{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T15:49:08Z","timestamp":1783007348892,"version":"3.54.5"},"reference-count":190,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2026,1,20]],"date-time":"2026-01-20T00:00:00Z","timestamp":1768867200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2026,1,20]],"date-time":"2026-01-20T00:00:00Z","timestamp":1768867200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"name":"Natural Science Foundation for Excellent Young Scholars of Henan Province","award":["252300421233"],"award-info":[{"award-number":["252300421233"]}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62202495"],"award-info":[{"award-number":["62202495"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62172435"],"award-info":[{"award-number":["62172435"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U23A20305"],"award-info":[{"award-number":["U23A20305"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"National Key Research and Development Program of China","award":["2022YFB3102900"],"award-info":[{"award-number":["2022YFB3102900"]}]},{"DOI":"10.13039\/501100013057","name":"Innovation Scientists and Technicians Troop Construction Projects of Henan Province","doi-asserted-by":"publisher","award":["254000510007"],"award-info":[{"award-number":["254000510007"]}],"id":[{"id":"10.13039\/501100013057","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Cybersecurity"],"abstract":"<jats:title>Abstract<\/jats:title>\n                  <jats:p>Artificial intelligence technology based on deep learning has been widely used in key fields such as automatic driving, medical diagnosis and financial risk control. These applications also bring more and more serious security problems. In particular, as the means of attack continue to evolve, well-designed countermeasures seriously threaten the reliability of the model and the security of the system. In order to deal with this risk, defensive confrontation samples have become the core task of AI security research, playing a key role in improving the security and credibility of the model. Aiming at the problems of unclear concepts and overlapping standards in previous classification methods, this paper proposes a clearer and unified classification framework, combs and defines the contents of existing research, and solves the inconsistencies. The framework systematically divides the existing countermeasures and defense methods into three categories: detection, purification and optimization. This classification will help researchers understand the actual effects of different methods in the face of various attacks more clearly. This paper also analyzes the tradeoffs between accuracy, robustness, operational efficiency and generalization capability of various defense mechanisms, and reveals how they balance the calculation cost and actual deployment requirements. In addition, the paper points out the main challenges facing the current research, and puts forward the future research directions, including developing more efficient, adaptive, and cross modal defense methods to comprehensively improve the security of AI systems. The purpose of this review is to help researchers understand the development process of anti sample defense technology and provide a reference path for building a stable and reliable AI system.<\/jats:p>","DOI":"10.1186\/s42400-025-00546-3","type":"journal-article","created":{"date-parts":[[2026,1,20]],"date-time":"2026-01-20T09:57:09Z","timestamp":1768903029000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Advancements in adversarial example defense for deep learning models: a review"],"prefix":"10.1186","volume":"9","author":[{"given":"Ruipu","family":"Ma","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1832-1235","authenticated-orcid":false,"given":"Yi","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jinwei","family":"Wang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Wei","family":"Lu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xiangyang","family":"Luo","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,1,20]]},"reference":[{"key":"546_CR1","doi-asserted-by":"publisher","DOI":"10.1186\/s42400-024-00241-9","author":"S Alam","year":"2024","unstructured":"Alam S, Demir AK (2024) SIFT: sifting file types-application of explainable artificial intelligence in cyber forensics. Cybersecurity. https:\/\/doi.org\/10.1186\/s42400-024-00241-9","journal-title":"Cybersecurity"},{"key":"546_CR2","doi-asserted-by":"publisher","DOI":"10.1186\/s42400-023-00154-z","author":"Z Ying","year":"2023","unstructured":"Ying Z, Wu B (2023) NBA: defensive distillation for backdoor removal via neural behavior alignment. Cybersecurity. https:\/\/doi.org\/10.1186\/s42400-023-00154-z","journal-title":"Cybersecurity"},{"key":"546_CR3","doi-asserted-by":"publisher","DOI":"10.1186\/s42400-023-00141-4","author":"Z Ying","year":"2023","unstructured":"Ying Z, Wu B (2023) DLP: towards active defense against backdoor attacks with decoupled learning process. Cybersecurity. https:\/\/doi.org\/10.1186\/s42400-023-00141-4","journal-title":"Cybersecurity"},{"key":"546_CR4","doi-asserted-by":"publisher","DOI":"10.1186\/s42400-023-00175-8","author":"G Feng","year":"2023","unstructured":"Feng G, Zheng S, Chen Y, Ju L (2023) Towards the transferable audio adversarial attack via ensemble methods. Cybersecurity. https:\/\/doi.org\/10.1186\/s42400-023-00175-8","journal-title":"Cybersecurity"},{"key":"546_CR5","doi-asserted-by":"publisher","DOI":"10.1186\/s42400-023-00145-0","author":"Y Mirsky","year":"2023","unstructured":"Mirsky Y (2023) IPatch: a remote adversarial patch. Cybersecurity. https:\/\/doi.org\/10.1186\/s42400-023-00145-0","journal-title":"Cybersecurity"},{"key":"546_CR6","doi-asserted-by":"publisher","DOI":"10.1186\/s42400-023-00197-2","author":"R Liu","year":"2024","unstructured":"Liu R, Zhou W, Jin X, Gao S, Wang Y, Wang R (2024) DTA: distribution transform-based attack for query-limited scenario. Cybersecurity. https:\/\/doi.org\/10.1186\/s42400-023-00197-2","journal-title":"Cybersecurity"},{"key":"546_CR7","unstructured":"Metzen JH, Genewein T, Fischer V, Bischoff B (2017) On detecting adversarial perturbations. In: 5th international conference on learning representations (ICLR)"},{"key":"546_CR8","doi-asserted-by":"publisher","unstructured":"Meng D, Chen H (2017) MagNet: a two-pronged defense against adversarial examples. In: 24th ACM SIGSAC conference on computer and communications security (CCS), pp 135\u2013147 https:\/\/doi.org\/10.1145\/3133956.3134057","DOI":"10.1145\/3133956.3134057"},{"key":"546_CR9","doi-asserted-by":"publisher","unstructured":"Feinman R, Curtin RR, Shintre S, Gardner AB (2017) Detecting adversarial samples from artifacts. Preprint at https:\/\/doi.org\/10.48550\/arXiv.1703.00410","DOI":"10.48550\/arXiv.1703.00410"},{"key":"546_CR10","doi-asserted-by":"publisher","unstructured":"Xu W, Evans D, Qi Y (2018) Feature squeezing: detecting adversarial examples in deep neural networks. In: 25th network and distributed system security symposium (NDSS), pp 23198 https:\/\/doi.org\/10.14722\/ndss.2018.23198","DOI":"10.14722\/ndss.2018.23198"},{"key":"546_CR11","unstructured":"Hendrycks D, Gimpel K (2017) Early methods for detecting adversarial images. In: 5th international conference on learning representations (ICLR)"},{"key":"546_CR12","doi-asserted-by":"publisher","unstructured":"Pang T, Du C, Dong Y, Zhu J (2018) Towards robust detection of adversarial examples. In: 32nd international conference on neural information processing systems (NeurIPS), pp 4584\u20134594 https:\/\/doi.org\/10.5555\/3327345.3327369","DOI":"10.5555\/3327345.3327369"},{"key":"546_CR13","unstructured":"Song Y, Kim T, Nowozin S, Ermon S, Kushman N (2018) PixelDefend: leveraging generative models to understand and defend against adversarial examples. In: 6th international conference on learning representations (ICLR)"},{"key":"546_CR14","unstructured":"Samangouei P, Kabkab M, Chellappa R (2018) Defense-GAN: protecting classifiers against adversarial attacks using generative models. In: 6th international conference on learning representations (ICLR)"},{"key":"546_CR15","unstructured":"Gao J, Wang B, Lin Z, Xu W, Qi Y(2017) DeepCloak: masking deep neural network models