{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,20]],"date-time":"2025-06-20T21:23:32Z","timestamp":1750454612093,"version":"3.37.3"},"reference-count":21,"publisher":"IEEE","license":[{"start":{"date-parts":[[2021,9,19]],"date-time":"2021-09-19T00:00:00Z","timestamp":1632009600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2021,9,19]],"date-time":"2021-09-19T00:00:00Z","timestamp":1632009600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100012401","name":"Beijing Science and Technology Planning Project","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100012401","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2021,9,19]]},"DOI":"10.1109\/icip42928.2021.9506383","type":"proceedings-article","created":{"date-parts":[[2021,8,23]],"date-time":"2021-08-23T21:08:41Z","timestamp":1629752921000},"page":"494-498","source":"Crossref","is-referenced-by-count":5,"title":["Enhancing Adversarial Robustness For Image Classification By Regularizing Class Level Feature Distribution"],"prefix":"10.1109","author":[{"given":"Cheng","family":"Yu","sequence":"first","affiliation":[{"name":"Tsinghua University,Department of Electronic Engineering,China"}]},{"given":"Youze","family":"Xue","sequence":"additional","affiliation":[{"name":"Tsinghua University,Department of Electronic Engineering,China"}]},{"given":"Jiansheng","family":"Chen","sequence":"additional","affiliation":[{"name":"Tsinghua University,Department of Electronic Engineering,China"}]},{"given":"Yu","family":"Wang","sequence":"additional","affiliation":[{"name":"Tsinghua University,Department of Electronic Engineering,China"}]},{"given":"Huimin","family":"Ma","sequence":"additional","affiliation":[{"name":"University of Science and Technology,Beijing,China"}]}],"member":"263","reference":[{"key":"ref10","article-title":"Adversarial logit pairing","author":"kannan","year":"2018","journal-title":"arXiv preprint arXiv 1803 06373"},{"key":"ref11","first-page":"7472","article-title":"Theoretically principled trade-off between robustness and accuracy","author":"zhang","year":"2019","journal-title":"International Conference on Machine Learning"},{"key":"ref12","article-title":"Improving adversarial robustness requires revisiting misclassified examples","author":"wang","year":"2019","journal-title":"International Conference on Learning Representations"},{"key":"ref13","first-page":"1831","article-title":"Defense against adversarial attacks using feature scattering-based adversarial training","author":"zhang","year":"2019","journal-title":"Advances in neural information processing systems"},{"key":"ref14","article-title":"Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks","author":"croce","year":"2020","journal-title":"arXiv preprint arXiv 2003 07516"},{"key":"ref15","first-page":"480","article-title":"Metric learning for adversarial robustness","author":"mao","year":"2019","journal-title":"Advances in neural information processing systems"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58583-9_13"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.283"},{"key":"ref18","first-page":"448","article-title":"Batch normalization: Accelerating deep network training by reducing internal covariate shift","author":"ioffe","year":"2015","journal-title":"International Conference on Machine Learning"},{"journal-title":"Learning multiple layers of features from tiny images","year":"2009","author":"krizhevsky","key":"ref19"},{"key":"ref4","article-title":"Intriguing properties of neural networks","author":"szegedy","year":"2014","journal-title":"2nd International Conference on Learning Representations ICLR 2014"},{"key":"ref3","first-page":"2017","article-title":"Spatial transformer networks","volume":"28","author":"jaderberg","year":"2015","journal-title":"Advances in neural information processing systems"},{"key":"ref6","article-title":"Countering adversarial images using input transformations","author":"guo","year":"2017","journal-title":"arXiv preprint arXiv 1711 00540"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298640"},{"key":"ref8","article-title":"Certified defenses against adversarial examples","author":"raghunathan","year":"2018","journal-title":"International Conference on Learning Representations"},{"key":"ref7","article-title":"Defense-gan: Protecting classifiers against adversarial attacks using generative models","author":"samangouei","year":"2018","journal-title":"arXiv preprint arXiv 1805 06605"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2014.81"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1145\/3065386"},{"key":"ref9","article-title":"Towards deep learning models resistant to adversarial attacks","author":"madry","year":"2018","journal-title":"ICLRE"},{"key":"ref20","first-page":"630","article-title":"Identity mappings in deep residual networks","author":"he","year":"2016","journal-title":"European Conference on Computer Vision"},{"key":"ref21","first-page":"2579","article-title":"Visualizing data using t-sne","volume":"9","author":"der maaten","year":"2008","journal-title":"Journal of Machine Learning Research"}],"event":{"name":"2021 IEEE International Conference on Image Processing (ICIP)","start":{"date-parts":[[2021,9,19]]},"location":"Anchorage, AK, USA","end":{"date-parts":[[2021,9,22]]}},"container-title":["2021 IEEE International Conference on Image Processing (ICIP)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/9506008\/9506009\/09506383.pdf?arnumber=9506383","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,6,13]],"date-time":"2022-06-13T21:10:48Z","timestamp":1655154648000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9506383\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,9,19]]},"references-count":21,"URL":"https:\/\/doi.org\/10.1109\/icip42928.2021.9506383","relation":{},"subject":[],"published":{"date-parts":[[2021,9,19]]}}}