{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,2]],"date-time":"2026-05-02T06:48:03Z","timestamp":1777704483153,"version":"3.51.4"},"reference-count":27,"publisher":"SAGE Publications","issue":"5","license":[{"start":{"date-parts":[[2020,9,30]],"date-time":"2020-09-30T00:00:00Z","timestamp":1601424000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/journals.sagepub.com\/page\/policies\/text-and-data-mining-license"}],"content-domain":{"domain":["journals.sagepub.com"],"crossmark-restriction":true},"short-container-title":["Journal of Intelligent &amp; Fuzzy Systems"],"published-print":{"date-parts":[[2020,11,19]]},"abstract":"<jats:p>In recent years, deep neural networks have made significant progress in image classification, object detection and face recognition. However, they still have the problem of misclassification when facing adversarial examples. In order to address security issue and improve the robustness of the neural network, we propose a novel defense network based on generative adversarial network (GAN). The distribution of clean - and adversarial examples are matched to solve the mentioned problem. This guides the network to remove invisible noise accurately, and restore the adversarial example to a clean example to achieve the effect of defense. In addition, in order to maintain the classification accuracy of clean examples and improve the fidelity of neural network, we input clean examples into proposed network for denoising. Our method can effectively remove the noise of the adversarial examples, so that the denoised adversarial examples can be correctly classified. In this paper, extensive experiments are conducted on five benchmark datasets, namely MNIST, Fashion-MNIST, CIFAR10, CIFAR100 and ImageNet. Moreover, six mainstream attack methods are adopted to test the robustness of our defense method including FGSM, PGD, MIM, JSMA, CW and Deep-Fool. Results show that our method has strong defensive capabilities against the tested attack methods, which confirms the effectiveness of the proposed method.<\/jats:p>","DOI":"10.3233\/jifs-200280","type":"journal-article","created":{"date-parts":[[2020,10,2]],"date-time":"2020-10-02T13:40:06Z","timestamp":1601646006000},"page":"7085-7095","update-policy":"https:\/\/doi.org\/10.1177\/sage-journals-update-policy","source":"Crossref","is-referenced-by-count":3,"title":["GAN-based classifier protection against adversarial attacks"],"prefix":"10.1177","volume":"39","author":[{"given":"Shuqi","family":"Liu","sequence":"first","affiliation":[{"name":"School of Computer Science and Technology, China University of Petroleum (East China), Qingdao, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mingwen","family":"Shao","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, China University of Petroleum (East China), Qingdao, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xinping","family":"Liu","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, China University of Petroleum (East China), Qingdao, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"179","published-online":{"date-parts":[[2020,9,30]]},"reference":[{"key":"e_1_3_1_2_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2807385"},{"key":"e_1_3_1_3_2","unstructured":"ArjovskyM. ChintalaS. and Bottou Wasserstein generative adversarial networks. In International Conference on Learning Representations(ICLR) 2017."},{"key":"e_1_3_1_4_2","doi-asserted-by":"crossref","unstructured":"CarliniN. and WagnerD. Towards evaluating the robustness of neural networks. In IEEE Symposium on Security and Privacy (SP) pages 39\u201357. IEEE 2017.","DOI":"10.1109\/SP.2017.49"},{"key":"e_1_3_1_5_2","doi-asserted-by":"crossref","unstructured":"CoK.T. Mu\u00f1oz-Gonz\u00e1lezL. de MaupeouS. and LupuE.C. Procedural noise adversarial examples for blackbox attacks on deep convolutional networks. In ACM SIGSAC Conference on Computer and Communications Security pages 275\u2013289. ACM 2019.","DOI":"10.1145\/3319535.3345660"},{"key":"e_1_3_1_6_2","doi-asserted-by":"crossref","unstructured":"DingZ. GuoY. LeiZ. and YunF. Oneshot face recognition via generative learning. In 2018 13th IEEE International Conference on Automatic Face & Gesture Recognition (FG 2018) 2018.","DOI":"10.1109\/FG.2018.00011"},{"key":"e_1_3_1_7_2","doi-asserted-by":"crossref","unstructured":"DongY. LiaoF. PangT. SuH. ZhuJ. HuX. and LiJ. Boosting adversarial attacks with momentum. In IEEE Conference on Computer Vision and Pattern Recognition(CVPR) pages 9185\u20139193 2018.","DOI":"10.1109\/CVPR.2018.00957"},{"key":"e_1_3_1_8_2","doi-asserted-by":"crossref","unstructured":"EykholtK. EvtimovI. FernandesE. LiB. RahmatiA. XiaoC. PrakashA. KohnoT. and SongD. Robust physical-world attacks on deep learning visual classification. In IEEE Conference on Computer Vision and Pattern Recognition(CVPR) pages 1625\u20131634 2018.","DOI":"10.1109\/CVPR.2018.00175"},{"key":"e_1_3_1_9_2","unstructured":"GoodfellowI.J. ShlensJ. and SzegedyC. Explaining and harnessing adversarial examples. In International Conference on Learning Representations(ICLR) 2015."