{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,9]],"date-time":"2026-07-09T06:05:04Z","timestamp":1783577104934,"version":"3.55.0"},"reference-count":67,"publisher":"MDPI AG","issue":"10","license":[{"start":{"date-parts":[[2021,10,15]],"date-time":"2021-10-15T00:00:00Z","timestamp":1634256000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Algorithms"],"abstract":"<jats:p>Cyber security is used to protect and safeguard computers and various networks from ill-intended digital threats and attacks. It is getting more difficult in the information age due to the explosion of data and technology. There is a drastic rise in the new types of attacks where the conventional signature-based systems cannot keep up with these attacks. Machine learning seems to be a solution to solve many problems, including problems in cyber security. It is proven to be a very useful tool in the evolution of malware detection systems. However, the security of AI-based malware detection models is fragile. With advancements in machine learning, attackers have found a way to work around such detection systems using an adversarial attack technique. Such attacks are targeted at the data level, at classifier models, and during the testing phase. These attacks tend to cause the classifier to misclassify the given input, which can be very harmful in real-time AI-based malware detection. This paper proposes a framework for generating the adversarial malware images and retraining the classification models to improve malware detection robustness. Different classification models were implemented for malware detection, and attacks were established using adversarial images to analyze the model\u2019s behavior. The robustness of the models was improved by means of adversarial training, and better attack resistance is observed.<\/jats:p>","DOI":"10.3390\/a14100297","type":"journal-article","created":{"date-parts":[[2021,10,15]],"date-time":"2021-10-15T13:35:47Z","timestamp":1634304947000},"page":"297","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":34,"title":["Improving the Robustness of AI-Based Malware Detection Using Adversarial Machine Learning"],"prefix":"10.3390","volume":"14","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-4903-1540","authenticated-orcid":false,"given":"Shruti","family":"Patil","sequence":"first","affiliation":[{"name":"Symbiosis Center for Artificial Intelligence, Symbiosis Institute of Technology, Symbiosis International (Deemed University), Pune 412115, India"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Vijayakumar","family":"Varadarajan","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, The University of New South Wales, Sydney 1466, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Devika","family":"Walimbe","sequence":"additional","affiliation":[{"name":"Symbiosis Center for Artificial Intelligence, Symbiosis Institute of Technology, Symbiosis International (Deemed University), Pune 412115, India"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Siddharth","family":"Gulechha","sequence":"additional","affiliation":[{"name":"Symbiosis Center for Artificial Intelligence, Symbiosis Institute of Technology, Symbiosis International (Deemed University), Pune 412115, India"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Sushant","family":"Shenoy","sequence":"additional","affiliation":[{"name":"Symbiosis Center for Artificial Intelligence, Symbiosis Institute of Technology, Symbiosis International (Deemed University), Pune 412115, India"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4112-1231","authenticated-orcid":false,"given":"Aditya","family":"Raina","sequence":"additional","affiliation":[{"name":"Symbiosis Center for Artificial Intelligence, Symbiosis Institute of Technology, Symbiosis International (Deemed University), Pune 412115, India"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2653-3780","authenticated-orcid":false,"given":"Ketan","family":"Kotecha","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, The University of New South Wales, Sydney 1466, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2021,10,15]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"102248","DOI":"10.1016\/j.cose.2021.102248","article-title":"Cyber security in the age of COVID-19: A timeline and analysis of cyber-crime and cyber-attacks during the pandemic","volume":"105","author":"Lallie","year":"2021","journal-title":"Comput. Secur."