{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,19]],"date-time":"2026-06-19T02:51:11Z","timestamp":1781837471188,"version":"3.54.5"},"reference-count":66,"publisher":"Springer Science and Business Media LLC","issue":"9","license":[{"start":{"date-parts":[[2022,8,2]],"date-time":"2022-08-02T00:00:00Z","timestamp":1659398400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2022,8,2]],"date-time":"2022-08-02T00:00:00Z","timestamp":1659398400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"name":"Ecocloud Research Center","award":["Postdoctoral Research Award"],"award-info":[{"award-number":["Postdoctoral Research Award"]}]},{"name":"EPFL Lausanne"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Mach Learn"],"published-print":{"date-parts":[[2022,9]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>This paper investigates the theory of robustness against adversarial attacks. We focus on randomized classifiers (i.e. classifiers that output random variables) and provide a thorough analysis of their behavior through the lens of statistical learning theory and information theory. To this aim, we introduce a new notion of robustness for randomized classifiers, enforcing local Lipschitzness using probability metrics. Equipped with this definition, we make two new contributions. The first one consists in devising a new upper bound on the adversarial generalization gap of randomized classifiers. More precisely, we devise bounds on the generalization gap and the adversarial gap i.e. the gap between the risk and the worst-case risk under attack) of randomized classifiers. The second contribution presents a yet simple but efficient noise injection method to design robust randomized classifiers. We show that our results are applicable to a wide range of machine learning models under mild hypotheses. We further corroborate our findings with experimental results using deep neural networks on standard image datasets, namely CIFAR-10 and CIFAR-100. On these tasks, we manage to design robust models that simultaneously achieve state-of-the-art accuracy (over 0.82 clean accuracy on CIFAR-10) and enjoy <jats:italic>guaranteed<\/jats:italic> robust accuracy bounds (0.45 against <jats:inline-formula><jats:alternatives><jats:tex-math>$$\\ell _{2}$$<\/jats:tex-math><mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                  <mml:msub>\n                    <mml:mi>\u2113<\/mml:mi>\n                    <mml:mn>2<\/mml:mn>\n                  <\/mml:msub>\n                <\/mml:math><\/jats:alternatives><\/jats:inline-formula> adversaries with magnitude 0.5 on CIFAR-10).<\/jats:p>","DOI":"10.1007\/s10994-022-06216-6","type":"journal-article","created":{"date-parts":[[2022,8,2]],"date-time":"2022-08-02T20:02:25Z","timestamp":1659470545000},"page":"3425-3457","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":5,"title":["On the robustness of randomized classifiers to adversarial examples"],"prefix":"10.1007","volume":"111","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-5372-8300","authenticated-orcid":false,"given":"Rafael","family":"Pinot","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Laurent","family":"Meunier","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Florian","family":"Yger","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"C\u00e9dric","family":"Gouy-Pailler","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yann","family":"Chevaleyre","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jamal","family":"Atif","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2022,8,2]]},"reference":[{"key":"6216_CR1","unstructured":"Athalye, A., Carlini, N., & Wagner, D. (2018). Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples. In J. Dy & A. Krause (Eds.), Proceedings of the 35th international conference on machine learning, proceedings of machine learning research (vol. 8, pp. 274\u2013283). Stockholm Sweden: Stockholmsm\u00e4ssan."},{"key":"6216_CR2","unstructured":"Awasthi, P., Frank, N., & Mohri, M. (2020). Adversarial learning guarantees for linear hypotheses and neural networks. In H.\u00a0D. III & A.\u00a0Singh (Eds.), Proceedings of the 37th international conference on machine learning, proceedings of machine learning research (vol. 119, pp. 431\u2013441). PMLR."},{"key":"6216_CR3","first-page":"463","volume":"3","author":"PL Bartlett","year":"2002","unstructured":"Bartlett, P. L., & Mendelson, S. (2002). Rademacher and Gaussian complexities: Risk bounds and structural results. Journal of Machine Learning Research, 3, 463\u2013482.","journal-title":"Journal of Machine Learning Research"},{"key":"6216_CR4","doi-asserted-by":"publisher","DOI":"10.1515\/9781400831050","volume-title":"Robust optimization","author":"A Ben-Tal","year":"2009","unstructured":"Ben-Tal, A., El Ghaoui, L., & Nemirovski, A. (2009). Robust optimization (Vol. 28). Princeton University Press."},{"key":"6216_CR5","doi-asserted-by":"crossref","unstructured":"Biggio, B., Corona, I., Maiorca, D., Nelson, B., \u0160rndi\u0107, N., Laskov, P., Giacinto, G., & Roli, F. (2013). Evasion attacks against machine learning at test time. In Joint European conference on machine learning and knowledge discovery in databases (pp. 387\u2013402). Springer.","DOI":"10.1007\/978-3-642-40994-3_25"},{"key":"6216_CR6","doi-asserted-by":"publisher","DOI":"10.1162\/99608f92.cfc5dd25","author":"Z Bu","year":"2020","unstructured":"Bu, Z., Dong, J., Long, Q., & Weijie, S. (2020). Deep learning with Gaussian differential privacy. Harvard Data Science Review. https:\/\/doi.org\/10.1162\/99608f92.cfc5dd25.","journal-title":"Harvard Data Science Review"},{"key":"6216_CR7","doi-asserted-by":"crossref","unstructured":"Carlini, N., & Wagner, D. (2017). Adversarial examples are not easily detected: Bypassing ten detection methods. In Proceedings of the 10th ACM workshop on artificial intelligence and security (pp. 3\u201314).","DOI":"10.1145\/3128572.3140444"},{"issue":"5","key":"6216_CR8","doi-asserted-by":"publisher","first-page":"1327","DOI":"10.1109\/TSP.2004.826176","volume":"52","author":"F Chapeau-Blondeau","year":"2004","unstructured":"Chapeau-Blondeau, F., & Rousseau, D. (2004). Noise-enhanced performance for an optimal Bayesian estimator. IEEE Transactions on Signal Processing, 52(5), 1327\u20131334. https:\/\/doi.org\/10.1109\/TSP.2004.826176.","journal-title":"IEEE Transactions on Signal Processing"},{"key":"6216_CR9","doi-asserted-by":"crossref","unstructured":"Chen, P. Y., Sharma, Y., Zhang, H., Yi, J., & Hsieh, C. J. (2018). Ead: Elastic-net attacks to deep neural networks via adversarial examples. In AAAI.","DOI":"10.1609\/aaai.v32i1.11302"},{"key":"6216_CR10","unstructured":"Cohen, J., Rosenfeld, E., & Kolter, Z. (2019). Certified adversarial robustness via randomized smoothing. In K.\u00a0Chaudhuri & R.\u00a0Salakhutdinov (Eds.), Proceedings of the 36th international conference on machine learning, proceedings of machine learning research (vol. 97, pp. 1310\u20131320). PMLR."},{"key":"6216_CR11","volume-title":"Elements of information theory","author":"TM Cover","year":"2012","unstructured":"Cover, T. M., & Thomas, J. A. (2012). Elements of information theory. Wiley."},{"key":"6216_CR12","unstructured":"Croce, F., & Hein, M. (2020). Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks. In Proceedings of the 37th international conference on machine learning, ICML 2020, 13\u201318 July 2020, virtual event, proceedings of machine learning research (vol. 119, pp. 2206\u20132216). PMLR."},{"key":"6216_CR13","doi-asserted-by":"crossref","unstructured":"Dalvi, N., Domingos, P., Sanghai, S., & Verma, D. (2004). Adversarial classification. In Proceedings of the tenth ACM SIGKDD international conference on Knowledge discovery and data mining (pp. 99\u2013108).","DOI":"10.1145\/1014052.1014066"},{"key":"6216_CR14","unstructured":"Dhillon, G. S., Azizzadenesheli, K., Lipton, Z. C., Bernstein, J., Kossaifi, J., Khanna, A., & Anandkumar, A. (2018). Stochastic activation pruning for robust adversarial defense. In 6th international conference on learning representations, ICLR 2018, Vancouver, BC, Canada, April 30\u2013May 3, 2018, conference track proceedings. OpenReview.net."},{"issue":"3","key":"6216_CR15","first-page":"419","volume":"70","author":"AL Gibbs","year":"2002","unstructured":"Gibbs, A. L., & Su, F. E. (2002). On choosing and bounding probability metrics. International Statistical Review\/Revue Internationale de Statistique, 70(3), 419\u2013435.","journal-title":"International Statistical Review\/Revue Internationale de Statistique"},{"issue":"11","key":"6216_CR16","doi-asserted-by":"publisher","first-page":"5377","DOI":"10.1109\/TIT.2010.2068710","volume":"56","author":"GL Gilardoni","year":"2010","unstructured":"Gilardoni, G. L. (2010). On Pinsker\u2019s and Vajda\u2019s type inequalities for Csisz\u00e1r\u2019s$$f$$-divergences. IEEE Transactions on Information Theory, 56(11), 5377\u20135386. https:\/\/doi.org\/10.1109\/TIT.2010.2068710.","journal-title":"IEEE Transactions on Information Theory"},{"key":"6216_CR17","doi-asserted-by":"crossref","unstructured":"Globerson, A., & Roweis, S. (2006). Nightmare at test time: Robust learning by feature deletion. In Proceedings of the 23rd international conference on Machine learning (pp. 353\u2013360).","DOI":"10.1145\/1143844.1143889"},{"key":"6216_CR18","unstructured":"Goodfellow, I. J., Shlens, J., & Szegedy, C. (2015). Explaining and harnessing adversarial examples. In Y.\u00a0Bengio & Y.\u00a0LeCun (Eds.), 3rd International conference on learning representations, ICLR 2015, San Diego, CA, USA, May 7\u20139, 2015, conference track proceedings."},{"issue":"5","key":"6216_CR19","doi-asserted-by":"publisher","first-page":"1093","DOI":"10.1162\/neco.1997.9.5.1093","volume":"9","author":"Y Grandvalet","year":"1997","unstructured":"Grandvalet, Y., Canu, S., & Boucheron, S. (1997). Noise injection: Theoretical prospects. Neural Computation, 9(5), 1093\u20131108.","journal-title":"Neural Computation"},{"key":"6216_CR20","unstructured":"He, W., Wei, J., Chen, X., Carlini, N. & Song, D. (2017). Adversarial example defense: Ensembles of weak defenses are not strong. In 11th USENIX Workshop on Offensive Technologies (WOOT 17)."},{"key":"6216_CR21","doi-asserted-by":"crossref","unstructured":"He, Z., Rakin, A. S., & Fan, D. (2019). Parametric noise injection: Trainable randomness to improve deep neural network robustness against adversarial attack. In Proceedings of the IEEE conference on computer vision and pattern recognition (pp. 588\u2013597).","DOI":"10.1109\/CVPR.2019.00068"},{"key":"6216_CR22","unstructured":"Hu, S., Yu, T., Guo, C., Chao, W. L. & Weinberger, K. Q. (2019). A new defense against adversarial images: Turning a weakness into a strength. In Advances in neural information processing systems (pp. 1635\u20131646)."},{"key":"6216_CR23","unstructured":"Jetley, S., Lord, N. A., & Torr, P. H. (2018). With friends like these, who needs adversaries? In Proceedings of the 32nd international conference on neural information processing systems, NIPS\u201918, Red Hook, NY, USA (pp. 10772\u201310782). Curran Associates Inc."