{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,14]],"date-time":"2026-05-14T07:55:17Z","timestamp":1778745317482,"version":"3.51.4"},"reference-count":75,"publisher":"Association for Computing Machinery (ACM)","issue":"5","license":[{"start":{"date-parts":[[2022,4,5]],"date-time":"2022-04-05T00:00:00Z","timestamp":1649116800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000001","name":"US National Science Foundation","doi-asserted-by":"crossref","award":["IIS-1938167, IIS-1955151, IIS-2008208, IIS-2106913, and OAC-1934600"],"award-info":[{"award-number":["IIS-1938167, IIS-1955151, IIS-2008208, IIS-2106913, and OAC-1934600"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Knowl. Discov. Data"],"published-print":{"date-parts":[[2022,10,31]]},"abstract":"<jats:p>Metric learning aims at automatically learning a distance metric from data so that the precise similarity between data instances can be faithfully reflected, and its importance has long been recognized in many fields. An implicit assumption in existing metric learning works is that the learned models are performed in a reliable and secure environment. However, the increasingly critical role of metric learning makes it susceptible to a risk of being malicious attacked. To well understand the performance of metric learning models in adversarial environments, in this article, we study the robustness of metric learning to adversarial perturbations, which are also known as the imperceptible changes to the input data that are crafted by an attacker to fool a well-learned model. However, different from traditional classification models, metric learning models take instance pairs rather than individual instances as input, and the perturbation on one instance may not necessarily affect the prediction result for an instance pair, which makes it more difficult to study the robustness of metric learning. To address this challenge, in this article, we first provide a definition of pairwise robustness for metric learning, and then propose a novel projected gradient descent-based attack method (called AckMetric) to evaluate the robustness of metric learning models. To further explore the capability of the attacker to change the prediction results, we also propose a theoretical framework to derive the upper bound of the pairwise adversarial loss. Finally, we incorporate the derived bound into the training process of metric learning and design a novel defense method to make the learned models more robust. Extensive experiments on real-world datasets demonstrate the effectiveness of the proposed methods.<\/jats:p>","DOI":"10.1145\/3502726","type":"journal-article","created":{"date-parts":[[2022,4,5]],"date-time":"2022-04-05T13:45:33Z","timestamp":1649166333000},"page":"1-25","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":6,"title":["On the Robustness of Metric Learning: An Adversarial Perspective"],"prefix":"10.1145","volume":"16","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-6368-5973","authenticated-orcid":false,"given":"Mengdi","family":"Huai","sequence":"first","affiliation":[{"name":"University of Virginia, Charlottesville, VA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tianhang","family":"Zheng","sequence":"additional","affiliation":[{"name":"University of Toronto, Toronto, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Chenglin","family":"Miao","sequence":"additional","affiliation":[{"name":"University of Georgia, Athens, GA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3828-796X","authenticated-orcid":false,"given":"Liuyi","family":"Yao","sequence":"additional","affiliation":[{"name":"Alibaba Group, Hangzhou, Zhejiang, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Aidong","family":"Zhang","sequence":"additional","affiliation":[{"name":"University of Virginia, Charlottesville, VA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2022,4,5]]},"reference":[{"key":"e_1_3_3_2_2","first-page":"921","article-title":"Metric transfer learning via geometric knowledge embedding","author":"Ahmadvand Mahya","year":"2020","unstructured":"Mahya Ahmadvand and Jafar Tahmoresnezhad. 