{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,16]],"date-time":"2026-07-16T14:49:55Z","timestamp":1784213395244,"version":"3.55.0"},"reference-count":296,"publisher":"Association for Computing Machinery (ACM)","issue":"8","license":[{"start":{"date-parts":[[2022,12,23]],"date-time":"2022-12-23T00:00:00Z","timestamp":1671753600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Comput. Surv."],"published-print":{"date-parts":[[2023,8,31]]},"abstract":"<jats:p>\n            The open-world deployment of Machine Learning (ML) algorithms in safety-critical applications such as autonomous vehicles needs to address a variety of ML vulnerabilities such as interpretability, verifiability, and performance limitations. Research explores different approaches to improve ML dependability by proposing new models and training techniques to reduce generalization error, achieve domain adaptation, and detect outlier examples and adversarial attacks. However, there is a missing connection between ongoing ML research and well-established safety principles. In this article, we present a structured and comprehensive review of ML techniques to improve the dependability of ML algorithms in uncontrolled open-world settings. From this review, we propose the\n            <jats:italic>Taxonomy of ML Safety<\/jats:italic>\n            that maps state-of-the-art ML techniques to key engineering safety strategies. Our taxonomy of ML safety presents a safety-oriented categorization of ML techniques to provide guidance for improving dependability of the ML design and development. The proposed taxonomy can serve as a safety checklist to aid designers in improving coverage and diversity of safety strategies employed in any given ML system.\n          <\/jats:p>","DOI":"10.1145\/3551385","type":"journal-article","created":{"date-parts":[[2022,7,27]],"date-time":"2022-07-27T11:22:21Z","timestamp":1658920941000},"page":"1-38","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":46,"title":["Taxonomy of Machine Learning Safety: A Survey and Primer"],"prefix":"10.1145","volume":"55","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-2747-2377","authenticated-orcid":false,"given":"Sina","family":"Mohseni","sequence":"first","affiliation":[{"name":"NVIDIA, Santa Clara, CA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0626-2058","authenticated-orcid":false,"given":"Haotao","family":"Wang","sequence":"additional","affiliation":[{"name":"The University of Texas at Austin, Austin, TX, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7043-4926","authenticated-orcid":false,"given":"Chaowei","family":"Xiao","sequence":"additional","affiliation":[{"name":"NVIDIA, Santa Clara, CA, USA and Arizona State University (ASU)"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1776-996X","authenticated-orcid":false,"given":"Zhiding","family":"Yu","sequence":"additional","affiliation":[{"name":"NVIDIA, Santa Clara, CA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2050-5693","authenticated-orcid":false,"given":"Zhangyang","family":"Wang","sequence":"additional","affiliation":[{"name":"The University of Texas at Austin, Austin, TX, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6636-0226","authenticated-orcid":false,"given":"Jay","family":"Yadawa","sequence":"additional","affiliation":[{"name":"NVIDIA, Santa Clara, CA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2022,12,23]]},"reference":[{"key":"e_1_3_1_2_2","volume-title":"Advances in Neural Information Processing Systems","author":"Adebayo Julius","year":"2018","unstructured":"Julius Adebayo, Justin Gilmer, Michael Muelly, Ian Goodfellow, Moritz Hardt, and Been Kim. 2018. Sanity checks for saliency maps. In Advances in Neural Information Processing Systems."},{"key":"e_1_3_1_3_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10916-018-0983-9"},{"key":"e_1_3_1_4_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE-SEIP.2019.00042"},{"key":"e_1_3_1_5_2","article-title":"Concrete problems in AI safety","author":"Amodei Dario","year":"2016","unstructured":"Dario Amodei, Chris Olah, Jacob Steinhardt, Paul Christiano, John Schulman, and Dan Man\u00e9. 2016. Concrete problems in AI safety. arXiv:1606.06565. Retrieved from https:\/\/arxiv.org\/abs\/1606.06565.","journal-title":"arXiv:1606.06565"},{"key":"e_1_3_1_6_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.inffus.2019.12.012"},{"key":"e_1_3_1_7_2","article-title":"Assuring the machine learning lifecycle: Desiderata, methods, and challenges","author":"Ashmore Rob","year":"2021","unstructured":"Rob Ashmore, Radu Calinescu, and Colin Paterson. 2021. Assuring the machine learning lifecycle: Desiderata, methods, and challenges. ACM Comput. Surv. (2021).","journal-title":"ACM Comput. Surv."},{"key":"e_1_3_1_8_2","first-page":"274","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Athalye Anish","year":"2018","unstructured":"Anish Athalye, Nicholas Carlini, and David Wagner. 2018. Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples. In Proceedings of the International Conference on Machine Learning. 274\u2013283."},{"key":"e_1_3_1_9_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00845"},{"key":"e_1_3_1_10_2","doi-asserted-by":"publisher","DOI":"10.1371\/journal.pone.0130140"},{"key":"e_1_3_1_11_2","volume-title":"Advances in Neural Information Processing Systems","author":"Bai Yutong","year":"2021","unstructured":"Yutong Bai, Jieru Mei, Alan L. Yuille, and Cihang Xie. 2021. Are transformers more robust than CNNs? In Advances in Neural Information Processing Systems."},{"key":"e_1_3_1_12_2","first-page":"1006","volume-title":"Advances in Neural Information Processing Systems","author":"Balaji Yogesh","year":"2018","unstructured":"Yogesh Balaji, Swami Sankaranarayanan, and Rama Chellappa. 2018. Metareg: Towards domain generalization using meta-regularization. In Advances in Neural Information Processing Systems. 1006\u20131016."},{"key":"e_1_3_1_13_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v32i1.11493"},{"key":"e_1_3_1_14_2","doi-asserted-by":"publisher","DOI":"10.5555\/3327144.3327339"},{"key":"e_1_3_1_15_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-75632-5_5"},{"key":"e_1_3_1_16_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00976"},{"key":"e_1_3_1_17_2","article-title":"Classification-based anomaly detection for general data","author":"Bergman Liron","year":"2020","unstructured":"Liron Bergman and Yedid Hoshen. 2020. Classification-based anomaly detection for general data. arXiv:2005.02359. Retrieved from https:\/\/arxiv.org\/abs\/2005.02359.","journal-title":"arXiv:2005.02359"},{"key":"e_1_3_1_18_2","article-title":"Are we done with ImageNet?","author":"Beyer Lucas","year":"2020","unstructured":"Lucas Beyer, Olivier J H\u00e9naff, Alexander Kolesnikov, Xiaohua Zhai, and A\u00e4ron van den Oord. 2020. Are we done with ImageNet? arXiv:2006.07159. Retrieved from https:\/\/arxiv.org\/abs\/2006.07159.","journal-title":"arXiv:2006.07159"},{"key":"e_1_3_1_19_2","article-title":"Understanding robustness of transformers for image classification","author":"Bhojanapalli Srinadh","year":"2021","unstructured":"Srinadh Bhojanapalli, Ayan Chakrabarti, Daniel Glasner, Daliang Li, Thomas Unterthiner, and Andreas Veit. 2021. Understanding robustness of transformers for image classification. arXiv:2103.14586. Retrieved from https:\/\/arxiv.org\/abs\/2103.14586.","journal-title":"arXiv:2103.14586"},{"key":"e_1_3_1_20_2","article-title":"Yolov4: Optimal speed and accuracy of object detection","author":"Bochkovskiy Alexey","year":"2020","unstructured":"Alexey Bochkovskiy, Chien-Yao Wang, and Hong-Yuan Mark Liao. 2020. Yolov4: Optimal speed and accuracy of object detection. arXiv:2004.10934. Retrieved from https:\/\/arxiv.org\/abs\/2004.10934.","journal-title":"arXiv:2004.10934"},{"key":"e_1_3_1_21_2","volume-title":"Proceedings of the IEEE International Conference on Robotics and Automation","author":"Bojarski Mariusz","unstructured":"Mariusz Bojarski, Anna Choromanska, Krzysztof Choromanski, Bernhard Firner, Larry J. Ackel, Urs Muller, Phil Yeres, and Karol Zieba. [n.d.]. Visualbackprop: Efficient visualization of cnns for autonomous driving. In Proceedings of the IEEE International Conference on Robotics and Automation."},{"key":"e_1_3_1_22_2","doi-asserted-by":"publisher","DOI":"10.1007\/s13042-017-0645-0"},{"key":"e_1_3_1_23_2","article-title":"Openai gym","author":"Brockman Greg","year":"2016","unstructured":"Greg Brockman, Vicki Cheung, Ludwig Pettersson, Jonas Schneider, John Schulman, Jie Tang, and Wojciech Zaremba. 2016. Openai gym. arXiv:1606.01540. Retrieved from https:\/\/arxiv.org\/abs\/1606.01540.","journal-title":"arXiv:1606.01540"},{"key":"e_1_3_1_24_2","article-title":"Adversarial patch","author":"Brown Tom B.","year":"2017","unstructured":"Tom B. Brown, Dandelion Man\u00e9, Aurko Roy, Mart\u00edn Abadi, and Justin Gilmer. 2017. Adversarial patch. arXiv:1712.09665. Retrieved from https:\/\/arxiv.org\/abs\/1712.09665.","journal-title":"arXiv:1712.09665"},{"key":"e_1_3_1_25_2","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140444"},{"key":"e_1_3_1_26_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v28i1.8990"},{"key":"e_1_3_1_27_2","volume-title":"Advances in Neural Information Processing Systems","author":"Chan Robin","year":"2021","unstructured":"Robin Chan, Krzysztof Lis, Svenja Uhlemeyer, Hermann Blum, Sina Honari, Roland Siegwart, Pascal Fua, Mathieu Salzmann, and Matthias Rottmann. 2021. SegmentMeIfYouCan: A benchmark for anomaly segmentation. In Advances in Neural Information Processing Systems."},{"key":"e_1_3_1_28_2","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Chang Nadine","year":"2021","unstructured":"Nadine Chang, Zhiding Yu, Yu-Xiong Wang, Animashree Anandkumar, Sanja Fidler, and Jose M. Alvarez. 2021. Image-level or object-level? A tale of two resampling strategies for long-tailed detection. In Proceedings of the International Conference on Machine Learning."},{"key":"e_1_3_1_29_2","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Chen Beidi","year":"2020","unstructured":"Beidi Chen, Weiyang Liu, Zhiding Yu, Jan Kautz, Anshumali Shrivastava, Animesh Garg, and Animashree Anandkumar. 2020. Angular visual hardness. In Proceedings of the International Conference on Machine Learning."},{"key":"e_1_3_1_30_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58601-0_5"},{"key":"e_1_3_1_31_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-86523-8_26"},{"key":"e_1_3_1_32_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00078"},{"key":"e_1_3_1_33_2","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Choi Sungik","year":"2020","unstructured":"Sungik Choi and Sae-Young Chung. 