{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,2,21]],"date-time":"2025-02-21T12:34:41Z","timestamp":1740141281715,"version":"3.37.3"},"reference-count":41,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2019,1,1]],"date-time":"2019-01-01T00:00:00Z","timestamp":1546300800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61872274"],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Dependable and Secure Comput."],"published-print":{"date-parts":[[2019]]},"DOI":"10.1109\/tdsc.2019.2929047","type":"journal-article","created":{"date-parts":[[2019,7,30]],"date-time":"2019-07-30T20:06:15Z","timestamp":1564517175000},"page":"1-1","source":"Crossref","is-referenced-by-count":19,"title":["Invisible Adversarial Attack against Deep Neural Networks: An Adaptive Penalization Approach"],"prefix":"10.1109","author":[{"given":"Zhibo","family":"Wang","sequence":"first","affiliation":[]},{"given":"Mengkai","family":"Song","sequence":"additional","affiliation":[]},{"given":"Siyan","family":"Zheng","sequence":"additional","affiliation":[]},{"given":"Zhifei","family":"Zhang","sequence":"additional","affiliation":[]},{"given":"Yang","family":"Song","sequence":"additional","affiliation":[]},{"given":"Qian","family":"Wang","sequence":"additional","affiliation":[]}],"member":"263","reference":[{"article-title":"Keras","year":"2015","author":"chollet","key":"ref39"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1371\/journal.pone.0157986"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1167\/14.7.4"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1167\/7.2.17"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.308"},{"key":"ref37","first-page":"1","article-title":"Learning multiple layers of features from tiny images","author":"krizhevsky","year":"2009"},{"article-title":"The mnist database of handwritten digits","year":"1998","author":"lecun","key":"ref36"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/TCSVT.2005.848313"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1049\/iet-ipr:20080034"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/MCOM.2019.1900006"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.632"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978392"},{"key":"ref12","first-page":"1","article-title":"Adversarial perturbations against deep neural networks for malware classification","author":"grosse","year":"2016","journal-title":"arXiv 1606 04435"},{"key":"ref13","first-page":"1","article-title":"Adversarial examples in the physical world","author":"kurakin","year":"2016","journal-title":"arXiv 1607 02533"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2018.00041"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW.2018.00210"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/5.241504"},{"key":"ref18","first-page":"1","article-title":"Delving into transferable adversarial examples and black-box attacks","author":"liu","year":"2017","journal-title":"Proc ICLR"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-40994-3_25"},{"key":"ref4","first-page":"1097","article-title":"Imagenet classification with deep convolutional neural networks","author":"krizhevsky","year":"2012","journal-title":"Proc Neural Inf Process Syst"},{"key":"ref27","doi-asserted-by":"crossref","first-page":"311","DOI":"10.7551\/mitpress\/10761.003.0012","article-title":"Adversarial perturbations of deep neural networks","author":"warde-farley","year":"2016","journal-title":"Perturbation Optimization and Statistics"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/TIM.2018.2792848"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2012.2205597"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.41"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/P16-1231"},{"key":"ref8","first-page":"1","article-title":"Intriguing properties of neural networks","author":"szegedy","year":"2013","journal-title":"arXiv 1312 6199"},{"key":"ref7","first-page":"1","article-title":"Explaining and harnessing adversarial examples","author":"goodfellow","year":"2015","journal-title":"Proc ICLR"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1161\/CIRCULATIONAHA.115.001593"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/MWC.2019.1800477"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/MPOT.2017.2737200"},{"key":"ref20","first-page":"1","article-title":"Learning with a strong adversary","author":"huang","year":"2015","journal-title":"arXiv 1511 03034"},{"key":"ref22","first-page":"1","article-title":"One pixel attack for fooling deep neural networks","author":"su","year":"2017","journal-title":"arXiv 1710 08864"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"ref24","first-page":"1","article-title":"Spatially transformed adversarial examples","author":"xiao","year":"2018","journal-title":"ArXiv 1801 02612"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-46487-9_40"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2018\/543"},{"key":"ref26","first-page":"1","article-title":"On the suitability of $ l\\_p$l_p-norms for creating and preventing adversarial examples","author":"sharif","year":"2018","journal-title":"arXiv 1802 09653"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW.2016.58"}],"container-title":["IEEE Transactions on Dependable and Secure Computing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/8858\/4358699\/08781934.pdf?arnumber=8781934","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,9,18]],"date-time":"2023-09-18T17:54:10Z","timestamp":1695059650000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/8781934\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019]]},"references-count":41,"URL":"https:\/\/doi.org\/10.1109\/tdsc.2019.2929047","relation":{},"ISSN":["1545-5971","1941-0018","2160-9209"],"issn-type":[{"type":"print","value":"1545-5971"},{"type":"electronic","value":"1941-0018"},{"type":"electronic","value":"2160-9209"}],"subject":[],"published":{"date-parts":[[2019]]}}}