{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,4]],"date-time":"2026-05-04T10:16:20Z","timestamp":1777889780647,"version":"3.51.4"},"reference-count":36,"publisher":"IEEE","license":[{"start":{"date-parts":[[2025,10,19]],"date-time":"2025-10-19T00:00:00Z","timestamp":1760832000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,10,19]],"date-time":"2025-10-19T00:00:00Z","timestamp":1760832000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100012166","name":"National Key Research and Development Program of China","doi-asserted-by":"publisher","award":["2022YFC3303200"],"award-info":[{"award-number":["2022YFC3303200"]}],"id":[{"id":"10.13039\/501100012166","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100021171","name":"GuangDong Basic and Applied Basic Research Foundation","doi-asserted-by":"publisher","award":["2024A1515010229"],"award-info":[{"award-number":["2024A1515010229"]}],"id":[{"id":"10.13039\/501100021171","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025,10,19]]},"DOI":"10.1109\/iccv51701.2025.00283","type":"proceedings-article","created":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T19:45:49Z","timestamp":1777491949000},"page":"2951-2960","source":"Crossref","is-referenced-by-count":0,"title":["Scaling and Taming Adversarial Training with Synthetic Data"],"prefix":"10.1109","author":[{"given":"Juntao","family":"Wu","sequence":"first","affiliation":[{"name":"Jinan University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xianting","family":"Huang","sequence":"additional","affiliation":[{"name":"Jinan University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yu","family":"Chen","sequence":"additional","affiliation":[{"name":"Jinan University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shuai","family":"Pang","sequence":"additional","affiliation":[{"name":"Jinan University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ke","family":"Wang","sequence":"additional","affiliation":[{"name":"Jinan University"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","article-title":"Understanding and improving fast adversarial training","author":"Andriushchenko","year":"2020","journal-title":"NeurIPS"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58592-1_29"},{"key":"ref3","article-title":"Synthetic data from diffusion models improves imagenet classification","author":"Azizi","year":"2023","journal-title":"arXiv preprint arXiv"},{"key":"ref4","article-title":"Adversarial robustness limits via scaling-law and human-alignment studies","author":"Bartoldson","year":"2024","journal-title":"arXiv preprint arXiv"},{"key":"ref5","article-title":"Robust overfitting may be mitigated by properly learned smoothening","volume-title":"International Conference on Learning Representations","author":"Chen","year":"2021"},{"key":"ref6","first-page":"2196","article-title":"Minimally distorted adversarial examples with a fast adaptive boundary attack","volume-title":"International Conference on Machine Learning","author":"Croce"},{"key":"ref7","article-title":"Robustbench: a standardized adversarial robustness benchmark","author":"Croce","year":"2020","journal-title":"arXiv preprint arXiv"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW50498.2020.00359"},{"key":"ref9","first-page":"7480","article-title":"Scaling vision transformers to 22 billion parameters","volume-title":"International Conference on Machine Learning","author":"Dehghani"},{"key":"ref10","article-title":"Exploring memorization in adversarial training","volume-title":"International Conference on Learning Representations","author":"Dong","year":"2022"},{"key":"ref11","article-title":"Explaining and harnessing adversarial examples","author":"Goodfellow","year":"2014","journal-title":"arXiv preprint arXiv"},{"key":"ref12","first-page":"4218","article-title":"Improving robustness using generated data","volume":"34","author":"Gowal","year":"2021","journal-title":"Advances in Neural Information Processing Systems"},{"key":"ref13","first-page":"6840","article-title":"Denoising diffusion probabilistic models","volume":"33","author":"Ho","year":"2020","journal-title":"Advances in neural information processing systems"},{"key":"ref14","article-title":"Loss spike in training neural networks","author":"Li","year":"2023","journal-title":"arXiv preprint arXiv"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-024-02196-3"},{"key":"ref16","article-title":"Towards deep learning models resistant to adversarial attacks","author":"Madry","year":"2017","journal-title":"arXiv preprint arXiv"},{"key":"ref17","article-title":"A theory on adam instability in large-scale machine learning","author":"Molybog","year":"2023","journal-title":"arXiv preprint arXiv"},{"key":"ref18","article-title":"Robustness to adversarial perturbations in learning from incomplete data","volume":"32","author":"Najafi","year":"2019","journal-title":"Advances in Neural Information Processing Systems"},{"key":"ref19","article-title":"Robust principles: Architectural design principles for adversarially robust cnns","author":"Peng","year":"2023","journal-title":"arXiv preprint arXiv"},{"key":"ref20","first-page":"8093","article-title":"Overfitting in adversarially robust deep learning","volume-title":"International conference on machine learning","author":"Rice","year":"2020"},{"key":"ref21","article-title":"Adversarially robust generalization requires more data","volume":"31","author":"Schmidt","year":"2018","journal-title":"Advances in neural information processing systems"},{"key":"ref22","article-title":"Revisiting adversarial training for imagenet: Architectures, training and generalization across threat models","volume":"36","author":"Deep Singh","year":"2024","journal-title":"Advances in Neural Information Processing Systems"},{"key":"ref23","article-title":"Score-based generative modeling through stochastic differential equations","author":"Song","year":"2020","journal-title":"arXiv preprint arXiv"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00714"},{"key":"ref25","article-title":"Spike no more: Stabilizing the pre-training of large language models","author":"Takase","year":"2023","journal-title":"arXiv preprint arXiv"},{"key":"ref26","article-title":"Improving adversarial robustness requires revisiting misclassified examples","volume-title":"International conference on learning representations","author":"Wang","year":"2019"},{"key":"ref27","first-page":"36246","article-title":"Better diffusion models further improve adversarial training","volume-title":"International Conference on Machine Learning","author":"Wang"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.02330"},{"key":"ref29","article-title":"Stable and low-precision training for large-scale vision-language models. arxiv 2023","author":"Wortsman","journal-title":"arXiv preprint arXiv"},{"key":"ref30","article-title":"Mimir: Masked image modeling for mutual information-based adversarial robustness","author":"Xu","year":"2023","journal-title":"arXiv preprint arXiv"},{"key":"ref31","article-title":"Understanding robust overfitting of adversarial training and beyond","author":"Yu","year":"2022","journal-title":"arXiv preprint arXiv"},{"key":"ref32","article-title":"Representation alignment for generation: Training diffusion transformers is easier than you think","author":"Yu","year":"2024","journal-title":"arXiv preprint arXiv"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2023.3329173"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00612"},{"key":"ref35","article-title":"Adversarially robust generalization just requires more unlabeled data","author":"Zhai","year":"2019","journal-title":"arXiv preprint arXiv"},{"key":"ref36","article-title":"mixup: Beyond empirical risk minimization","author":"Zhang","year":"2017","journal-title":"arXiv preprint arXiv"}],"event":{"name":"2025 IEEE\/CVF International Conference on Computer Vision (ICCV)","location":"Honolulu, HI, USA","start":{"date-parts":[[2025,10,19]]},"end":{"date-parts":[[2025,10,25]]}},"container-title":["2025 IEEE\/CVF International Conference on Computer Vision (ICCV)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11443115\/11443287\/11445154.pdf?arnumber=11445154","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T05:19:23Z","timestamp":1777612763000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11445154\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,19]]},"references-count":36,"URL":"https:\/\/doi.org\/10.1109\/iccv51701.2025.00283","relation":{},"subject":[],"published":{"date-parts":[[2025,10,19]]}}}