{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,2,21]],"date-time":"2025-02-21T07:31:41Z","timestamp":1740123101223,"version":"3.37.3"},"reference-count":67,"publisher":"Springer Science and Business Media LLC","issue":"8","license":[{"start":{"date-parts":[[2023,6,20]],"date-time":"2023-06-20T00:00:00Z","timestamp":1687219200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2023,6,20]],"date-time":"2023-06-20T00:00:00Z","timestamp":1687219200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Mach Learn"],"published-print":{"date-parts":[[2023,8]]},"DOI":"10.1007\/s10994-023-06348-3","type":"journal-article","created":{"date-parts":[[2023,6,20]],"date-time":"2023-06-20T21:01:21Z","timestamp":1687294881000},"page":"3003-3031","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Lagrangian objective function leads to improved unforeseen attack generalization"],"prefix":"10.1007","volume":"112","author":[{"given":"Mohammad","family":"Azizmalayeri","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6589-850X","authenticated-orcid":false,"given":"Mohammad Hossein","family":"Rohban","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2023,6,20]]},"reference":[{"issue":"August","key":"6348_CR2","doi-asserted-by":"publisher","first-page":"14410","DOI":"10.1109\/ACCESS.2018.2807385","volume":"6","author":"N Akhtar","year":"2018","unstructured":"Akhtar, N., & Mian, A. (2018). Threat of adversarial attacks on deep learning in computer vision: A survey. IEEE Access 6(August), 14410\u201314430. https:\/\/doi.org\/10.1109\/ACCESS.2018.2807385.","journal-title":"IEEE Access"},{"key":"6348_CR3","doi-asserted-by":"publisher","unstructured":"Allen-Zhu, Z., &  Li, Y. (2022). Feature purification: How adversarial training performs robust deep learning. In IEEE 62nd annual symposium on foundations of computer science, FOCS. https:\/\/doi.org\/10.1109\/FOCS52979.2021.00098.","DOI":"10.1109\/FOCS52979.2021.00098"},{"key":"6348_CR4","unstructured":"Andriushchenko, M., & Flammarion, N. (2020). Understanding and improving fast adversarial training. In Advances in neural information processing systems, NeurIPS. https:\/\/proceedings.neurips.cc\/paper\/2020\/file\/b8ce47761ed7b3b6f48b583350b7f9e4-Paper.pdf."},{"key":"6348_CR5","unstructured":"Athalye, A., Carlini, N., & Wagner, D.A. (2018). Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples. In Proceedings of the 35th international conference on machine learning, ICML. http:\/\/proceedings.mlr.press\/v80\/athalye18a.html."},{"key":"6348_CR6","unstructured":"Athalye, A., Engstrom, L., Ilyas, A., & Kwok, K. (2018). Synthesizing robust adversarial examples. In Proceedings of the 35th international conference on machine learning, ICML. http:\/\/proceedings.mlr.press\/v80\/athalye18b.html."},{"key":"6348_CR7","doi-asserted-by":"publisher","unstructured":"Bai, T., Luo, J., Zhao, J., Wen, B., & Wang, Q. (2021). Recent advances in adversarial training for adversarial robustness. In Proceedings of the 30th international joint conference on artificial intelligence, IJCAI. https:\/\/doi.org\/10.24963\/ijcai.2021\/591. https:\/\/doi.org\/10.24963\/ijcai.2021\/591.","DOI":"10.24963\/ijcai.2021\/591"},{"key":"6348_CR8","unstructured":"Balaji, Y., Goldstein, T., & Hoffman, J. (2019). Instance adaptive adversarial training: Improved accuracy tradeoffs in neural nets. CoRR arXiv:1910.08051."},{"key":"6348_CR1","unstructured":"Cohen, J.M., Rosenfeld, E., & Kolter, J.Z. (2019). Certified adversarial robustness via randomized smoothing. In Proceedings of the 36th international conference on machine learning, ICML. http:\/\/proceedings.mlr.press\/v97\/cohen19c.html."