},{"issue":"4","key":"6216_CR24","doi-asserted-by":"publisher","first-page":"807","DOI":"10.1137\/0222052","volume":"22","author":"M Kearns","year":"1993","unstructured":"Kearns, M., & Li, M. (1993). Learning in the presence of malicious errors. SIAM Journal on Computing, 22(4), 807\u2013837.","journal-title":"SIAM Journal on Computing"},{"issue":"2\u20133","key":"6216_CR25","first-page":"115","volume":"17","author":"MJ Kearns","year":"1994","unstructured":"Kearns, M. J., Schapire, R. E., & Sellie, L. M. (1994). Toward efficient agnostic learning. Machine Learning, 17(2\u20133), 115\u2013141.","journal-title":"Machine Learning"},{"key":"6216_CR26","unstructured":"Khim, J., & Loh, P. L. (2018). Adversarial risk bounds for binary classification via function transformation. arXiv preprint arXiv:1810.09519 ."},{"key":"6216_CR27","unstructured":"Krizhevsky, A., & Hinton, G. (2009). Learning multiple layers of features from tiny images. Citeseer: Technical report."},{"key":"6216_CR28","doi-asserted-by":"crossref","unstructured":"Langlois, A., Stehl\u00e9, D., & Steinfeld, R. (2014). Gghlite: More efficient multilinear maps from ideal lattices. In Annual international conference on the theory and applications of cryptographic techniques (pp. 239\u2013256). Springer.","DOI":"10.1007\/978-3-642-55220-5_14"},{"key":"6216_CR29","doi-asserted-by":"crossref","unstructured":"Lecuyer, M., Atlidakis, V., Geambasu, R., Hsu, D., & Jana, S. (2019). Certified robustness to adversarial examples with differential privacy. In 2019 IEEE symposium on security and privacy (SP) (pp. 656\u2013672). IEEE.","DOI":"10.1109\/SP.2019.00044"},{"key":"6216_CR30","unstructured":"Li, B., Chen, C., Wang, W., & Carin, L. (2019). Certified adversarial robustness with additive noise. In Advances in neural information processing systems (pp. 9464\u20139474)."},{"key":"6216_CR31","doi-asserted-by":"crossref","unstructured":"Liu, X., Cheng, M., Zhang, H., & Hsieh, C. J. (2018). Towards robust neural networks via random self-ensemble. In European conference on computer vision (pp. 381\u2013397). Springer.","DOI":"10.1007\/978-3-030-01234-2_23"},{"key":"6216_CR32","doi-asserted-by":"crossref","unstructured":"Lowd, D., & Meek, C. (2005). Adversarial learning. In Proceedings of the eleventh ACM SIGKDD international conference on Knowledge discovery in data mining (pp. 641\u2013647).","DOI":"10.1145\/1081870.1081950"},{"key":"6216_CR33","unstructured":"Madry, A., Makelov, A., Schmidt, L., Tsipras, D., & Vladu, A. (2018). Towards deep learning models resistant to adversarial attacks. In 6th International conference on learning representations, ICLR 2018, Vancouver, BC, Canada, April 30\u2013May 3, 2018, conference track proceedings. OpenReview.net."},{"key":"6216_CR34","unstructured":"Metzen, J. H., Genewein, T., Fischer, V. & Bischoff, B. (2017). On detecting adversarial perturbations. In 5th International conference on learning representations, ICLR 2017, Toulon, France, April 24\u201326, 2017, conference track proceedings. OpenReview.net."},{"issue":"11","key":"6216_CR35","doi-asserted-by":"publisher","first-page":"2152","DOI":"10.1109\/5.726785","volume":"86","author":"S Mitaim","year":"1998","unstructured":"Mitaim, S., & Kosko, B. (1998). Adaptive stochastic resonance. Proceedings of the IEEE, 86(11), 2152\u20132183.","journal-title":"Proceedings of the IEEE"},{"key":"6216_CR36","unstructured":"Mohri, M., Rostamizadeh, A., & Talwalkar, A. (2018). Foundations of machine learning."