for robustness against adversarial samples. In: 5th international conference on learning representations (ICLR)"},{"issue":"7","key":"546_CR16","doi-asserted-by":"publisher","first-page":"3691","DOI":"10.1109\/TNNLS.2021.3113342","volume":"34","author":"X Chen","year":"2023","unstructured":"Chen X, Weng J, Deng X, Luo W, Lan Y, Tian Q (2023) Feature distillation in deep attention network against adversarial examples. IEEE Trans Neural Netw Learn Syst 34(7):3691\u20133705. https:\/\/doi.org\/10.1109\/TNNLS.2021.3113342","journal-title":"IEEE Trans Neural Netw Learn Syst"},{"key":"546_CR17","doi-asserted-by":"publisher","unstructured":"Zhao B, Cui Q, Song R, Qiu Y, Liang J (2022) Decoupled knowledge distillation. In: 35th IEEE\/CVF conference on computer vision and pattern recognition (CVPR), pp 11943\u201311952 https:\/\/doi.org\/10.1109\/CVPR52688.2022.01165","DOI":"10.1109\/CVPR52688.2022.01165"},{"key":"546_CR18","doi-asserted-by":"publisher","first-page":"3690","DOI":"10.1109\/TIFS.2024.3361172","volume":"19","author":"Z Chen","year":"2024","unstructured":"Chen Z, Wang Z, Xu D, Zhu J, Shen W, Zheng S, Xuan Q, Yang X (2024) Learn to defend: adversarial multi-distillation for automatic modulation recognition models. IEEE Trans Inf Forensics Secur 19:3690\u20133702. https:\/\/doi.org\/10.1109\/TIFS.2024.3361172","journal-title":"IEEE Trans Inf Forensics Secur"},{"key":"546_CR19","unstructured":"Goodfellow IJ, Shlens J, Szegedy C (2015) Explaining and harnessing adversarial examples. In: 3rd international conference on learning representations (ICLR)"},{"key":"546_CR20","doi-asserted-by":"publisher","unstructured":"Shafahi A, Najibi M, Ghiasi A, Xu Z, Dickerson J, Studer C, Davis LS, Taylor G, Goldstein T (2019) Adversarial training for free! In: 33rd international conference on neural information processing systems (NeurIPS), https:\/\/doi.org\/10.5555\/3454287.3454589","DOI":"10.5555\/3454287.3454589"},{"key":"546_CR21","unstructured":"Gu S, Rigazio L (2015) Towards deep neural network architectures robust to adversarial examples. In: 3rd international conference on learning representations (ICLR)"},{"key":"546_CR22","doi-asserted-by":"publisher","unstructured":"Olfat M, Aswani A (2020) Average margin regularization for classifiers. In: 59th IEEE conference on decision and control (CDC), pp 3194\u20133199 https:\/\/doi.org\/10.1109\/CDC42340.2020.9303984","DOI":"10.1109\/CDC42340.2020.9303984"},{"key":"546_CR23","doi-asserted-by":"publisher","first-page":"101537","DOI":"10.1016\/j.cose.2019.05.014","volume":"88","author":"F Menet","year":"2020","unstructured":"Menet F, Berthier P, Gagnon M, Fernandez JM (2020) Spartan networks: self-feature-squeezing neural networks for increased robustness in adversarial settings. Comput Secur 88:101537. https:\/\/doi.org\/10.1016\/j.cose.2019.05.014","journal-title":"Comput Secur"},{"key":"546_CR24","doi-asserted-by":"publisher","unstructured":"He Z, Rakin AS, Fan D (2019) Parametric noise injection: trainable randomness to improve deep neural network robustness against adversarial attack. In: 32nd IEEE\/CVF conference on computer vision and pattern recognition (CVPR), pp 588\u2013597 https:\/\/doi.org\/10.1109\/CVPR.2019.00068","DOI":"10.1109\/CVPR.2019.00068"},{"key":"546_CR25","doi-asserted-by":"publisher","unstructured":"Rozsa A, Gunther M, Boult TE (2018) Towards robust deep neural networks with bang. In: 18th IEEE winter conference on applications of computer vision (WACV), pp 803\u2013811 https:\/\/doi.org\/10.1109\/WACV.2018.00093","DOI":"10.1109\/WACV.2018.00093"},{"key":"546_CR26","doi-asserted-by":"publisher","unstructured":"Folz J, Palacio S, Hees J, Dengel A (2020) Adversarial defense based on structure-to-signal autoencoders. In: 20th IEEE winter conference on applications of computer vision (WACV), pp 3568\u20133577 https:\/\/doi.org\/10.1109\/WACV45572.2020.9093310","DOI":"10.1109\/WACV45572.2020.9093310"},{"issue":"1","key":"546_CR27","doi-asserted-by":"publisher","first-page":"25","DOI":"10.1049\/cit2.12028","volume":"6","author":"A Chakraborty","year":"2021","unstructured":"Chakraborty A, Alam M, Dey V, Chattopadhyay A, Mukhopadhyay D (2021) A survey on adversarial attacks and defences. CAAI Trans Intell Technol 6(1):25\u201345","journal-title":"CAAI Trans Intell Technol"},{"issue":"9","key":"546_CR28","doi-asserted-by":"publisher","first-page":"2805","DOI":"10.1109\/TNNLS.2018.2886017","volume":"30","author":"X Yuan","year":"2019","unstructured":"Yuan X, He P, Zhu Q, Li X (2019) Adversarial examples: attacks and defenses for deep learning. IEEE Trans Neural Netw Learn Syst 30(9):2805\u20132824","journal-title":"IEEE Trans Neural Netw Learn Syst"},{"issue":"1","key":"546_CR29","doi-asserted-by":"publisher","first-page":"14410","DOI":"10.1109\/ACCESS.2018.2807385","volume":"51","author":"N Akhtar","year":"2018","unstructured":"Akhtar N, Mian A (2018) Threat of adversarial attacks on deep learning in computer vision: a survey. IEEE Access 51(1):14410\u201314430","journal-title":"IEEE Access"},{"key":"546_CR30","unstructured":"Szegedy C, Zaremba W, Sutskever I, Bruna J, Erhan D, Goodfellow IJ, Fergus R (2014) Intriguing properties of neural networks. In: 2nd international conference on learning representations (ICLR)"},{"key":"546_CR31","unstructured":"Kannan H, Kurakin A, Goodfellow IJ (2018) Adversarial Logit Pairing. Preprint at https:\/\/doi.org\/10.48550\/arXiv.1803.06373"},{"key":"546_CR32","unstructured":"Madry A, Makelov A, Schmidt L, Tsipras D, Vladu A (2018) Towards deep learning models resistant to adversarial attacks. In: 6th international conference on learning representations (ICLR)"},{"key":"546_CR33","doi-asserted-by":"publisher","unstructured":"Moosavi-Dezfooli S-M, Fawzi A, Frossard P (2016) DeepFool: a simple and accurate method to fool deep neural networks. In: 29th IEEE\/CVF conference on computer vision and pattern recognition (CVPR), pp 2574\u20132582 https:\/\/doi.org\/10.1109\/CVPR.2016.282","DOI":"10.1109\/CVPR.2016.282"},{"key":"546_CR34","doi-asserted-by":"publisher","unstructured":"Carlini N, Wagner D (2017) Towards evaluating the robustness of neural networks. In: 38th IEEE symposium on security and privacy (SP), pp 39\u201357 https:\/\/doi.org\/10.1109\/SP.2017.49","DOI":"10.1109\/SP.2017.49"},{"key":"546_CR35","doi-asserted-by":"publisher","unstructured":"Chen P-Y, Zhang H, Sharma Y, Yi J, Hsieh C-J (2017) ZOO: zeroth order optimization based black-box attacks to deep neural networks without training substitute models. In: 10th ACM workshop on artificial intelligence and security (AI-Sec), pp 15\u201326 https:\/\/doi.org\/10.1145\/3128572.3140448","DOI":"10.1145\/3128572.3140448"},{"key":"546_CR36","unstructured":"Ilyas A, Engstrom L, Athalye A, Lin J (2018) Black-box adversarial attacks with limited queries and information. In: International conference on machine learning (ICML), pp 2137\u20132146"},{"key":"546_CR37","unstructured":"Brendel W, Rauber J, Bethge M (2018) Decision-based adversarial attacks: Reliable attacks against black-box machine learning models. In: 6th international conference on learning representations (ICLR)"},{"key":"546_CR38","doi-asserted-by":"crossref","unstructured":"Chen J, Jordan MI, Wainwright MJ (2020) Hopskipjumpattack: a query-efficient decision-based attack. In: 2020 IEEE symposium on security and privacy (SP), pp 1286\u20131302","DOI":"10.1109\/SP40000.2020.00045"},{"key":"546_CR39","doi-asserted-by":"publisher","unstructured":"Chen J, Gu Q (2020) Rays: a ray searching method for hard-label adversarial attack. In: 26th ACM SIGKDD international conference on knowledge discovery & data mining (KDD), pp 1739\u20131747 https:\/\/doi.org\/10.1145\/3394486.3403225","DOI":"10.1145\/3394486.3403225"},{"key":"546_CR40","doi-asserted-by":"crossref","unstructured":"Andriushchenko M, Croce F, Flammarion N, Hein M (2020) Square attack: a query-efficient black-box adversarial attack via random search. In: 16th European conference on computer vision (ECCV), pp 484\u2013501","DOI":"10.1007\/978-3-030-58592-1_29"},{"key":"546_CR41","doi-asserted-by":"crossref","unstructured":"Dong Y, Liao F, Pang T, Su H, Zhu J, Hu X, Li J (2018) Boosting adversarial attacks with momentum. In: 31st IEEE\/CVF conference on computer vision and pattern recognition (CVPR), pp 9185\u20139193","DOI":"10.1109\/CVPR.2018.00957"},{"key":"546_CR42","unstructured":"Lin J, Song C, He K, Wang L, Hopcroft JE (2020) Nesterov accelerated gradient and scale invariance for adversarial attacks. In: 8th international conference on learning representations (ICLR)"},{"key":"546_CR43","doi-asserted-by":"publisher","unstructured":"Gong Z, Wang W (2023) Adversarial and clean data are not twins. In: 6th international workshop on exploiting artificial intelligence techniques for data management (aiDM), https:\/\/doi.org\/10.1145\/3593078.3593935","DOI":"10.1145\/3593078.3593935"},{"key":"546_CR44","unstructured":"Carlini N, Wagner D (2017) On evaluating adversarial robustness. In: 2017 IEEE symposium on security and privacy (SP), IEEE, pp 109\u2013124"},{"key":"546_CR45","doi-asserted-by":"publisher","unstructured":"Mao X, Chen Y, Li Y, He Y, Xue H (2020) Learning to characterize adversarial subspaces. In: 45th IEEE international conference on acoustics, speech and signal processing (ICASSP), pp 2438\u20132442 https:\/\/doi.org\/10.1109\/ICASSP40776.2020.9052933","DOI":"10.1109\/ICASSP40776.2020.9052933"},{"key":"546_CR46","unstructured":"Mizrahi E, Lapid R, Sipper M (2025) Pulling back the curtain: unsupervised adversarial detection via contrastive auxiliary networks. In: IEEE\/CVF international conference on computer vision (ICCV) workshops, pp 2294\u20132305"},{"key":"546_CR47","unstructured":"Yin X, Kolouri S, Rohde GK(2020) GAT: generative adversarial training for adversarial example detection and robust classification. In: 8th international conference on learning representations (ICLR)"},{"key":"546_CR48","unstructured":"Athalye A, Carlini N, Wagner D (2018) Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples. In: Dy J, Krause A (eds) 35th international conference on machine learning (ICML), Machine Learning Research, vol 80. pp 274\u2013283"},{"key":"546_CR49","unstructured":"Ma X, Li B, Wang Y, Erfani SM, Wijewickrema S, Schoenebeck G, Song D, Houle ME, Bailey J (2018) Characterizing adversarial subspaces using local intrinsic dimensionality. In: 6th international conference on learning representations (ICLR)"},{"key":"546_CR50","doi-asserted-by":"publisher","unstructured":"Lee K, Lee K, Lee H, Shin J (2018) A simple unified framework for detecting out-of-distribution samples and adversarial attacks. In: 32nd international conference on neural information processing systems (NeurIPS), pp 7167\u20137177 https:\/\/doi.org\/10.5555\/3327757.3327819","DOI":"10.5555\/3327757.3327819"},{"key":"546_CR51","doi-asserted-by":"publisher","unstructured":"Wang Q, Li C, Luo Y, Ling H, Huang S, Jia R, Yu N (2025) Detecting adversarial data using perturbation forgery. In: 38th IEEE\/CVF conference on computer vision and pattern recognition (CVPR), pp 13917\u201313926 https:\/\/doi.org\/10.1109\/CVPR52734.2025.01299","DOI":"10.1109\/CVPR52734.2025.01299"},{"key":"546_CR52","doi-asserted-by":"crossref","unstructured":"Carrara F, Becarelli R, Caldelli R, Falchi F, Amato G (2018) Adversarial examples detection in features distance spaces. In: 15th European conference on computer vision workshops (ECCV)","DOI":"10.1007\/978-3-030-11012-3_26"},{"key":"546_CR53","doi-asserted-by":"publisher","unstructured":"Monteiro J, Albuquerque I, Akhtar Z, Falk TH (2019) Generalizable adversarial examples detection based on bi-model decision mismatch. In: 49th IEEE international conference on systems, man and cybernetics (SMC), pp 2839\u20132844 https:\/\/doi.org\/10.1109\/SMC.2019.8913861","DOI":"10.1109\/SMC.2019.8913861"},{"key":"546_CR54","doi-asserted-by":"publisher","unstructured":"Fidel G, Bitton R, Shabtai A (2020) When explainability meets adversarial learning: Detecting adversarial examples using shap signatures. In: 29th international joint conference on neural networks (IJCNN), pp 1\u20138 https:\/\/doi.org\/10.1109\/IJCNN48605.2020.9207637","DOI":"10.1109\/IJCNN48605.2020.9207637"},{"key":"546_CR55","unstructured":"Grosse K, Manoharan P, Papernot N, Backes M, McDaniel P (2017) On the statistical detection of adversarial examples. Preprint at https:\/\/doi.org\/10.48550\/arXiv.1702.06280"},{"key":"546_CR56","unstructured":"Zhang J, Rubinstein BIP, Zhang J, Liu F (2025) One stone, two birds: enhancing adversarial defense through the lens of distributional discrepancy. In: 42nd international conference on machine learning (ICML)"},{"key":"546_CR57","doi-asserted-by":"publisher","DOI":"10.1145\/3636460","author":"J Dong","year":"2024","unstructured":"Dong J, Zhou P (2024) Detecting adversarial examples utilizing pixel value diversity. ACM Trans Des Autom Electron Syst. https:\/\/doi.org\/10.1145\/3636460","journal-title":"ACM Trans Des Autom Electron Syst"},{"issue":"12","key":"546_CR58","doi-asserted-by":"publisher","first-page":"7015","DOI":"10.1109\/TFUZZ.2024.3473768","volume":"32","author":"Y Li","year":"2024","unstructured":"Li Y, Angelov P, Suri N (2024) Adversarial attack detection via fuzzy predictions. IEEE Trans Fuzzy Syst 32(12):7015\u20137024. https:\/\/doi.org\/10.1109\/TFUZZ.2024.3473768","journal-title":"IEEE Trans Fuzzy Syst"},{"key":"546_CR59","doi-asserted-by":"publisher","unstructured":"Smith L, Gal Y (2018) Understanding measures of uncertainty for adversarial example detection. Preprint at https:\/\/doi.org\/10.48550\/arXiv.1803.08533","DOI":"10.48550\/arXiv.1803.08533"},{"key":"546_CR60","doi-asserted-by":"publisher","unstructured":"Zheng Z, Hong P (2018). Robust detection of adversarial attacks by modeling the intrinsic properties of deep neural networks. In: 32nd international conference on neural information processing systems (NeurIPS), pp 7924\u20137933 https:\/\/doi.org\/10.5555\/3327757.3327888","DOI":"10.5555\/3327757.3327888"},{"key":"546_CR61","doi-asserted-by":"publisher","unstructured":"Zhang C, Zhou W, Zhang K, Zhang J, Zhang W, Yu N (2024) Detecting adversarial examples via reconstruction-based semantic inconsistency. In: 6th ACM turing award celebration conference (ACM-TURC), pp 126\u2013131 https:\/\/doi.org\/10.1145\/3674399.3674448","DOI":"10.1145\/3674399.3674448"},{"key":"546_CR62","doi-asserted-by":"publisher","unstructured":"Lorenz P, Durall R, Keuper J (2024). Adversarial examples are misaligned in diffusion model manifolds. In: 33rd international joint conference on neural networks (IJCNN), pp 1\u20138 https:\/\/doi.org\/10.1109\/IJCNN60899.2024.10650024","DOI":"10.1109\/IJCNN60899.2024.10650024"},{"key":"546_CR63","doi-asserted-by":"publisher","unstructured":"Wang J, Dong G, Sun J, Wang X, Zhang P (2019) Adversarial sample detection for deep neural network through model mutation testing. In: 41st international conference on software engineering (ICSE), pp 1245\u20131256 https:\/\/doi.org\/10.1109\/ICSE.2019.00126","DOI":"10.1109\/ICSE.2019.00126"},{"key":"546_CR64","unstructured":"Roth K, Lucchi A, Nowozin S, Hofmann T (2019) The odds are odd: a statistical test for detecting adversarial examples. In: 7th international conference on learning representations (ICLR)"},{"key":"546_CR65","doi-asserted-by":"publisher","DOI":"10.1145\/3631977","author":"Z Zhao","year":"2024","unstructured":"Zhao Z, Chen G, Liu T, Li T, Song F, Wang J, Sun J (2024) Attack as detection: using adversarial attack methods to detect abnormal examples. ACM Trans Softw Eng Methodol. https:\/\/doi.org\/10.1145\/3631977","journal-title":"ACM Trans Softw Eng Methodol"},{"key":"546_CR66","doi-asserted-by":"publisher","unstructured":"Cohen G, Sapiro G, Giryes R (2020) Detecting adversarial samples using influence functions and nearest neighbors. In: 33rd IEEE\/CVF conference on computer vision and pattern recognition (CVPR), pp 14441\u201314450 https:\/\/doi.org\/10.1109\/CVPR42600.2020.01446","DOI":"10.1109\/CVPR42600.2020.01446"},{"key":"546_CR67","doi-asserted-by":"crossref","unstructured":"Papernot N, McDaniel P, Jha S, Fredrikson M, Celik ZB, Swami A (2016) The limitations of deep learning in adversarial settings. In: 1st IEEE European symposium on security and privacy (EuroS&P), pp 372\u2013387","DOI":"10.1109\/EuroSP.2016.36"},{"key":"546_CR68","doi-asserted-by":"publisher","unstructured":"Croce F, Hein M (2020) Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks. In: 37th international conference on machine learning (ICML) https:\/\/doi.org\/10.5555\/3524938.3525144","DOI":"10.5555\/3524938.3525144"},{"key":"546_CR69","unstructured":"Alexey K, Goodfellow IJ, Samy B (2017) Adversarial machine learning at scale. In: 5th international conference on learning representations (ICLR)"},{"key":"546_CR70","unstructured":"Papernot N, McDaniel P, Goodfellow IJ (2016) Transferability in machine learning: from phenomena to black-box attacks using adversarial samples. Preprint at https:\/\/doi.org\/10.48550\/arXiv.1605.07277"},{"key":"546_CR71","doi-asserted-by":"crossref","unstructured":"Kurakin A, Goodfellow I, Bengio S (2017) Adversarial examples in the physical world. In: 34th international conference on machine learning (ICML)","DOI":"10.1201\/9781351251389-8"},{"key":"546_CR72","doi-asserted-by":"publisher","unstructured":"Chen P, Sharma Y, Zhang H, Yi J, Hsieh C (2018) EAD: elastic-net attacks to deep neural networks via adversarial examples. In: 32rd AAAI conference on artificial intelligence (AAAI), vol 33. https:\/\/doi.org\/10.1609\/aaai.v32i1.11302","DOI":"10.1609\/aaai.v32i1.11302"},{"key":"546_CR73","unstructured":"Ilyas A, Engstrom L, Athalye A, Lin J (2018) Black-box adversarial attacks with limited queries and information. In: 35th international conference on machine learning (ICML)"},{"key":"546_CR74","unstructured":"Ilyas A, Engstrom L, Madry A (2019) Prior convictions: black-box adversarial attacks with bandits and priors. In: 7th international conference on learning representations (ICLR)"},{"key":"546_CR75","unstructured":"Dziugaite GK, Ghahramani Z, Roy DM (2016) A study of the effect of JPG compression on adversarial images. Preprint at https:\/\/doi.org\/10.48550\/arXiv.1608.00853"},{"key":"546_CR76","unstructured":"Guo C, Rana M, Cisse M, Maaten L (2018) Countering adversarial images using input transformations. In: 6th international conference on learning representations (ICLR)"},{"key":"546_CR77","unstructured":"Xie C, Wang J, Zhang Z, Ren Z, Yuille A (2018) Mitigating adversarial effects through randomization. In: 6th international conference on learning representations (ICLR)"},{"key":"546_CR78","unstructured":"Chen Y, Shao S, Huang E, Li Y, Chen P-Y, Qin Z, Ren K (2025) REFINE: inversion-free backdoor defense via model reprogramming. In: 13th international conference on learning representations (ICLR)"},{"key":"546_CR79","doi-asserted-by":"publisher","unstructured":"Jin G, Shen S, Zhang D, Dai F, Zhang Y (2019) APE-GAN: adversarial perturbation elimination with gan. In: 44th IEEE international conference on acoustics (ICASSP), pp 3842\u20133846 https:\/\/doi.org\/10.1109\/ICASSP.2019.8683044","DOI":"10.1109\/ICASSP.2019.8683044"},{"key":"546_CR80","doi-asserted-by":"publisher","unstructured":"Song K, Lai H, Pan Y, Yin J (2024) Mimicdiffusion: purifying adversarial perturbation via mimicking clean diffusion model. In: 37th IEEE\/CVF conference on computer vision and pattern recognition (CVPR), pp 24665\u201324674 https:\/\/doi.org\/10.1109\/CVPR52733.2024.02329","DOI":"10.1109\/CVPR52733.2024.02329"},{"key":"546_CR81","doi-asserted-by":"publisher","unstructured":"Chun Tong L, Hon Ming Y, Guo Z, Qian Y, Chun Pong L (2025) Instant adversarial purification with adversarial consistency distillation. In: 38th IEEE\/CVF conference on computer vision and pattern recognition (CVPR), pp 24331\u201324340 https:\/\/doi.org\/10.1109\/CVPR52734.2025.02266","DOI":"10.1109\/CVPR52734.2025.02266"},{"key":"546_CR82","doi-asserted-by":"publisher","unstructured":"Naseer M, Khan S, Hayat M, Khan FS, Porikli F (2020) A self-supervised approach for adversarial robustness. In: 33rd IEEE\/CVF conference on computer vision and pattern recognition (CVPR), pp 259\u2013268 https:\/\/doi.org\/10.1109\/CVPR42600.2020.00034","DOI":"10.1109\/CVPR42600.2020.00034"},{"key":"546_CR83","doi-asserted-by":"crossref","unstructured":"Prakash A, Moran N, Garber S, DiLillo A, Storer J (2018) Deflecting adversarial attacks with pixel deflection. In: 31st IEEE\/CVF conference on computer vision and pattern recognition (CVPR)","DOI":"10.1109\/CVPR.2018.00894"},{"key":"546_CR84","unstructured":"Zhang Y, Liang P (2019) Defending against whitebox adversarial attacks via randomized discretization. In: 22nd international conference on artificial intelligence and statistics (AISTATS), pp 684\u2013693"},{"key":"546_CR85","doi-asserted-by":"publisher","unstructured":"Jia X, Wei X, Cao X, Foroosh H (2019) ComDefend: an efficient image compression model to defend adversarial examples. In: 32nd IEEE\/CVF conference on computer vision and pattern recognition (CVPR), pp 6077\u20136085 https:\/\/doi.org\/10.1109\/CVPR.2019.00624","DOI":"10.1109\/CVPR.2019.00624"},{"key":"546_CR86","doi-asserted-by":"publisher","first-page":"1711","DOI":"10.1109\/TIP.2019.2940533","volume":"29","author":"A Mustafa","year":"2020","unstructured":"Mustafa A, Khan SH, Hayat M, Shen J, Shao L (2020) Image super-resolution as a defense against adversarial attacks. IEEE Trans Image Process 29:1711\u20131724. https:\/\/doi.org\/10.1109\/TIP.2019.2940533","journal-title":"IEEE Trans Image Process"},{"key":"546_CR87","doi-asserted-by":"publisher","DOI":"10.1007\/s10489-022-03847-z","author":"X Chai","year":"2023","unstructured":"Chai X, Wei T, Chen Z, He X, Gan Z, Wu X (2023) LDN-RC: a lightweight denoising network with residual connection to improve adversarial robustness. Appl Intell. https:\/\/doi.org\/10.1007\/s10489-022-03847-z","journal-title":"Appl Intell"},{"key":"546_CR88","doi-asserted-by":"publisher","unstructured":"Li S, Chen Y, Peng Y, Bai L (2018) Learning more robust features with adversarial training. Preprint at https:\/\/doi.org\/10.48550\/arXiv.1804.07757","DOI":"10.48550\/arXiv.1804.07757"},{"key":"546_CR89","doi-asserted-by":"publisher","unstructured":"Xie C, Wu Y, Maaten Lvd, Yuille AL, He K (2019) Feature denoising for improving adversarial robustness. In: 32nd IEEE\/CVF conference on computer vision and pattern recognition (CVPR), pp 501\u2013509 https:\/\/doi.org\/10.1109\/CVPR.2019.00059","DOI":"10.1109\/CVPR.2019.00059"},{"key":"546_CR90","doi-asserted-by":"crossref","unstructured":"Li Z, Rei M, Specia L (2024) Diffusedef: improved robustness to adversarial attacks. In: 63rd annual meeting of the association for computational linguistics (ACL)","DOI":"10.18653\/v1\/2025.acl-long.454"},{"key":"546_CR91","unstructured":"Xiang C, Bhagoji AN, Sehwag V, Mittal P(2021) PatchGuard: a provably robust defense against adversarial patches via small receptive fields and masking. In: 30th USENIX security symposium (USENIX Security), pp 2237\u20132254"},{"key":"546_CR92","doi-asserted-by":"crossref","unstructured":"Jeddi A, Shafiee MJ, Karg M, Scharfenberger C, Wong A (2020) Learn2Perturb: an end-to-end feature perturbation learning to improve adversarial robustness. In: 33rd IEEE\/CVF conference on computer vision and pattern recognition (CVPR), pp 1241\u20131250","DOI":"10.1109\/CVPR42600.2020.00132"},{"issue":"3","key":"546_CR93","doi-asserted-by":"publisher","first-page":"5480","DOI":"10.1109\/TNNLS.2024.3379172","volume":"36","author":"J Dong","year":"2025","unstructured":"Dong J, Wang Y, Xie X, Lai J, Ong Y-S (2025) Generalizable and discriminative representations for adversarially robust few-shot learning. IEEE Trans Neural Netw Learn Syst 36(3):5480\u20135493. https:\/\/doi.org\/10.1109\/TNNLS.2024.3379172","journal-title":"IEEE Trans Neural Netw Learn Syst"},{"key":"546_CR94","doi-asserted-by":"publisher","unstructured":"Zhou Z, Yang J (2022) Attentive manifold mixup for model robustness. In: 6th international conference on machine learning and soft computing (ICMLSC), pp 85\u201391 https:\/\/doi.org\/10.1145\/3523150.3523164","DOI":"10.1145\/3523150.3523164"},{"key":"546_CR95","doi-asserted-by":"crossref","unstructured":"Xie C, Zhang Y, Zhishuaiand\u00a0Zhou, Bai S, Wang J, Ren Z, Yuille AL (2019) Improving transferability of adversarial examples with input diversity. In: 32nd IEEE\/CVF conference on computer vision and pattern recognition (CVPR), pp 2730\u20132739","DOI":"10.1109\/CVPR.2019.00284"},{"key":"546_CR96","doi-asserted-by":"publisher","unstructured":"Rony J, Hafemann LG, Oliveira LS, Ben\u00a0Ayed I, Sabourin R, Granger E (2019) Decoupling direction and norm for efficient gradient-based l2 adversarial attacks