{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,9,4]],"date-time":"2024-09-04T00:25:25Z","timestamp":1725409525546},"reference-count":27,"publisher":"IEEE","license":[{"start":{"date-parts":[[2024,5,27]],"date-time":"2024-05-27T00:00:00Z","timestamp":1716768000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2024,5,27]],"date-time":"2024-05-27T00:00:00Z","timestamp":1716768000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2024,5,27]]},"DOI":"10.1109\/isbi56570.2024.10635644","type":"proceedings-article","created":{"date-parts":[[2024,8,22]],"date-time":"2024-08-22T17:49:54Z","timestamp":1724348994000},"page":"1-5","source":"Crossref","is-referenced-by-count":0,"title":["Nowhere to Hide: Toward Robust Reactive Medical Adversarial Defense"],"prefix":"10.1109","author":[{"given":"Qingsong","family":"Yao","sequence":"first","affiliation":[{"name":"Institute of Computing Technology,Chinese Academy of Science"}]},{"given":"Zecheng","family":"He","sequence":"additional","affiliation":[{"name":"Institute of Computing Technology,Chinese Academy of Science"}]},{"given":"Xiaodong","family":"Yu","sequence":"additional","affiliation":[{"name":"Institute of Computing Technology,Chinese Academy of Science"}]},{"given":"S. Kevin","family":"Zhou","sequence":"additional","affiliation":[{"name":"Institute of Computing Technology,Chinese Academy of Science"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140444"},{"key":"ref2","article-title":"On adaptive attacks to adversarial example defenses","author":"Tramer","year":"2020","journal-title":"NIPS"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-87199-4_4"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/TMI.2023.3335098"},{"key":"ref5","article-title":"Intriguing properties of neural networks","author":"Szegedy","year":"2014","journal-title":"ICLR"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-32245-8_34"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-87199-4_1"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-00928-1_56"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1126\/science.aaw4399"},{"article-title":"A study of the effect of JPG compression on adversarial images","year":"2016","author":"Dziugaite","key":"ref10"},{"key":"ref11","article-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","author":"Athalye","year":"2018","journal-title":"ICLR"},{"key":"ref12","article-title":"Ensemble adversarial training: Attacks and defenses","author":"Tram\u00e8r","year":"2018","journal-title":"ICLR"},{"key":"ref13","article-title":"Robustness may be at odds with accuracy","author":"Tsipras","year":"2019","journal-title":"ICLR"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2020.107332"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/ISBI45749.2020.9098628"},{"article-title":"Adversarial manipulation of deep representations","volume-title":"Proc. - IEEE Symp. Secur. Priv","author":"Sabour","key":"ref16"},{"article-title":"Detecting adversarial samples from artifacts","year":"2017","author":"Feinman","key":"ref17"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.06083"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00444"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00284"},{"key":"ref21","article-title":"Explaining and harnessing adversarial examples","author":"Goodfellow","year":"2015","journal-title":"ICLR"},{"key":"ref22","article-title":"Adversarial machine learning at scale","author":"Kurakin","year":"2017","journal-title":"ICLR"},{"key":"ref23","first-page":"7167","article-title":"A simple unified framework for detecting out-of-distribution samples and adversarial attacks","author":"Lee","year":"2018","journal-title":"NIPS"},{"key":"ref24","article-title":"Characterizing adversarial subspaces using local intrinsic dimensionality","author":"Ma","year":"2018","journal-title":"ICLR"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref27","first-page":"2206","article-title":"Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks","volume-title":"International Conference on machine learning","author":"Croce"}],"event":{"name":"2024 IEEE International Symposium on Biomedical Imaging (ISBI)","start":{"date-parts":[[2024,5,27]]},"location":"Athens, Greece","end":{"date-parts":[[2024,5,30]]}},"container-title":["2024 IEEE International Symposium on Biomedical Imaging (ISBI)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/10635099\/10635102\/10635644.pdf?arnumber=10635644","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,9,3]],"date-time":"2024-09-03T05:25:51Z","timestamp":1725341151000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10635644\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,5,27]]},"references-count":27,"URL":"https:\/\/doi.org\/10.1109\/isbi56570.2024.10635644","relation":{},"subject":[],"published":{"date-parts":[[2024,5,27]]}}}