{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,18]],"date-time":"2025-11-18T21:05:58Z","timestamp":1763499958627,"version":"3.37.3"},"reference-count":49,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"12","license":[{"start":{"date-parts":[[2024,12,1]],"date-time":"2024-12-01T00:00:00Z","timestamp":1733011200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2024,12,1]],"date-time":"2024-12-01T00:00:00Z","timestamp":1733011200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2024,12,1]],"date-time":"2024-12-01T00:00:00Z","timestamp":1733011200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"NSCF","award":["62076178"],"award-info":[{"award-number":["62076178"]}]},{"name":"Tianjin S&#x0026;T","award":["22ZYYYJC00020"],"award-info":[{"award-number":["22ZYYYJC00020"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Pattern Anal. Mach. Intell."],"published-print":{"date-parts":[[2024,12]]},"DOI":"10.1109\/tpami.2024.3432973","type":"journal-article","created":{"date-parts":[[2024,7,24]],"date-time":"2024-07-24T18:29:44Z","timestamp":1721845784000},"page":"10210-10227","source":"Crossref","is-referenced-by-count":4,"title":["Adversarial Training With Anti-Adversaries"],"prefix":"10.1109","volume":"46","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-7305-1779","authenticated-orcid":false,"given":"Xiaoling","family":"Zhou","sequence":"first","affiliation":[{"name":"Center for Applied Mathematics, Tianjin University, Tianjin, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8060-7739","authenticated-orcid":false,"given":"Ou","family":"Wu","sequence":"additional","affiliation":[{"name":"Center for Applied Mathematics, Tianjin University, Tianjin, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-6674-7632","authenticated-orcid":false,"given":"Nan","family":"Yang","sequence":"additional","affiliation":[{"name":"Center for Applied Mathematics, Tianjin University, Tianjin, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2022.3169217"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2021\/591"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.06083"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i10.17075"},{"key":"ref5","first-page":"12907","article-title":"Theoretically principled trade-off between robustness and accuracy","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Zhang"},{"key":"ref6","first-page":"1","article-title":"Improving adversarial robustness requires revisiting misclassified examples","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Wang"},{"key":"ref7","first-page":"8588","article-title":"A closer look at accuracy vs. robustness","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Yang"},{"article-title":"Smooth adversarial training","year":"2020","author":"Xie","key":"ref8"},{"key":"ref9","first-page":"8093","article-title":"Overfitting in adversarially robust deep learning","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Rice"},{"article-title":"Exploring memorization in adversarial training","year":"2021","author":"Dong","key":"ref10"},{"key":"ref11","first-page":"11492","article-title":"To be robust or to be fair: Towards fairness in adversarial training","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Xu"},{"key":"ref12","first-page":"12214","article-title":"Are labels required for improving adversarial robustness?","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Uesato"},{"article-title":"Understanding the interaction of adversarial training with noisy labels","year":"2021","author":"Zhu","key":"ref13"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v36i6.20545"},{"issue":"2","key":"ref15","first-page":"4","article-title":"Reading digits in natural images with unsupervised feature learning","volume-title":"Proc. Neural Inf. Process. Syst. Workshop Deep Learn. Unsupervised Feature Learn.","volume":"2011","author":"Netzer","year":"2011"},{"article-title":"Cat: Customized adversarial training for improved robustness","year":"2020","author":"Cheng","key":"ref16"},{"article-title":"Instance adaptive adversarial training: Improved accuracy tradeoffs in neural nets","year":"2019","author":"Balaji","key":"ref17"},{"key":"ref18","first-page":"1","article-title":"MMA training: Direct input space margin maximization through adversarial training","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Ding"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i4.16424"},{"article-title":"Adversarial training can hurt generalization","year":"2019","author":"Raghunathan","key":"ref20"},{"key":"ref21","first-page":"11258","article-title":"Attacks which do not kill training make adversarial learning stronger","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Zhang"},{"key":"ref22","first-page":"1","article-title":"Robust local features for improving the generalization of adversarial training","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Song"},{"key":"ref23","first-page":"1","article-title":"Bag of tricks for adversarial training","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Pang"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2021.3079209"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.5555\/3294996.3295163"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00131"},{"key":"ref27","first-page":"2740","article-title":"Meta learning with memory-augmented neural networks","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Santoro"},{"key":"ref28","first-page":"1856","article-title":"Model-agnostic meta-learning for fast adaptation of deep networks","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Finn"},{"article-title":"On first-order meta-learning algorithms","year":"2018","author":"Nichol","key":"ref29"},{"key":"ref30","first-page":"6900","article-title":"Learning to reweight examples for robust deep learning","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Ren"},{"key":"ref31","first-page":"1917","article-title":"Meta-weight-net: Learning an explicit mapping for sample weighting","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Shu"},{"volume-title":"Reinforcement Learning: An Introduction","year":"2018","author":"Sutton","key":"ref32"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1613\/jair.301"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1016\/j.inffus.2022.03.003"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2021.3096966"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01304"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2017.2743240"},{"key":"ref38","first-page":"171","article-title":"A class of distributions which includes the normal ones","volume":"12","author":"Azzalini","year":"1985","journal-title":"Scand. J. Statist."},{"key":"ref39","first-page":"1","article-title":"Geometry-aware instance-reweighted adversarial training","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Zhang"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2020.107585"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1088\/1751-8113\/41\/6\/065004"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00949"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00076"},{"key":"ref44","first-page":"5809","article-title":"First-order adversarial vulnerability of neural networks and input dimension","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Simon-Gabriel"},{"article-title":"Learning multiple layers of features from tiny images","year":"2009","author":"Krizhevsky","key":"ref45"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-015-0816-y"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.5244\/C.30.87"},{"key":"ref49","first-page":"60","article-title":"A reductions approach to fair classification","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Agarwal"}],"container-title":["IEEE Transactions on Pattern Analysis and Machine Intelligence"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/34\/10746266\/10608444.pdf?arnumber=10608444","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,11,27]],"date-time":"2024-11-27T00:01:49Z","timestamp":1732665709000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10608444\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,12]]},"references-count":49,"journal-issue":{"issue":"12"},"URL":"https:\/\/doi.org\/10.1109\/tpami.2024.3432973","relation":{},"ISSN":["0162-8828","2160-9292","1939-3539"],"issn-type":[{"type":"print","value":"0162-8828"},{"type":"electronic","value":"2160-9292"},{"type":"electronic","value":"1939-3539"}],"subject":[],"published":{"date-parts":[[2024,12]]}}}