},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Anderson, R., Barton, C., B\u00f6hme, R., Clayton, R., van Eeten, M.J.G., Levi, M., Moore, T., and Savage, S. (2013). Measuring the Cost of Cybercrime. The Economics of Information Security and Privacy, Springer.","DOI":"10.1007\/978-3-642-39498-0_12"},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Dama\u0161evi\u010dius, R., Ven\u010dkauskas, A., Toldinas, J., and Grigali\u016bnas, \u0160. (2021). The Great Bank Robbery: Carbanak cybergang steals $ 1bn from 100 financial institutions worldwide. Electronics, 10.","DOI":"10.3390\/electronics10040485"},{"key":"ref_4","unstructured":"Cisco (2021, October 10). 2015 Annual Security Report. Available online: https:\/\/www.cisco.com\/c\/dam\/assets\/global\/DE\/unified_channels\/partner_with_cisco\/newsletter\/2015\/edition2\/download\/cisco-annual-security-report-2015-e.pdf."},{"key":"ref_5","unstructured":"Bissell, K., Lasalle, R.M., and Dal Chin, P. The Cost of Cybercrime: Ninth Annual Cost of Cybercrime Study. Ninth Annu. Cost Cybercrime Study, Available online: https:\/\/www.accenture.com\/_acnmedia\/PDF-96\/Accenture-2019-Cost-of-Cybercrime-Study-Final.pdf."},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Upstream Security (2020). 2020 Global Automotive Cyber security Report. Netw. Secur., 2020, 4.","DOI":"10.1016\/S1353-4858(20)30005-2"},{"key":"ref_7","unstructured":"Cybersecurity Ventures (2019). 2017 CyberVentures Cybercrime Report. Herjavec Gr."},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Seh, A.H., Zarour, M., Alenezi, M., Sarkar, A.K., Agrawal, A., Kumar, R., and Ahmad Khan, R. (2020). Healthcare Data Breaches: Insights and Implications. Healthcare, 8.","DOI":"10.3390\/healthcare8020133"},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"4412","DOI":"10.35940\/ijitee.J9835.0881019","article-title":"Demystifying user data privacy in the world of IOT","volume":"10","author":"Patil","year":"2019","journal-title":"Int. J. Innov. Technol. Explor. Eng."},{"key":"ref_10","first-page":"34","article-title":"Survey on Machine Learning Techniques: Concepts and Algorithms","volume":"10","author":"Minaam","year":"2019","journal-title":"Int. J. Electron. Inf. Eng."},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"3","DOI":"10.1186\/s13673-018-0125-x","article-title":"A state-of-the-art survey of malware detection approaches using data mining techniques","volume":"8","author":"Souri","year":"2018","journal-title":"Hum. Cent. Comput. Inf. Sci."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3073559","article-title":"A Survey on Malware Detection Using Data Mining Techniques","volume":"50","author":"Ye","year":"2017","journal-title":"ACM Comput. Surv."},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"6249","DOI":"10.1109\/ACCESS.2019.2963724","article-title":"A Comprehensive Review on Malware Detection Approaches","volume":"8","author":"Aslan","year":"2020","journal-title":"IEEE Access"},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"295","DOI":"10.1016\/j.future.2019.03.006","article-title":"Machine-Learning based analysis and classification of Android malware signatures","volume":"97","author":"Santos","year":"2019","journal-title":"Futur. Gener. Comput. Syst."},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"123","DOI":"10.1016\/j.cose.2018.11.001","article-title":"Survey of machine learning techniques for malware analysis","volume":"81","author":"Ucci","year":"2019","journal-title":"Comput. Secur."