{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,3]],"date-time":"2025-11-03T19:13:34Z","timestamp":1762197214027,"version":"build-2065373602"},"reference-count":72,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"11","license":[{"start":{"date-parts":[[2025,11,1]],"date-time":"2025-11-01T00:00:00Z","timestamp":1761955200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,11,1]],"date-time":"2025-11-01T00:00:00Z","timestamp":1761955200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,11,1]],"date-time":"2025-11-01T00:00:00Z","timestamp":1761955200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62072112"],"award-info":[{"award-number":["62072112"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100018625","name":"Scientific and Technological Innovation Action Plan of Shanghai Science and Technology Committee","doi-asserted-by":"publisher","award":["22511102202"],"award-info":[{"award-number":["22511102202"]}],"id":[{"id":"10.13039\/501100018625","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Circuits Syst. Video Technol."],"published-print":{"date-parts":[[2025,11]]},"DOI":"10.1109\/tcsvt.2025.3579120","type":"journal-article","created":{"date-parts":[[2025,6,12]],"date-time":"2025-06-12T13:45:11Z","timestamp":1749735911000},"page":"11474-11487","source":"Crossref","is-referenced-by-count":0,"title":["VideoPure: Diffusion-Based Adversarial Purification for Video Recognition"],"prefix":"10.1109","volume":"35","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-2878-0497","authenticated-orcid":false,"given":"Kaixun","family":"Jiang","sequence":"first","affiliation":[{"name":"Shanghai Engineering Research Center of AI Robotics and the Engineering Research Center of AI and Robotics, Ministry of Education, Academy for Engineering and Technology, Fudan University, Shanghai, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7112-2596","authenticated-orcid":false,"given":"Zhaoyu","family":"Chen","sequence":"additional","affiliation":[{"name":"Shanghai Engineering Research Center of AI Robotics and the Engineering Research Center of AI and Robotics, Ministry of Education, Academy for Engineering and Technology, Fudan University, Shanghai, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0005-4832-4631","authenticated-orcid":false,"given":"Jiyuan","family":"Fu","sequence":"additional","affiliation":[{"name":"Shanghai Key Laboratory of Intelligent Information Processing, School of Computer Science, Fudan University, Shanghai, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2749-5133","authenticated-orcid":false,"given":"Lingyi","family":"Hong","sequence":"additional","affiliation":[{"name":"Shanghai Key Laboratory of Intelligent Information Processing, School of Computer Science, Fudan University, Shanghai, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jinglun","family":"Li","sequence":"additional","affiliation":[{"name":"Shanghai Engineering Research Center of AI Robotics and the Engineering Research Center of AI and Robotics, Ministry of Education, Academy for Engineering and Technology, Fudan University, Shanghai, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3339-8751","authenticated-orcid":false,"given":"Wenqiang","family":"Zhang","sequence":"additional","affiliation":[{"name":"Shanghai Engineering Research Center of AI Robotics and the Engineering Research Center of AI and Robotics, Ministry of Education, Academy for Engineering and Technology, and Shanghai Key Laboratory of Intelligent Information Processing, School of Computer Science, Fudan University, Shanghai, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00516"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2022.3147032"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2023.3284038"},{"article-title":"Towards deep learning models resistant to adversarial attacks","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"M\u0105dry","key":"ref5"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/TCSVT.2024.3452475"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/TCSVT.2024.3455799"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/TCSVT.2023.3234266"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/TCSVT.2021.3120479"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1201\/9781351251389-8"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00437"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3465212"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.33018973"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW.2018.00141"},{"article-title":"A system for video surveillance and monitoring","year":"2000","author":"Collins","key":"ref15"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1145\/3219819.3219910"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1145\/3444685.3446308"},{"key":"ref18","article-title":"Uncovering the limits of adversarial training against norm-bounded adversarial examples","author":"Gowal","year":"2020","journal-title":"arXiv:2010.03593"},{"key":"ref19","first-page":"7472","article-title":"Theoretically principled trade-off between robustness and accuracy","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Zhang"},{"key":"ref20","first-page":"4218","article-title":"Improving robustness using generated data","volume-title":"Proc. Adv. Neural Inform. Process. Syst.","author":"Gowal"},{"article-title":"Adversarial machine learning at scale","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Kurakin","key":"ref21"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2024.129124"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2021.3137648"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW56347.2022.00385"},{"article-title":"Defense-GAN: Protecting classifiers against adversarial attacks using generative models","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Samangouei","key":"ref25"},{"article-title":"PixelDefend: Leveraging generative models to understand and defend against adversarial