{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,4]],"date-time":"2026-05-04T10:23:45Z","timestamp":1777890225674,"version":"3.51.4"},"reference-count":36,"publisher":"IEEE","license":[{"start":{"date-parts":[[2025,10,19]],"date-time":"2025-10-19T00:00:00Z","timestamp":1760832000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,10,19]],"date-time":"2025-10-19T00:00:00Z","timestamp":1760832000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/100000001","name":"NSF","doi-asserted-by":"publisher","award":["2112562"],"award-info":[{"award-number":["2112562"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000183","name":"ARO","doi-asserted-by":"publisher","award":["W911NF-23-2-0224"],"award-info":[{"award-number":["W911NF-23-2-0224"]}],"id":[{"id":"10.13039\/100000183","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025,10,19]]},"DOI":"10.1109\/iccv51701.2025.00381","type":"proceedings-article","created":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T19:45:49Z","timestamp":1777491949000},"page":"3999-4008","source":"Crossref","is-referenced-by-count":0,"title":["SAFER: Sharpness Aware Layer-Selective Finetuning for Enhanced Robustness in Vision Transformers"],"prefix":"10.1109","author":[{"given":"Bhavna","family":"Gopal","sequence":"first","affiliation":[{"name":"Duke University,Durham,NC,USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Huanrui","family":"Yang","sequence":"additional","affiliation":[{"name":"University of Arizona,Tucson,AZ,USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mark","family":"Horton","sequence":"additional","affiliation":[{"name":"Duke University,Durham,NC,USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yiran","family":"Chen","sequence":"additional","affiliation":[{"name":"Duke University,Durham,NC,USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","volume-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","author":"Athalye","year":"2018"},{"key":"ref2","volume-title":"Are transformers more robust than cnns?","author":"Bai","year":"2021"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58452-8_13"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref5","volume-title":"Unlabeled data improves adversarial robustness","author":"Carmon","year":"2022"},{"key":"ref6","volume-title":"Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks","author":"Croce","year":"2020"},{"key":"ref7","article-title":"An image is worth $16 \\times 16$ words: Transformers for image recognition at scale","author":"Dosovitskiy","year":"2020","journal-title":"arXiv preprint"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1088\/1742-5468\/ac9830"},{"key":"ref9","volume-title":"Sharpness-aware minimization for efficiently improving generalization","author":"Foret","year":"2021"},{"key":"ref10","volume-title":"Explaining and harnessing adversarial examples","author":"Goodfellow","year":"2015"},{"key":"ref11","volume-title":"Criticality leveraged adversarial training (clat) for boosted performance via parameter efficiency","author":"Gopal","year":"2024"},{"key":"ref12","volume-title":"Parameter-efficient fine-tuning for large models: A comprehensive survey","author":"Han","year":"2024"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref14","volume-title":"Imagewang","author":"Howard"},{"key":"ref15","volume-title":"Lora: Low-rank adaptation of large language models","author":"Hu","year":"2021"},{"key":"ref16","volume-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-20077-9_1"},{"key":"ref18","article-title":"Dora: Weight-decomposed low-rank adaptation","author":"Liu","year":"2024","journal-title":"arXiv preprint"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00986"},{"key":"ref20","volume-title":"Towards deep learning models resistant to adversarial attacks","author":"Madry","year":"2019"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.52202\/068431-1351"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.52202\/068431-1351"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00387"},{"key":"ref24","volume-title":"Overfitting in adversarially robust deep learning","author":"Rice","year":"2020"},{"key":"ref25","volume-title":"Adversarial training for free!","author":"Shafahi","year":"2019"},{"key":"ref26","volume-title":"Intriguing properties of neural networks","author":"Szegedy","year":"2014"},{"key":"ref27","article-title":"Deeper insights into the robustness of vits towards common corruptions","author":"Tian","year":"2022","journal-title":"arXiv preprint"},{"key":"ref28","first-page":"10347","article-title":"Training data-efficient image transformers & distillation through attention","volume-title":"International conference on machine learning","author":"Touvron"},{"key":"ref29","volume-title":"Attention is all you need","author":"Vaswani","year":"2023"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00090"},{"key":"ref31","first-page":"5505","article-title":"Dverge: diversifying vulnerabilities for enhanced robust generation of ensembles","volume":"33","author":"Yang","year":"2020","journal-title":"Advances in Neural Information Processing Systems"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.5244\/c.30.87"},{"key":"ref33","volume-title":"Theoretically principled trade-off between robustness and accuracy","author":"Zhang","year":"2019"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.naacl-long.282"},{"key":"ref35","article-title":"On the duality between sharpness-aware minimization and adversarial training","author":"Zhang","year":"2024","journal-title":"arXiv preprint"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00408"}],"event":{"name":"2025 IEEE\/CVF International Conference on Computer Vision (ICCV)","location":"Honolulu, HI, USA","start":{"date-parts":[[2025,10,19]]},"end":{"date-parts":[[2025,10,25]]}},"container-title":["2025 IEEE\/CVF International Conference on Computer Vision (ICCV)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11443115\/11443287\/11446123.pdf?arnumber=11446123","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T05:33:36Z","timestamp":1777613616000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11446123\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,19]]},"references-count":36,"URL":"https:\/\/doi.org\/10.1109\/iccv51701.2025.00381","relation":{},"subject":[],"published":{"date-parts":[[2025,10,19]]}}}