{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,1]],"date-time":"2026-06-01T23:24:54Z","timestamp":1780356294053,"version":"3.54.1"},"reference-count":132,"publisher":"Wiley","issue":"1","license":[{"start":{"date-parts":[[2021,6,22]],"date-time":"2021-06-22T00:00:00Z","timestamp":1624320000000},"content-version":"vor","delay-in-days":172,"URL":"http:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62072037"],"award-info":[{"award-number":["62072037"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U1936218"],"award-info":[{"award-number":["U1936218"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61876019"],"award-info":[{"award-number":["61876019"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["onlinelibrary.wiley.com"],"crossmark-restriction":true},"short-container-title":["Wireless Communications and Mobile Computing"],"published-print":{"date-parts":[[2021,1]]},"abstract":"<jats:p>With the rapid evolution of the Internet, the application of artificial intelligence fields is more and more extensive, and the era of AI has come. At the same time, adversarial attacks in the AI field are also frequent. Therefore, the research into adversarial attack security is extremely urgent. An increasing number of researchers are working in this field. We provide a comprehensive review of the theories and methods that enable researchers to enter the field of adversarial attack. This article is according to the \u201cWhy? \u2192 What? \u2192 How?\u201d research line for elaboration. Firstly, we explain the significance of adversarial attack. Then, we introduce the concepts, types, and hazards of adversarial attack. Finally, we review the typical attack algorithms and defense techniques in each application area. Facing the increasingly complex neural network model, this paper focuses on the fields of image, text, and malicious code and focuses on the adversarial attack classifications and methods of these three data types, so that researchers can quickly find their own type of study. At the end of this review, we also raised some discussions and open issues and compared them with other similar reviews.<\/jats:p>","DOI":"10.1155\/2021\/4907754","type":"journal-article","created":{"date-parts":[[2021,6,22]],"date-time":"2021-06-22T19:35:13Z","timestamp":1624390513000},"update-policy":"https:\/\/doi.org\/10.1002\/crossmark_policy","source":"Crossref","is-referenced-by-count":68,"title":["A Survey on Adversarial Attack in the Age of Artificial Intelligence"],"prefix":"10.1155","volume":"2021","author":[{"given":"Zixiao","family":"Kong","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jingfeng","family":"Xue","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1572-068X","authenticated-orcid":false,"given":"Yong","family":"Wang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Lu","family":"Huang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zequn","family":"Niu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Feng","family":"Li","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"311","published-online":{"date-parts":[[2021,6,22]]},"reference":[{"key":"e_1_2_12_1_2","doi-asserted-by":"crossref","unstructured":"GaoY. XuC. WangD. ChenS. RanasingheD. C. andNepalS. STRIP: a defence against Trojan attacks on deep neural networks Proceedings of the 35th Annual Computer Security Applications Conference 2019 New York NY USA 113\u2013125.","DOI":"10.1145\/3359789.3359790"},{"key":"e_1_2_12_2_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2018.07.023"},{"key":"e_1_2_12_3_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.ipm.2020.102468"},{"key":"e_1_2_12_4_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2018.02.060"},{"key":"e_1_2_12_5_2","unstructured":"SzegedyC. ZarembaW. SutskeverI. BrunaJ. ErhanD. GoodfellowI. andFergusR. Intriguing properties of neural networks 2nd International Conference on Learning Representations ICLR 2014 2014 Banff Canada https:\/\/nyuscholars.nyu.edu\/en\/publications\/intriguing-properties-of-neural-networks."