},{"key":"e_1_3_1_10_2","doi-asserted-by":"crossref","unstructured":"JinG. ShenS. ZhangD. DaiF. and ZhangY. Ape-gan: Adversarial perturbation elimination with gan. In International Conference on Acoustics Speech and Signal Processing (ICASSP) pages 3842\u20133846. IEEE 2019.","DOI":"10.1109\/ICASSP.2019.8683044"},{"key":"e_1_3_1_11_2","unstructured":"KrizhevskyA. Learning multiple layers of features from tiny images. Technical report 2009."},{"key":"e_1_3_1_12_2","unstructured":"KrizhevskyA. SutskeverI. and HintonG.E. Imagenet classification with deep convolutional neural networks. In Advances in Neural Information Processing Systems pages 1097\u20131105 2012."},{"key":"e_1_3_1_13_2","unstructured":"KurakinA. GoodfellowI.J. and BengioS. Adversarial examples in the physicalworld. In International Conference on Learning Representations(ICLR) 2017."},{"key":"e_1_3_1_14_2","doi-asserted-by":"crossref","unstructured":"LecunY. BottouL. BengioY. and HaffnerP. Gradient-based learning applied to document recognition 86 (1998) 2278\u20132324.","DOI":"10.1109\/5.726791"},{"key":"e_1_3_1_15_2","doi-asserted-by":"publisher","DOI":"10.1109\/TSMC.2018.2841063"},{"key":"e_1_3_1_16_2","unstructured":"LiuX. YangH. LiuZ. SongL. ChenY. and LiH. Dpatch: An adversarial patch attack on object detectors. In SafeAI@AAAI 2019."},{"key":"e_1_3_1_17_2","unstructured":"MadryA. MakelovA. SchmidtL. TsiprasD. and VladuA. Towards deep learning models resistant to adversarial attacks. In International Conference on Learning Representations(ICLR) 2018."},{"key":"e_1_3_1_18_2","doi-asserted-by":"crossref","unstructured":"MengD. and ChenH. Magnet: a two-pronged defense against adversarial examples. In ACM SIGSAC Conference on Computer and Communications Security pages 135\u2013147 2017.","DOI":"10.1145\/3133956.3134057"},{"key":"e_1_3_1_19_2","doi-asserted-by":"crossref","unstructured":"Moosavi-DezfooliS.-M. FawziA. and FrossardP. Deepfool: A simple and accurate method to fool deep neural networks. In IEEE Conference on Computer Vision and Pattern Recognition(CVPR) pages 2574\u20132582. IEEE Computer Society 2016.","DOI":"10.1109\/CVPR.2016.282"},{"key":"e_1_3_1_20_2","unstructured":"PapernotN. McDanielP. and GoodfellowI. Transferability in machine learning: from phenomena to black-box attacks using adversarial samples. arXiv preprint arXiv:1605.07277 2016."},{"key":"e_1_3_1_21_2","doi-asserted-by":"crossref","unstructured":"PapernotN. McDanielP. JhaS. FredriksonM. CelikZ.B. and SwamiA. The limitations of deep learning in adversarial settings. In IEEE Symposium on Security and Privacy (SP) pages 372\u2013387. IEEE 2016.","DOI":"10.1109\/EuroSP.2016.36"},{"key":"e_1_3_1_22_2","doi-asserted-by":"crossref","unstructured":"PapernotN. McDanielP. WuX. JhaS. and SwamiA. Distillation as a defense to adversarial perturbations against deep neural networks. In IEEE Symposium on Security and Privacy (SP) pages 582\u2013597. IEEE 2016.","DOI":"10.1109\/SP.2016.41"},{"key":"e_1_3_1_23_2","unstructured":"SamangoueiP. KabkabM. and ChellappaR. Defense-gan: Protecting classifiers against adversarial attacks using generative models. In International Conference on Learning Representations(ICLR) 2018."},{"key":"e_1_3_1_24_2","doi-asserted-by":"publisher","DOI":"10.1109\/TGRS.2013.2245509"},{"key":"e_1_3_1_25_2","unstructured":"SzegedyC. ZarembaW. SutskeverI. BrunaJ. ErhanD. GoodfellowI.J. and FergusR. Intriguing properties of neural networks. In Yoshua Bengio and Yann LeCun editors International Conference on Learning Representations(ICLR) 2014."},{"key":"e_1_3_1_26_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2003.819861"},{"key":"e_1_3_1_27_2","unstructured":"XiaoH. RasulK. and VollgrafR. Fashion-mnist: a novel image dataset for benchmarking machine learning algorithms. arXiv preprint arXiv:1708.07747 2017."},{"issue":"99","key":"e_1_3_1_28_2","first-page":"1","article-title":"Self-paced balance learning for clinical skin disease recognition","author":"Yang J.","year":"2019","unstructured":"YangJ., WuX., LiangJ., SunX. and WangL., Self-paced balance learning for clinical skin disease recognition, IEEE Transactions on Neural Networks and Learning Systems PP(99) (2019), 1\u201315.","journal-title":"IEEE Transactions on Neural Networks and Learning Systems"}],"container-title":["Journal of Intelligent &amp; Fuzzy Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.3233\/JIFS-200280","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/journals.sagepub.com\/doi\/full-xml\/10.3233\/JIFS-200280","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.3233\/JIFS-200280","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T09:41:19Z","timestamp":1777455679000},"score":1,"resource":{"primary":{"URL":"https:\/\/journals.sagepub.com\/doi\/10.3233\/JIFS-200280"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,9,30]]},"references-count":27,"journal-issue":{"issue":"5","published-print":{"date-parts":[[2020,11,19]]}},"alternative-id":["10.3233\/JIFS-200280"],"URL":"https:\/\/doi.org\/10.3233\/jifs-200280","relation":{},"ISSN":["1064-1246","1875-8967"],"issn-type":[{"value":"1064-1246","type":"print"},{"value":"1875-8967","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,9,30]]}}}