{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,18]],"date-time":"2026-04-18T16:39:44Z","timestamp":1776530384975,"version":"3.51.2"},"reference-count":78,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"7","license":[{"start":{"date-parts":[[2023,7,1]],"date-time":"2023-07-01T00:00:00Z","timestamp":1688169600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2023,7,1]],"date-time":"2023-07-01T00:00:00Z","timestamp":1688169600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2023,7,1]],"date-time":"2023-07-01T00:00:00Z","timestamp":1688169600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61825203"],"award-info":[{"award-number":["61825203"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U1736203"],"award-info":[{"award-number":["U1736203"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61732021"],"award-info":[{"award-number":["61732021"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61906074"],"award-info":[{"award-number":["61906074"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61675003"],"award-info":[{"award-number":["61675003"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61972178"],"award-info":[{"award-number":["61972178"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Major Program of Guangdong Basic and Applied Research Project","award":["2019B030302008"],"award-info":[{"award-number":["2019B030302008"]}]},{"DOI":"10.13039\/501100012166","name":"National Key Research and Development Plan of China","doi-asserted-by":"publisher","award":["2020YFB1005600"],"award-info":[{"award-number":["2020YFB1005600"]}],"id":[{"id":"10.13039\/501100012166","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Guangdong Provincial Science and Technology Project","award":["2017B010111005"],"award-info":[{"award-number":["2017B010111005"]}]},{"DOI":"10.13039\/501100013069","name":"Leading Talents of Guangdong Province Program","doi-asserted-by":"publisher","award":["2016LJ06G689"],"award-info":[{"award-number":["2016LJ06G689"]}],"id":[{"id":"10.13039\/501100013069","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Key-Area Research and Development Program of Guangdong Province","award":["2019B020214003"],"award-info":[{"award-number":["2019B020214003"]}]},{"name":"Key-Area Research and Development Program of Guangzhou","award":["202103000090"],"award-info":[{"award-number":["202103000090"]}]},{"name":"Key-Areas of Artificial Intelligence in General Colleges and Universities of Guangdong Province","award":["2019KZDZX1012"],"award-info":[{"award-number":["2019KZDZX1012"]}]},{"name":"Laboratory of Lingnan Modern Agriculture Project","award":["NT2021009"],"award-info":[{"award-number":["NT2021009"]}]},{"DOI":"10.13039\/501100021171","name":"Basic and Applied Basic Research Foundation of Guangdong Province","doi-asserted-by":"publisher","award":["2019A1515011276"],"award-info":[{"award-number":["2019A1515011276"]}],"id":[{"id":"10.13039\/501100021171","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100012226","name":"Fundamental Research Funds for the Central Universities","doi-asserted-by":"publisher","award":["21620432"],"award-info":[{"award-number":["21620432"]}],"id":[{"id":"10.13039\/501100012226","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Key-Area Research and Development Program of Guangdong Province","award":["2019B1515120010"],"award-info":[{"award-number":["2019B1515120010"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Neural Netw. Learning Syst."],"published-print":{"date-parts":[[2023,7]]},"DOI":"10.1109\/tnnls.2021.3113342","type":"journal-article","created":{"date-parts":[[2021,11,5]],"date-time":"2021-11-05T19:17:49Z","timestamp":1636139869000},"page":"3691-3705","source":"Crossref","is-referenced-by-count":15,"title":["Feature Distillation in Deep Attention Network Against Adversarial Examples"],"prefix":"10.1109","volume":"34","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-2903-5525","authenticated-orcid":false,"given":"Xin","family":"Chen","sequence":"first","affiliation":[{"name":"College of Electronic Engineering, College of Artificial Intelligence, South China Agricultural University, Guangzhou, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4067-8230","authenticated-orcid":false,"given":"Jian","family":"Weng","sequence":"additional","affiliation":[{"name":"College of Information Science and Technology, Jinan University, Guangzhou, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xiaoling","family":"Deng","sequence":"additional","affiliation":[{"name":"College of Electronic Engineering, College of Artificial Intelligence, South China Agricultural University, Guangzhou, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5605-7397","authenticated-orcid":false,"given":"Weiqi","family":"Luo","sequence":"additional","affiliation":[{"name":"College of Information Science and Technology, Jinan University, Guangzhou, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yubin","family":"Lan","sequence":"additional","affiliation":[{"name":"College