{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,7]],"date-time":"2026-03-07T18:21:27Z","timestamp":1772907687221,"version":"3.50.1"},"reference-count":90,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"3","license":[{"start":{"date-parts":[[2025,3,1]],"date-time":"2025-03-01T00:00:00Z","timestamp":1740787200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,3,1]],"date-time":"2025-03-01T00:00:00Z","timestamp":1740787200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,3,1]],"date-time":"2025-03-01T00:00:00Z","timestamp":1740787200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100012166","name":"National Key Research and Development Program of China","doi-asserted-by":"publisher","award":["2021YFB3100800"],"award-info":[{"award-number":["2021YFB3100800"]}],"id":[{"id":"10.13039\/501100012166","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62271090"],"award-info":[{"award-number":["62271090"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Chongqing Natural Science Fund","award":["cstc2021jcyj-jqX0023"],"award-info":[{"award-number":["cstc2021jcyj-jqX0023"]}]},{"DOI":"10.13039\/501100012456","name":"National Youth Talent Project","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100012456","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Circuits Syst. Video Technol."],"published-print":{"date-parts":[[2025,3]]},"DOI":"10.1109\/tcsvt.2024.3487761","type":"journal-article","created":{"date-parts":[[2024,10,29]],"date-time":"2024-10-29T17:36:16Z","timestamp":1730223376000},"page":"1999-2012","source":"Crossref","is-referenced-by-count":3,"title":["Remove to Regenerate: Boosting Adversarial Generalization With Attack Invariance"],"prefix":"10.1109","volume":"35","author":[{"given":"Xiaowei","family":"Fu","sequence":"first","affiliation":[{"name":"Chongqing Key Laboratory of Bio-Perception and Multimodal Intelligent Information Processing and the School of Microelectronics and Communication Engineering, Chongqing University, Chongqing, China"}]},{"given":"Lina","family":"Ma","sequence":"additional","affiliation":[{"name":"Chongqing Key Laboratory of Bio-Perception and Multimodal Intelligent Information Processing and the School of Microelectronics and Communication Engineering, Chongqing University, Chongqing, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5305-8543","authenticated-orcid":false,"given":"Lei","family":"Zhang","sequence":"additional","affiliation":[{"name":"Chongqing Key Laboratory of Bio-Perception and Multimodal Intelligent Information Processing and the School of Microelectronics and Communication Engineering, Chongqing University, Chongqing, China"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58592-1_29"},{"key":"ref2","first-page":"1","article-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","volume-title":"Proc. ICML","author":"Athalye"},{"issue":"6","key":"ref3","first-page":"1803","article-title":"How to explain individual classification decisions","volume":"11","author":"Baehrens","year":"2010","journal-title":"J. Mach. Learn. Res."},{"key":"ref4","article-title":"Training ensembles to detect adversarial examples","author":"Bagnall","year":"2017","journal-title":"arXiv:1712.04006"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2020.3031625"},{"key":"ref6","first-page":"1","article-title":"Improving adversarial robustness via channel-wise activation suppressing","volume-title":"Proc. ICLR","author":"Bai"},{"key":"ref7","article-title":"Decision-based adversarial attacks: Reliable attacks against black-box machine learning models","author":"Brendel","year":"2017","journal-title":"arXiv:1712.04248"},{"key":"ref8","first-page":"1","article-title":"A unified Wasserstein distributional robustness framework for adversarial training","volume-title":"Proc. ICLR","author":"Bui"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00414"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140448"},{"key":"ref12","first-page":"1","article-title":"Robust overfitting may be mitigated by properly learned smoothening","volume-title":"Proc. ICLR","author":"Chen"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/TCSVT.2023.3276442"},{"key":"ref14","first-page":"2196","article-title":"Minimally distorted adversarial examples with a fast adaptive boundary attack","volume-title":"Proc. ICML","author":"Croce"},{"key":"ref15","first-page":"2206","article-title":"Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks","volume-title":"Proc. ICML","author":"Croce"},{"key":"ref16","article-title":"Advertorch v0.1: An adversarial robustness toolbox based on PyTorch","author":"Weiguang Ding","year":"2019","journal-title":"arXiv:1902.07623"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"issue":"3","key":"ref18","first-page":"1","article-title":"Visualizing