{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,17]],"date-time":"2026-08-17T15:44:03Z","timestamp":1786981443008,"version":"build-2736575974"},"reference-count":51,"publisher":"Springer Science and Business Media LLC","issue":"2","license":[{"start":{"date-parts":[[2021,10,12]],"date-time":"2021-10-12T00:00:00Z","timestamp":1633996800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2021,10,12]],"date-time":"2021-10-12T00:00:00Z","timestamp":1633996800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61902245"],"award-info":[{"award-number":["61902245"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62032020"],"award-info":[{"award-number":["62032020"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Mach Learn"],"published-print":{"date-parts":[[2022,2]]},"DOI":"10.1007\/s10994-021-06049-9","type":"journal-article","created":{"date-parts":[[2021,10,12]],"date-time":"2021-10-12T23:14:56Z","timestamp":1634080496000},"page":"685-711","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":11,"title":["Achieving adversarial robustness via sparsity"],"prefix":"10.1007","volume":"111","author":[{"given":"Ningyi","family":"Liao","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Shufan","family":"Wang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0165-4930","authenticated-orcid":false,"given":"Liyao","family":"Xiang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Nanyang","family":"Ye","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Shuo","family":"Shao","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Pengzhi","family":"Chu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2021,10,12]]},"reference":[{"key":"6049_CR1","doi-asserted-by":"crossref","unstructured":"Alzantot, M., Sharma, Y., Elgohary, A., Ho, B. J., Srivastava, M., & Chang, K. W. (2018). Generating Natural Language Adversarial Examples. In: Proceedings of the 2018 Conference on Empirical Methods in Natural Language Processing, Association for Computational Linguistics, pp 2890\u20132896.","DOI":"10.18653\/v1\/D18-1316"},{"key":"6049_CR2","unstructured":"Arora, S., Ge, R., Neyshabur, B., & Zhang, Y. (2018). Stronger generalization bounds for deep nets via a compression approach. In: 35th International Conference on Machine Learning, vol\u00a01, pp 390\u2013418."},{"key":"6049_CR3","unstructured":"Balda, E. R., Behboodi, A., Koep, N., & Mathar, R. (2019). Adversarial Risk Bounds for Neural Networks through Sparsity based Compression. In: 23rd International Conference on Artificial Intelligence and Statistics, vol 108, pp 3816\u20133825."},{"key":"6049_CR4","unstructured":"Bartoldson, B. R., Morcos, A. S., Barbu, A., & Erlebacher, G. (2020). The Generalization-Stability Tradeoff in Neural Network Pruning. 33rd Advances in Neural Information Processing Systems."},{"key":"6049_CR5","unstructured":"Bastani, O., Ioannou, Y., Lampropoulos, L., Vytiniotis, D., Nori, A., & Criminisi, A. (2016). Measuring neural net robustness with constraints. In: Advances in neural information processing systems, pp 2613\u20132621."},{"key":"6049_CR6","unstructured":"Cosentino, J., Zaiter, F., Pei, D., & Zhu, J. (2019). The search for sparse, robust neural networks. In: 33rd Conference on Neural Information Processing Systems, NeurIPS 2019."},{"key":"6049_CR7","unstructured":"Dhillon, G. S., Azizzadenesheli, K., Lipton, Z. C., Bernstein, J., Kossaifi, J., Khanna, A., & Anandkumar, A. (2018). Stochastic activation pruning for robust adversarial defense. arXiv preprint arXiv:180301442."},{"key":"6049_CR8","doi-asserted-by":"crossref","unstructured":"Dinh, T., Wang, B., Bertozzi, A. L., & Osher, S. J. (2020). Sparsity meets robustness: channel pruning for the feynman-kac formalism principled robust deep neural nets. arXiv preprint arXiv:200300631.","DOI":"10.1007\/978-3-030-64580-9_31"},{"key":"6049_CR9","unstructured":"Fawzi, A., Moosavi-Dezfooli, S. M., & Frossard, P. (2016). Robustness of classifiers: From adversarial to random noise. In: 29th Advances in Neural Information Processing Systems, pp 1632\u20131640."