{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,16]],"date-time":"2025-10-16T07:00:18Z","timestamp":1760598018028,"version":"3.37.3"},"reference-count":55,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61672421"],"award-info":[{"award-number":["61672421"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Blockchain Core Technology Strategic Research Program","award":["2020KJ010801"],"award-info":[{"award-number":["2020KJ010801"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2021]]},"DOI":"10.1109\/tifs.2020.3047752","type":"journal-article","created":{"date-parts":[[2020,12,28]],"date-time":"2020-12-28T20:44:58Z","timestamp":1609188298000},"page":"2447-2460","source":"Crossref","is-referenced-by-count":15,"title":["Adversarial Adaptive Neighborhood With Feature Importance-Aware Convex Interpolation"],"prefix":"10.1109","volume":"16","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-0110-451X","authenticated-orcid":false,"given":"Qian","family":"Li","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7682-5653","authenticated-orcid":false,"given":"Yong","family":"Qi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Qingyuan","family":"Hu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0394-4432","authenticated-orcid":false,"given":"Saiyu","family":"Qi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8255-0118","authenticated-orcid":false,"given":"Yun","family":"Lin","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jin Song","family":"Dong","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref39","article-title":"Spectrally-normalized margin bounds for neural networks","author":"bartlett","year":"2017","journal-title":"arXiv 1706 08498"},{"key":"ref38","article-title":"Max-margin deep generative models","author":"li","year":"2015","journal-title":"arXiv 1504 06787"},{"key":"ref33","article-title":"Feature importance estimation with self-attention networks","author":"\u0161krlj","year":"2020","journal-title":"arXiv 2002 04464"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2019\/403"},{"key":"ref31","article-title":"BUZz: BUffer zones for defending adversarial examples in image classification","author":"mahmood","year":"2019","journal-title":"arXiv 1910 02785"},{"key":"ref30","article-title":"Adversarial training with Voronoi constraints","author":"khoury","year":"2019","journal-title":"arXiv 1905 01019"},{"key":"ref37","first-page":"1","article-title":"Mixup: Beyond empirical risk minimization","author":"zhang","year":"2018","journal-title":"Proc 6th Int Conf Learn Represent (ICLR)"},{"key":"ref36","first-page":"6438","article-title":"Manifold mixup: Better representations by interpolating hidden states","author":"verma","year":"2019","journal-title":"Proc 36th Int Conf Mach Learn (ICML)"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP.2018.8461704"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP.2007.365989"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"ref27","article-title":"Understanding and improving fast adversarial training","author":"andriushchenko","year":"2020","journal-title":"arXiv 2007 02617"},{"key":"ref29","first-page":"1","article-title":"Decision boundary analysis of adversarial examples","author":"he","year":"2018","journal-title":"Proc 6th Int Conf Learn Represent (ICLR)"},{"key":"ref2","first-page":"1","article-title":"Explaining and harnessing adversarial examples","author":"goodfellow","year":"2015","journal-title":"Proc 3rd Int Conf Learn Represent (ICLR)"},{"key":"ref1","first-page":"1","article-title":"Intriguing properties of neural networks","author":"szegedy","year":"2014","journal-title":"Proc 2nd Int Conf Learn Represent (ICLR)"},{"key":"ref20","first-page":"274","article-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","volume":"80","author":"athalye","year":"2018","journal-title":"Proc 35th Int Conf Mach Learn (ICML)"},{"key":"ref22","article-title":"Logit pairing methods can fool gradient-based attacks","author":"mosbach","year":"2018","journal-title":"arXiv 1810 12042"},{"key":"ref21","first-page":"1","article-title":"Mitigating adversarial effects through randomization","author":"xie","year":"2018","journal-title":"Proc 6th Int Conf Learn Represent (ICLR)"},{"key":"ref24","first-page":"6","article-title":"Robustness may be at odds with accuracy","author":"tsipras","year":"2019","journal-title":"Proc 7th Int Conf Learn Represent (ICLR)"},{"journal-title":"Deep Learning","year":"2016","author":"goodfellow","key":"ref23"},{"key":"ref26","article-title":"Certifying some distributional robustness with principled adversarial training","author":"sinha","year":"2018","journal-title":"Proc 6th Int Conf Learn Represent (ICLR)"},{"key":"ref25","first-page":"7472","article-title":"Theoretically principled trade-off between robustness and accuracy","author":"zhang","year":"2019","journal-title":"Proc 36th Int Conf Mach Learn (ICML)"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref51","article-title":"On the robustness of the CVPR 2018 white-box adversarial example