{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,2]],"date-time":"2025-10-02T00:30:58Z","timestamp":1759365058018,"version":"build-2065373602"},"reference-count":76,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62133011"],"award-info":[{"award-number":["62133011"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Shanghai Pujiang Program","award":["23PJ1412100"],"award-info":[{"award-number":["23PJ1412100"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2025]]},"DOI":"10.1109\/tifs.2025.3611108","type":"journal-article","created":{"date-parts":[[2025,9,17]],"date-time":"2025-09-17T17:30:20Z","timestamp":1758130220000},"page":"9979-9992","source":"Crossref","is-referenced-by-count":0,"title":["Exploring Causal Information Bottleneck for Adversarial Defense"],"prefix":"10.1109","volume":"20","author":[{"ORCID":"https:\/\/orcid.org\/0009-0001-7706-7268","authenticated-orcid":false,"given":"Jun","family":"Yan","sequence":"first","affiliation":[{"name":"College of Electronic and Information Engineering, Tongji University, Shanghai, China"}]},{"given":"Huan","family":"Hua","sequence":"additional","affiliation":[{"name":"Tongji University, Shanghai, China"}]},{"given":"Weiquan","family":"Huang","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, Tongji University, Shanghai, China"}]},{"given":"Xi","family":"Fang","sequence":"additional","affiliation":[{"name":"DP Technology Company Ltd., Shanghai, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6659-3433","authenticated-orcid":false,"given":"Wancheng","family":"Ge","sequence":"additional","affiliation":[{"name":"College of Electronic and Information Engineering, Tongji University, Shanghai, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4455-7145","authenticated-orcid":false,"given":"Jiancheng","family":"Yang","sequence":"additional","affiliation":[{"name":"ELLIS Institute Finland, Espoo, Finland"}]},{"given":"Yongwei","family":"Wang","sequence":"additional","affiliation":[{"name":"CMIC and SIAS, Zhejiang University, Hangzhou, China"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/TSMC.1973.4309314"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.91"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.3115\/112405.112427"},{"key":"ref4","article-title":"BERT: Pre-training of deep bidirectional transformers for language understanding","author":"Devlin","year":"2018","journal-title":"arXiv:1810.04805"},{"key":"ref5","first-page":"1","article-title":"Intriguing properties of neural networks","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Szegedy"},{"key":"ref6","first-page":"1","article-title":"Explaining and harnessing adversarial examples","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Goodfellow"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.06083"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1007\/s11633-019-1211-x"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00175"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978392"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58601-0_24"},{"key":"ref12","first-page":"1624","article-title":"Robustness of classifiers: From adversarial to random noise","volume-title":"Proc. 29th Adv. Neural Inf. Process. Syst. Annu. Conf. Neural Inf. Process. Syst.","volume":"29","author":"Fawzi"},{"key":"ref13","article-title":"The information bottleneck method","author":"Tishby","year":"2000","journal-title":"arXiv:physics\/0004057"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2022.3183095"},{"key":"ref15","article-title":"Opening the black box of deep neural networks via information","author":"Shwartz-Ziv","year":"2017","journal-title":"arXiv:1703.00810"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/ITW.2015.7133169"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2017.2784440"},{"key":"ref18","first-page":"1","article-title":"Deep variational information bottleneck","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Alemi"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.3390\/e22090999"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i10.17120"},{"key":"ref21","article-title":"Distilling robust and non-robust features in adversarial examples by information bottleneck","author":"Kim","year":"2022","journal-title":"arXiv:2204.02735"},{"key":"ref22","article-title":"Information bottleneck through variational glasses","author":"Voloshynovskiy","year":"2019","journal-title":"arXiv:1912.00830"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.3390\/e22101081"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1038\/368542a0"},{"key":"ref25","article-title":"Learning independent causal mechanisms","author":"Parascandolo","year":"2017","journal-title":"arXiv:1712.00961"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1017\/CBO9780511803161"},{"key":"ref27","article-title":"Adversarial visual robustness by causal intervention","author":"Tang","year":"2021","journal-title":"arXiv:2106.09534"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"key":"ref30","article-title":"Fashion-MNIST: A novel image dataset for benchmarking machine learning algorithms","author":"Xiao","year":"2017","journal-title":"arXiv:1708.07747"},{"volume-title":"A Learning Multiple Layers of Features from Tiny Images","year":"2009","author":"Krizhevsky","key":"ref31"},{"key":"ref32","article-title":"A downsampled variant of ImageNet as an alternative to the CIFAR datasets","author":"Chrabaszcz","year":"2017","journal-title":"arXiv:1707.08819"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2807385"},{"key":"ref34","first-page":"2","article-title":"Adversarial training methods for semi-supervised text classification","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Miyato"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.485"},{"article-title":"Diffusion models for adversarial purification","volume-title":"Proc. Int. Conf. Mach. Learn. (ICML)","author":"Nie","key":"ref36"},{"key":"ref37","first-page":"1","article-title":"Characterizing adversarial subspaces using local intrinsic