{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,17]],"date-time":"2026-07-17T11:07:25Z","timestamp":1784286445682,"version":"3.55.0"},"publisher-location":"Cham","reference-count":45,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783032323569","type":"print"},{"value":"9783032323576","type":"electronic"}],"license":[{"start":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T00:00:00Z","timestamp":1784332800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T00:00:00Z","timestamp":1784332800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2027]]},"DOI":"10.1007\/978-3-032-32357-6_14","type":"book-chapter","created":{"date-parts":[[2026,7,17]],"date-time":"2026-07-17T10:33:56Z","timestamp":1784284436000},"page":"299-313","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Enhancing the\u00a0Robustness of\u00a0Counterfactual Explanations via\u00a0Adversarial Training"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0009-0002-9265-6121","authenticated-orcid":false,"given":"Rithik Appachi","family":"Senthilkumar","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8245-9429","authenticated-orcid":false,"given":"Francesco","family":"Leofante","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6029-2047","authenticated-orcid":false,"given":"Vijay","family":"Ganesh","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,7,18]]},"reference":[{"key":"14_CR1","doi-asserted-by":"crossref","unstructured":"Altmeyer, P., Farmanbar, M., van Deursen, A., Liem, C.C.: Faithful model explanations through energy-constrained conformal counterfactuals. In: Proceedings of the AAAI Conference on Artificial Intelligence. vol.\u00a038, pp. 10829\u201310837 (2024)","DOI":"10.1609\/aaai.v38i10.28956"},{"key":"14_CR2","doi-asserted-by":"publisher","unstructured":"Ansel, J., et al.: PyTorch 2: faster machine learning through dynamic python bytecode transformation and graph compilation. In: 29th ACM International Conference on Architectural Support for Programming Languages and Operating Systems, vol. 2 (ASPLOS \u201924). ACM (2024). https:\/\/doi.org\/10.1145\/3620665.3640366, https:\/\/docs.pytorch.org\/assets\/pytorch2-2.pdf","DOI":"10.1145\/3620665.3640366"},{"key":"14_CR3","doi-asserted-by":"crossref","unstructured":"Breunig, M.M., Kriegel, H.P., Ng, R.T., Sander, J.: Lof: identifying density-based local outliers. In: Proceedings of the 2000 ACM SIGMOD International Conference on Management of Data, pp. 93\u2013104 (2000)","DOI":"10.1145\/342009.335388"},{"issue":"5","key":"14_CR4","doi-asserted-by":"publisher","first-page":"2665","DOI":"10.1007\/s10618-023-00930-y","volume":"38","author":"D Brughmans","year":"2024","unstructured":"Brughmans, D., Leyman, P., Martens, D.: Nice: an algorithm for nearest instance counterfactual explanations. Data Min. Knowl. Disc. 38(5), 2665\u20132703 (2024)","journal-title":"Data Min. Knowl. Disc."},{"key":"14_CR5","unstructured":"Carlini, N., et al.: On evaluating adversarial robustness. arXiv preprint arXiv:1902.06705 (2019)"},{"key":"14_CR6","unstructured":"Croce, F., et al.: Robustbench: a standardized adversarial robustness benchmark. arXiv preprint arXiv:2010.09670 (2020)"},{"key":"14_CR7","unstructured":"Dutta, S., Long, J., Mishra, S., Tilli, C., Magazzeni, D.: Robust counterfactual explanations for tree-based ensembles. In: International Conference on Machine Learning, ICML 2022, 17-23 July 2022, Baltimore, Maryland, USA. Proceedings of Machine Learning Research, vol.\u00a0162, pp. 5742\u20135756. PMLR (2022)"},{"issue":"1","key":"14_CR8","doi-asserted-by":"publisher","first-page":"77","DOI":"10.1007\/s11023-021-09580-9","volume":"32","author":"T Freiesleben","year":"2022","unstructured":"Freiesleben, T.: The intriguing relation between counterfactual explanations and adversarial examples. Mind. Mach. 32(1), 77\u2013109 (2022)","journal-title":"Mind. Mach."