{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,19]],"date-time":"2026-08-19T10:30:33Z","timestamp":1787135433691,"version":"3.56.0"},"publisher-location":"Cham","reference-count":29,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031999901","type":"print"},{"value":"9783031999918","type":"electronic"}],"license":[{"start":{"date-parts":[[2025,10,28]],"date-time":"2025-10-28T00:00:00Z","timestamp":1761609600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,10,28]],"date-time":"2025-10-28T00:00:00Z","timestamp":1761609600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-3-031-99991-8_2","type":"book-chapter","created":{"date-parts":[[2025,10,27]],"date-time":"2025-10-27T05:35:51Z","timestamp":1761543351000},"page":"29-48","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Robustness Margin: A New Measure for\u00a0the\u00a0Robustness of\u00a0Neural Networks"],"prefix":"10.1007","author":[{"given":"Lionel","family":"Kielh\u00f6fer","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-1050-5165","authenticated-orcid":false,"given":"Annelot W.","family":"Bosman","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0629-0099","authenticated-orcid":false,"given":"Holger H.","family":"Hoos","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2898-2168","authenticated-orcid":false,"given":"Jan N.","family":"van Rijn","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,10,28]]},"reference":[{"key":"2_CR1","unstructured":"Bastani, O., Ioannou, Y., Lampropoulos, L., Vytiniotis, D., Nori, A., Criminisi, A.: Measuring neural net robustness with constraints. In: Advances in Neural Information Processing Systems 29 (NeurIPS 2016), vol. 29, pp. 2613\u20132621 (2016)"},{"key":"2_CR2","doi-asserted-by":"crossref","unstructured":"Bosman, A.W., Berger, A., Hoos, H.H., van Rijn, J.N.: Robustness distributions in neural network verification. J. Artif. Intell. Res. (2025, to appear)","DOI":"10.1613\/jair.1.18403"},{"key":"2_CR3","doi-asserted-by":"crossref","unstructured":"Bosman, A.W., M\u00fcnz, A.L., Hoos, H.H., van Rijn, J.N.: A preliminary study to examining per-class performance bias via robustness distributions. In: International Symposium on AI Verification (SAIV) co-located with the 36th International Conference on Computer Aided Verification (CAV 2024), pp. 116\u2013133. Springer (2024)","DOI":"10.1007\/978-3-031-65112-0_6"},{"key":"2_CR4","doi-asserted-by":"crossref","unstructured":"Botoeva, E., Kouvaros, P., Kronqvist, J., Lomuscio, A., Misener, R.: Efficient verification of ReLU-based neural networks via dependency analysis. In: Proceedings of the 34th AAAI Conference on Artificial Intelligence (AAAI 2020), pp. 3291\u20133299 (2020)","DOI":"10.1609\/aaai.v34i04.5729"},{"key":"2_CR5","unstructured":"Bunel, R., Turkaslan, I., Torr, P., Kohli, P., Mudigonda, P.K.: A unified view of piecewise linear neural network verification. In: Advances in Neural Information Processing Systems 31 (NeurIPS 2018), pp. 1\u201310 (2018)"},{"key":"2_CR6","unstructured":"Carlini, N., Katz, G., Barrett, C., Dill, D.L.: Ground-Truth Adversarial Examples. arXiv preprint arXiv:1709.10207 (2017)"},{"key":"2_CR7","doi-asserted-by":"crossref","unstructured":"Carlini, N., Wagner, D.: Towards evaluating the robustness of neural networks. In: 2017 IEEE Symposium on Security and Privac (SP), pp. 39\u201357. IEEE (2017)","DOI":"10.1109\/SP.2017.49"},{"issue":"3","key":"2_CR8","doi-asserted-by":"publisher","first-page":"247","DOI":"10.1016\/j.dam.2003.11.004","volume":"144","author":"F Cicalese","year":"2004","unstructured":"Cicalese, F., Gargano, L., Vaccaro, U.: On searching strategies, parallel questions, and delayed answers. Discret. Appl. Math. 144(3), 247\u2013262 (2004)","journal-title":"Discret. Appl. Math."