},{"key":"e_1_2_12_6_2","doi-asserted-by":"crossref","unstructured":"LiuX. ZhangJ. LinY. andLiH. ATMPA: attacking machine learning-based malware visualization detection methods via adversarial examples Proc. IEEE\/ACM Int. Symp. Qual. Service June 2019 Phoenix AZ USA.","DOI":"10.1145\/3326285.3329073"},{"key":"e_1_2_12_7_2","doi-asserted-by":"crossref","unstructured":"ZhouM. WuJ. LiuY. LiuS. andZhuC. DaST: data-free substitute training for adversarial attacks 2020 IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR) 2020 Seattle WA USA.","DOI":"10.1109\/CVPR42600.2020.00031"},{"key":"e_1_2_12_8_2","doi-asserted-by":"publisher","DOI":"10.1109\/TNSE.2020.2985096"},{"key":"e_1_2_12_9_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2021.107956"},{"key":"e_1_2_12_10_2","doi-asserted-by":"crossref","unstructured":"Di WuJ. L. DasS. K. WuJ. JiY. andLiZ. A novel distributed denial-of-service attack detection scheme for software defined networking environments 2018 IEEE international conference on communications (ICC) 2018 Kansas City MO USA.","DOI":"10.1109\/ICC.2018.8422448"},{"key":"e_1_2_12_11_2","doi-asserted-by":"crossref","unstructured":"ZhouB. LiJ. WuJ. GuoS. GuY. andLiZ. Machine-learning-based online distributed denial-of-service attack detection using spark streaming IEEE International Conference on Communications (ICC) 2018 Kansas City MO USA.","DOI":"10.1109\/ICC.2018.8422327"},{"key":"e_1_2_12_12_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2945787"},{"key":"e_1_2_12_13_2","unstructured":"CarliniN. KatzG. BarrettC. andDillD. Ground-truth adversarial examples 2017 https:\/\/arxiv.org\/abs\/1709.10207."},{"key":"e_1_2_12_14_2","doi-asserted-by":"crossref","unstructured":"NasrM. ShokriR. andHoumansadrA. Comprehensive privacy analysis of deep learning: passive and active white-box inference attacks against centralized and federated learning 2019 IEEE Symposium on Security and Privacy (SP) 2019 San Francisco CA USA 739\u2013753 https:\/\/doi.org\/10.1109\/SP.2019.00065 2-s2.0-85072925335.","DOI":"10.1109\/SP.2019.00065"},{"key":"e_1_2_12_15_2","doi-asserted-by":"crossref","unstructured":"XiaoW. JiangH. andXiaS. A new black box attack generating adversarial examples based on reinforcement learning 2020 Information Communication Technologies Conference (ICTC) 2020 Nanjing China 141\u2013146 https:\/\/doi.org\/10.1109\/ICTC49638.2020.9123270.","DOI":"10.1109\/ICTC49638.2020.9123270"},{"key":"e_1_2_12_16_2","doi-asserted-by":"publisher","DOI":"10.1109\/TSMC.2019.2896323"},{"key":"e_1_2_12_17_2","unstructured":"KatzirZ.andEloviciY. Why blocking targeted adversarial perturbations impairs the ability to learn 2019 https:\/\/arxiv.org\/abs\/1907.05718."},{"key":"e_1_2_12_18_2","doi-asserted-by":"crossref","unstructured":"WuA. HanY. ZhangQ. andKuangX. Untargeted adversarial attack via expanding the semantic gap 2019 IEEE International Conference on Multimedia and Expo (ICME) 2019 Shanghai China 514\u2013519 https:\/\/doi.org\/10.1109\/ICME.2019.00095 2-s2.0-85070990557.","DOI":"10.1109\/ICME.2019.00095"},{"key":"e_1_2_12_19_2","unstructured":"AndersonH. S. KharkarA. FilarB. EvansD. andRothP. Learning to evade static PE machine learning malware models via reinforcement learning 2018 https:\/\/arxiv.org\/abs\/1801.08917."},{"key":"e_1_2_12_20_2","unstructured":"DemontisA. MelisM. PintorM. JagielskiM. BiggioB. OpreaA. Nita-RotaruC. andRoliF. Why do adversarial attacks transfer? Explaining transferability of evasion and poisoning attacks 28th {USENIX} Security Symposium ({USENIX} Security 19) 2019 USA 321\u2013338."},{"key":"e_1_2_12_21_2","doi-asserted-by":"crossref","unstructured":"WangB. YaoY. ShanS. LiH. ViswanathB. ZhengH. andZhaoB. Y. Neural cleanse: identifying and mitigating backdoor attacks in neural networks 2019 IEEE Symposium on Security and Privacy (SP) 2019 San Francisco CA USA 707\u2013723 https:\/\/doi.org\/10.1109\/SP.2019.00031 2-s2.0-85072920050.","DOI":"10.1109\/SP.2019.00031"},{"key":"e_1_2_12_22_2","doi-asserted-by":"crossref","unstructured":"NguyenT. D. RiegerP. MiettinenM. andSadeghiA.-R. Poisoning attacks on federated learning-based iot intrusion detection system Workshop on Decentralized IoT Systems and Security (DISS) @ NDSS Symposium 2020 2020 San Diego USA 23\u201326.02.","DOI":"10.14722\/diss.2020.23003"},{"key":"e_1_2_12_23_2","doi-asserted-by":"crossref","unstructured":"MonteiroJ. AkhtarZ. andFalkT. Generalizable adversarial examples detection based on bi-model decision mismatch 2019 IEEE International Conference on Systems Man and Cybernetics (SMC) 2019 Bari Italy 2839\u20132844 https:\/\/doi.org\/10.1109\/SMC.2019.8913861.","DOI":"10.1109\/SMC.2019.8913861"},{"key":"e_1_2_12_24_2","doi-asserted-by":"crossref","unstructured":"PapernotN. McDanielP. SwamiA. andHarangR. E. Crafting adversarial input sequences for recurrent neural networks MILCOM 2016-2016 IEEE Military Communications Conference 2016 Baltimore MD USA 49\u201354 https:\/\/doi.org\/10.1109\/MILCOM.2016.7795300 2-s2.0-85011845631.","DOI":"10.1109\/MILCOM.2016.7795300"},{"key":"e_1_2_12_25_2","unstructured":"JinD.andJinZ. Text Fool: Fool your Model with Natural Adversarial Text 2019."