{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,4]],"date-time":"2026-02-04T16:41:14Z","timestamp":1770223274339,"version":"3.49.0"},"reference-count":73,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"4","license":[{"start":{"date-parts":[[2022,4,1]],"date-time":"2022-04-01T00:00:00Z","timestamp":1648771200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2022,4,1]],"date-time":"2022-04-01T00:00:00Z","timestamp":1648771200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2022,4,1]],"date-time":"2022-04-01T00:00:00Z","timestamp":1648771200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100012166","name":"National Key Research and Development Program of China","doi-asserted-by":"publisher","award":["2018YFC0830103"],"award-info":[{"award-number":["2018YFC0830103"]}],"id":[{"id":"10.13039\/501100012166","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61976250"],"award-info":[{"award-number":["61976250"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61702565"],"award-info":[{"award-number":["61702565"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U1811463"],"award-info":[{"award-number":["U1811463"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100021171","name":"Basic and Applied Basic Research Foundation of Guangdong Province","doi-asserted-by":"publisher","award":["2020B1515020048"],"award-info":[{"award-number":["2020B1515020048"]}],"id":[{"id":"10.13039\/501100021171","id-type":"DOI","asserted-by":"publisher"}]},{"name":"National High Level Talents Special Support Plan"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Pattern Anal. Mach. Intell."],"published-print":{"date-parts":[[2022,4,1]]},"DOI":"10.1109\/tpami.2020.3032061","type":"journal-article","created":{"date-parts":[[2020,10,21]],"date-time":"2020-10-21T17:45:42Z","timestamp":1603302342000},"page":"1725-1737","source":"Crossref","is-referenced-by-count":21,"title":["A Hamiltonian Monte Carlo Method for Probabilistic Adversarial Attack and Learning"],"prefix":"10.1109","volume":"44","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-5269-5471","authenticated-orcid":false,"given":"Hongjun","family":"Wang","sequence":"first","affiliation":[{"name":"school of Data and Computer Science, Sun Yat-sen University, Guangzhou, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4805-0926","authenticated-orcid":false,"given":"Guanbin","family":"Li","sequence":"additional","affiliation":[{"name":"school of Data and Computer Science, Sun Yat-sen University, Guangzhou, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2086-5410","authenticated-orcid":false,"given":"Xiaobai","family":"Liu","sequence":"additional","affiliation":[{"name":"Department of Computer Science, San Diego State University, San Diego, CA, USA"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2248-3755","authenticated-orcid":false,"given":"Liang","family":"Lin","sequence":"additional","affiliation":[{"name":"school of Data and Computer Science, Sun Yat-sen University, Guangzhou, China"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978392"},{"key":"ref2","article-title":"DARTS: Deceiving autonomous cars with toxic signs","volume":"abs\/1802.06430","author":"Sitawarin","year":"2018","journal-title":"CoRR"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00042"},{"key":"ref4","article-title":"Adversarial spheres","volume-title":"Proc. 6th Int. Conf. Learn. Representations","author":"Gilmer"},{"key":"ref5","article-title":"PixelDefend: Leveraging generative models to understand and defend against adversarial examples","volume-title":"Proc. 6th Int. Conf. Learn. Representations","author":"Song"},{"key":"ref6","article-title":"A boundary tilting persepective on the phenomenon of adversarial examples","volume":"abs\/1608.07690","author":"Tanay","year":"2016","journal-title":"CoRR"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00714"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1007\/s10479-011-0841-3"},{"key":"ref9","article-title":"Towards deep learning models resistant to adversarial attacks","volume-title":"Proc. 6th Int. Conf. Learn. Representations","author":"Madry"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"ref11","article-title":"Exploring the space of black-box attacks on deep neural networks","author":"Bhagoji","year":"2017"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.33012253"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00445"},{"key":"ref15","first-page":"6626","article-title":"GANs trained by a two time-scale update rule converge to a local nash equilibrium","volume-title":"Proc. Advances Neural Inf. Process. Syst.","author":"Heusel"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1017\/cbo9781316026786.010"},{"key":"ref17","article-title":"Unsupervised representation learning with deep convolutional generative adversarial networks","volume-title":"Proc. 4th Int. Conf. Learn. Representations","author":"Radford"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.01153"},{"key":"ref19","article-title":"Towards GAN benchmarks which require generalization","volume-title":"Proc. 7th Int. Conf. Learn. Representations","author":"Gulrajani"},{"key":"ref20","article-title":"Intriguing properties of neural networks","volume-title":"Proc. 2nd Int. Conf. Learn. Representations","author":"Szegedy"},{"key":"ref21","article-title":"Adversarial machine learning at scale","volume-title":"Proc. 5th Int. Conf. Learn. Representations","author":"Kurakin"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1162\/089976602760128018"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00059"},{"key":"ref24","article-title":"Explaining and harnessing adversarial examples","volume-title":"Proc. 3rd Int. Conf. Learn. Representations","author":"Goodfellow"},{"key":"ref25","first-page":"3866","article-title":"Nattack: Learning the distributions of adversarial examples for an improved black-box attack on deep neural networks","volume":"97","author":"Li","year":"2019"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.615"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/CISS.2018.8362326"},{"key":"ref28","article-title":"On