{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,8]],"date-time":"2026-02-08T08:06:34Z","timestamp":1770537994687,"version":"3.49.0"},"reference-count":78,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"2","license":[{"start":{"date-parts":[[2026,2,1]],"date-time":"2026-02-01T00:00:00Z","timestamp":1769904000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2026,2,1]],"date-time":"2026-02-01T00:00:00Z","timestamp":1769904000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,2,1]],"date-time":"2026-02-01T00:00:00Z","timestamp":1769904000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62271090"],"award-info":[{"award-number":["62271090"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62221005"],"award-info":[{"award-number":["62221005"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"National Key R&amp;D Program of China","award":["2021YFB3100800"],"award-info":[{"award-number":["2021YFB3100800"]}]},{"name":"Chongqing Natural Science Fund","award":["CSTB2024NSCQ-JQX0038"],"award-info":[{"award-number":["CSTB2024NSCQ-JQX0038"]}]},{"name":"National Youth Talent Project"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Pattern Anal. Mach. Intell."],"published-print":{"date-parts":[[2026,2]]},"DOI":"10.1109\/tpami.2025.3614495","type":"journal-article","created":{"date-parts":[[2025,9,25]],"date-time":"2025-09-25T17:55:03Z","timestamp":1758822903000},"page":"1390-1406","source":"Crossref","is-referenced-by-count":2,"title":["M3C: Resist Agnostic Attacks by Mitigating Consistent Class Confusion Prior"],"prefix":"10.1109","volume":"48","author":[{"ORCID":"https:\/\/orcid.org\/0009-0004-9723-2955","authenticated-orcid":false,"given":"Xiaowei","family":"Fu","sequence":"first","affiliation":[{"name":"School of Microelectronics and Communication Engineering, Chongqing University, Chongqing, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0399-9932","authenticated-orcid":false,"given":"Fuxiang","family":"Huang","sequence":"additional","affiliation":[{"name":"Chongqing Key Laboratory of Bio-perception and Multimodal Intelligent Information Processing, Chongqing University, Chongqing, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8521-5232","authenticated-orcid":false,"given":"Guoyin","family":"Wang","sequence":"additional","affiliation":[{"name":"National Center for Applied Mathematics in Chongqing, Chongqing Normal University, Chongqing, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7985-0037","authenticated-orcid":false,"given":"Xinbo","family":"Gao","sequence":"additional","affiliation":[{"name":"Chongqing Key Laboratory of Image Cognition, Chongqing University of Posts and Telecommunications, Chongqing, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5305-8543","authenticated-orcid":false,"given":"Lei","family":"Zhang","sequence":"additional","affiliation":[{"name":"School of Microelectronics and Communication Engineering, Chongqing University, Chongqing, China"}]}],"member":"263","reference":[{"key":"ref1","first-page":"1","article-title":"Sign bits are all you need for black-box attacks","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Al-Dujaili","year":"2020"},{"key":"ref2","first-page":"274","article-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Athalye","year":"2018"},{"key":"ref3","first-page":"274","article-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Athalye","year":"2018"},{"key":"ref4","article-title":"Training ensembles to detect adversarial examples","author":"Bagnall","year":"2017"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2020.3031625"},{"key":"ref6","first-page":"1","article-title":"Improving adversarial robustness via channel-wise activation suppressing","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Bai","year":"2020"},{"key":"ref7","first-page":"325","article-title":"Robustness may be at odds with fairness: An empirical study on class-wise accuracy","volume-title":"Proc. NeurIPS 2020 Workshop Pre-Registration Mach. Learn.","author":"Benz","year":"2021"},{"key":"ref8","article-title":"Decision-based adversarial attacks: Reliable attacks against black-box machine learning models","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Brendel","year":"2018"},{"key":"ref9","first-page":"1","article-title":"A unified Wasserstein distributional robustness framework for adversarial training","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Bui","year":"2022"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2022.3200245"},{"key":"ref12","first-page":"1310","article-title":"Certified adversarial robustness via randomized smoothing","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Cohen","year":"2019"},{"key":"ref13","first-page":"2206","article-title":"Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Croce","year":"2020"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00103"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00444"},{"key":"ref17","first-page":"1","article-title":"Exploring memorization in adversarial training","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Dong","year":"2021"},{"key":"ref18","first-page":"1","article-title":"An image is worth 16 x 16 words: Transformers for image recognition at scale","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Dosovitskiy","year":"2021"},{"key":"ref19","article-title":"Explaining and harnessing adversarial examples","author":"Goodfellow","year":"2014"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.32657\/10356\/143316"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.02363"},{"key":"ref23","first-page":"19365","article-title":"Self-adaptive training: Beyond empirical risk minimization","volume-title":"Proc. 34th Int. Conf. Neural Inf. Process. Syst.","author":"Huang","year":"2020"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01484"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01484"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.02311"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.00791"},{"key":"ref28","article-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2023.3322785"},{"key":"ref30","first-page":"1","article-title":"Adversarial machine learning at scale","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Kurakin","year":"2016"},{"key":"ref31","first-page":"7167","article-title":"A