Page 326 - 《软件学报》2026年第7期
P. 326
杨波 等: PBAT: 基于代理分布的深度学习模型防御加固方法 3011
training. In: Proc. of the 36th Annual Conf. on Neural Information Processing Systems. New Orleans: NeurIPS, 2022. 1–13.
[29] Yun S, Han D, Chun S, Oh SJ, Yoo Y, Choe J. CutMix: Regularization strategy to train strong classifiers with localizable features. In:
Proc. of the 2019 IEEE/CVF Int’l Conf. on Computer Vision (ICCV). Seoul: IEEE, 2019. 6022–6031. [doi: 10.1109/ICCV.2019.00612]
[30] Cubuk ED, Zoph B, Shlens J, Le QV. Randaugment: Practical automated data augmentation with a reduced search space. In: Proc. of the
2020 IEEE/CVF Conf. on Computer Vision and Pattern Recognition Workshops. Seattle: IEEE, 2020. 702–703. [doi: 10.1109/
CVPRW50498.2020.00359]
[31] Ho D, Liang E, Chen X, Stoica I, Abbeel P. Population based augmentation: Efficient learning of augmentation policy schedules. In:
Proc. of the 36th Int’l Conf. on Machine Learning. Long Beach: PMLR, 2019. 2731–2741.
[32] Li BY, Wu F, Lim SN, Belongie S, Weinberger KQ. On feature normalization and data augmentation. In: Proc. of the 2021 IEEE/CVF
Conf. on Computer Vision and Pattern Recognition (CVPR). Nashville: IEEE, 2021. 12378–12387. [doi: 10.1109/CVPR46437.2021.
01220]
[33] Radford A, Metz L, Chintala S. Unsupervised representation learning with deep convolutional generative adversarial networks. In: Proc.
of the 4th Int’l Conf. on Learning Representations. San Juan: OpenReview.net, 2016. 1–16.
[34] Choi Y, Choi M, Kim M, Ha JW, Kim S, Choo J. StarGAN: Unified generative adversarial networks for multi-domain image-to-image
translation. In: Proc. of the 2018 IEEE/CVF Conf. on Computer Vision and Pattern Recognition. Salt Lake City: IEEE, 2018. 8789–8797.
[doi: 10.1109/CVPR.2018.00916]
[35] Zhang H, Goodfellow I, Metaxas D, Odena A. Self-attention generative adversarial networks. In: Proc. of the 36th Int’l Conf. on Machine
Learning. Long Beach: PMLR, 2019. 7354–7363.
[36] Brock A, Donahue J, Simonyan K. Large scale GAN training for high fidelity natural image synthesis. In: Proc. of the 7th Int’l Conf. on
Learning Representations. New Orleans: OpenReview.net, 2019. 1–35.
[37] Karras T, Laine S, Aila T. A style-based generator architecture for generative adversarial networks. In: Proc. of the 2019 IEEE/CVF Conf.
on Computer Vision and Pattern Recognition (CVPR). Long Beach: IEEE, 2018. 4396–4405. [doi: 10.1109/CVPR.2019.00453]
[38] Gulrajani I, Ahmed F, Arjovsky M, Dumoulin V, Courville A. Improved training of Wasserstein GANs. In: Proc. of the 31st Int’l Conf.
on Neural Information Processing Systems. Long Beach: Curran Associates Inc., 2017. 5769–5779.
[39] Xie CH, Tan MX, Gong BQ, Yuille A, Le QV. Smooth adversarial training. arXiv:2006.14536, 2020.
[40] Maini P, Wong E, Kolter Z. Adversarial robustness against the union of multiple perturbation models. In: Proc. of the 37th Int’l Conf. on
Machine Learning. PMLR, 2020. 6640–6650.
[41] Chen HR, Dong YP, Wang ZY, Yang X, Duan CQ, Su H, Zhu J. Robust classification via a single diffusion model. In: Proc. of the 41st
Int’l Conf. on Machine Learning. Vienna: PMLR, 2024. 6643–6665.
[42] Sui CH, Wang A, Wang HP, Liu H, Gong QT, Yao J, Hong DF. ISDAT: An image-semantic dual adversarial training framework for
robust image classification. Pattern Recognition, 2025, 158: 110968. [doi: 10.1016/j.patcog.2024.110968]
[43] Jin GQ, Shen SW, Zhang DM, Dai F, Zhang YD. APE-GAN: Adversarial perturbation elimination with GAN. In: Proc. of the 2019 IEEE
Int’l Conf. on Acoustics, Speech and Signal Processing (ICASSP). Brighton: IEEE, 2017. 3842–3846. [doi: 10.1109/ICASSP.2019.
8683044]
[44] Jolicoeur-Martineau A. The relativistic discriminator: A key element missing from standard GAN. In: Proc. of the 7th Int’l Conf. on
Learning Representations. New Orleans: OpenReview.net, 2019. 1–26.
[45] Dobriban E, Hassani H, Hong D, Robey A. Provable tradeoffs in adversarially robust classification. IEEE Trans. on Information Theory,
2023, 69(12): 7793–7822. [doi: 10.1109/TIT.2022.3205449]
[46] Mehrabi M, Javanmard A, Rossi RA, Rao A, Mai T. Fundamental tradeoffs in distributionally adversarial training. In: Proc. of the 38th
Int’l Conf. on Machine Learning. PMLR, 2021. 7544–7554.
[47] Liu H. Rethinking adversarial training with a simple baseline. arXiv:2306.07613, 2023.
[48] Madry A, Makelov A, Schmidt L, Tsipras D, Vladu A. Towards deep learning models resistant to adversarial attacks. In: Proc. of the 6th
Int’l Conf. on Learning Representations. Vancouver: OpenReview.net, 2018. 1–23.
[49] Goodfellow IJ, Shlens J, Szegedy C. Explaining and harnessing adversarial examples. In: Proc. of the 3rd Int’l Conf. on Learning
Representations. San Diego: OpenReview.net, 2015. 1–11.
[50] Cui JQ, Liu S, Wang LW, Jia JY. Learnable boundary guided adversarial training. In: Proc. of the 2021 IEEE/CVF Int’l Conf. on
Computer Vision. Montreal: IEEE, 2021. 15701–15710. [doi: 10.1109/ICCV48922.2021.01543]
[51] Gong HH, Dong MJ, Ma SQ, Camtepe S, Nepal S, Xu C. Parameter-saving adversarial training: Reinforcing multi-perturbation
robustness via hypernetworks. arXiv:2309.16207, 2023.
[52] Li L, Spratling MW. Data augmentation alone can improve adversarial training. In: Proc. of the 11th Int’l Conf. on Learning

