{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,15]],"date-time":"2026-01-15T22:51:59Z","timestamp":1768517519522,"version":"3.49.0"},"reference-count":51,"publisher":"IEEE","license":[{"start":{"date-parts":[[2025,12,14]],"date-time":"2025-12-14T00:00:00Z","timestamp":1765670400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,12,14]],"date-time":"2025-12-14T00:00:00Z","timestamp":1765670400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100012166","name":"National Key R&D Program of China","doi-asserted-by":"publisher","award":["2022ZD0160201"],"award-info":[{"award-number":["2022ZD0160201"]}],"id":[{"id":"10.13039\/501100012166","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025,12,14]]},"DOI":"10.1109\/icpads67057.2025.11322909","type":"proceedings-article","created":{"date-parts":[[2026,1,14]],"date-time":"2026-01-14T20:36:54Z","timestamp":1768423014000},"page":"1-8","source":"Crossref","is-referenced-by-count":0,"title":["Two Heads are Better than One: Robust Learning Meets Multi-branch Models"],"prefix":"10.1109","author":[{"given":"Zongyuan","family":"Zhang","sequence":"first","affiliation":[{"name":"The University of Hong Kong,Department of Computer Science,Hong Kong,China"}]},{"given":"Qingwen","family":"Bu","sequence":"additional","affiliation":[{"name":"Shanghai Jiao Tong University,Department of Electronic Engineering,Shanghai,China"}]},{"given":"Tianyang","family":"Duan","sequence":"additional","affiliation":[{"name":"The University of Hong Kong,Department of Computer Science,Hong Kong,China"}]},{"given":"Zheng","family":"Lin","sequence":"additional","affiliation":[{"name":"The University of Hong Kong,Department of Electrical and Electronic Engineering,Hong Kong,China"}]},{"given":"Yuhao","family":"Qing","sequence":"additional","affiliation":[{"name":"The University of Hong Kong,Department of Computer Science,Hong Kong,China"}]},{"given":"Zihan","family":"Fang","sequence":"additional","affiliation":[{"name":"City University of Hong Kong,Department of Computer Science,Hong Kong,China"}]},{"given":"Heming","family":"Cui","sequence":"additional","affiliation":[{"name":"The University of Hong Kong,Department of Computer Science,Hong Kong,China"}]},{"given":"Dong","family":"Huang","sequence":"additional","affiliation":[{"name":"School of Computing, National University of Singapore,Singapore"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/TMC.2024.3359040"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM55648.2025.11044496"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/tmc.2024.3509861"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/ton.2025.3577790"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/tmc.2025.3649881"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/TMC.2025.3565509"},{"key":"ref7","article-title":"Sample efficient experience replay in nonstationary environments","author":"Duan","year":"2025","journal-title":"arXiv preprint"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/TGCN.2024.3424552"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/IROS60139.2025.11246652"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP49660.2025.10890540"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2025.3601175"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/TMC.2025.3601531"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/tits.2021.3108520"},{"key":"ref14","article-title":"IC3M: In-Car Multimodal Multi-Object Monitoring for Abnormal Status of Both Driver and Passengers","author":"Fang","year":"2024","journal-title":"arXiv preprint"},{"key":"ref15","article-title":"HSplitLoRA: A Heterogeneous Split ParameterEfficient Fine-Tuning Framework for Large Language Models","author":"Lin","year":"2025","journal-title":"arXiv preprint"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1038\/s41591-018-0107-6"},{"key":"ref17","article-title":"Dynamic uncertainty-aware multimodal fusion for outdoor health monitoring","author":"Fang","year":"2025","journal-title":"arXiv preprint"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/SWC62898.2024.00178"},{"key":"ref19","first-page":"2206","article-title":"Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks","volume-title":"in Int. Conf. Mach. Learn. PMLR","author":"Croce"},{"key":"ref20","article-title":"Intriguing properties of neural networks","author":"Szegedy","year":"2013","journal-title":"arXiv preprint"},{"key":"ref21","first-page":"284","article-title":"Synthesizing robust adversarial examples","volume-title":"in Int. Conf. Mach. Learn. PMLR","author":"Athalye"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00132"},{"key":"ref23","article-title":"Towards deep learning models resistant to adversarial attacks","author":"Madry","year":"2017","journal-title":"arXiv preprint"},{"key":"ref24","article-title":"Deep defense: Training dnns with improved adversarial robustness","volume":"31","author":"Yan","year":"2018","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"ref25","article-title":"Fast