{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,2,21]],"date-time":"2025-02-21T19:23:31Z","timestamp":1740165811131,"version":"3.37.3"},"reference-count":49,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"2","license":[{"start":{"date-parts":[[2025,2,1]],"date-time":"2025-02-01T00:00:00Z","timestamp":1738368000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,2,1]],"date-time":"2025-02-01T00:00:00Z","timestamp":1738368000000},"content-version":"am","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,2,1]],"date-time":"2025-02-01T00:00:00Z","timestamp":1738368000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,2,1]],"date-time":"2025-02-01T00:00:00Z","timestamp":1738368000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["1909320","2003035","193464","2009030"],"award-info":[{"award-number":["1909320","2003035","193464","2009030"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100004052","name":"GR8 award from King Abdullah University of Science and Technology","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100004052","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Neural Netw. Learning Syst."],"published-print":{"date-parts":[[2025,2]]},"DOI":"10.1109\/tnnls.2023.3290592","type":"journal-article","created":{"date-parts":[[2023,7,18]],"date-time":"2023-07-18T17:41:36Z","timestamp":1689702096000},"page":"2004-2012","source":"Crossref","is-referenced-by-count":0,"title":["Asymptotic Behavior of Adversarial Training in Binary Linear Classification"],"prefix":"10.1109","volume":"36","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-9597-995X","authenticated-orcid":false,"given":"Hossein","family":"Taheri","sequence":"first","affiliation":[{"name":"Department of Electrical and Computer Engineering, University of California at Santa Barbara, Santa Barbara, CA, USA"}]},{"given":"Ramtin","family":"Pedarsani","sequence":"additional","affiliation":[{"name":"Department of Electrical and Computer Engineering, University of California at Santa Barbara, Santa Barbara, CA, USA"}]},{"given":"Christos","family":"Thrampoulidis","sequence":"additional","affiliation":[{"name":"Department of Electrical and Computer Engineering, University of California at Santa Barbara, Santa Barbara, CA, USA"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/FOCS52979.2021.00098"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1073\/pnas.1307845110"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1073\/pnas.1903070116"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1137\/20M1336072"},{"key":"ref5","first-page":"7498","article-title":"Lower bounds on adversarial robustness from optimal transport","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Bhagoji"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1214\/18-AOS1789"},{"key":"ref7","article-title":"Unlabeled data improves adversarial robustness","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"32","author":"Carmon"},{"key":"ref8","article-title":"CAD: Debiasing the LASSO with inaccurate covariate model","author":"Celentano","year":"2021","journal-title":"arXiv:2107.14172"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1214\/21-AOS2100"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1214\/23-aos2327"},{"key":"ref11","article-title":"Adversarial attacks and defences: A survey","author":"Chakraborty","year":"2018","journal-title":"arXiv:1810.00069"},{"key":"ref12","article-title":"Convergence and margin of adversarial training on separable data","author":"Charles","year":"2019","journal-title":"arXiv:1905.09209"},{"key":"ref13","first-page":"2345","article-title":"Sharp statistical guaratees for adversarially robust Gaussian classification","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Dan"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP40776.2020.9053524"},{"key":"ref15","first-page":"2665","article-title":"On the inherent regularization effects of noise injection during training","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Dhifallah"},{"key":"ref16","article-title":"A precise performance analysis of learning with random features","author":"Dhifallah","year":"2020","journal-title":"arXiv:2008.11904"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/tit.2022.3205449"},{"article-title":"Limitations of lazy training of two-layers neural network","volume-title":"Proc. NIPS","author":"Ghorbani","key":"ref18"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1103\/PhysRevX.10.041044"},{"article-title":"Explaining and harnessing adversarial examples","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Goodfellow","key":"ref20"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1214\/21-AOS2133"},{"key":"ref22","article-title":"Neural tangent kernel: Convergence and generalization in neural