2020. Novelty detection via blurring. In Proceedings of the International Conference on Learning Representations."},{"key":"e_1_3_1_34_2","article-title":"Concepts of design assurance for neural networks (CoDANN)","author":"Cluzeau J. M.","year":"2020","unstructured":"J. M. Cluzeau, X. Henriquel, G. Rebender, G. Soudain, L. van Dijk, A. Gronskiy, D. Haber, C. Perret-Gentil, and R. Polak. 2020. Concepts of design assurance for neural networks (CoDANN). Public Report Extract Version 1.0 (2020).","journal-title":"Public Report Extract Version 1.0"},{"key":"e_1_3_1_35_2","volume-title":"Functional Safety of Electrical\/Electronic\/Programmable Electronic Safety-related Systems","author":"Commission International Electrotechnical","year":"2000","unstructured":"International Electrotechnical Commission. 2000. Functional Safety of Electrical\/Electronic\/Programmable Electronic Safety-related Systems. Technical Report."},{"key":"e_1_3_1_36_2","article-title":"Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks","author":"Croce Francesco","year":"2020","unstructured":"Francesco Croce and Matthias Hein. 2020. Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks. arXiv:2003.01690. Retrieved from https:\/\/arxiv.org\/abs\/2003.01690.","journal-title":"arXiv:2003.01690"},{"key":"e_1_3_1_37_2","article-title":"Autoaugment: Learning augmentation policies from data","author":"Cubuk Ekin D.","year":"2018","unstructured":"Ekin D. Cubuk, Barret Zoph, Dandelion Mane, Vijay Vasudevan, and Quoc V. Le. 2018. Autoaugment: Learning augmentation policies from data. arXiv:1805.09501. Retrieved from https:\/\/arxiv.org\/abs\/1805.09501.","journal-title":"arXiv:1805.09501"},{"key":"e_1_3_1_38_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW50498.2020.00359"},{"key":"e_1_3_1_39_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cviu.2017.10.001"},{"key":"e_1_3_1_40_2","article-title":"Keeping the bad guys out: Protecting and vaccinating deep learning with jpeg compression","author":"Das Nilaksh","year":"2017","unstructured":"Nilaksh Das, Madhuri Shanbhogue, Shang-Tse Chen, Fred Hohman, Li Chen, Michael E. Kounavis, and Duen Horng Chau. 2017. Keeping the bad guys out: Protecting and vaccinating deep learning with jpeg compression. arXiv:1705.02900. Retrieved from https:\/\/arxiv.org\/abs\/1705.02900.","journal-title":"arXiv:1705.02900"},{"key":"e_1_3_1_41_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"e_1_3_1_42_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.strusafe.2008.06.020"},{"key":"e_1_3_1_43_2","volume-title":"Proceedings of the International Conference on Learning Representations","author":"DeVries Terrance","year":"2018","unstructured":"Terrance DeVries and Graham W Taylor. 2018. Learning confidence for out-of-distribution detection in neural networks. In Proceedings of the International Conference on Learning Representations."},{"key":"e_1_3_1_44_2","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Ding Gavin Weiguang","year":"2020","unstructured":"Gavin Weiguang Ding, Yash Sharma, Kry Yik Chau Lui, and Ruitong Huang. 2020. MMA training: Direct input space margin maximization through adversarial training. In Proceedings of the International Conference on Learning Representations."},{"key":"e_1_3_1_45_2","article-title":"On robustness and transferability of convolutional neural networks","author":"Djolonga Josip","year":"2020","unstructured":"Josip Djolonga, Jessica Yung, Michael Tschannen, Rob Romijnders, Lucas Beyer, Alexander Kolesnikov, Joan Puigcerver, Matthias Minderer, Alexander D\u2019Amour, Dan Moldovan, et\u00a0al. 2020. On robustness and transferability of convolutional neural networks. arXiv:2007.08558. Retrieved from https:\/\/arxiv.org\/abs\/2007.08558.","journal-title":"arXiv:2007.08558"},{"key":"e_1_3_1_46_2","article-title":"Towards a rigorous science of interpretable machine learning","author":"Doshi-Velez Finale","year":"2017","unstructured":"Finale Doshi-Velez and Been Kim. 2017. Towards a rigorous science of interpretable machine learning. arXiv:1702.08608. Retrieved from https:\/\/arxiv.org\/abs\/1702.08608.","journal-title":"arXiv:1702.08608"},{"key":"e_1_3_1_47_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10817-018-09509-5"},{"key":"e_1_3_1_48_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-25540-4_25"},{"key":"e_1_3_1_49_2","article-title":"A formalization of robustness for deep neural networks","author":"Dreossi Tommaso","year":"2019","unstructured":"Tommaso Dreossi, Shromona Ghosh, Alberto Sangiovanni-Vincentelli, and Sanjit A. Seshia. 2019. A formalization of robustness for deep neural networks. arXiv:1903.10033. Retrieved from https:\/\/arxiv.org\/abs\/1903.10033.","journal-title":"arXiv:1903.10033"},{"key":"e_1_3_1_50_2","doi-asserted-by":"publisher","DOI":"10.5555\/3304889.3304947"},{"key":"e_1_3_1_51_2","first-page":"3608","volume-title":"Advances in Neural Information Processing Systems","author":"Du Yilun","year":"2019","unstructured":"Yilun Du and Igor Mordatch. 2019. Implicit generation and modeling with energy based models. In Advances in Neural Information Processing Systems. 3608\u20133618."},{"key":"e_1_3_1_52_2","volume-title":"NASA Formal Methods Symposium","author":"Dutta Souradeep","year":"2018","unstructured":"Souradeep Dutta, Susmit Jha, Sriram Sankaranarayanan, and Ashish Tiwari. 2018. Output range analysis for deep feedforward neural networks. In NASA Formal Methods Symposium. Springer."},{"key":"e_1_3_1_53_2","article-title":"Training verified learners with learned verifiers","author":"Dvijotham Krishnamurthy","year":"2018","unstructured":"Krishnamurthy Dvijotham, Sven Gowal, Robert Stanforth, Relja Arandjelovic, Brendan O\u2019Donoghue, Jonathan Uesato, and Pushmeet Kohli. 2018. Training verified learners with learned verifiers. arXiv:1805.10265. Retrieved from https:\/\/arxiv.org\/abs\/1805.10265.","journal-title":"arXiv:1805.10265"},{"key":"e_1_3_1_54_2","article-title":"Detecting adversarial samples from artifacts","author":"Feinman Reuben","year":"2017","unstructured":"Reuben Feinman, Ryan R. Curtin, Saurabh Shintre, and Andrew B. Gardner. 2017. Detecting adversarial samples from artifacts. arXiv:1703.00410. Retrieved from https:\/\/arxiv.org\/abs\/1703.00410.","journal-title":"arXiv:1703.00410"},{"key":"e_1_3_1_55_2","article-title":"Distributionally robust deep learning using hardness weighted sampling","author":"Fidon Lucas","year":"2020","unstructured":"Lucas Fidon, Sebastien Ourselin, and Tom Vercauteren. 2020. Distributionally robust deep learning using hardness weighted sampling. arXiv:2001.02658. Retrieved from https:\/\/arxiv.org\/abs\/2001.02658.","journal-title":"arXiv:2001.02658"},{"key":"e_1_3_1_56_2","volume-title":"ISO 26262: Road Vehicles\u2013Functional Safety","author":"Standardization International Organization for","year":"2011","unstructured":"International Organization for Standardization. 2011. ISO 26262: Road Vehicles\u2013Functional Safety. Technical Report."},{"key":"e_1_3_1_57_2","volume-title":"ISO\/PAS 21448: Road Vehicles\u2013Safety of the Intended Functionality","author":"Standardization International Organization for","year":"2019","unstructured":"International Organization for Standardization. 2019. ISO\/PAS 21448: Road Vehicles\u2013Safety of the Intended Functionality. Technical Report."},{"key":"e_1_3_1_58_2","volume-title":"Advances in Neural Information Processing Systems","author":"Fort Stanislav","year":"2021","unstructured":"Stanislav Fort, Jie Ren, and Balaji Lakshminarayanan. 2021. Exploring the limits of out-of-distribution detection. In Advances in Neural Information Processing Systems."},{"key":"e_1_3_1_59_2","doi-asserted-by":"publisher","DOI":"10.1109\/ITSC45102.2020.9294368"},{"key":"e_1_3_1_60_2","volume-title":"Uncertainty in Deep Learning","author":"Gal Yarin","year":"2016","unstructured":"Yarin Gal. 2016. Uncertainty in Deep Learning. Ph.D. Dissertation. University of Cambridge."},{"key":"e_1_3_1_61_2","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Gal Yarin","year":"2016","unstructured":"Yarin Gal and Zoubin Ghahramani. 2016. Dropout as a bayesian approximation: Representing model uncertainty in deep learning. In Proceedings of the International Conference on Machine Learning."},{"key":"e_1_3_1_62_2","volume-title":"Advances in Neural Information Processing Systems","author":"Gal Yarin","year":"2017","unstructured":"Yarin Gal, Jiri Hron, and Alex Kendall. 2017. Concrete dropout. In Advances in Neural Information Processing Systems."},{"key":"e_1_3_1_63_2","first-page":"1183","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Gal Yarin","year":"2017","unstructured":"Yarin Gal, Riashat Islam, and Zoubin Ghahramani. 2017. Deep bayesian active learning with image data. In Proceedings of the International Conference on Machine Learning. 1183\u20131192."},{"key":"e_1_3_1_64_2","article-title":"Unsupervised domain adaptation by backpropagation","author":"Ganin Yaroslav","year":"2014","unstructured":"Yaroslav Ganin and Victor Lempitsky. 2014. Unsupervised domain adaptation by backpropagation. arXiv:1409.7495. Retrieved from https:\/\/arxiv.org\/abs\/1409.7495.","journal-title":"arXiv:1409.7495"},{"key":"e_1_3_1_65_2","first-page":"13029","volume-title":"Advances in Neural Information Processing Systems","author":"Gao Ruiqi","year":"2019","unstructured":"Ruiqi Gao, Tianle Cai, Haochuan Li, Cho-Jui Hsieh, Liwei Wang, and Jason D Lee. 2019. Convergence of adversarial training in overparametrized neural networks. In Advances in Neural Information Processing Systems. 13029\u201313040."},{"key":"e_1_3_1_66_2","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Garg Saurabh","year":"2022","unstructured":"Saurabh Garg, Sivaraman Balakrishnan, Zachary C. Lipton, Behnam Neyshabur, and Hanie Sedghi. 2022. Leveraging unlabeled data to predict out-of-distribution performance. In Proceedings of the International Conference on Learning Representations."},{"key":"e_1_3_1_67_2","first-page":"4878","volume-title":"Advances in Neural Information Processing Systems","author":"Geifman Yonatan","year":"2017","unstructured":"Yonatan Geifman and Ran El-Yaniv. 2017. Selective classification for deep neural networks. In Advances in Neural Information Processing Systems. 4878\u20134887."},{"key":"e_1_3_1_68_2","article-title":"SelectiveNet: A deep neural network with an integrated reject option","author":"Geifman Yonatan","year":"2019","unstructured":"Yonatan Geifman and Ran El-Yaniv. 2019. SelectiveNet: A deep neural network with an integrated reject option. arXiv:1901.09192. Retrieved from https:\/\/arxiv.org\/abs\/1901.09192.","journal-title":"arXiv:1901.09192"},{"key":"e_1_3_1_69_2","article-title":"ImageNet-trained CNNs are biased towards texture; increasing shape bias improves accuracy and robustness","author":"Geirhos Robert","year":"2018","unstructured":"Robert Geirhos, Patricia Rubisch, Claudio Michaelis, Matthias Bethge, Felix A. Wichmann, and Wieland Brendel. 