Page 325 - 《软件学报》2026年第7期
P. 325

3010                                                       软件学报  2026  年第  37  卷第  7  期


                     vehicles. In: Proc. of the 2020 IEEE/RSJ Int’l Conf. on Intelligent Robots and Systems (IROS). Las Vegas: IEEE, 2020. 2150–2156. [doi:
                     10.1109/IROS45743.2020.9340979]
                  [6]   Zhang X, Zhang Y, Zhong M, Ding D, Cao Y, Zhang Y, Zhang M, Yang M. Enhancing state-of-the-art classifiers with API semantics to
                     detect evolved Android malware. In: Proc. of the 2020 ACM SIGSAC Conf. on Computer and Communications Security. 2020. ACM,
                     2020. 757–770. [doi: 10.1145/3372297.3417291]
                  [7]   Chiu  YC,  Chen  HIH,  Zhang  TH,  Zhang  SY,  Gorthi  A,  Wang  LJ,  Huang  YF,  Chen  YD.  Predicting  drug  response  of  tumors  from
                     integrated genomic profiles by deep neural networks. BMC Medical Genomics, 2019, 12(S1): 18. [doi: 10.1186/s12920-018-0460-9]
                  [8]   Szegedy C, Zaremba W, Sutskever I, Bruna J, Erhan D, Goodfellow I, Fergus R. Intriguing properties of neural networks. arXiv:1312.
                     6199, 2013.
                  [9]   Liu AS, Liu XL, Fan JX, Ma YQ, Zhang AL, Xie HY, Tao DC. Perceptual-sensitive GAN for generating adversarial patches. In: Proc. of
                     the 33rd AAAI Conf. on Artificial Intelligence. Honolulu: AAAI Press, 2019. 1028–1035. [doi: 10.1609/aaai.v33i01.33011028]
                 [10]   Finlayson SG, Bowers JD, Ito J, Zittrain JL, Beam AL, Kohane IS. Adversarial attacks on medical machine learning. Science, 2019,
                     363(6433): 1287–1289. [doi: 10.1126/science.aaw4399]
                 [11]   Tramèr F, Kurakin A, Papernot N, Goodfellow I, Boneh D, McDaniel P. Ensemble adversarial training: Attacks and defenses. In: Proc. of
                     the 6th Int’l Conf. on Learning Representations. Vancouver: OpenReview.net, 2018. 1–18.
                 [12]   Zhang HY, Yu YD, Jiao JT, Xing EP, Ghaoui LE, Jordan MI. Theoretically principled trade-off between robustness and accuracy. In:
                     Proc. of the 36th Int’l Conf. on Machine Learning. Long Beach: PMLR, 2019. 7472–7482.
                 [13]   Chen JH, Cheng Y, Gan Z, Gu QQ, Liu JJ. Efficient robust training via backward smoothing. In: Proc. of the 36th AAAI Conf. on
                     Artificial Intelligence. AAAI Press, 2020. 6222–6230. [doi: 10.1609/aaai.v36i6.20571]
                 [14]   Rade R, Moosavi-Dezfooli SM. Helper-based adversarial training: Reducing excessive margin to achieve a better accuracy vs. robustness
                     trade-off. In: Proc. of the 2021 ICML Workshop on a Blessing in Disguise: The Prospects and Perils of Adversarial Machine Learning.
                     2021.
                 [15]   Cheng Z, Zhu F, Zhang XY, Liu CL. Adversarial training with distribution normalization and margin balance. Pattern Recognition, 2023,
                     136: 109182. [doi: 10.1016/j.patcog.2022.109182]
                 [16]   Dong JH, Moosavi-Dezfooli SM, Lai JH, Xie XH. The enemy of my enemy is my friend: Exploring inverse adversaries for improving
                     adversarial training. In: Proc. of the 2023 IEEE/CVF Conf. on Computer Vision and Pattern Recognition (CVPR). Vancouver: IEEE,
                     2023. 24678–24687. [doi: 10.1109/CVPR52729.2023.02364]
                 [17]   Tsipras D, Santurkar S, Engstrom L, Turner A, Madry A. Robustness may be at odds with accuracy. In: Proc. of the 7th Int’l Conf. on
                     Learning Representations. New Orleans: OpenReview.net. 1–23.
                 [18]   Yang  R,  Chen  XQ,  Cao  TJ.  APE-GAN++:  An  improved  APE-GAN  to  eliminate  adversarial  perturbations.  IAENG  Int’l  Journal  of
                     Computer Science, 2021, 48(3): 827.
                 [19]   Zhou DW, Wang NN, Peng CL, Gao XB, Wang XY, Yu J, Liu TL. Removing adversarial noise in class activation feature space. In: Proc.
                     of the 2021 IEEE/CVF Int’l Conf. on Computer Vision (ICCV). Montreal: IEEE, 2021. 7858–7867. [doi: 10.1109/ICCV48922.2021.
                     00778]
                 [20]   Ho  CH,  Vasconcelos  N.  DISCO:  Adversarial  defense  with  local  implicit  functions.  In:  Proc.  of  the  36th  Annual  Conf.  on  Neural
                     Information Processing Systems. New Orleans: NeurIPS, 2022. 1–20.
                 [21]   Nie WL, Guo B, Huang YJ, Xiao CW, Vahdat A, Anandkumar A. Diffusion models for adversarial purification. In: Proc. of the 39th Int’l
                     Conf. on Machine Learning. Baltimore: PMLR, 2022. 16805–16827.
                 [22]   Croce F, Hein M. Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks. In: Proc. of the 37th
                     Int’l Conf. on Machine Learning. JMLR.org, 2020. 2206–2216.
                 [23]   Qian Z, Zhang SF, Huang KZ, Wang QF, Zhang R, Yi XP. Improving model robustness with latent distribution locally and globally.
                     arXiv:2107.04401, 2021.
                 [24]   Stutz D, Hein M, Schiele B. Confidence-calibrated adversarial training: Generalizing to unseen attacks. In: Proc. of the 37th Int’l Conf. on
                     Machine Learning. JMLR.org, 2019. 849.
                 [25]   DeVries T, Taylor GW. Improved regularization of convolutional neural networks with cutout. arXiv:1708.04552, 2017.
                 [26]   Zhang H, Cissé M, Dauphin Y, Lopez-Paz D. Mixup: Beyond empirical risk minimization. In: Proc. of the 6th Int’l Conf. on Learning
                     Representations. Vancouver: OpenReview.net, 2018. 1–13.
                 [27]   Zhong  Z,  Zheng  L,  Kang  GL,  Li  SZ,  Yang  Y.  Random  erasing  data  augmentation.  In:  Proc.  of  the  34th  AAAI  Conf.  on  Artificial
                     Intelligence. New York: AAAI Press, 2020. 13001–13008. [doi: 10.1609/aaai.v34i07.7000]
                 [28]   de Jorge P, Bibi A, Volpi R, Sanyal A, Torr PH, Rogez G, Dokania PK. Make some noise: Reliable and efficient single-step adversarial
   320   321   322   323   324   325   326   327   328   329   330