BibTeX records: Yinpeng Dong

download as .bib file

@article{DBLP:journals/isci/ZhangDZZKY24,
  author       = {Jinlai Zhang and
                  Yinpeng Dong and
                  Jun Zhu and
                  Jihong Zhu and
                  Minchi Kuang and
                  Xiaming Yuan},
  title        = {Improving transferability of 3D adversarial attacks with scale and
                  shear transformations},
  journal      = {Inf. Sci.},
  volume       = {662},
  pages        = {120245},
  year         = {2024},
  url          = {https://doi.org/10.1016/j.ins.2024.120245},
  doi          = {10.1016/J.INS.2024.120245},
  timestamp    = {Tue, 28 May 2024 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/journals/isci/ZhangDZZKY24.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/iclr/ChenZDY0024,
  author       = {Huanran Chen and
                  Yichi Zhang and
                  Yinpeng Dong and
                  Xiao Yang and
                  Hang Su and
                  Jun Zhu},
  title        = {Rethinking Model Ensemble in Transfer-based Adversarial Attacks},
  booktitle    = {The Twelfth International Conference on Learning Representations,
                  {ICLR} 2024, Vienna, Austria, May 7-11, 2024},
  publisher    = {OpenReview.net},
  year         = {2024},
  url          = {https://openreview.net/forum?id=AcJrSoArlh},
  timestamp    = {Wed, 07 Aug 2024 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/conf/iclr/ChenZDY0024.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/iclr/WuYDX0024,
  author       = {Lingxuan Wu and
                  Xiao Yang and
                  Yinpeng Dong and
                  Liuwei Xie and
                  Hang Su and
                  Jun Zhu},
  title        = {Embodied Active Defense: Leveraging Recurrent Feedback to Counter
                  Adversarial Patches},
  booktitle    = {The Twelfth International Conference on Learning Representations,
                  {ICLR} 2024, Vienna, Austria, May 7-11, 2024},
  publisher    = {OpenReview.net},
  year         = {2024},
  url          = {https://openreview.net/forum?id=uXjfOmTiDt},
  timestamp    = {Wed, 07 Aug 2024 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/conf/iclr/WuYDX0024.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/icml/ChenDWYD0024,
  author       = {Huanran Chen and
                  Yinpeng Dong and
                  Zhengyi Wang and
                  Xiao Yang and
                  Chengqi Duan and
                  Hang Su and
                  Jun Zhu},
  title        = {Robust Classification via a Single Diffusion Model},
  booktitle    = {Forty-first International Conference on Machine Learning, {ICML} 2024,
                  Vienna, Austria, July 21-27, 2024},
  publisher    = {OpenReview.net},
  year         = {2024},
  url          = {https://openreview.net/forum?id=xaSpuvNYwS},
  timestamp    = {Mon, 02 Sep 2024 16:45:29 +0200},
  biburl       = {https://dblp.org/rec/conf/icml/ChenDWYD0024.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/icml/ChengMDYG024,
  author       = {Shuyu Cheng and
                  Yibo Miao and
                  Yinpeng Dong and
                  Xiao Yang and
                  Xiao{-}Shan Gao and
                  Jun Zhu},
  title        = {Efficient Black-box Adversarial Attacks via Bayesian Optimization
                  Guided by a Function Prior},
  booktitle    = {Forty-first International Conference on Machine Learning, {ICML} 2024,
                  Vienna, Austria, July 21-27, 2024},
  publisher    = {OpenReview.net},
  year         = {2024},
  url          = {https://openreview.net/forum?id=CR6Sl80cn8},
  timestamp    = {Mon, 02 Sep 2024 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/conf/icml/ChengMDYG024.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/icml/Huang0D0ZL24,
  author       = {Zhuo Huang and
                  Chang Liu and
                  Yinpeng Dong and
                  Hang Su and
                  Shibao Zheng and
                  Tongliang Liu},
  title        = {Machine Vision Therapy: Multimodal Large Language Models Can Enhance
                  Visual Robustness via Denoising In-Context Learning},
  booktitle    = {Forty-first International Conference on Machine Learning, {ICML} 2024,
                  Vienna, Austria, July 21-27, 2024},
  publisher    = {OpenReview.net},
  year         = {2024},
  url          = {https://openreview.net/forum?id=LwOfVWgEzS},
  timestamp    = {Mon, 02 Sep 2024 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/conf/icml/Huang0D0ZL24.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/icml/ZhuMDG24,
  author       = {Yifan Zhu and
                  Yibo Miao and
                  Yinpeng Dong and
                  Xiao{-}Shan Gao},
  title        = {Toward Availability Attacks in 3D Point Clouds},
  booktitle    = {Forty-first International Conference on Machine Learning, {ICML} 2024,
                  Vienna, Austria, July 21-27, 2024},
  publisher    = {OpenReview.net},
  year         = {2024},
  url          = {https://openreview.net/forum?id=C0sGIO2MZN},
  timestamp    = {Mon, 02 Sep 2024 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/conf/icml/ZhuMDG24.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/uss/LiuZZDM024,
  author       = {Tong Liu and
                  Yingjie Zhang and
                  Zhe Zhao and
                  Yinpeng Dong and
                  Guozhu Meng and
                  Kai Chen},
  editor       = {Davide Balzarotti and
                  Wenyuan Xu},
  title        = {Making Them Ask and Answer: Jailbreaking Large Language Models in
                  Few Queries via Disguise and Reconstruction},
  booktitle    = {33rd {USENIX} Security Symposium, {USENIX} Security 2024, Philadelphia,
                  PA, USA, August 14-16, 2024},
  publisher    = {{USENIX} Association},
  year         = {2024},
  url          = {https://www.usenix.org/conference/usenixsecurity24/presentation/liu-tong},
  timestamp    = {Mon, 22 Jul 2024 17:10:49 +0200},
  biburl       = {https://dblp.org/rec/conf/uss/LiuZZDM024.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2402-02316,
  author       = {Huanran Chen and
                  Yinpeng Dong and
                  Shitong Shao and
                  Zhongkai Hao and
                  Xiao Yang and
                  Hang Su and
                  Jun Zhu},
  title        = {Your Diffusion Model is Secretly a Certifiably Robust Classifier},
  journal      = {CoRR},
  volume       = {abs/2402.02316},
  year         = {2024},
  url          = {https://doi.org/10.48550/arXiv.2402.02316},
  doi          = {10.48550/ARXIV.2402.02316},
  eprinttype    = {arXiv},
  eprint       = {2402.02316},
  timestamp    = {Mon, 08 Jul 2024 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2402-02316.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2402-07562,
  author       = {Shengfang Zhai and
                  Weilong Wang and
                  Jiajun Li and
                  Yinpeng Dong and
                  Hang Su and
                  Qingni Shen},
  title        = {Discovering Universal Semantic Triggers for Text-to-Image Synthesis},
  journal      = {CoRR},
  volume       = {abs/2402.07562},
  year         = {2024},
  url          = {https://doi.org/10.48550/arXiv.2402.07562},
  doi          = {10.48550/ARXIV.2402.07562},
  eprinttype    = {arXiv},
  eprint       = {2402.07562},
  timestamp    = {Mon, 19 Feb 2024 00:00:00 +0100},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2402-07562.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2402-15218,
  author       = {Yu Tian and
                  Xiao Yang and
                  Yinpeng Dong and
                  Heming Yang and
                  Hang Su and
                  Jun Zhu},
  title        = {{BSPA:} Exploring Black-box Stealthy Prompt Attacks against Image
                  Generators},
  journal      = {CoRR},
  volume       = {abs/2402.15218},
  year         = {2024},
  url          = {https://doi.org/10.48550/arXiv.2402.15218},
  doi          = {10.48550/ARXIV.2402.15218},
  eprinttype    = {arXiv},
  eprint       = {2402.15218},
  timestamp    = {Fri, 26 Jul 2024 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2402-15218.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2402-18104,
  author       = {Tong Liu and
                  Yingjie Zhang and
                  Zhe Zhao and
                  Yinpeng Dong and
                  Guozhu Meng and
                  Kai Chen},
  title        = {Making Them Ask and Answer: Jailbreaking Large Language Models in
                  Few Queries via Disguise and Reconstruction},
  journal      = {CoRR},
  volume       = {abs/2402.18104},
  year         = {2024},
  url          = {https://doi.org/10.48550/arXiv.2402.18104},
  doi          = {10.48550/ARXIV.2402.18104},
  eprinttype    = {arXiv},
  eprint       = {2402.18104},
  timestamp    = {Thu, 18 Jul 2024 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2402-18104.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2404-00540,
  author       = {Lingxuan Wu and
                  Xiao Yang and
                  Yinpeng Dong and
                  Liuwei Xie and
                  Hang Su and
                  Jun Zhu},
  title        = {Embodied Active Defense: Leveraging Recurrent Feedback to Counter
                  Adversarial Patches},
  journal      = {CoRR},
  volume       = {abs/2404.00540},
  year         = {2024},
  url          = {https://doi.org/10.48550/arXiv.2404.00540},
  doi          = {10.48550/ARXIV.2404.00540},
  eprinttype    = {arXiv},
  eprint       = {2404.00540},
  timestamp    = {Fri, 26 Jul 2024 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2404-00540.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2404-09193,
  author       = {Jiawei Chen and
                  Xiao Yang and
                  Yinpeng Dong and
                  Hang Su and
                  Jianteng Peng and
                  Zhaoxia Yin},
  title        = {FaceCat: Enhancing Face Recognition Security with a Unified Generative
                  Model Framework},
  journal      = {CoRR},
  volume       = {abs/2404.09193},
  year         = {2024},
  url          = {https://doi.org/10.48550/arXiv.2404.09193},
  doi          = {10.48550/ARXIV.2404.09193},
  eprinttype    = {arXiv},
  eprint       = {2404.09193},
  timestamp    = {Wed, 14 Aug 2024 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2404-09193.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2404-11207,
  author       = {Yichi Zhang and
                  Yinpeng Dong and
                  Siyuan Zhang and
                  Tianzan Min and
                  Hang Su and
                  Jun Zhu},
  title        = {Exploring the Transferability of Visual Prompting for Multimodal Large
                  Language Models},
  journal      = {CoRR},
  volume       = {abs/2404.11207},
  year         = {2024},
  url          = {https://doi.org/10.48550/arXiv.2404.11207},
  doi          = {10.48550/ARXIV.2404.11207},
  eprinttype    = {arXiv},
  eprint       = {2404.11207},
  timestamp    = {Fri, 26 Jul 2024 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2404-11207.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2404-12139,
  author       = {Shouwei Ruan and
                  Yinpeng Dong and
                  Hanqing Liu and
                  Yao Huang and
                  Hang Su and
                  Xingxing Wei},
  title        = {Omniview-Tuning: Boosting Viewpoint Invariance of Vision-Language
                  Pre-training Models},
  journal      = {CoRR},
  volume       = {abs/2404.12139},
  year         = {2024},
  url          = {https://doi.org/10.48550/arXiv.2404.12139},
  doi          = {10.48550/ARXIV.2404.12139},
  eprinttype    = {arXiv},
  eprint       = {2404.12139},
  timestamp    = {Wed, 22 May 2024 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2404-12139.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2405-08816,
  author       = {Lingdong Kong and
                  Shaoyuan Xie and
                  Hanjiang Hu and
                  Yaru Niu and
                  Wei Tsang Ooi and
                  Benoit R. Cottereau and
                  Lai Xing Ng and
                  Yuexin Ma and
                  Wenwei Zhang and
                  Liang Pan and
                  Kai Chen and
                  Ziwei Liu and
                  Weichao Qiu and
                  Wei Zhang and
                  Xu Cao and
                  Hao Lu and
                  Ying{-}Cong Chen and
                  Caixin Kang and
                  Xinning Zhou and
                  Chengyang Ying and
                  Wentao Shang and
                  Xingwei Wang and
                  Yinpeng Dong and
                  Bo Yang and
                  Shengyin Jiang and
                  Zeliang Ma and
                  Dengyi Ji and
                  Haiwen Li and
                  Xingliang Huang and
                  Yu Tian and
                  Genghua Kou and
                  Fan Jia and
                  Yingfei Liu and
                  Tiancai Wang and
                  Ying Li and
                  Xiaoshuai Hao and
                  Yifan Yang and
                  Hui Zhang and
                  Mengchuan Wei and
                  Yi Zhou and
                  Haimei Zhao and
                  Jing Zhang and
                  Jinke Li and
                  Xiao He and
                  Xiaoqiang Cheng and
                  Bingyang Zhang and
                  Lirong Zhao and
                  Dianlei Ding and
                  Fangsheng Liu and
                  Yixiang Yan and
                  Hongming Wang and
                  Nanfei Ye and
                  Lun Luo and
                  Yubo Tian and
                  Yiwei Zuo and
                  Zhe Cao and
                  Yi Ren and
                  Yunfan Li and
                  Wenjie Liu and
                  Xun Wu and
