{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,7]],"date-time":"2026-05-07T15:45:11Z","timestamp":1778168711966,"version":"3.51.4"},"reference-count":100,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"2","license":[{"start":{"date-parts":[[2023,2,1]],"date-time":"2023-02-01T00:00:00Z","timestamp":1675209600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2023,2,1]],"date-time":"2023-02-01T00:00:00Z","timestamp":1675209600000},"content-version":"am","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2023,2,1]],"date-time":"2023-02-01T00:00:00Z","timestamp":1675209600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2023,2,1]],"date-time":"2023-02-01T00:00:00Z","timestamp":1675209600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100008982","name":"National Science Foundation","doi-asserted-by":"publisher","award":["1149783"],"award-info":[{"award-number":["1149783"]}],"id":[{"id":"10.13039\/501100008982","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61673234"],"award-info":[{"award-number":["61673234"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U20B2062"],"award-info":[{"award-number":["U20B2062"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Beijing Science and Technology Planning","award":["Z191100007419001"],"award-info":[{"award-number":["Z191100007419001"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Pattern Anal. Mach. Intell."],"published-print":{"date-parts":[[2023,2,1]]},"DOI":"10.1109\/tpami.2022.3166879","type":"journal-article","created":{"date-parts":[[2022,4,12]],"date-time":"2022-04-12T19:37:58Z","timestamp":1649792278000},"page":"2430-2444","source":"Crossref","is-referenced-by-count":12,"title":["Shaping Deep Feature Space Towards Gaussian Mixture for Visual Classification"],"prefix":"10.1109","volume":"45","author":[{"given":"Weitao","family":"Wan","sequence":"first","affiliation":[{"name":"Department of Electronic Engineering, Tsinghua University, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Cheng","family":"Yu","sequence":"additional","affiliation":[{"name":"Department of Electronic Engineering, Tsinghua University, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2040-7938","authenticated-orcid":false,"given":"Jiansheng","family":"Chen","sequence":"additional","affiliation":[{"name":"School of Computer and Communication Engineering, University of Science and Technology Beijing, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tong","family":"Wu","sequence":"additional","affiliation":[{"name":"Department of Electronic Engineering, Tsinghua University, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4679-7548","authenticated-orcid":false,"given":"Yuanyi","family":"Zhong","sequence":"additional","affiliation":[{"name":"Department of Computer Science, University of Illinois Urbana-Champaign, Champaign, IL, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4848-2304","authenticated-orcid":false,"given":"Ming-Hsuan","family":"Yang","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Engineering, University of California, Merced, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1201\/9781351251389-8"},{"key":"ref2","first-page":"1106","article-title":"ImageNet classification with deep convolutional neural networks","volume-title":"Proc. Annu. Conf. Neural Informat. Process. Syst.","author":"Krizhevsky"},{"key":"ref3","first-page":"448","article-title":"Batch normalization: Accelerating deep network training by reducing internal covariate shift","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Ioffe"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298682"},{"key":"ref6","first-page":"1988","article-title":"Deep learning face representation by joint identification-verification","volume-title":"Proc. Annu. Conf. Neural Informat. Process. Syst.","author":"Sun"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/TASL.2011.2134090"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2012.2205597"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.308"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.5244\/C.30.87"},{"key":"ref11","article-title":"FractalNet: Ultra-deep neural networks without residuals","author":"Larsson","year":"2016"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.243"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-46478-7_31"},{"key":"ref14","first-page":"507","article-title":"Large-margin softmax loss for convolutional neural networks","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Liu"},{"key":"ref15","article-title":"Large margin in softmax cross-entropy loss","volume-title":"Proc. Brit. Mach. Vis. Conf.","author":"Kobayashi"},{"key":"ref16","first-page":"3953","article-title":"Deep hyperspherical learning","volume-title":"Proc. Annu. Conf. Neural Informat. Process. Syst.","author":"Liu"},{"key":"ref17","first-page":"6225","article-title":"Learning towards minimum hyperspherical energy","volume-title":"Proc. Annu. Conf. Neural Informat. Process. Syst.","author":"Liu"},{"key":"ref18","first-page":"1487","article-title":"Hyperspherical prototype