{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,25]],"date-time":"2026-07-25T04:39:21Z","timestamp":1784954361983,"version":"3.55.0"},"reference-count":126,"publisher":"Walter de Gruyter GmbH","issue":"1","license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025,3,29]]},"abstract":"<jats:title>Abstract<\/jats:title>\n                  <jats:p>The enhanced use of artificial intelligence (AI) in organizations has changed and revolutionized the approaches to solving problems, processing information, and decision making. While the algorithms turned out to be highly effective, AI systems faced adversarial attacks, which can be described as slight alterations of inputs that would fool an AI algorithm. These attacks remain major challenges to the dependability and protection of AI systems and thus the need to develop stable and flexible protection strategies and procedures. The aim of this article is to discuss the existing trends in adversarial attack techniques and protection mechanisms. To this end, papers, exact match, and systematically applied operative inclusion\/exclusion criteria pertinent to protection strategies against adversarial attacks in multiple databases were incorporated and used. Specifically, 1988 papers were retrieved from Web of Science, IEEE Explore, and Science Direct, which were published between January 1, 2021, and July 1, 2024, where we used 51 of the identified journal articles for the quantitative synthesis in the final stage. Thus, the protection taxonomy, which resulted from our analysis, discusses the motivation, and best practices in relation to the threats in question. The taxonomy also describes challenges and suggests other ideas on how to improve the robustness of adversarial attack systems. Not only this study is a response to gaps in the literature but it also presents the reader with a map for further studies. It is necessary to draw attention to the fact that an objective criterion must be introduced to measure the degree of defense, collaboration with researchers of other fields, and the necessity to consider the ethical implications of the created defense mechanisms. Our results shall assist industry practitioners, researchers, and policymakers in designing an optimal AI security that can protect AI systems against dynamic adversary strategies. This review provides a reference of entry to the topic of AI security and the challenges that may be encountered together with the measures that can be taken to forward the studies.<\/jats:p>","DOI":"10.1515\/jisys-2024-0277","type":"journal-article","created":{"date-parts":[[2025,6,4]],"date-time":"2025-06-04T09:00:58Z","timestamp":1749027658000},"source":"Crossref","is-referenced-by-count":14,"title":["Strategies for protection against adversarial attacks in AI models: An in-depth review"],"prefix":"10.1515","volume":"34","author":[{"given":"Ghadeer Ghazi","family":"Shayea","sequence":"first","affiliation":[{"name":"College of Information Technology, Universiti Tenaga Nasional (UNITEN) , 43000 , Kajang , Selangor , Malaysia"},{"name":"Technical College, Imam Ja\u2019afar Al-Sadiq University , Baghdad , 10001 , Iraq"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mohd Hazli Mohammed","family":"Zabil","sequence":"additional","affiliation":[{"name":"College of Information Technology, Universiti Tenaga Nasional (UNITEN) , 43000 , Kajang , Selangor , Malaysia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mustafa Abdulfattah","family":"Habeeb","sequence":"additional","affiliation":[{"name":"Department of Computer Science, College of Computer Science and Mathematics, Tikrit University , Salah Al Deen , 34001 , Iraq"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yahya Layth","family":"Khaleel","sequence":"additional","affiliation":[{"name":"Department of Computer Science, College of Computer Science and Mathematics, Tikrit University , Salah Al Deen , 34001 , Iraq"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"A. S.","family":"Albahri","sequence":"additional","affiliation":[{"name":"Technical College, Imam Ja\u2019afar Al-Sadiq University , Baghdad , 10001 , Iraq"},{"name":"Electronic Computer Center, University of Information Technology and Communications (UoITC) , Baghdad 10013 , Iraq"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"374","published-online":{"date-parts":[[2025,3,29]]},"reference":[{"key":"2025122009032208204_j_jisys-2024-0277_ref_001","unstructured":"Khaleel YL. Fake news detection using deep learning. Master Thesis. University of Miskolc, Hungary; 2021. p. 249\u201359. 10.1007\/978-3-030-91305-2_19."},{"key":"2025122009032208204_j_jisys-2024-0277_ref_002","doi-asserted-by":"crossref","unstructured":"Mihna FKH, Habeeb MA, Khaleel YL, Ali YH, Al-Saeedi LAE. Using information technology for comprehensive analysis and prediction in forensic evidence. Mesop J Cybersecur. 2024;4(1):4\u201316. 10.58496\/MJCS\/2024\/002.","DOI":"10.58496\/MJCS\/2024\/002"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_003","doi-asserted-by":"crossref","unstructured":"Katarya R, Massoudi M. Recognizing fake news in social media with deep learning: a systematic review. 4th International Conference on Computer, Communication and Signal Processing, ICCCSP 2020. IEEE; 2020. p. 1\u20134. 10.1109\/ICCCSP49186.2020.9315255.","DOI":"10.1109\/ICCCSP49186.2020.9315255"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_004","doi-asserted-by":"crossref","unstructured":"Ongsulee P. Artificial intelligence, machine learning and deep learning. 2017 15th international conference on ICT and knowledge engineering (ICT&KE). IEEE; 2017. p. 1\u20136.","DOI":"10.1109\/ICTKE.2017.8259629"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_005","doi-asserted-by":"crossref","unstructured":"Campesato O. Artificial intelligence, machine learning, and deep learning. Mercury Learning and Information; 2020.","DOI":"10.1515\/9781683924654"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_006","unstructured":"Habeeb MA. Hate speech detection using deep learning master thesis. Master Thesis. University of Miskolc, Hungary; 2021. http:\/\/midra.uni-miskolc.hu\/document\/40792\/38399.pdf."