{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,13]],"date-time":"2025-11-13T13:40:35Z","timestamp":1763041235278,"version":"3.45.0"},"reference-count":46,"publisher":"Association for Computing Machinery (ACM)","issue":"4","funder":[{"name":"National Science Foundation","award":["NSF-1915398, NSF-2143274, and NSF-2339637"],"award-info":[{"award-number":["NSF-1915398, NSF-2143274, and NSF-2339637"]}]},{"name":"U.S. Department of Defense","award":["ARO MURI W911NF-20-1-0080"],"award-info":[{"award-number":["ARO MURI W911NF-20-1-0080"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Cyber-Phys. Syst."],"published-print":{"date-parts":[[2025,10,31]]},"abstract":"<jats:p>\n                    Medical cyber-physical systems (MCPS) are increasingly adopting learning-enabled components (LECs) to enhance their decision-making capabilities. Due to the safety-critical nature of MCPS, these systems must maintain high performance on both expected and unexpected input data. Therefore, ensuring the robustness of LE-MCPS is crucial for their successful deployment. Existing research predominantly focuses on robustness to\n                    <jats:italic toggle=\"yes\">synthetic adversarial examples<\/jats:italic>\n                    , crafted by adding imperceptible perturbations to clean input data. However, these synthetic adversarial examples do not accurately reflect the most challenging real-world scenarios, especially in the context of healthcare data. Consequently, robustness to synthetic adversarial examples may not necessarily translate to robustness against\n                    <jats:italic toggle=\"yes\">naturally occurring adversarial examples<\/jats:italic>\n                    . We propose a method to evaluate the robustness of LE-MCPS to natural adversarial examples. The method curates naturally adversarial datasets leveraging probabilistic labels obtained from automated weakly supervised labeling which combines noisy and cheap-to-obtain labeling heuristics. Based on these labels, the method adversarially orders the input data and uses this ordering to construct a sequence of increasingly adversarial datasets for assessing robustness. Our evaluation on six MCPS case studies and two non-medical case studies demonstrates (1) the efficacy and statistical validity of our approach to generating naturally adversarial datasets and (2) the utility of our robustness evaluation in classifying robust and non-robust LE-MCPS.\n                  <\/jats:p>","DOI":"10.1145\/3734695","type":"journal-article","created":{"date-parts":[[2025,5,7]],"date-time":"2025-05-07T12:01:41Z","timestamp":1746619301000},"page":"1-39","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Evaluating Robustness of Learning-Enabled Medical Cyber-Physical Systems with Naturally Adversarial Datasets"],"prefix":"10.1145","volume":"9","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-1465-983X","authenticated-orcid":false,"given":"Sydney","family":"Pugh","sequence":"first","affiliation":[{"name":"Computer and Information Science, University of Pennsylvania, Philadelphia, Pennsylvania, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3546-414X","authenticated-orcid":false,"given":"Ivan","family":"Ruchkin","sequence":"additional","affiliation":[{"name":"Electrical and Computer Engineering, University of Florida, Gainesville, Florida, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8167-9163","authenticated-orcid":false,"given":"James","family":"Weimer","sequence":"additional","affiliation":[{"name":"Computer Science, Vanderbilt University, Nashville, Tennessee, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2672-1132","authenticated-orcid":false,"given":"Insup","family":"Lee","sequence":"additional","affiliation":[{"name":"Computer and Information Science, University of Pennsylvania, Philadelphia, Pennsylvania, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2025,11,4]]},"reference":[{"key":"e_1_3_1_2_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cmpb.2018.04.005"},{"key":"e_1_3_1_3_2","doi-asserted-by":"publisher","DOI":"10.1145\/3531326"},{"key":"e_1_3_1_4_2","doi-asserted-by":"publisher","DOI":"10.1109\/IEEECONF56349.2022.10052004"},{"key":"e_1_3_1_5_2","unstructured":"C. Szegedy W. Zaremba I. Sutskever J. Bruna D. Erhan I. Goodfellow and R. Fergus. 