and defenses. In: 32nd IEEE\/CVF conference on computer vision and pattern recognition (CVPR), pp. 4317\u20134325 https:\/\/doi.org\/10.1109\/CVPR.2019.00445","DOI":"10.1109\/CVPR.2019.00445"},{"key":"546_CR97","unstructured":"Goodfellow IJ, Shlens J, Szegedy C (2017) Adversarial examples in the physical world. In: 5th international conference on learning representations (ICLR)"},{"key":"546_CR98","doi-asserted-by":"publisher","unstructured":"Moosavi-Dezfooli S-M, Fawzi A, Fawzi O, Frossard P (2017) Universal adversarial perturbations. In: 30th IEEE\/CVF conference on computer vision and pattern recognition (CVPR), pp 86\u201394 https:\/\/doi.org\/10.1109\/CVPR.2017.17","DOI":"10.1109\/CVPR.2017.17"},{"key":"546_CR99","doi-asserted-by":"crossref","unstructured":"Papernot N, McDaniel P, Wu X, Jha S, Swami A (2016) Distillation as a defense to adversarial perturbations against deep neural networks. In: 37th IEEE symposium on security and privacy (SP), pp 582\u2013597","DOI":"10.1109\/SP.2016.41"},{"key":"546_CR100","unstructured":"Papernot N, McDaniel P (2017) Extending Defensive Distillation. Preprint at https:\/\/doi.org\/10.48550\/arXiv.1705.05264"},{"key":"546_CR101","doi-asserted-by":"crossref","unstructured":"Zi B, Zhao S, Ma X, Jiang Y-G (2021) Revisiting adversarial robustness distillation: robust soft labels make student better. In: 18th IEEE\/CVF international conference on computer vision (ICCV), pp 16443\u201316452","DOI":"10.1109\/ICCV48922.2021.01613"},{"key":"546_CR102","doi-asserted-by":"publisher","first-page":"9643","DOI":"10.1109\/TIFS.2023.3237371","volume":"19","author":"T Bai","year":"2024","unstructured":"Bai T, Zhao J, Wen B (2024) Guided adversarial contrastive distillation for robust students. IEEE Trans Inform Forensics Secur 19:9643\u20139655. https:\/\/doi.org\/10.1109\/TIFS.2023.3237371","journal-title":"IEEE Trans Inform Forensics Secur"},{"key":"546_CR103","doi-asserted-by":"publisher","unstructured":"Huang B, Chen M, Wang Y, Lu J, Cheng M, Wang W (2023) Boosting accuracy and robustness of student models via adaptive adversarial distillation. In: 36th IEEE\/CVF conference on computer vision and pattern recognition (CVPR), pp 24668\u201324677 https:\/\/doi.org\/10.1109\/CVPR52729.2023.02363","DOI":"10.1109\/CVPR52729.2023.02363"},{"issue":"3","key":"546_CR104","doi-asserted-by":"publisher","first-page":"3069","DOI":"10.1007\/s10489-022-03495-3","volume":"53","author":"Y Liang","year":"2023","unstructured":"Liang Y, Samavi R (2023) Advanced defensive distillation with ensemble voting and noisy logits. Appl Intell 53(3):3069\u20133094. https:\/\/doi.org\/10.1007\/s10489-022-03495-3","journal-title":"Appl Intell"},{"key":"546_CR105","doi-asserted-by":"publisher","unstructured":"Chen E-C, Lee C-R (2023) LTD: low temperature distillation for robust adversarial training. Preprint at https:\/\/doi.org\/10.48550\/arXiv.2111.02331","DOI":"10.48550\/arXiv.2111.02331"},{"key":"546_CR106","unstructured":"Liu Y, Gao J, Jiao X, Liu Z, Fan X, Liu R (2024) Learn from the past: a proxy guided adversarial defense framework with self distillation regularization. In: 12th international conference on learning representations (ICLR)"},{"key":"546_CR107","doi-asserted-by":"crossref","unstructured":"Levi YY, Grolman E, Yankelev I, Giloni A, Hofman O, Shimizu T, Shabtai A, Elovici Y (2025) Kdat: inherent adversarial robustness via knowledge distillation with adversarial tuning for object detection models. In: 39th AAAI conference on artificial intelligence (AAAI), pp 4598\u20134606","DOI":"10.1609\/aaai.v39i5.32485"},{"issue":"12","key":"546_CR108","doi-asserted-by":"publisher","first-page":"9338","DOI":"10.1109\/TPAMI.2024.3416308","volume":"46","author":"S Zhao","year":"2024","unstructured":"Zhao S, Wang X, Wei X (2024) Mitigating accuracy-robustness trade-off via balanced multi-teacher adversarial distillation. IEEE Trans Pattern Anal Mach Intell 46(12):9338\u20139352. https:\/\/doi.org\/10.1109\/TPAMI.2024.3416308","journal-title":"IEEE Trans Pattern Anal Mach Intell"},{"key":"546_CR109","doi-asserted-by":"crossref","unstructured":"Yang C, Yu X, Yang H, An Z, Yu C, Huang L, Xu Y (2025) Multi-teacher knowledge distillation with reinforcement learning for visual recognition. In: 39th AAAI conference on artificial intelligence (AAAI), pp 9148\u20139156","DOI":"10.1609\/aaai.v39i9.32990"},{"key":"546_CR110","unstructured":"Sinha A, Namkoong H, Volpi R, Duchi J (2018) Certifying some distributional robustness with principled adversarial training. In: 6th international conference on learning representations (ICLR)"},{"key":"546_CR111","unstructured":"Wong E, Rice L, Kolter JZ(2020) Fast is better than free: revisiting adversarial training. In: International conference on learning representations (ICLR)"},{"key":"546_CR112","doi-asserted-by":"publisher","unstructured":"Zheng H, Zhang Z, Gu J, Lee H, Prakash A (2020) Efficient adversarial training with transferable adversarial examples. In: 33rd IEEE\/CVF conference on computer vision and pattern recognition (CVPR), pp 1178\u20131187 https:\/\/doi.org\/10.1109\/CVPR42600.2020.00126","DOI":"10.1109\/CVPR42600.2020.00126"},{"key":"546_CR113","doi-asserted-by":"crossref","unstructured":"Mummadi CK, Brox T, Metzen JH (2019) Defending against universal perturbations with shared adversarial training. In: 17th IEEE\/CVF international conference on computer vision (ICCV)","DOI":"10.1109\/ICCV.2019.00503"},{"key":"546_CR114","doi-asserted-by":"publisher","first-page":"4547","DOI":"10.1109\/TIFS.2024.3377004","volume":"19","author":"X Jia","year":"2024","unstructured":"Jia X, Li J, Gu J, Bai Y, Cao X (2024) Fast propagation is better: accelerating single-step adversarial training via sampling subnetworks. IEEE Trans Inf Forensics Secur 19:4547\u20134559. https:\/\/doi.org\/10.1109\/TIFS.2024.3377004","journal-title":"IEEE Trans Inf Forensics Secur"},{"key":"546_CR115","unstructured":"Zhang H, Yu Y, Jiao J, Xing E, Ghaoui LE, Jordan M (2019) Theoretically principled trade-off between robustness and accuracy. In: 36th international conference on machine learning (ICML), pp 7472\u20137482"},{"key":"546_CR116","doi-asserted-by":"publisher","unstructured":"Tong H, Zhang X, Jin Y, Lou J, Wu K, Chen X (2024) Balancing generalization and robustness in adversarial training via steering through clean and adversarial gradient directions. In: 32nd ACM international conference on multimedia (MM), pp 1014\u20131023 https:\/\/doi.org\/10.1145\/3664647.3680963","DOI":"10.1145\/3664647.3680963"},{"issue":"1","key":"546_CR117","doi-asserted-by":"publisher","first-page":"664","DOI":"10.1109\/TDSC.2024.3411302","volume":"22","author":"G Cao","year":"2025","unstructured":"Cao G, Wang Z, Dong X, Zhang Z, Guo H, Qin Z, Ren K (2025) Vanilla feature distillation for improving the accuracy-robustness trade-off in adversarial training. IEEE Trans Dependable Secure Comput 22(1):664\u2013676. https:\/\/doi.org\/10.1109\/TDSC.2024.3411302","journal-title":"IEEE Trans Dependable Secure Comput"},{"key":"546_CR118","unstructured":"Na T, Ko JH, Mukhopadhyay S (2018) Cascade adversarial machine learning regularized with a unified embedding. In: 6th international conference on learning representations (ICLR)"},{"key":"546_CR119","doi-asserted-by":"publisher","unstructured":"Song C, Cheng H-P, Yang H, Li S, Wu C, Wu Q, Chen Y, Li H (2018) MAT: a multi-strength adversarial training method to mitigate adversarial attacks. In: 17th IEEE computer society annual symposium on VLSI (ISVLSI), pp 476\u2013481 https:\/\/doi.org\/10.1109\/ISVLSI.2018.00092","DOI":"10.1109\/ISVLSI.2018.00092"},{"key":"546_CR120","doi-asserted-by":"publisher","first-page":"7748","DOI":"10.1109\/TMM.2024.3371211","volume":"26","author":"S He","year":"2024","unstructured":"He S, Wei J, Zhang C, Xu X, Song J, Yang Y, Shen HT (2024) Boosting adversarial training with hardness-guided attack strategy. IEEE Trans Multimedia 26:7748\u20137760. https:\/\/doi.org\/10.1109\/TMM.2024.3371211","journal-title":"IEEE Trans Multimedia"},{"key":"546_CR121","doi-asserted-by":"publisher","first-page":"10367","DOI":"10.1109\/TMM.2024.3407677","volume":"26","author":"J Wei","year":"2024","unstructured":"Wei J, Pan C, He S, Wang G, Yang Y, Shen HT (2024) Towards robust person re-identification by