{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,5]],"date-time":"2026-06-05T16:10:14Z","timestamp":1780675814618,"version":"3.54.1"},"reference-count":80,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2023,3,10]],"date-time":"2023-03-10T00:00:00Z","timestamp":1678406400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2023,3,10]],"date-time":"2023-03-10T00:00:00Z","timestamp":1678406400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["EURASIP J. on Info. Security"],"abstract":"<jats:title>Abstract<\/jats:title><jats:p>In this work, we present the Gaussian Class-Conditional Simplex (GCCS) loss: a novel approach for training deep robust multiclass classifiers that improves over the state-of-the-art in terms of classification accuracy and adversarial robustness, with little extra cost for network training. The proposed method learns a mapping of the input classes onto Gaussian target distributions in a latent space such that a hyperplane can be used as the optimal decision surface. Instead of maximizing the likelihood of target labels for individual samples, our loss function pushes the network to produce feature distributions yielding high inter-class separation and low intra-class separation. The mean values of the learned distributions are centered on the vertices of a simplex such that each class is at the same distance from every other class. We show that the regularization of the latent space based on our approach yields excellent classification accuracy. Moreover, GCCS provides improved robustness against adversarial perturbations, outperforming models trained with conventional adversarial training (AT). In particular, our model learns a decision space that minimizes the presence of short paths toward neighboring decision regions. We provide a comprehensive empirical evaluation that shows how GCCS outperforms state-of-the-art approaches over challenging datasets for targeted and untargeted gradient-based, as well as gradient-free adversarial attacks, both in terms of classification accuracy and adversarial robustness.<\/jats:p>","DOI":"10.1186\/s13635-023-00137-0","type":"journal-article","created":{"date-parts":[[2023,3,26]],"date-time":"2023-03-26T20:21:48Z","timestamp":1679862108000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Gaussian class-conditional simplex loss for accurate, adversarially robust deep classifier training"],"prefix":"10.1186","volume":"2023","author":[{"given":"Arslan","family":"Ali","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9239-0568","authenticated-orcid":false,"given":"Andrea","family":"Migliorati","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Tiziano","family":"Bianchi","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Enrico","family":"Magli","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2023,3,10]]},"reference":[{"key":"137_CR1","unstructured":"A. Kirzhevsky, I. Sutskever, G. E. Hinton,\u00a0Imagenet classification with deep convolutional neural networks.\u00a0Adv. Neural. Inf. Process. Syst,\u00a025, 1097\u20131105 (2012)"},{"key":"137_CR2","unstructured":"L. Wan, M. Zeiler, S. Zhang, Y. Le Cun, R. Fergus, Regularization of neural networks using dropconnect. In International conference on machine learning (2013) pp. 1058\u20131066. PMLR"},{"key":"137_CR3","unstructured":"J. Y. Zhu, R. Zhang, D. Pathak, T. Darrell, A. A. Efros, O. Wang, & E. Shechtman,\u00a0Toward multimodal image-to-image translation.\u00a0Adv. Neural. Inf. Process. Syst,\u00a030 (2017)"},{"key":"137_CR4","unstructured":"A. Gonzalez-Garcia, J. Van De Weijer, Y. Bengio, Image-to-image translation for cross-domain disentanglement.\u00a0Adv. Neural. Inf. Process. Syst.