{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,10]],"date-time":"2025-11-10T13:07:31Z","timestamp":1762780051538,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":76,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,10,28]],"date-time":"2024-10-28T00:00:00Z","timestamp":1730073600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"Fundamental Research Funds for Central Universities under Grant","award":["D5000230355 and D5000240037"],"award-info":[{"award-number":["D5000230355 and D5000240037"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,10,28]]},"DOI":"10.1145\/3664647.3681077","type":"proceedings-article","created":{"date-parts":[[2024,10,26]],"date-time":"2024-10-26T06:59:33Z","timestamp":1729925973000},"page":"9799-9808","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":2,"title":["Sustainable Self-evolution Adversarial Training"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-7142-9734","authenticated-orcid":false,"given":"Wenxuan","family":"Wang","sequence":"first","affiliation":[{"name":"School of Computer Science, National Engineering Laboratory for Integrated Aero-Space-Ground-Ocean Big Data Application Technology, Northwestern Polytechnical University, Xi'an, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-3922-3081","authenticated-orcid":false,"given":"Chenglei","family":"Wang","sequence":"additional","affiliation":[{"name":"School of Computer Science, National Engineering Laboratory for Integrated Aero-Space-Ground-Ocean Big Data Application Technology, Northwestern Polytechnical University, Xi'an, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0003-4807-6207","authenticated-orcid":false,"given":"Huihui","family":"Qi","sequence":"additional","affiliation":[{"name":"School of Computer Science, National Engineering Laboratory for Integrated Aero-Space-Ground-Ocean Big Data Application Technology, Northwestern Polytechnical University, Xi'an, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0008-5620-4885","authenticated-orcid":false,"given":"Menghao","family":"Ye","sequence":"additional","affiliation":[{"name":"School of Computer Science, National Engineering Laboratory for Integrated Aero-Space-Ground-Ocean Big Data Application Technology, Northwestern Polytechnical University, Xi'an, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8049-7288","authenticated-orcid":false,"given":"Xuelin","family":"Qian","sequence":"additional","affiliation":[{"name":"School of Automation, The BRain and Artificial INtelligence Lab, Northwestern Polytechnical University, Xi'an, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9218-9132","authenticated-orcid":false,"given":"Peng","family":"Wang","sequence":"additional","affiliation":[{"name":"School of Computer Science, National Engineering Laboratory for Integrated Aero-Space-Ground-Ocean Big Data Application Technology, Northwestern Polytechnical University, Xi'an, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2977-8057","authenticated-orcid":false,"given":"Yanning","family":"Zhang","sequence":"additional","affiliation":[{"name":"School of Computer Science, National Engineering Laboratory for Integrated Aero-Space-Ground-Ocean Big Data Application Technology, Northwestern Polytechnical University, Xi'an, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2024,10,28]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58592-1_29"},{"key":"e_1_3_2_1_2_1","volume-title":"Cbcl-pr: A cognitively inspired model for class-incremental learning in robotics","author":"Ayub Ali","year":"2023","unstructured":"Ali Ayub and Alan R Wagner. 2023. Cbcl-pr: A cognitively inspired model for class-incremental learning in robotics. IEEE Transactions on Cognitive and Developmental Systems (2023)."},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"crossref","unstructured":"Jihwan Bang Heesu Kim YoungJoon Yoo Jung-Woo Ha and Jonghyun Choi. 2021. Rainbow memory:Continuallearning with a memoryofdiversesamples.In Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition. 