{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,19]],"date-time":"2026-06-19T15:51:22Z","timestamp":1781884282177,"version":"3.54.5"},"publisher-location":"Cham","reference-count":45,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031200823","type":"print"},{"value":"9783031200830","type":"electronic"}],"license":[{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2022]]},"DOI":"10.1007\/978-3-031-20083-0_28","type":"book-chapter","created":{"date-parts":[[2022,11,2]],"date-time":"2022-11-02T19:46:34Z","timestamp":1667418394000},"page":"467-483","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":5,"title":["$$\\ell _\\infty $$-Robustness and\u00a0Beyond: Unleashing Efficient Adversarial Training"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-9418-1487","authenticated-orcid":false,"given":"Hadi M.","family":"Dolatabadi","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0885-0643","authenticated-orcid":false,"given":"Sarah","family":"Erfani","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4388-0517","authenticated-orcid":false,"given":"Christopher","family":"Leckie","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2022,11,3]]},"reference":[{"issue":"1","key":"28_CR1","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1186\/s40537-021-00419-9","volume":"8","author":"A Adadi","year":"2021","unstructured":"Adadi, A.: A survey on data-efficient algorithms in big data era. J. Big Data 8(1), 1\u201354 (2021). https:\/\/doi.org\/10.1186\/s40537-021-00419-9","journal-title":"J. Big Data"},{"key":"28_CR2","unstructured":"Andriushchenko, M., Flammarion, N.: Understanding and improving fast adversarial training. In: Proceedings of the Advances in Neural Information Processing Systems 33: Annual Conference on Neural Information Processing Systems (NeurIPS) (2020)"},{"key":"28_CR3","series-title":"Lecture Notes in Computer Science (Lecture Notes in Artificial Intelligence)","doi-asserted-by":"publisher","first-page":"387","DOI":"10.1007\/978-3-642-40994-3_25","volume-title":"Machine Learning and Knowledge Discovery in Databases","author":"B Biggio","year":"2013","unstructured":"Biggio, B., Corona, I., Maiorca, D., Nelson, B., \u0160rndi\u0107, N., Laskov, P., Giacinto, G., Roli, F.: Evasion attacks against machine learning at test time. In: Blockeel, H., Kersting, K., Nijssen, S., \u017delezn\u00fd, F. (eds.) ECML PKDD 2013. LNCS (LNAI), vol. 8190, pp. 387\u2013402. Springer, Heidelberg (2013). https:\/\/doi.org\/10.1007\/978-3-642-40994-3_25"},{"key":"28_CR4","unstructured":"Campbell, T., Broderick, T.: Bayesian coreset construction via greedy iterative geodesic ascent. In: Proceedings of the 35th International Conference on Machine Learning (ICML), pp. 697\u2013705 (2018)"},{"key":"28_CR5","unstructured":"Croce, F., Hein, M.: Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks. In: Proceedings of the 37th International Conference on Machine Learning (ICML), pp. 2206\u20132216 (2020)"},{"key":"28_CR6","doi-asserted-by":"publisher","unstructured":"Danskin, J.M.: The Theory of Max-min and its Application to Weapons Allocation Problems, vol. 5. Springer Science & Business Media (1967). https:\/\/doi.org\/10.1007\/978-3-642-46092-0","DOI":"10.1007\/978-3-642-46092-0"},{"key":"28_CR7","unstructured":"Elenberg, E.R., Khanna, R., Dimakis, A.G., Negahban, S.N.: Restricted strong convexity implies weak submodularity. CoRR abs\/1612.00804 (2016)"},{"key":"28_CR8","doi-asserted-by":"crossref","unstructured":"Eykholt, K., et al.: Robust physical-world attacks on deep learning visual classification. In: Proceeding of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR), pp. 1625\u20131634 (2018)","DOI":"10.1109\/CVPR.2018.00175"},{"key":"28_CR9","unstructured":"Feldman, D.: Introduction to core-sets: an updated survey. CoRR abs\/2011.09384 (2020)"},{"key":"28_CR10","unstructured":"Goodfellow, I.J., Shlens, J., Szegedy, C.: Explaining and harnessing adversarial examples. In: Proceedings of the 3rd International Conference on Learning Representations (ICLR) (2015)"},{"key":"28_CR11","doi-asserted-by":"crossref","unstructured":"Har-Peled, S., Mazumdar, S.: On coresets for k-means and k-median clustering. In: Proceedings of the 36th Annual ACM Symposium on Theory of Computing (STOC), pp. 291\u2013300 (2004)","DOI":"10.1145\/1007352.1007400"},{"key":"28_CR12","doi-asserted-by":"crossref","unstructured":"He, K., Zhang, X., Ren, S., Sun, J.: Deep residual learning for image recognition. In: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR), pp. 770\u2013778 (2016)","DOI":"10.1109\/CVPR.2016.90"},{"key":"28_CR13","unstructured":"Kang, D., Sun, Y., Hendrycks, D., Brown, T., Steinhardt, J.: Testing robustness against unforeseen adversaries. CoRR abs\/1908.08016 (2019)"},{"key":"28_CR14","doi-asserted-by":"crossref","unstructured":"Karras, T., Laine, S., Aittala, M., Hellsten, J., Lehtinen, J., Aila, T.: Analyzing and improving the image quality of stylegan. In: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR), pp. 8107\u20138116 (2020)","DOI":"10.1109\/CVPR42600.2020.00813"},{"key":"28_CR15","unstructured":"Katharopoulos, A., Fleuret, F.: Not all samples are created equal: Deep learning with importance sampling. In: Proceedings of the 35th International Conference on Machine Learning (ICML), pp. 2530\u20132539 (2018)"},{"key":"28_CR16","unstructured":"Killamsetty, K., Sivasubramanian, D., Ramakrishnan, G., De, A., Iyer, R.K.: GRAD-MATCH: gradient matching based data subset selection for efficient deep model training. In: Proceedings of the 38th International Conference on Machine Learning (ICML), pp. 5464\u20135474 (2021)"},{"key":"28_CR17","doi-asserted-by":"crossref","unstructured":"Killamsetty, K., Sivasubramanian, D., Ramakrishnan, G., Iyer, R.K.: GLISTER: generalization based data subset selection for efficient and robust learning. In: Proceedings of the 35th AAAI Conference on Artificial Intelligence, pp. 8110\u20138118 (2021)","DOI":"10.1609\/aaai.v35i9.16988"},{"key":"28_CR18","unstructured":"Kolter, Z., Madry, A.: Adversarial robustness: theory and practice. In: Tutorial in the Advances in Neural Information Processing Systems 31: Annual Conference on Neural Information Processing Systems (NeurIPS) (2018). https:\/\/adversarial-ml-tutorial.org\/"},{"key":"28_CR19","unstructured":"Krizhevsky, A., Hinton, G.: Learning multiple layers of features from tiny images. Master\u2019s thesis, Department of Computer Science, University of Toronto (2009)"},{"key":"28_CR20","unstructured":"Krizhevsky, A., Sutskever, I., Hinton, G.E.: ImageNet classification with deep convolutional neural networks. In: Proceedings of the Advances in Neural Information Processing Systems 25: Annual Conference on Neural Information Processing Systems (NeurIPS), pp. 1106\u20131114 (2012)"},{"key":"28_CR21","unstructured":"Laidlaw, C., Feizi, S.: Functional adversarial attacks. In: Proceedings of the Advances in Neural Information Processing Systems 32: Annual Conference on Neural Information Processing Systems (NeurIPS), pp. 10408\u201310418 (2019)"},{"key":"28_CR22","unstructured":"Laidlaw, C., Singla, S., Feizi, S.: Perceptual adversarial robustness: defense against unseen threat models. In: Proceedings of the 9th International Conference on Learning Representations (ICLR) (2021)"},{"key":"28_CR23","doi-asserted-by":"publisher","unstructured":"Liu, Y., Ma, X., Bailey, J., Lu, F.: Reflection backdoor: a natural backdoor attack on deep neural networks. In: Proceedings of the 16th European Conference on Computer Vision (ECCV), pp. 182\u2013199 (2020). https:\/\/doi.org\/10.1007\/978-3-030-58607-2_11","DOI":"10.1007\/978-3-030-58607-2_11"},{"key":"28_CR24","doi-asserted-by":"crossref","unstructured":"Ma, X., et al.: Understanding adversarial attacks on deep learning based medical image analysis systems. Pattern Recogn. 