{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,7]],"date-time":"2026-07-07T04:50:58Z","timestamp":1783399858031,"version":"3.54.6"},"reference-count":76,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2020,6,1]],"date-time":"2020-06-01T00:00:00Z","timestamp":1590969600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2020,6,1]],"date-time":"2020-06-01T00:00:00Z","timestamp":1590969600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/501100001711","name":"Schweizerischer Nationalfonds zur F\u00f6rderung der Wissenschaftlichen Forschung","doi-asserted-by":"crossref","award":["200021_182063"],"award-info":[{"award-number":["200021_182063"]}],"id":[{"id":"10.13039\/501100001711","id-type":"DOI","asserted-by":"crossref"}]},{"DOI":"10.13039\/501100001711","name":"Schweizerischer Nationalfonds zur F\u00f6rderung der Wissenschaftlichen Forschung","doi-asserted-by":"publisher","award":["200021_182063"],"award-info":[{"award-number":["200021_182063"]}],"id":[{"id":"10.13039\/501100001711","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["EURASIP J. on Info. Security"],"published-print":{"date-parts":[[2020,12]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>In recent years, classification techniques based on deep neural networks (DNN) were widely used in many fields such as computer vision, natural language processing, and self-driving cars. However, the vulnerability of the DNN-based classification systems to adversarial attacks questions their usage in many critical applications. Therefore, the development of robust DNN-based classifiers is a critical point for the future deployment of these methods. Not less important issue is understanding of the mechanisms behind this vulnerability. Additionally, it is not completely clear how to link machine learning with cryptography to create an information advantage of the defender over the attacker. In this paper, we propose a key-based diversified aggregation (KDA) mechanism as a defense strategy in a gray- and black-box scenario. KDA assumes that the attacker (i) knows the architecture of classifier and the used defense strategy, (ii) has an access to the training data set, but (iii) does not know a secret key and does not have access to the internal states of the system. The robustness of the system is achieved by a specially designed key-based randomization. The proposed randomization prevents the gradients\u2019 back propagation and restricts the attacker to create a \u201cbypass\u201d system. The randomization is performed simultaneously in several channels. Each channel introduces its own randomization in a special transform domain. The sharing of a secret key between the training and test stages creates an information advantage to the defender. Finally, the aggregation of soft outputs from each channel stabilizes the results and increases the reliability of the final score. The performed experimental evaluation demonstrates a high robustness and universality of the KDA against state-of-the-art gradient-based gray-box transferability attacks and the non-gradient-based black-box attacks (The results reported in this paper have been partially presented in CVPR 2019 (Taran et al., Defending against adversarial attacks by randomized diversification, 2019) &amp; ICIP 2019 (Taran et al., Robustification of deep net classifiers by key-based diversified aggregation with pre-filtering, 2019)).