                  Yifan Mao and
                  Ming Li and
                  Jian Liu and
                  Jiayang Liu and
                  Zihan Qin and
                  Cunxi Chu and
                  Jialei Xu and
                  Wenbo Zhao and
                  Junjun Jiang and
                  Xianming Liu and
                  Ziyan Wang and
                  Chiwei Li and
                  Shilong Li and
                  Chendong Yuan and
                  Songyue Yang and
                  Wentao Liu and
                  Peng Chen and
                  Bin Zhou and
                  Yubo Wang and
                  Chi Zhang and
                  Jianhang Sun and
                  Hai Chen and
                  Xiao Yang and
                  Lizhong Wang and
                  Dongyi Fu and
                  Yongchun Lin and
                  Huitong Yang and
                  Haoang Li and
                  Yadan Luo and
                  Xianjing Cheng and
                  Yong Xu},
  title        = {The RoboDrive Challenge: Drive Anytime Anywhere in Any Condition},
  journal      = {CoRR},
  volume       = {abs/2405.08816},
  year         = {2024},
  url          = {https://doi.org/10.48550/arXiv.2405.08816},
  doi          = {10.48550/ARXIV.2405.08816},
  eprinttype    = {arXiv},
  eprint       = {2405.08816},
  timestamp    = {Mon, 26 Aug 2024 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2405-08816.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2405-14800,
  author       = {Shengfang Zhai and
                  Huanran Chen and
                  Yinpeng Dong and
                  Jiajun Li and
                  Qingni Shen and
                  Yansong Gao and
                  Hang Su and
                  Yang Liu},
  title        = {Membership Inference on Text-to-Image Diffusion Models via Conditional
                  Likelihood Discrepancy},
  journal      = {CoRR},
  volume       = {abs/2405.14800},
  year         = {2024},
  url          = {https://doi.org/10.48550/arXiv.2405.14800},
  doi          = {10.48550/ARXIV.2405.14800},
  eprinttype    = {arXiv},
  eprint       = {2405.14800},
  timestamp    = {Mon, 22 Jul 2024 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2405-14800.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2405-19098,
  author       = {Shuyu Cheng and
                  Yibo Miao and
                  Yinpeng Dong and
                  Xiao Yang and
                  Xiao{-}Shan Gao and
                  Jun Zhu},
  title        = {Efficient Black-box Adversarial Attacks via Bayesian Optimization
                  Guided by a Function Prior},
  journal      = {CoRR},
  volume       = {abs/2405.19098},
  year         = {2024},
  url          = {https://doi.org/10.48550/arXiv.2405.19098},
  doi          = {10.48550/ARXIV.2405.19098},
  eprinttype    = {arXiv},
  eprint       = {2405.19098},
  timestamp    = {Fri, 21 Jun 2024 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2405-19098.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2405-19668,
  author       = {Jiawei Chen and
                  Xiao Yang and
                  Zhengwei Fang and
                  Yu Tian and
                  Yinpeng Dong and
                  Zhaoxia Yin and
                  Hang Su},
  title        = {AutoBreach: Universal and Adaptive Jailbreaking with Efficient Wordplay-Guided
                  Optimization},
  journal      = {CoRR},
  volume       = {abs/2405.19668},
  year         = {2024},
  url          = {https://doi.org/10.48550/arXiv.2405.19668},
  doi          = {10.48550/ARXIV.2405.19668},
  eprinttype    = {arXiv},
  eprint       = {2405.19668},
  timestamp    = {Fri, 21 Jun 2024 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2405-19668.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2406-07057,
  author       = {Yichi Zhang and
                  Yao Huang and
                  Yitong Sun and
                  Chang Liu and
                  Zhe Zhao and
                  Zhengwei Fang and
                  Yifan Wang and
                  Huanran Chen and
                  Xiao Yang and
                  Xingxing Wei and
                  Hang Su and
                  Yinpeng Dong and
                  Jun Zhu},
  title        = {Benchmarking Trustworthiness of Multimodal Large Language Models:
                  {A} Comprehensive Study},
  journal      = {CoRR},
  volume       = {abs/2406.07057},
  year         = {2024},
  url          = {https://doi.org/10.48550/arXiv.2406.07057},
  doi          = {10.48550/ARXIV.2406.07057},
  eprinttype    = {arXiv},
  eprint       = {2406.07057},
  timestamp    = {Tue, 23 Jul 2024 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2406-07057.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2407-05965,
  author       = {Yibo Miao and
                  Yifan Zhu and
                  Yinpeng Dong and
                  Lijia Yu and
                  Jun Zhu and
                  Xiao{-}Shan Gao},
  title        = {T2VSafetyBench: Evaluating the Safety of Text-to-Video Generative
                  Models},
  journal      = {CoRR},
  volume       = {abs/2407.05965},
  year         = {2024},
  url          = {https://doi.org/10.48550/arXiv.2407.05965},
  doi          = {10.48550/ARXIV.2407.05965},
  eprinttype    = {arXiv},
  eprint       = {2407.05965},
  timestamp    = {Tue, 13 Aug 2024 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2407-05965.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2407-11011,
  author       = {Yifan Zhu and
                  Yibo Miao and
                  Yinpeng Dong and
                  Xiao{-}Shan Gao},
  title        = {Toward Availability Attacks in 3D Point Clouds},
  journal      = {CoRR},
  volume       = {abs/2407.11011},
  year         = {2024},
  url          = {https://doi.org/10.48550/arXiv.2407.11011},
  doi          = {10.48550/ARXIV.2407.11011},
  eprinttype    = {arXiv},
  eprint       = {2407.11011},
  timestamp    = {Fri, 23 Aug 2024 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2407-11011.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/aiopen/DengDZ23,
  author       = {Zhijie Deng and
                  Yinpeng Dong and
                  Jun Zhu},
  title        = {Batch virtual adversarial training for graph convolutional networks},
  journal      = {{AI} Open},
  volume       = {4},
  pages        = {73--79},
  year         = {2023},
  url          = {https://doi.org/10.1016/j.aiopen.2023.08.007},
  doi          = {10.1016/J.AIOPEN.2023.08.007},
  timestamp    = {Fri, 26 Jan 2024 00:00:00 +0100},
  biburl       = {https://dblp.org/rec/journals/aiopen/DengDZ23.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/tifs/ZhangDKLOZWM23,
  author       = {Jinlai Zhang and
                  Yinpeng Dong and
                  Minchi Kuang and
                  Binbin Liu and
                  Bo Ouyang and
                  Jihong Zhu and
                  Houqing Wang and
                  Yanmei Meng},
  title        = {The Art of Defense: Letting Networks Fool the Attacker},
  journal      = {{IEEE} Trans. Inf. Forensics Secur.},
  volume       = {18},
  pages        = {3267--3276},
  year         = {2023},
  url          = {https://doi.org/10.1109/TIFS.2023.3278458},
  doi          = {10.1109/TIFS.2023.3278458},
  timestamp    = {Thu, 15 Jun 2023 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/journals/tifs/ZhangDKLOZWM23.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/cvpr/DongKZZ0YSWZ23,
  author       = {Yinpeng Dong and
                  Caixin Kang and
                  Jinlai Zhang and
                  Zijian Zhu and
                  Yikai Wang and
                  Xiao Yang and
                  Hang Su and
                  Xingxing Wei and
                  Jun Zhu},
  title        = {Benchmarking Robustness of 3D Object Detection to Common Corruptions
                  in Autonomous Driving},
  booktitle    = {{IEEE/CVF} Conference on Computer Vision and Pattern Recognition,
                  {CVPR} 2023, Vancouver, BC, Canada, June 17-24, 2023},
  pages        = {1022--1032},
  publisher    = {{IEEE}},
  year         = {2023},
  url          = {https://doi.org/10.1109/CVPR52729.2023.00105},
  doi          = {10.1109/CVPR52729.2023.00105},
  timestamp    = {Mon, 30 Oct 2023 00:00:00 +0100},
  biburl       = {https://dblp.org/rec/conf/cvpr/DongKZZ0YSWZ23.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/cvpr/YangLXWDCSZ23,
  author       = {Xiao Yang and
                  Chang Liu and
                  Longlong Xu and
                  Yikai Wang and
                  Yinpeng Dong and
                  Ning Chen and
                  Hang Su and
                  Jun Zhu},
  title        = {Towards Effective Adversarial Textured 3D Meshes on Physical Face
                  Recognition},
  booktitle    = {{IEEE/CVF} Conference on Computer Vision and Pattern Recognition,
                  {CVPR} 2023, Vancouver, BC, Canada, June 17-24, 2023},
  pages        = {4119--4128},
  publisher    = {{IEEE}},
  year         = {2023},
  url          = {https://doi.org/10.1109/CVPR52729.2023.00401},
  doi          = {10.1109/CVPR52729.2023.00401},
  timestamp    = {Sun, 21 Jan 2024 00:00:00 +0100},
  biburl       = {https://dblp.org/rec/conf/cvpr/YangLXWDCSZ23.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/cvpr/ZhuZCDZDZZ23,
  author       = {Zijian Zhu and
                  Yichi Zhang and
                  Hai Chen and
                  Yinpeng Dong and
                  Shu Zhao and
                  Wenbo Ding and
                  Jiachen Zhong and
                  Shibao Zheng},
  title        = {Understanding the Robustness of 3D Object Detection with Bird'View
                  Representations in Autonomous Driving},
  booktitle    = {{IEEE/CVF} Conference on Computer Vision and Pattern Recognition,
                  {CVPR} 2023, Vancouver, BC, Canada, June 17-24, 2023},
  pages        = {21600--21610},
  publisher    = {{IEEE}},
  year         = {2023},
  url          = {https://doi.org/10.1109/CVPR52729.2023.02069},
  doi          = {10.1109/CVPR52729.2023.02069},
  timestamp    = {Tue, 29 Aug 2023 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/conf/cvpr/ZhuZCDZDZZ23.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/cvpr/Wang0D0Y23,
  author       = {Yikai Wang and
                  Wenbing Huang and
                  Yinpeng Dong and
                  Fuchun Sun and
                  Anbang Yao},
  title        = {Compacting Binary Neural Networks by Sparse Kernel Selection},
  booktitle    = {{IEEE/CVF} Conference on Computer Vision and Pattern Recognition,
                  {CVPR} 2023, Vancouver, BC, Canada, June 17-24, 2023},
  pages        = {24374--24383},
  publisher    = {{IEEE}},
  year         = {2023},
  url          = {https://doi.org/10.1109/CVPR52729.2023.02335},
  doi          = {10.1109/CVPR52729.2023.02335},
  timestamp    = {Fri, 01 Sep 2023 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/conf/cvpr/Wang0D0Y23.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/iccv/RuanD0P0W23,
  author       = {Shouwei Ruan and
                  Yinpeng Dong and
                  Hang Su and
                  Jianteng Peng and
                  Ning Chen and
                  Xingxing Wei},
  title        = {Towards Viewpoint-Invariant Visual Recognition via Adversarial Training},
  booktitle    = {{IEEE/CVF} International Conference on Computer Vision, {ICCV} 2023,
                  Paris, France, October 1-6, 2023},
  pages        = {4686--4696},
  publisher    = {{IEEE}},
  year         = {2023},
  url          = {https://doi.org/10.1109/ICCV51070.2023.00434},
  doi          = {10.1109/ICCV51070.2023.00434},
  timestamp    = {Mon, 22 Jan 2024 00:00:00 +0100},
  biburl       = {https://dblp.org/rec/conf/iccv/RuanD0P0W23.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/iccv/WangD0Y23,
  author       = {Yikai Wang and
                  Yinpeng Dong and
                  Fuchun Sun and
                  Xiao Yang},
  title        = {Root Pose Decomposition Towards Generic Non-rigid 3D Reconstruction
                  with Monocular Videos},
  booktitle    = {{IEEE/CVF} International Conference on Computer Vision, {ICCV} 2023,
                  Paris, France, October 1-6, 2023},
  pages        = {13844--13854},
  publisher    = {{IEEE}},
  year         = {2023},
  url          = {https://doi.org/10.1109/ICCV51070.2023.01277},
  doi          = {10.1109/ICCV51070.2023.01277},
  timestamp    = {Fri, 26 Jan 2024 00:00:00 +0100},
  biburl       = {https://dblp.org/rec/conf/iccv/WangD0Y23.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/icml/HaoWSYDLCSZ23,
  author       = {Zhongkai Hao and
                  Zhengyi Wang and
                  Hang Su and
                  Chengyang Ying and
                  Yinpeng Dong and
                  Songming Liu and
                  Ze Cheng and
                  Jian Song and
                  Jun Zhu},
  editor       = {Andreas Krause and
                  Emma Brunskill and
                  Kyunghyun Cho and
                  Barbara Engelhardt and
                  Sivan Sabato and
                  Jonathan Scarlett},
  title        = {{GNOT:} {A} General Neural Operator Transformer for Operator Learning},
  booktitle    = {International Conference on Machine Learning, {ICML} 2023, 23-29 July
                  2023, Honolulu, Hawaii, {USA}},
  series       = {Proceedings of Machine Learning Research},
  volume       = {202},
  pages        = {12556--12569},
  publisher    = {{PMLR}},
  year         = {2023},
  url          = {https://proceedings.mlr.press/v202/hao23c.html},
  timestamp    = {Mon, 30 Oct 2023 00:00:00 +0100},
  biburl       = {https://dblp.org/rec/conf/icml/HaoWSYDLCSZ23.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/mm/ZhaiDSPF023,
  author       = {Shengfang Zhai and
                  Yinpeng Dong and
                  Qingni Shen and
                  Shi Pu and
                  Yuejian Fang and