},{"key":"2_CR9","unstructured":"Cohen, J., Rosenfeld, E., Kolter, Z.: Certified adversarial robustness via randomized smoothing. In: Chaudhuri, K., Salakhutdinov, R. (eds.) Proceedings of the 36th International Conference on Machine Learning. Proceedings of Machine Learning Research, vol.\u00a097, pp. 1310\u20131320. PMLR (2019)"},{"key":"2_CR10","unstructured":"De\u00a0Palma, A., et al.: Improved Branch and Bound for Neural Network Verification via Lagrangian Decomposition. arXiv preprint arXiv:2104.06718 (2021)"},{"issue":"6","key":"2_CR11","doi-asserted-by":"publisher","first-page":"141","DOI":"10.1109\/MSP.2012.2211477","volume":"29","author":"L Deng","year":"2012","unstructured":"Deng, L.: The MNIST database of handwritten digit images for machine learning research [best of the web]. IEEE Signal Process. Mag. 29(6), 141\u2013142 (2012)","journal-title":"IEEE Signal Process. Mag."},{"key":"2_CR12","unstructured":"Dvijotham, K., Stanforth, R., Gowal, S., Mann, T.A., Kohli, P.: A dual approach to scalable verification of deep networks. In: Proceedings of the 38th Conference on Uncertainty in Artificial Intelligence (UAI 2018), pp. 550\u2013559 (2018)"},{"key":"2_CR13","doi-asserted-by":"crossref","unstructured":"Gehr, T., Mirman, M., Drachsler-Cohen, D., Tsankov, P., Chaudhuri, S., Vechev, M.: Safety and robustness certification of neural networks with abstract interpretation. In: 2018 IEEE Symposium on Security and Privacy (SP), pp. 3\u201318. IEEE (2018)","DOI":"10.1109\/SP.2018.00058"},{"key":"2_CR14","unstructured":"Goodfellow, I.J., Shlens, J., Szegedy, C.: Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572 (2014)"},{"key":"2_CR15","unstructured":"Huang, R., Xu, B., Schuurmans, D., Szepesvari, C.: Learning with a Strong Adversary. arXiv e-prints pp. arXiv\u20131511 (2015)"},{"issue":"3","key":"2_CR16","doi-asserted-by":"publisher","first-page":"598","DOI":"10.2514\/1.G003724","volume":"42","author":"KD Julian","year":"2019","unstructured":"Julian, K.D., Kochenderfer, M.J., Owen, M.P.: Deep neural network compression for aircraft collision avoidance systems. J. Guid. Control Dyn. 42(3), 598\u2013608 (2019)","journal-title":"J. Guid. Control Dyn."},{"key":"2_CR17","doi-asserted-by":"crossref","unstructured":"Katz, G., Barrett, C., Dill, D.L., Julian, K., Kochenderfer, M.J.: Reluplex: an efficient SMT solver for verifying deep neural networks. In: Proceedings of the 29th International Conference on Computer Aided Verification (CAV 2022), pp. 97\u2013117. Springer (2017)","DOI":"10.1007\/978-3-319-63387-9_5"},{"key":"2_CR18","first-page":"89","volume":"4","author":"A Kolmogorov","year":"1933","unstructured":"Kolmogorov, A.: Sulla determinazione empirica di una legge didistribuzione. Giorn Dell\u2019inst Ital Degli Att 4, 89\u201391 (1933)","journal-title":"Giorn Dell\u2019inst Ital Degli Att"},{"issue":"12","key":"2_CR19","first-page":"1","volume":"25","author":"M K\u00f6nig","year":"2024","unstructured":"K\u00f6nig, M., Bosman, A.W., Hoos, H.H., Rijn, J.N.: Critically assessing the state of the art in neural network verification. J. Mach. Learn. Res. 25(12), 1\u201353 (2024)","journal-title":"J. Mach. Learn. Res."