Page 147 - 《软件学报》2026年第4期
P. 147

1588                                                       软件学报  2026  年第  37  卷第  4  期


                 [30]   Long S, Tao W, Zhang ZD, Tao Q. Adaptive NAG methods based on AdaGrad and its optimal individual convergence. Ruan Jian Xue
                     Bao/Journal of Software, 2022, 33(4): 1231–1243 (in Chinese with English abstract). http://www.jos.org.cn/1000-9825/6464.htm [doi: 10.
                     13328/j.cnki.jos.006464]
                 [31]   Xie XY, Zhou P, Li H, Lin ZC, Yan SC. Adan: Adaptive nesterov momentum algorithm for faster optimizing deep models. IEEE Trans.
                     on Pattern Analysis and Machine Intelligence, 2024, 46(12): 9508–9520. [doi: 10.1109/TPAMI.2024.3423382]
                 [32]   Lin JD, Song CB, He K, Wang LW, Hopcroft JE. Nesterov accelerated gradient and scale invariance for adversarial attacks. In: Proc. of
                     the 2020 Int’l Conf. on Learning Representations. OpenReview.net. 2020.
                 [33]   Zou JH, Duan YX, Ren CL, Qiu JY, Zhou XY, Pan ZS. Perturbation initialization, Adam-Nesterov and quasi-hyperbolic momentum for
                     adversarial examples. Acta Electronica Sinica, 2022, 50(1): 207–216 (in Chinese with English abstract). [doi: 10.12263/DZXB.20200839]
                 [34]   Bao  L,  Tao  W,  Tao  Q.  Boosting  adversarial  transferability  through  adaptive-learning-rate  with  data  augmentation  mechanism.  Acta
                     Electronica Sinica, 2024, 52(1): 157–169 (in Chinese with English abstract). [doi: 10.12263/DZXB.20220737]
                 [35]   Shafahi A, Najibi M, Ghiasi M, Xu Z, Dickerson J, Studer C, Davis LS, Taylor G, Goldstein T. Adversarial training for free! In: Proc. of
                     the 33rd Int’l Conf. on Neural Information Processing Systems. Vancouver: Curran Associates Inc., 2019. 3358–3369.
                 [36]   Wong  E,  Rice  L,  Kolter  JZ.  FAST  is  better  than  free:  Revisiting  adversarial  training.  In:  Proc.  of  the  2020  Int’l  Conf.  on  Learning
                     Representations. OpenReview.net. 2020.
                 [37]   Jia XJ, Zhang Y, Wei XX, Wu BY, Ma K, Wang J, Cao XC. Prior-guided adversarial initialization for fast adversarial training. In: Avidan
                     S,  Brostow  G,  Cissé  M,  Farinella  GM,  Hassner  T,  eds.  Proc.  of  the  17th  European  Conf.  on  Computer  Vision  (ECCV).  Tel  Aviv:
                     Springer, 2022. 567–584. [doi: 10.1007/978-3-031-19772-7_33]
                 [38]   Jia XJ, Zhang Y, Wei XX, Wu BY, Ma K, Wang J, Cao XC. Improving fast adversarial training with prior-guided knowledge. IEEE
                     Trans. on Pattern Analysis and Machine Intelligence, 2024, 46(9): 6367–6383. [doi: 10.1109/TPAMI.2024.3381180]
                 [39]   Nesterov Y. Introductory Lectures on Convex Optimization—A Basic Course. New York: Springer, 2004. 1–236. [doi: 10.1007/978-1-
                     4419-8853-9]
                 [40]   Ghadimi S, Lan GH. Accelerated gradient methods for nonconvex nonlinear and stochastic programming. Mathematical Programming,
                     2016, 156(1–2): 59–99. [doi: 10.1007/s10107-015-0871-8]
                 [41]   Everingham  M,  Eslami  SMA,  van  Gool  L,  Williams  CKI,  Winn  J,  Zisserman  A.  The  PASCAL  visual  object  classes  challenge:  A
                     retrospective. Int’l Journal of Computer Vision, 2015, 111(1): 98–136. [doi: 10.1007/s11263-014-0733-5]
                 [42]   Lin TY, Maire M, Belongie S, Hays J, Perona P, Ramanan D, Dollár P, Zitnick CL. Microsoft COCO: Common objects in context. In:
                     Fleet D, Pajdla T, Schiele B, Tuytelaars T, eds. Proc. of the 13th European Conf. on Computer Vision (ECCV). Zurich: Springer, 2014.
                     740–755. [doi: 10.1007/978-3-319-10602-1_48]

                 附中文参考文献
                  [8]   王璐瑶, 曹渊, 刘博涵, 曾恩, 刘坤, 夏元清. 时间序列分类模型的集成对抗训练防御方法. 自动化学报, 2025, 51(1): 144–160. [doi:
                     10.16383/j.aas.c240050]
                 [16]   王生生, 路淑贞, 曹斌. 面向隐私保护联邦学习的医学影像目标检测算法. 计算机辅助设计与图形学学报, 2021, 33(10): 1553–1562.
                     [doi: 10.3724/SP.J.1089.2021.18416]
                 [24]   陆宇轩, 刘泽禹, 罗咏刚, 邓森友, 江天, 马金燕, 董胤蓬. 基于生成对抗网络的目标检测黑盒迁移攻击算法. 软件学报, 2024, 35(7):
                     3531–3550. http://www.jos.org.cn/1000-9825/6937.htm [doi: 10.13328/j.cnki.jos.006937]
                 [25]   汪欣欣, 陈晶, 何琨, 张子君, 杜瑞颖, 李瞧, 佘计思. 面向目标检测的对抗攻击与防御综述. 通信学报, 2023, 44(11): 260–277. [doi:
                     10.11959/j.issn.1000-436x.2023223]
                 [30]   陇盛, 陶蔚, 张泽东, 陶卿. 基于  AdaGrad  的自适应  NAG  方法及其最优个体收敛性. 软件学报, 2022, 33(4): 1231–1243. http://www.
                     jos.org.cn/1000-9825/6464.htm [doi: 10.13328/j.cnki.jos.006464]
                 [33]   邹军华, 段晔鑫, 任传伦, 邱俊洋, 周星宇, 潘志松. 基于噪声初始化、Adam-Nesterov  方法和准双曲动量方法的对抗样本生成方法.
                     电子学报, 2022, 50(1): 207–216. [doi: 10.12263/DZXB.20200839]
                 [34]   鲍蕾, 陶蔚, 陶卿. 结合自适应步长策略和数据增强机制提升对抗攻击迁移性. 电子学报, 2024, 52(1): 157–169. [doi: 10.12263/
                     DZXB.20220737]


                  附录  A. 定理  1  证明

                           d
                    若  S x = R , 那么有:
   142   143   144   145   146   147   148   149   150   151   152