{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,20]],"date-time":"2026-07-20T18:35:34Z","timestamp":1784572534218,"version":"3.55.0"},"reference-count":103,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"5","license":[{"start":{"date-parts":[[2024,5,1]],"date-time":"2024-05-01T00:00:00Z","timestamp":1714521600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2024,5,1]],"date-time":"2024-05-01T00:00:00Z","timestamp":1714521600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2024,5,1]],"date-time":"2024-05-01T00:00:00Z","timestamp":1714521600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Science Foundation of China","doi-asserted-by":"crossref","award":["U20B2072"],"award-info":[{"award-number":["U20B2072"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"crossref"}]},{"DOI":"10.13039\/501100001809","name":"National Science Foundation of China","doi-asserted-by":"crossref","award":["61976137"],"award-info":[{"award-number":["61976137"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"crossref"}]},{"name":"Shanghai Jiaotong University Medical Engineering Cross Research","award":["YG2021ZD18"],"award-info":[{"award-number":["YG2021ZD18"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Pattern Anal. Mach. Intell."],"published-print":{"date-parts":[[2024,5]]},"DOI":"10.1109\/tpami.2023.3341639","type":"journal-article","created":{"date-parts":[[2023,12,12]],"date-time":"2023-12-12T18:47:07Z","timestamp":1702406827000},"page":"3047-3063","source":"Crossref","is-referenced-by-count":10,"title":["Variational Adversarial Defense: A Bayes Perspective for Adversarial Training"],"prefix":"10.1109","volume":"46","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-4583-4258","authenticated-orcid":false,"given":"Chenglong","family":"Zhao","sequence":"first","affiliation":[{"name":"School of Electronic Information and Electrical Engineering, Shanghai Jiaotong University, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0005-6315-4642","authenticated-orcid":false,"given":"Shibin","family":"Mei","sequence":"additional","affiliation":[{"name":"School of Electronic Information and Electrical Engineering, Shanghai Jiaotong University, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7339-028X","authenticated-orcid":false,"given":"Bingbing","family":"Ni","sequence":"additional","affiliation":[{"name":"School of Electronic Information and Electrical Engineering, Shanghai Jiaotong University, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8914-489X","authenticated-orcid":false,"given":"Shengchao","family":"Yuan","sequence":"additional","affiliation":[{"name":"School of Electronic Information and Electrical Engineering, Shanghai Jiaotong University, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1310-5728","authenticated-orcid":false,"given":"Zhenbo","family":"Yu","sequence":"additional","affiliation":[{"name":"School of Electronic Information and Electrical Engineering, Shanghai Jiaotong University, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2177-9757","authenticated-orcid":false,"given":"Jun","family":"Wang","sequence":"additional","affiliation":[{"name":"HIK Research Institute of China Electronics Technology Group Corporation, Zhejiang, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2015.169"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2017.2761348"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298965"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2021.3106790"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01358"},{"key":"ref7","first-page":"1","article-title":"Intriguing properties of neural networks","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Szegedy"},{"key":"ref8","first-page":"1","article-title":"Explaining and harnessing adversarial examples","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Goodfellow"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1201\/9781351251389-8"},{"key":"ref12","first-page":"3910","article-title":"Adversarial examples that fool both computer vision and time-limited humans","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Elsayed"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00175"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00492"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00035"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.06083"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00498"},{"key":"ref18","article-title":"Mixup inference: Better exploiting mixup to defend adversarial attacks","author":"Pang","year":"2019"},{"key":"ref19","first-page":"11278","article-title":"Attacks which do not kill training make adversarial learning stronger","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Zhang"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.41"},{"key":"ref21","first-page":"274","article-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Athalye"},{"key":"ref22","first-page":"7472","article-title":"Theoretically principled trade-off between robustness and accuracy","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Zhang"},{"key":"ref23","first-page":"1","article-title":"Improving adversarial robustness requires revisiting misclassified examples","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Wang"},{"key":"ref24","first-page":"5014","article-title":"Adversarially robust generalization requires more data","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Schmidt"},{"key":"ref25","first-page":"11192","article-title":"Unlabeled data improves adversarial