{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,19]],"date-time":"2026-02-19T23:23:00Z","timestamp":1771543380013,"version":"3.50.1"},"reference-count":44,"publisher":"Springer Science and Business Media LLC","issue":"12","license":[{"start":{"date-parts":[[2025,11,26]],"date-time":"2025-11-26T00:00:00Z","timestamp":1764115200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,11,26]],"date-time":"2025-11-26T00:00:00Z","timestamp":1764115200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"funder":[{"name":"Center for Connected Multimodal Mobility"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Mach Learn"],"published-print":{"date-parts":[[2025,12]]},"DOI":"10.1007\/s10994-025-06894-y","type":"journal-article","created":{"date-parts":[[2025,11,26]],"date-time":"2025-11-26T19:54:56Z","timestamp":1764186896000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["A robust adversarial ensemble with causal (feature interaction) interpretations for image classification"],"prefix":"10.1007","volume":"114","author":[{"given":"Chunheng","family":"Zhao","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Pierluigi","family":"Pisu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Gurcan","family":"Comert","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Negash","family":"Begashaw","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Varghese","family":"Vaidyan","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Nina","family":"Hubig","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,11,26]]},"reference":[{"key":"6894_CR1","doi-asserted-by":"publisher","first-page":"35479","DOI":"10.1109\/ACCESS.2023.3266093","volume":"11","author":"AB Amjoud","year":"2023","unstructured":"Amjoud, A. B., & Amrouch, M. (2023). Object detection using deep learning, CNNs and vision transformers: A review. IEEE Access, 11, 35479\u201335516.","journal-title":"IEEE Access"},{"key":"6894_CR2","first-page":"16048","volume":"33","author":"M Andriushchenko","year":"2020","unstructured":"Andriushchenko, M., & Flammarion, N. (2020). Understanding and improving fast adversarial training. Advances in Neural Information Processing Systems, 33, 16048\u201316059.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"6894_CR3","unstructured":"Athalye, A., Carlini, N., & Wagner, D. (2018). Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples. In International conference on machine learning, 274\u2013283. PMLR."},{"key":"6894_CR4","unstructured":"Boopathy, A., Liu, S., Zhang, G., Liu, C., Chen, P.Y., Chang, S., & Daniel, L. (2020). Proper network interpretability helps adversarial robustness in classification. In International Conference on Machine Learning, 1014\u20131023. PMLR."},{"key":"6894_CR5","doi-asserted-by":"crossref","unstructured":"Carlini, N., & Wagner, D. (2017). Towards evaluating the robustness of neural networks. In 2017 ieee symposium on security and privacy (sp), 39\u201357. IEEE.","DOI":"10.1109\/SP.2017.49"},{"key":"6894_CR6","unstructured":"Carlini, N., Athalye, A., Papernot, N., Brendel, W., Rauber, J., Tsipras, D., Goodfellow, I., Madry, A., & Kurakin, A. (2019). On evaluating adversarial robustness. arXiv preprint arXiv:1902.06705."},{"issue":"22","key":"6894_CR7","doi-asserted-by":"publisher","first-page":"4712","DOI":"10.3390\/rs13224712","volume":"13","author":"L Chen","year":"2021","unstructured":"Chen, L., Li, S., Bai, Q., Yang, J., Jiang, S., & Miao, Y. (2021). Review of image classification algorithms based on convolutional neural networks. Remote Sensing, 13(22), 4712.","journal-title":"Remote Sensing"},{"key":"6894_CR8","unstructured":"Croce, F., & Hein, M. (2020). Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks. In International conference on machine learning, 2206\u20132216. PMLR."},{"key":"6894_CR9","unstructured":"Dosovitskiy, A. (2020). An image is worth 16x16 words: Transformers for image recognition at scale. arXiv preprint arXiv:2010.11929."