{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,19]],"date-time":"2026-04-19T21:42:52Z","timestamp":1776634972593,"version":"3.51.2"},"reference-count":47,"publisher":"Springer Science and Business Media LLC","issue":"3","license":[{"start":{"date-parts":[[2024,11,20]],"date-time":"2024-11-20T00:00:00Z","timestamp":1732060800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,11,20]],"date-time":"2024-11-20T00:00:00Z","timestamp":1732060800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Front. Comput. Sci."],"published-print":{"date-parts":[[2025,3]]},"DOI":"10.1007\/s11704-024-3587-1","type":"journal-article","created":{"date-parts":[[2024,11,20]],"date-time":"2024-11-20T04:12:35Z","timestamp":1732075955000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Fairness is essential for robustness: fair adversarial training by identifying and augmenting hard examples"],"prefix":"10.1007","volume":"19","author":[{"given":"Ningping","family":"Mou","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xinli","family":"Yue","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Lingchen","family":"Zhao","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Qian","family":"Wang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2024,11,20]]},"reference":[{"key":"3587_CR1","volume-title":"Proceedings of the 2nd International Conference on Learning Representations","author":"C Szegedy","year":"2014","unstructured":"Szegedy C, Zaremba W, Sutskever I, Bruna J, Erhan D, Goodfellow I J, Fergus R. Intriguing properties of neural networks. In: Proceedings of the 2nd International Conference on Learning Representations. 2014"},{"key":"3587_CR2","volume-title":"Proceedings of the 3rd International Conference on Learning Representations","author":"I J Goodfellow","year":"2015","unstructured":"Goodfellow I J, Shlens J, Szegedy C. Explaining and harnessing adversarial examples. In: Proceedings of the 3rd International Conference on Learning Representations. 2015"},{"key":"3587_CR3","first-page":"39","volume-title":"Proceedings of IEEE Symposium on Security and Privacy","author":"N Carlini","year":"2017","unstructured":"Carlini N, Wagner D. Towards evaluating the robustness of neural networks. In: Proceedings of IEEE Symposium on Security and Privacy. 2017, 39\u201357."},{"key":"3587_CR4","first-page":"206","volume-title":"Proceedings of the 37th International Conference on Machine Learning","author":"F Croce","year":"2020","unstructured":"Croce F, Hein M. Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks. In: Proceedings of the 37th International Conference on Machine Learning. 2020, 206."},{"key":"3587_CR5","first-page":"274","volume-title":"Proceedings of the 35th International Conference on Machine Learning","author":"A Athalye","year":"2018","unstructured":"Athalye A, Carlini N, Wagner D A. Obfuscated gradients give a false sense of security: circumventing defenses to adversarial examples. In: Proceedings of the 35th International Conference on Machine Learning. 2018, 274\u2013283."},{"key":"3587_CR6","volume-title":"Proceedings of the 6th International Conference on Learning Representations","author":"A Madry","year":"2018","unstructured":"Madry A, Makelov A, Schmidt L, Tsipras D, Vladu A. Towards deep learning models resistant to adversarial attacks. In: Proceedings of the 6th International Conference on Learning Representations. 2018"},{"key":"3587_CR7","first-page":"7472","volume-title":"Proceedings of the 36th International Conference on Machine Learning","author":"H Zhang","year":"2019","unstructured":"Zhang H, Yu Y, Jiao J, Xing E P, El Ghaoui L, Jordan M I. Theoretically principled trade-off between robustness and accuracy. In: Proceedings of the 36th International Conference on Machine Learning. 2019, 7472\u20137482."},{"key":"3587_CR8","first-page":"749","volume-title":"Proceedings of the 37th International Conference on Machine Learning","author":"L Rice","year":"2020","unstructured":"Rice L, Wong E, Kolter J Z. Overfitting in adversarially robust deep learning. In: Proceedings of the 37th International Conference on Machine Learning. 