{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,3]],"date-time":"2026-04-03T15:48:35Z","timestamp":1775231315437,"version":"3.50.1"},"publisher-location":"Singapore","reference-count":50,"publisher":"Springer Nature Singapore","isbn-type":[{"value":"9789819691005","type":"print"},{"value":"9789819691012","type":"electronic"}],"license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025]]},"DOI":"10.1007\/978-981-96-9101-2_16","type":"book-chapter","created":{"date-parts":[[2025,7,10]],"date-time":"2025-07-10T09:48:44Z","timestamp":1752140924000},"page":"307-326","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Understanding the\u00a0Robustness of\u00a0Machine-Unlearning Models"],"prefix":"10.1007","author":[{"given":"Guanqin","family":"Zhang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Feng","family":"Xu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"H. M. N. Dilum","family":"Bandara","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shiping","family":"Chen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yulei","family":"Sui","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,7,7]]},"reference":[{"key":"16_CR1","doi-asserted-by":"crossref","unstructured":"Bai, T., Luo, J., Zhao, J., Wen, B., Wang, Q.: Recent advances in adversarial training for adversarial robustness. In: Proceedings of 30th International Joint Conference on Artificial Intelligence (IJCAI 2021), Montreal, Canada, pp. 4312\u20134321. ijcai.org (2021)","DOI":"10.24963\/ijcai.2021\/591"},{"key":"16_CR2","doi-asserted-by":"crossref","unstructured":"Bertram, T., et al.: Five years of the right to be forgotten. In: Proceedings of 2019 ACM SIGSAC Conference on Computer and Communications Security (CCS 2019), London, UK, pp. 959\u2013972. Association for Computing Machinery (2019)","DOI":"10.1145\/3319535.3354208"},{"key":"16_CR3","doi-asserted-by":"crossref","unstructured":"Bourtoule, L., et al.: Machine unlearning. In: 42nd IEEE Symposium on Security and Privacy (S &P 2021), Virtual, San Francisco, CA, United States, vol. 2021-May, pp. 141\u2013159. Institute of Electrical and Electronics Engineers Inc. (2021)","DOI":"10.1109\/SP40001.2021.00019"},{"key":"16_CR4","doi-asserted-by":"crossref","unstructured":"Byali, M., Chaudhari, H., Patra, A., Suresh, A.: Flash: fast and robust framework for privacy-preserving machine learning. Cryptology ePrint Archive (2019)","DOI":"10.2478\/popets-2020-0036"},{"key":"16_CR5","unstructured":"Office of the Privacy Commissioner of Canada: Announcement: Privacy commissioner seeks federal court determination on key issue for Canadians online reputation (2018). https:\/\/www.priv.gc.ca\/en\/opc-news\/news-and-announcements\/2018\/an181010\/"},{"key":"16_CR6","doi-asserted-by":"crossref","unstructured":"Carlini, N., Wagner, D.: Towards evaluating the robustness of neural networks. In: 2017 IEEE Symposium on Security and Privacy (S &P 2017), San Jose, CA, United States, pp. 39\u201357. Institute of Electrical and Electronics Engineers Inc. (2017)","DOI":"10.1109\/SP.2017.49"},{"key":"16_CR7","doi-asserted-by":"crossref","unstructured":"Chen, J., Gu, Q.: Rays: a ray searching method for hard-label adversarial attack. In: Proceedings of 26th ACM SIGKDD International Conference on Knowledge Discovery & Data Mining (KDD 2020), Virtual Event, CA, USA, pp. 1739\u20131747. Association for Computing Machinery (2020)","DOI":"10.1145\/3394486.3403225"},{"key":"16_CR8","doi-asserted-by":"publisher","first-page":"397","DOI":"10.1016\/j.ins.2022.05.066","volume":"606","author":"Z Chen","year":"2022","unstructured":"Chen, Z., Jiang, L., Li, C.: Label augmented and weighted majority voting for crowdsourcing. Inf. Sci. 606, 397\u2013409 (2022)","journal-title":"Inf. Sci."},{"key":"16_CR9","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"39","DOI":"10.1007\/978-3-030-89432-0_4","volume-title":"Information Security Applications","author":"J Choi","year":"2021","unstructured":"Choi, J., Kim, H.: On the robustness of intrusion detection systems for vehicles against adversarial attacks. In: Kim, H. (ed.) WISA 2021. LNCS, vol. 13009, pp. 39\u201350. