{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,4]],"date-time":"2026-07-04T17:07:14Z","timestamp":1783184834037,"version":"3.54.6"},"reference-count":37,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100000923","name":"Australian Government through the Australian Research Council","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100000923","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100005014","name":"Northrop Grumman Mission Systems\u2019 Basic Research Program","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100005014","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2021]]},"DOI":"10.1109\/tifs.2021.3058771","type":"journal-article","created":{"date-parts":[[2021,2,13]],"date-time":"2021-02-13T01:52:55Z","timestamp":1613181175000},"page":"2566-2578","source":"Crossref","is-referenced-by-count":30,"title":["Defending Support Vector Machines Against Data Poisoning Attacks"],"prefix":"10.1109","volume":"16","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-7060-2021","authenticated-orcid":false,"given":"Sandamal","family":"Weerasinghe","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Tansu","family":"Alpcan","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0885-0643","authenticated-orcid":false,"given":"Sarah M.","family":"Erfani","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Christopher","family":"Leckie","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2010.2051543"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1201\/9781315140919"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/ICDMW.2013.139"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1145\/361002.361007"},{"key":"ref37","first-page":"274","article-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","author":"athalye","year":"2018","journal-title":"Proc 35th Int Conf Mach Learn"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/LCN.2018.8638065"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.4108\/ICST.SIMUTOOLS2008.3027"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2019.2934069"},{"key":"ref10","first-page":"1","article-title":"Characterizing adversarial subspaces using local intrinsic dimensionality","author":"ma","year":"2018","journal-title":"Proc 6th Int Conf Learn Represent (ICLR)"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-68474-1_5"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-68474-1_6"},{"key":"ref13","first-page":"3355","article-title":"Dimensionality-driven learning with noisy labels","volume":"80","author":"ma","year":"2018","journal-title":"Proc 35th Int Conf Mach Learn"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2013.2292894"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2013.57"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1007\/s10462-010-9156-z"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1007\/BF03192573"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1145\/860435.860471"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/TSMCB.2012.2223460"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1145\/2783258.2783405"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2019.2956591"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1142\/S0218001407005703"},{"key":"ref3","first-page":"1467","article-title":"Poisoning attacks against support vector machines","author":"biggio","year":"2012","journal-title":"Proc 29th Int Conf Mach Learn (ICML)"},{"key":"ref6","first-page":"3517","article-title":"Certified defenses for data poisoning attacks","author":"steinhardt","year":"2017","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref29","author":"omohundro","year":"1989","journal-title":"Five balltree construction algorithms"},{"key":"ref5","doi-asserted-by":"crossref","first-page":"1019","DOI":"10.1109\/ICDSP.2002.1028263","article-title":"On-road vehicle detection using Gabor filters and support vector machines","volume":"2","author":"sun","year":"2002","journal-title":"Proc 14th Int Conf Digit Signal Process (DSP)"},{"key":"ref8","first-page":"97","article-title":"Support vector machines under adversarial label noise","author":"biggio","year":"2011","journal-title":"Proc Asian Conf Mach Learn"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1023\/A:1018628609742"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1145\/1014052.1014066"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/WIFS.2017.8267651"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.2200\/S00861ED1V01Y201806AIM039"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2012.11.023"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2015.2456899"},{"key":"ref21","first-page":"1196","article-title":"Learning with noisy labels","author":"natarajan","year":"2013","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref24","article-title":"Curie: A method for protecting SVM classifier from poisoning attack","author":"laishram","year":"2016","journal-title":"arXiv 1606 01584"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1145\/2339530.2339697"},{"key":"ref26","article-title":"A general retraining framework for scalable adversarial classification","author":"li","year":"2016","journal-title":"arXiv 1604 02606"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2014.08.081"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/10206\/9151439\/09352750.pdf?arnumber=9352750","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,5,10]],"date-time":"2022-05-10T14:52:42Z","timestamp":1652194362000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9352750\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021]]},"references-count":37,"URL":"https:\/\/doi.org\/10.1109\/tifs.2021.3058771","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"value":"1556-6013","type":"print"},{"value":"1556-6021","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021]]}}}