{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,5]],"date-time":"2026-06-05T05:20:17Z","timestamp":1780636817916,"version":"3.54.1"},"reference-count":97,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"8","license":[{"start":{"date-parts":[[2024,8,1]],"date-time":"2024-08-01T00:00:00Z","timestamp":1722470400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/summer-heart-0930.chufeiyun1688.workers.dev:443\/https\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2024,8,1]],"date-time":"2024-08-01T00:00:00Z","timestamp":1722470400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/summer-heart-0930.chufeiyun1688.workers.dev:443\/https\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2024,8,1]],"date-time":"2024-08-01T00:00:00Z","timestamp":1722470400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/summer-heart-0930.chufeiyun1688.workers.dev:443\/https\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62133011"],"award-info":[{"award-number":["62133011"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Artif. Intell."],"published-print":{"date-parts":[[2024,8]]},"DOI":"10.1109\/tai.2024.3364121","type":"journal-article","created":{"date-parts":[[2024,2,9]],"date-time":"2024-02-09T13:43:45Z","timestamp":1707486225000},"page":"4202-4216","source":"Crossref","is-referenced-by-count":6,"title":["Enhance Adversarial Robustness via Geodesic Distance"],"prefix":"10.1109","volume":"5","author":[{"ORCID":"https:\/\/summer-heart-0930.chufeiyun1688.workers.dev:443\/https\/orcid.org\/0000-0003-3048-9604","authenticated-orcid":false,"given":"Jun","family":"Yan","sequence":"first","affiliation":[{"name":"College of Electronics and Information Engineering, Tongji University, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/summer-heart-0930.chufeiyun1688.workers.dev:443\/https\/orcid.org\/0000-0002-8507-015X","authenticated-orcid":false,"given":"Huilin","family":"Yin","sequence":"additional","affiliation":[{"name":"College of Electronics and Information Engineering, Tongji University, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/summer-heart-0930.chufeiyun1688.workers.dev:443\/https\/orcid.org\/0009-0008-6002-5257","authenticated-orcid":false,"given":"Ziming","family":"Zhao","sequence":"additional","affiliation":[{"name":"College of Electronics and Information Engineering, Tongji University, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/summer-heart-0930.chufeiyun1688.workers.dev:443\/https\/orcid.org\/0000-0001-6659-3433","authenticated-orcid":false,"given":"Wancheng","family":"Ge","sequence":"additional","affiliation":[{"name":"College of Electronics and Information Engineering, Tongji University, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/summer-heart-0930.chufeiyun1688.workers.dev:443\/https\/orcid.org\/0000-0003-3491-8074","authenticated-orcid":false,"given":"Jingfeng","family":"Zhang","sequence":"additional","affiliation":[{"name":"Faculty of Science, University of Auckland, Auckland, New Zealand"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1038\/s42256-019-0099-z"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1038\/s41586-019-1923-7"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1038\/s41586-021-03854-z"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref5","first-page":"1","article-title":"Explaining and harnessing adversarial examples","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Goodfellow","year":"2015"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.06083"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01467"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00790"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58555-6_17"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00760"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00175"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978392"},{"key":"ref15","first-page":"559","article-title":"Adversarial multiclass classification: A risk minimization perspective","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"29","author":"Fathony","year":"2016"},{"key":"ref16","first-page":"7472","article-title":"Theoretically principled trade-off between robustness and accuracy","volume-title":"Proc. 36th Int. Conf. Mach. Learn.","author":"Zhang","year":"2019"},{"key":"ref17","first-page":"11.192","article-title":"Unlabeled data improves adversarial robustness","volume-title":"Proc. 33rd Conf. Adv. Neural Inf. Process. Syst.","volume":"32","author":"Carmon","year":"2019"},{"key":"ref18","first-page":"1","article-title":"Improving adversarial robustness requires revisiting misclassified examples","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Wang","year":"2020"},{"key":"ref19","first-page":"1","article-title":"Robustness may be at odds with accuracy","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Tsipras","year":"2019"},{"key":"ref20","first-page":"7909","article-title":"Understanding and mitigating the tradeoff between robustness and accuracy","volume-title":"Proc. 37th Int. Conf. Mach. Learn.","author":"Raghunathan","year":"2020"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.3301541"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00090"},{"key":"ref23","first-page":"18 583","article-title":"Measuring robustness to natural distribution shifts in image classification","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"33","author":"Taori","year":"2020"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1090\/mmono\/191"},{"key":"ref25","volume-title":"Riemannian Geometry","author":"Peterson","year":"2006"},{"key":"ref26","first-page":"1","article-title":"Are