{"id":"https://openalex.org/W7137952227","doi":"https://doi.org/10.1609/aaai.v40i7.37452","title":"Diversifying Counterattacks: Orthogonal Exploration for Robust CLlP Inference","display_name":"Diversifying Counterattacks: Orthogonal Exploration for Robust CLlP Inference","publication_year":2026,"publication_date":"2026-03-14","ids":{"openalex":"https://openalex.org/W7137952227","doi":"https://doi.org/10.1609/aaai.v40i7.37452"},"language":null,"primary_location":{"id":"doi:10.1609/aaai.v40i7.37452","is_oa":true,"landing_page_url":"https://doi.org/10.1609/aaai.v40i7.37452","pdf_url":null,"source":{"id":"https://openalex.org/S4210191458","display_name":"Proceedings of the AAAI Conference on Artificial Intelligence","issn_l":"2159-5399","issn":["2159-5399","2374-3468"],"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/P4310320058","host_organization_name":"Association for the Advancement of Artificial Intelligence","host_organization_lineage":["https://openalex.org/P4310320058"],"host_organization_lineage_names":["Association for the Advancement of Artificial Intelligence"],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the AAAI Conference on Artificial Intelligence","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"diamond","oa_url":"https://doi.org/10.1609/aaai.v40i7.37452","any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5061961316","display_name":"Chengze Jiang","orcid":"https://orcid.org/0000-0002-1681-8128"},"institutions":[{"id":"https://openalex.org/I76569877","display_name":"Southeast University","ror":"https://ror.org/04ct4d772","country_code":"CN","type":"education","lineage":["https://openalex.org/I76569877"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Chengze Jiang","raw_affiliation_strings":["Southeast University, Nanjing, China"],"affiliations":[{"raw_affiliation_string":"Southeast University, Nanjing, China","institution_ids":["https://openalex.org/I76569877"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5129707200","display_name":"Minjing Dong","orcid":null},"institutions":[{"id":"https://openalex.org/I168719708","display_name":"City University of Hong Kong","ror":"https://ror.org/03q8dnn23","country_code":"HK","type":"education","lineage":["https://openalex.org/I168719708"]}],"countries":["HK"],"is_corresponding":false,"raw_author_name":"Minjing Dong","raw_affiliation_strings":["City University of Hong Kong, Hong Kong"],"affiliations":[{"raw_affiliation_string":"City University of Hong Kong, Hong Kong","institution_ids":["https://openalex.org/I168719708"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5129642585","display_name":"Xinli Shi","orcid":null},"institutions":[{"id":"https://openalex.org/I76569877","display_name":"Southeast University","ror":"https://ror.org/04ct4d772","country_code":"CN","type":"education","lineage":["https://openalex.org/I76569877"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Xinli Shi","raw_affiliation_strings":["Southeast University, Nanjing, China"],"affiliations":[{"raw_affiliation_string":"Southeast University, Nanjing, China","institution_ids":["https://openalex.org/I76569877"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5129709112","display_name":"Jie Gui","orcid":null},"institutions":[{"id":"https://openalex.org/I4210155350","display_name":"Purple Mountain Laboratories","ror":"https://ror.org/04zcbk583","country_code":"CN","type":"facility","lineage":["https://openalex.org/I4210155350"]},{"id":"https://openalex.org/I76569877","display_name":"Southeast University","ror":"https://ror.org/04ct4d772","country_code":"CN","type":"education","lineage":["https://openalex.org/I76569877"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Jie Gui","raw_affiliation_strings":["Southeast University, Nanjing, China\nEngineering Research Center of Blockchain Application, Supervision And Management (Southeast University), Ministry of Education, China\nPurple Mountain Laboratories, China"],"affiliations":[{"raw_affiliation_string":"Southeast University, Nanjing, China\nEngineering Research Center of Blockchain Application, Supervision And Management (Southeast University), Ministry