2020. Metric transfer learning via geometric knowledge embedding. Applied Intelligence 51, 2 (2020), 921\u2013934.","journal-title":"Applied Intelligence"},{"key":"e_1_3_3_3_2","volume-title":"Proceedings of the NeurIPS","author":"Bastani Osbert","year":"2016","unstructured":"Osbert Bastani, Yani Ioannou, Leonidas Lampropoulos, Dimitrios Vytiniotis, Aditya Nori, and Antonio Criminisi. 2016. Measuring neural net robustness with constraints. In Proceedings of the NeurIPS."},{"key":"e_1_3_3_4_2","article-title":"Curriculum adversarial training","author":"Cai Qi-Zhi","year":"2018","unstructured":"Qi-Zhi Cai, Min Du, Chang Liu, and Dawn Song. 2018. Curriculum adversarial training. arXiv:1805.04807. Retrieved from https:\/\/arxiv.org\/abs\/1805.04807.","journal-title":"arXiv:1805.04807"},{"key":"e_1_3_3_5_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"e_1_3_3_6_2","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2018\/279"},{"key":"e_1_3_3_7_2","doi-asserted-by":"publisher","DOI":"10.1145\/1273496.1273523"},{"key":"e_1_3_3_8_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00294"},{"key":"e_1_3_3_9_2","doi-asserted-by":"crossref","unstructured":"Ismail Elezi Sebastiano Vascon Alessandro Torcinovich Marcello Pelillo and Laura Leal-Taixe. 2020. The group loss for deep metric learning. In Proceedings of the European Conference on Computer Vision . Springer 277\u2013294.","DOI":"10.1007\/978-3-030-58571-6_17"},{"key":"e_1_3_3_10_2","doi-asserted-by":"crossref","unstructured":"Xingyu Gao Steven CH Hoi Yongdong Zhang Ji Wan and Jintao Li. 2014. Soml: Sparse online metric learning with application to image retrieval. In Proceedings of the 28th AAAI Conference on Artificial Intelligence . 1206\u20131212.","DOI":"10.1609\/aaai.v28i1.8911"},{"key":"e_1_3_3_11_2","article-title":"Explaining and harnessing adversarial examples","author":"Goodfellow Ian J.","year":"2014","unstructured":"Ian J. Goodfellow, Jonathon Shlens, and Christian Szegedy. 2014. Explaining and harnessing adversarial examples. arXiv:1412.6572. Retrieved from https:\/\/arxiv.org\/abs\/1412.6572.","journal-title":"arXiv:1412.6572"},{"key":"e_1_3_3_12_2","article-title":"Explaining and harnessing adversarial examples","author":"Goodfellow Ian J.","year":"2014","unstructured":"Ian J. Goodfellow, Jonathon Shlens, and Christian Szegedy. 2014. Explaining and harnessing adversarial examples. arXiv:1412.6572. Retrieved from https:\/\/arxiv.org\/abs\/1412.6572.","journal-title":"arXiv:1412.6572"},{"key":"e_1_3_3_13_2","volume-title":"Proceedings of the AAAI Conference on Artificial Intelligence","author":"Guo Jiaxian","year":"2018","unstructured":"Jiaxian Guo, Sidi Lu, Han Cai, Weinan Zhang, Yong Yu, and Jun Wang. 2018. Long text generation via adversarial training with leaked information. In Proceedings of the AAAI Conference on Artificial Intelligence."},{"key":"e_1_3_3_14_2","unstructured":"Jamie Hayes and George Danezis. 2017. Machine learning as an adversarial service: Learning black-box adversarial examples. arXiv preprint arXiv:1708.05207."},{"key":"e_1_3_3_15_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2014.242"},{"key":"e_1_3_3_16_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298629"},{"key":"e_1_3_3_17_2","doi-asserted-by":"publisher","DOI":"10.1145\/2700405"},{"key":"e_1_3_3_18_2","doi-asserted-by":"publisher","DOI":"10.1145\/3219819.3219976"},{"key":"e_1_3_3_19_2","doi-asserted-by":"publisher","DOI":"10.1145\/3364320"},{"key":"e_1_3_3_20_2","doi-asserted-by":"publisher","DOI":"10.1109\/BIBM49941.2020.9313255"},{"key":"e_1_3_3_21_2","doi-asserted-by":"publisher","DOI":"10.1145\/3394486.3403089"},{"key":"e_1_3_3_22_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i01.5411"},{"key":"e_1_3_3_23_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i04.5837"},{"key":"e_1_3_3_24_2","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2019\/352"},{"key":"e_1_3_3_25_2","volume-title":"Proceedings of the Neural Information Processing Systems","author":"Huang Chen","year":"2016","unstructured":"Chen Huang, Chen Change Loy, and Xiaoou Tang. 2016. Local similarity-aware deep feature embedding. In Proceedings of the Neural Information Processing Systems."