\u00a031,\u00a01287\u20131298 (2018)"},{"key":"137_CR5","doi-asserted-by":"crossref","unstructured":"M. Uric\u00e1r, P. Krizek, D. Hurych, I. Sobh, S. Yogamani, P. Denny,Yes, we gan: Applying adversarial techniques for autonomous driving. arXiv preprint. (2019). arXiv:1902.03442","DOI":"10.2352\/ISSN.2470-1173.2019.15.AVM-048"},{"key":"137_CR6","doi-asserted-by":"crossref","unstructured":"K. Eykholt, I. Evtimov, E. Fernandes, B. Li, A. Rahmati, C. Xiao, ... D. Song, Robust physical-world attacks on deep learning visual classification. In Proceedings of the IEEE conference on computer vision and pattern recognition. (2018), pp. 1625\u20131634","DOI":"10.1109\/CVPR.2018.00175"},{"key":"137_CR7","doi-asserted-by":"crossref","unstructured":"S. G. Finlayson, J. D. Bowers, J. Ito, J. L. Zittrain, A. L., Beam, I. S. Kohane, Adversarial attacks on medical machine learning. Science, 363(6433), 1287-1289 (2019)","DOI":"10.1126\/science.aaw4399"},{"key":"137_CR8","doi-asserted-by":"crossref","unstructured":"T. Zheng, C. Chen, K. Ren, Distributionally adversarial attack. In Proceedings of the AAAI Conference on Artificial Intelligence,\u00a033(01), 2253\u20132260) (2019)","DOI":"10.1609\/aaai.v33i01.33012253"},{"key":"137_CR9","unstructured":"H. Zhang, H. Chen, Z. Song, D. Boning, I.S. Dhillon, C.J. Hsieh, The limitations of adversarial training and the blind-spot attack. (2019). arXiv preprint arXiv:1901.04684"},{"key":"137_CR10","unstructured":"A. Raghunathan, J. Steinhardt, P. Liang, Certified defenses against adversarial examples. (2018). arXiv preprint arXiv:1801.09344"},{"key":"137_CR11","unstructured":"E. Wong, Z. Kolter, Provable defenses against adversarial examples via the convex outer adversarial polytope. In International conference on machine learning. (2018), pp. 5286\u20135295. PMLR"},{"key":"137_CR12","doi-asserted-by":"crossref","unstructured":"M. Lecuyer, V. Atlidakis, R. Geambasu, D. Hsu, S. Jana, Certified robustness to adversarial examples with differential privacy. In 2019 IEEE Symposium on Security and Privacy (SP). (2019), p. 656\u2013672. IEEE","DOI":"10.1109\/SP.2019.00044"},{"key":"137_CR13","doi-asserted-by":"crossref","unstructured":"Y. Dong, Q.A. Fu, X. Yang, T. Pang, H. Su, Z. Xiao, J. Zhu, in Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, Benchmarking adversarial robustness on image classification (2020), pp. 321\u2013331","DOI":"10.1109\/CVPR42600.2020.00040"},{"issue":"6","key":"137_CR14","doi-asserted-by":"publisher","first-page":"50","DOI":"10.1109\/MSP.2017.2740965","volume":"34","author":"A Fawzi","year":"2017","unstructured":"A. Fawzi, S. Moosavi-Dezfooli, P. Frossard, The robustness of deep networks: A geometrical perspective. IEEE Signal Process. Mag. 34(6), 50\u201362 (2017). https:\/\/doi.org\/10.1109\/MSP.2017.2740965","journal-title":"IEEE Signal Process. Mag."},{"key":"137_CR15","unstructured":"M. Khoury, D. Hadfield-Menell, On the geometry of adversarial examples. (2018). arXiv preprint arXiv:1811.00525"},{"key":"137_CR16","unstructured":"A. Madry, A. Makelov, L. Schmidt, D. Tsipras, A. Vladu, Towards deep learning models resistant to adversarial attacks. (2017). arXiv preprint arXiv:1706.06083"},{"key":"137_CR17","unstructured":"F. Tram\u00e8r, A. Kurakin, N. Papernot, I. Goodfellow, D. Boneh, P. McDaniel, Ensemble adversarial training: Attacks and defenses. (2017). arXiv preprint arXiv:1705.07204"},{"key":"137_CR18","doi-asserted-by":"crossref","unstructured":"O. Poursaeed, I. Katsman, B. Gao, S. Belongie, Generative adversarial perturbations. In Proceedings of the IEEE conference on computer vision and pattern recognition. (2018), pp. 4422\u20134431","DOI":"10.1109\/CVPR.2018.00465"},{"key":"137_CR19","doi-asserted-by":"crossref","unstructured":"S. M.Moosavi-Dezfooli, A. Fawzi, J. Uesato, P. Frossard, Robustness via curvature regularization, and vice versa. In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition. (2019), pp. 9078\u20139086","DOI":"10.1109\/CVPR.2019.00929"},{"key":"137_CR20","unstructured":"C. Summers, M.J. Dinneen, Improved adversarial robustness via logit regularization methods. (2019). arXiv preprint