},{"key":"e_1_2_12_26_2","doi-asserted-by":"crossref","unstructured":"EbrahimiJ. RaoA. LowdD. andDouD. Hot flip: white-box adversarial examples for text classification Proceedings of the 56th Annual Meeting of the Association for Computational Linguistics (Volume 2: Short Papers) 2018 Melbourne Australia 31\u201336 https:\/\/doi.org\/10.18653\/v1\/P18-2006.","DOI":"10.18653\/v1\/P18-2006"},{"key":"e_1_2_12_27_2","doi-asserted-by":"crossref","unstructured":"AlzantotM. SharmaY. ElgoharyA. HoB.-J. SrivastavaM. andChangK.-W. Generating natural language adversarial examples Proceedings of the 2018 Conference on Empirical Methods in Natural Language Processing 2018 Brussels Belgium https:\/\/doi.org\/10.18653\/v1\/d18-1316.","DOI":"10.18653\/v1\/D18-1316"},{"key":"e_1_2_12_28_2","doi-asserted-by":"crossref","unstructured":"GaoJ. LanchantinJ. SoffaM. L. andQiY. Black-box generation of adversarial text sequences to evade deep learning classifiers 2018 IEEE Security and Privacy Workshops (SPW) 2018 San Francisco CA USA 50\u201356 https:\/\/doi.org\/10.1109\/SPW.2018.00016 2-s2.0-85052223531.","DOI":"10.1109\/SPW.2018.00016"},{"key":"e_1_2_12_29_2","unstructured":"ZhaoZ. DuaD. andSinghS. Generating natural adversarial examples 2018 https:\/\/arxiv.org\/abs\/1710.11342."},{"key":"e_1_2_12_30_2","doi-asserted-by":"crossref","unstructured":"LiJ. JiS. DuT. LiB. andWangT. Text bugger: generating adversarial text against real-world applications Proceedings 2019 Network and Distributed System Security Symposium 2019 San Diego CA USA https:\/\/doi.org\/10.14722\/ndss.2019.23138.","DOI":"10.14722\/ndss.2019.23138"},{"key":"e_1_2_12_31_2","doi-asserted-by":"crossref","unstructured":"GilY. ChaiY. GorodisskyO. andBerantJ. White-to-black: efficient distillation of black-box adversarial attacks Proceedings of the 2019 Conference of the North 2019 Minneapolis Minnesota https:\/\/doi.org\/10.18653\/v1\/n19-1139.","DOI":"10.18653\/v1\/N19-1139"},{"key":"e_1_2_12_32_2","doi-asserted-by":"publisher","DOI":"10.1109\/TEVC.2010.2059031"},{"key":"e_1_2_12_33_2","doi-asserted-by":"publisher","DOI":"10.1007\/BF01589116"},{"key":"e_1_2_12_34_2","unstructured":"GoodfellowI. J. ShlensJ. andSzegedyC. Explaining and harnessing adversarial examples 2014 https:\/\/arxiv.org\/abs\/1412.6572."},{"key":"e_1_2_12_35_2","doi-asserted-by":"crossref","unstructured":"PapernotN. McdanielP. JhaS. FredriksonM. CelikZ. B. andSwamiA. The limitations of deep learning in adversarial settings 2016 IEEE European Symposium on Security and Privacy (EuroS&P) 2015 Saarbruecken Germany 372\u2013387 https:\/\/doi.org\/10.1109\/eurosp.2016.36 2-s2.0-84978047763.","DOI":"10.1109\/EuroSP.2016.36"},{"key":"e_1_2_12_36_2","doi-asserted-by":"crossref","unstructured":"Moosavi-DezfooliS. M. FawziA. andFrossardP. DeepFool: a simple and accurate method to fool deep neural networks 2016 IEEE Conference on Computer Vision and Pattern Recognition (CVPR) 2016 Las Vegas NV USA 2574\u20132582 https:\/\/doi.org\/10.1109\/cvpr.2016.282 2-s2.0-84986325571.","DOI":"10.1109\/CVPR.2016.282"},{"key":"e_1_2_12_37_2","first-page":"99","volume-title":"Artificial Intelligence Safety and Security","author":"Kurakin A.","year":"2016"},{"key":"e_1_2_12_38_2","doi-asserted-by":"publisher","DOI":"10.1109\/tevc.2019.2890858"},{"key":"e_1_2_12_39_2","doi-asserted-by":"crossref","unstructured":"CarliniN.andWagnerD. Towards evaluating the robustness of neural networks 2017 IEEE Symposium on Security and Privacy (SP) 2017 San Jose CA USA 39\u201357 https:\/\/doi.org\/10.1109\/SP.2017.49 2-s2.0-85024480368.","DOI":"10.1109\/SP.2017.49"},{"key":"e_1_2_12_40_2","doi-asserted-by":"crossref","unstructured":"Moosavi-DezfooliS.-M. FawziA. FawziO. andFrossardP. Universal adversarial perturbations 2017 IEEE Conference on Computer Vision and Pattern Recognition (CVPR) 2017 Honolulu HI USA 86\u201394 https:\/\/doi.org\/10.1109\/CVPR.2017.17 2-s2.0-85041904512.","DOI":"10.1109\/CVPR.2017.17"},{"key":"e_1_2_12_41_2","unstructured":"SarkarS. BansalA. MahbubU. andChellappaR. UPSET and ANGRI : breaking high performance image classifiers 2017 https:\/\/arxiv.org\/abs\/1707.01159."},{"key":"e_1_2_12_42_2","article-title":"Houdini: fooling deep structured visual and speech recognition models with adversarial examples","volume":"30","author":"Cisse M.","year":"2017","journal-title":"Advances in neural information processing systems"},{"key":"e_1_2_12_43_2","unstructured":"BalujaS.andFischerI. Adversarial transformation networks: learning to generate adversarial examples 2017 https:\/\/arxiv.org\/abs\/1703.09387."