{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,14]],"date-time":"2026-04-14T03:57:39Z","timestamp":1776139059638,"version":"3.50.1"},"reference-count":59,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"6","license":[{"start":{"date-parts":[[2023,6,1]],"date-time":"2023-06-01T00:00:00Z","timestamp":1685577600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2023,6,1]],"date-time":"2023-06-01T00:00:00Z","timestamp":1685577600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2023,6,1]],"date-time":"2023-06-01T00:00:00Z","timestamp":1685577600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"National Key R &#x0026; D Program of China","award":["2018AAA0102000"],"award-info":[{"award-number":["2018AAA0102000"]}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U21B2038"],"award-info":[{"award-number":["U21B2038"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61931008"],"award-info":[{"award-number":["61931008"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62025604"],"award-info":[{"award-number":["62025604"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U1936208"],"award-info":[{"award-number":["U1936208"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["6212200758"],"award-info":[{"award-number":["6212200758"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61976202"],"award-info":[{"award-number":["61976202"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100012226","name":"Fundamental Research Funds for the Central Universities","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100012226","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100004739","name":"Youth Innovation Promotion Association of the Chinese Academy of Sciences","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100004739","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Strategic Priority Research Program of Chinese Academy of Sciences","award":["XDB28000000"],"award-info":[{"award-number":["XDB28000000"]}]},{"name":"China National Postdoctoral Program for Innovative Talents","award":["BX2021298"],"award-info":[{"award-number":["BX2021298"]}]},{"DOI":"10.13039\/501100002858","name":"China Postdoctoral Science Foundation","doi-asserted-by":"publisher","award":["2022M713101"],"award-info":[{"award-number":["2022M713101"]}],"id":[{"id":"10.13039\/501100002858","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Pattern Anal. Mach. Intell."],"published-print":{"date-parts":[[2023,6,1]]},"DOI":"10.1109\/tpami.2022.3220849","type":"journal-article","created":{"date-parts":[[2022,11,9]],"date-time":"2022-11-09T20:41:18Z","timestamp":1668026478000},"page":"7668-7685","source":"Crossref","is-referenced-by-count":17,"title":["Rethinking Label Flipping Attack: From Sample Masking to Sample Thresholding"],"prefix":"10.1109","volume":"45","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-3512-7277","authenticated-orcid":false,"given":"Qianqian","family":"Xu","sequence":"first","affiliation":[{"name":"Key Laboratory of Intelligent Information Processing, Institute of Computing Technology, Chinese Academy of Sciences, Beijing, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4409-4999","authenticated-orcid":false,"given":"Zhiyong","family":"Yang","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, University of Chinese Academy of Sciences, Beijing, China"}]},{"given":"Yunrui","family":"Zhao","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, University of Chinese Academy of Sciences, Beijing, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7141-708X","authenticated-orcid":false,"given":"Xiaochun","family":"Cao","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Technology, Shenzhen Campus of Sun Yat-sen University, Shenzhen, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7542-296X","authenticated-orcid":false,"given":"Qingming","family":"Huang","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, University of Chinese Academy of Sciences, Beijing, China"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1145\/1128817.1128824"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-40994-3_25"},{"key":"ref3","first-page":"97","article-title":"Support vector machines under adversarial label noise","volume-title":"Proc. Asian Conf. Mach. Learn.","author":"Biggio"},{"key":"ref4","first-page":"1467","article-title":"Poisoning attacks against support vector machines","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Biggio"},{"key":"ref5","first-page":"695","article-title":"Adversarial attacks on node embeddings via graph poisoning","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Bojchevski"},{"key":"ref6","article-title":"Adversarial attacks and defences: A survey","author":"Chakraborty","year":"2018","journal-title":"CoRR"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1145\/2433396.2433420"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.2139\/ssrn.2408163"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2005.202"},{"key":"ref10","first-page":"321","article-title":"Why do adversarial attacks transfer? explaining transferability of evasion and poisoning attacks","volume-title":"Proc. USENIX Secur. Symp.","author":"Demontis"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref12","first-page":"1596","article-title":"Sever: A robust meta-algorithm for stochastic