{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,6]],"date-time":"2026-05-06T02:01:31Z","timestamp":1778032891987,"version":"3.51.4"},"reference-count":60,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. on Image Process."],"published-print":{"date-parts":[[2021]]},"DOI":"10.1109\/tip.2021.3082317","type":"journal-article","created":{"date-parts":[[2021,6,23]],"date-time":"2021-06-23T19:49:59Z","timestamp":1624477799000},"page":"5769-5781","source":"Crossref","is-referenced-by-count":91,"title":["Training Robust Deep Neural Networks via Adversarial Noise Propagation"],"prefix":"10.1109","volume":"30","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-4224-1318","authenticated-orcid":false,"given":"Aishan","family":"Liu","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8425-4195","authenticated-orcid":false,"given":"Xianglong","family":"Liu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7858-8789","authenticated-orcid":false,"given":"Hang","family":"Yu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1378-322X","authenticated-orcid":false,"given":"Chongzhi","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Qiang","family":"Liu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7225-5449","authenticated-orcid":false,"given":"Dacheng","family":"Tao","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"ref38","article-title":"Adversarial examples in the physical world","author":"kurakin","year":"2016","journal-title":"arXiv 1607 02533"},{"key":"ref33","first-page":"1","article-title":"Image synthesis with a single (robust) classifier","author":"santurkar","year":"2019","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref32","first-page":"1","article-title":"Adversarial examples are not bugs, they are features","author":"ilyas","year":"2019","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00191"},{"key":"ref30","article-title":"Shape-texture debiased neural network training","author":"li","year":"2021","journal-title":"arXiv 2010 05981"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref36","article-title":"Learning multiple layers of features from tiny images","author":"krizhevsky","year":"2009"},{"key":"ref35","author":"lecun","year":"1998","journal-title":"The MNIST Database of Handwritten Digits"},{"key":"ref34","article-title":"On evaluating adversarial robustness","author":"carlini","year":"2019","journal-title":"arXiv 1902 06705"},{"key":"ref60","article-title":"Learning adversary-resistant deep neural networks","author":"wang","year":"2016","journal-title":"arXiv 1612 01401"},{"key":"ref28","article-title":"Benchmarking neural network robustness to common corruptions and perturbations","author":"hendrycks","year":"2019","journal-title":"arXiv 1903 12261"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.485"},{"key":"ref29","article-title":"The many faces of robustness: A critical analysis of out-of-distribution generalization","author":"hendrycks","year":"2020","journal-title":"arXiv 2006 16241"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2016.2577031"},{"key":"ref1","first-page":"1097","article-title":"ImageNet classification with deep convolutional neural networks","author":"krizhevsky","year":"2012","journal-title":"Proc Int Conf Neural Inf Process"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2018.2858821"},{"key":"ref22","first-page":"274","article-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","author":"athalye","year":"2018","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2020.3042083"},{"key":"ref24","first-page":"417","article-title":"Deep defense: Training DNNs with improved adversarial robustness","author":"yan","year":"2018","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref23","article-title":"Adversarial machine learning at scale","author":"kurakin","year":"2016","journal-title":"arXiv 1611 01236"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/ICCCN.2017.8038465"},{"key":"ref25","first-page":"854","article-title":"Parseval networks: Improving robustness to adversarial examples","author":"cisse","year":"2017","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1016\/0893-6080(91)90009-T"},{"key":"ref51","first-page":"666","article-title":"Shallow vs. Deep sum-product networks","author":"delalleau","year":"2011","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref59","article-title":"Towards deep neural network architectures robust to adversarial examples","author":"gu","year":"2014","journal-title":"arXiv 1412 5068 [cs]"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.41"},{"key":"ref57","first-page":"12817","article-title":"Accurate, reliable and fast robustness evaluation","author":"brendel","year":"2019","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref56","first-page":"1","article-title":"Adversarially robust generalization requires more data","author":"schmidt","year":"2018","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref55","article-title":"Theoretically