{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,9]],"date-time":"2025-10-09T06:30:54Z","timestamp":1759991454465,"version":"3.28.0"},"reference-count":57,"publisher":"IEEE","license":[{"start":{"date-parts":[[2021,7,18]],"date-time":"2021-07-18T00:00:00Z","timestamp":1626566400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2021,7,18]],"date-time":"2021-07-18T00:00:00Z","timestamp":1626566400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2021,7,18]],"date-time":"2021-07-18T00:00:00Z","timestamp":1626566400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2021,7,18]]},"DOI":"10.1109\/ijcnn52387.2021.9533363","type":"proceedings-article","created":{"date-parts":[[2021,9,20]],"date-time":"2021-09-20T21:27:41Z","timestamp":1632173261000},"page":"1-8","source":"Crossref","is-referenced-by-count":7,"title":["Dual Head Adversarial Training"],"prefix":"10.1109","author":[{"given":"Yujing","family":"Jiang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xingjun","family":"Ma","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Sarah Monazam","family":"Erfani","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"James","family":"Bailey","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref39","first-page":"2574","article-title":"Deepfool: a simple and accurate method to fool deep neural networks","author":"moosavi-dezfooli","year":"2016","journal-title":"CVPR"},{"key":"ref38","article-title":"Adversarial machine learning at scale","author":"kurakin","year":"2016","journal-title":"ArXiv Preprint"},{"key":"ref33","article-title":"Adversarial weight perturbation helps robust generalization","volume":"33","author":"wu","year":"2020","journal-title":"Advances in neural information processing systems"},{"key":"ref32","article-title":"Self-adaptive training: beyond empirical risk minimization","volume":"33","author":"huang","year":"2020","journal-title":"Advances in neural information processing systems"},{"key":"ref31","article-title":"Does network width really help adversarial robustness?","author":"wu","year":"2020","journal-title":"ArXiv Preprint"},{"key":"ref30","article-title":"Improving adversarial robustness requires revisiting misclassified examples","author":"wang","year":"2020","journal-title":"ICLRE"},{"key":"ref37","article-title":"Learnable boundary guided adversarial training","author":"cui","year":"2020","journal-title":"ArXiv Preprint"},{"key":"ref36","article-title":"Boosting adversarial training with hypersphere embedding","author":"pang","year":"2020","journal-title":"ArXiv Preprint"},{"key":"ref35","article-title":"Bag of tricks for adversarial training","author":"pang","year":"2020","journal-title":"ArXiv Preprint"},{"key":"ref34","first-page":"8093","article-title":"Overfitting in adversarially robust deep learning","author":"rice","year":"0","journal-title":"ICML"},{"key":"ref28","article-title":"Wide residual networks","author":"zagoruyko","year":"2016","journal-title":"ArXiv Preprint"},{"key":"ref27","first-page":"6586","article-title":"On the convergence and robustness of adversarial training","author":"wang","year":"2019","journal-title":"ICML"},{"key":"ref29","article-title":"Theoretically principled trade-off between robustness and accuracy","author":"zhang","year":"2019","journal-title":"ICML"},{"key":"ref2","article-title":"Bert: Pre-training of deep bidirectional transformers for language understanding","author":"devlin","year":"2018","journal-title":"ar Xiv preprint"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref20","article-title":"Countering adversarial images using input transformations","author":"guo","year":"2018","journal-title":"ICLRE"},{"key":"ref22","article-title":"Stochastic activation pruning for robust adversarial defense","author":"dhillon","year":"2018","journal-title":"ICLRE"},{"key":"ref21","article-title":"Characterizing adversarial subspaces using local intrinsic dimensionality","author":"ma","year":"2018","journal-title":"ICLRE"},{"key":"ref24","first-page":"274","article-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","author":"athalye","year":"2018","journal-title":"ICML"},{"key":"ref23","article-title":"Mitigating adversarial effects through randomization","author":"xie","year":"2018","journal-title":"ICLRE"},{"key":"ref26","article-title":"Imbalanced gradients: A new cause of overestimated adversarial robustness","author":"jiang","year":"2020","journal-title":"ArXiv Preprint"},{"key":"ref25","article-title":"Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks","author":"croce","year":"2020","journal-title":"ArXiv Preprint"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00020"},{"key":"ref51","article-title":"Sparse dnns with improved adversarial