},{"key":"6348_CR9","doi-asserted-by":"publisher","unstructured":"Carlini, N., & Wagner, D. (2016). Towards evaluating the robustness of neural networks. In IEEE symposium on security and privacy, SP. https:\/\/doi.org\/10.1109\/SP.2017.49.","DOI":"10.1109\/SP.2017.49"},{"key":"6348_CR10","doi-asserted-by":"publisher","unstructured":"Chen, T., Liu, S., Chang, S., Cheng, Y., Amini, L., & Wang, Z. (2020). Adversarial robustness: From self-supervised pre-training to fine-tuning. In Proceedings of the IEEE computer society conference on computer vision and pattern recognition, CVPR. https:\/\/doi.org\/10.1109\/CVPR42600.2020.00078.","DOI":"10.1109\/CVPR42600.2020.00078"},{"key":"6348_CR11","doi-asserted-by":"crossref","unstructured":"Croce, F., & Hein, M. (2019). Sparse and imperceivable adversarial attacks. In Proceedings of the IEEE international conference on computer vision, ICCV. http:\/\/arxiv.org\/abs\/1909.05040.","DOI":"10.1109\/ICCV.2019.00482"},{"key":"6348_CR12","unstructured":"Croce, F., & Hein, M. (2020). Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks. In Proceedings of the 37th international conference on machine learning, ICML. http:\/\/proceedings.mlr.press\/v119\/croce20b.html"},{"key":"6348_CR13","unstructured":"Ding, G.W., Lui, K.Y.C., Jin, X., Wang, L., & Huang, R. (2019). On the sensitivity of adversarial robustness to input data distributions. In 7th international conference on learning representations, ICLR. https:\/\/openreview.net\/forum?id=S1xNEhR9KX."},{"key":"6348_CR14","unstructured":"Ding, G.W., Sharma, Y., Lui, K.Y.C., & Huang, R. (2020). Mma training: Direct input space margin maximization through adversarial training. In 8th international conference on learning representations, ICLR. https:\/\/openreview.net\/forum?id=HkeryxBtPB."},{"key":"6348_CR15","doi-asserted-by":"publisher","unstructured":"Dong, Y., Liao, F., Pang, T., Su, H., Zhu, J., Hu, X., & Li, J. (2017). Boosting Adversarial Attacks with Momentum. In Proceedings of the IEEE computer society conference on computer vision and pattern recognition, CVPR. https:\/\/doi.org\/10.1109\/CVPR.2018.00957.","DOI":"10.1109\/CVPR.2018.00957"},{"key":"6348_CR16","unstructured":"Goodfellow, I.J., Shlens, J., & Szegedy, C. (2015). Explaining and harnessing adversarial examples. In 3rd international conference on learning representations, ICLR. arXiv:abs\/1412.6572."},{"key":"6348_CR17","unstructured":"Gulrajani, I., & Lopez-Paz, D. (2021). In search of lost domain generalization. In 9th international conference on learning representations, ICLR. https:\/\/openreview.net\/forum?id=lQdXeXDoWtI."},{"key":"6348_CR18","doi-asserted-by":"crossref","unstructured":"Hendrycks, D., Zou, A., Mazeika, M., Tang, L., Li, B., Song, D., & Steinhardt, J. (2022). PixMix: Dreamlike pictures comprehensively improve safety measures. In Proceedings of the IEEE computer society conference on computer vision and pattern recognition, CVPR. https:\/\/doi.org\/10.1109\/CVPR52688.2022.01628.","DOI":"10.1109\/CVPR52688.2022.01628"},{"key":"6348_CR19","unstructured":"Ilyas, A., Santurkar, S., Tsipras, D., Engstrom, L., Tran, B., & Madry, A. (2019). Adversarial examples are not bugs, they are features. In Advances in neural information processing systems, NeurIPS. https:\/\/proceedings.neurips.cc\/paper\/2019\/file\/e2c420d928d4bf8ce0ff2ec19b371514-Paper.pdf."},{"key":"6348_CR20","unstructured":"Javanmard, A., Soltanolkotabi, M., & Hassani, H. (2020). Precise tradeoffs in adversarial training for linear regression. In Conference on learning theory, COLT. http:\/\/proceedings.mlr.press\/v125\/javanmard20a.html."},{"key":"6348_CR21","unstructured":"Kang, D., Sun, Y., Hendrycks, D., Brown, T., & Steinhardt, J. (2019). Testing robustness against unforeseen adversaries. CoRR arXiv:abs\/1908.08016."},{"key":"6348_CR22","unstructured":"Kettunen, M., H\u00e4rk\u00f6nen, E., & Lehtinen, J. (2019). E-LPIPS: Robust perceptual image similarity via random transformation ensembles. CoRR arXiv:abs\/1906.03973."