},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Shaikh, A., and Patil, S.G. (2018, January 9). A Survey on Privacy Enhanced Role Based Data Aggregation via Differential Privacy. Proceedings of the 2018 International Conference On Advances in Communication and Computing Technology (ICACCT), Delhi, India.","DOI":"10.1109\/ICACCT.2018.8529634"},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"461","DOI":"10.1007\/s00521-017-3077-6","article-title":"Malware detection based on deep learning algorithm","volume":"31","author":"Yuxin","year":"2017","journal-title":"Neural Comput. Appl."},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Berman, D.S., Buczak, A.L., Chavis, J.S., and Corbett, C.L. (2019). A Survey of Deep Learning Methods for Cyber Security. Information, 10.","DOI":"10.3390\/info10040122"},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Nisa, M., Shah, J.H., Kanwal, S., Raza, M., Khan, M.A., Dama\u0161evi\u010dius, R., and Bla\u017eauskas, T. (2020). Hybrid Malware Classification Method Using Segmentation-Based Fractal Texture Analysis and Deep Convolution Neural Network Features. Appl. Sci., 10.","DOI":"10.3390\/app10144966"},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"326","DOI":"10.1016\/j.cose.2017.11.007","article-title":"Automated poisoning attacks and defenses in malware detection systems: An adversarial machine learning approach","volume":"73","author":"Chen","year":"2018","journal-title":"Comput. Secur."},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Peng, X., Xian, H., Lu, Q., and Lu, X. (2020). Generating Adversarial Malware Examples with API Semantics-Awareness for Black-Box Attacks. International Symposium on Security and Privacy in Social Networks and Big Data, Springer.","DOI":"10.1007\/978-981-15-9031-3_5"},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"35403","DOI":"10.1109\/ACCESS.2020.2974752","article-title":"Adversarial Machine Learning Applied to Intrusion and Malware Scenarios: A Systematic Review","volume":"8","author":"Martins","year":"2020","journal-title":"IEEE Access"},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Patil, S.G., Joshi, S., and Patil, D. (2020). Enhanced Privacy Preservation Using Anonymization in IOT-Enabled Smart Homes. Smart Intelligent Computing and Applications, Springer.","DOI":"10.1007\/978-981-13-9282-5_42"},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"280","DOI":"10.1016\/j.icte.2020.04.005","article-title":"A survey of IoT malware and detection methods based on static features","volume":"6","author":"Ngo","year":"2020","journal-title":"ICT Express"},{"key":"ref_25","first-page":"492","article-title":"A Survey on Internet of Things","volume":"6","author":"Joshi","year":"2018","journal-title":"Int. J. Comput. Sci. Eng."},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"102098","DOI":"10.1016\/j.adhoc.2020.102098","article-title":"End-to-end malware detection for android IoT devices using deep learning","volume":"101","author":"Ren","year":"2020","journal-title":"Ad Hoc Netw."},{"key":"ref_27","first-page":"20","article-title":"A Study on Malware and Malware Detection Techniques","volume":"8","author":"Tahir","year":"2018","journal-title":"Int. J. Educ. Manag. Eng."},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Yong, B., Wei, W., Li, K., Shen, J., Zhou, Q., Wozniak, M., Po\u0142ap, D., and Dama\u0161evi\u010dius, R. (2020). Ensemble machine learning approaches for webshell detection in Internet of things environments. Trans. Emerg. Telecommun. Technol.","DOI":"10.1002\/ett.4085"},{"key":"ref_29","first-page":"1796","article-title":"Classification of malware detection using machine learning algorithms: A survey","volume":"9","author":"Harshalatha","year":"2020","journal-title":"Int. J. Sci. Technol. Res."},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"103","DOI":"10.1080\/01969722.2018.1429835","article-title":"Big Data Framework for Zero-Day Malware Detection","volume":"49","author":"Gupta","year":"2018","journal-title":"Cybern. Syst."