2018. ImageNet-trained CNNs are biased towards texture; increasing shape bias improves accuracy and robustness. arXiv:1811.12231. Retrieved from https:\/\/arxiv.org\/abs\/1811.12231.","journal-title":"arXiv:1811.12231"},{"key":"e_1_3_1_70_2","first-page":"9277","volume-title":"Advances in Neural Information Processing Systems","author":"Ghorbani Amirata","year":"2019","unstructured":"Amirata Ghorbani, James Wexler, James Y. Zou, and Been Kim. 2019. Towards automatic concept-based explanations. In Advances in Neural Information Processing Systems, Vol. 32. 9277\u20139286."},{"key":"e_1_3_1_71_2","first-page":"9758","volume-title":"Advances in Neural Information Processing Systems","author":"Golan Izhak","year":"2018","unstructured":"Izhak Golan and Ran El-Yaniv. 2018. Deep anomaly detection using geometric transformations. In Advances in Neural Information Processing Systems. 9758\u20139769."},{"key":"e_1_3_1_72_2","volume-title":"Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition","author":"Gong Chengyue","year":"2021","unstructured":"Chengyue Gong, Tongzheng Ren, Mao Ye, and Qiang Liu. 2021. MaxUp: A simple way to improve generalization of neural network training. In Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition."},{"key":"e_1_3_1_73_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00258"},{"key":"e_1_3_1_74_2","article-title":"Adversarial and clean data are not twins","author":"Gong Zhitao","year":"2017","unstructured":"Zhitao Gong, Wenlu Wang, and Wei-Shinn Ku. 2017. Adversarial and clean data are not twins. arXiv:1704.04960. Retrieved from https:\/\/arxiv.org\/abs\/1704.04960.","journal-title":"arXiv:1704.04960"},{"key":"e_1_3_1_75_2","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Goodfellow Ian J.","year":"2015","unstructured":"Ian J. Goodfellow, Jonathon Shlens, and Christian Szegedy. 2015. Explaining and harnessing adversarial examples. In Proceedings of the International Conference on Learning Representations."},{"key":"e_1_3_1_76_2","doi-asserted-by":"publisher","DOI":"10.1609\/aimag.v38i3.2741"},{"key":"e_1_3_1_77_2","article-title":"On the effectiveness of interval bound propagation for training verifiably robust models","author":"Gowal Sven","year":"2018","unstructured":"Sven Gowal, Krishnamurthy Dvijotham, Robert Stanforth, Rudy Bunel, Chongli Qin, Jonathan Uesato, Timothy Mann, and Pushmeet Kohli. 2018. On the effectiveness of interval bound propagation for training verifiably robust models. arXiv:1810.12715. Retrieved from https:\/\/arxiv.org\/abs\/1810.12715.","journal-title":"arXiv:1810.12715"},{"key":"e_1_3_1_78_2","volume-title":"Proceedings of the 37th International Conference on Machine Learning","author":"Goyal Sachin","year":"2020","unstructured":"Sachin Goyal, Aditi Raghunathan, Moksh Jain, Harsha Vardhan Simhadri, and Prateek Jain. 2020. DROCC: Deep robust one-class classification. In Proceedings of the 37th International Conference on Machine Learning."},{"key":"e_1_3_1_79_2","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Grathwohl Will","year":"2019","unstructured":"Will Grathwohl, Kuan-Chieh Wang, Joern-Henrik Jacobsen, David Duvenaud, Mohammad Norouzi, and Kevin Swersky. 2019. Your classifier is secretly an energy based model and you should treat it like one. In Proceedings of the International Conference on Learning Representations."},{"key":"e_1_3_1_80_2","article-title":"On the (statistical) detection of adversarial examples","author":"Grosse Kathrin","year":"2017","unstructured":"Kathrin Grosse, Praveen Manoharan, Nicolas Papernot, Michael Backes, and Patrick McDaniel. 2017. On the (statistical) detection of adversarial examples. arXiv:1702.06280. Retrieved from https:\/\/arxiv.org\/abs\/1702.06280.","journal-title":"arXiv:1702.06280"},{"key":"e_1_3_1_81_2","volume-title":"Advances in Neural Information Processing Systems","author":"Gui Shupeng","year":"2019","unstructured":"Shupeng Gui, Haotao Wang, Haichuan Yang, Chen Yu, Zhangyang Wang, and Ji Liu. 2019. Model compression with adversarial robustness: A unified optimization framework. In Advances in Neural Information Processing Systems."},{"key":"e_1_3_1_82_2","article-title":"Local rule-based explanations of black box decision systems","author":"Guidotti Riccardo","year":"2018","unstructured":"Riccardo Guidotti, Anna Monreale, Salvatore Ruggieri, Dino Pedreschi, Franco Turini, and Fosca Giannotti. 2018. Local rule-based explanations of black box decision systems. arXiv:1805.10820. Retrieved from https:\/\/arxiv.org\/abs\/1805.10820.","journal-title":"arXiv:1805.10820"},{"key":"e_1_3_1_83_2","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Guo Chuan","year":"2017","unstructured":"Chuan Guo, Geoff Pleiss, Yu Sun, and Kilian Q. Weinberger. 2017. On calibration of modern neural networks. In Proceedings of the International Conference on Machine Learning."},{"key":"e_1_3_1_84_2","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Guo Chuan","year":"2018","unstructured":"Chuan Guo, Mayank Rana, Moustapha Cisse, and Laurens van der Maaten. 2018. Countering adversarial images using input transformations. In Proceedings of the International Conference on Learning Representations."},{"key":"e_1_3_1_85_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00071"},{"key":"e_1_3_1_86_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2016.12.035"},{"key":"e_1_3_1_87_2","volume-title":"Advances in Neural Information Processing Systems","author":"Han Bo","year":"2018","unstructured":"Bo Han, Quanming Yao, Xingrui Yu, Gang Niu, Miao Xu, Weihua Hu, Ivor Tsang, and Masashi Sugiyama. 2018. Co-teaching: Robust training of deep neural networks with extremely noisy labels. In Advances in Neural Information Processing Systems."},{"key":"e_1_3_1_88_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00524"},{"key":"e_1_3_1_89_2","doi-asserted-by":"publisher","DOI":"10.1109\/IV47402.2020.9304793"},{"key":"e_1_3_1_90_2","article-title":"Guidance on the assurance of machine learning in autonomous systems (AMLAS)","author":"Hawkins Richard","year":"2021","unstructured":"Richard Hawkins, Colin Paterson, Chiara Picardi, Yan Jia, Radu Calinescu, and Ibrahim Habli. 2021. Guidance on the assurance of machine learning in autonomous systems (AMLAS). arXiv:2102.01564. Retrieved from https:\/\/arxiv.org\/abs\/2102.01564.","journal-title":"arXiv:2102.01564"},{"key":"e_1_3_1_91_2","article-title":"Why ReLU networks yield high-confidence predictions far away from the training data and how to mitigate the problem","author":"Hein Matthias","year":"2019","unstructured":"Matthias Hein, Maksym Andriushchenko, and Julian Bitterwolf. 2019. Why ReLU networks yield high-confidence predictions far away from the training data and how to mitigate the problem. arXiv:1812.05720. Retrieved from https:\/\/arxiv.org\/abs\/1812.05720.","journal-title":"arXiv:1812.05720"},{"key":"e_1_3_1_92_2","article-title":"Scaling out-of-distribution detection for real-world settings","author":"Hendrycks Dan","year":"2019","unstructured":"Dan Hendrycks, Steven Basart, Mantas Mazeika, Mohammadreza Mostajabi, Jacob Steinhardt, and Dawn Song. 2019. Scaling out-of-distribution detection for real-world settings. arXiv:1911.11132. Retrieved from https:\/\/arxiv.org\/abs\/1911.11132.","journal-title":"arXiv:1911.11132"},{"key":"e_1_3_1_93_2","article-title":"The many faces of robustness: A critical analysis of out-of-distribution generalization","author":"Hendrycks Dan","year":"2020","unstructured":"Dan Hendrycks, Steven Basart, Norman Mu, Saurav Kadavath, Frank Wang, Evan Dorundo, Rahul Desai, Tyler Zhu, Samyak Parajuli, Mike Guo, et\u00a0al. 2020. The many faces of robustness: A critical analysis of out-of-distribution generalization. arXiv:2006.16241. Retrieved from https:\/\/arxiv.org\/abs\/2006.16241.","journal-title":"arXiv:2006.16241"},{"key":"e_1_3_1_94_2","article-title":"Unsolved problems in ml safety","author":"Hendrycks Dan","year":"2021","unstructured":"Dan Hendrycks, Nicholas Carlini, John Schulman, and Jacob Steinhardt. 2021. Unsolved problems in ml safety. arXiv:2109.13916. Retrieved from https:\/\/arxiv.org\/abs\/2109.13916.","journal-title":"arXiv:2109.13916"},{"key":"e_1_3_1_95_2","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Hendrycks Dan","year":"2019","unstructured":"Dan Hendrycks and Thomas Dietterich. 2019. Benchmarking neural network robustness to common corruptions and perturbations. In Proceedings of the International Conference on Learning Representations."},{"key":"e_1_3_1_96_2","article-title":"A baseline for detecting misclassified and out-of-distribution examples in neural networks","author":"Hendrycks Dan","year":"2016","unstructured":"Dan Hendrycks and Kevin Gimpel. 2016. A baseline for detecting misclassified and out-of-distribution examples in neural networks. arXiv:1610.02136. Retrieved from https:\/\/arxiv.org\/abs\/1610.02136.","journal-title":"arXiv:1610.02136"},{"key":"e_1_3_1_97_2","article-title":"Early methods for detecting adversarial images","author":"Hendrycks Dan","year":"2016","unstructured":"Dan Hendrycks and Kevin Gimpel. 2016. Early methods for detecting adversarial images. arXiv:1608.00530. Retrieved from https:\/\/arxiv.org\/abs\/1608.00530.","journal-title":"arXiv:1608.00530"},{"key":"e_1_3_1_98_2","article-title":"Using pre-training can improve model robustness and uncertainty","author":"Hendrycks Dan","year":"2019","unstructured":"Dan Hendrycks, Kimin Lee, and Mantas Mazeika. 2019. Using pre-training can improve model robustness and uncertainty. arXiv:1901.09960. Retrieved from https:\/\/arxiv.org\/abs\/1901.09960.","journal-title":"arXiv:1901.09960"},{"key":"e_1_3_1_99_2","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Hendrycks Dan","year":"2018","unstructured":"Dan Hendrycks, Mantas Mazeika, and Thomas Dietterich. 2018. Deep anomaly detection with outlier exposure. In Proceedings of the International Conference on Learning Representations."},{"key":"e_1_3_1_100_2","first-page":"15663","volume-title":"Advances in Neural Information Processing Systems","author":"Hendrycks Dan","year":"2019","unstructured":"Dan Hendrycks, Mantas Mazeika, Saurav Kadavath, and Dawn Song. 2019. Using self-supervised learning can improve model robustness and uncertainty. In Advances in Neural Information Processing Systems. 15663\u201315674."},{"key":"e_1_3_1_101_2","article-title":"Augmix: A simple data processing method to improve robustness and uncertainty","author":"Hendrycks Dan","year":"2019","unstructured":"Dan Hendrycks, Norman Mu, Ekin D. Cubuk, Barret Zoph, Justin Gilmer, and Balaji Lakshminarayanan. 