{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,8,15]],"date-time":"2025-08-15T01:07:23Z","timestamp":1755220043977,"version":"3.43.0"},"reference-count":53,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"9","license":[{"start":{"date-parts":[[2025,9,1]],"date-time":"2025-09-01T00:00:00Z","timestamp":1756684800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,9,1]],"date-time":"2025-09-01T00:00:00Z","timestamp":1756684800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,9,1]],"date-time":"2025-09-01T00:00:00Z","timestamp":1756684800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Pattern Anal. Mach. Intell."],"published-print":{"date-parts":[[2025,9]]},"DOI":"10.1109\/tpami.2025.3575618","type":"journal-article","created":{"date-parts":[[2025,6,2]],"date-time":"2025-06-02T14:00:26Z","timestamp":1748872826000},"page":"8025-8039","source":"Crossref","is-referenced-by-count":0,"title":["Analyzing the Implicit Bias of Adversarial Training From a Generalized Margin Perspective"],"prefix":"10.1109","volume":"47","author":[{"ORCID":"https:\/\/orcid.org\/0009-0005-1150-7637","authenticated-orcid":false,"given":"Bochen","family":"Lyu","sequence":"first","affiliation":[{"name":"University of Southampton, Southampton, U.K."}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2141-6553","authenticated-orcid":false,"given":"Zhanxing","family":"Zhu","sequence":"additional","affiliation":[{"name":"University of Southampton, Southampton, U.K."}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.06083"},{"key":"ref2","first-page":"1097","article-title":"Imagenet classification with deep convolutional neural networks","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Krizhevsky"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2015.123"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1145\/1390156.1390177"},{"key":"ref5","first-page":"1","article-title":"Intriguing properties of neural networks","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Szegedy"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298640"},{"key":"ref7","first-page":"1","article-title":"Mitigating adversarial effects through randomization","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Xie"},{"key":"ref8","first-page":"1","article-title":"Countering adversarial images using input transformations","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Guo"},{"key":"ref9","first-page":"274","article-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Athalye"},{"key":"ref10","first-page":"7472","article-title":"Theoretically principled trade-off between robustness and accuracy","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Zhang"},{"key":"ref11","first-page":"3051","article-title":"Inductive bias of gradient descent based adversarial training on separable data","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Li"},{"key":"ref12","first-page":"1","article-title":"The implicit bias of gradient descent on separable data","volume":"19","author":"Soudry","year":"2018","journal-title":"J. Mach. Learn. Res."},{"article-title":"Risk and parameter convergence of logistic regression","year":"2018","author":"Ji","key":"ref13"},{"article-title":"Stochastic gradient descent on separable data: Exact convergence with a fixed learning rate","volume-title":"Proc. Mach. Learn. Res.","author":"Nacson","key":"ref14"},{"key":"ref15","first-page":"1","article-title":"Gradient descent aligns the layers of deep linear networks","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Ji"},{"key":"ref16","first-page":"1","article-title":"Gradient descent maximizes the margin of homogeneous neural networks","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Lyu"},{"key":"ref17","first-page":"1","article-title":"Explaining and harnessing adversarial examples","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Goodfellow"},{"key":"ref18","first-page":"1","article-title":"Implicit bias of adversarial training for deep neural networks","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Lyu"},{"article-title":"Understanding generalization in adversarial training via the bias-variance decomposition","year":"2021","author":"Yu","key":"ref19"},{"article-title":"Bridging the gap between adversarial robustness and optimization bias","year":"2021","author":"Faghri","key":"ref20"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1515\/9781400831050"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/FOCS52979.2021.00098"},{"key":"ref23","first-page":"18667","article-title":"Probabilistically robust learning: Balancing average and worst-case performance","volume-title":"Proc. 39th Int. Conf. Mach. Learn.","author":"Robey"},{"key":"ref24","first-page":"4683","article-title":"Lexicographic and depth-sensitive margins in homogeneous and non-homogeneous deep models","volume-title":"Proc. 36th Int. Conf. Mach. Learn.","author":"Nacson"},{"article-title":"On the optimization of deep networks: Implicit acceleration by overparameterization","year":"2018","author":"Arora","key":"ref25"},{"key":"ref26","first-page":"3847","article-title":"Gradient methods never overfit on separable data","volume":"22","author":"Shamir","year":"2021","journal-title":"J. Mach. Learn. Res."