of Education, China\nPurple Mountain Laboratories, China","institution_ids":["https://openalex.org/I4210155350","https://openalex.org/I76569877"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5061961316"],"corresponding_institution_ids":["https://openalex.org/I76569877"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.16648822,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":"40","issue":"7","first_page":"5359","last_page":"5368"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.991599977016449,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.991599977016449,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10883","display_name":"Ethics and Social Impacts of AI","score":0.0010999999940395355,"subfield":{"id":"https://openalex.org/subfields/3311","display_name":"Safety Research"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}},{"id":"https://openalex.org/T10036","display_name":"Advanced Neural Network Applications","score":0.0010000000474974513,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.8962000012397766},{"id":"https://openalex.org/keywords/counterattack","display_name":"Counterattack","score":0.786300003528595},{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.6193000078201294},{"id":"https://openalex.org/keywords/inference","display_name":"Inference","score":0.48330000042915344},{"id":"https://openalex.org/keywords/overfitting","display_name":"Overfitting","score":0.38350000977516174},{"id":"https://openalex.org/keywords/embedding","display_name":"Embedding","score":0.32519999146461487}],"concepts":[{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.8962000012397766},{"id":"https://openalex.org/C2776617961","wikidata":"https://www.wikidata.org/wiki/Q2329143","display_name":"Counterattack","level":2,"score":0.786300003528595},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.6193000078201294},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.5971999764442444},{"id":"https://openalex.org/C2776214188","wikidata":"https://www.wikidata.org/wiki/Q408386","display_name":"Inference","level":2,"score":0.48330000042915344},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.46720001101493835},{"id":"https://openalex.org/C22019652","wikidata":"https://www.wikidata.org/wiki/Q331309","display_name":"Overfitting","level":3,"score":0.38350000977516174},{"id":"https://openalex.org/C126255220","wikidata":"https://www.wikidata.org/wiki/Q141495","display_name":"Mathematical optimization","level":1,"score":0.3361999988555908},{"id":"https://openalex.org/C41608201","wikidata":"https://www.wikidata.org/wiki/Q980509","display_name":"Embedding","level":2,"score":0.32519999146461487},{"id":"https://openalex.org/C21200559","wikidata":"https://www.wikidata.org/wiki/Q7451068","display_name":"Sensitivity (control systems)","level":2,"score":0.3230000138282776},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.3176000118255615},{"id":"https://openalex.org/C181335050","wikidata":"https://www.wikidata.org/wiki/Q14915018","display_name":"Swarm behaviour","level":2,"score":0.3037000000476837},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.3005000054836273},{"id":"https://openalex.org/C137836250","wikidata":"https://www.wikidata.org/wiki/Q984063","display_name":"Optimization problem","level":2,"score":0.2870999872684479},{"id":"https://openalex.org/C11413529","wikidata":"https://www.wikidata.org/wiki/Q8366","display_name":"Algorithm","level":1,"score":0.2712000012397766},{"id":"https://openalex.org/C111030470","wikidata":"https://www.wikidata.org/wiki/Q1430460","display_name":"Curse of dimensionality","level":2,"score":0.25850000977516174},{"id":"https://openalex.org/C70518039","wikidata":"https://www.wikidata.org/wiki/Q16000077","display_name":"Dimensionality reduction","level":2,"score":0.25529998540878296}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1609/aaai.v40i7.37452","is_oa":true,"landing_page_url":"https://doi.org/10.1609/aaai.v40i7.37452","pdf_url":null,"source":{"id":"https://openalex.org/S4210191458","display_name":"Proceedings of the AAAI Conference on Artificial