2019. Augmix: A simple data processing method to improve robustness and uncertainty. arXiv:1912.02781. Retrieved from https:\/\/arxiv.org\/abs\/1912.02781.","journal-title":"arXiv:1912.02781"},{"key":"e_1_3_1_102_2","article-title":"Natural adversarial examples","author":"Hendrycks Dan","year":"2019","unstructured":"Dan Hendrycks, Kevin Zhao, Steven Basart, Jacob Steinhardt, and Dawn Song. 2019. Natural adversarial examples. arXiv:1907.07174. Retrieved from https:\/\/arxiv.org\/abs\/1907.07174.","journal-title":"arXiv:1907.07174"},{"key":"e_1_3_1_103_2","volume-title":"Proceedings of the AAAI Conference on Artificial Intelligence Workshop","author":"Hern\u00e1ndez-Orallo Jos\u00e9","year":"2019","unstructured":"Jos\u00e9 Hern\u00e1ndez-Orallo, Fernando Mart\u00ednez-Plumed, Shahar Avin, and Se\u00e1n \u00d3 h\u00c9igeartaigh. 2019. Surveying safety-relevant AI characteristics. In Proceedings of the AAAI Conference on Artificial Intelligence Workshop."},{"key":"e_1_3_1_104_2","article-title":"Summit: Scaling deep learning interpretability by visualizing activation and attribution summarizations","author":"Hohman Fred","year":"2019","unstructured":"Fred Hohman, Haekyu Park, Caleb Robinson, and Duen Horng Polo Chau. 2019. Summit: Scaling deep learning interpretability by visualizing activation and attribution summarizations. IEEE Trans. Vis. Comput. Graph. (2019).","journal-title":"IEEE Trans. Vis. Comput. Graph."},{"key":"e_1_3_1_105_2","article-title":"Federated robustness propagation: Sharing adversarial robustness in federated learning","author":"Hong Junyuan","year":"2021","unstructured":"Junyuan Hong, Haotao Wang, Zhangyang Wang, and Jiayu Zhou. 2021. Federated robustness propagation: Sharing adversarial robustness in federated learning. arXiv:2106.10196. Retrieved from https:\/\/arxiv.org\/abs\/2106.10196.","journal-title":"arXiv:2106.10196"},{"key":"e_1_3_1_106_2","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Hong Junyuan","year":"2022","unstructured":"Junyuan Hong, Haotao Wang, Zhangyang Wang, and Jiayu Zhou. 2022. Efficient split-mix federated learning for on-demand and in-situ customization. In Proceedings of the International Conference on Learning Representations."},{"key":"e_1_3_1_107_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.01096"},{"key":"e_1_3_1_108_2","article-title":"Triple wins: Boosting accuracy, robustness and efficiency together by enabling input-adaptive inference","author":"Hu Ting-Kuei","year":"2020","unstructured":"Ting-Kuei Hu, Tianlong Chen, Haotao Wang, and Zhangyang Wang. 2020. Triple wins: Boosting accuracy, robustness and efficiency together by enabling input-adaptive inference. arXiv:2002.10025. Retrieved from https:\/\/arxiv.org\/abs\/2002.10025.","journal-title":"arXiv:2002.10025"},{"key":"e_1_3_1_109_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cosrev.2020.100270"},{"key":"e_1_3_1_110_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-63387-9_1"},{"key":"e_1_3_1_111_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58536-5_8"},{"key":"e_1_3_1_112_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.tele.2018.03.005"},{"key":"e_1_3_1_113_2","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/N18-1170"},{"key":"e_1_3_1_114_2","article-title":"Robust pre-training by adversarial contrastive learning","author":"Jiang Ziyu","year":"2020","unstructured":"Ziyu Jiang, Tianlong Chen, Ting Chen, and Zhangyang Wang. 2020. Robust pre-training by adversarial contrastive learning. arXiv:2010.13337. Retrieved from https:\/\/arxiv.org\/abs\/2010.13337.","journal-title":"arXiv:2010.13337"},{"key":"e_1_3_1_115_2","doi-asserted-by":"publisher","DOI":"10.1109\/TVCG.2017.2744718"},{"key":"e_1_3_1_116_2","article-title":"Testing robustness against unforeseen adversaries","author":"Kang Daniel","year":"2019","unstructured":"Daniel Kang, Yi Sun, Dan Hendrycks, Tom Brown, and Jacob Steinhardt. 2019. Testing robustness against unforeseen adversaries. arXiv:1908.08016. Retrieved from https:\/\/arxiv.org\/abs\/1908.08016.","journal-title":"arXiv:1908.08016"},{"key":"e_1_3_1_117_2","volume-title":"Advances in Neural Information Processing Systems","author":"Karandikar Archit","year":"2021","unstructured":"Archit Karandikar, Nicholas Cain, Dustin Tran, Balaji Lakshminarayanan, Jonathon Shlens, Michael C. Mozer, and Rebecca Roelofs. 2021. Soft calibration objectives for neural networks. In Advances in Neural Information Processing Systems."},{"key":"e_1_3_1_118_2","first-page":"2525","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Katharopoulos Angelos","year":"2018","unstructured":"Angelos Katharopoulos and Fran\u00e7ois Fleuret. 2018. Not all samples are created equal: Deep learning with importance sampling. In Proceedings of the International Conference on Machine Learning. 2525\u20132534."},{"key":"e_1_3_1_119_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-63387-9_5"},{"key":"e_1_3_1_120_2","first-page":"5574","volume-title":"Advances in Neural Information Processing Systems","author":"Kendall Alex","year":"2017","unstructured":"Alex Kendall and Yarin Gal. 2017. What uncertainties do we need in bayesian deep learning for computer vision? In Advances in Neural Information Processing Systems. 5574\u20135584."},{"key":"e_1_3_1_121_2","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Kim Been","year":"2018","unstructured":"Been Kim, Martin Wattenberg, Justin Gilmer, Carrie Cai, James Wexler, Fernanda Viegas, et\u00a0al. 2018. Interpretability beyond feature attribution: Quantitative testing with concept activation vectors (tcav). In Proceedings of the International Conference on Machine Learning."},{"key":"e_1_3_1_122_2","article-title":"A programmatic and semantic approach to explaining and debuggingneural network based object detectors","author":"Kim Edward","year":"2019","unstructured":"Edward Kim, Divya Gopinath, Corina Pasareanu, and Sanjit Seshia. 2019. A programmatic and semantic approach to explaining and debuggingneural network based object detectors. arXiv:1912.00289. Retrieved from https:\/\/arxiv.org\/abs\/1912.00289.","journal-title":"arXiv:1912.00289"},{"key":"e_1_3_1_123_2","volume-title":"Explainable AI: Interpreting, Explaining and Visualizing Deep Learning","author":"Kindermans Pieter-Jan","year":"2019","unstructured":"Pieter-Jan Kindermans, Sara Hooker, Julius Adebayo, Maximilian Alber, Kristof T. Sch\u00fctt, Sven D\u00e4hne, Dumitru Erhan, and Been Kim. 2019. The (un) reliability of saliency methods. In Explainable AI: Interpreting, Explaining and Visualizing Deep Learning. Springer."},{"key":"e_1_3_1_124_2","doi-asserted-by":"publisher","DOI":"10.1109\/MITS.2016.2583491"},{"key":"e_1_3_1_125_2","first-page":"18237","volume-title":"Advances in Neural Information Processing Systems","author":"Krishnan Ranganath","year":"2020","unstructured":"Ranganath Krishnan and Omesh Tickoo. 2020. Improving model calibration with accuracy versus uncertainty optimization. In Advances in Neural Information Processing Systems. 18237\u201318248."},{"key":"e_1_3_1_126_2","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Kumar Aviral","year":"2018","unstructured":"Aviral Kumar, Sunita Sarawagi, and Ujjwal Jain. 2018. Trainable calibration measures for neural networks from kernel mean embeddings. In Proceedings of the International Conference on Machine Learning."},{"key":"e_1_3_1_127_2","first-page":"10180","volume-title":"Advances in Neural Information Processing Systems","author":"Lage Isaac","year":"2018","unstructured":"Isaac Lage, Andrew Slavin Ross, Samuel J. Gershman, Been Kim, and Finale Doshi-Velez. 2018. Human-in-the-loop interpretability prior. In Advances in Neural Information Processing Systems. 10180\u201310189."},{"key":"e_1_3_1_128_2","first-page":"5628","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Lakkaraju Himabindu","year":"2020","unstructured":"Himabindu Lakkaraju, Nino Arsov, and Osbert Bastani. 2020. Robust and stable black box explanations. In Proceedings of the International Conference on Machine Learning. 5628\u20135638."},{"key":"e_1_3_1_129_2","doi-asserted-by":"publisher","DOI":"10.1145\/2939672.2939874"},{"key":"e_1_3_1_130_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v31i1.10821"},{"key":"e_1_3_1_131_2","doi-asserted-by":"publisher","DOI":"10.1145\/3306618.3314229"},{"key":"e_1_3_1_132_2","volume-title":"Advances in Neural Information Processing Systems","author":"Lakshminarayanan Balaji","year":"2017","unstructured":"Balaji Lakshminarayanan, Alexander Pritzel, and Charles Blundell. 2017. Simple and scalable predictive uncertainty estimation using deep ensembles. In Advances in Neural Information Processing Systems."},{"key":"e_1_3_1_133_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00295"},{"key":"e_1_3_1_134_2","doi-asserted-by":"publisher","DOI":"10.1038\/nature14539"},{"key":"e_1_3_1_135_2","article-title":"Training confidence-calibrated classifiers for detecting out-of-distribution samples","author":"Lee Kimin","year":"2017","unstructured":"Kimin Lee, Honglak Lee, Kibok Lee, and Jinwoo Shin. 2017. Training confidence-calibrated classifiers for detecting out-of-distribution samples. arXiv:1711.09325. Retrieved from https:\/\/arxiv.org\/abs\/1711.09325.","journal-title":"arXiv:1711.09325"},{"key":"e_1_3_1_136_2","first-page":"7167","volume-title":"Advances in Neural Information Processing Systems","author":"Lee Kimin","year":"2018","unstructured":"Kimin Lee, Kibok Lee, Honglak Lee, and Jinwoo Shin. 2018. A simple unified framework for detecting out-of-distribution samples and adversarial attacks. In Advances in Neural Information Processing Systems. 7167\u20137177."},{"key":"e_1_3_1_137_2","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Lee Kimin","year":"2020","unstructured":"Kimin Lee, Kibok Lee, Jinwoo Shin, and Honglak Lee. 2020. Network randomization: A simple technique for generalization in deep reinforcement learning. In Proceedings of the International Conference on Learning Representations."},{"key":"e_1_3_1_138_2","article-title":"Ai safety gridworlds","author":"Leike Jan","year":"2017","unstructured":"Jan Leike, Miljan Martic, Victoria Krakovna, Pedro A. Ortega, Tom Everitt, Andrew Lefrancq, Laurent Orseau, and Shane Legg. 2017. Ai safety gridworlds. arXiv:1711.09883. Retrieved from https:\/\/arxiv.org\/abs\/1711.09883.","journal-title":"arXiv:1711.09883"},{"key":"e_1_3_1_139_2","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/D19-1523"},{"key":"e_1_3_1_140_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v32i1.11596"},{"key":"e_1_3_1_141_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.591"},{"key":"e_1_3_1_142_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.615"},{"key":"e_1_3_1_143_2","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Li Yingwei","year":"2020","unstructured":"Yingwei Li, Qihang Yu, Mingxing Tan, Jieru Mei, Peng Tang, Wei Shen, Alan Yuille, et\u00a0al. 2020. Shape-texture debiased neural network training. In Proceedings of the International Conference on Learning Representations."