{"id":"https://openalex.org/W4407782565","doi":"https://doi.org/10.1109/access.2025.3544107","title":"Evaluating Pretrained Deep Learning Models for Image Classification Against Individual and Ensemble Adversarial Attacks","display_name":"Evaluating Pretrained Deep Learning Models for Image Classification Against Individual and Ensemble Adversarial Attacks","publication_year":2025,"publication_date":"2025-01-01","ids":{"openalex":"https://openalex.org/W4407782565","doi":"https://doi.org/10.1109/access.2025.3544107"},"language":"en","primary_location":{"id":"doi:10.1109/access.2025.3544107","is_oa":true,"landing_page_url":"https://doi.org/10.1109/access.2025.3544107","pdf_url":null,"source":{"id":"https://openalex.org/S2485537415","display_name":"IEEE Access","issn_l":"2169-3536","issn":["2169-3536"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Access","raw_type":"journal-article"},"type":"article","indexed_in":["crossref","doaj"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://doi.org/10.1109/access.2025.3544107","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5100876112","display_name":"Mafizur Rahman","orcid":"https://orcid.org/0009-0007-4870-0232"},"institutions":[{"id":"https://openalex.org/I250520410","display_name":"Prairie View A&M University","ror":"https://ror.org/0449kf092","country_code":"US","type":"education","lineage":["https://openalex.org/I250520410"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Mafizur Rahman","raw_affiliation_strings":["Department of Computer Science, Prairie View A&#x0026;M University, Prairie View, TX, USA","Department of Computer Science, Prairie View A &#x0026; M University, Prairie View, Texas, USA"],"raw_orcid":"https://orcid.org/0009-0007-4870-0232","affiliations":[{"raw_affiliation_string":"Department of Computer Science, Prairie View A&#x0026;M University, Prairie View, TX, USA","institution_ids":["https://openalex.org/I250520410"]},{"raw_affiliation_string":"Department of Computer Science, Prairie View A &#x0026; M University, Prairie View, Texas, USA","institution_ids":["https://openalex.org/I250520410"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Prosenjit Roy","orcid":"https://orcid.org/0009-0004-0563-3656"},"institutions":[{"id":"https://openalex.org/I250520410","display_name":"Prairie View A&M University","ror":"https://ror.org/0449kf092","country_code":"US","type":"education","lineage":["https://openalex.org/I250520410"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Prosenjit Roy","raw_affiliation_strings":["Department of Computer Science, Prairie View A&#x0026;M University, Prairie View, TX, USA","Department of Computer Science, Prairie View A &#x0026; M University, Prairie View, Texas, USA"],"raw_orcid":"https://orcid.org/0009-0004-0563-3656","affiliations":[{"raw_affiliation_string":"Department of Computer Science, Prairie View A&#x0026;M University, Prairie View, TX, USA","institution_ids":["https://openalex.org/I250520410"]},{"raw_affiliation_string":"Department of Computer Science, Prairie View A &#x0026; M University, Prairie View, Texas, USA","institution_ids":["https://openalex.org/I250520410"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5064164109","display_name":"Sherri Frizell","orcid":null},"institutions":[{"id":"https://openalex.org/I250520410","display_name":"Prairie View A&M University","ror":"https://ror.org/0449kf092","country_code":"US","type":"education","lineage":["https://openalex.org/I250520410"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Sherri S. Frizell","raw_affiliation_strings":["Department of Computer Science, Prairie View A&#x0026;M University, Prairie View, TX, USA","Department of Computer Science, Prairie View A &#x0026; M University, Prairie View, Texas, USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Department of Computer Science, Prairie View A&#x0026;M University, Prairie View, TX, USA","institution_ids":["https://openalex.org/I250520410"]},{"raw_affiliation_string":"Department of Computer Science, Prairie View A &#x0026; M University, Prairie View, Texas, USA","institution_ids":["https://openalex.org/I250520410"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5085031765","display_name":"Lijun Qian","orcid":"https://orcid.org/0000-0003-1577-3359"},"institutions":[{"id":"https://openalex.org/I250520410","display_name":"Prairie View A&M University","ror":"https://ror.org/0449kf092","country_code":"US","type":"education","lineage":["https://openalex.org/I250520410"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Lijun Qian","raw_affiliation_strings":["CREDIT Center, Prairie View A&#x0026;M University, Prairie View, TX, USA","CREDIT Center and Department of Electrical and Computer Engineering, Prairie View A &#x0026; M University, Prairie