                  Hang Su},
  editor       = {Abdulmotaleb El{-}Saddik and
                  Tao Mei and
                  Rita Cucchiara and
                  Marco Bertini and
                  Diana Patricia Tobon Vallejo and
                  Pradeep K. Atrey and
                  M. Shamim Hossain},
  title        = {Text-to-Image Diffusion Models can be Easily Backdoored through Multimodal
                  Data Poisoning},
  booktitle    = {Proceedings of the 31st {ACM} International Conference on Multimedia,
                  {MM} 2023, Ottawa, ON, Canada, 29 October 2023- 3 November 2023},
  pages        = {1577--1587},
  publisher    = {{ACM}},
  year         = {2023},
  url          = {https://doi.org/10.1145/3581783.3612108},
  doi          = {10.1145/3581783.3612108},
  timestamp    = {Tue, 20 Aug 2024 07:54:43 +0200},
  biburl       = {https://dblp.org/rec/conf/mm/ZhaiDSPF023.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/nips/0007ZDDZ23,
  author       = {Peng Cui and
                  Dan Zhang and
                  Zhijie Deng and
                  Yinpeng Dong and
                  Jun Zhu},
  editor       = {Alice Oh and
                  Tristan Naumann and
                  Amir Globerson and
                  Kate Saenko and
                  Moritz Hardt and
                  Sergey Levine},
  title        = {Learning Sample Difficulty from Pre-trained Models for Reliable Prediction},
  booktitle    = {Advances in Neural Information Processing Systems 36: Annual Conference
                  on Neural Information Processing Systems 2023, NeurIPS 2023, New Orleans,
                  LA, USA, December 10 - 16, 2023},
  year         = {2023},
  url          = {http://papers.nips.cc/paper\_files/paper/2023/hash/50251f54848a433f3e47ae3b7cbded53-Abstract-Conference.html},
  timestamp    = {Fri, 21 Jun 2024 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/conf/nips/0007ZDDZ23.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2302-14301,
  author       = {Chang Liu and
                  Yinpeng Dong and
                  Wenzhao Xiang and
                  Xiao Yang and
                  Hang Su and
                  Jun Zhu and
                  Yuefeng Chen and
                  Yuan He and
                  Hui Xue and
                  Shibao Zheng},
  title        = {A Comprehensive Study on Robustness of Image Classification Models:
                  Benchmarking and Rethinking},
  journal      = {CoRR},
  volume       = {abs/2302.14301},
  year         = {2023},
  url          = {https://doi.org/10.48550/arXiv.2302.14301},
  doi          = {10.48550/ARXIV.2302.14301},
  eprinttype    = {arXiv},
  eprint       = {2302.14301},
  timestamp    = {Tue, 12 Sep 2023 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2302-14301.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2302-14376,
  author       = {Zhongkai Hao and
                  Chengyang Ying and
                  Zhengyi Wang and
                  Hang Su and
                  Yinpeng Dong and
                  Songming Liu and
                  Ze Cheng and
                  Jun Zhu and
                  Jian Song},
  title        = {{GNOT:} {A} General Neural Operator Transformer for Operator Learning},
  journal      = {CoRR},
  volume       = {abs/2302.14376},
  year         = {2023},
  url          = {https://doi.org/10.48550/arXiv.2302.14376},
  doi          = {10.48550/ARXIV.2302.14376},
  eprinttype    = {arXiv},
  eprint       = {2302.14376},
  timestamp    = {Thu, 02 Mar 2023 00:00:00 +0100},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2302-14376.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2303-09105,
  author       = {Huanran Chen and
                  Yichi Zhang and
                  Yinpeng Dong and
                  Jun Zhu},
  title        = {Rethinking Model Ensemble in Transfer-based Adversarial Attacks},
  journal      = {CoRR},
  volume       = {abs/2303.09105},
  year         = {2023},
  url          = {https://doi.org/10.48550/arXiv.2303.09105},
  doi          = {10.48550/ARXIV.2303.09105},
  eprinttype    = {arXiv},
  eprint       = {2303.09105},
  timestamp    = {Tue, 21 Mar 2023 00:00:00 +0100},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2303-09105.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2303-11040,
  author       = {Yinpeng Dong and
                  Caixin Kang and
                  Jinlai Zhang and
                  Zijian Zhu and
                  Yikai Wang and
                  Xiao Yang and
                  Hang Su and
                  Xingxing Wei and
                  Jun Zhu},
  title        = {Benchmarking Robustness of 3D Object Detection to Common Corruptions
                  in Autonomous Driving},
  journal      = {CoRR},
  volume       = {abs/2303.11040},
  year         = {2023},
  url          = {https://doi.org/10.48550/arXiv.2303.11040},
  doi          = {10.48550/ARXIV.2303.11040},
  eprinttype    = {arXiv},
  eprint       = {2303.11040},
  timestamp    = {Thu, 20 Apr 2023 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2303-11040.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2303-14470,
  author       = {Yikai Wang and
                  Wenbing Huang and
                  Yinpeng Dong and
                  Fuchun Sun and
                  Anbang Yao},
  title        = {Compacting Binary Neural Networks by Sparse Kernel Selection},
  journal      = {CoRR},
  volume       = {abs/2303.14470},
  year         = {2023},
  url          = {https://doi.org/10.48550/arXiv.2303.14470},
  doi          = {10.48550/ARXIV.2303.14470},
  eprinttype    = {arXiv},
  eprint       = {2303.14470},
  timestamp    = {Thu, 20 Apr 2023 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2303-14470.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2303-15818,
  author       = {Xiao Yang and
                  Chang Liu and
                  Longlong Xu and
                  Yikai Wang and
                  Yinpeng Dong and
                  Ning Chen and
                  Hang Su and
                  Jun Zhu},
  title        = {Towards Effective Adversarial Textured 3D Meshes on Physical Face
                  Recognition},
  journal      = {CoRR},
  volume       = {abs/2303.15818},
  year         = {2023},
  url          = {https://doi.org/10.48550/arXiv.2303.15818},
  doi          = {10.48550/ARXIV.2303.15818},
  eprinttype    = {arXiv},
  eprint       = {2303.15818},
  timestamp    = {Wed, 13 Sep 2023 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2303-15818.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2303-17297,
  author       = {Zijian Zhu and
                  Yichi Zhang and
                  Hai Chen and
                  Yinpeng Dong and
                  Shu Zhao and
                  Wenbo Ding and
                  Jiachen Zhong and
                  Shibao Zheng},
  title        = {Understanding the Robustness of 3D Object Detection with Bird's-Eye-View
                  Representations in Autonomous Driving},
  journal      = {CoRR},
  volume       = {abs/2303.17297},
  year         = {2023},
  url          = {https://doi.org/10.48550/arXiv.2303.17297},
  doi          = {10.48550/ARXIV.2303.17297},
  eprinttype    = {arXiv},
  eprint       = {2303.17297},
  timestamp    = {Fri, 14 Apr 2023 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2303-17297.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2304-10127,
  author       = {Peng Cui and
                  Dan Zhang and
                  Zhijie Deng and
                  Yinpeng Dong and
                  Jun Zhu},
  title        = {Learning Sample Difficulty from Pre-trained Models for Reliable Prediction},
  journal      = {CoRR},
  volume       = {abs/2304.10127},
  year         = {2023},
  url          = {https://doi.org/10.48550/arXiv.2304.10127},
  doi          = {10.48550/ARXIV.2304.10127},
  eprinttype    = {arXiv},
  eprint       = {2304.10127},
  timestamp    = {Mon, 16 Oct 2023 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2304-10127.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2305-04175,
  author       = {Shengfang Zhai and
                  Yinpeng Dong and
                  Qingni Shen and
                  Shi Pu and
                  Yuejian Fang and
                  Hang Su},
  title        = {Text-to-Image Diffusion Models can be Easily Backdoored through Multimodal
                  Data Poisoning},
  journal      = {CoRR},
  volume       = {abs/2305.04175},
  year         = {2023},
  url          = {https://doi.org/10.48550/arXiv.2305.04175},
  doi          = {10.48550/ARXIV.2305.04175},
  eprinttype    = {arXiv},
  eprint       = {2305.04175},
  timestamp    = {Thu, 11 May 2023 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2305-04175.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2305-15241,
  author       = {Huanran Chen and
                  Yinpeng Dong and
                  Zhengyi Wang and
                  Xiao Yang and
                  Chengqi Duan and
                  Hang Su and
                  Jun Zhu},
  title        = {Robust Classification via a Single Diffusion Model},
  journal      = {CoRR},
  volume       = {abs/2305.15241},
  year         = {2023},
  url          = {https://doi.org/10.48550/arXiv.2305.15241},
  doi          = {10.48550/ARXIV.2305.15241},
  eprinttype    = {arXiv},
  eprint       = {2305.15241},
  timestamp    = {Sat, 30 Sep 2023 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2305-15241.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2306-09124,
  author       = {Caixin Kang and
                  Yinpeng Dong and
                  Zhengyi Wang and
                  Shouwei Ruan and
                  Hang Su and
                  Xingxing Wei},
  title        = {DIFFender: Diffusion-Based Adversarial Defense against Patch Attacks
                  in the Physical World},
  journal      = {CoRR},
  volume       = {abs/2306.09124},
  year         = {2023},
  url          = {https://doi.org/10.48550/arXiv.2306.09124},
  doi          = {10.48550/ARXIV.2306.09124},
  eprinttype    = {arXiv},
  eprint       = {2306.09124},
  timestamp    = {Fri, 30 Jun 2023 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2306-09124.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2306-13103,
  author       = {Hongcheng Gao and
                  Hao Zhang and
                  Yinpeng Dong and
                  Zhijie Deng},
  title        = {Evaluating the Robustness of Text-to-image Diffusion Models against
                  Real-world Attacks},
  journal      = {CoRR},
  volume       = {abs/2306.13103},
  year         = {2023},
  url          = {https://doi.org/10.48550/arXiv.2306.13103},
  doi          = {10.48550/ARXIV.2306.13103},
  eprinttype    = {arXiv},
  eprint       = {2306.13103},
  timestamp    = {Tue, 27 Jun 2023 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2306-13103.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2306-16131,
  author       = {Xingxing Wei and
                  Shouwei Ruan and
                  Yinpeng Dong and
                  Hang Su},
  title        = {Distributional Modeling for Location-Aware Adversarial Patches},
  journal      = {CoRR},
  volume       = {abs/2306.16131},
  year         = {2023},
  url          = {https://doi.org/10.48550/arXiv.2306.16131},
  doi          = {10.48550/ARXIV.2306.16131},
  eprinttype    = {arXiv},
  eprint       = {2306.16131},
  timestamp    = {Mon, 03 Jul 2023 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2306-16131.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2307-10235,
  author       = {Shouwei Ruan and
                  Yinpeng Dong and
                  Hang Su and
                  Jianteng Peng and
                  Ning Chen and
                  Xingxing Wei},
  title        = {Towards Viewpoint-Invariant Visual Recognition via Adversarial Training},
  journal      = {CoRR},
  volume       = {abs/2307.10235},
  year         = {2023},
  url          = {https://doi.org/10.48550/arXiv.2307.10235},
  doi          = {10.48550/ARXIV.2307.10235},
  eprinttype    = {arXiv},
  eprint       = {2307.10235},
  timestamp    = {Wed, 26 Jul 2023 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2307-10235.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2307-11528,
  author       = {Shouwei Ruan and
                  Yinpeng Dong and
                  Hang Su and
                  Jianteng Peng and
                  Ning Chen and
                  Xingxing Wei},
  title        = {Improving Viewpoint Robustness for Visual Recognition via Adversarial
                  Training},
  journal      = {CoRR},
  volume       = {abs/2307.11528},
  year         = {2023},
  url          = {https://doi.org/10.48550/arXiv.2307.11528},
  doi          = {10.48550/ARXIV.2307.11528},
  eprinttype    = {arXiv},
  eprint       = {2307.11528},
  timestamp    = {Sun, 21 Jan 2024 00:00:00 +0100},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2307-11528.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2308-10089,
  author       = {Yikai Wang and
                  Yinpeng Dong and
                  Fuchun Sun and
                  Xiao Yang},
  title        = {Root Pose Decomposition Towards Generic Non-rigid 3D Reconstruction
                  with Monocular Videos},
  journal      = {CoRR},
  volume       = {abs/2308.10089},
  year         = {2023},
  url          = {https://doi.org/10.48550/arXiv.2308.10089},
  doi          = {10.48550/ARXIV.2308.10089},
  eprinttype    = {arXiv},
  eprint       = {2308.10089},
  timestamp    = {Fri, 01 Sep 2023 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2308-10089.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2308-12636,
  author       = {Youze Wang and
                  Wenbo Hu and
                  Yinpeng Dong and
                  Richang Hong},
  title        = {Exploring Transferability of Multimodal Adversarial Samples for Vision-Language
                  Pre-training Models with Contrastive Learning},
  journal      = {CoRR},
