{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,26]],"date-time":"2026-03-26T16:14:45Z","timestamp":1774541685867,"version":"3.50.1"},"reference-count":50,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"5","license":[{"start":{"date-parts":[[2025,9,1]],"date-time":"2025-09-01T00:00:00Z","timestamp":1756684800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,9,1]],"date-time":"2025-09-01T00:00:00Z","timestamp":1756684800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,9,1]],"date-time":"2025-09-01T00:00:00Z","timestamp":1756684800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Dependable and Secure Comput."],"published-print":{"date-parts":[[2025,9]]},"DOI":"10.1109\/tdsc.2025.3560246","type":"journal-article","created":{"date-parts":[[2025,4,11]],"date-time":"2025-04-11T14:08:50Z","timestamp":1744380530000},"page":"5047-5059","source":"Crossref","is-referenced-by-count":4,"title":["MTD-AD: Moving Target Defense as Adversarial Defense"],"prefix":"10.1109","volume":"22","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-5585-6859","authenticated-orcid":false,"given":"Ke","family":"He","sequence":"first","affiliation":[{"name":"CSSE Department, University of Canterbury, Christchurch, New Zealand"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2605-187X","authenticated-orcid":false,"given":"Dan Dongseong","family":"Kim","sequence":"additional","affiliation":[{"name":"School of EECS, The University of Queensland, Brisbane, QLD, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9607-376X","authenticated-orcid":false,"given":"Muhammad Rizwan","family":"Asghar","sequence":"additional","affiliation":[{"name":"Department of Computer Science, University of Surrey, Guildford, U.K."}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","article-title":"YOLOv4: Optimal speed and accuracy of object detection","author":"Bochkovskiy","year":"2020"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.21437\/interspeech.2014-80"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1007\/978-981-19-8991-9_29"},{"key":"ref4","article-title":"Intriguing properties of neural networks","volume-title":"Proc. 2nd Int. Conf. Learn. Representations","author":"Szegedy"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/jsac.2021.3087242"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1145\/3359992.3366642"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM42981.2021.9488874"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/ICCCN52240.2021.9522215"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1016\/j.future.2022.08.011"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/CISDA.2009.5356528"},{"key":"ref11","article-title":"Liuer mihou: A practical framework for generating and evaluating grey-box adversarial attacks against nids","author":"He","year":"2022"},{"key":"ref12","article-title":"Kitsune-py","author":"Mirsky","year":"2020"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1145\/3339252.3339266"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2019.2963791"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/jiot.2025.3533016"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"ref18","article-title":"Towards deep learning models resistant to adversarial attacks","volume-title":"Proc. 6th Int. Conf. Learn. Representations","author":"Madry"},{"key":"ref19","doi-asserted-by":"crossref","DOI":"10.14722\/ndss.2018.23204","article-title":"Kitsune: An ensemble of autoencoders for online network intrusion detection","volume-title":"Proc. 25th Annu. Netw. Distrib. Syst. Secur. Symp.","author":"Mirsky"},{"key":"ref20","article-title":"Scapy","year":"2022"},{"key":"ref21","article-title":"Wireshark. go deep","author":"Team","year":"2022"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2010.25"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/GLOBECOM38437.2019.9014337"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-05981-0_7"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2021.115782"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2023.103176"},{"key":"ref27","article-title":"Detecting adversarial samples from artifacts","author":"Feinman","year":"2017"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1145\/3411495.3421359"},{"key":"ref29","article-title":"RAIDS: Robust autoencoder-based intrusion detection system model against adversarial attacks","volume-title":"Comput. Secur.","volume":"135","author":"Sarikaya","year":"2023"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2023.3237604"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-32430-8_28"},{"key":"ref32","article-title":"$n$n-ML: Mitigating adversarial examples via ensembles of topologically manipulated classifiers","author":"Sharif","year":"2019"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/ACCTCS58815.2023.00115"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"ref35","article-title":"Transferability in machine learning: From phenomena to black-box attacks using adversarial samples","author":"Papernot","year":"2016"},{"key":"ref36","first-page":"321","article-title":"Why do adversarial attacks transfer? Explaining transferability of evasion and poisoning attacks","volume-title":"Proc. 28th USENIX Secur. Symp.","author":"Demontis"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.4324\/9781410605337-29"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.5220\/0006639801080116"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1145\/3517806"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/MILCOM52596.2021.9652915"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2022.3233793"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/ISI.2013.6578785"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1145\/3356250.3360025"},{"key":"ref44","article-title":"EMPIR: Ensembles of mixed precision deep networks for increased robustness against adversarial attacks","volume-title":"Proc. 8th Int. Conf. Learn. Representations","author":"Sen"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2019.00126"},{"key":"ref46","article-title":"UQ IoT IDS dataset 2021","author":"He","year":"2022"},{"key":"ref47","article-title":"LOIC","year":"2019"},{"key":"ref48","volume-title":"Computer Networking for LANs to WANs: Hardware, Software and Security","author":"Mansfield","year":"2009"},{"key":"ref49","first-page":"274","article-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","volume-title":"Proc. 35th Int. Conf. Mach. Learn.","author":"Athalye"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1016\/j.proeng.2011.08.800"}],"container-title":["IEEE Transactions on Dependable and Secure Computing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/8858\/11150357\/10962442.pdf?arnumber=10962442","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,9,5]],"date-time":"2025-09-05T18:28:03Z","timestamp":1757096883000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10962442\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,9]]},"references-count":50,"journal-issue":{"issue":"5"},"URL":"https:\/\/doi.org\/10.1109\/tdsc.2025.3560246","relation":{},"ISSN":["1545-5971","1941-0018","2160-9209"],"issn-type":[{"value":"1545-5971","type":"print"},{"value":"1941-0018","type":"electronic"},{"value":"2160-9209","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,9]]}}}