{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,28]],"date-time":"2025-10-28T05:55:56Z","timestamp":1761630956576,"version":"3.37.3"},"reference-count":42,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"6","license":[{"start":{"date-parts":[[2022,11,1]],"date-time":"2022-11-01T00:00:00Z","timestamp":1667260800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2022,11,1]],"date-time":"2022-11-01T00:00:00Z","timestamp":1667260800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2022,11,1]],"date-time":"2022-11-01T00:00:00Z","timestamp":1667260800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Serv. Comput."],"published-print":{"date-parts":[[2022,11,1]]},"DOI":"10.1109\/tsc.2021.3090365","type":"journal-article","created":{"date-parts":[[2021,6,18]],"date-time":"2021-06-18T19:30:55Z","timestamp":1624044655000},"page":"3184-3197","source":"Crossref","is-referenced-by-count":7,"title":["Defending Adversarial Attacks via Semantic Feature Manipulation"],"prefix":"10.1109","volume":"15","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-8938-2364","authenticated-orcid":false,"given":"Shuo","family":"Wang","sequence":"first","affiliation":[{"name":"CSIRO&#x0027;s Data61 &amp; Cybersecurity CRC, Eveleigh, NSW, Australia"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3289-6599","authenticated-orcid":false,"given":"Surya","family":"Nepal","sequence":"additional","affiliation":[{"name":"CSIRO&#x0027;s Data61 &amp; Cybersecurity CRC, Eveleigh, NSW, Australia"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9050-5675","authenticated-orcid":false,"given":"Carsten","family":"Rudolph","sequence":"additional","affiliation":[{"name":"Faculty of Information Technology, Monash University, Melbourne, VIC, Australia"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6933-0145","authenticated-orcid":false,"given":"Marthie","family":"Grobler","sequence":"additional","affiliation":[{"name":"CSIRO&#x0027;s Data61 &amp; Cybersecurity CRC, Eveleigh, NSW, Australia"}]},{"given":"Shangyu","family":"Chen","sequence":"additional","affiliation":[{"name":"University of Melbourne, Melbourne, VIC, Australia"}]},{"given":"Tianle","family":"Chen","sequence":"additional","affiliation":[{"name":"Faculty of Information Technology, Monash University, Melbourne, VIC, Australia"}]},{"given":"Zike","family":"An","sequence":"additional","affiliation":[{"name":"University of British Columbia, Vancouver, BC, Canada"}]}],"member":"263","reference":[{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"article-title":"Adversarial examples in the physical world","year":"2016","author":"kurakin","key":"ref38"},{"article-title":"Fashion-MNIST: A novel image dataset for benchmarking machine learning algorithms","year":"2017","author":"xiao","key":"ref33"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/COMPSAC48688.2020.0-224"},{"key":"ref30","first-page":"1105","article-title":"Learning deep energy models","author":"ng","year":"2011","journal-title":"Int Conf Mach Learn"},{"article-title":"Very deep convolutional networks for large-scale image recognition","year":"2014","author":"simonyan","key":"ref37"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-015-0816-y"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2015.425"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2013.50"},{"article-title":"Foolbox: A python toolbox to benchmark the robustness of machine learning models","year":"2017","author":"rauber","key":"ref40"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1007\/s10994-010-5188-5"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1145\/1081870.1081950"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-40994-3_25"},{"article-title":"Intriguing properties of neural networks","year":"2013","author":"szegedy","key":"ref14"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.41"},{"article-title":"Distilling the knowledge in a neural network","year":"2015","author":"hinton","key":"ref16"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"article-title":"Understanding adversarial training: Increasing local stability of neural nets through robust optimization","year":"2015","author":"shaham","key":"ref18"},{"article-title":"Explaining and harnessing adversarial examples (2014)","year":"2014","author":"goodfellow","key":"ref19"},{"article-title":"Deep unsupervised clustering with Gaussian mixture variational autoencoders","year":"2016","author":"dilokthanakul","key":"ref28"},{"article-title":"On detecting adversarial perturbations","year":"2017","author":"metzen","key":"ref4"},{"article-title":"Disentangling by factorising","year":"2018","author":"kim","key":"ref27"},{"article-title":"On the (statistical) detection of adversarial examples","year":"2017","author":"grosse","key":"ref3"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134057"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.01247"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v32i1.11828"},{"article-title":"Defense-GAN: Protecting classifiers against adversarial attacks using generative models","year":"2018","author":"samangouei","key":"ref8"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140444"},{"article-title":"Delving into transferable adversarial examples and black-box attacks","year":"2016","author":"liu","key":"ref2"},{"article-title":"Featurized bidirectional GAN: Adversarial defense via adversarially learned semantic inference","year":"2018","author":"bao","key":"ref9"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00348"},{"article-title":"There is no free lunch in adversarial robustness (but there are unexpected benefits)","year":"2018","author":"tsipras","key":"ref22"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.01446"},{"article-title":"GANs trained by a two time-scale update rule converge to a local Nash equilibrium","year":"2017","author":"heusel","key":"ref42"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2021.3105238"},{"article-title":"Differentiable augmentation for data-efficient GAN training","year":"2020","author":"zhao","key":"ref41"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2019.2940533"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1147\/rd.41.0066"},{"key":"ref25","article-title":"beta-VAE: Learning basic visual concepts with a constrained variational framework","author":"higgins","year":"2017","journal-title":"Proc Int Conf Lear Representations"}],"container-title":["IEEE Transactions on Services Computing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/4629386\/9985445\/09460767.pdf?arnumber=9460767","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,1,9]],"date-time":"2023-01-09T21:17:14Z","timestamp":1673299034000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9460767\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,11,1]]},"references-count":42,"journal-issue":{"issue":"6"},"URL":"https:\/\/doi.org\/10.1109\/tsc.2021.3090365","relation":{},"ISSN":["1939-1374","2372-0204"],"issn-type":[{"type":"electronic","value":"1939-1374"},{"type":"electronic","value":"2372-0204"}],"subject":[],"published":{"date-parts":[[2022,11,1]]}}}