{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,30]],"date-time":"2026-04-30T16:54:13Z","timestamp":1777568053148,"version":"3.51.4"},"reference-count":68,"publisher":"Springer Science and Business Media LLC","issue":"5","license":[{"start":{"date-parts":[[2023,3,30]],"date-time":"2023-03-30T00:00:00Z","timestamp":1680134400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2023,3,30]],"date-time":"2023-03-30T00:00:00Z","timestamp":1680134400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"funder":[{"DOI":"10.13039\/501100012166","name":"National Key R &D Program of China","doi-asserted-by":"crossref","award":["2021ZD0112804"],"award-info":[{"award-number":["2021ZD0112804"]}],"id":[{"id":"10.13039\/501100012166","id-type":"DOI","asserted-by":"crossref"}]},{"DOI":"10.13039\/501100003399","name":"Shanghai Science and Technology Committee","doi-asserted-by":"crossref","award":["20511101000"],"award-info":[{"award-number":["20511101000"]}],"id":[{"id":"10.13039\/501100003399","id-type":"DOI","asserted-by":"crossref"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62032006"],"award-info":[{"award-number":["62032006"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62276067"],"award-info":[{"award-number":["62276067"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Mach Learn"],"published-print":{"date-parts":[[2024,5]]},"DOI":"10.1007\/s10994-023-06328-7","type":"journal-article","created":{"date-parts":[[2023,4,4]],"date-time":"2023-04-04T11:41:54Z","timestamp":1680608514000},"page":"2301-2326","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":6,"title":["Imbalanced gradients: a subtle cause of overestimated adversarial robustness"],"prefix":"10.1007","volume":"113","author":[{"given":"Xingjun","family":"Ma","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Linxi","family":"Jiang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hanxun","family":"Huang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zejia","family":"Weng","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"James","family":"Bailey","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yu-Gang","family":"Jiang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2023,3,30]]},"reference":[{"key":"6328_CR1","unstructured":"Alayrac, J., Uesato, J., & Huang, P. et\u00a0al. (2019). Are labels required for improving adversarial robustness?. In Neural information processing systems."},{"key":"6328_CR2","doi-asserted-by":"crossref","unstructured":"Andriushchenko, M., Croce, F., & Flammarion, N., et\u00a0al. (2019). Square attack: a query-efficient black-box adversarial attack via random search. arXiv:1912.00049.","DOI":"10.1007\/978-3-030-58592-1_29"},{"key":"6328_CR3","unstructured":"Athalye, A., Carlini, N., & Wagner, D. (2018). Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples. In International conference on machine learning."},{"key":"6328_CR4","unstructured":"Bai, Y., Zeng, Y., Jiang, Y., et\u00a0al. (2020). Improving adversarial robustness via channel-wise activation suppressing. In International conference on learning representations."},{"key":"6328_CR5","doi-asserted-by":"crossref","unstructured":"Carlini, N., & Wagner, D. (2017). Towards evaluating the robustness of neural networks. In S &P.","DOI":"10.1109\/SP.2017.49"},{"key":"6328_CR6","unstructured":"Carlini, N., Athalye, A., Papernot, N., et\u00a0al. (2019). On evaluating adversarial robustness. arXiv preprint arXiv:1902.06705."},{"key":"6328_CR7","unstructured":"Carmon, Y., Raghunathan, A., Schmidt, L. et\u00a0al. (2019). Unlabeled data improves adversarial robustness. In Neural information processing systems."},{"key":"6328_CR8","unstructured":"Chan, A., Tay, Y., Ong, Y.S., et\u00a0al. (2020). Jacobian adversarially regularized networks for robustness. In International conference on learning representations."