robustness","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Carmon"},{"key":"ref26","first-page":"13842","article-title":"Adversarial robustness through local linearization","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Qin"},{"key":"ref27","first-page":"22745","article-title":"Training certifiably robust neural networks with efficient local lipschitz bounds","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Huang"},{"key":"ref28","first-page":"12368","article-title":"Towards certifying l-infinity robustness using neural networks with l-inf-dist neurons","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Zhang"},{"key":"ref29","article-title":"Rethinking softmax cross-entropy loss for adversarial robustness","author":"Pang","year":"2019"},{"key":"ref30","article-title":"Auto-encoding variational bayes","author":"Kingma","year":"2013"},{"issue":"1","key":"ref31","first-page":"1303","article-title":"Stochastic variational inference","volume":"14","author":"Hoffman","year":"2013","journal-title":"J. Mach. Learn. Res."},{"key":"ref32","first-page":"1","article-title":"Markov chain Monte Carlo and Gibbs sampling","volume":"581","author":"Carlo","year":"2004","journal-title":"Lecture Notes EEB"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.01149"},{"key":"ref34","first-page":"8312","article-title":"Constructing unrestricted adversarial examples with generative models","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Song"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.5555\/2969033.2969125"},{"key":"ref36","article-title":"Adversarial distributional training for robust deep learning","author":"Dong","year":"2020"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00514"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00487"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00407"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref41","first-page":"2206","article-title":"Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Croce"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58592-1_29"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.17"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01240-3_2"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140448"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01258-8_10"},{"key":"ref48","first-page":"1","article-title":"Query-efficient hard-label black-box attack: An optimization-based approach","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Cheng"},{"key":"ref49","first-page":"1","article-title":"Prior convictions: Black-box adversarial attacks with bandits and priors","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Ilyas"},{"key":"ref50","first-page":"4636","article-title":"Parsimonious black-box adversarial attacks via efficient combinatorial optimization","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Moon"},{"key":"ref51","first-page":"3866","article-title":"Nattack: Learning the distributions of adversarial examples for an improved black-box attack on deep neural networks","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Li"},{"key":"ref52","first-page":"3866","article-title":"Nattack: Learning the distributions of adversarial examples for an improved black-box attack on deep neural networks","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Li"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00021"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00668"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01264-9_28"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00483"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00506"},{"key":"ref58","first-page":"10932","article-title":"Improving black-box adversarial attacks with a transfer-based prior","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Cheng"},{"key":"ref59","first-page":"3820","article-title":"Subspace attack: Exploiting promising subspaces for query-efficient black-box attacks","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Guo"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00488"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00498"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00503"},{"key":"ref63","first-page":"26250","article-title":"Gradient-free adversarial training against image corruption for learning-based steering","volume-title":"Proc. Adv. Neural Inf. Process. Syst. 34: Annu. Conf. Neural Inf. Process. Syst.","author":"Shen"},{"key":"ref64","first-page":"3259","article-title":"Learning to generate realistic noisy images via pixel-level noise-aware adversarial training","volume":"34","author":"Cai","year":"2021","journal-title":"Proc. Adv. Neural Inf. Process. Syst."},{"key":"ref65","first-page":"26693","article-title":"Revisiting and advancing fast adversarial training through the lens of bi-level optimization","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Zhang"},{"key":"ref66","first-page":"1","article-title":"Explaining and harnessing adversarial examples","author":"Goodfellow","year":"2015","journal-title":"Proc. Int. Conf. Learn. Representations"},{"key":"ref67","first-page":"1","article-title":"Adversarial machine learning at scale","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Kurakin"},{"key":"ref68","first-page":"1","article-title":"Ensemble adversarial training: Attacks and defenses","author":"Tram\u00e8r","year":"2018","journal-title":"Proc. Int. Conf. Learn. Representations"},{"key":"ref69","first-page":"1829","article-title":"Defense against adversarial attacks using feature scattering-based adversarial