{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,18]],"date-time":"2025-12-18T14:22:52Z","timestamp":1766067772936},"reference-count":29,"publisher":"IEEE","license":[{"start":{"date-parts":[[2023,5,31]],"date-time":"2023-05-31T00:00:00Z","timestamp":1685491200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2023,5,31]],"date-time":"2023-05-31T00:00:00Z","timestamp":1685491200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2023,5,31]]},"DOI":"10.23919\/acc55779.2023.10156358","type":"proceedings-article","created":{"date-parts":[[2023,7,3]],"date-time":"2023-07-03T17:48:03Z","timestamp":1688406483000},"page":"4083-4089","source":"Crossref","is-referenced-by-count":2,"title":["Adversarial Tradeoffs in Robust State Estimation"],"prefix":"10.23919","author":[{"given":"Thomas T. C. K.","family":"Zhang","sequence":"first","affiliation":[]},{"given":"Bruce D.","family":"Lee","sequence":"additional","affiliation":[]},{"given":"Hamed","family":"Hassani","sequence":"additional","affiliation":[]},{"given":"Nikolai","family":"Matni","sequence":"additional","affiliation":[]}],"member":"263","reference":[{"key":"ref13","first-page":"1670","article-title":"More data can expand the generalization gap between adversarially robust and standard models","author":"chen","year":"2020","journal-title":"International Conference on Machine Learning"},{"year":"2019","author":"raghunathan","article-title":"Adversarial training can hurt generalization","key":"ref12"},{"doi-asserted-by":"publisher","key":"ref15","DOI":"10.15607\/RSS.2021.XVII.007"},{"key":"ref14","first-page":"2034","article-title":"Precise tradeoffs in adversarial training for linear regression","author":"javanmard","year":"2020","journal-title":"Conference on Learning Theory"},{"year":"2019","author":"nakkiran","article-title":"Adversarial robustness may be at odds with simplicity","key":"ref11"},{"year":"2019","author":"zhang","article-title":"Theoretically principled trade-off between robustness and accuracy","key":"ref10"},{"year":"2014","author":"goodfellow","article-title":"Explaining and harnessing adversarial examples","key":"ref2"},{"year":"2016","author":"carlini","article-title":"Defensive distillation is not robust to adversarial examples","key":"ref1"},{"doi-asserted-by":"publisher","key":"ref17","DOI":"10.1109\/IROS.2017.8206245"},{"key":"ref16","first-page":"2817","article-title":"Robust adversarial reinforcement learning","author":"pinto","year":"2017","journal-title":"International Conference on Machine Learning"},{"year":"1999","author":"hassibi","journal-title":"Indefinite-Quadratic Estimation and Control A Unified Approach to H2 and H? Theories","key":"ref19"},{"year":"1998","author":"zhou","journal-title":"Essentials of Robust Control","key":"ref18"},{"doi-asserted-by":"publisher","key":"ref24","DOI":"10.1017\/CBO9780511804441"},{"year":"2021","author":"lee","article-title":"Adversarial tradeoffs in linear inverse problems and robust state estimation","key":"ref23"},{"year":"2020","author":"dobriban","article-title":"Provable tradeoffs in adversarially robust classification","key":"ref26"},{"doi-asserted-by":"publisher","key":"ref25","DOI":"10.1137\/16M1080173"},{"doi-asserted-by":"publisher","key":"ref20","DOI":"10.1002\/(SICI)1099-1239(199605)6:4<313::AID-RNC235>3.3.CO;2-#"},{"doi-asserted-by":"publisher","key":"ref22","DOI":"10.1109\/CDC51059.2022.9992393"},{"doi-asserted-by":"publisher","key":"ref21","DOI":"10.23919\/ACC45564.2020.9147981"},{"year":"2008","author":"lewis","journal-title":"Optimal and Robust Estimation With an Introduction to Stochastic Control Theory","key":"ref28"},{"doi-asserted-by":"publisher","key":"ref27","DOI":"10.1109\/TAC.1979.1102095"},{"year":"2019","author":"caverly","article-title":"Lmi properties and applications in systems, stability, and control theory","key":"ref29"},{"year":"2020","author":"deka","article-title":"Dynamically computing adversarial perturbations for recurrent neural networks","key":"ref8"},{"year":"2020","author":"xie","article-title":"Smooth adversarial training","key":"ref7"},{"year":"2018","author":"tsipras","article-title":"Robustness may be at odds with accuracy","key":"ref9"},{"year":"2017","author":"huang","article-title":"Adversarial attacks on neural network policies","key":"ref4"},{"year":"2013","author":"szegedy","article-title":"Intriguing properties of neural networks","key":"ref3"},{"year":"2017","author":"madry","article-title":"Towards deep learning models resistant to adversarial attacks","key":"ref6"},{"doi-asserted-by":"publisher","key":"ref5","DOI":"10.1109\/SP.2017.49"}],"event":{"name":"2023 American Control Conference (ACC)","start":{"date-parts":[[2023,5,31]]},"location":"San Diego, CA, USA","end":{"date-parts":[[2023,6,2]]}},"container-title":["2023 American Control Conference (ACC)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/10155646\/10155787\/10156358.pdf?arnumber=10156358","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,8,21]],"date-time":"2023-08-21T17:40:23Z","timestamp":1692639623000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10156358\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,5,31]]},"references-count":29,"URL":"https:\/\/doi.org\/10.23919\/acc55779.2023.10156358","relation":{},"subject":[],"published":{"date-parts":[[2023,5,31]]}}}