{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,5]],"date-time":"2026-06-05T04:50:28Z","timestamp":1780635028873,"version":"3.54.1"},"reference-count":62,"publisher":"Springer Science and Business Media LLC","issue":"10","license":[{"start":{"date-parts":[[2022,9,9]],"date-time":"2022-09-09T00:00:00Z","timestamp":1662681600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2022,9,9]],"date-time":"2022-09-09T00:00:00Z","timestamp":1662681600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/501100001775","name":"University of Technology Sydney","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100001775","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Data61 CSIRO"},{"DOI":"10.13039\/501100001774","name":"The University of Sydney","doi-asserted-by":"crossref","id":[{"id":"10.13039\/501100001774","id-type":"DOI","asserted-by":"crossref"}]},{"DOI":"10.13039\/501100001775","name":"University of Technology Sydney","doi-asserted-by":"crossref","id":[{"id":"10.13039\/501100001775","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Mach Learn"],"published-print":{"date-parts":[[2023,10]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>Deep Neural Networks (DNNs) have recently achieved great success in many classification tasks. Unfortunately, they are vulnerable to adversarial attacks that generate adversarial examples with a small perturbation to fool DNN models, especially in model sharing scenarios. Adversarial training is proved to be the most effective strategy that injects adversarial examples into model training to improve the robustness of DNN models against adversarial attacks. However, adversarial training based on the existing adversarial examples fails to generalize well to standard, unperturbed test data. To achieve a better trade-off between standard accuracy and adversarial robustness, we propose a novel adversarial training framework called <jats:italic>LAtent bounDary-guided aDvErsarial tRaining<\/jats:italic> (LADDER) that adversarially trains DNN models on latent boundary-guided adversarial examples. As opposed to most of the existing methods that generate adversarial examples in the input space, LADDER generates a myriad of high-quality adversarial examples through adding perturbations to latent features. The perturbations are made along the normal of the decision boundary constructed by an SVM with an attention mechanism. We analyze the merits of our generated boundary-guided adversarial examples from a boundary field perspective and visualization view. Extensive experiments and detailed analysis on MNIST, SVHN, CelebA, and CIFAR-10 validate the effectiveness of LADDER in achieving a better trade-off between standard accuracy and adversarial robustness as compared with vanilla DNNs and competitive baselines.<\/jats:p>","DOI":"10.1007\/s10994-022-06203-x","type":"journal-article","created":{"date-parts":[[2022,9,9]],"date-time":"2022-09-09T21:03:00Z","timestamp":1662757380000},"page":"3851-3879","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":9,"title":["LADDER:\u00a0Latent boundary-guided adversarial training"],"prefix":"10.1007","volume":"112","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-5871-2762","authenticated-orcid":false,"given":"Xiaowei","family":"Zhou","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ivor W.","family":"Tsang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jie","family":"Yin","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2022,9,9]]},"reference":[{"key":"6203_CR1","doi-asserted-by":"publisher","unstructured":"Alikaniotis, D., Yannakoudakis, H., & Rei, M. (2016). Automatic text scoring using neural networks. In ACL (Vol. 1, pp. 715\u2013725, Long Papers), Association for Computational Linguistics, https:\/\/doi.org\/10.18653\/v1\/P16-1068","DOI":"10.18653\/v1\/P16-1068"},{"key":"6203_CR2","unstructured":"Amazon. (2019). Machine learning on aws. Retrieved Feb 22, 2019 from https:\/\/aws.amazon.com\/machine-learning\/."