defenses","author":"athalye","year":"2018","journal-title":"arXiv 1804 03286"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.41"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1109\/ICDM.2018.00029"},{"key":"ref53","first-page":"3111","article-title":"Distributed representations of words and phrases and their compositionality","author":"mikolov","year":"2013","journal-title":"Advances in Neural Information Processing Systems 26"},{"key":"ref52","first-page":"1","article-title":"L2-nonexpansive neural networks","author":"qian","year":"2019","journal-title":"Proc 7th Int Conf Learn Represent (ICLR)"},{"key":"ref10","first-page":"1","article-title":"Towards deep learning models resistant to adversarial attacks","author":"madry","year":"2018","journal-title":"Proc 6th Int Conf Learn Represent (ICLR)"},{"key":"ref11","first-page":"854","article-title":"Parseval networks: Improving robustness to adversarial examples","volume":"70","author":"cisse","year":"2017","journal-title":"Proc 34th Int Conf Mach Learn"},{"key":"ref40","first-page":"190","article-title":"Marginal structured SVM with hidden variables","author":"ping","year":"2014","journal-title":"Proc 31th Int Conf Mach Learn (ICML)"},{"key":"ref12","first-page":"7025","article-title":"ME-net: Towards effective adversarial robustness with matrix estimation","volume":"97","author":"yang","year":"2019","journal-title":"Proc 36th Int Conf Mach Learn (ICML)"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2020\/324"},{"key":"ref14","first-page":"1","article-title":"MMA training: Direct input space margin maximization through adversarial training","author":"ding","year":"2020","journal-title":"Proc 8th Int Conf Learn Represent (ICLR)"},{"key":"ref15","first-page":"26","article-title":"Fast is better than free: Revisiting adversarial training","author":"wong","year":"2020","journal-title":"Proc 8th Int Conf Learn Represent (ICLR)"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140444"},{"key":"ref17","article-title":"Adversarial transformation networks: Learning to generate adversarial examples","author":"baluja","year":"2017","journal-title":"arXiv 1703 09387"},{"key":"ref18","first-page":"24","article-title":"Adversarial machine learning at scale","author":"kurakin","year":"2017","journal-title":"Proc 5th Int Conf Learn Represent (ICLR)"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/ICDM.2018.00159"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1038\/nature21056"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/ICRA.2018.8460487"},{"key":"ref8","first-page":"1","article-title":"Stochastic activation pruning for robust adversarial defense","author":"dhillon","year":"2018","journal-title":"Proc 6th Int Conf Learn Represent (ICLR)"},{"key":"ref7","article-title":"Can you fool ai with adversarial examples on a visual turing test","author":"xu","year":"2017","journal-title":"arXiv 1709 08693"},{"key":"ref49","first-page":"1","article-title":"Restricting the flow: Information bottlenecks for attribution","author":"schulz","year":"2020","journal-title":"Proc 8th Int Conf Learn Represent (ICLR)"},{"key":"ref9","first-page":"1","article-title":"Thermometer encoding: One hot way to resist adversarial examples","author":"buckman","year":"2018","journal-title":"Proc 6th Int Conf Learn Represent (ICLR)"},{"key":"ref46","first-page":"142","article-title":"Learning word vectors for sentiment analysis","author":"maas","year":"2011","journal-title":"Proc Conf 49th Annu Meeting Assoc Comput Linguist Hum Lang Technol"},{"journal-title":"Learning multiple layers of features from tiny images","year":"2009","author":"krizhevsky","key":"ref45"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00068"},{"key":"ref47","article-title":"Delving into transferable adversarial examples and black-box attacks","author":"liu","year":"2016","journal-title":"arXiv 1611 02770"},{"key":"ref42","article-title":"Characterizing implicit bias in terms of optimization geometry","author":"gunasekar","year":"2018","journal-title":"arXiv 1802 08246"},{"key":"ref41","article-title":"An exploration of softmax alternatives belonging to the spherical loss family","author":"de br\u00e9bisson","year":"2015","journal-title":"arXiv 1511 05042"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"key":"ref43","first-page":"416","article-title":"Vicinal risk minimization","author":"chapelle","year":"2000","journal-title":"Proc Neural Inf Process Syst (NIPS)"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/10206\/9151439\/09309245.pdf?arnumber=9309245","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,5,10]],"date-time":"2022-05-10T14:52:45Z","timestamp":1652194365000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9309245\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021]]},"references-count":55,"URL":"https:\/\/doi.org\/10.1109\/tifs.2020.3047752","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"type":"print","value":"1556-6013"},{"type":"electronic","value":"1556-6021"}],"subject":[],"published":{"date-parts":[[2021]]}}}