8218--8227.","DOI":"10.1109\/CVPR46437.2021.00812"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"crossref","unstructured":"Nicholas Carlini and David Wagner. 2017. Towards evaluating the robustness of neural networks. In 2017 ieee symposium on security and privacy (sp). Ieee 39--57.","DOI":"10.1109\/SP.2017.49"},{"key":"e_1_3_2_1_5_1","volume-title":"Proceedings of the IEEE\/CVF International Conference on Computer Vision. 4489--4498","author":"Yin Jiali","year":"2023","unstructured":"BinChen,Jiali Yin, Shukai Chen, Bohao Chen, and Ximeng Liu. 2023. An adaptive model ensemble adversarial attack for boosting adversarial transferability. In Proceedings of the IEEE\/CVF International Conference on Computer Vision. 4489--4498."},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.02275"},{"key":"e_1_3_2_1_7_1","unstructured":"Jinghui Chen Yuan Cao and Quanquan Gu. 2023. Benign overfitting in adversarially robust linear classification. In Uncertainty in Artificial Intelligence. PMLR 313--323."},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140448"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.195"},{"key":"e_1_3_2_1_10_1","volume-title":"International Conference on Machine Learning. PMLR","author":"Chrysakis Aristotelis","year":"2020","unstructured":"Aristotelis Chrysakis and Marie-Francine Moens. 2020. Online continual learning from imbalanced data. In International Conference on Machine Learning. PMLR, 1952--1961."},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01543"},{"key":"e_1_3_2_1_12_1","first-page":"12881","article-title":"Make some noise: Reliable and efficient single-step adversarial training","volume":"35","author":"de Jorge Aranda Pau","year":"2022","unstructured":"Pau de Jorge Aranda, Adel Bibi, Riccardo Volpi, Amartya Sanyal, Philip Torr, Gr\u00e9gory Rogez, and Puneet Dokania. 2022. Make some noise: Reliable and efficient single-step adversarial training. Advances in Neural Information Processing Systems 35 (2022), 12881--12893.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_1_13_1","first-page":"33676","article-title":"Random normalization aggregation for adversarial defense","volume":"35","author":"Dong Minjing","year":"2022","unstructured":"Minjing Dong, Xinghao Chen, Yunhe Wang, and Chang Xu. 2022. Random normalization aggregation for adversarial defense. Advances in Neural Information Processing Systems 35 (2022), 33676--33688.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"e_1_3_2_1_15_1","volume-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition. 6360--6370","author":"Escalera Sergio","year":"2023","unstructured":"Sergio Escalera, Hugo Jair Escalante, Zhen Lei, Hao Fang, Ajian Liu, and Jun Wan. 2023. Surveillance Face Presentation Attack Detection Challenge. In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition. 6360--6370."},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW59228.2023.00113"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.01574"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.00396"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.01723"},{"key":"e_1_3_2_1_20_1","volume-title":"Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572","author":"Goodfellow Ian J","year":"2014","unstructured":"Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy. 2014. Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572 (2014)."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"crossref","unstructured":"Choi J. Lee H. Kim Han G. and J. 2023. Reinforcement learning-based black-box model inversion attacks. In CVPR. 20504--20513.","DOI":"10.1109\/CVPR52729.2023.01964"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"e_1_3_2_1_23_1","first-page":"23818","article-title":"DISCO: Adversarial defense with local implicit functions","volume":"35","author":"Ho Chih-Hui","year":"2022","unstructured":"Chih-Hui Ho and Nuno Vasconcelos. 2022. DISCO: Adversarial defense with local implicit functions. Advances in Neural Information Processing Systems 35 (2022), 23818--23837.