{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,19]],"date-time":"2025-12-19T09:44:15Z","timestamp":1766137455587,"version":"3.37.3"},"reference-count":35,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"2","license":[{"start":{"date-parts":[[2021,4,1]],"date-time":"2021-04-01T00:00:00Z","timestamp":1617235200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"funder":[{"DOI":"10.13039\/501100003725","name":"National Research Foundation of Korea","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100003725","id-type":"DOI","asserted-by":"publisher"}]},{"name":"ministry of science, ICT and future planning, Republic of Korea","award":["NRF-2018R1D1A3B07043392"],"award-info":[{"award-number":["NRF-2018R1D1A3B07043392"]}]},{"DOI":"10.13039\/100016732","name":"LG Yeonam Cultural Foundation","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100016732","id-type":"DOI","asserted-by":"publisher"}]},{"name":"ARO","award":["W911NF-13-1-0421 (MURI)"],"award-info":[{"award-number":["W911NF-13-1-0421 (MURI)"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Netw. Sci. Eng."],"published-print":{"date-parts":[[2021,4,1]]},"DOI":"10.1109\/tnse.2020.3008394","type":"journal-article","created":{"date-parts":[[2020,7,10]],"date-time":"2020-07-10T20:39:22Z","timestamp":1594413562000},"page":"908-920","source":"Crossref","is-referenced-by-count":11,"title":["EEJE: Two-Step Input Transformation for Robust DNN Against Adversarial Examples"],"prefix":"10.1109","volume":"8","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-3590-6024","authenticated-orcid":false,"given":"Seok-Hwan","family":"Choi","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jinmyeong","family":"Shin","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5091-8464","authenticated-orcid":false,"given":"Peng","family":"Liu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3556-5082","authenticated-orcid":false,"given":"Yoon-Ho","family":"Choi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"article-title":"Deep residual learning for image recognition","year":"2015","author":"he","key":"ref33"},{"article-title":"cleverhans v1.0.0: An adversarial machine learning library","year":"2016","author":"papernot","key":"ref32"},{"article-title":"MNIST handwritten digit database","year":"2010","author":"lecun","key":"ref31"},{"article-title":"On evaluating adversarial robustness","year":"2019","author":"carlini","key":"ref30"},{"article-title":"Defense against adversarial attacks with saak transform","year":"2018","author":"song","key":"ref35"},{"key":"ref34","article-title":"Very deep convolutional networks for large-scale image recognition","author":"simonyan","year":"2015","journal-title":"Proc Int Conf Learn Representations"},{"key":"ref10","article-title":"Deep learning godfathers bengio, hinton, and lecun say the field can fix its flaws","author":"ray","year":"2020","journal-title":"ZDNet"},{"article-title":"Learning with a strong adversary","year":"2015","author":"huang","key":"ref11"},{"article-title":"Adversarial machine learning at scale","year":"2016","author":"kurakin","key":"ref12"},{"article-title":"Distillation as a defense to adversarial perturbations against deep neural networks","year":"2015","author":"papernot","key":"ref13"},{"key":"ref14","article-title":"Explaining and harnessing adversarial examples","author":"goodfellow","year":"0","journal-title":"Proc Int Conf Learn Representations"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134057"},{"article-title":"Feature squeezing: Detecting adversarial examples in deep neural networks","year":"2017","author":"xu","key":"ref16"},{"article-title":"Pixeldefend: Leveraging generative models to understand and defend against adversarial examples","year":"2017","author":"song","key":"ref17"},{"article-title":"Deepfool: A simple and accurate method to fool deep neural networks","year":"2015","author":"moosavi-dezfooli","key":"ref18"},{"article-title":"Towards evaluating the robustness of neural networks","year":"2016","author":"carlini","key":"ref19"},{"key":"ref28","article-title":"Dozens of popular iphone apps vulnerable to man-in-the-middle attacks","author":"whittaker","year":"2017","journal-title":"ZDNet"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP.2019.8682351"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/PST47121.2019.8949068"},{"key":"ref3","article-title":"Intriguing properties of neural networks","author":"szegedy","year":"2014","journal-title":"Proc Int Conf Learn Representations"},{"article-title":"Adversarial examples in the physical world","year":"2016","author":"kurakin","key":"ref6"},{"article-title":"Cifar-10 (canadian institute for advanced research)","year":"2009","author":"krizhevsky","key":"ref29"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/ASAP.2019.00-16"},{"article-title":"Practical adversarial attack against object detector","year":"2018","author":"zhao","key":"ref8"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978392"},{"article-title":"Imbalanced malware images classification: A CNN based approach","year":"2017","author":"yue","key":"ref2"},{"article-title":"Ad-versarial: Defeating perceptual ad-blocking","year":"2018","author":"tram\u00e8r","key":"ref9"},{"article-title":"End to end learning for self-driving cars","year":"0","author":"bojarski","key":"ref1"},{"article-title":"The limitations of deep learning in adversarial settings","year":"2015","author":"papernot","key":"ref20"},{"article-title":"Countering adversarial images using input transformations","year":"2017","author":"guo","key":"ref22"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00894"},{"article-title":"Towards the science of security and privacy in machine learning","year":"2016","author":"papernot","key":"ref24"},{"key":"ref23","article-title":"Towards deep learning models resistant to adversarial attacks","author":"madry","year":"0","journal-title":"Proc Int Conf Learn Representations"},{"article-title":"Towards deep neural network architectures robust to adversarial examples","year":"2014","author":"gu","key":"ref26"},{"article-title":"Defensive distillation is not robust to adversarial examples","year":"2016","author":"carlini","key":"ref25"}],"container-title":["IEEE Transactions on Network Science and Engineering"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/6488902\/9475902\/09138779.pdf?arnumber=9138779","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,12,17]],"date-time":"2021-12-17T20:01:52Z","timestamp":1639771312000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9138779\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,4,1]]},"references-count":35,"journal-issue":{"issue":"2"},"URL":"https:\/\/doi.org\/10.1109\/tnse.2020.3008394","relation":{},"ISSN":["2327-4697","2334-329X"],"issn-type":[{"type":"electronic","value":"2327-4697"},{"type":"electronic","value":"2334-329X"}],"subject":[],"published":{"date-parts":[[2021,4,1]]}}}