{"id":"https://openalex.org/W4394585815","doi":"https://doi.org/10.1109/tpami.2024.3385745","title":"Meta Invariance Defense Towards Generalizable Robustness to Unknown Adversarial Attacks","display_name":"Meta Invariance Defense Towards Generalizable Robustness to Unknown Adversarial Attacks","publication_year":2024,"publication_date":"2024-04-08","ids":{"openalex":"https://openalex.org/W4394585815","doi":"https://doi.org/10.1109/tpami.2024.3385745","pmid":"https://pubmed.ncbi.nlm.nih.gov/38587963"},"language":"en","primary_location":{"id":"doi:10.1109/tpami.2024.3385745","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tpami.2024.3385745","pdf_url":null,"source":{"id":"https://openalex.org/S199944782","display_name":"IEEE Transactions on Pattern Analysis and Machine Intelligence","issn_l":"0162-8828","issn":["0162-8828","1939-3539","2160-9292"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320439","host_organization_name":"IEEE Computer Society","host_organization_lineage":["https://openalex.org/P4310320439","https://openalex.org/P4310319808"],"host_organization_lineage_names":["IEEE Computer Society","Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Pattern Analysis and Machine Intelligence","raw_type":"journal-article"},"type":"article","indexed_in":["crossref","pubmed"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5106578837","display_name":"Lei Zhang","orcid":"https://orcid.org/0000-0002-5305-8543"},"institutions":[{"id":"https://openalex.org/I158842170","display_name":"Chongqing University","ror":"https://ror.org/023rhb549","country_code":"CN","type":"education","lineage":["https://openalex.org/I158842170"]},{"id":"https://openalex.org/I4210136793","display_name":"Peng Cheng Laboratory","ror":"https://ror.org/03qdqbt06","country_code":"CN","type":"facility","lineage":["https://openalex.org/I4210136793"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Lei Zhang","raw_affiliation_strings":["School of Microelectronics and Communication Engineering, Chongqing University, Chongqing, China","Peng Cheng Lab, Shenzhen, China"],"affiliations":[{"raw_affiliation_string":"School of Microelectronics and Communication Engineering, Chongqing University, Chongqing, China","institution_ids":["https://openalex.org/I158842170"]},{"raw_affiliation_string":"Peng Cheng Lab, Shenzhen, China","institution_ids":["https://openalex.org/I4210136793"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101924581","display_name":"Yuhang Zhou","orcid":"https://orcid.org/0000-0002-9221-3331"},"institutions":[{"id":"https://openalex.org/I158842170","display_name":"Chongqing University","ror":"https://ror.org/023rhb549","country_code":"CN","type":"education","lineage":["https://openalex.org/I158842170"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yuhang Zhou","raw_affiliation_strings":["School of Microelectronics and Communication Engineering, Chongqing University, Chongqing, China"],"affiliations":[{"raw_affiliation_string":"School of Microelectronics and Communication Engineering, Chongqing University, Chongqing, China","institution_ids":["https://openalex.org/I158842170"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5005421447","display_name":"Yi Yang","orcid":"https://orcid.org/0000-0002-0512-880X"},"institutions":[{"id":"https://openalex.org/I168879160","display_name":"Zhejiang University of Science and Technology","ror":"https://ror.org/05mx0wr29","country_code":"CN","type":"education","lineage":["https://openalex.org/I168879160"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yi Yang","raw_affiliation_strings":["College of Computer Science and Technology, Zhejiang University, Hangzhou, China"],"affiliations":[{"raw_affiliation_string":"College of Computer Science and Technology, Zhejiang University, Hangzhou, China","institution_ids":["https://openalex.org/I168879160"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5101785348","display_name":"Xinbo Gao","orcid":"https://orcid.org/0000-0003-1443-0776"},"institutions":[{"id":"https://openalex.org/I10535382","display_name":"Chongqing University of Posts and Telecommunications","ror":"https://ror.org/03dgaqz26","country_code":"CN","type":"education","lineage":["https://openalex.org/I10535382"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Xinbo Gao","raw_affiliation_strings":["Chongqing Key Laboratory of Image Cognition, Chongqing University of Posts and Telecommunications, Chongqing, China"],"affiliations":[{"raw_affiliation_string":"Chongqing Key Laboratory of Image Cognition, Chongqing University of Posts and