{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,11]],"date-time":"2026-03-11T01:45:13Z","timestamp":1773193513733,"version":"3.50.1"},"reference-count":71,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Fund of China","doi-asserted-by":"crossref","award":["92570110"],"award-info":[{"award-number":["92570110"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"crossref"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Fund of China","doi-asserted-by":"crossref","award":["62271090"],"award-info":[{"award-number":["62271090"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"crossref"}]},{"name":"Chongqing Natural Science Fund","award":["CSTB2024NSCQ-JQX0038"],"award-info":[{"award-number":["CSTB2024NSCQ-JQX0038"]}]},{"DOI":"10.13039\/501100012166","name":"National Key R&D Program of China","doi-asserted-by":"crossref","award":["2021YFB3100800"],"award-info":[{"award-number":["2021YFB3100800"]}],"id":[{"id":"10.13039\/501100012166","id-type":"DOI","asserted-by":"crossref"}]},{"name":"National Youth Talent Project"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Multimedia"],"published-print":{"date-parts":[[2026]]},"DOI":"10.1109\/tmm.2025.3632635","type":"journal-article","created":{"date-parts":[[2025,11,13]],"date-time":"2025-11-13T18:44:30Z","timestamp":1763059470000},"page":"1104-1118","source":"Crossref","is-referenced-by-count":0,"title":["Rectifying Adversarial Sample With Low Entropy Prior for Test-Time Defense"],"prefix":"10.1109","volume":"28","author":[{"given":"Lina","family":"Ma","sequence":"first","affiliation":[{"name":"Chongqing Key Laboratory of Bio-perception and Multimodal Intelligent Information Processing, Chongqing University, Chongqing, China"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-9723-2955","authenticated-orcid":false,"given":"Xiaowei","family":"Fu","sequence":"additional","affiliation":[{"name":"Chongqing Key Laboratory of Bio-perception and Multimodal Intelligent Information Processing, Chongqing University, Chongqing, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0399-9932","authenticated-orcid":false,"given":"Fuxiang","family":"Huang","sequence":"additional","affiliation":[{"name":"Chongqing Key Laboratory of Bio-perception and Multimodal Intelligent Information Processing, Chongqing University, Chongqing, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7985-0037","authenticated-orcid":false,"given":"Xinbo","family":"Gao","sequence":"additional","affiliation":[{"name":"Chongqing Key Laboratory of Image Cognition, Chongqing University of Posts and Telecommunications, Chongqing, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5305-8543","authenticated-orcid":false,"given":"Lei","family":"Zhang","sequence":"additional","affiliation":[{"name":"Chongqing Key Laboratory of Bio-perception and Multimodal Intelligent Information Processing, Chongqing University, Chongqing, China"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/TMM.2020.2969784"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58592-1_29"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/ICSPIS51611.2020.9349536"},{"key":"ref4","first-page":"274","article-title":"Obfuscated\n      gradients give a false sense of security: Circumventing defenses to adversarial\n      examples","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Athalye","year":"2018"},{"key":"ref5","first-page":"284","article-title":"Synthesizing\n      robust adversarial examples","volume-title":"Proc. Int. Conf. Mach.\n      Learn.","author":"Athalye","year":"2018"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.00816"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref8","first-page":"6643","article-title":"Robust classification via a single diffusion\n      model","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Chen","year":"2024"},{"key":"ref9","first-page":"1","article-title":"Robust\n      overfitting may be mitigated by properly learned smoothening","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Chen","year":"2020"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.5555\/3524938.3525087"},{"key":"ref11","first-page":"4421","article-title":"Evaluating the adversarial robustness of adaptive\n      test-time defenses","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Croce","year":"2022"},{"key":"ref12","first-page":"2196","article-title":"Minimally\n      distorted adversarial examples with a fast adaptive boundary attack","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Croce","year":"2020"},{"key":"ref13","first-page":"2206","article-title":"Reliable\n      evaluation of adversarial robustness with an ensemble of diverse parameter-free\n      attacks","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Croce","year":"2020"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00103"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.02364"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/TMM.2018.2887018"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00425"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/TMM.2021.3079723"},{"key":"ref20","first-page":"1","article-title":"Unsupervised\n      representation learning by predicting image rotations","volume-title":"Proc.\n      Int. Conf. Learn. Representations","author":"Gidaris","year":"2018"},{"key":"ref21","article-title":"Explaining and\n      harnessing adversarial examples","volume-title":"Proc. Int. Conf. Learn.\n      Representations","author":"Goodfellow","year":"2015"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00975"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-46493-0_38"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2023.126251"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2939352"},{"key":"ref27","article-title":"Learning multiple layers of features from tiny\n      images","author":"Krizhevsky","year":"2009","journal-title":"Tech. Report."},{"key":"ref28","first-page":"1","article-title":"Adversarial\n      machine learning at scale","volume-title":"Proc. Int. Conf. Learn.