},{"key":"e_1_2_12_44_2","unstructured":"HuW.andTanY. Generating adversarial malware examples for black-box attacks based on GAN 2017 https:\/\/arxiv.org\/abs\/1702.05983."},{"key":"e_1_2_12_45_2","doi-asserted-by":"crossref","unstructured":"Al-DujailiA. HuangA. HembergE. andO\u2019ReillyU. M. Adversarial deep learning for robust detection of binary encoded malware 2018 IEEE Security and Privacy Workshops (SPW) 2018 San Francisco CA USA 76\u201382 https:\/\/doi.org\/10.1109\/spw.2018.00020 2-s2.0-85052222151.","DOI":"10.1109\/SPW.2018.00020"},{"key":"e_1_2_12_46_2","doi-asserted-by":"crossref","unstructured":"KolosnjajiB. DemontisA. BiggioB. MaiorcaD. GiacintoG. EckertC. andRoliF. Adversarial malware binaries: evading deep learning for malware detection in executables 2018 26th European Signal Processing Conference (EUSIPCO) 2018 Rome Italy 533\u2013537 https:\/\/doi.org\/10.23919\/eusipco.2018.8553214 2-s2.0-85058628512.","DOI":"10.23919\/EUSIPCO.2018.8553214"},{"key":"e_1_2_12_47_2","unstructured":"SongW. LiX. AfrozS. GargD. KuznetsovD. andYinH. Automatic generation of adversarial examples for interpreting malware classifiers 2020 https:\/\/arxiv.org\/abs\/2003.03100."},{"key":"e_1_2_12_48_2","doi-asserted-by":"crossref","unstructured":"RosenbergI. ShabtaiA. EloviciY. andRokachL. Query-efficient black-box attack against sequence-based malware classifiers Annual Computer Security Applications Conference 2020 Austin TX USA 611\u2013626 https:\/\/doi.org\/10.1145\/3427228.3427230.","DOI":"10.1145\/3427228.3427230"},{"key":"e_1_2_12_49_2","unstructured":"EbrahimiM. ZhangN. HuJ. RazaM. T. andChenH. Binary black-box evasion attacks against deep learning-based static malware detectors with adversarial byte-level language model 2020 https:\/\/arxiv.org\/abs\/2012.07994."},{"key":"e_1_2_12_50_2","doi-asserted-by":"crossref","unstructured":"SharifM. BhagavatulaS. BauerL. andReiterM. K. Accessorize to a crime: real and stealthy attacks on state-of-the-art face recognition Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security 2016 Vienna Austria 1528\u20131540 https:\/\/doi.org\/10.1145\/2976749.2978392 2-s2.0-84995426895.","DOI":"10.1145\/2976749.2978392"},{"key":"e_1_2_12_51_2","doi-asserted-by":"crossref","unstructured":"PapernotN. McDanielP. GoodfellowI. JhaS. CelikZ. B. andSwamiA. Practical black-box attacks against machine learning Proceedings of the 2017 ACM on Asia Conference on Computer and Communications Security 2017 Abu Dhabi United Arab Emirates 506\u2013519 https:\/\/doi.org\/10.1145\/3052973.3053009 2-s2.0-85021992078.","DOI":"10.1145\/3052973.3053009"},{"key":"e_1_2_12_52_2","unstructured":"ShafahiA. HuangW. R. NajibiM. SuciuO. StuderC. DumitrasT. andGoldsteinT. Poison frogs! Targeted clean-label poisoning attacks on neural networks 2018 https:\/\/arxiv.org\/abs\/1804.00792."},{"key":"e_1_2_12_53_2","unstructured":"MirskyY. MahlerT. ShelefI. andEloviciY. CT-GAN: malicious tampering of 3D medical imagery using deep learning 28th {USENIX} Security Symposium ({USENIX} Security 19 2019 USA 461\u2013478."},{"key":"e_1_2_12_54_2","doi-asserted-by":"crossref","unstructured":"ChenS. T. CorneliusC. MartinJ. andChauD. H. P. Shape Shifter: Robust Physical Adversarial Attack on Faster R-CNN Object Detector: Recognizing Outstanding [Ph.D. thesis] 2019 Springer.","DOI":"10.1007\/978-3-030-10925-7_4"},{"key":"e_1_2_12_55_2","unstructured":"XiaoQ. ChenY. ShenC. ChenY. andLiK. Seeing is not believing: camouflage attacks on image scaling algorithms 28th {USENIX} Security Symposium ({USENIX} Security 19) 2019 USENIX Association Santa Clara CA 443\u2013460."},{"key":"e_1_2_12_56_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.jnca.2020.102634"},{"key":"e_1_2_12_57_2","doi-asserted-by":"crossref","unstructured":"SolanoJ. LopezC. RiveraE. CastelblancoA. TenganaL. andOchoaM. SCRAP: synthetically composed replay attacks vs. adversarial machine learning attacks against mouse-based biometric authentication CCS \u203220: 2020 ACM SIGSAC Conference on Computer and Communications Security 2020 37\u201347 https:\/\/doi.org\/10.1145\/3411508.3421378.","DOI":"10.1145\/3411508.3421378"},{"key":"e_1_2_12_58_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i04.5767"},{"key":"e_1_2_12_59_2","doi-asserted-by":"crossref","unstructured":"ZhangH. ZhouH. MiaoN. andLiL. Generating fluent adversarial