[1] L. Zhong, L. Li, and G. Yang, "Benchmarking robustness of deep neural networks in semantic segmentation of fluorescence microscopy images," BMC Bioinformatics, vol. 25, no. 1, art. no. 269, 2024.
[2] X. Zhang, N. Wang, H. Shen, S. Ji, X. Luo, and T. Wang, "Interpretable deep learning under fire: Adversarial attacks and defenses," IEEE Reviews in Biomedical Engineering, vol. 16, pp. 217-245, 2023.
[3] J. C. Costa, T. Roxo, H. Proença, and P. R. M. Inácio, "How deep learning sees the world: A survey on adversarial attacks & defenses," IEEE Access, vol. 12, pp. 61113-61136, 2024.
[4] A. Chakraborty, M. Alam, V. Dey, A. Chattopadhyay, and D. Mukhopadhyay, "A survey on adversarial attacks and defences," CAAI Transactions on Intelligence Technology, vol. 6, no. 1, pp. 25-45, 2021.
[5] B. Lyu and Z. Zhu, "Analyzing the implicit bias of adversarial training from a generalized margin perspective," IEEE Transactions on Pattern Analysis and Machine Intelligence, vol. 47, no. 9, pp. 8025-8039, 2025.
[6] Y. Dong, F. Liao, T. Pang, H. Su, J. Zhu, X. Hu, and J. Li, "Boosting adversarial attacks with momentum," in Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, 2018, pp. 9185-9193.
[7] Y. Wang, W. Hong, X. Zhang, Q. Zhang, and C. Gu, "Boosting transferability of adversarial samples via saliency distribution and frequency domain enhancement," Knowledge-Based Systems, vol. 300, art. no. 112152, 2024. [8] A. Ilyas, S. Santurkar, D. Tsipras, L. Engstrom, B. Tran, and A. Madry, "Adversarial examples are not bugs, they are features," in Advances in Neural Information Processing Systems, vol. 32, 2019, pp. 125-136.
[9] D. Jin, Z. Jin, J. T. Zhou, and P. Szolovits, "Is BERT really robust? A strong baseline for natural language attack on text classification and entailment," in Proceedings of the AAAI Conference on Artificial Intelligence, vol. 34, no. 05, 2020, pp. 8018-8025.
[10] L. Sun, Y. Dou, C. Yang, J. Wang, P. S. Yu, L. He, and B. Li, "Adversarial attack and defense on graph data: A survey," IEEE Transactions on Knowledge and Data Engineering, vol. 35, no. 8, pp. 7693-7711, 2022.
[11] T. Bai, J. Luo, J. Zhao, B. Wen, and Q. Wang, "Recent advances in adversarial training for adversarial robustness," in Proceedings of the International Joint Conference on Artificial Intelligence (IJCAI), 2021, pp. 4312-4321.
[12] H. Eghbalzadeh, W. Zellinger, M. Pintor, K. Grosse, K. Koutini, B. A. Moser, B. Biggio, and G. Widmer, "Rethinking data augmentation for adversarial robustness," Information Sciences, vol. 654, art. no. 119838, 2024.
[13] L. Rice, E. Wong, and Z. Kolter, "Overfitting in adversarially robust deep learning," in Proceedings of the International Conference on Machine Learning (ICML), 2020, pp. 8093-8104.
[14] J. Zhang, X. Xu, B. Han, G. Niu, L. Cui, M. Sugiyama, and M. Kankanhalli, "Attacks which do not kill training make adversarial learning stronger," in Proceedings of the International Conference on Machine Learning (ICML), 2020, pp. 11278-11287.
[15] M. K. Roshan and A. Zafar, "Boosting robustness of network intrusion detection systems: A novel two phase defense strategy against untargeted white-box optimization adversarial attack," Expert Systems with Applications, vol. 249, art. no. 123729, 2024.
[16] J. Cohen, E. Rosenfeld, and Z. Kolter, "Certified adversarial robustness via randomized smoothing," in Proceedings of the International Conference on Machine Learning (ICML), 2019, pp. 1310-1320.
[17] A. Athalye, N. Carlini, and D. Wagner, "Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples," in Proceedings of the International Conference on Machine Learning (ICML), 2018, pp. 274-283.
[18] N. Carlini and D. Wagner, "Adversarial examples are not easily detected: Bypassing ten detection methods," in Proceedings of the 10th ACM Workshop on Artificial Intelligence and Security, 2017, pp. 3-14.
