{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,22]],"date-time":"2026-07-22T16:40:25Z","timestamp":1784738425289,"version":"3.55.0"},"reference-count":56,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"5","license":[{"start":{"date-parts":[[2025,9,1]],"date-time":"2025-09-01T00:00:00Z","timestamp":1756684800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,9,1]],"date-time":"2025-09-01T00:00:00Z","timestamp":1756684800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,9,1]],"date-time":"2025-09-01T00:00:00Z","timestamp":1756684800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62432012"],"award-info":[{"award-number":["62432012"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62121001"],"award-info":[{"award-number":["62121001"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100018925","name":"Overseas Expertise Introduction Center for Discipline Innovation of Food Nutrition and Human Health","doi-asserted-by":"publisher","award":["B16037"],"award-info":[{"award-number":["B16037"]}],"id":[{"id":"10.13039\/501100018925","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Dependable and Secure Comput."],"published-print":{"date-parts":[[2025,9]]},"DOI":"10.1109\/tdsc.2025.3562600","type":"journal-article","created":{"date-parts":[[2025,4,18]],"date-time":"2025-04-18T13:40:13Z","timestamp":1744983613000},"page":"5134-5151","source":"Crossref","is-referenced-by-count":5,"title":["CARD: Robustness-Preserving Transfer Learning for Network Intrusion Detection via Contrastive Adversarial Representation Distillation"],"prefix":"10.1109","volume":"22","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-3705-7345","authenticated-orcid":false,"given":"Mengdie","family":"Huang","sequence":"first","affiliation":[{"name":"State Key Laboratory of Integrated Services Networks, Xidian University, Xi&#x2019;an, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-5749-2058","authenticated-orcid":false,"given":"Yingjun","family":"Lin","sequence":"additional","affiliation":[{"name":"Department of Computer Science, Purdue University, West Lafayette, IN, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8207-9717","authenticated-orcid":false,"given":"Ninghui","family":"Li","sequence":"additional","affiliation":[{"name":"Department of Computer Science, Purdue University, West Lafayette, IN, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5858-5070","authenticated-orcid":false,"given":"Xiaofeng","family":"Chen","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Integrated Services Networks, Xidian University, Xi&#x2019;an, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4029-7051","authenticated-orcid":false,"given":"Elisa","family":"Bertino","sequence":"additional","affiliation":[{"name":"Department of Computer Science, Purdue University, West Lafayette, IN, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/CCC.2019.000-6"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2019.10.069"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1002\/ett.4150"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2009.191"},{"key":"ref5","first-page":"5019","article-title":"Adversarially robust generalization requires more data","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Schmidt"},{"key":"ref6","first-page":"1","article-title":"Adversarially robust transfer learning","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Shafahi"},{"key":"ref7","first-page":"2712","article-title":"Using pre-training can improve model robustness and uncertainty","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Hendrycks"},{"key":"ref8","first-page":"7054","article-title":"Do wider neural networks really help adversarial robustness?","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Wu"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01613"},{"key":"ref10","article-title":"Adversarial training via adaptive knowledge amalgamation of an ensemble of teachers","author":"Hamidi","year":"2024"},{"key":"ref11","article-title":"Distilling the knowledge in a neural network","author":"Hinton","year":"2015"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v25i1.8090"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2021.11.061"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1145\/3320269.3384718"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2022.3164770"},{"key":"ref16","article-title":"On the opportunities and risks of foundation models","author":"Bommasani","year":"2021"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/SMARTCOMP.2019.00031"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/ICC42927.2021.9500574"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2022.117671"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i04.5816"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.01577"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.02363"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.06083"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-88942-5_9"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1007\/978-981-15-3341-9_18"},{"key":"ref26","first-page":"4694","article-title":"When does label smoothing help?","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"M\u00fcller"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.33013779"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1145\/3586102.3586107"},{"key":"ref29","first-page":"80","article-title":"When does contrastive learning preserve adversarial robustness from pretraining to finetuning?","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Fan"},{"key":"ref30","first-page":"55","article-title":"MixACM: Mixup-based robustness transfer via distillation of activated channel maps","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Muhammad"},{"key":"ref31","first-page":"1","article-title":"Reliable adversarial distillation with unreliable teachers","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Zhu"},{"key":"ref32","article-title":"On the benefits of know-ledge distillation for adversarial robustness","author":"Maroto","year":"2022"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2023.3237371"},{"key":"ref34","first-page":"2983","article-title":"Adversarial self-supervised contrastive learning","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Kim"},{"key":"ref35","first-page":"59206","article-title":"On transfer of adversarial robustness from pretraining to downstream tasks","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Nern"},{"key":"ref36","first-page":"16199","article-title":"Robust pre-training by adversarial contrastive learning","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Jiang"},{"key":"ref37","article-title":"Explaining and harnessing adversarial examples","author":"Goodfellow","year":"2014"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2023.24508"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1145\/3660646"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1145\/3715121"},{"key":"ref41","first-page":"3571","article-title":"On interaction between augmentations and corruptions in natural corruption robustness","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Mintun"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/TASLP.2023.3294692"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.5555\/3524938.3525087"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00935"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/tdsc.2025.3544106"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00975"},{"key":"ref47","first-page":"1","article-title":"Contrastive representation distillation","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Tian"},{"key":"ref48","first-page":"1101","article-title":"Do more negative samples necessarily hurt in contrastive learning?","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Awasthi"},{"key":"ref49","article-title":"NSL-KDD dataset","year":"2009"},{"key":"ref50","article-title":"UNSW-NB15","year":"2015"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.5244\/C.30.87"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref53","article-title":"MobileNets: Efficient convolutional neural networks for mobile vision applications","author":"Howard","year":"2017"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"ref55","first-page":"2206","article-title":"Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Croce"},{"key":"ref56","first-page":"1633","article-title":"On adaptive attacks to adversarial example defenses","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Tramer"}],"container-title":["IEEE Transactions on Dependable and Secure Computing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/8858\/11150357\/10970424.pdf?arnumber=10970424","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,9,8]],"date-time":"2025-09-08T22:52:07Z","timestamp":1757371927000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10970424\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,9]]},"references-count":56,"journal-issue":{"issue":"5"},"URL":"https:\/\/doi.org\/10.1109\/tdsc.2025.3562600","relation":{},"ISSN":["1545-5971","1941-0018","2160-9209"],"issn-type":[{"value":"1545-5971","type":"print"},{"value":"1941-0018","type":"electronic"},{"value":"2160-9209","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,9]]}}}