{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,2,21]],"date-time":"2025-02-21T12:34:55Z","timestamp":1740141295540,"version":"3.37.3"},"reference-count":20,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"2","license":[{"start":{"date-parts":[[2019,3,1]],"date-time":"2019-03-01T00:00:00Z","timestamp":1551398400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2019,3,1]],"date-time":"2019-03-01T00:00:00Z","timestamp":1551398400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2019,3,1]],"date-time":"2019-03-01T00:00:00Z","timestamp":1551398400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Secur. Privacy"],"published-print":{"date-parts":[[2019,3]]},"DOI":"10.1109\/msec.2018.2888779","type":"journal-article","created":{"date-parts":[[2019,3,29]],"date-time":"2019-03-29T18:37:01Z","timestamp":1553884621000},"page":"31-38","source":"Crossref","is-referenced-by-count":33,"title":["Safe Machine Learning and Defeating Adversarial Attacks"],"prefix":"10.1109","volume":"17","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-8412-4320","authenticated-orcid":false,"given":"Bita","family":"Darvish Rouani","sequence":"first","affiliation":[{"name":"Research, Microsoft, United States"}]},{"given":"Mohammad","family":"Samragh","sequence":"additional","affiliation":[{"name":"Electrical and Computer Engineering and Microelectronics, University of California San Diego, United States"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7112-1043","authenticated-orcid":false,"given":"Tara","family":"Javidi","sequence":"additional","affiliation":[{"name":"Electrical and Computer Engineering and Microelectronics, University of California San Diego, United States"}]},{"given":"Farinaz","family":"Koushanfar","sequence":"additional","affiliation":[{"name":"Electrical and Computer Engineering and Microelectronics, University of California San Diego, United States"}]}],"member":"263","reference":[{"article-title":"Towards deep learning models resistant to adversarial attacks","year":"2017","author":"madry","key":"ref13"},{"article-title":"MagNet and “efficient defenses against adversarial attacks","year":"2017","author":"carlini","key":"ref12"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140449"},{"article-title":"APE-GAN: Adversarial perturbation elimination with GAN","year":"2017","author":"shen","key":"ref14"},{"key":"ref2-sidebar1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134057"},{"article-title":"Defensive distillation is not robust to adversarial examples","year":"2016","author":"carlini","key":"ref10"},{"article-title":"Robust convolutional neural networks under adversarial noise","year":"2015","author":"jin","key":"ref2"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1145\/3240765.3240791"},{"key":"ref3-sidebar1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"article-title":"Practical black-box attacks against deep learning systems using adversarial examples","year":"2016","author":"papernot","key":"ref16"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"article-title":"Distributional smoothing with virtual adversarial training","year":"2015","author":"miyato","key":"ref7"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.41"},{"article-title":"Understanding adversarial training: Increasing local stability of neural nets through robust optimization","year":"2015","author":"shaham","key":"ref4"},{"article-title":"Learning with a strong adversary","year":"2015","author":"huang","key":"ref3"},{"article-title":"Towards deep neural network architectures robust to adversarial examples","year":"2014","author":"gu","key":"ref6"},{"article-title":"Intriguing properties of neural networks","year":"2013","author":"szegedy","key":"ref5"},{"article-title":"CleverHans v2.0.0: An adversarial machine learning library","year":"2017","author":"papernot","key":"ref4-sidebar1"},{"article-title":"Explaining and harnessing adversarial examples","year":"2014","author":"goodfellow","key":"ref1-sidebar1"}],"container-title":["IEEE Security & Privacy"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/8013\/8677281\/08677311.pdf?arnumber=8677311","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,2,23]],"date-time":"2023-02-23T21:28:20Z","timestamp":1677187700000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/8677311\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,3]]},"references-count":20,"journal-issue":{"issue":"2"},"URL":"https:\/\/doi.org\/10.1109\/msec.2018.2888779","relation":{},"ISSN":["1540-7993","1558-4046"],"issn-type":[{"type":"print","value":"1540-7993"},{"type":"electronic","value":"1558-4046"}],"subject":[],"published":{"date-parts":[[2019,3]]}}}