{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,17]],"date-time":"2026-03-17T19:53:57Z","timestamp":1773777237061,"version":"3.50.1"},"reference-count":65,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"4","license":[{"start":{"date-parts":[[2024,4,1]],"date-time":"2024-04-01T00:00:00Z","timestamp":1711929600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2024,4,1]],"date-time":"2024-04-01T00:00:00Z","timestamp":1711929600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2024,4,1]],"date-time":"2024-04-01T00:00:00Z","timestamp":1711929600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100000038","name":"Natural Sciences and Engineering Research Council (NSERC) of Canada","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100000038","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"NSFC-FRQSC Research Program on Smart Cities and Big Data","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100000196","name":"Canada Foundation for Innovation","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100000196","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Neural Netw. Learning Syst."],"published-print":{"date-parts":[[2024,4]]},"DOI":"10.1109\/tnnls.2023.3252175","type":"journal-article","created":{"date-parts":[[2023,3,13]],"date-time":"2023-03-13T17:56:55Z","timestamp":1678730215000},"page":"4744-4755","source":"Crossref","is-referenced-by-count":9,"title":["Adversarial Danger Identification on Temporally Dynamic Graphs"],"prefix":"10.1109","volume":"35","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-9803-5719","authenticated-orcid":false,"given":"Fuqiang","family":"Liu","sequence":"first","affiliation":[{"name":"Department of Civil Engineering, McGill University, Montreal, Canada"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6985-0025","authenticated-orcid":false,"given":"Jingbo","family":"Tian","sequence":"additional","affiliation":[{"name":"Department of Civil Engineering, McGill University, Montreal, Canada"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3322-1814","authenticated-orcid":false,"given":"Luis","family":"Miranda-Moreno","sequence":"additional","affiliation":[{"name":"Department of Civil Engineering, McGill University, Montreal, Canada"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9488-0712","authenticated-orcid":false,"given":"Lijun","family":"Sun","sequence":"additional","affiliation":[{"name":"Department of Civil Engineering, McGill University, Montreal, Canada"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.3301922"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1007\/s42786-018-00006-2"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1016\/j.ijforecast.2015.11.011"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2019\/317"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/tnnls.2022.3165554"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/tnnls.2022.3224007"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/tnnls.2022.3186103"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/tnnls.2022.3220548"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/TEVC.2019.2890858"},{"key":"ref10","article-title":"Practical black-box attacks against machine learning","author":"Papernot","year":"2016","journal-title":"arXiv:1602.02697"},{"key":"ref11","article-title":"Ensemble adversarial training: Attacks and defenses","author":"Tram\u00e8r","year":"2017","journal-title":"arXiv:1705.07204"},{"key":"ref12","article-title":"Adversarial machine learning at scale","author":"Kurakin","year":"2016","journal-title":"arXiv:1611.01236"},{"key":"ref13","article-title":"Adversarial training methods for semi-supervised text classification","author":"Miyato","year":"2016","journal-title":"arXiv:1605.07725"},{"key":"ref14","first-page":"2484","article-title":"Simple black-box adversarial attacks","volume-title":"Proc. ICML","author":"Guo"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/tnnls.2021.3105617"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v30i1.10237"},{"key":"ref17","article-title":"Adversarial diffusion attacks on graph-based traffic prediction models","author":"Zhu","year":"2021","journal-title":"arXiv:2104.09369"},{"key":"ref18","article-title":"Spatially focused attack against spatiotemporal graph neural networks","author":"Liu","year":"2021","journal-title":"arXiv:2109.04608"},{"key":"ref19","first-page":"1","article-title":"Practical adversarial attacks on spatiotemporal traffic forecasting models","volume-title":"Proc. NeurIPS","author":"Liu"},{"key":"ref20","first-page":"274","article-title":"Circumventing defenses to adversarial examples","volume-title":"Proc. ICML","author":"Athalye"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01258-8_39"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1145\/3292500.3330851"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.485"},{"key":"ref24","first-page":"1","article-title":"On detecting adversarial perturbations","volume-title":"Proc. ICLR","author":"Metzen"},{"key":"ref25","article-title":"Explaining and harnessing