},{"key":"e_1_3_1_144_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00276"},{"key":"e_1_3_1_145_2","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Lin Ji","year":"2019","unstructured":"Ji Lin, Chuang Gan, and Song Han. 2019. Defensive quantization: When efficiency meets robustness. In Proceedings of the International Conference on Learning Representations."},{"key":"e_1_3_1_146_2","first-page":"3122","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Lipton Zachary","year":"2018","unstructured":"Zachary Lipton, Yu-Xiang Wang, and Alexander Smola. 2018. Detecting and correcting for label shift with black box predictors. In Proceedings of the International Conference on Machine Learning. 3122\u20133130."},{"key":"e_1_3_1_147_2","article-title":"Simple and principled uncertainty estimation with deterministic deep learning via distance awareness","author":"Liu Jeremiah Zhe","year":"2020","unstructured":"Jeremiah Zhe Liu, Zi Lin, Shreyas Padhy, Dustin Tran, Tania Bedrax-Weiss, and Balaji Lakshminarayanan. 2020. Simple and principled uncertainty estimation with deterministic deep learning via distance awareness. arXiv:2006.10108. Retrieved from https:\/\/arxiv.org\/abs\/2006.10108.","journal-title":"arXiv:2006.10108"},{"key":"e_1_3_1_148_2","article-title":"Energy-based Out-of-distribution detection","author":"Liu Weitang","year":"2020","unstructured":"Weitang Liu, Xiaoyun Wang, John D. Owens, and Yixuan Li. 2020. Energy-based Out-of-distribution detection. arXiv:2010.03759. Retrieved from https:\/\/arxiv.org\/abs\/2010.03759.","journal-title":"arXiv:2010.03759"},{"key":"e_1_3_1_149_2","article-title":"Software engineering for responsible AI: An empirical study and operationalised patterns","author":"Lu Qinghua","year":"2021","unstructured":"Qinghua Lu, Liming Zhu, Xiwei Xu, Jon Whittle, David Douglas, and Conrad Sanderson. 2021. Software engineering for responsible AI: An empirical study and operationalised patterns. arXiv:2111.09478. Retrieved from https:\/\/arxiv.org\/abs\/2111.09478.","journal-title":"arXiv:2111.09478"},{"key":"e_1_3_1_150_2","first-page":"4765","volume-title":"Advances in Neural Information Processing Systems","author":"Lundberg Scott M.","year":"2017","unstructured":"Scott M. Lundberg and Su-In Lee. 2017. A unified approach to interpreting model predictions. In Advances in Neural Information Processing Systems. 4765\u20134774."},{"key":"e_1_3_1_151_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2017.2696365"},{"key":"e_1_3_1_152_2","article-title":"Characterizing adversarial subspaces using local intrinsic dimensionality","author":"Ma Xingjun","year":"2018","unstructured":"Xingjun Ma, Bo Li, Yisen Wang, Sarah M. Erfani, Sudanthi Wijewickrema, Grant Schoenebeck, Dawn Song, Michael E. Houle, and James Bailey. 2018. Characterizing adversarial subspaces using local intrinsic dimensionality. arXiv:1801.02613. Retrieved from https:\/\/arxiv.org\/abs\/1801.02613.","journal-title":"arXiv:1801.02613"},{"key":"e_1_3_1_153_2","article-title":"Visualizing data using t-SNE","author":"Maaten Laurens van der","year":"2008","unstructured":"Laurens van der Maaten and Geoffrey Hinton. 2008. Visualizing data using t-SNE. J. Mach. Learn. Res. (2008).","journal-title":"J. Mach. Learn. Res."},{"key":"e_1_3_1_154_2","article-title":"Towards deep learning models resistant to adversarial attacks","author":"Madry Aleksander","year":"2017","unstructured":"Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu. 2017. Towards deep learning models resistant to adversarial attacks. arXiv:1706.06083. Retrieved from https:\/\/arxiv.org\/abs\/1706.06083.","journal-title":"arXiv:1706.06083"},{"key":"e_1_3_1_155_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01216-8_12"},{"key":"e_1_3_1_156_2","article-title":"On the robustness of vision transformers to adversarial examples","author":"Mahmood Kaleel","year":"2021","unstructured":"Kaleel Mahmood, Rigel Mahmood, and Marten Van Dijk. 2021. On the robustness of vision transformers to adversarial examples. arXiv:2104.02610. Retrieved from https:\/\/arxiv.org\/abs\/2104.02610.","journal-title":"arXiv:2104.02610"},{"key":"e_1_3_1_157_2","volume-title":"Advances in Neural Information Processing Systems","author":"Malinin Andrey","year":"2021","unstructured":"Andrey Malinin, Neil Band, Yarin Gal, Mark Gales, Alexander Ganshin, German Chesnokov, Alexey Noskov, Andrey Ploskonosov, Liudmila Prokhorenkova, Ivan Provilkov, et\u00a0al. 2021. Shifts: A dataset of real distributional shift across multiple large-scale tasks. In Advances in Neural Information Processing Systems."},{"key":"e_1_3_1_158_2","doi-asserted-by":"crossref","unstructured":"Rowan McAllister Yarin Gal Alex Kendall Mark Van Der Wilk Amar Shah Roberto Cipolla and Adrian Vivian Weller. 2017. Concrete problems for autonomous vehicle safety: Advantages of bayesian deep learning. In Proceedings of the International Joint Conference on Artificial Intelligence ( IJCAI \u201917) .","DOI":"10.24963\/ijcai.2017\/661"},{"key":"e_1_3_1_159_2","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Meinke Alexander","year":"2019","unstructured":"Alexander Meinke and Matthias Hein. 2019. Towards neural networks that provably know when they don\u2019t know. In Proceedings of the International Conference on Learning Representations."},{"key":"e_1_3_1_160_2","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134057"},{"key":"e_1_3_1_161_2","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2021.3063611"},{"key":"e_1_3_1_162_2","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2018.2858821"},{"key":"e_1_3_1_163_2","doi-asserted-by":"publisher","DOI":"10.5555\/3360093"},{"key":"e_1_3_1_164_2","doi-asserted-by":"publisher","DOI":"10.1145\/3397481.3450689"},{"key":"e_1_3_1_165_2","article-title":"Practical solutions for machine learning safety in autonomous vehicles","author":"Mohseni Sina","year":"2019","unstructured":"Sina Mohseni, Mandar Pitale, Vasu Singh, and Zhangyang Wang. 2019. Practical solutions for machine learning safety in autonomous vehicles. arXiv:1912.09630. Retrieved from https:\/\/arxiv.org\/abs\/1912.09630.","journal-title":"arXiv:1912.09630"},{"key":"e_1_3_1_166_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i04.5966"},{"key":"e_1_3_1_167_2","article-title":"Shifting transformation learning for out-of-distribution detection","author":"Mohseni Sina","year":"2021","unstructured":"Sina Mohseni, Arash Vahdat, and Jay Yadawa. 2021. Shifting transformation learning for out-of-distribution detection. arXiv:2106.03899. Retrieved from https:\/\/arxiv.org\/abs\/2106.03899.","journal-title":"arXiv:2106.03899"},{"key":"e_1_3_1_168_2","unstructured":"Sina Mohseni Niloofar Zarei and Eric D. Ragan. 2018. A multidisciplinary survey and framework for design and evaluation of explainable AI systems (unpublished)."},{"key":"e_1_3_1_169_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01210"},{"key":"e_1_3_1_170_2","first-page":"7034","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Moon Jooyoung","year":"2020","unstructured":"Jooyoung Moon, Jihyo Kim, Younghak Shin, and Sangheum Hwang. 2020. Confidence-aware learning for deep neural networks. In Proceedings of the International Conference on Machine Learning. 7034\u20137044."},{"key":"e_1_3_1_171_2","article-title":"Deterministic neural networks with appropriate inductive biases capture epistemic and aleatoric uncertainty","author":"Mukhoti Jishnu","year":"2021","unstructured":"Jishnu Mukhoti, Andreas Kirsch, Joost van Amersfoort, Philip H. S. Torr, and Yarin Gal. 2021. Deterministic neural networks with appropriate inductive biases capture epistemic and aleatoric uncertainty. arXiv:2102.11582. Retrieved from https:\/\/arxiv.org\/abs\/2102.11582.","journal-title":"arXiv:2102.11582"},{"key":"e_1_3_1_172_2","article-title":"When does label smoothing help?","author":"M\u00fcller Rafael","year":"2019","unstructured":"Rafael M\u00fcller, Simon Kornblith, and Geoffrey Hinton. 2019. When does label smoothing help? arXiv:1906.02629. Retrieved from https:\/\/arxiv.org\/abs\/1906.02629.","journal-title":"arXiv:1906.02629"},{"key":"e_1_3_1_173_2","article-title":"Adversarial robustness may be at odds with simplicity","author":"Nakkiran Preetum","year":"2019","unstructured":"Preetum Nakkiran. 2019. Adversarial robustness may be at odds with simplicity. arXiv:1901.00532. Retrieved from https:\/\/arxiv.org\/abs\/1901.00532.","journal-title":"arXiv:1901.00532"},{"key":"e_1_3_1_174_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v32i1.12206"},{"key":"e_1_3_1_175_2","article-title":"Multi-shot NAS for discovering adversarially robust convolutional neural architectures at targeted capacities","author":"Ning Xuefei","year":"2020","unstructured":"Xuefei Ning, Junbo Zhao, Wenshuo Li, Tianchen Zhao, Huazhong Yang, and Yu Wang. 2020. Multi-shot NAS for discovering adversarially robust convolutional neural architectures at targeted capacities. arXiv:2012.11835. Retrieved from https:\/\/arxiv.org\/abs\/2012.11835.","journal-title":"arXiv:2012.11835"},{"key":"e_1_3_1_176_2","doi-asserted-by":"publisher","DOI":"10.23915\/distill.00010"},{"key":"e_1_3_1_177_2","article-title":"Can you trust your model\u2019s uncertainty? Evaluating predictive uncertainty under dataset shift","author":"Ovadia Yaniv","year":"2019","unstructured":"Yaniv Ovadia, Emily Fertig, Jie Ren, Zachary Nado, David Sculley, Sebastian Nowozin, Joshua V Dillon, Balaji Lakshminarayanan, and Jasper Snoek. 2019. Can you trust your model\u2019s uncertainty? Evaluating predictive uncertainty under dataset shift. arXiv:1906.02530. Retrieved from https:\/\/arxiv.org\/abs\/1906.02530.","journal-title":"arXiv:1906.02530"},{"key":"e_1_3_1_178_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01225-0_29"},{"key":"e_1_3_1_179_2","doi-asserted-by":"publisher","DOI":"10.1145\/3132747.3132785"},{"key":"e_1_3_1_180_2","article-title":"Towards practical verification of machine learning: The case of computer vision systems","author":"Pei Kexin","year":"2017","unstructured":"Kexin Pei, Yinzhi Cao, Junfeng Yang, and Suman Jana. 2017. Towards practical verification of machine learning: The case of computer vision systems. arXiv:1712.01785. Retrieved from https:\/\/arxiv.org\/abs\/1712.01785.","journal-title":"arXiv:1712.01785"},{"key":"e_1_3_1_181_2","unstructured":"Haifeng Qian and Mark N. Wegman. 2018. L2-Nonexpansive Neural Networks."