of Electronic Engineering, College of Artificial Intelligence, South China Agricultural University, Guangzhou, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7252-5047","authenticated-orcid":false,"given":"Qi","family":"Tian","sequence":"additional","affiliation":[{"name":"Huawei Cloud &#x0026; AI, Shenzhen, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref13","first-page":"5998","article-title":"Attention is all you need","author":"vaswani","year":"2017","journal-title":"Proc Annu Conf Neural Inf Process Syst (NIPS)"},{"key":"ref57","first-page":"2","article-title":"Wide neural networks of any depth evolve as linear models under gradient descent","author":"lee","year":"2019","journal-title":"Proc Annu Conf Neural Inf Process Syst (NIPS)"},{"key":"ref12","first-page":"2","article-title":"A structured self-attentive sentence embedding","author":"lin","year":"2017","journal-title":"Proc Int Conf Learn Represent (ICLR)"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v32i1.11928"},{"key":"ref59","first-page":"1","article-title":"Wide residual networks","author":"zagoruyko","year":"2016","journal-title":"Proc Brit Mach Vis Conf"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.683"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1145\/3406325.3465355"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-017-1059-x"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.404"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref55","first-page":"427","article-title":"Deep neural networks are easily fooled: High confidence predictions for unrecognizable images","author":"nguyen","year":"2015","journal-title":"Proc IEEE Conf Comput Vis Pattern Recognit (CVPR)"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1371\/journal.pone.0139827"},{"key":"ref54","first-page":"1","article-title":"Intriguing properties of neural networks","author":"szegedy","year":"2014","journal-title":"Proc Int Conf Learn Represent (ICLR)"},{"key":"ref17","article-title":"Adversarial defense by suppressing high-frequency components","author":"zhang","year":"2019","journal-title":"arXiv 1908 06566"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00326"},{"key":"ref19","first-page":"1","article-title":"Ensemble adversarial training: Attacks and defenses","author":"tram\u00e8r","year":"2018","journal-title":"Proc Int Conf Learn Represent (ICLR)"},{"key":"ref18","first-page":"2","article-title":"Cascade adversarial machine learning regularized with a unified embedding","author":"na","year":"2018","journal-title":"Proc Int Conf Learn Represent (ICLR)"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2007.70822"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.570"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.58"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-46493-0_50"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/TGRS.2014.2357078"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.80"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2014.43"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2013.221"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298731"},{"key":"ref43","first-page":"5455","article-title":"Visual saliency based on multiscale deep features","author":"li","year":"2015","journal-title":"Proc IEEE Conf Comput Vis Pattern Recognit (CVPR)"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1016\/j.image.2016.04.001"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/MICRO50266.2020.00031"},{"key":"ref7","first-page":"1","article-title":"Countering adversarial images using input transformations","author":"guo","year":"2018","journal-title":"Proc Int Conf Learn Represent (ICLR)"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1145\/3240765.3240791"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.41"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00095"},{"key":"ref5","article-title":"Towards the science of security and privacy in machine learning","author":"papernot","year":"2016","journal-title":"arXiv 1611 03814"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2011.272"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00353"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00191"},{"key":"ref78","first-page":"1097","article-title":"ImageNet classification with deep convolutional neural networks","author":"krizhevsky","year":"2012","journal-title":"Proc Annu Conf Neural Inf Process Syst (NIPS)"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2007.383047"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2012.89"},{"key":"ref31","first-page":"1","article-title":"Enhancing transformation-based defenses against adversarial attacks with a distribution classifier","author":"kou","year":"2020","journal-title":"Proc Int Conf Learn Represent (ICLR)"},{"key":"ref75","first-page":"630","article-title":"Identity mappings in deep residual networks","author":"he","year":"2016","journal-title":"Proc Eur Conf Comput Vis (ECCV)"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00894"},{"key":"ref74","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-46493-0_39"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1145\/3219819.3219910"},{"key":"ref77","article-title":"Very deep convolutional networks for large-scale image recognition","author":"simonyan","year":"2014","journal-title":"arXiv 1409 1556"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/ICIP.2019.8803240"},{"key":"ref76","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00575"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1201\/9781351251389-8"},{"key":"ref1","first-page":"1","article-title":"Explaining and harnessing adversarial examples","author":"goodfellow","year":"2015","journal-title":"Proc Int Conf Learn Represent (ICLR)"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2014.2345401"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2012.6247743"},{"key":"ref71","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2015.123"},{"key":"ref70","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.243"},{"key":"ref73","first-page":"2","article-title":"Mixup: Beyond empirical risk minimization","author":"zhang","year":"2018","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref72","first-page":"448","article-title":"Batch normalization: Accelerating deep network training by reducing internal covariate shift","author":"ioffe","year":"2015","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref24","first-page":"1","article-title":"Biologically inspired sleep algorithm for increased generalization and adversarial robustness in deep neural networks","author":"tadros","year":"2020","journal-title":"Proc Int Conf Learn Represent (ICLR)"},{"key":"ref68","article-title":"Network in network","author":"lin","year":"2013","journal-title":"arXiv 1312 4400"},{"key":"ref23","article-title":"Biologically inspired protection of deep networks from adversarial attacks","author":"nayebi","year":"2017","journal-title":"arXiv 1703 09202"},{"key":"ref67","article-title":"Training very deep networks","author":"srivastava","year":"2015","journal-title":"arXiv 1507 06228"},{"key":"ref26","first-page":"1","article-title":"Keeping the bad guys out: Protecting and vaccinating deep learning with jpeg compression","author":"das","year":"2017","journal-title":"Proc IEEE Conf Comput Vis Pattern Recognit (CVPR)"},{"key":"ref25","first-page":"1","article-title":"A study of the effect of JPG compression on adversarial images","author":"dziugaite","year":"2016","journal-title":"arXiv 1608 00853"},{"key":"ref69","article-title":"FitNets: Hints for thin deep nets","author":"romero","year":"2014","journal-title":"arXiv 1412 6550"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00491"},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00503"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.01171"},{"key":"ref22","first-page":"1","article-title":"Improving adversarial robustness requires revisiting misclassified examples","author":"wang","year":"2020","journal-title":"Proc Int Conf Learn Represent (ICLR)"},{"key":"ref66","article-title":"On adaptive attacks to adversarial example defenses","author":"tramr","year":"2020","journal-title":"arXiv 2002 08347"},{"key":"ref21","first-page":"1","article-title":"Fast is better than free: Revisiting adversarial training","author":"wong","year":"2020","journal-title":"Proc Int Conf Learn Represent (ICLR)"},{"key":"ref65","article-title":"On evaluating adversarial robustness","author":"carlini","year":"2019","journal-title":"arXiv 1902 06705"},{"key":"ref28","first-page":"1","article-title":"Pixeldefend: Leveraging generative models to understand and defend against adversarial examples","author":"song","year":"2018","journal-title":"Proc Int Conf Learn Represent (ICLR)"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2017.2718479"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134057"},{"key":"ref60","article-title":"Learning multiple layers of features from tiny images","author":"krizhevsky","year":"2009"},{"key":"ref62","article-title":"A Hamiltonian Monte Carlo method for probabilistic adversarial attack and learning","author":"wang","year":"2020","journal-title":"IEEE Trans Pattern Anal Mach Intell"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"}],"container-title":["IEEE Transactions on Neural Networks and Learning Systems"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/5962385\/10175014\/09604767.pdf?arnumber=9604767","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,7,31]],"date-time":"2023-07-31T17:36:39Z","timestamp":1690824999000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9604767\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,7]]},"references-count":78,"journal-issue":{"issue":"7"},"URL":"https:\/\/doi.org\/10.1109\/tnnls.2021.3113342","relation":{},"ISSN":["2162-237X","2162-2388"],"issn-type":[{"value":"2162-237X","type":"print"},{"value":"2162-2388","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,7]]}}}