{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,8,2]],"date-time":"2025-08-02T19:46:30Z","timestamp":1754163990014,"version":"3.41.2"},"reference-count":42,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["12326618"],"award-info":[{"award-number":["12326618"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100018599","name":"Project of Guangdong Provincial Key Laboratory of Information Security Technology","doi-asserted-by":"publisher","award":["2023B1212060026"],"award-info":[{"award-number":["2023B1212060026"]}],"id":[{"id":"10.13039\/501100018599","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2025]]},"DOI":"10.1109\/tifs.2025.3573121","type":"journal-article","created":{"date-parts":[[2025,5,29]],"date-time":"2025-05-29T13:13:10Z","timestamp":1748524390000},"page":"5632-5646","source":"Crossref","is-referenced-by-count":0,"title":["Releasing Inequality Phenomenon in \u2113<sub>\u221e<\/sub>-Norm Adversarial Training via Input Gradient Distillation"],"prefix":"10.1109","volume":"20","author":[{"given":"Junxi","family":"Chen","sequence":"first","affiliation":[{"name":"School of Computer Science and Engineering, Sun Yat-sen University, Guangzhou, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Junhao","family":"Dong","sequence":"additional","affiliation":[{"name":"College of Computing and Data Science, Nanyang Technological University, Singapore, Singapore"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0310-4679","authenticated-orcid":false,"given":"Xiaohua","family":"Xie","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, Sun Yat-sen University, Guangzhou, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3883-2024","authenticated-orcid":false,"given":"Jianhuang","family":"Lai","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, Sun Yat-sen University, Guangzhou, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","article-title":"Intriguing properties of neural networks","volume-title":"Proc. 2nd Int. Conf. Learn. Represent. (ICLR)","author":"Szegedy","year":"2014"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.06083"},{"key":"ref3","first-page":"1","article-title":"Improving adversarial robustness requires revisiting misclassified examples","volume-title":"Proc. 8th Int. Conf. Learn. Represent. (ICLR)","author":"Wang"},{"key":"ref4","first-page":"1","article-title":"Detecting and diagnosing adversarial images with class-conditional capsule reconstructions","volume-title":"Proc. 8th Int. Conf. Learn. Represent. (ICLR)","author":"Qin"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58592-1_24"},{"key":"ref6","first-page":"1383","article-title":"Concise explanations of neural networks using adversarial training","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Chalasani"},{"key":"ref7","first-page":"3319","article-title":"Axiomatic attribution for deep networks","volume-title":"Proc. Int. Conf. Mach. Learn.","volume":"70","author":"Sundararajan"},{"key":"ref8","first-page":"1","article-title":"Inequality phenomenon in l\u221e-adversarial training, and its unrealized threats","volume-title":"Proc. 11th Int. Conf. Learn. Represent. (ICLR)","author":"Duan"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.2307\/1924845"},{"key":"ref10","article-title":"Improved regularization of convolutional neural networks with cutout","author":"DeVries","year":"2017","journal-title":"arXiv:1708.04552"},{"key":"ref11","first-page":"1","article-title":"Benchmarking neural network robustness to common corruptions and perturbations","volume-title":"Proc. 7th Int. Conf. Learn. Represent. (ICLR)","author":"Hendrycks"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2025.3533925"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3359820"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3377004"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3420128"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2023.3263637"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2022.3184262"},{"key":"ref18","first-page":"43685","article-title":"Robust CLIP: Unsupervised adversarial fine-tuning of vision embeddings for robust large vision-language models","volume-title":"Proc. 41st Int. Conf. Mach. Learn. (ICML)","author":"Schlarmann"},{"key":"ref19","article-title":"Double visual defense: Adversarial pre-training and instruction tuning for improving vision-language model robustness","author":"Wang","year":"2025","journal-title":"arXiv:2501.09446"},{"key":"ref20","article-title":"Robust-LLaVA: On the effectiveness of large-scale robust image encoders for multi-modal large language models","author":"Malik","year":"2025","journal-title":"arXiv:2502.01576"},{"key":"ref21","first-page":"1","article-title":"RobustBench: A standardized adversarial robustness benchmark","volume-title":"Proc. Neural Inf. Process. Syst. Track Datasets Benchmarks (NeurIPS) Datasets Benchmarks","author":"Croce"},{"key":"ref22","first-page":"4421","article-title":"Evaluating the adversarial robustness of adaptive test-time defenses","volume-title":"Proc. Int. Conf. Mach. Learn. (ICML)","volume":"162","author":"Croce"},{"key":"ref23","article-title":"Adversarial ML problems are getting harder to solve and to evaluate","author":"Rando","year":"2025","journal-title":"arXiv:2502.02260"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v32i1.11504"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1016\/j.mlwa.2020.100017"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00041"},{"key":"ref27","article-title":"How and when adversarial robustness transfers in knowledge distillation?","author":"Shao","year":"2021","journal-title":"arXiv:2110.12072"},{"key":"ref28","first-page":"16048","article-title":"Understanding and improving fast adversarial training","volume-title":"Proc. Adv. Neural Inf. Process. Syst., Annu. Conf. Neural Inf. Process. Syst. (NeurIPS)","author":"Andriushchenko"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref31","article-title":"Not just a black box: Learning important features through propagating activation differences","author":"Shrikumar","year":"2016","journal-title":"arXiv:1605.01713"},{"key":"ref32","article-title":"A unified approach to interpreting model predictions","author":"Lundberg","year":"2017","journal-title":"arXiv:1705.07874"},{"key":"ref33","article-title":"SmoothGrad: Removing noise by adding noise","author":"Smilkov","year":"2017","journal-title":"arXiv:1706.03825"},{"key":"ref34","first-page":"1","article-title":"Deep inside convolutional networks: Visualising image classification models and saliency maps","volume-title":"Proc. 2nd Int. Conf. Learn. Represent. (ICLR)","author":"Simonyan"},{"key":"ref35","article-title":"Captum: A unified and generic model interpretability library for PyTorch","author":"Kokhlikyan","year":"2020","journal-title":"arXiv:2009.07896"},{"key":"ref36","first-page":"2206","article-title":"Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Croce"},{"key":"ref37","first-page":"13255","article-title":"A Fourier perspective on model robustness in computer vision","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Yin"},{"article-title":"Learning multiple layers of features from tiny images","year":"2009","author":"Krizhevsky","key":"ref38"},{"key":"ref39","first-page":"7472","article-title":"Theoretically principled trade-off between robustness and accuracy","volume-title":"Proc. 36th Int. Conf. Mach. Learn. (ICML)","volume":"97","author":"Zhang"},{"key":"ref40","first-page":"9","article-title":"One-vs-the-rest loss to focus on important samples in adversarial training","volume-title":"Proc. Int. Conf. Mach. Learn. (ICML)","volume":"202","author":"Kanai"},{"key":"ref41","first-page":"1","article-title":"MMA training: Direct input space margin maximization through adversarial training","volume-title":"Proc. 8th Int. Conf. Learn. Represent. (ICLR)","author":"Ding"},{"article-title":"Robustness (Python library)","year":"2019","author":"Engstrom","key":"ref42"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/10206\/10810755\/11018118.pdf?arnumber=11018118","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,31]],"date-time":"2025-07-31T18:31:21Z","timestamp":1753986681000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11018118\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"references-count":42,"URL":"https:\/\/doi.org\/10.1109\/tifs.2025.3573121","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"type":"print","value":"1556-6013"},{"type":"electronic","value":"1556-6021"}],"subject":[],"published":{"date-parts":[[2025]]}}}