{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,28]],"date-time":"2026-04-28T15:18:10Z","timestamp":1777389490628,"version":"3.51.4"},"reference-count":59,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62025604"],"award-info":[{"award-number":["62025604"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Shenzhen Science and Technology Program","award":["JCYJ20220818102012025"],"award-info":[{"award-number":["JCYJ20220818102012025"]}]},{"DOI":"10.13039\/501100001809","name":"National Research Foundation, Singapore","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Cyber Security Agency under its National Cybersecurity Research and Development Program","award":["NCRP25-P04-TAICeN"],"award-info":[{"award-number":["NCRP25-P04-TAICeN"]}]},{"name":"Nanyang Technological University (NTU)-DESAY SV Research Program","award":["2018-0980"],"award-info":[{"award-number":["2018-0980"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2024]]},"DOI":"10.1109\/tifs.2024.3420128","type":"journal-article","created":{"date-parts":[[2024,6,27]],"date-time":"2024-06-27T19:51:21Z","timestamp":1719517881000},"page":"8125-8139","source":"Crossref","is-referenced-by-count":9,"title":["Revisiting and Exploring Efficient Fast Adversarial Training via LAW: Lipschitz Regularization and Auto Weight Averaging"],"prefix":"10.1109","volume":"19","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-2018-9344","authenticated-orcid":false,"given":"Xiaojun","family":"Jia","sequence":"first","affiliation":[{"name":"Cyber Security Research Centre @ NTU, Nanyang Technological University, Jurong West, Singapore"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9027-3421","authenticated-orcid":false,"given":"Yuefeng","family":"Chen","sequence":"additional","affiliation":[{"name":"Security Department, Alibaba Group, Hangzhou, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xiaofeng","family":"Mao","sequence":"additional","affiliation":[{"name":"Security Department, Alibaba Group, Hangzhou, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ranjie","family":"Duan","sequence":"additional","affiliation":[{"name":"Security Department, Alibaba Group, Hangzhou, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-0574-0129","authenticated-orcid":false,"given":"Jindong","family":"Gu","sequence":"additional","affiliation":[{"name":"Department of Engineering Science, University of Oxford, Oxford, U.K."}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2288-2847","authenticated-orcid":false,"given":"Rong","family":"Zhang","sequence":"additional","affiliation":[{"name":"Security Department, Alibaba Group, Hangzhou, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2093-2839","authenticated-orcid":false,"given":"Hui","family":"Xue","sequence":"additional","affiliation":[{"name":"Security Department, Alibaba Group, Hangzhou, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7300-9215","authenticated-orcid":false,"given":"Yang","family":"Liu","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, Nanyang Technological University, Jurong West, Singapore"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7141-708X","authenticated-orcid":false,"given":"Xiaochun","family":"Cao","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Technology, Sun Yat-sen University, Shenzhen Campus, Shenzhen, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/icassp.2013.6639344"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/asru.2013.6707749"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1145\/3065386"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/tnnls.2018.2876865"},{"key":"ref5","first-page":"9185","article-title":"Boosting adversarial attacks with momentum","volume-title":"Proc. IEEE\/CVF Conf. Comput. Vis. Pattern Recognit.","author":"Dong"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58542-6_3"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1145\/3394171.3413976"},{"key":"ref8","first-page":"997","article-title":"Adversarial camouflage: Hiding physical-world attacks with natural styles","volume-title":"Proc. IEEE\/CVF Conf. Comput. Vis. Pattern Recognit. (CVPR)","author":"Duan"},{"key":"ref9","first-page":"1924","article-title":"Enhancing the transferability of adversarial attacks through variance tuning","volume-title":"Proc. IEEE\/CVF Conf. Comput. Vis. Pattern Recognit. (CVPR)","author":"Wang"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2018\/520"},{"key":"ref11","first-page":"1","article-title":"Improving adversarial robustness requires revisiting misclassified examples","volume-title":"Proc. 8th Int. Conf. Learn. Represent.","author":"Wang"},{"key":"ref12","first-page":"6586","article-title":"On the convergence and robustness of adversarial training","volume-title":"Proc. ICML","volume":"97","author":"Wang"},{"key":"ref13","first-page":"11278","article-title":"Attacks which do not kill training make adversarial learning stronger","volume-title":"Proc. 37th Int. Conf. Mach. Learn.","author":"Zhang"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/iccv48922.2021.01543"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1145\/3474369.3486878"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/cvpr52688.2022.01173"},{"key":"ref17","article-title":"Ensemble adversarial training: Attacks and defenses","author":"Tram\u00e9r","year":"2018","journal-title":"arXiv:1705.07204"},{"key":"ref18","volume-title":"Fast is Better Than Free: Revisiting Adversarial Training","author":"Wong","year":"2020"},{"key":"ref19","first-page":"8119","article-title":"Understanding catastrophic overfitting in single-step adversarial training","volume-title":"Proc. 34th Conf. Artif. Intell. (AAAI), 33rd Conf. Innov. Appl. Artif. Intell. (IAAI), 11th