simple unified framework for detecting out-of-distribution samples and adversarial attacks","volume-title":"Proc. 32nd Int. Conf. Neural Inf. Process. Syst.","author":"Lee","year":"2018"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1016\/j.neunet.2023.03.008"},{"key":"ref33","article-title":"Characterizing adversarial subspaces using local intrinsic dimensionality","author":"Ma","year":"2018"},{"key":"ref34","article-title":"Towards deep learning models resistant to adversarial attacks","author":"Madry","year":"2017"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/wacv61041.2025.00760"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134057"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW.2017.172"},{"key":"ref39","article-title":"Simple black-box adversarial perturbations for deep networks","author":"Narodytska","year":"2016"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00034"},{"key":"ref41","article-title":"Reading digits in natural images with unsupervised feature learning","author":"Netzer","year":"2011"},{"key":"ref42","first-page":"16805","article-title":"Diffusion models for adversarial purification","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Nie","year":"2022"},{"key":"ref43","article-title":"Diffusion models for adversarial purification","author":"Nie","year":"2022"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.41"},{"key":"ref46","article-title":"Tiny imagenet visual recognition challenge","author":"Pouransari","year":"2014"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00385"},{"key":"ref48","article-title":"Certified defenses against adversarial examples","author":"Raghunathan","year":"2018"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00445"},{"key":"ref50","article-title":"Defense-GAN: Protecting classifiers against adversarial attacks using generative models","author":"Samangouei","year":"2018"},{"key":"ref51","volume-title":"Introduction to Information Retrieval","volume":"39","author":"Sch\u00fctze","year":"2008"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.74"},{"key":"ref53","article-title":"Online adversarial purification based on self-supervised learning","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Shi","year":"2020"},{"key":"ref54","article-title":"Online adversarial purification based on self-supervision","author":"Shi","year":"2021"},{"key":"ref55","article-title":"PixelDefend: Leveraging generative models to understand and defend against adversarial examples","author":"Song","year":"2017"},{"key":"ref56","first-page":"1","article-title":"PixelDefend: Leveraging generative models to understand and defend against adversarial examples","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Song","year":"2018"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1109\/TEVC.2019.2890858"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1145\/3447548.3467403"},{"issue":"11","key":"ref59","article-title":"Visualizing data using T-SNE","volume":"9","author":"Maaten","year":"2008","journal-title":"J. Mach. Learn. Res."},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1145\/1390156.1390294"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.01099"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00756"},{"key":"ref63","article-title":"Improving adversarial robustness requires revisiting misclassified examples","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Wang","year":"2019"},{"key":"ref64","first-page":"1","article-title":"Improving adversarial robustness requires revisiting misclassified examples","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Wang","year":"2020"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.00792"},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.02324"},{"key":"ref67","article-title":"Mitigating adversarial effects through randomization","author":"Xie","year":"2017"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00284"},{"key":"ref69","first-page":"11693","article-title":"CIFS: Improving adversarial robustness of CNNs via channel-wise importance-based feature selection","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Yan","year":"2021"},{"key":"ref70","first-page":"12062","article-title":"Adversarial purification with score-based generative models","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Yoon","year":"2021"},{"key":"ref71","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2024.3367773"},{"key":"ref72","doi-asserted-by":"publisher","DOI":"10.5244\/C.30.87"},{"key":"ref73","first-page":"7472","article-title":"Theoretically principled trade-off between robustness and accuracy","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Zhang","year":"2019"},{"key":"ref74","first-page":"11278","article-title":"Attacks which do not kill training make adversarial learning stronger","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Zhang","year":"2020"},{"key":"ref75","first-page":"41429","article-title":"Detecting adversarial data by probing multiple perturbations using expected perturbation score","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Zhang","year":"2023"},{"key":"ref76","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.485"},{"key":"ref77","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2024.3365699"},{"key":"ref78","article-title":"Robust representation learning via asymmetric negative contrast and reverse attention","author":"Zhou","year":"2023"}],"container-title":["IEEE Transactions on Pattern Analysis and Machine Intelligence"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/34\/11345188\/11180132.pdf?arnumber=11180132","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,1,12]],"date-time":"2026-01-12T22:00:39Z","timestamp":1768255239000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11180132\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,2]]},"references-count":78,"journal-issue":{"issue":"2"},"URL":"https:\/\/doi.org\/10.1109\/tpami.2025.3614495","relation":{},"ISSN":["0162-8828","2160-9292","1939-3539"],"issn-type":[{"value":"0162-8828","type":"print"},{"value":"2160-9292","type":"electronic"},{"value":"1939-3539","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,2]]}}}