2013. Intriguing properties of neural networks. arXiv:1312.6199. Retrieved from https:\/\/arxiv.org\/abs\/1312.6199"},{"key":"e_1_3_1_6_2","doi-asserted-by":"publisher","DOI":"10.1001\/jamapediatrics.2016.5123"},{"key":"e_1_3_1_7_2","first-page":"5637","volume-title":"Proc. of ICML","author":"Koh P. W.","year":"2021","unstructured":"P. W. Koh, S. Sagawa, H. Marklund, S. M. Xie, M. Zhang, A. Balsubramani, W. Hu, M. Yasunaga, R. L. Phillips, I. Gao, et al. 2021. Wilds: A benchmark of in-the-wild distribution shifts. In Proc. of ICML. PMLR, 5637\u20135664."},{"key":"e_1_3_1_8_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01501"},{"key":"e_1_3_1_9_2","article-title":"Data programming: Creating large training sets, quickly","volume":"29","author":"Ratner A. J.","year":"2016","unstructured":"A. J. Ratner, C. M. De Sa, S. Wu, D. Selsam, and C. R\u00e9. 2016. Data programming: Creating large training sets, quickly. In Proc. of NeurIPS, Vol. 29.","journal-title":"Proc. of NeurIPS"},{"key":"e_1_3_1_10_2","doi-asserted-by":"publisher","DOI":"10.1148\/radiol.2018181422"},{"key":"e_1_3_1_11_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCPS61052.2024.00026"},{"key":"e_1_3_1_12_2","doi-asserted-by":"publisher","DOI":"10.5555\/3276449"},{"key":"e_1_3_1_13_2","unstructured":"C. Xiao J.-Y. Zhu B. Li W. He M. Liu and D. Song. 2018. Spatially transformed adversarial examples. arXiv:1801.02612. Retrieved from https:\/\/arxiv.org\/abs\/1801.02612"},{"key":"e_1_3_1_14_2","doi-asserted-by":"publisher","DOI":"10.5626\/JCSE.2016.10.3.75"},{"key":"e_1_3_1_15_2","doi-asserted-by":"crossref","unstructured":"T. Kushner B. Wayne Bequette F. Cameron G. Forlenza D. Maahs and S. Sankaranarayanan. 2019. Models devices properties and verification of artificial pancreas systems. In Automated Reasoning for Systems Biology and Medicine. Pietro Li\u00f2 and Paolo Zuliani (Eds.) Springer 93\u2013131.","DOI":"10.1007\/978-3-030-17297-8_4"},{"key":"e_1_3_1_16_2","volume-title":"Generating adversarial examples with adversarial networks","author":"Xiao C.","year":"2019","unstructured":"C. Xiao, B. Li, J.-Y. Zhu, W. He, M. Liu, and D. Song. 2019. Generating adversarial examples with adversarial networks. arXiv:1801.02610. Retrieved from https:\/\/arxiv.org\/abs\/1801.02610"},{"key":"e_1_3_1_17_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-981-19-8991-9_29"},{"key":"e_1_3_1_18_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-023-10393-w"},{"key":"e_1_3_1_19_2","unstructured":"K.-K. Sung. 1996. Learning and example selection for object and pattern detection. Ph. D. Dissertation. Massachusetts Institute of Technology."},{"key":"e_1_3_1_20_2","doi-asserted-by":"publisher","DOI":"10.1145\/3474381"},{"key":"e_1_3_1_21_2","unstructured":"C. Bhagavatula R. L. Bras C. Malaviya K. Sakaguchi A. Holtzman H. Rashkin D. Downey S. W.-t. Yih and Y. Choi. 2019. Abductive commonsense reasoning. arXiv:1908.05739. Retrieved from https:\/\/arxiv.org\/abs\/1908.05739"},{"key":"e_1_3_1_22_2","doi-asserted-by":"crossref","unstructured":"R. Zellers A. Holtzman Y. Bisk A. Farhadi and Y. Choi. 2019. Hellaswag: Can a machine really finish your sentence? arXiv:1905.07830. Retrieved from https:\/\/arxiv.org\/abs\/1905.07830","DOI":"10.18653\/v1\/P19-1472"},{"key":"e_1_3_1_23_2","unstructured":"D. Dua Y. Wang P. Dasigi G. Stanovsky S. Singh and M. Gardner. 2019. Drop: A reading comprehension benchmark requiring discrete reasoning over paragraphs. arXiv:1903.00161. Retrieved from https:\/\/arxiv.org\/abs\/1903.00161"},{"key":"e_1_3_1_24_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i05.6239"},{"key":"e_1_3_1_25_2","unstructured":"D. Hendrycks C. Burns S. Basart A. Critch J. Li D. Song and J. Steinhardt. 