  volume       = {abs/2308.12636},
  year         = {2023},
  url          = {https://doi.org/10.48550/arXiv.2308.12636},
  doi          = {10.48550/ARXIV.2308.12636},
  eprinttype    = {arXiv},
  eprint       = {2308.12636},
  timestamp    = {Wed, 30 Aug 2023 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2308-12636.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2309-02218,
  author       = {Haixu Song and
                  Shiyu Huang and
                  Yinpeng Dong and
                  Wei{-}Wei Tu},
  title        = {Robustness and Generalizability of Deepfake Detection: {A} Study with
                  Diffusion Models},
  journal      = {CoRR},
  volume       = {abs/2309.02218},
  year         = {2023},
  url          = {https://doi.org/10.48550/arXiv.2309.02218},
  doi          = {10.48550/ARXIV.2309.02218},
  eprinttype    = {arXiv},
  eprint       = {2309.02218},
  timestamp    = {Mon, 11 Sep 2023 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2309-02218.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2309-11751,
  author       = {Yinpeng Dong and
                  Huanran Chen and
                  Jiawei Chen and
                  Zhengwei Fang and
                  Xiao Yang and
                  Yichi Zhang and
                  Yu Tian and
                  Hang Su and
                  Jun Zhu},
  title        = {How Robust is Google's Bard to Adversarial Image Attacks?},
  journal      = {CoRR},
  volume       = {abs/2309.11751},
  year         = {2023},
  url          = {https://doi.org/10.48550/arXiv.2309.11751},
  doi          = {10.48550/ARXIV.2309.11751},
  eprinttype    = {arXiv},
  eprint       = {2309.11751},
  timestamp    = {Mon, 30 Oct 2023 00:00:00 +0100},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2309-11751.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2311-11855,
  author       = {Yu Tian and
                  Xiao Yang and
                  Jingyuan Zhang and
                  Yinpeng Dong and
                  Hang Su},
  title        = {Evil Geniuses: Delving into the Safety of LLM-based Agents},
  journal      = {CoRR},
  volume       = {abs/2311.11855},
  year         = {2023},
  url          = {https://doi.org/10.48550/arXiv.2311.11855},
  doi          = {10.48550/ARXIV.2311.11855},
  eprinttype    = {arXiv},
  eprint       = {2311.11855},
  timestamp    = {Thu, 23 Nov 2023 00:00:00 +0100},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2311-11855.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2312-02546,
  author       = {Zhuo Huang and
                  Chang Liu and
                  Yinpeng Dong and
                  Hang Su and
                  Shibao Zheng and
                  Tongliang Liu},
  title        = {Machine Vision Therapy: Multimodal Large Language Models Can Enhance
                  Visual Robustness via Denoising In-Context Learning},
  journal      = {CoRR},
  volume       = {abs/2312.02546},
  year         = {2023},
  url          = {https://doi.org/10.48550/arXiv.2312.02546},
  doi          = {10.48550/ARXIV.2312.02546},
  eprinttype    = {arXiv},
  eprint       = {2312.02546},
  timestamp    = {Sat, 27 Jul 2024 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2312-02546.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2312-07067,
  author       = {Qian Li and
                  Yuxiao Hu and
                  Yinpeng Dong and
                  Dongxiao Zhang and
                  Yuntian Chen},
  title        = {Focus on Hiders: Exploring Hidden Threats for Enhancing Adversarial
                  Training},
  journal      = {CoRR},
  volume       = {abs/2312.07067},
  year         = {2023},
  url          = {https://doi.org/10.48550/arXiv.2312.07067},
  doi          = {10.48550/ARXIV.2312.07067},
  eprinttype    = {arXiv},
  eprint       = {2312.07067},
  timestamp    = {Thu, 04 Jan 2024 00:00:00 +0100},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2312-07067.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2312-09558,
  author       = {Yao Huang and
                  Yinpeng Dong and
                  Shouwei Ruan and
                  Xiao Yang and
                  Hang Su and
                  Xingxing Wei},
  title        = {Towards Transferable Targeted 3D Adversarial Attack in the Physical
                  World},
  journal      = {CoRR},
  volume       = {abs/2312.09558},
  year         = {2023},
  url          = {https://doi.org/10.48550/arXiv.2312.09558},
  doi          = {10.48550/ARXIV.2312.09558},
  eprinttype    = {arXiv},
  eprint       = {2312.09558},
  timestamp    = {Tue, 09 Jan 2024 00:00:00 +0100},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2312-09558.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/pami/DongCPSZ22,
  author       = {Yinpeng Dong and
                  Shuyu Cheng and
                  Tianyu Pang and
                  Hang Su and
                  Jun Zhu},
  title        = {Query-Efficient Black-Box Adversarial Attacks Guided by a Transfer-Based
                  Prior},
  journal      = {{IEEE} Trans. Pattern Anal. Mach. Intell.},
  volume       = {44},
  number       = {12},
  pages        = {9536--9548},
  year         = {2022},
  url          = {https://doi.org/10.1109/TPAMI.2021.3126733},
  doi          = {10.1109/TPAMI.2021.3126733},
  timestamp    = {Mon, 05 Dec 2022 00:00:00 +0100},
  biburl       = {https://dblp.org/rec/journals/pami/DongCPSZ22.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/prl/YangLDSZZ22,
  author       = {Xiao Yang and
                  Shilong Liu and
                  Yinpeng Dong and
                  Hang Su and
                  Lei Zhang and
                  Jun Zhu},
  title        = {Towards generalizable detection of face forgery via self-guided model-agnostic
                  learning},
  journal      = {Pattern Recognit. Lett.},
  volume       = {160},
  pages        = {98--104},
  year         = {2022},
  url          = {https://doi.org/10.1016/j.patrec.2022.06.007},
  doi          = {10.1016/J.PATREC.2022.06.007},
  timestamp    = {Sat, 10 Sep 2022 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/journals/prl/YangLDSZZ22.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/cvpr/PangZHD000L22,
  author       = {Tianyu Pang and
                  Huishuai Zhang and
                  Di He and
                  Yinpeng Dong and
                  Hang Su and
                  Wei Chen and
                  Jun Zhu and
                  Tie{-}Yan Liu},
  title        = {Two Coupled Rejection Metrics Can Tell Adversarial Examples Apart},
  booktitle    = {{IEEE/CVF} Conference on Computer Vision and Pattern Recognition,
                  {CVPR} 2022, New Orleans, LA, USA, June 18-24, 2022},
  pages        = {15202--15212},
  publisher    = {{IEEE}},
  year         = {2022},
  url          = {https://doi.org/10.1109/CVPR52688.2022.01479},
  doi          = {10.1109/CVPR52688.2022.01479},
  timestamp    = {Fri, 10 Nov 2023 00:00:00 +0100},
  biburl       = {https://dblp.org/rec/conf/cvpr/PangZHD000L22.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/eccv/ChanDZZZ22,
  author       = {Shih{-}Han Chan and
                  Yinpeng Dong and
                  Jun Zhu and
                  Xiaolu Zhang and
                  Jun Zhou},
  editor       = {Leonid Karlinsky and
                  Tomer Michaeli and
                  Ko Nishino},
  title        = {BadDet: Backdoor Attacks on Object Detection},
  booktitle    = {Computer Vision - {ECCV} 2022 Workshops - Tel Aviv, Israel, October
                  23-27, 2022, Proceedings, Part {I}},
  series       = {Lecture Notes in Computer Science},
  volume       = {13801},
  pages        = {396--412},
  publisher    = {Springer},
  year         = {2022},
  url          = {https://doi.org/10.1007/978-3-031-25056-9\_26},
  doi          = {10.1007/978-3-031-25056-9\_26},
  timestamp    = {Sat, 25 Feb 2023 00:00:00 +0100},
  biburl       = {https://dblp.org/rec/conf/eccv/ChanDZZZ22.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/eccv/YangDPSZ22,
  author       = {Xiao Yang and
                  Yinpeng Dong and
                  Tianyu Pang and
                  Hang Su and
                  Jun Zhu},
  editor       = {Shai Avidan and
                  Gabriel J. Brostow and
                  Moustapha Ciss{\'{e}} and
                  Giovanni Maria Farinella and
                  Tal Hassner},
  title        = {Boosting Transferability of Targeted Adversarial Examples via Hierarchical
                  Generative Networks},
  booktitle    = {Computer Vision - {ECCV} 2022 - 17th European Conference, Tel Aviv,
                  Israel, October 23-27, 2022, Proceedings, Part {IV}},
  series       = {Lecture Notes in Computer Science},
  volume       = {13664},
  pages        = {725--742},
  publisher    = {Springer},
  year         = {2022},
  url          = {https://doi.org/10.1007/978-3-031-19772-7\_42},
  doi          = {10.1007/978-3-031-19772-7\_42},
  timestamp    = {Thu, 10 Nov 2022 10:31:48 +0100},
  biburl       = {https://dblp.org/rec/conf/eccv/YangDPSZ22.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/esorics/ChenDSZSW22,
  author       = {Xiaoyi Chen and
                  Yinpeng Dong and
                  Zeyu Sun and
                  Shengfang Zhai and
                  Qingni Shen and
                  Zhonghai Wu},
  editor       = {Vijayalakshmi Atluri and
                  Roberto Di Pietro and
                  Christian Damsgaard Jensen and
                  Weizhi Meng},
  title        = {Kallima: {A} Clean-Label Framework for Textual Backdoor Attacks},
  booktitle    = {Computer Security - {ESORICS} 2022 - 27th European Symposium on Research
                  in Computer Security, Copenhagen, Denmark, September 26-30, 2022,
                  Proceedings, Part {I}},
  series       = {Lecture Notes in Computer Science},
  volume       = {13554},
  pages        = {447--466},
  publisher    = {Springer},
  year         = {2022},
  url          = {https://doi.org/10.1007/978-3-031-17140-6\_22},
  doi          = {10.1007/978-3-031-17140-6\_22},
  timestamp    = {Mon, 27 May 2024 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/conf/esorics/ChenDSZSW22.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/iclr/DongXYPDSZ22,
  author       = {Yinpeng Dong and
                  Ke Xu and
                  Xiao Yang and
                  Tianyu Pang and
                  Zhijie Deng and
                  Hang Su and
                  Jun Zhu},
  title        = {Exploring Memorization in Adversarial Training},
  booktitle    = {The Tenth International Conference on Learning Representations, {ICLR}
                  2022, Virtual Event, April 25-29, 2022},
  publisher    = {OpenReview.net},
  year         = {2022},
  url          = {https://openreview.net/forum?id=7gE9V9GBZaI},
  timestamp    = {Tue, 18 Oct 2022 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/conf/iclr/DongXYPDSZ22.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/icml/HaoYD0SZ22,
  author       = {Zhongkai Hao and
                  Chengyang Ying and
                  Yinpeng Dong and
                  Hang Su and
                  Jian Song and
                  Jun Zhu},
  editor       = {Kamalika Chaudhuri and
                  Stefanie Jegelka and
                  Le Song and
                  Csaba Szepesv{\'{a}}ri and
                  Gang Niu and
                  Sivan Sabato},
  title        = {GSmooth: Certified Robustness against Semantic Transformations via
                  Generalized Randomized Smoothing},
  booktitle    = {International Conference on Machine Learning, {ICML} 2022, 17-23 July
                  2022, Baltimore, Maryland, {USA}},
  series       = {Proceedings of Machine Learning Research},
  volume       = {162},
  pages        = {8465--8483},
  publisher    = {{PMLR}},
  year         = {2022},
  url          = {https://proceedings.mlr.press/v162/hao22c.html},
  timestamp    = {Tue, 27 Sep 2022 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/conf/icml/HaoYD0SZ22.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/nips/BanD22,
  author       = {Yuanhao Ban and
                  Yinpeng Dong},
  editor       = {Sanmi Koyejo and
                  S. Mohamed and
                  A. Agarwal and
                  Danielle Belgrave and
                  K. Cho and
                  A. Oh},
  title        = {Pre-trained Adversarial Perturbations},
  booktitle    = {Advances in Neural Information Processing Systems 35: Annual Conference
                  on Neural Information Processing Systems 2022, NeurIPS 2022, New Orleans,
                  LA, USA, November 28 - December 9, 2022},
  year         = {2022},
  url          = {http://papers.nips.cc/paper\_files/paper/2022/hash/084727e8abf90a8365b940036329cb6f-Abstract-Conference.html},
  timestamp    = {Mon, 08 Jan 2024 00:00:00 +0100},
  biburl       = {https://dblp.org/rec/conf/nips/BanD22.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/nips/DongR0KW022,
  author       = {Yinpeng Dong and
                  Shouwei Ruan and
                  Hang Su and
                  Caixin Kang and
                  Xingxing Wei and
                  Jun Zhu},
  editor       = {Sanmi Koyejo and
                  S. Mohamed and
                  A. Agarwal and
                  Danielle Belgrave and
                  K. Cho and
                  A. Oh},
  title        = {ViewFool: Evaluating the Robustness of Visual Recognition to Adversarial
                  Viewpoints},
  booktitle    = {Advances in Neural Information Processing Systems 35: Annual Conference
                  on Neural Information Processing Systems 2022, NeurIPS 2022, New Orleans,
                  LA, USA, November 28 - December 9, 2022},
  year         = {2022},
  url          = {http://papers.nips.cc/paper\_files/paper/2022/hash/eee7ae5cf0c4356c2aeca400771791aa-Abstract-Conference.html},
  timestamp    = {Mon, 08 Jan 2024 00:00:00 +0100},