networks","volume-title":"Proc. Annu. Conf. Neural Informat. Process. Syst.","author":"Mettes"},{"key":"ref19","first-page":"9929","article-title":"Understanding contrastive representation learning through alignment and uniformity on the hypersphere","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Wang"},{"key":"ref20","first-page":"4016","article-title":"Max-mahalanobis linear discriminant analysis networks","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Pang"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1007\/978-0-387-45528-0"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-10590-1_4"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.5555\/3327345.3327369"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00950"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298682"},{"key":"ref26","first-page":"1106","article-title":"ImageNet classification with deep convolutional neural networks","volume-title":"Proc. Annu. Conf. Neural Informat. Process. Syst.","author":"Krizhevsky"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/FG.2018.00020"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00655"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.713"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00552"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00482"},{"key":"ref32","article-title":"Explaining and harnessing adversarial examples","author":"Goodfellow","year":"2014"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.06083"},{"key":"ref34","article-title":"Intriguing properties of neural networks","author":"Szegedy","year":"2013"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref36","first-page":"1633","article-title":"On adaptive attacks to adversarial example defenses","volume-title":"Proc. Annu. Conf. Neural Informat. Process. Syst.","author":"Tramer"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00284"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00444"},{"key":"ref40","article-title":"Delving into transferable adversarial examples and black-box attacks","author":"Liu","year":"2016"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i07.6810"},{"key":"ref42","first-page":"12288","article-title":"Learning black-box attackers with transferable priors and query feedback","volume-title":"Proc. Annu. Conf. Neural Informat. Process. Syst.","author":"Yang"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01166"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00506"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00514"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.41"},{"key":"ref47","article-title":"Defense-GAN: Protecting classifiers against adversarial attacks using generative models","author":"Samangouei","year":"2018"},{"key":"ref48","article-title":"Pixeldefend: Leveraging generative models to understand and defend against adversarial examples","author":"Song","year":"2017"},{"key":"ref49","article-title":"Mitigating adversarial effects through randomization","author":"Xie","year":"2017"},{"key":"ref50","article-title":"Countering adversarial images using input transformations","author":"Guo","year":"2017"},{"key":"ref51","first-page":"274","article-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Athalye"},{"key":"ref52","article-title":"Adversarial machine learning at scale","author":"Kurakin","year":"2016"},{"key":"ref53","first-page":"7472","article-title":"Theoretically principled trade-off between robustness and accuracy","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Zhang"},{"key":"ref54","article-title":"Improving adversarial robustness requires revisiting misclassified examples","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Wang"},{"key":"ref55","article-title":"Instance adaptive adversarial training: Improved accuracy tradeoffs in neural nets","author":"Balaji","year":"2019"},{"key":"ref56","first-page":"478","article-title":"Metric learning for adversarial robustness","volume-title":"Proc. Adv. Neural Informat. Process. Syst.","author":"Mao"},{"key":"ref57","article-title":"MMA training: Direct input space margin maximization through adversarial training","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Ding"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1109\/ICIP42928.2021.9506383"},{"key":"ref59","first-page":"9155","article-title":"Confidence-calibrated adversarial training: Towards robust models generalizing beyond the attack used during training","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Stutz"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00044"},{"key":"ref61","article-title":"Towards stable and efficient training of verifiably robust neural networks","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Zhang"},{"key":"ref62","first-page":"1310","article-title":"Certified adversarial robustness via randomized smoothing","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Cohen"},{"key":"ref63","first-page":"11292","article-title":"Provably robust deep learning via adversarially trained smoothed classifiers","volume-title":"Proc. Annu. Conf. Neural