[19] H. Salman, M. Sun, G. Yang, A. Kapoor, and J. Z. Kolter, "Provably robust deep learning via adversarially trained smoothed classifiers," in Advances in Neural Information Processing Systems, vol. 33, 2020, pp. 11289-11300.
[20] H. Zhang, Y. Yu, J. Jiao, E. Xing, L. El Ghaoui, and M. Jordan, "Theoretically principled trade-off between robustness and accuracy," in Proceedings of the International Conference on Machine Learning (ICML), 2019, pp. 7472-7482.
[21] Z. Qian, K. Huang, Q.-F. Wang, and X.-Y. Zhang, "A survey of robust adversarial training in pattern recognition: Fundamental, theory, and methodologies," Pattern Recognition, vol. 131, art. no. 108889, 2022.
[22] N. Wang, Y. Yu, and H. Wang, "ALAT: Adversarial label-guided adversarial training," Pattern Recognition Letters, vol. 187, pp. 104-111, 2025.
[23] F. Tramèr, N. Carlini, W. Brendel, and A. Madry, "On adaptive attacks to adversarial example defenses," in Advances in Neural Information Processing Systems, vol. 33, 2020, pp. 1633-1645.
[24] F. Croce and M. Hein, "Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks," in Proceedings of the International Conference on Machine Learning (ICML), 2020, pp. 2206-2216.
[25] Y. Dong, Z. Deng, T. Pang, J. Zhu, and H. Su, "Adversarial distributional training for robust deep learning," in Advances in Neural Information Processing Systems, vol. 36, 2023, pp. 24862-24879.
[26] I. Valentim, N. Lourenço, and N. Antunes, "Evolutionary model validation—An adversarial robustness perspective," in Handbook of Evolutionary Machine Learning, W. Banzhaf, P. Machado, and M. Zhang, Eds. Cham: Springer, 2024, pp. 457-485.
[27] W. Deng, J. Xu, and H. Zhao, "An improved ant colony optimization algorithm based on hybrid strategies for scheduling problem," IEEE Access, vol. 7, pp. 20281-20292, 2019.
[28] L. Li and M. Spratling, "Robust shortcut and disordered robustness: Improving adversarial training through adaptive smoothing," Pattern Recognition, vol. 163, art. no. 111474, 2025.
[29] D. Silver, S. Singh, D. Precup, and R. S. Sutton, "Reward is enough," Artificial Intelligence, vol. 299, art. no. 103535, 2021.
[30] K. Arulkumaran, M. P. Deisenroth, M. Brundage, and A. A. Bharath, "Deep reinforcement learning: A brief survey," IEEE Signal Processing Magazine, vol. 34, no. 6, pp. 26-38, 2017.
[31] V. Behzadan and A. Munir, "Vulnerability of deep reinforcement learning to policy induction attacks," in Proceedings of the International Conference on Machine Learning and Data Mining in Pattern Recognition, 2017, pp. 262-275.
[32] X. Huang, D. Kroening, W. Ruan, J. Sharp, Y. Sun, E. Thamo, M. Wu, and X. Yi, "A survey of safety and trustworthiness of deep neural networks: Verification, testing, adversarial attack and defence, and interpretability," Computer Science Review, vol. 37, art. no. 100270, 2020.
[33] Y. Wu, T. Shu, J. Yu, S. Lei, Q. Gu, and Y. Liu, "Adversarial weight perturbation helps robust generalization," in Advances in Neural Information Processing Systems, vol. 36, 2023, pp. 12847-12863.
[34] K. Ota, D. K. Jha, and A. Kanezaki, "A framework for training larger networks for deep reinforcement learning," Machine Learning, vol. 113, pp. 6115-6139, 2024.
[35] C. Schlarmann and M. Hein, "On the adversarial robustness of multi-modal foundation models," in Proceedings of the IEEE/CVF International Conference on Computer Vision (ICCV), 2023, pp. 3441-3451.
[36] Y. Li, Y. Jiang, Z. Li, and S. T. Xia, "Backdoor learning: A survey," IEEE Transactions on Neural Networks and Learning Systems, vol. 35, no. 1, pp. 5-22, 2024.
[37] J. Liu, Y. Li, Y. Guo, Y. Liu, J. Tang, and Y. Nie, "Generation and countermeasures of adversarial examples on vision: A survey," Artificial Intelligence Review, vol. 57, no. 8, art. no. 199, 2024.
[38] N. Carlini and D. Wagner, "Towards evaluating the robustness of neural networks," in Proceedings of the IEEE Symposium on Security and Privacy, 2017, pp. 39-57.