},{"issue":"9","key":"6894_CR10","doi-asserted-by":"publisher","first-page":"6463","DOI":"10.1002\/int.22851","volume":"37","author":"T Du","year":"2022","unstructured":"Du, T., Ji, S., Wang, B., He, S., Li, J., Li, B., Wei, T., Jia, Y., Beyah, R., & Wang, T. (2022). Detects ec: Evaluating the robustness of object detection models to adversarial attacks. International Journal of Intelligent Systems, 37(9), 6463\u20136492.","journal-title":"International Journal of Intelligent Systems"},{"key":"6894_CR11","doi-asserted-by":"crossref","unstructured":"Fan, J., Yan, Q., Li, M., Qu, G., & Xiao, Y. (2022). A survey on data poisoning attacks and defenses. In 2022 7th IEEE International Conference on Data Science in Cyberspace (DSC), 48\u201355. IEEE.","DOI":"10.1109\/DSC55868.2022.00014"},{"key":"6894_CR12","unstructured":"Fetaya, E., Jacobsen, J.H., Grathwohl, W., & Zemel, R. (2019). Understanding the limitations of conditional generative models. arXiv preprint arXiv:1906.01171."},{"issue":"1","key":"6894_CR13","doi-asserted-by":"publisher","first-page":"77","DOI":"10.1007\/s11023-021-09580-9","volume":"32","author":"T Freiesleben","year":"2022","unstructured":"Freiesleben, T. (2022). The intriguing relation between counterfactual explanations and adversarial examples. Minds and Machines, 32(1), 77\u2013109.","journal-title":"Minds and Machines"},{"key":"6894_CR14","unstructured":"Goodfellow, I.J., Shlens, J., & Szegedy, C. (2014). Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572."},{"key":"6894_CR15","doi-asserted-by":"crossref","unstructured":"He, K., Zhang, X., Ren, S., & Sun, J. (2016). Deep residual learning for image recognition. In Proceedings of the IEEE conference on computer vision and pattern recognition, 770\u2013778.","DOI":"10.1109\/CVPR.2016.90"},{"key":"6894_CR16","unstructured":"Hooker, S., Erhan, D., Kindermans, P. J., & Kim, B. (2019). A benchmark for interpretability methods in deep neural networks. Advances in neural information processing systems, 32."},{"key":"6894_CR17","doi-asserted-by":"publisher","DOI":"10.1016\/j.cmpb.2022.107291","volume":"229","author":"Z Hu","year":"2023","unstructured":"Hu, Z., Wang, Z., Jin, Y., & Hou, W. (2023). VGG-TSwinFormer: Transformer-based deep learning model for early Alzheimer\u2019s disease prediction. Computer Methods and Programs in Biomedicine, 229, Article 107291.","journal-title":"Computer Methods and Programs in Biomedicine"},{"key":"6894_CR18","doi-asserted-by":"publisher","first-page":"6367","DOI":"10.1109\/TPAMI.2024.3381180","volume":"46","author":"X Jia","year":"2024","unstructured":"Jia, X., Zhang, Y., Wei, X., Wu, B., Ma, K., Wang, J., & Cao, X. (2024). Improving fast adversarial training with prior-guided knowledge. IEEE Transactions on Pattern Analysis and Machine Intelligence, 46, 6367\u20136383.","journal-title":"IEEE Transactions on Pattern Analysis and Machine Intelligence"},{"key":"6894_CR19","unstructured":"Kingma, D.P., & Welling, M. (2013). Auto-encoding variational bayes. arXiv preprint arXiv:1312.6114."},{"key":"6894_CR20","volume-title":"Learning multiple layers of features from tiny images","author":"A Krizhevsky","year":"2009","unstructured":"Krizhevsky, A., Hinton, G., et al. (2009). Learning multiple layers of features from tiny images. ON, Canada."},{"issue":"1","key":"6894_CR21","doi-asserted-by":"publisher","first-page":"79","DOI":"10.1214\/aoms\/1177729694","volume":"22","author":"S Kullback","year":"1951","unstructured":"Kullback, S., & Leibler, R. A. (1951). On information and sufficiency. The Annals of Mathematical Statistics, 22(1), 79\u201386.","journal-title":"The Annals of Mathematical Statistics"},{"key":"6894_CR22","unstructured":"Kurakin, A., Goodfellow, I., & Bengio, S. (2016). Adversarial machine learning at scale. arXiv preprint arXiv:1611.01236."