{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,3]],"date-time":"2026-06-03T14:10:04Z","timestamp":1780495804173,"version":"3.54.1"},"reference-count":40,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"funder":[{"DOI":"10.13039\/501100001321","name":"National Research Foundation","doi-asserted-by":"publisher","award":["AISG3-TC-2024-014-SGKR"],"award-info":[{"award-number":["AISG3-TC-2024-014-SGKR"]}],"id":[{"id":"10.13039\/501100001321","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001381","name":"National Research Foundation Singapore","doi-asserted-by":"publisher","award":["AISG3-RP-2022-031"],"award-info":[{"award-number":["AISG3-RP-2022-031"]}],"id":[{"id":"10.13039\/501100001381","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Pattern Recognition"],"published-print":{"date-parts":[[2026,11]]},"DOI":"10.1016\/j.patcog.2026.113453","type":"journal-article","created":{"date-parts":[[2026,3,22]],"date-time":"2026-03-22T23:01:12Z","timestamp":1774220472000},"page":"113453","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"PA","title":["SwiftDistill: Efficient robust knowledge transfer via dual-branch adversarial distillation and hardness-balanced augmentation"],"prefix":"10.1016","volume":"179","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-6232-9157","authenticated-orcid":false,"given":"Junhao","family":"Dong","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-0085-585X","authenticated-orcid":false,"given":"Yuqing","family":"Wen","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-1023-4940","authenticated-orcid":false,"given":"Zhengdao","family":"Li","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Weijun","family":"Gao","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0008-3766-3488","authenticated-orcid":false,"given":"Zhixuan","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-8499-5217","authenticated-orcid":false,"given":"Siheng","family":"Wang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8072-2019","authenticated-orcid":false,"given":"Xinghua","family":"Qu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4480-169X","authenticated-orcid":false,"given":"Yew-Soon","family":"Ong","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"key":"10.1016\/j.patcog.2026.113453_bib0001","doi-asserted-by":"crossref","DOI":"10.1016\/j.patcog.2021.108102","article-title":"Explainable deep learning for efficient and robust pattern recognition: a survey of recent developments","volume":"120","author":"Bai","year":"2021","journal-title":"Pattern Recognit."},{"key":"10.1016\/j.patcog.2026.113453_bib0002","series-title":"ICLR","article-title":"Intriguing properties of neural networks","author":"Szegedy","year":"2014"},{"key":"10.1016\/j.patcog.2026.113453_bib0003","series-title":"ICLR","article-title":"Explaining and harnessing adversarial examples","author":"Goodfellow","year":"2015"},{"key":"10.1016\/j.patcog.2026.113453_bib0004","series-title":"International Joint Conference on Artificial Intelligence, IJCAI","article-title":"Recent advances in adversarial training for adversarial robustness","author":"Bai","year":"2021"},{"key":"10.1016\/j.patcog.2026.113453_bib0005","first-page":"3358","article-title":"Adversarial training for free!","volume":"32","author":"Shafahi","year":"2019","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"10.1016\/j.patcog.2026.113453_bib0006","series-title":"The Thirty-ninth Annual Conference on Neural Information Processing Systems","article-title":"Robust superalignment: weak-to-strong robustness generalization for vision-language models","author":"Dong","year":"2025"},{"key":"10.1016\/j.patcog.2026.113453_bib0007","series-title":"Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security","first-page":"4807","article-title":"SafeGen: mitigating sexually explicit content generation in text-to-image models","author":"Li","year":"2024"},{"key":"10.1016\/j.patcog.2026.113453_bib0008","series-title":"Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security","first-page":"3585","article-title":"SafEar: content privacy-preserving audio deepfake detection","author":"Li","year":"2024"},{"key":"10.1016\/j.patcog.2026.113453_bib0009","series-title":"Proceedings of the AAAI Conference on Artificial Intelligence","first-page":"3996","article-title":"Adversarially robust distillation","volume":"Vol. 