<\/jats:p>","DOI":"10.1186\/s13635-020-00106-x","type":"journal-article","created":{"date-parts":[[2020,6,3]],"date-time":"2020-06-03T14:53:56Z","timestamp":1591196036000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":13,"title":["Machine learning through cryptographic glasses: combating adversarial attacks by key-based diversified aggregation"],"prefix":"10.1186","volume":"2020","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-8537-5204","authenticated-orcid":false,"given":"Olga","family":"Taran","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Shideh","family":"Rezaeifar","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Taras","family":"Holotyak","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Slava","family":"Voloshynovskiy","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2020,6,1]]},"reference":[{"issue":"7553","key":"106_CR1","doi-asserted-by":"publisher","first-page":"436","DOI":"10.1038\/nature14539","volume":"521","author":"Y. LeCun","year":"2015","unstructured":"Y. LeCun, Y. Bengio, G. Hinton, Deep learning. Nature. 521(7553), 436 (2015).","journal-title":"Nature"},{"key":"106_CR2","doi-asserted-by":"publisher","unstructured":"A. Krizhevsky, I. Sutskever, G. E. Hinton, in Advances in Neural Information Processing Systems. Imagenet classification with deep convolutional neural networks, (2012), pp. 1097\u20131105. https:\/\/doi.org\/10.1145\/3065386.","DOI":"10.1145\/3065386"},{"key":"106_CR3","doi-asserted-by":"publisher","unstructured":"K. He, X. Zhang, S. Ren, J. Sun, in Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition. Deep residual learning for image recognition, (2016), pp. 770\u2013778. https:\/\/doi.org\/10.1109\/cvpr.2016.90.","DOI":"10.1109\/cvpr.2016.90"},{"key":"106_CR4","doi-asserted-by":"publisher","unstructured":"R. Girshick, in Proceedings of the IEEE International Conference on Computer Vision. Fast r-cnn, (2015), pp. 1440\u20131448. https:\/\/doi.org\/10.1109\/iccv.2015.169.","DOI":"10.1109\/iccv.2015.169"},{"key":"106_CR5","doi-asserted-by":"publisher","unstructured":"C. Szegedy, W. Liu, Y. Jia, P. Sermanet, S. Reed, D. Anguelov, D. Erhan, V. Vanhoucke, A. Rabinovich, in Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition. Going deeper with convolutions, (2015), pp. 1\u20139. https:\/\/doi.org\/10.1109\/cvpr.2015.7298594.","DOI":"10.1109\/cvpr.2015.7298594"},{"issue":"11","key":"106_CR6","doi-asserted-by":"publisher","first-page":"2049","DOI":"10.1109\/TMM.2015.2477042","volume":"17","author":"C. Ding","year":"2015","unstructured":"C. Ding, D. Tao, Robust face recognition via multimodal deep face representation. IEEE Trans. Multimedia. 17(11), 2049\u20132058 (2015).","journal-title":"IEEE Trans. Multimedia"},{"key":"106_CR7","doi-asserted-by":"publisher","unstructured":"M. Sharif, S. Bhagavatula, L. Bauer, M. K. Reiter, in Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security. Accessorize to a crime: real and stealthy attacks on state-of-the-art face recognition (ACM, 2016), pp. 1528\u20131540. https:\/\/doi.org\/10.1145\/2976749.2978392.","DOI":"10.1145\/2976749.2978392"},{"key":"106_CR8","unstructured":"R. Kiros, R. Salakhutdinov, R. Zemel, in International Conference on Machine Learning. Multimodal neural language models, (2014), pp. 595\u2013603."},{"key":"106_CR9","unstructured":"K. Xu, J. Ba, R. Kiros, K. Cho, A. Courville, R. Salakhudinov, R. Zemel, Y. Bengio, in International Conference on Machine Learning. Show, attend and tell: Neural image caption generation with visual attention, (2015), pp. 2048\u20132057."