{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,17]],"date-time":"2026-08-17T15:02:40Z","timestamp":1786978960156,"version":"build-2736575974"},"publisher-location":"Cham","reference-count":44,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031733895","type":"print"},{"value":"9783031733901","type":"electronic"}],"license":[{"start":{"date-parts":[[2024,10,31]],"date-time":"2024-10-31T00:00:00Z","timestamp":1730332800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,10,31]],"date-time":"2024-10-31T00:00:00Z","timestamp":1730332800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025]]},"DOI":"10.1007\/978-3-031-73390-1_9","type":"book-chapter","created":{"date-parts":[[2024,10,30]],"date-time":"2024-10-30T12:24:01Z","timestamp":1730291041000},"page":"144-160","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":8,"title":["Preventing Catastrophic Overfitting in Fast Adversarial Training: A Bi-level Optimization Perspective"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0009-0009-5860-8370","authenticated-orcid":false,"given":"Zhaoxin","family":"Wang","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4805-3780","authenticated-orcid":false,"given":"Handing","family":"Wang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5429-4580","authenticated-orcid":false,"given":"Cong","family":"Tian","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1100-0631","authenticated-orcid":false,"given":"Yaochu","family":"Jin","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2024,10,31]]},"reference":[{"key":"9_CR1","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"484","DOI":"10.1007\/978-3-030-58592-1_29","volume-title":"Computer Vision \u2013 ECCV 2020","author":"M Andriushchenko","year":"2020","unstructured":"Andriushchenko, M., Croce, F., Flammarion, N., Hein, M.: Square attack: a query-efficient black-box adversarial attack via random search. In: Vedaldi, A., Bischof, H., Brox, T., Frahm, J.-M. (eds.) ECCV 2020. LNCS, vol. 12368, pp. 484\u2013501. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-58592-1_29"},{"key":"9_CR2","first-page":"16048","volume":"33","author":"M Andriushchenko","year":"2020","unstructured":"Andriushchenko, M., Flammarion, N.: Understanding and improving fast adversarial training. Adv. Neural. Inf. Process. Syst. 33, 16048\u201316059 (2020)","journal-title":"Adv. Neural. Inf. Process. Syst."},{"key":"9_CR3","unstructured":"Brendel, W., Rauber, J., Bethge, M.: Decision-based adversarial attacks: Reliable attacks against black-box machine learning models. In: International Conference on Learning Representations (2018)"},{"key":"9_CR4","doi-asserted-by":"crossref","unstructured":"Carlini, N., Wagner, D.: Towards evaluating the robustness of neural networks. In: 2017 IEEE Symposium on Security and Privacy (SP). IEEE (2017)","DOI":"10.1109\/SP.2017.49"},{"key":"9_CR5","unstructured":"Chakraborty, A., Alam, M., Dey, V., Chattopadhyay, A., Mukhopadhyay, D.: Adversarial attacks and defences: A survey. arXiv preprint arXiv:1810.00069 (2018)"},{"key":"9_CR6","doi-asserted-by":"crossref","unstructured":"Chen, P.Y., Zhang, H., Sharma, Y., Yi, J., Hsieh, C.J.: Zoo: Zeroth order optimization based black-box attacks to deep neural networks without training substitute models. In: Proceedings of the 10th ACM Workshop on Artificial Intelligence and Security, pp. 15\u201326 (2017)","DOI":"10.1145\/3128572.3140448"},{"key":"9_CR7","doi-asserted-by":"publisher","first-page":"235","DOI":"10.1007\/s10479-007-0176-2","volume":"153","author":"B Colson","year":"2007","unstructured":"Colson, B., Marcotte, P., Savard, G.: An overview of bilevel optimization. Ann. Oper. Res. 153, 235\u2013256 (2007)","journal-title":"Ann. Oper. Res."},{"key":"9_CR8","unstructured":"Croce, F., Hein, M.: Minimally distorted adversarial examples with a fast adaptive boundary attack. In: International Conference on Machine Learning, pp. 2196\u20132205. PMLR (2020)"},{"key":"9_CR9","unstructured":"Croce, F., Hein, M.: Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks. In: International Conference on Machine Learning, pp. 2206\u20132216. PMLR (2020)"},{"key":"9_CR10","doi-asserted-by":"crossref","unstructured":"Dempe, S., Kalashnikov, V., P\u00e9rez-Vald\u00e9s, G.A., Kalashnykova, N.: Bilevel programming problems. Energy Syst. 10, 978\u20133 (2015)","DOI":"10.1007\/978-3-662-45827-3"},{"key":"9_CR11","doi-asserted-by":"crossref","unstructured":"Deng, J., Dong, W., Socher, R., Li, L.J., Li, K., Fei-Fei, L.: Imagenet: a large-scale hierarchical image database. In: 2009 IEEE Conference on Computer Vision and Pattern Recognition, pp. 248\u2013255. IEEE (2009)","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"9_CR12","doi-asserted-by":"crossref","unstructured":"Duan, R., et al.: Adversarial laser beam: Effective physical-world attack to dnns in a blink. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp. 16062\u201316071 (2021)","DOI":"10.1109\/CVPR46437.2021.01580"},{"key":"9_CR13","unstructured":"Goodfellow, I.J., Shlens, J., Szegedy, C.: Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572 (2014)"},{"key":"9_CR14","unstructured":"Gu, T., Dolan-Gavitt, B., Garg, S.: Badnets: Identifying vulnerabilities in the machine learning model supply chain. arXiv preprint arXiv:1708.06733 (2017)"},{"key":"9_CR15","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"630","DOI":"10.1007\/978-3-319-46493-0_38","volume-title":"Computer Vision \u2013 ECCV 2016","author":"K He","year":"2016","unstructured":"He, K., Zhang, X., Ren, S., Sun, J.: Identity mappings in deep residual networks. In: Leibe, B., Matas, J., Sebe, N., Welling, M. (eds.) ECCV 2016. LNCS, vol. 9908, pp. 630\u2013645. Springer, Cham (2016). https:\/\/doi.org\/10.1007\/978-3-319-46493-0_38"},{"key":"9_CR16","unstructured":"Ilyas, A., Engstrom, L., Athalye, A., Lin, J.: Black-box adversarial attacks with limited queries and information. In: International Conference on Machine Learning, pp. 2137\u20132146. PMLR (2018)"},{"key":"9_CR17","doi-asserted-by":"publisher","unstructured":"Jia, X., et al.: Prior-guided adversarial initialization for fast adversarial training. In: European Conference on Computer Vision. pp. 567\u2013584. Springer (2022). https:\/\/doi.org\/10.1007\/978-3-031-19772-7_3","DOI":"10.1007\/978-3-031-19772-7_3"},{"key":"9_CR18","first-page":"12881","volume":"35","author":"PO de Jorge Aranda","year":"2022","unstructured":"de Jorge Aranda, P.O., et al.: Make some noise: reliable and efficient single-step adversarial training. Adv. Neural. Inf. Process. Syst. 35, 12881\u201312893 (2022)","journal-title":"Adv. Neural. Inf. Process. Syst."},{"key":"9_CR19","doi-asserted-by":"crossref","unstructured":"Kim, H., Lee, W., Lee, J.: Understanding catastrophic overfitting in single-step adversarial training. In: Proceedings of the AAAI Conference on Artificial Intelligence, vol.\u00a035, pp. 8119\u20138127 (2021)","DOI":"10.1609\/aaai.v35i9.16989"},{"key":"9_CR20","unstructured":"Krizhevsky, A.: Learning multiple layers of features from tiny images (2009)"},{"key":"9_CR21","unstructured":"Li, Y., Jiang, Y., Li, Z., Xia, S.T.: Backdoor learning: a survey. IEEE Trans. Neural Netw. Learn. Syst. (2022)"},{"key":"9_CR22","doi-asserted-by":"publisher","first-page":"4566","DOI":"10.1109\/ACCESS.2020.3045078","volume":"9","author":"X Liu","year":"2020","unstructured":"Liu, X., et al.: Privacy and security issues in deep learning: a survey. IEEE Access 9, 4566\u20134593 (2020)","journal-title":"IEEE Access"},{"key":"9_CR23","unstructured":"Madry, A., Makelov, A., Schmidt, L., Tsipras, D., Vladu, A.: Towards deep learning models resistant to adversarial attacks. In: International Conference on Learning Representations (2018)"},{"key":"9_CR24","unstructured":"Mao, C., Zhong, Z., Yang, J., Vondrick, C., Ray, B.: Metric learning for adversarial robustness. Adv. Neural Inform. Process. Syst. 32 (2019)"},{"key":"9_CR25","doi-asserted-by":"crossref","unstructured":"Moosavi-Dezfooli, S.M., Fawzi, A., Frossard, P.: Deepfool: a simple and accurate method to fool deep neural networks. In: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, pp. 2574\u20132582 (2016)","DOI":"10.1109\/CVPR.2016.282"},{"key":"9_CR26","doi-asserted-by":"crossref","unstructured":"Moosavi-Dezfooli, S.M., Fawzi, A., Uesato, J., Frossard, P.: Robustness via curvature regularization, and vice versa. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp. 9078\u20139086 (2019)","DOI":"10.1109\/CVPR.2019.00929"},{"key":"9_CR27","unstructured":"Pang, T., Yang, X., Dong, Y., Su, H., Zhu, J.: Bag of tricks for adversarial training. arXiv preprint arXiv:2010.00467 (2020)"},{"key":"9_CR28","unstructured":"Qin, C., et al.: Adversarial robustness through local linearization. Adv. Neural Inform. Process. Syst. 32 (2019)"},{"key":"9_CR29","unstructured":"Rice, L., Wong, E., Kolter, Z.: Overfitting in adversarially robust deep learning. In: International Conference on Machine Learning, pp. 8093\u20138104. PMLR (2020)"},{"key":"9_CR30","unstructured":"Rocamora, E.A., Liu, F., Chrysos, G., Olmos, P.M., Cevher, V.: