{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,6]],"date-time":"2026-02-06T00:51:50Z","timestamp":1770339110319,"version":"3.49.0"},"reference-count":92,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"12","license":[{"start":{"date-parts":[[2023,12,1]],"date-time":"2023-12-01T00:00:00Z","timestamp":1701388800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2023,12,1]],"date-time":"2023-12-01T00:00:00Z","timestamp":1701388800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2023,12,1]],"date-time":"2023-12-01T00:00:00Z","timestamp":1701388800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"National Key R&#x0026;D Program of China","award":["2018AAA0102000"],"award-info":[{"award-number":["2018AAA0102000"]}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62236008"],"award-info":[{"award-number":["62236008"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U21B2038"],"award-info":[{"award-number":["U21B2038"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61931008"],"award-info":[{"award-number":["61931008"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62025604"],"award-info":[{"award-number":["62025604"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["6212200758"],"award-info":[{"award-number":["6212200758"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61976202"],"award-info":[{"award-number":["61976202"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62206264"],"award-info":[{"award-number":["62206264"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100012226","name":"Fundamental Research Funds for the Central Universities","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100012226","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100004739","name":"Youth Innovation Promotion Association of the Chinese Academy of Sciences","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100004739","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Strategic Priority Research Program of Chinese Academy of Sciences","award":["XDB28000000"],"award-info":[{"award-number":["XDB28000000"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Pattern Anal. Mach. Intell."],"published-print":{"date-parts":[[2023,12]]},"DOI":"10.1109\/tpami.2023.3303934","type":"journal-article","created":{"date-parts":[[2023,8,10]],"date-time":"2023-08-10T17:38:58Z","timestamp":1691689138000},"page":"15494-15511","source":"Crossref","is-referenced-by-count":3,"title":["Revisiting AUC-Oriented Adversarial Training With Loss-Agnostic Perturbations"],"prefix":"10.1109","volume":"45","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-4409-4999","authenticated-orcid":false,"given":"Zhiyong","family":"Yang","sequence":"first","affiliation":[{"name":"School of Computer Science and Technology, University of Chinese Academy of Sciences, Beijing, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3512-7277","authenticated-orcid":false,"given":"Qianqian","family":"Xu","sequence":"additional","affiliation":[{"name":"Key Laboratory of Intelligent Information Processing, Institute of Computing Technology, Chinese Academy of Sciences, Beijing, China"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-8786-2634","authenticated-orcid":false,"given":"Wenzheng","family":"Hou","sequence":"additional","affiliation":[{"name":"Key Laboratory of Intelligent Information Processing, Institute of Computing Technology, Chinese Academy of Sciences, Beijing, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4336-8900","authenticated-orcid":false,"given":"Shilong","family":"Bao","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Information Security (SKLOIS), Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6885-1341","authenticated-orcid":false,"given":"Yuan","family":"He","sequence":"additional","affiliation":[{"name":"Security Department of Alibaba Group, Hangzhou, Zhejiang, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7141-708X","authenticated-orcid":false,"given":"Xiaochun","family":"Cao","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Technology, Shenzhen Campus, Sun Yat-sen University, Shenzhen, Guangdong, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7542-296X","authenticated-orcid":false,"given":"Qingming","family":"Huang","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, University of Chinese Academy of Sciences, Beijing, China"}]}],"member":"263","reference":[{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00766"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-74976-9_8"},{"key":"ref56","article-title":"Introductory lectures on convex programming volume I: Basic course","volume":"3","author":"nesterov","year":"1998","journal-title":"Lecture notes"},{"key":"ref15","first-page":"313","article-title":"AUC optimization vs. error rate minimization","author":"cortes","year":"2003","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2022.108889"},{"key":"ref14","first-page":"1548","article-title":"Convex learning of multiple tasks and their structure","author":"ciliberto","year":"2015","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.1954.1057460"},{"key":"ref53","first-page":"703","article-title":"Predicting accurate probabilities with a ranking loss","author":"menon","year":"2012","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref52","first-page":"6640","article-title":"Adversarial robustness against the union of multiple perturbation models","author":"maini","year":"2020","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2018\/520"},{"key":"ref55","first-page":"16174","article-title":"On the generalization analysis of adversarial