{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,28]],"date-time":"2025-11-28T18:51:26Z","timestamp":1764355886551,"version":"3.46.0"},"reference-count":65,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U24B20182","62472158","62102337"],"award-info":[{"award-number":["U24B20182","62472158","62102337"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"Young Elite Scientists Sponsorship Program by Chinese Academy of Science and Technology","doi-asserted-by":"publisher","award":["2023QNRC001"],"award-info":[{"award-number":["2023QNRC001"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Science and Technology Innovation Program of Hunan Province","award":["2024RC3102"],"award-info":[{"award-number":["2024RC3102"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2025]]},"DOI":"10.1109\/tifs.2025.3629619","type":"journal-article","created":{"date-parts":[[2025,11,6]],"date-time":"2025-11-06T18:52:08Z","timestamp":1762455128000},"page":"12476-12490","source":"Crossref","is-referenced-by-count":0,"title":["Toward Defending Adversarial Patch Attacks With Mask-Reconstruction-Assisted Adversarial Training"],"prefix":"10.1109","volume":"20","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-5899-0962","authenticated-orcid":false,"given":"Hongshan","family":"Yang","sequence":"first","affiliation":[{"name":"State Key Laboratory of Blockchain and Data Security, the School of Cyber Science and Technology, and the College of Computer Science and Technology, Zhejiang University, Hangzhou, China"}]},{"given":"Zhichao","family":"Li","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Blockchain and Data Security, the School of Cyber Science and Technology, and the College of Computer Science and Technology, Zhejiang University, Hangzhou, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5804-3279","authenticated-orcid":false,"given":"Zhibo","family":"Wang","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Blockchain and Data Security, the School of Cyber Science and Technology, and the College of Computer Science and Technology, Zhejiang University, Hangzhou, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6221-8142","authenticated-orcid":false,"given":"Peng","family":"Sun","sequence":"additional","affiliation":[{"name":"College of Computer Science and Electronic Engineering, Hunan University, Changsha, China"}]},{"given":"Zhixuan","family":"Chu","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Blockchain and Data Security, the School of Cyber Science and Technology, and the College of Computer Science and Technology, Zhejiang University, Hangzhou, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5240-5200","authenticated-orcid":false,"given":"Feng","family":"Lin","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Blockchain and Data Security, the School of Cyber Science and Technology, and the College of Computer Science and Technology, Zhejiang University, Hangzhou, China"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/TITS.2023.3236274"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2807385"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2021.3127960"},{"key":"ref4","article-title":"Intriguing properties of neural networks","author":"Szegedy","year":"2013","journal-title":"arXiv:1312.6199"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00754"},{"key":"ref8","first-page":"51719","article-title":"Content-based unrestricted adversarial attack","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Chen"},{"key":"ref9","article-title":"Adversarial patch","author":"Brown","year":"2017","journal-title":"arXiv:1712.09665"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW.2019.00012"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00775"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978392"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01295"},{"key":"ref14","article-title":"Adversarial examples that fool detectors","author":"Lu","year":"2017","journal-title":"arXiv:1712.02494"},{"key":"ref15","article-title":"Robust physical-world attacks on deep learning models","author":"Eykholt","year":"2017","journal-title":"arXiv:1707.08945"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00108"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1145\/3317611"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01167"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58558-7_39"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00080"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.01187"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/SPW50608.2020.00025"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW.2018.00210"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/WACV.2019.00143"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01455"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.00398"},{"key":"ref27","first-page":"6465","article-title":"(de)randomized smoothing for certifiable defense against patch attacks","volume-title":"Proc. 34th Int. Conf. Neural Inf. Process. Syst.","author":"Levine"},{"key":"ref28","article-title":"Certified defenses for adversarial patches","author":"Chiang","year":"2020","journal-title":"arXiv:2003.06693"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/SPW50608.2020.00026"},{"key":"ref30","first-page":"28169","article-title":"ScaleCert: Scalable certified defense against adversarial patches with sparse superficial layers","volume-title":"Proc. 35th Int. Conf. Neural Inf. Process. Syst.","author":"Han"},{"key":"ref31","first-page":"2237","article-title":"$PatchGuard$: A provably robust defense against adversarial patches via small receptive fields and masking","volume-title":"Proc. 30th USENIX Secur. Symp. (USENIX Secur.)","author":"Xiang"},{"key":"ref32","article-title":"PatchGuard++: Efficient provable attack detection against adversarial patches","author":"Xiang","year":"2021","journal-title":"arXiv:2104.12609"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-68238-5_32"},{"key":"ref34","article-title":"Defending against physically realizable attacks on image classification","author":"Wu","year":"2019","journal-title":"arXiv:1909.09552"},{"key":"ref35","first-page":"2065","article-title":"$PatchCleanser$: Certifiably robust defense against adversarial patches for any image classifier","volume-title":"Proc. 31st USENIX Secur. Symp. (USENIX Secur.)","author":"Xiang"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/WACVW54805.2022.00036"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58601-0_24"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2024.24920"},{"key":"ref39","first-page":"2507","article-title":"LaVAN: Localized and visible adversarial noise","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Karmon"},{"key":"ref40","first-page":"3976","article-title":"Knowledge enhanced machine learning pipeline against diverse adversarial attacks","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"G\u00fcrel"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2022\/397"},{"key":"ref42","article-title":"Towards deep learning models resistant to adversarial attacks","author":"Madry","year":"2017","journal-title":"arXiv:1706.06083"},{"key":"ref43","first-page":"284","article-title":"Synthesizing robust adversarial examples","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Athalye"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01553"},{"key":"ref45","article-title":"MaskOCR: Text recognition with masked encoder\u2013decoder pretraining","author":"Lyu","year":"2022","journal-title":"arXiv:2206.00311"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.00943"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.00999"},{"key":"ref48","article-title":"Designing BERT for convolutional networks: Sparse and hierarchical masked modeling","author":"Tian","year":"2023","journal-title":"arXiv:2301.03580"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-023-01852-4"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1038\/nrn1869"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2021\/591"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1016\/j.neunet.2012.02.016"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1109\/FG.2018.00020"},{"volume-title":"Imagenette","year":"2024","author":"Howard","key":"ref55"},{"key":"ref56","article-title":"Very deep convolutional networks for large-scale image recognition","author":"Simonyan","year":"2014","journal-title":"arXiv:1409.1556"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.5244\/C.30.87"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.243"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-19772-7_31"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v38i15.29574"},{"key":"ref62","first-page":"1","article-title":"Explaining and harnessing adversarial examples","volume-title":"Proc. 3rd Int. Conf. Learn. Represent.","author":"Goodfellow"},{"key":"ref63","first-page":"1894","article-title":"Ensemble adversarial training: Attacks and defenses","volume-title":"Proc. 6th Int. Conf. Learn. Represent.","author":"Tram\u00e8r"},{"key":"ref64","first-page":"611","article-title":"An image is worth 16\u00d716 words: Transformers for image recognition at scale","volume-title":"Proc. 9th Int. Conf. Learn. Represent.","author":"Dosovitskiy","year":"2021"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-10602-1_48"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/10206\/10810755\/11230640.pdf?arnumber=11230640","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,11,28]],"date-time":"2025-11-28T18:42:16Z","timestamp":1764355336000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11230640\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"references-count":65,"URL":"https:\/\/doi.org\/10.1109\/tifs.2025.3629619","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"type":"print","value":"1556-6013"},{"type":"electronic","value":"1556-6021"}],"subject":[],"published":{"date-parts":[[2025]]}}}