},{"key":"e_1_3_1_182_2","doi-asserted-by":"publisher","DOI":"10.1109\/QRS.2018.00031"},{"key":"e_1_3_1_183_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58568-6_2"},{"key":"e_1_3_1_184_2","volume-title":"Dataset Shift in Machine Learning","author":"Qui\u00f1onero-Candela Joaquin","year":"2009","unstructured":"Joaquin Qui\u00f1onero-Candela, Masashi Sugiyama, Neil D. Lawrence, and Anton Schwaighofer. 2009. Dataset Shift in Machine Learning. MIT Press."},{"key":"e_1_3_1_185_2","first-page":"5389","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Recht Benjamin","year":"2019","unstructured":"Benjamin Recht, Rebecca Roelofs, Ludwig Schmidt, and Vaishaal Shankar. 2019. Do ImageNet classifiers generalize to imagenet? In Proceedings of the International Conference on Machine Learning. 5389\u20135400."},{"key":"e_1_3_1_186_2","first-page":"14707","volume-title":"Advances in Neural Information Processing Systems","author":"Ren Jie","year":"2019","unstructured":"Jie Ren, Peter J. Liu, Emily Fertig, Jasper Snoek, Ryan Poplin, Mark Depristo, Joshua Dillon, and Balaji Lakshminarayanan. 2019. Likelihood ratios for out-of-distribution detection. In Advances in Neural Information Processing Systems. 14707\u201314718."},{"key":"e_1_3_1_187_2","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/P19-1103"},{"key":"e_1_3_1_188_2","doi-asserted-by":"publisher","DOI":"10.1145\/2939672.2939778"},{"key":"e_1_3_1_189_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v32i1.11491"},{"key":"e_1_3_1_190_2","first-page":"4393","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Ruff Lukas","year":"2018","unstructured":"Lukas Ruff, Robert Vandermeulen, Nico Goernitz, Lucas Deecke, Shoaib Ahmed Siddiqui, Alexander Binder, Emmanuel M\u00fcller, and Marius Kloft. 2018. Deep one-class classification. In Proceedings of the International Conference on Machine Learning. 4393\u20134402."},{"key":"e_1_3_1_191_2","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Ruff Lukas","year":"2019","unstructured":"Lukas Ruff, Robert A. Vandermeulen, Nico G\u00f6rnitz, Alexander Binder, Emmanuel M\u00fcller, Klaus-Robert M\u00fcller, and Marius Kloft. 2019. Deep semi-supervised anomaly detection. In Proceedings of the International Conference on Learning Representations."},{"key":"e_1_3_1_192_2","volume-title":"Robotics: Science and Systems","author":"Sadigh Dorsa","year":"2016","unstructured":"Dorsa Sadigh, Shankar Sastry, Sanjit A. Seshia, and Anca D. Dragan. 2016. Planning for autonomous cars that leverage effects on human actions. In Robotics: Science and Systems, Vol. 2. Ann Arbor, MI."},{"key":"e_1_3_1_193_2","doi-asserted-by":"publisher","DOI":"10.1109\/IROS.2016.7759036"},{"key":"e_1_3_1_194_2","article-title":"An analysis of ISO 26262: Using machine learning safely in automotive software","author":"Salay Rick","year":"2017","unstructured":"Rick Salay, Rodrigo Queiroz, and Krzysztof Czarnecki. 2017. An analysis of ISO 26262: Using machine learning safely in automotive software. arXiv:1709.02435. Retrieved from https:\/\/arxiv.org\/abs\/1709.012435.","journal-title":"arXiv:1709.02435"},{"key":"e_1_3_1_195_2","article-title":"A unified survey on anomaly, novelty, open-set, and out-of-distribution detection: Solutions and future challenges","author":"Salehi Mohammadreza","year":"2021","unstructured":"Mohammadreza Salehi, Hossein Mirzaei, Dan Hendrycks, Yixuan Li, Mohammad Hossein Rohban, and Mohammad Sabokrou. 2021. A unified survey on anomaly, novelty, open-set, and out-of-distribution detection: Solutions and future challenges. arXiv:2110.14051. Retrieved from https:\/\/arxiv.org\/abs\/2110.14051.","journal-title":"arXiv:2110.14051"},{"key":"e_1_3_1_196_2","article-title":"Defense-GAN: Protecting classifiers against adversarial attacks using generative models","author":"Samangouei Pouya","year":"2018","unstructured":"Pouya Samangouei, Maya Kabkab, and Rama Chellappa. 2018. Defense-GAN: Protecting classifiers against adversarial attacks using generative models. arXiv:1805.06605.","journal-title":"arXiv:1805.06605"},{"key":"e_1_3_1_197_2","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2016.2599820"},{"key":"e_1_3_1_198_2","first-page":"8491","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Sastry Chandramouli Shama","year":"2020","unstructured":"Chandramouli Shama Sastry and Sageev Oore. 2020. Detecting out-of-distribution examples with in-distribution examples and gram matrices. In Proceedings of the International Conference on Machine Learning. 8491\u20138501."},{"key":"e_1_3_1_199_2","article-title":"Unsupervised anomaly detection with generative adversarial networks to guide marker discovery","author":"Schlegl Thomas","year":"2017","unstructured":"Thomas Schlegl, Philipp Seeb\u00f6ck, Sebastian M Waldstein, Ursula Schmidt-Erfurth, and Georg Langs. 2017. Unsupervised anomaly detection with generative adversarial networks to guide marker discovery. arXiv:1703.05921.","journal-title":"arXiv:1703.05921"},{"key":"e_1_3_1_200_2","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Sehwag Vikash","year":"2021","unstructured":"Vikash Sehwag, Mung Chiang, and Prateek Mittal. 2021. SSD: A unified framework for self-supervised outlier detection. In Proceedings of the International Conference on Learning Representations."},{"key":"e_1_3_1_201_2","article-title":"On pruning adversarially robust neural networks","author":"Sehwag Vikash","year":"2020","unstructured":"Vikash Sehwag, Shiqi Wang, Prateek Mittal, and Suman Jana. 2020. On pruning adversarially robust neural networks. arXiv:2002.10509. Retrieved from https:\/\/arxiv.org\/abs\/2002.10529.","journal-title":"arXiv:2002.10509"},{"key":"e_1_3_1_202_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.74"},{"key":"e_1_3_1_203_2","article-title":"Input complexity and out-of-distribution detection with likelihood-based generative models","author":"Serr\u00e0 Joan","year":"2019","unstructured":"Joan Serr\u00e0, David \u00c1lvarez, Vicen\u00e7 G\u00f3mez, Olga Slizovskaia, Jos\u00e9 F N\u00fa\u00f1ez, and Jordi Luque. 2019. Input complexity and out-of-distribution detection with likelihood-based generative models. arXiv:1909.11480. Retrieved from https:\/\/arxiv.org\/abs\/1909.11480.","journal-title":"arXiv:1909.11480"},{"key":"e_1_3_1_204_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01090-4_2"},{"key":"e_1_3_1_205_2","article-title":"Towards verified artificial intelligence","author":"Seshia Sanjit A.","year":"2016","unstructured":"Sanjit A. Seshia, Dorsa Sadigh, and S. Shankar Sastry. 2016. Towards verified artificial intelligence. arXiv:1606.08514. Retrieved from https:\/\/arxiv.org\/abs\/1606.08514.","journal-title":"arXiv:1606.08514"},{"key":"e_1_3_1_206_2","article-title":"Adversarial training for free!","author":"Shafahi Ali","year":"2019","unstructured":"Ali Shafahi, Mahyar Najibi, Amin Ghiasi, Zheng Xu, John Dickerson, Christoph Studer, Larry S. Davis, Gavin Taylor, and Tom Goldstein. 2019. Adversarial training for free! arXiv:1904.12843. Retrieved from https:\/\/arxiv.org\/abs\/1904.12843.","journal-title":"arXiv:1904.12843"},{"key":"e_1_3_1_207_2","article-title":"Defending against adversarial images using basis functions transformations","author":"Shaham Uri","year":"2018","unstructured":"Uri Shaham, James Garritano, Yutaro Yamada, Ethan Weinberger, Alex Cloninger, Xiuyuan Cheng, Kelly Stanton, and Yuval Kluger. 2018. Defending against adversarial images using basis functions transformations. arXiv:1803.10840. Retrieved from https:\/\/arxiv.org\/abs\/1803.10840.","journal-title":"arXiv:1803.10840"},{"key":"e_1_3_1_208_2","doi-asserted-by":"publisher","DOI":"10.1145\/3419764"},{"key":"e_1_3_1_209_2","first-page":"3145","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Shrikumar Avanti","year":"2017","unstructured":"Avanti Shrikumar, Peyton Greenside, and Anshul Kundaje. 2017. Learning important features through propagating activation differences. In Proceedings of the International Conference on Machine Learning. 3145\u20133153."},{"key":"e_1_3_1_210_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00945"},{"key":"e_1_3_1_211_2","article-title":"Towards guidelines for assessing qualities of machine learning systems","author":"Siebert Julien","year":"2020","unstructured":"Julien Siebert, Lisa Joeckel, Jens Heidrich, Koji Nakamichi, Kyoko Ohashi, Isao Namba, Rieko Yamamoto, and Mikio Aoyama. 2020. Towards guidelines for assessing qualities of machine learning systems. arXiv:2008.11007. Retrieved from https:\/\/arxiv.org\/abs\/2008.11007.","journal-title":"arXiv:2008.11007"},{"key":"e_1_3_1_212_2","article-title":"Deep inside convolutional networks: Visualising image classification models and saliency maps","author":"Simonyan Karen","year":"2013","unstructured":"Karen Simonyan, Andrea Vedaldi, and Andrew Zisserman. 2013. Deep inside convolutional networks: Visualising image classification models and saliency maps. arXiv:1312.6034. Retrieved from https:\/\/arxiv.org\/abs\/1312.6034.","journal-title":"arXiv:1312.6034"},{"key":"e_1_3_1_213_2","unstructured":"Sahil Singla and Soheil Feizi. [n.d.]. Fantastic four: Differentiable bounds on singular values of convolution layers."},{"key":"e_1_3_1_214_2","article-title":"Smoothgrad: Removing noise by adding noise","author":"Smilkov Daniel","year":"2017","unstructured":"Daniel Smilkov, Nikhil Thorat, Been Kim, Fernanda Vi\u00e9gas, and Martin Wattenberg. 2017. Smoothgrad: Removing noise by adding noise. arXiv:1706.03825. Retrieved from https:\/\/arxiv.org\/abs\/1706.03825.","journal-title":"arXiv:1706.03825"},{"key":"e_1_3_1_215_2","doi-asserted-by":"publisher","DOI":"10.9785\/cri-2019-200402"},{"key":"e_1_3_1_216_2","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Sohn Kihyuk","year":"2021","unstructured":"Kihyuk Sohn, Chun-Liang Li, Jinsung Yoon, Minho Jin, and Tomas Pfister. 2021. Learning and evaluating representations for deep one-class classification. In Proceedings of the International Conference on Learning Representations."},{"key":"e_1_3_1_217_2","article-title":"Striving for simplicity: The all convolutional net","author":"Springenberg Jost Tobias","year":"2014","unstructured":"Jost Tobias Springenberg, Alexey Dosovitskiy, Thomas Brox, and Martin Riedmiller. 2014. Striving for simplicity: The all convolutional net. arXiv:1412.6806. Retrieved from https:\/\/arxiv.org\/abs\/1412.6806.","journal-title":"arXiv:1412.6806"},{"key":"e_1_3_1_218_2","doi-asserted-by":"publisher","DOI":"10.5555\/2627435.2670313"},{"key":"e_1_3_1_219_2","doi-asserted-by":"publisher","DOI":"10.1109\/TVCG.2017.2744158"},{"key":"e_1_3_1_220_2","article-title":"Testing deep neural networks","author":"Sun Youcheng","year":"2018","unstructured":"Youcheng Sun, Xiaowei Huang, Daniel Kroening, James Sharp, Matthew Hill, and Rob Ashmore. 