2020, 749."},{"key":"3587_CR9","doi-asserted-by":"publisher","first-page":"1561","DOI":"10.1145\/3447548.3467403","volume-title":"Proceedings of the 27th ACM SIGKDD Conference on Knowledge Discovery & Data Mining","author":"Q Tian","year":"2021","unstructured":"Tian Q, Kuang K, Jiang K, Wu F, Wang Y. Analysis and applications of class-wise robustness in adversarial training. In: Proceedings of the 27th ACM SIGKDD Conference on Knowledge Discovery & Data Mining. 2021, 1561\u20131570."},{"key":"3587_CR10","first-page":"11492","volume-title":"Proceedings of the 38th International Conference on Machine Learning","author":"H Xu","year":"2021","unstructured":"Xu H, Liu X, Li Y, Jain A K, Tang J. To be robust or to be fair: towards fairness in adversarial training. In: Proceedings of the 38th International Conference on Machine Learning. 2021, 11492\u201311501."},{"key":"3587_CR11","first-page":"3323","volume-title":"Proceedings of the 30th International Conference on Neural Information Processing Systems","author":"M Hardt","year":"2016","unstructured":"Hardt M, Price E, Srebro N. Equality of opportunity in supervised learning. In: Proceedings of the 30th International Conference on Neural Information Processing Systems. 2016, 3323\u20133331."},{"key":"3587_CR12","first-page":"853","volume-title":"Proceedings of 2018 World Wide Web Conference","author":"E Krasanakis","year":"2018","unstructured":"Krasanakis E, Spyromitros-Xioufis E, Papadopoulos S, Kompatsiaris Y. Adaptive sensitive reweighting to mitigate bias in fairness-aware classification. In: Proceedings of 2018 World Wide Web Conference. 2018, 853\u2013862."},{"key":"3587_CR13","first-page":"6373","volume-title":"Proceedings of the 36th International Conference on Machine Learning","author":"B Ustun","year":"2019","unstructured":"Ustun B, Liu Y, Parkes D C. Fairness without harm: decoupled classifiers with preference guarantees. In: Proceedings of the 36th International Conference on Machine Learning. 2019, 6373\u20136382."},{"key":"3587_CR14","first-page":"26230","volume-title":"Proceedings of the 36th Conference on Neural Information Processing Systems","author":"X Ma","year":"2022","unstructured":"Ma X, Wang Z, Liu W. On the tradeoff between robustness and fairness. In: Proceedings of the 36th Conference on Neural Information Processing Systems. 2022, 26230\u201326241."},{"key":"3587_CR15","volume-title":"Improved regularization of convolutional neural networks with cutout","author":"T Devries","year":"2017","unstructured":"Devries T, Taylor G W. Improved regularization of convolutional neural networks with cutout. 2017, arXiv preprint arXiv: 1708.04552"},{"key":"3587_CR16","volume-title":"Proceedings of the 6th International Conference on Learning Representations","author":"H Zhang","year":"2018","unstructured":"Zhang H, Ciss\u00e9 M, Dauphin Y N, Lopez-Paz D. Mixup: beyond empirical risk minimization. In: Proceedings of the 6th International Conference on Learning Representations. 2018"},{"key":"3587_CR17","first-page":"6022","volume-title":"Proceedings of 2019 IEEE\/CVF International Conference on Computer Vision","author":"S Yun","year":"2019","unstructured":"Yun S, Han D, Chun S, Oh S J, Yoo Y, Choe J. CutMix: regularization strategy to train strong classifiers with localizable features. In: Proceedings of 2019 IEEE\/CVF International Conference on Computer Vision. 2019, 6022\u20136031."},{"key":"3587_CR18","volume-title":"Proceedings of the 8th International Conference on Learning Representations","author":"Y Wang","year":"2020","unstructured":"Wang Y, Zou D, Yi J, Bailey J, Ma X, Gu Q. Improving adversarial robustness requires revisiting misclassified examples. In: Proceedings of the 8th International Conference on Learning Representations. 