  biburl       = {https://dblp.org/rec/conf/nips/DongR0KW022.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/nips/MiaoD0G22,
  author       = {Yibo Miao and
                  Yinpeng Dong and
                  Jun Zhu and
                  Xiao{-}Shan Gao},
  editor       = {Sanmi Koyejo and
                  S. Mohamed and
                  A. Agarwal and
                  Danielle Belgrave and
                  K. Cho and
                  A. Oh},
  title        = {Isometric 3D Adversarial Examples in the Physical World},
  booktitle    = {Advances in Neural Information Processing Systems 35: Annual Conference
                  on Neural Information Processing Systems 2022, NeurIPS 2022, New Orleans,
                  LA, USA, November 28 - December 9, 2022},
  year         = {2022},
  url          = {http://papers.nips.cc/paper\_files/paper/2022/hash/7c818dd40651b420873af70b8a790e3f-Abstract-Conference.html},
  timestamp    = {Mon, 08 Jan 2024 00:00:00 +0100},
  biburl       = {https://dblp.org/rec/conf/nips/MiaoD0G22.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/uss/FuD00022,
  author       = {Qi{-}An Fu and
                  Yinpeng Dong and
                  Hang Su and
                  Jun Zhu and
                  Chao Zhang},
  editor       = {Kevin R. B. Butler and
                  Kurt Thomas},
  title        = {AutoDA: Automated Decision-based Iterative Adversarial Attacks},
  booktitle    = {31st {USENIX} Security Symposium, {USENIX} Security 2022, Boston,
                  MA, USA, August 10-12, 2022},
  pages        = {3557--3574},
  publisher    = {{USENIX} Association},
  year         = {2022},
  url          = {https://www.usenix.org/conference/usenixsecurity22/presentation/fu-qi},
  timestamp    = {Tue, 18 Oct 2022 17:10:36 +0200},
  biburl       = {https://dblp.org/rec/conf/uss/FuD00022.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2203-04623,
  author       = {Xiao Yang and
                  Yinpeng Dong and
                  Tianyu Pang and
                  Zihao Xiao and
                  Hang Su and
                  Jun Zhu},
  title        = {Controllable Evaluation and Generation of Physical Adversarial Patch
                  on Face Recognition},
  journal      = {CoRR},
  volume       = {abs/2203.04623},
  year         = {2022},
  url          = {https://doi.org/10.48550/arXiv.2203.04623},
  doi          = {10.48550/ARXIV.2203.04623},
  eprinttype    = {arXiv},
  eprint       = {2203.04623},
  timestamp    = {Wed, 16 Mar 2022 00:00:00 +0100},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2203-04623.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2203-06560,
  author       = {Yinpeng Dong and
                  Shuyu Cheng and
                  Tianyu Pang and
                  Hang Su and
                  Jun Zhu},
  title        = {Query-Efficient Black-box Adversarial Attacks Guided by a Transfer-based
                  Prior},
  journal      = {CoRR},
  volume       = {abs/2203.06560},
  year         = {2022},
  url          = {https://doi.org/10.48550/arXiv.2203.06560},
  doi          = {10.48550/ARXIV.2203.06560},
  eprinttype    = {arXiv},
  eprint       = {2203.06560},
  timestamp    = {Wed, 16 Mar 2022 00:00:00 +0100},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2203-06560.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2205-14497,
  author       = {Shih{-}Han Chan and
                  Yinpeng Dong and
                  Jun Zhu and
                  Xiaolu Zhang and
                  Jun Zhou},
  title        = {BadDet: Backdoor Attacks on Object Detection},
  journal      = {CoRR},
  volume       = {abs/2205.14497},
  year         = {2022},
  url          = {https://doi.org/10.48550/arXiv.2205.14497},
  doi          = {10.48550/ARXIV.2205.14497},
  eprinttype    = {arXiv},
  eprint       = {2205.14497},
  timestamp    = {Fri, 14 Apr 2023 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2205-14497.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2206-01832,
  author       = {Xiaoyi Chen and
                  Yinpeng Dong and
                  Zeyu Sun and
                  Shengfang Zhai and
                  Qingni Shen and
                  Zhonghai Wu},
  title        = {Kallima: {A} Clean-label Framework for Textual Backdoor Attacks},
  journal      = {CoRR},
  volume       = {abs/2206.01832},
  year         = {2022},
  url          = {https://doi.org/10.48550/arXiv.2206.01832},
  doi          = {10.48550/ARXIV.2206.01832},
  eprinttype    = {arXiv},
  eprint       = {2206.01832},
  timestamp    = {Mon, 27 May 2024 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2206-01832.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2206-04310,
  author       = {Zhongkai Hao and
                  Chengyang Ying and
                  Yinpeng Dong and
                  Hang Su and
                  Jun Zhu and
                  Jian Song},
  title        = {GSmooth: Certified Robustness against Semantic Transformations via
                  Generalized Randomized Smoothing},
  journal      = {CoRR},
  volume       = {abs/2206.04310},
  year         = {2022},
  url          = {https://doi.org/10.48550/arXiv.2206.04310},
  doi          = {10.48550/ARXIV.2206.04310},
  eprinttype    = {arXiv},
  eprint       = {2206.04310},
  timestamp    = {Tue, 14 Jun 2022 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2206-04310.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2210-03372,
  author       = {Yuanhao Ban and
                  Yinpeng Dong},
  title        = {Pre-trained Adversarial Perturbations},
  journal      = {CoRR},
  volume       = {abs/2210.03372},
  year         = {2022},
  url          = {https://doi.org/10.48550/arXiv.2210.03372},
  doi          = {10.48550/ARXIV.2210.03372},
  eprinttype    = {arXiv},
  eprint       = {2210.03372},
  timestamp    = {Wed, 12 Oct 2022 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2210-03372.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2210-03895,
  author       = {Yinpeng Dong and
                  Shouwei Ruan and
                  Hang Su and
                  Caixin Kang and
                  Xingxing Wei and
                  Jun Zhu},
  title        = {ViewFool: Evaluating the Robustness of Visual Recognition to Adversarial
                  Viewpoints},
  journal      = {CoRR},
  volume       = {abs/2210.03895},
  year         = {2022},
  url          = {https://doi.org/10.48550/arXiv.2210.03895},
  doi          = {10.48550/ARXIV.2210.03895},
  eprinttype    = {arXiv},
  eprint       = {2210.03895},
  timestamp    = {Tue, 18 Oct 2022 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2210-03895.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2210-15291,
  author       = {Yibo Miao and
                  Yinpeng Dong and
                  Jun Zhu and
                  Xiao{-}Shan Gao},
  title        = {Isometric 3D Adversarial Examples in the Physical World},
  journal      = {CoRR},
  volume       = {abs/2210.15291},
  year         = {2022},
  url          = {https://doi.org/10.48550/arXiv.2210.15291},
  doi          = {10.48550/ARXIV.2210.15291},
  eprinttype    = {arXiv},
  eprint       = {2210.15291},
  timestamp    = {Wed, 02 Nov 2022 00:00:00 +0100},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2210-15291.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2211-01093,
  author       = {Jinali Zhang and
                  Yinpeng Dong and
                  Jun Zhu and
                  Jihong Zhu and
                  Minchi Kuang and
                  Xiaming Yuan},
  title        = {Improving transferability of 3D adversarial attacks with scale and
                  shear transformations},
  journal      = {CoRR},
  volume       = {abs/2211.01093},
  year         = {2022},
  url          = {https://doi.org/10.48550/arXiv.2211.01093},
  doi          = {10.48550/ARXIV.2211.01093},
  eprinttype    = {arXiv},
  eprint       = {2211.01093},
  timestamp    = {Wed, 26 Jul 2023 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2211-01093.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2212-03412,
  author       = {Yinpeng Dong and
                  Peng Chen and
                  Senyou Deng and
                  Lianji L and
                  Yi Sun and
                  Hanyu Zhao and
                  Jiaxing Li and
                  Yunteng Tan and
                  Xinyu Liu and
                  Yangyi Dong and
                  Enhui Xu and
                  Jincai Xu and
                  Shu Xu and
                  Xuelin Fu and
                  Changfeng Sun and
                  Haoliang Han and
                  Xuchong Zhang and
                  Shen Chen and
                  Zhimin Sun and
                  Junyi Cao and
                  Taiping Yao and
                  Shouhong Ding and
                  Yu Wu and
                  Jian Lin and
                  Tianpeng Wu and
                  Ye Wang and
                  Yu Fu and
                  Lin Feng and
                  Kangkang Gao and
                  Zeyu Liu and
                  Yuanzhe Pang and
                  Chengqi Duan and
                  Huipeng Zhou and
                  Yajie Wang and
                  Yuhang Zhao and
                  Shangbo Wu and
                  Haoran Lyu and
                  Zhiyu Lin and
                  Yifei Gao and
                  Shuang Li and
                  Haonan Wang and
                  Jitao Sang and
                  Chen Ma and
                  Junhao Zheng and
                  Yijia Li and
                  Chao Shen and
                  Chenhao Lin and
                  Zhichao Cui and
                  Guoshuai Liu and
                  Huafeng Shi and
                  Kun Hu and
                  Mengxin Zhang},
  title        = {Artificial Intelligence Security Competition {(AISC)}},
  journal      = {CoRR},
  volume       = {abs/2212.03412},
  year         = {2022},
  url          = {https://doi.org/10.48550/arXiv.2212.03412},
  doi          = {10.48550/ARXIV.2212.03412},
  eprinttype    = {arXiv},
  eprint       = {2212.03412},
  timestamp    = {Fri, 26 Jul 2024 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2212-03412.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/cvpr/XiaoGFDGZ0021,
  author       = {Zihao Xiao and
                  Xianfeng Gao and
                  Chilin Fu and
                  Yinpeng Dong and
                  Wei Gao and
                  Xiaolu Zhang and
                  Jun Zhou and
                  Jun Zhu},
  title        = {Improving Transferability of Adversarial Patches on Face Recognition
                  With Generative Models},
  booktitle    = {{IEEE} Conference on Computer Vision and Pattern Recognition, {CVPR}
                  2021, virtual, June 19-25, 2021},
  pages        = {11845--11854},
  publisher    = {Computer Vision Foundation / {IEEE}},
  year         = {2021},
  url          = {https://openaccess.thecvf.com/content/CVPR2021/html/Xiao\_Improving\_Transferability\_of\_Adversarial\_Patches\_on\_Face\_Recognition\_With\_Generative\_CVPR\_2021\_paper.html},
  doi          = {10.1109/CVPR46437.2021.01167},
  timestamp    = {Fri, 14 Apr 2023 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/conf/cvpr/XiaoGFDGZ0021.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/iccv/YangDP00C021,
  author       = {Xiao Yang and
                  Yinpeng Dong and
                  Tianyu Pang and
                  Hang Su and
                  Jun Zhu and
                  Yuefeng Chen and
                  Hui Xue},
  title        = {Towards Face Encryption by Generating Adversarial Identity Masks},
  booktitle    = {2021 {IEEE/CVF} International Conference on Computer Vision, {ICCV}
                  2021, Montreal, QC, Canada, October 10-17, 2021},
  pages        = {3877--3887},
  publisher    = {{IEEE}},
  year         = {2021},
  url          = {https://doi.org/10.1109/ICCV48922.2021.00387},
  doi          = {10.1109/ICCV48922.2021.00387},
  timestamp    = {Fri, 11 Mar 2022 10:01:27 +0100},
  biburl       = {https://dblp.org/rec/conf/iccv/YangDP00C021.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/iccv/DongYDPX0021,
  author       = {Yinpeng Dong and
                  Xiao Yang and
                  Zhijie Deng and
                  Tianyu Pang and
                  Zihao Xiao and
                  Hang Su and
                  Jun Zhu},
  title        = {Black-box Detection of Backdoor Attacks with Limited Information and
                  Data},
  booktitle    = {2021 {IEEE/CVF} International Conference on Computer Vision, {ICCV}
                  2021, Montreal, QC, Canada, October 10-17, 2021},
  pages        = {16462--16471},
  publisher    = {{IEEE}},
  year         = {2021},
  url          = {https://doi.org/10.1109/ICCV48922.2021.01617},
  doi          = {10.1109/ICCV48922.2021.01617},
  timestamp    = {Fri, 11 Mar 2022 00:00:00 +0100},
  biburl       = {https://dblp.org/rec/conf/iccv/DongYDPX0021.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/iclr/PangYDSZ21,
  author       = {Tianyu Pang and
                  Xiao Yang and
                  Yinpeng Dong and
                  Hang Su and
                  Jun Zhu},
  title        = {Bag of Tricks for Adversarial Training},
  booktitle    = {9th International Conference on Learning Representations, {ICLR} 2021,
                  Virtual Event, Austria, May 3-7, 2021},
  publisher    = {OpenReview.net},
  year         = {2021},
  url          = {https://openreview.net/forum?id=Xb8xvrtB8Ce},
  timestamp    = {Wed, 11 Aug 2021 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/conf/iclr/PangYDSZ21.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/nips/PangYDSZ21,
  author       = {Tianyu Pang and
                  Xiao Yang and
                  Yinpeng Dong and
                  Hang Su and
                  Jun Zhu},
  editor       = {Marc'Aurelio Ranzato and
                  Alina Beygelzimer and
                  Yann N. Dauphin and
                  Percy Liang and