examples","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Song","key":"ref26"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2023.3346064"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1016\/j.neunet.2023.10.033"},{"key":"ref29","first-page":"16805","article-title":"Diffusion models for adversarial purification","volume-title":"Proc. Int. Conf. Mach. Learn. (ICML)","author":"Nie"},{"key":"ref30","first-page":"274","article-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Athalye"},{"key":"ref31","first-page":"284","article-title":"Synthesizing robust adversarial examples","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Athalye"},{"key":"ref32","first-page":"2206","article-title":"Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Croce"},{"key":"ref33","article-title":"Threat model-agnostic adversarial defense using diffusion models","author":"Blau","year":"2022","journal-title":"arXiv:2207.08089"},{"key":"ref34","article-title":"Guided diffusion model for adversarial purification from random noise","author":"Wu","year":"2022","journal-title":"arXiv:2206.10875"},{"key":"ref35","article-title":"Guided diffusion model for adversarial purification","author":"Wang","year":"2022","journal-title":"arXiv:2205.14969"},{"key":"ref36","first-page":"51810","article-title":"Enhancing adversarial robustness via score-based optimization","volume-title":"Proc. Adv. Neural Inform. Process. Syst.","volume":"36","author":"Zhang"},{"key":"ref37","first-page":"6840","article-title":"Denoising diffusion probabilistic models","volume-title":"Proc. NIPS","volume":"33","author":"Ho"},{"key":"ref38","article-title":"ModelScope text-to-video technical report","volume-title":"arXiv:2308.06571","author":"Wang","year":"2023"},{"article-title":"Denoising diffusion implicit models","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Song","key":"ref39"},{"article-title":"Intriguing properties of neural networks","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Szegedy","key":"ref40"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v36i1.19907"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00404"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/TMM.2024.3521832"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v36i3.20168"},{"key":"ref45","first-page":"2085","article-title":"Adversarial attacks on black box video classifiers: Leveraging the power of geometric transformations","volume-title":"Proc. Adv. Neural Inform. Process. Syst.","volume":"34","author":"Li"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1145\/3343031.3351088"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01464"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58565-5_15"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1145\/3581783.3611828"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1109\/TCSVT.2023.3341170"},{"key":"ref51","article-title":"Adam: A method for stochastic optimization","author":"Kingma","year":"2014","journal-title":"arXiv:1412.6980"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00757"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00058"},{"key":"ref54","first-page":"73919","article-title":"DiffAttack: Evasion attacks against diffusion-based adversarial purification","volume-title":"Proc. Adv. Neural Inform. Process. Syst.","volume":"36","author":"Kang"},{"key":"ref55","article-title":"Explaining and harnessing adversarial examples","author":"Goodfellow","year":"2014","journal-title":"arXiv:1412.6572"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2019.2940533"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01268"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.00585"},{"article-title":"Content-based unrestricted adversarial attack","volume-title":"Proc. Adv. Neural Inform. Process. Syst.","author":"Chen","key":"ref59"},{"key":"ref60","article-title":"Diffusion model-based image editing: A survey","author":"Huang","year":"2024","journal-title":"arXiv:2402.17525"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1109\/iccv51070.2023.01462"},{"key":"ref62","article-title":"Motion-guided latent diffusion for temporally consistent real-world video super-resolution","author":"Yang","year":"2023","journal-title":"arXiv:2312.00853"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1212.0402"},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.502"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00813"},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00630"},{"key":"ref67","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58536-5_24"},{"article-title":"Towards understanding the robustness of diffusion-based purification: A stochastic perspective","volume-title":"Proc. 13th Int. Conf. Learn. Represent.","author":"Liu","key":"ref68"},{"key":"ref69","article-title":"Boosting adversarial attacks with momentum","author":"Dong","year":"2017","journal-title":"arXiv:1710.06081"},{"key":"ref70","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01042"},{"key":"ref71","first-page":"8780","article-title":"Diffusion models beat GANs on image synthesis","volume-title":"Proc. NIPS","volume":"34","author":"Dhariwal"},{"key":"ref72","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.74"}],"container-title":["IEEE Transactions on Circuits and Systems for Video Technology"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/76\/11223720\/11031449.pdf?arnumber=11031449","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,11,3]],"date-time":"2025-11-03T18:47:11Z","timestamp":1762195631000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11031449\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,11]]},"references-count":72,"journal-issue":{"issue":"11"},"URL":"https:\/\/doi.org\/10.1109\/tcsvt.2025.3579120","relation":{},"ISSN":["1051-8215","1558-2205"],"issn-type":[{"type":"print","value":"1051-8215"},{"type":"electronic","value":"1558-2205"}],"subject":[],"published":{"date-parts":[[2025,11]]}}}