{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,6]],"date-time":"2026-02-06T00:23:12Z","timestamp":1770337392476,"version":"3.49.0"},"reference-count":57,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Access"],"published-print":{"date-parts":[[2024]]},"DOI":"10.1109\/access.2023.3347498","type":"journal-article","created":{"date-parts":[[2023,12,25]],"date-time":"2023-12-25T20:13:53Z","timestamp":1703535233000},"page":"48174-48188","source":"Crossref","is-referenced-by-count":1,"title":["Knowing is Half the Battle: Enhancing Clean Data Accuracy of Adversarial Robust Deep Neural Networks via Dual-Model Bounded Divergence Gating"],"prefix":"10.1109","volume":"12","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-4396-3993","authenticated-orcid":false,"given":"Hossein","family":"Aboutalebi","sequence":"first","affiliation":[{"name":"Department of Computer Science, University of Waterloo, Waterloo, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5989-8255","authenticated-orcid":false,"given":"Mohammad Javad","family":"Shafiee","sequence":"additional","affiliation":[{"name":"Department of Systems Design, University of Waterloo, Waterloo, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7023-8784","authenticated-orcid":false,"given":"Chi-En Amy","family":"Tai","sequence":"additional","affiliation":[{"name":"Department of Systems Design, University of Waterloo, Waterloo, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5729-5899","authenticated-orcid":false,"given":"Alexander","family":"Wong","sequence":"additional","affiliation":[{"name":"Department of Systems Design, University of Waterloo, Waterloo, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref2","first-page":"1097","article-title":"Imagenet classification with deep convolutional neural networks","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Krizhevsky"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/ISCAS.2010.5537907"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.91"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.03762"},{"key":"ref6","article-title":"Google\u2019s neural machine translation system: Bridging the gap between human and machine translation","author":"Wu","year":"2016","journal-title":"arXiv:1609.08144"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1038\/srep46450"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1038\/s41591-018-0107-6"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"ref10","article-title":"Intriguing properties of neural networks","author":"Szegedy","year":"2013","journal-title":"arXiv:1312.6199"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v30i1.10237"},{"key":"ref12","article-title":"Adversarial regression with multiple learners","author":"Tong","year":"2018","journal-title":"arXiv:1806.02256"},{"key":"ref13","article-title":"Explaining and harnessing adversarial examples","author":"Goodfellow","year":"2014","journal-title":"arXiv:1412.6572"},{"key":"ref14","article-title":"Learning with a strong adversary","author":"Huang","year":"2015","journal-title":"arXiv:1511.03034"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298640"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00277"},{"key":"ref17","article-title":"Robustness (Python library)","author":"Engstrom","year":"2019"},{"key":"ref18","article-title":"Towards deep learning models resistant to adversarial attacks","author":"Madry","year":"2017","journal-title":"arXiv:1706.06083"},{"key":"ref19","article-title":"Rethinking bias-variance trade-off for generalization of neural networks","author":"Yang","year":"2020","journal-title":"arXiv:2002.11328"},{"key":"ref20","article-title":"On the upper bound of the Kullback\u2013Leibler divergence and cross entropy","author":"Chen","year":"2019","journal-title":"arXiv:1911.08334"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00090"},{"key":"ref22","article-title":"Towards defending multiple adversarial perturbations via gated batch normalization","author":"Liu","year":"2020","journal-title":"arXiv:2012.01654"},{"key":"ref23","first-page":"1317","article-title":"Perturbation type categorization for multiple adversarial perturbation robustness","volume-title":"Proc. 38th Conf. Uncertainty Artif. Intell.","author":"Maini"},{"key":"ref24","first-page":"2206","article-title":"Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Croce"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58592-1_29"},{"key":"ref26","first-page":"2196","article-title":"Minimally distorted adversarial examples with a fast adaptive boundary attack","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Croce"},{"key":"ref27","article-title":"Adversarial machine learning at scale","author":"Kurakin","year":"2016","journal-title":"arXiv:1611.01236"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.308"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-015-0816-y"},{"key":"ref30","article-title":"ADV-BNN: Improved adversarial defense through robust Bayesian neural network","author":"Liu","year":"2018","journal-title":"arXiv:1810.01279"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.41"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1145\/3422622"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1145\/3626235"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1007\/s11633-019-1211-x"},{"key":"ref36","article-title":"Defense-GAN: Protecting classifiers against adversarial attacks using generative models","author":"Samangouei","year":"2018","journal-title":"arXiv:1805.06605"},{"key":"ref37","article-title":"Diffusion models for adversarial purification","author":"Nie","year":"2022","journal-title":"arXiv:2205.07460"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.01149"},{"key":"ref39","article-title":"RobustBench: A standardized adversarial robustness benchmark","author":"Croce","year":"2020","journal-title":"arXiv:2010.09670"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1162\/neco.1992.4.1.1"},{"key":"ref41","article-title":"Fast is better than free: Revisiting adversarial training","author":"Wong","year":"2020","journal-title":"arXiv:2001.03994"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.5244\/C.30.87"},{"key":"ref43","volume-title":"Thomas\u2019 Calculus","author":"Thomas","year":"2010"},{"key":"ref44","article-title":"A generalized bias-variance decomposition for Bregman divergences","author":"Pfau","year":"2013"},{"key":"ref45","first-page":"231","article-title":"A unified bias-variance decomposition","volume-title":"Proc. 17th Int. Conf. Mach. Learn.","author":"Domingos"},{"key":"ref46","first-page":"4218","article-title":"Improving robustness using generated data","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"34","author":"Gowal"},{"key":"ref47","first-page":"2958","article-title":"Adversarial weight perturbation helps robust generalization","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"33","author":"Wu"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.23919\/ACC53348.2022.9867880"},{"key":"ref49","article-title":"Geometry-aware instance-reweighted adversarial training","author":"Zhang","year":"2020","journal-title":"arXiv:2010.01736"},{"key":"ref50","article-title":"Robust learning meets generative models: Can proxy distributions improve adversarial robustness?","author":"Sehwag","year":"2021","journal-title":"arXiv:2104.09425"},{"key":"ref51","first-page":"16048","article-title":"Understanding and improving fast adversarial training","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"33","author":"Andriushchenko"},{"key":"ref52","article-title":"Fixing data augmentation to improve adversarial robustness","author":"Rebuffi","year":"2021","journal-title":"arXiv:2103.01946"},{"key":"ref53","article-title":"Theoretically principled trade-off between robustness and accuracy","author":"Zhang","year":"2019","journal-title":"arXiv:1901.08573"},{"key":"ref54","first-page":"274","article-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Athalye"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref56","article-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-46493-0_38"}],"container-title":["IEEE Access"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/6287639\/10380310\/10374121.pdf?arnumber=10374121","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,4,8]],"date-time":"2024-04-08T21:13:47Z","timestamp":1712610827000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10374121\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024]]},"references-count":57,"URL":"https:\/\/doi.org\/10.1109\/access.2023.3347498","relation":{},"ISSN":["2169-3536"],"issn-type":[{"value":"2169-3536","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024]]}}}