},{"key":"6348_CR23","unstructured":"Kim, M., Tack, J., & Hwang, S.J. (2020). Adversarial self-supervised contrastive learning. In Advances in neural information processing systems, NeurIPS. https:\/\/proceedings.neurips.cc\/paper\/2020\/file\/1f1baa5b8edac74eb4eaa329f14a0361-Paper.pdf."},{"key":"6348_CR24","unstructured":"Kireev, K., Andriushchenko, M., & Flammarion, N. (2021). On the effectiveness of adversarial training against common corruptions. arXiv:2103.02325."},{"key":"6348_CR25","unstructured":"Krizhevsky, A., & Hinton, G. (2009). Learning multiple layers of features from tiny images. Technical report."},{"key":"6348_CR26","unstructured":"Kurakin, A., Goodfellow, I.J., & Bengio, S. (2017). Adversarial examples in the physical world. In 5th international conference on learning representations workshop, ICLR. https:\/\/openreview.net\/forum?id=HJGU3Rodl."},{"key":"6348_CR27","unstructured":"Laidlaw, C., & Feizi, S. (2019). Functional adversarial attacks. In Advances in neural information processing systems, NeurIPS."},{"key":"6348_CR28","unstructured":"Laidlaw, C., Singla, S., & Feizi, S. (2021). Perceptual adversarial robustness: Defense against unseen threat models. In 9th international conference on learning representations, ICLR. https:\/\/openreview.net\/forum?id=dFwBosAcJkN."},{"key":"6348_CR29","unstructured":"Lehman, C. (2019). Learning to Segment CIFAR10. https:\/\/charlielehman.github.io\/post\/weak-segmentation-cifar10\/."},{"issue":"2","key":"6348_CR30","doi-asserted-by":"publisher","first-page":"751","DOI":"10.1145\/3173162.3173191","volume":"53","author":"SC Lin","year":"2018","unstructured":"Lin, S. C., Zhang, Y.,  Hsu, C. H., Skach, M.,  Haque,  M. E.,  Tang, L., & Mars, J.  (2018). The architectural implications of autonomous driving: Constraints and acceleration. ACM SIGPLAN Notices 53(2), 751\u2013766. https:\/\/doi.org\/10.1145\/3173162.3173191.","journal-title":"ACM SIGPLAN Notices"},{"key":"6348_CR31","unstructured":"Madry, A., Makelov, A., Schmidt, L., Tsipras, D., & Vladu, A. (2018). Towards deep learning models resistant to adversarial attacks. In 6th international conference on learning representations, ICLR. https:\/\/openreview.net\/forum?id=rJzIBfZAb."},{"key":"6348_CR32","unstructured":"Maini, P., Wong, E., & Zico Kolter, J. (2020). Adversarial robustness against the union of multiple perturbation models. In Proceedings of the 37th international conference on machine learning, ICML. http:\/\/proceedings.mlr.press\/v119\/maini20a.html."},{"issue":"2","key":"6348_CR33","doi-asserted-by":"publisher","first-page":"583","DOI":"10.1111\/1468-0262.00296","volume":"70","author":"P Milgrom","year":"2002","unstructured":"Milgrom, P. & Segal, I.  (2002). Envelope theorems for arbitrary choice sets. Econometrica 70(2), 583\u2013601.","journal-title":"Econometrica"},{"key":"6348_CR34","doi-asserted-by":"publisher","unstructured":"Modas, A., Moosavi-Dezfooli, S.-M., & Frossard, P. (2019). Sparsefool: A few pixels make a big difference. In Proceedings of the IEEE computer society conference on computer vision and pattern recognition, CVPR https:\/\/doi.org\/10.1109\/CVPR.2019.00930.","DOI":"10.1109\/CVPR.2019.00930"},{"issue":"8","key":"6348_CR35","doi-asserted-by":"publisher","first-page":"157","DOI":"10.1145\/3551385","volume":"55","author":"S Mohseni","year":"2023","unstructured":"Mohseni, S., Wang, H., Xiao, C., Yu, Z., Wang, Z., & Yadawa, J. (2023). Taxonomy of machine learning safety: A survey and primer. ACM Comput. Surv., 55(8), 157\u2013115738.","journal-title":"ACM Computing Surveys"},{"key":"6348_CR36","doi-asserted-by":"publisher","unstructured":"Moosavi-Dezfooli, S.