},{"key":"2025122009032208204_j_jisys-2024-0277_ref_007","unstructured":"Zhang L, Ghosh R, Dekhil M, Hsu M, Liu B. Combining lexicon-based and learning-based methods for twitter sentiment analysis. HP Lab Tech Rep. 2011;89(89):1\u20138. https:\/\/api.semanticscholar.org\/CorpusID:16228540."},{"key":"2025122009032208204_j_jisys-2024-0277_ref_008","doi-asserted-by":"crossref","unstructured":"Husnoo MA, Anwar A. Do not get fooled: Defense against the one-pixel attack to protect IoT-enabled Deep Learning systems. Ad Hoc Netw. 2021;122:102627. 10.1016\/j.adhoc.2021.102627.","DOI":"10.1016\/j.adhoc.2021.102627"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_009","doi-asserted-by":"crossref","unstructured":"Habeeb MA, Khaleel YL, Albahri AS. Toward smart bicycle safety: leveraging machine learning models and optimal lighting solutions. In: Daimi K, Al Sadoon A, editors. Proceedings of the Third International Conference on Innovations in Computing Research (ICR\u201924). Cham: Springer Nature Switzerland; 2024. p. 120\u201331.","DOI":"10.1007\/978-3-031-65522-7_11"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_010","doi-asserted-by":"crossref","unstructured":"Khaleel YL, Habeeb MA, Albahri AS, Al-Quraishi T, Albahri OS, Alamoodi AH. Network and cybersecurity applications of defense in adversarial attacks: A state-of-the-art using machine learning and deep learning methods. J Intell Syst. 2024;33(1):20240153. 10.1515\/jisys-2024-0153.","DOI":"10.1515\/jisys-2024-0153"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_011","doi-asserted-by":"crossref","unstructured":"Hasan Z, Mohammad HR, Jishkariani M. Machine learning and data mining methods for cyber security: a survey. Mesop J Cybersecur. 2022;2022:47\u201356. 10.58496\/MJCS\/2022\/006.","DOI":"10.58496\/MJCS\/2022\/006"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_012","doi-asserted-by":"crossref","unstructured":"Paya A, Arroni S, Garc\u00eda-D\u00edaz V, G\u00f3mez A. Apollon: A robust defense system against adversarial machine learning attacks in intrusion detection systems. Comput Secur. 2024;136:103546. 10.1016\/j.cose.2023.103546.","DOI":"10.1016\/j.cose.2023.103546"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_013","doi-asserted-by":"crossref","unstructured":"Ali G, Mijwil MM, Buruga BA, Abotaleb M, Adamopoulos I. A survey on artificial intelligence in cybersecurity for smart agriculture: state-of-the-art, cyber threats, artificial intelligence applications, and ethical concerns. Mesop J Comput Sci. 2024;2024:71\u2013121. 10.58496\/MJCSC\/2024\/007.","DOI":"10.58496\/MJCSC\/2024\/007"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_014","doi-asserted-by":"crossref","unstructured":"Mustaffa SNFNB, Farhan M. Detection of false data injection attack using machine learning approach. Mesop J Cybersecur. 2022;2022:38\u201346. 10.58496\/MJCS\/2022\/005.","DOI":"10.58496\/MJCS\/2022\/005"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_015","doi-asserted-by":"crossref","unstructured":"Akhtar N, Mian A, Kardan N, Shah M. Advances in adversarial attacks and defenses in computer vision: a survey. IEEE Access. 2021;9:155161\u201396. 10.1109\/ACCESS.2021.3127960.","DOI":"10.1109\/ACCESS.2021.3127960"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_016","doi-asserted-by":"crossref","unstructured":"Zhang WE, Sheng QZ, Alhazmi A, Li C. Adversarial attacks on deep-learning models in natural language processing. ACM Trans Intell Syst Technol. 2020;11(3):1\u201341. 10.1145\/3374217.","DOI":"10.1145\/3374217"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_017","doi-asserted-by":"crossref","unstructured":"Cai K, Zhu X, Hu Z. Reward poisoning attacks in deep reinforcement learning based on exploration strategies. Neurocomputing. 2023;553:126578. 10.1016\/j.neucom.2023.126578.","DOI":"10.1016\/j.neucom.2023.126578"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_018","doi-asserted-by":"crossref","unstructured":"Echeberria-Barrio X, Gil-Lerchundi A, Mendialdua I, Orduna-Urrutia R. Topological safeguard for evasion attack interpreting the neural networks\u2019 behavior. Pattern Recognit. 2024;147:110130. 10.1016\/j.patcog.2023.110130.","DOI":"10.1016\/j.patcog.2023.110130"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_019","doi-asserted-by":"crossref","unstructured":"Jodayree M, He W, Janicki R. Preventing image data poisoning attacks in federated machine learning by an encrypted verification key. Procedia Comput Sci. 2023;225:2723\u201332. 10.1016\/j.procs.2023.10.264.","DOI":"10.1016\/j.procs.2023.10.264"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_020","doi-asserted-by":"crossref","unstructured":"Macas M, Wu C, Fuertes W. Adversarial examples: A survey of attacks and defenses in deep learning-enabled cybersecurity systems. Expert Syst Appl. Mar. 2024;238:122223. 10.1016\/j.eswa.2023.122223.","DOI":"10.1016\/j.eswa.2023.122223"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_021","unstructured":"Devabhakthini P, Parida S, Shukla RM, Nayak SC. Analyzing the impact of adversarial examples on explainable machine learning. arXiv Prepr arXiv230708327. 2023."},{"key":"2025122009032208204_j_jisys-2024-0277_ref_022","doi-asserted-by":"crossref","unstructured":"Fang J, Jiang Y, Jiang C, Jiang ZL, Liu C, Yiu SM. State-of-the-art optical-based physical adversarial attacks for deep learning computer vision systems. Expert Syst Appl. 2024;250:123761. 10.1016\/j.eswa.2024.123761.","DOI":"10.1016\/j.eswa.2024.123761"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_023","doi-asserted-by":"crossref","unstructured":"Kong Z, Xue J, Wang Y, Huang L, Niu Z, Li F. A survey on adversarial attack in the age of artificial intelligence. Wirel Commun Mob Comput. 2021;2021(1):4907754. 10.1155\/2021\/4907754.","DOI":"10.1155\/2021\/4907754"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_024","doi-asserted-by":"crossref","unstructured":"Chen T, Ling J, Sun Y. White-box content camouflage attacks against deep learning. Comput Secur. 2022;117:102676. 10.1016\/j.cose.2022.102676.","DOI":"10.1016\/j.cose.2022.102676"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_025","unstructured":"Eyas A, Engstrom L, Athalye A, Lin J. Black-box adversarial attacks with limited queries and information. In: Dy J, Krause A, editors. 