| [1] |
CHAKRABORTY A, ALAM M, DEY V, et al. Adversarial attacks and defences: A survey [J]. 2018.
|
| [2] |
张思思, 左信, 计算机学报 刘 J. 深度学习中的对抗样本问题 [J]. 2019, 42 (8): 1886-904.
|
| [3] |
SZEGEDY C, ZAREMBA W, SUTSKEVER I, et al. Intriguing properties of neural networks [J]. 2013.
|
| [4] |
GOODFELLOW I J, SHLENS J, SZEGEDY C J A P A. Explaining and harnessing adversarial examples [J]. 2014.
|
| [5] |
GUO C, RANA M, CISSE M, et al. Countering adversarial images using input transformations [J]. 2017.
|
| [6] |
HE Z, RAKIN A S, FAN D. Parametric noise injection: Trainable randomness to improve deep neural network robustness against adversarial attack; proceedings of the Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition, F, 2019 [C].
|
| [7] |
LIAO F, LIANG M, DONG Y, et al. Defense against adversarial attacks using high-level representation guided denoiser; proceedings of the Proceedings of the IEEE conference on computer vision and pattern recognition, F, 2018 [C].
|
| [8] |
XIE C, WANG J, ZHANG Z, et al. Mitigating adversarial effects through randomization [J]. 2017.
|
| [9] |
MIRZA M, OSINDERO S J A P A. Conditional generative adversarial nets [J]. 2014.
|
| [10] |
SHEN S, JIN G, GAO K, et al. Ape-gan: Adversarial perturbation elimination with gan [J]. 2017.
|
| [11] |
SAMANGOUEI P, KABKAB M, CHELLAPPA R J A P A. Defense-gan: Protecting classifiers against adversarial attacks using generative models [J]. 2018.
|
| [12] |
MUSTAFA A, KHAN S H, HAYAT M, et al. Image super-resolution as a defense against adversarial attacks [J]. 2019, 29: 1711-24.
|
| [13] |
MOOSAVI-DEZFOOLI S-M, FAWZI A, FROSSARD P. Deepfool: a simple and accurate method to fool deep neural networks; proceedings of the Proceedings of the IEEE conference on computer vision and pattern recognition, F, 2016 [C].
|
| [14] |
MADRY A, MAKELOV A, SCHMIDT L, et al. Towards deep learning models resistant to adversarial attacks [J]. 2017.
|
| [15] |
NASEER M, KHAN S, HAYAT M, et al. A self-supervised approach for adversarial robustness; proceedings of the Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition, F, 2020 [C].
|
| [16] |
TRAMèR F, KURAKIN A, PAPERNOT N, et al. Ensemble adversarial training: Attacks and defenses [J]. 2017.
|
| [17] |
KABILAN V M, MORRIS B, NGUYEN H-P, et al. Vectordefense: Vectorization as a defense to adversarial examples [M]. Soft Computing for Biomedical Applications and Related Topics. Springer. 2021: 19-35.
|
| [18] |
DAS N, SHANBHOGUE M, CHEN S-T, et al. Keeping the bad guys out: Protecting and vaccinating deep learning with jpeg compression [J]. 2017.
|
| [19] |
HINTON G, VINYALS O, DEAN J J A P A. Distilling the knowledge in a neural network [J]. 2015, 2 (7).
|
| [20] |
LIN Y K, WANG C F, CHANG C-Y, et al. An efficient framework for counting pedestrians crossing a line using low-cost devices: the benefits of distilling the knowledge in a neural network [J]. 2021, 80 (3): 4037-51.
|
| [21] |
LEE H, HAN S, LEE J J A P A. Generative adversarial trainer: Defense to adversarial perturbations with gan [J]. 2017.
|
| [22] |
ZHOU J, LIANG C, CHEN J. Manifold projection for adversarial defense on face recognition; proceedings of the European Conference on Computer Vision, F, 2020 [C]. Springer.
|
| [23] |
ZHU J, SHI L, YAN J, et al. Automix: Mixup networks for sample interpolation via cooperative barycenter learning; proceedings of the European Conference on Computer Vision, F, 2020 [C]. Springer.
|
| [24] |
SIMONYAN K, ZISSERMAN A J A P A. Very deep convolutional networks for large-scale image recognition [J]. 2014.
|
| [25] |
NeurIPS Challenge [Z]. Kaggle. 2017.
|