{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,19]],"date-time":"2026-02-19T15:24:17Z","timestamp":1771514657332,"version":"3.50.1"},"reference-count":66,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/100015549","name":"Macau Science and Technology Development Fund","doi-asserted-by":"publisher","award":["001\/2024\/SKL"],"award-info":[{"award-number":["001\/2024\/SKL"]}],"id":[{"id":"10.13039\/100015549","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100015549","name":"Macau Science and Technology Development Fund","doi-asserted-by":"publisher","award":["0022\/2022\/A1"],"award-info":[{"award-number":["0022\/2022\/A1"]}],"id":[{"id":"10.13039\/100015549","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100015549","name":"Macau Science and Technology Development Fund","doi-asserted-by":"publisher","award":["0119\/2024\/RIB2"],"award-info":[{"award-number":["0119\/2024\/RIB2"]}],"id":[{"id":"10.13039\/100015549","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Research Committee at University of Macau","award":["MYRG-GRG2023-00058-FST-UMDF"],"award-info":[{"award-number":["MYRG-GRG2023-00058-FST-UMDF"]}]},{"DOI":"10.13039\/501100021171","name":"Basic and Applied Basic Research Foundation of Guangdong Province","doi-asserted-by":"publisher","award":["2024A1515012536"],"award-info":[{"award-number":["2024A1515012536"]}],"id":[{"id":"10.13039\/501100021171","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2025]]},"DOI":"10.1109\/tifs.2025.3581021","type":"journal-article","created":{"date-parts":[[2025,6,20]],"date-time":"2025-06-20T17:27:06Z","timestamp":1750440426000},"page":"6236-6251","source":"Crossref","is-referenced-by-count":3,"title":["Toward Robust Learning via Core Feature-Aware Adversarial Training"],"prefix":"10.1109","volume":"20","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-5080-7425","authenticated-orcid":false,"given":"Fengpeng","family":"Li","sequence":"first","affiliation":[{"name":"Department of Computer and Information Science, Faculty of Science and Technology, State Key Laboratory of Internet of Things for Smart City, University of Macau, Taipa, Macau, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6669-9713","authenticated-orcid":false,"given":"Kemou","family":"Li","sequence":"additional","affiliation":[{"name":"Department of Computer and Information Science, Faculty of Science and Technology, State Key Laboratory of Internet of Things for Smart City, University of Macau, Taipa, Macau, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8807-0254","authenticated-orcid":false,"given":"Haiwei","family":"Wu","sequence":"additional","affiliation":[{"name":"School of Information and Software Engineering, University of Electronic Science and Technology of China, Chengdu, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2449-5277","authenticated-orcid":false,"given":"Jinyu","family":"Tian","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, Macau University of Science and Technology, Taipa, Macau, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6015-2618","authenticated-orcid":false,"given":"Jiantao","family":"Zhou","sequence":"additional","affiliation":[{"name":"Department of Computer and Information Science, Faculty of Science and Technology, State Key Laboratory of Internet of Things for Smart City, University of Macau, Taipa, Macau, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","first-page":"1","article-title":"Intriguing properties of neural networks","volume-title":"Proc. ICLR","author":"Szegedy"},{"key":"ref2","first-page":"1","article-title":"Explaining and harnessing adversarial examples","volume-title":"Proc. Int. Conf. Learn. Represent. (ICLR)","author":"Goodfellow"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1186\/s12880-020-00530-y"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3465212"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3430508"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2019\/134"},{"key":"ref7","article-title":"An effective and robust detector for logo detection","author":"Jia","year":"2021","journal-title":"arXiv:2108.00422"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2020.acl-main.319"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.acl-long.153"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.06083"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01543"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2022.3184255"},{"key":"ref13","first-page":"127099","article-title":"DAT: Improving adversarial robustness via generative amplitude mix-up in frequency domain","volume-title":"Proc. NeurIPS","author":"Li"},{"key":"ref14","first-page":"1","article-title":"Robustness may be at odds with accuracy","volume-title":"Proc. Int. Conf. Learn. Represent. (ICLR)","author":"Tsipras"},{"key":"ref15","article-title":"Adversarial logit pairing","author":"Kannan","year":"2018","journal-title":"arXiv:1803.06373"},{"key":"ref16","first-page":"7472","article-title":"Theoretically principled trade-off between robustness and accuracy","volume-title":"Proc. 36th Int. Conf. Mach. Learn. (ICML)","volume":"97","author":"Zhang"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2023.3263637"},{"key":"ref18","first-page":"1","article-title":"Squeeze training for adversarial robustness","volume-title":"Proc. Int. Conf. Learn. Represent. (ICLR)","author":"Li"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2023.3306933"},{"key":"ref20","first-page":"1","article-title":"Robustness to adversarial examples through an ensemble of specialists","volume-title":"Proc. Int. Conf. Learn. Represent. Workshop (ICLRW)","author":"Abbasi"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3359820"},{"key":"ref22","article-title":"Fixing data augmentation to improve adversarial robustness","author":"Rebuffi","year":"2021","journal-title":"arXiv:2103.01946"},{"key":"ref23","first-page":"36246","article-title":"Better diffusion