-M., Fawzi, A., & Frossard, P. (2015). DeepFool: a simple and accurate method to fool deep neural networks. In Proceedings of the IEEE computer society conference on computer vision and pattern recognition, CVPR. https:\/\/doi.org\/10.1109\/CVPR.2016.282.","DOI":"10.1109\/CVPR.2016.282"},{"key":"6348_CR37","doi-asserted-by":"publisher","first-page":"108889","DOI":"10.1016\/j.patcog.2022.108889","volume":"131","author":"Z Qian","year":"2022","unstructured":"Qian, Z., Huang, K., Wang, Q., & Zhang, X. (2022). A survey of robust adversarial training in pattern recognition: Fundamental, theory, and methodologies. Pattern Recognition, 131, 108889.","journal-title":"Pattern Recognition"},{"key":"6348_CR38","unstructured":"Rade, R., Moosavi-Dezfooli, & S.-M. (2022). Reducing excessive margin to achieve a better accuracy vs. robustness trade-off. In 10th international conference on learning representations, ICLR. https:\/\/openreview.net\/forum?id=Azh9QBQ4tR7."},{"key":"6348_CR39","unstructured":"Rebuffi, S.-A., Gowal, S., Calian, D.A., Stimberg, F., Wiles, O., & Mann, T.A. (2021) Data augmentation can improve robustness. In Advances in Neural Information Processing Systems, NeurIPS."},{"key":"6348_CR40","unstructured":"Rice, L., Wong, E., & Kolter, J.Z. (2020). Overfitting in adversarially robust deep learning. In Proceedings of the 37th international conference on machine learning, ICML. http:\/\/proceedings.mlr.press\/v119\/rice20a.html."},{"key":"6348_CR41","doi-asserted-by":"crossref","unstructured":"Rony, J., Granger, E., Pedersoli, M., & Ayed, I.B. (2020). Augmented Lagrangian adversarial attacks. CoRR arXiv:abs\/2011.11857.","DOI":"10.1109\/ICCV48922.2021.00764"},{"key":"6348_CR42","doi-asserted-by":"publisher","unstructured":"Rony, J., Hafemann, L.G., Oliveira, L.S., Ben\u00a0Ayed, I., Sabourin, R., & Granger, E. (2019). Decoupling direction and norm for efficient gradient-based l2 adversarial attacks and defenses. In Proceedings of the IEEE computer society conference on computer vision and pattern recognition, CVPR. https:\/\/doi.org\/10.1109\/CVPR.2019.00445.","DOI":"10.1109\/CVPR.2019.00445"},{"issue":"3","key":"6348_CR43","doi-asserted-by":"publisher","first-page":"211","DOI":"10.1007\/s11263-015-0816-y","volume":"115","author":"O Russakovsky","year":"2015","unstructured":"Russakovsky, O., Deng, J., Su, H., Krause, J., Satheesh, S., Ma, S., Huang, Z., Karpathy, A., Khosla, A., Bernstein, M., Berg, A. C., & Fei-Fei, L. (2015). ImageNet Large Scale Visual Recognition Challenge. International Journal of Computer Vision, IJCV, 115(3), 211\u2013252. https:\/\/doi.org\/10.1007\/s11263-015-0816-y","journal-title":"International Journal of Computer Vision, IJCV"},{"key":"6348_CR44","unstructured":"Sehwag, V., Mahloujifar, S., Handina, T., Dai, S., Xiang, C., Chiang, M., & Mittal, P. (2022). Robust learning meets generative models: Can proxy distributions improve adversarial robustness? In 10th international conference on learning representations, ICLR. https:\/\/openreview.net\/forum?id=WVX0NNVBBkV."},{"key":"6348_CR45","unstructured":"Sen, A., Zhu, X., Marshall, L., Nowak, & R.D. (2019). Should adversarial attacks use pixel p-norm? CoRR arXiv:1906.02439."},{"key":"6348_CR46","unstructured":"Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I.J., & Fergus, R. (2014). Intriguing properties of neural networks. In 2nd international conference on learning representations, ICLR. arXiv:abs\/1312.6199."},{"key":"6348_CR47","unstructured":"Taori, R., Dave, A., Shankar, V., Carlini, N., Recht, B., & Schmidt, L. (2020). Measuring robustness to natural distribution shifts in image classification. In Advances in neural information processing systems, NeurIPS. https:\/\/proceedings.neurips.cc\/paper\/2020\/hash\/d8330f857a17c53d217014ee776bfd50-Abstract.html."},{"key":"6348_CR48","unstructured":"Tramer, F., & Boneh, D. (2019). Adversarial training and robustness for multiple perturbations. In Advances in neural information processing systems, NeurIPS. https:\/\/proceedings.neurips.cc\/paper\/2019\/file\/5d4ae76f053f8f2516ad12961ef7fe97-Paper.pdf."