{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,2,21]],"date-time":"2025-02-21T19:23:14Z","timestamp":1740165794339,"version":"3.37.3"},"reference-count":53,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"2","license":[{"start":{"date-parts":[[2024,2,1]],"date-time":"2024-02-01T00:00:00Z","timestamp":1706745600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2024,2,1]],"date-time":"2024-02-01T00:00:00Z","timestamp":1706745600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2024,2,1]],"date-time":"2024-02-01T00:00:00Z","timestamp":1706745600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Neural Netw. Learning Syst."],"published-print":{"date-parts":[[2024,2]]},"DOI":"10.1109\/tnnls.2022.3186278","type":"journal-article","created":{"date-parts":[[2022,7,11]],"date-time":"2022-07-11T19:45:50Z","timestamp":1657568750000},"page":"2042-2053","source":"Crossref","is-referenced-by-count":0,"title":["Guidance Through Surrogate: Toward a Generic Diagnostic Attack"],"prefix":"10.1109","volume":"35","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-7663-7161","authenticated-orcid":false,"given":"Muzammal","family":"Naseer","sequence":"first","affiliation":[{"name":"Computer Vision Department, Mohamed Bin Zayed University of Artificial Intelligence, Abu Dhabi, United Arab Emirates"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9502-1749","authenticated-orcid":false,"given":"Salman","family":"Khan","sequence":"additional","affiliation":[{"name":"Computer Vision Department, Mohamed Bin Zayed University of Artificial Intelligence, Abu Dhabi, United Arab Emirates"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1520-4466","authenticated-orcid":false,"given":"Fatih","family":"Porikli","sequence":"additional","affiliation":[{"name":"Qualcomm, San Diego, CA, USA"}]},{"given":"Fahad Shahbaz","family":"Khan","sequence":"additional","affiliation":[{"name":"Computer Vision Department, Mohamed Bin Zayed University of Artificial Intelligence, Abu Dhabi, United Arab Emirates"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"ref2","first-page":"1831","article-title":"Defense against adversarial attacks using feature scattering-based adversarial training","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Zhang"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00035"},{"article-title":"Mixup inference: Better exploiting mixup to defend adversarial attacks","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Pang","key":"ref4"},{"key":"ref5","article-title":"Explaining and harnessing adversarial examples","author":"Goodfellow","year":"2014","journal-title":"arXiv:1412.6572"},{"article-title":"Ensemble adversarial training: Attacks and defenses","volume-title":"Proc. Int. Conf. Learn. Represent. (ICRL)","author":"Tram\u00e8r","key":"ref6"},{"article-title":"Towards deep learning models resistant to adversarial attacks","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Madry","key":"ref7"},{"article-title":"Adversarial examples in the physical world","volume-title":"Proc. Int. Conf. Learn. Represent. (ICRL)","author":"Goodfellow","key":"ref8"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00284"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"ref11","first-page":"4696","article-title":"When does label smoothing help?","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"M\u00fcller"},{"key":"ref12","article-title":"Regularizing neural networks by penalizing confident output distributions","author":"Pereyra","year":"2017","journal-title":"arXiv:1701.06548"},{"key":"ref13","article-title":"Theoretically principled trade-off between robustness and accuracy","author":"Zhang","year":"2019","journal-title":"arXiv:1901.08573"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN.2016.7727230"},{"key":"ref15","article-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","author":"Athalye","year":"2018","journal-title":"arXiv:1802.00420"},{"key":"ref16","first-page":"3358","article-title":"Adversarial training for free!","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Shafahi"},{"key":"ref17","first-page":"227","article-title":"You only propagate once: Accelerating adversarial training via maximal principle","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Zhang"},{"key":"ref18","article-title":"Towards stable and efficient training of verifiably robust neural networks","author":"Zhang","year":"2019","journal-title":"arXiv:1906.06316"},{"key":"ref19","article-title":"Provably robust deep learning via adversarially trained smoothed classifiers","author":"Salman","year":"2019","journal-title":"arXiv:1906.04584"},{"article-title":"Fast is better than free: Revisiting adversarial training","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Wong","key":"ref20"},{"article-title":"Improving adversarial robustness requires revisiting misclassified examples","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Wang","key":"ref21"},{"key":"ref22","first-page":"11190","article-title":"Unlabeled data improves adversarial robustness","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Carmon"},{"article-title":"Countering adversarial images using input transformations","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Guo","key":"ref23"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00357"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00034"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.48550\/arxiv.1710.09412"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00930"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/TEVC.2019.2890858"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref31","first-page":"12905","article-title":"Cross-domain transferability of adversarial perturbations","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Naseer"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00761"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/WACV.2019.00143"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v32i1.11302"},{"article-title":"Skip connections matter: On the transferability of adversarial examples generated with ResNets","volume-title":"Proc. ICLR","author":"Wu","key":"ref35"},{"article-title":"On improving adversarial transferability of vision transformers","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Naseer","key":"ref36"},{"key":"ref37","article-title":"Diversity can be transferred: Output diversification for White- and black-box attacks","author":"Tashiro","year":"2020","journal-title":"arXiv:2003.06878"},{"key":"ref38","article-title":"Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks","author":"Croce","year":"2020","journal-title":"arXiv:2003.01690"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58592-1_29"},{"volume-title":"Minimally Distorted Adversarial Examples With a Fast Adaptive Boundary Attack","year":"2020","author":"Croce","key":"ref40"},{"key":"ref41","article-title":"On adaptive attacks to adversarial example defenses","author":"Tramer","year":"2020","journal-title":"arXiv:2002.08347"},{"article-title":"Bag of tricks for adversarial training","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Pang","key":"ref42"},{"key":"ref43","article-title":"Label smoothing and logit squeezing: A replacement for adversarial training?","author":"Shafahi","year":"2019","journal-title":"arXiv:1910.11585"},{"key":"ref44","article-title":"Label smoothing and adversarial robustness","author":"Fu","year":"2020","journal-title":"arXiv:2009.08233"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.3048120"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.5555\/3454287.3455008"},{"key":"ref47","article-title":"Do adversarially robust ImageNet models transfer better?","author":"Salman","year":"2020","journal-title":"arXiv:2007.08489"},{"volume-title":"Mixup-Inference","year":"2019","author":"Pang","key":"ref48"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1109\/WACV51458.2022.00387"},{"article-title":"Random noise defense against query-based black-box attacks","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Qin","key":"ref51"},{"key":"ref52","article-title":"Adversarial examples are not bugs, they are features","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"32","author":"Ilyas"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.74"}],"container-title":["IEEE Transactions on Neural Networks and Learning Systems"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/5962385\/10422842\/09825707.pdf?arnumber=9825707","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,2,16]],"date-time":"2024-02-16T19:11:24Z","timestamp":1708110684000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9825707\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,2]]},"references-count":53,"journal-issue":{"issue":"2"},"URL":"https:\/\/doi.org\/10.1109\/tnnls.2022.3186278","relation":{},"ISSN":["2162-237X","2162-2388"],"issn-type":[{"type":"print","value":"2162-237X"},{"type":"electronic","value":"2162-2388"}],"subject":[],"published":{"date-parts":[[2024,2]]}}}