{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,7]],"date-time":"2026-04-07T20:45:32Z","timestamp":1775594732376,"version":"3.50.1"},"reference-count":68,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"2","license":[{"start":{"date-parts":[[2025,4,1]],"date-time":"2025-04-01T00:00:00Z","timestamp":1743465600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,4,1]],"date-time":"2025-04-01T00:00:00Z","timestamp":1743465600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,4,1]],"date-time":"2025-04-01T00:00:00Z","timestamp":1743465600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"Research Grants Council of the Hong Kong Special Administrative Region","award":["CityU11215622"],"award-info":[{"award-number":["CityU11215622"]}]},{"name":"Research Grants Council of the Hong Kong Special Administrative Region","award":["CityU11215723"],"award-info":[{"award-number":["CityU11215723"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Emerg. Top. Comput. Intell."],"published-print":{"date-parts":[[2025,4]]},"DOI":"10.1109\/tetci.2025.3535656","type":"journal-article","created":{"date-parts":[[2025,2,13]],"date-time":"2025-02-13T13:46:59Z","timestamp":1739454419000},"page":"1367-1378","source":"Crossref","is-referenced-by-count":4,"title":["Exploring the Adversarial Frontier: Quantifying Robustness via Adversarial Hypervolume"],"prefix":"10.1109","volume":"9","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-5412-914X","authenticated-orcid":false,"given":"Ping","family":"Guo","sequence":"first","affiliation":[{"name":"Department of Computer Science, City University of Hong Kong, Hong Kong"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7859-1777","authenticated-orcid":false,"given":"Cheng","family":"Gong","sequence":"additional","affiliation":[{"name":"Department of Computer Science, City University of Hong Kong, Hong Kong"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5298-6893","authenticated-orcid":false,"given":"Xi","family":"Lin","sequence":"additional","affiliation":[{"name":"Department of Computer Science, City University of Hong Kong, Hong Kong"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1738-6096","authenticated-orcid":false,"given":"Zhiyuan","family":"Yang","sequence":"additional","affiliation":[{"name":"Department of Computer Science, City University of Hong Kong, Hong Kong"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0786-0671","authenticated-orcid":false,"given":"Qingfu","family":"Zhang","sequence":"additional","affiliation":[{"name":"Department of Computer Science, City University of Hong Kong, Hong Kong"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.06083"},{"key":"ref2","first-page":"4334","article-title":"Learning to reweight examples for robust deep learning","volume-title":"Proc. 35th Int. Conf. Mach. Learn.","author":"Ren","year":"2018"},{"key":"ref3","first-page":"11292","article-title":"Provably robust deep learning via adversarially trained smoothed classifiers","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Salman","year":"2019"},{"key":"ref4","first-page":"8270","article-title":"Adversarial distributional training for robust deep learning","volume-title":"Proc. Adv. Neural Inf. Process. Syst. 33: Annu. Conf. Neural Inf. Process. Syst.","author":"Dong","year":"2020"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/tetci.2020.2968933"},{"key":"ref6","article-title":"Intriguing properties of neural networks","volume-title":"Proc. 2nd Int. Conf. Learn. Representations","author":"Szegedy","year":"2014"},{"key":"ref7","article-title":"Explaining and harnessing adversarial examples","volume-title":"Proc. 3rd Int. Conf. Learn. Representations","author":"Goodfellow","year":"2015"},{"key":"ref8","article-title":"Adversarial examples in the physical world","volume-title":"Proc. 5th Int. Conf. Learn. Representations","author":"Kurakin","year":"2017"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00790"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3339815"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref12","first-page":"274","article-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","volume-title":"Proc. 35th Int. Conf. Mach. Learn.","author":"Athalye","year":"2018"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"ref14","first-page":"2206","article-title":"Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks","volume-title":"Proc. Proc. 37th Int. Conf. Mach. Learn.","author":"Croce","year":"2020"},{"key":"ref15","first-page":"484","article-title":"Square attack: A query-efficient black-box adversarial attack via random search","volume-title":"Proc. 16th Eur. Conf. Comput. Vis.","author":"Andriushchenko","year":"2020"},{"key":"ref16","article-title":"Robustbench: A standardized adversarial robustness benchmark","volume-title":"Proc. Neural Inf. Process. Syst. Track Datasets Benchmarks","author":"Croce","year":"2021"},{"key":"ref17","first-page":"18667","article-title":"Probabilistically robust learning: Balancing average and worst-case performance","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Robey","year":"2022"},{"key":"ref18","first-page":"26583","article-title":"How many perturbations break this model? evaluating robustness beyond adversarial accuracy","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Olivier","year":"2023"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23198"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1162\/EVCO_a_00009"},{"key":"ref21","doi-asserted-by":"crossref","first-page":"161","DOI":"10.1201\/9781315183176-4","article-title":"Multi-objective optimization","volume-title":"Decision Sciences","author":"Deb","year":"2016"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/4235.996017"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/TEVC.2007.892759"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2807385"},{"key":"ref25","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3485133","article-title":"Adversarial machine learning in image classification: A survey toward the defender\u2019s perspective","volume":"55","author":"Machado","year":"2023","journal-title":"ACM Comput. Surv."},{"key":"ref26","first-page":"1","article-title":"Trustworthy AI: From principles to practices","volume":"55","author":"Li","year":"2023","journal-title":"ACM Comput. Surv."