{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,11]],"date-time":"2025-11-11T05:58:14Z","timestamp":1762840694820,"version":"build-2065373602"},"reference-count":38,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"Israeli Innovation Authority through the Trust. AI consortium"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Signal Process. Lett."],"published-print":{"date-parts":[[2025]]},"DOI":"10.1109\/lsp.2025.3624151","type":"journal-article","created":{"date-parts":[[2025,10,22]],"date-time":"2025-10-22T17:27:18Z","timestamp":1761154038000},"page":"4219-4223","source":"Crossref","is-referenced-by-count":0,"title":["Diffusion Models are Robust Pretrainers"],"prefix":"10.1109","volume":"32","author":[{"ORCID":"https:\/\/orcid.org\/0009-0003-2752-6926","authenticated-orcid":false,"given":"Mika","family":"Yagoda","sequence":"first","affiliation":[{"name":"Electrical Engineering Department, Tel Aviv University, Tel Aviv, Israel"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0019-5875","authenticated-orcid":false,"given":"Shady","family":"Abu-Hussein","sequence":"additional","affiliation":[{"name":"Electrical Engineering Department, Tel Aviv University, Tel Aviv, Israel"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2830-0297","authenticated-orcid":false,"given":"Raja","family":"Giryes","sequence":"additional","affiliation":[{"name":"Electrical Engineering Department, Tel Aviv University, Tel Aviv, Israel"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","first-page":"6840","article-title":"Denoising diffusion probabilistic models","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"33","author":"Ho","year":"2020"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.52202\/079017-0868"},{"key":"ref3","first-page":"26565","article-title":"Elucidating the design space of diffusion-based generative models","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"35","author":"Karras","year":"2022"},{"article-title":"Score-based generative modeling through stochastic differential equations","year":"2020","author":"Song","key":"ref4"},{"key":"ref5","first-page":"8780","article-title":"Diffusion models beat gans on image synthesis","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"34","author":"Dhariwal","year":"2021"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01042"},{"article-title":"Explaining and harnessing adversarial examples","year":"2014","author":"Goodfellow","key":"ref7"},{"article-title":"Towards deep learning models resistant to adversarial attacks","year":"2017","author":"Madry","key":"ref8"},{"key":"ref9","first-page":"2206","article-title":"Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Croce","year":"2020"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.06083"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00740"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/TMM.2020.2969784"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP40776.2020.9052913"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00057"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2021.3082317"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2020.3042083"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01612"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2021.3101395"},{"key":"ref19","first-page":"2","article-title":"Large scale adversarial representation learning","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"32","author":"Donahue","year":"2019"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.00213"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01553"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00078"},{"article-title":"Diffusion models beat GANs on image classification","year":"2023","author":"Mukhopadhyay","key":"ref23"},{"article-title":"Robust classification via a single diffusion model","year":"2023","author":"Chen","key":"ref24"},{"article-title":"Learning multiple layers of features from tiny images","year":"2009","author":"Krizhevsky","key":"ref25"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-20077-9_18"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1201\/9781351251389-8"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref30","first-page":"2196","article-title":"Minimally distorted adversarial examples with a fast adaptive boundary attack","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Croce","year":"2020"},{"key":"ref31","first-page":"4615","article-title":"Semi-supervised learning with normalizing flows","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Izmailov","year":"2020"},{"article-title":"Self-supervised pretraining for image embedding","year":"2019","author":"Trinh","key":"ref32"},{"article-title":"Unsupervised representation learning by predicting image rotations","year":"2018","author":"Gidaris","key":"ref33"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-46466-4_5"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00233"},{"article-title":"Adversarial robustness limits via scaling-law and human-alignment studies","year":"2024","author":"Bartoldson","key":"ref36"},{"article-title":"Meansparse: Post-training robustness enhancement through mean-centered feature sparsification","year":"2024","author":"Amini","key":"ref37"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01028"}],"container-title":["IEEE Signal Processing Letters"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/97\/10802935\/11214201.pdf?arnumber=11214201","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,11,11]],"date-time":"2025-11-11T05:54:11Z","timestamp":1762840451000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11214201\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"references-count":38,"URL":"https:\/\/doi.org\/10.1109\/lsp.2025.3624151","relation":{},"ISSN":["1070-9908","1558-2361"],"issn-type":[{"type":"print","value":"1070-9908"},{"type":"electronic","value":"1558-2361"}],"subject":[],"published":{"date-parts":[[2025]]}}}