{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,13]],"date-time":"2026-03-13T22:55:52Z","timestamp":1773442552004,"version":"3.50.1"},"publisher-location":"New York, NY, USA","reference-count":55,"publisher":"ACM","license":[{"start":{"date-parts":[[2022,10,17]],"date-time":"2022-10-17T00:00:00Z","timestamp":1665964800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"the Innovation Project of ICT CAS","award":["E261090"],"award-info":[{"award-number":["E261090"]}]},{"name":"the Young Elite Scientist Sponsorship Program by CAST","award":["YESS20200121"],"award-info":[{"award-number":["YESS20200121"]}]},{"name":"the Hybrid Intelligence Center"},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62006218, 61902381"],"award-info":[{"award-number":["62006218, 61902381"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100004739","name":"Youth Innovation Promotion Association of the Chinese Academy of Sciences","doi-asserted-by":"publisher","award":["20144310, 2021100"],"award-info":[{"award-number":["20144310, 2021100"]}],"id":[{"id":"10.13039\/501100004739","id-type":"DOI","asserted-by":"publisher"}]},{"name":"the Lenovo-CAS Joint Lab Youth Scientist Project"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2022,10,17]]},"DOI":"10.1145\/3511808.3557256","type":"proceedings-article","created":{"date-parts":[[2022,10,16]],"date-time":"2022-10-16T01:22:22Z","timestamp":1665883342000},"page":"2128-2137","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":8,"title":["Certified Robustness to Word Substitution Ranking Attack for Neural Ranking Models"],"prefix":"10.1145","author":[{"given":"Chen","family":"Wu","sequence":"first","affiliation":[{"name":"CAS Key Lab of Network Data Science and Technology, ICT, CAS; University of Chinese Academy of Sciences, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ruqing","family":"Zhang","sequence":"additional","affiliation":[{"name":"CAS Key Lab of Network Data Science and Technology, ICT, CAS; University of Chinese Academy of Sciences, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jiafeng","family":"Guo","sequence":"additional","affiliation":[{"name":"CAS Key Lab of Network Data Science and Technology, ICT, CAS; University of Chinese Academy of Sciences, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wei","family":"Chen","sequence":"additional","affiliation":[{"name":"CAS Key Lab of Network Data Science and Technology, ICT, CAS; University of Chinese Academy of Sciences, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yixing","family":"Fan","sequence":"additional","affiliation":[{"name":"CAS Key Lab of Network Data Science and Technology, ICT, CAS; University of Chinese Academy of Sciences, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Maarten","family":"de Rijke","sequence":"additional","affiliation":[{"name":"University of Amsterdam, Amsterdam, Netherlands"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xueqi","family":"Cheng","sequence":"additional","affiliation":[{"name":"CAS Key Lab of Network Data Science and Technology, ICT, CAS; University of Chinese Academy of Sciences, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2022,10,17]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Generating natural language adversarial examples. arXiv preprint arXiv:1804.07998","author":"Alzantot Moustafa","year":"2018","unstructured":"Moustafa Alzantot , Yash Sharma , Ahmed Elgohary , Bo-Jhang Ho , Mani Srivastava , and Kai-Wei Chang . 2018. Generating natural language adversarial examples. arXiv preprint arXiv:1804.07998 ( 2018 ). Moustafa Alzantot, Yash Sharma, Ahmed Elgohary, Bo-Jhang Ho, Mani Srivastava, and Kai-Wei Chang. 2018. Generating natural language adversarial examples. arXiv preprint arXiv:1804.07998 (2018)."},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/1102351.1102363"},{"key":"e_1_3_2_1_3_1","volume-title":"Adversarial web search","author":"Castillo Carlos","unstructured":"Carlos Castillo and Brian D Davison . 2011. Adversarial web search . Vol. 4 . Carlos Castillo and Brian D Davison. 2011. Adversarial web search. Vol. 4."},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"crossref","unstructured":"Minhao Cheng Wei Wei and Cho-Jui Hsieh. 2019. Evaluating and enhancing the robustness of dialogue systems: A case study on a negotiation agent. In NAACL.  Minhao Cheng Wei Wei and Cho-Jui Hsieh. 