{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,20]],"date-time":"2026-07-20T20:04:12Z","timestamp":1784577852097,"version":"3.55.0"},"reference-count":42,"publisher":"Springer Science and Business Media LLC","issue":"6","license":[{"start":{"date-parts":[[2025,5,7]],"date-time":"2025-05-07T00:00:00Z","timestamp":1746576000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,5,7]],"date-time":"2025-05-07T00:00:00Z","timestamp":1746576000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Sci. China Inf. Sci."],"published-print":{"date-parts":[[2025,6]]},"DOI":"10.1007\/s11432-022-3861-8","type":"journal-article","created":{"date-parts":[[2025,5,10]],"date-time":"2025-05-10T00:08:15Z","timestamp":1746835695000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Pareto adversarial robustness: balancing spatial robustness and sensitivity-based robustness"],"prefix":"10.1007","volume":"68","author":[{"given":"Ke","family":"Sun","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mingjie","family":"Li","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zhouchen","family":"Lin","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,5,7]]},"reference":[{"key":"3861_CR1","doi-asserted-by":"publisher","first-page":"11","DOI":"10.1007\/978-3-319-21852-6_3","volume-title":"Proceedings of the Measures of Complexity","author":"V N Vapnik","year":"2015","unstructured":"Vapnik V N, Chervonenkis A Y. On the uniform convergence of relative frequencies of events to their probabilities. In: Proceedings of the Measures of Complexity, 2015. 11\u201330"},{"key":"3861_CR2","unstructured":"Krueger D, Caballero E, Jacobsen J H, et al. Out-of-distribution generalization via risk extrapolation (REx). 2020. ArXiv:2003.00688"},{"key":"3861_CR3","volume-title":"Proceedings of the International Conference on Learning Representations","author":"I J Goodfellow","year":"2014","unstructured":"Goodfellow I J, Shlens J, Szegedy C. Explaining and harnessing adversarial examples. In: Proceedings of the International Conference on Learning Representations, 2014"},{"key":"3861_CR4","unstructured":"Szegedy C, Zaremba W, Sutskever I, et al. Intriguing properties of neural networks. 2013. ArXiv:1312.6199"},{"key":"3861_CR5","volume-title":"Proceedings of the International Conference on Learning Representations","author":"D Hendrycks","year":"2019","unstructured":"Hendrycks D, Dietterich T. Benchmarking neural network robustness to common corruptions and perturbations. In: Proceedings of the International Conference on Learning Representations, 2019"},{"key":"3861_CR6","first-page":"13276","volume-title":"Proceedings of Advances in Neural Information Processing Systems","author":"D Yin","year":"2019","unstructured":"Yin D, Lopes R G, Shlens J, et al. A Fourier perspective on model robustness in computer vision. In: Proceedings of Advances in Neural Information Processing Systems, 2019. 13276\u201313286"},{"key":"3861_CR7","volume-title":"Bayesian Learning for Neural Networks","author":"R M Neal","year":"2012","unstructured":"Neal R M. Bayesian Learning for Neural Networks. New York: Springer Science & Business Media, 2012"},{"key":"3861_CR8","volume-title":"Uncertainty in Deep Learning","author":"Y Gal","year":"2016","unstructured":"Gal Y. Uncertainty in Deep Learning. Cambridge: University of Cambridge, 2016"},{"key":"3861_CR9","unstructured":"Arjovsky M, Bottou L, Gulrajani I, et al. Invariant risk minimization. 