2018. Testing deep neural networks. arXiv:1803.04792. Retrieved from https:\/\/arxiv.org\/abs\/1803.04792.","journal-title":"arXiv:1803.04792"},{"key":"e_1_3_1_221_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.308"},{"key":"e_1_3_1_222_2","volume-title":"Advances in Neural Information Processing Systems","author":"Tack Jihoon","year":"2020","unstructured":"Jihoon Tack, Sangwoo Mo, Jongheon Jeong, and Jinwoo Shin. 2020. CSI: Novelty detection via contrastive learning on distributionally shifted instances. In Advances in Neural Information Processing Systems."},{"key":"e_1_3_1_223_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00030"},{"key":"e_1_3_1_224_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.neunet.2021.02.023"},{"key":"e_1_3_1_225_2","volume-title":"Proceedings of the Asian Conference on Computer Vision","author":"Techapanurak Engkarat","year":"2020","unstructured":"Engkarat Techapanurak, Masanori Suganuma, and Takayuki Okatani. 2020. Hyperparameter-free out-of-distribution detection using cosine similarity. In Proceedings of the Asian Conference on Computer Vision."},{"key":"e_1_3_1_226_2","article-title":"On mixup training: Improved calibration and predictive uncertainty for deep neural networks","author":"Thulasidasan Sunil","year":"2019","unstructured":"Sunil Thulasidasan, Gopinath Chennupati, Jeff Bilmes, Tanmoy Bhattacharya, and Sarah Michalak. 2019. On mixup training: Improved calibration and predictive uncertainty for deep neural networks. arXiv:1905.11001. Retrieved from https:\/\/arxiv.org\/abs\/1905.11001.","journal-title":"arXiv:1905.11001"},{"key":"e_1_3_1_227_2","doi-asserted-by":"publisher","DOI":"10.1109\/IROS.2017.8202133"},{"key":"e_1_3_1_228_2","first-page":"1633","volume-title":"Advances in Neural Information Processing Systems","author":"Tramer Florian","year":"2020","unstructured":"Florian Tramer, Nicholas Carlini, Wieland Brendel, and Aleksander Madry. 2020. On adaptive attacks to adversarial example defenses. In Advances in Neural Information Processing Systems. 1633\u20131645."},{"key":"e_1_3_1_229_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW.2018.00143"},{"key":"e_1_3_1_230_2","article-title":"From ImageNet to image classification: Contextualizing progress on benchmarks","author":"Tsipras Dimitris","year":"2020","unstructured":"Dimitris Tsipras, Shibani Santurkar, Logan Engstrom, Andrew Ilyas, and Aleksander Madry. 2020. From ImageNet to image classification: Contextualizing progress on benchmarks. arXiv:2005.11295. Retrieved from https:\/\/arxiv.org\/abs\/2005.11295.","journal-title":"arXiv:2005.11295"},{"key":"e_1_3_1_231_2","article-title":"Robustness may be at odds with accuracy","author":"Tsipras Dimitris","year":"2018","unstructured":"Dimitris Tsipras, Shibani Santurkar, Logan Engstrom, Alexander Turner, and Aleksander Madry. 2018. Robustness may be at odds with accuracy. arXiv:1805.12152. Retrieved from https:\/\/arxiv.org\/abs\/1805.12152.","journal-title":"arXiv:1805.12152"},{"key":"e_1_3_1_232_2","first-page":"9690","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Amersfoort Joost Van","year":"2020","unstructured":"Joost Van Amersfoort, Lewis Smith, Yee Whye Teh, and Yarin Gal. 2020. Uncertainty estimation using a single deep deterministic neural network. In Proceedings of the International Conference on Machine Learning. 9690\u20139700."},{"key":"e_1_3_1_233_2","article-title":"The devil is in the tails: Fine-grained classification in the wild","author":"Horn Grant Van","year":"2017","unstructured":"Grant Van Horn and Pietro Perona. 2017. The devil is in the tails: Fine-grained classification in the wild. arXiv:1709.01450. Retrieved from https:\/\/arxiv.org\/abs\/1709.01450.","journal-title":"arXiv:1709.01450"},{"key":"e_1_3_1_234_2","doi-asserted-by":"publisher","DOI":"10.1109\/ITA.2016.7888195"},{"key":"e_1_3_1_235_2","article-title":"An effective anti-aliasing approach for residual networks","author":"Vasconcelos Cristina","year":"2020","unstructured":"Cristina Vasconcelos, Hugo Larochelle, Vincent Dumoulin, Nicolas Le Roux, and Ross Goroshin. 2020. An effective anti-aliasing approach for residual networks. arXiv:2011.10675. Retrieved from https:\/\/arxiv.org\/abs\/2011.10675.","journal-title":"arXiv:2011.10675"},{"key":"e_1_3_1_236_2","volume-title":"Advances in Neural Information Processing Systems","author":"Volpi Riccardo","year":"2018","unstructured":"Riccardo Volpi, Hongseok Namkoong, Ozan Sener, John C. Duchi, Vittorio Murino, and Silvio Savarese. 2018. Generalizing to unseen domains via adversarial data augmentation. In Advances in Neural Information Processing Systems."},{"key":"e_1_3_1_237_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01237-3_34"},{"key":"e_1_3_1_238_2","article-title":"Once-for-all adversarial training: In-situ tradeoff between robustness and accuracy for free","author":"Wang Haotao","year":"2020","unstructured":"Haotao Wang, Tianlong Chen, Shupeng Gui, Ting-Kuei Hu, Ji Liu, and Zhangyang Wang. 2020. Once-for-all adversarial training: In-situ tradeoff between robustness and accuracy for free. arXiv:2010.11828. Retrieved from https:\/\/arxiv.org\/abs\/2010.11828.","journal-title":"arXiv:2010.11828"},{"key":"e_1_3_1_239_2","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Wang Haotao","year":"2020","unstructured":"Haotao Wang, Tianlong Chen, Zhangyang Wang, and Kede Ma. 2020. I am going MAD: Maximum discrepancy competition for comparing classifiers adaptively. In Proceedings of the International Conference on Learning Representations."},{"key":"e_1_3_1_240_2","volume-title":"Advances in Neural Information Processing Systems","author":"Wang Haohan","year":"2019","unstructured":"Haohan Wang, Songwei Ge, Eric P. Xing, and Zachary C. Lipton. 2019. Learning robust global representations by penalizing local predictive power. In Advances in Neural Information Processing Systems."},{"key":"e_1_3_1_241_2","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Wang Haohan","year":"2019","unstructured":"Haohan Wang, Zexue He, Zachary C. Lipton, and Eric P. Xing. 2019. Learning robust representations by projecting superficial statistics out. In Proceedings of the International Conference on Learning Representations."},{"key":"e_1_3_1_242_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00871"},{"key":"e_1_3_1_243_2","volume-title":"Advances in Neural Information Processing Systems","author":"Wang Haotao","year":"2021","unstructured":"Haotao Wang, Chaowei Xiao, Jean Kossaifi, Zhiding Yu, Anima Anandkumar, and Zhangyang Wang. 2021. AugMax: Adversarial composition of random augmentations for robust training. In Advances in Neural Information Processing Systems."},{"key":"e_1_3_1_244_2","article-title":"MixTrain: Scalable training of formally robust neural networks","author":"Wang Shiqi","year":"2018","unstructured":"Shiqi Wang, Yizheng Chen, Ahmed Abdou, and Suman Jana. 2018. MixTrain: Scalable training of formally robust neural networks. arXiv:1811.02625. Retrieved from https:\/\/arxiv.org\/abs\/1811.02625.","journal-title":"arXiv:1811.02625"},{"key":"e_1_3_1_245_2","first-page":"6369","volume-title":"Advances in Neural Information Processing Systems","author":"Wang Shiqi","year":"2018","unstructured":"Shiqi Wang, Kexin Pei, Justin Whitehouse, Junfeng Yang, and Suman Jana. 2018. Efficient formal safety analysis of neural networks. In Advances in Neural Information Processing Systems. 6369\u20136379."},{"key":"e_1_3_1_246_2","article-title":"Further analysis of outlier detection with deep generative models","author":"Wang Ziyu","year":"2020","unstructured":"Ziyu Wang, Bin Dai, David Wipf, and Jun Zhu. 2020. Further analysis of outlier detection with deep generative models. arXiv:2010.13064. Retrieved from https:\/\/arxiv.org\/abs\/2010.13064.","journal-title":"arXiv:2010.13064"},{"key":"e_1_3_1_247_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.01374"},{"key":"e_1_3_1_248_2","article-title":"Facets: An open source visualization tool for machine learning training data","author":"Wexler James","year":"2017","unstructured":"James Wexler. 2017. Facets: An open source visualization tool for machine learning training data. Google Open Source Blog.","journal-title":"Google Open Source Blog"},{"key":"e_1_3_1_249_2","article-title":"Contrastive training for improved out-of-distribution detection","author":"Winkens Jim","year":"2020","unstructured":"Jim Winkens, Rudy Bunel, Abhijit Guha Roy, Robert Stanforth, Vivek Natarajan, Joseph R. Ledsam, Patricia MacWilliams, Pushmeet Kohli, Alan Karthikesalingam, Simon Kohl, et\u00a0al. 2020. Contrastive training for improved out-of-distribution detection. arXiv:2007.05566. Retrieved from https:\/\/arxiv\/org\/abs\/2007.05566.","journal-title":"arXiv:2007.05566"},{"key":"e_1_3_1_250_2","first-page":"5283","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Wong Eric","year":"2018","unstructured":"Eric Wong and Zico Kolter. 2018. Provable defenses against adversarial examples via the convex outer adversarial polytope. In Proceedings of the International Conference on Machine Learning. 5283\u20135292."},{"key":"e_1_3_1_251_2","article-title":"Fast is better than free: Revisiting adversarial training","author":"Wong Eric","year":"2020","unstructured":"Eric Wong, Leslie Rice, and J. Zico Kolter. 2020. Fast is better than free: Revisiting adversarial training. arXiv:2001.03994. Retrieved from https:\/\/arxiv.org\/abs\/2001.03994.","journal-title":"arXiv:2001.03994"},{"key":"e_1_3_1_252_2","article-title":"Visualizing dataflow graphs of deep learning models in tensorflow","author":"Wongsuphasawat Kanit","year":"2017","unstructured":"Kanit Wongsuphasawat, Daniel Smilkov, James Wexler, Jimbo Wilson, Dandelion Mane, Doug Fritz, Dilip Krishnan, Fernanda B. Vi\u00e9gas, and Martin Wattenberg. 2017. Visualizing dataflow graphs of deep learning models in tensorflow. IEEE Trans. Vis. Comput. Graph. (2017).","journal-title":"IEEE Trans. Vis. Comput. Graph."},{"key":"e_1_3_1_253_2","article-title":"Does network width really help adversarial robustness?","author":"Wu Boxi","year":"2020","unstructured":"Boxi Wu, Jinghui Chen, Deng Cai, Xiaofei He, and Quanquan Gu. 2020. Does network width really help adversarial robustness? arXiv:2010.01279. Retrieved from https:\/\/arxiv.org\/abs\/2010.01279.","journal-title":"arXiv:2010.01279"},{"key":"e_1_3_1_254_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v32i1.11501"},{"key":"e_1_3_1_255_2","volume-title":"Advances in Neural Information Processing Systems","author":"Wu Ruihan","year":"2021","unstructured":"Ruihan Wu, Chuan Guo, Yi Su, and Kilian Q. Weinberger. 2021. Online adaptation to label distribution shift. In Advances in Neural Information Processing Systems."