},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Dama\u0161evi\u010dius, R., Ven\u010dkauskas, A., Toldinas, J., and Grigali\u016bnas, \u0160. (2021). Ensemble-Based Classification Using Neural Networks and Machine Learning Models for Windows PE Malware Detection. Electronics, 10.","DOI":"10.3390\/electronics10040485"},{"key":"ref_32","doi-asserted-by":"crossref","first-page":"399","DOI":"10.1016\/j.cose.2017.11.016","article-title":"Malware classification using self organising feature maps and machine activity data","volume":"73","author":"Burnap","year":"2018","journal-title":"Comput. Secur."},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"AlAhmadi, B.A., and Martinovic, I. (2018). MalClassifier: Malware family classification using network flow sequence behaviour. 2018 APWG Symposium on Electronic Crime Research (eCrime), IEEE.","DOI":"10.1109\/ECRIME.2018.8376209"},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"95","DOI":"10.1007\/s11416-016-0265-3","article-title":"Clustering for malware classification","volume":"13","author":"Pai","year":"2017","journal-title":"J. Comput. Virol. Hacking Tech."},{"key":"ref_35","doi-asserted-by":"crossref","first-page":"1336","DOI":"10.1631\/FITEE.1601325","article-title":"Automatic malware classification and new malware detection using machine learning","volume":"18","author":"Liu","year":"2017","journal-title":"Front. Inf. Technol. Electron. Eng."},{"key":"ref_36","doi-asserted-by":"crossref","unstructured":"Kosmidis, K., and Kalloniatis, C. (2017, January 28\u201330). Machine Learning and Images for Malware Detection and Classification. Proceedings of the 21st Pan-Hellenic Conference on Informatics, Larissa, Greece.","DOI":"10.1145\/3139367.3139400"},{"key":"ref_37","doi-asserted-by":"crossref","unstructured":"Gandotra, E., Bansal, D., and Sofat, S. (2014, January 27\u201330). Integrated Framework for Classification of Malwares. Proceedings of the 7th International Conference on PErvasive Technologies Related to Assistive Environments, Rhodes, Greece.","DOI":"10.1145\/2659651.2659738"},{"key":"ref_38","doi-asserted-by":"crossref","unstructured":"Tian, R., Batten, L., Islam, R., and Versteeg, S. (2009, January 13\u201314). An automated classification system based on the strings of trojan and virus families. Proceedings of the 2009 4th International Conference on Malicious and Unwanted Software (MALWARE), Montreal, QC, Canada.","DOI":"10.1109\/MALWARE.2009.5403021"},{"key":"ref_39","unstructured":"Devesa, J., Santos, I., Cantero, X., Penya, Y.K., and Bringas, P.G. (2010, January 8\u201312). Automatic behaviour-based analysis and classification system for malware detection. Proceedings of the 12th International Conference on Enterprise Information Systems, Madeira, Portugal."},{"key":"ref_40","doi-asserted-by":"crossref","unstructured":"Han, Y., and Wang, Q. (2021, January 3\u20135). An adversarial sample defense model based on computer attention mechanism. Proceedings of the 2021 International Conference on Communications, Information System and Computer Engineering (CISCE), Kuala Lumpur, Malaysia.","DOI":"10.1109\/CISCE52179.2021.9446015"},{"key":"ref_41","doi-asserted-by":"crossref","first-page":"646","DOI":"10.1016\/j.jnca.2012.10.004","article-title":"Classification of malware based on integrated static and dynamic features","volume":"36","author":"Islam","year":"2013","journal-title":"J. Netw. Comput. Appl."},{"key":"ref_42","doi-asserted-by":"crossref","unstructured":"Fang, Y., Zeng, Y., Li, B., Liu, L., and Zhang, L. (2020). DeepDetectNet vs RLAttackNet: An adversarial method to improve deep learning-based static malware detection model. PLoS ONE, 15.","DOI":"10.1371\/journal.pone.0231626"},{"key":"ref_43","doi-asserted-by":"crossref","unstructured":"Kumar, A., Mehta, S., and Vijaykeerthy, D. (2017). An Introduction to Adversarial Machine Learning. International Conference on Big Data Analytics, Springer.","DOI":"10.1007\/978-3-319-72413-3_20"},{"key":"ref_44","doi-asserted-by":"crossref","first-page":"4","DOI":"10.1109\/MIC.2011.112","article-title":"Adversarial Machine Learning","volume":"15","author":"Tygar","year":"2011","journal-title":"IEEE Internet Comput."