110, 107332 (2021)","DOI":"10.1016\/j.patcog.2020.107332"},{"key":"28_CR25","unstructured":"Madry, A., Makelov, A., Schmidt, L., Tsipras, D., Vladu, A.: Towards deep learning models resistant to adversarial attacks. In: Proceedings of the 6th International Conference on Learning Representations (ICLR) (2018)"},{"key":"28_CR26","doi-asserted-by":"publisher","unstructured":"Minoux, M.: Accelerated greedy algorithms for maximizing submodular set functions. In: Optimization Techniques, pp. 234\u2013243. Springer (1978). https:\/\/doi.org\/10.1007\/BFb0006528","DOI":"10.1007\/BFb0006528"},{"key":"28_CR27","unstructured":"Mirzasoleiman, B., Bilmes, J.A., Leskovec, J.: Coresets for data-efficient training of machine learning models. In: Proceedings of the 37th International Conference on Machine Learning (ICML), pp. 6950\u20136960 (2020)"},{"key":"28_CR28","unstructured":"Mirzasoleiman, B., Cao, K., Leskovec, J.: Coresets for robust training of deep neural networks against noisy labels. In: Proceedings of the Advances in Neural Information Processing Systems 33: Annual Conference on Neural Information Processing Systems (NeurIPS) (2020)"},{"issue":"1","key":"28_CR29","doi-asserted-by":"publisher","first-page":"265","DOI":"10.1007\/BF01588971","volume":"14","author":"GL Nemhauser","year":"1978","unstructured":"Nemhauser, G.L., Wolsey, L.A., Fisher, M.L.: An analysis of approximations for maximizing submodular set functions - I. Math. Program. 14(1), 265\u2013294 (1978). https:\/\/doi.org\/10.1007\/BF01588971","journal-title":"Math. Program."},{"key":"28_CR30","unstructured":"Netzer, Y., Wang, T., Coates, A., Bissacco, A., Wu, B., Ng, A.Y.: Reading digits in natural images with unsupervised feature learning. In: NeurIPS Workshop on Deep Learning and Unsupervised Feature Learning (2011)"},{"key":"28_CR31","unstructured":"Pati, Y.C., Rezaiifar, R., Krishnaprasad, P.S.: Orthogonal matching pursuit: recursive function approximation with applications to wavelet decomposition. In: Proceedings of 27th Asilomar Conference on Signals, Systems and Computers, vol. 1, pp. 40\u201344 (1993)"},{"issue":"3","key":"28_CR32","doi-asserted-by":"publisher","first-page":"211","DOI":"10.1007\/s11263-015-0816-y","volume":"115","author":"O Russakovsky","year":"2015","unstructured":"Russakovsky, O., et al.: ImageNet large scale visual recognition challenge. Int. J. Comput. Vis. (IJCV) 115(3), 211\u2013252 (2015). https:\/\/doi.org\/10.1007\/s11263-015-0816-y","journal-title":"Int. J. Comput. Vis. (IJCV)"},{"key":"28_CR33","doi-asserted-by":"crossref","unstructured":"Schwartz, R., Dodge, J., Smith, N.A., Etzioni, O.: Green AI. Commun. ACM, 63(12), 54\u201363 (2020)","DOI":"10.1145\/3381831"},{"key":"28_CR34","doi-asserted-by":"crossref","unstructured":"Strubell, E., Ganesh, A., McCallum, A.: Energy and policy considerations for deep learning in NLP. In: Korhonen, A., Traum, D.R., M\u00e0rquez, L. (eds.) Proceedings of the 57th Conference of the Association for Computational Linguistics (ACL), pp. 3645\u20133650 (2019)","DOI":"10.18653\/v1\/P19-1355"},{"key":"28_CR35","unstructured":"Szegedy, C., et al.: Intriguing properties of neural networks. In: Proceedings of the 2nd International Conference on Learning Representations (ICLR) (2014)"},{"key":"28_CR36","unstructured":"Tram\u00e8r, F., Kurakin, A., Papernot, N., Goodfellow, I.J., Boneh, D., McDaniel, P.D.: Ensemble adversarial training: Attacks and defenses. In: Proceedings of the 6th International Conference on Learning Representations (ICLR) (2018)"},{"key":"28_CR37","unstructured":"Tsipras, D., Santurkar, S., Engstrom, L., Turner, A., Madry, A.: Robustness may be at odds with accuracy. In: Proceedings of the 7th International