35th International Conference on Machine Learning, ICML 2018. International Machine Learning Society (IMLS); 2018. p. 3392\u2013401. https:\/\/proceedings.mlr.press\/v80\/ilyas18a.html."},{"key":"2025122009032208204_j_jisys-2024-0277_ref_026","doi-asserted-by":"crossref","unstructured":"Apruzzese G, Subrahmanian VS. Mitigating adversarial gray-box attacks against phishing detectors. IEEE Trans Dependable Secur Comput. 2023;20(5):3753\u201369. 10.1109\/TDSC.2022.3210029.","DOI":"10.1109\/TDSC.2022.3210029"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_027","doi-asserted-by":"crossref","unstructured":"Wang Y, Wu Y, Wu S, Liu X, Zhou W, Zhu L, et al. Boosting the transferability of adversarial attacks with frequency-aware perturbation. IEEE Trans Inf Forensics Secur. 2024;19:6293\u2013304. 10.1109\/TIFS.2024.3411921.","DOI":"10.1109\/TIFS.2024.3411921"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_028","doi-asserted-by":"crossref","unstructured":"Zhang Y, Ruan W, Wang F, Huang X. Generalizing universal adversarial perturbations for deep neural networks. Mach Learn. 2023;112(5):1597\u2013626. 10.1007\/s10994-023-06306-z.","DOI":"10.1007\/s10994-023-06306-z"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_029","doi-asserted-by":"crossref","unstructured":"Bostani H, Moonsamy V. EvadeDroid: A practical evasion attack on machine learning for black-box Android malware detection. Comput Secur. 2024;139:103676. 10.1016\/j.cose.2023.103676.","DOI":"10.1016\/j.cose.2023.103676"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_030","doi-asserted-by":"crossref","unstructured":"Randhawa RH, Aslam N, Alauthman M, Khalid M, Rafiq H. Deep reinforcement learning based Evasion Generative Adversarial Network for botnet detection. Futur Gener Comput Syst. 2024;150:294\u2013302. 10.1016\/j.future.2023.09.011.","DOI":"10.1016\/j.future.2023.09.011"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_031","doi-asserted-by":"crossref","unstructured":"Shi L, Chen Z, Shi Y, Zhao G, Wei L, Tao Y, et al. Data poisoning attacks on federated learning by using adversarial samples. Proceedings - 2022 International Conference on Computer Engineering and Artificial Intelligence, ICCEAI 2022. 2022. p. 158\u201362. 10.1109\/ICCEAI55464.2022.00041.","DOI":"10.1109\/ICCEAI55464.2022.00041"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_032","doi-asserted-by":"crossref","unstructured":"Tolpegin V, Truex S, Gursoy ME, Liu L. Data poisoning attacks against federated learning systems. In: Chen L, Li N, Liang K, Schneider S, editors. Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics). Cham: Springer International Publishing; 2020. p. 480\u2013501. 10.1007\/978-3-030-58951-6_24.","DOI":"10.1007\/978-3-030-58951-6_24"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_033","doi-asserted-by":"crossref","unstructured":"Chakraborty A, Alam M, Dey V, Chattopadhyay A, Mukhopadhyay D. A survey on adversarial attacks and defences. CAAI Trans Intell Technol. 2021;6(1):25\u201345. 10.1049\/cit2.12028.","DOI":"10.1049\/cit2.12028"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_034","doi-asserted-by":"crossref","unstructured":"Wang T, Zhu L, Zhang Z, Zhang H, Han J. Targeted adversarial attack against deep cross-modal hashing retrieval. IEEE Trans Circuits Syst Video Technol. 2023;33(10):6159\u201372. 10.1109\/TCSVT.2023.3263054.","DOI":"10.1109\/TCSVT.2023.3263054"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_035","doi-asserted-by":"crossref","unstructured":"Sagduyu YE, Erpek T, Ulukus S, Yener A. Is semantic communication secure? a tale of multi-domain adversarial attacks. IEEE Commun Mag. 2023;61(11):50\u20135. 10.1109\/MCOM.006.2200878.","DOI":"10.1109\/MCOM.006.2200878"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_036","doi-asserted-by":"crossref","unstructured":"Aldahdooh A, Hamidouche W, D\u00e9forges O. Revisiting model\u2019s uncertainty and confidences for adversarial example detection. Appl Intell. 2023;53(1):509\u201331. 10.1007\/s10489-022-03373-y.","DOI":"10.1007\/s10489-022-03373-y"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_037","doi-asserted-by":"crossref","unstructured":"Yan A, Huang T, Ke L, Liu X, Chen Q, Dong C. Explanation leaks: Explanation-guided model extraction attacks. Inf Sci. 2023;632:269\u201384. 10.1016\/j.ins.2023.03.020.","DOI":"10.1016\/j.ins.2023.03.020"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_038","doi-asserted-by":"crossref","unstructured":"Park C, Kim Y, Park JG, Hong D, Seo C. Evaluating differentially private generative adversarial networks over membership inference attack. IEEE Access. 2021;9:167412\u201325. 10.1109\/ACCESS.2021.3137278.","DOI":"10.1109\/ACCESS.2021.3137278"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_039","doi-asserted-by":"crossref","unstructured":"Anthi E, Williams L, Javed A, Burnap P. Hardening machine learning denial of service (DoS) defences against adversarial attacks in IoT smart home networks. Comput Secur. 2021;108:102352. 10.1016\/j.cose.2021.102352.","DOI":"10.1016\/j.cose.2021.102352"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_040","doi-asserted-by":"crossref","unstructured":"Seo S, Lee Y, Kang P. Cost-free adversarial defense: Distance-based optimization for model robustness without adversarial training. Comput Vis Image Underst. 2023;227:103599. 10.1016\/j.cviu.2022.103599.","DOI":"10.1016\/j.cviu.2022.103599"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_041","unstructured":"Guo C, Rana M, Ciss\u00e9 M, Van Der Maaten L. Countering adversarial images using input transformations. 6th International Conference on Learning Representations, ICLR 2018 - Conference Track Proceedings, International Conference on Learning Representations, ICLR. 2018. https:\/\/openreview.net\/forum?id=SyJ7ClWCb."},{"key":"2025122009032208204_j_jisys-2024-0277_ref_042","doi-asserted-by":"crossref","unstructured":"McDaniel, Wu X, Jha S, Swami A. Distillation as a defense to adversarial perturbations against deep neural networks. In Proceedings - 2016 IEEE Symposium on Security and Privacy, SP 2016. 2016. p. 582\u201397. 