{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,13]],"date-time":"2026-01-13T13:22:38Z","timestamp":1768310558870,"version":"3.49.0"},"reference-count":27,"publisher":"IEEE","license":[{"start":{"date-parts":[[2025,12,9]],"date-time":"2025-12-09T00:00:00Z","timestamp":1765238400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,12,9]],"date-time":"2025-12-09T00:00:00Z","timestamp":1765238400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025,12,9]]},"DOI":"10.1109\/cdc57313.2025.11312067","type":"proceedings-article","created":{"date-parts":[[2026,1,12]],"date-time":"2026-01-12T18:19:56Z","timestamp":1768241996000},"page":"1526-1531","source":"Crossref","is-referenced-by-count":0,"title":["Distributionally Robust Adversarial Attacks with Mirrored Loss"],"prefix":"10.1109","author":[{"given":"Andr\u00e9","family":"Bertolace","sequence":"first","affiliation":[{"name":"University of Oxford,Department of Engineering Science,Oxford,U.K.,OX1 3PJ"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Konstantinos","family":"Gatsis","sequence":"additional","affiliation":[{"name":"Villanova University,Electrical and Computer Engennering,Villanova,PA,USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Kostas","family":"Margellos","sequence":"additional","affiliation":[{"name":"University of Oxford,Department of Engineering Science,Oxford,U.K.,OX1 3PJ"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1145\/1014052.1014066"},{"key":"ref2","article-title":"Adversarial examples in the physical world","author":"Kurakin","year":"2016","journal-title":"CoRR"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2018.2886017"},{"key":"ref4","article-title":"Intriguing properties of neural networks","author":"Szegedy","year":"2014"},{"key":"ref5","article-title":"Explaining and harnessing adversarial examples","author":"Goodfellow","year":"2015"},{"key":"ref6","article-title":"Towards deep learning models resistant to adversarial attacks","author":"Madry","year":"2019"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.41"},{"key":"ref8","first-page":"7472","article-title":"Theoretically principled trade-off between robustness and accuracy","volume-title":"Proceedings of the 36th International Conference on Machine Learning","volume":"97","author":"Zhang"},{"key":"ref9","article-title":"Adversarial training and robustness for multiple perturbations","author":"Tramer`","year":"2019","journal-title":"CoRR"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00764"},{"key":"ref11","article-title":"Distributionally robust deep learning as a generalization of adversarial training","volume-title":"NIPS Machine Learning and Computer Security Workshop","author":"Staib"},{"key":"ref12","article-title":"Certifiable distributional robustness with principled adversarial training","volume-title":"International Conference on Learning Representations","author":"Sinha"},{"key":"ref13","first-page":"6808","article-title":"Wasserstein adversarial examples via projected Sinkhorn iterations","volume-title":"Proceedings of Machine Learning Research","volume":"97","author":"Wong"},{"key":"ref14","first-page":"8270","article-title":"Adversarial distributional training for robust deep learning","volume-title":"Advances in Neural Information Processing Systems","volume":"33","author":"Dong","year":"2020"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1007\/s40687-022-00349-9"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1007\/s10107-022-01796-6"},{"key":"ref17","article-title":"Wasserstein distributional robustness of neural networks","volume-title":"Thirty-seventh Conference on Neural Information Processing Systems","author":"Bai"},{"key":"ref18","first-page":"555","article-title":"A robust minimax approach to classification","volume":"3","author":"Lanckriet","year":"2003","journal-title":"J. Mach. Learn. Res"},{"key":"ref19","article-title":"Distributionally robust logistic regression","volume-title":"Advances in Neural Information Processing Systems","volume":"28","author":"Shafieezadeh Abadeh","year":"2015"},{"key":"ref20","first-page":"1233","article-title":"Discrete chebyshev classifiers","volume-title":"Proceedings of the 31st International Conference on Machine Learning","volume":"32","author":"Eban"},{"key":"ref21","first-page":"xxii+973","volume-title":"Optimal transport \u2013 Old and new","volume":"338","author":"Villani","year":"2008"},{"key":"ref22","first-page":"262","article-title":"On projection robust optimal transport: Sample complexity and model misspecification","volume-title":"Proceedings of The 24th International Conference on Artificial Intelligence and Statistics","volume":"130","author":"Lin"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1007\/s10107-017-1172-1"},{"key":"ref24","volume-title":"Foundations of Machine Learning","author":"Mohri","year":"2018"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1017\/CBO9781107298019"},{"issue":"153","key":"ref26","first-page":"1","article-title":"Automatic differentiation in machine learning: a survey","volume":"18","author":"Baydin","year":"2018","journal-title":"Journal of Machine Learning Research"},{"key":"ref27","article-title":"Clarabel: An interior-point solver for conic programs with quadratic objectives","author":"Goulart","year":"2024"}],"event":{"name":"2025 IEEE 64th Conference on Decision and Control (CDC)","location":"Rio de Janeiro, Brazil","start":{"date-parts":[[2025,12,9]]},"end":{"date-parts":[[2025,12,12]]}},"container-title":["2025 IEEE 64th Conference on Decision and Control (CDC)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11311984\/11311968\/11312067.pdf?arnumber=11312067","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,1,13]],"date-time":"2026-01-13T08:13:44Z","timestamp":1768292024000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11312067\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,12,9]]},"references-count":27,"URL":"https:\/\/doi.org\/10.1109\/cdc57313.2025.11312067","relation":{},"subject":[],"published":{"date-parts":[[2025,12,9]]}}}