{"id":"https://openalex.org/W3199675190","doi":"https://doi.org/10.1109/ijcnn52387.2021.9533363","title":"Dual Head Adversarial Training","display_name":"Dual Head Adversarial Training","publication_year":2021,"publication_date":"2021-07-18","ids":{"openalex":"https://openalex.org/W3199675190","doi":"https://doi.org/10.1109/ijcnn52387.2021.9533363","mag":"3199675190"},"language":"en","primary_location":{"id":"doi:10.1109/ijcnn52387.2021.9533363","is_oa":false,"landing_page_url":"https://doi.org/10.1109/ijcnn52387.2021.9533363","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2021 International Joint Conference on Neural Networks (IJCNN)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5060827560","display_name":"Yujing Jiang","orcid":"https://orcid.org/0000-0002-4020-5989"},"institutions":[{"id":"https://openalex.org/I165779595","display_name":"University of Melbourne","ror":"https://ror.org/01ej9dk98","country_code":"AU","type":"education","lineage":["https://openalex.org/I165779595"]}],"countries":["AU"],"is_corresponding":true,"raw_author_name":"Yujing Jiang","raw_affiliation_strings":["School of Computing and Information Systems, The University of Melbourne"],"affiliations":[{"raw_affiliation_string":"School of Computing and Information Systems, The University of Melbourne","institution_ids":["https://openalex.org/I165779595"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5078711649","display_name":"Xingjun Ma","orcid":"https://orcid.org/0000-0003-2099-4973"},"institutions":[{"id":"https://openalex.org/I149704539","display_name":"Deakin University","ror":"https://ror.org/02czsnj07","country_code":"AU","type":"education","lineage":["https://openalex.org/I149704539"]}],"countries":["AU"],"is_corresponding":false,"raw_author_name":"Xingjun Ma","raw_affiliation_strings":["School of Information Technology, Deakin University"],"affiliations":[{"raw_affiliation_string":"School of Information Technology, Deakin University","institution_ids":["https://openalex.org/I149704539"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5070030398","display_name":"Sarah Erfani","orcid":"https://orcid.org/0000-0003-0885-0643"},"institutions":[{"id":"https://openalex.org/I165779595","display_name":"University of Melbourne","ror":"https://ror.org/01ej9dk98","country_code":"AU","type":"education","lineage":["https://openalex.org/I165779595"]}],"countries":["AU"],"is_corresponding":false,"raw_author_name":"Sarah Monazam Erfani","raw_affiliation_strings":["School of Computing and Information Systems, The University of Melbourne"],"affiliations":[{"raw_affiliation_string":"School of Computing and Information Systems, The University of Melbourne","institution_ids":["https://openalex.org/I165779595"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5101609697","display_name":"James Bailey","orcid":"https://orcid.org/0000-0002-3769-3811"},"institutions":[{"id":"https://openalex.org/I165779595","display_name":"University of Melbourne","ror":"https://ror.org/01ej9dk98","country_code":"AU","type":"education","lineage":["https://openalex.org/I165779595"]}],"countries":["AU"],"is_corresponding":false,"raw_author_name":"James Bailey","raw_affiliation_strings":["School of Computing and Information Systems, The University of Melbourne"],"affiliations":[{"raw_affiliation_string":"School of Computing and Information Systems, The University of Melbourne","institution_ids":["https://openalex.org/I165779595"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5060827560"],"corresponding_institution_ids":["https://openalex.org/I165779595"],"apc_list":null,"apc_paid":null,"fwci":0.6798,"has_fulltext":false,"cited_by_count":7,"citation_normalized_percentile":{"value":0.75876101,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":94,"max":97},"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"8"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9613000154495239,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10645","display_name":"Cardiac Arrest and Resuscitation","score":0.9241999983787537,"subfield":{"id":"https://openalex.org/subfields/2711","display_name":"Emergency Medicine"},"field":{"id":"https://openalex.org/fields/27","display_name":"Medicine"},"domain":{"id":"https://openalex.org/domains/4","display_name":"Health Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.9396630525588989},{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.858522891998291},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7904269695281982},{"id":"https://openalex.org/keywords/deep-neural-networks","display_name":"Deep neural