arXiv:1906.03749"},{"key":"137_CR21","unstructured":"R. Pinot, L. Meunier, A. Araujo, H. Kashima, F. Yger, C. Gouy-Pailler, J. Atif, Theoretical evidence for adversarial robustness through randomization. Adv. Neural. Inf. Process. Syst, 32, pp. 11838\u201311848 (2019)"},{"key":"137_CR22","unstructured":"Y. Carmon, A. Raghunathan, L. Schmidt, J.C. Duchi, P.S. Liang, in Advances in Neural Information Processing Systems. Unlabeled data improves adversarial robustness (2019), pp. 11190\u201311201"},{"key":"137_CR23","unstructured":"A. Araujo, L. Meunier, R. Pinot, B. Negrevergne, Robust neural networks using randomized adversarial training. (2019). arXiv preprint arXiv:1903.10219"},{"key":"137_CR24","unstructured":"R. Pinot, R. Ettedgui, G. Rizk, Y. Chevaleyre, J. Atif, Randomization matters. How to defend against strong adversarial attacks. (2020). arXiv preprint arXiv:2002.11565"},{"key":"137_CR25","doi-asserted-by":"crossref","unstructured":"A. Ali, A. Migliorati, T. Bianchi, E. Magli, Beyond cross-entropy: learning highly separable feature distributions for robust and accurate classification. In 2020 25th International Conference on Pattern Recognition (ICPR). (2021), pp. 9711\u20139718). IEEE","DOI":"10.1109\/ICPR48806.2021.9412277"},{"key":"137_CR26","doi-asserted-by":"crossref","unstructured":"Y. LeCun, L. Bottou, Y. Bengio, P. Haffner, Gradient-based learning applied to document recognition. Proc. IEEE, 86(11), 2278\u20132324 (1998)","DOI":"10.1109\/5.726791"},{"key":"137_CR27","unstructured":"H. Xiao, K. Rasul, R. Vollgraf, Fashion-mnist: a novel image dataset for benchmarking machine learning algorithms. (2017). arXiv preprint arXiv:1708.07747"},{"key":"137_CR28","unstructured":"Y. Netzer, T. Wang, A. Coates, A., Bissacco, B. Wu, A. Y. Ng, Reading digits in natural images with unsupervised feature learning. (2011)"},{"key":"137_CR29","unstructured":"A. Krizhevsky, G. Hinton et al., Learning multiple layers of features from tiny images. Technical report, Citeseer, (2009)"},{"key":"137_CR30","unstructured":"A. Kurakin, I. Goodfellow, S. Bengio, Adversarial examples in the physical world. (2016). arXiv preprint arXiv:1607.02533"},{"key":"137_CR31","doi-asserted-by":"crossref","unstructured":"N. Papernot, P. McDaniel, S. Jha, M. Fredrikson, Z. B. Celik, A. Swami, The limitations of deep learning in adversarial settings. In 2016 IEEE European symposium on security and privacy (EuroS&P). (2016), pp. 372\u2013387. IEEE","DOI":"10.1109\/EuroSP.2016.36"},{"key":"137_CR32","doi-asserted-by":"crossref","unstructured":"S. M. Moosavi-Dezfooli, A. Fawzi, P. Frossard, Deepfool: a simple and accurate method to fool deep neural networks. In Proceedings of the IEEE conference on computer vision and pattern recognition. (2016), pp. 2574\u20132582","DOI":"10.1109\/CVPR.2016.282"},{"key":"137_CR33","unstructured":"C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, R. Fergus, Intriguing properties of neural networks. (2013). arXiv preprint arXiv:1312.6199"},{"key":"137_CR34","unstructured":"J. Uesato, B. O\u2019donoghue, P. Kohli, A. Oord, Adversarial risk and the dangers of evaluating against weak attacks. In International Conference on Machine Learning. (2018),\u00a0pp. 5025-5034. PMLR"},{"key":"137_CR35","doi-asserted-by":"crossref","unstructured":"N. Carlini, D. Wagner, Adversarial examples are not easily detected: Bypassing ten detection methods. In Proceedings of the 10th ACM workshop on artificial intelligence and security. (2017), pp. 3\u201314","DOI":"10.1145\/3128572.3140444"},{"key":"137_CR36","unstructured":"N. Carlini, A. Athalye, N. Papernot, W. Brendel, J. Rauber, D. Tsipras, I. Goodfellow, A. Madry, A. Kurakin, On evaluating adversarial robustness. (2019). arXiv preprint arXiv:1902.06705"},{"key":"137_CR37","doi-asserted-by":"crossref","unstructured":"N. Dalvi, P. Domingos, S. Sanghai, D. Verma, Adversarial classification. In Proceedings of the tenth ACM SIGKDD international conference on Knowledge discovery and data mining. (2004), pp. 99\u2013108","DOI":"10.1145\/1014052.1014066"},{"key":"137_CR38","doi-asserted-by":"crossref","unstructured":"D. Lowd, C. Meek, Adversarial learning. In Proceedings of the eleventh ACM SIGKDD international conference on Knowledge discovery in data mining. (2005), pp. 641\u2013647","DOI":"10.1145\/1081870.1081950"},{"key":"137_CR39","doi-asserted-by":"crossref","unstructured":"M. Barreno, B. Nelson, A. D. Joseph, J. D. Tygar, The security of machine learning.