},{"key":"106_CR10","doi-asserted-by":"publisher","unstructured":"R. Collobert, J. Weston, in Proceedings of the 25th International Conference on Machine Learning. A unified architecture for natural language processing: deep neural networks with multitask learning (ACM, 2008), pp. 160\u2013167. https:\/\/doi.org\/10.1145\/1390156.1390177.","DOI":"10.1145\/1390156.1390177"},{"issue":"3","key":"106_CR11","doi-asserted-by":"publisher","first-page":"55","DOI":"10.1109\/MCI.2018.2840738","volume":"13","author":"T. Young","year":"2018","unstructured":"T. Young, D. Hazarika, S. Poria, E. Cambria, Recent trends in deep learning based natural language processing. IEEE Comput. Intell. Mag.13(3), 55\u201375 (2018).","journal-title":"IEEE Comput. Intell. Mag."},{"key":"106_CR12","doi-asserted-by":"crossref","unstructured":"G. Hinton, L. Deng, D. Yu, G. Dahl, A. -r. Mohamed, N. Jaitly, A. Senior, V. Vanhoucke, P. Nguyen, B. Kingsbury, et al., Deep neural networks for acoustic modeling in speech recognition. IEEE Sig. Process Mag.29: (2012).","DOI":"10.1109\/MSP.2012.2205597"},{"key":"106_CR13","doi-asserted-by":"publisher","unstructured":"W. Xiong, L. Wu, F. Alleva, J. Droppo, X. Huang, A. Stolcke, in 2018 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP). The microsoft 2017 conversational speech recognition system (IEEE, 2018), pp. 5934\u20135938. https:\/\/doi.org\/10.1109\/icassp.2018.8461870.","DOI":"10.1109\/icassp.2018.8461870"},{"issue":"7540","key":"106_CR14","doi-asserted-by":"publisher","first-page":"529","DOI":"10.1038\/nature14236","volume":"518","author":"V. Mnih","year":"2015","unstructured":"V. Mnih, K. Kavukcuoglu, D. Silver, A. A. Rusu, J. Veness, M. G. Bellemare, A. Graves, M. Riedmiller, A. K. Fidjeland, G. Ostrovski, et al., Human-level control through deep reinforcement learning. Nature. 518(7540), 529 (2015).","journal-title":"Nature"},{"key":"106_CR15","doi-asserted-by":"publisher","unstructured":"M. Melis, A. Demontis, B. Biggio, G. Brown, G. Fumera, F. Roli, in Proceedings of the IEEE International Conference on Computer Vision. Is deep learning safe for robot vision? Adversarial examples against the icub humanoid, (2017), pp. 751\u2013759. https:\/\/doi.org\/10.1109\/iccvw.2017.94.","DOI":"10.1109\/iccvw.2017.94"},{"key":"106_CR16","doi-asserted-by":"publisher","unstructured":"B. Biggio, I. Corona, D. Maiorca, B. Nelson, N. \u0160rndi\u0107, P. Laskov, G. Giacinto, F. Roli, in Joint European Conference on Machine Learning and Knowledge Discovery in Databases. Evasion attacks against machine learning at test time (Springer, 2013), pp. 387\u2013402. https:\/\/doi.org\/10.1007\/978-3-642-40994-3_25.","DOI":"10.1007\/978-3-642-40994-3_25"},{"key":"106_CR17","doi-asserted-by":"publisher","unstructured":"J. Saxe, K. Berlin, in 2015 10th International Conference on Malicious and Unwanted Software (MALWARE). Deep neural network based malware detection using two dimensional binary program features (IEEE, 2015), pp. 11\u201320. https:\/\/doi.org\/10.1109\/malware.2015.7413680.","DOI":"10.1109\/malware.2015.7413680"},{"issue":"2","key":"106_CR18","doi-asserted-by":"publisher","first-page":"263","DOI":"10.1021\/ci500747n","volume":"55","author":"J. Ma","year":"2015","unstructured":"J. Ma, R. P. Sheridan, A. Liaw, G. E. Dahl, V. Svetnik, Deep neural nets as a method for quantitative structure\u2013activity relationships. J. Chem. Inf. Model.55(2), 263\u2013274 (2015). https:\/\/doi.org\/10.1021\/ci500747n. PMID: 25635324.","journal-title":"J. Chem. Inf. Model."