Symp. Educ. Adv. Artif. Intell. (EAAI)","author":"Kim"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/tip.2022.3184255"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/cvpr52688.2022.01305"},{"key":"ref22","first-page":"12881","article-title":"Make some noise: Reliable and efficient single-step adversarial training","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"de Jorge Aranda"},{"key":"ref23","first-page":"1178","article-title":"Efficient adversarial training with transferable adversarial examples","volume-title":"Proc. IEEE\/CVF Conf. Comput. Vis. Pattern Recognit. (CVPR)","author":"Zheng"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-19772-7_33"},{"key":"ref25","first-page":"20297","article-title":"Guided adversarial attack for evaluating and enhancing adversarial defenses","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Sriramanan"},{"key":"ref26","first-page":"11821","article-title":"Towards efficient and effective adversarial training","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Sriramanan"},{"key":"ref27","first-page":"16048","article-title":"Understanding and improving fast adversarial training","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Andriushchenko"},{"key":"ref28","article-title":"Fixing data augmentation to improve adversarial robustness","author":"Rebuffi","year":"2021","journal-title":"arXiv:2103.01946"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/tpami.2018.2858821"},{"key":"ref30","first-page":"1625","article-title":"Robust physical-world attacks on deep learning visual classification","volume-title":"Proc. IEEE\/CVF Conf. Comput. Vis. Pattern Recognit.","author":"Eykholt"},{"key":"ref31","article-title":"Adversarial examples on segmentation models can be easy to transfer","author":"Gu","year":"2021","journal-title":"arXiv:2111.11368"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2021\/173"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/iccv48922.2021.00775"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/iccv48922.2021.00741"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/cvpr52688.2022.01295"},{"key":"ref36","article-title":"Explaining and harnessing adversarial examples","author":"Goodfellow","year":"2014","journal-title":"arXiv:1412.6572"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.06083"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/sp.2017.49"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58592-1_29"},{"key":"ref40","first-page":"2196","article-title":"Minimally distorted adversarial examples with a fast adaptive boundary attack","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Croce"},{"key":"ref41","first-page":"2206","article-title":"Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Croce"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/cvpr52688.2022.00015"},{"key":"ref43","first-page":"26693","article-title":"Revisiting and advancing fast adversarial training through the lens of bi-level optimization","volume-title":"Proc. Int. Conf. Mach. Learn.","volume":"162","author":"Zhang"},{"key":"ref44","first-page":"2958","article-title":"Adversarial weight perturbation helps robust generalization","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Wu"},{"key":"ref45","article-title":"Uncovering the limits of adversarial training against norm-bounded adversarial examples","author":"Gowal","year":"2020","journal-title":"arXiv:2010.03593"},{"key":"ref46","article-title":"Improved regularization of convolutional neural networks with cutout","author":"DeVries","year":"2017","journal-title":"arXiv:1708.04552"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4899-7687-1_79"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/iccv.2019.00612"},{"key":"ref49","article-title":"AutoAugment: Learning augmentation policies from data","author":"Cubuk","year":"2018","journal-title":"arXiv:1805.09501"},{"key":"ref50","first-page":"876","article-title":"Averaging weights leads to wider optima and better generalization","volume-title":"Proc. Conf. Uncertainty Artif. Intell.","author":"Izmailov"},{"key":"ref51","first-page":"1","article-title":"Robust overfitting may be mitigated by properly learned smoothening","volume-title":"Proc. 9th Int. Conf. Learn. Represent.","author":"Chen"},{"key":"ref52","volume-title":"Self-Ensemble Adversarial Training for Improved Robustness","author":"Wang","year":"2022"},{"key":"ref53","volume-title":"Evaluating the Robustness of Neural Networks: An Extreme Value Theory Approach","author":"Weng","year":"2018"},{"key":"ref54","first-page":"7054","article-title":"Do wider neural networks really help adversarial robustness?","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Wu"},{"key":"ref55","volume-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1109\/cvpr.2009.5206848"},{"key":"ref57","first-page":"8093","article-title":"Overfitting in adversarially robust deep learning","volume-title":"Proc. 37th Int. Conf. Mach. Learn.","author":"Rice"},{"key":"ref58","first-page":"3353","article-title":"Adversarial training for free!","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Shafahi"},{"key":"ref59","volume-title":"Bag of Tricks for Adversarial Training","author":"Pang","year":"2021"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/10206\/10319981\/10574880.pdf?arnumber=10574880","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,1,14]],"date-time":"2025-01-14T19:44:10Z","timestamp":1736883850000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10574880\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024]]},"references-count":59,"URL":"https:\/\/doi.org\/10.1109\/tifs.2024.3420128","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"value":"1556-6013","type":"print"},{"value":"1556-6021","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024]]}}}