{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,4]],"date-time":"2026-05-04T10:20:47Z","timestamp":1777890047235,"version":"3.51.4"},"reference-count":91,"publisher":"IEEE","license":[{"start":{"date-parts":[[2025,10,19]],"date-time":"2025-10-19T00:00:00Z","timestamp":1760832000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,10,19]],"date-time":"2025-10-19T00:00:00Z","timestamp":1760832000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025,10,19]]},"DOI":"10.1109\/iccv51701.2025.00223","type":"proceedings-article","created":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T19:45:49Z","timestamp":1777491949000},"page":"2313-2324","source":"Crossref","is-referenced-by-count":0,"title":["Adversarial Robustness of Discriminative Self-Supervised Learning in Vision"],"prefix":"10.1109","author":[{"given":"\u00d6mer Veysel","family":"\u00c7a\u011fatan","sequence":"first","affiliation":[{"name":"Ko&#x00E7; University,Department of Computer Engineering"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"\u00d6mer Faruk","family":"Tal","sequence":"additional","affiliation":[{"name":"Ko&#x00E7; University,Department of Computer Engineering"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"M. Emre","family":"G\u00fcrsoy","sequence":"additional","affiliation":[{"name":"Ko&#x00E7; University,Department of Computer Engineering"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","author":"Markus Asano","year":"2020","journal-title":"Self-labelling via simultaneous clustering and representation learning"},{"key":"ref2","author":"Bai","year":"2021","journal-title":"Are transformers more robust than cnns?"},{"key":"ref3","author":"Bai","year":"2022","journal-title":"Improving adversarial robustness via channel-wise activation suppressing"},{"key":"ref4","volume":"abs\/2304.12210","author":"Balestriero","year":"2023","journal-title":"A cookbook of self-supervised learning"},{"key":"ref5","author":"Bardes","year":"2022","journal-title":"Vicreg: Variance-invariance-covariance regularization for selfsupervised learning"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1126\/science.adn0117"},{"key":"ref7","author":"Bommasani","year":"2022","journal-title":"On the opportunities and risks of foundation models"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-10599-4_29"},{"key":"ref9","author":"Carmon","year":"2022","journal-title":"Unlabeled data improves adversarial robustness"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01264-9_9"},{"key":"ref11","author":"Caron","year":"2020","journal-title":"Unsupervised learning of visual features by contrasting cluster assignments"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00951"},{"key":"ref13","author":"Chakraborty","year":"2018","journal-title":"Adversarial attacks and defences: A survey"},{"key":"ref14","author":"Chaubey","year":"2020","journal-title":"Universal adversarial perturbations: A survey"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01234-2_49"},{"key":"ref16","volume":"abs\/2002.05709","author":"Chen","year":"2020","journal-title":"A simple framework for contrastive learning of visual representations"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00078"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01549"},{"key":"ref19","author":"Chen","year":"2020","journal-title":"Improved baselines with momentum contrastive learning"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00950"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/iccvw60793.2023.00481"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/cvpr.2014.461"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.350"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2005.177"},{"key":"ref25","author":"Dehghani","year":"2023","journal-title":"Scaling vision transformers to 22 billion parameters"},{"key":"ref26","author":"Devlin","year":"2019","journal-title":"Bert: Pre-training of deep bidirectional transformers for language understanding"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"ref28","author":"Dosovitskiy","year":"2021","journal-title":"An image is worth 16x16 words: Transformers for image recognition at scale"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00537"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.70675\/dc53ad72z177fz4bb4z91fbzd00576ba3f2e"},{"key":"ref31","volume-title":"The PASCAL Visual Object Classes Challenge 2012 (VOC2012) Results","author":"Everingham"},{"key":"ref32","author":"Fawzi","year":"2016","journal-title":"Robustness of classifiers: from adversarial to random noise"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2004.383"},{"key":"ref34","author":"Goldblum","year":"2023","journal-title":"Battle of the backbones: A large-scale comparison of pretrained models across computer vision tasks"},{"key":"ref35","author":"Goodfellow","year":"2014","journal-title":"Explaining and harnessing adversarial examples"},{"key":"ref36","volume":"abs\/2006.07733","author":"Grill","year":"2020","journal-title":"Bootstrap your own latent: A new approach to self-supervised learning"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v37i12.26733"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/cvpr.2016.90"},{"key":"ref39","author":"He","year":"2019","journal-title":"Momentum contrast for unsupervised visual representation learning"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01553"},{"key":"ref41","author":"Hendrycks","year":"2019","journal-title":"Using self-supervised learning can improve model robustness and uncertainty"},{"key":"ref42","author":"Ho","year":"2020","journal-title":"Contrastive learning with adversarial examples"},{"key":"ref43","author":"Ho","year":"2020","journal-title":"Denoising diffusion probabilistic models"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.01965"},{"key":"ref45","author":"Huh","year":"2016","journal-title":"What makes imagenet good for transfer learning?"},{"key":"ref46","author":"Ibrahim","year":"2024","journal-title":"Occam\u2019s razor for self supervised learning: What is sufficient to learn good representations?"