{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,4]],"date-time":"2026-05-04T10:04:38Z","timestamp":1777889078891,"version":"3.51.4"},"reference-count":52,"publisher":"IEEE","license":[{"start":{"date-parts":[[2025,10,19]],"date-time":"2025-10-19T00:00:00Z","timestamp":1760832000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,10,19]],"date-time":"2025-10-19T00:00:00Z","timestamp":1760832000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["CNS-2343611"],"award-info":[{"award-number":["CNS-2343611"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000183","name":"U.S. Army Research Office","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100000183","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100014036","name":"MURI","doi-asserted-by":"publisher","award":["W911NF-21-1-0317"],"award-info":[{"award-number":["W911NF-21-1-0317"]}],"id":[{"id":"10.13039\/100014036","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025,10,19]]},"DOI":"10.1109\/iccv51701.2025.00466","type":"proceedings-article","created":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T19:45:49Z","timestamp":1777491949000},"page":"4898-4907","source":"Crossref","is-referenced-by-count":0,"title":["On the Robustness Tradeoff in Fine-Tuning"],"prefix":"10.1109","author":[{"given":"Kunyang","family":"Li","sequence":"first","affiliation":[{"name":"University of Wisconsin-Madison"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jean-Charles Noirot","family":"Ferrand","sequence":"additional","affiliation":[{"name":"University of Wisconsin-Madison"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ryan","family":"Sheatsley","sequence":"additional","affiliation":[{"name":"University of Wisconsin-Madison"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Blaine","family":"Hoak","sequence":"additional","affiliation":[{"name":"University of Wisconsin-Madison"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yohan","family":"Beugin","sequence":"additional","affiliation":[{"name":"University of Wisconsin-Madison"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Eric","family":"Pauley","sequence":"additional","affiliation":[{"name":"University of Wisconsin-Madison"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Patrick","family":"McDaniel","sequence":"additional","affiliation":[{"name":"University of Wisconsin-Madison"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","volume-title":"AdapterHub. AdapterHub Documentation - AdapterHub documentation","year":"2025"},{"key":"ref2","article-title":"Language Models are Few-Shot Learners","author":"Brown","year":"2020","journal-title":"arXiv"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref4","article-title":"CARTL: Cooperative AdversariallyRobust Transfer Learning","author":"Chen","year":"2021","journal-title":"arXiv"},{"key":"ref5","article-title":"Parameter-Efficient Fine-Tuning Design Spaces","author":"Chen","year":"2023","journal-title":"arXiv"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00078"},{"key":"ref7","article-title":"Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks","author":"Croce","year":"2020","journal-title":"arXiv"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP.2018.8462506"},{"key":"ref9","article-title":"An Image is Worth 16x16 Words: Transformers for Image Recognition at Scale","author":"Dosovitskiy","year":"2021","journal-title":"arXiv"},{"key":"ref10","article-title":"KronA: Parameter Efficient Tuning with Kronecker Adapter","author":"Edalati","year":"2022","journal-title":"arXiv"},{"key":"ref11","article-title":"Explaining and Harnessing Adversarial Examples","author":"Goodfellow","year":"2015","journal-title":"arXiv"},{"key":"ref12","article-title":"Criticality Leveraged Adversarial Training (CLAT) for Boosted Performance via Parameter Efficiency","author":"Gopal","year":"2024","journal-title":"arXiv"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.4135\/9781412963954.n28"},{"key":"ref14","article-title":"ParameterEfficient Transfer Learning with Diff Pruning","author":"Guo","year":"2021","journal-title":"arXiv"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v37i1.25160"},{"key":"ref16","article-title":"Parameter-Efficient Transfer Learning for NLP","author":"Houlsby","year":"2019","journal-title":"arXiv"},{"key":"ref17","article-title":"LoRA: Low-Rank Adaptation of Large Language Models","author":"Hu","year":"2021","journal-title":"arXiv"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.02345"},{"key":"ref19","volume-title":"google\/vit-base-patch16-224-in21k\u22c5Hugging Face","year":"2025"},{"key":"ref20","article-title":"Adversarial Examples Are Not Bugs, They Are Features","author":"Ilyas","year":"2019","journal-title":"arXiv"},{"key":"ref21","article-title":"A