training","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Zhang"},{"key":"ref70","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00059"},{"key":"ref71","first-page":"23433","article-title":"Removing batch normalization boosts adversarial training","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Wang"},{"key":"ref72","first-page":"18378","article-title":"A closer look at smoothness in domain adversarial training","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Rangwani"},{"key":"ref73","first-page":"2958","article-title":"Adversarial weight perturbation helps robust generalization","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Wu"},{"key":"ref74","first-page":"3358","article-title":"Adversarial training for free!","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Shafahi"},{"key":"ref75","article-title":"Large-margin softmax loss for convolutional neural networks.","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Liu"},{"key":"ref76","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00348"},{"key":"ref77","article-title":"Improve adversarial robustness via weight penalization on classification layer","author":"Xu","year":"2020"},{"key":"ref78","first-page":"7779","article-title":"Boosting adversarial training with hypersphere embedding","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Pang"},{"key":"ref79","first-page":"1","article-title":"Mitigating adversarial effects through randomization","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Xie"},{"key":"ref80","first-page":"1","article-title":"Countering adversarial images using input transformations","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Guo"},{"key":"ref81","first-page":"1","article-title":"Thermometer encoding: One hot way to resist adversarial examples","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Buckman"},{"key":"ref82","article-title":"Stochastic activation pruning for robust adversarial defense","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Dhillon"},{"key":"ref83","first-page":"1","article-title":"Defense-GAN: Protecting classifiers against adversarial attacks using generative models","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Samangouei"},{"key":"ref84","article-title":"Defending against image corruptions through adversarial augmentations","author":"Calian","year":"2021"},{"key":"ref85","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58580-8_4"},{"key":"ref86","article-title":"Model-based robust deep learning: Generalizing to natural, out-of-distribution data","author":"Robey","year":"2020"},{"key":"ref87","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00090"},{"key":"ref88","article-title":"Robustness may be at odds with accuracy","author":"Tsipras","year":"2018"},{"key":"ref89","doi-asserted-by":"publisher","DOI":"10.1007\/978-0-387-30164-8_251"},{"key":"ref90","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00612"},{"key":"ref91","article-title":"AT-GAN: An adversarial generator model for non-constrained adversarial examples","author":"Wang","year":"2019"},{"key":"ref92","first-page":"854","article-title":"Parseval networks: Improving robustness to adversarial examples","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Ciss\u00e9"},{"key":"ref93","article-title":"Loopy belief propagation for approximate inference: An empirical study","author":"Murphy","year":"2013"},{"key":"ref94","article-title":"Expectation propagation for approximate Bayesian inference","author":"Lobato","year":"2007"},{"key":"ref95","article-title":"Pattern recognition and machine learning","volume-title":"Pattern Recognition and Machine Learning","volume":"4","author":"Bishop","year":"2006"},{"key":"ref96","article-title":"Beta-VAE: Learning basic visual concepts with a constrained variational framework","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Higgins"},{"key":"ref97","article-title":"Uncovering the limits of adversarial training against norm-bounded adversarial examples","author":"Gowal","year":"2020"},{"key":"ref98","first-page":"8093","article-title":"Overfitting in adversarially robust deep learning","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Rice"},{"key":"ref99","article-title":"Distributionally robust optimization: A review","author":"Rahimian","year":"2019"},{"key":"ref100","doi-asserted-by":"publisher","DOI":"10.1023\/A:1020281327116"},{"key":"ref101","first-page":"2142","article-title":"Black-box adversarial attacks with limited queries and information","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Ilyas"},{"key":"ref102","first-page":"2484","article-title":"Simple black-box adversarial attacks","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Guo"},{"key":"ref103","first-page":"274","article-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Athalye"}],"container-title":["IEEE Transactions on Pattern Analysis and Machine Intelligence"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/34\/10490207\/10354457.pdf?arnumber=10354457","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,4,9]],"date-time":"2024-04-09T19:35:01Z","timestamp":1712691301000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10354457\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,5]]},"references-count":103,"journal-issue":{"issue":"5"},"URL":"https:\/\/doi.org\/10.1109\/tpami.2023.3341639","relation":{},"ISSN":["0162-8828","2160-9292","1939-3539"],"issn-type":[{"value":"0162-8828","type":"print"},{"value":"2160-9292","type":"electronic"},{"value":"1939-3539","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,5]]}}}