{"id":"https://openalex.org/W7123354371","doi":"https://doi.org/10.1109/tpami.2026.3652456","title":"Armor: Shielding Unlearnable Examples Against Data Augmentation","display_name":"Armor: Shielding Unlearnable Examples Against Data Augmentation","publication_year":2026,"publication_date":"2026-01-12","ids":{"openalex":"https://openalex.org/W7123354371","doi":"https://doi.org/10.1109/tpami.2026.3652456","pmid":"https://pubmed.ncbi.nlm.nih.gov/41525586"},"language":"en","primary_location":{"id":"doi:10.1109/tpami.2026.3652456","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tpami.2026.3652456","pdf_url":null,"source":{"id":"https://openalex.org/S199944782","display_name":"IEEE Transactions on Pattern Analysis and Machine Intelligence","issn_l":"0162-8828","issn":["0162-8828","1939-3539","2160-9292"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320439","host_organization_name":"IEEE Computer Society","host_organization_lineage":["https://openalex.org/P4310320439","https://openalex.org/P4310319808"],"host_organization_lineage_names":["IEEE Computer Society","Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Pattern Analysis and Machine Intelligence","raw_type":"journal-article"},"type":"article","indexed_in":["crossref","pubmed"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5122904895","display_name":"Xueluan Gong","orcid":null},"institutions":[{"id":"https://openalex.org/I37461747","display_name":"Wuhan University","ror":"https://ror.org/033vjfk17","country_code":"CN","type":"education","lineage":["https://openalex.org/I37461747"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Xueluan Gong","raw_affiliation_strings":["School of Computer Science, Wuhan University, Wuhan, China"],"affiliations":[{"raw_affiliation_string":"School of Computer Science, Wuhan University, Wuhan, China","institution_ids":["https://openalex.org/I37461747"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5122848696","display_name":"Yuji Wang","orcid":null},"institutions":[{"id":"https://openalex.org/I37461747","display_name":"Wuhan University","ror":"https://ror.org/033vjfk17","country_code":"CN","type":"education","lineage":["https://openalex.org/I37461747"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yuji Wang","raw_affiliation_strings":["School of Cyber Science and Engineering, Wuhan University, Wuhan, China"],"affiliations":[{"raw_affiliation_string":"School of Cyber Science and Engineering, Wuhan University, Wuhan, China","institution_ids":["https://openalex.org/I37461747"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5122906078","display_name":"Yanjiao Chen","orcid":null},"institutions":[{"id":"https://openalex.org/I76130692","display_name":"Zhejiang University","ror":"https://ror.org/00a2xv884","country_code":"CN","type":"education","lineage":["https://openalex.org/I76130692"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yanjiao Chen","raw_affiliation_strings":["College of Electrical Engineering, Zhejiang University, Hangzhou, China"],"affiliations":[{"raw_affiliation_string":"College of Electrical Engineering, Zhejiang University, Hangzhou, China","institution_ids":["https://openalex.org/I76130692"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5122860736","display_name":"Haocheng Dong","orcid":null},"institutions":[{"id":"https://openalex.org/I37461747","display_name":"Wuhan University","ror":"https://ror.org/033vjfk17","country_code":"CN","type":"education","lineage":["https://openalex.org/I37461747"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Haocheng Dong","raw_affiliation_strings":["School of Cyber Science and Engineering, Wuhan University, Wuhan, China"],"affiliations":[{"raw_affiliation_string":"School of Cyber Science and Engineering, Wuhan University, Wuhan, China","institution_ids":["https://openalex.org/I37461747"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5113134285","display_name":"Yiming Li","orcid":"https://orcid.org/0000-0001-5871-2316"},"institutions":[{"id":"https://openalex.org/I172675005","display_name":"Nanyang Technological University","ror":"https://ror.org/02e7b5302","country_code":"SG","type":"education","lineage":["https://openalex.org/I172675005"]}],"countries":["SG"],"is_corresponding":false,"raw_author_name":"Yiming Li","raw_affiliation_strings":["Nanyang Technological University, Singapore"],"affiliations":[{"raw_affiliation_string":"Nanyang Technological University, Singapore","institution_ids":["https://openalex.org/I172675005"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5109833992","display_name":"Sun","orcid":null},"institutions":[{"id":"https://openalex.org/I37461747","display_name":"Wuhan University","ror":"https://ror.org/033vjfk17","country_code":"CN","type":"education","lineage":["https://openalex.org/I37461747"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Mengyuan