                  Jennifer Wortman Vaughan},
  title        = {Accumulative Poisoning Attacks on Real-time Data},
  booktitle    = {Advances in Neural Information Processing Systems 34: Annual Conference
                  on Neural Information Processing Systems 2021, NeurIPS 2021, December
                  6-14, 2021, virtual},
  pages        = {2899--2912},
  year         = {2021},
  url          = {https://proceedings.neurips.cc/paper/2021/hash/16d11e9595188dbad0418a85f0351aba-Abstract.html},
  timestamp    = {Tue, 03 May 2022 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/conf/nips/PangYDSZ21.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2103-13127,
  author       = {Yinpeng Dong and
                  Xiao Yang and
                  Zhijie Deng and
                  Tianyu Pang and
                  Zihao Xiao and
                  Hang Su and
                  Jun Zhu},
  title        = {Black-box Detection of Backdoor Attacks with Limited Information and
                  Data},
  journal      = {CoRR},
  volume       = {abs/2103.13127},
  year         = {2021},
  url          = {https://arxiv.org/abs/2103.13127},
  eprinttype    = {arXiv},
  eprint       = {2103.13127},
  timestamp    = {Tue, 06 Apr 2021 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2103-13127.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2105-03931,
  author       = {Qi{-}An Fu and
                  Yinpeng Dong and
                  Hang Su and
                  Jun Zhu},
  title        = {Automated Decision-based Adversarial Attacks},
  journal      = {CoRR},
  volume       = {abs/2105.03931},
  year         = {2021},
  url          = {https://arxiv.org/abs/2105.03931},
  eprinttype    = {arXiv},
  eprint       = {2105.03931},
  timestamp    = {Fri, 14 May 2021 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2105-03931.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2105-14785,
  author       = {Tianyu Pang and
                  Huishuai Zhang and
                  Di He and
                  Yinpeng Dong and
                  Hang Su and
                  Wei Chen and
                  Jun Zhu and
                  Tie{-}Yan Liu},
  title        = {Adversarial Training with Rectified Rejection},
  journal      = {CoRR},
  volume       = {abs/2105.14785},
  year         = {2021},
  url          = {https://arxiv.org/abs/2105.14785},
  eprinttype    = {arXiv},
  eprint       = {2105.14785},
  timestamp    = {Fri, 10 Nov 2023 00:00:00 +0100},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2105-14785.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2106-01606,
  author       = {Yinpeng Dong and
                  Ke Xu and
                  Xiao Yang and
                  Tianyu Pang and
                  Zhijie Deng and
                  Hang Su and
                  Jun Zhu},
  title        = {Exploring Memorization in Adversarial Training},
  journal      = {CoRR},
  volume       = {abs/2106.01606},
  year         = {2021},
  url          = {https://arxiv.org/abs/2106.01606},
  eprinttype    = {arXiv},
  eprint       = {2106.01606},
  timestamp    = {Wed, 11 Aug 2021 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2106-01606.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2106-09993,
  author       = {Tianyu Pang and
                  Xiao Yang and
                  Yinpeng Dong and
                  Hang Su and
                  Jun Zhu},
  title        = {Accumulative Poisoning Attacks on Real-time Data},
  journal      = {CoRR},
  volume       = {abs/2106.09993},
  year         = {2021},
  url          = {https://arxiv.org/abs/2106.09993},
  eprinttype    = {arXiv},
  eprint       = {2106.09993},
  timestamp    = {Wed, 11 Aug 2021 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2106-09993.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2106-15058,
  author       = {Zihao Xiao and
                  Xianfeng Gao and
                  Chilin Fu and
                  Yinpeng Dong and
                  Wei Gao and
                  Xiaolu Zhang and
                  Jun Zhou and
                  Jun Zhu},
  title        = {Improving Transferability of Adversarial Patches on Face Recognition
                  with Generative Models},
  journal      = {CoRR},
  volume       = {abs/2106.15058},
  year         = {2021},
  url          = {https://arxiv.org/abs/2106.15058},
  eprinttype    = {arXiv},
  eprint       = {2106.15058},
  timestamp    = {Mon, 05 Jul 2021 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2106-15058.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2107-01809,
  author       = {Xiao Yang and
                  Yinpeng Dong and
                  Tianyu Pang and
                  Hang Su and
                  Jun Zhu},
  title        = {Boosting Transferability of Targeted Adversarial Examples via Hierarchical
                  Generative Networks},
  journal      = {CoRR},
  volume       = {abs/2107.01809},
  year         = {2021},
  url          = {https://arxiv.org/abs/2107.01809},
  eprinttype    = {arXiv},
  eprint       = {2107.01809},
  timestamp    = {Mon, 16 Aug 2021 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2107-01809.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2110-08042,
  author       = {Yinpeng Dong and
                  Qi{-}An Fu and
                  Xiao Yang and
                  Wenzhao Xiang and
                  Tianyu Pang and
                  Hang Su and
                  Jun Zhu and
                  Jiayu Tang and
                  Yuefeng Chen and
                  Xiaofeng Mao and
                  Yuan He and
                  Hui Xue and
                  Chao Li and
                  Ye Liu and
                  Qilong Zhang and
                  Lianli Gao and
                  Yunrui Yu and
                  Xitong Gao and
                  Zhe Zhao and
                  Daquan Lin and
                  Jiadong Lin and
                  Chuanbiao Song and
                  Zihao Wang and
                  Zhennan Wu and
                  Yang Guo and
                  Jiequan Cui and
                  Xiaogang Xu and
                  Pengguang Chen},
  title        = {Adversarial Attacks on {ML} Defense Models Competition},
  journal      = {CoRR},
  volume       = {abs/2110.08042},
  year         = {2021},
  url          = {https://arxiv.org/abs/2110.08042},
  eprinttype    = {arXiv},
  eprint       = {2110.08042},
  timestamp    = {Fri, 16 Sep 2022 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2110-08042.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2110-08256,
  author       = {Xiao Yang and
                  Yinpeng Dong and
                  Wenzhao Xiang and
                  Tianyu Pang and
                  Hang Su and
                  Jun Zhu},
  title        = {Model-Agnostic Meta-Attack: Towards Reliable Evaluation of Adversarial
                  Robustness},
  journal      = {CoRR},
  volume       = {abs/2110.08256},
  year         = {2021},
  url          = {https://arxiv.org/abs/2110.08256},
  eprinttype    = {arXiv},
  eprint       = {2110.08256},
  timestamp    = {Wed, 16 Mar 2022 00:00:00 +0100},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2110-08256.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2110-09903,
  author       = {Yuefeng Chen and
                  Xiaofeng Mao and
                  Yuan He and
                  Hui Xue and
                  Chao Li and
                  Yinpeng Dong and
                  Qi{-}An Fu and
                  Xiao Yang and
                  Wenzhao Xiang and
                  Tianyu Pang and
                  Hang Su and
                  Jun Zhu and
                  Fangcheng Liu and
                  Chao Zhang and
                  Hongyang Zhang and
                  Yichi Zhang and
                  Shilong Liu and
                  Chang Liu and
                  Wenzhao Xiang and
                  Yajie Wang and
                  Huipeng Zhou and
                  Haoran Lyu and
                  Yidan Xu and
                  Zixuan Xu and
                  Taoyu Zhu and
                  Wenjun Li and
                  Xianfeng Gao and
                  Guoqiu Wang and
                  Huanqian Yan and
                  Ying Guo and
                  Chaoning Zhang and
                  Zheng Fang and
                  Yang Wang and
                  Bingyang Fu and
                  Yunfei Zheng and
                  Yekui Wang and
                  Haorong Luo and
                  Zhen Yang},
  title        = {Unrestricted Adversarial Attacks on ImageNet Competition},
  journal      = {CoRR},
  volume       = {abs/2110.09903},
  year         = {2021},
  url          = {https://arxiv.org/abs/2110.09903},
  eprinttype    = {arXiv},
  eprint       = {2110.09903},
  timestamp    = {Tue, 16 Jan 2024 00:00:00 +0100},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2110-09903.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/cvpr/DongFYPSXZ20,
  author       = {Yinpeng Dong and
                  Qi{-}An Fu and
                  Xiao Yang and
                  Tianyu Pang and
                  Hang Su and
                  Zihao Xiao and
                  Jun Zhu},
  title        = {Benchmarking Adversarial Robustness on Image Classification},
  booktitle    = {2020 {IEEE/CVF} Conference on Computer Vision and Pattern Recognition,
                  {CVPR} 2020, Seattle, WA, USA, June 13-19, 2020},
  pages        = {318--328},
  publisher    = {Computer Vision Foundation / {IEEE}},
  year         = {2020},
  url          = {https://openaccess.thecvf.com/content\_CVPR\_2020/html/Dong\_Benchmarking\_Adversarial\_Robustness\_on\_Image\_Classification\_CVPR\_2020\_paper.html},
  doi          = {10.1109/CVPR42600.2020.00040},
  timestamp    = {Tue, 31 Aug 2021 14:00:04 +0200},
  biburl       = {https://dblp.org/rec/conf/cvpr/DongFYPSXZ20.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/iclr/PangXDD0Z20,
  author       = {Tianyu Pang and
                  Kun Xu and
                  Yinpeng Dong and
                  Chao Du and
                  Ning Chen and
                  Jun Zhu},
  title        = {Rethinking Softmax Cross-Entropy Loss for Adversarial Robustness},
  booktitle    = {8th International Conference on Learning Representations, {ICLR} 2020,
                  Addis Ababa, Ethiopia, April 26-30, 2020},
  publisher    = {OpenReview.net},
  year         = {2020},
  url          = {https://openreview.net/forum?id=Byg9A24tvB},
  timestamp    = {Mon, 26 Oct 2020 00:00:00 +0100},
  biburl       = {https://dblp.org/rec/conf/iclr/PangXDD0Z20.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/ijcai/TangD020,
  author       = {Zhicong Tang and
                  Yinpeng Dong and
                  Hang Su},
  editor       = {Hu{\'{a}}scar Espinoza and
                  John A. McDermid and
                  Xiaowei Huang and
                  Mauricio Castillo{-}Effen and
                  Xin Cynthia Chen and
                  Jos{\'{e}} Hern{\'{a}}ndez{-}Orallo and
                  Se{\'{a}}n {\'{O}} h{\'{E}}igeartaigh and
                  Richard Mallah},
  title        = {Error-Silenced Quantization: Bridging Robustness and Compactness},
  booktitle    = {Proceedings of the Workshop on Artificial Intelligence Safety 2020
                  co-located with the 29th International Joint Conference on Artificial
                  Intelligence and the 17th Pacific Rim International Conference on
                  Artificial Intelligence {(IJCAI-PRICAI} 2020), Yokohama, Japan, January,
                  2021},
  series       = {{CEUR} Workshop Proceedings},
  volume       = {2640},
  publisher    = {CEUR-WS.org},
  year         = {2020},
  url          = {https://ceur-ws.org/Vol-2640/paper\_8.pdf},
  timestamp    = {Fri, 10 Mar 2023 16:23:32 +0100},
  biburl       = {https://dblp.org/rec/conf/ijcai/TangD020.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/nips/DengDZ020,
  author       = {Zhijie Deng and
                  Yinpeng Dong and
                  Shifeng Zhang and
                  Jun Zhu},
  editor       = {Hugo Larochelle and
                  Marc'Aurelio Ranzato and
                  Raia Hadsell and
                  Maria{-}Florina Balcan and
                  Hsuan{-}Tien Lin},
  title        = {Understanding and Exploring the Network with Stochastic Architectures},
  booktitle    = {Advances in Neural Information Processing Systems 33: Annual Conference
                  on Neural Information Processing Systems 2020, NeurIPS 2020, December
                  6-12, 2020, virtual},
  year         = {2020},
  url          = {https://proceedings.neurips.cc/paper/2020/hash/aa85e45da94cb0d78853c50ba636a15a-Abstract.html},
  timestamp    = {Tue, 19 Jan 2021 00:00:00 +0100},
  biburl       = {https://dblp.org/rec/conf/nips/DengDZ020.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/nips/DongDP0020,
  author       = {Yinpeng Dong and
                  Zhijie Deng and
                  Tianyu Pang and
                  Jun Zhu and
                  Hang Su},
  editor       = {Hugo Larochelle and
                  Marc'Aurelio Ranzato and
                  Raia Hadsell and
                  Maria{-}Florina Balcan and
                  Hsuan{-}Tien Lin},
  title        = {Adversarial Distributional Training for Robust Deep Learning},
  booktitle    = {Advances in Neural Information Processing Systems 33: Annual Conference
                  on Neural Information Processing Systems 2020, NeurIPS 2020, December
                  6-12, 2020, virtual},
  year         = {2020},
  url          = {https://proceedings.neurips.cc/paper/2020/hash/5de8a36008b04a6167761fa19b61aa6c-Abstract.html},
  timestamp    = {Tue, 19 Jan 2021 00:00:00 +0100},
  biburl       = {https://dblp.org/rec/conf/nips/DongDP0020.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/nips/PangYDX0020,
  author       = {Tianyu Pang and
                  Xiao Yang and
                  Yinpeng Dong and
                  Taufik Xu and