2019. ArXiv:1907.02893"},{"key":"3861_CR10","volume-title":"Proceedings of the International Conference on Learning Representations","author":"A Madry","year":"2018","unstructured":"Madry A, Makelov A, Schmidt L, et al. Towards deep learning models resistant to adversarial attacks. In: Proceedings of the International Conference on Learning Representations, 2018"},{"key":"3861_CR11","volume-title":"Proceedings of the International Conference on Learning Representations","author":"G W Ding","year":"2020","unstructured":"Ding G W, Sharma Y, Lui K Y C, et al. Max-margin adversarial (MMA) training: direct input space margin maximization through adversarial training. In: Proceedings of the International Conference on Learning Representations, 2020"},{"key":"3861_CR12","doi-asserted-by":"publisher","first-page":"882","DOI":"10.1109\/TNNLS.2021.3103528","volume":"34","author":"N Ye","year":"2023","unstructured":"Ye N, Li Q, Zhou X Y, et al. An annealing mechanism for adversarial training acceleration. IEEE Trans Neural Netw Learn Syst, 2023, 34: 882\u2013893","journal-title":"IEEE Trans Neural Netw Learn Syst"},{"key":"3861_CR13","unstructured":"Hendrycks D, Basart S, Mu N, et al. The many faces of robustness: a critical analysis of out-of-distribution generalization. 2020. ArXiv:2006.16241"},{"key":"3861_CR14","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1109\/TNNLS.2021.3089128","volume":"34","author":"Q Liu","year":"2023","unstructured":"Liu Q, Wen W. Model compression hardens deep neural networks: a new perspective to prevent adversarial attacks. IEEE Trans Neural Netw Learn Syst, 2023, 34: 3\u201314","journal-title":"IEEE Trans Neural Netw Learn Syst"},{"key":"3861_CR15","doi-asserted-by":"publisher","first-page":"1051","DOI":"10.1109\/TNNLS.2020.3039295","volume":"33","author":"Z Che","year":"2022","unstructured":"Che Z, Borji A, Zhai G, et al. SMGEA: a new ensemble adversarial attack powered by long-term gradient memories. IEEE Trans Neural Netw Learn Syst, 2022, 33: 1051\u20131065","journal-title":"IEEE Trans Neural Netw Learn Syst"},{"key":"3861_CR16","first-page":"9561","volume-title":"Proceedings of the 37th International Conference on Machine Learning","author":"F Tramer","year":"2020","unstructured":"Tramer F, Behrmann J, Carlini N, et al. Fundamental tradeoffs between invariance and sensitivity to adversarial perturbations. In: Proceedings of the 37th International Conference on Machine Learning, 2020. 9561\u20139571"},{"key":"3861_CR17","volume-title":"Proceedings of the International Conference on Learning Representations","author":"C Xiao","year":"2018","unstructured":"Xiao C, Zhu J Y, Li B, et al. Spatially transformed adversarial examples. In: Proceedings of the International Conference on Learning Representations, 2018"},{"key":"3861_CR18","volume-title":"Computer Vision: Algorithms and Applications","author":"R Szeliski","year":"2010","unstructured":"Szeliski R. Computer Vision: Algorithms and Applications. Berlin: Springer Science & Business Media, 2010"},{"key":"3861_CR19","unstructured":"Engstrom L, Tsipras D, Schmidt L, et al. A rotation and a translation suffice: fooling CNNs with simple transformations. 2017. ArXiv:1712.02779"},{"key":"3861_CR20","first-page":"1802","volume-title":"Proceedings of the International Conference on Machine Learning","author":"L Engstrom","year":"2019","unstructured":"Engstrom L, Tran B, Tsipras D, et al. Exploring the landscape of spatial robustness. In: Proceedings of the International Conference on Machine Learning, 2019. 1802\u20131811"},{"key":"3861_CR21","first-page":"1605","volume-title":"Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition Workshops","author":"M Sharif","year":"2018","unstructured":"Sharif M, Bauer L, Reiter M K. On the suitability of Lp-norms for creating and preventing adversarial examples. In: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition Workshops, 2018. 1605\u20131613"},{"key":"3861_CR22","first-page":"7472","volume-title":"Proceedings of the International Conference on Machine Learning","author":"H Zhang","year":"2019","unstructured":"Zhang H, Yu Y, Jiao J, et al. Theoretically principled trade-off between robustness and accuracy. In: Proceedings of the International Conference on Machine Learning, 2019. 