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-89432-0_4"},{"key":"16_CR10","unstructured":"Croce, F., et al.: Robustbench: a standardized adversarial robustness benchmark. In: Proceedings of Neural Information Processing Systems Track on Datasets and Benchmarks. Neural Information Processing Systems Foundation, Virtual (2021)"},{"key":"16_CR11","doi-asserted-by":"crossref","unstructured":"Dalvi, N., Domingos, P., Sanghai, S., Verma, D.: Adversarial classification. In: Proc. of 10th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining (SIGKDD 2004), Seattle, Washington, USA, pp. 99\u2013108. Association for Computing Machinery (2004)","DOI":"10.1145\/1014052.1014066"},{"key":"16_CR12","doi-asserted-by":"crossref","unstructured":"Dang, Q.V.: Right to be forgotten in the age of machine learning. In: International Conference on Advances in Digital Science (ICADS 2021), Salvador, Brazil, pp. 403\u2013411. Springer (2021)","DOI":"10.1007\/978-3-030-71782-7_35"},{"key":"16_CR13","doi-asserted-by":"crossref","unstructured":"Deng, J., Dong, W., Socher, R., Li, L.J., Li, K., Fei-Fei, L.: Imagenet: a large-scale hierarchical image database. In: 2009 IEEE Conference on Computer Vision and Pattern Recognition, pp. 248\u2013255. IEEE (2009)","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"16_CR14","unstructured":"George, N.: All lending club loan data (2019). https:\/\/www.kaggle.com\/datasets\/wordsforthewise\/lending-club"},{"key":"16_CR15","unstructured":"Goodfellow, I.J., Shlens, J., Szegedy, C.: Explaining and harnessing adversarial examples. In: 3rd International Conference on Learning Representations (ICLR 2015). ICLR, San Diego, CA, United States (2015)"},{"key":"16_CR16","doi-asserted-by":"crossref","unstructured":"Graves, L., Nagisetty, V., Ganesh, V.: Amnesiac machine learning. In: Proceedings of AAAI Conference on Artificial Intelligence (AAAI 2021), pp. 11516\u201311524. AAAI Press, Virtual Event (2021)","DOI":"10.1609\/aaai.v35i13.17371"},{"key":"16_CR17","unstructured":"Guo, C., Goldstein, T., Hannun, A., Van Der\u00a0Maaten, L.: Certified data removal from machine learning models. In: Proceedings of 37th International Conference on Machine Learning (ICML 2020), vol.\u00a0119, pp. 3832\u20133842. International Machine Learning Society (IMLS), Virtual Event (2020)"},{"key":"16_CR18","unstructured":"Ji, F., et al.: Evaluating the effectiveness and robustness of visual similarity-based phishing detection models. arXiv preprint arXiv:2405.19598 (2024)"},{"issue":"1","key":"16_CR19","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1038\/s41467-019-13056-x","volume":"10","author":"D Kobak","year":"2019","unstructured":"Kobak, D., Berens, P.: The art of using t-SNE for single-cell transcriptomics. Nat. Commun. 10(1), 1\u201314 (2019)","journal-title":"Nat. Commun."},{"key":"16_CR20","unstructured":"Krizhevsky, A., Hinton, G., et\u00a0al.: Learning multiple layers of features from tiny images (2009)"},{"key":"16_CR21","unstructured":"Krizhevsky, A., Nair, V., Hinton, G.: The CIFAR-10 and CIFAR-100 dataset (2014). http:\/\/www.cs.toronto.edu\/kriz\/cifar.html"},{"issue":"11","key":"16_CR22","doi-asserted-by":"publisher","first-page":"2278","DOI":"10.1109\/5.726791","volume":"86","author":"Y LeCun","year":"1998","unstructured":"LeCun, Y., Bottou, L., Bengio, Y., Haffner, P.: Gradient-based learning applied to document recognition. Proc. IEEE 86(11), 2278\u20132324 (1998)","journal-title":"Proc. IEEE"},{"key":"16_CR23","doi-asserted-by":"crossref","unstructured":"Lin, W., et al.: Robustness verification of classification deep neural networks via linear programming. In: Proceedings of IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR 2019), Long Beach, CA, USA, pp. 11418\u201311427. Computer Vision Foundation\/IEEE (2019)","DOI":"10.1109\/CVPR.2019.01168"},{"key":"16_CR24","doi-asserted-by":"crossref","unstructured":"Ma, Z., Li, J., Bai, G.: Relu hull approximation. Proc. ACM Program. Lang. 8(POPL), 2260\u20132287 (2024)","DOI":"10.1145\/3632917"},{"key":"16_CR25","unstructured":"Madry, A., Makelov, A., Schmidt, L., Tsipras, D., Vladu, A.: Towards deep learning models resistant to adversarial attacks. In: 6th International Conference on Learning Representations (ICLR 2018). ICLR, Vancouver, Canada (2018)"},{"key":"16_CR26","doi-asserted-by":"crossref","unstructured":"Magdziarczyk, M.: Right to be forgotten in light of regulation (EU) 2016\/679 of the European parliament and of the council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing directive 95\/46\/EC. In: 6th International Multidisciplinary