View, Texas, USA"],"raw_orcid":"https://orcid.org/0000-0003-1577-3359","affiliations":[{"raw_affiliation_string":"CREDIT Center, Prairie View A&#x0026;M University, Prairie View, TX, USA","institution_ids":["https://openalex.org/I250520410"]},{"raw_affiliation_string":"CREDIT Center and Department of Electrical and Computer Engineering, Prairie View A &#x0026; M University, Prairie View, Texas, USA","institution_ids":["https://openalex.org/I250520410"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5100876112"],"corresponding_institution_ids":["https://openalex.org/I250520410"],"apc_list":{"value":1850,"currency":"USD","value_usd":1850},"apc_paid":{"value":1850,"currency":"USD","value_usd":1850},"fwci":32.3695,"has_fulltext":false,"cited_by_count":16,"citation_normalized_percentile":{"value":0.99607429,"is_in_top_1_percent":true,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":99,"max":100},"biblio":{"volume":"13","issue":null,"first_page":"35230","last_page":"35242"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9991000294685364,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9991000294685364,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9745000004768372,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11515","display_name":"Bacillus and Francisella bacterial research","score":0.9531999826431274,"subfield":{"id":"https://openalex.org/subfields/1312","display_name":"Molecular Biology"},"field":{"id":"https://openalex.org/fields/13","display_name":"Biochemistry, Genetics and Molecular Biology"},"domain":{"id":"https://openalex.org/domains/1","display_name":"Life Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.805370569229126},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7719110250473022},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.6905144453048706},{"id":"https://openalex.org/keywords/deep-learning","display_name":"Deep learning","score":0.5762287974357605},{"id":"https://openalex.org/keywords/contextual-image-classification","display_name":"Contextual image classification","score":0.559653639793396},{"id":"https://openalex.org/keywords/image","display_name":"Image (mathematics)","score":0.5443529486656189},{"id":"https://openalex.org/keywords/ensemble-learning","display_name":"Ensemble learning","score":0.5062260031700134},{"id":"https://openalex.org/keywords/pattern-recognition","display_name":"Pattern recognition (psychology)","score":0.4894973039627075},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.4746159613132477}],"concepts":[{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.805370569229126},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7719110250473022},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.6905144453048706},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.5762287974357605},{"id":"https://openalex.org/C75294576","wikidata":"https://www.wikidata.org/wiki/Q5165192","display_name":"Contextual image classification","level":3,"score":0.559653639793396},{"id":"https://openalex.org/C115961682","wikidata":"https://www.wikidata.org/wiki/Q860623","display_name":"Image (mathematics)","level":2,"score":0.5443529486656189},{"id":"https://openalex.org/C45942800","wikidata":"https://www.wikidata.org/wiki/Q245652","display_name":"Ensemble learning","level":2,"score":0.5062260031700134},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.4894973039627075},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.4746159613132477}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1109/access.2025.3544107","is_oa":true,"landing_page_url":"https://doi.org/10.1109/access.2025.3544107","pdf_url":null,"source":{"id":"https://openalex.org/S2485537415","display_name":"IEEE Access","issn_l":"2169-3536","issn":["2169-3536"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Access","raw_type":"journal-article"},{"id":"pmh:oai:doaj.org/article:1b1b69a4277640008aabc506ba238102","is_oa":true,"landing_page_url":"https://doaj.org/article/1b1b69a4277640008aabc506ba238102","pdf_url":null,"source":{"id":"https://openalex.org/S4306401280","display_name":"DOAJ (DOAJ: Directory of Open Access Journals)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by-sa","license_id":"https://openalex.org/licenses/cc-by-sa","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"IEEE Access, Vol 13, Pp 35230-35242 (2025)","raw_type":"article"}],"best_oa_location":{"id":"doi:10.1109/access.2025.3544107","is_oa":true,"landing_page_url":"https://doi.org/10.1109/access.2025.3544107","pdf_url":null,"source":{"id":"https://openalex.org/S2485537415","display_name":"IEEE Access","issn_l":"2169-3536","issn":["2169-3536"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Access","raw_type":"journal-article"},"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/10","score":0.41999998688697815,"display_name":"Reduced