},{"article-title":"Implicit bias of gradient descent on linear convolutional networks","year":"2018","author":"Gunasekar","key":"ref27"},{"key":"ref28","first-page":"9712","article-title":"Regularization matters: Generalization and optimization of neural nets v.s. their induced kernel","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Wei"},{"article-title":"Mirror descent maximizes generalized margin and can be implemented efficiently","year":"2022","author":"Sun","key":"ref29"},{"issue":"14","key":"ref30","first-page":"1","article-title":"On $\/ell_{p}$\/ellp-support vector machines and multidimensional kernels","volume":"21","author":"Blanco","year":"2020","journal-title":"J. Mach. Learn. Res."},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1016\/S0167-6377(98)00049-2"},{"volume-title":"Foundations of Machine Learning","year":"2018","author":"Mohri","key":"ref32"},{"key":"ref33","first-page":"1485","article-title":"Robustness and regularization of support vector machines","volume":"10","author":"Xu","year":"2009","journal-title":"J. Mach. Learn. Res."},{"key":"ref34","first-page":"240","article-title":"Sparse DNNs with improved adversarial robustness","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Guo"},{"article-title":"Over-parameterized adversarial training: An analysis overcoming the curse of dimensionality","year":"2020","author":"Zhang","key":"ref35"},{"article-title":"Convergence of adversarial training in overparametrized neural networks","year":"2019","author":"Gao","key":"ref36"},{"article-title":"Adversarialtraining methods for semi-supervised text classification","year":"2016","author":"Miyato","key":"ref37"},{"key":"ref38","first-page":"3635","article-title":"Kernel and rich regimes in overparametrized models","volume-title":"Proc. Conf. Learn. Theory","author":"Woodworth"},{"key":"ref39","first-page":"468","article-title":"On the implicit bias of initialization shape: Beyond infinitesimal mirror descent","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Azulay"},{"key":"ref40","first-page":"1","article-title":"Robustness may be at odds with accuracy","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Tsipras"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.2022.3205449"},{"article-title":"Precise tradeoffs in adversarial training for linear regression","year":"2020","author":"Javanmard","key":"ref42"},{"key":"ref43","first-page":"8588","article-title":"A closer look at accuracy vs. robustness","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Yang"},{"article-title":"Very deep convolutional networks for large-scale image recognition","year":"2015","author":"Simonyan","key":"ref44"},{"volume-title":"Interpolation of Operators","year":"1998","author":"Bennett","key":"ref45"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.7551\/mitpress\/7503.003.0048"},{"key":"ref47","first-page":"1237","article-title":"Margin maximizing loss functions","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Rosset"},{"key":"ref48","doi-asserted-by":"crossref","DOI":"10.1561\/9781601988614","article-title":"Convex optimization: Algorithms and complexity","author":"Bubeck","year":"2015"},{"article-title":"Directional convergence and alignment in deep learning","year":"2020","author":"Ji","key":"ref49"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1007\/s10898-012-9920-5"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1090\/S0002-9947-1975-0367131-6"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1137\/1.9781611971309"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1007\/s10208-018-09409-5"}],"container-title":["IEEE Transactions on Pattern Analysis and Machine Intelligence"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/34\/11118328\/11020710.pdf?arnumber=11020710","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,7]],"date-time":"2025-08-07T17:44:15Z","timestamp":1754588655000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11020710\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,9]]},"references-count":53,"journal-issue":{"issue":"9"},"URL":"https:\/\/doi.org\/10.1109\/tpami.2025.3575618","relation":{},"ISSN":["0162-8828","2160-9292","1939-3539"],"issn-type":[{"type":"print","value":"0162-8828"},{"type":"electronic","value":"2160-9292"},{"type":"electronic","value":"1939-3539"}],"subject":[],"published":{"date-parts":[[2025,9]]}}}