                  Jun Zhu and
                  Hang Su},
  editor       = {Hugo Larochelle and
                  Marc'Aurelio Ranzato and
                  Raia Hadsell and
                  Maria{-}Florina Balcan and
                  Hsuan{-}Tien Lin},
  title        = {Boosting Adversarial Training with Hypersphere Embedding},
  booktitle    = {Advances in Neural Information Processing Systems 33: Annual Conference
                  on Neural Information Processing Systems 2020, NeurIPS 2020, December
                  6-12, 2020, virtual},
  year         = {2020},
  url          = {https://proceedings.neurips.cc/paper/2020/hash/5898d8095428ee310bf7fa3da1864ff7-Abstract.html},
  timestamp    = {Tue, 19 Jan 2021 00:00:00 +0100},
  biburl       = {https://dblp.org/rec/conf/nips/PangYDX0020.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2002-05999,
  author       = {Zhijie Deng and
                  Yinpeng Dong and
                  Tianyu Pang and
                  Hang Su and
                  Jun Zhu},
  title        = {Adversarial Distributional Training for Robust Deep Learning},
  journal      = {CoRR},
  volume       = {abs/2002.05999},
  year         = {2020},
  url          = {https://arxiv.org/abs/2002.05999},
  eprinttype    = {arXiv},
  eprint       = {2002.05999},
  timestamp    = {Mon, 12 Oct 2020 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2002-05999.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2002-08619,
  author       = {Tianyu Pang and
                  Xiao Yang and
                  Yinpeng Dong and
                  Kun Xu and
                  Hang Su and
                  Jun Zhu},
  title        = {Boosting Adversarial Training with Hypersphere Embedding},
  journal      = {CoRR},
  volume       = {abs/2002.08619},
  year         = {2020},
  url          = {https://arxiv.org/abs/2002.08619},
  eprinttype    = {arXiv},
  eprint       = {2002.08619},
  timestamp    = {Fri, 04 Dec 2020 00:00:00 +0100},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2002-08619.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2003-06814,
  author       = {Xiao Yang and
                  Yinpeng Dong and
                  Tianyu Pang and
                  Jun Zhu and
                  Hang Su},
  title        = {Towards Privacy Protection by Generating Adversarial Identity Masks},
  journal      = {CoRR},
  volume       = {abs/2003.06814},
  year         = {2020},
  url          = {https://arxiv.org/abs/2003.06814},
  eprinttype    = {arXiv},
  eprint       = {2003.06814},
  timestamp    = {Fri, 04 Dec 2020 00:00:00 +0100},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2003-06814.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2007-04118,
  author       = {Xiao Yang and
                  Dingcheng Yang and
                  Yinpeng Dong and
                  Wenjian Yu and
                  Hang Su and
                  Jun Zhu},
  title        = {Delving into the Adversarial Robustness on Face Recognition},
  journal      = {CoRR},
  volume       = {abs/2007.04118},
  year         = {2020},
  url          = {https://arxiv.org/abs/2007.04118},
  eprinttype    = {arXiv},
  eprint       = {2007.04118},
  timestamp    = {Fri, 04 Dec 2020 00:00:00 +0100},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2007-04118.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2010-00467,
  author       = {Tianyu Pang and
                  Xiao Yang and
                  Yinpeng Dong and
                  Hang Su and
                  Jun Zhu},
  title        = {Bag of Tricks for Adversarial Training},
  journal      = {CoRR},
  volume       = {abs/2010.00467},
  year         = {2020},
  url          = {https://arxiv.org/abs/2010.00467},
  eprinttype    = {arXiv},
  eprint       = {2010.00467},
  timestamp    = {Fri, 04 Dec 2020 00:00:00 +0100},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2010-00467.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2010-01979,
  author       = {Zhijie Deng and
                  Xiao Yang and
                  Hao Zhang and
                  Yinpeng Dong and
                  Jun Zhu},
  title        = {BayesAdapter: Being Bayesian, Inexpensively and Robustly, via Bayeisan
                  Fine-tuning},
  journal      = {CoRR},
  volume       = {abs/2010.01979},
  year         = {2020},
  url          = {https://arxiv.org/abs/2010.01979},
  eprinttype    = {arXiv},
  eprint       = {2010.01979},
  timestamp    = {Mon, 12 Oct 2020 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2010-01979.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/ijcv/DongNLCSZ19,
  author       = {Yinpeng Dong and
                  Renkun Ni and
                  Jianguo Li and
                  Yurong Chen and
                  Hang Su and
                  Jun Zhu},
  title        = {Stochastic Quantization for Learning Accurate Low-Bit Deep Neural
                  Networks},
  journal      = {Int. J. Comput. Vis.},
  volume       = {127},
  number       = {11-12},
  pages        = {1629--1642},
  year         = {2019},
  url          = {https://doi.org/10.1007/s11263-019-01168-2},
  doi          = {10.1007/S11263-019-01168-2},
  timestamp    = {Wed, 01 Sep 2021 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/journals/ijcv/DongNLCSZ19.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/aaai/QiaobenWLDJZ19,
  author       = {You Qiaoben and
                  Zheng Wang and
                  Jianguo Li and
                  Yinpeng Dong and
                  Yu{-}Gang Jiang and
                  Jun Zhu},
  title        = {Composite Binary Decomposition Networks},
  booktitle    = {The Thirty-Third {AAAI} Conference on Artificial Intelligence, {AAAI}
                  2019, The Thirty-First Innovative Applications of Artificial Intelligence
                  Conference, {IAAI} 2019, The Ninth {AAAI} Symposium on Educational
                  Advances in Artificial Intelligence, {EAAI} 2019, Honolulu, Hawaii,
                  USA, January 27 - February 1, 2019},
  pages        = {4747--4754},
  publisher    = {{AAAI} Press},
  year         = {2019},
  url          = {https://doi.org/10.1609/aaai.v33i01.33014747},
  doi          = {10.1609/AAAI.V33I01.33014747},
  timestamp    = {Tue, 07 May 2024 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/conf/aaai/QiaobenWLDJZ19.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/cvpr/DongPSZ19,
  author       = {Yinpeng Dong and
                  Tianyu Pang and
                  Hang Su and
                  Jun Zhu},
  title        = {Evading Defenses to Transferable Adversarial Examples by Translation-Invariant
                  Attacks},
  booktitle    = {{IEEE} Conference on Computer Vision and Pattern Recognition, {CVPR}
                  2019, Long Beach, CA, USA, June 16-20, 2019},
  pages        = {4312--4321},
  publisher    = {Computer Vision Foundation / {IEEE}},
  year         = {2019},
  url          = {http://openaccess.thecvf.com/content\_CVPR\_2019/html/Dong\_Evading\_Defenses\_to\_Transferable\_Adversarial\_Examples\_by\_Translation-Invariant\_Attacks\_CVPR\_2019\_paper.html},
  doi          = {10.1109/CVPR.2019.00444},
  timestamp    = {Mon, 30 Aug 2021 17:01:14 +0200},
  biburl       = {https://dblp.org/rec/conf/cvpr/DongPSZ19.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/cvpr/DongSWLL0019,
  author       = {Yinpeng Dong and
                  Hang Su and
                  Baoyuan Wu and
                  Zhifeng Li and
                  Wei Liu and
                  Tong Zhang and
                  Jun Zhu},
  title        = {Efficient Decision-Based Black-Box Adversarial Attacks on Face Recognition},
  booktitle    = {{IEEE} Conference on Computer Vision and Pattern Recognition, {CVPR}
                  2019, Long Beach, CA, USA, June 16-20, 2019},
  pages        = {7714--7722},
  publisher    = {Computer Vision Foundation / {IEEE}},
  year         = {2019},
  url          = {http://openaccess.thecvf.com/content\_CVPR\_2019/html/Dong\_Efficient\_Decision-Based\_Black-Box\_Adversarial\_Attacks\_on\_Face\_Recognition\_CVPR\_2019\_paper.html},
  doi          = {10.1109/CVPR.2019.00790},
  timestamp    = {Fri, 22 Apr 2022 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/conf/cvpr/DongSWLL0019.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/nips/ChengDPSZ19,
  author       = {Shuyu Cheng and
                  Yinpeng Dong and
                  Tianyu Pang and
                  Hang Su and
                  Jun Zhu},
  editor       = {Hanna M. Wallach and
                  Hugo Larochelle and
                  Alina Beygelzimer and
                  Florence d'Alch{\'{e}}{-}Buc and
                  Emily B. Fox and
                  Roman Garnett},
  title        = {Improving Black-box Adversarial Attacks with a Transfer-based Prior},
  booktitle    = {Advances in Neural Information Processing Systems 32: Annual Conference
                  on Neural Information Processing Systems 2019, NeurIPS 2019, December
                  8-14, 2019, Vancouver, BC, Canada},
  pages        = {10932--10942},
  year         = {2019},
  url          = {https://proceedings.neurips.cc/paper/2019/hash/32508f53f24c46f685870a075eaaa29c-Abstract.html},
  timestamp    = {Mon, 16 May 2022 15:41:51 +0200},
  biburl       = {https://dblp.org/rec/conf/nips/ChengDPSZ19.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-1901-09035,
  author       = {Yinpeng Dong and
                  Fan Bao and
                  Hang Su and
                  Jun Zhu},
  title        = {Towards Interpretable Deep Neural Networks by Leveraging Adversarial
                  Examples},
  journal      = {CoRR},
  volume       = {abs/1901.09035},
  year         = {2019},
  url          = {http://arxiv.org/abs/1901.09035},
  eprinttype    = {arXiv},
  eprint       = {1901.09035},
  timestamp    = {Thu, 05 Mar 2020 00:00:00 +0100},
  biburl       = {https://dblp.org/rec/journals/corr/abs-1901-09035.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-1902-09192,
  author       = {Zhijie Deng and
                  Yinpeng Dong and
                  Jun Zhu},
  title        = {Batch Virtual Adversarial Training for Graph Convolutional Networks},
  journal      = {CoRR},
  volume       = {abs/1902.09192},
  year         = {2019},
  url          = {http://arxiv.org/abs/1902.09192},
  eprinttype    = {arXiv},
  eprint       = {1902.09192},
  timestamp    = {Tue, 21 May 2019 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/journals/corr/abs-1902-09192.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-1904-02884,
  author       = {Yinpeng Dong and
                  Tianyu Pang and
                  Hang Su and
                  Jun Zhu},
  title        = {Evading Defenses to Transferable Adversarial Examples by Translation-Invariant
                  Attacks},
  journal      = {CoRR},
  volume       = {abs/1904.02884},
  year         = {2019},
  url          = {http://arxiv.org/abs/1904.02884},
  eprinttype    = {arXiv},
  eprint       = {1904.02884},
  timestamp    = {Thu, 05 Mar 2020 00:00:00 +0100},
  biburl       = {https://dblp.org/rec/journals/corr/abs-1904-02884.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-1904-04433,
  author       = {Yinpeng Dong and
                  Hang Su and
                  Baoyuan Wu and
                  Zhifeng Li and
                  Wei Liu and
                  Tong Zhang and
                  Jun Zhu},
  title        = {Efficient Decision-based Black-box Adversarial Attacks on Face Recognition},
  journal      = {CoRR},
  volume       = {abs/1904.04433},
  year         = {2019},
  url          = {http://arxiv.org/abs/1904.04433},
  eprinttype    = {arXiv},
  eprint       = {1904.04433},
  timestamp    = {Fri, 22 Apr 2022 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/journals/corr/abs-1904-04433.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-1905-10626,
  author       = {Tianyu Pang and
                  Kun Xu and
                  Yinpeng Dong and
                  Chao Du and
                  Ning Chen and
                  Jun Zhu},
  title        = {Rethinking Softmax Cross-Entropy Loss for Adversarial Robustness},
  journal      = {CoRR},
  volume       = {abs/1905.10626},
  year         = {2019},
  url          = {http://arxiv.org/abs/1905.10626},
  eprinttype    = {arXiv},
  eprint       = {1905.10626},
  timestamp    = {Thu, 17 Sep 2020 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/journals/corr/abs-1905-10626.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-1906-06919,
  author       = {Shuyu Cheng and
                  Yinpeng Dong and
                  Tianyu Pang and
                  Hang Su and
                  Jun Zhu},
  title        = {Improving Black-box Adversarial Attacks with a Transfer-based Prior},
  journal      = {CoRR},
  volume       = {abs/1906.06919},
  year         = {2019},
  url          = {http://arxiv.org/abs/1906.06919},
  eprinttype    = {arXiv},
  eprint       = {1906.06919},
  timestamp    = {Thu, 05 Mar 2020 00:00:00 +0100},
  biburl       = {https://dblp.org/rec/journals/corr/abs-1906-06919.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-1912-11852,
  author       = {Yinpeng Dong and
                  Qi{-}An Fu and
                  Xiao Yang and
                  Tianyu Pang and
                  Hang Su and
                  Zihao Xiao and
                  Jun Zhu},
  title        = {Benchmarking Adversarial Robustness},
  journal      = {CoRR},
  volume       = {abs/1912.11852},
  year         = {2019},
  url          = {http://arxiv.org/abs/1912.11852},
  eprinttype    = {arXiv},
  eprint       = {1912.11852},
  timestamp    = {Fri, 04 Dec 2020 00:00:00 +0100},
  biburl       = {https://dblp.org/rec/journals/corr/abs-1912-11852.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/cvpr/LiaoLDPH018,
  author       = {Fangzhou Liao and
                  Ming Liang and
                  Yinpeng Dong and
                  Tianyu Pang and
                  Xiaolin Hu and