networks","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"31","author":"Jacot"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1214\/22-AOS2180"},{"key":"ref24","first-page":"2034","article-title":"Precise tradeoffs in adversarial training for linear regression","volume-title":"Proc. Conf. Learn. Theory","author":"Javanmard"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.06083"},{"key":"ref26","article-title":"High dimensional classification via regularized and unregularized empirical risk minimization: Precise error and optimal loss","author":"Mai","year":"2019","journal-title":"arXiv:1905.13742"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP.2019.8683376"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1002\/cpa.22008"},{"key":"ref29","first-page":"129","article-title":"The curious case of adversarially robust models: More data can help, double descend, or hurt generalization","volume-title":"Proc. Uncertainty Artif. Intell.","author":"Min"},{"key":"ref30","article-title":"The generalization error of max-margin linear classifiers: Benign overfitting and high dimensional asymptotics in the overparametrized regime","author":"Montanari","year":"2019","journal-title":"arXiv:1911.01544"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"ref32","first-page":"7909","article-title":"Understanding and mitigating the tradeoff between robustness and accuracy","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Raghunathan"},{"article-title":"Adversarial training can hurt generalization","volume-title":"Proc. ICML Workshop Identifying Understand. Deep Learn. Phenomena","author":"Raghunathan","key":"ref33"},{"key":"ref34","article-title":"Random features for large-scale kernel machines","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"20","author":"Rahimi"},{"key":"ref35","volume-title":"Variational Analysis","volume":"317","author":"Rockafellar","year":"2009"},{"key":"ref36","article-title":"The impact of regularization on high-dimensional logistic regression","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"32","author":"Salehi"},{"key":"ref37","first-page":"5014","article-title":"Adversarially robust generalization requires more data","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Schmidt"},{"key":"ref38","article-title":"Opportunities and challenges in deep learning adversarial robustness: A survey","author":"Silva","year":"2020","journal-title":"arXiv:2007.00753"},{"key":"ref39","article-title":"Various thresholds for \u2113\u2081-optimization in compressed sensing","author":"Stojnic","year":"2009","journal-title":"arXiv:0907.3666"},{"key":"ref40","article-title":"A framework to characterize performance of LASSO algorithms","author":"Stojnic","year":"2013","journal-title":"arXiv:1303.7291"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1073\/pnas.1810420116"},{"key":"ref42","article-title":"Intriguing properties of neural networks","author":"Szegedy","year":"2013","journal-title":"arXiv:1312.6199"},{"key":"ref43","first-page":"3739","article-title":"Sharp asymptotics and optimal performance for inference in binary models","volume-title":"Proc. Int. Conf. Artif. Intell. Statist.","author":"Taheri"},{"key":"ref44","first-page":"2773","article-title":"Fundamental limits of ridge-regularized empirical risk minimization in high dimensions","volume-title":"Proc. Int. Conf. Artif. Intell. Statist.","author":"Taheri"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/ISIT50566.2022.9834717"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.2018.2840720"},{"key":"ref47","first-page":"1683","article-title":"Regularized linear regression: A precise analysis of the estimation error","volume-title":"Proc. 28th Conf. Learn. Theory","author":"Thrampoulidis"},{"article-title":"Robustness may be at odds with accuracy","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Tsipras","key":"ref48"},{"article-title":"Theoretically principled trade-off between robustness and accuracy","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Zhang","key":"ref49"}],"container-title":["IEEE Transactions on Neural Networks and Learning Systems"],"original-title":[],"link":[{"URL":"https:\/\/ieeexplore.ieee.org\/ielam\/5962385\/10877690\/10186217-aam.pdf","content-type":"application\/pdf","content-version":"am","intended-application":"syndication"},{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/5962385\/10877690\/10186217.pdf?arnumber=10186217","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,2,7]],"date-time":"2025-02-07T07:11:06Z","timestamp":1738912266000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10186217\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,2]]},"references-count":49,"journal-issue":{"issue":"2"},"URL":"https:\/\/doi.org\/10.1109\/tnnls.2023.3290592","relation":{},"ISSN":["2162-237X","2162-2388"],"issn-type":[{"type":"print","value":"2162-237X"},{"type":"electronic","value":"2162-2388"}],"subject":[],"published":{"date-parts":[[2025,2]]}}}