{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,20]],"date-time":"2026-02-20T18:11:01Z","timestamp":1771611061230,"version":"3.50.1"},"reference-count":73,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U1836217"],"award-info":[{"award-number":["U1836217"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62006225"],"award-info":[{"award-number":["62006225"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61622310"],"award-info":[{"award-number":["61622310"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62071468"],"award-info":[{"award-number":["62071468"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100002367","name":"Strategic Priority Research Program of Chinese Academy of Sciences through the CAAI-Huawei Mindspore Open Fund","doi-asserted-by":"publisher","award":["XDA27040700"],"award-info":[{"award-number":["XDA27040700"]}],"id":[{"id":"10.13039\/501100002367","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2022]]},"DOI":"10.1109\/tifs.2022.3195384","type":"journal-article","created":{"date-parts":[[2022,8,5]],"date-time":"2022-08-05T00:21:30Z","timestamp":1659658890000},"page":"2947-2962","source":"Crossref","is-referenced-by-count":23,"title":["Perturbation Inactivation Based Adversarial Defense for Face Recognition"],"prefix":"10.1109","volume":"17","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-0126-1726","authenticated-orcid":false,"given":"Min","family":"Ren","sequence":"first","affiliation":[{"name":"School of Artificial Intelligence, University of Chinese Academy of Sciences, Beijing, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0776-3719","authenticated-orcid":false,"given":"Yuhao","family":"Zhu","sequence":"additional","affiliation":[{"name":"Postgraduate Department, China Academy of Railway Sciences, Beijing, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3535-308X","authenticated-orcid":false,"given":"Yunlong","family":"Wang","sequence":"additional","affiliation":[{"name":"National Laboratory of Pattern Recognition, Center for Research on Intelligent Perception and Computing, Institute of Automation, Chinese Academy of Sciences, Beijing, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4029-9935","authenticated-orcid":false,"given":"Zhenan","family":"Sun","sequence":"additional","affiliation":[{"name":"National Laboratory of Pattern Recognition, Center for Research on Intelligent Perception and Computing, Institute of Automation, Chinese Academy of Sciences, Beijing, China"}]}],"member":"263","reference":[{"key":"ref73","first-page":"1","article-title":"Auto-encoding variational Bayes","author":"kingma","year":"2014","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref72","first-page":"234","article-title":"U-Net: Convolutional networks for biomedical image segmentation","author":"olaf","year":"2015","journal-title":"Proc Int Conf Med Image Comput Comput -Assist Intervent"},{"key":"ref71","first-page":"1","article-title":"Adversarial examples in the physical world","author":"kurakin","year":"2017","journal-title":"Proc Int Conf Learn Represent Workshop"},{"key":"ref70","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00059"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00348"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00498"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.41"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978392"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/TEVC.2019.2890858"},{"key":"ref30","first-page":"1","article-title":"Towards deep learning models resistant to adversarial attacks","author":"madry","year":"2018","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00068"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00283"},{"key":"ref35","article-title":"Generative adversarial trainer: Defense to adversarial perturbations with GAN","author":"lee","year":"2017","journal-title":"arXiv 1705 03387"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1145\/3134600.3134606"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2020.3036801"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00754"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00777"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00765"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00707"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2018.2833032"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00758"},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00778"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref67","first-page":"274","article-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","author":"anish","year":"2018","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00284"},{"key":"ref69","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00191"},{"key":"ref2","first-page":"1","article-title":"ImageNet classification with deep convolutional neural networks","author":"krizhevsky","year":"2012","journal-title":"Proc Int Conf Neural Inf Process"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2014.244"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.713"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298682"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00552"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00482"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/ICPR48806.2021.9412236"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00790"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-25958-1_8"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.527"},{"key":"ref59","year":"2020","journal-title":"Transferable Adversarial LFW"},{"key":"ref58","year":"2020","journal-title":"Face++ Research Toolkit"},{"key":"ref57","year":"2020","journal-title":"Baidu cloud vision api"},{"key":"ref56","year":"2020","journal-title":"Microsoft Azure"},{"key":"ref55","year":"2020","journal-title":"Amazon&#x2019;s rekognition tool"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1007\/BF00992696"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01225-0_9"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1109\/WACV.2016.7477558"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298965"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.322"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00665"},{"key":"ref12","first-page":"1","article-title":"Intriguing properties of neural networks","author":"szegedy","year":"2014","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref13","first-page":"1","article-title":"Explaining and harnessing adversarial examples","author":"ian goodfellow","year":"2015","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.17"},{"key":"ref15","first-page":"1","article-title":"Adversarial machine learning at scale","author":"kurakin","year":"2017","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref16","first-page":"1","article-title":"Cascade adversarial machine learning regularized with a unified embedding","author":"taesik","year":"2018","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref17","first-page":"1","article-title":"Ensemble adversarial training: Attacks and defenses","author":"florian","year":"2018","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref18","first-page":"1","article-title":"Improving the adversarial robustness and interpretability of deep neural networks by regularizing their input gradients","author":"florian","year":"2018","journal-title":"Proc 32nd AAAI Conf Artif Intell 13th Innov Appl Artif Intell Conf"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2014.220"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298594"},{"key":"ref3","first-page":"1","article-title":"Very deep convolutional networks for large-scale image recognition","author":"simonyan","year":"2015","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00745"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.243"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2015.169"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00681"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.91"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00488"},{"key":"ref45","first-page":"1","article-title":"PixelDefend: Leveraging generative models to understand and defend against adversarial examples","author":"yang","year":"2018","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.01171"},{"key":"ref47","article-title":"Divide, denoise, and defend against adversarial attacks","author":"moosavi-dezfooli","year":"2018","journal-title":"arXiv 1802 06806"},{"key":"ref42","first-page":"1","article-title":"Countering adversarial images using input transformations","author":"guo","year":"2018","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref41","article-title":"Keeping the bad guys out: Protecting and vaccinating deep learning with JPEG compression","author":"das","year":"2017","journal-title":"arXiv 1705 02900"},{"key":"ref44","first-page":"1","article-title":"PixelCNN++: Improving the PixelCNN with discretized logistic mixture likelihood and other modifications","author":"salimans","year":"2017","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134057"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/10206\/9652463\/09845464.pdf?arnumber=9845464","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,10,10]],"date-time":"2022-10-10T20:08:31Z","timestamp":1665432511000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9845464\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022]]},"references-count":73,"URL":"https:\/\/doi.org\/10.1109\/tifs.2022.3195384","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"value":"1556-6013","type":"print"},{"value":"1556-6021","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022]]}}}