2020"},{"key":"3587_CR19","first-page":"1","volume-title":"Proceedings of 2022 IEEE International Conference on Multimedia and Expo","author":"Y Zhan","year":"2022","unstructured":"Zhan Y, Zheng B, Wang Q, Mou N, Guo B, Li Q, Shen C, Wang C. Towards black-box adversarial attacks on interpretable deep learning systems. In: Proceedings of 2022 IEEE International Conference on Multimedia and Expo. 2022, 1\u20136."},{"key":"3587_CR20","first-page":"3342","volume-title":"Proceedings of the 31st International Joint Conference on Artificial Intelligence","author":"N Mou","year":"2022","unstructured":"Mou N, Zheng B, Wang Q, Ge Y, Guo B. A few seconds can change everything: Fast decision-based attacks against DNNs. In: Proceedings of the 31st International Joint Conference on Artificial Intelligence. 2022, 3342\u20133350."},{"key":"3587_CR21","first-page":"138","volume-title":"Proceedings of the 34th International Conference on Neural Information Processing Systems","author":"F Tram\u00e8r","year":"2020","unstructured":"Tram\u00e8r F, Carlini N, Brendel W, Madry A. On adaptive attacks to adversarial example defenses. In: Proceedings of the 34th International Conference on Neural Information Processing Systems. 2020, 138."},{"key":"3587_CR22","first-page":"1418","volume-title":"Proceedings of the 33rd AAAI Conference on Artificial Intelligence","author":"S Aghaei","year":"2019","unstructured":"Aghaei S, Azizi M J, Vayanos P. Learning optimal and fair decision trees for non-discriminative decision-making. In: Proceedings of the 33rd AAAI Conference on Artificial Intelligence. 2019, 1418\u20131426."},{"key":"3587_CR23","doi-asserted-by":"publisher","first-page":"116","DOI":"10.1145\/3278721.3278722","volume-title":"Proceedings of 2018 AAAI\/ACM Conference on AI, Ethics, and Society","author":"N Goel","year":"2018","unstructured":"Goel N, Yaghini M, Faltings B. Non-discriminatory machine learning through convex fairness criteria. In: Proceedings of 2018 AAAI\/ACM Conference on AI, Ethics, and Society. 2018, 116."},{"issue":"6","key":"3587_CR24","doi-asserted-by":"publisher","first-page":"115","DOI":"10.1145\/3457607","volume":"54","author":"N Mehrabi","year":"2022","unstructured":"Mehrabi N, Morstatter F, Saxena N, Lerman K, Galstyan A. A survey on bias and fairness in machine learning. ACM Computing Surveys, 2022, 54(6): 115","journal-title":"ACM Computing Surveys"},{"key":"3587_CR25","first-page":"7032","volume-title":"Proceedings of the 31st International Conference on Neural Information Processing Systems","author":"Y X Wang","year":"2017","unstructured":"Wang Y X, Ramanan D, Hebert M. Learning to model the tail. In: Proceedings of the 31st International Conference on Neural Information Processing Systems. 2017, 7032\u20137042."},{"key":"3587_CR26","first-page":"1567","volume-title":"Proceedings of the 33rd International Conference on Neural Information Processing Systems","author":"K Cao","year":"2019","unstructured":"Cao K, Wei C, Gaidon A, Ar\u00e9chiga N, Ma T. Learning imbalanced datasets with label-distribution-aware margin loss. In: Proceedings of the 33rd International Conference on Neural Information Processing Systems. 2019, 1567\u20131578."},{"key":"3587_CR27","first-page":"60","volume-title":"Proceedings of the 35th International Conference on Machine Learning","author":"A Agarwal","year":"2018","unstructured":"Agarwal A, Beygelzimer A, Dudik M, Langford J, Wallach H. A reductions approach to fair classification. In: Proceedings of the 35th International Conference on Machine Learning. 2018, 60\u201369."},{"key":"3587_CR28","first-page":"9260","volume-title":"Proceedings of 2019 IEEE\/CVF Conference on Computer Vision and Pattern Recognition","author":"Y Cui","year":"2019","unstructured":"Cui Y, Jia M, Lin T Y, Song Y, Belongie S. Class-balanced loss based on effective number of samples. In: Proceedings of 2019 IEEE\/CVF Conference on Computer Vision and Pattern Recognition. 2019, 9260\u20139269."},{"key":"3587_CR29","first-page":"4679","volume-title":"Proceedings of the 30th International Joint Conference on Artificial Intelligence","author":"X Zhan","year":"2021","unstructured":"Zhan X, Liu H, Li Q, Chan A B. A comparative survey: benchmarking for pool-based active learning. In: Proceedings of the 30th International Joint Conference on Artificial Intelligence. 