7472\u20137482"},{"key":"3861_CR23","volume-title":"Proceedings of the International Conference on Learning Representations","author":"D Tsipras","year":"2019","unstructured":"Tsipras D, Santurkar S, Engstrom L, et al. Robustness may be at odds with accuracy. In: Proceedings of the International Conference on Learning Representations, 2019"},{"key":"3861_CR24","volume-title":"Proceedings of the International Conference on Machine Learning","author":"A Raghunathan","year":"2020","unstructured":"Raghunathan A, Xie S M, Yang F, et al. Understanding and mitigating the tradeoff between robustness and accuracy. In: Proceedings of the International Conference on Machine Learning, 2020"},{"key":"3861_CR25","volume-title":"Proceedings of Advances in Neural Information Processing Systems","author":"F Tramer","year":"2019","unstructured":"Tramer F, Boneh D. Adversarial training and robustness for multiple perturbations. In: Proceedings of Advances in Neural Information Processing Systems, 2019"},{"key":"3861_CR26","unstructured":"Kamath S, Deshpande A, Subrahmanyam K. Invariance vs. robustness of neural networks. 2020. ArXiv:2002.11318"},{"key":"3861_CR27","unstructured":"Zhang H, Wang J. Joint adversarial training: incorporating both spatial and pixel attacks. 2019. ArXiv:1907.10737"},{"key":"3861_CR28","doi-asserted-by":"publisher","first-page":"149","DOI":"10.1007\/s00158-004-0465-1","volume":"29","author":"I Y Kim","year":"2005","unstructured":"Kim I Y, de Weck O L. Adaptive weighted-sum method for bi-objective optimization: Pareto front generation. Struct Multidisc Optim, 2005, 29: 149\u2013158","journal-title":"Struct Multidisc Optim"},{"key":"3861_CR29","doi-asserted-by":"publisher","first-page":"105","DOI":"10.1007\/s00158-005-0557-6","volume":"31","author":"I Y Kim","year":"2006","unstructured":"Kim I Y, de Weck O L. Adaptive weighted sum method for multiobjective optimization: a new method for Pareto front generation. Struct Multidisc Optim, 2006, 31: 105\u2013116","journal-title":"Struct Multidisc Optim"},{"key":"3861_CR30","volume-title":"Multiple Criteria Decision Making Kyoto 1975","author":"M Zeleny","year":"2012","unstructured":"Zeleny M. Multiple Criteria Decision Making Kyoto 1975. New York: Springer Science & Business Media, 2012"},{"key":"3861_CR31","volume-title":"Proceedings of the 34th Conference on Neural Information Processing Systems","author":"H Wang","year":"2020","unstructured":"Wang H, Chen T, Gui S, et al. Once-for-all adversarial training: in-situ tradeoff between robustness and accuracy for free. In: Proceedings of the 34th Conference on Neural Information Processing Systems, 2020"},{"key":"3861_CR32","first-page":"39","volume-title":"Proceedings of IEEE Symposium on Security and Privacy, San Jose","author":"N Carlini","year":"2017","unstructured":"Carlini N, Wagner D. Towards evaluating the robustness of neural networks. In: Proceedings of IEEE Symposium on Security and Privacy, San Jose, 2017. 39\u201357"},{"key":"3861_CR33","first-page":"2017","volume-title":"Proceedings of Advances in Neural Information Processing Systems","author":"M Jaderberg","year":"2015","unstructured":"Jaderberg M, Simonyan K, Zisserman A, et al. Spatial transformer networks. In: Proceedings of Advances in Neural Information Processing Systems, 2015. 2017\u20132025"},{"key":"3861_CR34","first-page":"6389","volume-title":"Proceedings of Advances in Neural Information Processing Systems","author":"H Li","year":"2018","unstructured":"Li H, Xu Z, Taylor G, et al. Visualizing the loss landscape of neural nets. In: Proceedings of Advances in Neural Information Processing Systems, 2018. 