Telecommunications, Chongqing, China","institution_ids":["https://openalex.org/I10535382"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5106578837"],"corresponding_institution_ids":["https://openalex.org/I158842170","https://openalex.org/I4210136793"],"apc_list":null,"apc_paid":null,"fwci":3.1276,"has_fulltext":false,"cited_by_count":9,"citation_normalized_percentile":{"value":0.92253391,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":94,"max":99},"biblio":{"volume":"46","issue":"10","first_page":"6669","last_page":"6687"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9689000248908997,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9441999793052673,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.8268443942070007},{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.7005243897438049},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.6026906371116638},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.580700159072876},{"id":"https://openalex.org/keywords/pattern-recognition","display_name":"Pattern recognition (psychology)","score":0.3746514916419983},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.3283466696739197}],"concepts":[{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.8268443942070007},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.7005243897438049},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.6026906371116638},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.580700159072876},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.3746514916419983},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.3283466696739197},{"id":"https://openalex.org/C185592680","wikidata":"https://www.wikidata.org/wiki/Q2329","display_name":"Chemistry","level":0,"score":0.0},{"id":"https://openalex.org/C55493867","wikidata":"https://www.wikidata.org/wiki/Q7094","display_name":"Biochemistry","level":1,"score":0.0},{"id":"https://openalex.org/C104317684","wikidata":"https://www.wikidata.org/wiki/Q7187","display_name":"Gene","level":2,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1109/tpami.2024.3385745","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tpami.2024.3385745","pdf_url":null,"source":{"id":"https://openalex.org/S199944782","display_name":"IEEE Transactions on Pattern Analysis and Machine Intelligence","issn_l":"0162-8828","issn":["0162-8828","1939-3539","2160-9292"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320439","host_organization_name":"IEEE Computer Society","host_organization_lineage":["https://openalex.org/P4310320439","https://openalex.org/P4310319808"],"host_organization_lineage_names":["IEEE Computer Society","Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Pattern Analysis and Machine Intelligence","raw_type":"journal-article"},{"id":"pmid:38587963","is_oa":false,"landing_page_url":"https://pubmed.ncbi.nlm.nih.gov/38587963","pdf_url":null,"source":{"id":"https://openalex.org/S4306525036","display_name":"PubMed","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I1299303238","host_organization_name":"National Institutes of Health","host_organization_lineage":["https://openalex.org/I1299303238"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE transactions on pattern analysis and machine intelligence","raw_type":null}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G5217806235","display_name":null,"funder_award_id":"62271090","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"}],"funders":[{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":96,"referenced_works":["https://openalex.org/W1673923490","https://openalex.org/W1852255964","https://openalex.org/W1920962657","https://openalex.org/W1945616565","https://openalex.org/W1982250103","https://openalex.org/W1996579288","https://openalex.org/W2001141328","https://openalex.org/W2053186076","https://openalex.org/W2112796928","https://openalex.org/W2123341385","https://openalex.org/W2140095548","https://openalex.org/W2149298154","https://openalex.org/W2156718197","https://openalex.org/W2180612164","https://openalex.org/W2194775991","https://openalex.org/W2243397390","https://openalex.org/W2342045095","https://openalex.org/W2618043096","https://openalex.org/W2746600820","https://openalex.org/W2759358869","https://openalex.org/W2765424254","https://openalex.org/W2768346313","https://openalex.org/W2771622532","https://openalex.org/W2774018344","https://openalex.org/W2774644650","https://openalex.org/W2783784437","https://openalex.org/W2786163515","https://openalex.org/W2895106137","https://openalex.org/W2916286792","https://openalex.org/W2962847335","https://openalex.org/W2963043696","https://openalex.org/W2963070423","https://openalex.org/W2963389226","https://openalex.org/W2963446712","https://openalex.org/W2963693747","https://openalex.org/W2963857521","https://openalex.org/W2963920068","https://openalex.org/W2964082701","https://openalex.org/W2969542116","https://openalex.org/W2976752987","https://openalex.org/W2996490176","https://openalex.org/W2997560666","https://openalex.org/W3