higherlayer features of a deep network","volume":"1341","author":"Erhan","year":"2009","journal-title":"Univ. Montreal"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00175"},{"key":"ref20","article-title":"Explaining and harnessing adversarial examples","author":"Goodfellow","year":"2014","journal-title":"arXiv:1412.6572"},{"key":"ref21","article-title":"Towards deep neural network architectures robust to adversarial examples","author":"Gu","year":"2014","journal-title":"arXiv:1412.5068"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/TCSVT.2024.3357987"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1186\/s12880-020-00530-y"},{"key":"ref25","article-title":"What do adversarially trained neural networks focus: A Fourier domain-based study","author":"Huang","year":"2022","journal-title":"arXiv:2203.08739"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.02363"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.243"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01484"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.02311"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.3389\/frai.2022.890016"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.01184"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.00791"},{"issue":"4","key":"ref33","article-title":"Learning multiple layers of features from tiny images","volume":"1","author":"Krizhevsky","year":"2009","journal-title":"Handbook Systemic Autoimmune Diseases"},{"key":"ref34","article-title":"Adversarial machine learning at scale","author":"Kurakin","year":"2016","journal-title":"arXiv:1611.01236"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00415"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00191"},{"key":"ref38","article-title":"CAT: Collaborative adversarial training","author":"Liu","year":"2023","journal-title":"arXiv:2303.14922"},{"key":"ref39","article-title":"Dropout with expectation-linear regularization","author":"Ma","year":"2016","journal-title":"arXiv:1609.08017"},{"key":"ref40","article-title":"Towards deep learning models resistant to adversarial attacks","author":"Madry","year":"2017","journal-title":"arXiv:1706.06083"},{"key":"ref41","article-title":"A frequency perspective of adversarial robustness","author":"Maiya","year":"2021","journal-title":"arXiv:2111.00861"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134057"},{"key":"ref43","article-title":"Conditional generative adversarial nets","author":"Mirza","year":"2014","journal-title":"arXiv:1411.1784"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2020.2978474"},{"key":"ref46","article-title":"LPFdefense: 3D adversarial defense based on frequency analysis","author":"Naderi","year":"2022","journal-title":"arXiv:2202.11287"},{"key":"ref47","first-page":"262","article-title":"A selfsupervised approach for adversarial robustness","volume-title":"Proc. IEEE\/CVF Conf. Comput. Vis. Pattern Recognit. (CVPR)","author":"Naseer"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.2118\/18761-MS"},{"key":"ref49","article-title":"Bag of tricks for adversarial training","author":"Pang","year":"2020","journal-title":"arXiv:2010.00467"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.41"},{"issue":"7","key":"ref51","first-page":"3","article-title":"Tiny imagenet visual recognition challenge","volume":"7","author":"Le","year":"2015","journal-title":"CS 231N"},{"key":"ref52","article-title":"Certified defenses against adversarial examples","author":"Raghunathan","year":"2018","journal-title":"arXiv:1801.09344"},{"key":"ref53","first-page":"8093","article-title":"Overfitting in adversarially robust deep learning","volume-title":"Proc. ICML","author":"Rice"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/K18-2019"},{"key":"ref55","article-title":"Defense-GAN: Protecting classifiers against adversarial attacks using generative models","author":"Samangouei","year":"2018","journal-title":"arXiv:1805.06605"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1016\/j.neunet.2024.106194"},{"key":"ref57","article-title":"APE-GAN: Adversarial perturbation elimination with GAN","author":"Shen","year":"2017","journal-title":"arXiv:1707.05474"},{"key":"ref58","article-title":"Online adversarial purification based on self-supervision","author":"Shi","year":"2021","journal-title":"arXiv:2101.09387"},{"key":"ref59","article-title":"Deep inside convolutional networks: Visualising image classification models and saliency maps","author":"Simonyan","year":"2013","journal-title":"arXiv:1312.6034"},{"key":"ref60","first-page":"1","article-title":"Very deep convolutional networks for large-scale image recognition","volume-title":"Proc. ICLR","author":"Simonyan"},{"key":"ref61","article-title":"PixelDefend: Leveraging generative models to understand and defend against adversarial examples","author":"Song","year":"2017","journal-title":"arXiv:1710.10766"},{"issue":"1","key":"ref62","first-page":"1929","article-title":"Dropout: A simple way to prevent neural networks from overfitting","volume":"15","author":"Srivastava","year":"2014","journal-title":"J. Mach. Learn. Res."