{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,4]],"date-time":"2026-08-04T15:24:38Z","timestamp":1785857078317,"version":"3.56.0"},"reference-count":70,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"9","license":[{"start":{"date-parts":[[2024,9,1]],"date-time":"2024-09-01T00:00:00Z","timestamp":1725148800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2024,9,1]],"date-time":"2024-09-01T00:00:00Z","timestamp":1725148800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2024,9,1]],"date-time":"2024-09-01T00:00:00Z","timestamp":1725148800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"National Key R&#x0026;D Program of China","award":["2022ZD0118100"],"award-info":[{"award-number":["2022ZD0118100"]}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62025604"],"award-info":[{"award-number":["62025604"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62376257"],"award-info":[{"award-number":["62376257"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62076213"],"award-info":[{"award-number":["62076213"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Shenzhen Science and Technology Program","award":["KQTD20221101093559018"],"award-info":[{"award-number":["KQTD20221101093559018"]}]},{"name":"Guangdong Major Project of Basic and Applied Basic Research","award":["2023B0303000010"],"award-info":[{"award-number":["2023B0303000010"]}]},{"name":"Shenzhen Science and Technology Program","award":["RCYX20210609103057050"],"award-info":[{"award-number":["RCYX20210609103057050"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Pattern Anal. Mach. Intell."],"published-print":{"date-parts":[[2024,9]]},"DOI":"10.1109\/tpami.2024.3381180","type":"journal-article","created":{"date-parts":[[2024,3,26]],"date-time":"2024-03-26T20:16:12Z","timestamp":1711484172000},"page":"6367-6383","source":"Crossref","is-referenced-by-count":50,"title":["Improving Fast Adversarial Training With Prior-Guided Knowledge"],"prefix":"10.1109","volume":"46","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-2018-9344","authenticated-orcid":false,"given":"Xiaojun","family":"Jia","sequence":"first","affiliation":[{"name":"Cyber Security Research Centre at NTU, Nanyang Technological University, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0066-3448","authenticated-orcid":false,"given":"Yong","family":"Zhang","sequence":"additional","affiliation":[{"name":"AI Lab, Tencent Inc., Shenzhen, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0778-8377","authenticated-orcid":false,"given":"Xingxing","family":"Wei","sequence":"additional","affiliation":[{"name":"Institute of Artificial Intelligence, Beihang University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Baoyuan","family":"Wu","sequence":"additional","affiliation":[{"name":"School of Data Science, Chinese University of Hong Kong, Shenzhen, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ke","family":"Ma","sequence":"additional","affiliation":[{"name":"School of Electronic, Electrical and Communication Engineering, University of Chinese Academy of Sciences, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3641-3136","authenticated-orcid":false,"given":"Jue","family":"Wang","sequence":"additional","affiliation":[{"name":"AI Lab, Tencent Inc., Shenzhen, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7141-708X","authenticated-orcid":false,"given":"Xiaochun","family":"Cao","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Technology, Shenzhen Campus, Sun Yat-sen University, Shenzhen, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58592-1_29"},{"key":"ref2","first-page":"16048","article-title":"Understanding and improving fast adversarial training","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Andriushchenko"},{"key":"ref3","first-page":"274","article-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Athalye"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2022.109037"},{"key":"ref5","article-title":"Clustering effect of (linearized) adversarial robust models","author":"Bai","year":"2021","journal-title":"arXiv:2111.12922"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58595-2_7"},{"key":"ref7","article-title":"Improving adversarial robustness via channel-wise activation suppressing","author":"Bai","year":"2021","journal-title":"arXiv:2103.08307"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref9","article-title":"Robust overfitting may be mitigated by properly learned smoothening","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Chen"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2023.3242292"},{"key":"ref11","first-page":"2196","article-title":"Minimally distorted adversarial examples with a fast adaptive boundary attack","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Croce"},{"key":"ref12","first-page":"2206","article-title":"Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Croce"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2021.108249"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2021.3126733"},{"key":"ref16","article-title":"Viewfool: Evaluating the robustness of visual recognition to adversarial viewpoints","author":"Dong","year":"2022","journal-title":"arXiv:2210.03895"},{"key":"ref17","article-title":"Jonathon Shlens, and Christian Szegedy. explaining and harnessing adversarial examples","author":"Goodfellow","year":"2014","journal-title":"arXiv:1412.6572"},{"key":"ref18","article-title":"Uncovering the limits of adversarial training against norm-bounded adversarial examples","author":"Gowal","year":"2020","journal-title":"arXiv: 2010.03593"},{"key":"ref19","first-page":"4218","article-title":"Improving robustness using generated data","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Gowal"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v37i1.25154"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-46493-0_38"},{"key":"ref23","first-page":"6840","article-title":"Denoising diffusion probabilistic models","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Ho"},{"key":"ref24","article-title":"MIXPGD: Hybrid adversarial training for speech recognition systems","author":"Huq","year":"2023","journal-title":"arXiv:2303.05758"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/ICIP42928.2021.9506548"},{"key":"ref26","article-title":"Averaging weights leads to wider optima and better generalization","author":"Izmailov","year":"2018","journal-title":"arXiv: 1803.05407"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00624"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1145\/3394171.3413976"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-19772-7_33"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01304"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2022.3184255"},{"key":"ref32","article-title":"Adversarial logit pairing","author":"Kannan","year":"2018","journal-title":"arXiv: 1803.06373"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i9.16989"},{"key":"ref34","article-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00035"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2022.109229"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00072"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01305"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2023.3237935"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i07.6810"},{"key":"ref41","article-title":"Towards deep learning models resistant to adversarial attacks","author":"Madry","year":"2017","journal-title":"arXiv: 1706.06083"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v37i8.26095"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"ref44","first-page":"17258","article-title":"Robustness and accuracy could be reconcilable by (proper) definition","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Pang"},{"key":"ref45","first-page":"7779","article-title":"Boosting adversarial training with hypersphere embedding","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Pang"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1016\/S0893-6080(98)00116-6"},{"key":"ref48","article-title":"Fixing data augmentation to improve adversarial robustness","author":"Gowal","year":"2021","journal-title":"arXiv:2103.01946"},{"key":"ref49","first-page":"8093","article-title":"Overfitting in adversarially robust deep learning","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Rice"},{"key":"ref50","first-page":"14973","article-title":"Adversarial training is a form of data-dependent operator norm regularization","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Roth"},{"key":"ref51","first-page":"3358","article-title":"Adversarial training for free!","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Shafahi"},{"key":"ref52","article-title":"Very deep convolutional networks for large-scale image recognition","author":"Simonyan","year":"2014","journal-title":"arXiv:1409.1556"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1109\/WACV.2017.58"},{"key":"ref54","article-title":"PixelDefend: Leveraging generative models to understand and defend against adversarial examples","author":"Song","year":"2017","journal-title":"arXiv: 1710.10766"},{"key":"ref55","first-page":"20297","article-title":"Guided adversarial attack for evaluating and enhancing adversarial defenses","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Sriramanan"},{"key":"ref56","first-page":"11821","article-title":"Towards efficient and effective adversarial training","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Sriramanan"},{"key":"ref57","article-title":"Intriguing properties of neural networks","author":"Szegedy","year":"2013","journal-title":"arXiv:1312.6199"},{"key":"ref58","article-title":"Ensemble adversarial training: Attacks and defenses","author":"Tram\u00e8r","year":"2017","journal-title":"arXiv: 1705.07204"},{"key":"ref59","article-title":"Self-ensemble adversarial training for improved robustness","author":"Wang","year":"2022","journal-title":"arXiv:2203.09678"},{"key":"ref60","article-title":"Improving adversarial robustness requires revisiting misclassified examples","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Wang"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.01967"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2022.3231886"},{"key":"ref63","article-title":"Fast is better than free: Revisiting adversarial training","author":"Wong","year":"2020","journal-title":"arXiv: 2001.03994"},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-19778-9_18"},{"key":"ref65","first-page":"2958","article-title":"Adversarial weight perturbation helps robust generalization","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Wu"},{"key":"ref66","first-page":"18","article-title":"Understanding adversarial robustness through loss landscape geometries","volume-title":"Proc. Int. Conf. Mach. Learn. Workshops","author":"Xu"},{"key":"ref67","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-19772-7_42"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.1002\/int.22258"},{"key":"ref69","doi-asserted-by":"publisher","DOI":"10.5244\/C.30.87"},{"key":"ref70","article-title":"Bridging mode connectivity in loss landscapes and adversarial robustness","author":"Zhao","year":"2020","journal-title":"arXiv: 2005.00060"}],"container-title":["IEEE Transactions on Pattern Analysis and Machine Intelligence"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/34\/10627928\/10478545.pdf?arnumber=10478545","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,8,7]],"date-time":"2024-08-07T17:43:34Z","timestamp":1723052614000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10478545\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,9]]},"references-count":70,"journal-issue":{"issue":"9"},"URL":"https:\/\/doi.org\/10.1109\/tpami.2024.3381180","relation":{},"ISSN":["0162-8828","2160-9292","1939-3539"],"issn-type":[{"value":"0162-8828","type":"print"},{"value":"2160-9292","type":"electronic"},{"value":"1939-3539","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,9]]}}}