{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,14]],"date-time":"2026-04-14T15:52:45Z","timestamp":1776181965344,"version":"3.50.1"},"reference-count":76,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"9","license":[{"start":{"date-parts":[[2022,9,1]],"date-time":"2022-09-01T00:00:00Z","timestamp":1661990400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2022,9,1]],"date-time":"2022-09-01T00:00:00Z","timestamp":1661990400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2022,9,1]],"date-time":"2022-09-01T00:00:00Z","timestamp":1661990400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/100002427","name":"Ford Motor Company","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100002427","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Neural Netw. Learning Syst."],"published-print":{"date-parts":[[2022,9]]},"DOI":"10.1109\/tnnls.2021.3056046","type":"journal-article","created":{"date-parts":[[2021,2,16]],"date-time":"2021-02-16T14:58:14Z","timestamp":1613487494000},"page":"4184-4198","source":"Crossref","is-referenced-by-count":34,"title":["Certifiable Robustness to Adversarial State Uncertainty in Deep Reinforcement Learning"],"prefix":"10.1109","volume":"33","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-9377-6745","authenticated-orcid":false,"given":"Michael","family":"Everett","sequence":"first","affiliation":[{"name":"Aerospace Controls Laboratory, Massachusetts Institute of Technology, Cambridge, MA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1616-4830","authenticated-orcid":false,"given":"Bjorn","family":"Lutjens","sequence":"additional","affiliation":[{"name":"Aerospace Controls Laboratory, Massachusetts Institute of Technology, Cambridge, MA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8576-1930","authenticated-orcid":false,"given":"Jonathan P.","family":"How","sequence":"additional","affiliation":[{"name":"Aerospace Controls Laboratory, Massachusetts Institute of Technology, Cambridge, MA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","first-page":"1328","article-title":"Certified adversarial robustness for deep reinforcement learning","volume-title":"Proc. Conf. Robot Learn. (CoRL)","author":"L\u00fctjens"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/ICRA.2017.7989385"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/LRA.2019.2891491"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/IROS.2018.8593871"},{"key":"ref5","article-title":"Intriguing properties of neural networks","volume-title":"Proc. Int. Conf. Learn. Represent. (ICLR)","author":"Szegedy"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2807385"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2018.2886017"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1201\/9781351251389-8"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978392"},{"key":"ref10","volume-title":"Experimental security research of Tesla Autopilot","year":"2019"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/IROS.2017.8206245"},{"key":"ref12","article-title":"Epopt: Learning robust neural network policies using model ensembles","volume-title":"Proc. Int. Conf. Learn. Represent. (ICLR)","author":"Rajeswaran"},{"key":"ref13","first-page":"700","article-title":"Domain randomization for simulation-based policy optimization with transferability assessment","volume-title":"Proc. 2nd Annu. Conf. Robot Learn. (CoRL)","author":"Muratore"},{"key":"ref14","first-page":"2817","article-title":"Robust adversarial reinforcement learning","volume-title":"Proc. 34th Int. Conf. Mach. Learn. (ICML) (PMLR)","volume":"70","author":"Pinto"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1162\/0899766053011528"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-68167-2_19"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-63387-9_5"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-63387-9_1"},{"key":"ref19","article-title":"An approach to reachability analysis for feed-forward ReLU neural networks","volume":"abs\/1706.07351","author":"Lomuscio","year":"2017"},{"key":"ref20","article-title":"Evaluating robustness of neural networks with mixed integer programming","volume-title":"Proc. Int. Conf. Learn. Represent. (ICLR)","author":"Tjeng"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00058"},{"key":"ref22","first-page":"5283","article-title":"Provable defenses against adversarial examples via the convex outer adversarial polytope","volume-title":"Proc. Mach. Learn. Res. (ICML)","volume":"80","author":"Wong"},{"key":"ref23","first-page":"6367","article-title":"Efficient formal safety analysis of neural networks","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Wang"},{"key":"ref24","article-title":"Training verified learners with learned verifiers","author":"Dvijotham","year":"2018","journal-title":"arXiv:1805.10265"},{"key":"ref25","first-page":"10802","article-title":"Fast and effective robustness certification","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Singh"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1145\/3290354"},{"key":"ref27","first-page":"5276","article-title":"Towards fast computation of certified robustness for ReLU networks","volume-title":"Proc. Int. Conf. Mach. Learn. (ICML)","author":"Weng"},{"key":"ref28","first-page":"4939","article-title":"Efficient neural network robustness certification with general activation functions","volume-title":"Advances in Neural Information Processing Systems 31","author":"Zhang","year":"2018"},{"key":"ref29","first-page":"9832","article-title":"A convex relaxation barrier to tight robustness verification of neural networks","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Salman"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/TAI.2021.3111139"},{"key":"ref31","article-title":"Explaining and harnessing adversarial examples","volume-title":"Proc. Int. Conf. Learn. Represent. (ICLR)","author":"Goodfellow"},{"key":"ref32","article-title":"Adversarial attacks on neural network policies","volume-title":"Proc. ICLR Workshop