examples for natural languages Proceedings of the 57th Annual Meeting of the Association for Computational Linguistics 2019 Florence Italy https:\/\/doi.org\/10.18653\/v1\/P19-1559.","DOI":"10.18653\/v1\/P19-1559"},{"key":"e_1_2_12_60_2","doi-asserted-by":"crossref","unstructured":"ZangY. QiF. YangC. LiuZ. ZhangM. LiuQ. andSunM. Word-level textual adversarial attacking as combinatorial optimization Proceedings of the 58th Annual Meeting of the Association for Computational Linguistics 2019 https:\/\/doi.org\/10.18653\/v1\/2020.acl-main.540.","DOI":"10.18653\/v1\/2020.acl-main.540"},{"key":"e_1_2_12_61_2","unstructured":"RaffE. BarkerJ. SylvesterJ. BrandonR. CatanzaroB. andNicholasC. Malware detection by eating a whole EXE 2017 https:\/\/arxiv.org\/abs\/1710.09435."},{"key":"e_1_2_12_62_2","unstructured":"DemetrioL. BiggioB. LagorioG. RoliF. andArmandoA. Functionality-preserving black-box optimization of adversarial windows malware 2020 https:\/\/www.semanticscholar.org\/paper\/32ff17fb274e7c455587c30cc092d42ccce53a80."},{"key":"e_1_2_12_63_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2019.2932228"},{"key":"e_1_2_12_64_2","unstructured":"HendrycksD.andGimpelK. Early methods for detecting adversarial images Proc. Int. Conf. Learn. Represent. (ICLR) 2017 Toulon France 1\u20139."},{"key":"e_1_2_12_65_2","doi-asserted-by":"crossref","unstructured":"ZhangJ. PengS. HuY. PengF. HuW. LaiJ. andYeJ. HRAE: hardware-assisted randomization against adversarial example attacks 2020 IEEE 29th Asian Test Symposium (ATS) 2020 Penang Malaysia.","DOI":"10.1109\/ATS49688.2020.9301586"},{"key":"e_1_2_12_66_2","unstructured":"HUAWEI \u2018ai-security-white-paper-cn\u2019 http:\/\/huawei.com\/-\/media\/corporate\/pdf\/cyber-security\/ai-security-white-paper-cn.pdf."},{"key":"e_1_2_12_67_2","unstructured":"WangJ. ZhangT. LiuS. ChenP. Y. XuJ. FardadM. andLiB. Beyond Adversarial Training: Min-Max Optimization in Adversarial Attack and Defense 2019 http:\/\/arxiv.org\/abs\/1906.03563."},{"key":"e_1_2_12_68_2","unstructured":"AnJ.andWagnerD. E-ABS: extending the analysis-by-synthesis robust classification model to more complex image domains CCS \u203220: 2020 ACM SIGSAC Conference on Computer and Communications Security 2020 25\u201336."},{"key":"e_1_2_12_69_2","unstructured":"ChenY. WangS. SheD. andJanaS. On training robust PDF malware classifiers 29th USENIX Security Symposium (USENIX Security 20) 2020 2343\u20132360 https:\/\/www.usenix.org\/conference\/usenixsecurity20\/presentation\/chen-yizheng."},{"key":"e_1_2_12_70_2","unstructured":"ZhangZ.andWuT. Adversarial distillation for ordered top-k attacks 2019 https:\/\/arxiv.org\/abs\/1905.10695."},{"key":"e_1_2_12_71_2","doi-asserted-by":"crossref","unstructured":"PapernotN. McDanielP. WuX. JhaS. andSwamiA. Distillation as a defense to adversarial perturbations against deep neural networks 2016 IEEE symposium on security and privacy (SP) 2016 San Jose CA USA 582\u2013597.","DOI":"10.1109\/SP.2016.41"},{"key":"e_1_2_12_72_2","unstructured":"AmatoA. G. Adversarial examples detection in features distance spaces: subvolume B European Conference on Computer Vision 2019 Munich Germany."},{"key":"e_1_2_12_73_2","doi-asserted-by":"crossref","unstructured":"ShumailovI. ZhaoY. MullinsR. andAndersonR. Towards certifiable adversarial sample detection Proceedings of the 13th ACM Workshop on Artificial Intelligence and Security 2020 USA 13\u201324 https:\/\/doi.org\/10.1145\/3411508.3421381.","DOI":"10.1145\/3411508.3421381"},{"key":"e_1_2_12_74_2","unstructured":"GuS.andRigazioL. Towards deep neural network architectures robust to adversarial examples 2015 https:\/\/arxiv.org\/abs\/1412.5068."},{"key":"e_1_2_12_75_2","unstructured":"QianY. G. ZhangX. M. WangB. LiW. ChenJ. H. ZhouW. J. andLeiJ. S. Towards robust DNNs: a Taylor expansion-based method for generating powerful adversarial examples 2020 https:\/\/arxiv.org\/abs\/2001.08389."