robustness","author":"guo","year":"2018","journal-title":"NeurIPS"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1142\/S0218001493000339"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00090"},{"key":"ref55","article-title":"Robustness may be at odds with accuracy","author":"tsipras","year":"2019","journal-title":"ICLRE"},{"key":"ref54","first-page":"12214","article-title":"Are labels required for improving adversarial robustness?","author":"alayrac","year":"2019","journal-title":"Advances in neural information processing systems"},{"key":"ref53","article-title":"Improving adversarial robustness via channel-wise activation suppressing","author":"bai","year":"2021","journal-title":"ICLRE"},{"key":"ref52","article-title":"Ensemble adversarial training: Attacks and defenses","author":"tramer","year":"2017","journal-title":"ArXiv Preprint"},{"key":"ref10","first-page":"1115","article-title":"Adversarial attack on graph structured data","author":"dai","year":"0","journal-title":"ICML"},{"key":"ref11","article-title":"Adv-bert: Bert is not robust on misspellings! generating nature adversarial samples on bert","author":"sun","year":"2020","journal-title":"ArXiv Preprint"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"ref12","doi-asserted-by":"crossref","DOI":"10.1609\/aaai.v32i1.12341","article-title":"Un-ravelling robustness of deep learning based face recognition against adversarial attacks","volume":"32","author":"goswami","year":"2018","journal-title":"AAAI"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00175"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.01426"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00108"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.01373"},{"key":"ref17","article-title":"Adversarial objects against lidar-based autonomous driving systems","author":"cao","year":"2019","journal-title":"ArXiv Preprint"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1126\/science.aaw4399"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2020.107332"},{"key":"ref4","article-title":"Intriguing properties of neural networks","author":"szegedy","year":"2014","journal-title":"ICLRE"},{"key":"ref3","first-page":"173","article-title":"Deep speech 2: End-to-end speech recognition in english and mandarin","author":"amodei","year":"0","journal-title":"ICML"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref5","article-title":"Explaining and harnessing adversarial examples","author":"goodfellow","year":"2014","journal-title":"ArXiv Preprint"},{"key":"ref8","article-title":"Skip connections matter: On the transferability of adversarial examples generated with resnets","author":"wu","year":"2020","journal-title":"ICLRE"},{"key":"ref7","article-title":"Towards deep learning models resistant to adversarial attacks","author":"madry","year":"2018","journal-title":"ICLRE"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1016\/j.mlwa.2020.100017"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1145\/3343031.3351088"},{"key":"ref46","article-title":"On the limitations of denoising strategies as adversarial defenses","author":"niu","year":"2020","journal-title":"ArXiv Preprint"},{"key":"ref45","article-title":"Countering adversarial images using input transformations","author":"guo","year":"0","journal-title":"2018 ICLR"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01258-8_32"},{"key":"ref47","article-title":"Improving the adversarial robustness and interpretability of deep neural networks by regularizing their input gradients","volume":"32","author":"ross","year":"0","journal-title":"Proceedings of the AAAI Conference on Artificial Intelligence"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.33012253"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"ref44","article-title":"Feature squeezing: Detecting adversarial examples in deep neural networks","author":"xu","year":"2017","journal-title":"NDSS"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.41"}],"event":{"name":"2021 International Joint Conference on Neural Networks (IJCNN)","start":{"date-parts":[[2021,7,18]]},"location":"Shenzhen, China","end":{"date-parts":[[2021,7,22]]}},"container-title":["2021 International Joint Conference on Neural Networks (IJCNN)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/9533266\/9533267\/09533363.pdf?arnumber=9533363","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,1,9]],"date-time":"2023-01-09T19:45:18Z","timestamp":1673293518000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9533363\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,7,18]]},"references-count":57,"URL":"https:\/\/doi.org\/10.1109\/ijcnn52387.2021.9533363","relation":{},"subject":[],"published":{"date-parts":[[2021,7,18]]}}}