghua","family":"Yao","sequence":"additional","affiliation":[{"name":"University of Technology,SUSTech,Dept.of CSE,Shenzhen,Sydney,China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zeqi","family":"Zhang","sequence":"additional","affiliation":[{"name":"Huawei Technologies Co., Ltd.,Shenzhen,China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Bifei","family":"Mao","sequence":"additional","affiliation":[{"name":"Huawei Technologies Co., Ltd.,Shenzhen,China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xin","family":"Yao","sequence":"additional","affiliation":[{"name":"SUSTech,Dept.of CSE,Shenzhen,China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"key":"ref12","article-title":"Improving adversarial robustness requires revisiting misclassified examples","author":"wang","year":"0","journal-title":"International Conference on Learning Representations"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i9.16927"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00487"},{"key":"ref31","article-title":"Fashion-mnist: a novel image dataset for benchmarking machine learning algorithms","author":"xiao","year":"2017","journal-title":"ArXiv Preprint"},{"key":"ref30","article-title":"Diversity-sensitive conditional generative adversarial networks","author":"yang","year":"0","journal-title":"International Conference on Learning Representations"},{"key":"ref11","first-page":"7472","article-title":"Theoretically principled trade-off between robustness and accuracy","author":"zhang","year":"2019","journal-title":"ICML"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1016\/j.cmpb.2020.105637"},{"key":"ref10","article-title":"Adversarial machine learning at scale","author":"kurakin","year":"0","journal-title":"International Conference on Learning Representations"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2015.425"},{"key":"ref2","first-page":"1097","article-title":"Imagenet classification with deep convolutional neural networks","volume":"25","author":"krizhevsky","year":"2012","journal-title":"Advances in neural information processing systems"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref17","article-title":"Intriguing properties of neural networks","author":"szegedy","year":"2013","journal-title":"ArXiv Preprint"},{"key":"ref16","article-title":"Are adversarial robustness and common perturbation robustness independant attributes ?","author":"laugros","year":"0","journal-title":"Proceedings of the IEEE\/CVF International Conference on Computer Vision (ICCV) Workshops"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i9.16989"},{"key":"ref18","article-title":"Fast is better than free: Revisiting adversarial training","author":"wong","year":"0","journal-title":"International Conference on Learning Representations"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00283"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00084"},{"key":"ref26","article-title":"Beyond pixel norm-balls: Parametric adversaries using an analytically differentiable renderer","author":"liu","year":"0","journal-title":"International Conference on Learning Representations"},{"key":"ref25","article-title":"Benchmarking neural network robustness to common corruptions and perturbations","author":"hendrycks","year":"0","journal-title":"International Conference on Learning Representations"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref22","article-title":"A direct approach to robust deep learning using adversarial networks","author":"wang","year":"0","journal-title":"International Conference on Learning Representations"},{"key":"ref21","article-title":"Learning to defense by learning to attack","volume":"130","author":"jiang","year":"2021","journal-title":"AISTATS"},{"key":"ref28","first-page":"5916","article-title":"Latent space factorisation and manipulation via matrix subspace projection","author":"li","year":"2020","journal-title":"ICML"},{"key":"ref27","article-title":"Conditional generative adversarial nets","author":"mirza","year":"2014","journal-title":"ArXiv Preprint"},{"key":"ref29","first-page":"2017","article-title":"Spatial transformer networks","volume":"28","author":"jaderberg","year":"2015","journal-title":"Advances in neural information processing systems"},{"key":"ref8","article-title":"Bag of tricks for adversarial training","author":"pang","year":"0","journal-title":"International Conference on Learning Representations"},{"key":"ref7","first-page":"274","article-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","author":"athalye","year":"2018","journal-title":"ICML"},{"key":"ref9","first-page":"1633","article-title":"On adaptive attacks to adversarial example defenses","volume":"33","author":"tramer","year":"2020","journal-title":"Advances in neural information processing systems"},{"key":"ref4","article-title":"Explaining and harnessing adversarial examples","author":"goodfellow","year":"2014","journal-title":"ArXiv Preprint"},{"key":"ref3","first-page":"3104","article-title":"Sequence to sequence learning with neural networks","author":"sutskever","year":"2014","journal-title":"Advances in neural information processing systems"},{"key":"ref6","article-title":"Towards deep learning models resistant to adversarial attacks","author":"madry","year":"0","journal-title":"International Conference on Learning Representations"},{"key":"ref5","article-title":"Adversarial examples in the physical world","author":"kurakin","year":"2016","journal-title":"ArXiv e-prints"}],"event":{"name":"2023 International Joint Conference on Neural Networks (IJCNN)","start":{"date-parts":[[2023,6,18]]},"location":"Gold Coast, Australia","end":{"date-parts":[[2023,6,23]]}},"container-title":["2023 International Joint Conference on Neural Networks (IJCNN)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/10190990\/10190992\/10191198.pdf?arnumber=10191198","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,8,21]],"date-time":"2023-08-21T17:42:00Z","timestamp":1692639720000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10191198\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,6,18]]},"references-count":33,"URL":"https:\/\/doi.org\/10.1109\/ijcnn54540.2023.10191198","relation":{},"subject":[],"published":{"date-parts":[[2023,6,18]]}}}