{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,25]],"date-time":"2025-10-25T12:47:49Z","timestamp":1761396469376,"version":"3.37.3"},"reference-count":57,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"Swedish Research Council and by Kjell och M&#x00E4;rta Beijer Foundation"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Signal Process."],"published-print":{"date-parts":[[2023]]},"DOI":"10.1109\/tsp.2023.3246228","type":"journal-article","created":{"date-parts":[[2023,2,17]],"date-time":"2023-02-17T21:09:37Z","timestamp":1676668177000},"page":"601-614","source":"Crossref","is-referenced-by-count":7,"title":["Overparameterized Linear Regression Under Adversarial Attacks"],"prefix":"10.1109","volume":"71","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-3632-8529","authenticated-orcid":false,"given":"Ant\u00f4nio H.","family":"Ribeiro","sequence":"first","affiliation":[{"name":"Department of Information Technology, Uppsala University, Uppsala, Sweden"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5183-234X","authenticated-orcid":false,"given":"Thomas B.","family":"Sch\u00f6n","sequence":"additional","affiliation":[{"name":"Department of Information Technology, Uppsala University, Uppsala, Sweden"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1038\/s41591-021-01614-0"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2018.2869360"},{"article-title":"Unsolved problems in ML safety","year":"2022","author":"Hendrycks","key":"ref3"},{"key":"ref4","article-title":"Intriguing properties of neural networks","volume-title":"Proc. 2nd Int. Conf. Learn. Representations","author":"Bruna","year":"2014"},{"article-title":"Adversarial spheres","year":"2018","author":"Gilmer","key":"ref5"},{"key":"ref6","article-title":"Robustness may be at odds with accuracy","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Tsipras","year":"2019"},{"key":"ref7","first-page":"125","article-title":"Adversarial examples are not bugs, they are features","volume-title":"Proc. 33rd Int. Conf. Neural Inf. Process. Syst.","author":"Ilyas","year":"2019"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1073\/pnas.1907378117"},{"key":"ref9","article-title":"A universal law of robustness via isoperimetry","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Bubeck","year":"2021"},{"key":"ref10","article-title":"Explaining and harnessing adversarial examples","volume-title":"Proc. 3rd Int. Conf. Learn. Representations","author":"Goodfellow","year":"2015"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1214\/21-aos2133"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/isit50566.2022.9834717"},{"key":"ref13","first-page":"2034","article-title":"Precise tradeoffs in adversarial training for linear regression","volume-title":"Proc. 33rd Conf. Learn. Theory","author":"Javanmard","year":"2020"},{"article-title":"The curse of overparametrization in adversarial training: Precise analysis of robust generalization for random features regression","year":"2022","author":"Hassani","key":"ref14"},{"key":"ref15","first-page":"129","article-title":"The curious case of adversarially robust models: More data can help, double descend, or hurt generalization","volume-title":"Proc. 37th Conf. Uncertainty Artif. Intell.","author":"Min","year":"2021"},{"key":"ref16","first-page":"7085","article-title":"Rademacher complexity for adversarially robust generalization","volume-title":"Proc. 36th Int. Conf. Mach. Learn. Res.","author":"Yin","year":"2019"},{"key":"ref17","doi-asserted-by":"crossref","first-page":"195","DOI":"10.1007\/978-3-319-94042-7_11","article-title":"Adversarial attacks and defences competition","volume-title":"Proc. NIPS 17 Competition: Building Intell. Syst.","author":"Kurakin","year":"2018"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1007\/s10994-017-5663-3"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2018.2886017"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1073\/pnas.1903070116"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.06083"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1111\/j.2517-6161.1996.tb02080.x"},{"volume-title":"Probability and Measure Theory","year":"2000","author":"Ash","key":"ref23"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1017\/9781108231596"},{"key":"ref25","doi-asserted-by":"crossref","DOI":"10.1017\/CBO9781107298019","volume-title":"Understanding Mach. Learn.: From Theory to Algorithms","author":"Shalev-Shwartz","year":"2014"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1017\/CBO9780511804441"},{"issue":"83","key":"ref27","first-page":"1","article-title":"CVXPY: A Python-embedded modeling language for convex optimization","volume":"17","author":"Diamond","year":"2016","journal-title":"J. Mach. Learn. Res."