{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,8]],"date-time":"2026-05-08T11:11:55Z","timestamp":1778238715473,"version":"3.51.4"},"reference-count":45,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"3","license":[{"start":{"date-parts":[[2024,3,1]],"date-time":"2024-03-01T00:00:00Z","timestamp":1709251200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2024,3,1]],"date-time":"2024-03-01T00:00:00Z","timestamp":1709251200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2024,3,1]],"date-time":"2024-03-01T00:00:00Z","timestamp":1709251200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001459","name":"Ministry of Education - Singapore","doi-asserted-by":"publisher","award":["Tier 1 RS02\/19"],"award-info":[{"award-number":["Tier 1 RS02\/19"]}],"id":[{"id":"10.13039\/501100001459","id-type":"DOI","asserted-by":"publisher"}]},{"name":"National Key Research and Development Plan of China","award":["2018YFB1800301"],"award-info":[{"award-number":["2018YFB1800301"]}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61832013"],"award-info":[{"award-number":["61832013"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Comput."],"published-print":{"date-parts":[[2024,3]]},"DOI":"10.1109\/tc.2021.3076826","type":"journal-article","created":{"date-parts":[[2021,4,30]],"date-time":"2021-04-30T19:48:30Z","timestamp":1619812110000},"page":"645-655","source":"Crossref","is-referenced-by-count":31,"title":["An Efficient Preprocessing-Based Approach to Mitigate Advanced Adversarial Attacks"],"prefix":"10.1109","volume":"73","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-2678-8070","authenticated-orcid":false,"given":"Han","family":"Qiu","sequence":"first","affiliation":[{"name":"Institute for Network Sciences and Cyberspace, Beijing National Research Center for Information Science and Technology, Tsinghua University, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yi","family":"Zeng","sequence":"additional","affiliation":[{"name":"University of California San Diego, San Diego, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5391-9446","authenticated-orcid":false,"given":"Qinkai","family":"Zheng","sequence":"additional","affiliation":[{"name":"Shanghai Jiao Tong University, Shanghai, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shangwei","family":"Guo","sequence":"additional","affiliation":[{"name":"College of Computer Science, Chongqing University, Chongqing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6595-6650","authenticated-orcid":false,"given":"Tianwei","family":"Zhang","sequence":"additional","affiliation":[{"name":"Nanyang Technological University, Singapore"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6331-6542","authenticated-orcid":false,"given":"Hewu","family":"Li","sequence":"additional","affiliation":[{"name":"Institute for Network Sciences and Cyberspace, Beijing National Research Center for Information Science and Technology, Tsinghua University, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","first-page":"15","article-title":"Deep learning inference service at Microsoft","volume-title":"Proc. USENIX Conf. Oper. Mach. learn.","author":"Soifer"},{"key":"ref2","article-title":"Intriguing properties of neural networks","author":"Szegedy","year":"2013"},{"key":"ref3","article-title":"Explaining and harnessing adversarial examples","author":"Goodfellow","year":"2014"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1201\/9781351251389-8"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref6","article-title":"Countering adversarial images using input transformations","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Guo"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00894"},{"key":"ref8","article-title":"Mitigating adversarial effects through randomization","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Xie"},{"key":"ref9","article-title":"Thermometer encoding: One hot way to resist adversarial examples","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Buckman"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2020.3004498"},{"key":"ref11","article-title":"A complete list of all (arxiv) adversarial example papers","year":"2020"},{"key":"ref12","first-page":"274","article-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Athalye"},{"key":"ref13","first-page":"284","article-title":"Synthesizing robust adversarial examples","volume-title":"Int. Conf. Mach. Learn.","author":"Athalye","year":"2018"},{"key":"ref14","article-title":"On adaptive attacks to adversarial example defenses","author":"Tramer","year":"2020"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00669"},{"key":"ref16","article-title":"On evaluating adversarial robustness","author":"Carlini","year":"2019"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-40994-3_25"},{"key":"ref18","article-title":"Discovering adversarial examples with momentum","author":"Dong","year":"2017"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/TEVC.2019.2890858"},{"key":"ref22","article-title":"Learning with a strong adversary","author":"Huang","year":"2015"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2018.04.027"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134057"},{"key":"ref25","article-title":"Generative adversarial trainer: Defense to adversarial perturbations with GAN","author":"Lee","year":"2017"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.32657\/10356\/143316"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v32i1.11504"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.41"},{"key":"ref29","article-title":"MagNet and \u201cefficient defenses against adversarial attacks","author":"Carlini","year":"2017"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1145\/3219819.3219910"},{"key":"ref31","article-title":"Synthesizing robust adversarial examples","author":"Athalye","year":"2017"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00130"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1145\/3359789.3359790"},{"key":"ref34","article-title":"Ensemble adversarial training: Attacks and defenses","author":"Tram\u00e8r","year":"2017"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00095"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/T-C.1974.223784"},{"key":"ref38","article-title":"Countering adversarial images using input transformations","author":"Guo","year":"2017"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23198"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/ICPR.2010.579"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.308"},{"key":"ref42","article-title":"Technical report on the CleverHans v2.1.0 adversarial examples library","author":"Papernot","year":"2018"},{"key":"ref43","article-title":"PixelDefend: Leveraging generative models to understand and defend against adversarial examples","author":"Song","year":"2017"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00191"},{"key":"ref45","first-page":"7025","article-title":"Me-net: Towards effective adversarial robustness with matrix estimation","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Yang","year":"2019"}],"container-title":["IEEE Transactions on Computers"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/12\/10431415\/09420266.pdf?arnumber=9420266","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,2,19]],"date-time":"2024-02-19T20:03:55Z","timestamp":1708373035000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9420266\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,3]]},"references-count":45,"journal-issue":{"issue":"3"},"URL":"https:\/\/doi.org\/10.1109\/tc.2021.3076826","relation":{},"ISSN":["0018-9340","1557-9956","2326-3814"],"issn-type":[{"value":"0018-9340","type":"print"},{"value":"1557-9956","type":"electronic"},{"value":"2326-3814","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,3]]}}}