is better than free: Revisiting adversarial training","author":"Wong","year":"2020","journal-title":"arXiv preprint"},{"key":"ref26","article-title":"Unlabeled data improves adversarial robustness","volume":"32","author":"Carmon","year":"2019","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"ref27","first-page":"11278","article-title":"Attacks which do not kill training make adversarial learning stronger","volume-title":"in Int. Conf. Mach. Learn. PMLR","author":"Zhang"},{"key":"ref28","article-title":"Robustness to adversarial perturbations in learning from incomplete data","volume":"32","author":"Najafi","year":"2019","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"ref29","article-title":"Adversarially robust generalization just requires more unlabeled data","author":"Zhai","year":"2019","journal-title":"arXiv preprint"},{"key":"ref30","article-title":"Uncovering the limits of adversarial training against norm-bounded adversarial examples","author":"Gowal","year":"2020","journal-title":"arXiv preprint"},{"key":"ref31","article-title":"Explaining and harnessing adversarial examples","author":"Goodfellow","year":"2014","journal-title":"arXiv preprint"},{"key":"ref32","article-title":"Ensemble adversarial training: Attacks and defenses","author":"Tram\u00e8r","year":"2017","journal-title":"arXiv preprint"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1201\/9781351251389-8"},{"key":"ref34","article-title":"Formal guarantees on the robustness of a classifier against adversarial manipulation","volume":"30","author":"Hein","year":"2017","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"ref35","article-title":"Certified defenses against adversarial examples","author":"Raghunathan","year":"2018","journal-title":"arXiv preprint"},{"key":"ref36","article-title":"Certifiable distributional robustness with principled adversarial training. corr, abs\/1710.10571","author":"Sinha","year":"2017","journal-title":"arXiv preprint"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.41"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.1803.01442"},{"key":"ref39","article-title":"Countering adversarial images using input transformations","author":"Guo","year":"2017","journal-title":"arXiv preprint"},{"key":"ref40","first-page":"274","article-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","volume-title":"in Int. Conf. Mach. Learn. PMLR","author":"Athalye"},{"key":"ref41","first-page":"7472","article-title":"Theoretically principled trade-off between robustness and accuracy","volume-title":"in Int. Conf. Mach. Learn.","author":"Zhang"},{"key":"ref42","article-title":"Improving adversarial robustness requires revisiting misclassified examples","volume-title":"in Int. Conf. Learn. Represent.","author":"Wang","year":"2019"},{"key":"ref43","first-page":"4218","article-title":"Improving robustness using generated data","volume":"34","author":"Gowal","year":"2021","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"ref44","article-title":"Fixing data augmentation to improve adversarial robustness","author":"Rebuffi","year":"2021","journal-title":"arXiv preprint"},{"key":"ref45","first-page":"2958","article-title":"Adversarial weight perturbation helps robust generalization","volume":"33","author":"Wu","year":"2020","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"ref46","first-page":"29935","article-title":"Data augmentation can improve robustness","volume":"34","author":"Rebuffi","year":"2021","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"ref47","article-title":"Robust learning meets generative models: Can proxy distributions improve adversarial robustness?","author":"Sehwag","year":"2021","journal-title":"arXiv preprint"},{"key":"ref48","article-title":"Robustness and accuracy could be reconcilable by (proper) definition","author":"Pang","year":"2022","journal-title":"arXiv preprint"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01304"},{"key":"ref50","article-title":"Torchattacks: A pytorch repository for adversarial attacks","author":"Kim","year":"2020","journal-title":"arXiv preprint"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.5244\/C.30.87"}],"event":{"name":"2025 IEEE 31th International Conference on Parallel and Distributed Systems (ICPADS)","location":"Hefei, China","start":{"date-parts":[[2025,12,14]]},"end":{"date-parts":[[2025,12,18]]}},"container-title":["2025 IEEE 31th International Conference on Parallel and Distributed Systems (ICPADS)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11322805\/11322871\/11322909.pdf?arnumber=11322909","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,1,15]],"date-time":"2026-01-15T07:09:00Z","timestamp":1768460940000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11322909\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,12,14]]},"references-count":51,"URL":"https:\/\/doi.org\/10.1109\/icpads67057.2025.11322909","relation":{},"subject":[],"published":{"date-parts":[[2025,12,14]]}}}