},{"key":"6348_CR49","unstructured":"Tram\u00e8r, F., Behrmann, J., Carlini, N., Papernot, N., & Jacobsen, J. (2020). Fundamental tradeoffs between invariance and sensitivity to adversarial perturbations. In Proceedings of the 37th international conference on machine learning, ICML. http:\/\/proceedings.mlr.press\/v119\/tramer20a.html"},{"key":"6348_CR50","unstructured":"Tsipras, D., Santurkar, S., Engstrom, L., Turner, A., & Madry, A. (2019). Robustness may be at odds with accuracy. In 7th international conference on learning representations, ICLR. https:\/\/openreview.net\/forum?id=SyxAb30cY7."},{"key":"6348_CR51","unstructured":"Uesato, J., O\u2019Donoghue, B., Kohli, P., & van\u00a0den Oord, A. (2018). Adversarial risk and the dangers of evaluating against weak attacks. In Proceedings of the 35th International Conference on Machine Learning, ICML. http:\/\/proceedings.mlr.press\/v80\/uesato18a.html."},{"key":"6348_CR52","unstructured":"Wang, Z., Pang, T., Du, C., Lin, M., Liu, W., & Yan, S. (2023). Better diffusion models further improve adversarial training. CoRR arXiv: abs\/2302.04638."},{"key":"6348_CR53","unstructured":"Wang, H., Xiao, C., Kossaifi, J., Yu, Z., Anandkumar, A., & Wang, Z. (2021). Augmax: Adversarial composition of random augmentations for robust training. In Advances in neural information processing systems, NeurIPS. https:\/\/proceedings.neurips.cc\/paper\/2021\/hash\/01e9565cecc4e989123f9620c1d09c09-Abstract.html."},{"key":"6348_CR54","unstructured":"Wang, H., Zhang, A., Zheng, S., Shi, X., Li, M., & Wang, Z. (2022). Removing batch normalization boosts adversarial training. In Proceedings of the 39th international conference on machine learning, ICML. https:\/\/proceedings.mlr.press\/v162\/wang22ap.html."},{"key":"6348_CR55","unstructured":"Wang, Y., Zou, D., Yi, J., Bailey, J., Ma, X., & Gu, Q. (2020). Improving adversarial robustness requires revisiting misclassified examples. In 8th international conference on learning representations, ICLR. https:\/\/openreview.net\/forum?id=rklOg6EFwS."},{"key":"6348_CR56","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2003.819861","author":"Z Wang","year":"2004","unstructured":"Wang, Z., Bovik, A.C., Sheikh, H.R., \\& Simoncelli, E.P. (2004). Simoncelli, Image quality assessment: From error visibility to structural similarity. IEEE Transactions on Image Processing. https:\/\/doi.org\/10.1109\/TIP.2003.819861.","journal-title":"IEEE Transactions on Image Processing"},{"key":"6348_CR57","doi-asserted-by":"publisher","first-page":"215","DOI":"10.1016\/j.neucom.2020.10.081","volume":"429","author":"M Wang","year":"2021","unstructured":"Wang, M., & Deng, W. (2021). Deep face recognition: A survey. Neurocomputing, 429, 215\u2013244. https:\/\/doi.org\/10.1016\/j.neucom.2020.10.081","journal-title":"Neurocomputing"},{"key":"6348_CR58","unstructured":"Wong, E., Schmidt, F.R., & Kolter, J.Z. (2019). Wasserstein adversarial examples via projected Sinkhorn iterations. In Proceedings of the 36th international conference on machine learning, ICML. http:\/\/proceedings.mlr.press\/v97\/wong19a.html."},{"key":"6348_CR59","unstructured":"Wu, D., Xia, S., & Wang, Y. (2020). Adversarial weight perturbation helps robust generalization. In Advances in neural information processing systems, NeurIPS. https:\/\/proceedings.neurips.cc\/paper\/2020\/hash\/1ef91c212e30e14bf125e9374262401f-Abstract.html."},{"key":"6348_CR60","unstructured":"Xiao, C., Zhu, J.-Y., Li, B., He, W., Liu, M., & Song, D. (2018). Spatially transformed adversarial examples. In 6th international conference on learning representations, ICLR. https:\/\/openreview.net\/forum?id=HyydRMZC-."