},{"key":"14_CR9","unstructured":"Goodfellow, I.J., Shlens, J., Szegedy, C.: Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572 (2014)"},{"issue":"4","key":"14_CR10","doi-asserted-by":"publisher","first-page":"291","DOI":"10.2174\/1389202922666210705124359","volume":"22","author":"H Habehh","year":"2021","unstructured":"Habehh, H., Gohel, S.: Machine learning in healthcare. Curr. Genom. 22(4), 291 (2021)","journal-title":"Curr. Genom."},{"key":"14_CR11","doi-asserted-by":"publisher","unstructured":"Hopkins, M., Reeber, E., Forman, G., Suermondt, J.: Spambase. UCI Mach. Learn. Repository (1999). https:\/\/doi.org\/10.24432\/C53G6X","DOI":"10.24432\/C53G6X"},{"key":"14_CR12","doi-asserted-by":"crossref","unstructured":"Izza, Y., Huang, X., Morgado, A., Planes, J., Ignatiev, A., Marques-Silva, J.: Distance-restricted explanations: theoretical underpinnings & efficient implementation. arXiv preprint arXiv:2405.08297 (2024)","DOI":"10.24963\/kr.2024\/45"},{"key":"14_CR13","doi-asserted-by":"crossref","unstructured":"Jiang, J., Leofante, F., Rago, A., Toni, F.: Formalising the robustness of counterfactual explanations for neural networks. In: Thirty-Seventh AAAI Conference on Artificial Intelligence, pp. 14901\u201314909. AAAI Press (2023)","DOI":"10.1609\/aaai.v37i12.26740"},{"key":"14_CR14","unstructured":"Jiang, J., Leofante, F., Rago, A., Toni, F.: Robust counterfactual explanations in machine learning: A survey. In: Proceedings of the Thirty-Third International Joint Conference on Artificial Intelligence, IJCAI 2024, Jeju, South Korea, 3-9 August 2024, pp. 8086\u20138094. ijcai.org (2024)"},{"key":"14_CR15","doi-asserted-by":"crossref","unstructured":"Jiang, J., Marzari, L., Purohit, A., Leofante, F.: Robustx: robust counterfactual explanations made easy. In: Proceedings of the Thirty-Fourth International Joint Conference on Artificial Intelligence, IJCAI 2025, Montreal, Canada, 16-22 August 2025, pp. 11067\u201311071. ijcai.org (2025)","DOI":"10.24963\/ijcai.2025\/1264"},{"key":"14_CR16","unstructured":"Joshi, S., Koyejo, O., Vijitbenjaronk, W., Kim, B., Ghosh, J.: Towards realistic individual recourse and actionable explanations in black-box decision making systems. arXiv preprint arXiv:1907.09615 (2019)"},{"key":"14_CR17","unstructured":"Karimi, A.H., Barthe, G., Sch\u00f6lkopf, B., Valera, I.: A survey of algorithmic recourse: definitions, formulations, solutions, and prospects arXiv:2010.04050 (2020)"},{"key":"14_CR18","doi-asserted-by":"publisher","unstructured":"Katz, G., Barrett, C., Dill, D.L., Julian, K., Kochenderfer, M.J.: Reluplex: an efficient SMT solver for verifying deep neural networks. In: Majumdar, R., Kun\u010dak, V. (eds.) CAV 2017. LNCS, vol. 10426, pp. 97\u2013117. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-63387-9_5","DOI":"10.1007\/978-3-319-63387-9_5"},{"issue":"12","key":"14_CR19","first-page":"1","volume":"25","author":"M K\u00f6nig","year":"2024","unstructured":"K\u00f6nig, M., Bosman, A.W., Hoos, H.H., van Rijn, J.N.: Critically assessing the state of the art in neural network verification. J. Mach. Learn. Res. 25(12), 1\u201353 (2024)","journal-title":"J. Mach. Learn. Res."},{"key":"14_CR20","doi-asserted-by":"crossref","unstructured":"Kotha, S., Brix, C., Kolter, J.Z., Dvijotham, K., Zhang, H.: Provably bounding neural network preimages. In: Advances in Neural Information Processing Systems, vol. 36, pp. 80270\u201380290. Curran Associates, Inc (2023)","DOI":"10.52202\/075280-3518"},{"key":"14_CR21","doi-asserted-by":"crossref","unstructured":"Leofante, F., Lomuscio, A.: Towards robust contrastive explanations for human-neural multi-agent systems. In: Proceedings of the 2023 International Conference on Autonomous Agents and Multiagent Systems, AAMAS 2023, London, United Kingdom, 29 May 2023 - 2 June 2023, pp. 2343\u20132345. ACM (2023)","DOI":"10.65109\/LNZE3711"},{"key":"14_CR22","unstructured":"Madry, A., Makelov, A., Schmidt, L., Tsipras, D., Vladu, A.: Towards deep learning models resistant to adversarial attacks arXiv preprint arXiv:1706.06083 (2017)"},{"key":"14_CR23","doi-asserted-by":"publisher","unstructured":"Mar\u00edn