},{"key":"6328_CR9","unstructured":"Chen, J., Zhou, D., & Yi, J., et\u00a0al. (2018a). A frank-wolfe framework for efficient and effective adversarial attacks. arXiv preprint arXiv:1811.10828."},{"key":"6328_CR10","doi-asserted-by":"crossref","unstructured":"Chen, P.Y., Sharma, Y., & Zhang, H., et\u00a0al. (2018b). Ead: elastic-net attacks to deep neural networks via adversarial examples. In AAAI conference on artificial intelligence.","DOI":"10.1609\/aaai.v32i1.11302"},{"key":"6328_CR11","unstructured":"Croce, F., & Hein, M. (2019). Minimally distorted adversarial examples with a fast adaptive boundary attack. arXiv:1907.02044."},{"key":"6328_CR12","unstructured":"Croce, F., & Hein, M. (2020a). Minimally distorted adversarial examples with a fast adaptive boundary attack. In International conference on machine learning, PMLR."},{"key":"6328_CR13","unstructured":"Croce, F., & Hein, M. (2020b). Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks. arXiv preprint arXiv:2003.01690."},{"key":"6328_CR14","unstructured":"Croce, F., Andriushchenko, M., & Sehwag, V. et\u00a0al. (2020). Robustbench: A standardized adversarial robustness benchmark. arXiv preprint arXiv:2010.09670."},{"key":"6328_CR15","unstructured":"Croce, F., Andriushchenko, M., & Sehwag, V., et\u00a0al. (2021). Robustbench: A standardized adversarial robustness benchmark. In Thirty-fifth conference on neural information processing systems datasets and benchmarks track."},{"key":"6328_CR16","unstructured":"Das, N., Shanbhogue, M., & Chen, S.T., et\u00a0al. (2018). Compression to the rescue: Defending from adversarial attacks across modalities. In KDD."},{"key":"6328_CR17","doi-asserted-by":"crossref","unstructured":"Debenedetti, E., Sehwag, V., & Mittal, P. (2022). A light recipe to train robust vision transformers. arXiv preprint arXiv:2209.07399.","DOI":"10.1109\/SaTML54575.2023.00024"},{"key":"6328_CR18","unstructured":"Ding, G.W., Sharma, Y., & Lui, K.Y.C. et\u00a0al. (2018). Max-margin adversarial (MMA) training: Direct input space margin maximization through adversarial training. arXiv preprint arXiv:1812.02637."},{"key":"6328_CR19","doi-asserted-by":"crossref","unstructured":"Dong, Y., Liao, F., & Pang, T., et\u00a0al. (2018). Boosting adversarial attacks with momentum. In IEEE\/CVF international conference on computer vision.","DOI":"10.1109\/CVPR.2018.00957"},{"key":"6328_CR20","unstructured":"Du, X., Zhang, J., Han, B., et al. (2021). Learning diverse-structured networks for adversarial robustness."},{"key":"6328_CR21","unstructured":"Engstrom, L., Ilyas, A., & Athalye, A. (2018). Evaluating and understanding the robustness of adversarial logit pairing. arXiv preprint arXiv:1807.10272."},{"key":"6328_CR22","unstructured":"Engstrom, L., Ilyas, A., Santurkar, S., et\u00a0al. (2019). Adversarial robustness as a prior for learned representations. arXiv preprint arXiv:1906.00945."},{"key":"6328_CR23","doi-asserted-by":"crossref","unstructured":"Goldblum, M., Fowl, L., & Feizi, S., et\u00a0al. (2020). Adversarially robust distillation. In AAAI conference on artificial intelligence.","DOI":"10.1609\/aaai.v34i04.5816"},{"key":"6328_CR24","unstructured":"Goodfellow, I.J., Shlens, J., & Szegedy, C. (2015). Explaining and harnessing adversarial examples. In International conference on learning representations."},{"key":"6328_CR25","unstructured":"Gowal, S., Uesato, J., & Qin, C., et\u00a0al. (2019). An alternative surrogate loss for pgd-based adversarial testing. arXiv preprint arXiv:1910.09338."},{"key":"6328_CR26","unstructured":"Gu, S., & Rigazio, L. (2014). Towards deep neural network architectures robust to adversarial examples. arXiv preprint arXiv:1412.5068."},{"key":"6328_CR27","unstructured":"Guo, C., Rana, M., & Cisse, M., et\u00a0al. (2018). Countering adversarial images using input transformations. In International conference on learning representations."