2019. Evaluating and enhancing the robustness of dialogue systems: A case study on a negotiation agent. In NAACL.","DOI":"10.18653\/v1\/N19-1336"},{"key":"e_1_3_2_1_5_1","unstructured":"Jeremy Cohen Elan Rosenfeld and Zico Kolter. 2019. Certified adversarial robustness via randomized smoothing. In ICML.  Jeremy Cohen Elan Rosenfeld and Zico Kolter. 2019. Certified adversarial robustness via randomized smoothing. In ICML."},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"crossref","unstructured":"Zhuyun Dai and Jamie Callan. 2019. Deeper text understanding for IR with contextual neural language modeling. In SIGIR. 985--988.  Zhuyun Dai and Jamie Callan. 2019. Deeper text understanding for IR with contextual neural language modeling. In SIGIR. 985--988.","DOI":"10.1145\/3331184.3331303"},{"key":"e_1_3_2_1_7_1","volume-title":"BERT: Pre-training of Deep Bidirectional Transformers for Language Understanding. In NAACL.","author":"Devlin Jacob","year":"2019","unstructured":"Jacob Devlin , Ming-Wei Chang , Kenton Lee , and Kristina Toutanova . 2019 . BERT: Pre-training of Deep Bidirectional Transformers for Language Understanding. In NAACL. Jacob Devlin, Ming-Wei Chang, Kenton Lee, and Kristina Toutanova. 2019. BERT: Pre-training of Deep Bidirectional Transformers for Language Understanding. In NAACL."},{"key":"e_1_3_2_1_8_1","volume-title":"Towards Robustness Against Natural Language Word Substitutions. In International Conference on Learning Representations.","author":"Dong Xinshuai","year":"2020","unstructured":"Xinshuai Dong , Anh Tuan Luu , Rongrong Ji , and Hong Liu . 2020 . Towards Robustness Against Natural Language Word Substitutions. In International Conference on Learning Representations. Xinshuai Dong, Anh Tuan Luu, Rongrong Ji, and Hong Liu. 2020. Towards Robustness Against Natural Language Word Substitutions. In International Conference on Learning Representations."},{"key":"e_1_3_2_1_9_1","volume-title":"Training verified learners with learned verifiers. arXiv preprint arXiv:1805.10265","author":"Dvijotham Krishnamurthy","year":"2018","unstructured":"Krishnamurthy Dvijotham , Sven Gowal , Robert Stanforth , Relja Arandjelovic , Brendan O'Donoghue , Jonathan Uesato , and Pushmeet Kohli . 2018. Training verified learners with learned verifiers. arXiv preprint arXiv:1805.10265 ( 2018 ). Krishnamurthy Dvijotham, Sven Gowal, Robert Stanforth, Relja Arandjelovic, Brendan O'Donoghue, Jonathan Uesato, and Pushmeet Kohli. 2018. Training verified learners with learned verifiers. arXiv preprint arXiv:1805.10265 (2018)."},{"key":"e_1_3_2_1_10_1","volume-title":"Mary Lou Soffa, and Yanjun Qi","author":"Gao Ji","year":"2018","unstructured":"Ji Gao , Jack Lanchantin , Mary Lou Soffa, and Yanjun Qi . 2018 . Black-box generation of adversarial text sequences to evade deep learning classifiers. In SPW. IEEE , 50--56. Ji Gao, Jack Lanchantin, Mary Lou Soffa, and Yanjun Qi. 2018. Black-box generation of adversarial text sequences to evade deep learning classifiers. In SPW. IEEE, 50--56."},{"key":"e_1_3_2_1_11_1","volume-title":"Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572","author":"Goodfellow Ian J","year":"2014","unstructured":"Ian J Goodfellow , Jonathon Shlens , and Christian Szegedy . 2014. Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572 ( 2014 ). Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy. 2014. Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572 (2014)."},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"crossref","unstructured":"Gregory Goren Oren Kurland Moshe Tennenholtz and Fiana Raiber. 2018. Ranking robustness under adversarial document manipulations. In SIGIR.  Gregory Goren Oren Kurland Moshe Tennenholtz and Fiana Raiber. 2018. Ranking robustness under adversarial document manipulations. In SIGIR.","DOI":"10.1145\/3209978.3210012"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"crossref","unstructured":"Gregory Goren Oren Kurland Moshe Tennenholtz and Fiana Raiber. 2020. Ranking-Incentivized Quality Preserving Content Modification. In SIGIR.  Gregory Goren Oren Kurland Moshe Tennenholtz and Fiana Raiber. 2020. Ranking-Incentivized Quality Preserving Content Modification. In SIGIR.","DOI":"10.1145\/3397271.3401058"},{"key":"e_1_3_2_1_14_1","unstructured":"Jia-Chen Gu Tianda Li Quan Liu Zhen-Hua Ling Zhiming Su Si Wei and Xiaodan Zhu. 2020. Speaker-aware BERT for multi-turn response selection in retrieval-based chatbots. In CIKM. 2041--2044.  