{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,28]],"date-time":"2026-04-28T05:40:37Z","timestamp":1777354837844,"version":"3.51.4"},"reference-count":63,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"CIPS-SMP-Zhipu Large Model Fund"},{"name":"Start-up of the City University of Hong Kong","award":["9610680"],"award-info":[{"award-number":["9610680"]}]},{"name":"Young Scientist Fund of NSFC","award":["62406265"],"award-info":[{"award-number":["62406265"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2026]]},"DOI":"10.1109\/tifs.2026.3679189","type":"journal-article","created":{"date-parts":[[2026,3,30]],"date-time":"2026-03-30T20:05:29Z","timestamp":1774901129000},"page":"4190-4204","source":"Crossref","is-referenced-by-count":0,"title":["Rethinking Frequency Modeling: Tail-Aware Dynamic Adversarial Training for Long-Tailed Robustness"],"prefix":"10.1109","volume":"21","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-1681-8128","authenticated-orcid":false,"given":"Chengze","family":"Jiang","sequence":"first","affiliation":[{"name":"School of Cyber Science and Engineering, Southeast University, Nanjing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0003-1717-818X","authenticated-orcid":false,"given":"Minjing","family":"Dong","sequence":"additional","affiliation":[{"name":"Department of Computer Science, City University of Hong Kong, Pokfulam, Hong Kong"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-0454-613X","authenticated-orcid":false,"given":"Zhuangzhuang","family":"Wang","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Southeast University, Nanjing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9450-1759","authenticated-orcid":false,"given":"Jie","family":"Gui","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Southeast University, Nanjing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6894-1331","authenticated-orcid":false,"given":"Ju","family":"Jia","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Southeast University, Nanjing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6887-130X","authenticated-orcid":false,"given":"Yuan Yan","family":"Tang","sequence":"additional","affiliation":[{"name":"Department of Computer and Information Science, University of Macau, Macau, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4828-8248","authenticated-orcid":false,"given":"James Tin-Yau","family":"Kwok","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Engineering, The Hong Kong University of Science and Technology, Hong Kong, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2024.3415112"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2022.3152247"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3390609"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2025.3526067"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2025.3573237"},{"key":"ref6","first-page":"2206","article-title":"Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Croce"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2025.3542964"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.02304"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.06083"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v38i6.28330"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3420128"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3474973"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.02330"},{"key":"ref14","first-page":"7472","article-title":"Theoretically principled trade-off between robustness and accuracy","volume-title":"Proc. 36th Int. Conf. Mach. Learn. (ICML)","volume":"97","author":"Zhang"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.52202\/079017-1158"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01304"},{"key":"ref17","first-page":"8909","article-title":"Improving adversarial robustness requires revisiting misclassified examples","volume-title":"Proc. ICLR","author":"Wang"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.00792"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2023.3268118"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00855"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1016\/j.neunet.2024.106932"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.02312"},{"key":"ref23","first-page":"1","article-title":"Long-tailed adversarial training with self-distillation","volume-title":"Proc. ICLR","author":"Cho"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52734.2025.01442"},{"key":"ref25","first-page":"59024","article-title":"On the duality between sharpness-aware minimization and adversarial training","volume-title":"Proc. ICML","author":"Zhang"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2025.3533925"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3359820"},{"key":"ref28","first-page":"2958","article-title":"Adversarial weight perturbation helps robust generalization","volume-title":"Proc. NeurIPS","author":"Wu"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.52202\/075280-0694"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2025.3554041"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2025.3587598"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.02336"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/TCSVT.2023.3337538"},{"issue":"14","key":"ref34","first-page":"15787","article-title":"EAT: Towards long-tailed out-of-distribution detection","volume-title":"Proc. AAAI","volume":"38","author":"Tong"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1007\/s10462-024-10759-6"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1007\/11538059_91"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00949"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00974"},{"key":"ref39","first-page":"7032","article-title":"Learning to model the tail","volume-title":"Proc. NeurIPS","volume":"30","author":"Wang"},{"key":"ref40","first-page":"4175","article-title":"Balanced meta-softmax for long-tailed visual recognition","volume-title":"Proc. NeurIPS","author":"Ren"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.00341"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.01518"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v38i2.27902"},{"key":"ref44","article-title":"Alleviating the effect of data imbalance on adversarial training","author":"Li","year":"2023","journal-title":"arXiv:2307.10205"},{"key":"ref45","first-page":"27037","article-title":"Rethinking the flat minima searching in federated learning","volume-title":"Proc. ICML","author":"Lee"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.52202\/075280-2119"},{"key":"ref47","article-title":"How learning dynamics drive adversarially robust generalization?","author":"Xu","year":"2024","journal-title":"arXiv:2410.07719"},{"key":"ref48","first-page":"17258","article-title":"Robustness and accuracy could be reconcilable by (proper) definition","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Pang"},{"key":"ref49","first-page":"20297","article-title":"Guided adversarial attack for evaluating and enhancing adversarial defenses","volume-title":"Proc. NeurIPS","volume":"33","author":"Sriramanan"},{"key":"ref50","first-page":"2874","article-title":"On large-batch training for deep learning: Generalization gap and sharp minima","volume-title":"Proc. ICLR","author":"Keskar"},{"key":"ref51","first-page":"5652","article-title":"Self-ensemble adversarial training for improved robustness","volume-title":"Proc. ICLR","author":"Wang"},{"key":"ref52","first-page":"7229","article-title":"Robust overfitting may be mitigated by properly learned smoothening","volume-title":"Proc. ICLR","author":"Chen"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2024.3381180"},{"key":"ref54","first-page":"6241","article-title":"Spectrally-normalized margin bounds for neural networks","volume-title":"Proc. NeurIPS","author":"Bartlett"},{"key":"ref55","first-page":"1172","article-title":"Geometry-aware instance-reweighted adversarial training","volume-title":"Proc. ICLR","author":"Zhang"},{"key":"ref56","article-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009"},{"key":"ref57","volume-title":"Tiny Imagenet Visual Recognition Challenge","year":"2015"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-46493-0_38"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3377004"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1016\/j.neunet.2024.106224"},{"key":"ref62","first-page":"876","article-title":"Averaging weights leads to wider optima and better generalization","volume-title":"Proc. 34th Conf. Uncertainty Artif. Intell.","volume":"2","author":"Izmailov"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2024.3371008"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/10206\/11313711\/11458004.pdf?arnumber=11458004","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,28]],"date-time":"2026-04-28T04:49:44Z","timestamp":1777351784000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11458004\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"references-count":63,"URL":"https:\/\/doi.org\/10.1109\/tifs.2026.3679189","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"value":"1556-6013","type":"print"},{"value":"1556-6021","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]}}}