\u00a0Mach. Learn, 81, 121\u2013148 (2010)","DOI":"10.1007\/s10994-010-5188-5"},{"key":"137_CR40","unstructured":"A. Ilyas, S. Santurkar, D. Tsipras, L. Engstrom, B. Tran, A. Madry, in Advances in Neural Information Processing Systems, Adversarial examples are not bugs, they are features (2019)"},{"key":"137_CR41","unstructured":"J. Cohen, E. Rosenfeld, Z. Kolter, Certified adversarial robustness via randomized smoothing. In international conference on machine learning. (2019), pp. 1310\u20131320. PMLR"},{"key":"137_CR42","doi-asserted-by":"crossref","unstructured":"M. Sharif, S. Bhagavatula, L. Bauer, M. K. Reiter, Accessorize to a crime: Real and stealthy attacks on state-of-the-art face recognition. In Proceedings of the 2016 acm sigsac conference on computer and communications security. (2016), pp. 1528-1540","DOI":"10.1145\/2976749.2978392"},{"key":"137_CR43","unstructured":"A. Athalye, L. Engstrom, A. Ilyas, K. Kwok, Synthesizing robust adversarial examples. In International conference on machine learning. (2018),\u00a0pp. 284\u2013293. PMLR"},{"key":"137_CR44","doi-asserted-by":"crossref","unstructured":"A. Ross, F. Doshi-Velez, Improving the adversarial robustness and interpretability of deep neural networks by regularizing their input gradients. In Proceedings of the AAAI Conference on Artificial Intelligence 32(1), (2018)","DOI":"10.1609\/aaai.v32i1.11504"},{"key":"137_CR45","unstructured":"T.B. Brown, D. Man\u00e9, A. Roy, M. Abadi, J. Gilmer, Adversarial patch. (2017). arXiv preprint arXiv:1712.09665"},{"key":"137_CR46","unstructured":"S. Bhambri, S. Muku, A. Tulasi, A. Balaji Buduru, A survey of black-box adversarial attacks on computer vision models. (2019). arXiv"},{"key":"137_CR47","doi-asserted-by":"crossref","unstructured":"S. Lee, H. Lee, S. Yoon, Adversarial vertex mixup: Toward better adversarially robust generalization. In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition. (2020), pp. 272\u2013281","DOI":"10.1109\/CVPR42600.2020.00035"},{"key":"137_CR48","unstructured":"A. Athalye, N. Carlini, D. Wagner, Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples. In International conference on machine learning. (2018), pp. 274\u2013283. PMLR"},{"key":"137_CR49","unstructured":"A. Shafahi, W.R. Huang, C. Studer, S. Feizi, T. Goldstein, Are adversarial examples inevitable? (2018). arXiv preprint"},{"key":"137_CR50","unstructured":"D. Tsipras, S. Santurkar, L. Engstrom, A. Turner, A. Madry, Robustness may be at odds with accuracy. (2018). arXiv preprint arXiv:1805.12152."},{"key":"137_CR51","doi-asserted-by":"crossref","unstructured":"D. Stutz, M. Hein, B. Schiele, Disentangling adversarial robustness and generalization. In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition. (2019),\u00a0pp. 6976\u20136987","DOI":"10.1109\/CVPR.2019.00714"},{"key":"137_CR52","unstructured":"M. Hein, M. Andriushchenko, Formal guarantees on the robustness of a classifier against adversarial manipulation. Advances in neural information processing systems, 30, 6976\u20136987 (2017)"},{"key":"137_CR53","doi-asserted-by":"crossref","unstructured":"D. Jakubovitz, R. Giryes, in Proceedings of the European Conference on Computer Vision (ECCV), Improving dnn robustness to adversarial attacks using jacobian regularization (2018), pp. 514\u2013529","DOI":"10.1007\/978-3-030-01258-8_32"},{"key":"137_CR54","unstructured":"J. Hoffman, D.A. Roberts, S. Yaida, Robust learning with jacobian regularization. (2019). arXiv