adversarial training with dynamic attack strategy. IEEE Trans Multimedia 26:10367\u201310380. https:\/\/doi.org\/10.1109\/TMM.2024.3407677","journal-title":"IEEE Trans Multimedia"},{"key":"546_CR122","doi-asserted-by":"publisher","unstructured":"Dong Y, Deng Z, Pang T, Zhu J, Su H (2020) Adversarial distributional training for robust deep learning. In: 34th international conference on neural information processing systems (NeurIPS) https:\/\/doi.org\/10.5555\/3495724.3496417","DOI":"10.5555\/3495724.3496417"},{"key":"546_CR123","doi-asserted-by":"publisher","unstructured":"Wang Z, Zhou Z, Liu W (2024) DRF: improving certified robustness via distributional robustness framework. In: 38th AAAI conference on artificial intelligence (AAAI), vol 38. pp 15752\u201315760 https:\/\/doi.org\/10.1609\/aaai.v38i14.29504","DOI":"10.1609\/aaai.v38i14.29504"},{"issue":"2","key":"546_CR124","doi-asserted-by":"publisher","first-page":"876","DOI":"10.1109\/TDSC.2023.3264850","volume":"21","author":"J Yang","year":"2024","unstructured":"Yang J, Xiang L, Chu P, Wang X, Zhou C (2024) Certified distributional robustness on smoothed classifiers. IEEE Trans Dependable Secure Comput 21(2):876\u2013888. https:\/\/doi.org\/10.1109\/TDSC.2023.3264850","journal-title":"IEEE Trans Dependable Secure Comput"},{"issue":"12","key":"546_CR125","doi-asserted-by":"publisher","first-page":"8302","DOI":"10.1109\/TPAMI.2024.3400988","volume":"46","author":"L Zhang","year":"2024","unstructured":"Zhang L, Yang N, Sun Y, Yu PS (2024) Provable unrestricted adversarial training without compromise with generalizability. IEEE Trans Pattern Anal Mach Intell 46(12):8302\u20138319. https:\/\/doi.org\/10.1109\/TPAMI.2024.3400988","journal-title":"IEEE Trans Pattern Anal Mach Intell"},{"key":"546_CR126","unstructured":"Lin G, Li C, Zhang J, Tanaka T, Zhao Q (2024) Adversarial training on purification (ATop): advancing both robustness and generalization. In: 12th international conference on learning representations (ICLR)"},{"key":"546_CR127","doi-asserted-by":"publisher","unstructured":"Salman H, Yang G, Li J, Zhang P, Zhang H, Razenshteyn I, Bubeck S (2019) Provably robust deep learning via adversarially trained smoothed classifiers. In: 33rd international conference on neural information processing systems (NeurIPS) https:\/\/doi.org\/10.5555\/3454287.3455300","DOI":"10.5555\/3454287.3455300"},{"key":"546_CR128","doi-asserted-by":"publisher","unstructured":"Chen K, Chen Y, Zhou H, Mao X, Li Y, He Y, Xue H, Zhang W, Yu N (2020) Self-supervised adversarial training. In: 45th IEEE international conference on acoustics, speech and signal processing (ICASSP), pp 2218\u20132222 https:\/\/doi.org\/10.1109\/ICASSP40776.2020.9054475","DOI":"10.1109\/ICASSP40776.2020.9054475"},{"key":"546_CR129","doi-asserted-by":"publisher","unstructured":"Zhang H, Jia F, Zhang Q, Han Y, Kuang X, Tan Y-a (2020) Two-way feature-aligned and attention-rectified adversarial training. In: 21st IEEE international conference on multimedia and expo (ICME), pp 1\u20136 https:\/\/doi.org\/10.1109\/ICME46284.2020.9102777","DOI":"10.1109\/ICME46284.2020.9102777"},{"key":"546_CR130","doi-asserted-by":"publisher","unstructured":"Chen X, Zhang N(2020) Layer-wise adversarial training approach to improve adversarial robustness. In: 29th international joint conference on neural networks (IJCNN), pp 1\u20138 https:\/\/doi.org\/10.1109\/IJCNN48605.2020.9206760","DOI":"10.1109\/IJCNN48605.2020.9206760"},{"key":"546_CR131","doi-asserted-by":"publisher","first-page":"5769","DOI":"10.1109\/TIP.2021.3082317","volume":"30","author":"A Liu","year":"2021","unstructured":"Liu A, Liu X, Yu H, Zhang C, Liu Q, Tao D (2021) Training robust deep neural networks via adversarial noise propagation. IEEE Trans Image Process 30:5769\u20135781. https:\/\/doi.org\/10.1109\/TIP.2021.3082317","journal-title":"IEEE Trans Image Process"},{"issue":"10","key":"546_CR132","doi-asserted-by":"publisher","first-page":"3851","DOI":"10.1007\/s10994-022-06203-x","volume":"112","author":"X Zhou","year":"2023","unstructured":"Zhou X, Tsang IW, Yin J (2023) LADDER: latent boundary-guided adversarial training. Mach Learn 112(10):3851\u20133879. https:\/\/doi.org\/10.1007\/s10994-022-06203-x","journal-title":"Mach Learn"},{"key":"546_CR133","doi-asserted-by":"crossref","unstructured":"Vivek BS, Reddy\u00a0Mopuri K, Venkatesh\u00a0Babu R (2018) Gray-box adversarial training. In: 15th European conference on computer vision (ECCV)","DOI":"10.1007\/978-3-030-01267-0_13"},{"key":"546_CR134","doi-asserted-by":"publisher","unstructured":"Qin Y, Hunt R, Yue C (2019) On improving the effectiveness of adversarial training. In: 9th acm international workshop on security and privacy analytics (IWSPA), pp 5\u201313 https:\/\/doi.org\/10.1145\/3309182.3309190","DOI":"10.1145\/3309182.3309190"},{"key":"546_CR135","doi-asserted-by":"publisher","unstructured":"Vivek BS, Venkatesh\u00a0Babu R (2020) Single-step adversarial training with dropout scheduling. In: 33rd IEEE\/CVF conference on computer vision and pattern recognition (CVPR), pp 947\u2013956 https:\/\/doi.org\/10.1109\/CVPR42600.2020.00103","DOI":"10.1109\/CVPR42600.2020.00103"},{"key":"546_CR136","doi-asserted-by":"publisher","unstructured":"Serban A, Poll E, Visser J (2020) Learning to learn from mistakes: Robust optimization for adversarial noise. In: 29th international conference on artificial neural networks (ICANN), pp 467\u2013478 https:\/\/doi.org\/10.1007\/978-3-030-61609-0_37","DOI":"10.1007\/978-3-030-61609-0_37"},{"key":"546_CR137","doi-asserted-by":"publisher","unstructured":"Hwang J-w, Lee Y, Oh S, Bae Y (2021) Adversarial training with stochastic weight average. In: 28th IEEE international conference on image processing (ICIP), pp 814\u2013818 https:\/\/doi.org\/10.1109\/ICIP42928.2021.9506548","DOI":"10.1109\/ICIP42928.2021.9506548"},{"key":"546_CR138","doi-asserted-by":"publisher","first-page":"1613","DOI":"10.1109\/TIFS.2025.3533925","volume":"20","author":"X Liu","year":"2025","unstructured":"Liu X, Yang Y, He K, Hopcroft JE (2025) Parameter interpolation adversarial training for robust image classification. IEEE Trans Inf Forensics Secur 20:1613\u20131623. https:\/\/doi.org\/10.1109\/TIFS.2025.3533925","journal-title":"IEEE Trans Inf Forensics Secur"},{"issue":"9","key":"546_CR139","doi-asserted-by":"publisher","first-page":"6367","DOI":"10.1109\/TPAMI.2024.3381180","volume":"46","author":"X Jia","year":"2024","unstructured":"Jia X, Zhang Y, Wei X, Wu B, Ma K, Wang J, Cao X (2024) Improving fast adversarial training with prior-guided knowledge. IEEE Trans Pattern Anal Mach Intell 46(9):6367\u20136383. https:\/\/doi.org\/10.1109\/TPAMI.2024.3381180","journal-title":"IEEE Trans Pattern Anal Mach Intell"},{"key":"546_CR140","doi-asserted-by":"publisher","unstructured":"Wang S, Huang Y, Shi J, Yang Y, Guo X (2023) Improving single-step adversarial training by local smoothing. In: 32nd international joint conference on neural networks (IJCNN), pp 1\u20138 https:\/\/doi.org\/10.1109\/IJCNN54540.2023.10191877","DOI":"10.1109\/IJCNN54540.2023.10191877"},{"key":"546_CR141","doi-asserted-by":"publisher","unstructured":"Du P, Zheng X, Liu L, Ma H (2022) Defending against universal attack via curvature-aware category adversarial training. In: 47th IEEE international conference on acoustics, speech and signal processing (ICASSP), pp 2470\u20132474 https:\/\/doi.org\/10.1109\/ICASSP43922.2022.9746983","DOI":"10.1109\/ICASSP43922.2022.9746983"},{"key":"546_CR142","doi-asserted-by":"publisher","unstructured":"Hou P, Zhou M, Han J, Musilek P, Li X (2022) Adversarial fine-tune with dynamically regulated adversary. In: 31st international joint conference on neural networks (IJCNN), pp 01\u201308 https:\/\/doi.org\/10.1109\/IJCNN55064.2022.9892485","DOI":"10.1109\/IJCNN55064.2022.9892485"},{"key":"546_CR143","doi-asserted-by":"publisher","first-page":"3659","DOI":"10.1109\/TIFS.2024.3359820","volume":"19","author":"H Kuang","year":"2024","unstructured":"Kuang H, Liu H, Lin X, Ji R (2024) Defense against adversarial attacks using topology aligning adversarial training. IEEE Trans Inf Forensics Secur 19:3659\u20133673. https:\/\/doi.org\/10.1109\/TIFS.2024.3359820","journal-title":"IEEE Trans Inf Forensics Secur"},{"key":"546_CR144","doi-asserted-by":"publisher","unstructured":"Hein