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.02363"},{"key":"e_1_3_2_1_25_1","volume-title":"picking and growing for unforgetting continual learning. Advances in neural information processing systems 32","author":"Hung Ching-Yi","year":"2019","unstructured":"Ching-Yi Hung, Cheng-HaoTu,Cheng-EnWu,Chien-HungChen,Yi-MingChan, and Chu-Song Chen. 2019. Compacting, picking and growing for unforgetting continual learning. Advances in neural information processing systems 32 (2019)."},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.01576"},{"key":"e_1_3_2_1_27_1","volume-title":"Torchattacks: A pytorch repository for adversarial attacks. arXiv preprint arXiv:2010.01950","author":"Kim Hoki","year":"2020","unstructured":"Hoki Kim. 2020. Torchattacks: A pytorch repository for adversarial attacks. arXiv preprint arXiv:2010.01950 (2020)."},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.01184"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.01148"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1073\/pnas.1611835114"},{"key":"e_1_3_2_1_31_1","unstructured":"Alex Krizhevsky Geoffrey Hinton et al. 2009. Learning multiple layers of features from tiny images. (2009)."},{"key":"e_1_3_2_1_32_1","volume-title":"Adversarial machine learning at scale. arXiv preprint arXiv:1611.01236","author":"Kurakin Alexey","year":"2016","unstructured":"Alexey Kurakin, Ian Goodfellow, and Samy Bengio. 2016. Adversarial machine learning at scale. arXiv preprint arXiv:1611.01236 (2016)."},{"volume-title":"Artificial intelligence safety and security","author":"Kurakin Alexey","key":"e_1_3_2_1_33_1","unstructured":"Alexey Kurakin, Ian J Goodfellow, and Samy Bengio. 2018. Adversarial examples in the physical world. In Artificial intelligence safety and security. Chapman and Hall\/CRC, 99--112."},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2022.109229"},{"key":"e_1_3_2_1_35_1","volume-title":"International conference on machine learning. PMLR, 3925--3934","author":"Li Xilai","year":"2019","unstructured":"Xilai Li, Yingbo Zhou, Tianfu Wu, Richard Socher, and Caiming Xiong. 2019. Learn to grow: A continual structure learning framework for overcoming catastrophic forgetting. In International conference on machine learning. PMLR, 3925--3934."},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.00730"},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.02322"},{"key":"e_1_3_2_1_38_1","volume-title":"Nesterov accelerated gradient and scale invariance for adversarial attacks. arXiv preprint arXiv:1908.06281","author":"Lin Jiadong","year":"2019","unstructured":"Jiadong Lin, Chuanbiao Song, Kun He, Liwei Wang, and John E Hopcroft. 2019. Nesterov accelerated gradient and scale invariance for adversarial attacks. arXiv preprint arXiv:1908.06281 (2019)."},{"key":"e_1_3_2_1_39_1","volume-title":"Efficient algorithms for t-distributed stochastic neighborhood embedding. arXiv preprint arXiv:1712.09005","author":"Linderman George C","year":"2017","unstructured":"George C Linderman, Manas Rachh, Jeremy G Hoskins, Stefan Steinerberger, and Yuval Kluger. 2017. Efficient algorithms for t-distributed stochastic neighborhood embedding. arXiv preprint arXiv:1712.09005 (2017)."},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.01462"},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00016"},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDM.2015.84"},{"key":"e_1_3_2_1_43_1","volume-title":"Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083","author":"Madry Aleksander","year":"2017","unstructured":"Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and AdrianVladu.2017. Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083 (2017)."},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00419"},{"key":"e_1_3_2_1_45_1","volume-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition. 16026--16035","author":"Nie Xing","year":"2023","unstructured":"Xing Nie, Shixiong Xu, Xiyan Liu, Gaofeng Meng, Chunlei Huo, and Shiming Xiang. 2023. Bilateral memoryconsolidation for continual learning. In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition. 