},{"key":"6049_CR10","doi-asserted-by":"crossref","unstructured":"Fawzi, A., Fawzi, O., & Frossard, P. (2018). Analysis of classifiers\u2019 robustness to adversarial perturbations. Machine Learning, 107(3), 481\u2013508.","DOI":"10.1007\/s10994-017-5663-3"},{"key":"6049_CR11","unstructured":"Frankle, J., & Carbin, M. (2019). The lottery ticket hypothesis: Finding sparse, trainable neural networks. In: 7th International Conference on Learning Representations, ICLR 2019, New Orleans, LA, USA, May 6-9, 2019."},{"key":"6049_CR12","doi-asserted-by":"crossref","unstructured":"Goldblum, M., Fowl, L., Feizi, S., & Goldstein, T. (2020). Adversarially robust distillation. In: Thirty-Fourth AAAI Conference on Artificial Intelligence.","DOI":"10.1609\/aaai.v34i04.5816"},{"key":"6049_CR13","unstructured":"Goodfellow, I. J., Shlens, J., & Szegedy, C. (2015). Explaining and harnessing adversarial examples. In: 3rd International Conference on Learning Representations, ICLR 2015, San Diego, CA, USA, May 7\u20139, 2015, Conference Track Proceedings."},{"key":"6049_CR14","unstructured":"Gui, S., Wang, H., Yu, C., Yang, H., Wang, Z., & Liu, J. (2019). Model compression with adversarial robustness: A unified optimization framework. In: Advances in Neural Information Processing Systems, pp 1283\u20131294."},{"key":"6049_CR15","doi-asserted-by":"crossref","unstructured":"Guo, M., Yang, Y., Xu, R., Liu, Z., & Lin, D. (2020). When nas meets robustness: In search of robust architectures against adversarial attacks. In: IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR), pp 631\u2013640.","DOI":"10.1109\/CVPR42600.2020.00071"},{"key":"6049_CR16","unstructured":"Guo, Y., Zhang, C., Zhang, C., & Chen, Y. (2018). Sparse dnns with improved adversarial robustness. In: Advances in neural information processing systems, pp 242\u2013251."},{"key":"6049_CR17","unstructured":"Han, S., Pool, J., Tran, J., & Dally, W. (2015). Learning both weights and connections for efficient neural network. In: Advances in neural information processing systems, pp 1135\u20131143."},{"key":"6049_CR18","unstructured":"Han, S., Mao, H., & Dally, W. J. (2016). Deep compression: Compressing deep neural network with pruning, trained quantization and huffman coding. In: 4th International Conference on Learning Representations, ICLR 2016, San Juan, Puerto Rico, May 2\u20134, 2016, Conference Track Proceedings."},{"key":"6049_CR19","unstructured":"Hassibi, B., & Stork, D. G. (1993). Second order derivatives for network pruning: Optimal brain surgeon. In: Advances in neural information processing systems, pp 164\u2013171."},{"key":"6049_CR20","doi-asserted-by":"crossref","unstructured":"He, K., Zhang, X., Ren, S., & Sun, J. (2016). Deep residual learning for image recognition. In: 2016 IEEE Conference on Computer Vision and Pattern Recognition, CVPR 2016, Las Vegas, NV, USA, June 27-30, 2016, pp 770\u2013778.","DOI":"10.1109\/CVPR.2016.90"},{"key":"6049_CR21","unstructured":"Hein, M., & Andriushchenko, M. (2017). Formal guarantees on the robustness of a classifier against adversarial manipulation. In: Advances in Neural Information Processing Systems, pp 2266\u20132276."},{"key":"6049_CR22","doi-asserted-by":"crossref","unstructured":"Huang, G., Liu, Z., van\u00a0der Maaten, L., & Weinberger, K. Q. (2017). Densely connected convolutional networks. In: 2017 IEEE Conference on Computer Vision and Pattern Recognition, CVPR 2017, Honolulu, HI, USA, July 21-26, 2017, pp 2261\u20132269.","DOI":"10.1109\/CVPR.2017.243"},{"key":"6049_CR23","unstructured":"Keskar, N. S., Nocedal, J., Tang, P. T. P., Mudigere, D., & Smelyanskiy, M. (2017). On large-batch training for deep learning: Generalization gap and sharp minima. In: 5th International Conference on Learning Representations."},{"key":"6049_CR24","unstructured":"Kurakin, A., Goodfellow, I. J., & Bengio, S. (2017). Adversarial machine learning at scale. In: 5th International Conference on Learning Representations, ICLR 2017, Toulon, France, April 24\u201326, 2017, Conference Track Proceedings."},{"key":"6049_CR25","unstructured":"Lang, J. (ed) (2018) Proceedings of the Twenty-Seventh International Joint Conference on Artificial Intelligence, IJCAI 2018, July 13\u201319, 2018, Stockholm, Sweden, ijcai.org."