{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,25]],"date-time":"2026-06-25T04:49:12Z","timestamp":1782362952294,"version":"3.54.5"},"reference-count":77,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2021,11,24]],"date-time":"2021-11-24T00:00:00Z","timestamp":1637712000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2021,11,24]],"date-time":"2021-11-24T00:00:00Z","timestamp":1637712000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"funder":[{"DOI":"10.13039\/100014895","name":"Open Philanthropy Project","doi-asserted-by":"crossref","id":[{"id":"10.13039\/100014895","id-type":"DOI","asserted-by":"crossref"}]},{"name":"Facebook Fellowship Program"},{"DOI":"10.13039\/100005883","name":"Hertz Foundation","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100005883","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Mach Learn"],"published-print":{"date-parts":[[2022,1]]},"DOI":"10.1007\/s10994-021-06119-y","type":"journal-article","created":{"date-parts":[[2021,11,24]],"date-time":"2021-11-24T21:02:35Z","timestamp":1637787755000},"page":"1-47","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":90,"title":["Stronger data poisoning attacks break data sanitization defenses"],"prefix":"10.1007","volume":"111","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-4330-6969","authenticated-orcid":false,"given":"Pang Wei","family":"Koh","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jacob","family":"Steinhardt","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Percy","family":"Liang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2021,11,24]]},"reference":[{"key":"6119_CR1","unstructured":"Agarwal, N., Bullins, B., & Hazan, E. (2016). Second order stochastic optimization in linear time. arXiv:160203943"},{"key":"6119_CR2","unstructured":"Athalye, A., Carlini, N.&, Wagner, D. (2018). Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples. In International conference on machine learning (ICML)."},{"key":"6119_CR3","doi-asserted-by":"crossref","unstructured":"Awasthi, P., Balcan, M. F., & Long, P. M. (2014). The power of localization for efficiently learning linear separators with noise. In Symposium on theory of computing (STOC) (pp. 449\u2013458).","DOI":"10.1145\/2591796.2591839"},{"issue":"3","key":"6119_CR4","doi-asserted-by":"publisher","first-page":"783","DOI":"10.1007\/s00454-012-9439-z","volume":"48","author":"I B\u00e1r\u00e1ny","year":"2012","unstructured":"B\u00e1r\u00e1ny, I., & Karasev, R. (2012). Notes about the Carath\u00e9odory number. Discrete & Computational Geometry, 48(3), 783\u2013792.","journal-title":"Discrete & Computational Geometry"},{"key":"6119_CR5","doi-asserted-by":"crossref","unstructured":"Bard, J. F. (1999). Practical bilevel optimization: Algorithms and applications. Springer.","DOI":"10.1007\/978-1-4757-2836-1"},{"issue":"2","key":"6119_CR6","doi-asserted-by":"publisher","first-page":"371","DOI":"10.1007\/BF00941574","volume":"68","author":"JF Bard","year":"1991","unstructured":"Bard, J. F. (1991). Some properties of the bilevel programming problem. Journal of Optimization Theory and Applications, 68(2), 371\u2013378.","journal-title":"Journal of Optimization Theory and Applications"},{"issue":"2","key":"6119_CR7","doi-asserted-by":"publisher","first-page":"121","DOI":"10.1007\/s10994-010-5188-5","volume":"81","author":"M Barreno","year":"2010","unstructured":"Barreno, M., Nelson, B., Joseph, A. D., & Tygar, J. D. (2010). The security of machine learning. Machine Learning, 81(2), 121\u2013148.","journal-title":"Machine Learning"},{"key":"6119_CR8","doi-asserted-by":"crossref","unstructured":"Biggio, B., Didaci, L., Fumera, G., & Roli, F. (2013). Poisoning attacks to compromise face templates. In 2013 international conference on biometrics (ICB) (pp. 