{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,24]],"date-time":"2026-07-24T14:53:21Z","timestamp":1784904801224,"version":"3.55.0"},"reference-count":48,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"Center for Applied Research in Artificial Intelligence (CARAI) grant funded by DAPA and ADD","award":["(UD230017TD)"],"award-info":[{"award-number":["(UD230017TD)"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2023]]},"DOI":"10.1109\/tifs.2023.3288672","type":"journal-article","created":{"date-parts":[[2023,6,24]],"date-time":"2023-06-24T00:37:50Z","timestamp":1687567070000},"page":"4021-4033","source":"Crossref","is-referenced-by-count":6,"title":["Robust Proxy: Improving Adversarial Robustness by Robust Proxy Learning"],"prefix":"10.1109","volume":"18","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-6626-5683","authenticated-orcid":false,"given":"Hong Joo","family":"Lee","sequence":"first","affiliation":[{"name":"Image and Video Systems Laboratory, School of Electrical Engineering, Korea Advanced Institute of Science and Technology (KAIST), Daejeon, South Korea"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5306-6853","authenticated-orcid":false,"given":"Yong Man","family":"Ro","sequence":"additional","affiliation":[{"name":"Image and Video Systems Laboratory, School of Electrical Engineering, Korea Advanced Institute of Science and Technology (KAIST), Daejeon, South Korea"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref13","first-page":"4970","article-title":"Improving adversarial robustness via promoting ensemble diversity","author":"pang","year":"2019","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00756"},{"key":"ref12","article-title":"Countering adversarial images using input transformations","author":"guo","year":"2017","journal-title":"arXiv 1711 00117"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01258-8_32"},{"key":"ref15","first-page":"1","article-title":"Improving adversarial robustness requires revisiting misclassified examples","author":"wang","year":"2019","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref37","article-title":"Learning multiple layers of features from tiny images","author":"krizhevsky","year":"2009"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01470"},{"key":"ref36","first-page":"1","article-title":"Deep variational information bottleneck","author":"alemi","year":"2017","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i4.16424"},{"key":"ref30","article-title":"Robustness may be at odds with accuracy","author":"tsipras","year":"2018","journal-title":"arXiv 1805 12152"},{"key":"ref11","article-title":"Stochastic activation pruning for robust adversarial defense","author":"dhillon","year":"2018","journal-title":"arXiv 1803 01442"},{"key":"ref33","article-title":"Geometry-aware instance-reweighted adversarial training","author":"zhang","year":"2020","journal-title":"arXiv 2010 01736"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00191"},{"key":"ref32","first-page":"12302","article-title":"Demystifying causal features on adversarial examples and causal inoculation for robust network by adversarial instrumental variable regression","author":"kim","year":"2023","journal-title":"Proc IEEE\/CVF Conf Comput Vis Pattern Recognit (CVPR)"},{"key":"ref2","article-title":"Deep speech: Scaling up end-to-end speech recognition","author":"hannun","year":"2014","journal-title":"arXiv 1412 5567"},{"key":"ref1","first-page":"1","article-title":"ImageNet classification with deep convolutional neural networks","volume":"25","author":"krizhevsky","year":"2012","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref17","first-page":"1","article-title":"Reducing excessive margin to achieve a better accuracy vs. robustness trade-off","author":"rade","year":"2022","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref16","first-page":"7472","article-title":"Theoretically principled trade-off between robustness and accuracy","author":"zhang","year":"2019","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref38","first-page":"3","article-title":"Tiny ImageNet visual recognition challenge","volume":"7","author":"le","year":"2015","journal-title":"CS 231N"},{"key":"ref19","first-page":"274","article-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","author":"athalye","year":"2018","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2021\/591"},{"key":"ref24","first-page":"16199","article-title":"Robust pre-training by adversarial contrastive learning","volume":"33","author":"jiang","year":"2020","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref46","first-page":"21692","article-title":"Detecting adversarial examples is (nearly) as hard as classifying them","author":"tramer","year":"2022","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref23","first-page":"2983","article-title":"Adversarial self-supervised contrastive learning","volume":"33","author":"kim","year":"2020","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref45","first-page":"1633","article-title":"On adaptive attacks to adversarial example defenses","volume":"33","author":"tramer","year":"2020","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref26","first-page":"1","article-title":"Adversarial examples are not bugs, they are features","volume":"32","author":"ilyas","year":"2019","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01489"},{"key":"ref25","article-title":"Self-supervised adversarial robustness for the low-label, high-data regime","author":"gowal","year":"2021","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/ICIP40778.2020.9191259"},{"key":"ref20","first-page":"1","article-title":"Metric learning for adversarial robustness","volume":"32","author":"mao","year":"2019","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref42","first-page":"2196","article-title":"Minimally distorted adversarial examples with a fast adaptive boundary attack","author":"croce","year":"2020","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref41","first-page":"2206","article-title":"Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks","author":"croce","year":"2020","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00665"},{"key":"ref44","article-title":"On evaluating adversarial robustness","author":"carlini","year":"2019","journal-title":"arXiv 1902 06705"},{"key":"ref21","first-page":"1","article-title":"When does contrastive learning preserve adversarial robustness from pretraining to finetuning?","volume":"34","author":"fan","year":"2021","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58592-1_29"},{"key":"ref28","first-page":"5498","article-title":"The odds are odd: A statistical test for detecting adversarial examples","author":"roth","year":"2019","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref27","first-page":"17148","article-title":"Distilling robust and non-robust features in adversarial examples by information bottleneck","volume":"34","author":"kim","year":"2021","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref29","first-page":"1","article-title":"Are adversarial examples inevitable?","author":"shafahi","year":"2019","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140448"},{"key":"ref7","article-title":"Intriguing properties of neural networks","author":"szegedy","year":"2013","journal-title":"arXiv 1312 6199"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref4","article-title":"Explaining and harnessing adversarial examples","author":"goodfellow","year":"2014","journal-title":"arXiv 1412 6572"},{"key":"ref3","first-page":"1","article-title":"Distributed representations of words and phrases and their compositionality","volume":"26","author":"mikolov","year":"2013","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref6","article-title":"Towards deep learning models resistant to adversarial attacks","author":"madry","year":"2017","journal-title":"arXiv 1706 06083"},{"key":"ref5","first-page":"427","article-title":"Deep neural networks are easily fooled: High confidence predictions for unrecognizable images","author":"nguyen","year":"2015","journal-title":"Proc IEEE Conf Comput Vis Pattern Recognit (CVPR)"},{"key":"ref40","article-title":"Wide residual networks","author":"zagoruyko","year":"2016","journal-title":"arXiv 1605 07146"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/10206\/9970396\/10159405.pdf?arnumber=10159405","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,7,31]],"date-time":"2023-07-31T17:28:23Z","timestamp":1690824503000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10159405\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023]]},"references-count":48,"URL":"https:\/\/doi.org\/10.1109\/tifs.2023.3288672","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"value":"1556-6013","type":"print"},{"value":"1556-6021","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023]]}}}