Scientific Conference on Social Sciences and Art SGEM 2019, pp. 177\u2013184. Curran Associates, Inc, Vienna, Austria (2019). https:\/\/gdpr-info.eu\/","DOI":"10.5593\/sgemsocial2019V\/1.1\/S02.022"},{"key":"16_CR27","doi-asserted-by":"crossref","unstructured":"Marchant, N.G., Rubinstein, B.I., Alfeld, S.: Hard to forget: poisoning attacks on certified machine unlearning. In: 36th AAAI Conference on Artificial Intelligence (AAAI 2022), pp. 7691\u20137700. Association for the Advancement of Artificial Intelligence, Virtual, Online (2022)","DOI":"10.1609\/aaai.v36i7.20736"},{"issue":"6","key":"16_CR28","doi-asserted-by":"publisher","first-page":"85","DOI":"10.1109\/MSP.2017.2739299","volume":"34","author":"MT McCann","year":"2017","unstructured":"McCann, M.T., Jin, K.H., Unser, M.: Convolutional neural networks for inverse problems in imaging: a review. IEEE Signal Process. Mag. 34(6), 85\u201395 (2017)","journal-title":"IEEE Signal Process. Mag."},{"key":"16_CR29","unstructured":"Nguyen, T.T., Huynh, T.T., Nguyen, P.L., Liew, A.W.C., Yin, H., Nguyen, Q.V.H.: A survey of machine unlearning. arXiv preprint arXiv:2209.02299abs\/2209.02299 (2022)"},{"key":"16_CR30","unstructured":"Nicolae, M.I., et al.: Adversarial robustness toolbox v1. 0.0. arXiv preprint arXiv:1807.01069 abs\/1807.01069 (2018)"},{"key":"16_CR31","first-page":"68","volume":"23","author":"SL Pardau","year":"2018","unstructured":"Pardau, S.L.: The California consumer privacy act: towards a European-style privacy regime in the united states. J. Tech. L. Pol\u2019y 23, 68 (2018)","journal-title":"J. Tech. L. Pol\u2019y"},{"key":"16_CR32","unstructured":"Phan, H., Thai, M.T., Hu, H., Jin, R., Sun, T., Dou, D.: Scalable differential privacy with certified robustness in adversarial learning. In: International Conference on Machine Learning (ICML 2020), pp. 7683\u20137694. International Machine Learning Society (IMLS), Virtual Event (2020)"},{"key":"16_CR33","doi-asserted-by":"crossref","unstructured":"Picot, M., Messina, F., Boudiaf, M., Labeau, F., Ayed, I.B., Piantanida, P.: Adversarial robustness via fisher-RAO regularization. IEEE Trans. Pattern Anal. Mach. Intell. (2022)","DOI":"10.1109\/TPAMI.2022.3174724"},{"issue":"3","key":"16_CR34","doi-asserted-by":"publisher","first-page":"346","DOI":"10.1016\/j.eng.2019.12.012","volume":"6","author":"K Ren","year":"2020","unstructured":"Ren, K., Zheng, T., Qin, Z., Liu, X.: Adversarial attacks and defenses in deep learning. Engineering 6(3), 346\u2013360 (2020)","journal-title":"Engineering"},{"issue":"1","key":"16_CR35","first-page":"1","volume":"11","author":"JG Richens","year":"2020","unstructured":"Richens, J.G., Lee, C.M., Johri, S.: Improving the accuracy of medical diagnosis with causal machine learning. Nat. Commun. 11(1), 1\u20139 (2020)","journal-title":"Nat. Commun."},{"key":"16_CR36","unstructured":"Rish, I.: An empirical study of the Na\u00efve Bayes classifier. In: IJCAI 2001 Workshop on Empirical Methods in Artificial Intelligence (IJCAI 2001), vol.\u00a03, pp. 41\u201346. International Joint Conference on Artificial Intelligence, Inc., Seattle (2001)"},{"key":"16_CR37","unstructured":"Salman, H., Yang, G., Zhang, H., Hsieh, C., Zhang, P.: A convex relaxation barrier to tight robustness verification of neural networks. In: Advances in Neural Information Processing Systems (NeurIPS 2019), Vancouver, BC, Canada, pp. 9832\u20139842. Curran Associates, Inc. (2019)"},{"key":"16_CR38","unstructured":"Sinha, A., Namkoong, H., Volpi, R., Duchi, J.: Certifying some distributional robustness with principled adversarial training. In: 6th International Conference on Learning Representations (ICLR 2018), Vancouver, Canada. ICLR (2018)"},{"key":"16_CR39","unstructured":"Szegedy, C., et al.: Intriguing properties of neural networks. In: 2rd International Conference on Learning Representations (ICLR 2014), Banff, Canada. ICLR (2014)"},{"key":"16_CR40","unstructured":"Weng, L., et al.: Towards fast computation of certified robustness for RELU networks. In: International Conference on Machine Learning (ICML 2018), Vienna, Austria, pp. 5276\u20135285. PMLR (2018)"},{"key":"16_CR41","unstructured":"Wu, Y.H., Yuan, C.H., Wu, S.H.: Adversarial robustness via runtime masking and cleansing. In: International Conference on Machine Learning (ICML 2020), pp. 10399\u201310409. International Machine Learning