{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,9]],"date-time":"2026-07-09T20:26:12Z","timestamp":1783628772708,"version":"3.55.0"},"reference-count":40,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"7","license":[{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U24A20333"],"award-info":[{"award-number":["U24A20333"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62472443"],"award-info":[{"award-number":["62472443"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62376287"],"award-info":[{"award-number":["62376287"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100012166","name":"National Key Research and Development Program of China","doi-asserted-by":"publisher","award":["2023ZD0508201"],"award-info":[{"award-number":["2023ZD0508201"]}],"id":[{"id":"10.13039\/501100012166","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100004735","name":"Hunan Provincial Natural Science Foundation","doi-asserted-by":"publisher","award":["2024JJ3032"],"award-info":[{"award-number":["2024JJ3032"]}],"id":[{"id":"10.13039\/501100004735","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100004735","name":"Hunan Provincial Natural Science Foundation","doi-asserted-by":"publisher","award":["2025JJ60421"],"award-info":[{"award-number":["2025JJ60421"]}],"id":[{"id":"10.13039\/501100004735","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Frontier Cross Project of Central South University","award":["2023QYJC008"],"award-info":[{"award-number":["2023QYJC008"]}]},{"name":"International Science and Technology Innovation Joint Base of Machine Vision and Medical Image Processing in Hunan Province","award":["2021CB1013"],"award-info":[{"award-number":["2021CB1013"]}]},{"name":"Humanity and Social Science Youth Foundation of Chinese Ministry of Education","award":["25YJCZH079"],"award-info":[{"award-number":["25YJCZH079"]}]},{"name":"Open Research Fund of Hunan Provincial Key Laboratory of Intelligent Processing of Big Data on Transportation","award":["B202405"],"award-info":[{"award-number":["B202405"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Neural Netw. Learning Syst."],"published-print":{"date-parts":[[2026,7]]},"DOI":"10.1109\/tnnls.2025.3648421","type":"journal-article","created":{"date-parts":[[2026,1,6]],"date-time":"2026-01-06T18:36:24Z","timestamp":1767724584000},"page":"3300-3310","source":"Crossref","is-referenced-by-count":0,"title":["Boosting Adversarial Training With Mitigating Hard Sample Interference"],"prefix":"10.1109","volume":"37","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-2974-1166","authenticated-orcid":false,"given":"Bin","family":"Hu","sequence":"first","affiliation":[{"name":"School of Computer Science and Technology, Changsha University of Science and Technology, Changsha, Hunan, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4143-6399","authenticated-orcid":false,"given":"Kehua","family":"Guo","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering and Furong Laboratory, Central South University, Changsha, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Tian","family":"Qiu","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering and Furong Laboratory, Central South University, Changsha, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7360-7928","authenticated-orcid":false,"given":"Shaojun","family":"Guo","sequence":"additional","affiliation":[{"name":"National Innovation of Defense Technology, Academy of Military Sciences PLA China, Fengtai, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","first-page":"1","article-title":"Explaining and harnessing adversarial examples","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Goodfellow"},{"key":"ref2","first-page":"1","article-title":"Intriguing properties of neural networks","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Szegedy"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/TVT.2021.3061065"},{"key":"ref4","first-page":"1","article-title":"Considerations for distribution shift robustness in health","volume-title":"Proc. Workshop Trustworthy Mach. Learn. Healthcare","author":"Blaas"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1145\/3332184"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-19772-7_34"},{"key":"ref7","first-page":"18080","article-title":"Bag of tricks for adversarial training","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Pang"},{"key":"ref8","article-title":"Why adversarial training of ReLU networks is difficult?","author":"Cheng","year":"2022","journal-title":"arXiv:2205.15130"},{"key":"ref9","first-page":"8909","article-title":"Improving adversarial robustness requires revisiting misclassified examples","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Wang"},{"key":"ref10","first-page":"17258","article-title":"Robustness and accuracy could be reconcilable by (proper) definition","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Pang"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref12","first-page":"8093","article-title":"Overfitting in adversarially robust deep learning","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Rice"},{"key":"ref13","first-page":"7472","article-title":"Theoretically principled trade-off between robustness and accuracy","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Zhang"},{"key":"ref14","first-page":"2958","article-title":"Adversarial weight perturbation helps robust generalization","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Wu"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01543"},{"key":"ref16","first-page":"11278","article-title":"Attacks which do not kill training make adversarial learning stronger","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Zhang"},{"key":"ref17","article-title":"Adversarial logit pairing","author":"Kannan","year":"2018","journal-title":"arXiv:1803.06373"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01304"},{"key":"ref19","first-page":"6586","article-title":"On the convergence and robustness of adversarial training","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Wang"},{"key":"ref20","first-page":"11190","article-title":"Unlabeled data improves adversarial robustness","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Carmon"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.06083"},{"key":"ref23","first-page":"9057","article-title":"Robust local features for improving the generalization of adversarial training","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Song"},{"key":"ref24","article-title":"Uncovering the limits of adversarial training against norm-bounded adversarial examples","author":"Gowal","year":"2020","journal-title":"arXiv:2010.03593"},{"key":"ref25","first-page":"4218","article-title":"Improving robustness using generated data","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"34","author":"Gowal"},{"key":"ref26","article-title":"Fixing data augmentation to improve adversarial robustness","author":"Rebuffi","year":"2021","journal-title":"arXiv:2103.01946"},{"key":"ref27","article-title":"On the impact of hard adversarial instances on overfitting in adversarial training","author":"Liu","year":"2021","journal-title":"arXiv:2112.07324"},{"key":"ref28","first-page":"7910","article-title":"Exploring memorization in adversarial training","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Dong"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/TMM.2022.3168146"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3359820"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2023.3306933"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00406"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4615-5563-6"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2025.3533925"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2025.3580116"},{"key":"ref36","article-title":"RobustBench: A standardized adversarial robustness benchmark","author":"Croce","year":"2020","journal-title":"arXiv:2010.09670"},{"key":"ref37","first-page":"2206","article-title":"Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Croce"},{"key":"ref38","first-page":"2280","article-title":"Adversarial examples are a natural consequence of test error in noise","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Ford"},{"key":"ref39","article-title":"Benchmarking neural network robustness to common corruptions and surface variations","author":"Hendrycks","year":"2018","journal-title":"arXiv:1807.01697"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2023.3263637"}],"container-title":["IEEE Transactions on Neural Networks and Learning Systems"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/5962385\/11600559\/11329528.pdf?arnumber=11329528","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,9]],"date-time":"2026-07-09T19:44:26Z","timestamp":1783626266000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11329528\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,7]]},"references-count":40,"journal-issue":{"issue":"7"},"URL":"https:\/\/doi.org\/10.1109\/tnnls.2025.3648421","relation":{},"ISSN":["2162-237X","2162-2388"],"issn-type":[{"value":"2162-237X","type":"print"},{"value":"2162-2388","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,7]]}}}