10.1109\/SP.2016.41.","DOI":"10.1109\/SP.2016.41"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_043","doi-asserted-by":"crossref","unstructured":"Hang J, Han K, Chen H, Li Y. Ensemble adversarial black-box attacks against deep learning systems. Pattern Recognit. 2020;101:107184. 10.1016\/j.patcog.2019.107184.","DOI":"10.1016\/j.patcog.2019.107184"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_044","doi-asserted-by":"crossref","unstructured":"Li D, Li Q. Adversarial deep ensemble: evasion attacks and defenses for malware detection. IEEE Trans Inf Forensics Secur. 2020;15:3886\u2013900. 10.1109\/TIFS.2020.3003571.","DOI":"10.1109\/TIFS.2020.3003571"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_045","doi-asserted-by":"crossref","unstructured":"Zheng Y, Velipasalar S. Part-based feature squeezing to detect adversarial examples in person re-identification networks. In Proceedings - International Conference on Image Processing. ICIP; 2021. p. 844\u20138. 10.1109\/ICIP42928.2021.9506511.","DOI":"10.1109\/ICIP42928.2021.9506511"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_046","doi-asserted-by":"crossref","unstructured":"Shaham U, Yamada Y, Negahban S. Understanding adversarial training: Increasing local stability of supervised models through robust optimization. Neurocomputing. 2018;307:195\u2013204. 10.1016\/j.neucom.2018.04.027.","DOI":"10.1016\/j.neucom.2018.04.027"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_047","doi-asserted-by":"crossref","unstructured":"Schwartz D, Alparslan Y, Kim E. Regularization and Sparsity for Adversarial Robustness and Stable Attribution. In: Bebis G, Yin Z, Kim E, Bender J, Subr K, Kwon BC, et al., editors. Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics). Cham: Springer International Publishing; 2020. p. 3\u201314. 10.1007\/978-3-030-64556-4_1.","DOI":"10.1007\/978-3-030-64556-4_1"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_048","doi-asserted-by":"crossref","unstructured":"Panda P, Roy K. Implicit adversarial data augmentation and robustness with Noise-based Learning. Neural Netw. 2021;141:120\u201332. 10.1016\/j.neunet.2021.04.008.","DOI":"10.1016\/j.neunet.2021.04.008"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_049","doi-asserted-by":"crossref","unstructured":"Anand D, Tank D, Tibrewal H, Sethi A. Self-supervision vs. transfer learning: robust biomedical image analysis against adversarial attacks. In Proceedings - International Symposium on Biomedical Imaging. 2020. p. 1159\u201363. 10.1109\/ISBI45749.2020.9098369.","DOI":"10.1109\/ISBI45749.2020.9098369"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_050","doi-asserted-by":"crossref","unstructured":"Siva Kumar RS, Nystrom M, Lambert J, Marshall A, Goertzel M, Comissoneru A, et al. Adversarial machine learning-industry perspectives. In Proceedings - 2020 IEEE Symposium on Security and Privacy Workshops, SPW 2020. 2020. p. 69\u201375. 10.1109\/SPW50608.2020.00028.","DOI":"10.1109\/SPW50608.2020.00028"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_051","doi-asserted-by":"crossref","unstructured":"Li W, Tug S, Meng W, Wang Y. Designing collaborative blockchained signature-based intrusion detection in IoT environments. Futur Gener Comput Syst. 2019;96:481\u20139. 10.1016\/j.future.2019.02.064.","DOI":"10.1016\/j.future.2019.02.064"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_052","doi-asserted-by":"crossref","unstructured":"Roshan K, Zafar A, Ul Haque SB. Untargeted white-box adversarial attack with heuristic defence methods in real-time deep learning based network intrusion detection system. Comput Commun. 2024;218:97\u2013113. 10.1016\/j.comcom.2023.09.030.","DOI":"10.1016\/j.comcom.2023.09.030"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_053","doi-asserted-by":"crossref","unstructured":"Siu K, Moitra A, Li M, Durling M, Herencia-Zapana H, Interrante J, et al. Architectural and behavioral analysis for cyber security. In AIAA\/IEEE Digital Avionics Systems Conference \u2013 Proceedings. 2019. p. 1\u201310. 10.1109\/DASC43569.2019.9081652.","DOI":"10.1109\/DASC43569.2019.9081652"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_054","doi-asserted-by":"crossref","unstructured":"Kuppa A, Grzonkowski S, Asghar MR, Le-Khac NA. Black box attacks on deep anomaly detectors. In ACM International Conference Proceeding Series, in ARES \u201919. New York, NY, USA: Association for Computing Machinery; 2019. 10.1145\/3339252.3339266.","DOI":"10.1145\/3339252.3339266"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_055","doi-asserted-by":"crossref","unstructured":"Apruzzese G, Colajanni M, Ferretti L, Marchetti M. Addressing adversarial attacks against security systems based on machine learning. In International Conference on Cyber Conflict. CYCON; 2019. p. 1\u201318. 10.23919\/CYCON.2019.8756865.","DOI":"10.23919\/CYCON.2019.8756865"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_056","unstructured":"DIng X, Fang H, Zhang Z, Choo KKR, Jin H. Privacy-preserving feature extraction via adversarial training. IEEE Trans Knowl Data Eng. 2022;34(4):1967\u201379. 10.1109\/TKDE.2020.2997604."},{"key":"2025122009032208204_j_jisys-2024-0277_ref_057","doi-asserted-by":"crossref","unstructured":"Ali Z, Mohammed A, Ahmad I. Vulnerability of deep forest to adversarial attacks. IEEE Trans Inf Forensics Secur. 2024;19:5464\u201375. 10.1109\/TIFS.2024.3402309.","DOI":"10.1109\/TIFS.2024.3402309"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_058","doi-asserted-by":"crossref","unstructured":"Owezarski P. Investigating adversarial attacks against Random Forest-based network attack detection systems. In Proceedings of IEEE\/IFIP Network Operations and Management Symposium 2023, NOMS 2023. 2023. p. 1\u20136. 10.1109\/NOMS56928.2023.10154328.","DOI":"10.1109\/NOMS56928.2023.10154328"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_059","doi-asserted-by":"crossref","unstructured":"Mustapha A, Khatoun R, Zeadally S, Chbib F, Fadlallah A, Fahs W, et al. Detecting DDoS attacks using adversarial neural network. Comput Secur. 2023;127:103117. 