{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,3]],"date-time":"2026-06-03T15:38:39Z","timestamp":1780501119638,"version":"3.54.1"},"reference-count":67,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62072482"],"award-info":[{"award-number":["62072482"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. on Image Process."],"published-print":{"date-parts":[[2023]]},"DOI":"10.1109\/tip.2023.3290532","type":"journal-article","created":{"date-parts":[[2023,7,10]],"date-time":"2023-07-10T19:51:00Z","timestamp":1689018660000},"page":"3862-3872","source":"Crossref","is-referenced-by-count":21,"title":["Toward Intrinsic Adversarial Robustness Through Probabilistic Training"],"prefix":"10.1109","volume":"32","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-6232-9157","authenticated-orcid":false,"given":"Junhao","family":"Dong","sequence":"first","affiliation":[{"name":"School of Computer Science and Engineering, Sun Yat-sen University, Guangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Lingxiao","family":"Yang","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, Sun Yat-sen University, Guangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1007-8843","authenticated-orcid":false,"given":"Yuan","family":"Wang","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, Sun Yat-sen University, Guangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0310-4679","authenticated-orcid":false,"given":"Xiaohua","family":"Xie","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, Sun Yat-sen University, Guangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3883-2024","authenticated-orcid":false,"given":"Jianhuang","family":"Lai","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, Sun Yat-sen University, Guangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref13","first-page":"7472","article-title":"Theoretically principled trade-off between robustness and accuracy","author":"zhang","year":"2019","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref57","article-title":"Learning multiple layers of features from tiny images","author":"krizhevsky","year":"2009"},{"key":"ref12","first-page":"1","article-title":"Towards deep learning models resistant to adversarial attacks","author":"madry","year":"2018","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref56","first-page":"21","article-title":"Power comparisons of Shapiro-Wilk, Kolmogorov-Smirnov, Lilliefors and Anderson-Darling tests","volume":"2","author":"razali","year":"2011","journal-title":"Journal of Statistical Modeling and Analytics"},{"key":"ref15","first-page":"1","article-title":"Geometry-aware instance-reweighted adversarial training","author":"zhang","year":"2021","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref59","first-page":"1050","article-title":"Dropout as a Bayesian approximation: Representing model uncertainty in deep learning","author":"gal","year":"2016","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref14","first-page":"1","article-title":"Improving adversarial robustness requires revisiting misclassified examples","author":"wang","year":"2020","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref58","first-page":"1","article-title":"Auto-encoding variational Bayes","author":"kingma","year":"2014","journal-title":"Proc 2nd Int Conf Learn Represent"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.153"},{"key":"ref52","article-title":"Understanding and enhancing the transferability of adversarial examples","author":"wu","year":"2018","journal-title":"arXiv 1802 09707"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2021.3127849"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1093\/biomet\/52.3-4.591"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58558-7_39"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1109\/SPW50608.2020.00028"},{"key":"ref17","first-page":"1","article-title":"PixelDefend: Leveraging generative models to understand and defend against adversarial examples","author":"song","year":"2018","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref16","first-page":"1","article-title":"A unified Wasserstein distributional robustness framework for adversarial training","author":"bui","year":"2022","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref19","first-page":"1","article-title":"Explaining and harnessing adversarial examples","author":"goodfellow","year":"2015","journal-title":"Proc 3rd Int Conf Learn Represent (ICLR)"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00090"},{"key":"ref51","first-page":"5574","article-title":"What uncertainties do we need in Bayesian deep learning for computer vision?","volume":"30","author":"kendall","year":"2017","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00575"},{"key":"ref46","first-page":"1","article-title":"Adversarial robustness through the lens of causality","author":"zhang","year":"2022","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref45","first-page":"8270","article-title":"Adversarial distributional training for robust deep learning","volume":"33","author":"dong","year":"2020","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00064"},{"key":"ref47","article-title":"Auto-encoding variational Bayes","author":"kingma","year":"2013","journal-title":"arXiv 1312 6114"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2021.3053398"},{"key":"ref41","first-page":"11693","article-title":"CIFS: Improving adversarial robustness of CNNs via channel-wise importance-based feature selection","author":"yan","year":"2021","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref44","article-title":"Domain invariant adversarial learning","author":"levi","year":"2022","journal-title":"arXiv 2104 00322"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2022.3184255"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00700"},{"key":"ref8","first-page":"1","article-title":"Intriguing properties of neural networks","author":"szegedy","year":"2014","journal-title":"Proc 2nd Int Conf Learn Represent"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP.2018.8462105"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00790"},{"key":"ref4","article-title":"BERT: Pre-training of deep bidirectional transformers for language understanding","author":"devlin","year":"2018","journal-title":"arXiv 1810 04805"},{"key":"ref3","first-page":"234","article-title":"U-Net: Convolutional networks for biomedical image segmentation","author":"ronneberger","year":"2015","journal-title":"Proc Int Conf Med Image Comput Comput -Assist Intervent"},{"key":"ref6","article-title":"A fully convolutional neural network for speech enhancement","author":"park","year":"2016","journal-title":"arXiv 1609 07132"},{"key":"ref5","article-title":"Improving language understanding by generative pre-training","author":"radford","year":"2018"},{"key":"ref40","first-page":"3353","article-title":"Adversarial training for free!","volume":"32","author":"shafahi","year":"2019","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref35","first-page":"1","article-title":"Stochastic activation pruning for robust adversarial defense","author":"dhillon","year":"2018","journal-title":"Proc 6th Int Conf Learn Represent (ICLR)"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00103"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2021.3082317"},{"key":"ref36","first-page":"1","article-title":"Mitigating adversarial effects through randomization","author":"xie","year":"2018","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1145\/3474085.3475290"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1145\/3474085.3475542"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1145\/3394171.3413603"},{"key":"ref32","first-page":"7167","article-title":"A simple unified framework for detecting out-of-distribution samples and adversarial attacks","volume":"31","author":"lee","year":"2018","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref2","first-page":"1","article-title":"Faster R-CNN: Towards real-time object detection with region proposal networks","volume":"28","author":"ren","year":"2015","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01613"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i04.5816"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2018.00014"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2020.2975918"},{"key":"ref67","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58592-1_29"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-66823-5_14"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"ref64","first-page":"1","article-title":"Reading digits in natural images with unsupervised feature learning","author":"netzer","year":"2011"},{"key":"ref63","first-page":"1","article-title":"Exploring memorization in adversarial training","author":"dong","year":"2022","journal-title":"Proc 10th Int Conf Learn Represent"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00526"},{"key":"ref66","first-page":"8093","article-title":"Overfitting in adversarially robust deep learning","author":"rice","year":"2020","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref21","first-page":"1","article-title":"Nesterov accelerated gradient and scale invariance for adversarial attacks","author":"lin","year":"2020","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00284"},{"key":"ref27","first-page":"2206","article-title":"Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks","author":"croce","year":"2020","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref29","article-title":"Skip connections matter: On the transferability of adversarial examples generated with ResNets","author":"wu","year":"2020","journal-title":"arXiv 2002 05990"},{"key":"ref60","first-page":"1","article-title":"Deep variational information bottleneck","author":"alemi","year":"2017","journal-title":"Proc 5th Int Conf Learn Represent"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01304"},{"key":"ref61","first-page":"11821","article-title":"Towards efficient and effective adversarial training","volume":"34","author":"sriramanan","year":"2021","journal-title":"Proc Adv Neural Inf Process Syst"}],"container-title":["IEEE Transactions on Image Processing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/83\/9991910\/10177878.pdf?arnumber=10177878","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,8,7]],"date-time":"2023-08-07T18:36:09Z","timestamp":1691433369000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10177878\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023]]},"references-count":67,"URL":"https:\/\/doi.org\/10.1109\/tip.2023.3290532","relation":{},"ISSN":["1057-7149","1941-0042"],"issn-type":[{"value":"1057-7149","type":"print"},{"value":"1941-0042","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023]]}}}