detecting adversarial perturbations","volume-title":"Proc. 5th Int. Conf. Learn. Representations","author":"Metzen"},{"key":"ref29","article-title":"Characterizing adversarial subspaces using local intrinsic dimensionality","volume-title":"Proc. 6th Int. Conf. Learn. Representations","author":"Ma"},{"key":"ref30","first-page":"7167","article-title":"A simple unified framework for detecting out-of-distribution samples and adversarial attacks","volume-title":"Proc. Advances Neural Inf. Process. Syst.","author":"Lee"},{"key":"ref31","first-page":"7717","article-title":"Attacks meet interpretability: Attribute-steered detection of adversarial samples","volume-title":"Proc. Advances Neural Inf. Process. Syst.","author":"Tao"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/SIPROCESS.2018.8600516"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.41"},{"key":"ref34","article-title":"Extending defensive distillation","author":"Papernot","year":"2017"},{"key":"ref35","first-page":"274","article-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","volume-title":"Proc. 35th Int. Conf. Mach. Learn.","author":"Athalye"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01234-2_23"},{"key":"ref37","article-title":"Mitigating adversarial effects through randomization","volume-title":"Proc. 6th Int. Conf. Learn. Representations","author":"Xie"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1145\/3357384.3357999"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00044"},{"key":"ref40","article-title":"Adv-BNN: Improved adversarial defense through robust Bayesian neural network","volume-title":"Proc. 7th Int. Conf. Learn. Representations","author":"Liu"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00357"},{"key":"ref42","article-title":"Towards deep neural network architectures robust to adversarial examples","volume-title":"Proc. 3rd Int. Conf. Learn. Representations","author":"Gu"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00191"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/TCYB.2019.2914099"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.33018417"},{"key":"ref46","article-title":"Adversarial logit pairing","author":"Kannan","year":"2018"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.01149"},{"key":"ref48","first-page":"3353","article-title":"Adversarial training for free!","volume-title":"Proc. Advances Neural Inf. Process. Syst.","author":"Shafahi"},{"key":"ref49","first-page":"227","article-title":"You only propagate once: Accelerating adversarial training via maximal principle","volume-title":"Proc. Advances Neural Inf. Process. Syst.","author":"Zhang"},{"key":"ref50","article-title":"Probabilistic inference using Markov Chain Monte Carlo methods","author":"Neal","year":"1993"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1016\/0370-2693(87)91197-X"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1201\/b10905-6"},{"key":"ref53","first-page":"343","article-title":"Adaptively scaling the metropolis algorithm using expected squared jumped distance","volume":"20","author":"Pasarica","year":"2010","journal-title":"Statistica Sinica"},{"key":"ref54","first-page":"1218","article-title":"Markov chain monte carlo and variational inference: Bridging the gap","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Salimans"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.5555\/2627435.2638586"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1109\/34.1000239"},{"key":"ref57","first-page":"1683","article-title":"Stochastic gradient hamiltonian monte carlo","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Chen"},{"key":"ref58","first-page":"5140","article-title":"A-NICE-MC: Adversarial training for MCMC","volume-title":"Proc. Advances Neural Inf. Process. Syst.","author":"Song"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v32i1.11834"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1063\/1.1698728"},{"key":"ref61","article-title":"On the convergence of adam and beyond","volume-title":"Proc. 6th Int. Conf. Learn. Representations","author":"Reddi"},{"key":"ref62","article-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref64","article-title":"The MNIST database of handwritten digits","author":"LeCun","year":"1998"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref66","article-title":"Very deep convolutional networks for large-scale image recognition","author":"Simonyan","year":"2015"},{"key":"ref67","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.634"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.243"},{"key":"ref69","article-title":"Adversarial robustness toolbox v1.0.1","volume":"1807.01069","author":"Nicolae","year":"2018","journal-title":"CoRR"},{"key":"ref70","article-title":"Delving into transferable adversarial examples and black-box attacks","volume-title":"Proc. 5th Int. Conf. Learn. Representations","author":"Liu"},{"key":"ref71","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00284"},{"key":"ref72","first-page":"7472","article-title":"Theoretically principled trade-off between robustness and accuracy","volume-title":"Proc. 36th Int. Conf. Mach. Learn.","author":"Zhang"},{"key":"ref73","doi-asserted-by":"publisher","DOI":"10.1109\/CEC.2008.4631255"}],"container-title":["IEEE Transactions on Pattern Analysis and Machine Intelligence"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/34\/9729045\/09229176.pdf?arnumber=9229176","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,1,9]],"date-time":"2024-01-09T23:13:41Z","timestamp":1704842021000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9229176\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,4,1]]},"references-count":73,"journal-issue":{"issue":"4"},"URL":"https:\/\/doi.org\/10.1109\/tpami.2020.3032061","relation":{},"ISSN":["0162-8828","2160-9292","1939-3539"],"issn-type":[{"value":"0162-8828","type":"print"},{"value":"2160-9292","type":"electronic"},{"value":"1939-3539","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,4,1]]}}}