dimensionality","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Ma"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134057"},{"key":"ref39","first-page":"2","article-title":"Ensemble adversarial training: Attacks and defenses","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Tram\u00e8r"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.1503.02531"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2023.3286772"},{"key":"ref42","first-page":"2","article-title":"On adaptive attacks to adversarial example defenses","volume-title":"Proc. Adv. Neural Inf. Process. Syst. Annu. Conf. Neural Inf. Process. Syst.","author":"Tram\u00e8r"},{"key":"ref43","first-page":"11838","article-title":"Theoretical evidence for adversarial robustness through randomization","volume-title":"Proc. 32nd Adv. Neural Inf. Process. Syst. Annu. Conf. Neural Inf. Process. Syst.","author":"Pinot"},{"key":"ref44","first-page":"1310","article-title":"Certified adversarial robustness via randomized smoothing","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Cohen"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.153"},{"key":"ref46","first-page":"3","article-title":"Auto-encoding variational Bayes","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Kingma"},{"key":"ref47","article-title":"A closer look at the adversarial robustness of information bottleneck models","author":"Korshunova","year":"2021","journal-title":"arXiv:2107.05712"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i11.17163"},{"key":"ref49","first-page":"3","article-title":"A causal view on robustness of neural networks","volume-title":"Proc. Adv. Neural Inf. Process. Syst. Annu. Conf. Neural Inf. Process. Syst.","author":"Zhang"},{"volume-title":"Causal Inference in Statistics: A Primer","year":"2016","author":"Pearl","key":"ref50"},{"key":"ref51","article-title":"Counterfactual fairness","author":"Kusner","year":"2017","journal-title":"arXiv:1703.06856"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1109\/JPROC.2021.3058954"},{"key":"ref53","article-title":"CausalAdv: Adversarial robustness through the lens of causality","author":"Zhang","year":"2021","journal-title":"arXiv:2106.06196"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1111\/rssb.12167"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1109\/tkde.2022.3169333"},{"volume-title":"Elements of Causal Inference: Foundations and Learning Algorithms","year":"2017","author":"Peters","key":"ref56"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1145\/3065386"},{"key":"ref58","first-page":"2206","article-title":"Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Croce"},{"key":"ref59","first-page":"6","article-title":"Mixup: Beyond empirical risk minimization","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Zhang"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58592-1_29"},{"key":"ref62","first-page":"2196","article-title":"Minimally distorted adversarial examples with a fast adaptive boundary attack","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Croce"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.5244\/C.30.87"},{"key":"ref64","first-page":"3353","article-title":"Adversarial training for free","volume-title":"Proc. 29th Adv. Neural Inf. Process. Syst. Annu. Conf. Neural Inf. Process. Syst.","volume":"32","author":"Shafahi"},{"key":"ref65","first-page":"227","article-title":"You only propagate once: Accelerating adversarial training via maximal principle","volume-title":"Proc. 32nd Adv. Neural Inf. Process. Syst. Annu. Conf. Neural Inf. Process. Syst.","volume":"32","author":"Zhang"},{"key":"ref66","first-page":"10","article-title":"Improving adversarial robustness via information bottleneck distillation","volume-title":"Proc. Adv. Neural Inf. Process. Syst. Annu. Conf. Neural Inf. Process. Syst.","author":"Kuang"},{"key":"ref67","first-page":"7472","article-title":"Theoretically principled trade-off between robustness and accuracy","volume-title":"Proc. 36th Int. Conf. Mach. Learn. (ICML)","volume":"97","author":"Zhang"},{"article-title":"An image is worth 16\u00d716 words: Transformers for image recognition at scale","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Dosovitskiy","key":"ref68"},{"key":"ref69","article-title":"Hyper adversarial tuning for boosting adversarial robustness of pretrained large vision models","author":"Lv","year":"2024","journal-title":"arXiv:2410.05951"},{"key":"ref70","first-page":"11","article-title":"Improving adversarial robustness requires revisiting misclassified examples","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Wang"},{"key":"ref71","first-page":"74461","article-title":"Decoupled Kullback\u2013Leibler divergence loss","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Cui"},{"key":"ref72","article-title":"On evaluating adversarial robustness","author":"Carlini","year":"2019","journal-title":"arXiv:1902.06705"},{"key":"ref73","first-page":"11","article-title":"Countering adversarial images using input transformations","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Guo"},{"key":"ref74","first-page":"125","article-title":"Adversarial examples are not bugs, they are features","volume-title":"Proc. Annu. Conf. Neural Inf. Process. Syst. (NeurIPS)","author":"Ilyas"},{"key":"ref75","first-page":"12","article-title":"A Fourier perspective on model robustness in computer vision","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Yin"},{"key":"ref76","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.1811.12231"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/10206\/10810755\/11168967.pdf?arnumber=11168967","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,1]],"date-time":"2025-10-01T05:13:59Z","timestamp":1759295639000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11168967\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"references-count":76,"URL":"https:\/\/doi.org\/10.1109\/tifs.2025.3611108","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"type":"print","value":"1556-6013"},{"type":"electronic","value":"1556-6021"}],"subject":[],"published":{"date-parts":[[2025]]}}}