{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,14]],"date-time":"2026-03-14T17:54:58Z","timestamp":1773510898279,"version":"3.50.1"},"reference-count":51,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"4","license":[{"start":{"date-parts":[[2023,7,1]],"date-time":"2023-07-01T00:00:00Z","timestamp":1688169600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62076054"],"award-info":[{"award-number":["62076054"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62072074"],"award-info":[{"award-number":["62072074"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62027827"],"award-info":[{"award-number":["62027827"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61902054"],"award-info":[{"award-number":["61902054"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62002047"],"award-info":[{"award-number":["62002047"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Frontier Science and Technology Innovation Projects of National Key R&amp;D Program","award":["2019QY1405"],"award-info":[{"award-number":["2019QY1405"]}]},{"name":"Sichuan Science and Technology Innovation Platform and Talent Plan","award":["2020JDJQ0020"],"award-info":[{"award-number":["2020JDJQ0020"]}]},{"name":"Sichuan Science and Technology Innovation Platform and Talent Plan","award":["2022JDJQ0039"],"award-info":[{"award-number":["2022JDJQ0039"]}]},{"name":"Sichuan Science and Technology Support Plan","award":["2020YFSY0010"],"award-info":[{"award-number":["2020YFSY0010"]}]},{"name":"Sichuan Science and Technology Support Plan","award":["2022YFQ0045"],"award-info":[{"award-number":["2022YFQ0045"]}]},{"name":"Sichuan Science and Technology Support Plan","award":["2022YFS0220"],"award-info":[{"award-number":["2022YFS0220"]}]},{"name":"Sichuan Science and Technology Support Plan","award":["2019YJ0636"],"award-info":[{"award-number":["2019YJ0636"]}]},{"name":"Sichuan Science and Technology Support Plan","award":["2021YFG0131"],"award-info":[{"award-number":["2021YFG0131"]}]},{"name":"Medico-Engineering Cooperation Funds from University of Electronic Science and Technology of China","award":["ZYGX2021YGLH212"],"award-info":[{"award-number":["ZYGX2021YGLH212"]}]},{"name":"Medico-Engineering Cooperation Funds from University of Electronic Science and Technology of China","award":["ZYGX2022YGRH012"],"award-info":[{"award-number":["ZYGX2022YGRH012"]}]},{"name":"Cloud Technology Endowed Professorship"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Dependable and Secure Comput."],"published-print":{"date-parts":[[2023,7,1]]},"DOI":"10.1109\/tdsc.2022.3202544","type":"journal-article","created":{"date-parts":[[2022,8,29]],"date-time":"2022-08-29T21:05:43Z","timestamp":1661807143000},"page":"3392-3407","source":"Crossref","is-referenced-by-count":16,"title":["Interpreting Universal Adversarial Example Attacks on Image Classification Models"],"prefix":"10.1109","volume":"20","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-3406-9770","authenticated-orcid":false,"given":"Yi","family":"Ding","sequence":"first","affiliation":[{"name":"Network and Data Security Key Laboratory of Sichuan Province, School of Information and Software Engineering, University of Electronic Science and Technology of China, Chengdu, Sichuan, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8682-1138","authenticated-orcid":false,"given":"Fuyuan","family":"Tan","sequence":"additional","affiliation":[{"name":"Network and Data Security Key Laboratory of Sichuan Province, School of Information and Software Engineering, University of Electronic Science and Technology of China, Chengdu, Sichuan, China"}]},{"given":"Ji","family":"Geng","sequence":"additional","affiliation":[{"name":"Network and Data Security Key Laboratory of Sichuan Province, School of Information and Software Engineering, University of Electronic Science and Technology of China, Chengdu, Sichuan, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7857-9719","authenticated-orcid":false,"given":"Zhen","family":"Qin","sequence":"additional","affiliation":[{"name":"Network and Data Security Key Laboratory of Sichuan Province, School of Information and Software Engineering, University of Electronic Science and Technology of China, Chengdu, Sichuan, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0691-2724","authenticated-orcid":false,"given":"Mingsheng","family":"Cao","sequence":"additional","affiliation":[{"name":"Network and Data Security Key Laboratory of Sichuan Province, School of Information and Software Engineering, University of Electronic Science and Technology of China, Chengdu, Sichuan, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9208-5336","authenticated-orcid":false,"given":"Kim-Kwang Raymond","family":"Choo","sequence":"additional","affiliation":[{"name":"Department of Information Systems and Cyber Security, University of Texas at San Antonio, San Antonio, TX, USA"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6745-6377","authenticated-orcid":false,"given":"Zhiguang","family":"Qin","sequence":"additional","affiliation":[{"name":"Network and Data Security Key Laboratory of Sichuan Province, School of Information and Software Engineering, University of Electronic Science and Technology of China, Chengdu, Sichuan, China"}]}],"member":"263","reference":[{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140448"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/TEVC.2019.2890858"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.17"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"ref17","article-title":"Characterizing