{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,30]],"date-time":"2026-07-30T10:53:40Z","timestamp":1785408820437,"version":"3.56.0"},"reference-count":56,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"1","license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100012166","name":"National Key Research and Development Program of China","doi-asserted-by":"publisher","award":["2022ZD0117902"],"award-info":[{"award-number":["2022ZD0117902"]}],"id":[{"id":"10.13039\/501100012166","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62376024"],"award-info":[{"award-number":["62376024"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U20B2062"],"award-info":[{"award-number":["U20B2062"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Neural Netw. Learning Syst."],"published-print":{"date-parts":[[2025,1]]},"DOI":"10.1109\/tnnls.2023.3326871","type":"journal-article","created":{"date-parts":[[2023,11,2]],"date-time":"2023-11-02T13:59:27Z","timestamp":1698933567000},"page":"1410-1424","source":"Crossref","is-referenced-by-count":9,"title":["Improving Adversarial Robustness Against Universal Patch Attacks Through Feature Norm Suppressing"],"prefix":"10.1109","volume":"36","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-6956-884X","authenticated-orcid":false,"given":"Cheng","family":"Yu","sequence":"first","affiliation":[{"name":"School of Computer and Communication Engineering, University of Science and Technology Beijing, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2040-7938","authenticated-orcid":false,"given":"Jiansheng","family":"Chen","sequence":"additional","affiliation":[{"name":"School of Computer and Communication Engineering, University of Science and Technology Beijing, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2931-8958","authenticated-orcid":false,"given":"Yu","family":"Wang","sequence":"additional","affiliation":[{"name":"Department of Electronic Engineering, Tsinghua University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7054-5204","authenticated-orcid":false,"given":"Youze","family":"Xue","sequence":"additional","affiliation":[{"name":"Department of Electronic Engineering, Tsinghua University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5383-5667","authenticated-orcid":false,"given":"Huimin","family":"Ma","sequence":"additional","affiliation":[{"name":"School of Computer and Communication Engineering, University of Science and Technology Beijing, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2018.2886017"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2019.2933524"},{"key":"ref3","article-title":"Adversarial patch","author":"Brown","year":"2017","journal-title":"arXiv:1712.09665"},{"key":"ref4","first-page":"2507","article-title":"LaVAN: Localized and visible adversarial noise","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Karmon"},{"key":"ref5","first-page":"1","article-title":"Physical adversarial examples for object detectors","volume-title":"Proc. 12th USENIX Conf. Offensive Technol.","author":"Eykholt"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58558-7_39"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00080"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978392"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW.2018.00210"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/WACV.2019.00143"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01455"},{"key":"ref12","first-page":"1","article-title":"Defending against physically realizable attacks on image classification","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Wu"},{"key":"ref13","first-page":"1106","article-title":"ImageNet classification with deep convolutional neural networks","volume-title":"Proc. Annu. Conf. Neural Inf. Process. Syst.","author":"Krizhevsky"},{"key":"ref14","first-page":"1","article-title":"Certified defenses for adversarial patches","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Chiang"},{"key":"ref15","first-page":"6465","article-title":"(De)randomized smoothing for certifiable defense against patch attacks","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"33","author":"Levine"},{"key":"ref16","first-page":"4905","article-title":"Understanding the effective receptive field in deep convolutional neural networks","volume-title":"Proc. Annu. Conf. Neural Inf. Process. Syst.","author":"Luo"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298594"},{"key":"ref19","volume-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-014-0733-5"},{"key":"ref21","article-title":"YOLOv3: An incremental improvement","author":"Redmon","year":"2018","journal-title":"arXiv:1804.02767"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.l007\/978-3-319-46448-0_2"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-10602-1_48"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01612"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00042"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3278515"},{"key":"ref27","first-page":"1","article-title":"DPATCH: An adversarial patch attack on object detectors","volume-title":"Proc. Workshop Artif. Intell. Saf.","author":"Liu"},{"key":"ref28","article-title":"On physical adversarial patches for object detection","author":"Lee","year":"2019","journal-title":"arXiv:1906.11897"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW.2019.00012"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58520-4_11"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/WACV51458.2022.00288"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58601-0_24"},{"key":"ref33","article-title":"TnT attacks! Universal naturalistic adversarial patches against deep neural network systems","author":"Doan","year":"2021","journal-title":"arXiv:2111.09999"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.06083"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01471"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01472"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1145\/3475724.3483606"},{"key":"ref38","article-title":"PatchGuard: A provably robust defense against adversarial patches via small receptive fields and masking","author":"Xiang","year":"2020","journal-title":"arXiv:2005.10884"},{"key":"ref39","first-page":"1","article-title":"Efficient certified defenses against patch attacks on image classifiers","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Metzen"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/SPW50608.2020.00026"},{"key":"ref41","article-title":"Adversarial YOLO: Defense human detection patch attacks via detecting adversarial patches","author":"Ji","year":"2021","journal-title":"arXiv:2103.08860"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW50498.2020.00400"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2022.3217375"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484757"},{"key":"ref45","article-title":"Fortified networks: Improving the robustness of deep networks by modeling the manifold of hidden representations","author":"Lamb","year":"2018","journal-title":"arXiv:1804.02485"},{"key":"ref46","article-title":"Explaining and harnessing adversarial examples","author":"Goodfellow","year":"2014","journal-title":"arXiv:1412.6572"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00059"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2018.2852738"},{"key":"ref49","first-page":"1","article-title":"Improving adversarial robustness via channel-wise activation suppressing","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Bai"},{"key":"ref50","first-page":"11693","article-title":"CIFs: Improving adversarial robustness of CNNs via channel-wise importance-based feature selection","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Yan"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00079"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.01453"},{"key":"ref53","volume-title":"Discrete-Time Signal Processing","volume":"2","author":"Oppenheim","year":"2001"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00474"},{"key":"ref55","first-page":"274","article-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Athalye"},{"key":"ref56","first-page":"7472","article-title":"Theoretically principled trade-off between robustness and accuracy","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Zhang"}],"container-title":["IEEE Transactions on Neural Networks and Learning Systems"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/5962385\/10832116\/10305196.pdf?arnumber=10305196","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,12,5]],"date-time":"2025-12-05T18:39:14Z","timestamp":1764959954000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10305196\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,1]]},"references-count":56,"journal-issue":{"issue":"1"},"URL":"https:\/\/doi.org\/10.1109\/tnnls.2023.3326871","relation":{},"ISSN":["2162-237X","2162-2388"],"issn-type":[{"value":"2162-237X","type":"print"},{"value":"2162-2388","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,1]]}}}