1\u20137)","DOI":"10.1109\/ICB.2013.6613006"},{"key":"6119_CR9","doi-asserted-by":"crossref","unstructured":"Biggio, B., Fumera, G., Roli, F., & Didaci, L. (2012a). Poisoning adaptive biometric systems. In Joint IAPR international workshops on statistical techniques in pattern recognition (SPR) and structural and syntactic pattern recognition (SSPR) (pp. 417\u2013425).","DOI":"10.1007\/978-3-642-34166-3_46"},{"key":"6119_CR10","unstructured":"Biggio, B., Nelson, B., & Laskov, P. (2012b). Poisoning attacks against support vector machines. In International conference on machine learning (ICML) (pp. 1467\u20131474)."},{"issue":"4","key":"6119_CR11","doi-asserted-by":"publisher","first-page":"984","DOI":"10.1109\/TKDE.2013.57","volume":"26","author":"B Biggio","year":"2014","unstructured":"Biggio, B., Fumera, G., & Roli, F. (2014). Security evaluation of pattern classifiers under attack. IEEE Transactions on Knowledge and Data Engineering, 26(4), 984\u2013996.","journal-title":"IEEE Transactions on Knowledge and Data Engineering"},{"key":"6119_CR12","first-page":"97","volume":"20","author":"B Biggio","year":"2011","unstructured":"Biggio, B., Nelson, B., & Laskov, P. (2011). Support vector machines under adversarial label noise. ACML, 20, 97\u2013112.","journal-title":"ACML"},{"key":"6119_CR13","doi-asserted-by":"crossref","unstructured":"Burkard, C., & Lagesse, B. (2017). Analysis of causative attacks against SVMs learning from data streams. In International workshop on security and privacy analytics.","DOI":"10.1145\/3041008.3041012"},{"key":"6119_CR14","unstructured":"Carlini, N., Mishra, P., Vaidya, T., Zhang, Y., Sherr, M., Shields, C., Wagner, D. & Zhou, W. (2016). Hidden voice commands. In: USENIX security."},{"key":"6119_CR15","doi-asserted-by":"crossref","unstructured":"Charikar, M., Steinhardt, J., & Valiant, G. (2017). Learning from untrusted data. In Symposium on theory of computing (STOC).","DOI":"10.1145\/3055399.3055491"},{"key":"6119_CR16","unstructured":"Chen, X., Liu, C., Li, B., Lu, K., & Song, D. (2017). Targeted backdoor attacks on deep learning systems using data poisoning. arXiv:171205526"},{"issue":"2","key":"6119_CR17","doi-asserted-by":"publisher","first-page":"201","DOI":"10.1023\/A:1013637720281","volume":"47","author":"K Crammer","year":"2002","unstructured":"Crammer, K., & Singer, Y. (2002). On the learnability and design of output codes for multiclass problems. Machine Learning, 47(2), 201\u2013233.","journal-title":"Machine Learning"},{"key":"6119_CR18","doi-asserted-by":"crossref","unstructured":"Cretu, G. F., Stavrou, A., Locasto, M. E., Stolfo, S. J., & Keromytis, A. D. (2008). Casting out demons: Sanitizing training data for anomaly sensors. In IEEE symposium on security and privacy (pp. 81\u201395).","DOI":"10.1109\/SP.2008.11"},{"key":"6119_CR19","unstructured":"Demontis, A., Melis, M., Pintor, M., Jagielski, M., Biggio, B., Oprea, A., Nita-Rotaru, C., & Roli, F. (2019). Why do adversarial attacks transfer? Explaining transferability of evasion and poisoning attacks. In 28th USENIX security symposium (USENIX security 19) (pp. 321\u2013338)."},{"key":"6119_CR20","doi-asserted-by":"crossref","unstructured":"Diakonikolas, I., Kamath, G., Kane, D., Li, J., Moitra, A., & Stewart, A. (2016). Robust estimators in high dimensions without the computational intractability. In Foundations of computer science (FOCS).","DOI":"10.1109\/FOCS.2016.85"},{"key":"6119_CR21","unstructured":"Diakonikolas, I., Kamath, G., Kane, D.M., Li, J., Steinhardt, J., & Stewart, A. (2018). Sever: A robust meta-algorithm for stochastic optimization. arXiv:180302815"},{"key":"6119_CR22","unstructured":"Diakonikolas, I., Kamath, G., Kane, D., Lim J., Moitra, A., & Stewart, A. (2017a). Being robust (in high dimensions) can be practical. arXiv."