{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,8]],"date-time":"2026-05-08T21:36:36Z","timestamp":1778276196164,"version":"3.51.4"},"reference-count":63,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"National Key Research and Development Plan of China","award":["2020AAA0103502"],"award-info":[{"award-number":["2020AAA0103502"]}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62022009"],"award-info":[{"award-number":["62022009"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61872021"],"award-info":[{"award-number":["61872021"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. on Image Process."],"published-print":{"date-parts":[[2021]]},"DOI":"10.1109\/tip.2020.3042083","type":"journal-article","created":{"date-parts":[[2020,12,9]],"date-time":"2020-12-09T04:18:31Z","timestamp":1607487511000},"page":"1291-1304","source":"Crossref","is-referenced-by-count":84,"title":["Interpreting and Improving Adversarial Robustness of Deep Neural Networks With Neuron Sensitivity"],"prefix":"10.1109","volume":"30","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-1378-322X","authenticated-orcid":false,"given":"Chongzhi","family":"Zhang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4224-1318","authenticated-orcid":false,"given":"Aishan","family":"Liu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8425-4195","authenticated-orcid":false,"given":"Xianglong","family":"Liu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yitao","family":"Xu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7858-8789","authenticated-orcid":false,"given":"Hang","family":"Yu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1936-9396","authenticated-orcid":false,"given":"Yuqing","family":"Ma","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2207-1622","authenticated-orcid":false,"given":"Tianlin","family":"Li","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2020.2993098"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00928"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58555-6_17"},{"key":"ref32","article-title":"Intriguing properties of neural networks","author":"szegedy","year":"2013","journal-title":"arXiv 1312 6199"},{"key":"ref31","article-title":"Robustness may be at odds with accuracy","author":"tsipras","year":"2018","journal-title":"arXiv 1805 12152"},{"key":"ref30","article-title":"Interpreting adversarial examples by activation promotion and suppression","author":"xu","year":"2019","journal-title":"arXiv 1904 02057"},{"key":"ref37","article-title":"Adversarial examples are not bugs, they are features","author":"ilyas","year":"2019","journal-title":"arXiv 1905 02175"},{"key":"ref36","article-title":"Towards interpretable deep neural networks by leveraging adversarial examples","author":"dong","year":"2017","journal-title":"arXiv 1708 05493"},{"key":"ref35","first-page":"395","article-title":"Bias-based universal adversarial patch attack for automatic check-out","author":"liu","year":"2020","journal-title":"Proc Eur Conf Comput Vis"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58520-4_8"},{"key":"ref60","first-page":"1","article-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","author":"athalye","year":"2018","journal-title":"Proc 35th Int Conf Mach Learn"},{"key":"ref62","first-page":"13255","article-title":"A Fourier perspective on model robustness in computer vision","author":"yin","year":"2019","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2018.04.027"},{"key":"ref63","article-title":"Are all layers created equal?","author":"zhang","year":"2019","journal-title":"arXiv 1902 01996"},{"key":"ref28","first-page":"5498","article-title":"The odds are odd: A statistical test for detecting adversarial examples","author":"roth","year":"2019","journal-title":"Proc 36th Int Conf Mach Learn"},{"key":"ref27","article-title":"On detecting adversarial perturbations","author":"metzen","year":"2017","journal-title":"arXiv 1702 04267"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23198"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2017.2669880"},{"key":"ref1","first-page":"1","article-title":"Imagenet classification with deep convolutional neural networks","author":"krizhevsky","year":"2012","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref20","first-page":"1","article-title":"Countering adversarial images using input transformations","author":"guo","year":"2018","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2018.2839891"},{"key":"ref21","article-title":"Mitigating adversarial effects through randomization","author":"xie","year":"2017","journal-title":"arXiv 1711 01991"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00191"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.41"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.56"},{"key":"ref25","article-title":"Training robust deep neural networks via adversarial noise propagation","author":"liu","year":"2019","journal-title":"arXiv 1909 09034"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-015-0816-y"},{"key":"ref51","first-page":"1","article-title":"Very deep convolutional networks for large-scale image recognition","author":"simonyan","year":"2015","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref59","article-title":"Adversarial logit pairing","author":"kannan","year":"2018","journal-title":"arXiv 1803 06373"},{"key":"ref58","first-page":"487","article-title":"Learning deep features for scene recognition using places database","author":"zhou","year":"2014","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref57","first-page":"818","article-title":"Visualizing and understanding convolutional networks","author":"zeiler","year":"2014","journal-title":"Proc Eur Conf Comput Vis (ECCV)"},{"key":"ref56","first-page":"1","article-title":"Benchmarking neural network robustness to common corruptions and perturbations","author":"hendrycks","year":"2019","journal-title":"Proc Int Conf Learn Represent (ICLR)ICLR"},{"key":"ref55","first-page":"3866","article-title":"NATTACK: Learning the distributions of adversarial examples for an improved black-box attack on deep neural networks","author":"li","year":"2019","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref54","first-page":"5025","article-title":"Adversarial risk and the dangers of evaluating against weak attacks","author":"uesato","year":"2018","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.308"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/TMM.2019.2949872"},{"key":"ref12","first-page":"2484","article-title":"Simple black-box adversarial attacks","author":"guo","year":"2019","journal-title":"Proc 34th Int Conf Mach Learn"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2019.2948472"},{"key":"ref14","article-title":"Adversarial examples in the physical world","author":"kurakin","year":"2016","journal-title":"arXiv 1607 02533"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.33011028"},{"key":"ref16","first-page":"1","article-title":"Physical adversarial examples for object detectors","author":"song","year":"2018","journal-title":"Proc WOOT"},{"key":"ref17","article-title":"Adversarial machine learning at scale","author":"kurakin","year":"2016","journal-title":"arXiv 1611 01236"},{"key":"ref18","article-title":"Towards deep learning models resistant to adversarial attacks","author":"madry","year":"2017","journal-title":"arXiv 1706 06083"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2017.2662206"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2019.2895460"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2018.2794218"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/TASL.2011.2109382"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2019.2952690"},{"key":"ref8","first-page":"3104","article-title":"Sequence to sequence learning with neural networks","author":"sutskever","year":"2014","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.3115\/v1\/D14-1082"},{"key":"ref49","article-title":"Learning multiple layers of features from tiny images","author":"krizhevsky","year":"2009"},{"key":"ref9","article-title":"Explaining and harnessing adversarial examples","author":"goodfellow","year":"2014","journal-title":"arXiv 1412 6572"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.354"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1038\/89044"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1007\/s10994-011-5268-1"},{"key":"ref47","first-page":"1","article-title":"Object detectors emerge in deep scene CNNs","author":"zhou","year":"2015","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref42","article-title":"Characterizing adversarial subspaces using local intrinsic dimensionality","author":"ma","year":"2018","journal-title":"arXiv 1801 02613"},{"key":"ref41","article-title":"DeepFense: Online accelerated defense against adversarial deep learning","author":"darvish rouhani","year":"2017","journal-title":"arXiv 1709 02538"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1016\/S0957-4174(98)00041-4"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1016\/j.dsp.2017.10.011"}],"container-title":["IEEE Transactions on Image Processing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/83\/9263394\/09286885.pdf?arnumber=9286885","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,5,10]],"date-time":"2022-05-10T14:50:18Z","timestamp":1652194218000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9286885\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021]]},"references-count":63,"URL":"https:\/\/doi.org\/10.1109\/tip.2020.3042083","relation":{},"ISSN":["1057-7149","1941-0042"],"issn-type":[{"value":"1057-7149","type":"print"},{"value":"1941-0042","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021]]}}}