Page 326 - 《软件学报》2026年第7期
P. 326

杨波 等: PBAT: 基于代理分布的深度学习模型防御加固方法                                                 3011


                     training. In: Proc. of the 36th Annual Conf. on Neural Information Processing Systems. New Orleans: NeurIPS, 2022. 1–13.
                 [29]   Yun S, Han D, Chun S, Oh SJ, Yoo Y, Choe J. CutMix: Regularization strategy to train strong classifiers with localizable features. In:
                     Proc. of the 2019 IEEE/CVF Int’l Conf. on Computer Vision (ICCV). Seoul: IEEE, 2019. 6022–6031. [doi: 10.1109/ICCV.2019.00612]
                 [30]   Cubuk ED, Zoph B, Shlens J, Le QV. Randaugment: Practical automated data augmentation with a reduced search space. In: Proc. of the
                     2020  IEEE/CVF  Conf.  on  Computer  Vision  and  Pattern  Recognition  Workshops.  Seattle:  IEEE,  2020.  702–703.  [doi:  10.1109/
                     CVPRW50498.2020.00359]
                 [31]   Ho D, Liang E, Chen X, Stoica I, Abbeel P. Population based augmentation: Efficient learning of augmentation policy schedules. In:
                     Proc. of the 36th Int’l Conf. on Machine Learning. Long Beach: PMLR, 2019. 2731–2741.
                 [32]   Li BY, Wu F, Lim SN, Belongie S, Weinberger KQ. On feature normalization and data augmentation. In: Proc. of the 2021 IEEE/CVF
                     Conf.  on  Computer  Vision  and  Pattern  Recognition  (CVPR).  Nashville:  IEEE,  2021.  12378–12387.  [doi:  10.1109/CVPR46437.2021.
                     01220]
                 [33]   Radford A, Metz L, Chintala S. Unsupervised representation learning with deep convolutional generative adversarial networks. In: Proc.
                     of the 4th Int’l Conf. on Learning Representations. San Juan: OpenReview.net, 2016. 1–16.
                 [34]   Choi Y, Choi M, Kim M, Ha JW, Kim S, Choo J. StarGAN: Unified generative adversarial networks for multi-domain image-to-image
                     translation. In: Proc. of the 2018 IEEE/CVF Conf. on Computer Vision and Pattern Recognition. Salt Lake City: IEEE, 2018. 8789–8797.
                     [doi: 10.1109/CVPR.2018.00916]
                 [35]   Zhang H, Goodfellow I, Metaxas D, Odena A. Self-attention generative adversarial networks. In: Proc. of the 36th Int’l Conf. on Machine
                     Learning. Long Beach: PMLR, 2019. 7354–7363.
                 [36]   Brock A, Donahue J, Simonyan K. Large scale GAN training for high fidelity natural image synthesis. In: Proc. of the 7th Int’l Conf. on
                     Learning Representations. New Orleans: OpenReview.net, 2019. 1–35.
                 [37]   Karras T, Laine S, Aila T. A style-based generator architecture for generative adversarial networks. In: Proc. of the 2019 IEEE/CVF Conf.
                     on Computer Vision and Pattern Recognition (CVPR). Long Beach: IEEE, 2018. 4396–4405. [doi: 10.1109/CVPR.2019.00453]
                 [38]   Gulrajani I, Ahmed F, Arjovsky M, Dumoulin V, Courville A. Improved training of Wasserstein GANs. In: Proc. of the 31st Int’l Conf.
                     on Neural Information Processing Systems. Long Beach: Curran Associates Inc., 2017. 5769–5779.
                 [39]   Xie CH, Tan MX, Gong BQ, Yuille A, Le QV. Smooth adversarial training. arXiv:2006.14536, 2020.
                 [40]   Maini P, Wong E, Kolter Z. Adversarial robustness against the union of multiple perturbation models. In: Proc. of the 37th Int’l Conf. on
                     Machine Learning. PMLR, 2020. 6640–6650.
                 [41]   Chen HR, Dong YP, Wang ZY, Yang X, Duan CQ, Su H, Zhu J. Robust classification via a single diffusion model. In: Proc. of the 41st
                     Int’l Conf. on Machine Learning. Vienna: PMLR, 2024. 6643–6665.
                 [42]   Sui CH, Wang A, Wang HP, Liu H, Gong QT, Yao J, Hong DF. ISDAT: An image-semantic dual adversarial training framework for
                     robust image classification. Pattern Recognition, 2025, 158: 110968. [doi: 10.1016/j.patcog.2024.110968]
                 [43]   Jin GQ, Shen SW, Zhang DM, Dai F, Zhang YD. APE-GAN: Adversarial perturbation elimination with GAN. In: Proc. of the 2019 IEEE
                     Int’l  Conf.  on  Acoustics,  Speech  and  Signal  Processing  (ICASSP).  Brighton:  IEEE,  2017.  3842–3846.  [doi:  10.1109/ICASSP.2019.
                     8683044]
                 [44]   Jolicoeur-Martineau A. The relativistic discriminator: A key element missing from standard GAN. In: Proc. of the 7th Int’l Conf. on
                     Learning Representations. New Orleans: OpenReview.net, 2019. 1–26.
                 [45]   Dobriban E, Hassani H, Hong D, Robey A. Provable tradeoffs in adversarially robust classification. IEEE Trans. on Information Theory,
                     2023, 69(12): 7793–7822. [doi: 10.1109/TIT.2022.3205449]
                 [46]   Mehrabi M, Javanmard A, Rossi RA, Rao A, Mai T. Fundamental tradeoffs in distributionally adversarial training. In: Proc. of the 38th
                     Int’l Conf. on Machine Learning. PMLR, 2021. 7544–7554.
                 [47]   Liu H. Rethinking adversarial training with a simple baseline. arXiv:2306.07613, 2023.
                 [48]   Madry A, Makelov A, Schmidt L, Tsipras D, Vladu A. Towards deep learning models resistant to adversarial attacks. In: Proc. of the 6th
                     Int’l Conf. on Learning Representations. Vancouver: OpenReview.net, 2018. 1–23.
                 [49]   Goodfellow  IJ,  Shlens  J,  Szegedy  C.  Explaining  and  harnessing  adversarial  examples.  In:  Proc.  of  the  3rd  Int’l  Conf.  on  Learning
                     Representations. San Diego: OpenReview.net, 2015. 1–11.
                 [50]   Cui  JQ,  Liu  S,  Wang  LW,  Jia  JY.  Learnable  boundary  guided  adversarial  training.  In:  Proc.  of  the  2021  IEEE/CVF  Int’l  Conf.  on
                     Computer Vision. Montreal: IEEE, 2021. 15701–15710. [doi: 10.1109/ICCV48922.2021.01543]
                 [51]   Gong  HH,  Dong  MJ,  Ma  SQ,  Camtepe  S,  Nepal  S,  Xu  C.  Parameter-saving  adversarial  training:  Reinforcing  multi-perturbation
                     robustness via hypernetworks. arXiv:2309.16207, 2023.
                 [52]   Li  L,  Spratling  MW.  Data  augmentation  alone  can  improve  adversarial  training.  In:  Proc.  of  the  11th  Int’l  Conf.  on  Learning
   321   322   323   324   325   326   327   328   329   330   331