Track","author":"Huang"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-62416-7_19"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP40776.2020.9053342"},{"key":"ref35","article-title":"Adversarial reinforcement learning","volume-title":"AAAI Fall Symp. Model Directed Auton. Syst.","author":"Uther"},{"key":"ref36","article-title":"Adversarial policies: Attacking deep reinforcement learning","volume-title":"Proc. ICLR","author":"Gleave"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1016\/b978-1-55860-335-6.50027-1"},{"key":"ref38","article-title":"Adversarial machine learning at scale","volume-title":"Proc. Int. Conf. Learn. Represent. (ICLR)","author":"Kurakin"},{"key":"ref39","article-title":"Towards deep learning models resistant to adversarial attacks","volume-title":"Proc. Int. Conf. Learn. Represent. (ICLR)","author":"Madry"},{"key":"ref40","article-title":"Delving into adversarial attacks on deep policies","volume-title":"Proc. Int. Conf. Learn. Represent. (ICLR)","author":"Kos"},{"key":"ref41","volume-title":"Distilled agent DQN for provable adversarial robustness","author":"Mirman","year":"2019"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.41"},{"key":"ref43","article-title":"Ensemble adversarial training: Attacks and defenses","volume-title":"Proc. Int. Conf. Learn. Represent. (ICLR)","author":"Tram\u00e9r"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23198"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140444"},{"key":"ref46","first-page":"15","article-title":"Adversarial example defenses: Ensembles of weak defenses are not strong","volume-title":"Proc. 11th USENIX Conf. Offensive Technol. (WOOT)","author":"He"},{"key":"ref47","first-page":"274","article-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","volume-title":"Proc. 35th Int. Conf. Mach. Learn. (ICML) (PMLR)","volume":"80","author":"Athalye"},{"key":"ref48","first-page":"5025","article-title":"Adversarial risk and the dangers of evaluating against weak attacks","volume-title":"Proc. 35th Int. Conf. Mach. Learn. (ICML) (PMLR)","volume":"80","author":"Uesato"},{"issue":"1","key":"ref49","first-page":"1437","article-title":"A comprehensive survey on safe reinforcement learning","volume":"16","author":"Garc\u00eda","year":"2015","journal-title":"J. Mach. Learn. Res."},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1016\/B978-1-55860-335-6.50021-0"},{"key":"ref51","article-title":"Risk-sensitive and efficient reinforcement learning algorithms","author":"Tamar","year":"2015"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1613\/jair.1666"},{"key":"ref53","article-title":"Certified adversarial robustness via randomized smoothing","author":"Cohen","year":"2019","journal-title":"arXiv:1902.02918"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1038\/nature14236"},{"key":"ref55","first-page":"1928","article-title":"Asynchronous methods for deep reinforcement learning","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Mnih"},{"key":"ref56","article-title":"Proximal policy optimization algorithms","author":"Schulman","year":"2017","journal-title":"arXiv:1707.06347"},{"key":"ref57","article-title":"Soft actor-critic: Off-policy maximum entropy deep reinforcement learning with a stochastic actor","author":"Haarnoja","year":"2018","journal-title":"arXiv:1801.01290"},{"key":"ref58","article-title":"Soft actor-critic for discrete action settings","author":"Christodoulou","year":"2019","journal-title":"arXiv:1910.07207"},{"key":"ref59","article-title":"Ga3c: Gpu-based a3c for deep reinforcement learning","volume":"abs\/1611.06256","author":"Babaeizadeh","year":"2016"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140448"},{"key":"ref61","volume-title":"Gym: Collision Avoidance","author":"Everett","year":"2020"},{"key":"ref62","article-title":"OpenAI gym","author":"Brockman","year":"2016","journal-title":"arXiv:1606.01540"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-19457-3_1"},{"key":"ref64","first-page":"2951","article-title":"Practical Bayesian optimization of machine learning algorithms","volume-title":"Advances in Neural Information Processing Systems","author":"Snoek","year":"2012"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.1109\/TSMC.1983.6313077"},{"key":"ref66","volume-title":"Stable Baselines","author":"Hill","year":"2018"},{"key":"ref67","doi-asserted-by":"publisher","DOI":"10.1613\/jair.3912"},{"key":"ref68","volume-title":"Stella: A Multiplatform Atari 2600 VCS Emulator","author":"Mott","year":"1995"},{"key":"ref69","doi-asserted-by":"publisher","DOI":"10.1117\/3.682726.p64"},{"key":"ref70","volume-title":"CROWN-IBP: Towards Stable and Efficient Training of Verifiably Robust Neural Networks","author":"Zhang","year":"2020"},{"key":"ref71","article-title":"Adversarial patch","volume-title":"Proc. Conf. Neural Inf. Process. Syst. (NeurIPS) Workshop","author":"Brown"},{"key":"ref72","first-page":"6808","article-title":"Wasserstein adversarial examples via projected sinkhorn iterations","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Wong"},{"key":"ref73","article-title":"Verification of neural network control policy under persistent adversarial perturbation","volume-title":"Proc. NeurIPS Workshop Saf. Robustness Decis. Making","author":"Wang"},{"key":"ref74","doi-asserted-by":"publisher","DOI":"10.1017\/CBO9780511804441"},{"key":"ref75","doi-asserted-by":"publisher","DOI":"10.1016\/j.crma.2015.11.009"},{"key":"ref76","doi-asserted-by":"publisher","DOI":"10.1109\/TRO.2020.3033695"}],"container-title":["IEEE Transactions on Neural Networks and Learning Systems"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/5962385\/9872163\/09354500.pdf?arnumber=9354500","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,1,9]],"date-time":"2024-01-09T23:22:34Z","timestamp":1704842554000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9354500\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,9]]},"references-count":76,"journal-issue":{"issue":"9"},"URL":"https:\/\/doi.org\/10.1109\/tnnls.2021.3056046","relation":{},"ISSN":["2162-237X","2162-2388"],"issn-type":[{"value":"2162-237X","type":"print"},{"value":"2162-2388","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,9]]}}}