preprint arXiv:1908.02729"},{"key":"137_CR55","unstructured":"I.J. Goodfellow, J. Shlens, C. Szegedy, Explaining and harnessing adversarial examples. (2014). arXiv preprint arXiv:1412.6572"},{"key":"137_CR56","unstructured":"R. Huang, B. Xu, D. Schuurmans, C. Szepesv\u00e1ri, Learning with a strong adversary. (2015). arXiv preprint arXiv:1511.03034"},{"key":"137_CR57","doi-asserted-by":"crossref","unstructured":"N. Papernot, P. McDaniel, X. Wu, S. Jha, A. Swami, Distillation as a defense to adversarial perturbations against deep neural networks. In 2016 IEEE symposium on security and privacy (SP). (2016), pp. 582\u2013597. IEEE","DOI":"10.1109\/SP.2016.41"},{"key":"137_CR58","unstructured":"Y. Liu, X. Chen, C. Liu, D. Song, Delving into transferable adversarial examples and black-box attacks. (2016). arXiv preprint"},{"key":"137_CR59","doi-asserted-by":"crossref","unstructured":"S. M. Moosavi-Dezfooli, A. Fawzi, O. Fawzi, P. Frossard, Universal adversarial perturbations. In Proceedings of the IEEE conference on computer vision and pattern recognition. (2017), pp. 1765\u20131773.","DOI":"10.1109\/CVPR.2017.17"},{"key":"137_CR60","unstructured":"A. Shafahi, M. Najibi, M. A. Ghiasi, Z. Xu, J. Dickerson, C. Studer, ... T. Goldstein, Adversarial training for free!\u00a0Adv. Neural. Inf. Process. Syst, 32, (2019)"},{"key":"137_CR61","unstructured":"D.P. Kingma, M. Welling, Auto-encoding variational bayes. (2013). arXiv preprint arXiv:1312.6114"},{"key":"137_CR62","unstructured":"A. Makhzani, J. Shlens, N. Jaitly, I. Goodfellow, B. Frey, Adversarial autoencoders. (2015). arXiv preprint arXiv:1511.05644"},{"key":"137_CR63","volume-title":"Discriminant analysis for dimensionality reduction: An overview of recent developments. Biometrics: Theory, Methods, and Applications","author":"J Ye","year":"2010","unstructured":"J. Ye, S. Ji, Discriminant analysis for dimensionality reduction: An overview of recent developments. Biometrics: Theory, Methods, and Applications (Wiley-IEEE Press, New York, 2010)"},{"issue":"4","key":"137_CR64","doi-asserted-by":"publisher","first-page":"596","DOI":"10.1109\/TNNLS.2012.2183645","volume":"23","author":"A Stuhlsatz","year":"2012","unstructured":"A. Stuhlsatz, J. Lippel, T. Zielke, Feature extraction with deep neural networks by a generalized discriminant analysis. IEEE Trans. Neural Netw. Learn. Syst. 23(4), 596\u2013608 (2012)","journal-title":"IEEE Trans. Neural Netw. Learn. Syst."},{"key":"137_CR65","unstructured":"M. Dorfer, R. Kelz, G. Widmer, Deep linear discriminant analysis. (2015). arXiv preprint arXiv:1511.04707"},{"key":"137_CR66","doi-asserted-by":"crossref","unstructured":"M. Testa, A. Ali, T. Bianchi, E. Magli, Learning mappings onto regularized latent spaces for biometric authentication. In 2019 IEEE 21st International Workshop on Multimedia Signal Processing (MMSP). (2019),\u00a0pp. 1-6. IEEE","DOI":"10.1109\/MMSP.2019.8901698"},{"key":"137_CR67","doi-asserted-by":"crossref","unstructured":"Ali, A., Testa, M., Bianchi, T., & Magli, E. (2019). Authnet: Biometric authentication through adversarial learning. In 2019 IEEE 29th International Workshop on Machine Learning for Signal Processing (MLSP) (pp. 1\u20136). IEEE.","DOI":"10.1109\/MLSP.2019.8918810"},{"key":"137_CR68","doi-asserted-by":"crossref","unstructured":"Ali, A., Testa, M., Bianchi, T., & Magli, E. (2020). Biometricnet: deep unconstrained face verification through learning of metrics regularized onto gaussian distributions. In Computer Vision\u2013ECCV 2020: 16th European Conference, Glasgow, UK, August 23\u201328, 2020, Proceedings, Part XXV 16 (pp. 133\u2013149). Springer International Publishing.","DOI":"10.1007\/978-3-030-58595-2_9"},{"key":"137_CR69","doi-asserted-by":"crossref","unstructured":"W. Wan, Y. Zhong, T. Li, J. Chen, Rethinking feature distribution for loss functions in image classification. In Proceedings of the IEEE conference on computer vision and pattern recognition. (2018),\u00a0pp. 9117\u20139126","DOI":"10.1109\/CVPR.2018.00950"},{"key":"137_CR70","unstructured":"T. Pang, K. Xu, Y. Dong, C. Du, N. Chen, J. Zhu, Rethinking softmax cross-entropy loss for adversarial robustness. (2019). arXiv preprint arXiv:1905.10626"},{"key":"137_CR71","doi-asserted-by":"crossref","unstructured":"D. N. Joanes, C. A. Gill, Comparing measures of sample skewness and kurtosis.