Conference on Learning Representations (ICLR) (2019)"},{"key":"28_CR38","unstructured":"Vahdat, A., Kautz, J.: NVAE: a deep hierarchical variational autoencoder. In: Proceedings of the Advances in Neural Information Processing Systems 33: Annual Conference on Neural Information Processing Systems (NeurIPS) (2020)"},{"key":"28_CR39","unstructured":"Wei, K., Iyer, R., Bilmes, J.: Submodularity in data subset selection and active learning. In: Proceedings of the 32nd International Conference on Machine Learning (ICML), pp. 1954\u20131963 (2015)"},{"issue":"4","key":"28_CR40","doi-asserted-by":"publisher","first-page":"385","DOI":"10.1007\/BF02579435","volume":"2","author":"LA Wolsey","year":"1982","unstructured":"Wolsey, L.A.: An analysis of the greedy algorithm for the submodular set covering problem. Combinatorica 2(4), 385\u2013393 (1982). https:\/\/doi.org\/10.1007\/BF02579435","journal-title":"Combinatorica"},{"key":"28_CR41","unstructured":"Wong, E., Rice, L., Kolter, J.Z.: Fast is better than free: revisiting adversarial training. In: Proceedings of the 8th International Conference on Learning Representations (ICLR) (2020)"},{"key":"28_CR42","unstructured":"Wu, Y., Kirillov, A., Massa, F., Lo, W.Y., Girshick, R.: Detectron2 (2019). https:\/\/github.com\/facebookresearch\/detectron2"},{"key":"28_CR43","unstructured":"Xiao, C., Zhu, J., Li, B., He, W., Liu, M., Song, D.: Spatially transformed adversarial examples. In: Proceedings of the 6th International Conference on Learning Representations (ICLR) (2018)"},{"key":"28_CR44","unstructured":"Zhang, H., Yu, Y., Jiao, J., Xing, E.P., Ghaoui, L.E., Jordan, M.I.: Theoretically principled trade-off between robustness and accuracy. In: Proceedings of the 36th International Conference on Machine Learning (ICML), pp. 7472\u20137482 (2019)"},{"key":"28_CR45","doi-asserted-by":"crossref","unstructured":"Zhang, R., Isola, P., Efros, A.A., Shechtman, E., Wang, O.: The unreasonable effectiveness of deep features as a perceptual metric. In: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR), pp. 586\u2013595 (2018)","DOI":"10.1109\/CVPR.2018.00068"}],"container-title":["Lecture Notes in Computer Science","Computer Vision \u2013 ECCV 2022"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-20083-0_28","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,3,13]],"date-time":"2024-03-13T12:03:53Z","timestamp":1710331433000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-20083-0_28"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022]]},"ISBN":["9783031200823","9783031200830"],"references-count":45,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-20083-0_28","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022]]},"assertion":[{"value":"3 November 2022","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ECCV","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"European Conference on Computer Vision","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Tel Aviv","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Israel","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2022","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"23 October 2022","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"27 October 2022","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"17","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"eccv2022","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/eccv2022.ecva.net\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"CMT","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"5804","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"1645","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"28% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3.21","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3.91","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}