[39] C. Li, H. Wang, W. Yao, and T. Jiang, "Adversarial attacks in computer vision: A survey," Journal of Membrane Computing, vol. 6, no. 2, pp. 130-147, 2024.
[40] Y. Zhu, Y. Zhao, Z. Hu, T. Luo, and L. He, "A review of black-box adversarial attacks on image classification," Neurocomputing, vol. 610, art. no. 128512, 2024.
[41] W. E. Zhang, Q. Z. Sheng, A. Alhazmi, and C. Li, "Adversarial attacks on deep-learning models in natural language processing: A survey," ACM Transactions on Intelligent Systems and Technology, vol. 11, no. 3, art. no. 24, pp. 1-41, 2020.
[42] D. Jin, Z. Jin, J. T. Zhou, and P. Szolovits, "Is BERT really robust? A strong baseline for natural language attack on text classification and entailment," in Proceedings of the AAAI Conference on Artificial Intelligence, vol. 34, no. 05, 2020, pp. 8018-8025.
[43] D. Zügner, A. Akbarnejad, and S. Günnemann, "Adversarial attacks on neural networks for graph data," in Proceedings of the ACM SIGKDD International Conference on Knowledge Discovery & Data Mining, 2018, pp. 2847-2856.
[44] Y. Bu, Y. Zhu, L. Geng, and K. Zhou, "Unleashing the power of indirect attacks against trust prediction via preferential path," Knowledge and Information Systems, vol. 67, no. 5, pp. 4459-4486, 2025.
[45] X. Wei, S. Zhao, and B. Li, "Revisiting the trade-off between accuracy and robustness via weight distribution of filters," IEEE Transactions on Pattern Analysis and Machine Intelligence, vol. 46, no. 12, pp. 8870-8882, 2024.
[46] Q. Z. Cai, M. Du, C. Liu, and D. Song, "Curriculum adversarial training," in Proceedings of the International Joint Conference on Artificial Intelligence (IJCAI), 2018, pp. 3740-3747.
[47] Y. Zhao, W. Huang, W. Liu, and X. Yao, "Negatively correlated ensemble against transfer adversarial attacks," Pattern Recognition, vol. 161, art. no. 111155, 2025.
[48] Y. Qing, T. Bai, Z. Liu, P. Moulin, and B. Wen, "Detection of adversarial attacks via disentangling natural images and perturbations," IEEE Transactions on Information Forensics and Security, vol. 19, pp. 2814-2825, 2024.
[49] C. Zhao, H. Li, D. Wang, and R. Liu, "Adversarial example detection for deep neural networks: A review," in Proceedings of the 8th International Conference on Data Science in Cyberspace (DSC), 2023, pp. 468-475.
[50] B. Tekeste, K. Al-Hussaeni, B. C. M. Fung, I. Alawadhi, and C. Fachkha, "Adversarial machine learning: A 20-year survey of attacks, defenses, and standards," IEEE Access, vol. 14, pp. 69778-69812, 2026.
[51] K. Lee, K. Lee, H. Lee, and J. Shin, "A simple unified framework for detecting out-of-distribution samples and adversarial attacks," in Advances in Neural Information Processing Systems, vol. 31, 2018, pp. 7167-7177.
[52] G. Bachmann, S.-M. Moosavi-Dezfooli, and T. Hofmann, "Uniform convergence, adversarial spheres and a simple remedy," in Proceedings of the 38th International Conference on Machine Learning (ICML), vol. 139, 2021, pp. 490-499.
[53] A. Mohammadi Gohar, K. Rahbar, B. Minaei-Bidgoli, and Z. Beheshtifard, "Study on generative adversarial network (GAN) in discrete data: A survey," Journal of AI and Data Mining, Online First, 2025.
[54] Y. Xia, B. Chen, Y. Feng, T. Ge, Y. Huang, H. Wang, and Y. Wang, "Multi-scale architectures matter: Examining the adversarial robustness of flow-based lossless compression," Pattern Recognition, vol. 149, art. no. 110242, 2024.
[55] Z. Liu, Q. Liu, T. Liu, N. Xu, X. Lin, Y. Wang, and W. Wen, "Feature distillation: DNN-oriented JPEG compression against adversarial examples," in Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, 2019, pp. 860-868.
[56] S.-H. Choi, J.-M. Shin, P. Liu, and Y.-H. Choi, "ARGAN: Adversarially robust generative adversarial networks for deep neural networks against adversarial examples," IEEE Access, vol. 10, pp. 33602-33615, 2022.