adversarial subspaces using local intrinsic dimensionality","author":"ma","year":"2018"},{"key":"ref16","article-title":"Thermometer encoding: One hot way to resist adversarial examples","author":"buckman","year":"2018","journal-title":"Proc Int Conf Learn Representations"},{"key":"ref19","article-title":"Stochastic activation pruning for robust adversarial defense","author":"dhillon","year":"2018"},{"key":"ref18","article-title":"Countering adversarial images using input transformations","author":"guo","year":"2017"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1097\/JTO.0b013e3181ec173d"},{"key":"ref50","article-title":"Towards deep learning models resistant to adversarial attacks","author":"madry","year":"2017"},{"key":"ref46","first-page":"3358","article-title":"Adversarial training for free!","author":"shafahi","year":"2019","journal-title":"Proc Int Conf Neural Inf Process"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23415"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00444"},{"key":"ref47","article-title":"Rethinking natural adversarial examples for classification models","author":"li","year":"2021"},{"key":"ref42","first-page":"8930","article-title":"This looks like that: Deep learning for interpretable image recognition","author":"chen","year":"2019","journal-title":"Proc Int Conf Neural Inf Process"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2018.2858759"},{"key":"ref44","first-page":"7717","article-title":"Attacks meet interpretability: Attribute-steered detection of adversarial examples","author":"tao","year":"2018","journal-title":"Proc Int Conf Neural Inf Process"},{"key":"ref43","article-title":"Improving the adversarial robustness and interpretability of deep neural networks by regularizing their input gradients","author":"ross","year":"2017"},{"key":"ref49","article-title":"Spatially transformed adversarial examples","author":"xiao","year":"2018"},{"key":"ref8","article-title":"Explaining and harnessing adversarial examples","author":"goodfellow","year":"2014"},{"key":"ref7","article-title":"Intriguing properties of neural networks","author":"szegedy","year":"2013"},{"key":"ref9","article-title":"Adversarial examples in the physical world","author":"kurakin","year":"2016"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/JBHI.2021.3122328"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2021.3062754"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.2981380"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2021.07.066"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00920"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134057"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref37","first-page":"7167","article-title":"A simple unified framework for detecting out-of-distribution examples and adversarial attacks","author":"lee","year":"2018","journal-title":"Proc Int Conf Neural Inf Process"},{"key":"ref36","article-title":"Detecting adversarial examples from artifacts","author":"feinman","year":"2017"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i13.17390"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00642"},{"key":"ref33","article-title":"DAmageNet: A universal adversarial dataset","author":"chen","year":"2019"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1145\/3394486.3403241"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1016\/j.media.2019.02.010"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.683"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.371"},{"key":"ref38","article-title":"Feature squeezing: Detecting adversarial examples in deep neural networks","author":"xu","year":"2017"},{"key":"ref24","article-title":"Tensorflow\/lucid: A collection of infrastructure and tools for research in neural network interpretability","author":"schubert","year":"0","journal-title":"Github"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1016\/j.visinf.2017.01.006"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.319"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1145\/2939672.2939778"},{"key":"ref20","article-title":"Mitigating adversarial effects through randomization","author":"xie","year":"2017"},{"key":"ref22","article-title":"Towards deep learning models resistant to adversarial attacks","author":"madry","year":"2017"},{"key":"ref21","article-title":"PixelDefend: Leveraging generative models to understand and defend against adversarial examples","author":"song","year":"2017"},{"key":"ref28","article-title":"Interpreting CNN knowledge via an explanatory graph","author":"zhang","year":"2017"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.74"},{"key":"ref29","article-title":"DLIME: A deterministic local interpretable model-agnostic explanations approach for computer-aided diagnosis systems","author":"zafar","year":"2019"}],"container-title":["IEEE Transactions on Dependable and Secure Computing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/8858\/10177761\/09869709.pdf?arnumber=9869709","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,8,1]],"date-time":"2023-08-01T18:36:47Z","timestamp":1690915007000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9869709\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,7,1]]},"references-count":51,"journal-issue":{"issue":"4"},"URL":"https:\/\/doi.org\/10.1109\/tdsc.2022.3202544","relation":{},"ISSN":["1545-5971","1941-0018","2160-9209"],"issn-type":[{"value":"1545-5971","type":"print"},{"value":"1941-0018","type":"electronic"},{"value":"2160-9209","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,7,1]]}}}