},{"key":"2_CR20","doi-asserted-by":"crossref","unstructured":"K\u00f6nig, M., Hoos, H.H., van Rijn, J.N.: Accelerating adversarially robust model selection for deep neural networks via racing. In: Thirty-Eighth AAAI Conference on Artificial Intelligence (AAAI 2024), pp. 21267\u201321275. AAAI Press (2024)","DOI":"10.1609\/aaai.v38i19.30121"},{"key":"2_CR21","unstructured":"Leino, K., Wang, Z., Fredrikson, M.: Globally-robust neural networks. In: Meila, M., Zhang, T. (eds.) Proceedings of the 38th International Conference on Machine Learning. Proceedings of Machine Learning Research, vol.\u00a0139, pp. 6212\u20136222. PMLR (2021)"},{"key":"2_CR22","doi-asserted-by":"crossref","unstructured":"Li, L., Xie, T., Li, B.: SoK: certified robustness for deep neural networks. In: 2023 IEEE Symposium on Security and Privacy (SP 2023), pp. 94\u2013115. IEEE Computer Society (2023)","DOI":"10.1109\/SP46215.2023.10179303"},{"key":"2_CR23","doi-asserted-by":"crossref","unstructured":"Meeker, W.Q., Hahn, G.J., Escobar, L.A.: Distribution-Free Statistical Intervals, chap.\u00a05, pp. 73\u201398. Wiley (2017)","DOI":"10.1002\/9781118594841.ch5"},{"key":"2_CR24","doi-asserted-by":"crossref","unstructured":"Papernot, N., McDaniel, P., Wu, X., Jha, S., Swami, A.: Distillation as a defense to adversarial perturbations against deep neural networks. In: 2016 IEEE Symposium on Security and Privacy (SP), pp. 582\u2013597. IEEE (2016)","DOI":"10.1109\/SP.2016.41"},{"key":"2_CR25","unstructured":"Shaham, U., Yamada, Y., Negahban, S.: Understanding Adversarial Training: Increasing Local Stability of Neural Nets through Robust Optimization. arXiv preprint arXiv:1511.05432 (2015)"},{"key":"2_CR26","first-page":"179","volume":"10","author":"NV Smirnov","year":"1944","unstructured":"Smirnov, N.V.: Approximate laws of distribution of random variables from empirical data. Uspekhi Matematicheskikh Nauk 10, 179\u2013206 (1944)","journal-title":"Uspekhi Matematicheskikh Nauk"},{"key":"2_CR27","unstructured":"Szegedy, C., et al.: Intriguing properties of neural networks. In: Proceedings of the 2nd International Conference on Learning Representations (ICLR 2014), pp. 1\u201310 (2014)"},{"key":"2_CR28","unstructured":"Tjeng, V., Xiao, K., Tedrake, R.: Evaluating robustness of neural networks with mixed integer programming. In: Proceedings of the 7th International Conference on Learning Representations (ICLR 2019), pp. 1\u201321 (2019)"},{"key":"2_CR29","unstructured":"Yang, Y.Y., Rashtchian, C., Zhang, H., Salakhutdinov, R.R., Chaudhuri, K.: A closer look at accuracy vs. robustness. In: Advances in Neural Information Processing Systems 33 (NeurIPS 2020), pp. 8588\u20138601 (2020)"}],"container-title":["Lecture Notes in Computer Science","AI Verification"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-99991-8_2","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,8,19]],"date-time":"2026-08-19T10:13:52Z","timestamp":1787134432000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-99991-8_2"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,28]]},"ISBN":["9783031999901","9783031999918"],"references-count":29,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-99991-8_2","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,10,28]]},"assertion":[{"value":"28 October 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"SAIV","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Symposium on AI Verification","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Zagreb","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Croatia","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"21 July 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"22 July 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"saiv2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/www.aiverification.org\/2025\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}