34","author":"Goldblum","year":"2020"},{"key":"10.1016\/j.patcog.2026.113453_bib0010","series-title":"Proceedings of the IEEE\/CVF International Conference on Computer Vision","first-page":"16443","article-title":"Revisiting adversarial robustness distillation: robust soft labels make student better","author":"Zi","year":"2021"},{"key":"10.1016\/j.patcog.2026.113453_bib0011","series-title":"The Tenth International Conference on Learning Representations, ICLR","article-title":"Reliable adversarial distillation with unreliable teachers","author":"Zhu","year":"2022"},{"key":"10.1016\/j.patcog.2026.113453_bib0012","series-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","first-page":"24668","article-title":"Boosting accuracy and robustness of student models via adaptive adversarial distillation","author":"Huang","year":"2023"},{"key":"10.1016\/j.patcog.2026.113453_bib0013","series-title":"European Conference on Computer Vision","first-page":"92","article-title":"Adversarially robust distillation by reducing the student-teacher variance gap","author":"Dong","year":"2024"},{"key":"10.1016\/j.patcog.2026.113453_bib0014","series-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","first-page":"28432","article-title":"Robust distillation via untargeted and targeted intermediate adversarial samples","author":"Dong","year":"2024"},{"key":"10.1016\/j.patcog.2026.113453_bib0015","unstructured":"G. Hinton, O. Vinyals, J. Dean, Distilling the knowledge in a neural network, arXiv: 1503.02531(2015)."},{"key":"10.1016\/j.patcog.2026.113453_bib0016","series-title":"ICML","first-page":"7472","article-title":"Theoretically principled trade-off between robustness and accuracy","author":"Zhang","year":"2019"},{"key":"10.1016\/j.patcog.2026.113453_bib0017","series-title":"International Conference on Learning Representations","article-title":"Towards deep learning models resistant to adversarial attacks","author":"Madry","year":"2018"},{"key":"10.1016\/j.patcog.2026.113453_bib0018","series-title":"International Conference on Machine Learning","first-page":"2206","article-title":"Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks","author":"Croce","year":"2020"},{"key":"10.1016\/j.patcog.2026.113453_bib0019","series-title":"8th International Conference on Learning Representations, ICLR","article-title":"Fast is better than free: revisiting adversarial training","author":"Wong","year":"2020"},{"key":"10.1016\/j.patcog.2026.113453_bib0020","first-page":"12881","article-title":"Make some noise: reliable and efficient single-step adversarial training","volume":"35","author":"de Jorge Aranda","year":"2022","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"10.1016\/j.patcog.2026.113453_bib0021","doi-asserted-by":"crossref","DOI":"10.1016\/j.patcog.2022.108889","article-title":"A survey of robust adversarial training in pattern recognition: fundamental, theory, and methodologies","volume":"131","author":"Qian","year":"2022","journal-title":"Pattern Recognit."},{"key":"10.1016\/j.patcog.2026.113453_bib0022","series-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","article-title":"The enemy of my enemy is my friend: exploring inverse adversaries for improving adversarial training","author":"Dong","year":"2023"},{"key":"10.1016\/j.patcog.2026.113453_bib0023","doi-asserted-by":"crossref","DOI":"10.1016\/j.patcog.2022.109182","article-title":"Adversarial training with distribution normalization and margin balance","volume":"136","author":"Cheng","year":"2023","journal-title":"Pattern Recognit."},{"key":"10.1016\/j.patcog.2026.113453_bib0024","doi-asserted-by":"crossref","DOI":"10.1016\/j.patcog.2025.111474","article-title":"Robust shortcut and disordered robustness: improving adversarial training through adaptive smoothing","volume":"163","author":"Li","year":"2025","journal-title":"Pattern Recognit."},{"key":"10.1016\/j.patcog.2026.113453_bib0025","series-title":"The Theory of Max-Min and its Application to Weapons Allocation Problems","volume":"Vol. 5","author":"Danskin","year":"2012"},{"key":"10.1016\/j.patcog.2026.113453_bib0026","unstructured":"A. Krizhevsky, G. Hinton, et al., Learning multiple layers of features from tiny images (2009)."