{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,28]],"date-time":"2026-03-28T12:32:06Z","timestamp":1774701126597,"version":"3.50.1"},"reference-count":28,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"7","license":[{"start":{"date-parts":[[2020,7,1]],"date-time":"2020-07-01T00:00:00Z","timestamp":1593561600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2020,7,1]],"date-time":"2020-07-01T00:00:00Z","timestamp":1593561600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2020,7,1]],"date-time":"2020-07-01T00:00:00Z","timestamp":1593561600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/100012338","name":"Alan Turing Institute","doi-asserted-by":"publisher","award":["EP\/N510129\/1"],"award-info":[{"award-number":["EP\/N510129\/1"]}],"id":[{"id":"10.13039\/100012338","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100000266","name":"Engineering and Physical Sciences Research Council","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100000266","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Multimedia"],"published-print":{"date-parts":[[2020,7]]},"DOI":"10.1109\/tmm.2020.2987694","type":"journal-article","created":{"date-parts":[[2020,4,16]],"date-time":"2020-04-16T20:18:16Z","timestamp":1587068296000},"page":"1862-1873","source":"Crossref","is-referenced-by-count":24,"title":["Exploiting Vulnerabilities of Deep Neural Networks for Privacy Protection"],"prefix":"10.1109","volume":"22","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-2330-0973","authenticated-orcid":false,"given":"Ricardo","family":"Sanchez-Matilla","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0845-0770","authenticated-orcid":false,"given":"Chau Yi","family":"Li","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2649-8700","authenticated-orcid":false,"given":"Ali Shahin","family":"Shamsabadi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Riccardo","family":"Mazzon","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5086-7858","authenticated-orcid":false,"given":"Andrea","family":"Cavallaro","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref10","article-title":"Adversarial machine learning at scale","author":"kurakin","year":"0","journal-title":"Proc Int Conf Learn Representations"},{"key":"ref11","article-title":"Towards deep learning models resistant to adversarial attacks","author":"madry","year":"0","journal-title":"Proc Int Conf Learn Representations"},{"key":"ref12","article-title":"Adversarial examples in the physical world","author":"kurakin","year":"0","journal-title":"Proc Workshop Int Conf Learn Represent"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00284"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00444"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00930"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00396"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1364\/JOSAA.15.002036"},{"key":"ref19","article-title":"JPEG-resistant adversarial images","author":"shin","year":"0","journal-title":"Proc Adv Neural Inf Process Syst Workshop"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref28","article-title":"Automatic differentiation in PyTorch","author":"paszke","year":"0","journal-title":"Proc Adv Neural Inf Process Syst Workshop"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"ref27","first-page":"1","article-title":"Most apparent distortion: Full-reference image quality assessment and the role of strategy","volume":"19","author":"larson","year":"2010","journal-title":"J Electron Imag"},{"key":"ref6","article-title":"Ensemble adversarial training: Attacks and defenses","author":"tram\u00e8r","year":"0","journal-title":"Proc Int Conf Learn Representations"},{"key":"ref5","first-page":"284","article-title":"Synthesizing robust adversarial examples","author":"athalye","year":"0","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00095"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23198"},{"key":"ref2","article-title":"Explaining and harnessing adversarial examples","author":"goodfellow","year":"0","journal-title":"Proc Int Conf Learn Representations"},{"key":"ref9","article-title":"Pixel privacy task, MediaEval 2018","year":"2018"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP.2019.8682225"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2017.2723009"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1145\/3065386"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref24","article-title":"A study of the effect of JPG compression on adversarial images","author":"dziugaite","year":"2016","journal-title":"arXiv 1608 00853"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.243"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2012.2214050"},{"key":"ref25","article-title":"Keeping the bad guys out: Protecting and vaccinating deep learning with JPEG compression","author":"das","year":"2017","journal-title":"arXiv 1705 02900"}],"container-title":["IEEE Transactions on Multimedia"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/6046\/9132597\/09069287.pdf?arnumber=9069287","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,4,27]],"date-time":"2022-04-27T15:56:14Z","timestamp":1651074974000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9069287\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,7]]},"references-count":28,"journal-issue":{"issue":"7"},"URL":"https:\/\/doi.org\/10.1109\/tmm.2020.2987694","relation":{},"ISSN":["1520-9210","1941-0077"],"issn-type":[{"value":"1520-9210","type":"print"},{"value":"1941-0077","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,7]]}}}