},{"key":"6328_CR28","unstructured":"Hendrycks, D., Lee, K., & Mazeika, M. (2019). Using pre-training can improve model robustness and uncertainty. In International conference on machine learning."},{"key":"6328_CR29","doi-asserted-by":"crossref","unstructured":"Huang, G., Liu, Z., & Van Der\u00a0Maaten, L., et\u00a0al. (2017). Densely connected convolutional networks. In IEEE\/CVF international conference on computer vision.","DOI":"10.1109\/CVPR.2017.243"},{"key":"6328_CR30","unstructured":"Huang, H., & Wang, Y., Erfani, S.M., et\u00a0al. (2021). Exploring architectural ingredients of adversarially robust deep neural networks. In Neural information processing systems."},{"key":"6328_CR31","unstructured":"Kim, J., & Wang, X. (2020). Sensible adversarial learning. https:\/\/openreview.net\/forum?id=rJlf_RVKwr."},{"key":"6328_CR32","unstructured":"Kurakin, A., Goodfellow, I., & Bengio, S. (2017). Adversarial machine learning at scale."},{"key":"6328_CR33","doi-asserted-by":"crossref","unstructured":"Liao, F., Liang, M., & Dong, Y., et\u00a0al. (2018). Defense against adversarial attacks using high-level representation guided denoiser. In IEEE\/CVF international conference on computer vision.","DOI":"10.1109\/CVPR.2018.00191"},{"key":"6328_CR34","unstructured":"Liu, H., Simonyan, K., & Yang, Y. (2019). DARTS: Differentiable architecture search. In International conference on learning representations."},{"key":"6328_CR35","doi-asserted-by":"crossref","unstructured":"Liu, Q., Liu, T., & Liu, Z., et\u00a0al. (2018). Security analysis and enhancement of model compressed deep learning systems under adversarial attacks. In: ASPDAC.","DOI":"10.1109\/ASPDAC.2018.8297407"},{"key":"6328_CR36","unstructured":"Ma, X., Li, B., & Wang, Y., et\u00a0al. (2018). Characterizing adversarial subspaces using local intrinsic dimensionality. In International conference on learning representations."},{"key":"6328_CR37","unstructured":"Madry, A., Makelov, A., & Schmidt, L., et\u00a0al. (2018). Towards deep learning models resistant to adversarial attacks. In International conference on learning representations."},{"key":"6328_CR38","unstructured":"Pang, T., Yang, X., & Dong, Y., et\u00a0al. (2020). Boosting adversarial training with hypersphere embedding. In Neural information processing systems."},{"key":"6328_CR39","doi-asserted-by":"crossref","unstructured":"Papernot, N., McDaniel, P., Wu, X., et\u00a0al. (2016). Distillation as a defense to adversarial perturbations against deep neural networks. In S &P.","DOI":"10.1109\/SP.2016.41"},{"key":"6328_CR40","doi-asserted-by":"crossref","unstructured":"Papernot, N., McDaniel, P., Goodfellow, I., et\u00a0al. (2017). Practical black-box attacks against machine learning. In Asia CCS.","DOI":"10.1145\/3052973.3053009"},{"key":"6328_CR41","unstructured":"Rakin, A.S., Yi, J., & Gong, B., et\u00a0al. (2018). Defend deep neural networks against adversarial examples via fixed and dynamic quantized activation functions. arXiv preprint arXiv:1807.06714."},{"key":"6328_CR42","unstructured":"Rice, L., Wong, E., & Kolter, Z. (2020). Overfitting in adversarially robust deep learning. In International conference on machine learning, PMLR (pp. 8093\u20138104)."},{"key":"6328_CR43","doi-asserted-by":"crossref","unstructured":"Ross, A.S., & Doshi-Velez, F. (2018). Improving the adversarial robustness and interpretability of deep neural networks by regularizing their input gradients. In AAAI conference on artificial intelligence.","DOI":"10.1609\/aaai.v32i1.11504"},{"key":"6328_CR44","unstructured":"Salman, H., Ilyas, A., & Engstrom, L., et\u00a0al. (2020). Do adversarially robust imagenet models transfer better? Neural Information Processing Systems"},{"key":"6328_CR45","unstructured":"Samangouei, P., Kabkab, M., & Chellappa, R. (2018). Defense-GAN: Protecting classifiers against adversarial attacks using generative models. In International conference on learning representations."