Sun","raw_affiliation_strings":["School of Cyber Science and Engineering, Wuhan University, Wuhan, China"],"affiliations":[{"raw_affiliation_string":"School of Cyber Science and Engineering, Wuhan University, Wuhan, China","institution_ids":["https://openalex.org/I37461747"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5059696543","display_name":"Shuaike Li","orcid":"https://orcid.org/0009-0006-6063-8817"},"institutions":[{"id":"https://openalex.org/I37461747","display_name":"Wuhan University","ror":"https://ror.org/033vjfk17","country_code":"CN","type":"education","lineage":["https://openalex.org/I37461747"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Shuaike Li","raw_affiliation_strings":["School of Cyber Science and Engineering, Wuhan University, Wuhan, China"],"affiliations":[{"raw_affiliation_string":"School of Cyber Science and Engineering, Wuhan University, Wuhan, China","institution_ids":["https://openalex.org/I37461747"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5122852982","display_name":"Qian Wang","orcid":null},"institutions":[{"id":"https://openalex.org/I37461747","display_name":"Wuhan University","ror":"https://ror.org/033vjfk17","country_code":"CN","type":"education","lineage":["https://openalex.org/I37461747"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Qian Wang","raw_affiliation_strings":["School of Cyber Science and Engineering, Wuhan University, Wuhan, China"],"affiliations":[{"raw_affiliation_string":"School of Cyber Science and Engineering, Wuhan University, Wuhan, China","institution_ids":["https://openalex.org/I37461747"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":8,"corresponding_author_ids":["https://openalex.org/A5122904895"],"corresponding_institution_ids":["https://openalex.org/I37461747"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.09092681,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":"48","issue":"4","first_page":"3988","last_page":"4004"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9293000102043152,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9293000102043152,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.04450000077486038,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11612","display_name":"Stochastic Gradient Optimization Techniques","score":0.00279999990016222,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/generalization","display_name":"Generalization","score":0.5950000286102295},{"id":"https://openalex.org/keywords/data-modeling","display_name":"Data modeling","score":0.5544999837875366},{"id":"https://openalex.org/keywords/noise","display_name":"Noise (video)","score":0.5145000219345093},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.48350000381469727},{"id":"https://openalex.org/keywords/learnability","display_name":"Learnability","score":0.4691999852657318},{"id":"https://openalex.org/keywords/raw-data","display_name":"Raw data","score":0.43470001220703125},{"id":"https://openalex.org/keywords/training-set","display_name":"Training set","score":0.42910000681877136},{"id":"https://openalex.org/keywords/synthetic-data","display_name":"Synthetic data","score":0.3955000042915344},{"id":"https://openalex.org/keywords/information-privacy","display_name":"Information privacy","score":0.39340001344680786},{"id":"https://openalex.org/keywords/differential-privacy","display_name":"Differential privacy","score":0.3828999996185303}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7732999920845032},{"id":"https://openalex.org/C177148314","wikidata":"https://www.wikidata.org/wiki/Q170084","display_name":"Generalization","level":2,"score":0.5950000286102295},{"id":"https://openalex.org/C67186912","wikidata":"https://www.wikidata.org/wiki/Q367664","display_name":"Data modeling","level":2,"score":0.5544999837875366},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5289999842643738},{"id":"https://openalex.org/C99498987","wikidata":"https://www.wikidata.org/wiki/Q2210247","display_name":"Noise (video)","level":3,"score":0.5145000219345093},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.5092999935150146},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.48350000381469727},{"id":"https://openalex.org/C2777723229","wikidata":"https://www.wikidata.org/wiki/Q4367921","display_name":"Learnability","level":2,"score":0.4691999852657318},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.4377000033855438},{"id":"https://openalex.org/C132964779","wikidata":"https://www.wikidata.org/wiki/Q2110223","display_name":"Raw data","level":2,"score":0.43470001220703125},{"id":"https://openalex.org/C51632099","wikidata":"https://www.wikidata.org/wiki/Q3985153","display_name":"Training set","level":2,"score":0.42910000681877136},{"id":"https://openalex.org/C160920958","wikidata":"https://www.wikidata.org/wiki/Q7662746","display_name":"Synthetic