},{"key":"ref_45","doi-asserted-by":"crossref","first-page":"83","DOI":"10.1016\/j.ins.2018.04.092","article-title":"Zero-day malware detection using transferred generative adversarial networks based on deep autoencoders","volume":"460\u2013461","author":"Kim","year":"2018","journal-title":"Inf. Sci."},{"key":"ref_46","doi-asserted-by":"crossref","unstructured":"Biggio, B., Corona, I., Maiorca, D., Nelson, B., \u0160rndi\u0107, N., Laskov, P., Giacinto, G., and Roli, F. (2013). Evasion Attacks against Machine Learning at Test Time. Joint European Conference on Machine Learning and Knowledge Discovery in Databases, Springer.","DOI":"10.1007\/978-3-642-40994-3_25"},{"key":"ref_47","doi-asserted-by":"crossref","unstructured":"Grosse, K., Papernot, N., Manoharan, P., Backes, M., and McDaniel, P. (2017). Adversarial Examples for Malware Detection. European Symposium on Research in Computer Security, Springer.","DOI":"10.1007\/978-3-319-66399-9_4"},{"key":"ref_48","unstructured":"Anderson, H.S., Kharkar, A., Filar, B., and Roth, P. (2019, January 20\u201322). Evading Machine Learning Malware Detection. Proceedings of the 2019 IEEE Symposium on Security and Privacy Workshops, San Francisco, CA, USA."},{"key":"ref_49","doi-asserted-by":"crossref","unstructured":"Xu, W., Qi, Y., and Evans, D. (2016, January 21\u201324). Automatically Evading Classifiers: A Case Study on PDF Malware Classifiers. Proceedings of the 2016 Network and Distributed System Security Symposium, San Diego, CA, USA.","DOI":"10.14722\/ndss.2016.23115"},{"key":"ref_50","doi-asserted-by":"crossref","first-page":"113","DOI":"10.1016\/j.eswa.2017.11.032","article-title":"Picking on the family: Disrupting android malware triage by forcing misclassification","volume":"95","author":"Calleja","year":"2018","journal-title":"Expert Syst. Appl."},{"key":"ref_51","doi-asserted-by":"crossref","first-page":"246","DOI":"10.1016\/j.eswa.2018.10.011","article-title":"The arms race: Adversarial search defeats entropy used to detect malware","volume":"118","author":"Bhattacharya","year":"2019","journal-title":"Expert Syst. Appl."},{"key":"ref_52","doi-asserted-by":"crossref","unstructured":"Chen, L., Ye, Y., and Bourlai, T. (2017, January 11\u201313). Adversarial Machine Learning in Malware Detection: Arms Race between Evasion Attack and Defense. Proceedings of the 2017 European Intelligence and Security Informatics Conference (EISIC), Athens, Greece.","DOI":"10.1109\/EISIC.2017.21"},{"key":"ref_53","unstructured":"Clements, J., Yang, Y., Sharma, A., Hu, H., and Lao, Y. (2019). Rallying adversarial techniques against deep learning for network security. arXiv."},{"key":"ref_54","doi-asserted-by":"crossref","unstructured":"Anderson, H.S., Woodbridge, J., and Filar, B. (2016, January 28). DeepDGA: Adversarially-tuned domain generation and detection. Proceedings of the 2016 ACM Workshop on Artificial Intelligence and Security, Vienna, Austria.","DOI":"10.1145\/2996758.2996767"},{"key":"ref_55","unstructured":"(2021, October 02). MaleVis Dataset Home Page. Available online: https:\/\/web.cs.hacettepe.edu.tr\/~selman\/malevis\/>."},{"key":"ref_56","doi-asserted-by":"crossref","first-page":"102166","DOI":"10.1016\/j.cose.2020.102166","article-title":"Catch them alive: A malware detection approach through memory forensics, manifold learning and computer vision","volume":"103","author":"Bozkir","year":"2021","journal-title":"Comput. Secur."