},{"key":"e_1_3_1_256_2","article-title":"Delving into robust object detection from unmanned aerial vehicles: A deep nuisance disentanglement approach","author":"Wu Zhenyu","year":"2019","unstructured":"Zhenyu Wu, Karthik Suresh, Priya Narayanan, Hongyu Xu, Heesung Kwon, and Zhangyang Wang. 2019. Delving into robust object detection from unmanned aerial vehicles: A deep nuisance disentanglement approach. arXiv:1908.03856. Retrieved from https:\/\/arxiv.org\/abs\/1908.03856.","journal-title":"arXiv:1908.03856"},{"key":"e_1_3_1_257_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01249-6_14"},{"key":"e_1_3_1_258_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00706"},{"key":"e_1_3_1_259_2","article-title":"Spatially transformed adversarial examples","author":"Xiao Chaowei","year":"2018","unstructured":"Chaowei Xiao, Jun-Yan Zhu, Bo Li, Warren He, Mingyan Liu, and Dawn Song. 2018. Spatially transformed adversarial examples. arXiv:1801.02612. Retrieved from https:\/\/arxiv.org\/abs\/1801.02312.","journal-title":"arXiv:1801.02612"},{"key":"e_1_3_1_260_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00090"},{"key":"e_1_3_1_261_2","article-title":"Smooth adversarial training","author":"Xie Cihang","year":"2020","unstructured":"Cihang Xie, Mingxing Tan, Boqing Gong, Alan Yuille, and Quoc V. Le. 2020. Smooth adversarial training. arXiv:2006.14536. Retrieved from https:\/\/arxiv.org\/abs\/2006.14536.","journal-title":"arXiv:2006.14536"},{"key":"e_1_3_1_262_2","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Xie Cihang","year":"2018","unstructured":"Cihang Xie, Jianyu Wang, Zhishuai Zhang, Zhou Ren, and Alan Yuille. 2018. Mitigating adversarial effects through randomization. In Proceedings of the International Conference on Learning Representations."},{"key":"e_1_3_1_263_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00059"},{"key":"e_1_3_1_264_2","article-title":"Intriguing properties of adversarial training at scale","author":"Xie Cihang","year":"2019","unstructured":"Cihang Xie and Alan Yuille. 2019. Intriguing properties of adversarial training at scale. arXiv:1906.03787. Retrieved from https:\/\/arxiv.org\/abs\/1906.03787.","journal-title":"arXiv:1906.03787"},{"key":"e_1_3_1_265_2","article-title":"Feature squeezing: Detecting adversarial examples in deep neural networks","author":"Xu Weilin","year":"2017","unstructured":"Weilin Xu, David Evans, and Yanjun Qi. 2017. Feature squeezing: Detecting adversarial examples in deep neural networks. arXiv:1704.01155. Retrieved from https:\/\/arxiv.org\/abs\/1704.01155.","journal-title":"arXiv:1704.01155"},{"key":"e_1_3_1_266_2","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Xu Zhenlin","year":"2021","unstructured":"Zhenlin Xu, Deyi Liu, Junlin Yang, and Marc Niethammer. 2021. Robust and generalizable visual representation learning via random convolutions. In Proceedings of the International Conference on Learning Representations."},{"key":"e_1_3_1_267_2","doi-asserted-by":"publisher","DOI":"10.1109\/FMCAD.2016.7886680"},{"key":"e_1_3_1_268_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00819"},{"key":"e_1_3_1_269_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00020"},{"key":"e_1_3_1_270_2","volume-title":"Advances in Neural Information Processing Systems","author":"Yeh Chih-Kuan","year":"2020","unstructured":"Chih-Kuan Yeh, Been Kim, Sercan Arik, Chun-Liang Li, Tomas Pfister, and Pradeep Ravikumar. 2020. On Completeness-aware concept-based explanations in deep neural networks. In Advances in Neural Information Processing Systems, Vol. 33."},{"key":"e_1_3_1_271_2","first-page":"3320","volume-title":"Advances in Neural Information Processing Systems","author":"Yosinski Jason","year":"2014","unstructured":"Jason Yosinski, Jeff Clune, Yoshua Bengio, and Hod Lipson. 2014. How transferable are features in deep neural networks? In Advances in Neural Information Processing Systems. 3320\u20133328."},{"key":"e_1_3_1_272_2","first-page":"10871","volume-title":"Proceedings of the International Conference on Machine Learning","author":"You Yuning","year":"2020","unstructured":"Yuning You, Tianlong Chen, Zhangyang Wang, and Yang Shen. 2020. When does self-supervision help graph convolutional networks? In Proceedings of the International Conference on Machine Learning. 10871\u201310880."},{"key":"e_1_3_1_273_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00961"},{"key":"e_1_3_1_274_2","first-page":"7164","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Yu Xingrui","year":"2019","unstructured":"Xingrui Yu, Bo Han, Jiangchao Yao, Gang Niu, Ivor Tsang, and Masashi Sugiyama. 2019. How does disagreement help generalization against label corruption? In Proceedings of the International Conference on Machine Learning. 7164\u20137173."},{"key":"e_1_3_1_275_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00396"},{"key":"e_1_3_1_276_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00219"},{"key":"e_1_3_1_277_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00612"},{"key":"e_1_3_1_278_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00237"},{"key":"e_1_3_1_279_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-10590-1_53"},{"key":"e_1_3_1_280_2","article-title":"You only propagate once: Accelerating adversarial training via maximal principle","author":"Zhang Dinghuai","year":"2019","unstructured":"Dinghuai Zhang, Tianyuan Zhang, Yiping Lu, Zhanxing Zhu, and Bin Dong. 2019. You only propagate once: Accelerating adversarial training via maximal principle. arXiv:1905.00877. Retrieved from https:\/\/arxiv.org\/abs\/1905.00877.","journal-title":"arXiv:1905.00877"},{"key":"e_1_3_1_281_2","article-title":"Towards stable and efficient training of verifiably robust neural networks","author":"Zhang Huan","year":"2019","unstructured":"Huan Zhang, Hongge Chen, Chaowei Xiao, Sven Gowal, Robert Stanforth, Bo Li, Duane Boning, and Cho-Jui Hsieh. 2019. Towards stable and efficient training of verifiably robust neural networks. arXiv:1906.06316. Retrieved from https:\/\/arxiv.org\/abs\/1906.06316.","journal-title":"arXiv:1906.06316"},{"key":"e_1_3_1_282_2","article-title":"MixUp: Beyond empirical risk minimization","author":"Zhang Hongyi","year":"2017","unstructured":"Hongyi Zhang, Moustapha Cisse, Yann N. Dauphin, and David Lopez-Paz. 2017. MixUp: Beyond empirical risk minimization. arXiv:1710.09412. Retrieved from https:\/\/arxiv.org\/abs\/1710.09412.","journal-title":"arXiv:1710.09412"},{"key":"e_1_3_1_283_2","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Zhang Hongyang","year":"2019","unstructured":"Hongyang Zhang, Yaodong Yu, Jiantao Jiao, Eric Xing, Laurent El Ghaoui, and Michael Jordan. 2019. Theoretically principled trade-off between robustness and accuracy. In Proceedings of the International Conference on Machine Learning."},{"key":"e_1_3_1_284_2","article-title":"Fine-grained out-of-distribution detection with mixup outlier exposure","author":"Zhang Jingyang","year":"2021","unstructured":"Jingyang Zhang, Nathan Inkawhich, Yiran Chen, and Hai Li. 2021. Fine-grained out-of-distribution detection with mixup outlier exposure. arXiv:2106.03917. Retrieved from https:\/\/arxiv.org\/abs\/2106.03917.","journal-title":"arXiv:2106.03917"},{"key":"e_1_3_1_285_2","article-title":"Geometry-aware instance-reweighted adversarial training","author":"Zhang Jingfeng","year":"2020","unstructured":"Jingfeng Zhang, Jianing Zhu, Gang Niu, Bo Han, Masashi Sugiyama, and Mohan Kankanhalli. 2020. Geometry-aware instance-reweighted adversarial training. arXiv:2010.01736.","journal-title":"arXiv:2010.01736"},{"key":"e_1_3_1_286_2","article-title":"Machine learning testing: Survey, landscapes and horizons","author":"Zhang Jie M.","year":"2020","unstructured":"Jie M. Zhang, Mark Harman, Lei Ma, and Yang Liu. 2020. Machine learning testing: Survey, landscapes and horizons. IEEE Trans. Softw. Eng. (2020).","journal-title":"IEEE Trans. Softw. Eng."},{"key":"e_1_3_1_287_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v32i1.11833"},{"key":"e_1_3_1_288_2","first-page":"7324","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Zhang Richard","year":"2019","unstructured":"Richard Zhang. 2019. Making convolutional networks shift-invariant again. In Proceedings of the International Conference on Machine Learning. 7324\u20137334."},{"key":"e_1_3_1_289_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v31i1.10768"},{"key":"e_1_3_1_290_2","doi-asserted-by":"publisher","DOI":"10.1109\/TCSVT.2020.2967419"},{"key":"e_1_3_1_291_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01001"},{"key":"e_1_3_1_292_2","article-title":"Confidence calibration for convolutional neural networks using structured dropout","author":"Zhang Zhilu","year":"2019","unstructured":"Zhilu Zhang, Adrian V. Dalca, and Mert R. Sabuncu. 2019. Confidence calibration for convolutional neural networks using structured dropout. arXiv:1906.09551. Retrieved from https:\/\/arxiv.org\/abs\/1906.09551.","journal-title":"arXiv:1906.09551"},{"key":"e_1_3_1_293_2","volume-title":"Advances in Neural Information Processing Systems","author":"Zhao Long","year":"2020","unstructured":"Long Zhao, Ting Liu, Xi Peng, and Dimitris Metaxas. 2020. Maximum-entropy adversarial data augmentation for improved generalization and robustness. In Advances in Neural Information Processing Systems."},{"key":"e_1_3_1_294_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.485"},{"key":"e_1_3_1_295_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i07.7000"},{"key":"e_1_3_1_296_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01237-3_8"},{"key":"e_1_3_1_297_2","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Zong Bo","year":"2018","unstructured":"Bo Zong, Qi Song, Martin Renqiang Min, Wei Cheng, Cristian Lumezanu, Daeki Cho, and Haifeng Chen. 2018. Deep autoencoding gaussian mixture model for unsupervised anomaly detection. In Proceedings of the International Conference on Learning Representations."}],"container-title":["ACM Computing Surveys"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3551385","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3551385","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T19:00:25Z","timestamp":1750186825000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3551385"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,12,23]]},"references-count":296,"journal-issue":{"issue":"8","published-print":{"date-parts":[[2023,8,31]]}},"alternative-id":["10.1145\/3551385"],"URL":"https:\/\/doi.org\/10.1145\/3551385","relation":{},"ISSN":["0360-0300","1557-7341"],"issn-type":[{"value":"0360-0300","type":"print"},{"value":"1557-7341","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,12,23]]},"assertion":[{"value":"2021-06-09","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2022-06-20","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2022-12-23","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}