{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,28]],"date-time":"2026-02-28T04:13:49Z","timestamp":1772252029070,"version":"3.50.1"},"reference-count":53,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"8","license":[{"start":{"date-parts":[[2024,8,1]],"date-time":"2024-08-01T00:00:00Z","timestamp":1722470400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Neural Netw. Learning Syst."],"published-print":{"date-parts":[[2024,8]]},"DOI":"10.1109\/tnnls.2023.3244172","type":"journal-article","created":{"date-parts":[[2023,2,22]],"date-time":"2023-02-22T18:31:48Z","timestamp":1677090708000},"page":"10817-10831","source":"Crossref","is-referenced-by-count":7,"title":["Relationship Between Nonsmoothness in Adversarial Training, Constraints of Attacks, and Flatness in the Input Space"],"prefix":"10.1109","volume":"35","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-4383-4454","authenticated-orcid":false,"given":"Sekitoshi","family":"Kanai","sequence":"first","affiliation":[{"name":"Nippon Telegraph and Telephone Corporation (NTT), Tokyo, Japan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Masanori","family":"Yamada","sequence":"additional","affiliation":[{"name":"Nippon Telegraph and Telephone Corporation (NTT), Tokyo, Japan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5102-2830","authenticated-orcid":false,"given":"Hiroshi","family":"Takahashi","sequence":"additional","affiliation":[{"name":"NTT Docomo, Tokyo, Japan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9527-1721","authenticated-orcid":false,"given":"Yuki","family":"Yamanaka","sequence":"additional","affiliation":[{"name":"Nippon Telegraph and Telephone Corporation (NTT), Tokyo, Japan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4279-9503","authenticated-orcid":false,"given":"Yasutoshi","family":"Ida","sequence":"additional","affiliation":[{"name":"Nippon Telegraph and Telephone Corporation (NTT), Tokyo, Japan"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2018.2876865"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2020.2979670"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2021.3084827"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2018.2790388"},{"key":"ref5","article-title":"Intriguing properties of neural networks","author":"Szegedy","year":"2013","journal-title":"arXiv:1312.6199"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2018.2886017"},{"key":"ref7","article-title":"Adversarial machine learning at scale","author":"Kurakin","year":"2016","journal-title":"arXiv:1611.01236"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.06083"},{"key":"ref9","first-page":"1310","article-title":"Certified adversarial robustness via randomized smoothing","volume-title":"Proc. ICML","author":"Cohen"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/tnnls.2021.3111892"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2021.3103528"},{"key":"ref12","first-page":"11821","article-title":"Towards efficient and effective adversarial training","volume-title":"Proc. NeurIPS","author":"Sriramanan"},{"key":"ref13","first-page":"1","article-title":"Improving adversarial robustness requires revisiting misclassified examples","volume-title":"Proc. ICLR","author":"Wang"},{"key":"ref14","first-page":"11190","article-title":"Unlabeled data improves adversarial robustness","volume-title":"Proc. NeurIPS","author":"Carmon"},{"key":"ref15","first-page":"8093","article-title":"Overfitting in adversarially robust deep learning","volume-title":"Proc. ICML","author":"Rice"},{"key":"ref16","first-page":"505","article-title":"On the generalization properties of adversarial training","volume-title":"Proc. ICML","volume":"130","author":"Xing"},{"key":"ref17","first-page":"21476","article-title":"On the loss landscape of adversarial training: Identifying challenges and how to overcome them","volume-title":"Proc. NeurIPS","author":"Liu"},{"key":"ref18","first-page":"2958","article-title":"Adversarial weight perturbation helps robust generalization","volume-title":"Proc. NeurIPS","author":"Wu"},{"key":"ref19","article-title":"Adversarial training makes weight loss landscape sharper in logistic regression","author":"Yamada","year":"2021","journal-title":"arXiv:2102.02950"},{"key":"ref20","first-page":"15823","article-title":"Regret bounds without Lipschitz continuity: Online learning with relative-Lipschitz losses","volume-title":"Proc. NeurIPS","volume":"33","author":"Zhou"},{"key":"ref21","first-page":"26523","article-title":"On the algorithmic stability of adversarial training","volume-title":"Proc. NeurIPS","author":"Xing"},{"key":"ref22","first-page":"13847","article-title":"Adversarial robustness through local linearization","volume-title":"Proc. NeurIPS","author":"Qin"},{"key":"ref23","first-page":"854","article-title":"Parseval