009153202","https://openalex.org/W3009213340","https://openalex.org/W3013880646","https://openalex.org/W3034175346","https://openalex.org/W3094502228","https://openalex.org/W3099502074","https://openalex.org/W3103557498","https://openalex.org/W3106050153","https://openalex.org/W3106412272","https://openalex.org/W3122730565","https://openalex.org/W3150450875","https://openalex.org/W3172666366","https://openalex.org/W3195816215","https://openalex.org/W3202281277","https://openalex.org/W3204279503","https://openalex.org/W4214502238","https://openalex.org/W4221160817","https://openalex.org/W4221167724","https://openalex.org/W4225928697","https://openalex.org/W4226239489","https://openalex.org/W4293846201","https://openalex.org/W4312443924","https://openalex.org/W4312716239","https://openalex.org/W4313011609","https://openalex.org/W6637162671","https://openalex.org/W6640425456","https://openalex.org/W6683124652","https://openalex.org/W6683161245","https://openalex.org/W6729756640","https://openalex.org/W6736057607","https://openalex.org/W6739868092","https://openalex.org/W6744817461","https://openalex.org/W6746383792","https://openalex.org/W6746402973","https://openalex.org/W6746608116","https://openalex.org/W6747473890","https://openalex.org/W6748277150","https://openalex.org/W6754979576","https://openalex.org/W6759129252","https://openalex.org/W6759204839","https://openalex.org/W6765597837","https://openalex.org/W6767506513","https://openalex.org/W6768366551","https://openalex.org/W6772461460","https://openalex.org/W6774469542","https://openalex.org/W6783646676","https://openalex.org/W6784333009","https://openalex.org/W6796288065","https://openalex.org/W6796715692","https://openalex.org/W6796913975","https://openalex.org/W6798971518","https://openalex.org/W6803790678","https://openalex.org/W6809830653","https://openalex.org/W6809925265"],"related_works":["https://openalex.org/W2502115930","https://openalex.org/W2482350142","https://openalex.org/W4246396837","https://openalex.org/W3126451824","https://openalex.org/W1561927205","https://openalex.org/W3191453585","https://openalex.org/W4297672492","https://openalex.org/W4310988119","https://openalex.org/W2033914206","https://openalex.org/W2042327336"],"abstract_inverted_index":{"Despite":[0],"providing":[1],"high-performance":[2],"solutions":[3],"for":[4,53],"computer":[5],"vision":[6],"tasks,":[7],"the":[8,29,33,37,116,143,154,180],"deep":[9],"neural":[10],"network":[11],"(DNN)":[12],"model":[13,149],"has":[14,126],"been":[15],"proved":[16],"to":[17,21,36,66,96,114,153],"be":[18],"extremely":[19],"vulnerable":[20],"adversarial":[22,34,54,85,140,156],"attacks.":[23,189],"Current":[24],"defense":[25,55,74,99],"mainly":[26],"focuses":[27],"on":[28,173],"known":[30],"attacks,":[31,103],"but":[32],"robustness":[35,152,182],"unknown":[38,102],"attacks":[39,86],"is":[40,51,58,109],"seriously":[41],"overlooked.":[42],"Besides,":[43],"commonly":[44],"used":[45],"adaptive":[46],"learning":[47],"and":[48,135,139,162,170,183],"fine-tuning":[49],"technique":[50],"unsuitable":[52],"since":[56],"it":[57],"essentially":[59],"a":[60,91,106,120],"zero-shot":[61],"problem":[62],"when":[63],"deployed.":[64],"Thus,":[65],"tackle":[67],"this":[68],"challenge,":[69],"we":[70],"propose":[71],"an":[72],"attack-agnostic":[73],"method":[75],"named":[76],"Meta":[77],"Invariance":[78],"Defense":[79],"(MID).":[80],"Specifically,":[81],"various":[82,188],"combinations":[83],"of":[84,145,185],"are":[87],"randomly":[88],"sampled":[89],"from":[90,132],"manually":[92],"constructed":[93],"Attacker":[94],"Pool":[95],"constitute":[97],"different":[98],"tasks":[100],"against":[101],"in":[104,158,164],"which":[105],"student":[107],"encoder":[108],"supervised":[110],"by":[111],"multi-consistency":[112],"distillation":[113,131],"learn":[115],"attack-invariant":[117],"features":[118],"via":[119],"meta":[121],"principle.":[122],"The":[123,148],"proposed":[124],"MID":[125,186],"two":[127],"merits:":[128],"1)":[129],"Full":[130],"pixel-,":[133],"feature-":[134],"prediction-level":[136],"between":[137],"benign":[138],"samples":[141],"facilitates":[142],"discovery":[144],"attack-invariance.":[146],"2)":[147],"simultaneously":[150],"achieves":[151],"imperceptible":[155],"perturbations":[157],"high-level":[159],"image":[160,167],"classification":[161],"attack-suppression":[163],"low-level":[165],"robust":[166],"regeneration.":[168],"Theoretical":[169],"empirical":[171],"studies":[172],"numerous":[174],"benchmarks":[175],"such":[176],"as":[177],"ImageNet":[178],"verify":[179],"generalizable":[181],"superiority":[184],"under":[187]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2025,"cited_by_count":6},{"year":2024,"cited_by_count":2}],"updated_date":"2026-03-27T05:58:40.876381","created_date":"2025-10-10T00:00:00"}