\n      Representations","author":"Kurakin","year":"2017"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"key":"ref30","first-page":"1","article-title":"A simple unified\n      framework for detecting out-of-distribution samples and adversarial\n     attacks","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Lee","year":"2018"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00019"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1016\/j.neunet.2023.03.008"},{"key":"ref33","first-page":"3487","article-title":"Dual manifold\n      adversarial robustness: Defense against Lp and non-Lp adversarial\n     attacks","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"33","author":"Lin","year":"2020"},{"key":"ref34","first-page":"1","article-title":"Characterizing adversarial subspaces using local\n      intrinsic dimensionality","volume-title":"Proc. Int. Conf. Learn.\n      Representations","author":"Ma","year":"2018"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.06083"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00070"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/ISIT.1994.394764"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2020.2985363"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"ref40","first-page":"16805","article-title":"Diffusion models for adversarial\n      purification","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Nie","year":"2022"},{"key":"ref41","first-page":"8093","article-title":"Overfitting in\n      adversarially robust deep learning","volume-title":"Proc. Int. Conf. Mach.\n      Learn.","author":"Rice","year":"2020"},{"key":"ref42","first-page":"1","article-title":"Defense-GAN:\n      Protecting classifiers against adversarial attacks using generative\n     models","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Samangouei","year":"2018"},{"key":"ref43","first-page":"1","article-title":"Online\n      adversarial purification based on self-supervised learning","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Shi","year":"2021"},{"key":"ref44","first-page":"1","article-title":"Pixeldefend:\n      Leveraging generative models to understand and defend against adversarial\n      examples","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Song","year":"2018"},{"key":"ref45","article-title":"Test-time training for out-of-distribution\n      generalization","author":"Sun","year":"2019","journal-title":"Tech. Report."},{"key":"ref46","article-title":"Intriguing properties of neural\n      networks","author":"Szegedy","year":"2013"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.02298"},{"key":"ref48","article-title":"Test-time defense against adversarial attacks:\n      Detection and reconstruction of adversarial examples via masked\n     autoencoder","author":"Tsai","year":"2023"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/TMM.2023.3255742"},{"key":"ref50","article-title":"Fighting\n      gradients with gradients: Dynamic defenses against adversarial attacks","author":"Wang","year":"2021"},{"key":"ref51","first-page":"1","article-title":"Tent: Fully\n      test-time adaptation by entropy minimization","volume-title":"Proc. Int.\n      Conf. Learn. Representations","author":"Wang","year":"2020"},{"key":"ref52","first-page":"1","article-title":"Improving adversarial robustness requires revisiting\n      misclassified examples","volume-title":"Proc. Int. Conf. Learn.\n      Representations","author":"Wang","year":"2019"},{"key":"ref53","first-page":"36246","article-title":"Better diffusion models further improve adversarial\n      training","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Wang","year":"2023"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1109\/TMM.2024.3407677"},{"key":"ref55","first-page":"1","article-title":"Improving\n      VAEs\u2019 robustness to adversarial attack","volume-title":"Proc. Int.\n      Conf. Learn. Representations","author":"Willetts","year":"2019"},{"key":"ref56","first-page":"1","article-title":"Fast is better\n      than free: Revisiting adversarial training","volume-title":"Proc. Int. Conf.\n      Learn. Representations","author":"Wong","year":"2020"},{"key":"ref57","article-title":"Densepure: Understanding diffusion models towards\n      adversarial robustness","author":"Xiao","year":"2022"},{"key":"ref58","first-page":"1","article-title":"Spatially transformed adversarial\n      examples","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Xiao","year":"2018"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2020.3024643"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00426"},{"key":"ref61","first-page":"16051","article-title":"Class-disentanglement and applications in adversarial detection and\n      defense","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"34","author":"Yang","year":"2021"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v38i15.29574"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2021.12.080"},{"key":"ref64","first-page":"12062","article-title":"Adversarial\n      purification with score-based generative models","volume-title":"Proc. Int.\n      Conf. Mach. Learn.","author":"Yoon","year":"2021"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.1109\/TMM.2021.3124083"},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.5244\/C.30.87"},{"key":"ref67","first-page":"7472","article-title":"Theoretically principled trade-off between\n      robustness and accuracy","volume-title":"Proc. Int. Conf. Mach.\n      Learn.","author":"Zhang","year":"2019"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2024.3385745"},{"key":"ref69","first-page":"38629","article-title":"Memo: Test time\n      robustness via adaptation and augmentation","volume-title":"Proc. Adv.\n      Neural Inf. Process. Syst.","volume":"35","author":"Zhang","year":"2022"},{"key":"ref70","first-page":"41429","article-title":"Detecting adversarial data by probing multiple\n      perturbations using expected perturbation score","volume-title":"Proc. Int.\n      Conf. Mach. Learn.","author":"Zhang","year":"2023"},{"key":"ref71","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2022.109009"}],"container-title":["IEEE Transactions on Multimedia"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/6046\/11342315\/11247785.pdf?arnumber=11247785","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,3,10]],"date-time":"2026-03-10T05:21:29Z","timestamp":1773120089000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11247785\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"references-count":71,"URL":"https:\/\/doi.org\/10.1109\/tmm.2025.3632635","relation":{},"ISSN":["1520-9210","1941-0077"],"issn-type":[{"value":"1520-9210","type":"print"},{"value":"1941-0077","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]}}}