},{"key":"6049_CR26","unstructured":"LeCun, Y., Denker, J. S., & Solla, S. A. (1990). Optimal brain damage. In: Advances in neural information processing systems, pp 598\u2013605."},{"key":"6049_CR27","unstructured":"Li, B., Wang, S., Jia, Y., Lu, Y., Zhong, Z., Carin, L., & Jana, S. (2020). Towards practical lottery ticket hypothesis for adversarial training. arXiv preprint arXiv:200305733."},{"key":"6049_CR28","unstructured":"Li, H., Kadav, A., Durdanovic, I., Samet, H., & Graf, H. P. (2017). Pruning filters for efficient convnets. In: 5th International Conference on Learning Representations, ICLR 2017, Toulon, France, April 24\u201326, 2017, Conference Track Proceedings."},{"key":"6049_CR29","doi-asserted-by":"crossref","unstructured":"Liu, Z., Li, J., Shen, Z., Huang, G., Yan, S., & Zhang, C. (2017). Learning efficient convolutional networks through network slimming. In: IEEE International Conference on Computer Vision, ICCV 2017, Venice, Italy, October 22\u201329, 2017, pp 2755\u20132763.","DOI":"10.1109\/ICCV.2017.298"},{"key":"6049_CR30","unstructured":"Liu, Z., Sun, M., Zhou, T., Huang, G., & Darrell, T. (2019). Rethinking the value of network pruning. In: 7th International Conference on Learning Representations, ICLR 2019, New Orleans, LA, USA, May 6\u20139, 2019."},{"key":"6049_CR31","doi-asserted-by":"crossref","unstructured":"Luo, J. H., Wu, J., & Lin, W. (2017). Thinet: A filter level pruning method for deep neural network compression. In: IEEE International Conference on Computer Vision, ICCV 2017, Venice, Italy, October 22-29, 2017, pp 5068\u20135076.","DOI":"10.1109\/ICCV.2017.541"},{"key":"6049_CR32","unstructured":"Madaan, D., Shin, J., & Hwang, S. J. (2019). Adversarial neural pruning with latent vulnerability suppression. arXiv e-prints."},{"key":"6049_CR33","unstructured":"Madry, A., Makelov, A., Schmidt, L., Tsipras, D., & Vladu, A. (2018). Towards deep learning models resistant to adversarial attacks. In: 6th International Conference on Learning Representations, ICLR 2018, Vancouver, BC, Canada, April 30\u2013May 3, 2018, Conference Track Proceedings."},{"key":"6049_CR34","unstructured":"Miyato, T., Dai, A. M., & Goodfellow, I. (2017). Adversarial training methods for semi-supervised text classification. In: 5th International Conference on Learning Representations."},{"key":"6049_CR35","doi-asserted-by":"crossref","unstructured":"Moosavi-Dezfooli, S. M., Fawzi, A., & Frossard, P. (2016). Deepfool: a simple and accurate method to fool deep neural networks. In: Proceedings of the IEEE conference on computer vision and pattern recognition, pp 2574\u20132582.","DOI":"10.1109\/CVPR.2016.282"},{"key":"6049_CR36","unstructured":"Morcos, A. S., Yu, H., Paganini, M., & Tian, Y. (2019). One ticket to win them all: generalizing lottery ticket initializations across datasets and optimizers. In: 32nd Advances in Neural Information Processing Systems."},{"key":"6049_CR37","unstructured":"Petzka, H., Kamp, M., Adilova, L., Boley, M., & Sminchisescu, C. (2020). Relative Flatness and Generalization in the Interpolation Regime. arXiv e-prints."},{"key":"6049_CR38","unstructured":"Rakin, A. S., He, Z., Yang, L., Wang, Y., Wang, L., & Fan, D. (2019). Robust sparse regularization: Simultaneously optimizing neural network robustness and compactness. arXiv preprint arXiv:190513074."},{"key":"6049_CR39","unstructured":"Salman, H., Yang, G., Zhang, H., Hsieh, C. J., & Zhang, P. (2019). A convex relaxation barrier to tight robustness verification of neural networks. In: Advances in Neural Information Processing Systems, pp 9832\u20139842."},{"key":"6049_CR40","unstructured":"Sehwag, V., Wang, S., Mittal, P., & Jana, S. (2019). Towards compact and robust deep neural networks. arXiv e-prints."},{"key":"6049_CR41","unstructured":"Simonyan, K., & Zisserman, A. (2015). Very deep convolutional networks for large-scale image recognition. In: 3rd International Conference on Learning Representations, ICLR 2015, San Diego, CA, USA, May 7\u20139, 2015, Conference Track Proceedings."