M, Andriushchenko M (2017) Formal guarantees on the robustness of a classifier against adversarial manipulation. In: 31st international conference on neural information processing systems (NeurIPS), pp 2263\u20132273 https:\/\/doi.org\/10.5555\/3294771.3294987","DOI":"10.5555\/3294771.3294987"},{"key":"546_CR145","unstructured":"Serrurier M, Mamalet F, Fel T, B\u00e9thune L, Boissin T (2023) On the explainable properties of 1-lipschitz neural networks: an optimal transport perspective. In: 37th international conference on neural information processing systems (NIPS)"},{"key":"546_CR146","doi-asserted-by":"publisher","unstructured":"Hu J, Ye J, Feng Z, Yang J, Liu S, Yu X, Jia L, Song M (2024) Improving adversarial robustness via feature pattern consistency constraint. In: Proceedings of the thirty-third international joint conference on artificial intelligence (IJCAI), pp 848\u2013856 https:\/\/doi.org\/10.24963\/ijcai.2024\/94","DOI":"10.24963\/ijcai.2024\/94"},{"key":"546_CR147","doi-asserted-by":"publisher","unstructured":"Qiao Y, Yin Y, Chen C, Ma J (2025) Certified causal defense with generalizable robustness. In: Proceedings of the 39th AAAI conference on artificial intelligence (AAAI), vol 39. pp 20024\u201320032 https:\/\/doi.org\/10.1609\/aaai.v39i19.34205","DOI":"10.1609\/aaai.v39i19.34205"},{"key":"546_CR148","doi-asserted-by":"publisher","unstructured":"Cisse M, Bojanowski P, Grave E, Dauphin Y, Usunier N (2017) Parseval Networks: improving robustness to adversarial examples. In: 34th international conference on machine learning (ICML), pp 854\u2013863 https:\/\/doi.org\/10.5555\/3305381.3305470","DOI":"10.5555\/3305381.3305470"},{"key":"546_CR149","unstructured":"Rocamora EA, Chrysos G, Cevher V (2025) Certified robustness under bounded levenshtein distance. In: 13th international conference on learning representations (ICLR)"},{"key":"546_CR150","unstructured":"Fazlyab M, Entesari T, Roy A, Chellappa R (2023) Certified robustness via dynamic margin maximization and improved lipschitz regularization. In: 37th international conference on neural information processing systems (NIPS), vol 36. pp 34451\u201334464"},{"key":"546_CR151","doi-asserted-by":"publisher","unstructured":"Ross AS, Doshi-Velez F (2018) Improving the adversarial robustness and interpretability of deep neural networks by regularizing their input gradients. In: 32nd AAAI conference on artificial intelligence (AAAI) https:\/\/doi.org\/10.5555\/3504035.3504238","DOI":"10.5555\/3504035.3504238"},{"issue":"8","key":"546_CR152","doi-asserted-by":"publisher","first-page":"1979","DOI":"10.1109\/TPAMI.2018.2858821","volume":"41","author":"T Miyato","year":"2019","unstructured":"Miyato T, Maeda S-I, Koyama M, Ishii S (2019) Virtual adversarial training: a regularization method for supervised and semi-supervised learning. IEEE Trans Pattern Anal Mach Intell 41(8):1979\u20131993. https:\/\/doi.org\/10.1109\/TPAMI.2018.2858821","journal-title":"IEEE Trans Pattern Anal Mach Intell"},{"key":"546_CR153","doi-asserted-by":"publisher","unstructured":"Yu B, Wu J, Ma J, Zhu Z(2019) Tangent-normal adversarial regularization for semi-supervised learning. In: 32nd IEEE\/CVF conference on computer vision and pattern recognition (CVPR), pp 10668\u201310676 https:\/\/doi.org\/10.1109\/CVPR.2019.01093","DOI":"10.1109\/CVPR.2019.01093"},{"key":"546_CR154","doi-asserted-by":"publisher","unstructured":"Jakubovitz D, Giryes R (2018) Improving dnn robustness to adversarial attacks using jacobian regularization. In: 15th European conference on computer vision (ECCV), pp 525\u2013541 https:\/\/doi.org\/10.1007\/978-3-030-01258-8_32","DOI":"10.1007\/978-3-030-01258-8_32"},{"key":"546_CR155","doi-asserted-by":"publisher","unstructured":"Qin C, Martens J, Gowal S, Krishnan D, Dvijotham K, Fawzi A, De S, Stanforth R, Kohli P (2019) Adversarial robustness through local linearization. In: 33rd international conference on neural information processing systems (NeurIPS) https:\/\/doi.org\/10.5555\/3454287.3455527","DOI":"10.5555\/3454287.3455527"},{"key":"546_CR156","doi-asserted-by":"publisher","unstructured":"Moosavi-Dezfooli S-M, Fawzi A, Uesato J, Frossard P (2019) Robustness via curvature regularization, and vice versa. In: 32nd IEEE\/CVF conference on computer vision and pattern recognition (CVPR), pp 9070\u20139078 https:\/\/doi.org\/10.1109\/CVPR.2019.00929","DOI":"10.1109\/CVPR.2019.00929"},{"key":"546_CR157","doi-asserted-by":"publisher","unstructured":"Wang J, Fu X, Xu G, Wu Y, Chen Z, Wei Y, Jin L (2018) A3Net: adversarial-and-attention network for machine reading comprehension. In: 7th CCF international conference on natural language processing and chinese computing (NLPCC), pp 64\u201375 https:\/\/doi.org\/10.1007\/978-3-319-99495-6_6","DOI":"10.1007\/978-3-319-99495-6_6"},{"key":"546_CR158","doi-asserted-by":"publisher","unstructured":"Yan Z, Guo Y, Zhang C (2018) Deep defense: training dnns with improved adversarial robustness. In: 32nd international conference on neural information processing systems (NeurIPS), pp 417\u2013426 https:\/\/doi.org\/10.5555\/3326943.3326982","DOI":"10.5555\/3326943.3326982"},{"key":"546_CR159","doi-asserted-by":"publisher","unstructured":"Sankaranarayanan S, Jain A, Chellappa R, Lim SN (2018) Regularizing deep networks using efficient layerwise adversarial training. In: 32nd AAAI conference on artificial intelligence (AAAI) https:\/\/doi.org\/10.1609\/aaai.v32i1.11688","DOI":"10.1609\/aaai.v32i1.11688"},{"key":"546_CR160","unstructured":"Mao Y, Mueller MN, Fischer M, Vechev M (2024) Understanding certified training with interval bound propagation. In: 12th international conference on learning representations (ICLR)"},{"key":"546_CR161","doi-asserted-by":"publisher","unstructured":"Kung B-H, Chen S.-T (2024) Towards large certified radius in randomized smoothing using quasiconcave optimization. In: 38th AAAI conference on artificial intelligence (AAAI) https:\/\/doi.org\/10.1609\/aaai.v38i19.30123","DOI":"10.1609\/aaai.v38i19.30123"},{"key":"546_CR162","unstructured":"Ugare S, Suresh T, Banerjee D, Singh G, Misailovic S (2024) Incremental randomized smoothing certification. In: 12th international conference on learning representations (ICLR)"},{"key":"546_CR163","unstructured":"Lyu S, Shaikh S, Shpilevskiy F, Shelhamer E, L\u00e9cuyer M (2024) Adaptive randomized smoothing: certified adversarial robustness for multi-step defences. In: 38th annual conference on neural information processing systems"},{"key":"546_CR164","doi-asserted-by":"publisher","unstructured":"Tsai Y-L, Hsu C-Y, Yu C-M, Chen P-Y (2021) Non-singular adversarial robustness of neural networks. In: 46th IEEE international conference on acoustics, speech and signal processing (ICASSP), pp 3840\u20133844 https:\/\/doi.org\/10.1109\/ICASSP39728.2021.9414325","DOI":"10.1109\/ICASSP39728.2021.9414325"},{"key":"546_CR165","doi-asserted-by":"publisher","unstructured":"Co KT, Martinez-Rego D, Hau Z, Lupu EC (2022) Jacobian ensembles improve robustness trade-offs to adversarial attacks. In: 31st international conference on artificial neural networks (ICANN), pp 680\u2013691 https:\/\/doi.org\/10.1007\/978-3-031-15934-3_56","DOI":"10.1007\/978-3-031-15934-3_56"},{"issue":"6","key":"546_CR166","doi-asserted-by":"publisher","first-page":"3146","DOI":"10.1109\/TNNLS.2021.3111892","volume":"34","author":"C Liu","year":"2023","unstructured":"Liu C, Salzmann M, S\u00fcsstrunk S (2023) Training provably robust models by polyhedral envelope regularization. IEEE Trans Neural Netw Learn Syst 34(6):3146\u20133160. https:\/\/doi.org\/10.1109\/TNNLS.2021.3111892","journal-title":"IEEE Trans Neural Netw Learn Syst"},{"key":"546_CR167","doi-asserted-by":"publisher","unstructured":"Liu X, Cheng M, Zhang H, Hsieh C-J (2018) Towards robust neural networks via random self-ensemble. In: 15th European conference on computer vision (ECCV), pp 381\u2013397 https:\/\/doi.org\/10.1007\/978-3-030-01234-2_23","DOI":"10.1007\/978-3-030-01234-2_23"},{"key":"546_CR168","unstructured":"Buckman J, Roy A, Raffel C, Goodfellow IJ (2018) Thermometer Encoding: One hot way to resist adversarial examples. In: 6th international conference on learning representations (ICLR)"},{"key":"546_CR169","doi-asserted-by":"publisher","unstructured":"Liao