},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1145\/1014052.1014066"},{"key":"ref29","first-page":"353","article-title":"Nightmare at test time: Robust learning by feature deletion","volume-title":"Proc. 23rd Int. Conf. Mach. Learn.","author":"Globerson","year":"2006"},{"key":"ref30","first-page":"317","article-title":"Wild patterns: Ten years after the rise of adversarial machine learning","volume-title":"Pattern Recognit.","volume":"84","author":"Biggio","year":"2018"},{"key":"ref31","first-page":"804","article-title":"A law of robustness for two-layers neural networks","volume-title":"Proc. Mach. Learn. Res., Conf. Learn. Theory","author":"Bubeck","year":"2021"},{"key":"ref32","first-page":"6629","article-title":"Most ReLU networks suffer from $\\ell ^{2}$ adversarial perturbations","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Daniely","year":"2020"},{"key":"ref33","first-page":"2021","article-title":"Adversarial examples in multi-layer random ReLU networks","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Bartlett"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1088\/1742-5468\/ac3a74"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1103\/physreve.100.012115"},{"issue":"2","key":"ref36","article-title":"Scaling description of generalization with number of parameters in deep learning","volume-title":"J. Stat. Mechanics: Theory Exp.","volume":"2020","author":"Geiger","year":"2020"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1016\/j.ifacol.2021.08.341"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP40776.2020.9053524"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/JSAIT.2020.2984716"},{"key":"ref40","first-page":"2637","article-title":"Nonlinear random matrix theory for deep learning","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Pennington","year":"2017"},{"key":"ref41","first-page":"1924","article-title":"The emergence of spectral universality in deep networks","volume-title":"Proc. 21st Int. Conf. Artif. Intell. Statist.","author":"Pennington","year":"2018"},{"article-title":"On random matrices arising in deep neural networks. Gaussian Case","year":"2020","author":"Pastur","key":"ref42"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1137\/20M1336072"},{"issue":"4","key":"ref44","first-page":"667","article-title":"The generalization error of random features regression: Precise asymptotics and the double descent curve","volume-title":"Commun. Pure Appl. Math.","volume":"75","author":"Mei","year":"2022"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1016\/j.neunet.2020.08.022"},{"key":"ref46","first-page":"74","article-title":"The neural tangent kernel in high dimensions: Triple descent and a multi-scale theory of generalization","volume-title":"Proc. 37th Int. Conf. Mach. Learn.","author":"Adlam","year":"2020"},{"article-title":"Underspecification presents challenges for credibility in modern machine learning","year":"2020","author":"DAmour","key":"ref47"},{"key":"ref48","first-page":"10380","article-title":"Adversarial risk and robustness: General definitions and implications for the uniform distribution","volume-title":"Proc. 32nd Int. Conf. Neural Inf. Process. Syst.","author":"Diochnos","year":"2018"},{"key":"ref49","first-page":"1646","article-title":"Generalized no free lunch theorem for adversarial robustness","volume-title":"Proc. 36th Int. Conf. Mach. Learn. Res.","author":"Dohmatob","year":"2019"},{"key":"ref50","first-page":"7498","article-title":"Lower bounds on adversarial robustness from optimal transport","volume-title":"Proc. 33rd Int. Conf. Neural Inf. Process. Syst.","author":"Bhagoji","year":"2019"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1214\/22-aos2180"},{"key":"ref52","first-page":"505","article-title":"On the generalization properties of adversarial training","volume-title":"Proc. 24th Int. Conf. Artif. Intell. Statist.","author":"Xing","year":"2021"},{"key":"ref53","article-title":"A convergence theory for deep learning via over-parameterization","volume-title":"Proc. 36th Int. Conf. Mach. Learn.","author":"Allen-Zhu","year":"2019"},{"key":"ref54","first-page":"3040","article-title":"On the global convergence of gradient descent for over-parameterized models using optimal transport","volume-title":"Proc. 32nd Int. Conf. Neural Inf. Process. Syst.","author":"Chizat","year":"2018"},{"key":"ref55","first-page":"1675","article-title":"Gradient descent finds global minima of deep neural networks","volume-title":"Proc. 36th Int. Conf. Mach. Learn. Res.","author":"Du","year":"2019"},{"key":"ref56","article-title":"Neural tangent kernel: Convergence and generalization in neural networks","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Jacot","year":"2018"},{"key":"ref57","first-page":"11427","article-title":"Efficient and accurate estimation of Lipschitz constants for deep neural networks","volume-title":"Proc. 33rd Int. Conf. Neural Inf. Process. Syst.","author":"Fazlyab","year":"2019"}],"container-title":["IEEE Transactions on Signal Processing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/78\/10040758\/10048547.pdf?arnumber=10048547","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,2,13]],"date-time":"2024-02-13T17:59:58Z","timestamp":1707847198000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10048547\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023]]},"references-count":57,"URL":"https:\/\/doi.org\/10.1109\/tsp.2023.3246228","relation":{},"ISSN":["1053-587X","1941-0476"],"issn-type":[{"type":"print","value":"1053-587X"},{"type":"electronic","value":"1941-0476"}],"subject":[],"published":{"date-parts":[[2023]]}}}