{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,6]],"date-time":"2026-05-06T06:19:55Z","timestamp":1778048395728,"version":"3.51.4"},"reference-count":56,"publisher":"IEEE","license":[{"start":{"date-parts":[[2026,3,6]],"date-time":"2026-03-06T00:00:00Z","timestamp":1772755200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,3,6]],"date-time":"2026-03-06T00:00:00Z","timestamp":1772755200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026,3,6]]},"DOI":"10.1109\/wacv61042.2026.00075","type":"proceedings-article","created":{"date-parts":[[2026,5,5]],"date-time":"2026-05-05T19:59:32Z","timestamp":1778011172000},"page":"698-707","source":"Crossref","is-referenced-by-count":0,"title":["Data-Driven Lipschitz Continuity: A Cost-Effective Approach to Improve Adversarial Robustness"],"prefix":"10.1109","author":[{"given":"Erh-Chung","family":"Chen","sequence":"first","affiliation":[{"name":"National Tsing Hua University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Pin-Yu","family":"Chen","sequence":"additional","affiliation":[{"name":"IBM Research"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"I-Hsin","family":"Chung","sequence":"additional","affiliation":[{"name":"IBM Research"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Che-Rung","family":"Lee","sequence":"additional","affiliation":[{"name":"National Tsing Hua University"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.52202\/068431-0109"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58592-1_29"},{"key":"ref3","first-page":"274","article-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","volume-title":"International conference on machine learning","author":"Athalye"},{"key":"ref4","article-title":"Improving adversarial robustness via channel-wise activation suppressing","author":"Bai","year":"2021"},{"key":"ref5","article-title":"Mixednuts: Training-free accuracy-robustness balance via nonlinearly mixed classifiers","author":"Bai","year":"2024"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2018.00009"},{"key":"ref7","article-title":"On evaluating adversarial robustness","author":"Carlini","year":"2019"},{"key":"ref8","article-title":"Unlabeled data improves adversarial robustness","volume":"32","author":"Carmon","year":"2019","journal-title":"Advances in neural information processing systems"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-69535-4_35"},{"key":"ref10","article-title":"Ltd: Low temperature distillation for robust adversarial training","author":"Chen","year":"2021"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2024.110394"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/cvpr52733.2024.02334"},{"key":"ref13","article-title":"Steal now and attack later: Evaluating robustness of object detection against black-box adversarial attacks","author":"Chen","year":"2024"},{"key":"ref14","volume-title":"Adversarial robustness for machine learning","author":"Chen","year":"2022"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v32i1.11302"},{"key":"ref16","first-page":"1310","article-title":"Certified adversarial robustness via randomized smoothing","volume-title":"international conference on machine learning","author":"Cohen"},{"key":"ref17","first-page":"2206","article-title":"Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks","volume-title":"International conference on machine learning","author":"Croce"},{"key":"ref18","article-title":"Robustbench: a standardized adversarial robustness benchmark","author":"Croce","year":"2020"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.52202\/079017-2370"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/WACV51458.2022.00385"},{"key":"ref21","article-title":"Generalizable adversarial training via spectral normalization","author":"Farnia","year":"2018"},{"key":"ref22","article-title":"Explaining and harnessing adversarial examples","author":"Goodfellow","year":"2014"},{"key":"ref23","article-title":"On the effectiveness of interval bound propagation for training verifiably robust models","author":"Gowal","year":"2018"},{"key":"ref24","first-page":"4218","article-title":"Improving robustness using generated data","volume":"34","author":"Gowal","year":"2021","journal-title":"Advances in Neural Information Processing Systems"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2023.3334614"},{"key":"ref26","first-page":"22745","article-title":"Training certifiably robust neural networks with efficient local lipschitz bounds","volume":"34","author":"Huang","year":"2021","journal-title":"Advances in Neural Information Processing Systems"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/TAI.2021.3111139"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/ICPR48806.2021.9412236"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.5555\/2999134.2999257"},{"key":"ref30","article-title":"Certifying llm safety against adversarial prompting","author":"Kumar","year":"2023"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23138"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-024-02196-3"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00986"},{"key":"ref34","article-title":"Towards deep learning models resistant to adversarial attacks","author":"Madry","year":"2017"},{"key":"ref35","article-title":"Understanding certified training with interval bound propagation","volume-title":"The Twelfth International Conference on Learning Representations","author":"Mao"},{"key":"ref36","article-title":"Certified training: Small boxes are all you need","author":"M\u00fcller","year":"2022"},{"key":"ref37","article-title":"Robust principles: Architectural design principles for adversarially robust cnns","author":"Peng","year":"2023"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.91"},{"key":"ref39","first-page":"8093","article-title":"Overfitting in adversarially robust deep learning","volume-title":"International conference on machine learning","author":"Rice"},{"key":"ref40","article-title":"Intriguing properties of neural networks","author":"Szegedy","year":"2013"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01585"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2022.07.157"},{"key":"ref43","first-page":"36246","article-title":"Better diffusion models further improve adversarial training","volume-title":"International Conference on Machine Learning","author":"Wang"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2022.3176760"},{"key":"ref45","first-page":"2958","article-title":"Adversarial weight perturbation helps robust generalization","volume":"33","author":"Wu","year":"2020","journal-title":"Advances in neural information processing systems"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i16.17663"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58558-7_39"},{"key":"ref48","article-title":"Llm lies: Hallucinations are not bugs, but features as adversarial examples","author":"Yao","year":"2023"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/WACV51458.2022.00289"},{"key":"ref50","article-title":"Spectral norm regularization for improving the generalizability of deep learning","author":"Yoshida","year":"2017"},{"key":"ref51","first-page":"7472","article-title":"Theoretically principled trade-off between robustness and accuracy","volume-title":"International conference on machine learning","author":"Zhang"},{"key":"ref52","first-page":"11278","article-title":"Attacks which do not kill training make adversarial learning stronger","volume-title":"International conference on machine learning","author":"Zhang"},{"key":"ref53","first-page":"26693","article-title":"Revisiting and advancing fast adversarial training through the lens of bi-level optimization","volume-title":"International Conference on Machine Learning","author":"Zhang"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i04.6173"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1145\/3689217.3690621"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1145\/3648351"}],"event":{"name":"2026 IEEE\/CVF Winter Conference on Applications of Computer Vision (WACV)","location":"Tucson, AZ, USA","start":{"date-parts":[[2026,3,6]]},"end":{"date-parts":[[2026,3,10]]}},"container-title":["2026 IEEE\/CVF Winter Conference on Applications of Computer Vision (WACV)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11491838\/11491925\/11492649.pdf?arnumber=11492649","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,6]],"date-time":"2026-05-06T05:59:22Z","timestamp":1778047162000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11492649\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,3,6]]},"references-count":56,"URL":"https:\/\/doi.org\/10.1109\/wacv61042.2026.00075","relation":{},"subject":[],"published":{"date-parts":[[2026,3,6]]}}}