networks","score":0.6482911109924316},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.6236815452575684},{"id":"https://openalex.org/keywords/training-set","display_name":"Training set","score":0.5555737018585205},{"id":"https://openalex.org/keywords/convolutional-neural-network","display_name":"Convolutional neural network","score":0.512549877166748},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.4897770881652832},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.4315924048423767}],"concepts":[{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.9396630525588989},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.858522891998291},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7904269695281982},{"id":"https://openalex.org/C2984842247","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep neural networks","level":3,"score":0.6482911109924316},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.6236815452575684},{"id":"https://openalex.org/C51632099","wikidata":"https://www.wikidata.org/wiki/Q3985153","display_name":"Training set","level":2,"score":0.5555737018585205},{"id":"https://openalex.org/C81363708","wikidata":"https://www.wikidata.org/wiki/Q17084460","display_name":"Convolutional neural network","level":2,"score":0.512549877166748},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.4897770881652832},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.4315924048423767},{"id":"https://openalex.org/C185592680","wikidata":"https://www.wikidata.org/wiki/Q2329","display_name":"Chemistry","level":0,"score":0.0},{"id":"https://openalex.org/C55493867","wikidata":"https://www.wikidata.org/wiki/Q7094","display_name":"Biochemistry","level":1,"score":0.0},{"id":"https://openalex.org/C104317684","wikidata":"https://www.wikidata.org/wiki/Q7187","display_name":"Gene","level":2,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/ijcnn52387.2021.9533363","is_oa":false,"landing_page_url":"https://doi.org/10.1109/ijcnn52387.2021.9533363","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2021 International Joint Conference on Neural Networks (IJCNN)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"score":0.5299999713897705,"id":"https://metadata.un.org/sdg/9","display_name":"Industry, innovation and infrastructure"}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":109,"referenced_works":["https://openalex.org/W1673923490","https://openalex.org/W1945616565","https://openalex.org/W2171590421","https://openalex.org/W2180612164","https://openalex.org/W2193413348","https://openalex.org/W2194775991","https://openalex.org/W2243397390","https://openalex.org/W2401231614","https://openalex.org/W2607219512","https://openalex.org/W2768346313","https://openalex.org/W2774644650","https://openalex.org/W2788741149","https://openalex.org/W2798302089","https://openalex.org/W2891710009","https://openalex.org/W2896457183","https://openalex.org/W2913266441","https://openalex.org/W2924551358","https://openalex.org/W2945793108","https://openalex.org/W2947188859","https://openalex.org/W2960644152","https://openalex.org/W2962729158","https://openalex.org/W2962821226","https://openalex.org/W2963001136","https://openalex.org/W2963143631","https://openalex.org/W2963158386","https://openalex.org/W2963207607","https://openalex.org/W2963249138","https://openalex.org/W2963341956","https://openalex.org/W2963389226","https://openalex.org/W2963516603","https://openalex.org/W2963694625","https://openalex.org/W2963744840","https://openalex.org/W2963752115","https://openalex.org/W2963857521","https://openalex.org/W2963920068","https://openalex.org/W2964082701","https://openalex.org/W2964116600","https://openalex.org/W2964137095","https://openalex.org/W2964153729","https://openalex.org/W2964224652","https://openalex.org/W2964253222","https://openalex.org/W2964283260","https://openalex.org/W2971316968","https://openalex.org/W2982109374","https://openalex.org/W2996344901","https://openalex.org/W3006076803","https://openalex.org/W3006752788","https://openalex.org/W3007873534","https://openalex.org/W3009542902","https://openalex.org/W3009751875","https://openalex.org/W3011279327","https://openalex.org/W3021182036","https://openalex.org/W3034455297","https://openalex.org/W3034994123","https://openalex.org/W3035032188","https://openalex.org/W3035447895","https://openalex.org/W3035524670","https://openalex.org/W3035743198","https://openalex.org/W3037903526","https://openalex.org/W3090285675","https://openalex.org/W3092873005","https://openalex.org/W3100593864","https://openalex.org/W3103385169","https://openalex.org/W3104620392","https://openalex.org/W3109