10.1016\/j.cose.2023.103117.","DOI":"10.1016\/j.cose.2023.103117"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_060","doi-asserted-by":"crossref","unstructured":"Sohrabi C, Franchi T, Mathew G, Kerwan A, Nicola M, Griffin M, et al. PRISMA 2020 statement: What\u2019s new and the importance of reporting guidelines. Int J Surg. 2021;88:105918. Elsevier. 10.1016\/j.ijsu.2021.105918.","DOI":"10.1016\/j.ijsu.2021.105918"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_061","doi-asserted-by":"crossref","unstructured":"Khaw KW, Alnoor A, Al-Abrrow H, Tiberius V, Ganesan Y, Atshan NA. Reactions towards organizational change: a systematic literature review. Curr Psychol. 2023;42:19137\u201360. 10.1007\/s12144-022-03070-6.","DOI":"10.1007\/s12144-022-03070-6"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_062","doi-asserted-by":"crossref","unstructured":"Albahri AS, Duhaim AM, Fadhel MA, Alnoor A, Baqer NS, Alzubaidi L, et al. A systematic review of trustworthy and explainable artificial intelligence in healthcare: Assessment of quality, bias risk, and data fusion. Inf Fusion. 2023;96:156\u201391. 10.1016\/j.inffus.2023.03.008.","DOI":"10.1016\/j.inffus.2023.03.008"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_063","doi-asserted-by":"crossref","unstructured":"Albahri AS, Khaleel YL, Habeeb MA, Ismael RD, Hameed QA, Deveci M, et al. A systematic review of trustworthy artificial intelligence applications in natural disasters. Comput Electr Eng. 2024;118:109409. 10.1016\/j.compeleceng.2024.109409.","DOI":"10.1016\/j.compeleceng.2024.109409"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_064","doi-asserted-by":"crossref","unstructured":"Albahri AS, Alwan JK, Taha ZK, Ismail SF, Hamid RA, Zaidan AA, et al. IoT-based telemedicine for disease prevention and health promotion: State-of-the-Art. J Netw Comput Appl. 2021;173:102873. 10.1016\/j.jnca.2020.102873.","DOI":"10.1016\/j.jnca.2020.102873"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_065","doi-asserted-by":"crossref","unstructured":"Rusydiana AS. Bibliometric analysis of journals, authors, and topics related to COVID-19 and Islamic finance listed in the Dimensions database by Biblioshiny. Sci Ed. 2021;8(1):72\u20138. 10.6087\/kcse.232.","DOI":"10.6087\/kcse.232"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_066","unstructured":"Jadeja M, Shah K. Tree-map: A visualization tool for large data. In CEUR Workshop Proceedings. 2015. p. 9\u201313.  http:\/\/ceur-ws.org\/Vol-1393\/paper-07.pdf."},{"key":"2025122009032208204_j_jisys-2024-0277_ref_067","doi-asserted-by":"crossref","unstructured":"Zaidan AA, Alnoor A, Albahri OS, Mohammed RT, Alamoodi AH, Albahri AS, et al. Review of artificial neural networks-contribution methods integrated with structural equation modeling and multi-criteria decision analysis for selection customization. Eng Appl Artif Intell. 2023;124:106643. 10.1016\/j.engappai.2023.106643.","DOI":"10.1016\/j.engappai.2023.106643"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_068","doi-asserted-by":"crossref","unstructured":"Shi J, Li L, Zeng D. ASCL: Adversarial supervised contrastive learning for defense against word substitution attacks. Neurocomputing. 2022;510:59\u201368. 10.1016\/j.neucom.2022.09.032.","DOI":"10.1016\/j.neucom.2022.09.032"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_069","doi-asserted-by":"crossref","unstructured":"Shao K, Yang J, Ai Y, Liu H, Zhang Y. BDDR: An effective defense against textual backdoor attacks. Comput Secur. 2021;110:102433. 10.1016\/j.cose.2021.102433.","DOI":"10.1016\/j.cose.2021.102433"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_070","doi-asserted-by":"crossref","unstructured":"Li P, Huang J, Wu H, Zhang Z, Qi C. SecureNet: Proactive intellectual property protection and model security defense for DNNs based on backdoor learning. Neural Netw. 2024;174:106199. 10.1016\/j.neunet.2024.106199.","DOI":"10.1016\/j.neunet.2024.106199"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_071","doi-asserted-by":"crossref","unstructured":"Al-Andoli MN, Tan SC, Sim KS, Goh Y, Lim CP. A framework for robust deep learning models against adversarial attacks based on a protection layer approach. IEEE Access. 2024;12:17522\u201340. 10.1109\/ACCESS.2024.3354699.","DOI":"10.1109\/ACCESS.2024.3354699"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_072","doi-asserted-by":"crossref","unstructured":"Yin L, Wang S, Wang Z, Wang C, Zhan D. Attribution guided purification against adversarial patch. Displays. 2024;83:102720. 10.1016\/j.displa.2024.102720.","DOI":"10.1016\/j.displa.2024.102720"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_073","doi-asserted-by":"crossref","unstructured":"Abdel-Basset M, Hawash H, Moustafa N, Razzak I, Abd Elfattah M. Privacy-preserved learning from non-i.i.d data in fog-assisted IoT: A federated learning approach. Digit Commun Netw. 2024;10(2):404\u201315. 10.1016\/j.dcan.2022.12.013.","DOI":"10.1016\/j.dcan.2022.12.013"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_074","doi-asserted-by":"crossref","unstructured":"Zhang Y, Fang Y, Cao Y, Wu J. RBGAN: Realistic-generation and balanced-utility GAN for face de-identification. Image Vis Comput. 2024;141:104868. 10.1016\/j.imavis.2023.104868.","DOI":"10.1016\/j.imavis.2023.104868"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_075","doi-asserted-by":"crossref","unstructured":"Luo Y, Zhu T, Liu Z, Mao T, Chen Z, Pi H, et al. GANFAT: Robust federated adversarial learning with label distribution skew. Futur Gener Comput Syst. 2024;160:711\u201323. 10.1016\/j.future.2024.06.030.","DOI":"10.1016\/j.future.2024.06.030"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_076","doi-asserted-by":"crossref","unstructured":"Perez Tobia J, Braun P, Narayan A. AGS: attribution guided sharpening as a defense against adversarial attacks. In Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), The University of British Columbia. Kelowna, Canada: Springer Science and Business Media Deutschland GmbH; 2022. p. 225\u201336. 10.1007\/978-3-031-01333-1_18.","DOI":"10.1007\/978-3-031-01333-1_18"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_077","doi-asserted-by":"crossref","unstructured":"Hwang D, Lee E, Rhee W. AID-purifier: A light auxiliary network for boosting adversarial defense. Neurocomputing. 