Intelligence","issn_l":"2159-5399","issn":["2159-5399","2374-3468"],"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/P4310320058","host_organization_name":"Association for the Advancement of Artificial Intelligence","host_organization_lineage":["https://openalex.org/P4310320058"],"host_organization_lineage_names":["Association for the Advancement of Artificial Intelligence"],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the AAAI Conference on Artificial Intelligence","raw_type":"journal-article"}],"best_oa_location":{"id":"doi:10.1609/aaai.v40i7.37452","is_oa":true,"landing_page_url":"https://doi.org/10.1609/aaai.v40i7.37452","pdf_url":null,"source":{"id":"https://openalex.org/S4210191458","display_name":"Proceedings of the AAAI Conference on Artificial Intelligence","issn_l":"2159-5399","issn":["2159-5399","2374-3468"],"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/P4310320058","host_organization_name":"Association for the Advancement of Artificial Intelligence","host_organization_lineage":["https://openalex.org/P4310320058"],"host_organization_lineage_names":["Association for the Advancement of Artificial Intelligence"],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the AAAI Conference on Artificial Intelligence","raw_type":"journal-article"},"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/10","display_name":"Reduced inequalities","score":0.612121045589447}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"Vision-language":[0],"pre-training":[1],"models":[2],"(VLPs)":[3],"demonstrate":[4,207],"strong":[5],"multimodal":[6],"understanding":[7],"and":[8,61,92,113,142,154,168,196],"zero-shot":[9],"generalization,":[10],"yet":[11],"remain":[12],"vulnerable":[13],"to":[14,51,71,78,96,119,173,189],"adversarial":[15,38,47,59,73,90,121,175,211],"examples,":[16],"raising":[17],"concerns":[18],"about":[19],"their":[20,46],"reliability.":[21],"Recent":[22],"work,":[23,106],"Test-Time":[24],"Counterattack":[25,131],"(TTC),":[26],"improves":[27,170,210],"robustness":[28,122,212],"by":[29,137,192],"generating":[30,63],"perturbations":[31],"that":[32,109,208],"maximize":[33],"the":[34,52,72,76,85,94,111,148,151,156,162,171,199],"embedding":[35],"deviation":[36],"of":[37,102,115,150,158,164],"inputs":[39],"using":[40],"PGD,":[41],"pushing":[42],"them":[43],"away":[44],"from":[45],"representations.":[48],"However,":[49],"due":[50],"fundamental":[53],"difference":[54],"in":[55,123],"optimization":[56,136],"objectives":[57],"between":[58],"attacks":[60,215],"counterattacks,":[62],"counterattacks":[64,86,116,167],"solely":[65],"based":[66,184],"on":[67,185,204],"gradients":[68],"with":[69],"respect":[70],"input":[74],"confines":[75],"search":[77],"a":[79,83,99,180],"narrow":[80],"space.":[81],"As":[82],"result,":[84],"could":[87],"overfit":[88],"limited":[89],"patterns":[91],"lack":[93],"diversity":[95,112,157],"fully":[97],"neutralize":[98,174],"broad":[100],"range":[101],"perturbations.":[103,176],"In":[104],"this":[105],"we":[107,127,178],"argue":[108],"enhancing":[110],"coverage":[114],"is":[117],"crucial":[118],"improving":[120,193],"test-time":[124],"defense.":[125],"Accordingly,":[126],"propose":[128],"Directional":[129],"Orthogonal":[130],"(DOC),":[132],"which":[133,160],"augments":[134],"counterattack":[135,152,200],"incorporating":[138],"orthogonal":[139],"gradient":[140],"directions":[141],"momentum-based":[143],"updates.":[144],"This":[145],"design":[146],"expands":[147],"exploration":[149],"space":[153],"increases":[155],"perturbations,":[159],"facilitates":[161],"discovery":[163],"more":[165],"generalizable":[166],"ultimately":[169],"ability":[172],"Meanwhile,":[177],"present":[179],"directional":[181],"sensitivity":[182],"score":[183],"averaged":[186],"cosine":[187],"similarity":[188],"boost":[190],"DOC":[191,209],"example":[194],"discrimination":[195],"adaptively":[197],"modulating":[198],"strength.":[201],"Extensive":[202],"experiments":[203],"16":[205],"datasets":[206],"under":[213],"various":[214],"while":[216],"maintaining":[217],"competitive":[218],"clean":[219],"accuracy.":[220]},"counts_by_year":[],"updated_date":"2026-03-20T20:47:17.329874","created_date":"2026-03-18T00:00:00"}