},{"key":"6119_CR23","doi-asserted-by":"crossref","unstructured":"Diakonikolas, I., Kane, D. M., & Stewart, A. (2017b). Learning geometric concepts with nasty noise. arXiv.","DOI":"10.1145\/3188745.3188754"},{"key":"6119_CR24","unstructured":"Duchi, J., Hazan, E., & Singer, Y. (2010). Adaptive subgradient methods for online learning and stochastic optimization. In Conference onlearning theory (COLT)."},{"issue":"2","key":"6119_CR25","doi-asserted-by":"publisher","first-page":"606","DOI":"10.1137\/070684914","volume":"39","author":"V Feldman","year":"2009","unstructured":"Feldman, V., Gopalan, P., Khot, S., & Ponnuswami, A. K. (2009). On agnostic learning of parities, monomials, and halfspaces. SIAM Journal on Computing, 39(2), 606\u2013645.","journal-title":"SIAM Journal on Computing"},{"issue":"6","key":"6119_CR26","doi-asserted-by":"publisher","first-page":"381","DOI":"10.1145\/358669.358692","volume":"24","author":"MA Fischler","year":"1981","unstructured":"Fischler, M. A., & Bolles, R. C. (1981). Random sample consensus: a paradigm for model fitting with applications to image analysis and automated cartography. Communications of the ACM, 24(6), 381\u2013395.","journal-title":"Communications of the ACM"},{"key":"6119_CR27","doi-asserted-by":"crossref","unstructured":"Frederickson, C., Moore, M., Dawson, G., & Polikar, R. (2018). Attack strength vs. detectability dilemma in adversarial machine learning. In 2018 international joint conference on neural networks (IJCNN) (pp. 1\u20138).","DOI":"10.1109\/IJCNN.2018.8489495"},{"key":"6119_CR28","doi-asserted-by":"crossref","unstructured":"Gardiner, J., & Nagaraja, S. (2016). On the security of machine learning in malware C&C detection: A survey. ACM Computing Surveys (CSUR),49(3)**","DOI":"10.1145\/3003816"},{"key":"6119_CR29","unstructured":"Goodfellow, I. J., Pouget-Abadie, J., Mirza, M., Xu, B., Warde-Farley, D., Ozair, S., Courville, A., & Bengio, Y. (2014). Generative adversarial nets. In Advances in neural information processing systems (NeurIPS)."},{"key":"6119_CR30","unstructured":"Goodfellow, I. J., Shlens, J., & Szegedy, C. (2015). Explaining and harnessing adversarial examples. In International conference on learning representations (ICLR)."},{"key":"6119_CR31","unstructured":"Gu, T., Dolan-Gavitt, B., Garg, S. (2017). Badnets: Identifying vulnerabilities in the machine learning model supply chain. arXiv:170806733"},{"issue":"2","key":"6119_CR32","doi-asserted-by":"publisher","first-page":"742","DOI":"10.1137\/070685798","volume":"39","author":"V Guruswami","year":"2009","unstructured":"Guruswami, V., & Raghavendra, P. (2009). Hardness of learning halfspaces with noise. SIAM Journal on Computing, 39(2), 742\u2013765.","journal-title":"SIAM Journal on Computing"},{"issue":"2","key":"6119_CR33","doi-asserted-by":"publisher","first-page":"85","DOI":"10.1023\/B:AIRE.0000045502.10941.a9","volume":"22","author":"V Hodge","year":"2004","unstructured":"Hodge, V., & Austin, J. (2004). A survey of outlier detection methodologies. Artificial Intelligence Review, 22(2), 85\u2013126.","journal-title":"Artificial Intelligence Review"},{"key":"6119_CR34","doi-asserted-by":"crossref","unstructured":"Jagielski, M., Oprea, A., Biggio, B., Liu, C., Nita-Rotaru, C., & Li, B. (2018). Manipulating machine learning: Poisoning attacks and countermeasures for regression learning. In 2018 IEEE symposium on security and privacy (SP) (pp. 19\u201335).","DOI":"10.1109\/SP.2018.00057"},{"issue":"4","key":"6119_CR35","doi-asserted-by":"publisher","first-page":"807","DOI":"10.1137\/0222052","volume":"22","author":"M Kearns","year":"1993","unstructured":"Kearns, M., & Li, M. (1993). Learning in the presence of malicious errors. SIAM Journal on Computing, 22(4), 