2023;541:126251. 10.1016\/j.neucom.2023.126251.","DOI":"10.1016\/j.neucom.2023.126251"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_078","doi-asserted-by":"crossref","unstructured":"Dai T, Feng Y, Chen B, Lu J, Xia ST. Deep image prior based defense against adversarial examples. Pattern Recognit. 2022;122:108249. 10.1016\/j.patcog.2021.108249.","DOI":"10.1016\/j.patcog.2021.108249"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_079","doi-asserted-by":"crossref","unstructured":"Rodr\u00edguez-Barroso N, Mart\u00ednez-C\u00e1mara E, Luz\u00f3n MV, Herrera F. Dynamic defense against byzantine poisoning attacks in federated learning. Futur Gener Comput Syst. 2022;133:1\u20139. 10.1016\/j.future.2022.03.003.","DOI":"10.1016\/j.future.2022.03.003"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_080","doi-asserted-by":"crossref","unstructured":"Choi SH, Shin J, Choi YH. PIHA: Detection method using perceptual image hashing against query-based adversarial attacks. Futur Gener Comput Syst. 2023;145:563\u201377. 10.1016\/j.future.2023.04.005.","DOI":"10.1016\/j.future.2023.04.005"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_081","doi-asserted-by":"crossref","unstructured":"Li Y, Wu B, Feng Y, Fan Y, Jiang Y, Li Z, et al. Semi-supervised robust training with generalized perturbed neighborhood. Pattern Recognit. 2022;124:108472. 10.1016\/j.patcog.2021.108472.","DOI":"10.1016\/j.patcog.2021.108472"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_082","doi-asserted-by":"crossref","unstructured":"Lu S, Li R, Liu W, Chen X. Defense against backdoor attack in federated learning. Comput Secur. 2022;121:102819. 10.1016\/j.cose.2022.102819.","DOI":"10.1016\/j.cose.2022.102819"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_083","doi-asserted-by":"crossref","unstructured":"Li W, Liu X, Yan A, Yang J. Kernel-based adversarial attacks and defenses on support vector classification. Digit Commun Netw. 2022;8(4):492\u20137. 10.1016\/j.dcan.2021.12.003.","DOI":"10.1016\/j.dcan.2021.12.003"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_084","doi-asserted-by":"crossref","unstructured":"Hassanin M, Radwan I, Moustafa N, Tahtali M, Kumar N. Mitigating the impact of adversarial attacks in very deep networks. Appl Soft Comput. 2021;105:107231. 10.1016\/j.asoc.2021.107231.","DOI":"10.1016\/j.asoc.2021.107231"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_085","doi-asserted-by":"crossref","unstructured":"Liu J, Jin Y. Multi-objective search of robust neural architectures against multiple types of adversarial attacks. Neurocomputing. 2021;453:73\u201384. 10.1016\/j.neucom.2021.04.111.","DOI":"10.1016\/j.neucom.2021.04.111"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_086","doi-asserted-by":"crossref","unstructured":"Pestana C, Liu W, Glance D, Mian A. Defense-friendly images in adversarial attacks: Dataset and metrics for perturbation difficulty. Proceedings - 2021 IEEE Winter Conference on Applications of Computer Vision, WACV 2021, IEEE Winter Conference on Applications of Computer Vision (WACV) CL-Electr Network. 35 Stirling Hwy, Crawley, WA 6009, Australia: Univ Western Australia; 2021. p. 556\u201365. 10.1109\/WACV48630.2021.00060.","DOI":"10.1109\/WACV48630.2021.00060"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_087","doi-asserted-by":"crossref","unstructured":"Yuan X, Zhang Z, Wang X, Wu L. Semantic-aware adversarial training for reliable deep hashing retrieval. IEEE Trans Inf Forensics Secur. 2023;18:4681\u201394. 10.1109\/TIFS.2023.3297791.","DOI":"10.1109\/TIFS.2023.3297791"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_088","doi-asserted-by":"crossref","unstructured":"Shi C, Liu Y, Zhao M, Pun CM, Miao Q. Attack-invariant attention feature for adversarial defense in hyperspectral image classification. Pattern Recognit. 2024;145:109955. 10.1016\/j.patcog.2023.109955.","DOI":"10.1016\/j.patcog.2023.109955"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_089","doi-asserted-by":"crossref","unstructured":"Yamany W, Moustafa N, Turnbull B. OQFL: An optimized quantum-based federated learning framework for defending against adversarial attacks in intelligent transportation systems. IEEE Trans Intell Transp Syst. 2023;24(1):893\u2013903. 10.1109\/TITS.2021.3130906.","DOI":"10.1109\/TITS.2021.3130906"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_090","doi-asserted-by":"crossref","unstructured":"Lee Y, Han SW. CAGCN: Causal attention graph convolutional network against adversarial attacks. Neurocomputing. 2023;538:126187. 10.1016\/j.neucom.2023.03.048.","DOI":"10.1016\/j.neucom.2023.03.048"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_091","doi-asserted-by":"crossref","unstructured":"Zha H, Zhang W, Yu N, Fan Z. Enhancing image steganography via adversarial optimization of the stego distribution. Signal Process. 2023;212:109155. 10.1016\/j.sigpro.2023.109155.","DOI":"10.1016\/j.sigpro.2023.109155"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_092","doi-asserted-by":"crossref","unstructured":"Rodr\u00edguez-Barroso N, Mart\u00ednez-C\u00e1mara E, Luz\u00f3n MV, Herrera F. Backdoor attacks-resilient aggregation based on Robust Filtering of Outliers in federated learning for image classification. Knowl Syst. 2022;245:108588. 10.1016\/j.knosys.2022.108588.","DOI":"10.1016\/j.knosys.2022.108588"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_093","doi-asserted-by":"crossref","unstructured":"Kanwal S, Shah JH, Khan MA, Nisa M, Kadry S, Sharif M, et al. Person re-identification using adversarial haze attack and defense: A deep learning framework. Comput Electr Eng. 2021;96:107542. 10.1016\/j.compeleceng.2021.107542.","DOI":"10.1016\/j.compeleceng.2021.107542"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_094","doi-asserted-by":"crossref","unstructured":"Nair AK, Sahoo J, Raj ED. Privacy preserving Federated Learning framework for IoMT based big data analysis using edge computing. Comput Stand Interfaces. 2023;86:103720. 