adversarial examples inevitable?","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Shafahi","year":"2019"},{"key":"ref27","article-title":"A learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.2118\/18761-MS"},{"key":"ref29","article-title":"A downsampled variant of imagenet as an alternative to the CIFAR datasets","author":"Chrabaszcz","year":"2017"},{"key":"ref30","article-title":"Understanding riemannian geometry: Measuring the geodesics","author":"Su","year":"2016"},{"key":"ref31","first-page":"1","article-title":"Intriguing properties of neural networks","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Szegedy","year":"2014"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"ref34","article-title":"Transferability in machine learning: From phenomena to black-box attacks using adversarial samples","author":"Papernot","year":"2016"},{"key":"ref35","first-page":"1","article-title":"Delving into transferable adversarial examples and black-box attacks","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Liu","year":"2017"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140448"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1145\/3321707.3321749"},{"key":"ref38","first-page":"2142","article-title":"Black-box adversarial attacks with limited queries and information","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Ilyas","year":"2018"},{"key":"ref39","first-page":"1","article-title":"Benchmarking neural network robustness to common corruptions and perturbations","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Hendrycks","year":"2019"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"ref41","first-page":"274","article-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Athalye","year":"2018"},{"key":"ref42","first-page":"2206","article-title":"Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Croce","year":"2020"},{"key":"ref43","first-page":"1","article-title":"PixelDefend: Leveraging generative models to understand and defend against adversarial examples","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Song","year":"2018"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.56"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134057"},{"key":"ref46","first-page":"125","article-title":"Adversarial examples are not bugs, they are features","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"32","author":"Ilyas","year":"2019"},{"key":"ref47","first-page":"1","article-title":"Countering adversarial images using input transformations","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Guo","year":"2018"},{"key":"ref48","first-page":"1","article-title":"Mitigating adversarial effects through randomization","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Xie","year":"2018"},{"key":"ref49","first-page":"1","article-title":"Thermometer encoding: One hot way to resist adversarial examples","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Buckman","year":"2018"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.41"},{"key":"ref51","first-page":"854","article-title":"Parseval networks: Improving robustness to adversarial examples","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Ciss\u00e9","year":"2017"},{"key":"ref52","first-page":"2990","article-title":"Group equivariant convolutional networks","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Cohen","year":"2016"},{"key":"ref53","first-page":"11 278","article-title":"Attacks which do not kill training make adversarial learning stronger","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Zhang","year":"2020"},{"key":"ref54","first-page":"1","article-title":"Geometry-aware instance-reweighted adversarial training","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Zhang","year":"2021"},{"key":"ref55","first-page":"8093","article-title":"Overfitting in adversarially robust deep learning","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Rice","year":"2020"},{"key":"ref56","first-page":"1","article-title":"Bag of tricks for adversarial training","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Pang","year":"2021"},{"key":"ref57","first-page":"3358","article-title":"Adversarial training for free!","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"32","author":"Shafahi","year":"2019"},{"key":"ref58","first-page":"1","article-title":"Fast is better than free: Revisiting adversarial training","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Wong","year":"2020"},{"key":"ref59","first-page":"1","article-title":"Ensemble adversarial training: Attacks and defenses","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Tramer","year":"2018"},{"key":"ref60","first-page":"4970","article-title":"Improving adversarial robustness via promoting ensemble diversity","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Pang","year":"2019"},{"key":"ref61","first-page":"1","article-title":"Adversarial spheres","volume-title":"Proc. Int. Conf. Learn. Representations Workshop","author":"Gilmer","year":"2018"},{"key":"ref62","article-title":"A boundary tilting persepective on the phenomenon of adversarial examples","author":"Tanay","year":"2016"},{"key":"ref63","first-page":"1","article-title":"Defense-GAN: Protecting classifiers against adversarial attacks using generative models","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Samangouei","year":"2018"},{"key":"ref64","first-page":"3487","article-title":"Dual manifold adversarial robustness: Defense against Lp and non-Lp adversarial attacks","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"33","author":"Lin","year":"2020"},{"key":"ref65","first-page":"1632","article-title":"Robustness