{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,10]],"date-time":"2026-02-10T16:05:15Z","timestamp":1770739515574,"version":"3.49.0"},"reference-count":46,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"2","license":[{"start":{"date-parts":[[2026,2,1]],"date-time":"2026-02-01T00:00:00Z","timestamp":1769904000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2026,2,1]],"date-time":"2026-02-01T00:00:00Z","timestamp":1769904000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,2,1]],"date-time":"2026-02-01T00:00:00Z","timestamp":1769904000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Neural Netw. Learning Syst."],"published-print":{"date-parts":[[2026,2]]},"DOI":"10.1109\/tnnls.2025.3610816","type":"journal-article","created":{"date-parts":[[2025,11,11]],"date-time":"2025-11-11T18:28:29Z","timestamp":1762885709000},"page":"701-710","source":"Crossref","is-referenced-by-count":0,"title":["On Continuity of Robust and Accurate Classifiers"],"prefix":"10.1109","volume":"37","author":[{"ORCID":"https:\/\/orcid.org\/0009-0008-7770-7035","authenticated-orcid":false,"given":"Ramin","family":"Barati","sequence":"first","affiliation":[{"name":"Department of Computer Engineering, Amirkabir University of Technology, Tehran, Iran"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4937-8026","authenticated-orcid":false,"given":"Reza","family":"Safabakhsh","sequence":"additional","affiliation":[{"name":"Department of Computer Engineering, Amirkabir University of Technology, Tehran, Iran"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0591-6910","authenticated-orcid":false,"given":"Mohammad","family":"Rahmati","sequence":"additional","affiliation":[{"name":"Department of Computer Engineering, Amirkabir University of Technology, Tehran, Iran"}]}],"member":"263","reference":[{"key":"ref1","first-page":"2235","article-title":"Delving into transferable adversarial examples and black-box attacks","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Liu"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP43922.2022.9747469"},{"key":"ref3","article-title":"Intriguing properties of neural networks","volume-title":"Proc. 2nd Int. Conf. Learn. Represent.","author":"Szegedy"},{"key":"ref4","article-title":"Explaining and harnessing adversarial examples","volume-title":"Proc. 3rd Int. Conf. Learn. Represent.","author":"Goodfellow"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2021\/591"},{"key":"ref6","article-title":"Robustness may be at odds with accuracy","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Tsipras"},{"key":"ref7","article-title":"Transfer of adversarial robustness between perturbation types","author":"Kang","year":"2019","journal-title":"arXiv:1905.01034"},{"key":"ref8","first-page":"6640","article-title":"Adversarial robustness against the union of multiple perturbation models","volume-title":"Proc. 37th Int. Conf. Mach. Learn.","author":"Maini"},{"key":"ref9","first-page":"854","article-title":"Parseval networks: Improving robustness to adversarial examples","volume-title":"Proc. 34th Int. Conf. Mach. Learn.","author":"Cisse"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-13453-2_2"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2021.3118409"},{"key":"ref12","article-title":"Adversarial training can hurt generalization","volume-title":"Proc. ICML Workshop Identifying Understand. Deep Learn. Phenomena","author":"Raghunathan"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1038\/s42256-020-00266-y"},{"key":"ref14","first-page":"8588","article-title":"A closer look at accuracy vs. robustness","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Yang"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01258-8_39"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/ICDM.2015.84"},{"key":"ref17","article-title":"Implicit gradient regularization","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Barrett"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v32i1.11504"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1007\/s10462-021-10125-w"},{"key":"ref20","article-title":"On the (statisstical) detection of adversarial examples","author":"Grosse","year":"2017","journal-title":"arXiv:1702.06280"},{"key":"ref21","article-title":"A baseline for detecting misclassified and out-of-distribution examples in neural networks","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Hendrycks"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1090\/chel\/340"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1216\/RMJ-2013-43-1-273"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-61798-0"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1017\/CBO9781107298019"},{"key":"ref26","volume-title":"Testing Statistical Hypotheses","author":"Lehmann","year":"2005"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"key":"ref28","article-title":"Fashion-MNIST: A novel image dataset for benchmarking machine learning algorithms","author":"Xiao","year":"2017","journal-title":"arXiv:1708.07747"},{"key":"ref29","article-title":"Deep learning for classical Japanese literature","author":"Clanuwat","year":"2018","journal-title":"arXiv:1812.01718"},{"key":"ref30","article-title":"EMNIST: An extension of MNIST to handwritten letters","author":"Cohen","year":"2017","journal-title":"arXiv:1702.05373"},{"key":"ref31","volume-title":"Learning Multiple Layers of Features From Tiny Images","author":"Alex","year":"2009"},{"key":"ref32","first-page":"8024","article-title":"PyTorch: An imperative style, high-performance deep learning library","volume-title":"Proc. NIPS","author":"Paszke"},{"key":"ref33","article-title":"Technical report on the CleverHans v2.1.0 adversarial examples library","volume-title":"arXiv:1610.00768","author":"Papernot","year":"2016"},{"key":"ref34","article-title":"Torchattacks: A PyTorch repository for adversarial attacks","author":"Kim","year":"2020","journal-title":"arXiv:2010.01950"},{"key":"ref35","first-page":"2206","article-title":"Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks","volume-title":"Proc. ICML","author":"Croce"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.5555\/1953048.2078195"},{"key":"ref37","first-page":"2201","article-title":"Mind the box: l1-APGD for sparse adversarial attacks on image classifiers","volume-title":"Proc. ICML","author":"Croce"},{"key":"ref38","first-page":"2196","article-title":"Minimally distorted adversarial examples with a fast adaptive boundary attack","volume-title":"Proc. 37th Int. Conf. Mach. Learn.","author":"Croce"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58592-1_29"},{"key":"ref40","first-page":"9229","article-title":"Test-time training with self-supervision for generalization under distribution shifts","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Sun"},{"key":"ref41","article-title":"Learning factored representations in a deep mixture of experts","author":"Eigen","year":"2013","journal-title":"arXiv:1312.4314"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1016\/j.jcp.2020.109409"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1137\/22m1488405"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2023.3347498"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2024.3411035"},{"key":"ref46","article-title":"Optimizing robustness and accuracy in mixture of experts: A dual-model approach","author":"Zhang","year":"2025","journal-title":"arXiv:2502.06832"}],"container-title":["IEEE Transactions on Neural Networks and Learning Systems"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/5962385\/11372199\/11239514.pdf?arnumber=11239514","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,2,9]],"date-time":"2026-02-09T21:07:11Z","timestamp":1770671231000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11239514\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,2]]},"references-count":46,"journal-issue":{"issue":"2"},"URL":"https:\/\/doi.org\/10.1109\/tnnls.2025.3610816","relation":{},"ISSN":["2162-237X","2162-2388"],"issn-type":[{"value":"2162-237X","type":"print"},{"value":"2162-2388","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,2]]}}}