},{"key":"e_1_2_12_76_2","doi-asserted-by":"crossref","unstructured":"ShiY.andHanY. Schmidt: image augmentation for black-box adversarial attack 2018 IEEE International Conference on Multimedia and Expo (ICME) 2018 San Diego USA 1\u20136 https:\/\/doi.org\/10.1109\/ICME.2018.8486449 2-s2.0-85061447901.","DOI":"10.1109\/ICME.2018.8486449"},{"key":"e_1_2_12_77_2","volume-title":"A Method for Protecting SVM Classifier from Poisoning Attack","author":"Laishram R.","year":"2016"},{"key":"e_1_2_12_78_2","doi-asserted-by":"crossref","unstructured":"JagielskiM. OpreaA. BiggioB. LiuC. Nita-RotaruC. andLiB. Manipulating machine learning: poisoning attacks and countermeasures for regression learning 2018 IEEE Symposium on Security and Privacy (SP) 2018 San Francisco CA USA 19\u201335 https:\/\/doi.org\/10.1109\/SP.2018.00057 2-s2.0-85050640069.","DOI":"10.1109\/SP.2018.00057"},{"key":"e_1_2_12_79_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2020.3003571"},{"key":"e_1_2_12_80_2","doi-asserted-by":"crossref","unstructured":"LiaoC. ChengY. FangC. andShiJ. Where does the robustness come from?: a study of the transformation-based ensemble defence Proceedings of the 13th ACM Workshop on Artificial Intelligence and Security 2020 USA 1\u201312 https:\/\/doi.org\/10.1145\/3411508.3421380.","DOI":"10.1145\/3411508.3421380"},{"key":"e_1_2_12_81_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2021.3054879"},{"key":"e_1_2_12_82_2","doi-asserted-by":"crossref","unstructured":"LiuY. YangX. andSrivastavaA. Neural Trojans 2017 IEEE 35th International Conference on Computer Design (ICCD) 2017 Boston MA USA.","DOI":"10.1109\/ICCD.2017.16"},{"key":"e_1_2_12_83_2","volume-title":"International Symposium on Research in Attacks, Intrusions, and Defenses","author":"Kang L.","year":"2018"},{"key":"e_1_2_12_84_2","unstructured":"PapernotN. AbadiM. ErlingssonU. GoodfellowI. andTalwarK. Semi-supervised knowledge transfer for deep learning from private training data 2016 https:\/\/arxiv.org\/abs\/1610.05755."},{"key":"e_1_2_12_85_2","doi-asserted-by":"crossref","unstructured":"AbadiM. ChuA. GoodfellowI. McMahanH. B. MironovI. TalwarK. andZhangL. Deep learning with differential privacy Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security 2016 https:\/\/dl.acm.org\/doi\/10.1145\/2976749.2978318.","DOI":"10.1145\/2976749.2978318"},{"key":"e_1_2_12_86_2","doi-asserted-by":"crossref","unstructured":"GiraldoJ. CardenasA. KantarciogluM. andKatzJ. Adversarial classification under differential privacy Network and Distributed System Security Symposium 2020 San Diego California.","DOI":"10.14722\/ndss.2020.23047"},{"key":"e_1_2_12_87_2","article-title":"Turning your weakness into a strength: watermarking deep neural networks by backdooring","author":"Adi Y.","year":"2018","journal-title":"27th {USENIX} Security Symposium ({USENIX} Security 18)"},{"key":"e_1_2_12_88_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2019.101592"},{"key":"e_1_2_12_89_2","doi-asserted-by":"crossref","unstructured":"MachadoG. GoldschmidtR. andSilvaE. MultiMagNet: a non-deterministic approach based on the formation of ensembles for defending against adversarial images 21st International Conference on Enterprise Information Systems 2019 Heraklion Crete Greece.","DOI":"10.5220\/0007714203070318"},{"key":"e_1_2_12_90_2","doi-asserted-by":"crossref","unstructured":"LiaoF. LiangM. DongY. PangT. HuX. andZhuJ. Defense against adversarial attacks using high-level representation guided denoiser 2018 IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR) 2018 Salt Lake City UT USA.","DOI":"10.1109\/CVPR.2018.00191"},{"key":"e_1_2_12_91_2","volume-title":"Lecture Notes in Computer Science","author":"Yi Z.","year":"2019"},{"key":"e_1_2_12_92_2","doi-asserted-by":"crossref","unstructured":"MaS. LiuY. TaoG. LeeW.-C. andZhangX. NIC: detecting adversarial samples with neural network invariant checking Presented at the Network and Distributed System Security Symposium 2019 San Diego CA https:\/\/doi.org\/10.14722\/ndss.2019.23415.","DOI":"10.14722\/ndss.2019.23415"},{"key":"e_1_2_12_93_2","doi-asserted-by":"crossref","unstructured":"LingX. JiS. ZouJ. WangJ. WuC. LiB. andWangT. DEEPSEC: a uniform platform for security analysis of deep learning model 2019 IEEE Symposium on Security and Privacy (SP) May 2019 San Francisco CA USA 673\u2013690 https:\/\/doi.org\/10.1109\/SP.2019.00023 2-s2.0-85072917091.","DOI":"10.1109\/SP.2019.00023"},{"key":"e_1_2_12_94_2","unstructured":"FangM. CaoX. JiaJ. andGongN. Local model poisoning attacks to byzantine-robust federated learning 29th {USENIX} Security Symposium ({USENIX} Security 20) 2019 USENIX Association."},{"key":"e_1_2_12_95_2","doi-asserted-by":"crossref","unstructured":"YangZ. ZhangJ. ChangE.-C. andLiangZ. Neural network inversion in adversarial setting via background knowledge alignment Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security 2019 London United Kingdom 225\u2013240 https:\/\/doi.org\/10.1145\/3319535.3354261.","DOI":"10.1145\/3319535.3354261"},{"key":"e_1_2_12_96_2","unstructured":"KorshunovP.andMarcelS. Deep Fakes: a new threat to face recognition? Assessment and detection 2018 https:\/\/arxiv.org\/abs\/1812.08685."