{"id":"https://openalex.org/W4414563739","doi":"https://doi.org/10.1109/tpami.2025.3614495","title":"M3C: Resist Agnostic Attacks by Mitigating Consistent Class Confusion Prior","display_name":"M3C: Resist Agnostic Attacks by Mitigating Consistent Class Confusion Prior","publication_year":2025,"publication_date":"2025-09-25","ids":{"openalex":"https://openalex.org/W4414563739","doi":"https://doi.org/10.1109/tpami.2025.3614495","pmid":"https://pubmed.ncbi.nlm.nih.gov/40996997"},"language":"en","primary_location":{"id":"doi:10.1109/tpami.2025.3614495","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tpami.2025.3614495","pdf_url":null,"source":{"id":"https://openalex.org/S199944782","display_name":"IEEE Transactions on Pattern Analysis and Machine Intelligence","issn_l":"0162-8828","issn":["0162-8828","1939-3539","2160-9292"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320439","host_organization_name":"IEEE Computer Society","host_organization_lineage":["https://openalex.org/P4310320439","https://openalex.org/P4310319808"],"host_organization_lineage_names":["IEEE Computer Society","Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Pattern Analysis and Machine Intelligence","raw_type":"journal-article"},"type":"article","indexed_in":["crossref","pubmed"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5082943474","display_name":"Xiaowei Fu","orcid":null},"institutions":[{"id":"https://openalex.org/I158842170","display_name":"Chongqing University","ror":"https://ror.org/023rhb549","country_code":"CN","type":"education","lineage":["https://openalex.org/I158842170"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Xiaowei Fu","raw_affiliation_strings":["School of Microelectronics and Communication Engineering, Chongqing University, Chongqing, China"],"affiliations":[{"raw_affiliation_string":"School of Microelectronics and Communication Engineering, Chongqing University, Chongqing, China","institution_ids":["https://openalex.org/I158842170"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5028808297","display_name":"Fuxiang Huang","orcid":null},"institutions":[{"id":"https://openalex.org/I158842170","display_name":"Chongqing University","ror":"https://ror.org/023rhb549","country_code":"CN","type":"education","lineage":["https://openalex.org/I158842170"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Fuxiang Huang","raw_affiliation_strings":["Chongqing Key Laboratory of Bio-perception and Multimodal Intelligent Information Processing, Chongqing University, Chongqing, China"],"affiliations":[{"raw_affiliation_string":"Chongqing Key Laboratory of Bio-perception and Multimodal Intelligent Information Processing, Chongqing University, Chongqing, China","institution_ids":["https://openalex.org/I158842170"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5031220156","display_name":"Guoyin Wang","orcid":"https://orcid.org/0000-0002-8521-5232"},"institutions":[{"id":"https://openalex.org/I126924076","display_name":"Chongqing Normal University","ror":"https://ror.org/01dcw5w74","country_code":"CN","type":"education","lineage":["https://openalex.org/I126924076"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Guoyin Wang","raw_affiliation_strings":["National Center for Applied Mathematics in Chongqing, Chongqing Normal University, Chongqing, China"],"affiliations":[{"raw_affiliation_string":"National Center for Applied Mathematics in Chongqing, Chongqing Normal University, Chongqing, China","institution_ids":["https://openalex.org/I126924076"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101785348","display_name":"Xinbo Gao","orcid":"https://orcid.org/0000-0003-1443-0776"},"institutions":[{"id":"https://openalex.org/I10535382","display_name":"Chongqing University of Posts and Telecommunications","ror":"https://ror.org/03dgaqz26","country_code":"CN","type":"education","lineage":["https://openalex.org/I10535382"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Xinbo Gao","raw_affiliation_strings":["Chongqing Key Laboratory of Image Cognition, Chongqing University of Posts and Telecommunications, Chongqing, China"],"affiliations":[{"raw_affiliation_string":"Chongqing Key Laboratory of Image Cognition, Chongqing University of Posts and Telecommunications, Chongqing, China","institution_ids":["https://openalex.org/I10535382"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5100433931","display_name":"Lei Zhang","orcid":"https://orcid.org/0000-0002-5808-5313"},"institutions":[{"id":"https://openalex.org/I158842170","display_name":"Chongqing University","ror":"https://ror.org/023rhb549","country_code":"CN","type":"education","lineage":["https://openalex.org/I158842170"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Lei Zhang","raw_affiliation_strings":["School of Microelectronics and Communication Engineering, Chongqing University, Chongqing, China"],"affiliations":[{"raw_affiliation_string":"School of Microelectronics and Communication Engineering, Chongqing