},{"key":"6328_CR46","unstructured":"Shao, R., Shi, Z., Yi, J., et\u00a0al. (2021). On the adversarial robustness of visual transformers. arXiv preprint arXiv:2103.15670."},{"key":"6328_CR47","unstructured":"Simonyan, K., & Zisserman, A. (2014). Very deep convolutional networks for large-scale image recognition. arXiv preprint arXiv:1409.1556."},{"key":"6328_CR48","doi-asserted-by":"crossref","unstructured":"Spall, J.C., et\u00a0al. (1992). Multivariate stochastic approximation using a simultaneous perturbation gradient approximation. IEEE Transactions on Automatic Control","DOI":"10.1109\/9.119632"},{"key":"6328_CR49","unstructured":"Sutskever, I., Martens, J., & Dahl, G., et\u00a0al. (2013). On the importance of initialization and momentum in deep learning. In International conference on machine learning."},{"key":"6328_CR50","unstructured":"Szegedy, C., Zaremba, W., & Sutskever, I., et\u00a0al. (2014). Intriguing properties of neural networks. In International conference on learning representations."},{"key":"6328_CR51","unstructured":"Tang, S., Gong, R., & Wang, Y., et\u00a0al. (2021). Robustart: Benchmarking robustness on architecture design and training techniques. arXiv preprint arXiv:2109.05211."},{"key":"6328_CR52","unstructured":"Tashiro, Y., Song, Y., & Ermon, S. (2020). Diversity can be transferred: Output diversification for white- and black-box attacks. In Advances in neural information processing systems."},{"key":"6328_CR53","unstructured":"Tram\u00e8r, F., Kurakin, A., Papernot, N., et\u00a0al. (2018). Ensemble adversarial training: Attacks and defenses. In International conference on learning representations."},{"key":"6328_CR54","unstructured":"Tramer, F., Carlini, N., & Brendel, W., et\u00a0al. (2020). On adaptive attacks to adversarial example defenses. In Neural information processing systems."},{"key":"6328_CR55","unstructured":"Uesato, J., O\u2019Donoghue, B., & Kohli, P., et\u00a0al. (2018). Adversarial risk and the dangers of evaluating against weak attacks. In International conference on machine learning."},{"key":"6328_CR56","doi-asserted-by":"crossref","unstructured":"Wang, J., & Zhang, H. (2019). Bilateral adversarial training: Towards fast training of more robust models against adversarial attacks. In International conference on computer vision.","DOI":"10.1109\/ICCV.2019.00673"},{"key":"6328_CR57","unstructured":"Wang, Y., Ma, X., & Bailey, J., et\u00a0al. (2019). On the convergence and robustness of adversarial training. In International conference on machine learning."},{"key":"6328_CR58","unstructured":"Wang, Y., Zou, D., & Yi, J., et\u00a0al. (2020). Improving adversarial robustness requires revisiting misclassified examples. In International conference on learning representations."},{"key":"6328_CR59","unstructured":"Wong, E., Rice, L., & Kolter, J.Z. (2020). Fast is better than free: Revisiting adversarial training. In International conference on learning representations."},{"key":"6328_CR60","unstructured":"Wu, D., Xia, S.T., & Wang, Y. (2020). Adversarial weight perturbation helps robust generalization. Neural Information Processing Systems, 33."},{"key":"6328_CR61","doi-asserted-by":"crossref","unstructured":"Xu, W., Evans, D., & Qi, Y. (2017). Feature squeezing: Detecting adversarial examples in deep neural networks. arXiv preprint arXiv:1704.01155.","DOI":"10.14722\/ndss.2018.23198"},{"key":"6328_CR62","doi-asserted-by":"crossref","unstructured":"Zagoruyko, S., & Komodakis, N. (2016). Wide residual networks. In BMVC.","DOI":"10.5244\/C.30.87"},{"key":"6328_CR63","unstructured":"Zhang, H., & Wang, J. (2019). Defense against adversarial attacks using feature scattering-based adversarial training. In Neural information processing systems."