                  Jun Zhu},
  title        = {Defense Against Adversarial Attacks Using High-Level Representation
                  Guided Denoiser},
  booktitle    = {2018 {IEEE} Conference on Computer Vision and Pattern Recognition,
                  {CVPR} 2018, Salt Lake City, UT, USA, June 18-22, 2018},
  pages        = {1778--1787},
  publisher    = {Computer Vision Foundation / {IEEE} Computer Society},
  year         = {2018},
  url          = {http://openaccess.thecvf.com/content\_cvpr\_2018/html/Liao\_Defense\_Against\_Adversarial\_CVPR\_2018\_paper.html},
  doi          = {10.1109/CVPR.2018.00191},
  timestamp    = {Fri, 24 Mar 2023 00:00:00 +0100},
  biburl       = {https://dblp.org/rec/conf/cvpr/LiaoLDPH018.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/cvpr/SuZDCCL18,
  author       = {Zhou Su and
                  Chen Zhu and
                  Yinpeng Dong and
                  Dongqi Cai and
                  Yurong Chen and
                  Jianguo Li},
  title        = {Learning Visual Knowledge Memory Networks for Visual Question Answering},
  booktitle    = {2018 {IEEE} Conference on Computer Vision and Pattern Recognition,
                  {CVPR} 2018, Salt Lake City, UT, USA, June 18-22, 2018},
  pages        = {7736--7745},
  publisher    = {Computer Vision Foundation / {IEEE} Computer Society},
  year         = {2018},
  url          = {http://openaccess.thecvf.com/content\_cvpr\_2018/html/Su\_Learning\_Visual\_Knowledge\_CVPR\_2018\_paper.html},
  doi          = {10.1109/CVPR.2018.00807},
  timestamp    = {Fri, 24 Mar 2023 00:00:00 +0100},
  biburl       = {https://dblp.org/rec/conf/cvpr/SuZDCCL18.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/cvpr/DongLPS0HL18,
  author       = {Yinpeng Dong and
                  Fangzhou Liao and
                  Tianyu Pang and
                  Hang Su and
                  Jun Zhu and
                  Xiaolin Hu and
                  Jianguo Li},
  title        = {Boosting Adversarial Attacks With Momentum},
  booktitle    = {2018 {IEEE} Conference on Computer Vision and Pattern Recognition,
                  {CVPR} 2018, Salt Lake City, UT, USA, June 18-22, 2018},
  pages        = {9185--9193},
  publisher    = {Computer Vision Foundation / {IEEE} Computer Society},
  year         = {2018},
  url          = {http://openaccess.thecvf.com/content\_cvpr\_2018/html/Dong\_Boosting\_Adversarial\_Attacks\_CVPR\_2018\_paper.html},
  doi          = {10.1109/CVPR.2018.00957},
  timestamp    = {Fri, 24 Mar 2023 00:00:00 +0100},
  biburl       = {https://dblp.org/rec/conf/cvpr/DongLPS0HL18.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/nips/PangDDZ18,
  author       = {Tianyu Pang and
                  Chao Du and
                  Yinpeng Dong and
                  Jun Zhu},
  editor       = {Samy Bengio and
                  Hanna M. Wallach and
                  Hugo Larochelle and
                  Kristen Grauman and
                  Nicol{\`{o}} Cesa{-}Bianchi and
                  Roman Garnett},
  title        = {Towards Robust Detection of Adversarial Examples},
  booktitle    = {Advances in Neural Information Processing Systems 31: Annual Conference
                  on Neural Information Processing Systems 2018, NeurIPS 2018, December
                  3-8, 2018, Montr{\'{e}}al, Canada},
  pages        = {4584--4594},
  year         = {2018},
  url          = {https://proceedings.neurips.cc/paper/2018/hash/e0f7a4d0ef9b84b83b693bbf3feb8e6e-Abstract.html},
  timestamp    = {Mon, 16 May 2022 15:41:51 +0200},
  biburl       = {https://dblp.org/rec/conf/nips/PangDDZ18.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-1804-00097,
  author       = {Alexey Kurakin and
                  Ian J. Goodfellow and
                  Samy Bengio and
                  Yinpeng Dong and
                  Fangzhou Liao and
                  Ming Liang and
                  Tianyu Pang and
                  Jun Zhu and
                  Xiaolin Hu and
                  Cihang Xie and
                  Jianyu Wang and
                  Zhishuai Zhang and
                  Zhou Ren and
                  Alan L. Yuille and
                  Sangxia Huang and
                  Yao Zhao and
                  Yuzhe Zhao and
                  Zhonglin Han and
                  Junjiajia Long and
                  Yerkebulan Berdibekov and
                  Takuya Akiba and
                  Seiya Tokui and
                  Motoki Abe},
  title        = {Adversarial Attacks and Defences Competition},
  journal      = {CoRR},
  volume       = {abs/1804.00097},
  year         = {2018},
  url          = {http://arxiv.org/abs/1804.00097},
  eprinttype    = {arXiv},
  eprint       = {1804.00097},
  timestamp    = {Sat, 26 Aug 2023 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/journals/corr/abs-1804-00097.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-1806-04860,
  author       = {Zhou Su and
                  Chen Zhu and
                  Yinpeng Dong and
                  Dongqi Cai and
                  Yurong Chen and
                  Jianguo Li},
  title        = {Learning Visual Knowledge Memory Networks for Visual Question Answering},
  journal      = {CoRR},
  volume       = {abs/1806.04860},
  year         = {2018},
  url          = {http://arxiv.org/abs/1806.04860},
  eprinttype    = {arXiv},
  eprint       = {1806.04860},
  timestamp    = {Wed, 01 Sep 2021 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/journals/corr/abs-1806-04860.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-1811-06668,
  author       = {You Qiaoben and
                  Zheng Wang and
                  Jianguo Li and
                  Yinpeng Dong and
                  Yu{-}Gang Jiang and
                  Jun Zhu},
  title        = {Composite Binary Decomposition Networks},
  journal      = {CoRR},
  volume       = {abs/1811.06668},
  year         = {2018},
  url          = {http://arxiv.org/abs/1811.06668},
  eprinttype    = {arXiv},
  eprint       = {1811.06668},
  timestamp    = {Thu, 09 Feb 2023 00:00:00 +0100},
  biburl       = {https://dblp.org/rec/journals/corr/abs-1811-06668.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/bmvc/DongLN17,
  author       = {Yinpeng Dong and
                  Jianguo Li and
                  Renkun Ni},
  title        = {Learning Accurate Low-Bit Deep Neural Networks with Stochastic Quantization},
  booktitle    = {British Machine Vision Conference 2017, {BMVC} 2017, London, UK, September
                  4-7, 2017},
  publisher    = {{BMVA} Press},
  year         = {2017},
  url          = {https://www.dropbox.com/s/lc8qzyyirr561zr/0333.pdf},
  timestamp    = {Fri, 08 Sep 2023 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/conf/bmvc/DongLN17.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/cvpr/DongSZZ17,
  author       = {Yinpeng Dong and
                  Hang Su and
                  Jun Zhu and
                  Bo Zhang},
  title        = {Improving Interpretability of Deep Neural Networks with Semantic Information},
  booktitle    = {2017 {IEEE} Conference on Computer Vision and Pattern Recognition,
                  {CVPR} 2017, Honolulu, HI, USA, July 21-26, 2017},
  pages        = {975--983},
  publisher    = {{IEEE} Computer Society},
  year         = {2017},
  url          = {https://doi.org/10.1109/CVPR.2017.110},
  doi          = {10.1109/CVPR.2017.110},
  timestamp    = {Fri, 24 Mar 2023 00:00:00 +0100},
  biburl       = {https://dblp.org/rec/conf/cvpr/DongSZZ17.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/ijcai/SuZDZ17,
  author       = {Hang Su and
                  Jun Zhu and
                  Yinpeng Dong and
                  Bo Zhang},
  editor       = {Carles Sierra},
  title        = {Forecast the Plausible Paths in Crowd Scenes},
  booktitle    = {Proceedings of the Twenty-Sixth International Joint Conference on
                  Artificial Intelligence, {IJCAI} 2017, Melbourne, Australia, August
                  19-25, 2017},
  pages        = {2772--2778},
  publisher    = {ijcai.org},
  year         = {2017},
  url          = {https://doi.org/10.24963/ijcai.2017/386},
  doi          = {10.24963/IJCAI.2017/386},
  timestamp    = {Thu, 05 Mar 2020 00:00:00 +0100},
  biburl       = {https://dblp.org/rec/conf/ijcai/SuZDZ17.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/DongSZZ17,
  author       = {Yinpeng Dong and
                  Hang Su and
                  Jun Zhu and
                  Bo Zhang},
  title        = {Improving Interpretability of Deep Neural Networks with Semantic Information},
  journal      = {CoRR},
  volume       = {abs/1703.04096},
  year         = {2017},
  url          = {http://arxiv.org/abs/1703.04096},
  eprinttype    = {arXiv},
  eprint       = {1703.04096},
  timestamp    = {Thu, 05 Mar 2020 00:00:00 +0100},
  biburl       = {https://dblp.org/rec/journals/corr/DongSZZ17.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-1708-01001,
  author       = {Yinpeng Dong and
                  Renkun Ni and
                  Jianguo Li and
                  Yurong Chen and
                  Jun Zhu and
                  Hang Su},
  title        = {Learning Accurate Low-Bit Deep Neural Networks with Stochastic Quantization},
  journal      = {CoRR},
  volume       = {abs/1708.01001},
  year         = {2017},
  url          = {http://arxiv.org/abs/1708.01001},
  eprinttype    = {arXiv},
  eprint       = {1708.01001},
  timestamp    = {Wed, 01 Sep 2021 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/journals/corr/abs-1708-01001.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-1708-05493,
  author       = {Yinpeng Dong and
                  Hang Su and
                  Jun Zhu and
                  Fan Bao},
  title        = {Towards Interpretable Deep Neural Networks by Leveraging Adversarial
                  Examples},
  journal      = {CoRR},
  volume       = {abs/1708.05493},
  year         = {2017},
  url          = {http://arxiv.org/abs/1708.05493},
  eprinttype    = {arXiv},
  eprint       = {1708.05493},
  timestamp    = {Thu, 05 Mar 2020 00:00:00 +0100},
  biburl       = {https://dblp.org/rec/journals/corr/abs-1708-05493.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-1710-06081,
  author       = {Yinpeng Dong and
                  Fangzhou Liao and
                  Tianyu Pang and
                  Xiaolin Hu and
                  Jun Zhu},
  title        = {Discovering Adversarial Examples with Momentum},
  journal      = {CoRR},
  volume       = {abs/1710.06081},
  year         = {2017},
  url          = {http://arxiv.org/abs/1710.06081},
  eprinttype    = {arXiv},
  eprint       = {1710.06081},
  timestamp    = {Thu, 24 Jan 2019 00:00:00 +0100},
  biburl       = {https://dblp.org/rec/journals/corr/abs-1710-06081.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-1712-02976,
  author       = {Fangzhou Liao and
                  Ming Liang and
                  Yinpeng Dong and
                  Tianyu Pang and
                  Jun Zhu and
                  Xiaolin Hu},
  title        = {Defense against Adversarial Attacks Using High-Level Representation
                  Guided Denoiser},
  journal      = {CoRR},
  volume       = {abs/1712.02976},
  year         = {2017},
  url          = {http://arxiv.org/abs/1712.02976},
  eprinttype    = {arXiv},
  eprint       = {1712.02976},
  timestamp    = {Thu, 24 Jan 2019 00:00:00 +0100},
  biburl       = {https://dblp.org/rec/journals/corr/abs-1712-02976.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/eccv/SuZYDZ16,
  author       = {Hang Su and
                  Jun Zhu and
                  Zhaozheng Yin and
                  Yinpeng Dong and
                  Bo Zhang},
  editor       = {Bastian Leibe and
                  Jiri Matas and
                  Nicu Sebe and
                  Max Welling},
  title        = {Efficient and Robust Semi-supervised Learning Over a Sparse-Regularized
                  Graph},
  booktitle    = {Computer Vision - {ECCV} 2016 - 14th European Conference, Amsterdam,
                  The Netherlands, October 11-14, 2016, Proceedings, Part {VIII}},
  series       = {Lecture Notes in Computer Science},
  volume       = {9912},
  pages        = {583--598},
  publisher    = {Springer},
  year         = {2016},
  url          = {https://doi.org/10.1007/978-3-319-46484-8\_35},
  doi          = {10.1007/978-3-319-46484-8\_35},
  timestamp    = {Wed, 07 Dec 2022 23:10:23 +0100},
  biburl       = {https://dblp.org/rec/conf/eccv/SuZYDZ16.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/ijcai/SuDZLZ16,
  author       = {Hang Su and
                  Yinpeng Dong and
                  Jun Zhu and
                  Haibin Ling and
                  Bo Zhang},
  editor       = {Subbarao Kambhampati},
  title        = {Crowd Scene Understanding with Coherent Recurrent Neural Networks},
  booktitle    = {Proceedings of the Twenty-Fifth International Joint Conference on
                  Artificial Intelligence, {IJCAI} 2016, New York, NY, USA, 9-15 July
                  2016},
  pages        = {3469--3476},
  publisher    = {{IJCAI/AAAI} Press},
  year         = {2016},
  url          = {http://www.ijcai.org/Abstract/16/490},
  timestamp    = {Thu, 05 Mar 2020 00:00:00 +0100},
  biburl       = {https://dblp.org/rec/conf/ijcai/SuDZLZ16.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/QianDMJL16,
  author       = {Yujie Qian and
                  Yinpeng Dong and
                  Ye Ma and
                  Hailong Jin and
                  Juanzi Li},
  title        = {Feature Engineering and Ensemble Modeling for Paper Acceptance Rank
                  Prediction},
  journal      = {CoRR},
  volume       = {abs/1611.04369},
  year         = {2016},
  url          = {http://arxiv.org/abs/1611.04369},
  eprinttype    = {arXiv},
  eprint       = {1611.04369},
  timestamp    = {Mon, 13 Aug 2018 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/journals/corr/QianDMJL16.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}