{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,15]],"date-time":"2025-11-15T07:38:18Z","timestamp":1763192298215,"version":"3.45.0"},"reference-count":26,"publisher":"IEEE","license":[{"start":{"date-parts":[[2025,6,30]],"date-time":"2025-06-30T00:00:00Z","timestamp":1751241600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,6,30]],"date-time":"2025-06-30T00:00:00Z","timestamp":1751241600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025,6,30]]},"DOI":"10.1109\/ijcnn64981.2025.11227740","type":"proceedings-article","created":{"date-parts":[[2025,11,14]],"date-time":"2025-11-14T18:46:15Z","timestamp":1763145975000},"page":"1-8","source":"Crossref","is-referenced-by-count":0,"title":["MTD-Net: Moving Target Defense for Defending Neural Networks Adversarial Attacks"],"prefix":"10.1109","author":[{"given":"Zeshan","family":"Pang","sequence":"first","affiliation":[{"name":"College of Electronic Engineering, National University of Defense Technology,Anhui Province Key Laboratory of Cyberspace Security Situation Awareness and Evaluation"}]},{"given":"Shasha","family":"Guo","sequence":"additional","affiliation":[{"name":"College of Electronic Engineering, National University of Defense Technology,Anhui Province Key Laboratory of Cyberspace Security Situation Awareness and Evaluation"}]},{"given":"Yuyuan","family":"Sun","sequence":"additional","affiliation":[{"name":"College of Electronic Engineering, National University of Defense Technology,Anhui Province Key Laboratory of Cyberspace Security Situation Awareness and Evaluation"}]},{"given":"Rongtao","family":"Liao","sequence":"additional","affiliation":[{"name":"College of Electronic Engineering, National University of Defense Technology,Anhui Province Key Laboratory of Cyberspace Security Situation Awareness and Evaluation"}]},{"given":"Xuehu","family":"Yan","sequence":"additional","affiliation":[{"name":"College of Electronic Engineering, National University of Defense Technology,Anhui Province Key Laboratory of Cyberspace Security Situation Awareness and Evaluation"}]},{"given":"Yuliang","family":"Lu","sequence":"additional","affiliation":[]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"article-title":"Towards deep learning models resistant to adversarial attacks","volume-title":"International Conference on Learning Representations","author":"Madry","key":"ref2"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"article-title":"Explaining and harnessing adversarial examples","volume-title":"International Conference on Learning Representations","author":"Goodfellow","key":"ref4"},{"key":"ref5","first-page":"1","article-title":"An analysis of adversarial attacks and defenses on autonomous driving models","volume-title":"2020 IEEE International Conference on Pervasive Computing and Communications (PerCom)","author":"Deng"},{"article-title":"Dverge: diversifying vulnerabilities for enhanced robust generation of ensembles","volume-title":"Proceedings of the 34th International Conference on Neural Information Processing Systems, ser. NIPS \u201920","author":"Yang","key":"ref6"},{"key":"ref7","article-title":"TRS: Transferability reduced ensemble via promoting gradient diversity and model smoothness","volume-title":"Advances in Neural Information Processing Systems","author":"Yang","year":"2021"},{"key":"ref8","first-page":"4970","article-title":"Improving adversarial robustness via promoting ensemble diversity","volume-title":"Proceedings of the 36th International Conference on Machine Learning","volume":"97","author":"Pang"},{"article-title":"Mora: improving ensemble robustness evaluation with model-reweighing attack","volume-title":"Proceedings of the 36th International Conference on Neural Information Processing Systems, ser. NIPS \u201922","author":"Yu","key":"ref9"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1145\/3356250.3360025"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1145\/3517806"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-32430-8_28"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1145\/3485832.3485899"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1145\/3615593.3615724"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1007\/s10994-021-06049-9"},{"issue":"1","key":"ref16","first-page":"1929","article-title":"Dropout: a simple way to prevent neural networks from overfitting","volume":"15","author":"Srivastava","year":"2014","journal-title":"The journal of machine learning research"},{"article-title":"The cifar 10 dataset","year":"2014","author":"Alex","key":"ref17"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN.2011.6033395"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58592-1_29"},{"key":"ref20","first-page":"274","article-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","volume-title":"International conference on machine learning","author":"Athalye"},{"article-title":"Very deep convolutional networks for large-scale image recognition","year":"2014","author":"Simonyan","key":"ref21"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.5244\/c.30.87"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1145\/3240765.3264699"},{"key":"ref25","first-page":"4970","article-title":"Improving adversarial robustness via promoting ensemble diversity","volume-title":"International Conference on Machine Learning","author":"Pang"},{"key":"ref26","first-page":"7472","article-title":"Theoretically principled trade-off between robustness and accuracy","volume-title":"International conference on machine learning","author":"Zhang"}],"event":{"name":"2025 International Joint Conference on Neural Networks (IJCNN)","start":{"date-parts":[[2025,6,30]]},"location":"Rome, Italy","end":{"date-parts":[[2025,7,5]]}},"container-title":["2025 International Joint Conference on Neural Networks (IJCNN)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11227166\/11227148\/11227740.pdf?arnumber=11227740","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,11,15]],"date-time":"2025-11-15T07:33:49Z","timestamp":1763192029000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11227740\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,6,30]]},"references-count":26,"URL":"https:\/\/doi.org\/10.1109\/ijcnn64981.2025.11227740","relation":{},"subject":[],"published":{"date-parts":[[2025,6,30]]}}}