},{"issue":"7461","key":"106_CR19","doi-asserted-by":"publisher","first-page":"168","DOI":"10.1038\/nature12346","volume":"500","author":"M. Helmstaedter","year":"2013","unstructured":"M. Helmstaedter, K. L. Briggman, S. C. Turaga, V. Jain, H. S. Seung, W. Denk, Connectomic reconstruction of the inner plexiform layer in the mouse retina. Nature. 500(7461), 168 (2013).","journal-title":"Nature"},{"issue":"6218","key":"106_CR20","doi-asserted-by":"publisher","first-page":"1254806","DOI":"10.1126\/science.1254806","volume":"347","author":"H. Y. Xiong","year":"2015","unstructured":"H. Y. Xiong, B. Alipanahi, L. J. Lee, H. Bretschneider, D. Merico, R. K. Yuen, Y. Hua, S. Gueroussov, H. S. Najafabadi, T. R. Hughes, et al., The human splicing code reveals new insights into the genetic determinants of disease. Science. 347(6218), 1254806 (2015).","journal-title":"Science"},{"key":"106_CR21","unstructured":"I. J. Goodfellow, J. Shlens, C. Szegedy, in International Conference on Learning Representations (ICLR). Explaining and harnessing adversarial examples, (2015)."},{"key":"106_CR22","unstructured":"N. Papernot, P. McDaniel, I. Goodfellow, Transferability in machine learning: from phenomena to black-box attacks using adversarial samples. arXiv preprint (2016). arXiv:1605.07277."},{"key":"106_CR23","unstructured":"A. Kurakin, I. Goodfellow, S. Bengio, Adversarial examples in the physical world. arXiv preprint (2016). arXiv:1607.02533."},{"key":"106_CR24","unstructured":"X. Yuan, P. He, Q. Zhu, R. R. Bhat, X. Li, Adversarial examples: attacks and defenses for deep learning. arXiv preprint (2017). arXiv:1712.07107."},{"key":"106_CR25","doi-asserted-by":"crossref","unstructured":"O. Taran, S. Rezaeifar, S. Voloshynovskiy, in Workshop on Objectionable Content and Misinformation (WOCM), ECCV2018. Bridging machine learning and cryptography in defence against adversarial attacks (Munich, Germany, 2018).","DOI":"10.1007\/978-3-030-11012-3_23"},{"key":"106_CR26","doi-asserted-by":"publisher","unstructured":"X. Yuan, P. He, Q. Zhu, X. Li, Adversarial examples: attacks and defenses for deep learning. IEEE Trans. Neural Netw. Learn Syst. (2019). https:\/\/doi.org\/10.1109\/tnnls.2018.2886017.","DOI":"10.1109\/tnnls.2018.2886017"},{"key":"106_CR27","doi-asserted-by":"crossref","unstructured":"N. Das, M. Shanbhogue, S. -T. Chen, F. Hohman, S. Li, L. Chen, M. E. Kounavis, D. H. Chau, Shield: fast, practical defense and vaccination for deep learning using jpeg compression. arXiv preprint (2018). arXiv:1802.06816.","DOI":"10.1145\/3219819.3219910"},{"key":"106_CR28","doi-asserted-by":"crossref","unstructured":"N. Akhtar, A. Mian, Threat of adversarial attacks on deep learning in computer vision: a survey. arXiv preprint (2018). arXiv:1801.00553.","DOI":"10.1109\/ACCESS.2018.2807385"},{"key":"106_CR29","unstructured":"J. L. Massey, in Copies of Transparencies, Advanced Technology Seminars. vol. 109. Cryptography: fundamentals and applications, (1993), p. 119."},{"key":"106_CR30","doi-asserted-by":"publisher","unstructured":"O. Taran, S. Rezaeifar, T. Holotyak, S. Voloshynovskiy, in IEEE Conference on Computer Vision and Pattern Recognition (CVPR). Defending against adversarial attacks by randomized diversification (Long Beach, USA, 2019). https:\/\/doi.org\/10.1109\/cvpr.2019.01148.","DOI":"10.1109\/cvpr.2019.01148"},{"key":"106_CR31","doi-asserted-by":"publisher","unstructured":"O. Taran, S. Rezaeifar, T. Holotyak, S. Voloshynovskiy, in IEEE International Conference on Image Processing (ICIP). Robustification of deep net classifiers by key based diversified aggregation with pre-filtering (Taipei, Taiwan, 2019). https:\/\/doi.org\/10.1109\/icip.2019.8803714.","DOI":"10.1109\/icip.2019.8803714"},{"key":"106_CR32","unstructured":"A. Madry, A. Makelov, L. Schmidt, D. Tsipras, A. Vladu, Towards deep learning models resistant to adversarial attacks. arXiv preprint (2017). arXiv:1706.06083."