{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,30]],"date-time":"2026-04-30T16:34:46Z","timestamp":1777566886814,"version":"3.51.4"},"reference-count":59,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"6","license":[{"start":{"date-parts":[[2022,11,1]],"date-time":"2022-11-01T00:00:00Z","timestamp":1667260800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2022,11,1]],"date-time":"2022-11-01T00:00:00Z","timestamp":1667260800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2022,11,1]],"date-time":"2022-11-01T00:00:00Z","timestamp":1667260800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62072406"],"award-info":[{"award-number":["62072406"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Natural Science Foundation of Zhejiang Provincial","award":["LY19F020025"],"award-info":[{"award-number":["LY19F020025"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Dependable and Secure Comput."],"published-print":{"date-parts":[[2022,11,1]]},"DOI":"10.1109\/tdsc.2021.3124337","type":"journal-article","created":{"date-parts":[[2021,11,2]],"date-time":"2021-11-02T21:30:13Z","timestamp":1635888613000},"page":"4204-4224","source":"Crossref","is-referenced-by-count":26,"title":["GRIP-GAN: An Attack-Free Defense Through General Robust Inverse Perturbation"],"prefix":"10.1109","volume":"19","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-8997-5343","authenticated-orcid":false,"given":"Haibin","family":"Zheng","sequence":"first","affiliation":[{"name":"College of Information Engineering, Zhejiang University of Technology, Hangzhou, Zhejiang, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7153-2755","authenticated-orcid":false,"given":"Jinyin","family":"Chen","sequence":"additional","affiliation":[{"name":"Institute of Cyberspace Security and the College of Information Engineering, Zhejiang University of Technology, Hangzhou, Zhejiang, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hang","family":"Du","sequence":"additional","affiliation":[{"name":"College of System Engineering, National University of Defense Technology, Changsha, Hunan, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Weipeng","family":"Zhu","sequence":"additional","affiliation":[{"name":"College of Computer Science and Technology, Soochow University, Suzhou, Jiangsu, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4268-372X","authenticated-orcid":false,"given":"Shouling","family":"Ji","sequence":"additional","affiliation":[{"name":"College of Computer Science and Technology, Zhejiang University, Hangzhou, Zhejiang, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xuhong","family":"Zhang","sequence":"additional","affiliation":[{"name":"College of Control Science and Engineering, Zhejiang University, Hangzhou, Zhejiang, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref39","first-page":"1","article-title":"Very deep convolutional networks for large-scale image recognition","author":"simonyan","year":"2015","journal-title":"Proc 3rd Int Conf Learn Representations"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2021.102220"},{"key":"ref33","article-title":"Learning multiple layers of features from tiny images","author":"alex","year":"2009"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1162\/neco.1989.1.4.541"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00068"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00348"},{"key":"ref37","first-page":"2672","article-title":"Generative adversarial nets","author":"goodfellow","year":"2014","journal-title":"Proc Annual Conf Neural Inf Process Syst"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-10590-1_53"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2011.6126474"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.7557\/18.5173"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00283"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.01171"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cosrev.2019.100203"},{"key":"ref1","doi-asserted-by":"crossref","first-page":"436","DOI":"10.1038\/nature14539","article-title":"Deep learning","volume":"521","author":"lecun","year":"2015","journal-title":"Nature"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1080\/02664763.2018.1441383"},{"key":"ref22","first-page":"1","article-title":"Defense-GAN: Protecting classifiers against adversarial attacks using generative models","author":"samangouei","year":"2018","journal-title":"Proc 6th Int Conf Learn Representations"},{"key":"ref21","first-page":"4579","article-title":"Towards robust detection of adversarial examples","author":"pang","year":"2018","journal-title":"Proc Annu Conf Neural Inf Process Syst"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.17"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00669"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2018.2874243"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.74"},{"key":"ref50","first-page":"1","article-title":"Decision-based adversarial attacks: Reliable attacks against black-box machine learning models","author":"brendel","year":"2018","journal-title":"Proc 6th Int Conf Learn Representations"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140448"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.26599\/TST.2020.9010038"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2021.01.035"},{"key":"ref57","first-page":"274","article-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","author":"athalye","year":"2018","journal-title":"Proc 35th Int Conf Mach Learn"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58592-1_29"},{"key":"ref55","article-title":"Gaussian blur attack in foolbox tool","author":"jonas","year":"2020"},{"key":"ref54","article-title":"Salt and pepper noise attack in foolbox tool","author":"jonas","year":"2020"},{"key":"ref53","article-title":"Additive uniform noise attack in foolbox tool","author":"jonas","year":"2020"},{"key":"ref52","article-title":"Additive gaussian noise attack in foolbox tool","author":"jonas","year":"2020"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/TIM.2020.2992873"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2019.2949358"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.308"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2020.04.019"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2020.101916"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00503"},{"key":"ref15","first-page":"1","article-title":"Countering adversarial images using input transformations","author":"guo","year":"2018","journal-title":"Proc 6th Int Conf Learn Representations"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP.2019.8683044"},{"key":"ref17","first-page":"1","article-title":"Towards deep neural network architectures robust to adversarial examples","author":"gu","year":"2015","journal-title":"Proc 3rd Int Conf Learn Representations"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00191"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.41"},{"key":"ref4","first-page":"173","article-title":"Invisible poisoning: Highly stealthy targeted poisoning attack","author":"chen","year":"2019","journal-title":"Proc 15th Int Conf Inf Secur Cryptol"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1021\/acs.iecr.0c02398"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1007\/s11432-018-9704-7"},{"key":"ref5","first-page":"4171","article-title":"Bert: Pre-training of deep bidirectional transformers for language understanding","author":"devlin","year":"2019","journal-title":"Proc Conf North Amer Chapter Assoc Comput Linguistics Human Lang Technol"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/IVS.2018.8500504"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/TCSS.2019.2914935"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1145\/3134600.3134635"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1007\/s00521-018-3689-5"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"ref45","first-page":"1","article-title":"Towards deep learning models resistant to adversarial attacks","author":"madry","year":"2018","journal-title":"Proc 6th Int Conf Learn Representations"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref42","first-page":"1","article-title":"Explaining and harnessing adversarial examples","author":"goodfellow","year":"2015","journal-title":"Proc 3rd Int Conf Learn Representations"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2807385"},{"key":"ref44","first-page":"1","article-title":"Adversarial examples in the physical world","author":"kurakin","year":"2017","journal-title":"Proc 5th Int Conf Learn Representations"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN.2016.7727230"}],"container-title":["IEEE Transactions on Dependable and Secure Computing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/8858\/9945627\/09599477.pdf?arnumber=9599477","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,12,12]],"date-time":"2022-12-12T19:24:46Z","timestamp":1670873086000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9599477\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,11,1]]},"references-count":59,"journal-issue":{"issue":"6"},"URL":"https:\/\/doi.org\/10.1109\/tdsc.2021.3124337","relation":{},"ISSN":["1545-5971","1941-0018","2160-9209"],"issn-type":[{"value":"1545-5971","type":"print"},{"value":"1941-0018","type":"electronic"},{"value":"2160-9209","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,11,1]]}}}