Society (IMLS), Virtual Event (2020)"},{"key":"16_CR42","doi-asserted-by":"crossref","unstructured":"Wu, Y., Zou, D., Yang, W., Li, X., Jin, H.: Homdroid: detecting android covert malware by social-network homophily analysis. In: Proceedings of 30th ACM SIGSOFT International Symposium on Software Testing and Analysis (ISSTA 2021), Virtual, Aarhus, Denmark, pp. 216\u2013229. ACM (2021)","DOI":"10.1145\/3460319.3464833"},{"key":"16_CR43","doi-asserted-by":"crossref","unstructured":"Xiao, G., Liu, J., Zheng, Z., Sui, Y.: Nondeterministic impact of CPU multithreading on training deep learning systems. In: 2021 IEEE 32nd International Symposium on Software Reliability Engineering (ISSRE 2021), Wuhan, China, pp. 557\u2013568. IEEE (2021)","DOI":"10.1109\/ISSRE52982.2021.00063"},{"key":"16_CR44","doi-asserted-by":"crossref","unstructured":"Yan, H., Li, X., Guo, Z., Li, H., Li, F., Lin, X.: ARCANE: an efficient architecture for exact machine unlearning. In: Proceedings of 31st International Joint Conference on Artificial Intelligence (IJCAI 2022), Vienna, Austria, pp. 4006\u20134013. ijcai.org (2022)","DOI":"10.24963\/ijcai.2022\/556"},{"key":"16_CR45","doi-asserted-by":"publisher","first-page":"6751","DOI":"10.1109\/TIFS.2024.3422799","volume":"19","author":"C Zhang","year":"2024","unstructured":"Zhang, C., Wang, W., Tian, Z., Yu, S.: Forgetting and remembering are both you need: balanced graph structure unlearning. IEEE Trans. Inf. Forensics Secur. 19, 6751\u20136763 (2024)","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"16_CR46","doi-asserted-by":"crossref","unstructured":"Zhang, G.: Eager to stop: efficient falsification of deep neural networks. In: International Conference on Formal Engineering Methods, pp. 267\u2013272. Springer (2023)","DOI":"10.1007\/978-981-99-7584-6_18"},{"issue":"6","key":"16_CR47","doi-asserted-by":"publisher","first-page":"13","DOI":"10.1109\/MIC.2023.3322283","volume":"27","author":"G Zhang","year":"2023","unstructured":"Zhang, G., et al.: A tale of two cities: data and configuration variances in robust deep learning. IEEE Internet Comput. 27(6), 13\u201320 (2023)","journal-title":"IEEE Internet Comput."},{"issue":"OOPSLA1","key":"16_CR48","doi-asserted-by":"publisher","first-page":"85","DOI":"10.1145\/3720417","volume":"9","author":"G Zhang","year":"2025","unstructured":"Zhang, G., Zhang, Z., Bandara, H.D., Chen, S., Zhao, J., Sui, Y.: Efficient incremental verification of neural networks guided by counterexample potentiality. Proc. ACM Program. Lang. 9(OOPSLA1), 85\u2013112 (2025)","journal-title":"Proc. ACM Program. Lang."},{"key":"16_CR49","unstructured":"Zhou, D., Wang, N., Han, B., Liu, T.: Modeling adversarial noise for adversarial training. In: International Conference on Machine Learning (ICML 2022), Baltimore, Maryland, USA, pp. 27353\u201327366. PMLR (2022)"},{"key":"16_CR50","doi-asserted-by":"publisher","DOI":"10.1007\/978-981-15-1967-3","volume-title":"Machine Learning","author":"ZH Zhou","year":"2021","unstructured":"Zhou, Z.H.: Machine Learning. Springer, London (2021)"}],"container-title":["Lecture Notes in Computer Science","Information Security and Privacy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-981-96-9101-2_16","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,3]],"date-time":"2026-04-03T14:55:28Z","timestamp":1775228128000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-981-96-9101-2_16"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"ISBN":["9789819691005","9789819691012"],"references-count":50,"URL":"https:\/\/doi.org\/10.1007\/978-981-96-9101-2_16","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025]]},"assertion":[{"value":"7 July 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ACISP","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Australasian Conference on Information Security and Privacy","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Wollongong, NSW","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Australia","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"14 July 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"16 July 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"30","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"acisp2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/uow-ic2.github.io\/acisp2025\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}