},{"key":"ref47","author":"Ilyas","year":"2019","journal-title":"Adversarial examples are not bugs, they are features"},{"key":"ref48","author":"Jiang","year":"2020","journal-title":"Robust pre-training by adversarial contrastive learning"},{"key":"ref49","author":"Kim","year":"2020","journal-title":"Adversarial self-supervised contrastive learning"},{"key":"ref50","author":"Jin Kim","year":"2024","journal-title":"Openvla: An opensource vision-language-action model"},{"key":"ref51","author":"Kingma","year":"2017","journal-title":"Adam: A method for stochastic optimization"},{"key":"ref52","author":"Kowalczuk","year":"2024","journal-title":"Benchmarking robust self-supervised learning across diverse downstream tasks"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1109\/ICCVW.2013.77"},{"key":"ref54","author":"Krizhevsky","year":"2009","journal-title":"Learning multiple layers of features from tiny images"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"key":"ref56","author":"Li","year":"2024","journal-title":"Adversarial examples are not real features"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-10602-1_48"},{"key":"ref58","author":"Luo","year":"2023","journal-title":"Rethinking the effect of data augmentation in adversarial contrastive learning"},{"key":"ref59","author":"Madry","year":"2017","journal-title":"Towards deep learning models resistant to adversarial attacks"},{"key":"ref60","author":"Maji","year":"2013","journal-title":"Fine-grained visual classification of aircraft"},{"key":"ref61","author":"Morningstar","year":"2024","journal-title":"Augmentations vs algorithms: What works in self-supervised learning"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00034"},{"key":"ref63","first-page":"543","article-title":"A method for solving the convex programming problem with convergence rate $o\\left(1 \/ k^{2}\\right)$","volume-title":"Proceedings of the USSR Academy of Sciences","volume":"269","author":"Nesterov","year":"1983"},{"key":"ref64","author":"Tuan Nguyen","year":"2022","journal-title":"Taskagnostic robust representation learning"},{"key":"ref65","author":"Oquab","year":"2024","journal-title":"Dinov2: Learning robust visual features without supervision"},{"key":"ref66","author":"Ozbulak","year":"2023","journal-title":"Know your self-supervised learning: A survey on image-based generative and discriminative training"},{"key":"ref67","author":"Ozsoy","year":"2022","journal-title":"Self-supervised learning with an information maximization criterion"},{"key":"ref68","author":"Paszke","year":"2019","journal-title":"Pytorch: An imperative style, high-performance deep learning library"},{"key":"ref69","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-19778-9_27"},{"key":"ref70","author":"Pintor","year":"2021","journal-title":"Fast minimum-norm adversarial attacks through adaptive norm constraints"},{"key":"ref71","author":"Radford","year":"2018","journal-title":"Improving language understanding by generative pre-training"},{"key":"ref72","author":"Ren","year":"2016","journal-title":"Faster r-cnn: Towards real-time object detection with region proposal networks"},{"key":"ref73","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.01966"},{"key":"ref74","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-015-0816-y"},{"key":"ref75","author":"Schmidt","year":"2018","journal-title":"Adversarially robust generalization requires more data"},{"key":"ref76","author":"Shafahi","year":"2020","journal-title":"Are adversarial examples inevitable?"},{"key":"ref77","article-title":"Improved deep metric learning with multiclass n-pair loss objective","author":"Sohn","year":"2016","journal-title":"Neural Information Processing Systems"},{"key":"ref78","author":"Szegedy","year":"2013","journal-title":"Intriguing properties of neural networks"},{"key":"ref79","author":"Tanay","year":"2016","journal-title":"A boundary tilting persepective on the phenomenon of adversarial examples"},{"key":"ref80","author":"Touvron","year":"2023","journal-title":"Llama: Open and efficient foundation language models"},{"key":"ref81","author":"van den Oord","year":"2019","journal-title":"Representation learning with contrastive predictive coding"},{"issue":"86","key":"ref82","first-page":"2579","article-title":"Visualizing data using t -sne","volume":"9","author":"van der Maaten","year":"2008","journal-title":"Journal of Machine Learning Research"},{"key":"ref83","article-title":"Improving adversarial robustness requires revisiting misclassified examples","author":"Wang","year":"2020","journal-title":"In ICLR"},{"key":"ref84","author":"Wang","year":"2022","journal-title":"On the convergence and robustness of adversarial training"},{"key":"ref85","author":"Wu","year":"2020","journal-title":"Adversarial weight perturbation helps robust generalization"},{"key":"ref86","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.153"},{"key":"ref87","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00090"},{"key":"ref88","author":"Xu","year":"2023","journal-title":"Efficient adversarial contrastive learning via robustness-aware coreset selection"},{"key":"ref89","author":"Zbontar","year":"2021","journal-title":"Barlow twins: Self-supervised learning via redundancy reduction"},{"key":"ref90","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-20056-4_42"},{"key":"ref91","author":"Zhong","year":"2022","journal-title":"Is self-supervised learning more robust than supervised learning?"}],"event":{"name":"2025 IEEE\/CVF International Conference on Computer Vision (ICCV)","location":"Honolulu, HI, USA","start":{"date-parts":[[2025,10,19]]},"end":{"date-parts":[[2025,10,25]]}},"container-title":["2025 IEEE\/CVF International Conference on Computer Vision (ICCV)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11443115\/11443287\/11443415.pdf?arnumber=11443415","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T05:28:40Z","timestamp":1777613320000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11443415\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,19]]},"references-count":91,"URL":"https:\/\/doi.org\/10.1109\/iccv51701.2025.00223","relation":{},"subject":[],"published":{"date-parts":[[2025,10,19]]}}}