},{"key":"6203_CR3","unstructured":"Amodei, D., Ananthanarayanan, S., Anubhai, R., Bai, J., Battenberg, E., Case, C., Casper, J., Catanzaro, B., Cheng, Q., Chen, G., & Chen, J. (2016). Deep speech 2: End-to-end speech recognition in english and mandarin. In ICML (pp. 173\u2013182)."},{"key":"6203_CR4","doi-asserted-by":"crossref","unstructured":"Andriushchenko, M., Croce, F., Flammarion, N., & Hein, M. (2020). Square attack: A query-efficient black-box adversarial attack via random search. In: ECCV (pp. 484\u2013501). Springer.","DOI":"10.1007\/978-3-030-58592-1_29"},{"key":"6203_CR5","doi-asserted-by":"crossref","unstructured":"Boser, B. E., Guyon, I. M., & Vapnik, V. N. (1992) A training algorithm for optimal margin classifiers. In: Proceedings of the fifth annual workshop on computational learning theory (pp. 144\u2013152) ACM.","DOI":"10.1145\/130385.130401"},{"key":"6203_CR6","doi-asserted-by":"crossref","unstructured":"Carlini, N., & Wagner, D (2017). Towards evaluating the robustness of neural networks. In: 2017 IEEE symposium on security and privacy (SP) (pp. 39\u201357) IEEE.","DOI":"10.1109\/SP.2017.49"},{"key":"6203_CR7","unstructured":"Croce, F., & Hein, M. (2020a). Minimally distorted adversarial examples with a fast adaptive boundary attack. In: ICML (pp. 2196\u20132205). PMLR."},{"key":"6203_CR8","unstructured":"Croce, F., & Hein, M. (2020b). Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks. In: ICML (pp. 2206\u20132216). PMLR."},{"key":"6203_CR9","doi-asserted-by":"crossref","unstructured":"Dai, T., Feng, Y., Wu, D., Chen, B., Lu, J., Jiang, Y., & Xia, S. T. (2020). Dipdefend: Deep image prior driven defense against adversarial examples. In: ACM MM (pp. 1404\u20131412).","DOI":"10.1145\/3394171.3413898"},{"key":"6203_CR10","unstructured":"Ding, G., Sharma, Y., Lui K. Y. C., & Huang, R. (2020). Mma training: Direct input space margin maximization through adversarial training. In: ICLR."},{"key":"6203_CR11","unstructured":"Dlib. (2019). Dlib python library. Retrieved May 20, 2019 from http:\/\/dlib.net\/."},{"key":"6203_CR12","unstructured":"Fedus, W., Goodfellow, I., & Dai, A. M. (2018) Maskgan: Better text generation via filling in the_. In: ICLR."},{"key":"6203_CR13","unstructured":"Goodfellow, I. J., Shlens, J., & Szegedy, C. (2015). Explaining and harnessing adversarial examples. In: ICLR."},{"key":"6203_CR14","first-page":"2672","volume":"27","author":"I Goodfellow","year":"2014","unstructured":"Goodfellow, I., Pouget-Abadie, J., Mirza, M., Xu, B., Warde-Farley, D., Ozair, S., et al. (2014). Generative adversarial nets. NIPS, 27, 2672\u20132680.","journal-title":"NIPS"},{"key":"6203_CR15","unstructured":"Google. (2019). Cloud vision. Retrieved Feb 22, 2019 from https:\/\/cloud.google.com\/vision\/."},{"key":"6203_CR16","unstructured":"Guo, C., Rana, M., Cisse, M., & van\u00a0der Maaten, L. (2018). Countering adversarial images using input transformations. In: ICLR."},{"key":"6203_CR17","doi-asserted-by":"crossref","unstructured":"Huang, G., Liu, Z., Van Der\u00a0Maaten, L., & Weinberger, K. Q. (2017). Densely connected convolutional networks. In: CVPR (pp. 4700\u20134708).","DOI":"10.1109\/CVPR.2017.243"},{"key":"6203_CR18","doi-asserted-by":"crossref","unstructured":"Jang, Y., Zhao, T., Hong, S., & Lee, H. (2019). Adversarial defense via learning to generate diverse attacks. In: ICCV (pp. 2740\u20132749).","DOI":"10.1109\/ICCV.2019.00283"},{"key":"6203_CR19","unstructured":"Kannan, H., Kurakin, A., & Goodfellow, I. (2018). Adversarial logit pairing. arXiv preprint arXiv:1803.06373"},{"key":"6203_CR20","unstructured":"Krizhevsky, A., & Hinton. G, et\u00a0al. (2009). Learning multiple layers of features from tiny images. Technical Report."