},{"key":"ref27","article-title":"A survey of black-box adversarial attacks on computer vision models","author":"Bhambri","year":"2019"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/tetci.2022.3214627"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00130"},{"key":"ref30","first-page":"3557","article-title":"L-AutoDA: Automated decision-based iterative adversarial attacks","volume-title":"Proc. 31st USENIX Secur. Symp.","author":"Fu","year":"2022"},{"key":"ref31","article-title":"L-AutoDA: Leveraging large language models for automated decision-based adversarial attacks","author":"Guo","year":"2024"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/TETCI.2021.3122467"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i10.17075"},{"key":"ref34","first-page":"8852","article-title":"Reliable robustness evaluation via automatically constructed attack ensembles","volume-title":"Proc. 37th AAAI Conf. Artif. Intell.","author":"Liu","year":"2023"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2021\/591"},{"key":"ref36","article-title":"SHED: Shapley-based automated dataset refinement for instruction fine-tuning","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"He","year":"2024"},{"key":"ref37","article-title":"FLoRA: Federated fine-tuning large language models with heterogeneous low-rank adaptations","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Wang","year":"2024"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.01577"},{"key":"ref39","article-title":"Countering adversarial images using input transformations","volume-title":"Proc. 6th Int. Conf. Learn. Representations","author":"Guo","year":"2018"},{"key":"ref40","article-title":"PuriDefense: Randomized local implicit adversarial purification for defending black-box query-based attacks","author":"Guo","year":"2024"},{"key":"ref41","article-title":"(Certified!!) adversarial robustness for free!","volume-title":"Proc. 11th Int. Conf. Learn. Representations","author":"Carlini","year":"2023"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23415"},{"key":"ref43","first-page":"2117","article-title":"Blacklight: Scalable defense for neural networks against query-based black-box attacks","volume-title":"Proc. 31st USENIX Secur. Symp.","author":"Li","year":"2022"},{"key":"ref44","first-page":"7472","article-title":"Theoretically principled trade-off between robustness and accuracy","volume-title":"Proc. 36th Int. Conf. Mach. Learn.","author":"Zhang","year":"2019"},{"key":"ref45","first-page":"36246","article-title":"Better diffusion models further improve adversarial training","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Wang","year":"2023"},{"key":"ref46","article-title":"Uncovering the limits of adversarial training against norm-bounded adversarial examples","author":"Gowal","year":"2020"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.01183"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-27250-9_9"},{"key":"ref49","doi-asserted-by":"crossref","first-page":"103","DOI":"10.1007\/978-3-031-27250-9_8","article-title":"Multi-objective learning using HV maximization","volume-title":"Proc. Evol. Multi-Criterion Optim. 12th Int. Conf.","author":"Deist","year":"2023"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1109\/CEC.2019.8790123"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-72699-7_35"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1145\/3651166"},{"key":"ref53","article-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009"},{"key":"ref54","article-title":"Helper-based adversarial training: Reducing excessive margin to achieve a better accuracy vs. robustness trade-off","volume-title":"Proc. 2021 Workshop Adversarial Mach. Learn.","author":"Rade","year":"2021"},{"key":"ref55","article-title":"Robust learning meets generative models: Can proxy distributions improve adversarial robustness?","volume-title":"Proc. 10th Int. Conf. Learn. Representations","author":"Sehwag","year":"2022"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58574-7_14"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-10762-2_65"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1109\/TEVC.2010.2077298"},{"key":"ref59","first-page":"1488","article-title":"Efficient and effective augmentation strategy for adversarial training","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Addepalli","year":"2022"},{"key":"ref60","article-title":"Reducing excessive margin to achieve a better accuracy vs. robustness trade-off","volume-title":"Proc. 10th Int. Conf. Learn. Representations","author":"Rade","year":"2022"},{"key":"ref61","first-page":"29935","article-title":"Data augmentation can improve robustness","volume-title":"Proc. Adv. Neural Inf. Process. Syst. 34: Annu. Conf. Neural Inf. Process. Syst.","author":"Rebuffi","year":"2021"},{"key":"ref62","first-page":"5545","article-title":"Exploring architectural ingredients of adversarially robust deep neural networks","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Huang","year":"2021"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref64","article-title":"Fast is better than free: Revisiting adversarial training","volume-title":"Proc. 8th Int. Conf. Learn. Representations","author":"Wong","year":"2020"},{"key":"ref65","first-page":"3533","article-title":"Do adversarially robust imagenet models transfer better?","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Salman","year":"2020"},{"key":"ref66","article-title":"Robustness (python library)","author":"Engstrom","year":"2019"},{"issue":"83","key":"ref67","first-page":"1","article-title":"CVXPY: A python-embedded modeling language for convex optimization","volume":"17","author":"Diamond","year":"2016","journal-title":"J. Mach. Learn. Res."},{"key":"ref68","first-page":"3533","article-title":"Adversarial patch","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Brown","year":"2017"}],"container-title":["IEEE Transactions on Emerging Topics in Computational Intelligence"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/7433297\/10939044\/10885038.pdf?arnumber=10885038","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,11,27]],"date-time":"2025-11-27T18:59:54Z","timestamp":1764269994000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10885038\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,4]]},"references-count":68,"journal-issue":{"issue":"2"},"URL":"https:\/\/doi.org\/10.1109\/tetci.2025.3535656","relation":{},"ISSN":["2471-285X"],"issn-type":[{"value":"2471-285X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,4]]}}}