},{"key":"e_1_3_3_26_2","doi-asserted-by":"publisher","DOI":"10.1049\/iet-ipr.2018.5871"},{"key":"e_1_3_3_27_2","doi-asserted-by":"publisher","DOI":"10.1145\/3292500.3330975"},{"key":"e_1_3_3_28_2","article-title":"Adversarial machine learning: Perspectives from adversarial risk analysis","author":"Insua David Rios","year":"2020","unstructured":"David Rios Insua, Roi Naveiro, Victor Gallego, and Jason Poulos. 2020. Adversarial machine learning: Perspectives from adversarial risk analysis. arXiv:2003.03546. Retrieved from https:\/\/arxiv.org\/abs\/2003.03546.","journal-title":"arXiv:2003.03546"},{"key":"e_1_3_3_29_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00239"},{"key":"e_1_3_3_30_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01246-5_45"},{"key":"e_1_3_3_31_2","doi-asserted-by":"publisher","DOI":"10.1007\/s41019-020-00125-1"},{"key":"e_1_3_3_32_2","article-title":"Adversarial machine learning at scale","author":"Kurakin Alexey","year":"2016","unstructured":"Alexey Kurakin, Ian Goodfellow, and Samy Bengio. 2016. Adversarial machine learning at scale. In Proceedings of the International Conference on Learning Representations.","journal-title":"Proceedings of the International Conference on Learning Representations"},{"key":"e_1_3_3_33_2","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Law Marc T.","year":"2017","unstructured":"Marc T. Law, Raquel Urtasun, and Richard S. Zemel. 2017. Deep spectral clustering learning. In Proceedings of the International Conference on Machine Learning."},{"key":"e_1_3_3_34_2","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"key":"e_1_3_3_35_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01267-0_42"},{"key":"e_1_3_3_36_2","doi-asserted-by":"crossref","unstructured":"Max A. Little Patrick E. McSharry Eric J Hunter Jennifer Spielman and Lorraine O Ramig. 2008. Suitability of dysphonia measurements for telemonitoring of Parkinson\u2019s disease. Nature Precedings (2008) 1\u20131.","DOI":"10.1038\/npre.2008.2298.1"},{"key":"e_1_3_3_37_2","doi-asserted-by":"publisher","DOI":"10.1109\/ITNEC.2019.8729439"},{"key":"e_1_3_3_38_2","article-title":"Transfer metric learning: Algorithms, applications and outlooks","author":"Luo Yong","year":"2018","unstructured":"Yong Luo, Yonggang Wen, Ling-Yu Duan, and Dacheng Tao. 2018. Transfer metric learning: Algorithms, applications and outlooks. arXiv:1810.03944. Retrieved from https:\/\/arxiv.org\/abs\/1810.03944.","journal-title":"arXiv:1810.03944"},{"key":"e_1_3_3_39_2","article-title":"Towards deep learning models resistant to adversarial attacks","author":"Madry Aleksander","year":"2017","unstructured":"Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu. 2017. Towards deep learning models resistant to adversarial attacks. arXiv:1706.06083. Retrieved from https:\/\/arxiv.org\/abs\/1706.06083.","journal-title":"arXiv:1706.06083"},{"key":"e_1_3_3_40_2","first-page":"480","volume-title":"Proceedings of the Advances in Neural Information Processing Systems","author":"Mao Chengzhi","year":"2019","unstructured":"Chengzhi Mao, Ziyuan Zhong, Junfeng Yang, Carl Vondrick, and Baishakhi Ray. 2019. Metric learning for adversarial robustness. In Proceedings of the Advances in Neural Information Processing Systems. 480\u2013491."},{"key":"e_1_3_3_41_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.17"},{"key":"e_1_3_3_42_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"e_1_3_3_43_2","doi-asserted-by":"publisher","DOI":"10.1117\/1.JEI.27.4.043026"},{"key":"e_1_3_3_44_2","doi-asserted-by":"publisher","DOI":"10.1162\/neco_a_00614"},{"key":"e_1_3_3_45_2","article-title":"Seven: Deep semi-supervised verification networks","author":"Noroozi Vahid","year":"2017","unstructured":"Vahid Noroozi, Lei Zheng, Sara Bahaadini, Sihong Xie, and Philip S Yu. 2017. Seven: Deep semi-supervised verification networks. arXiv:1706.03692. Retrieved from https:\/\/arxiv.org\/abs\/1706.03692.","journal-title":"arXiv:1706.03692"},{"key":"e_1_3_3_46_2","doi-asserted-by":"publisher","DOI":"10.1137\/1.9781611975321.48"},{"key":"e_1_3_3_47_2","article-title":"Certified defenses against adversarial examples","author":"Raghunathan Aditi","year":"2018","unstructured":"Aditi Raghunathan, Jacob Steinhardt, and Percy Liang. 