{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,15]],"date-time":"2025-11-15T07:28:47Z","timestamp":1763191727133,"version":"3.45.0"},"reference-count":37,"publisher":"IEEE","license":[{"start":{"date-parts":[[2025,6,30]],"date-time":"2025-06-30T00:00:00Z","timestamp":1751241600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,6,30]],"date-time":"2025-06-30T00:00:00Z","timestamp":1751241600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025,6,30]]},"DOI":"10.1109\/ijcnn64981.2025.11228412","type":"proceedings-article","created":{"date-parts":[[2025,11,14]],"date-time":"2025-11-14T18:46:15Z","timestamp":1763145975000},"page":"1-10","source":"Crossref","is-referenced-by-count":0,"title":["Fast Adversarial Training with Neighborhood Diversity Alignment"],"prefix":"10.1109","author":[{"given":"Hongxin","family":"Zhi","sequence":"first","affiliation":[{"name":"Information Engineering University,Institute of Information Technology,Zhengzhou,China"}]},{"given":"Hongtao","family":"Yu","sequence":"additional","affiliation":[{"name":"Information Engineering University,Institute of Information Technology,Zhengzhou,China"}]},{"given":"Shaomei","family":"Li","sequence":"additional","affiliation":[{"name":"Information Engineering University,Institute of Information Technology,Zhengzhou,China"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/cvpr.2016.90"},{"article-title":"Bert: Pre-training of deep bidirectional transformers for language understanding","year":"2018","author":"Devlin","key":"ref2"},{"article-title":"Intriguing properties of neural networks","year":"2013","author":"Szegedy","key":"ref3"},{"article-title":"Explaining and harnessing adversarial examples","year":"2014","author":"Goodfellow","key":"ref4"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/iccv.2015.312"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2020.107332"},{"article-title":"Fooling a real car with adversarial traffic signs","year":"2019","author":"Morgulis","key":"ref7"},{"article-title":"Towards deep learning models resistant to adversarial attacks","year":"2017","author":"Madry","key":"ref8"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1002\/aisy.202300658"},{"key":"ref10","first-page":"16048","article-title":"Understanding and improving fast adversarial training","volume":"33","author":"Andriushchenko","year":"2020","journal-title":"Advances in Neural Information Processing Systems"},{"article-title":"Fast is better than free: Revisiting adversarial training","year":"2020","author":"Wong","key":"ref11"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2024.111007"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2024.110356"},{"key":"ref14","first-page":"12881","article-title":"Make some noise: Reliable and efficient single-step adversarial training","volume":"35","author":"de Jorge Aranda","year":"2022","journal-title":"Advances in Neural Information Processing Systems"},{"key":"ref15","article-title":"Adversarial training for free!","volume":"32","author":"Shafahi","year":"2019","journal-title":"Advances in neural information processing systems"},{"key":"ref16","first-page":"20297","article-title":"Guided adversarial attack for evaluating and enhancing adversarial defenses","volume":"33","author":"Sriramanan","year":"2020","journal-title":"Advances in Neural Information Processing Systems"},{"article-title":"Distributionally robust optimization: A review","year":"2019","author":"Rahimian","key":"ref17"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2023.3326398"},{"article-title":"Ensemble adversarial training: Attacks and defenses","year":"2017","author":"Tram\u00e8r","key":"ref19"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1016\/j.probengmech.2023.103479"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1007\/s40747-025-02038-w"},{"article-title":"Geometry-aware instance-reweighted adversarial training","year":"2020","author":"Zhang","key":"ref22"},{"article-title":"Learning multiple layers of features from tiny images","year":"2009","author":"Krizhevsky","key":"ref23"},{"issue":"2","key":"ref24","first-page":"4","article-title":"Reading digits in natural images with unsupervised feature learning","volume-title":"NIPS workshop on deep learning and unsupervised feature learning","volume":"2011","author":"Netzer"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.5244\/C.30.87"},{"key":"ref27","first-page":"7472","article-title":"Theoretically principled trade-off between robustness and accuracy","volume-title":"International conference on machine learning","author":"Zhang"},{"key":"ref28","first-page":"8093","article-title":"Overfitting in adversarially robust deep learning","volume-title":"International conference on machine learning","author":"Rice"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1016\/S0893-6080(98)00116-6"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/sp.2017.49"},{"key":"ref31","first-page":"2206","article-title":"Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks","volume-title":"International conference on machine learning","author":"Croce"},{"key":"ref32","first-page":"2196","article-title":"Minimally distorted adversarial examples with a fast adaptive boundary attack","volume-title":"International Conference on Machine Learning","author":"Croce"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58592-1_29"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2022.109229"},{"article-title":"Understanding adversarial robustness through loss landscape geometries","year":"2019","author":"Prabhu","key":"ref35"},{"key":"ref36","first-page":"2958","article-title":"Adversarial weight perturbation helps robust generalization","volume":"33","author":"Wu","year":"2020","journal-title":"Advances in neural information processing systems"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/WACV.2017.58"}],"event":{"name":"2025 International Joint Conference on Neural Networks (IJCNN)","start":{"date-parts":[[2025,6,30]]},"location":"Rome, Italy","end":{"date-parts":[[2025,7,5]]}},"container-title":["2025 International Joint Conference on Neural Networks (IJCNN)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11227166\/11227148\/11228412.pdf?arnumber=11228412","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,11,15]],"date-time":"2025-11-15T07:27:15Z","timestamp":1763191635000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11228412\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,6,30]]},"references-count":37,"URL":"https:\/\/doi.org\/10.1109\/ijcnn64981.2025.11228412","relation":{},"subject":[],"published":{"date-parts":[[2025,6,30]]}}}