L\u00f3pez, D., Mar\u00edn, D., Fonollosa, J., Llano, J., Perera, A., Haddi, Z.: Single elder home monitoring: gas and position. UCI Mach. Learn. Repository (2023). https:\/\/doi.org\/10.24432\/C5762W","DOI":"10.24432\/C5762W"},{"key":"14_CR24","doi-asserted-by":"crossref","unstructured":"Mohammadi, K., Karimi, A.H., Barthe, G., Valera, I.: Scaling guarantees for nearest counterfactual explanations. In: Proceedings of the 2021 AAAI\/ACM Conference on AI, Ethics, and Society, pp. 177\u2013187 (2021)","DOI":"10.1145\/3461702.3462514"},{"key":"14_CR25","unstructured":"Molnar, C.: Interpretable machine learning. Lulu. com (2020)"},{"issue":"3","key":"14_CR26","doi-asserted-by":"publisher","first-page":"291","DOI":"10.1016\/S0167-7152(96)00140-X","volume":"33","author":"RK Pace","year":"1997","unstructured":"Pace, R.K., Barry, R.: Sparse spatial autoregressions. Stat. Probabil. Lett. 33(3), 291\u2013297 (1997)","journal-title":"Stat. Probabil. Lett."},{"key":"14_CR27","unstructured":"Pawelczyk, M., Agarwal, C., Joshi, S., Upadhyay, S., Lakkaraju, H.: Exploring counterfactual explanations through the lens of adversarial examples: a theoretical and empirical analysis. In: International Conference on Artificial Intelligence and Statistics, pp. 4574\u20134594. PMLR (2022)"},{"key":"14_CR28","unstructured":"Pawelczyk, M., Datta, T., van\u00a0den Heuvel, J., Kasneci, G., Lakkaraju, H.: Probabilistically robust recourse: navigating the trade-offs between costs and robustness in algorithmic recourse. In: The Eleventh International Conference on Learning Representations, ICLR. OpenReview.net (2023)"},{"key":"14_CR29","unstructured":"Schut, L., Key, O., Mc Grath, R., Costabello, L., Sacaleanu, B., Gal, Y.: Generating interpretable counterfactual explanations by implicit minimisation of epistemic and aleatoric uncertainties. In: International Conference on Artificial Intelligence and Statistics, pp. 1756\u20131764. PMLR (2021)"},{"key":"14_CR30","unstructured":"Shafahi, A., et al.: Adversarial training for free! Advances in Neural Information Processing Systems, p. 32 (2019)"},{"key":"14_CR31","doi-asserted-by":"crossref","unstructured":"Shi, Z., Jin, Q., Kolter, Z., Jana, S., Hsieh, C.J., Zhang, H.: Neural network verification with branch-and-bound for general nonlinearities. In: International Conference on Tools and Algorithms for the Construction and Analysis of Systems (2025)","DOI":"10.1007\/978-3-031-90643-5_17"},{"key":"14_CR32","doi-asserted-by":"crossref","unstructured":"Singh, G., Gehr, T., P\u00fcschel, M., Vechev, M.: An abstract domain for certifying neural networks. Proc. ACM Program. Languages 3(POPL), 1\u201330 (2019)","DOI":"10.1145\/3290354"},{"issue":"17","key":"14_CR33","doi-asserted-by":"publisher","first-page":"10594","DOI":"10.3390\/ijerph191710594","volume":"19","author":"GV Travaini","year":"2022","unstructured":"Travaini, G.V., Pacchioni, F., Bellumore, S., Bosia, M., De Micco, F.: Machine learning and criminal justice: a systematic review of advanced methodology for recidivism risk prediction. Int. J. Environ. Res. Publ. Heal. 19(17), 10594 (2022)","journal-title":"Int. J. Environ. Res. Publ. Heal."},{"key":"14_CR34","unstructured":"Upadhyay, S., Joshi, S., Lakkaraju, H.: Towards robust and reliable algorithmic recourse. In: Ranzato, M., Beygelzimer, A., Dauphin, Y.N., Liang, P., Vaughan, J.W. (eds.) Advances in Neural Information Processing Systems 34: Annual Conference on Neural Information Processing Systems 2021, NeurIPS 2021, 6-14 December 2021, virtual, pp. 16926\u201316937 (2021)"},{"key":"14_CR35","first-page":"841","volume":"31","author":"S Wachter","year":"2017","unstructured":"Wachter, S., Mittelstadt, B., Russell, C.: Counterfactual explanations without opening the black box: automated decisions and the GDPR. Harv. JL & Tech. 31, 841 (2017)","journal-title":"Harv. JL & Tech."