{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,11]],"date-time":"2026-03-11T07:46:07Z","timestamp":1773215167557,"version":"3.50.1"},"reference-count":42,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"3","license":[{"start":{"date-parts":[[2021,3,1]],"date-time":"2021-03-01T00:00:00Z","timestamp":1614556800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2021,3,1]],"date-time":"2021-03-01T00:00:00Z","timestamp":1614556800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2021,3,1]],"date-time":"2021-03-01T00:00:00Z","timestamp":1614556800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61977046"],"award-info":[{"award-number":["61977046"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61603248"],"award-info":[{"award-number":["61603248"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61876107"],"award-info":[{"award-number":["61876107"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U1803261"],"award-info":[{"award-number":["U1803261"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Committee of Science and Technology, Shanghai, China","award":["19510711200"],"award-info":[{"award-number":["19510711200"]}]},{"name":"1000-Talent Plan"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Pattern Anal. Mach. Intell."],"published-print":{"date-parts":[[2021,3,1]]},"DOI":"10.1109\/tpami.2019.2936378","type":"journal-article","created":{"date-parts":[[2019,8,22]],"date-time":"2019-08-22T19:46:06Z","timestamp":1566503166000},"page":"1100-1109","source":"Crossref","is-referenced-by-count":21,"title":["Adversarial Attack Type I: Cheat Classifiers by Significant Changes"],"prefix":"10.1109","volume":"43","author":[{"given":"Sanli","family":"Tang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4285-6520","authenticated-orcid":false,"given":"Xiaolin","family":"Huang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0584-6286","authenticated-orcid":false,"given":"Mingjian","family":"Chen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9992-7919","authenticated-orcid":false,"given":"Chengjin","family":"Sun","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4801-7162","authenticated-orcid":false,"given":"Jie","family":"Yang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23198"},{"key":"ref38","article-title":"Labeled faces in the wild: A database for studying face recognition in unconstrained environments","author":"huang","year":"2007"},{"key":"ref33","article-title":"BEGAN: Boundary equilibrium generative adversarial networks","author":"berthelot","year":"2017","journal-title":"arXiv 1703 10717"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298682"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.645"},{"key":"ref30","first-page":"5967","article-title":"Fader networks: Manipulating images by sliding attributes","author":"lample","year":"2017","journal-title":"Proc Int Conf Neural Inf Process"},{"key":"ref37","article-title":"TensorFlow: Large-scale machine learning on heterogeneous distributed systems","author":"abadi","year":"2016","journal-title":"arXiv 1603 04467"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2015.425"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"key":"ref34","article-title":"Adam: A method for stochastic optimization","author":"kingma","year":"2015","journal-title":"Proc Int Conf Learn Representations"},{"key":"ref10","article-title":"A theoretical framework for robustness of (deep) classifiers against adversarial examples","author":"wang","year":"2017","journal-title":"Proc Int Conf Learn Representations Workshop"},{"key":"ref40","article-title":"Adversarial logit pairing","author":"kannan","year":"2018"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.41"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref13","first-page":"10","article-title":"EAD: Elastic-net attacks to deep neural networks via adversarial examples","author":"chen","year":"2018","journal-title":"Proc 32nd AAAI Conf Artif Intell"},{"key":"ref14","article-title":"Towards deep learning models resistant to adversarial attacks","author":"madry","year":"2018","journal-title":"Proc Int Conf Learn Representations"},{"key":"ref15","first-page":"8312","article-title":"Constructing unrestricted adversarial examples with generative models","author":"song","year":"2018","journal-title":"Proc Int Conf Neural Inf Process"},{"key":"ref16","article-title":"Adversarial autoencoders","author":"makhzani","year":"2015"},{"key":"ref17","first-page":"2642","article-title":"Conditional image synthesis with auxiliary classifier GANs","author":"odena","year":"2017","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00453"},{"key":"ref19","first-page":"2687","article-title":"Learning to Attack: Adversarial Transformation Networks","author":"baluja","year":"2018","journal-title":"Proc 32rd AAAI Conf Artif Intell"},{"key":"ref28","first-page":"3581","article-title":"Semi-supervised learning with deep generative models","author":"kingma","year":"2014","journal-title":"Proc Int Conf Neural Inf Process"},{"key":"ref4","first-page":"2672","article-title":"Generative adversarial nets","author":"goodfellow","year":"2014","journal-title":"Proc Int Conf Neural Inf Process"},{"key":"ref27","article-title":"Conditional generative adversarial nets","author":"mirza","year":"2014","journal-title":"arXiv preprint arXiv 1411 1784"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.660"},{"key":"ref6","article-title":"Explaining and harnessing adversarial examples","author":"goodfellow","year":"2015","journal-title":"Proc Int Conf Learn Representations"},{"key":"ref29","first-page":"6513","article-title":"Good semi-supervised learning that requires a bad GAN","author":"dai","year":"2017","journal-title":"Proc Int Conf Neural Inf Process"},{"key":"ref5","article-title":"Auto-encoding variational Bayes","author":"kingma","year":"2014","journal-title":"Proc Int Conf Learn Representations"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2018.2886017"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.4204\/EPTCS.257.3"},{"key":"ref2","first-page":"1097","article-title":"ImageNet classification with deep convolutional neural networks","author":"krizhevsky","year":"2012","journal-title":"Proc Int Conf Neural Inf Process"},{"key":"ref9","article-title":"Intriguing properties of neural networks","author":"szegedy","year":"2014","journal-title":"Proc Int Conf Learn Representations"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref20","article-title":"Generative adversarial trainer: Defense to adversarial perturbations with GAN","author":"lee","year":"2017"},{"key":"ref22","first-page":"52","article-title":"IntroVAE: Introspective variational autoencoders for photographic image synthesis","author":"huang","year":"2018","journal-title":"Proc Int Conf Neural Inf Process"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2018\/543"},{"key":"ref42","article-title":"Ensemble adversarial training: Attacks and defenses","author":"tramer","year":"2018","journal-title":"Proc Int Conf Learn Representations"},{"key":"ref24","article-title":"Adversarial spheres","author":"gilmer","year":"2018"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298640"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1201\/9781351251389-8"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"}],"container-title":["IEEE Transactions on Pattern Analysis and Machine Intelligence"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/34\/9346108\/08807315.pdf?arnumber=8807315","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,5,10]],"date-time":"2022-05-10T14:49:27Z","timestamp":1652194167000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/8807315\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,3,1]]},"references-count":42,"journal-issue":{"issue":"3"},"URL":"https:\/\/doi.org\/10.1109\/tpami.2019.2936378","relation":{},"ISSN":["0162-8828","2160-9292","1939-3539"],"issn-type":[{"value":"0162-8828","type":"print"},{"value":"2160-9292","type":"electronic"},{"value":"1939-3539","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,3,1]]}}}