2020. Aligning AI with shared human values. arXiv:2008.02275. Retrieved from https:\/\/arxiv.org\/abs\/2008.02275"},{"key":"e_1_3_1_26_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4614-6396-2"},{"key":"e_1_3_1_27_2","doi-asserted-by":"publisher","DOI":"10.1109\/JPROC.2021.3052449"},{"key":"e_1_3_1_28_2","doi-asserted-by":"publisher","DOI":"10.1007\/s00778-019-00552-1"},{"key":"e_1_3_1_29_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00168"},{"key":"e_1_3_1_30_2","unstructured":"A. Pal and V. N. Balasubramanian. 2020. Generative adversarial data programming. arXiv:2005.00364. Retrieved from https:\/\/arxiv.org\/abs\/2005.00364"},{"key":"e_1_3_1_31_2","doi-asserted-by":"publisher","DOI":"10.2307\/1422689"},{"key":"e_1_3_1_32_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.33014763"},{"key":"e_1_3_1_33_2","first-page":"273","volume-title":"Proc. of ICML","author":"Bach S. H.","year":"2017","unstructured":"S. H. Bach, B. He, A. Ratner, and C. R\u00e9. 2017. Learning the structure of generative models without labeled data. In Proc. of ICML. PMLR, 273\u2013282."},{"key":"e_1_3_1_34_2","doi-asserted-by":"publisher","DOI":"10.1109\/CHASE52844.2021.00015"},{"key":"e_1_3_1_35_2","first-page":"1321","volume-title":"Proc. of ICML","author":"Guo C.","year":"2017","unstructured":"C. Guo, G. Pleiss, Y. Sun, and K. Q. Weinberger. 2017. On calibration of modern neural networks. In Proc. of ICML. PMLR, 1321\u20131330."},{"key":"e_1_3_1_36_2","doi-asserted-by":"publisher","DOI":"10.1093\/biomet\/26.4.404"},{"key":"e_1_3_1_37_2","doi-asserted-by":"publisher","DOI":"10.2345\/0899-8205-51.1.25"},{"key":"e_1_3_1_38_2","doi-asserted-by":"publisher","DOI":"10.1145\/3549942"},{"key":"e_1_3_1_39_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.patter.2020.100019"},{"key":"e_1_3_1_40_2","doi-asserted-by":"publisher","DOI":"10.14778\/3291264.3291268"},{"key":"e_1_3_1_41_2","doi-asserted-by":"publisher","DOI":"10.1145\/3318464.3380592"},{"key":"e_1_3_1_42_2","first-page":"332","volume-title":"Proc. of AAMAS","author":"Cheng M.","year":"2021","unstructured":"M. Cheng, C. Yin, J. Zhang, S. Nazarian, J. Deshmukh, and P. Bogdan. 2021. A general trust framework for multi-agent systems. In Proc. of AAMAS, 332\u2013340."},{"key":"e_1_3_1_43_2","doi-asserted-by":"publisher","DOI":"10.3389\/frai.2020.00054"},{"key":"e_1_3_1_44_2","first-page":"1086","volume-title":"Proc. of CoLLAs","author":"Cheng M.","year":"2022","unstructured":"M. Cheng, T. Sun, S. Nazarian, and P. Bogdan. 2022. Trustworthiness evaluation and trust-aware design of CNN architectures. In Proc. of CoLLAs. PMLR, 1086\u20131102."},{"key":"e_1_3_1_45_2","doi-asserted-by":"publisher","DOI":"10.1002\/widm.1356"},{"key":"e_1_3_1_46_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cviu.2022.103552"},{"key":"e_1_3_1_47_2","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-022-01625-5"}],"container-title":["ACM Transactions on Cyber-Physical Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3734695","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,11,13]],"date-time":"2025-11-13T13:35:07Z","timestamp":1763040907000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3734695"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,31]]},"references-count":46,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2025,10,31]]}},"alternative-id":["10.1145\/3734695"],"URL":"https:\/\/doi.org\/10.1145\/3734695","relation":{},"ISSN":["2378-962X","2378-9638"],"issn-type":[{"type":"print","value":"2378-962X"},{"type":"electronic","value":"2378-9638"}],"subject":[],"published":{"date-parts":[[2025,10,31]]},"assertion":[{"value":"2024-09-04","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-04-16","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-11-04","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}