},{"key":"6203_CR21","unstructured":"Kurakin, A., Goodfellow, I., & Bengio, S. (2016). Adversarial machine learning at scale. In: ICLR."},{"key":"6203_CR22","unstructured":"LeCun, Y., & Cortes, C. (1998). The mnist database of handwritten digits. http:\/\/yann.lecun.com\/exdb\/mnist\/."},{"key":"6203_CR23","first-page":"276","volume":"261","author":"Y LeCun","year":"1995","unstructured":"LeCun, Y., Jackel, L., Bottou, L., Cortes, C., Denker, J. S., Drucker, H., et al. (1995). Learning algorithms for classification: A comparison on handwritten digit recognition. Neural Networks: The Statistical Mechanics Perspective, 261, 276.","journal-title":"Neural Networks: The Statistical Mechanics Perspective"},{"key":"6203_CR24","doi-asserted-by":"crossref","unstructured":"Lee, S., Lee, H., & Yoon, S. (2020). Adversarial vertex mixup: Toward better adversarially robust generalization. In: CVPR (pp. 272\u2013281).","DOI":"10.1109\/CVPR42600.2020.00035"},{"key":"6203_CR25","unstructured":"Li, Y., Ding, L., & Gao, X. (2018). On the decision boundary of deep neural networks. arXiv preprint arXiv:1808.05385"},{"key":"6203_CR26","unstructured":"Li, Y., Li, L., Wang, L., Zhang, T., & Gong, B. (2019). Nattack: Learning the distributions of adversarial examples for an improved black-box attack on deep neural networks. In: ICML (pp. 3866\u20133876). PMLR."},{"key":"6203_CR27","doi-asserted-by":"crossref","unstructured":"Liu, Z., Luo, P., Wang, X., & Tang, X. (2015). Deep learning face attributes in the wild. In: ICCV.","DOI":"10.1109\/ICCV.2015.425"},{"key":"6203_CR28","doi-asserted-by":"publisher","first-page":"108140","DOI":"10.1016\/j.patcog.2021.108140","volume":"120","author":"L Liu","year":"2021","unstructured":"Liu, L., & Tan, R. T. (2021). Certainty driven consistency loss on multi-teacher networks for semi-supervised learning. Pattern Recognition, 120, 108140.","journal-title":"Pattern Recognition"},{"key":"6203_CR29","unstructured":"Madry, A., Makelov, A., Schmidt, L., Tsipras, D., & Vladu, A. (2018). Towards deep learning models resistant to adversarial attacks. In: ICLR."},{"key":"6203_CR30","doi-asserted-by":"crossref","unstructured":"Meng, D., Chen, H. (2017). Magnet: a two-pronged defense against adversarial examples. In: The 2017 ACM SIGSAC CCS (pp. 135\u2013147). ACM.","DOI":"10.1145\/3133956.3134057"},{"key":"6203_CR31","doi-asserted-by":"crossref","unstructured":"Moosavi-Dezfooli, SM., Fawzi, A., & Frossard, P. (2016). Deepfool: A simple and accurate method to fool deep neural networks. In: CVPR (pp. 2574\u20132582).","DOI":"10.1109\/CVPR.2016.282"},{"key":"6203_CR32","doi-asserted-by":"crossref","unstructured":"Mustafa, A., Khan, S., Hayat, M., Goecke, R., Shen, J., & Shao, L. (2019). Adversarial defense by restricting the hidden space of deep neural networks. In: ICCV (pp. 3385\u20133394).","DOI":"10.1109\/ICCV.2019.00348"},{"key":"6203_CR33","unstructured":"Netzer, Y., Wang, T., Coates, A., Bissacco, A., Wu, B., & Ng, A. Y. (2011). Reading digits in natural images with unsupervised feature learning. In: NIPS."},{"key":"6203_CR34","unstructured":"Odena, A., Olah, C., & Shlens, J. (2017). Conditional image synthesis with auxiliary classifier gans. In: ICML (pp. 2642\u20132651). JMLR. org."},{"key":"6203_CR35","unstructured":"Papernot, N., Faghri, F., Carlini, N., Goodfellow, I., Feinman, R., Kurakin, A., Xie, C,. Sharma, Y., Brown, T., & Roy, A., et\u00a0al. (2016a). Technical report on the cleverhans v2. 