},{"key":"ref_57","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1109\/ACCESS.2021.3089586","article-title":"A New Malware Classification Framework Based on Deep Learning Algorithms","volume":"9","author":"Aslan","year":"2021","journal-title":"IEEE Access"},{"key":"ref_58","doi-asserted-by":"crossref","unstructured":"Mills, A., Spyridopoulos, T., and Legg, P. (2019, January 3\u20134). Efficient and Interpretable Real-Time Malware Detection Using Random-Forest. Proceedings of the 2019 International Conference on Cyber Situational Awareness, Data Analytics and Assessment (Cyber SA), Oxford, UK.","DOI":"10.1109\/CyberSA.2019.8899533"},{"key":"ref_59","doi-asserted-by":"crossref","unstructured":"Morales-Molina, C.D., Santamaria-Guerrero, D., Sanchez-Perez, G., Perez-Meana, H., and Hernandez-Suarez, A. (2018, January 14\u201316). Methodology for Malware Classification using a Random Forest Classifier. Proceedings of the 2018 IEEE International Autumn Meeting on Power, Electronics and Computing (ROPEC), Guerrero, Mexico.","DOI":"10.1109\/ROPEC.2018.8661441"},{"key":"ref_60","doi-asserted-by":"crossref","unstructured":"Roseline, S.A., and Geetha, S. (2018, January 19). Intelligent Malware Detection using Oblique Random Forest Paradigm. Proceedings of the 2018 International Conference on Advances in Computing, Communications and Informatics (ICACCI), Bangalore, India.","DOI":"10.1109\/ICACCI.2018.8554903"},{"key":"ref_61","doi-asserted-by":"crossref","unstructured":"Ganesh, M., Pednekar, P., Prabhuswamy, P., Nair, D.S., Park, Y., and Jeon, H. (2017, January 24\u201325). CNN-Based Android Malware Detection. Proceedings of the 2017 International Conference on Software Security and Assurance (ICSSA), Altoona, PA, USA.","DOI":"10.1109\/ICSSA.2017.18"},{"key":"ref_62","doi-asserted-by":"crossref","first-page":"101748","DOI":"10.1016\/j.cose.2020.101748","article-title":"Image-Based malware classification using ensemble of CNN architectures (IMCEC)","volume":"92","author":"Vasan","year":"2020","journal-title":"Comput. Secur."},{"key":"ref_63","doi-asserted-by":"crossref","unstructured":"Pacheco, Y., and Sun, W. (2021, January 11\u201313). Adversarial Machine Learning: A Comparative Study on Contemporary Intrusion Detection Datasets. Proceedings of the 7th International Conference on Information Systems Security and Privacy, Austria, Vienna.","DOI":"10.5220\/0010253501600171"},{"key":"ref_64","doi-asserted-by":"crossref","first-page":"1075","DOI":"10.1109\/TVCG.2019.2934631","article-title":"Explaining Vulnerabilities to Adversarial Machine Learning through Visual Analytics. IEEE Trans","volume":"26","author":"Ma","year":"2020","journal-title":"Vis. Comput. Graph."},{"key":"ref_65","doi-asserted-by":"crossref","first-page":"346","DOI":"10.1016\/j.eng.2019.12.012","article-title":"Adversarial Attacks and Defenses in Deep Learning","volume":"6","author":"Ren","year":"2020","journal-title":"Engineering"},{"key":"ref_66","doi-asserted-by":"crossref","unstructured":"Xu, J. (2020, January 21\u201323). Generate Adversarial Examples by Nesterov-momentum Iterative Fast Gradient Sign Method. Proceedings of the 2020 IEEE 11th International Conference on Software Engineering and Service Science (ICSESS), Beijing, China.","DOI":"10.1109\/ICSESS49938.2020.9237700"},{"key":"ref_67","unstructured":"Huang, T., Menkovski, V., Pei, Y., and Pechenizkiy, M. (2020). Bridging the performance gap between fgsm and pgd adversarial training. arXiv."}],"container-title":["Algorithms"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1999-4893\/14\/10\/297\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T07:15:20Z","timestamp":1760166920000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1999-4893\/14\/10\/297"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,10,15]]},"references-count":67,"journal-issue":{"issue":"10","published-online":{"date-parts":[[2021,10]]}},"alternative-id":["a14100297"],"URL":"https:\/\/doi.org\/10.3390\/a14100297","relation":{},"ISSN":["1999-4893"],"issn-type":[{"value":"1999-4893","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,10,15]]}}}