},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1109\/TEVC.2019.2890858"},{"key":"ref64","article-title":"Are labels required for improving adversarial robustness?","author":"Uesato","year":"2019","journal-title":"arXiv:1905.13725"},{"issue":"11","key":"ref65","first-page":"2579","article-title":"Visualizing data using t-SNE","volume":"9","author":"Van der Maaten","year":"2008","journal-title":"J. Mach. Learn. Res."},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.1145\/1390156.1390294"},{"key":"ref67","doi-asserted-by":"publisher","DOI":"10.1109\/TCSVT.2020.3017006"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.1109\/tcsvt.2024.3432932"},{"key":"ref69","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00756"},{"key":"ref70","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00425"},{"key":"ref71","first-page":"1","article-title":"Improving adversarial robustness requires revisiting misclassified examples","volume-title":"Proc. ICLR","author":"Wang"},{"key":"ref72","first-page":"1","article-title":"Diversifying the high-level features for better adversarial transferability","volume-title":"Proc. BMVC","author":"Wang"},{"key":"ref73","article-title":"Towards frequency-based explanation for robust CNN","author":"Wang","year":"2020","journal-title":"arXiv:2005.03141"},{"key":"ref74","first-page":"1","article-title":"Adversarial weight perturbation helps robust generalization","volume-title":"Proc. NeurIPS","author":"Wu"},{"key":"ref75","first-page":"10890","article-title":"R-drop: Regularized dropout for neural networks","volume-title":"Proc. NeurIPS","volume":"34","author":"Wu"},{"key":"ref76","article-title":"Mitigating adversarial effects through randomization","author":"Xie","year":"2017","journal-title":"arXiv:1711.01991"},{"key":"ref77","first-page":"1","article-title":"Enhancing adversarial contrastive learning via adversarial invariant regularization","volume-title":"Proc. NeurIPS","volume":"36","author":"Xu"},{"key":"ref78","first-page":"11693","article-title":"CIFS: Improving adversarial robustness of CNNs via channel-wise importancebased feature selection","volume-title":"Proc. ICML","author":"Yan"},{"key":"ref79","first-page":"1","article-title":"How transferable are features in deep neural networks?","volume-title":"Proc. NeurIPS","volume":"27","author":"Yosinski"},{"key":"ref80","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.02340"},{"key":"ref81","first-page":"7472","article-title":"Theoretically principled trade-off between robustness and accuracy","volume-title":"Proc. ICML","author":"Zhang"},{"key":"ref82","doi-asserted-by":"publisher","DOI":"10.1109\/TCSVT.2022.3207008"},{"key":"ref83","first-page":"1","article-title":"Attacks which do not kill training make adversarial learning stronger","volume-title":"Proc. ICML","author":"Zhang"},{"key":"ref84","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2024.3385745"},{"key":"ref85","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.485"},{"key":"ref86","first-page":"12835","article-title":"Towards defending against adversarial examples via attack-invariant features","volume-title":"Proc. ICML","author":"Zhou"},{"key":"ref87","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00437"},{"key":"ref88","first-page":"1","article-title":"Reliable adversarial distillation with unreliable teachers","volume-title":"Proc. ICLR","author":"Zhu"},{"key":"ref89","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01613"},{"key":"ref90","article-title":"Fraternal dropout","author":"Zolna","year":"2017","journal-title":"arXiv:1711.00066"}],"container-title":["IEEE Transactions on Circuits and Systems for Video Technology"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/76\/10916540\/10737447.pdf?arnumber=10737447","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,3,7]],"date-time":"2025-03-07T18:52:34Z","timestamp":1741373554000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10737447\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,3]]},"references-count":90,"journal-issue":{"issue":"3"},"URL":"https:\/\/doi.org\/10.1109\/tcsvt.2024.3487761","relation":{},"ISSN":["1051-8215","1558-2205"],"issn-type":[{"value":"1051-8215","type":"print"},{"value":"1558-2205","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,3]]}}}