{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,3]],"date-time":"2026-06-03T06:03:12Z","timestamp":1780466592117,"version":"3.54.1"},"reference-count":47,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"9","license":[{"start":{"date-parts":[[2025,9,1]],"date-time":"2025-09-01T00:00:00Z","timestamp":1756684800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,9,1]],"date-time":"2025-09-01T00:00:00Z","timestamp":1756684800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,9,1]],"date-time":"2025-09-01T00:00:00Z","timestamp":1756684800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"Horizon Europe projects ELSA","award":["101070617"],"award-info":[{"award-number":["101070617"]}]},{"name":"CoEvolution","award":["101168560"],"award-info":[{"award-number":["101168560"]}]},{"name":"SERICS","award":["PE00000014"],"award-info":[{"award-number":["PE00000014"]}]},{"name":"FAIR","award":["PE00000013"],"award-info":[{"award-number":["PE00000013"]}]},{"name":"MUR NRRP"},{"name":"EU-NGEU"},{"name":"EU-NGEU National Sustainable Mobility Center","award":["CN00000023"],"award-info":[{"award-number":["CN00000023"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Pattern Anal. Mach. Intell."],"published-print":{"date-parts":[[2025,9]]},"DOI":"10.1109\/tpami.2025.3573237","type":"journal-article","created":{"date-parts":[[2025,5,23]],"date-time":"2025-05-23T13:04:30Z","timestamp":1748005470000},"page":"7457-7469","source":"Crossref","is-referenced-by-count":6,"title":["Robustness-Congruent Adversarial Training for Secure Machine Learning Model Updates"],"prefix":"10.1109","volume":"47","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-4008-2314","authenticated-orcid":false,"given":"Daniele","family":"Angioni","sequence":"first","affiliation":[{"name":"Department of Electrical and Electronic Engineering, University of Cagliari, Cagliari, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5104-1476","authenticated-orcid":false,"given":"Luca","family":"Demetrio","sequence":"additional","affiliation":[{"name":"Department of Informatics, Bioengineering, Robotics and Systems Engineering, University of Genova, Genova, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1944-2875","authenticated-orcid":false,"given":"Maura","family":"Pintor","sequence":"additional","affiliation":[{"name":"Department of Electrical and Electronic Engineering, University of Cagliari, Cagliari, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8445-395X","authenticated-orcid":false,"given":"Luca","family":"Oneto","sequence":"additional","affiliation":[{"name":"Department of Informatics, Bioengineering, Robotics and Systems Engineering, University of Genova, Genova, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7523-5291","authenticated-orcid":false,"given":"Davide","family":"Anguita","sequence":"additional","affiliation":[{"name":"Department of Informatics, Bioengineering, Robotics and Systems Engineering, University of Genova, Genova, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7752-509X","authenticated-orcid":false,"given":"Battista","family":"Biggio","sequence":"additional","affiliation":[{"name":"Department of Electrical and Electronic Engineering, University of Cagliari, Cagliari, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4103-9190","authenticated-orcid":false,"given":"Fabio","family":"Roli","sequence":"additional","affiliation":[{"name":"Department of Electrical and Electronic Engineering, University of Cagliari, Cagliari, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01407"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-40994-3_25"},{"key":"ref3","article-title":"Intriguing properties of neural networks","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Szegedy"},{"key":"ref4","article-title":"RobustBench: A standardized adversarial robustness benchmark","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Croce"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.06083"},{"key":"ref6","article-title":"On evaluating adversarial robustness","author":"Carlini","year":"2019"},{"key":"ref7","first-page":"20052","article-title":"Fast minimum-norm adversarial attacks through adaptive norm constraints","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Pintor"},{"key":"ref8","first-page":"2206","article-title":"Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Croce"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1007\/978-0-387-84858-7"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2022.07.010"},{"key":"ref11","volume-title":"Deep Learning","author":"Goodfellow","year":"2016"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-94463-0"},{"issue":"1","key":"ref13","first-page":"1929","article-title":"Dropout: A simple way to prevent neural networks from overfitting","volume":"15","author":"Srivastava","year":"2014","journal-title":"J. Mach. Learn. Res."},{"key":"ref14","first-page":"463","article-title":"Rademacher and Gaussian complexities: Risk bounds and structural results","volume":"3","author":"Bartlett","year":"2002","journal-title":"J. Mach. Learn. Res."},{"key":"ref15","first-page":"7085","article-title":"Rademacher complexity for adversarially robust generalization","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Yin"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1145\/2897518.2897566"},{"key":"ref17","first-page":"1232","article-title":"Controlling bias in adaptive data analysis using information theory","volume-title":"Proc. 19th Int. Conf. Artif. Intell. Statist.","author":"Russo"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1017\/CBO9781107298019"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1142\/SAM"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1007\/s10994-015-5540-x"},{"key":"ref21","article-title":"Robustness (Python library)","author":"Engstrom","year":"2019"},{"key":"ref22","first-page":"11278","article-title":"Attacks which do not kill training make adversarial learning stronger","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Zhang"},{"key":"ref23","first-page":"8093","article-title":"Overfitting in adversarially robust deep learning","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Rice"},{"key":"ref24","article-title":"Helper-based adversarial training: Reducing excessive margin to achieve a better accuracy vs. robustness trade-off","volume-title":"Proc. ICML Workshop Adversarial Mach. Learn.","author":"Rade"},{"key":"ref25","first-page":"2712","article-title":"Using pre-training can improve model robustness and uncertainty","volume-title":"Proc. 36th Int. Conf. Mach. Learn.","author":"Hendrycks"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-20065-6_18"},{"key":"ref27","first-page":"11190","article-title":"Unlabeled data improves adversarial robustness","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Carmon"},{"key":"ref28","article-title":"Do adversarially robust ImageNet models transfer better?","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Salman"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2024.110394"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-024-02196-3"},{"key":"ref31","article-title":"Fast is better than free: Revisiting adversarial training","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Wong"},{"key":"ref32","article-title":"Explaining and harnessing adversarial examples","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Goodfellow"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-01581-6"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2021.3057446"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1073\/pnas.1611835114"},{"key":"ref36","article-title":"An empirical study of example forgetting during deep neural network learning","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Toneva"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00088"},{"key":"ref38","article-title":"Continual learning with tiny episodic memories","volume-title":"Proc. Workshop Multi-Task Lifelong Reinforcement Learn.","author":"Chaudhry"},{"key":"ref39","first-page":"4394","article-title":"Uncertainty-based continual learning with adaptive regularization","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Ahn"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00025"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00810"},{"key":"ref42","first-page":"4548","article-title":"Overcoming catastrophic forgetting with hard attention to the task","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Serra"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/tpami.2024.3392724"},{"key":"ref44","first-page":"116","article-title":"Backward-compatible prediction updates: A probabilistic approach","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Tr\u00e4uble"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00640"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1145\/3394486.3403379"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1162\/neco.1996.8.7.1341"}],"container-title":["IEEE Transactions on Pattern Analysis and Machine Intelligence"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/34\/11118328\/11014530.pdf?arnumber=11014530","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,7]],"date-time":"2025-08-07T17:44:14Z","timestamp":1754588654000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11014530\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,9]]},"references-count":47,"journal-issue":{"issue":"9"},"URL":"https:\/\/doi.org\/10.1109\/tpami.2025.3573237","relation":{},"ISSN":["0162-8828","2160-9292","1939-3539"],"issn-type":[{"value":"0162-8828","type":"print"},{"value":"2160-9292","type":"electronic"},{"value":"1939-3539","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,9]]}}}