},{"key":"106_CR33","doi-asserted-by":"publisher","unstructured":"N. Papernot, P. McDaniel, X. Wu, S. Jha, A. Swami, in Security and Privacy (SP), 2016 IEEE Symposium On. Distillation as a defense to adversarial perturbations against deep neural networks (IEEE, 2016), pp. 582\u2013597. https:\/\/doi.org\/10.1109\/sp.2016.41.","DOI":"10.1109\/sp.2016.41"},{"key":"106_CR34","unstructured":"I. J. Goodfellow, J. Shlens, C. Szegedy, Explaining and harnessing adversarial examples. arXiv preprint (2014). arXiv:1412.6572."},{"key":"106_CR35","doi-asserted-by":"publisher","unstructured":"Y. Wu, D. Bamman, S. Russell, in Proceedings of the 2017 Conference on Empirical Methods in Natural Language Processing. Adversarial training for relation extraction, (2017), pp. 1778\u20131783. https:\/\/doi.org\/10.18653\/v1\/d17-1187.","DOI":"10.18653\/v1\/d17-1187"},{"key":"106_CR36","doi-asserted-by":"publisher","unstructured":"P. Moulin, A. Goel, in 2017 IEEE International Conference on Multimedia & Expo Workshops (ICMEW). Locally optimal detection of adversarial inputs to image classifiers (IEEE, 2017), pp. 459\u2013464. https:\/\/doi.org\/10.1109\/icmew.2017.8026257.","DOI":"10.1109\/icmew.2017.8026257"},{"key":"106_CR37","unstructured":"J. H. Metzen, T. Genewein, V. Fischer, B. Bischoff, On detecting adversarial perturbations. arXiv preprint (2017). arXiv:1702.04267."},{"key":"106_CR38","unstructured":"D. Hendrycks, K. Gimpel, Early methods for detecting adversarial images. arXiv preprint (2016). arXiv:1608.00530."},{"key":"106_CR39","doi-asserted-by":"publisher","unstructured":"X. Li, F. Li, in Proceedings of the IEEE International Conference on Computer Vision. Adversarial examples detection in deep networks with convolutional filter statistics, (2017), pp. 5764\u20135772. https:\/\/doi.org\/10.1109\/iccv.2017.615.","DOI":"10.1109\/iccv.2017.615"},{"key":"106_CR40","unstructured":"R. Feinman, R. R. Curtin, S. Shintre, A. B. Gardner, Detecting adversarial samples from artifacts. arXiv preprint (2017). arXiv:1703.00410."},{"key":"106_CR41","doi-asserted-by":"crossref","unstructured":"H. Zhang, Y. Avrithis, T. Furon, L. Amsaleg, Smooth adversarial examples. arXiv preprint (2019). arXiv:1903.11862.","DOI":"10.1186\/s13635-020-00112-z"},{"key":"106_CR42","doi-asserted-by":"crossref","unstructured":"S. Voloshynovskiy, S. Pereira, A. Herrigel, N. Baumg\u00e4rtner, T. Pun, in IS&T\/SPIE\u2019s 12th Annual Symposium, Electronic Imaging 2000: Security and Watermarking of Multimedia Content II. SPIE Proceedings, vol. 3971, ed. by P. Wah Wong, E. J. Delp. Generalized watermark attack based on watermark estimation and perceptual remodulation (San Jose, California USA, 2000). (Paper EI 3971-34) - slides.","DOI":"10.1117\/12.384990"},{"key":"106_CR43","unstructured":"S. Gu, L. Rigazio, Towards deep neural network architectures robust to adversarial examples. arXiv preprint (2014). arXiv:1412.5068."