},{"key":"6216_CR37","doi-asserted-by":"crossref","unstructured":"Papernot, N., McDaniel, P., Wu, X., Jha, S., & Swami, A. (2016). Distillation as a defense to adversarial perturbations against deep neural networks. In 2016 IEEE symposium on security and privacy (SP) (pp. 582\u2013597). IEEE.","DOI":"10.1109\/SP.2016.41"},{"key":"6216_CR38","unstructured":"Perez, L., & Wang, J. (2017). The effectiveness of data augmentation in image classification using deep learning. arXiv preprint arXiv:1712.04621."},{"key":"6216_CR39","first-page":"18420","volume-title":"Advances in neural information processing systems","author":"H Petzka","year":"2021","unstructured":"Petzka, H., Kamp, M., Adilova, L., Sminchisescu, C., & Boley, M. (2021). Relative flatness and generalization. In M. Ranzato, A. Beygelzimer, Y. Dauphin, P. Liang, & J. W. Vaughan (Eds.), Advances in neural information processing systems (Vol. 34, pp. 18420\u201318432). Curran Associates Inc."},{"key":"6216_CR40","doi-asserted-by":"crossref","unstructured":"Peyr\u00e9, G., & Cuturi, M. (2019). Computational optimal transport: With applications to data science. Foundations and Trends\u00ae in Machine Learning\u00a011(5-6): 355\u2013607.","DOI":"10.1561\/2200000073"},{"key":"6216_CR41","unstructured":"Pinot, R., Meunier, L., Araujo, A., Kashima, H., Yger, F., Gouy-Pailler, C., & Atif, J. (2019). Theoretical evidence for adversarial robustness through randomization. In Advances in neural information processing systems (pp. 11838\u201311848)."},{"key":"6216_CR42","unstructured":"R\u00e9nyi, A. (1961). On measures of entropy and information. Hungarian Academy of Sciences Budapest Hungary: Technical report."},{"key":"6216_CR43","volume-title":"The Bayesian choice: From decision-theoretic foundations to computational implementation","author":"C Robert","year":"2007","unstructured":"Robert, C. (2007). The Bayesian choice: From decision-theoretic foundations to computational implementation. Springer."},{"key":"6216_CR44","unstructured":"Salman, H., Li, J., Razenshteyn, I., Zhang, P., Zhang, H., Bubeck, S., & Yang, G. (2019). Provably robust deep learning via adversarially trained smoothed classifiers. In Advances in neural information processing systems (pp. 11289\u201311300)."},{"key":"6216_CR45","unstructured":"Schmidt, L., Santurkar, S., Tsipras, D., Talwar, K., & Madry, A. (2018). Adversarially robust generalization requires more data. In Advances in neural information processing systems (pp. 5014\u20135026)."},{"key":"6216_CR46","doi-asserted-by":"publisher","DOI":"10.1017\/CBO9781107298019","volume-title":"Understanding machine learning: From theory to algorithms","author":"S Shalev-Shwartz","year":"2014","unstructured":"Shalev-Shwartz, S., & Ben-David, S. (2014). Understanding machine learning: From theory to algorithms. Cambridge University Press."},{"key":"6216_CR47","doi-asserted-by":"crossref","unstructured":"Sharif, M., Bhagavatula, S., Bauer, L., & Reiter, M. K. (2016). Accessorize to a crime: Real and stealthy attacks on state-of-the-art face recognition. In Proceedings of the 2016 ACM SIGSAC conference on computer and communications security (pp. 1528\u20131540).","DOI":"10.1145\/2976749.2978392"},{"key":"6216_CR48","unstructured":"Simon-Gabriel, C. J., Ollivier, Y., Bottou, L., Sch\u00f6lkopf, B., & Lopez-Paz, D. (2019). First-order adversarial vulnerability of neural networks and input dimension. In International conference on machine learning (pp. 5809\u20135817)."},{"key":"6216_CR49","unstructured":"Sitawarin, C., Bhagoji, A. N., Mosenia, A., Chiang, M., & Mittal, P. (2018). Darts: Deceiving autonomous cars with toxic signs. arXiv preprint arXiv:1802.06430."},{"key":"6216_CR50","doi-asserted-by":"crossref","unstructured":"Su, D., Zhang, H., Chen, H., Yi, J., Chen, P. Y., & Gao, Y. (2018). Is robustness the cost of accuracy?