16026--16035."},{"key":"e_1_3_2_1_46_1","volume-title":"International Conference on Machine Learning. PMLR, 17258--17277","author":"Pang Tianyu","year":"2022","unstructured":"Tianyu Pang, Min Lin, Xiao Yang, Jun Zhu, and Shuicheng Yan. 2022. Robustness and accuracy could be reconcilable by (proper) definition. In International Conference on Machine Learning. PMLR, 17258--17277."},{"key":"e_1_3_2_1_47_1","volume-title":"Transferability in machine learning: from phenomena to black-box attacks using adversarial samples. arXiv preprint arXiv:1605.07277","author":"Papernot Nicolas","year":"2016","unstructured":"Nicolas Papernot, Patrick McDaniel, and Ian Goodfellow. 2016. Transferability in machine learning: from phenomena to black-box attacks using adversarial samples. arXiv preprint arXiv:1605.07277 (2016)."},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"e_1_3_2_1_50_1","volume-title":"Leader-based multi-scale attention deep architecture for person re-identification","author":"Qian Xuelin","year":"2019","unstructured":"Xuelin Qian, Yanwei Fu, Tao Xiang, Yu-Gang Jiang, and Xiangyang Xue. 2019. Leader-based multi-scale attention deep architecture for person re-identification. IEEE transactions on pattern analysis and machine intelligence 42, 2 (2019), 371--385."},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1109\/WACV56688.2023.00424"},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00018"},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1145\/3474369.3486878"},{"key":"e_1_3_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.02365"},{"key":"e_1_3_2_1_55_1","first-page":"27075","article-title":"Exploring example influence in continual learning","volume":"35","author":"Sun Qing","year":"2022","unstructured":"Qing Sun, Fan Lyu, Fanhua Shang, Wei Feng, and Liang Wan. 2022. Exploring example influence in continual learning. Advances in Neural Information Processing Systems 35 (2022), 27075--27086.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00405"},{"volume-title":"Proceedings of the IEEE\/CVF International Conference on Computer Vision. 14340--14350","author":"Tao Yunbo","key":"e_1_3_2_1_57_1","unstructured":"Yunbo Tao,Daizong Liu,Pan Zhou,Yulai Xie,Wei Du,and Wei Hu.2023. 3dhacker: Spectrum-based decision boundary generation for hard-label 3d point cloud attack. In Proceedings of the IEEE\/CVF International Conference on Computer Vision. 14340--14350."},{"key":"e_1_3_2_1_58_1","volume-title":"Ensemble adversarial training: Attacks and defenses. arXiv preprint arXiv:1705.07204","author":"Tram\u00e8r Florian","year":"2017","unstructured":"Florian Tram\u00e8r, Alexey Kurakin, Nicolas Papernot, Ian Goodfellow, Dan Boneh, and Patrick McDaniel. 2017. Ensemble adversarial training: Attacks and defenses. arXiv preprint arXiv:1705.07204 (2017)."},{"key":"e_1_3_2_1_59_1","volume-title":"Continual Adversarial Defense. arXiv preprint arXiv:2312.09481","author":"Wang Qian","year":"2023","unstructured":"Qian Wang, Yaoyao Liu, Hefei Ling, Yingwei Li, Qihao Liu, Ping Li, Jiazhong Chen, Alan Yuille, and Ning Yu. 2023. Continual Adversarial Defense. arXiv preprint arXiv:2312.09481 (2023)."},{"volume-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition. 14361--14370","author":"Wang Wenxuan","key":"e_1_3_2_1_60_1","unstructured":"Wenxuan Wang,Xuelin Qian,Yanwei Fu,and Xiangyang Xue.2022. Dst:Dynamic substitute training for data-free black-box attack. In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition. 14361--14370."},{"key":"e_1_3_2_1_61_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00473"},{"key":"e_1_3_2_1_62_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00196"},{"key":"e_1_3_2_1_63_1","volume-title":"International conference on learning representations.","author":"Wang Yisen","year":"2019","unstructured":"Yisen Wang, Difan Zou, Jinfeng Yi, James Bailey, Xingjun Ma, and Quanquan Gu. 2019. Improving adversarial robustness requires revisiting misclassified examples. In International conference on learning representations."