networks: Improving robustness to adversarial examples","volume-title":"Proc. ICML","author":"Cisse"},{"key":"ref24","article-title":"Evaluating and understanding the robustness of adversarial Logit pairing","author":"Engstrom","year":"2018","journal-title":"arXiv:1807.10272"},{"key":"ref25","first-page":"1225","article-title":"Train faster, generalize better: Stability of stochastic gradient descent","volume-title":"Proc. ICML","author":"Hardt"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1137\/120880811"},{"key":"ref27","first-page":"4381","article-title":"Stability of stochastic gradient descent on nonsmooth convex losses","volume-title":"Proc. NeurIPS","volume":"33","author":"Bassily"},{"key":"ref28","first-page":"7472","article-title":"Theoretically principled trade-off between robustness and accuracy","volume-title":"Proc. ICML","volume":"97","author":"Zhang"},{"key":"ref29","first-page":"1","article-title":"Entropy-SGD: Biasing gradient descent into wide valleys","volume-title":"Proc. ICLR","author":"Chaudhari"},{"key":"ref30","first-page":"1","article-title":"Certifiable distributional robustness with principled adversarial training","volume-title":"Proc. ICLR","author":"Sinha"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1057\/palgrave.jors.2600425"},{"key":"ref32","first-page":"1","article-title":"Accelerated gradient methods for stochastic optimization and online learning","volume-title":"Proc. NeurIPS","author":"Hu"},{"issue":"1","key":"ref33","first-page":"71","article-title":"Stochastic gradient descent for non-smooth optimization: Convergence results and optimal averaging schemes","volume-title":"Proc. ICML","volume":"28","author":"Shamir"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1088\/1742-5468\/ab39d9"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1016\/j.neunet.2020.12.024"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.3389\/frai.2021.780843"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i9.16989"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1710.05941"},{"key":"ref39","volume-title":"SciPy: Open Source Scientific Tools for Python","author":"Jones","year":"2001"},{"key":"ref40","first-page":"1","article-title":"Why gradient clipping accelerates training: A theoretical justification for adaptivity","volume-title":"Proc. ICLR","author":"Zhang"},{"key":"ref41","first-page":"15511","article-title":"Improved analysis of clipping algorithms for non-convex optimization","volume-title":"Proc. NeurIPS","author":"Zhang"},{"key":"ref42","volume-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009"},{"key":"ref43","article-title":"Reading digits in natural images with unsupervised feature learning","volume-title":"Proc. NIPS Workshop Deep Learn. Unsupervised Feature Learn.","author":"Netzer"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.5244\/C.30.87"},{"key":"ref46","first-page":"2206","article-title":"Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks","volume-title":"Proc. ICML","author":"Croce"},{"key":"ref47","article-title":"Explaining and harnessing adversarial examples","author":"Goodfellow","year":"2014","journal-title":"arXiv:1412.6572"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref49","first-page":"5025","article-title":"Adversarial risk and the dangers of evaluating against weak attacks","volume-title":"Proc. ICML","volume":"80","author":"Uesato"},{"key":"ref50","article-title":"Robustness and accuracy could be reconcilable by (proper) definition","author":"Pang","year":"2022","journal-title":"arXiv:2202.10103"},{"key":"ref51","first-page":"4218","article-title":"Improving robustness using generated data","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"34","author":"Gowal"},{"key":"ref52","article-title":"Fixing data augmentation to improve adversarial robustness","author":"Rebuffi","year":"2021","journal-title":"arXiv:2103.01946"},{"key":"ref53","article-title":"Improving generalization performance by switching from Adam to SGD","author":"Keskar","year":"2017","journal-title":"arXiv:1712.07628"}],"container-title":["IEEE Transactions on Neural Networks and Learning Systems"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/5962385\/10623582\/10049380.pdf?arnumber=10049380","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,8,6]],"date-time":"2024-08-06T10:29:30Z","timestamp":1722940170000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10049380\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,8]]},"references-count":53,"journal-issue":{"issue":"8"},"URL":"https:\/\/doi.org\/10.1109\/tnnls.2023.3244172","relation":{},"ISSN":["2162-237X","2162-2388"],"issn-type":[{"value":"2162-237X","type":"print"},{"value":"2162-2388","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,8]]}}}