learning","author":"mustafa","year":"2022","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1016\/S0031-3203(96)00142-2"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1016\/S0001-2998(78)80014-2"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1145\/1014052.1014066"},{"key":"ref16","first-page":"2206","article-title":"Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks","author":"croce","year":"2020","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref19","article-title":"MMA training: Direct input space margin maximization through adversarial training","author":"ding","year":"2020","journal-title":"Proc Int Conf Learn Representations"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.00951"},{"key":"ref92","first-page":"27548","article-title":"When AUC meets DRO: Optimizing partial AUC for deep learning with non-convex convergence guarantee","author":"zhu","year":"2022","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref51","article-title":"Towards deep learning models resistant to adversarial attacks","author":"madry","year":"2018","journal-title":"Proc Int Conf Learn Representations"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2020.3005393"},{"key":"ref91","doi-asserted-by":"publisher","DOI":"10.1109\/ISBI45749.2020.9098374"},{"key":"ref90","first-page":"233","article-title":"Online AUC maximization","author":"zhao","year":"2011","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref46","article-title":"Stochastic AUC maximization with deep neural networks","author":"liu","year":"2020","journal-title":"Proc Int Conf Learn Representations"},{"key":"ref45","first-page":"519","article-title":"AUC: A statistically consistent and more discriminating measure than accuracy","author":"ling","year":"2003","journal-title":"Proc Int Joint Conf Artif Intell"},{"key":"ref89","first-page":"3623","article-title":"Smoothing multivariate performance measures","volume":"13","author":"zhang","year":"2012","journal-title":"J Mach Learn Res"},{"key":"ref48","article-title":"Generalization bounds for deep convolutional neural networks","author":"long","year":"2020","journal-title":"Proc 8th Int Conf Learn Representations"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00684"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i9.17007"},{"key":"ref86","first-page":"7472","article-title":"Theoretically principled trade-off between robustness and accuracy","author":"zhang","year":"2019","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref41","article-title":"Adversarial machine learning at scale","author":"kurakin","year":"2017","journal-title":"Proc Int Conf Learn Representations"},{"key":"ref85","first-page":"227","article-title":"You only propagate once: Accelerating adversarial training via maximal principle","author":"zhang","year":"2019","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref44","first-page":"6083","article-title":"On gradient descent ascent for nonconvex-concave minimax problems","author":"lin","year":"2020","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref88","article-title":"Geometry-aware instance-reweighted adversarial training","author":"zhang","year":"2020","journal-title":"Proc Int Conf Learn Representations"},{"key":"ref43","author":"ledoux","year":"2013","journal-title":"Probability in Banach spaces Isoperimetry and Processes"},{"key":"ref87","first-page":"11278","article-title":"Attacks which do not kill training make adversarial learning stronger","author":"zhang","year":"2020","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1145\/1081870.1081950"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1016\/0362-546X(94)00186-L"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2022.3141095"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-40994-3_25"},{"key":"ref4","first-page":"162","article-title":"Improved generalization bounds for robust learning","author":"attias","year":"2019","journal-title":"Proc Int Conf Algorithmic Learn Theory"},{"key":"ref3","first-page":"274","article-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","author":"athalye","year":"2018","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref6","article-title":"Efficient global optimization of two-layer relu networks: Quadratic-time algorithms and adversarial training","author":"bai","year":"2022"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2021\/591"},{"key":"ref82","first-page":"451","article-title":"Stochastic online AUC maximization","author":"ying","year":"2016","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref81","first-page":"7085","article-title":"Rademacher complexity for adversarially robust generalization","author":"yin","year":"2019","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i9.16989"},{"key":"ref84","article-title":"Adversarially robust generalization just requires more unlabeled data","author":"zhai","year":"2019"},{"key":"ref83","first-page":"12219","article-title":"Federated deep AUC maximization for hetergeneous data with a constant communication complexity","author":"yuan","year":"2021","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref80","first-page":"11987","article-title":"Improved OOD generalization via adversarial training and pretraing","author":"yi","year":"2021","journal-title":"Proc 38th Int Conf Mach Learn"},{"key":"ref35","article-title":"Learning with a strong adversary","author":"huang","year":"2015"},{"key":"ref79","article-title":"Large-scale optimization of partial auc in a range of false positive