2018. Certified defenses against adversarial examples. arXiv:1801.09344. Retrieved from https:\/\/arxiv.org\/abs\/1801.09344.","journal-title":"arXiv:1801.09344"},{"key":"e_1_3_3_48_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2019.03.021"},{"key":"e_1_3_3_49_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v28i1.8968"},{"key":"e_1_3_3_50_2","doi-asserted-by":"publisher","DOI":"10.1145\/2408736.2408740"},{"key":"e_1_3_3_51_2","article-title":"Ensemble adversarial training: Attacks and defenses","author":"Tram\u00e8r Florian","year":"2017","unstructured":"Florian Tram\u00e8r, Alexey Kurakin, Nicolas Papernot, Ian Goodfellow, Dan Boneh, and Patrick McDaniel. 2017. Ensemble adversarial training: Attacks and defenses. arXiv:1705.07204. Retrieved from https:\/\/arxiv.org\/abs\/1705.07204.","journal-title":"arXiv:1705.07204"},{"key":"e_1_3_3_52_2","article-title":"The space of transferable adversarial examples","author":"Tram\u00e8r Florian","year":"2017","unstructured":"Florian Tram\u00e8r, Nicolas Papernot, Ian Goodfellow, Dan Boneh, and Patrick McDaniel. 2017. The space of transferable adversarial examples. arXiv:1704.03453. Retrieved from https:\/\/arxiv.org\/abs\/1704.03453.","journal-title":"arXiv:1704.03453"},{"key":"e_1_3_3_53_2","article-title":"Image classification based on principal component analysis optimized generative adversarial networks","author":"Wang Chunzhi","year":"2021","unstructured":"Chunzhi Wang, Pan Wu, Lingyu Yan, Zhiwei Ye, Hongwei Chen, and Hefei Ling. 2021. Image classification based on principal component analysis optimized generative adversarial networks. Multimedia Tools and Applications 80, 6 (2021), 9687\u20139701.","journal-title":"Multimedia Tools and Applications"},{"key":"e_1_3_3_54_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.283"},{"key":"e_1_3_3_55_2","doi-asserted-by":"publisher","DOI":"10.1109\/BIBM47256.2019.8983411"},{"key":"e_1_3_3_56_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00516"},{"key":"e_1_3_3_57_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00535"},{"key":"e_1_3_3_58_2","volume-title":"Proceedings of the Conference on Neural Information Processing Systems","author":"Weinberger Kilian Q","year":"2006","unstructured":"Kilian Q Weinberger, John Blitzer, and Lawrence K Saul. 2006. Distance metric learning for large margin nearest neighbor classification. In Proceedings of the Conference on Neural Information Processing Systems."},{"issue":"2","key":"e_1_3_3_59_2","first-page":"207","article-title":"Distance metric learning for large margin nearest neighbor classification","volume":"10","author":"Weinberger Kilian Q","year":"2009","unstructured":"Kilian Q Weinberger and Lawrence K Saul. 2009. Distance metric learning for large margin nearest neighbor classification. Journal of Machine Learning Research 10, 2 (2009), 207\u2013244.","journal-title":"Journal of Machine Learning Research"},{"key":"e_1_3_3_60_2","volume-title":"Proceedings of the IInternational Conference on Machine Learning","author":"Wong Eric","year":"2018","unstructured":"Eric Wong and Zico Kolter. 2018. Provable defenses against adversarial examples via the convex outer adversarial polytope. In Proceedings of the IInternational Conference on Machine Learning."},{"key":"e_1_3_3_61_2","volume-title":"Proceedings of the IInternational Conference on Machine Learning","author":"Xie Pengtao","year":"2018","unstructured":"Pengtao Xie, Wei Wu, Yichen Zhu, and Eric Xing. 2018. Orthogonality-promoting distance metric learning: Convex relaxation and theoretical analysis. In Proceedings of the IInternational Conference on Machine Learning."