Page 325 - 《软件学报》2026年第7期
P. 325
3010 软件学报 2026 年第 37 卷第 7 期
vehicles. In: Proc. of the 2020 IEEE/RSJ Int’l Conf. on Intelligent Robots and Systems (IROS). Las Vegas: IEEE, 2020. 2150–2156. [doi:
10.1109/IROS45743.2020.9340979]
[6] Zhang X, Zhang Y, Zhong M, Ding D, Cao Y, Zhang Y, Zhang M, Yang M. Enhancing state-of-the-art classifiers with API semantics to
detect evolved Android malware. In: Proc. of the 2020 ACM SIGSAC Conf. on Computer and Communications Security. 2020. ACM,
2020. 757–770. [doi: 10.1145/3372297.3417291]
[7] Chiu YC, Chen HIH, Zhang TH, Zhang SY, Gorthi A, Wang LJ, Huang YF, Chen YD. Predicting drug response of tumors from
integrated genomic profiles by deep neural networks. BMC Medical Genomics, 2019, 12(S1): 18. [doi: 10.1186/s12920-018-0460-9]
[8] Szegedy C, Zaremba W, Sutskever I, Bruna J, Erhan D, Goodfellow I, Fergus R. Intriguing properties of neural networks. arXiv:1312.
6199, 2013.
[9] Liu AS, Liu XL, Fan JX, Ma YQ, Zhang AL, Xie HY, Tao DC. Perceptual-sensitive GAN for generating adversarial patches. In: Proc. of
the 33rd AAAI Conf. on Artificial Intelligence. Honolulu: AAAI Press, 2019. 1028–1035. [doi: 10.1609/aaai.v33i01.33011028]
[10] Finlayson SG, Bowers JD, Ito J, Zittrain JL, Beam AL, Kohane IS. Adversarial attacks on medical machine learning. Science, 2019,
363(6433): 1287–1289. [doi: 10.1126/science.aaw4399]
[11] Tramèr F, Kurakin A, Papernot N, Goodfellow I, Boneh D, McDaniel P. Ensemble adversarial training: Attacks and defenses. In: Proc. of
the 6th Int’l Conf. on Learning Representations. Vancouver: OpenReview.net, 2018. 1–18.
[12] Zhang HY, Yu YD, Jiao JT, Xing EP, Ghaoui LE, Jordan MI. Theoretically principled trade-off between robustness and accuracy. In:
Proc. of the 36th Int’l Conf. on Machine Learning. Long Beach: PMLR, 2019. 7472–7482.
[13] Chen JH, Cheng Y, Gan Z, Gu QQ, Liu JJ. Efficient robust training via backward smoothing. In: Proc. of the 36th AAAI Conf. on
Artificial Intelligence. AAAI Press, 2020. 6222–6230. [doi: 10.1609/aaai.v36i6.20571]
[14] Rade R, Moosavi-Dezfooli SM. Helper-based adversarial training: Reducing excessive margin to achieve a better accuracy vs. robustness
trade-off. In: Proc. of the 2021 ICML Workshop on a Blessing in Disguise: The Prospects and Perils of Adversarial Machine Learning.
2021.
[15] Cheng Z, Zhu F, Zhang XY, Liu CL. Adversarial training with distribution normalization and margin balance. Pattern Recognition, 2023,
136: 109182. [doi: 10.1016/j.patcog.2022.109182]
[16] Dong JH, Moosavi-Dezfooli SM, Lai JH, Xie XH. The enemy of my enemy is my friend: Exploring inverse adversaries for improving
adversarial training. In: Proc. of the 2023 IEEE/CVF Conf. on Computer Vision and Pattern Recognition (CVPR). Vancouver: IEEE,
2023. 24678–24687. [doi: 10.1109/CVPR52729.2023.02364]
[17] Tsipras D, Santurkar S, Engstrom L, Turner A, Madry A. Robustness may be at odds with accuracy. In: Proc. of the 7th Int’l Conf. on
Learning Representations. New Orleans: OpenReview.net. 1–23.
[18] Yang R, Chen XQ, Cao TJ. APE-GAN++: An improved APE-GAN to eliminate adversarial perturbations. IAENG Int’l Journal of
Computer Science, 2021, 48(3): 827.
[19] Zhou DW, Wang NN, Peng CL, Gao XB, Wang XY, Yu J, Liu TL. Removing adversarial noise in class activation feature space. In: Proc.
of the 2021 IEEE/CVF Int’l Conf. on Computer Vision (ICCV). Montreal: IEEE, 2021. 7858–7867. [doi: 10.1109/ICCV48922.2021.
00778]
[20] Ho CH, Vasconcelos N. DISCO: Adversarial defense with local implicit functions. In: Proc. of the 36th Annual Conf. on Neural
Information Processing Systems. New Orleans: NeurIPS, 2022. 1–20.
[21] Nie WL, Guo B, Huang YJ, Xiao CW, Vahdat A, Anandkumar A. Diffusion models for adversarial purification. In: Proc. of the 39th Int’l
Conf. on Machine Learning. Baltimore: PMLR, 2022. 16805–16827.
[22] Croce F, Hein M. Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks. In: Proc. of the 37th
Int’l Conf. on Machine Learning. JMLR.org, 2020. 2206–2216.
[23] Qian Z, Zhang SF, Huang KZ, Wang QF, Zhang R, Yi XP. Improving model robustness with latent distribution locally and globally.
arXiv:2107.04401, 2021.
[24] Stutz D, Hein M, Schiele B. Confidence-calibrated adversarial training: Generalizing to unseen attacks. In: Proc. of the 37th Int’l Conf. on
Machine Learning. JMLR.org, 2019. 849.
[25] DeVries T, Taylor GW. Improved regularization of convolutional neural networks with cutout. arXiv:1708.04552, 2017.
[26] Zhang H, Cissé M, Dauphin Y, Lopez-Paz D. Mixup: Beyond empirical risk minimization. In: Proc. of the 6th Int’l Conf. on Learning
Representations. Vancouver: OpenReview.net, 2018. 1–13.
[27] Zhong Z, Zheng L, Kang GL, Li SZ, Yang Y. Random erasing data augmentation. In: Proc. of the 34th AAAI Conf. on Artificial
Intelligence. New York: AAAI Press, 2020. 13001–13008. [doi: 10.1609/aaai.v34i07.7000]
[28] de Jorge P, Bibi A, Volpi R, Sanyal A, Torr PH, Rogez G, Dokania PK. Make some noise: Reliable and efficient single-step adversarial