Efficient local linearity regularization to overcome catastrophic overfitting. In: The Twelfth International Conference on Learning Representations (2024)"},{"key":"9_CR31","unstructured":"Shafahi, A., et al.: Adversarial training for free! Adv. Neural Inform. Process. Syst. 32 (2019)"},{"key":"9_CR32","doi-asserted-by":"crossref","unstructured":"Shokri, R., Stronati, M., Song, C., Shmatikov, V.: Membership inference attacks against machine learning models. In: 2017 IEEE Symposium on Security and Privacy (SP), pp. 3\u201318. IEEE (2017)","DOI":"10.1109\/SP.2017.41"},{"key":"9_CR33","doi-asserted-by":"crossref","unstructured":"Smith, L.N.: Cyclical learning rates for training neural networks. In: 2017 IEEE winter conference on applications of computer vision (WACV), pp. 464\u2013472. IEEE (2017)","DOI":"10.1109\/WACV.2017.58"},{"key":"9_CR34","unstructured":"Szegedy, C., et al.: Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199 (2013)"},{"key":"9_CR35","unstructured":"Wang, Y., Zou, D., Yi, J., Bailey, J., Ma, X., Gu, Q.: Improving adversarial robustness requires revisiting misclassified examples. In: International Conference on Learning Representations (2019)"},{"key":"9_CR36","unstructured":"Wang, Z., Pang, T., Du, C., Lin, M., Liu, W., Yan, S.: Better diffusion models further improve adversarial training. arXiv preprint arXiv:2302.04638 (2023)"},{"key":"9_CR37","doi-asserted-by":"crossref","unstructured":"Wang, Z., Wang, H., Tian, C., Jin, Y.: Adversarial training of deep neural networks guided by texture and structural information. In: Proceedings of the 31st ACM International Conference on Multimedia, pp. 4958\u20134967 (2023)","DOI":"10.1145\/3581783.3612163"},{"key":"9_CR38","unstructured":"Wong, E., Rice, L., Kolter, J.Z.: Fast is better than free: Revisiting adversarial training. Learning (2020)"},{"key":"9_CR39","doi-asserted-by":"crossref","unstructured":"Zagoruyko, S., Komodakis, N.: Wide residual networks. arXiv: Computer Vision and Pattern Recognition (2016)","DOI":"10.5244\/C.30.87"},{"key":"9_CR40","unstructured":"Zhang, D., Zhang, T., Lu, Y., Zhu, Z., Dong, B.: You only propagate once: Accelerating adversarial training via maximal principle. Adv. Neural Inform. Process. Syst. 32 (2019)"},{"key":"9_CR41","unstructured":"Zhang, H., Yu, Y., Jiao, J., Xing, E., El\u00a0Ghaoui, L., Jordan, M.: Theoretically principled trade-off between robustness and accuracy. In: International Conference on Machine Learning, pp. 7472\u20137482. PMLR (2019)"},{"key":"9_CR42","unstructured":"Zhang, Y., Zhang, G., Khanduri, P., Hong, M., Chang, S., Liu, S.: Revisiting and advancing fast adversarial training through the lens of bi-level optimization (2022)"},{"key":"9_CR43","doi-asserted-by":"crossref","unstructured":"Zhao, M., Zhang, L., Kong, Y., Yin, B.: Fast adversarial training with smooth convergence. In: Proceedings of the IEEE\/CVF International Conference on Computer Vision, pp. 4720\u20134729 (2023)","DOI":"10.1109\/ICCV51070.2023.00435"},{"key":"9_CR44","unstructured":"Zhu, L., Liu, Z., Han, S.: Deep leakage from gradients. Adv. Neural Inform. Process. Syst. 32 (2019)"}],"container-title":["Lecture Notes in Computer Science","Computer Vision \u2013 ECCV 2024"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-73390-1_9","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,10,30]],"date-time":"2024-10-30T12:28:40Z","timestamp":1730291320000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-73390-1_9"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,10,31]]},"ISBN":["9783031733895","9783031733901"],"references-count":44,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-73390-1_9","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,10,31]]},"assertion":[{"value":"31 October 2024","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ECCV","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"European Conference on Computer Vision","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Milan","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Italy","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2024","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"29 September 2024","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"4 October 2024","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"18","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"eccv2024","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/eccv2024.ecva.net\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}