{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,19]],"date-time":"2026-03-19T21:59:07Z","timestamp":1773957547683,"version":"3.50.1"},"reference-count":37,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"2","license":[{"start":{"date-parts":[[2021,1,15]],"date-time":"2021-01-15T00:00:00Z","timestamp":1610668800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2021,1,15]],"date-time":"2021-01-15T00:00:00Z","timestamp":1610668800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2021,1,15]],"date-time":"2021-01-15T00:00:00Z","timestamp":1610668800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Internet Things J."],"published-print":{"date-parts":[[2021,1,15]]},"DOI":"10.1109\/jiot.2020.3008232","type":"journal-article","created":{"date-parts":[[2020,7,9]],"date-time":"2020-07-09T20:37:07Z","timestamp":1594327027000},"page":"802-812","source":"Crossref","is-referenced-by-count":18,"title":["Toward Invisible Adversarial Examples Against DNN-Based Privacy Leakage for Internet of Things"],"prefix":"10.1109","volume":"8","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-8785-9015","authenticated-orcid":false,"given":"Xuyang","family":"Ding","sequence":"first","affiliation":[]},{"given":"Shuai","family":"Zhang","sequence":"additional","affiliation":[]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7907-3469","authenticated-orcid":false,"given":"Mengkai","family":"Song","sequence":"additional","affiliation":[]},{"given":"Xiaocong","family":"Ding","sequence":"additional","affiliation":[]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6289-1265","authenticated-orcid":false,"given":"Fagen","family":"Li","sequence":"additional","affiliation":[]}],"member":"263","reference":[{"key":"ref33","first-page":"1","article-title":"MMA training: direct input space margin maximization through adversarial training","author":"ding","year":"2020","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00897"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.41"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23198"},{"key":"ref37","first-page":"125","article-title":"Adversarial examples are not bugs, they are features","author":"ilyas","year":"2019","journal-title":"Proc Neural Inf Process Syst"},{"key":"ref36","first-page":"1765","article-title":"Universal adversarial perturbations","author":"moosavidezfooli","year":"2017","journal-title":"Proc IEEE Conf Comput Vision Pattern Recognit"},{"key":"ref35","first-page":"1","article-title":"Delving into transferable adversarial examples and black-box attacks","author":"liu","year":"2017","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref34","author":"singla","year":"2020","journal-title":"Second-Order Provable Defenses Against Adversarial Attacks"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/TEVC.2019.2890858"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298783"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.308"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1007\/s10994-010-5188-5"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1145\/1128817.1128824"},{"key":"ref16","first-page":"1","article-title":"Intriguing properties of neural networks","author":"szegedy","year":"2014","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"ref18","first-page":"1","article-title":"Adversarial machine learning at scale","author":"kurakin","year":"2017","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1145\/2939672.2939778"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/GLOBECOM38437.2019.9014337"},{"key":"ref4","first-page":"361","article-title":"Multimodal residual learning for visual QA","author":"kim","year":"2016","journal-title":"Proc Neural Inf Process Syst"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.300"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2015.169"},{"key":"ref6","author":"goodfellow","year":"2015","journal-title":"Explaining and Harnessing Adversarial Examples"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.3390\/s19040974"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/D16-1044"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"ref7","first-page":"1","article-title":"Adversarial examples in the physical world","author":"kurakin","year":"2017","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref2","first-page":"379","article-title":"R-FCN: Object detection via region-based fully convolutional networks","author":"dai","year":"2016","journal-title":"Proc Neural Inf Process Syst"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"ref1","first-page":"1097","article-title":"Imagenet classification with deep convolutional neural networks","author":"krizhevsky","year":"2012","journal-title":"Proc Neural Inf Process Syst"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.319"},{"key":"ref22","first-page":"513","article-title":"Hidden voice commands","author":"carlini","year":"2016","journal-title":"Proc Usenix Security Symp"},{"key":"ref21","author":"evtimov","year":"2017","journal-title":"Robust physical-world attacks on machine learning models"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.153"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134052"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/MMSP.2018.8547128"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978392"}],"container-title":["IEEE Internet of Things Journal"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/6488907\/9316336\/09137128.pdf?arnumber=9137128","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,5,10]],"date-time":"2022-05-10T14:53:36Z","timestamp":1652194416000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9137128\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,1,15]]},"references-count":37,"journal-issue":{"issue":"2"},"URL":"https:\/\/doi.org\/10.1109\/jiot.2020.3008232","relation":{},"ISSN":["2327-4662","2372-2541"],"issn-type":[{"value":"2327-4662","type":"electronic"},{"value":"2372-2541","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,1,15]]}}}