2021, 4679\u20134686."},{"key":"3587_CR30","doi-asserted-by":"publisher","first-page":"9368","DOI":"10.1109\/CVPR.2018.00976","volume-title":"Proceedings of 2018 IEEE\/CVF Conference on Computer Vision and Pattern Recognition","author":"W H Beluch","year":"2018","unstructured":"Beluch W H, Genewein T, N\u00fcrnberger A, K\u00f6hler J M. The power of ensembles for active learning in image classification. In: Proceedings of 2018 IEEE\/CVF Conference on Computer Vision and Pattern Recognition. 2018, 9368\u20139377."},{"key":"3587_CR31","first-page":"1183","volume-title":"Proceedings of the 34th International Conference on Machine Learning","author":"Y Gal","year":"2017","unstructured":"Gal Y, Islam R, Ghahramani Z. Deep Bayesian active learning with image data. In: Proceedings of the 34th International Conference on Machine Learning. 2017, 1183\u20131192."},{"key":"3587_CR32","volume-title":"Proceedings of the 10th International Conference on Learning Representations","author":"R Rade","year":"2022","unstructured":"Rade R, Moosavi-Dezfooli S M. Reducing excessive margin to achieve a better accuracy vs. robustness trade-off. In: Proceedings of the 10th International Conference on Learning Representations. 2022"},{"key":"3587_CR33","volume-title":"Proceedings of the 9th International Conference on Learning Representations","author":"J Zhang","year":"2021","unstructured":"Zhang J, Zhu J, Niu G, Han B, Sugiyama M, Kankanhalli M S. Geometry-aware instance-reweighted adversarial training. In: Proceedings of the 9th International Conference on Learning Representations. 2021"},{"key":"3587_CR34","first-page":"1004","volume-title":"Proceedings of the 33rd International Conference on Neural Information Processing Systems","author":"Y Carmon","year":"2019","unstructured":"Carmon Y, Raghunathan A, Schmidt L, Liang P, Duchi J C. Unlabeled data improves adversarial robustness. In: Proceedings of the 33rd International Conference on Neural Information Processing Systems. 2019, 1004."},{"key":"3587_CR35","first-page":"2712","volume-title":"Proceedings of the 36th International Conference on Machine Learning","author":"D Hendrycks","year":"2019","unstructured":"Hendrycks D, Lee K, Mazeika M. Using pre-training can improve model robustness and uncertainty. In: Proceedings of the 36th International Conference on Machine Learning. 2019, 2712\u20132721."},{"key":"3587_CR36","first-page":"497","volume-title":"Proceedings of the 33rd International Conference on Neural Information Processing Systems","author":"A Najafi","year":"2019","unstructured":"Najafi A, Maeda S I, Koyama M, Miyato T. Robustness to adversarial perturbations in learning from incomplete data. In: Proceedings of the 33rd International Conference on Neural Information Processing Systems. 2019, 497."},{"key":"3587_CR37","volume-title":"Proceedings of ICLR 2020","author":"R Zhai","year":"2020","unstructured":"Zhai R, Cai T, He D, Dan C, He K, Hopcroft J, Wang L. Adversarially robust generalization just requires more unlabeled data. In: Proceedings of ICLR 2020. 2020"},{"issue":"11","key":"3587_CR38","doi-asserted-by":"publisher","first-page":"1958","DOI":"10.1109\/TPAMI.2008.128","volume":"30","author":"A Torralba","year":"2008","unstructured":"Torralba A, Fergus R, Freeman W T. 80 million tiny images: a large data set for nonparametric object and scene recognition. IEEE Transactions on Pattern Analysis and Machine Intelligence, 2008, 30(11): 1958\u20131970","journal-title":"IEEE Transactions on Pattern Analysis and Machine Intelligence"},{"key":"3587_CR39","volume-title":"AutoAugment: learning augmentation policies from data","author":"E D Cubuk","year":"2018","unstructured":"Cubuk E D, Zoph B, Man\u00e9 D, Vasudevan V, Le Q V. AutoAugment: learning augmentation policies from data. 2018, arXiv preprint arXiv: 1805.09501"},{"key":"3587_CR40","series-title":"Technical Report","volume-title":"Learning multiple layers of features from tiny images","author":"A Krizhevsky","year":"2009","unstructured":"Krizhevsky A. Learning multiple layers of features from tiny images. Technical Report, University of Toronto, 2009"},{"key":"3587_CR41","volume-title":"Proceedings of NIPS Workshop on Deep Learning and Unsupervised Feature Learning","author":"Y Netzer","year":"2011","unstructured":"Netzer Y, Wang T, Coates A, Bissacco A, Wu B, Ng A Y. Reading digits in natural images with unsupervised feature learning. In: Proceedings of NIPS Workshop on Deep Learning and Unsupervised Feature Learning. 