{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,13]],"date-time":"2026-03-13T05:02:09Z","timestamp":1773378129089,"version":"3.50.1"},"reference-count":51,"publisher":"IEEE","license":[{"start":{"date-parts":[[2022,6,26]],"date-time":"2022-06-26T00:00:00Z","timestamp":1656201600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2022,6,26]],"date-time":"2022-06-26T00:00:00Z","timestamp":1656201600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2022,6,26]]},"DOI":"10.1109\/isit50566.2022.9834475","type":"proceedings-article","created":{"date-parts":[[2022,8,3]],"date-time":"2022-08-03T15:34:22Z","timestamp":1659540862000},"page":"1453-1458","source":"Crossref","is-referenced-by-count":5,"title":["Breaking Fair Binary Classification with Optimal Flipping Attacks"],"prefix":"10.1109","author":[{"given":"Changhun","family":"Jo","sequence":"first","affiliation":[{"name":"University of Wisconsin-Madison,Dept. of Mathematics,Madison,Wisconsin,USA"}]},{"given":"Jy-Yong","family":"Sohn","sequence":"additional","affiliation":[{"name":"University of Wisconsin-Madison,Dept. of ECE,Madison,Wisconsin,USA"}]},{"given":"Kangwook","family":"Lee","sequence":"additional","affiliation":[{"name":"University of Wisconsin-Madison,Dept. of ECE,Madison,Wisconsin,USA"}]}],"member":"263","reference":[{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v29i1.9569"},{"key":"ref38","article-title":"Adversarial label flips attack on support vector machines","author":"xiao","year":"2012","journal-title":"European Conference on Artificial Intelligence (ECAI)"},{"key":"ref33","article-title":"Fair classification with noisy protected attributes: A framework with provable guarantees","author":"celis","year":"2021","journal-title":"ICML"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1145\/3442188.3445887"},{"key":"ref31","article-title":"Robust optimization for fairness with noisy protected groups","author":"wang","year":"2020","journal-title":"Advances in Neural IInformation Processing Systems"},{"key":"ref30","article-title":"Equalized odds postprocessing under imperfect group information","author":"awasthi","year":"2020","journal-title":"International Conference on Artificial Intelligence and Statistics (AISTATS)"},{"key":"ref37","article-title":"Poisoning attacks against support vector machines","author":"biggio","year":"2012","journal-title":"ICML"},{"key":"ref36","article-title":"Good word attacks on statistical spam filters","author":"lowd","year":"2005","journal-title":"Conference on Email and Anti-Spam"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1145\/1014052.1014066"},{"key":"ref34","doi-asserted-by":"crossref","DOI":"10.1109\/CVPR52688.2022.01010","article-title":"Learning fair classifiers with partially annotated group labels","author":"jung","year":"2022"},{"key":"ref28","article-title":"Sample selection for fair and robust training","author":"roh","year":"2021","journal-title":"Advances in Neural IInformation Processing Systems"},{"key":"ref27","article-title":"Leveraging labeled and unlabeled data for consistent fair binary classification","author":"chzhen","year":"2019","journal-title":"Advances in Neural IInformation Processing Systems"},{"key":"ref29","article-title":"Noise-tolerant fair classification","author":"lamy","year":"2019","journal-title":"Advances in Neural IInformation Processing Systems"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1145\/2783258.2783311"},{"key":"ref1","article-title":"Ethics guidelines for trustworthy AI","year":"2019"},{"key":"ref20","first-page":"671","article-title":"Big data&#x2019;s disparate impact","author":"barocas","year":"2016","journal-title":"California Law Review"},{"key":"ref22","article-title":"Beyond parity: Fairness objectives for collaborative filtering","author":"yao","year":"2017","journal-title":"Advances in Neural Information Processing Systems (NIPS)"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-33486-3_3"},{"key":"ref24","article-title":"Two-player games for efficient non-convex constrained optimization","author":"cotter","year":"2019","journal-title":"International Conference on Algorithmic Learning Theory (ALT)"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1145\/3278721.3278779"},{"key":"ref26","article-title":"On fairness and calibration","author":"pleiss","year":"2017","journal-title":"Advances in Neural Information Processing Systems (NIPS)"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/ICDM.2012.45"},{"key":"ref50","article-title":"On the impossibility of fairness-aware learning from corrupted data","author":"konstantinov","year":"2022","journal-title":"NeurIPS Workshop Algorithmic Fairness through the Lens of Causality and Robustness"},{"key":"ref51","author":"billingsley","year":"1995","journal-title":"Probability and Measure"},{"key":"ref10","article-title":"Fairness Constraints: Mechanisms for Fair