},{"key":"6348_CR61","unstructured":"Xing, Y., Zhang, R., & Cheng, G. (2021). Adversarially robust estimate and risk analysis in linear regression. In The 24th international conference on artificial intelligence and statistics, AISTATS. http:\/\/proceedings.mlr.press\/v130\/xing21c.html."},{"key":"6348_CR62","unstructured":"Zagoruyko, S., & Komodakis, N. (2017). Paying more attention to attention: Improving the performance of convolutional neural networks via attention transfer. In 5th international conference on learning representations, ICLR. https:\/\/openreview.net\/forum?id=Sks9_ajex"},{"key":"6348_CR63","unstructured":"Zhai, R., Dan, C., He, D., Zhang, H., Gong, B., Ravikumar, P., Hsieh, C., & Wang, L. (2020). MACER: attack-free and scalable robust training via maximizing certified radius. In 8th international conference on learning representations, ICLR. https:\/\/openreview.net\/forum?id=rJx1Na4Fwr."},{"key":"6348_CR64","doi-asserted-by":"publisher","unstructured":"Zhang, R., Isola, P., Efros, A.A., Shechtman, E., & Wang, O. (2018). The unreasonable effectiveness of deep features as a perceptual metric. In Proceedings of the IEEE computer society conference on computer vision and pattern recognition, CVPR. https:\/\/doi.org\/10.1109\/CVPR.2018.00068.","DOI":"10.1109\/CVPR.2018.00068"},{"key":"6348_CR65","unstructured":"Zhang, B., Jiang, D., He, D., & Wang, L. (2022). Rethinking lipschitz neural networks and certified robustness: A Boolean function perspective. In Advances in neural information processing systems, NeurIPS. https:\/\/openreview.net\/forum?id=xaWO6bAY0xM."},{"key":"6348_CR66","unstructured":"Zhang, J., Xu, X., Han, B., Niu, G., Cui, L., Sugiyama, M., & Kankanhalli, M.S. (2020). Attacks which do not kill training make adversarial learning stronger. In Proceedings of the 37th international conference on machine learning, ICML. http:\/\/proceedings.mlr.press\/v119\/zhang20z.html."},{"key":"6348_CR67","unstructured":"Zhang, H., Yu, Y., Jiao, J., Xing, E.P., Ghaoui, L.E., & Jordan, M.I. (2019). Theoretically principled trade-off between robustness and accuracy. In Proceedings of the 36th international conference on machine learning, ICML. http:\/\/proceedings.mlr.press\/v97\/zhang19p.html."}],"container-title":["Machine Learning"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10994-023-06348-3.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10994-023-06348-3\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10994-023-06348-3.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,6,20]],"date-time":"2024-06-20T00:02:37Z","timestamp":1718841757000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10994-023-06348-3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,6,20]]},"references-count":67,"journal-issue":{"issue":"8","published-print":{"date-parts":[[2023,8]]}},"alternative-id":["6348"],"URL":"https:\/\/doi.org\/10.1007\/s10994-023-06348-3","relation":{},"ISSN":["0885-6125","1573-0565"],"issn-type":[{"type":"print","value":"0885-6125"},{"type":"electronic","value":"1573-0565"}],"subject":[],"published":{"date-parts":[[2023,6,20]]},"assertion":[{"value":"16 August 2022","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"20 March 2023","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"26 April 2023","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"20 June 2023","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors have no competing interests to declare.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}},{"value":"Not applicable.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethical approval"}},{"value":"Not applicable.","order":4,"name":"Ethics","group":{"name":"EthicsHeading","label":"Consent to participate"}},{"value":"Not applicable.","order":5,"name":"Ethics","group":{"name":"EthicsHeading","label":"Consent for publication"}},{"value":"This content has been made available to all.","name":"free","label":"Free to read"}]}}