},{"key":"e_1_3_2_1_64_1","volume-title":"Betterdiffusionmodelsfurtherimproveadversarialtraining.InInternational Conference on Machine Learning. PMLR, 36246--36263","author":"Wang Zekai","year":"2023","unstructured":"Zekai Wang, Tianyu Pang, Chao Du, Min Lin, Weiwei Liu, and Shuicheng Yan. 2023. Betterdiffusionmodelsfurtherimproveadversarialtraining.InInternational Conference on Machine Learning. PMLR, 36246--36263."},{"key":"e_1_3_2_1_65_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.01720"},{"key":"e_1_3_2_1_66_1","volume-title":"Adversarial weight perturbation helps robust generalization. Advances in neural information processing systems 33","author":"Wu Dongxian","year":"2020","unstructured":"Dongxian Wu, Shu-Tao Xia, and Yisen Wang. 2020. Adversarial weight perturbation helps robust generalization. Advances in neural information processing systems 33 (2020), 2958--2969."},{"key":"e_1_3_2_1_67_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00891"},{"key":"e_1_3_2_1_68_1","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2021\/173"},{"key":"e_1_3_2_1_69_1","volume-title":"Bitfit: Simple parameter-efficient fine-tuning for transformer-based masked language-models. arXiv preprint arXiv:2106.10199","author":"Zaken Elad Ben","year":"2021","unstructured":"Elad Ben Zaken, Shauli Ravfogel, and Yoav Goldberg. 2021. Bitfit: Simple parameter-efficient fine-tuning for transformer-based masked language-models. arXiv preprint arXiv:2106.10199 (2021)."},{"key":"e_1_3_2_1_70_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.01733"},{"key":"e_1_3_2_1_71_1","volume-title":"International conference on machine learning. PMLR, 7472--7482","author":"Zhang Hongyang","year":"2019","unstructured":"Hongyang Zhang, Yaodong Yu, Jiantao Jiao, Eric Xing, Laurent El Ghaoui, and Michael Jordan. 2019. Theoretically principled trade-off between robustness and accuracy. In International conference on machine learning. PMLR, 7472--7482."},{"key":"e_1_3_2_1_72_1","volume-title":"International conference on machine learning. PMLR, 11278--11287","author":"Zhang Jingfeng","year":"2020","unstructured":"Jingfeng Zhang, Xilie Xu, Bo Han, Gang Niu, Lizhen Cui, Masashi Sugiyama, and Mohan Kankanhalli. 2020. Attacks which do not kill training make adversarial learning stronger. In International conference on machine learning. PMLR, 11278--11287."},{"volume-title":"Proceedings of the IEEE conference on computer vision and pattern recognition. 6848--6856","author":"Zhang Xiangyu","key":"e_1_3_2_1_73_1","unstructured":"Xiangyu Zhang,Xinyu Zhou,Mengxiao Lin,and Jian Sun.2018. Shufflenet:An extremely efficient convolutional neural network for mobile devices. In Proceedings of the IEEE conference on computer vision and pattern recognition. 6848--6856."},{"key":"e_1_3_2_1_74_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00435"},{"key":"e_1_3_2_1_75_1","unstructured":"Hu-X. Wang J. Xie X. Yang Zhu K. and G. 2023. Improving generalization of adversarial training via robust critical fine-tuning. In CVPR. 4424--4434."},{"key":"e_1_3_2_1_76_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW59228.2023.00236"}],"event":{"name":"MM '24: The 32nd ACM International Conference on Multimedia","sponsor":["SIGMM ACM Special Interest Group on Multimedia"],"location":"Melbourne VIC Australia","acronym":"MM '24"},"container-title":["Proceedings of the 32nd ACM International Conference on Multimedia"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3664647.3681077","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3664647.3681077","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T00:57:52Z","timestamp":1750294672000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3664647.3681077"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,10,28]]},"references-count":76,"alternative-id":["10.1145\/3664647.3681077","10.1145\/3664647"],"URL":"https:\/\/doi.org\/10.1145\/3664647.3681077","relation":{},"subject":[],"published":{"date-parts":[[2024,10,28]]},"assertion":[{"value":"2024-10-28","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}