rates","author":"yao","year":"2022"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1145\/3485447.3512178"},{"key":"ref78","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2022.3185311"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1145\/1102351.1102399"},{"key":"ref36","article-title":"Multi-block-single-probe variance reduced estimator for coupled compositional optimization","author":"jiang","year":"2022"},{"key":"ref31","article-title":"Open-narrow-synechiae anterior chamber angle classification in AS-OCT sequences","author":"hao","year":"2020"},{"key":"ref75","first-page":"505","article-title":"On the generalization properties of adversarial training","author":"xing","year":"2021","journal-title":"Proc Int Conf Artif Intell Statist"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE.2019.00141"},{"key":"ref74","first-page":"26523","article-title":"On the algorithmic stability of adversarial training","author":"xing","year":"2021","journal-title":"Proc Int Conf Neural Inf Process"},{"key":"ref33","first-page":"36","article-title":"Accelerated zeroth-order and first-order momentum methods from mini to minimax optimization","volume":"23","author":"huang","year":"2022","journal-title":"J Mach Learn Res"},{"key":"ref77","article-title":"When all we need is a piece of the pie: A generic framework for optimizing two-way partial AUC","author":"yang","year":"2021","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref32","first-page":"8903","article-title":"AdAUC: End-to-end adversarial AUC optimization against long-tail problems","author":"hou","year":"2022","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref76","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2021.3101125"},{"key":"ref2","article-title":"On the robustness of the CVPR 2018 white-box adversarial example defenses","author":"athalye","year":"2018"},{"key":"ref1","first-page":"49","article-title":"Optimising area under the ROC curve using gradient descent","author":"alan","year":"2004","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref39","first-page":"315","article-title":"Accelerating stochastic gradient descent using predictive variance reduction","author":"johnson","year":"2013","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1145\/1150402.1150429"},{"key":"ref71","article-title":"Fast is better than free: Revisiting adversarial training","author":"wong","year":"2019","journal-title":"Proc Int Conf Learn Representations"},{"key":"ref70","doi-asserted-by":"publisher","DOI":"10.1037\/xlm0000732"},{"key":"ref73","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00855"},{"key":"ref72","doi-asserted-by":"publisher","DOI":"10.1109\/42.585767"},{"key":"ref24","first-page":"906","article-title":"One-pass AUC optimization","author":"gao","year":"2013","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00673"},{"key":"ref23","first-page":"13009","article-title":"Convergence of adversarial training in overparametrized neural networks","author":"gao","year":"2019","journal-title":"Proc Int Conf Neural Inf Process"},{"key":"ref67","first-page":"12280","article-title":"Theoretical analysis of adversarial learning: A minimax approach","author":"tu","year":"2019","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1148\/110.1.89"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1145\/3543507.3583268"},{"key":"ref69","first-page":"6586","article-title":"On the convergence and robustness of adversarial training","author":"wang","year":"2019","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref20","author":"egan","year":"1975","journal-title":"Signal Detection Theory and ROC Analysis"},{"key":"ref64","article-title":"Certifying some distributional robustness with principled adversarial training","author":"sinha","year":"2017"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1037\/h0035203"},{"key":"ref22","first-page":"933","article-title":"An efficient boosting algorithm for combining preferences","volume":"4","author":"freund","year":"2003","journal-title":"J Mach Learn Res"},{"key":"ref66","article-title":"Minimax problems with coupled linear constraints: Computational complexity, duality and solution methods","author":"tsaknakis","year":"2021"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1016\/j.patrec.2005.10.010"},{"key":"ref65","article-title":"Intriguing properties of neural networks","author":"szegedy","year":"2014","journal-title":"Proc Int Conf Learn Representations"},{"key":"ref28","author":"green","year":"1966","journal-title":"Signal Detection Theory and Psychophysics"},{"key":"ref27","article-title":"Explaining and harnessing adversarial examples","author":"goodfellow","year":"2015","journal-title":"Proc Int Conf Learn Representations"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1016\/0022-2496(72)90009-0"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1145\/1835804.1835928"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2018.04.027"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i04.6017"}],"container-title":["IEEE Transactions on Pattern Analysis and Machine Intelligence"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/34\/10308548\/10214340.pdf?arnumber=10214340","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,11,27]],"date-time":"2023-11-27T19:53:47Z","timestamp":1701114827000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10214340\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,12]]},"references-count":92,"journal-issue":{"issue":"12"},"URL":"https:\/\/doi.org\/10.1109\/tpami.2023.3303934","relation":{},"ISSN":["0162-8828","2160-9292","1939-3539"],"issn-type":[{"value":"0162-8828","type":"print"},{"value":"2160-9292","type":"electronic"},{"value":"1939-3539","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,12]]}}}