},{"issue":"7","key":"6894_CR23","first-page":"3","volume":"7","author":"Y Le","year":"2015","unstructured":"Le, Y., & Yang, X. (2015). Tiny imagenet visual recognition challenge. CS 231N, 7(7), 3.","journal-title":"CS 231N"},{"key":"6894_CR24","unstructured":"Li, Y., Bradshaw, J., & Sharma, Y. (2019). Are generative classifiers more robust to adversarial attacks? In International Conference on Machine Learning, pp. 3804\u20133814. PMLR."},{"key":"6894_CR25","doi-asserted-by":"crossref","unstructured":"Mackowiak, R., Ardizzone, L., Kothe, U., & Rother, C. (2021). Generative classifiers as a basis for trustworthy image classification. In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, 2971\u20132981.","DOI":"10.1109\/CVPR46437.2021.00299"},{"key":"6894_CR26","unstructured":"Madry, A., Makelov, A., Schmidt, L., Tsipras, D., & Vladu, A. (2017). Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083."},{"issue":"9","key":"6894_CR27","doi-asserted-by":"publisher","first-page":"5521","DOI":"10.3390\/app13095521","volume":"13","author":"J Maur\u00edcio","year":"2023","unstructured":"Maur\u00edcio, J., Domingues, I., & Bernardino, J. (2023). Comparing vision transformers and convolutional neural networks for image classification: A literature review. Applied Sciences, 13(9), 5521.","journal-title":"Applied Sciences"},{"issue":"1","key":"6894_CR28","doi-asserted-by":"publisher","first-page":"18","DOI":"10.1145\/3400051.3400058","volume":"22","author":"R Moraffah","year":"2020","unstructured":"Moraffah, R., Karami, M., Guo, R., Raglin, A., & Liu, H. (2020). Causal interpretability for machine learning-problems, methods and evaluation. Acm Sigkdd Explorations Newsletter, 22(1), 18\u201333.","journal-title":"Acm Sigkdd Explorations Newsletter"},{"key":"6894_CR29","unstructured":"Ng, A., & Jordan, M. (2001). On discriminative vs. generative classifiers: A comparison of logistic regression and naive bayes. Advances in neural information processing systems, 14."},{"key":"6894_CR30","unstructured":"Pawelczyk, M., Agarwal, C., Joshi, S., Upadhyay, S., & Lakkaraju, H. (2022). Exploring counterfactual explanations through the lens of adversarial examples: A theoretical and empirical analysis. In International Conference on Artificial Intelligence and Statistics, pp. 4574\u20134594. PMLR."},{"key":"6894_CR31","unstructured":"Sabour, S., Cao, Y., Faghri, F., & Fleet, D.J. (2015). Adversarial manipulation of deep representations. arXiv preprint arXiv:1511.05122."},{"key":"6894_CR32","unstructured":"Shafahi, A., Najibi, M., Ghiasi, A., Xu, Z., Dickerson, J., Studer, C., Davis, L.S., Taylor, G., & Goldstein, T. (2019). Adversarial training for free! arXiv preprint arXiv:1904.12843."},{"key":"6894_CR33","unstructured":"Simonyan, K., & Zisserman, A. (2014). Very deep convolutional networks for large-scale image recognition. arXiv preprint arXiv:1409.1556."},{"key":"6894_CR34","unstructured":"Sundararajan, M., Taly, A., & Yan, Q. (2017). Axiomatic attribution for deep networks. In International conference on machine learning, 3319\u20133328. PMLR."},{"key":"6894_CR35","unstructured":"Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I., & Fergus, R. (2013). Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199."},{"key":"6894_CR36","first-page":"650","volume-title":"Joint European Conference on Machine Learning and Knowledge Discovery in Databases","author":"A Van Looveren","year":"2021","unstructured":"Van Looveren, A., & Klaise, J. (2021). Interpretable counterfactual explanations guided by prototypes. Joint European Conference on Machine Learning and Knowledge Discovery in Databases (pp. 650\u2013665). Springer."