F, Liang M, Dong Y, Pang T, Hu X, Zhu J (2018) Defense against adversarial attacks using high-level representation guided denoiser. In: 31st IEEE\/CVF conference on computer vision and pattern recognition (CVPR), pp 1778\u20131787 https:\/\/doi.org\/10.1109\/CVPR.2018.00191","DOI":"10.1109\/CVPR.2018.00191"},{"key":"546_CR170","unstructured":"Lamb A, Binas J, Goyal A, Serdyuk D, Subramanian S, Mitliagkas I, Bengio Y (2019) Fortified networks: improving the robustness of deep networks by modeling the manifold of hidden representations. In: 7th international conference on learning representations (ICLR)"},{"key":"546_CR171","unstructured":"Wu X, Jang U, Chen J, Chen L, Jha S (2018) Reinforcing adversarial robustness using model confidence induced by adversarial training. In: 35th international conference on machine learning (ICML), pp 5334\u20135342"},{"key":"546_CR172","doi-asserted-by":"publisher","unstructured":"Liu X, Hsieh C-J (2019) Rob-GAN: generator, discriminator, and adversarial attacker. In: 32nd IEEE\/CVF conference on computer vision and pattern recognition (CVPR), pp 11226\u201311235 https:\/\/doi.org\/10.1109\/CVPR.2019.01149","DOI":"10.1109\/CVPR.2019.01149"},{"issue":"12","key":"546_CR173","doi-asserted-by":"publisher","first-page":"8870","DOI":"10.1109\/TPAMI.2024.3411035","volume":"46","author":"X Wei","year":"2024","unstructured":"Wei X, Zhao S, Li B (2024) Revisiting the trade-off between accuracy and robustness via weight distribution of filters. IEEE Trans Pattern Anal Mach Intell 46(12):8870\u20138882. https:\/\/doi.org\/10.1109\/TPAMI.2024.3411035","journal-title":"IEEE Trans Pattern Anal Mach Intell"},{"key":"546_CR174","doi-asserted-by":"publisher","unstructured":"Yuan J, He Z (2020) Ensemble generative cleaning with feedback loops for defending adversarial attacks. In: 33rd IEEE\/CVF conference on computer vision and pattern recognition (CVPR), pp 578\u2013587 https:\/\/doi.org\/10.1109\/CVPR42600.2020.00066","DOI":"10.1109\/CVPR42600.2020.00066"},{"key":"546_CR175","doi-asserted-by":"publisher","unstructured":"Li G, Ding S, Luo J, Liu C (2020) Enhancing intrinsic adversarial robustness via feature pyramid decoder. In: 33rd IEEE\/CVF conference on computer vision and pattern recognition (CVPR), pp 797\u2013805 https:\/\/doi.org\/10.1109\/CVPR42600.2020.00088","DOI":"10.1109\/CVPR42600.2020.00088"},{"key":"546_CR176","unstructured":"Lai B-H, Huang P-H, Kung B-H, Chen S-T (2025) Enhancing certified robustness via block reflector orthogonal layers. In: 13th international conference on learning representations (ICLR)"},{"key":"546_CR177","unstructured":"Gupta K, Verma S (2023) Certvit: certified robustness of pre-trained vision transformers. In: 2nd workshop on new frontiers in adversarial machine learning"},{"key":"546_CR178","doi-asserted-by":"publisher","first-page":"100017","DOI":"10.1016\/j.mlwa.2020.100017","volume":"3","author":"C Finlay","year":"2021","unstructured":"Finlay C, Oberman AM (2021) Scaleable input gradient regularization for adversarial robustness. Mach Learn Appl 3:100017. https:\/\/doi.org\/10.1016\/j.mlwa.2020.100017","journal-title":"Mach Learn Appl"},{"key":"546_CR179","doi-asserted-by":"publisher","unstructured":"Jakubovitz D, Giryes R (2018) Improving DNN robustness to adversarial attacks using jacobian regularization. In: 15th European conference on computer vision (ECCV), pp 525\u2013541 https:\/\/doi.org\/10.1007\/978-3-030-01258-8_32","DOI":"10.1007\/978-3-030-01258-8_32"},{"key":"546_CR180","doi-asserted-by":"crossref","unstructured":"Liu Y, Yang C, Li D, Ding J, Jiang T (2024) Defense against adversarial attacks on no-reference image quality models with gradient norm regularization. In: 37th IEEE\/CVF conference on computer vision and pattern recognition (CVPR)","DOI":"10.1109\/CVPR52733.2024.02414"},{"key":"546_CR181","doi-asserted-by":"publisher","unstructured":"Liu Q, Liu T, Liu Z, Wang Y, Jin Y, Wen W (2018) Security analysis and enhancement of model compressed deep learning systems under adversarial attacks. In: 23rd Asia and South Pacific design automation conference (ASP-DAC), pp 721\u2013726 https:\/\/doi.org\/10.1109\/ASPDAC.2018.8297407","DOI":"10.1109\/ASPDAC.2018.8297407"},{"key":"546_CR182","doi-asserted-by":"publisher","unstructured":"Wu Y-H, Yuan C-H, Wu S-H(2020) Adversarial robustness via runtime masking and cleansing. In: 37th international conference on machine learning (ICML) https:\/\/doi.org\/10.5555\/3524938.3525901","DOI":"10.5555\/3524938.3525901"},{"key":"546_CR183","doi-asserted-by":"publisher","unstructured":"Qiu H, Zeng Y, Zheng Q, Zhang T, Qiu M, Memmi G (2020) Mitigating advanced adversarial attacks with more advanced gradient obfuscation techniques. Preprint at https:\/\/doi.org\/10.48550\/arXiv.2005.13712","DOI":"10.48550\/arXiv.2005.13712"},{"key":"546_CR184","unstructured":"Athalye A, Carlini N, Wagner D (2018) Obfuscated gradients give a false sense of security: circumventing defenses to adversarial examples. In: 35th international conference on machine learning (ICML), pp 274\u2013283"},{"key":"546_CR185","doi-asserted-by":"crossref","unstructured":"Rozsa A, Rudd EM, Boult TE (2016) Adversarial diversity and hard positive generation. In: 29th IEEE\/CVF conference on computer vision and pattern recognition (CVPR) workshops, pp 25\u201332","DOI":"10.1109\/CVPRW.2016.58"},{"key":"546_CR186","unstructured":"Athalye A, Engstrom L, Ilyas A, Kwok K (2018) Synthesizing robust adversarial examples. In: 35th international conference on machine learning (ICML), pp 274\u2013283"},{"key":"546_CR187","doi-asserted-by":"publisher","unstructured":"Carlini N, Wagner D (2017) Adversarial examples are not easily detected: bypassing ten detection methods. In: 10th ACM workshop on artificial intelligence and security (AISec), pp 3\u201314 https:\/\/doi.org\/10.1145\/3128572.3140444","DOI":"10.1145\/3128572.3140444"},{"key":"546_CR188","unstructured":"Zhang H, Yu Y, Jiao J, Xing EP, El\u00a0Ghaoui L, Jordan MI (2019) Theoretically principled trade-off between robustness and accuracy. In: 36th international conference on machine learning (ICML), pp 7472\u20137482"},{"key":"546_CR189","doi-asserted-by":"publisher","unstructured":"Qin Y, Hunt R, Yue C (2019) On improving the effectiveness of adversarial training. In: 9th ACM international workshop on security and privacy analytics (IWSPA), pp 5\u201313 https:\/\/doi.org\/10.1145\/3309182.3309190","DOI":"10.1145\/3309182.3309190"},{"key":"546_CR190","doi-asserted-by":"publisher","unstructured":"Lee K, Lee H, Lee K, Shin J(2018) A simple unified framework for detecting out-of-distribution samples and adversarial attacks. In: 32nd international conference on neural information processing systems (NeurIPS), pp 7167\u20137177 https:\/\/doi.org\/10.5555\/3327757.3327819","DOI":"10.5555\/3327757.3327819"}],"container-title":["Cybersecurity"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-025-00546-3.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1186\/s42400-025-00546-3","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-025-00546-3.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,1,20]],"date-time":"2026-01-20T09:57:22Z","timestamp":1768903042000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1186\/s42400-025-00546-3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,1,20]]},"references-count":190,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2026,12]]}},"alternative-id":["546"],"URL":"https:\/\/doi.org\/10.1186\/s42400-025-00546-3","relation":{},"ISSN":["2523-3246"],"issn-type":[{"value":"2523-3246","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,1,20]]},"assertion":[{"value":"28 May 2025","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"23 December 2025","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"20 January 2026","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"Not applicable.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethics approval and consent to participate"}},{"value":"All authors consented to the publication of this manuscript.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Consent for publication"}},{"value":"The authors declare no Conflict of interest.","order":4,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"108"}}