{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,20]],"date-time":"2026-05-20T16:39:30Z","timestamp":1779295170919,"version":"3.51.4"},"reference-count":29,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"11","license":[{"start":{"date-parts":[[2022,11,1]],"date-time":"2022-11-01T00:00:00Z","timestamp":1667260800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2022,11,1]],"date-time":"2022-11-01T00:00:00Z","timestamp":1667260800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2022,11,1]],"date-time":"2022-11-01T00:00:00Z","timestamp":1667260800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Neural Netw. Learning Syst."],"published-print":{"date-parts":[[2022,11]]},"DOI":"10.1109\/tnnls.2021.3072166","type":"journal-article","created":{"date-parts":[[2021,4,23]],"date-time":"2021-04-23T19:50:48Z","timestamp":1619207448000},"page":"6976-6982","source":"Crossref","is-referenced-by-count":10,"title":["Breaking Neural Reasoning Architectures With Metamorphic Relation-Based Adversarial Examples"],"prefix":"10.1109","volume":"33","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-1041-3891","authenticated-orcid":false,"given":"Alvin","family":"Chan","sequence":"first","affiliation":[{"name":"School of Computer Science and Engineering, Nanyang Technological University, Singapore"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Lei","family":"Ma","sequence":"additional","affiliation":[{"name":"Department of Electrical and Computer Engineering, University of Alberta, Edmonton, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0857-8611","authenticated-orcid":false,"given":"Felix","family":"Juefei-Xu","sequence":"additional","affiliation":[{"name":"Alibaba Group, Sunnyvale, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4480-169X","authenticated-orcid":false,"given":"Yew-Soon","family":"Ong","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, Nanyang Technological University, Singapore"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xiaofei","family":"Xie","sequence":"additional","affiliation":[{"name":"Faculty of Information Science and Electrical Engineering, Kyushu University, Fukuoka, Japan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Minhui","family":"Xue","sequence":"additional","affiliation":[{"name":"School of Computer Science, The University of Adelaide, Adelaide, SA, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7300-9215","authenticated-orcid":false,"given":"Yang","family":"Liu","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, Nanyang Technological University, Singapore"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","article-title":"Neural turing machines","volume-title":"arXiv:1410.5401","author":"Graves","year":"2014"},{"key":"ref2","first-page":"2440","article-title":"End-to-end memory networks","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Sukhbaatar"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1038\/nature20101"},{"key":"ref4","article-title":"Tracking the world state with recurrent entity networks","volume-title":"arXiv:1612.03969","author":"Henaff","year":"2016"},{"key":"ref5","article-title":"Neural map: Structured memory for deep reinforcement learning","volume-title":"arXiv:1702.08360","author":"Parisotto","year":"2017"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/D18-1237"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/W18-2606"},{"key":"ref8","article-title":"Intriguing properties of neural networks","volume-title":"arXiv:1312.6199","author":"Szegedy","year":"2013"},{"key":"ref9","first-page":"1","article-title":"Explaining and harnessing adversarial examples","volume-title":"Proc. ICLR","author":"Goodfellow"},{"key":"ref10","article-title":"Towards deep learning models resistant to adversarial attacks","volume-title":"arXiv:1706.06083","author":"Madry","year":"2017"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/D17-1215"},{"key":"ref12","first-page":"5231","article-title":"Imperceptible, robust, and targeted adversarial examples for automatic speech recognition","volume-title":"Proc. 36th Int. Conf. Mach. Learn.","volume":"97","author":"Qin"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.33012253"},{"key":"ref14","article-title":"Theoretically principled trade-off between robustness and accuracy","volume-title":"arXiv:1901.08573","author":"Zhang","year":"2019"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1145\/3374217"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/D18-1316"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/MILCOM.2016.7795300"},{"key":"ref18","article-title":"Adversarial examples for natural language classification problems","author":"Kuleshov","journal-title":"OpenReview"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/D19-1221"},{"key":"ref20","article-title":"Adversarial training methods for semi-supervised text classification","volume-title":"arXiv:1605.07725","author":"Miyato","year":"2016"},{"key":"ref21","article-title":"Natural language adversarial attacks and defenses in word level","volume-title":"arXiv:1909.06723","author":"Wang","year":"2019"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/P19-1561"},{"key":"ref23","article-title":"Defense methods against adversarial examples for recurrent neural networks","volume-title":"arXiv:1901.09963","author":"Rosenberg","year":"2019"},{"key":"ref24","article-title":"Defense against adversarial attacks in NLP via Dirichlet neighborhood ensemble","volume-title":"arXiv:2006.11627","author":"Zhou","year":"2020"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2018\/601"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2020.findings-emnlp.373"},{"key":"ref27","article-title":"Towards AI-complete question answering: A set of prerequisite toy tasks","volume-title":"arXiv:1502.05698","author":"Weston","year":"2015"},{"key":"ref28","article-title":"Metamorphic testing: A new approach for generating next test cases","author":"Chen","year":"1998"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1016\/j.jss.2010.11.920"}],"container-title":["IEEE Transactions on Neural Networks and Learning Systems"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/5962385\/9931397\/09411718.pdf?arnumber=9411718","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,1,9]],"date-time":"2024-01-09T22:57:35Z","timestamp":1704841055000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9411718\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,11]]},"references-count":29,"journal-issue":{"issue":"11"},"URL":"https:\/\/doi.org\/10.1109\/tnnls.2021.3072166","relation":{},"ISSN":["2162-237X","2162-2388"],"issn-type":[{"value":"2162-237X","type":"print"},{"value":"2162-2388","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,11]]}}}