10.1016\/j.csi.2023.103720.","DOI":"10.1016\/j.csi.2023.103720"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_095","doi-asserted-by":"crossref","unstructured":"Gungor O, Rosing T, Aksanli B. \u201cROLDEF: RObust layered defense for intrusion detection against adversarial attacks. In Proceedings -Design, Automation and Test in Europe, DATE. Institute of Electrical and Electronics Engineers Inc; 2024. https:\/\/doi.org\/10.23919\/date58400.2024.10546886.","DOI":"10.23919\/DATE58400.2024.10546886"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_096","doi-asserted-by":"crossref","unstructured":"Shaukat K, Luo S, Varadharajan V. A novel method for improving the robustness of deep learning-based malware detectors against adversarial attacks. Eng Appl Artif Intell. 2022;116:105461. 10.1016\/j.engappai.2022.105461.","DOI":"10.1016\/j.engappai.2022.105461"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_097","doi-asserted-by":"crossref","unstructured":"Rathore H, Nandanwar A, Sahay SK, Sewak M. Adversarial superiority in android malware detection: Lessons from reinforcement learning based evasion attacks and defenses. Forensic Sci Int Digit Investig. 2023;44:301511. 10.1016\/j.fsidi.2023.301511.","DOI":"10.1016\/j.fsidi.2023.301511"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_098","doi-asserted-by":"crossref","unstructured":"Jia L, Yang Y, Tang B, Jiang Z. ERMDS: A obfuscation dataset for evaluating robustness of learning-based malware detection system. BenchCouncil Trans Benchmarks, Stand Eval. 2023;3(1):100106. 10.1016\/j.tbench.2023.100106.","DOI":"10.1016\/j.tbench.2023.100106"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_099","doi-asserted-by":"crossref","unstructured":"Lin YD, Pratama JH, Sudyana D, Lai YC, Hwang RH, Lin PC, et al. ELAT: Ensemble learning with adversarial training in defending against evaded intrusions. J Inf Secur Appl. 2022;71:103348. 10.1016\/j.jisa.2022.103348.","DOI":"10.1016\/j.jisa.2022.103348"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_100","doi-asserted-by":"crossref","unstructured":"Xue B, Wu L, Liu A, Zhang X, Chen X, Chen X. Detecting the universal adversarial perturbations on high-density sEMG signals. Comput Biol Med. 2022;149:105978. 10.1016\/j.compbiomed.2022.105978.","DOI":"10.1016\/j.compbiomed.2022.105978"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_101","doi-asserted-by":"crossref","unstructured":"Kopcan J, \u0160kvarek O, Klimo M. Anomaly detection using autoencoders and deep convolution generative adversarial networks. Transp Res Procedia. 2021;55:1296\u2013303. 10.1016\/j.trpro.2021.07.113.","DOI":"10.1016\/j.trpro.2021.07.113"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_102","doi-asserted-by":"crossref","unstructured":"Zhan D, Duan Y, Hu Y, Li W, Guo S, Pan Z. MalPatch: evading DNN-based malware detection with adversarial patches. IEEE Trans Inf Forensics Secur. 2024;19:1183\u201398. 10.1109\/TIFS.2023.3333567.","DOI":"10.1109\/TIFS.2023.3333567"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_103","doi-asserted-by":"crossref","unstructured":"Katebi M, Rezakhani A, Joudaki S. ADCAS: adversarial deep clustering of android streams. Comput Electr Eng. 2021;95:107443. 10.1016\/j.compeleceng.2021.107443.","DOI":"10.1016\/j.compeleceng.2021.107443"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_104","doi-asserted-by":"crossref","unstructured":"Zhuo Y, Shardt YAW, Ge Z. One-variable attack on the industrial fault classification system and its defense. Engineering. 2022;19:240\u201351. 10.1016\/j.eng.2021.07.033.","DOI":"10.1016\/j.eng.2021.07.033"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_105","doi-asserted-by":"crossref","unstructured":"Zhao M, Wang B, Guo W, Wang W. Protecting by attacking: A personal information protecting method with cross-modal adversarial examples. Neurocomputing. 2023;551:126481. 10.1016\/j.neucom.2023.126481.","DOI":"10.1016\/j.neucom.2023.126481"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_106","doi-asserted-by":"crossref","unstructured":"Xu M, Zhang T, Li Z, Liu M, Zhang D. Towards evaluating the robustness of deep diagnostic models by adversarial attack. Med Image Anal. 2021;69:101977. 10.1016\/j.media.2021.101977.","DOI":"10.1016\/j.media.2021.101977"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_107","doi-asserted-by":"crossref","unstructured":"Soremekun E, Udeshi S, Chattopadhyay S. Towards backdoor attacks and defense in robust machine learning models. Comput Secur. 2023;127:103101. 10.1016\/j.cose.2023.103101.","DOI":"10.1016\/j.cose.2023.103101"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_108","doi-asserted-by":"crossref","unstructured":"Charfeddine M, Kammoun HM, Hamdaoui B, Guizani M. ChatGPT\u2019s security risks and benefits: offensive and defensive use-cases, mitigation measures, and future implications. IEEE Access. 2024;12:30263\u2013310. 10.1109\/ACCESS.2024.3367792.","DOI":"10.1109\/ACCESS.2024.3367792"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_109","doi-asserted-by":"crossref","unstructured":"Khaleel TA. Developing robust machine learning models to defend against adversarial attacks in the field of cybersecurity. In HORA 2024 - 6th International Congress on Human-Computer Interaction, Optimization and Robotic Applications, Proceedings. Institute of Electrical and Electronics Engineers Inc; 2024. 10.1109\/HORA61326.2024.10550799.","DOI":"10.1109\/HORA61326.2024.10550799"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_110","doi-asserted-by":"crossref","unstructured":"Meng L, Jiang X, Wu D. Adversarial robustness benchmark for EEG-based brain\u2013computer interfaces. Futur Gener Comput Syst. 2023;143:231\u201347. 10.1016\/j.future.2023.01.028.","DOI":"10.1016\/j.future.2023.01.028"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_111","doi-asserted-by":"crossref","unstructured":"Ul Ghani MAN, She K, Rauf MA, Alajmi M, Ghadi YY, Algarni A. Securing synthetic faces: A GAN-blockchain approach to privacy-enhanced facial recognition. J King Saud Univ - Comput Inf Sci. 2024;36(4):102036. 10.1016\/j.jksuci.2024.102036.","DOI":"10.1016\/j.jksuci.2024.102036"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_112","doi-asserted-by":"crossref","unstructured":"Wei X, Wang X, Yan Y, Jiang N, Yue H. ALERT: A lightweight defense mechanism for enhancing DNN robustness against T-BFA. J Syst Archit. 