},{"key":"e_1_2_12_97_2","unstructured":"ShanS. WengerE. ZhangJ. LiH. ZhengH. andZhaoB. Y. Fawkes: protecting privacy against unauthorized deep learning models 29th {USENIX} Security Symposium ({USENIX} Security 20) 2020 USENIX Association."},{"key":"e_1_2_12_98_2","unstructured":"JinW. LiY. XuH. WangY. andTangJ. Adversarial attacks and defenses on graphs: a review and empirical study 2020 https:\/\/arxiv.org\/abs\/2003.00653."},{"key":"e_1_2_12_99_2","doi-asserted-by":"crossref","unstructured":"TaigmanY. YangM. RanzatoM. andWolfL. Deep face: closing the gap to human-level performance in face verification 2014 IEEE Conference on Computer Vision and Pattern Recognition 2014 Columbus OH USA 1701\u20131708 https:\/\/doi.org\/10.1109\/CVPR.2014.220 2-s2.0-84911198048.","DOI":"10.1109\/CVPR.2014.220"},{"key":"e_1_2_12_100_2","unstructured":"SimonyanK.andZissermanA. Very deep convolutional networks for large-scale image recognition 2015 https:\/\/arxiv.org\/abs\/1409.1556."},{"key":"e_1_2_12_101_2","first-page":"1571","volume-title":"29th USENIX Security Symposium (USENIX Security 20)","author":"Din Z. A.","year":"2020"},{"key":"e_1_2_12_102_2","doi-asserted-by":"crossref","unstructured":"YuH. YangK. ZhangT. TsaiY.-Y. HoT.-Y. andJinY. Cloud leak: large-scale deep learning models stealing through adversarial examples presented at the Network and Distributed System Security Symposium 2020 San Diego CA https:\/\/doi.org\/10.14722\/ndss.2020.24178.","DOI":"10.14722\/ndss.2020.24178"},{"key":"e_1_2_12_103_2","doi-asserted-by":"crossref","unstructured":"SatoM. SuzukiJ. ShindoH. andMatsumotoY. Interpretable adversarial perturbation in input embedding space for text Proceedings of the Twenty-Seventh International Joint Conference on Artificial Intelligence 2018 Stockholm https:\/\/doi.org\/10.24963\/ijcai.2018\/601.","DOI":"10.24963\/ijcai.2018\/601"},{"key":"e_1_2_12_104_2","doi-asserted-by":"crossref","unstructured":"NeekharaP. HussainS. DubnovS. andKoushanfarF. Adversarial reprogramming of text classification neural networks Proceedings of the 2019 Conference on Empirical Methods in Natural Language Processing and the 9th International Joint Conference on Natural Language Processing (EMNLP-IJCNLP) 2018 Hong Kong China https:\/\/arxiv.org\/abs\/1809.01829.","DOI":"10.18653\/v1\/D19-1525"},{"key":"e_1_2_12_105_2","doi-asserted-by":"crossref","unstructured":"LiD. VargasD. V. andSakuraiK. Universal rules for fooling deep neural networks based text classification 2019 IEEE Congress on Evolutionary Computation (CEC) 2019 Wellington New Zealand 2221\u20132228 https:\/\/doi.org\/10.1109\/CEC.2019.8790213 2-s2.0-85071302977.","DOI":"10.1109\/CEC.2019.8790213"},{"key":"e_1_2_12_106_2","doi-asserted-by":"crossref","unstructured":"HuangY. VermaU. FralickC. Infante-LopezG. KumarB. andWoodwardC. Malware evasion attack and defense 2019 49th Annual IEEE\/IFIP International Conference on Dependable Systems and Networks Workshops (DSN-W) 2019 Portland OR USA 34\u201338 https:\/\/doi.org\/10.1109\/DSN-W.2019.00014 2-s2.0-85072050003.","DOI":"10.1109\/DSN-W.2019.00014"},{"key":"e_1_2_12_107_2","doi-asserted-by":"crossref","unstructured":"SuciuO. CoullS. E. andJohnsJ. Exploring adversarial examples in malware detection 2019 IEEE Security and Privacy Workshops (SPW) 2019 San Francisco CA USA 8\u201314 https:\/\/doi.org\/10.1109\/SPW.2019.00015 2-s2.0-85073148884.","DOI":"10.1109\/SPW.2019.00015"},{"key":"e_1_2_12_108_2","unstructured":"XuP. KolosnjajiB. EckertC. andZarrasA. MANIS: evading malware detection system on graph structure Proceedings of the 35th Annual ACM Symposium on Applied Computing 2020 New York NY USA https:\/\/doi.org\/10.1145\/3341105.3373859."},{"key":"e_1_2_12_109_2","doi-asserted-by":"crossref","unstructured":"ArpD. SpreitzenbarthM. H\u00fcbnerM. GasconH. andRieckK. Drebin: effective and explainable detection of Android malware in your pocket Presented at the Network and Distributed System Security Symposium 2014 San Diego CA https:\/\/doi.org\/10.14722\/ndss.2014.23247.","DOI":"10.14722\/ndss.2014.23247"},{"key":"e_1_2_12_110_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.3008433"},{"key":"e_1_2_12_111_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.comcom.2020.04.033"},{"key":"e_1_2_12_112_2","doi-asserted-by":"crossref","unstructured":"SalemA. ZhangY. HumbertM. BerrangP. FritzM. andBackesM. ML-Leaks: model and data independent membership inference attacks and defenses on machine learning models