{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,5,20]],"date-time":"2025-05-20T14:34:21Z","timestamp":1747751661921,"version":"3.37.3"},"reference-count":51,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100012166","name":"National Key Research and Development Plan of China","doi-asserted-by":"publisher","award":["2020AAA0103502"],"award-info":[{"award-number":["2020AAA0103502"]}],"id":[{"id":"10.13039\/501100012166","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62022009","61872021"],"award-info":[{"award-number":["62022009","61872021"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. on Image Process."],"published-print":{"date-parts":[[2021]]},"DOI":"10.1109\/tip.2021.3121150","type":"journal-article","created":{"date-parts":[[2021,10,26]],"date-time":"2021-10-26T20:45:58Z","timestamp":1635281158000},"page":"8955-8967","source":"Crossref","is-referenced-by-count":8,"title":["Progressive Diversified Augmentation for General Robustness of DNNs: A Unified Approach"],"prefix":"10.1109","volume":"30","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-7858-8789","authenticated-orcid":false,"given":"Hang","family":"Yu","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4224-1318","authenticated-orcid":false,"given":"Aishan","family":"Liu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Gengchao","family":"Li","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jichen","family":"Yang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1378-322X","authenticated-orcid":false,"given":"Chongzhi","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1145\/1553374.1553380"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2018.04.027"},{"key":"ref33","article-title":"Improving robustness without sacrificing accuracy with patch Gaussian augmentation","author":"lopes","year":"2019","journal-title":"arXiv 1906 02611"},{"key":"ref32","article-title":"Using learned optimizers to make models robust to input noise","author":"metz","year":"2019","journal-title":"arXiv 1906 03367"},{"key":"ref31","first-page":"227","article-title":"You only propagate once: Accelerating adversarial training via maximal principle","author":"zhang","year":"2019","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref30","first-page":"3358","article-title":"Adversarial training for free!","author":"shafahi","year":"2019","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref37","article-title":"Adversarially robust generalization just requires more unlabeled data","author":"zhai","year":"2019","journal-title":"arXiv 1906 00555"},{"key":"ref36","article-title":"Convergence and margin of adversarial training on separable data","author":"charles","year":"2019","journal-title":"arXiv 1905 09209"},{"key":"ref35","article-title":"Towards understanding adversarial examples systematically: Exploring data size, task and model factors","author":"sun","year":"2019","journal-title":"arXiv 1902 11019"},{"key":"ref34","first-page":"5014","article-title":"Adversarially robust generalization requires more data","author":"schmidt","year":"2018","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref28","first-page":"29","article-title":"Certifiable distributional robustness with principled adversarial training","volume":"1050","author":"sinha","year":"2017","journal-title":"Statistics"},{"key":"ref27","first-page":"13276","article-title":"A Fourier perspective on model robustness in computer vision","author":"yin","year":"2019","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref29","first-page":"1","article-title":"Regularizing deep networks using efficient layerwise adversarial training","author":"sankaranarayanan","year":"2018","journal-title":"Proc 32nd AAAI Conf Artif Intell"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2016.2577031"},{"key":"ref1","first-page":"1097","article-title":"ImageNet classification with deep convolutional neural networks","author":"krizhevsky","year":"2012","journal-title":"Proc Int Conf Neural Inf Process"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.485"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/ICCCN.2017.8038465"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00830"},{"key":"ref24","first-page":"1","article-title":"Towards deep learning models resistant to adversarial attacks","author":"madry","year":"2018","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref23","first-page":"1","article-title":"Adversarial machine learning at scale","author":"kurakin","year":"2017","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref26","first-page":"2280","article-title":"Adversarial examples are a natural consequence of test error in noise","author":"gilmer","year":"2019","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref25","first-page":"1178","article-title":"Adversarial vulnerability for any classifier","author":"fawzi","year":"2018","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1007\/s10994-011-5268-1"},{"key":"ref51","first-page":"11","article-title":"Robustness may be at odds with accuracy","volume":"1050","author":"tsipras","year":"2018","journal-title":"Statistics"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.33011028"},{"key":"ref11","first-page":"1","article-title":"Explaining and harnessing adversarial examples","author":"goodfellow","year":"2015","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref40","first-page":"12259","article-title":"Theoretical analysis of adversarial learning: A minimax approach","author":"tu","year":"2019","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref12","first-page":"274","article-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","author":"athalye","year":"2018","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2018.2861800"},{"key":"ref14","first-page":"1","article-title":"Mitigating adversarial effects through randomization","author":"xie","year":"2018","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref15","first-page":"1","article-title":"Stochastic activation pruning for robust adversarial defense","author":"dhillon","year":"2018","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref16","first-page":"1","article-title":"Thermometer encoding: One hot way to resist adversarial examples","author":"buckman","year":"2018","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref17","first-page":"1","article-title":"Countering adversarial images using input transformations","author":"guo","year":"2018","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref18","first-page":"1","article-title":"Pixeldefend: Leveraging generative models to understand and defend against adversarial examples","author":"song","year":"2018","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2018.2858821"},{"key":"ref4","first-page":"1","article-title":"Neural machine translation by jointly learning to align and translate","author":"bahdanau","year":"2015","journal-title":"Proc 3rd Int Conf Learn Represent (ICLR)"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1515\/9783110524116"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2012.2205597"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1145\/2684822.2685316"},{"key":"ref8","first-page":"1","article-title":"Benchmarking neural network robustness to common corruptions and perturbations","author":"hendrycks","year":"2019","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref49","first-page":"7472","article-title":"Theoretically principled trade-off between robustness and accuracy","author":"zhang","year":"2019","journal-title":"Proc ICML"},{"key":"ref7","first-page":"173","article-title":"Deep speech 2: End-to-end speech recognition in English and Mandarin","author":"amodei","year":"2016","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref9","first-page":"1","article-title":"Adversarial examples in the physical world","author":"kurakin","year":"2017","journal-title":"Proc Int Conf Learn Represent Workshop"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref45","article-title":"Very deep convolutional networks for large-scale image recognition","author":"simonyan","year":"2014","journal-title":"arXiv 1409 1556"},{"key":"ref48","first-page":"1","article-title":"Decision-based adversarial attacks: Reliable attacks against black-box machine learning models","author":"brendel","year":"2018","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"article-title":"Learning multiple layers of features from tiny images","year":"2009","author":"krizhevsky","key":"ref42"},{"journal-title":"Perturbation Analysis of Optimization Problems","year":"2013","author":"bonnans","key":"ref41"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"article-title":"Reading digits in natural images with unsupervised feature learning","year":"2011","author":"netzer","key":"ref43"}],"container-title":["IEEE Transactions on Image Processing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/83\/9263394\/09585649.pdf?arnumber=9585649","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,5,10]],"date-time":"2022-05-10T14:50:57Z","timestamp":1652194257000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9585649\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021]]},"references-count":51,"URL":"https:\/\/doi.org\/10.1109\/tip.2021.3121150","relation":{},"ISSN":["1057-7149","1941-0042"],"issn-type":[{"type":"print","value":"1057-7149"},{"type":"electronic","value":"1941-0042"}],"subject":[],"published":{"date-parts":[[2021]]}}}