University, Chongqing, China","institution_ids":["https://openalex.org/I158842170"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5082943474"],"corresponding_institution_ids":["https://openalex.org/I158842170"],"apc_list":null,"apc_paid":null,"fwci":5.6662,"has_fulltext":false,"cited_by_count":2,"citation_normalized_percentile":{"value":0.96062428,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":91,"max":99},"biblio":{"volume":"48","issue":"2","first_page":"1390","last_page":"1406"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9916999936103821,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9916999936103821,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9905999898910522,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11775","display_name":"COVID-19 diagnosis using AI","score":0.977400004863739,"subfield":{"id":"https://openalex.org/subfields/2741","display_name":"Radiology, Nuclear Medicine and Imaging"},"field":{"id":"https://openalex.org/fields/27","display_name":"Medicine"},"domain":{"id":"https://openalex.org/domains/4","display_name":"Health Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.9247999787330627},{"id":"https://openalex.org/keywords/confusion","display_name":"Confusion","score":0.6687999963760376},{"id":"https://openalex.org/keywords/class","display_name":"Class (philosophy)","score":0.5580000281333923},{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.5475000143051147},{"id":"https://openalex.org/keywords/classifier","display_name":"Classifier (UML)","score":0.5336999893188477},{"id":"https://openalex.org/keywords/perspective","display_name":"Perspective (graphical)","score":0.4684000015258789},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.430400013923645},{"id":"https://openalex.org/keywords/generalization","display_name":"Generalization","score":0.4284999966621399}],"concepts":[{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.9247999787330627},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.760699987411499},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.6888999938964844},{"id":"https://openalex.org/C2781140086","wikidata":"https://www.wikidata.org/wiki/Q557945","display_name":"Confusion","level":2,"score":0.6687999963760376},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.5777999758720398},{"id":"https://openalex.org/C2777212361","wikidata":"https://www.wikidata.org/wiki/Q5127848","display_name":"Class (philosophy)","level":2,"score":0.5580000281333923},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.5475000143051147},{"id":"https://openalex.org/C95623464","wikidata":"https://www.wikidata.org/wiki/Q1096149","display_name":"Classifier (UML)","level":2,"score":0.5336999893188477},{"id":"https://openalex.org/C12713177","wikidata":"https://www.wikidata.org/wiki/Q1900281","display_name":"Perspective (graphical)","level":2,"score":0.4684000015258789},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.430400013923645},{"id":"https://openalex.org/C177148314","wikidata":"https://www.wikidata.org/wiki/Q170084","display_name":"Generalization","level":2,"score":0.4284999966621399},{"id":"https://openalex.org/C192209626","wikidata":"https://www.wikidata.org/wiki/Q190909","display_name":"Focus (optics)","level":2,"score":0.4108000099658966},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.3716999888420105},{"id":"https://openalex.org/C2984842247","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep neural networks","level":3,"score":0.36660000681877136},{"id":"https://openalex.org/C2778403875","wikidata":"https://www.wikidata.org/wiki/Q20312394","display_name":"Adversarial machine learning","level":3,"score":0.3407999873161316},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.3181000053882599},{"id":"https://openalex.org/C138602881","wikidata":"https://www.wikidata.org/wiki/Q2709591","display_name":"Confusion matrix","level":2,"score":0.295199990272522},{"id":"https://openalex.org/C140547941","wikidata":"https://www.wikidata.org/wiki/Q7797194","display_name":"Threat model","level":2,"score":0.2718000113964081},{"id":"https://openalex.org/C2776650193","wikidata":"https://www.wikidata.org/wiki/Q264661","display_name":"Obstacle","level":2,"score":0.26579999923706055},{"id":"https://openalex.org/C136197465","wikidata":"https://www.wikidata.org/wiki/Q1729295","display_name":"Variety (cybernetics)","level":2,"score":0.2653000056743622},{"id":"https://openalex.org/C75294576","wikidata":"https://www.wikidata.org/wiki/Q5165192","display_name":"Contextual image classification","level":3,"score":0.2621999979019165},{"id":"https://openalex.org/C105339364","wikidata":"https://www.wikidata.org/wiki/Q2297740","display_name":"Software deployment","level":2,"score":0.2612999975681305}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1109/tpami.2025.3614495","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tpami.2025.3614495","pdf_url":null,"source":{"id":"https://openalex.org/S199944782","display_name":"IEEE Transactions on Pattern Analysis and Machine Intelligence","issn_l":"0162-8828","issn":["0162-8828","1939-3539","2160-9292"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320439","host_organization_name":"IEEE Computer Society","host_organization_lineage":["https://openalex.org/P4310320439","https://openalex.org/P4310319808"],"host_organization_lineage_names":["IEEE