presented at the Network and Distributed System Security Symposium 2019 San Diego CA https:\/\/doi.org\/10.14722\/ndss.2019.23119.","DOI":"10.14722\/ndss.2019.23119"},{"key":"e_1_2_12_113_2","doi-asserted-by":"publisher","DOI":"10.1155\/2018\/7247095"},{"key":"e_1_2_12_114_2","doi-asserted-by":"crossref","unstructured":"StokesJ. W. WangD. MarinescuM. MarinoM. andBussoneB. Attack and defense of dynamic analysis-based adversarial neural malware detection models MILCOM 2018-2018 IEEE Military Communications Conference (MILCOM) 2018 Los Angeles CA USA 1\u20138 https:\/\/doi.org\/10.1109\/MILCOM.2018.8599855 2-s2.0-85061450935.","DOI":"10.1109\/MILCOM.2018.8599855"},{"key":"e_1_2_12_115_2","unstructured":"scikit-learn https:\/\/scikit-learn.org.cn\/."},{"key":"e_1_2_12_116_2","doi-asserted-by":"publisher","DOI":"10.11999\/JEIT191059"},{"key":"e_1_2_12_117_2","doi-asserted-by":"crossref","unstructured":"KrawczykH. HMQV: a high-performance secure Diffie-Hellman protocol Advances in Cryptology-CRYPTO 2005: 25th Annual International Cryptology Conference 2005 Santa Barbara California USA.","DOI":"10.1007\/11535218_33"},{"key":"e_1_2_12_118_2","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2018.2834351"},{"key":"e_1_2_12_119_2","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2020.3022797"},{"key":"e_1_2_12_120_2","doi-asserted-by":"publisher","DOI":"10.1109\/tdsc.2016.2605087"},{"key":"e_1_2_12_121_2","doi-asserted-by":"publisher","DOI":"10.1109\/access.2017.2780124"},{"key":"e_1_2_12_122_2","doi-asserted-by":"crossref","unstructured":"ZhengW. PopaR. A. GonzalezJ. E. andStoicaI. Helen: maliciously secure coopetitive learning for linear models 2019 IEEE Symposium on Security and Privacy (SP) May 2019 San Francisco CA USA 724\u2013738 https:\/\/doi.org\/10.1109\/SP.2019.00045 2-s2.0-85072932828.","DOI":"10.1109\/SP.2019.00045"},{"key":"e_1_2_12_123_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.future.2020.04.013"},{"key":"e_1_2_12_124_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10207-020-00488-6"},{"key":"e_1_2_12_125_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2799854"},{"key":"e_1_2_12_126_2","unstructured":"LiG. ZhuP. LiJ. YangZ. CaoN. andChenZ. Security matters: a survey on adversarial machine learning 2018 https:\/\/www.semanticscholar.org\/paper\/6ede8b02b817a1354b8bde1ab7af07b0ddb02acf."},{"key":"e_1_2_12_127_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2807385"},{"key":"e_1_2_12_128_2","doi-asserted-by":"publisher","DOI":"10.3390\/APP9050909"},{"key":"e_1_2_12_129_2","unstructured":"ZhangW. E. ShengQ. Z. AlhazmiA. andLiC. Adversarial attacks on deep learning models in natural language processing: a survey 2019 https:\/\/arxiv.org\/abs\/1901.06796."},{"key":"e_1_2_12_130_2","unstructured":"WangW. WangL. WangR. WangZ. andYeA. Towards a robust deep neural network in texts: a survey 2020 https:\/\/arxiv.org\/abs\/1902.07285."},{"key":"e_1_2_12_131_2","doi-asserted-by":"publisher","DOI":"10.1007\/s11633-019-1211-x"},{"key":"e_1_2_12_132_2","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2019.2933524"}],"container-title":["Wireless Communications and Mobile Computing"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/downloads.hindawi.com\/journals\/wcmc\/2021\/4907754.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/downloads.hindawi.com\/journals\/wcmc\/2021\/4907754.xml","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/onlinelibrary.wiley.com\/doi\/pdf\/10.1155\/2021\/4907754","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,8,7]],"date-time":"2024-08-07T13:41:41Z","timestamp":1723038101000},"score":1,"resource":{"primary":{"URL":"https:\/\/onlinelibrary.wiley.com\/doi\/10.1155\/2021\/4907754"}},"subtitle":[],"editor":[{"given":"Weizhi","family":"Meng","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"editor"}]}],"short-title":[],"issued":{"date-parts":[[2021,1]]},"references-count":132,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2021,1]]}},"alternative-id":["10.1155\/2021\/4907754"],"URL":"https:\/\/doi.org\/10.1155\/2021\/4907754","archive":["Portico"],"relation":{},"ISSN":["1530-8669","1530-8677"],"issn-type":[{"value":"1530-8669","type":"print"},{"value":"1530-8677","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,1]]},"assertion":[{"value":"2021-04-09","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2021-06-11","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2021-06-22","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}],"article-number":"4907754"}}