Simple Fine-tuning Is All You Need: Towards Robust Deep Learning Via Adversarial Fine-tuning","author":"Jeddi","year":"2020","journal-title":"arXiv"},{"key":"ref22","first-page":"16199","article-title":"Robust Pre-Training by Adversarial Contrastive Learning","volume-title":"Advances in Neural Information Processing Systems","author":"Jiang","year":"2020"},{"key":"ref23","article-title":"Novel Dataset for Fine-Grained Image Categorization: Stanford Dogs. In Workshop on FineGrained Visual Categorization (FGVI)","volume-title":"IEEE Conference on Computer Vision and Pattern Recognition (CVPR)","author":"Khosla"},{"key":"ref24","article-title":"Torchattacks: A PyTorch Repository for Adversarial Attacks","author":"Kim","year":"2021","journal-title":"arXiv"},{"key":"ref25","volume-title":"CIFAR-10 and CIFAR-100 datasets","author":"Krizhevsky","year":"2009"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1145\/3065386"},{"key":"ref27","article-title":"Fine-Tuning can Distort Pretrained Features and Underperform Out-of-Distribution","author":"Kumar","year":"2022","journal-title":"arXiv"},{"key":"ref28","article-title":"Fastfood: Approximate Kernel Expansions in Loglinear Time","author":"Le","year":"2014","journal-title":"arXiv"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.emnlp-main.243"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.acllong.353"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.00730"},{"key":"ref32","article-title":"Scaling Down to Scale Up: A Guide to Parameter-Efficient Fine-Tuning","author":"Lialin","year":"2024","journal-title":"arXiv"},{"key":"ref33","article-title":"To the Fairness Frontier and Beyond: Identifying, Quantifying, and Optimizing the Fairness-Accuracy Pareto Frontier","author":"Little","year":"2022","journal-title":"arXiv"},{"key":"ref34","article-title":"Few-Shot Parameter-Efficient Fine-Tuning is Better and Cheaper than In-Context Learning","author":"Liu","year":"2022","journal-title":"arXiv"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.01577"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.06083"},{"key":"ref37","article-title":"Compacter: Efficient Low-Rank Hypercomplex Adapter Layers","author":"Mahabadi","year":"2021","journal-title":"arXiv"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1145\/1015330.1015435"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.emnlp-main.1180"},{"key":"ref40","article-title":"The Limitations of Deep Learning in Adversarial Settings","author":"Papernot","year":"2015","journal-title":"arXiv"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00149"},{"key":"ref42","article-title":"Do CIFAR-10 Classifiers Generalize to CIFAR-10?","author":"Recht","year":"2018","journal-title":"arXiv"},{"key":"ref43","article-title":"ImageNet-21K Pretraining for the Masses","author":"Ridnik","year":"2021","journal-title":"arXiv"},{"key":"ref44","article-title":"Scale Efficiently: Insights from Pre-training and Fine-tuning Transformers","author":"Tay","year":"2022","journal-title":"arXiv"},{"key":"ref45","article-title":"Robustness May Be at Odds with Accuracy","author":"Tsipras","year":"2019","journal-title":"arXiv"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.03762"},{"key":"ref47","volume-title":"The Caltech-UCSD Birds-2002011 Dataset","author":"Wah","year":"2011"},{"key":"ref48","article-title":"AutoLoRa: A Parameter-Free Automated Robust Fine-Tuning Framework","author":"Xu","year":"2023","journal-title":"arXiv"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2022.acl-short.1"},{"key":"ref50","article-title":"A Large-scale Study of Representation Learning with the Visual Task Adaptation Benchmark","author":"Zhai","year":"2020","journal-title":"arXiv"},{"key":"ref51","first-page":"7472","article-title":"Theoretically Principled Trade-off between Robustness and Accuracy","volume-title":"Proceedings of the 36th International Conference on Machine Learning","author":"Zhang"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2017.2723009"}],"event":{"name":"2025 IEEE\/CVF International Conference on Computer Vision (ICCV)","location":"Honolulu, HI, USA","start":{"date-parts":[[2025,10,19]]},"end":{"date-parts":[[2025,10,25]]}},"container-title":["2025 IEEE\/CVF International Conference on Computer Vision (ICCV)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11443115\/11443287\/11443414.pdf?arnumber=11443414","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T05:06:33Z","timestamp":1777611993000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11443414\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,19]]},"references-count":52,"URL":"https:\/\/doi.org\/10.1109\/iccv51701.2025.00466","relation":{},"subject":[],"published":{"date-parts":[[2025,10,19]]}}}