},{"key":"10.1016\/j.patcog.2026.113453_bib0027","series-title":"2009\u202fIEEE Conference on Computer Vision and Pattern Recognition","first-page":"248","article-title":"ImageNet: a large-scale hierarchical image database","author":"Deng","year":"2009"},{"key":"10.1016\/j.patcog.2026.113453_bib0028","series-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","first-page":"113","article-title":"Autoaugment: learning augmentation strategies from data","author":"Cubuk","year":"2019"},{"key":"10.1016\/j.patcog.2026.113453_bib0029","series-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition Workshops","first-page":"702","article-title":"RandAugment: practical automated data augmentation with a reduced search space","author":"Cubuk","year":"2020"},{"key":"10.1016\/j.patcog.2026.113453_bib0030","series-title":"Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR)","article-title":"Deep residual learning for image recognition","author":"He","year":"2016"},{"key":"10.1016\/j.patcog.2026.113453_bib0031","series-title":"Proceedings of the British Machine Vision Conference BMVC","article-title":"Wide residual networks","author":"Zagoruyko","year":"2016"},{"key":"10.1016\/j.patcog.2026.113453_bib0032","series-title":"International Conference on Learning Representations, ICLR","article-title":"An image is worth 16x16 words: transformers for image recognition at scale","author":"Dosovitskiy","year":"2021"},{"key":"10.1016\/j.patcog.2026.113453_bib0033","series-title":"2017 IEEE Symposium on Security and Privacy (SP)","first-page":"39","article-title":"Towards evaluating the robustness of neural networks","author":"Carlini","year":"2017"},{"key":"10.1016\/j.patcog.2026.113453_bib0034","article-title":"Robustness and accuracy could be reconcilable by (proper) definition","author":"Pang","year":"2022","journal-title":"International Conference on Machine Learning"},{"key":"10.1016\/j.patcog.2026.113453_bib0035","unstructured":"J. Maroto, G. Ortiz-Jim\u00e9nez, P. Frossard, On the benefits of knowledge distillation for adversarial robustness, arXiv: 2203.07159(2022)."},{"key":"10.1016\/j.patcog.2026.113453_bib0036","first-page":"18599","article-title":"When adversarial training meets vision transformers: recipes from training to architecture","volume":"35","author":"Mo","year":"2022","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"10.1016\/j.patcog.2026.113453_bib0037","first-page":"26831","article-title":"Are transformers more robust than CNNs?","volume":"34","author":"Bai","year":"2021","journal-title":"Adv. Neural Inf. Process. Syst."},{"issue":"6","key":"10.1016\/j.patcog.2026.113453_bib0038","first-page":"1","article-title":"Triangular trade-off between robustness, accuracy, and fairness in deep neural networks: a survey","volume":"57","author":"Li","year":"2025","journal-title":"ACM Comput. Surv."},{"key":"10.1016\/j.patcog.2026.113453_bib0039","series-title":"Proceedings of the IEEE\/CVF International Conference on Computer Vision","first-page":"3677","article-title":"On the adversarial robustness of multi-modal foundation models","author":"Schlarmann","year":"2023"},{"key":"10.1016\/j.patcog.2026.113453_bib0040","series-title":"Proceedings of the AAAI Conference on Artificial Intelligence","first-page":"23951","article-title":"FigStep: jailbreaking large vision-language models via typographic visual prompts","volume":"Vol. 39","author":"Gong","year":"2025"}],"container-title":["Pattern Recognition"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S003132032600419X?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S003132032600419X?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,6,3]],"date-time":"2026-06-03T13:09:09Z","timestamp":1780492149000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S003132032600419X"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,11]]},"references-count":40,"alternative-id":["S003132032600419X"],"URL":"https:\/\/doi.org\/10.1016\/j.patcog.2026.113453","relation":{},"ISSN":["0031-3203"],"issn-type":[{"value":"0031-3203","type":"print"}],"subject":[],"published":{"date-parts":[[2026,11]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"SwiftDistill: Efficient robust knowledge transfer via dual-branch adversarial distillation and hardness-balanced augmentation","name":"articletitle","label":"Article Title"},{"value":"Pattern Recognition","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.patcog.2026.113453","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier Ltd. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"113453"}}