453310","https://openalex.org/W3112272555","https://openalex.org/W3116131084","https://openalex.org/W3122730565","https://openalex.org/W3125614726","https://openalex.org/W4214585697","https://openalex.org/W4288283367","https://openalex.org/W4293846201","https://openalex.org/W4300677102","https://openalex.org/W6637162671","https://openalex.org/W6640425456","https://openalex.org/W6687566353","https://openalex.org/W6713132643","https://openalex.org/W6729756640","https://openalex.org/W6736207377","https://openalex.org/W6738693630","https://openalex.org/W6739868092","https://openalex.org/W6745272055","https://openalex.org/W6745893766","https://openalex.org/W6746402973","https://openalex.org/W6747819456","https://openalex.org/W6748475379","https://openalex.org/W6748711285","https://openalex.org/W6751569023","https://openalex.org/W6754642193","https://openalex.org/W6755207826","https://openalex.org/W6755310938","https://openalex.org/W6759129252","https://openalex.org/W6762624066","https://openalex.org/W6765977438","https://openalex.org/W6767478848","https://openalex.org/W6772461460","https://openalex.org/W6773713311","https://openalex.org/W6774097037","https://openalex.org/W6774341790","https://openalex.org/W6774469542","https://openalex.org/W6774681163","https://openalex.org/W6774862694","https://openalex.org/W6780518370","https://openalex.org/W6783533957","https://openalex.org/W6783646676","https://openalex.org/W6784426856","https://openalex.org/W6786054437","https://openalex.org/W6787575297","https://openalex.org/W6790438916"],"related_works":["https://openalex.org/W2950183588","https://openalex.org/W3080754722","https://openalex.org/W4383221314","https://openalex.org/W3093978547","https://openalex.org/W2953536436","https://openalex.org/W3203790781","https://openalex.org/W2997056298","https://openalex.org/W2738001131","https://openalex.org/W4285785480","https://openalex.org/W3127875750"],"abstract_inverted_index":{"Deep":[0],"neural":[1,135],"networks":[2],"(DNNs)":[3],"are":[4],"known":[5],"to":[6,9,28,33,79,109,123,138,152,175],"be":[7],"vulnerable":[8],"adversarial":[10,34,38,86,95,177,185],"examples/attacks,":[11],"raising":[12],"concerns":[13],"about":[14],"their":[15],"reliability":[16],"in":[17,63],"safety-critical":[18],"applications.":[19],"A":[20],"number":[21],"of":[22,84,94,102,127,142,157],"defense":[23],"methods":[24],"have":[25,51],"been":[26],"proposed":[27],"train":[29],"robust":[30],"DNNs":[31],"resistant":[32],"attacks,":[35],"among":[36],"which":[37],"training":[39,87,107,147,178,186],"has":[40],"so":[41],"far":[42],"demonstrated":[43],"the":[44,82,100,103,106,128,140,143,154,158,192,208],"most":[45],"promising":[46],"results.":[47],"However,":[48],"recent":[49],"studies":[50],"shown":[52],"that":[53,168],"there":[54],"exists":[55],"an":[56],"inherent":[57],"tradeoff":[58],"between":[59],"accuracy":[60,210],"and":[61,105,201,205],"robustness":[62,83,173,193],"adversarially-trained":[64],"DNNs.":[65],"In":[66],"this":[67],"paper,":[68],"we":[69],"propose":[70],"a":[71,117,132],"novel":[72],"technique":[73],"Dual":[74],"Head":[75],"Adversarial":[76],"Training":[77],"(DH-AT)":[78],"further":[80],"improve":[81,191,207],"existing":[85,91,176],"methods.":[88,179],"Different":[89],"from":[90],"improved":[92],"variants":[93],"training,":[96],"DH-AT":[97,114,169,189],"modifies":[98],"both":[99],"architecture":[101],"network":[104,119,136],"strategy":[108,148],"seek":[110],"more":[111],"robustness.":[112],"Specifically,":[113],"first":[115],"attaches":[116],"second":[118],"head":[120],"(or":[121],"branch)":[122],"one":[124,183],"intermediate":[125],"layer":[126],"network,":[129],"then":[130],"uses":[131],"lightweight":[133],"convolutional":[134],"(CNN)":[137],"aggregate":[139],"outputs":[141],"two":[144,159],"heads.":[145,160],"The":[146],"is":[149],"also":[150,206],"adapted":[151],"reflect":[153],"relative":[155],"importance":[156],"We":[161],"empirically":[162],"show,":[163],"on":[164],"multiple":[165],"benchmark":[166],"datasets,":[167],"can":[170,190],"bring":[171],"notable":[172],"improvements":[174],"Compared":[180],"with":[181],"TRADES,":[182],"state-of-the-art":[184],"method,":[187],"our":[188],"by":[194,211],"3.4%":[195],"against":[196,203],"PGD":[197],"<sup":[198],"xmlns:mml=\"http://www.w3.org/1998/Math/MathML\"":[199],"xmlns:xlink=\"http://www.w3.org/1999/xlink\">40</sup>":[200],"2.3%":[202],"AutoAttack,":[204],"clean":[209],"1.8%.":[212]},"counts_by_year":[{"year":2025,"cited_by_count":2},{"year":2023,"cited_by_count":3},{"year":2022,"cited_by_count":2}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