[57] E. Wong and Z. Kolter, "Provable defenses against adversarial examples via the convex outer adversarial polytope," in Proceedings of the International Conference on Machine Learning (ICML), 2018, pp. 5286-5295.
[58] A. Raghunathan, J. Steinhardt, and P. S. Liang, "Semidefinite relaxations for certifying robustness to adversarial examples," in Advances in Neural Information Processing Systems, vol. 31, 2018, pp. 10877-10887.
[59] S. Gowal, R. Stanforth, C. Qin, J. Uesato, and P. Kohli, "Scalable verified training for provably robust image classification," in Proceedings of the IEEE/CVF International Conference on Computer Vision (ICCV), 2019, pp. 4841-4850.
[60] G. Singh, T. Gehr, M. Püschel, and M. Vechev, "An abstract domain for certifying neural networks," Proceedings of the ACM on Programming Languages, vol. 3, no. POPL, art. no. 41, pp. 1-30, 2019.
[61] A. Boopathy, T. W. Weng, P. Y. Chen, S. Liu, and L. Daniel, "CNN-Cert: An efficient framework for certifying robustness of convolutional neural networks," in Proceedings of the AAAI Conference on Artificial Intelligence, vol. 33, no. 01, 2019, pp. 3240-3247.
[62] R. Jia, A. Raghunathan, K. Göksel, and P. Liang, "Certified robustness to adversarial word substitutions," in Proceedings of the Conference on Empirical Methods in Natural Language Processing (EMNLP), 2019, pp. 4129-4142.
[63] J. Su, D. V. Vargas, and K. Sakurai, "One pixel attack for fooling deep neural networks," IEEE Transactions on Evolutionary Computation, vol. 23, no. 5, pp. 828-841, 2019.
[64] R. Mosli, M. Wright, B. Yuan, and Y. Pan, "They might not be giants: Crafting black-box adversarial examples using particle swarm optimization," in Computer Security – ESORICS 2020, L. Chen, N. Li, K. Liang, and S. Schneider, Eds. Cham: Springer, 2020, pp. 439-459.
[65] S. Saha, M. A. Pervaiz, M. S. Rahman, S. Ahmmed, and J. Maua, "Residual-guided hybrid framework for adversarially robust deep learning-based network intrusion detection," PLoS ONE, vol. 21, no. 6, art. no. e0350737, 2026.
[66] Y. Wu, Y. Wang, H. Wang, B. Zhu, P. Ding, and C. Liu, "Enhancing security in deep reinforcement learning: A comprehensive survey on adversarial attacks and defenses," Neurocomputing, vol. 685, art. no. 133503, 2026.
[67] K. Kandasamy, A. Krishnamurthy, J. Schneider, and B. Póczos, "Parallelised bayesian optimisation via Thompson sampling," in Proceedings of the International Conference on Artificial Intelligence and Statistics, 2018, pp. 133-142.
[68] X. He, K. Zhao, and X. Chu, "AutoML: A survey of the state-of-the-art," Knowledge-Based Systems, vol. 212, art. no. 106622, 2021.
[69] B.-K. Lee, J. Kim, and Y. M. Ro, "Mitigating adversarial vulnerability through causal parameter estimation by adversarial double machine learning," in Proceedings of the IEEE/CVF International Conference on Computer Vision (ICCV), 2023, pp. 4476-4486.
[70] Z. Pang, X. Yan, S. Guo, and Y. Lu, "Diversity-enhanced reconstruction as plug-in defenders against adversarial perturbations," Frontiers in Artificial Intelligence, vol. 8, art. no. 1665106, 2025.
[71] D. Yin, A. Pananjady, M. Lam, D. Papailiopoulos, K. Ramchandran, and P. Bartlett, "Gradient diversity: A key ingredient for scalable distributed learning," in Proceedings of the International Conference on Artificial Intelligence and Statistics, 2018, pp. 1998-2007.
[72] JL. Jia, B. Su, D. Xu, Y. Wang, J. Fang, and J. Wang, "Policy optimization algorithm with activation likelihood-ratio for multi-agent reinforcement learning," Neural Processing Letters, vol. 56, no. 6, art. no. 247, 2024.
[73] Y. Shi, Y. Han, and Q. Zhu, "Meta adversarial training against universal patches," IEEE Transactions on Artificial Intelligence, vol. 3, no. 5, pp. 814-825, 2022.