},{"key":"106_CR44","doi-asserted-by":"publisher","unstructured":"D. Meng, H. Chen, in Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security. Magnet: a two-pronged defense against adversarial examples (ACM, 2017), pp. 135\u2013147. https:\/\/doi.org\/10.1145\/3133956.3134057.","DOI":"10.1145\/3133956.3134057"},{"key":"106_CR45","volume-title":"6th International Conference on Learning Representations, ICLR 2018, Workshop Track Proceedings","author":"S. Lee","year":"2018","unstructured":"S. Lee, J. Lee, in 6th International Conference on Learning Representations, ICLR 2018, Workshop Track Proceedings. Defensive denoising methods against adversarial attack (OpenReview.netVancouver, 2018)."},{"key":"106_CR46","doi-asserted-by":"publisher","unstructured":"C. Xie, Y. Wu, L. v. d. Maaten, A. L. Yuille, K. He, in Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition. Feature denoising for improving adversarial robustness, (2019), pp. 501\u2013509. https:\/\/doi.org\/10.1109\/cvpr.2019.00059.","DOI":"10.1109\/cvpr.2019.00059"},{"key":"106_CR47","doi-asserted-by":"publisher","unstructured":"X. Jia, X. Wei, X. Cao, H. Foroosh, in Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition. Comdefend: an efficient image compression model to defend adversarial examples, (2019), pp. 6084\u20136092. https:\/\/doi.org\/10.1109\/cvpr.2019.00624.","DOI":"10.1109\/cvpr.2019.00624"},{"key":"106_CR48","doi-asserted-by":"crossref","unstructured":"Z. Liu, Q. Liu, T. Liu, Y. Wang, W. Wen, Feature distillation: Dnn-oriented jpeg compression against adversarial examples. arXiv preprint (2018). arXiv:1803.05787.","DOI":"10.1109\/CVPR.2019.00095"},{"key":"106_CR49","unstructured":"D. Smilkov, N. Thorat, B. Kim, F. Vi\u00e9gas, M. Wattenberg, Smoothgrad: removing noise by adding noise. arXiv preprint (2017). arXiv:1706.03825."},{"key":"106_CR50","doi-asserted-by":"publisher","unstructured":"V. Zantedeschi, M. -I. Nicolae, A. Rawat, in Proceedings of the 10th ACM Workshop on Artificial Intelligence and Security. Efficient defenses against adversarial attacks (ACM, 2017), pp. 39\u201349. https:\/\/doi.org\/10.1145\/3128572.3140449.","DOI":"10.1145\/3128572.3140449"},{"key":"106_CR51","unstructured":"N. Ford, J. Gilmer, N. Carlini, D. Cubuk, Adversarial examples are a natural consequence of test error in noise. arXiv preprint (2019). arXiv:1901.10513."},{"key":"106_CR52","unstructured":"C. Xie, J. Wang, Z. Zhang, Z. Ren, A. Yuille, Mitigating adversarial effects through randomization. arXiv preprint (2017). arXiv:1711.01991."},{"key":"106_CR53","doi-asserted-by":"publisher","unstructured":"E. Raff, J. Sylvester, S. Forsyth, M. McLean, in Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition. Barrage of random transforms for adversarially robust defense, (2019), pp. 6528\u20136537. https:\/\/doi.org\/10.1109\/cvpr.2019.00669.","DOI":"10.1109\/cvpr.2019.00669"},{"key":"106_CR54","doi-asserted-by":"publisher","unstructured":"X. Liu, M. Cheng, H. Zhang, C. -J. Hsieh, in Proceedings of the European Conference on Computer Vision (ECCV). Towards robust neural networks via random self-ensemble, (2018), pp. 369\u2013385. https:\/\/doi.org\/10.1007\/978-3-030-01234-2_23.","DOI":"10.1007\/978-3-030-01234-2_23"},{"key":"106_CR55","doi-asserted-by":"publisher","unstructured":"Z. He, A. S. Rakin, D. Fan, in Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition. Parametric noise injection: trainable randomness to improve deep neural network robustness against adversarial attack, (2019), pp. 588\u2013597. https:\/\/doi.org\/10.1109\/cvpr.2019.00068.","DOI":"10.1109\/cvpr.2019.00068"},{"key":"106_CR56","doi-asserted-by":"publisher","unstructured":"Z. You, J. Ye, K. Li, Z. Xu, P. Wang, in 2019 IEEE International Conference on Image Processing (ICIP). Adversarial noise layer: regularize neural network by adding noise (IEEE, 2019), pp. 909\u2013913. https:\/\/doi.org\/10.1109\/icip.2019.8803055.","DOI":"10.1109\/icip.2019.8803055"},{"key":"106_CR57","unstructured":"C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, R. Fergus, Intriguing properties of neural networks. arXiv preprint (2013). arXiv:1312.6199."