data","level":2,"score":0.3955000042915344},{"id":"https://openalex.org/C123201435","wikidata":"https://www.wikidata.org/wiki/Q456632","display_name":"Information privacy","level":2,"score":0.39340001344680786},{"id":"https://openalex.org/C23130292","wikidata":"https://www.wikidata.org/wiki/Q5275358","display_name":"Differential privacy","level":2,"score":0.3828999996185303},{"id":"https://openalex.org/C43214815","wikidata":"https://www.wikidata.org/wiki/Q7310987","display_name":"Reliability (semiconductor)","level":3,"score":0.38280001282691956},{"id":"https://openalex.org/C131675550","wikidata":"https://www.wikidata.org/wiki/Q7646884","display_name":"Surrogate model","level":2,"score":0.36959999799728394},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.3625999987125397},{"id":"https://openalex.org/C141353440","wikidata":"https://www.wikidata.org/wiki/Q182221","display_name":"Fuse (electrical)","level":2,"score":0.36059999465942383},{"id":"https://openalex.org/C2780909371","wikidata":"https://www.wikidata.org/wiki/Q4801092","display_name":"Artificial noise","level":4,"score":0.359499990940094},{"id":"https://openalex.org/C2984842247","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep neural networks","level":3,"score":0.33820000290870667},{"id":"https://openalex.org/C81917197","wikidata":"https://www.wikidata.org/wiki/Q628760","display_name":"Selection (genetic algorithm)","level":2,"score":0.336899995803833},{"id":"https://openalex.org/C21080849","wikidata":"https://www.wikidata.org/wiki/Q13611879","display_name":"Data point","level":2,"score":0.3089999854564667},{"id":"https://openalex.org/C137822555","wikidata":"https://www.wikidata.org/wiki/Q2587068","display_name":"Information sensitivity","level":2,"score":0.3025999963283539},{"id":"https://openalex.org/C93959086","wikidata":"https://www.wikidata.org/wiki/Q6888345","display_name":"Model selection","level":2,"score":0.2985999882221222},{"id":"https://openalex.org/C140547941","wikidata":"https://www.wikidata.org/wiki/Q7797194","display_name":"Threat model","level":2,"score":0.29339998960494995},{"id":"https://openalex.org/C2779280203","wikidata":"https://www.wikidata.org/wiki/Q17121211","display_name":"Small data","level":2,"score":0.2770000100135803},{"id":"https://openalex.org/C55037315","wikidata":"https://www.wikidata.org/wiki/Q5421151","display_name":"Experimental data","level":2,"score":0.27649998664855957},{"id":"https://openalex.org/C2776196576","wikidata":"https://www.wikidata.org/wiki/Q196113","display_name":"Camouflage","level":2,"score":0.2639000117778778},{"id":"https://openalex.org/C2776145971","wikidata":"https://www.wikidata.org/wiki/Q30673951","display_name":"Labeled data","level":2,"score":0.2621000111103058},{"id":"https://openalex.org/C29265498","wikidata":"https://www.wikidata.org/wiki/Q7047719","display_name":"Noise measurement","level":3,"score":0.25839999318122864},{"id":"https://openalex.org/C102366305","wikidata":"https://www.wikidata.org/wiki/Q1097688","display_name":"Nonparametric statistics","level":2,"score":0.25690001249313354},{"id":"https://openalex.org/C193519340","wikidata":"https://www.wikidata.org/wiki/Q891179","display_name":"Data loss","level":2,"score":0.2522999942302704},{"id":"https://openalex.org/C2781170535","wikidata":"https://www.wikidata.org/wiki/Q30587856","display_name":"Noisy data","level":2,"score":0.25060001015663147}],"mesh":[],"locations_count":3,"locations":[{"id":"doi:10.1109/tpami.2026.3652456","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tpami.2026.3652456","pdf_url":null,"source":{"id":"https://openalex.org/S199944782","display_name":"IEEE Transactions on Pattern Analysis and Machine Intelligence","issn_l":"0162-8828","issn":["0162-8828","1939-3539","2160-9292"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320439","host_organization_name":"IEEE Computer Society","host_organization_lineage":["https://openalex.org/P4310320439","https://openalex.org/P4310319808"],"host_organization_lineage_names":["IEEE Computer Society","Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Pattern Analysis and Machine Intelligence","raw_type":"journal-article"},{"id":"pmid:41525586","is_oa":false,"landing_page_url":"https://pubmed.ncbi.nlm.nih.gov/41525586","pdf_url":null,"source":{"id":"https://openalex.org/S4306525036","display_name":"PubMed","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I1299303238","host_organization_name":"National Institutes of Health","host_organization_lineage":["https://openalex.org/I1299303238"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE transactions on pattern analysis and machine intelligence","raw_type":null},{"id":"pmh:oai:dr.ntu.edu.sg:10356/212397","is_oa":false,"landing_page_url":"https://hdl.handle.net/10356/212397","pdf_url":null,"source":{"id":"https://openalex.org/S4306402609","display_name":"DR-NTU (Nanyang Technological University)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I172675005","host_organization_name":"Nanyang Technological University","host_organization_lineage":["https://openalex.org/I172675005"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"Journal Article"}],"best_oa_location":null,"sustainable_development_goals":[{"score":0.6811465620994568,"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16"}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":26,"referenced_works":["https://openalex.org/W2025183033","https://openalex.org/W2140196014","https://openalex.org/W2325939864","https://openalex.org/W2799040448","https://openalex.org/W2884283597","https://openalex.org/W2949736877","https://openalex.org/W2963091558","https://openalex.org/W2963384482","https://openalex.org/W2963587345","https://openalex.org/W3008297566","https://openalex.org/W3035682985","https://openalex.org/W3047916742","https://openalex.org/W3089683609","https://openalex.org/W3162804012","https://openalex.org/W3163966458","https://openalex.org/W3185321995","https://openalex.org/W4226323522","https://openalex.org/W4247999480","https://openalex.org/W4285292458","https://openalex.org/W4293846201","https://openalex.org/W4312937923","https://openalex.org/W4313178187","https://openalex.org/W4367047222","https://openalex.org/W4387965340","https://openalex.org/W4396790395","https://openalex.org/W4403908451"],"related_works":[],"abstract_inverted_index":{"Private":[0],"data,":[1],"when":[2],"published":[3],"online,":[4],"may":[5,67],"be":[6,23],"collected":[7],"by":[8,32,85,277],"unauthorized":[9],"parties":[10],"to":[11,25,28,43,94,131,144,162,200,218,237,292],"train":[12],"deep":[13],"neural":[14],"networks":[15],"(DNNs).":[16],"To":[17,133,154],"protect":[18,145],"privacy,":[19],"defensive":[20,221],"noises":[21],"can":[22,117,253],"added":[24],"original":[26],"samples":[27,276],"degrade":[29],"their":[30],"learnability":[31],"DNNs.":[33],"Recently,":[34],"unlearnable":[35,127],"examples":[36,128],"(Huang":[37],"et":[38],"al.,":[39],"2021)":[40],"are":[41,58,110,227],"proposed":[42],"minimize":[44],"the":[45,50,69,80,101,120,123,156,163,177,202,220,239,255,266,270],"training":[46,165],"loss":[47],"such":[48],"that":[49,114,174,191,251,288],"model":[51,96,124,164,173,271],"learns":[52],"almost":[53],"nothing.":[54],"However,":[55],"raw":[56],"data":[57,81,86,91,115,146,152,180,234,260,262],"often":[59],"pre-processed":[60],"before":[61],"being":[62],"used":[63,90],"for":[64,206],"training,":[65],"which":[66,99],"restore":[68],"private":[70,259],"information":[71],"of":[72,103,122,151,158,179,241,257,269],"protected":[73,258,275],"data.":[74],"In":[75,182],"this":[76,135],"paper,":[77],"we":[78,109,137,167,184],"reveal":[79],"privacy":[82,147],"violation":[83],"induced":[84],"augmentation,":[87],"a":[88,139,169,186,212],"commonly":[89],"pre-processing":[92],"technique":[93],"improve":[95],"generalization":[97],"capability,":[98],"is":[100,290],"first":[102],"its":[104],"kind":[105],"as":[106,108,278,280],"far":[107],"concerned.":[111],"We":[112,209,285,295],"demonstrate":[113],"augmentation":[116,188,204,235],"significantly":[118],"raise":[119],"accuracy":[121,268],"trained":[125,272],"on":[126,229,273],"from":[129,148],"21.3%":[130],"66.1%.":[132],"address":[134],"issue,":[136],"propose":[138],"defense":[140,247],"framework,":[141],"dubbed":[142],"Armor,":[143],"potential":[149],"breaches":[150],"augmentation.":[153,181,263],"overcome":[155],"difficulty":[157],"having":[159],"no":[160],"access":[161],"process,":[166],"design":[168,185],"non-local":[170],"module-assisted":[171],"surrogate":[172,187],"better":[175],"captures":[176],"effect":[178],"addition,":[183],"selection":[189],"strategy":[190,205],"maximizes":[192],"distribution":[193],"alignment":[194],"between":[195],"augmented":[196,274],"and":[197,232],"non-augmented":[198],"samples,":[199],"choose":[201],"optimal":[203],"each":[207],"class.":[208],"also":[210,286],"use":[211],"dynamic":[213],"step":[214],"size":[215],"adjustment":[216],"algorithm":[217],"enhance":[219],"noise":[222],"generation":[223],"process.":[224],"Extensive":[225],"experiments":[226],"conducted":[228],"4":[230],"datasets":[231],"5":[233],"methods":[236,248],"verify":[238],"performance":[240],"Armor.":[242],"Comparisons":[243],"with":[244],"6":[245],"state-of-the-art":[246],"have":[249],"demonstrated":[250],"Armor":[252,264,289],"preserve":[254],"unlearnability":[256],"under":[261],"reduces":[265],"test":[267],"much":[279],"60%":[281],"more":[282],"than":[283],"baselines.":[284],"show":[287],"robust":[291],"adversarial":[293],"training.":[294],"will":[296],"open-source":[297],"our":[298],"codes":[299],"upon":[300],"publication.":[301]},"counts_by_year":[],"updated_date":"2026-04-04T08:04:53.788161","created_date":"2026-01-14T00:00:00"}