inequalities"}],"awards":[{"id":"https://openalex.org/G3269630641","display_name":null,"funder_award_id":"W911NF-23-1-0214","funder_id":"https://openalex.org/F4320338281","funder_display_name":"Army Research Office"},{"id":"https://openalex.org/G3294896131","display_name":null,"funder_award_id":"W911NF-24-2-0133","funder_id":"https://openalex.org/F4320338281","funder_display_name":"Army Research Office"}],"funders":[{"id":"https://openalex.org/F4320338281","display_name":"Army Research Office","ror":"https://ror.org/05epdh915"}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":44,"referenced_works":["https://openalex.org/W2067050450","https://openalex.org/W2095577883","https://openalex.org/W2243397390","https://openalex.org/W2539093944","https://openalex.org/W2618492571","https://openalex.org/W2620038827","https://openalex.org/W2773474358","https://openalex.org/W2774644650","https://openalex.org/W2896078964","https://openalex.org/W2960833983","https://openalex.org/W2963231286","https://openalex.org/W2963302614","https://openalex.org/W2963516603","https://openalex.org/W2971545525","https://openalex.org/W2979878901","https://openalex.org/W2997127238","https://openalex.org/W2997532515","https://openalex.org/W2998279441","https://openalex.org/W3044456020","https://openalex.org/W3116676518","https://openalex.org/W3129287621","https://openalex.org/W3210909185","https://openalex.org/W3211999566","https://openalex.org/W3212790025","https://openalex.org/W3215206150","https://openalex.org/W4200625937","https://openalex.org/W4281735938","https://openalex.org/W4295136046","https://openalex.org/W4313141826","https://openalex.org/W4317812176","https://openalex.org/W4379806140","https://openalex.org/W4386066309","https://openalex.org/W4386939494","https://openalex.org/W4392154946","https://openalex.org/W4396542737","https://openalex.org/W4396667585","https://openalex.org/W6640425456","https://openalex.org/W6714069269","https://openalex.org/W6769581535","https://openalex.org/W6784750986","https://openalex.org/W6846476709","https://openalex.org/W6857282637","https://openalex.org/W6862179994","https://openalex.org/W6869727074"],"related_works":["https://openalex.org/W2502115930","https://openalex.org/W2482350142","https://openalex.org/W4246396837","https://openalex.org/W3126451824","https://openalex.org/W1561927205","https://openalex.org/W3191453585","https://openalex.org/W3124943098","https://openalex.org/W4308112567","https://openalex.org/W3162132941","https://openalex.org/W2795259429"],"abstract_inverted_index":{"The":[0,65],"robustness":[1,24],"of":[2,17,25,83,94,132,154],"Deep":[3],"Neural":[4],"Networks":[5],"(DNNs)":[6],"against":[7],"adversarial":[8,35,96,103,111,141,176],"attacks":[9,104,108,142],"is":[10,127],"an":[11],"important":[12],"topic":[13],"in":[14,91],"the":[15,23,39,61,92,114,130,133,138,152,155,163,173,184],"area":[16],"deep":[18],"learning.":[19],"To":[20],"fully":[21],"investigate":[22],"DNNs,":[26],"this":[27],"study":[28],"examines":[29],"four":[30],"frequently":[31],"used":[32],"white":[33],"box":[34],"attack":[36],"techniques,":[37],"namely,":[38],"Fast":[40],"Gradient":[41,46],"Sign":[42],"Method":[43,51],"(FGSM),":[44],"Projected":[45],"Descent":[47],"(PGD),":[48],"Basic":[49],"Iterative":[50],"(BIM),":[52],"DeepFool,":[53],"and":[54,70,119],"their":[55,87],"effects":[56],"on":[57],"DNN":[58,78,123,158],"models":[59,79],"for":[60,109,122],"image":[62],"classification":[63],"task.":[64],"results":[66],"show":[67],"that":[68,129,159],"ResNet152":[69],"DenseNet201":[71],"are":[72],"less":[73],"vulnerable":[74],"comparing":[75,178],"to":[76,80,179],"other":[77],"a":[81],"variety":[82],"individual":[84,107,185],"attacks,":[85,177],"highlighting":[86],"intrinsic":[88],"strength":[89],"even":[90,143],"lack":[93],"specific":[95],"training.":[97],"Further,":[98],"we":[99,160],"propose":[100],"two":[101],"ensemble":[102,140,175],"combining":[105],"three":[106],"generating":[110],"examples":[112],"from":[113],"tiny":[115],"ImageNet,":[116],"CIFAR-10,":[117],"CIFAR-100,":[118],"SVHN":[120],"datasets":[121],"model":[124],"evaluation.":[125],"It":[126],"observed":[128],"performance":[131],"DNNs":[134],"deteriorate":[135],"significantly":[136],"under":[137,172,183],"proposed":[139,174],"after":[144],"defensive":[145],"measures":[146],"have":[147],"been":[148],"applied.":[149],"For":[150],"instance,":[151],"accuracy":[153],"most":[156],"robust":[157],"tested,":[161],"namely":[162],"defense":[164],"distillation":[165],"enhanced":[166],"DenseNet201,":[167],"dropped":[168],"more":[169],"than":[170],"59%":[171],"only":[180],"34%":[181],"decrease":[182],"attacks.":[186]},"counts_by_year":[{"year":2026,"cited_by_count":7},{"year":2025,"cited_by_count":9}],"updated_date":"2026-05-10T08:33:47.465468","created_date":"2025-10-10T00:00:00"}