},{"key":"106_CR58","doi-asserted-by":"publisher","unstructured":"Y. Dong, F. Liao, T. Pang, H. Su, J. Zhu, X. Hu, J. Li, in Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition. Boosting adversarial attacks with momentum, (2018), pp. 9185\u20139193. https:\/\/doi.org\/10.1109\/cvpr.2018.00957.","DOI":"10.1109\/cvpr.2018.00957"},{"key":"106_CR59","unstructured":"F. Tram\u00e8r, A. Kurakin, N. Papernot, I. Goodfellow, D. Boneh, P. McDaniel, Ensemble adversarial training: attacks and defenses. arXiv preprint (2017). arXiv:1705.07204."},{"key":"106_CR60","doi-asserted-by":"publisher","unstructured":"N. Papernot, P. McDaniel, S. Jha, M. Fredrikson, Z. B. Celik, A. Swami, in Security and Privacy (EuroS&P), 2016 IEEE European Symposium On. The limitations of deep learning in adversarial settings (IEEE, 2016), pp. 372\u2013387. https:\/\/doi.org\/10.1109\/eurosp.2016.36.","DOI":"10.1109\/eurosp.2016.36"},{"key":"106_CR61","doi-asserted-by":"publisher","unstructured":"S. M. Moosavi Dezfooli, A. Fawzi, P. Frossard, in Proceedings of 2016 IEEE Conference on Computer Vision and Pattern Recognition (CVPR). Deepfool: a simple and accurate method to fool deep neural networks, (2016). https:\/\/doi.org\/10.1109\/cvpr.2016.282.","DOI":"10.1109\/cvpr.2016.282"},{"key":"106_CR62","doi-asserted-by":"crossref","unstructured":"S. -M. Moosavi-Dezfooli, A. Fawzi, O. Fawzi, P. Frossard, in Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition. Universal adversarial perturbations, (2017), pp. 1765\u20131773.","DOI":"10.1109\/CVPR.2017.17"},{"key":"106_CR63","doi-asserted-by":"publisher","unstructured":"N. Carlini, D. Wagner, in 2017 IEEE Symposium on Security and Privacy (SP). Towards evaluating the robustness of neural networks (IEEE, 2017), pp. 39\u201357. https:\/\/doi.org\/10.1109\/sp.2017.49.","DOI":"10.1109\/sp.2017.49"},{"key":"106_CR64","doi-asserted-by":"publisher","unstructured":"N. Carlini, D. Wagner, in Proceedings of the 10th ACM Workshop on Artificial Intelligence and Security. Adversarial examples are not easily detected: bypassing ten detection methods (ACM, 2017), pp. 3\u201314. https:\/\/doi.org\/10.1145\/3128572.3140444.","DOI":"10.1145\/3128572.3140444"},{"key":"106_CR65","unstructured":"W. He, J. Wei, X. Chen, N. Carlini, D. Song, Adversarial example defenses: ensembles of weak defenses are not strong. arXiv preprint (2017). arXiv:1706.04701."},{"key":"106_CR66","unstructured":"A. Athalye, N. Carlini, D. Wagner, ed. by J. Dy, A. Krause. Proceedings of the 35th International Conference on Machine Learning, Proceedings of Machine Learning Research, vol. 80 (PMLRStockholmsm\u00e4ssan, Stockholm Sweden, 2018), pp. 274\u2013283. http:\/\/proceedings.mlr.press\/v80\/athalye18a.html."},{"key":"106_CR67","unstructured":"P. -Y. Chen, H. Zhang, Y. Sharma, J. Yi, C. -J. Hsieh, in Proceedings of the 10th ACM Workshop on Artificial Intelligence and Security. Zoo: zeroth order optimization based black-box attacks to deep neural networks without training substitute models (ACM, 2017), pp. 15\u201326."