{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,14]],"date-time":"2026-03-14T18:01:23Z","timestamp":1773511283471,"version":"3.50.1"},"reference-count":61,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"Key Research and Development Program of Zhejiang Province of China","award":["2020C01024"],"award-info":[{"award-number":["2020C01024"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Dependable and Secure Comput."],"published-print":{"date-parts":[[2022]]},"DOI":"10.1109\/tdsc.2022.3165889","type":"journal-article","created":{"date-parts":[[2022,4,8]],"date-time":"2022-04-08T19:25:56Z","timestamp":1649445956000},"page":"1-1","source":"Crossref","is-referenced-by-count":11,"title":["Decision Boundary-aware Data Augmentation for Adversarial Training"],"prefix":"10.1109","author":[{"given":"Chen","family":"Chen","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jingfeng","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xilie","family":"Xu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Lingjuan","family":"Lyu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Chaochao","family":"Chen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tianlei","family":"Hu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Gang","family":"Chen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-40994-3_25"},{"key":"ref2","article-title":"Intriguing properties of neural networks","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Szegedy"},{"key":"ref3","article-title":"Explaining and harnessing adversarial examples","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Goodfellow"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298640"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.06083"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2018\/520"},{"key":"ref7","first-page":"6586","article-title":"On the convergence and robustness of adversarial training","volume-title":"Proc. 36th Int. Conf. Mach. Learn.","author":"Wang"},{"key":"ref8","article-title":"Improving adversarial robustness requires revisiting misclassified examples","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Wang"},{"key":"ref9","article-title":"On fast adversarial robustness adaptation in model-agnostic meta-learning","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Wang"},{"key":"ref10","first-page":"7472","article-title":"Theoretically principled trade-off between robustness and accuracy","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Zhang"},{"key":"ref11","first-page":"11278","article-title":"Attacks which do not kill training make adversarial learning stronger","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Zhang"},{"key":"ref12","first-page":"4970","article-title":"Improving adversarial robustness via promoting ensemble diversity","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Pang"},{"key":"ref13","article-title":"Rethinking softmax cross-entropy loss for adversarial robustness","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Pang"},{"key":"ref14","article-title":"Bag of tricks for adversarial training","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Pang"},{"key":"ref15","first-page":"2958","article-title":"Adversarial weight perturbation helps robust generalization","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Wu"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00103"},{"key":"ref17","article-title":"Fast is better than free: Revisiting adversarial training","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Wong"},{"key":"ref18","first-page":"8093","article-title":"Overfitting in adversarially robust deep learning","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Rice"},{"key":"ref19","first-page":"20297","article-title":"GAMA: Guided adversarial margin attack","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Sriramanan"},{"key":"ref20","article-title":"Improving adversarial robustness via channel-wise activation suppressing","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Bai"},{"key":"ref21","article-title":"MMA training: Direct input space margin maximization through adversarial training","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Ding"},{"key":"ref22","article-title":"Geometry-aware instance-reweighted adversarial training","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Zhang"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref24","article-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009"},{"key":"ref25","first-page":"5014","article-title":"Adversarially robust generalization requires more data","volume-title":"Proc. 32nd Int. Conf. Neural Inf. Process. Syst.","author":"Schmidt"},{"key":"ref26","first-page":"2712","article-title":"Using pre-training can improve model robustness and uncertainty","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Hendrycks"},{"key":"ref27","article-title":"Unlabeled data improves adversarial robustness","volume-title":"Proc. 33rd Int. Conf. Neural Inf. Process. Syst.","author":"Carmon"},{"key":"ref28","article-title":"Are labels required for improving adversarial robustness?","volume-title":"Proc. 33rd Int. Conf. Neural Inf. Process. Syst.","author":"Alayrac"},{"key":"ref29","article-title":"Robustness to adversarial perturbations in learning from incomplete data","volume-title":"Proc. 33rd Int. Conf. Neural Inf. Process. Syst.","author":"Najafi"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.3399\/bjgp18X695213"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1257\/aer.102.3.65"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-57959-7"},{"key":"ref33","article-title":"mixup: Beyond empirical risk minimization","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Zhang"},{"key":"ref34","article-title":"How does mixup help with robustness and generalization?","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Zhang"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2018.00035"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1145\/3338501.3357369"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-68238-5_14"},{"key":"ref38","article-title":"Mixup inference: Better exploiting mixup to defend adversarial attacks","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Pang"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/CISS.2018.8362326"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23198"},{"key":"ref41","article-title":"Countering adversarial images using input transformations","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Guo"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00669"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN.2016.7727230"},{"key":"ref44","article-title":"Mitigating adversarial effects through randomization","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Xie"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2022\/95"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.2172\/1525811"},{"key":"ref47","first-page":"5050","article-title":"MixMatch: A holistic approach to semi-supervised learning","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Berthelot"},{"key":"ref48","article-title":"ReMixMatch: Semi-supervised learning with distribution matching and augmentation anchoring","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Berthelot"},{"key":"ref49","article-title":"Co-mixup: Saliency guided joint mixup with supermodular diversity","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Kim"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1007\/BF00994018"},{"key":"ref52","first-page":"850","article-title":"Large margin deep networks for classification","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Elsayed"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1002\/wics.101"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.2118\/18761-MS"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.5244\/C.30.87"},{"key":"ref57","first-page":"8026","article-title":"PyTorch: An imperative style, high-performance deep learning library","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Paszke"},{"key":"ref58","article-title":"Robust overfitting may be mitigated by properly learned smoothening","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Chen"},{"key":"ref59","first-page":"2206","article-title":"Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Croce"},{"key":"ref60","article-title":"Robustness may be at odds with accuracy","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Tsipras"},{"key":"ref61","first-page":"11278","article-title":"Attacks which do not kill training make adversarial learning stronger","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Zhang"}],"container-title":["IEEE Transactions on Dependable and Secure Computing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/8858\/4358699\/09754227.pdf?arnumber=9754227","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,1,19]],"date-time":"2024-01-19T18:26:57Z","timestamp":1705688817000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9754227\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022]]},"references-count":61,"URL":"https:\/\/doi.org\/10.1109\/tdsc.2022.3165889","relation":{},"ISSN":["1545-5971","1941-0018","2160-9209"],"issn-type":[{"value":"1545-5971","type":"print"},{"value":"1941-0018","type":"electronic"},{"value":"2160-9209","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022]]}}}