{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,9,19]],"date-time":"2025-09-19T07:47:10Z","timestamp":1758268030336,"version":"3.44.0"},"publisher-location":"Cham","reference-count":34,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783032049773","type":"print"},{"value":"9783032049780","type":"electronic"}],"license":[{"start":{"date-parts":[[2025,9,19]],"date-time":"2025-09-19T00:00:00Z","timestamp":1758240000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,9,19]],"date-time":"2025-09-19T00:00:00Z","timestamp":1758240000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-3-032-04978-0_14","type":"book-chapter","created":{"date-parts":[[2025,9,18]],"date-time":"2025-09-18T16:16:15Z","timestamp":1758212175000},"page":"141-151","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["DGHFA: Dynamic Gradient and\u00a0Hierarchical Feature Alignment for\u00a0Robust Distillation of\u00a0Medical VLMs"],"prefix":"10.1007","author":[{"given":"Boyi","family":"Xiao","sequence":"first","affiliation":[]},{"given":"Jianghao","family":"Wu","sequence":"additional","affiliation":[]},{"given":"Lanfeng","family":"Zhong","sequence":"additional","affiliation":[]},{"given":"Xiaoguang","family":"Zou","sequence":"additional","affiliation":[]},{"given":"Yuanquan","family":"Wu","sequence":"additional","affiliation":[]},{"given":"Guotai","family":"Wang","sequence":"additional","affiliation":[]},{"given":"Shaoting","family":"Zhang","sequence":"additional","affiliation":[]}],"member":"297","published-online":{"date-parts":[[2025,9,19]]},"reference":[{"key":"14_CR1","unstructured":"Aggarwal, G., Sinha, A., Kumari, N., Singh, M.: On the benefits of models with perceptually-aligned gradients. arXiv preprint arXiv:2005.01499 (2020)"},{"key":"14_CR2","doi-asserted-by":"crossref","unstructured":"Carlini, N., Wagner, D.: Towards evaluating the robustness of neural networks. In: 2017 IEEE Symposium on Security and Privacy (SP), pp. 39\u201357. IEEE (2017)","DOI":"10.1109\/SP.2017.49"},{"key":"14_CR3","unstructured":"Croce, F., Hein, M.: Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks. In: International Conference on Machine Learning, pp. 2206\u20132216. PMLR (2020)"},{"key":"14_CR4","unstructured":"Fang, G., Song, J., Shen, C., Wang, X., Chen, D., Song, M.: Data-free adversarial distillation. arXiv preprint arXiv:1912.11006 (2019)"},{"key":"14_CR5","unstructured":"Ganz, R., Kawar, B., Elad, M.: Do perceptually aligned gradients imply robustness? In: International Conference on Machine Learning, pp. 10628\u201310648. PMLR (2023)"},{"key":"14_CR6","doi-asserted-by":"crossref","unstructured":"Goldblum, M., Fowl, L., Feizi, S., Goldstein, T.: Adversarially robust distillation. In: Proceedings of the AAAI Conference on Artificial Intelligence, vol.\u00a034, pp. 3996\u20134003 (2020)","DOI":"10.1609\/aaai.v34i04.5816"},{"key":"14_CR7","unstructured":"Goodfellow, I.J., Shlens, J., Szegedy, C.: Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572 (2014)"},{"issue":"6","key":"14_CR8","doi-asserted-by":"publisher","first-page":"1789","DOI":"10.1007\/s11263-021-01453-z","volume":"129","author":"J Gou","year":"2021","unstructured":"Gou, J., Yu, B., Maybank, S.J., Tao, D.: Knowledge distillation: a survey. Int. J. Comput. Vision 129(6), 1789\u20131819 (2021)","journal-title":"Int. J. Comput. Vision"},{"issue":"1","key":"14_CR9","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1038\/s43586-021-00018-1","volume":"1","author":"M Hafner","year":"2021","unstructured":"Hafner, M., et al.: Clip and complementary methods. Nat. Rev. Methods Primers 1(1), 1\u201323 (2021)","journal-title":"Nat. Rev. Methods Primers"},{"key":"14_CR10","unstructured":"He, B., Jia, X., Liang, S., Lou, T., Liu, Y., Cao, X.: Sa-attack: improving adversarial transferability of vision-language pre-training models via self-augmentation. arXiv preprint arXiv:2312.04913 (2023)"},{"key":"14_CR11","doi-asserted-by":"crossref","unstructured":"Huang, B., Chen, M., Wang, Y., Lu, J., Cheng, M., Wang, W.: Boosting accuracy and robustness of student models via adaptive adversarial distillation. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp. 24668\u201324677 (2023)","DOI":"10.1109\/CVPR52729.2023.02363"},{"key":"14_CR12","first-page":"5545","volume":"34","author":"H Huang","year":"2021","unstructured":"Huang, H., Wang, Y., Erfani, S., Gu, Q., Bailey, J., Ma, X.: Exploring architectural ingredients of adversarially robust deep neural networks. Adv. Neural. Inf. Process. Syst. 34, 5545\u20135559 (2021)","journal-title":"Adv. Neural. Inf. Process. Syst."},{"key":"14_CR13","doi-asserted-by":"publisher","unstructured":"Hussein, N., Shamshad, F., Naseer, M., Nandakumar, K.: Promptsmooth: Certifying robustness of medical vision-language models via prompt learning. In: International Conference on Medical Image Computing and Computer-Assisted Intervention, pp. 698\u2013708. Springer (2024). https:\/\/doi.org\/10.1007\/978-3-031-72390-2_65","DOI":"10.1007\/978-3-031-72390-2_65"},{"issue":"3","key":"14_CR14","doi-asserted-by":"publisher","first-page":"863","DOI":"10.1038\/s41591-024-02856-4","volume":"30","author":"MY Lu","year":"2024","unstructured":"Lu, M.Y., et al.: A visual-language foundation model for computational pathology. Nat. Med. 30(3), 863\u2013874 (2024)","journal-title":"Nat. Med."},{"key":"14_CR15","unstructured":"Ma, Y., Dong, M., Xu, C.: Adversarial robustness through random weight sampling. Adv. Neural Inform. Process. Syst. 36 (2024)"},{"key":"14_CR16","unstructured":"Madry, A., Makelov, A., Schmidt, L., Tsipras, D., Vladu, A.: Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083 (2017)"},{"key":"14_CR17","unstructured":"Maini, P., Wong, E., Kolter, Z.: Adversarial robustness against the union of multiple perturbation models. In: International Conference on Machine Learning, pp. 6640\u20136650. PMLR (2020)"},{"key":"14_CR18","doi-asserted-by":"crossref","unstructured":"Papernot, N., McDaniel, P., Wu, X., Jha, S., Swami, A.: Distillation as a defense to adversarial perturbations against deep neural networks. In: 2016 IEEE Symposium on Security and Privacy (SP), pp. 582\u2013597. IEEE (2016)","DOI":"10.1109\/SP.2016.41"},{"key":"14_CR19","doi-asserted-by":"publisher","unstructured":"Park, H., Min, D.: Dynamic guidance adversarial distillation with enhanced teacher knowledge. In: European Conference on Computer Vision. pp. 204\u2013219. Springer (2024). https:\/\/doi.org\/10.1007\/978-3-031-73220-1_12","DOI":"10.1007\/978-3-031-73220-1_12"},{"key":"14_CR20","doi-asserted-by":"crossref","unstructured":"Park, W., Kim, D., Lu, Y., Cho, M.: Relational knowledge distillation. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp. 3967\u20133976 (2019)","DOI":"10.1109\/CVPR.2019.00409"},{"key":"14_CR21","unstructured":"Radford, A., et\u00a0al.: Learning transferable visual models from natural language supervision. In: International Conference on Machine Learning, pp. 8748\u20138763. PMLR (2021)"},{"key":"14_CR22","unstructured":"Shi, C., Rezai, R., Yang, J., Dou, Q., Li, X.: A survey on trustworthiness in foundation models for medical image analysis. arXiv preprint arXiv:2407.15851 (2024)"},{"key":"14_CR23","unstructured":"Tsipras, D., Santurkar, S., Engstrom, L., Turner, A., Madry, A.: Robustness may be at odds with accuracy. arXiv preprint arXiv:1805.12152 (2018)"},{"key":"14_CR24","doi-asserted-by":"crossref","unstructured":"Wang, Z., Wu, Z., Agarwal, D., Sun, J.: Medclip: Contrastive learning from unpaired medical images and text. arXiv preprint arXiv:2210.10163 (2022)","DOI":"10.18653\/v1\/2022.emnlp-main.256"},{"key":"14_CR25","first-page":"7054","volume":"34","author":"B Wu","year":"2021","unstructured":"Wu, B., Chen, J., Cai, D., He, X., Gu, Q.: Do wider neural networks really help adversarial robustness? Adv. Neural. Inf. Process. Syst. 34, 7054\u20137067 (2021)","journal-title":"Adv. Neural. Inf. Process. Syst."