optimization","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Diakonikolas"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i04.5790"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2019\/810"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-05813-9_30"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-10605-2_32"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2015.2456887"},{"key":"ref18","article-title":"Explaining and harnessing adversarial examples","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Goodfellow"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2013.205"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-24261-3_7"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.3115\/1564131.1564137"},{"key":"ref23","article-title":"Labeled faces in the wild: A database for studying face recognition in unconstrained environments","volume-title":"Proc. Workshop Faces \u2018Real-Life\u2019 Images: Detection Alignment Recognit.","author":"Huang"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v27i1.8457"},{"key":"ref25","first-page":"405","article-title":"Online anomaly detection under adversarial impact","volume-title":"Proc. Int. Conf. Artif. Intell. Statist.","author":"Kloft"},{"key":"ref26","first-page":"26","article-title":"Siamese neural networks for one-shot image recognition","volume-title":"Proc. ICML Workshop Deep Learn.","author":"Koch"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1007\/s10994-021-06119-y"},{"key":"ref28","article-title":"Adversarial machine learning at scale","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Kurakin"},{"key":"ref29","first-page":"10791","article-title":"Cross-modal learning with adversarial samples","volume-title":"Proc. Annu. Conf. Neural Inf. Process. Syst.","author":"Li"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1145\/3394486.3403084"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-14267-3"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1145\/3397271.3401087"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v29i1.9569"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW50498.2020.00397"},{"key":"ref35","first-page":"1070","article-title":"Hamming distance metric learning","volume-title":"Proc. Annu. Conf. Neural Inf. Process. Syst.","author":"Norouzi"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1049\/iet-bmt.2014.0053"},{"key":"ref37","article-title":"Transferability in machine learning: From phenomena to black-box attacks using adversarial samples","author":"Papernot","year":"2016","journal-title":"CoRR"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-13453-2_1"},{"key":"ref40","article-title":"Certified robustness to label-flipping attacks via randomized smoothing","author":"Rosenfeld","year":"2020","journal-title":"CoRR"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2014.462"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1145\/1401890.1401965"},{"key":"ref43","first-page":"3517","article-title":"Certified defenses for data poisoning attacks","volume-title":"Proc. Annu. Conf. Neural Inf. Process. Syst.","author":"Steinhardt"},{"key":"ref44","article-title":"Intriguing properties of neural networks","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Szegedy"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2019.2893638"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1609\/hcomp.v2i1.13152"},{"key":"ref47","first-page":"870","article-title":"Adversarial label flips attack on support vector machines","volume-title":"Proc. Eur. Conf. Artif. Intell.","author":"Xiao"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1145\/2072298.2072350"},{"key":"ref49","first-page":"3896","article-title":"isplit LBI: Individualized partial ranking with ties via split LBI","volume-title":"Proc. Annu. Conf. Neural Inf. Process. Syst.","author":"Xu"},{"key":"ref50","first-page":"1282","article-title":"False discovery rate control and statistical quality assessment of annotators in crowdsourced ranking","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Xu"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1145\/3123266.3123267"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00920"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00426"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1109\/TCYB.2018.2882908"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2018.2867733"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1109\/CISS.2017.7926118"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2020.2975918"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1145\/2723372.2749430"},{"key":"ref59","first-page":"7614","article-title":"Transferable clean-label poisoning attacks on deep neural nets","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Zhu"}],"container-title":["IEEE Transactions on Pattern Analysis and Machine Intelligence"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/34\/10120646\/09944159.pdf?arnumber=9944159","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,4,4]],"date-time":"2025-04-04T19:26:32Z","timestamp":1743794792000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9944159\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,6,1]]},"references-count":59,"journal-issue":{"issue":"6"},"URL":"https:\/\/doi.org\/10.1109\/tpami.2022.3220849","relation":{},"ISSN":["0162-8828","2160-9292","1939-3539"],"issn-type":[{"value":"0162-8828","type":"print"},{"value":"2160-9292","type":"electronic"},{"value":"1939-3539","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,6,1]]}}}