\u2014A comprehensive study on the robustness of 18 deep image classification models. In Proceedings of the European conference on computer vision (ECCV) (pp. 631\u2013648).","DOI":"10.1007\/978-3-030-01258-8_39"},{"key":"6216_CR51","unstructured":"Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I. J., & Fergus, R. (2014). Intriguing properties of neural networks. In Y.\u00a0Bengio & Y.\u00a0LeCun (Eds.), 2nd international conference on learning representations, ICLR 2014, Banff, AB, Canada, April 14\u201316, 2014, conference track proceedings."},{"key":"6216_CR52","first-page":"1633","volume-title":"Advances in neural information processing systems","author":"F Tramer","year":"2020","unstructured":"Tramer, F., Carlini, N., Brendel, W., & Madry, A. (2020). On adaptive attacks to adversarial example defenses. In H. Larochelle, M. Ranzato, R. Hadsell, M. F. Balcan, & H. Lin (Eds.), Advances in neural information processing systems (Vol. 33, pp. 1633\u20131645). Curran Associates Inc."},{"key":"6216_CR53","unstructured":"Tsipras, D., Santurkar, S., Engstrom, L., Turner, A., & Madry, A. (2019). Robustness may be at odds with accuracy. In 7th International conference on learning representations, ICLR 2019, New Orleans, LA, USA, May 6\u20139, 2019. OpenReview.net."},{"issue":"6","key":"6216_CR54","doi-asserted-by":"publisher","first-page":"771","DOI":"10.1109\/TIT.1970.1054557","volume":"16","author":"I Vajda","year":"1970","unstructured":"Vajda, I. (1970). Note on discrimination information and variation. IEEE Transactions on Information Theory, 16(6), 771\u2013773.","journal-title":"IEEE Transactions on Information Theory"},{"key":"6216_CR55","volume-title":"Asymptotic statistics","author":"AW Van der Vaart","year":"2000","unstructured":"Van der Vaart, A. W. (2000). Asymptotic statistics (Vol. 3). Cambridge University Press."},{"issue":"7","key":"6216_CR56","doi-asserted-by":"publisher","first-page":"3797","DOI":"10.1109\/TIT.2014.2320500","volume":"60","author":"T van Erven","year":"2014","unstructured":"van Erven, T., & Harremos, P. (2014). R\u00e9nyi divergence and Kullback\u2013Leibler divergence. IEEE Transactions on Information Theory, 60(7), 3797\u20133820.","journal-title":"IEEE Transactions on Information Theory"},{"key":"6216_CR57","first-page":"8646","volume-title":"Advances in neural information processing systems 32","author":"G Verma","year":"2019","unstructured":"Verma, G., & Swami, A. (2019). Error correcting output codes improve probability estimation and adversarial robustness of deep neural networks. In H. Wallach, H. Larochelle, A. Beygelzimer, F. d\u2019Alch\u00e9-Buc, E. Fox, & R. Garnett (Eds.), Advances in neural information processing systems 32 (pp. 8646\u20138656). Curran Associates Inc."},{"key":"6216_CR58","doi-asserted-by":"crossref","unstructured":"Villani, C. (2003). Topics in optimal transportation. Number\u00a058. American Mathematical Soc.","DOI":"10.1090\/gsm\/058"},{"key":"6216_CR59","unstructured":"Xie, C., Wang, J., Zhang, Z., Ren, Z., & Yuille, A. L. (2018). Mitigating adversarial effects through randomization. In 6th International conference on learning representations, ICLR 2018, Vancouver, BC, Canada, April 30\u2013May 3, 2018, conference track proceedings. OpenReview.net."},{"issue":"3","key":"6216_CR60","doi-asserted-by":"publisher","first-page":"391","DOI":"10.1007\/s10994-011-5268-1","volume":"86","author":"H Xu","year":"2012","unstructured":"Xu, H., & Mannor, S. (2012). Robustness and generalization. Machine Learning, 86(3), 391\u2013423.","journal-title":"Machine Learning"},{"key":"6216_CR61","unstructured":"Yang, G., Duan, T., Hu, E., Salman, H., Razenshteyn, I., & Li, J. (2020). Randomized smoothing of all shapes and sizes."