807\u2013837.","journal-title":"SIAM Journal on Computing"},{"key":"6119_CR36","first-page":"2715","volume":"10","author":"AR Klivans","year":"2009","unstructured":"Klivans, A. R., Long, P. M., & Servedio, R. A. (2009). Learning halfspaces with malicious noise. Journal of Machine Learning Research (JMLR), 10, 2715\u20132740.","journal-title":"Journal of Machine Learning Research (JMLR)"},{"key":"6119_CR37","first-page":"3681","volume":"13","author":"M Kloft","year":"2012","unstructured":"Kloft, M., & Laskov, P. (2012). Security analysis of online centroid anomaly detection. Journal of Machine Learning Research (JMLR), 13, 3681\u20133724.","journal-title":"Journal of Machine Learning Research (JMLR)"},{"key":"6119_CR38","unstructured":"Koh, P. W., & Liang, P. (2017). Understanding black-box predictions via influence functions. In International conference on machine learning (ICML)."},{"key":"6119_CR39","unstructured":"Kurakin, A., Goodfellow, I., & Bengio, S. (2016). Adversarial examples in the physical world. arXiv."},{"key":"6119_CR40","doi-asserted-by":"crossref","unstructured":"Lai, K. A., Rao, A. B., & Vempala, S. (2016). Agnostic estimation of mean and covariance. In Foundations of computer science (FOCS).","DOI":"10.1109\/FOCS.2016.76"},{"issue":"11","key":"6119_CR41","doi-asserted-by":"publisher","first-page":"2278","DOI":"10.1109\/5.726791","volume":"86","author":"Y LeCun","year":"1998","unstructured":"LeCun, Y., Bottou, L., Bengio, Y., & Haffner, P. (1998). Gradient-based learning applied to document recognition. Proceedings of the IEEE, 86(11), 2278\u20132324.","journal-title":"Proceedings of the IEEE"},{"key":"6119_CR42","unstructured":"Li, J. (2018). Principled approaches to robust machine learning and beyond. Ph.D. thesis, Massachusetts Institute of Technology."},{"key":"6119_CR43","unstructured":"Li, B., Wang, Y., Singh, A., & Vorobeychik, Y. (2016). Data poisoning attacks on factorization-based collaborative filtering. In Advances in neural information processing systems (NeurIPS)."},{"key":"6119_CR44","doi-asserted-by":"crossref","unstructured":"Liu, C., Li, B., Vorobeychik, Y., & Oprea, A. (2017). Robust linear regression against training data poisoning. In Proceedings of the 10th ACM workshop on artificial intelligence and security (pp. 91\u2013102).","DOI":"10.1145\/3128572.3140447"},{"key":"6119_CR45","unstructured":"Maas, A. L., Daly, R. E., Pham, P. T., Huang, D., Ng, A. Y.,&Potts, C. (2011). Learning word vectors for sentiment analysis. In Association for computational linguistics (ACL)"},{"key":"6119_CR46","unstructured":"Madry, A., Makelov, A., Schmidt, L., Tsipras, D., & Vladu, A. (2017). Towards deep learning models resistant to adversarial attacks (published at ICLR 2018). arXiv."},{"key":"6119_CR47","unstructured":"Martens, J. (2010). Deep learning via hessian-free optimization. In International conference on machine learning (ICML) (pp. 735\u2013742)."},{"key":"6119_CR48","unstructured":"Mei, S., & Zhu, X. (2015a). The security of latent Dirichlet allocation. In Artificial intelligence and statistics (AISTATS)."},{"key":"6119_CR49","doi-asserted-by":"crossref","unstructured":"Mei, S., & Zhu, X. (2015b). Using machine teaching to identify optimal training-set attacks on machine learners. In Association for the advancement of artificial intelligence (AAAI).","DOI":"10.1609\/aaai.v29i1.9569"},{"key":"6119_CR50","first-page":"28","volume":"17","author":"V Metsis","year":"2006","unstructured":"Metsis, V., Androutsopoulos, I., & Paliouras, G. (2006). Spam filtering with naive Bayes\u2014Which naive Bayes? CEAS, 17, 28\u201369.","journal-title":"CEAS"},{"key":"6119_CR51","unstructured":"Mirrokni, V., Leme, R. P., Vladu, A., & Wai Wong, S.C. (2015). Tight bounds for approximate Carath\u00e9odory and beyond. arXiv:151208602."