adversarial examples","author":"Goodfellow","year":"2014","journal-title":"arXiv:1412.6572"},{"key":"ref26","article-title":"Towards deep learning models resistant to adversarial attacks","author":"Madry","year":"2017","journal-title":"arXiv:1706.06083"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1016\/j.eng.2019.12.012"},{"key":"ref28","article-title":"Feature denoising for improving adversarial robustness","author":"Xie","year":"2018","journal-title":"arXiv:1812.03411"},{"key":"ref29","article-title":"Local gradients smoothing: Defense against localized adversarial attacks","author":"Naseer","year":"2018","journal-title":"arXiv:1807.01216"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2807385"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2018\/505"},{"key":"ref32","first-page":"1","article-title":"Diffusion convolutional recurrent neural network: Data-driven traffic forecasting","volume-title":"Proc. ICLR","author":"Li"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2019\/264"},{"key":"ref34","article-title":"An empirical evaluation of generic convolutional and recurrent networks for sequence modeling","author":"Bai","year":"2018","journal-title":"arXiv:1803.01271"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1155\/2020\/1428104"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298594"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1201\/9781351251389-8"},{"key":"ref38","article-title":"Why do adversarial attacks transfer? Explaining transferability of evasion and poisoning attacks","author":"Demontis","year":"2018","journal-title":"arXiv:1809.02861"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2019.2933524"},{"key":"ref40","article-title":"Adversarial logit pairing","author":"Kannan","year":"2018","journal-title":"arXiv:1803.06373"},{"key":"ref41","article-title":"Defense-GAN: Protecting classifiers against adversarial attacks using generative models","author":"Samangouei","year":"2018","journal-title":"arXiv:1805.06605"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134057"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.06083"},{"key":"ref44","article-title":"Adversarial attacks on time series","author":"Karim","year":"2019","journal-title":"arXiv:1902.10755"},{"key":"ref45","article-title":"Benchmarking adversarial attacks and defenses for time-series data","author":"Ahmed","year":"2020","journal-title":"arXiv:2008.13261"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN.2019.8851936"},{"key":"ref47","first-page":"1115","article-title":"Adversarial attack on graph structured data","volume-title":"Proc. ICML","author":"Dai"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1145\/3336191.3371851"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/tnnls.2022.3182979"},{"key":"ref50","first-page":"1","article-title":"Adversarial attacks on graph neural network via meta learning","volume-title":"Proc. ICLR","author":"Zugner"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i04.5741"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1109\/tnnls.2022.3161030"},{"key":"ref53","first-page":"695","article-title":"Adversarial attacks on node embeddings via graph poisoning","volume-title":"Proc. ICML","author":"Bojchevski"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2019\/550"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1109\/tnnls.2022.3183210"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2021.3110982"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1109\/TITS.2022.3157129"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1109\/aipr50011.2020.9425190"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.1312.6203"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2012.2235192"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref62","article-title":"Dual teaching: A practical semi-supervised wrapper method","author":"Liu","year":"2016","journal-title":"arXiv:1611.03981"},{"key":"ref63","article-title":"The space of transferable adversarial examples","author":"Tram\u00e8r","year":"2017","journal-title":"arXiv:1704.03453"},{"key":"ref64","article-title":"Transferability in machine learning: From phenomena to black-box attacks using adversarial samples","author":"Papernot","year":"2016","journal-title":"arXiv:1605.07277"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.1145\/380995.381030"}],"container-title":["IEEE Transactions on Neural Networks and Learning Systems"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/5962385\/10492491\/10068359.pdf?arnumber=10068359","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,4,9]],"date-time":"2024-04-09T19:41:38Z","timestamp":1712691698000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10068359\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,4]]},"references-count":65,"journal-issue":{"issue":"4"},"URL":"https:\/\/doi.org\/10.1109\/tnnls.2023.3252175","relation":{},"ISSN":["2162-237X","2162-2388"],"issn-type":[{"value":"2162-237X","type":"print"},{"value":"2162-2388","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,4]]}}}