of classifiers: From adversarial to random noise","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"29","author":"Fawzi","year":"2016"},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.1007\/s10994-017-5663-3"},{"key":"ref67","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2017.2740965"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00396"},{"key":"ref69","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00929"},{"key":"ref70","first-page":"13842","article-title":"Adversarial robustness through local linearization","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"32","author":"Qin","year":"2019"},{"key":"ref71","first-page":"1","article-title":"Reducing excessive margin to achieve a better accuracy vs. robustness trade-off","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Rade","year":"2022"},{"key":"ref72","first-page":"1310","article-title":"Certified adversarial robustness via randomized smoothing","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Cohen","year":"2019"},{"key":"ref73","first-page":"10 693","article-title":"Randomized smoothing of all shapes and sizes","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Yang","year":"2020"},{"key":"ref74","first-page":"11.292","article-title":"Provably robust deep learning via adversarially trained smoothed classifiers","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"32","author":"Salman","year":"2019"},{"key":"ref75","doi-asserted-by":"publisher","DOI":"10.1109\/JPROC.2021.3050042"},{"key":"ref76","doi-asserted-by":"publisher","DOI":"10.1007\/s10851-009-0161-2"},{"key":"ref77","doi-asserted-by":"publisher","DOI":"10.1145\/256157.256160"},{"key":"ref78","doi-asserted-by":"publisher","DOI":"10.1109\/70.326576"},{"key":"ref79","first-page":"1","volume-title":"Preliminary Riemannian Geometry (Chinese Version)","author":"Wu","year":"2014"},{"key":"ref80","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01252-6_33"},{"key":"ref81","doi-asserted-by":"publisher","DOI":"10.5244\/C.30.87"},{"key":"ref82","first-page":"19 365","article-title":"Self-adaptive training: Beyond empirical risk minimization","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"33","author":"Huang","year":"2020"},{"key":"ref83","first-page":"1","article-title":"When optimizing f-divergence is robust with label noise","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Wei","year":"2021"},{"key":"ref84","first-page":"29 935","article-title":"Data augmentation can improve robustness","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"34","author":"Rebuffi","year":"2021"},{"key":"ref85","first-page":"2958","article-title":"Adversarial weight perturbation helps robust generalization","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"33","author":"Wu","year":"2020"},{"key":"ref86","first-page":"1","article-title":"RobustBench: A standardized adversarial robustness benchmark","volume-title":"Proc. 35th Conf. Neural Inf. Process. Syst. Datasets Benchmarks Track (Round 2)","author":"Croce","year":"2021"},{"key":"ref87","first-page":"5283","article-title":"Provable defenses against adversarial examples via the convex outer adversarial polytope","volume-title":"Proc. 35th Int. Conf. Mach. Learn.","author":"Wong","year":"2018"},{"key":"ref88","first-page":"1","article-title":"Towards stable and efficient training of verifiably robust neural networks","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Zhang","year":"2020"},{"key":"ref89","first-page":"7054","article-title":"Do wider neural networks really help adversarial robustness?","volume-title":"Proc. 35th Adv. Neural Inf. Process. Syst.","volume":"34","author":"Wu","year":"2021"},{"key":"ref90","first-page":"8580","article-title":"Neural tangent kernel: Convergence and generalization in neural networks","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"31","author":"Jacot","year":"2018"},{"key":"ref91","first-page":"1","article-title":"Robust overfitting may be mitigated by properly learned smoothening","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Chen","year":"2021"},{"key":"ref92","first-page":"876","article-title":"Averaging weights leads to wider optima and better generalization","volume-title":"Proc. Conf. Uncertainty Artif. Intell.","author":"Izmailov","year":"2018"},{"key":"ref93","doi-asserted-by":"publisher","DOI":"10.1007\/978-94-009-0909-0_7"},{"key":"ref94","doi-asserted-by":"publisher","DOI":"10.1017\/CBO9781107297296"},{"key":"ref95","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-16841-4"},{"key":"ref96","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00371"},{"key":"ref97","article-title":"Sequential modeling enables scalable learning for large vision models","author":"Bai","year":"2023"}],"container-title":["IEEE Transactions on Artificial Intelligence"],"original-title":[],"link":[{"URL":"https:\/\/summer-heart-0930.chufeiyun1688.workers.dev:443\/http\/xplorestaging.ieee.org\/ielx7\/9078688\/10635096\/10431598.pdf?arnumber=10431598","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,23]],"date-time":"2025-08-23T01:09:08Z","timestamp":1755911348000},"score":1,"resource":{"primary":{"URL":"https:\/\/summer-heart-0930.chufeiyun1688.workers.dev:443\/https\/ieeexplore.ieee.org\/document\/10431598\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,8]]},"references-count":97,"journal-issue":{"issue":"8"},"URL":"https:\/\/summer-heart-0930.chufeiyun1688.workers.dev:443\/https\/doi.org\/10.1109\/tai.2024.3364121","relation":{},"ISSN":["2691-4581"],"issn-type":[{"value":"2691-4581","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,8]]}}}