Classification","author":"zafar","year":"2017","journal-title":"International Conference on Artificial Intelligence and Statistics (AISTATS)"},{"key":"ref11","article-title":"FR-train: A mutual information-based approach to fair and robust training","author":"roh","year":"2020","journal-title":"ICML"},{"key":"ref40","article-title":"Stronger data poisoning attacks break data sanitization defenses","author":"koh","year":"2021","journal-title":"Machine Learning"},{"key":"ref12","article-title":"FairBatch: Batch selection for model fairness","author":"roh","year":"2021","journal-title":"ICLRE"},{"key":"ref13","article-title":"Adaptive sampling to reduce disparate performance","author":"abernethy","year":"2020"},{"key":"ref14","article-title":"A reductions approach to fair classification","author":"agarwal","year":"2018","journal-title":"ICML"},{"key":"ref15","article-title":"Empirical risk minimization under fairness constraints","author":"donini","year":"2018","journal-title":"Advances in Neural IInformation Processing Systems"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref17","article-title":"Bert: Pre-training of deep bidirectional transformers for language understanding","author":"devlin","year":"2019","journal-title":"Conference of the North American Chapter of the Association for Computational Linguistics - Human Language Technologies (NAACL-HLT)"},{"key":"ref18","article-title":"Language models are few-shot learners","author":"brown","year":"2020","journal-title":"Advances in Neural IInformation Processing Systems"},{"key":"ref19","article-title":"On adversarial bias and the robustness of fair machine learning","author":"chang","year":"2020","journal-title":"arXiv preprint arXiv 2006 04989"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1007\/s10115-011-0463-8"},{"key":"ref3","article-title":"Equality of opportunity in supervised learning","author":"hardt","year":"2016","journal-title":"Advances in Neural Information Processing Systems (NIPS)"},{"key":"ref6","article-title":"Optimized pre-processing for discrimination prevention","author":"calmon","year":"2017","journal-title":"Advances in Neural Information Processing Systems (NIPS)"},{"key":"ref5","article-title":"Learning fair representations","author":"zemel","year":"2013","journal-title":"ICML"},{"key":"ref8","article-title":"Identifying and correcting label bias in machine learning","author":"jiang","year":"2020","journal-title":"International Conference on Artificial Intelligence and Statistics (AISTATS)"},{"key":"ref7","article-title":"Fair generative modeling via weak supervision","author":"grover","year":"2020","journal-title":"ICML"},{"key":"ref49","article-title":"Fairness-aware pac learning from corrupted data","author":"konstantinov","year":"2021"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1145\/3038912.3052660"},{"key":"ref46","article-title":"Label sanitization against label flipping poisoning attacks","author":"paudice","year":"2018","journal-title":"MLD Workshop of ECML PKDD"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2017\/551"},{"key":"ref48","article-title":"Fair classification with adversarial perturbations","author":"celis","year":"2021","journal-title":"Advances in Neural IInformation Processing Systems"},{"key":"ref47","article-title":"Certified robustness to label-flipping attacks via randomized smoothing","author":"rosenfeld","year":"2020","journal-title":"ICML"},{"key":"ref42","article-title":"Model-targeted poisoning attacks with provable convergence","author":"suya","year":"2021","journal-title":"ICML"},{"key":"ref41","article-title":"Poisoning attacks on algorithmic fairness","author":"solans","year":"2020","journal-title":"European Conference on Machine Learning and Principles and Practice of Knowledge Discovery in Databases (ECML\/PKDD)"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-00123-9_30"},{"key":"ref43","doi-asserted-by":"crossref","DOI":"10.1609\/aaai.v35i10.17080","article-title":"Exacerbating algorithmic bias through fairness attacks","author":"mehrabi","year":"2021","journal-title":"AAAI Conference on Artificial Intelligence (AAAI)"}],"event":{"name":"2022 IEEE International Symposium on Information Theory (ISIT)","location":"Espoo, Finland","start":{"date-parts":[[2022,6,26]]},"end":{"date-parts":[[2022,7,1]]}},"container-title":["2022 IEEE International Symposium on Information Theory (ISIT)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/9834325\/9834269\/09834475.pdf?arnumber=9834475","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,3,12]],"date-time":"2026-03-12T20:36:27Z","timestamp":1773347787000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9834475\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,6,26]]},"references-count":51,"URL":"https:\/\/doi.org\/10.1109\/isit50566.2022.9834475","relation":{},"subject":[],"published":{"date-parts":[[2022,6,26]]}}}