},{"key":"6894_CR37","doi-asserted-by":"publisher","first-page":"61","DOI":"10.1016\/j.patrec.2020.07.042","volume":"141","author":"P Wang","year":"2021","unstructured":"Wang, P., Fan, E., & Wang, P. (2021). Comparative analysis of image classification algorithms based on traditional machine learning and deep learning. Pattern Recognition Letters, 141, 61\u201367.","journal-title":"Pattern Recognition Letters"},{"key":"6894_CR38","doi-asserted-by":"publisher","first-page":"87","DOI":"10.1016\/j.neucom.2019.11.051","volume":"382","author":"Y Wang","year":"2020","unstructured":"Wang, Y., Wang, K., Zhu, Z., & Wang, F. Y. (2020). Adversarial attacks on faster R-CNN object detector. Neurocomputing, 382, 87\u201395.","journal-title":"Neurocomputing"},{"key":"6894_CR39","unstructured":"Wang, Z., Pang, T., Du, C., Lin, M., Liu, W., & Yan, S. (2023). Better diffusion models further improve adversarial training. In International Conference on Machine Learning, 36246\u201336263. PMLR."},{"key":"6894_CR40","unstructured":"Wong, E., Rice, L., & Kolter, J.Z. (2020). Fast is better than free: Revisiting adversarial training. arXiv preprint arXiv:2001.03994."},{"key":"6894_CR41","first-page":"2894","volume":"36","author":"H Xue","year":"2024","unstructured":"Xue, H., Araujo, A., Hu, B., & Chen, Y. (2024). Diffusion-based adversarial sample generation for improved stealthiness and controllability. Advances in Neural Information Processing Systems, 36, 2894\u20132921.","journal-title":"Advances in Neural Information Processing Systems"},{"issue":"8","key":"6894_CR42","doi-asserted-by":"publisher","first-page":"2008","DOI":"10.1109\/TPAMI.2018.2889774","volume":"41","author":"C Zhang","year":"2018","unstructured":"Zhang, C., B\u00fctepage, J., Kjellstr\u00f6m, H., & Mandt, S. (2018). Advances in variational inference. IEEE Transactions on Pattern Analysis and Machine Intelligence, 41(8), 2008\u20132026.","journal-title":"IEEE Transactions on Pattern Analysis and Machine Intelligence"},{"key":"6894_CR43","first-page":"289","volume":"33","author":"C Zhang","year":"2020","unstructured":"Zhang, C., Zhang, K., & Li, Y. (2020). A causal view on robustness of neural networks. Advances in Neural Information Processing Systems, 33, 289\u2013301.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"6894_CR44","unstructured":"Zheng, C., Wu, G., Bao, F., Cao, Y., Li, C., & Zhu, J. (2023). Revisiting discriminative vs. generative classifiers: Theory and implications. In International Conference on Machine Learning, pp. 42420\u201342477. PMLR."}],"container-title":["Machine Learning"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10994-025-06894-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10994-025-06894-y","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10994-025-06894-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,12,22]],"date-time":"2025-12-22T21:30:03Z","timestamp":1766439003000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10994-025-06894-y"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,11,26]]},"references-count":44,"journal-issue":{"issue":"12","published-print":{"date-parts":[[2025,12]]}},"alternative-id":["6894"],"URL":"https:\/\/doi.org\/10.1007\/s10994-025-06894-y","relation":{},"ISSN":["0885-6125","1573-0565"],"issn-type":[{"value":"0885-6125","type":"print"},{"value":"1573-0565","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,11,26]]},"assertion":[{"value":"25 February 2025","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"8 August 2025","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"10 September 2025","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"26 November 2025","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors have no competing interests to declare that are relevant to the content of this article.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}},{"value":"Not applicable. This article does not contain any studies involving humans or animals performed by any of the authors.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethical approval and consent to participate"}}],"article-number":"291"}}