1.0 adversarial examples library. arXiv preprint arXiv:1610.00768"},{"key":"6203_CR36","doi-asserted-by":"crossref","unstructured":"Papernot, N., McDaniel, P., Goodfellow, I., Jha, S., Celik, Z. B., & Swami, A. (2017). Practical black-box attacks against machine learning. In: ACM ASIACCS (pp. 506\u2013519).","DOI":"10.1145\/3052973.3053009"},{"key":"6203_CR37","doi-asserted-by":"crossref","unstructured":"Papernot, N., McDaniel, P., Jha, S., Fredrikson, M., Celik, ZB., & Swami, A. (2016b). The limitations of deep learning in adversarial settings. In: 2016 IEEE European symposium on security and privacy (EuroS &P) (pp. 372\u2013387). IEEE.","DOI":"10.1109\/EuroSP.2016.36"},{"key":"6203_CR38","doi-asserted-by":"crossref","unstructured":"Papernot, N., McDaniel, P., Wu, X., Jha, S., & Swami A (2016c) Distillation as a defense to adversarial perturbations against deep neural networks. In 2016 IEEE symposium on security and privacy (SP), (pp. 582\u2013597). IEEE.","DOI":"10.1109\/SP.2016.41"},{"key":"6203_CR39","unstructured":"Papernot, N., & McDaniel, P. (2017). Extending defensive distillation. arXiv preprint arXiv:1705.05264"},{"key":"6203_CR40","doi-asserted-by":"crossref","unstructured":"Rahmati, A., Moosavi-Dezfooli, S. M., Frossard, P., & Dai, H. (2020). Geoda: a geometric framework for black-box adversarial attacks. In: CVPR (pp. 8446\u20138455).","DOI":"10.1109\/CVPR42600.2020.00847"},{"key":"6203_CR41","unstructured":"Samangouei, P., Kabkab, M., & Chellappa, R. (2018). Defense-gan: Protecting classifiers against adversarial attacks using generative models. In ICLR."},{"key":"6203_CR42","doi-asserted-by":"crossref","unstructured":"Seide, F., Li, G., & Yu, D. (2011). Conversational speech transcription using context-dependent deep neural networks. In: Twelfth annual conference of the international speech communication association.","DOI":"10.21437\/Interspeech.2011-169"},{"key":"6203_CR43","doi-asserted-by":"publisher","first-page":"195","DOI":"10.1016\/j.neucom.2018.04.027","volume":"307","author":"U Shaham","year":"2018","unstructured":"Shaham, U., Yamada, Y., & Negahban, S. (2018). Understanding adversarial training: Increasing local stability of supervised models through robust optimization. Neurocomputing, 307, 195\u2013204.","journal-title":"Neurocomputing"},{"key":"6203_CR44","unstructured":"Shi, Y., Zhou, X., Liu, P., & Tsang, I. (2021). Generative transition mechanism to image-to-image translation via encoded transformation. arXiv preprint arXiv:2103.05193"},{"key":"6203_CR45","doi-asserted-by":"crossref","unstructured":"Shrivastava, A., Pfister, T., Tuzel, O., Susskind, J., Wang, W., & Webb, R. (2017) Learning from simulated and unsupervised images through adversarial training. In: CVPR (pp. 2107\u20132116).","DOI":"10.1109\/CVPR.2017.241"},{"key":"6203_CR46","unstructured":"Simonyan, K., & Zisserman, A. (2014). Very deep convolutional networks for large-scale image recognition. arXiv preprint arXiv:1409.1556"},{"key":"6203_CR47","unstructured":"Song, Y., Shu, R., Kushman, N., & Ermon, S. (2018). Constructing unrestricted adversarial examples with generative models. In NeurIPS (pp. 8312\u20138323)."},{"issue":"5","key":"6203_CR48","doi-asserted-by":"publisher","first-page":"828","DOI":"10.1109\/TEVC.2019.2890858","volume":"23","author":"J Su","year":"2019","unstructured":"Su, J., Vargas, D. V., & Sakurai, K. (2019). One pixel attack for fooling deep neural networks. IEEE Transactions on Evolutionary Computation, 23(5), 828\u2013841.","journal-title":"IEEE Transactions on Evolutionary Computation"},{"key":"6203_CR49","unstructured":"Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow. I., & Fergus, R. (2013) Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199"},{"key":"6203_CR50","unstructured":"Tsipras, D., Santurkar, S., Engstrom, L., Turner, A., & Madry, A. (2019). Robustness may be at odds with accuracy. In: ICLR."},{"key":"6203_CR51","unstructured":"Verma, V., Lamb, A., Beckham, C., Najafi, A., Mitliagkas, I., Lopez-Paz, D., & Bengio, Y. (2019a). Manifold mixup: Better representations by interpolating hidden states. In: ICML (pp. 6438\u20136447). PMLR."