models further improve adversarial training","volume-title":"Proc. Int. Conf. Mach. Learn. (ICML)","volume":"202","author":"Wang"},{"key":"ref24","first-page":"74461","article-title":"Decoupled Kullback\u2013Leibler divergence loss","volume-title":"Proc. NeurIPS","author":"Cui"},{"key":"ref25","first-page":"26565","article-title":"Elucidating the design space of diffusion-based generative models","volume-title":"Proc. NeurIPS","volume":"35","author":"Karras"},{"key":"ref26","article-title":"Saliency guided adversarial training for learning generalizable features with applications to medical imaging classification system","author":"Li","year":"2022","journal-title":"arXiv:2209.04326"},{"key":"ref27","first-page":"38761","article-title":"Explicit tradeoffs between adversarial and natural distributional robustness","volume-title":"Proc. NeurIPS","author":"Moayeri"},{"key":"ref28","first-page":"1234","article-title":"On the clean generalization and robust overfitting in adversarial training from two theoretical views: Representation complexity and training dynamics","volume-title":"Proc. 41st Int. Conf. Mach. Learn. (ICML)","volume":"2024","author":"Li"},{"key":"ref29","first-page":"1","article-title":"Adversarial machine learning at scale","volume-title":"Proc. ICLR","author":"Kurakin"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"ref33","first-page":"2196","article-title":"Minimally distorted adversarial examples with a fast adaptive boundary attack","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Croce"},{"key":"ref34","first-page":"2142","article-title":"Black-box adversarial attacks with limited queries and information","volume-title":"Proc. Int. Conf. Mach. Learn.","volume":"80","author":"Ilyas"},{"key":"ref35","first-page":"10932","article-title":"Improving black-box adversarial attacks with a transfer-based prior","volume-title":"Proc. NeurIPS","author":"Cheng"},{"key":"ref36","first-page":"85","article-title":"Backpropagating linearly improves transferability of adversarial examples","volume-title":"Proc. NIPS","author":"Guo"},{"key":"ref37","first-page":"12849","article-title":"Practical no-box adversarial attacks against DNNs","volume-title":"Proc. NeurIPS","author":"Li"},{"key":"ref38","first-page":"2206","article-title":"Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Croce"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58592-1_29"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2018\/520"},{"key":"ref41","first-page":"1","article-title":"Improving adversarial robustness requires revisiting misclassified examples","volume-title":"Proc. ICLR","author":"Wang"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2022.3207917"},{"key":"ref43","first-page":"876","article-title":"Averaging weights leads to wider optima and better generalization","volume-title":"Proc. 34th Conf. Uncertainty Artif. Intell.","volume":"2","author":"Izmailov"},{"key":"ref44","first-page":"2958","article-title":"Adversarial weight perturbation helps robust generalization","volume-title":"Proc. NIPS","author":"Wu"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00665"},{"key":"ref46","first-page":"478","article-title":"Metric learning for adversarial robustness","volume-title":"Proc. Annu. Conf. Neural Inf. Process. Syst. (NIPS)","author":"Mao"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.319"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.74"},{"key":"ref49","first-page":"1823","article-title":"On the connection between adversarial robustness and saliency map interpretability","volume-title":"Proc. 36th Int. Conf. Mach. Learn. (ICML)","author":"Etmann"},{"key":"ref50","first-page":"11821","article-title":"Towards efficient and effective adversarial training","volume-title":"Proc. NeurIPS","volume":"34","author":"Sriramanan"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1145\/3065386"},{"key":"ref52","first-page":"1","article-title":"Exploring memorization in adversarial training","volume-title":"Proc. ICLR","author":"Dong"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01304"},{"key":"ref54","article-title":"RobustBench: A standardized adversarial robustness benchmark","author":"Croce","year":"2020","journal-title":"arXiv:2010.09670"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-19772-7_33"},{"key":"ref56","first-page":"3353","article-title":"Adversarial training for free","volume-title":"Proc. NeurIPS","volume":"32","author":"Shafahi"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2023.3326398"},{"key":"ref58","first-page":"1","article-title":"Geometry-aware instance-reweighted adversarial training","volume-title":"Proc. ICLR","author":"Zhang"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.00789"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00483"},{"key":"ref61","first-page":"1","article-title":"Data augmentation alone can improve adversarial training","volume-title":"Proc. ICLR","author":"Li"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-20065-6_18"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00612"},{"key":"ref64","article-title":"Improved regularization of convolutional neural networks with cutout","author":"DeVries","year":"2017","journal-title":"arXiv:1708.04552"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00020"},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-024-02206-4"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/10206\/10810755\/11045541.pdf?arnumber=11045541","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,30]],"date-time":"2025-06-30T17:37:35Z","timestamp":1751305055000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11045541\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"references-count":66,"URL":"https:\/\/doi.org\/10.1109\/tifs.2025.3581021","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"value":"1556-6013","type":"print"},{"value":"1556-6021","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025]]}}}