},{"key":"14_CR36","unstructured":"Wang, S., et al.: Beta-crown: efficient bound propagation with per-neuron split constraints for neural network robustness verification. Adv. Neural. Inf. Process. Syst. 34, 29909\u201329921 (2021)"},{"key":"14_CR37","doi-asserted-by":"crossref","unstructured":"Wu, H., et al.: Marabou 2.0: a versatile formal analyzer of neural networks (2024). https:\/\/arxiv.org\/abs\/2401.14461","DOI":"10.1007\/978-3-031-65630-9_13"},{"key":"14_CR38","unstructured":"Xu, K., et al.: Automatic perturbation analysis for scalable certified robustness and beyond. Adv. Neural. Inf. Process. Syst. 33 (2020)"},{"key":"14_CR39","unstructured":"Xu, K., et al.: Fast and complete: enabling complete neural network verification with rapid and massively parallel incomplete verifiers. In: International Conference on Learning Representations (2021). https:\/\/openreview.net\/forum?id=nVZtXBI6LNn"},{"key":"14_CR40","unstructured":"Zhang, H., et al.: Towards stable and efficient training of verifiably robust neural networks. arXiv preprint arXiv:1906.06316 (2019)"},{"key":"14_CR41","doi-asserted-by":"crossref","unstructured":"Zhang, H., et al.: General cutting planes for bound-propagation-based neural network verification. Adv. Neural Inf. Process. Syst. (2022)","DOI":"10.52202\/068431-0121"},{"key":"14_CR42","unstructured":"Zhang, H., et al.: A branch and bound framework for stronger adversarial attacks of ReLU networks. In: Proceedings of the 39th International Conference on Machine Learning. vol.\u00a0162, pp. 26591\u201326604 (2022)"},{"key":"14_CR43","unstructured":"Zhang, H., Weng, T.W., Chen, P.Y., Hsieh, C.J., Daniel, L.: Efficient neural network robustness certification with general activation functions. In: Advances in Neural Information Processing Systems (NuerIPS) (2018)"},{"issue":"1","key":"14_CR44","doi-asserted-by":"publisher","first-page":"27","DOI":"10.1631\/FITEE.1700808","volume":"19","author":"Q Zhang","year":"2018","unstructured":"Zhang, Q., Zhu, S.: Visual interpretability for deep learning: a survey. Front. Inf. Technol. Electron. Eng. 19(1), 27\u201339 (2018). https:\/\/doi.org\/10.1631\/FITEE.1700808","journal-title":"Front. Inf. Technol. Electron. Eng."},{"key":"14_CR45","doi-asserted-by":"crossref","unstructured":"Zhou, D., Brix, C., Hanasusanto, G.A., Zhang, H.: Scalable neural network verification with branch-and-bound inferred cutting planes. In: The Thirty-eighth Annual Conference on Neural Information Processing Systems (2024)","DOI":"10.52202\/079017-0923"}],"container-title":["Lecture Notes in Computer Science","AI Verification"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-032-32357-6_14","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,17]],"date-time":"2026-07-17T10:34:10Z","timestamp":1784284450000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-032-32357-6_14"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,7,18]]},"ISBN":["9783032323569","9783032323576"],"references-count":45,"URL":"https:\/\/doi.org\/10.1007\/978-3-032-32357-6_14","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,7,18]]},"assertion":[{"value":"18 July 2026","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"The authors have no competing interests to declare that are relevant to the content of this article.","order":1,"name":"Ethics","label":"Disclosure of Interests","group":{"name":"EthicsHeading","label":"Ethics"}},{"value":"SAIV","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Symposium on AI Verification","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Lisbon","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Portugal","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2026","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"24 July 2026","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"25 July 2026","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"3","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"saiv2026","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/aiverification.org\/2026","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}