2024;152:103160. 10.1016\/j.sysarc.2024.103160.","DOI":"10.1016\/j.sysarc.2024.103160"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_113","doi-asserted-by":"crossref","unstructured":"Shehu HA, Browne WN, Eisenbarth H. An anti-attack method for emotion categorization from images[Formula presented]. Appl Soft Comput. 2022;128:109456. 10.1016\/j.asoc.2022.109456.","DOI":"10.1016\/j.asoc.2022.109456"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_114","doi-asserted-by":"crossref","unstructured":"Nayak GK, Rawal R, Chakraborty A. DE-CROP: Data-efficient Certified Robustness for Pretrained Classifiers. In Proceedings - 2023 IEEE Winter Conference on Applications of Computer Vision, WACV 2023, Indian Institute of Science, Department of Computational and Data Sciences. Bangalore, India: Institute of Electrical and Electronics Engineers Inc.; 2023. p. 4611\u201320. 10.1109\/WACV56688.2023.00460.","DOI":"10.1109\/WACV56688.2023.00460"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_115","doi-asserted-by":"crossref","unstructured":"Yin Z, Zhuo Y, Ge Z. Transfer adversarial attacks across industrial intelligent systems. Reliab Eng Syst Saf. 2023;237:109299. 10.1016\/j.ress.2023.109299.","DOI":"10.1016\/j.ress.2023.109299"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_116","doi-asserted-by":"crossref","unstructured":"Cheng Z, Zhu F, Zhang XY, Liu CL. Adversarial training with distribution normalization and margin balance. Pattern Recognit. 2023;136:109182. 10.1016\/j.patcog.2022.109182.","DOI":"10.1016\/j.patcog.2022.109182"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_117","doi-asserted-by":"crossref","unstructured":"Dadvandipour S, Khaleel YL. Application of deep learning algorithms detecting fake and correct textual or verbal news. Prod Syst Inf Eng. 2022;10(2):37\u201351. 10.32968\/psaie.2022.2.4.","DOI":"10.32968\/psaie.2022.2.4."},{"key":"2025122009032208204_j_jisys-2024-0277_ref_118","doi-asserted-by":"crossref","unstructured":"Hassan A, Mahmood A. Efficient deep learning model for text classification based on recurrent and convolutional layers. In Proceedings - 16th IEEE International Conference on Machine Learning and Applications, ICMLA. 2017. p. 1108\u201313. 10.1109\/ICMLA.2017.00009.","DOI":"10.1109\/ICMLA.2017.00009"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_119","doi-asserted-by":"crossref","unstructured":"Albahri AS, Khaleel YL, Habeeb MA. The considerations of trustworthy AI components in generative AI; A Letter to Editor. Appl Data Sci Anal. 2023;2023:108\u20139. 10.58496\/adsa\/2023\/009.","DOI":"10.58496\/ADSA\/2023\/009"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_120","doi-asserted-by":"crossref","unstructured":"Ray PP. ChatGPT: A comprehensive review on background, applications, key challenges, bias, ethics, limitations and future scope. Internet Things Cyber-PhysSyst. 2023;3:121\u201354. 10.1016\/j. iotcps. 2023.04. 003.","DOI":"10.1016\/j.iotcps.2023.04.003"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_121","doi-asserted-by":"crossref","unstructured":"Wang C, Chen J, Yang Y, Ma X, Liu J. Poisoning attacks and countermeasures in intelligent networks: Status quo and prospects. Digit Commun Netw. 2022;8(2):225\u201334. 10.1016\/j.dcan.2021.07.009.","DOI":"10.1016\/j.dcan.2021.07.009"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_122","doi-asserted-by":"crossref","unstructured":"Hou X, Liu J, Xu B, Wang X, Liu B, Qiu G. Class-aware domain adaptation for improving adversarial robustness. Image Vis Comput. 2020;99:103926. 10.1016\/j.imavis.2020.103926.","DOI":"10.1016\/j.imavis.2020.103926"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_123","doi-asserted-by":"crossref","unstructured":"Qureshi AUH, Larijani H, Mtetwa N, Yousefi M, Javed A. An adversarial attack detection paradigm with swarm optimization. In Proceedings of the International Joint Conference on Neural Networks, glasgow caledonian university, school of computing, Engineering and Built Environment. Glasgow, United Kingdom: Institute of Electrical and Electronics Engineers Inc.; 2020. 10.1109\/IJCNN48605.2020.9207627.","DOI":"10.1109\/IJCNN48605.2020.9207627"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_124","doi-asserted-by":"crossref","unstructured":"Pawlicki M, Chora\u015b M, Kozik R. Defending network intrusion detection systems against adversarial evasion attacks. Futur Gener Comput Syst. 2020;110:148\u201354. 10.1016\/j.future.2020.04.013.","DOI":"10.1016\/j.future.2020.04.013"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_125","doi-asserted-by":"crossref","unstructured":"Ojo S, Krichen M, Alamro MA, Mihoub A. TXAI-ADV: Trustworthy XAI for Defending AI models against adversarial attacks in realistic CIoT. Electron. 2024;13(9):1769. 10.3390\/electronics13091769.","DOI":"10.3390\/electronics13091769"},{"key":"2025122009032208204_j_jisys-2024-0277_ref_126","doi-asserted-by":"crossref","unstructured":"Shayea GG, Zabil M, Albahri AS, Joudar SS, Hamid RA, Albahri OS, et al. Fuzzy evaluation and benchmarking framework for robust machine learning model in real-time autism triage applications. Int J Comput Intell Syst. 2024;17(1):151. 10.1007\/s44196-024-00543-3.","DOI":"10.1007\/s44196-024-00543-3"}],"container-title":["Journal of Intelligent Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.degruyterbrill.com\/document\/doi\/10.1515\/jisys-2024-0277\/xml","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.degruyterbrill.com\/document\/doi\/10.1515\/jisys-2024-0277\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,12,20]],"date-time":"2025-12-20T09:12:20Z","timestamp":1766221940000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.degruyterbrill.com\/document\/doi\/10.1515\/jisys-2024-0277\/html"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,1,1]]},"references-count":126,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2025,3,7]]},"published-print":{"date-parts":[[2025,3,7]]}},"alternative-id":["10.1515\/jisys-2024-0277"],"URL":"https:\/\/doi.org\/10.1515\/jisys-2024-0277","relation":{},"ISSN":["2191-026X"],"issn-type":[{"value":"2191-026X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,1,1]]},"article-number":"20240277"}}