},{"key":"14_CR26","doi-asserted-by":"crossref","unstructured":"Wu, K., et\u00a0al.: Tinyclip: clip distillation via affinity mimicking and weight inheritance. In: Proceedings of the IEEE\/CVF International Conference on Computer Vision, pp. 21970\u201321980 (2023)","DOI":"10.1109\/ICCV51070.2023.02008"},{"key":"14_CR27","unstructured":"Xie, C., Wang, J., Zhang, Z., Ren, Z., Yuille, A.: Mitigating adversarial effects through randomization. arXiv preprint arXiv:1711.01991 (2017)"},{"key":"14_CR28","doi-asserted-by":"crossref","unstructured":"Yin, S., Xiao, Z., Song, M., Long, J.: Adversarial distillation based on slack matching and attribution region alignment. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp. 24605\u201324614 (2024)","DOI":"10.1109\/CVPR52733.2024.02323"},{"key":"14_CR29","doi-asserted-by":"crossref","unstructured":"You, K., Gu, J., Ham, J., Park, B., Kim, J., Hong, E.K., Baek, W., Roh, B.: Cxr-clip: Toward large scale chest x-ray language-image pre-training. In: International Conference on Medical Image Computing and Computer-Assisted Intervention. pp. 101\u2013111. Springer (2023)","DOI":"10.1007\/978-3-031-43895-0_10"},{"key":"14_CR30","unstructured":"Zhang, H., Yu, Y., Jiao, J., Xing, E., El\u00a0Ghaoui, L., Jordan, M.: Theoretically principled trade-off between robustness and accuracy. In: International Conference on Machine Learning, pp. 7472\u20137482. PMLR (2019)"},{"key":"14_CR31","unstructured":"Zhang, J., et al.: Attacks which do not kill training make adversarial learning stronger. In: International Conference on Machine Learning, pp. 11278\u201311287. PMLR (2020)"},{"key":"14_CR32","unstructured":"Zhao, S., Wang, X., Wei, X.: Improving adversarial robust fairness via anti-bias soft label distillation. arXiv preprint arXiv:2312.05508 (2023)"},{"key":"14_CR33","doi-asserted-by":"crossref","unstructured":"Zhong, L., Liao, X., Zhang, S., Zhang, X., Wang, G.: Vlm-cpl: consensus pseudo labels from vision-language models for human annotation-free pathological image classification. arXiv preprint arXiv:2403.15836 (2024)","DOI":"10.1109\/TMI.2025.3595111"},{"key":"14_CR34","doi-asserted-by":"crossref","unstructured":"Zi, B., Zhao, S., Ma, X., Jiang, Y.G.: Revisiting adversarial robustness distillation: robust soft labels make student better. In: Proceedings of the IEEE\/CVF International Conference on Computer Vision, pp. 16443\u201316452 (2021)","DOI":"10.1109\/ICCV48922.2021.01613"}],"container-title":["Lecture Notes in Computer Science","Medical Image Computing and Computer Assisted Intervention \u2013 MICCAI 2025"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-032-04978-0_14","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,9,18]],"date-time":"2025-09-18T22:06:47Z","timestamp":1758233207000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-032-04978-0_14"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,9,19]]},"ISBN":["9783032049773","9783032049780"],"references-count":34,"URL":"https:\/\/doi.org\/10.1007\/978-3-032-04978-0_14","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,9,19]]},"assertion":[{"value":"19 September 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"The authors have no competing interests to declare that are relevant to the content of this article.","order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Disclosure of Interests"}},{"value":"MICCAI","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Medical Image Computing and Computer-Assisted Intervention","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Daejeon","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Korea (Republic of)","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"23 September 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"27 September 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"28","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"miccai2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/conferences.miccai.org\/2025\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}