2011"},{"key":"3587_CR42","first-page":"630","volume-title":"Proceedings of the 14th European Conference on Computer Vision","author":"K He","year":"2016","unstructured":"He K, Zhang X, Ren S, Sun J. Identity mappings in deep residual networks. In: Proceedings of the 14th European Conference on Computer Vision. 2016, 630\u2013645."},{"key":"3587_CR43","volume-title":"Proceedings of British Machine Vision Conference","author":"S Zagoruyko","year":"2016","unstructured":"Zagoruyko S, Komodakis N. Wide residual networks. In: Proceedings of British Machine Vision Conference. 2016"},{"key":"3587_CR44","doi-asserted-by":"publisher","first-page":"248","DOI":"10.1109\/CVPR.2009.5206848","volume-title":"Proceedings of 2009 IEEE Conference on Computer Vision and Pattern Recognition","author":"J Deng","year":"2009","unstructured":"Deng J, Dong W, Socher R, Li L J, Li K, Fei-Fei L. ImageNet: a large-scale hierarchical image database. In: Proceedings of 2009 IEEE Conference on Computer Vision and Pattern Recognition. 2009, 248\u2013255."},{"key":"3587_CR45","volume-title":"Proceedings of the 35th Conference on Neural Information Processing Systems","author":"F Croce","year":"2021","unstructured":"Croce F, Andriushchenko M, Sehwag V, Debenedetti E, Flammarion N, Chiang M, Mittal P, Hein M. RobustBench: a standardized adversarial robustness benchmark. In: Proceedings of the 35th Conference on Neural Information Processing Systems. 2021"},{"key":"3587_CR46","first-page":"112","volume-title":"Proceedings of 2014 International Joint Conference on Neural Networks","author":"D Wang","year":"2014","unstructured":"Wang D, Shang Y. A new active labeling method for deep learning. In: Proceedings of 2014 International Joint Conference on Neural Networks. 2014, 112\u2013119."},{"issue":"1","key":"3587_CR47","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1145\/584091.584093","volume":"5","author":"C E Shannon","year":"2001","unstructured":"Shannon C E. A mathematical theory of communication. ACM SIGMOBILE Mobile Computing and Communications Review, 2001, 5(1): 3\u201355","journal-title":"ACM SIGMOBILE Mobile Computing and Communications Review"}],"container-title":["Frontiers of Computer Science"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11704-024-3587-1.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s11704-024-3587-1","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11704-024-3587-1.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,19]],"date-time":"2026-04-19T21:02:43Z","timestamp":1776632563000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s11704-024-3587-1"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,11,20]]},"references-count":47,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2025,3]]}},"alternative-id":["3587"],"URL":"https:\/\/doi.org\/10.1007\/s11704-024-3587-1","relation":{},"ISSN":["2095-2228","2095-2236"],"issn-type":[{"value":"2095-2228","type":"print"},{"value":"2095-2236","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,11,20]]},"assertion":[{"value":"22 July 2023","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"16 January 2024","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"20 November 2024","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"Competing interests\n                      The authors declare that they have no competing interests or financial conflicts to disclose.","order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethics"}}],"article-number":"193803"}}