},{"key":"106_CR68","doi-asserted-by":"publisher","unstructured":"J. Su, D. V. Vargas, K. Sakurai, One pixel attack for fooling deep neural networks. IEEE Trans. Evol. Comput. (2019). https:\/\/doi.org\/10.1109\/tevc.2019.2890858.","DOI":"10.1109\/tevc.2019.2890858"},{"issue":"4","key":"106_CR69","doi-asserted-by":"publisher","first-page":"341","DOI":"10.1023\/A:1008202821328","volume":"11","author":"R. Storn","year":"1997","unstructured":"R. Storn, K. Price, Differential evolution\u2013a simple and efficient heuristic for global optimization over continuous spaces. J. Glob. Optim.11(4), 341\u2013359 (1997).","journal-title":"J. Glob. Optim."},{"issue":"8","key":"106_CR70","doi-asserted-by":"publisher","first-page":"2080","DOI":"10.1109\/TIP.2007.901238","volume":"16","author":"K. Dabov","year":"2007","unstructured":"K. Dabov, A. Foi, V. Katkovnik, K. Egiazarian, Image denoising by sparse 3-d transform-domain collaborative filtering. IEEE Trans. Image Process.16(8), 2080\u20132095 (2007).","journal-title":"IEEE Trans. Image Process."},{"issue":"Dec","key":"106_CR71","first-page":"3371","volume":"11","author":"P. Vincent","year":"2010","unstructured":"P. Vincent, H. Larochelle, I. Lajoie, Y. Bengio, P. -A. Manzagol, Stacked denoising autoencoders: learning useful representations in a deep network with a local denoising criterion. J. Mach. Learn. Res.11(Dec), 3371\u20133408 (2010).","journal-title":"J. Mach. Learn. Res."},{"key":"106_CR72","unstructured":"Z. Chen, B. Tondi, X. Li, R. Ni, Y. Zhao, M. Barni, Secure detection of image manipulation by means of random feature selection. CoRR. abs\/1802.00573: (2018)."},{"key":"106_CR73","unstructured":"Y. LeCun, C. Cortes, C. Burges, Mnist handwritten digit database. 2: (2010). AT&T Labs [Online]. Available: http:\/\/yann.lecun.com\/exdb\/mnist."},{"key":"106_CR74","unstructured":"H. Xiao, K. Rasul, R. Vollgraf, Fashion-mnist: a novel image dataset for benchmarking machine learning algorithms. arXiv preprint (2017). arXiv:1708.07747."},{"key":"106_CR75","unstructured":"A. Krizhevsky, V. Nair, G. Hinton, The cifar-10 datase (2014). online: http:\/\/www.cs.toronto.edu\/kriz\/cifar.html."},{"key":"106_CR76","unstructured":"K. Simonyan, A. Zisserman, Very deep convolutional networks for large-scale image recognition. arXiv preprint (2014). arXiv:1409.1556."}],"container-title":["EURASIP Journal on Information Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s13635-020-00106-x.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1186\/s13635-020-00106-x\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s13635-020-00106-x.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,5,31]],"date-time":"2021-05-31T23:26:17Z","timestamp":1622503577000},"score":1,"resource":{"primary":{"URL":"https:\/\/jis-eurasipjournals.springeropen.com\/articles\/10.1186\/s13635-020-00106-x"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,6,1]]},"references-count":76,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2020,12]]}},"alternative-id":["106"],"URL":"https:\/\/doi.org\/10.1186\/s13635-020-00106-x","relation":{},"ISSN":["2510-523X"],"issn-type":[{"value":"2510-523X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,6,1]]},"assertion":[{"value":"4 October 2019","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"22 April 2020","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"1 June 2020","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"The authors declare that they have no competing interests.","order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"10"}}