principled trade-off between robustness and accuracy","author":"zhang","year":"2019","journal-title":"arXiv 1901 08573"},{"key":"ref54","article-title":"Robustness may be at odds with accuracy","author":"tsipras","year":"2018","journal-title":"arXiv 1805 12152"},{"key":"ref53","article-title":"Batch normalization: Accelerating deep network training by reducing internal covariate shift","author":"ioffe","year":"2015","journal-title":"arXiv 1502 03167"},{"key":"ref52","article-title":"Are all layers created equal?","author":"zhang","year":"2019","journal-title":"arXiv 1902 01996"},{"key":"ref10","first-page":"3","article-title":"Practical black-box attacks against deep learning systems using adversarial examples","volume":"1","author":"papernot","year":"2016","journal-title":"ArXiv Preprint"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.33011028"},{"key":"ref40","article-title":"Towards deep learning models resistant to adversarial attacks","author":"madry","year":"2017","journal-title":"arXiv 1706 06083"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2018.2861800"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58520-4_8"},{"key":"ref14","first-page":"395","article-title":"Bias-based universal adversarial patch attack for automatic check-out","author":"liu","year":"2020","journal-title":"Proc Eur Conf Comput Vis"},{"key":"ref15","article-title":"Mitigating adversarial effects through randomization","author":"xie","year":"2017","journal-title":"arXiv 1711 01991"},{"key":"ref16","article-title":"Stochastic activation pruning for robust adversarial defense","author":"dhillon","year":"2018","journal-title":"arXiv 1803 01442"},{"key":"ref17","article-title":"Thermometer encoding: One hot way to resist adversarial examples","author":"buckman","year":"2018","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref18","article-title":"Countering adversarial images using input transformations","author":"guo","year":"2017","journal-title":"arXiv 1711 00117"},{"key":"ref19","article-title":"PixelDefend: Leveraging generative models to understand and defend against adversarial examples","author":"song","year":"2017","journal-title":"arXiv 1710 10766"},{"key":"ref4","article-title":"Neural machine translation by jointly learning to align and translate","author":"bahdanau","year":"2014","journal-title":"arXiv 1409 0473"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1515\/9783110524116"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2012.2205597"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1145\/2684822.2685316"},{"key":"ref8","article-title":"Intriguing properties of neural networks","author":"szegedy","year":"2013","journal-title":"arXiv 1312 6199"},{"key":"ref7","first-page":"173","article-title":"Deep speech 2: End-to-end speech recognition in English and mandarin","author":"amodei","year":"2016","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1007\/s10994-011-5268-1"},{"key":"ref9","article-title":"Explaining and harnessing adversarial examples","author":"goodfellow","year":"2014","journal-title":"arXiv 1412 6572"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1007\/BF00994018"},{"key":"ref45","article-title":"Foolbox: A Python toolbox to benchmark the robustness of machine learning models","author":"rauber","year":"2017","journal-title":"arXiv 1707 04131"},{"key":"ref48","article-title":"Decision boundary analysis of adversarial examples","author":"he","year":"2018","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref47","first-page":"842","article-title":"Large margin deep networks for classification","author":"elsayed","year":"2018","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref42","first-page":"2206","article-title":"Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks","author":"croce","year":"2020","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref44","first-page":"1","article-title":"Regularizing deep networks using efficient layerwise adversarial training","author":"sankaranarayanan","year":"2018","journal-title":"Proc 32nd AAAI Conf Artif Intell"},{"key":"ref43","article-title":"Ensemble adversarial training: Attacks and defenses","author":"tram\u00e8r","year":"2017","journal-title":"arXiv 1705 07204"}],"container-title":["IEEE Transactions on Image Processing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/83\/9263394\/09462815.pdf?arnumber=9462815","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,5,10]],"date-time":"2022-05-10T14:51:06Z","timestamp":1652194266000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9462815\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021]]},"references-count":60,"URL":"https:\/\/doi.org\/10.1109\/tip.2021.3082317","relation":{},"ISSN":["1057-7149","1941-0042"],"issn-type":[{"value":"1057-7149","type":"print"},{"value":"1941-0042","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021]]}}}