{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,5,15]],"date-time":"2025-05-15T13:32:16Z","timestamp":1747315936806},"reference-count":25,"publisher":"IEEE","license":[{"start":{"date-parts":[[2020,10,11]],"date-time":"2020-10-11T00:00:00Z","timestamp":1602374400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2020,10,11]],"date-time":"2020-10-11T00:00:00Z","timestamp":1602374400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2020,10,11]],"date-time":"2020-10-11T00:00:00Z","timestamp":1602374400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2020,10,11]]},"DOI":"10.1109\/smc42975.2020.9282889","type":"proceedings-article","created":{"date-parts":[[2020,12,14]],"date-time":"2020-12-14T16:44:48Z","timestamp":1607964288000},"page":"160-165","source":"Crossref","is-referenced-by-count":1,"title":["It is double pleasure to deceive the deceiver: disturbing classifiers against adversarial attacks"],"prefix":"10.1109","author":[{"given":"Joao G.","family":"Zago","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Eric A.","family":"Antonelo","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Fabio L.","family":"Baldissera","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Rodrigo T.","family":"Saad","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref10","article-title":"Adversarial Manipulation of Deep Representations","author":"sabour","year":"0","journal-title":"CoRR"},{"key":"ref11","article-title":"Obfuscated Gradients Give a False Sense of Security: Circumventing Defenses to Adversarial Examples","author":"athalye","year":"2018","journal-title":"ICML"},{"article-title":"Towards Deep Learning Models Resistant to Adversarial Attacks","year":"0","author":"madry","key":"ref12"},{"article-title":"Transferability in Machine Learning: from Phenomena to Black-Box Attacks using Adversarial Samples","year":"0","author":"papernot","key":"ref13"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW.2017.172"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140448"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/TEVC.2019.2890858"},{"article-title":"Generating Natural Adversarial Examples","year":"0","author":"zhao","key":"ref17"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.41"},{"article-title":"Adversarial Machine Learning at Scale","year":"0","author":"kurakin","key":"ref19"},{"key":"ref4","article-title":"Explaining and harnessing adversarial examples","author":"goodfellow","year":"0","journal-title":"CoRR"},{"key":"ref3","article-title":"Intriguing properties of neural networks","author":"szegedy","year":"0","journal-title":"CoRR"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"article-title":"Adversarial examples in the physical world","year":"0","author":"kurakin","key":"ref5"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"article-title":"Adam: A method for stochastic optimization","year":"2014","author":"kingma","key":"ref2"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.17"},{"key":"ref1","article-title":"Inception-v4, Inception- ResNet and the impact of residual connections on learning","author":"szegedy","year":"2016","journal-title":"AAAI Conference on Artificial Intelligence"},{"article-title":"Ensemble Adversarial Training: Attacks and Defenses","year":"0","author":"tram\u00e8r","key":"ref20"},{"article-title":"On Detecting Adversarial Perturbations","year":"0","author":"metzen","key":"ref22"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.56"},{"article-title":"On the (Statistical) Detection of Adversarial Examples","year":"0","author":"grosse","key":"ref24"},{"article-title":"Detecting Adversarial Samples from Artifacts","year":"0","author":"feinman","key":"ref23"},{"article-title":"PixelDefend: Leveraging Generative Models to Understand and Defend against Adversarial Examples","year":"2017","author":"song","key":"ref25"}],"event":{"name":"2020 IEEE International Conference on Systems, Man, and Cybernetics (SMC)","start":{"date-parts":[[2020,10,11]]},"location":"Toronto, ON, Canada","end":{"date-parts":[[2020,10,14]]}},"container-title":["2020 IEEE International Conference on Systems, Man, and Cybernetics (SMC)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/9282733\/9282811\/09282889.pdf?arnumber=9282889","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,6,30]],"date-time":"2022-06-30T11:16:06Z","timestamp":1656587766000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9282889\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,10,11]]},"references-count":25,"URL":"https:\/\/doi.org\/10.1109\/smc42975.2020.9282889","relation":{},"subject":[],"published":{"date-parts":[[2020,10,11]]}}}