},{"key":"e_1_3_3_62_2","first-page":"521","volume-title":"Proceedings of the Advances in Neural Information Processing Systems","author":"Xing Eric P.","year":"2003","unstructured":"Eric P. Xing, Michael I. Jordan, Stuart J. Russell, and Andrew Y. Ng. 2003. Distance metric learning with application to clustering with side-information. In Proceedings of the Advances in Neural Information Processing Systems. 521\u2013528."},{"key":"e_1_3_3_63_2","doi-asserted-by":"publisher","DOI":"10.1145\/2789212"},{"key":"e_1_3_3_64_2","doi-asserted-by":"publisher","DOI":"10.1145\/3219819.3220016"},{"key":"e_1_3_3_65_2","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2017.2669193"},{"key":"e_1_3_3_66_2","first-page":"2184","volume-title":"Proceedings of the 2018 IEEE International Conference on Robotics and Biomimetics","author":"Xu Yonghui","year":"2018","unstructured":"Yonghui Xu, Bo Xu, Jingtang Zhong, Zhen Zhu, Pengshuai Yin, Huaqing Min, et\u00a0al. 2018. A novel transfer metric learning approach based on multi-group. In Proceedings of the 2018 IEEE International Conference on Robotics and Biomimetics. IEEE, 2184\u20132189."},{"key":"e_1_3_3_67_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2020.106132"},{"key":"e_1_3_3_68_2","doi-asserted-by":"crossref","unstructured":"Zhiyu Xue Shaoyang Yang Mengdi Huai and Di Wang. 2021. Differentially private pairwise learning revisited. IJCAI.","DOI":"10.24963\/ijcai.2021\/446"},{"key":"e_1_3_3_69_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.ymeth.2020.05.015"},{"key":"e_1_3_3_70_2","first-page":"18","volume-title":"Proceedings of the International Workshop on Digital Watermarking","author":"Yang Zhongliang","year":"2019","unstructured":"Zhongliang Yang, Nan Wei, Qinghe Liu, Yongfeng Huang, and Yujin Zhang. 2019. GAN-TStega: Text steganography based on generative adversarial networks. In Proceedings of the International Workshop on Digital Watermarking. Springer, 18\u201331."},{"key":"e_1_3_3_71_2","first-page":"1235","volume-title":"Proceedings of the Advances in Neural Information Processing Systems","author":"Ye Han-Jia","year":"2016","unstructured":"Han-Jia Ye, De-Chuan Zhan, Xue-Min Si, Yuan Jiang, and Zhi-Hua Zhou. 2016. What makes objects similar: A unified multi-metric learning approach. In Proceedings of the Advances in Neural Information Processing Systems. 1235\u20131243."},{"key":"e_1_3_3_72_2","first-page":"2464","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Zadeh Pourya","year":"2016","unstructured":"Pourya Zadeh, Reshad Hosseini, and Suvrit Sra. 2016. Geometric mean metric learning. In Proceedings of the International Conference on Machine Learning. 2464\u20132471."},{"key":"e_1_3_3_73_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICDM.2016.0182"},{"key":"e_1_3_3_74_2","unstructured":"Dingyi Zhang Yingming Li and Zhongfei Zhang. 2020. Deep metric learning with spherical embedding. Advances in Neural Information Processing Systems 33 (2020)."},{"key":"e_1_3_3_75_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00397"},{"key":"e_1_3_3_76_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01240-3_31"}],"container-title":["ACM Transactions on Knowledge Discovery from Data"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3502726","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3502726","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T18:09:47Z","timestamp":1750183787000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3502726"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,4,5]]},"references-count":75,"journal-issue":{"issue":"5","published-print":{"date-parts":[[2022,10,31]]}},"alternative-id":["10.1145\/3502726"],"URL":"https:\/\/doi.org\/10.1145\/3502726","relation":{},"ISSN":["1556-4681","1556-472X"],"issn-type":[{"value":"1556-4681","type":"print"},{"value":"1556-472X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,4,5]]},"assertion":[{"value":"2020-08-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2021-11-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2022-04-05","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}