\u00a0J. R. Stat. Soc.: Series D (The Statistician), 47(1), 183\u2013189 (1998)","DOI":"10.1111\/1467-9884.00122"},{"key":"137_CR72","doi-asserted-by":"crossref","unstructured":"He, K., Zhang, X., Ren, S., & Sun, J. (2016). Deep residual learning for image recognition. In Proceedings of the IEEE conference on computer vision and pattern recognition (pp. 770\u2013778).","DOI":"10.1109\/CVPR.2016.90"},{"key":"137_CR73","unstructured":"X. Gastaldi, Shake-shake regularization. (2017). arXiv preprint arXiv:1705.07485"},{"key":"137_CR74","unstructured":"A. Gotmare, N.S. Keskar, C. Xiong, R. Socher, A closer look at deep learning heuristics: Learning rate restarts, warmup and distillation. (2018). arXiv preprint arXiv:1810.13243"},{"key":"137_CR75","unstructured":"N. Srivastava, G. Hinton, A. Krizhevsky, I. Sutskever, R. Salakhutdinov, Dropout: a simple way to prevent neural networks from overfitting.\u00a0J. Mach. Learn. Res, 15(1), 1929\u20131958\u00a0(2014)"},{"key":"137_CR76","doi-asserted-by":"crossref","unstructured":"Y. Luo, Y. Wong, M. Kankanhalli, Q. Zhao, G-softmax: improving intraclass compactness and interclass separability of features.\u00a0IEEE Trans. Neural Netw. Learn. Syst, 31(2), 685\u2013699 (2019)","DOI":"10.1109\/TNNLS.2019.2909737"},{"key":"137_CR77","unstructured":"T. Zheng, C. Chen, K. Ren, Is pgd-adversarial training necessary? Alternative training via a soft-quantization network with noisy-natural samples only. (2018). arXiv preprint arXiv:1810.05665"},{"key":"137_CR78","unstructured":"T. Davchev, T. Korres, S. Fotiadis, N. Antonopoulos, S. Ramamoorthy, An empirical evaluation of adversarial robustness under transfer learning. (2019). arXiv preprint arXiv:1905.02675"},{"issue":"3","key":"137_CR79","doi-asserted-by":"publisher","first-page":"332","DOI":"10.1109\/9.119632","volume":"37","author":"JC Spall","year":"1992","unstructured":"J.C. Spall et al., Multivariate stochastic approximation using a simultaneous perturbation gradient approximation. IEEE Trans. Autom. Control 37(3), 332\u2013341 (1992)","journal-title":"IEEE Trans. Autom. Control"},{"key":"137_CR80","unstructured":"H. Zhang, Y. Yu, J. Jiao, E.P. Xing, L.E. Ghaoui, M.I. Jordan, Theoretically principled trade-off between robustness and accuracy. (2019). arXiv preprint arXiv:1901.08573"}],"container-title":["EURASIP Journal on Information Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s13635-023-00137-0.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1186\/s13635-023-00137-0\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s13635-023-00137-0.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,3,26]],"date-time":"2023-03-26T20:24:21Z","timestamp":1679862261000},"score":1,"resource":{"primary":{"URL":"https:\/\/jis-eurasipjournals.springeropen.com\/articles\/10.1186\/s13635-023-00137-0"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,3,10]]},"references-count":80,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2023,12]]}},"alternative-id":["137"],"URL":"https:\/\/doi.org\/10.1186\/s13635-023-00137-0","relation":{},"ISSN":["2510-523X"],"issn-type":[{"value":"2510-523X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,3,10]]},"assertion":[{"value":"11 October 2022","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"11 February 2023","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"10 March 2023","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare that they have no competing interests.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"3"}}