{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,2]],"date-time":"2026-02-02T21:08:20Z","timestamp":1770066500660,"version":"3.49.0"},"reference-count":45,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"am","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62072024"],"award-info":[{"award-number":["62072024"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61971290"],"award-info":[{"award-number":["61971290"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100017579","name":"Project of Beijing Advanced Innovation Center for Future Urban Design, Beijing University of Civil Engineering and Architecture","doi-asserted-by":"publisher","award":["UDC2019033324"],"award-info":[{"award-number":["UDC2019033324"]}],"id":[{"id":"10.13039\/501100017579","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100008521","name":"Fundamental Research Funds for Municipal Universities of Beijing University of Civil Engineering and Architecture","doi-asserted-by":"publisher","award":["X20084"],"award-info":[{"award-number":["X20084"]}],"id":[{"id":"10.13039\/501100008521","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["1646162"],"award-info":[{"award-number":["1646162"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["1647213"],"award-info":[{"award-number":["1647213"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["1646065"],"award-info":[{"award-number":["1646065"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. on Image Process."],"published-print":{"date-parts":[[2021]]},"DOI":"10.1109\/tip.2021.3086596","type":"journal-article","created":{"date-parts":[[2021,6,10]],"date-time":"2021-06-10T20:04:08Z","timestamp":1623355448000},"page":"6485-6497","source":"Crossref","is-referenced-by-count":12,"title":["Removing Adversarial Noise via Low-Rank Completion of High-Sensitivity Points"],"prefix":"10.1109","volume":"30","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-5000-100X","authenticated-orcid":false,"given":"Zhiqun","family":"Zhao","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6693-0161","authenticated-orcid":false,"given":"Hengyou","family":"Wang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3238-8225","authenticated-orcid":false,"given":"Hao","family":"Sun","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4004-6236","authenticated-orcid":false,"given":"Jianhe","family":"Yuan","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zhongchao","family":"Huang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2255-4293","authenticated-orcid":false,"given":"Zhihai","family":"He","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref39","author":"yuan","year":"2009","journal-title":"Sparse and Low-rank Matrix Decomposition Via Alternating Direction Methods"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1007\/s00041-008-9045-x"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2016.11.068"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2013.188"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1007\/s10107-009-0306-5"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/JPROC.2009.2035722"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/TCYB.2014.2307854"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2017.2781425"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1007\/s10208-009-9045-5"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2014.05.021"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"ref40","first-page":"1","article-title":"Reading digits in natural images with unsupervised feature learning","author":"netzer","year":"2011","journal-title":"Proc NIPS Workshop on Deep Learning and Unsupervised Feature Learning"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref12","first-page":"2206","article-title":"Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks","author":"croce","year":"2020","journal-title":"Proc ICML"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00284"},{"key":"ref15","article-title":"Towards deep learning models resistant to adversarial attacks","author":"madry","year":"2017","journal-title":"arXiv 1706 06083"},{"key":"ref16","article-title":"Adversarial logit pairing","author":"kannan","year":"2018","journal-title":"arXiv 1803 06373"},{"key":"ref17","article-title":"Ensemble adversarial training: Attacks and defenses","author":"tram\u00e8r","year":"2017","journal-title":"arXiv 1705 07204"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134057"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00624"},{"key":"ref28","article-title":"Improving adversarial robustness requires revisiting misclassified examples","author":"wang","year":"2019","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"ref27","first-page":"1","article-title":"Cost-sensitive robustness against adversarial examples","author":"zhang","year":"2019","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/ICESS.2019.8782514"},{"key":"ref6","article-title":"PixelDefend: Leveraging generative models to understand and defend against adversarial examples","author":"song","year":"2017","journal-title":"arXiv 1710 10766"},{"key":"ref29","first-page":"11192","article-title":"Unlabeled data improves adversarial robustness","author":"carmon","year":"2019","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref5","first-page":"1","article-title":"Countering adversarial images using input transformations","author":"guo","year":"2018","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2009.2028250"},{"key":"ref7","article-title":"Defense-GAN: Protecting classifiers against adversarial attacks using generative models","author":"samangouei","year":"2018","journal-title":"arXiv 1805 06605"},{"key":"ref2","article-title":"Adversarial examples in the physical world","author":"kurakin","year":"2016","journal-title":"arXiv 1607 02533"},{"key":"ref9","first-page":"274","article-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","author":"athalye","year":"2018","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref1","article-title":"Explaining and harnessing adversarial examples","author":"goodfellow","year":"2014","journal-title":"arXiv 1412 6572"},{"key":"ref20","article-title":"Feature denoising for improving adversarial robustness","author":"xie","year":"2018","journal-title":"arXiv 1812 03411"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00491"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00928"},{"key":"ref42","author":"abadi","year":"2015","journal-title":"TensorFlow Large-Scale Machine Learning on Heterogeneous Systems"},{"key":"ref24","first-page":"1","article-title":"Certified defenses against adversarial examples","author":"raghunathan","year":"2018","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref23","first-page":"1","article-title":"Thermometer encoding: One hot way to resist adversarial examples","author":"buckman","year":"2018","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref44","article-title":"Very deep convolutional networks for large-scale image recognition","author":"simonyan","year":"2014","journal-title":"arXiv 1409 1556"},{"key":"ref26","first-page":"8410","article-title":"Scaling provable adversarial defenses","author":"wong","year":"2018","journal-title":"Proc Conf Neural Inf Process Syst"},{"key":"ref43","author":"papernot","year":"2016","journal-title":"arXiv 1610 00768"},{"key":"ref25","first-page":"5286","article-title":"Provable defenses against adversarial examples via the convex outer adversarial polytope","author":"wong","year":"2018","journal-title":"Proc Int Conf Mach Learn"}],"container-title":["IEEE Transactions on Image Processing"],"original-title":[],"link":[{"URL":"https:\/\/ieeexplore.ieee.org\/ielam\/83\/9263394\/9451562-aam.pdf","content-type":"application\/pdf","content-version":"am","intended-application":"syndication"},{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/83\/9263394\/09451562.pdf?arnumber=9451562","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,5,10]],"date-time":"2022-05-10T14:50:03Z","timestamp":1652194203000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9451562\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021]]},"references-count":45,"URL":"https:\/\/doi.org\/10.1109\/tip.2021.3086596","relation":{},"ISSN":["1057-7149","1941-0042"],"issn-type":[{"value":"1057-7149","type":"print"},{"value":"1941-0042","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021]]}}}