{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T17:14:01Z","timestamp":1777655641228,"version":"3.51.4"},"reference-count":35,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"2","license":[{"start":{"date-parts":[[2023,2,1]],"date-time":"2023-02-01T00:00:00Z","timestamp":1675209600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2023,2,1]],"date-time":"2023-02-01T00:00:00Z","timestamp":1675209600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2023,2,1]],"date-time":"2023-02-01T00:00:00Z","timestamp":1675209600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"KIAS Individual","award":["AP083601"],"award-info":[{"award-number":["AP083601"]}]},{"DOI":"10.13039\/501100003725","name":"National Research Foundation of Korea","doi-asserted-by":"publisher","award":["NRF-2019R1A2C2002358"],"award-info":[{"award-number":["NRF-2019R1A2C2002358"]}],"id":[{"id":"10.13039\/501100003725","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Pattern Anal. Mach. Intell."],"published-print":{"date-parts":[[2023,2,1]]},"DOI":"10.1109\/tpami.2022.3169217","type":"journal-article","created":{"date-parts":[[2022,4,21]],"date-time":"2022-04-21T19:38:15Z","timestamp":1650569895000},"page":"2645-2651","source":"Crossref","is-referenced-by-count":45,"title":["GradDiv: Adversarial Robustness of Randomized Neural Networks via Gradient Diversity Regularization"],"prefix":"10.1109","volume":"45","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-6097-0565","authenticated-orcid":false,"given":"Sungyoon","family":"Lee","sequence":"first","affiliation":[{"name":"Center for Artificial Intelligence and Natural Sciences, Korea Institute for Advanced Study (KIAS), Seoul, South Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5361-459X","authenticated-orcid":false,"given":"Hoki","family":"Kim","sequence":"additional","affiliation":[{"name":"Department of Industrial Engineering, Seoul National University, Seoul, South Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5720-8337","authenticated-orcid":false,"given":"Jaewook","family":"Lee","sequence":"additional","affiliation":[{"name":"Department of Industrial Engineering, Seoul National University, Seoul, South Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","article-title":"Intriguing properties of neural networks","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Szegedy"},{"key":"ref2","article-title":"Explaining and harnessing adversarial examples","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Goodfellow"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.06083"},{"key":"ref4","first-page":"7472","article-title":"Theoretically principled trade-off between robustness and accuracy","volume-title":"Proc. Int. Conf. Mach. Learn","author":"Zhang"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref6","article-title":"Countering adversarial images using input transformations","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Guo"},{"key":"ref7","article-title":"Mitigating adversarial effects through randomization","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Xie"},{"key":"ref8","article-title":"Stochastic activation pruning for robust adversarial defense","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Dhillon"},{"key":"ref9","first-page":"284","article-title":"Synthesizing robust adversarial examples","volume-title":"Proc. Int. Conf. Mach. Learn","author":"Athalye"},{"key":"ref10","first-page":"274","article-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","volume-title":"Proc. Int. Conf. Mach. Learn","author":"Athalye"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"ref12","article-title":"Transferability in machine learning: From phenomena to black-box attacks using adversarial samples","author":"Papernot","year":"2016"},{"key":"ref13","article-title":"The space of transferable adversarial examples","author":"Tramer","year":"2017"},{"key":"ref14","article-title":"Delving into transferable adversarial examples and black-box attacks","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Liu"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01234-2_23"},{"key":"ref16","article-title":"Adv-BNN: Improved adversarial defense through robust Bayesian neural network","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Liu"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00068"},{"key":"ref18","article-title":"Mixup inference: Better exploiting mixup to defend adversarial attacks","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Pang"},{"key":"ref19","first-page":"3047","article-title":"Weight-covariance alignment for adversarially robust neural networks","volume-title":"Proc. Int. Conf. Mach. Learn","author":"Eustratiadis"},{"key":"ref20","first-page":"2206","article-title":"Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks","volume-title":"Proc. Int. Conf. Mach. Learn","author":"Croce"},{"key":"ref21","article-title":"On adaptive attacks to adversarial example defenses","volume-title":"Proc. 34th Int. Conf. Neural Inf. Process. Syst.","author":"Tramer"},{"key":"ref22","article-title":"Comment on \u201cadv-BNN: Improved adversarial defense through robust Bayesian neural network,\u201d","author":"Zimmermann","year":"2019"},{"key":"ref23","article-title":"Improving adversarial robustness of ensembles with diversity training","author":"Kariyappa","year":"2019"},{"key":"ref24","first-page":"4970","article-title":"Improving adversarial robustness via promoting ensemble diversity","volume-title":"Proc. Int. Conf. Mach. Learn","author":"Pang"},{"key":"ref25","article-title":"DVERGE: Diversifying vulnerabilities for enhanced robust generation of ensembles","volume-title":"Proc. 34th Int. Conf. Neural Inf. Process. Syst.","author":"Yang"},{"key":"ref26","article-title":"Accurate, reliable and fast robustness evaluation","volume-title":"Proc. 33rd Int. Conf. Neural Inf. Process. Syst.","author":"Brendel"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58592-1_29"},{"key":"ref28","volume-title":"Directional Statistics","volume":"494","author":"Mardia","year":"2009"},{"issue":"Sep","key":"ref29","first-page":"1345","article-title":"Clustering on the unit hypersphere using von mises-fisher distributions","volume":"6","author":"Banerjee","year":"2005","journal-title":"J. Mach. Learn. Res."},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1561\/2200000044"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1007\/s10955-005-7583-z"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"key":"ref33","article-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009"},{"key":"ref34","first-page":"215","article-title":"An analysis of single-layer networks in unsupervised feature learning","volume-title":"Proc. Int. Conf. Artif. Intell. Statist","author":"Coates"},{"key":"ref35","first-page":"2196","article-title":"Minimally distorted adversarial examples with a fast adaptive boundary attack","volume-title":"Proc. Int. Conf. Mach. Learn","author":"Croce"}],"container-title":["IEEE Transactions on Pattern Analysis and Machine Intelligence"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/34\/10008914\/09761760.pdf?arnumber=9761760","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,1,22]],"date-time":"2024-01-22T21:02:47Z","timestamp":1705957367000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9761760\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,2,1]]},"references-count":35,"journal-issue":{"issue":"2"},"URL":"https:\/\/doi.org\/10.1109\/tpami.2022.3169217","relation":{},"ISSN":["0162-8828","2160-9292","1939-3539"],"issn-type":[{"value":"0162-8828","type":"print"},{"value":"2160-9292","type":"electronic"},{"value":"1939-3539","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,2,1]]}}}