Informat. Process. Syst.","author":"Salman"},{"key":"ref64","article-title":"Detecting adversarial samples using density ratio estimates","author":"Gondara","year":"2017"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.1109\/ITA50056.2020.9244964"},{"key":"ref66","article-title":"Characterizing adversarial subspaces using local intrinsic dimensionality","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Ma"},{"key":"ref67","article-title":"Detecting adversarial samples from artifacts","author":"Feinman","year":"2017"},{"key":"ref68","first-page":"7924","article-title":"Robust detection of adversarial attacks by modeling the intrinsic properties of deep neural networks","volume-title":"Proc. Annu. Conf. Neural Informat. Process. Syst.","author":"Zheng"},{"key":"ref69","article-title":"On detecting adversarial perturbations","author":"Metzen","year":"2017"},{"key":"ref70","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.56"},{"key":"ref71","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-020-01310-5"},{"key":"ref72","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140444"},{"key":"ref73","article-title":"Playing it safe: Adversarial robustness with an abstain option","author":"Laidlaw","year":"2019"},{"key":"ref74","article-title":"Evaluation methodology for attacks against confidence thresholding models","author":"Goodfellow","year":"2018"},{"key":"ref75","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP.2012.6289001"},{"key":"ref76","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v30i1.10243"},{"key":"ref77","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"key":"ref78","article-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009"},{"key":"ref79","first-page":"1139","article-title":"On the importance of initialization and momentum in deep learning","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Sutskever"},{"key":"ref80","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2015.123"},{"key":"ref81","article-title":"Very deep convolutional networks for large-scale image recognition","author":"Simonyan","year":"2014"},{"key":"ref82","article-title":"Batch normalization: Accelerating deep network training by reducing internal covariate shift","author":"Ioffe","year":"2015"},{"key":"ref83","article-title":"Network in network","author":"Lin","year":"2013"},{"key":"ref84","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref85","article-title":"Improving neural networks by preventing co-adaptation of feature detectors","author":"Hinton","year":"2012"},{"key":"ref86","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref87","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.634"},{"key":"ref88","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00745"},{"key":"ref89","article-title":"Labeled faces in the wild: A database for studying face recognition in unconstrained environments","author":"Huang","year":"2007"},{"key":"ref90","doi-asserted-by":"publisher","DOI":"10.1109\/WACV.2016.7477558"},{"key":"ref91","article-title":"Learning face representation from scratch","author":"Yi","year":"2014"},{"key":"ref92","doi-asserted-by":"publisher","DOI":"10.1109\/LSP.2016.2603342"},{"key":"ref93","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01252-6_48"},{"key":"ref94","article-title":"Multicolumn networks for face recognition","author":"Xie","year":"2018"},{"key":"ref95","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW.2017.87"},{"key":"ref96","doi-asserted-by":"publisher","DOI":"10.1109\/ICB2018.2018.00033"},{"key":"ref97","article-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009"},{"key":"ref98","article-title":"Adam: A method for stochastic optimization","author":"Kingma","year":"2014"},{"key":"ref99","article-title":"Characterizing adversarial subspaces using local intrinsic dimensionality","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Ma"},{"key":"ref100","first-page":"6640","article-title":"Adversarial robustness against the union of multiple perturbation models","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Maini"}],"container-title":["IEEE Transactions on Pattern Analysis and Machine Intelligence"],"original-title":[],"link":[{"URL":"https:\/\/ieeexplore.ieee.org\/ielam\/34\/10008914\/9756044-aam.pdf","content-type":"application\/pdf","content-version":"am","intended-application":"syndication"},{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/34\/10008914\/09756044.pdf?arnumber=9756044","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,1,22]],"date-time":"2024-01-22T21:15:50Z","timestamp":1705958150000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9756044\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,2,1]]},"references-count":100,"journal-issue":{"issue":"2"},"URL":"https:\/\/doi.org\/10.1109\/tpami.2022.3166879","relation":{},"ISSN":["0162-8828","2160-9292","1939-3539"],"issn-type":[{"value":"0162-8828","type":"print"},{"value":"2160-9292","type":"electronic"},{"value":"1939-3539","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,2,1]]}}}