[74] A. Mohan & T. Schön. (2026). Toward robust agents: A survey of adversarial attacks and defenses in deep reinforcement learning. IEEE Access, 14, 14481-14497. A. Mohan and T. Schön, "Toward robust agents: A survey of adversarial attacks and defenses in deep reinforcement learning," IEEE Access, vol. 14, pp. 14481-14497, 2026.
[75] M. Li, X. Xu, S.-L. Huang, and L. Zhang, "Dual feature distributional regularization for defending against adversarial attacks," in Neural Information Processing, T. Mantoro, M. Lee, M. A. Ayu, K. W. Wong, and A. N. Hidayanto, Eds. Cham: Springer, 2021, pp. 377-386.
[76] D. Meng and H. Chen, "MagNet: A two-pronged defense against adversarial examples," in Proceedings of the ACM SIGSAC Conference on Computer and Communications Security, 2017, pp. 135-147.
[77] M. Abbasi, A. Rajabi, C. Gagné, and R. B. Bobba, "Toward adversarial robustness by diversity in an ensemble of specialized deep neural networks," in Advances in Artificial Intelligence, C. Goutte and X. Zhu, Eds. Cham: Springer, 2020, pp. 1-14.
[78] X. Chen, W. Huang, Z. Peng, W. Guo, and F. Zhang, "Diversity supporting robustness: Enhancing adversarial robustness via differentiated ensemble predictions," Computers & Security, vol. 142, art. no. 103861, 2024.
[79] S. Shukla, S. Dalui, M. Alam, S. Datta, A. Mondal, D. Mukhopadhyay, and P. P. Chakrabarti, "Guardian of the ensembles: Introducing pairwise adversarially robust loss for resisting adversarial attacks in DNN ensembles," in Proceedings of the IEEE/CVF Winter Conference on Applications of Computer Vision (WACV), 2025, pp. 7205-7214.
[80] Y. Ma, Z. Huang, M. Dong, S. You, and C. Xu, "Adversarial robustness via deformable convolution with stochasticity," in Proceedings of the 42nd International Conference on Machine Learning (ICML), vol. 267, 2025, pp. 41943-41958.
[81] N. Akhtar and A. Mian, "Threat of adversarial attacks on deep learning in computer vision: A survey," IEEE Access, vol. 6, pp. 14410-14430, 2018.
[82] A. Radford, J. W. Kim, C. Hallacy, A. Ramesh, G. Agarwal, S. Girish, et al., "Learning transferable visual models from natural language supervision," in Proceedings of the International Conference on Machine Learning (ICML), 2021, pp. 8748-8763.
[83] T. Baltrusaitis, C. Ahuja, and L.-P. Morency, "Multimodal machine learning: A survey and taxonomy," IEEE Transactions on Pattern Analysis and Machine Intelligence, vol. 41, no. 2, pp. 423-443, 2019.
[84] H. Xu, Y. Ma, H.-C. Liu, D. Deb, H. Liu, J.-L. Tang, and A. K. Jain, "Adversarial attacks and defenses in images, graphs and text: A review," International Journal of Automation and Computing, vol. 17, no. 2, pp. 151-178, 2020.
[85] Z. Qin, Y. Fan, Y. Liu, L. Shen, Y. Zhang, J. Wang, and B. Wu, "Boosting the transferability of adversarial attacks with reverse adversarial perturbation," in Advances in Neural Information Processing Systems, vol. 35, 2022, pp. 29845-29858.
[86] G. Goh, N. Cammarata, C. Voss, S. Carter, M. Petrov, L. Schubert, et al., "Multimodal neurons in artificial neural networks," Distill, vol. 6, no. 3, art. no. e30, 2021.
[87] H. Wu, C. Wang, Y. Tyshetskiy, A. Docherty, K. Lu, and L. Zhu, "Adversarial examples for graph data: Deep insights into attack and defense," in Proceedings of the International Joint Conference on Artificial Intelligence (IJCAI), 2019, pp. 4816-4823.
[88] W. Jin, Y. Li, H. Xu, Y. Wang, S. Ji, C. Aggarwal, and J. Tang, "Adversarial attacks and defenses on graphs: A survey," ACM SIGKDD Explorations Newsletter, vol. 22, no. 2, pp. 19-34, 2021.
[89] H. Khodadadi and V. Derhami, "Employing chaos theory for exploration-exploitation balance in reinforcement learning," Journal of AI and Data Mining, vol. 13, no. 2, pp. 1-13, 2025.