},{"key":"6328_CR64","unstructured":"Zhang, H., & Xu, W. (2020). Adversarial interpolation training: A simple approach for improving model robustness. https:\/\/openreview.net\/forum?id=Syejj0NYvr."},{"key":"6328_CR65","unstructured":"Zhang, H., Yu, Y., & Jiao, J., et\u00a0al. (2019). Theoretically principled trade-off between robustness and accuracy. In International conference on machine learning."},{"key":"6328_CR66","doi-asserted-by":"crossref","unstructured":"Zheng, T., Chen, C., & Ren, K. (2019). Distributionally adversarial attack. In AAAI conference on artificial intelligence.","DOI":"10.1609\/aaai.v33i01.33012253"},{"key":"6328_CR67","unstructured":"Zhu, J., Yao, J., & Han, B., et\u00a0al. (2021). Reliable adversarial distillation with unreliable teachers. arXiv preprint arXiv:2106.04928."},{"key":"6328_CR68","doi-asserted-by":"crossref","unstructured":"Zi, B., Zhao, S., & Ma, X., et\u00a0al. (2021). Revisiting adversarial robustness distillation: Robust soft labels make student better. In International conference on computer vision.","DOI":"10.1109\/ICCV48922.2021.01613"}],"container-title":["Machine Learning"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10994-023-06328-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10994-023-06328-7\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10994-023-06328-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,5,2]],"date-time":"2024-05-02T18:11:32Z","timestamp":1714673492000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10994-023-06328-7"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,3,30]]},"references-count":68,"journal-issue":{"issue":"5","published-print":{"date-parts":[[2024,5]]}},"alternative-id":["6328"],"URL":"https:\/\/doi.org\/10.1007\/s10994-023-06328-7","relation":{},"ISSN":["0885-6125","1573-0565"],"issn-type":[{"value":"0885-6125","type":"print"},{"value":"1573-0565","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,3,30]]},"assertion":[{"value":"14 November 2021","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"19 December 2022","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"10 March 2023","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"30 March 2023","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"Xingjun Ma is currently employed at Fudan University and is also affiliated with The University of Melbourne as an honorary fellow. Linxi Jiang and Zejia Weng are master students at Fudan University. Hanxun Huang is a Ph.D. candidate at The University of Melbourne. James Bailey is employed at The University of Melbourne. Yu-Gang Jiang is employed at Fudan University.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}},{"value":"The authors declare that none of them is an Editorial Board Member or Editor of Machine Learning journal.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Editorial board members and editors"}},{"value":"The authors declare they have no financial interests.","order":4,"name":"Ethics","group":{"name":"EthicsHeading","label":"Financial interests"}},{"value":"Not applicable.","order":5,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethics approval"}},{"value":"Not applicable.","order":6,"name":"Ethics","group":{"name":"EthicsHeading","label":"Consent to participate"}},{"value":"Not applicable.","order":7,"name":"Ethics","group":{"name":"EthicsHeading","label":"Consent for publication"}},{"value":"The code used to produce the results in this work is publicly available at .","order":8,"name":"Ethics","group":{"name":"EthicsHeading","label":"Code availability"}},{"value":"This content has been made available to all.","name":"free","label":"Free to read"}]}}