},{"key":"6119_CR52","doi-asserted-by":"crossref","unstructured":"Moosavi-Dezfooli, S. M., Fawzi, A., & Frossard, P. (2016). Deepfool: a simple and accurate method to fool deep neural networks. In Computer vision and pattern recognition (CVPR) (pp. 2574\u20132582).","DOI":"10.1109\/CVPR.2016.282"},{"key":"6119_CR53","doi-asserted-by":"crossref","unstructured":"Mu\u00f1oz-Gonz\u00e1lez, L., Biggio, B., Demontis, A., Paudice, A., Wongrassamee, V., Lupu, E. C., & Roli, F. (2017). Towards poisoning of deep learning algorithms with back-gradient optimization. In Proceedings of the 10th ACM workshop on artificial intelligence and security (pp. 27\u201338).","DOI":"10.1145\/3128572.3140451"},{"key":"6119_CR54","first-page":"1","volume":"8","author":"B Nelson","year":"2008","unstructured":"Nelson, B., Barreno, M., Chi, F. J., Joseph, A. D., Rubinstein, B. I., Saini, U., et al. (2008). Exploiting machine learning to subvert your spam filter. LEET, 8, 1\u20139.","journal-title":"LEET"},{"key":"6119_CR55","doi-asserted-by":"crossref","unstructured":"Newell, A., Potharaju, R., Xiang, L., & Nita-Rotaru, C. (2014). On the practicality of integrity attacks on document-level sentiment analysis. In Workshop on artificial intelligence and security (AISec) (pp. 83\u201393)","DOI":"10.1145\/2666652.2666661"},{"key":"6119_CR56","unstructured":"Papernot, N., & McDaniel, P. (2018). Deep k-nearest neighbors: Towards confident, interpretable and robust deep learning. arXiv:180304765"},{"key":"6119_CR57","unstructured":"Papernot, N., McDaniel, P., & Goodfellow, I. (2016a). Transferability in machine learning: from phenomena to black-box attacks using adversarial samples. arXiv."},{"key":"6119_CR58","doi-asserted-by":"crossref","unstructured":"Papernot, N., McDaniel, P., Goodfellow, I., Jha, S., Celik, B. Z., & Swami, A. (2017). Practical black-box attacks against machine learning. In Asia conference on computer and communications security (pp. 506\u2013519).","DOI":"10.1145\/3052973.3053009"},{"key":"6119_CR59","unstructured":"Papernot, N., McDaniel, P., Sinha, A., & Wellman, M. (2016b). Towards the science of security and privacy in machine learning. arXiv."},{"key":"6119_CR60","doi-asserted-by":"crossref","unstructured":"Papernot, N., McDaniel, P., Wu, X., Jha, S., & Swami, A. (2016c). as a defense to adversarial perturbations against deep neural networks. In IEEE symposium on security and privacy (pp. 582\u2013597).","DOI":"10.1109\/SP.2016.41"},{"key":"6119_CR61","unstructured":"Paudice, A., Mu\u00f1oz-Gonz\u00e1lez, L., Gyorgy, A., & Lupu, E. C. (2018). Detection of adversarial training examples in poisoning attacks through anomaly detection. arXiv:180203041"},{"issue":"1","key":"6119_CR62","doi-asserted-by":"publisher","first-page":"147","DOI":"10.1162\/neco.1994.6.1.147","volume":"6","author":"BA Pearlmutter","year":"1994","unstructured":"Pearlmutter, B. A. (1994). Fast exact multiplication by the Hessian. Neural Computation, 6(1), 147\u2013160.","journal-title":"Neural Computation"},{"key":"6119_CR63","unstructured":"Raghunathan, A., Steinhardt, J., & Liang, P. (2018). Certified defenses against adversarial examples. In International conference on learning representations (ICLR)."},{"key":"6119_CR64","unstructured":"Rubinstein, B., Nelson, B., Huang, L., Joseph, A. D., Lau, S. H., Rao, S., Taft, N., & Tygar, J. (2009). Certified defenses against adversarial examples. In International conference on learning representations (ICLR)."},{"key":"6119_CR65","unstructured":"Shafahi, A., Huang, W. R., Najibi, M., Suciu, O., Studer, C., Dumitras, T., & Goldstein, T. (2018). Poison Frogs! Targeted clean-label poisoning attacks on neural networks. arXiv:180400792"},{"key":"6119_CR66","unstructured":"Sinha, A., Namkoong, H., & Duchi, J. (2018). Certifiable distributional robustness with principled adversarial training. In International conference on learning representations (ICLR)."