},{"key":"6216_CR62","unstructured":"Yao, D., Xi, Z., Tianyi, Z., Chen, C., Guannan, L., & Miryung, K. (2020). An analysis of adversarial attacks and defenses on autonomous driving models. In 18th Annual IEEE international conference on pervasive computing and communications. IEEE."},{"key":"6216_CR63","unstructured":"Yin, D., Kannan, R., & Bartlett, P. (2019). Rademacher complexity for adversarially robust generalization. In International conference on machine learning (pp. 7085\u20137094)."},{"key":"6216_CR64","doi-asserted-by":"crossref","unstructured":"Zagoruyko, S., & Komodakis, N. (2016). Wide residual networks. In Proceedings of the British machine vision conference (BMVC) (pp. 87.1\u201387.12). BMVA Press.","DOI":"10.5244\/C.30.87"},{"key":"6216_CR65","unstructured":"Zhang, H., Yu, Y., Jiao, J., Xing, E. P., Ghaoui, L. E., & Jordan, M. I. (2019). Theoretically principled trade-off between robustness and accuracy. In K.\u00a0Chaudhuri & R.\u00a0Salakhutdinov (Eds.), Proceedings of the 36th international conference on machine learning, ICML 2019, 9\u201315 June 2019, Long Beach, California, USA, proceedings of machine learning research (vol. 97, pp. 7472\u20137482). PMLR."},{"issue":"1","key":"6216_CR66","doi-asserted-by":"publisher","first-page":"108","DOI":"10.1109\/78.738244","volume":"47","author":"S Zozor","year":"1999","unstructured":"Zozor, S., & Amblard, P. O. (1999). Stochastic resonance in discrete time nonlinear AR(1) models. IEEE Transactions on Signal Processing, 47(1), 108\u2013122.","journal-title":"IEEE Transactions on Signal Processing"}],"container-title":["Machine Learning"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10994-022-06216-6.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10994-022-06216-6\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10994-022-06216-6.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,9,15]],"date-time":"2022-09-15T23:12:53Z","timestamp":1663283573000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10994-022-06216-6"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,8,2]]},"references-count":66,"journal-issue":{"issue":"9","published-print":{"date-parts":[[2022,9]]}},"alternative-id":["6216"],"URL":"https:\/\/doi.org\/10.1007\/s10994-022-06216-6","relation":{},"ISSN":["0885-6125","1573-0565"],"issn-type":[{"value":"0885-6125","type":"print"},{"value":"1573-0565","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,8,2]]},"assertion":[{"value":"26 October 2021","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"9 June 2022","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"13 June 2022","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"2 August 2022","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors have no relevant financial or non-financial interests to disclose, no conflicts of interest to declare that are relevant to the content of this article.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}},{"value":"All authors certify that they have no affiliations with or involvement in any organization or entity with any financial interest or non-financial interest in the subject matter or materials discussed in this manuscript nor financial or proprietary interests in any material discussed in this article. The authors approve the ethical standards of the publisher.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethics approval"}},{"value":"All authors are aware of the submission of this manuscript and agree to its publication.","order":4,"name":"Ethics","group":{"name":"EthicsHeading","label":"Consent to participate and publication"}}]}}