},{"key":"6049_CR42","unstructured":"Wang, B., Shi, Z., & Osher, S. (2019). Resnets ensemble via the feynman-kac formalism to improve natural and robust accuracies. In: Advances in Neural Information Processing Systems, pp 1655\u20131665."},{"key":"6049_CR43","unstructured":"Wang, L., Ding, G. W., Huang, R., Cao, Y., & Lui, Y. C. (2018). Adversarial robustness of pruned neural networks. In: Workshop of 6th International Conference on Learning Representations."},{"key":"6049_CR44","unstructured":"Wen, W., Wu, C., Wang, Y., Chen, Y., & Li, H. (2016). Learning structured sparsity in deep neural networks. In: Advances in neural information processing systems, pp 2074\u20132082."},{"issue":"3","key":"6049_CR45","doi-asserted-by":"publisher","first-page":"391","DOI":"10.1007\/s10994-011-5268-1","volume":"86","author":"H Xu","year":"2012","unstructured":"Xu, H., & Mannor, S. (2012). Robustness and generalization. Machine Learning, 86(3), 391\u2013423.","journal-title":"Machine Learning"},{"key":"6049_CR46","unstructured":"Yang, Y., Zhang, G., Xu, Z., & Katabi, D. (2019). Me-net: Towards effective adversarial robustness with matrix estimation. In: Proceedings of the 36th International Conference on Machine Learning, ICML 2019, 9-15 June 2019, Long Beach, California, USA, pp 7025\u20137034."},{"key":"6049_CR47","unstructured":"Ye, J., Lu, X., Lin, Z., & Wang, J. Z. (2018). Rethinking the smaller-norm-less-informative assumption in channel pruning of convolution layers. In: International Conference on Learning Representations."},{"key":"6049_CR48","doi-asserted-by":"crossref","unstructured":"Ye, S., Xu, K., Liu, S., Cheng, H., Lambrechts, J. H., Zhang, H., Zhou, A., Ma, K., Wang, Y., & Lin, X. (2019). Adversarial robustness vs model compression, or both? In: International Conference on Computer Vision.","DOI":"10.1109\/ICCV.2019.00020"},{"key":"6049_CR49","unstructured":"Zhang, H., Yu, Y., Jiao, J., Xing, E. P., Ghaoui, L. E., & Jordan, M. I. (2019). Theoretically principled trade-off between robustness and accuracy. In: Proceedings of the 36th International Conference on Machine Learning, ICML 2019, 9\u201315 June 2019, Long Beach, California, USA, pp 7472\u20137482."},{"key":"6049_CR50","unstructured":"Zhang, T., & Zhu, Z. (2019). Interpreting adversarially trained convolutional neural networks. In: Proceedings of the 36th International Conference on Machine Learning, ICML 2019, 9-15 June 2019, Long Beach, California, USA, pp 7502\u20137511."},{"key":"6049_CR51","unstructured":"Zhao, Y., Shumailov, I., Mullins, R., & Anderson, R. (2018). To compress or not to compress: Understanding the interactions between adversarial attacks and neural network compression. arXiv preprint arXiv:181000208."}],"container-title":["Machine Learning"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10994-021-06049-9.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10994-021-06049-9\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10994-021-06049-9.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,10,11]],"date-time":"2022-10-11T20:12:48Z","timestamp":1665519168000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10994-021-06049-9"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,10,12]]},"references-count":51,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2022,2]]}},"alternative-id":["6049"],"URL":"https:\/\/doi.org\/10.1007\/s10994-021-06049-9","relation":{},"ISSN":["0885-6125","1573-0565"],"issn-type":[{"value":"0885-6125","type":"print"},{"value":"1573-0565","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,10,12]]},"assertion":[{"value":"31 January 2021","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"26 July 2021","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"27 August 2021","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"12 October 2021","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare that they have no conflict of interest.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflicts of interest"}},{"value":"This content has been made available to all.","name":"free","label":"Free to read"}]}}