},{"key":"6203_CR52","doi-asserted-by":"crossref","unstructured":"Verma, V., Lamb, A., Kannala, J., Bengio, Y., & Lopez-Paz, D. (2019b). Interpolation consistency training for semi-supervised learning. In: IJCAI (pp. 3635\u20133641).","DOI":"10.24963\/ijcai.2019\/504"},{"key":"6203_CR53","unstructured":"Wang, H., Li, G., Liu, X., & Lin, L. (2020). A hamiltonian monte carlo method for probabilistic adversarial attack and learning. IEEE Transactions on Pattern Analysis and Machine Intelligence."},{"key":"6203_CR54","unstructured":"Wang, Y., Zou, D., Yi, J., Bailey, J., Ma, X., & Gu, Q. (2020). Improving adversarial robustness requires revisiting misclassified examples. In: ICLR."},{"key":"6203_CR55","unstructured":"Xiao, C., Zhong, P., & Zheng, C. (2020). Enhancing adversarial defense by k-winners-take-all. In: ICLR."},{"key":"6203_CR56","doi-asserted-by":"crossref","unstructured":"Xie, C., Zhang, Z., Zhou, Y., Bai, S., Wang, J., Ren, Z., & Yuille, A. L. (2019). Improving transferability of adversarial examples with input diversity. In: CVPR (pp. 2730\u20132739).","DOI":"10.1109\/CVPR.2019.00284"},{"key":"6203_CR57","doi-asserted-by":"crossref","unstructured":"Yuan, X., He, P., Zhu, Q., & Li, X. (2019). Adversarial examples: Attacks and defenses for deep learning. IEEE transactions on neural networks and learning systems.","DOI":"10.1109\/TNNLS.2018.2886017"},{"key":"6203_CR58","unstructured":"Zhang, H., Cisse, M., Dauphin, Y. N., & Lopez-Paz, D. (2018). Mixup: Beyond empirical risk minimization. In: ICLR."},{"key":"6203_CR59","unstructured":"Zhang, H., Goodfellow, I., Metaxas, D., & Odena, A. (2019a). Self-attention generative adversarial networks. In: ICML, PMLR (pp. 7354\u20137363)."},{"key":"6203_CR60","unstructured":"Zhang, H., Yu, Y., Jiao, J., Xing, E., El\u00a0Ghaoui, L., & Jordan, M. (2019b). Theoretically principled trade-off between robustness and accuracy. In: ICML (pp. 7472\u20137482)."},{"key":"6203_CR61","unstructured":"Zhang, J., Zhu, J., Niu, G., Han, B., Sugiyama, M., & Kankanhalli M. S. (2021). Geometry-aware instance-reweighted adversarial training. In: ICLR."},{"key":"6203_CR62","doi-asserted-by":"publisher","first-page":"2253","DOI":"10.1609\/aaai.v33i01.33012253","volume":"33","author":"T Zheng","year":"2019","unstructured":"Zheng, T., Chen, C., & Ren, K. (2019). Distributionally adversarial attack. AAAI, 33, 2253\u20132260.","journal-title":"Proceedings of the AAAI Conference on Artificial Intelligence"}],"container-title":["Machine Learning"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10994-022-06203-x.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10994-022-06203-x\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10994-022-06203-x.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,9,7]],"date-time":"2023-09-07T22:05:35Z","timestamp":1694124335000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10994-022-06203-x"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,9,9]]},"references-count":62,"journal-issue":{"issue":"10","published-print":{"date-parts":[[2023,10]]}},"alternative-id":["6203"],"URL":"https:\/\/doi.org\/10.1007\/s10994-022-06203-x","relation":{},"ISSN":["0885-6125","1573-0565"],"issn-type":[{"value":"0885-6125","type":"print"},{"value":"1573-0565","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,9,9]]},"assertion":[{"value":"21 September 2020","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"13 May 2022","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"26 May 2022","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"9 September 2022","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors de clare that they have no conflict of intrest.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}},{"value":"Not applicable","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethics approval"}},{"value":"Not applicable","order":4,"name":"Ethics","group":{"name":"EthicsHeading","label":"Consent to participate"}},{"value":"Not applicable","order":5,"name":"Ethics","group":{"name":"EthicsHeading","label":"Consent for publication"}}]}}