6389\u20136399"},{"key":"3861_CR35","first-page":"8828","volume-title":"Proceedings of the International Conference on Machine Learning","author":"B Shi","year":"2020","unstructured":"Shi B, Zhang D, Dai Q, et al. Informative dropout for robust representation learning: a shape-bias perspective. In: Proceedings of the International Conference on Machine Learning, 2020. 8828\u20138839"},{"key":"3861_CR36","first-page":"7502","volume-title":"Proceedings of the International Conference on Machine Learning","author":"T Zhang","year":"2019","unstructured":"Zhang T, Zhu Z. Interpreting adversarially trained convolutional neural networks. In: Proceedings of the International Conference on Machine Learning, 2019. 7502\u20137511"},{"key":"3861_CR37","unstructured":"Smilkov D, Thorat N, Kim B, et al. Smoothgrad: removing noise by adding noise. 2017. ArXiv:1706.03825"},{"key":"3861_CR38","doi-asserted-by":"publisher","first-page":"5738","DOI":"10.1109\/TNNLS.2018.2806481","volume":"29","author":"M F Leung","year":"2018","unstructured":"Leung M F, Wang J. A collaborative neurodynamic approach to multiobjective optimization. IEEE Trans Neural Netw Learn Syst, 2018, 29: 5738\u20135748","journal-title":"IEEE Trans Neural Netw Learn Syst"},{"key":"3861_CR39","first-page":"12060","volume-title":"Proceedings of Advances in Neural Information Processing Systems","author":"X Lin","year":"2019","unstructured":"Lin X, Zhen H L, Li Z, et al. Pareto multi-task learning. In: Proceedings of Advances in Neural Information Processing Systems, 2019. 12060\u201312070"},{"key":"3861_CR40","doi-asserted-by":"publisher","first-page":"51","DOI":"10.1109\/TNNLS.2014.2309939","volume":"26","author":"C Li","year":"2014","unstructured":"Li C, Georgiopoulos M, Anagnostopoulos G C. Pareto-path multitask multiple kernel learning. IEEE Trans Neural Netw Learn Syst, 2014, 26: 51\u201361","journal-title":"IEEE Trans Neural Netw Learn Syst"},{"key":"3861_CR41","doi-asserted-by":"publisher","first-page":"257","DOI":"10.1109\/4235.797969","volume":"3","author":"E Zitzler","year":"1999","unstructured":"Zitzler E, Thiele L. Multiobjective evolutionary algorithms: a comparative case study and the strength Pareto approach. IEEE Trans Evol Comput, 1999, 3: 257\u2013271","journal-title":"IEEE Trans Evol Comput"},{"key":"3861_CR42","first-page":"6640","volume-title":"Proceedings of the International Conference on Machine Learning","author":"P Maini","year":"2019","unstructured":"Maini P, Wong E, Kolter J Z. Adversarial robustness against the union of multiple perturbation models. In: Proceedings of the International Conference on Machine Learning, 2019. 6640\u20136650"}],"container-title":["Science China Information Sciences"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11432-022-3861-8.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s11432-022-3861-8","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11432-022-3861-8.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,20]],"date-time":"2026-07-20T19:34:03Z","timestamp":1784576043000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s11432-022-3861-8"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,5,7]]},"references-count":42,"journal-issue":{"issue":"6","published-print":{"date-parts":[[2025,6]]}},"alternative-id":["3861"],"URL":"https:\/\/doi.org\/10.1007\/s11432-022-3861-8","relation":{},"ISSN":["1674-733X","1869-1919"],"issn-type":[{"value":"1674-733X","type":"print"},{"value":"1869-1919","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,5,7]]},"assertion":[{"value":"27 November 2022","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"20 February 2023","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"15 June 2023","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"7 May 2025","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}],"article-number":"162101"}}