Computer Society","Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Pattern Analysis and Machine Intelligence","raw_type":"journal-article"},{"id":"pmid:40996997","is_oa":false,"landing_page_url":"https://pubmed.ncbi.nlm.nih.gov/40996997","pdf_url":null,"source":{"id":"https://openalex.org/S4306525036","display_name":"PubMed","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I1299303238","host_organization_name":"National Institutes of Health","host_organization_lineage":["https://openalex.org/I1299303238"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE transactions on pattern analysis and machine intelligence","raw_type":null}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":36,"referenced_works":["https://openalex.org/W2025768430","https://openalex.org/W2194775991","https://openalex.org/W2243397390","https://openalex.org/W2342045095","https://openalex.org/W2603766943","https://openalex.org/W2618043096","https://openalex.org/W2745565856","https://openalex.org/W2765424254","https://openalex.org/W2774644650","https://openalex.org/W2962847335","https://openalex.org/W2962858109","https://openalex.org/W2963693747","https://openalex.org/W2963857521","https://openalex.org/W2964082701","https://openalex.org/W2964137095","https://openalex.org/W2969542116","https://openalex.org/W2986093954","https://openalex.org/W3034190247","https://openalex.org/W3035402405","https://openalex.org/W3093070413","https://openalex.org/W3132864771","https://openalex.org/W3168784243","https://openalex.org/W3177410622","https://openalex.org/W3195816215","https://openalex.org/W4226058100","https://openalex.org/W4292347911","https://openalex.org/W4360798603","https://openalex.org/W4386057757","https://openalex.org/W4386065434","https://openalex.org/W4386075665","https://openalex.org/W4387449166","https://openalex.org/W4391791565","https://openalex.org/W4391952619","https://openalex.org/W4402715799","https://openalex.org/W4402727921","https://openalex.org/W4409262275"],"related_works":[],"abstract_inverted_index":{"Adversarial":[0,30,147],"attack":[1],"is":[2,152],"a":[3,67,82,106,119,128,187,240,247],"major":[4],"obstacle":[5],"to":[6,40,56,73,139,156,167,192,250],"the":[7,36,63,98,158,164,194,218,229,233],"deployment":[8],"of":[9,35,197,220,228,243],"deep":[10],"neural":[11,42],"networks":[12,43],"(DNNs)":[13],"for":[14,70,237],"security-sensitive":[15],"applications.":[16],"To":[17,173],"address":[18],"these":[19,170],"adversarial":[20,23,45],"perturbations,":[21],"various":[22,71,86],"defense":[24],"strategies":[25],"have":[26],"been":[27],"developed,":[28],"with":[29],"Training":[31],"(AT)":[32],"being":[33],"one":[34],"most":[37,159],"effective":[38],"methods":[39,50],"protect":[41],"from":[44],"attacks.":[46,112,142,225],"However,":[47],"existing":[48],"AT":[49,64,94,131,165,221],"struggle":[51],"against":[52,223,239],"training-agnostic":[53,141],"attacks":[54,72],"due":[55],"their":[57],"limited":[58],"generalizability.":[59],"This":[60,77],"suggests":[61],"that":[62,212],"models":[65],"lack":[66],"unified":[68],"perspective":[69,249],"conduct":[74],"universal":[75],"defense.":[76],"paper":[78],"sheds":[79],"light":[80],"on":[81,114,169,205],"generalizable":[83],"prior":[84,117,231],"under":[85],"attacks:":[87],"consistent":[88,135],"class":[89,136,183,202],"confusion":[90,137],"(3C),":[91],"i.e.,":[92],"an":[93,146],"classifier":[95],"often":[96],"confuses":[97],"predictions":[99,179],"between":[100,121],"correct":[101,178,198],"and":[102,123,162,180,200,208,235,245],"ambiguous":[103],"classes":[104,161,199],"in":[105,254],"highly":[107],"similar":[108],"pattern":[109],"among":[110],"diverse":[111],"Relying":[113],"this":[115,255],"latent":[116],"as":[118],"bridge":[120],"seen":[122],"agnostic":[124,224],"attacks,":[125,244],"we":[126,144,185],"propose":[127,186],"more":[129],"generalized":[130],"model":[132,166,215],"by":[133,154],"mitigating":[134],"(M3C)":[138],"resist":[140],"Specifically,":[143],"optimize":[145],"Confusion":[148],"Loss":[149],"(ACL),":[150],"which":[151],"weighted":[153],"uncertainty,":[155],"distinguish":[157],"confused":[160,171],"encourage":[163],"focus":[168],"samples.":[172],"suppress":[174],"malignant":[175],"features":[176],"affecting":[177],"producing":[181],"significant":[182],"confusion,":[184],"Gradient-Aware":[188],"Attention":[189],"(GAA)":[190],"mechanism":[191],"enhance":[193],"classification":[195],"confidence":[196],"eliminate":[201],"confusion.":[203],"Experiments":[204],"multiple":[206],"benchmarks":[207],"network":[209],"frameworks":[210],"demonstrate":[211],"our":[213],"M3C":[214],"significantly":[216],"improves":[217],"generalization":[219],"robustness":[222],"The":[226],"finding":[227],"3C":[230],"reveals":[232],"potential":[234],"possibility":[236],"defending":[238],"wide":[241],"range":[242],"provides":[246],"new":[248],"overcome":[251],"such":[252],"challenge":[253],"field.":[256]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2025,"cited_by_count":1}],"updated_date":"2026-03-07T16:01:11.037858","created_date":"2025-10-10T00:00:00"}