},{"key":"6119_CR67","unstructured":"Steinhardt, J. (2018). Robust learning: Information theory and algorithms. Ph.D. thesis, Stanford University."},{"key":"6119_CR68","unstructured":"Steinhardt, J., Charikar, M., & Valiant, G. (2018). Resilience: A criterion for learning in the presence of arbitrary outliers. In Innovations in theoretical computer science (ITCS)."},{"key":"6119_CR69","unstructured":"Steinhardt, J., Koh, P. W., & Liang, P. (2017). Certified defenses for data poisoning attacks. In Advances in neural information processing systems (NeurIPS)."},{"key":"6119_CR70","unstructured":"Suciu, O., M\u0103rginean, R., Kaya, Y., III, H. D., & Dumitra\u015f, T. (2018). When does machine learning fail? generalized transferability for evasion and poisoning attacks. arXiv:180306975"},{"key":"6119_CR71","unstructured":"Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I., & Fergus, R. (2014). Intriguing properties of neural networks. In International Conference on Learning Representations (ICLR)."},{"key":"6119_CR72","unstructured":"Tram\u00e8r, F., Kurakin, A., Papernot, N., Boneh, D., & McDaniel, P. (2017). Ensemble adversarial training: Attacks and defenses. arXiv:170507204"},{"issue":"3","key":"6119_CR73","first-page":"1","volume":"12","author":"Y Vorobeychik","year":"2018","unstructured":"Vorobeychik, Y., & Kantarcioglu, M. (2018). Adversarial machine learning. Machine Learning, 12(3), 1\u2013169.","journal-title":"Machine Learning"},{"key":"6119_CR74","unstructured":"Wong, E., & Kolter, J. Z. (2018). Provable defenses against adversarial examples via the convex outer adversarial polytope. In International conference on machine learning (ICML)."},{"key":"6119_CR75","unstructured":"Xiao, H., Xiao, H., & Eckert, C. (2012). Adversarial label flips attack on support vector machines. In European conference on artificial intelligence."},{"key":"6119_CR76","doi-asserted-by":"publisher","first-page":"53","DOI":"10.1016\/j.neucom.2014.08.081","volume":"160","author":"H Xiao","year":"2015","unstructured":"Xiao, H., Biggio, B., Nelson, B., Xiao, H., Eckert, C., & Roli, F. (2015). Support vector machines under adversarial label contamination. Neurocomputing, 160, 53\u201362.","journal-title":"Neurocomputing"},{"key":"6119_CR77","unstructured":"Yang, C., Wu, Q., Li, H., & Chen, Y. (2017). Generative poisoning attack method against neural networks. arXiv."}],"container-title":["Machine Learning"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10994-021-06119-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10994-021-06119-y\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10994-021-06119-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,11,24]],"date-time":"2022-11-24T16:30:37Z","timestamp":1669307437000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10994-021-06119-y"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,11,24]]},"references-count":77,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2022,1]]}},"alternative-id":["6119"],"URL":"https:\/\/doi.org\/10.1007\/s10994-021-06119-y","relation":{},"ISSN":["0885-6125","1573-0565"],"issn-type":[{"value":"0885-6125","type":"print"},{"value":"1573-0565","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,11,24]]},"assertion":[{"value":"24 March 2020","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"30 September 2021","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"27 October 2021","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"24 November 2021","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"This content has been made available to all.","name":"free","label":"Free to read"}]}}