Jia-Chen Gu Tianda Li Quan Liu Zhen-Hua Ling Zhiming Su Si Wei and Xiaodan Zhu. 2020. Speaker-aware BERT for multi-turn response selection in retrieval-based chatbots. In CIKM. 2041--2044."},{"key":"e_1_3_2_1_15_1","unstructured":"Zoltan Gyongyi and Hector Garcia-Molina. 2005. Web spam taxonomy. In AIRWeb.  Zoltan Gyongyi and Hector Garcia-Molina. 2005. Web spam taxonomy. In AIRWeb."},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"crossref","unstructured":"Po-Sen Huang Robert Stanforth Johannes Welbl Chris Dyer Dani Yogatama Sven Gowal Krishnamurthy Dvijotham and Pushmeet Kohli. 2019. Achieving Verified Robustness to Symbol Substitutions via Interval Bound Propagation. In EMNLP\/IJCNLP (1).  Po-Sen Huang Robert Stanforth Johannes Welbl Chris Dyer Dani Yogatama Sven Gowal Krishnamurthy Dvijotham and Pushmeet Kohli. 2019. Achieving Verified Robustness to Symbol Substitutions via Interval Bound Propagation. In EMNLP\/IJCNLP (1).","DOI":"10.18653\/v1\/D19-1419"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"crossref","unstructured":"Robin Jia and Percy Liang. 2017. Adversarial Examples for Evaluating Reading Comprehension Systems. In EMNLP.  Robin Jia and Percy Liang. 2017. Adversarial Examples for Evaluating Reading Comprehension Systems. In EMNLP.","DOI":"10.18653\/v1\/D17-1215"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"crossref","unstructured":"Robin Jia Aditi Raghunathan Kerem G\u00f6ksel and Percy Liang. 2019. Certified Robustness to Adversarial Word Substitutions. In EMNLP\/IJCNLP (1).  Robin Jia Aditi Raghunathan Kerem G\u00f6ksel and Percy Liang. 2019. Certified Robustness to Adversarial Word Substitutions. In EMNLP\/IJCNLP (1).","DOI":"10.18653\/v1\/D19-1423"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/3130332.3130334"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1162\/tacl_a_00300"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-63387-9_5"},{"key":"e_1_3_2_1_22_1","volume-title":"Colbert: Efficient and effective passage search via contextualized late interaction over bert. In SIGIR.","author":"Khattab Omar","year":"2020","unstructured":"Omar Khattab and Matei Zaharia . 2020 . Colbert: Efficient and effective passage search via contextualized late interaction over bert. In SIGIR. Omar Khattab and Matei Zaharia. 2020. Colbert: Efficient and effective passage search via contextualized late interaction over bert. In SIGIR."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00044"},{"key":"e_1_3_2_1_24_1","volume-title":"Deep text classification can be fooled. arXiv preprint arXiv:1704.08006","author":"Liang Bin","year":"2017","unstructured":"Bin Liang , Hongcheng Li , Miaoqiang Su , Pan Bian , Xirong Li , and Wenchang Shi . 2017. Deep text classification can be fooled. arXiv preprint arXiv:1704.08006 ( 2017 ). Bin Liang, Hongcheng Li, Miaoqiang Su, Pan Bian, Xirong Li, and Wenchang Shi. 2017. Deep text classification can be fooled. arXiv preprint arXiv:1704.08006 (2017)."},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.2200\/S01123ED1V01Y202108HLT053"},{"key":"e_1_3_2_1_26_1","volume-title":"Learning to Rank for Information Retrieval","author":"Liu Tie-Yan","unstructured":"Tie-Yan Liu . 2011. Learning to Rank for Information Retrieval . Springer Science & Business Media . Tie-Yan Liu. 2011. Learning to Rank for Information Retrieval. Springer Science & Business Media."},{"key":"e_1_3_2_1_27_1","volume-title":"B-PROP: Bootstrapped pre-training with representative words prediction for ad-hoc retrieval. arXiv preprint arXiv:2104.09791","author":"Ma Xinyu","year":"2021","unstructured":"Xinyu Ma , Jiafeng Guo , Ruqing Zhang , Yixing Fan , Yingyan Li , and Xueqi Cheng . 2021. B-PROP: Bootstrapped pre-training with representative words prediction for ad-hoc retrieval. arXiv preprint arXiv:2104.09791 ( 2021 ). Xinyu Ma, Jiafeng Guo, Ruqing Zhang, Yixing Fan, Yingyan Li, and Xueqi Cheng. 2021. B-PROP: Bootstrapped pre-training with representative words prediction for ad-hoc retrieval. arXiv preprint arXiv:2104.09791 (2021)."},{"key":"e_1_3_2_1_28_1","volume-title":"Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083","author":"Madry Aleksander","year":"2017","unstructured":"Aleksander Madry , Aleksandar Makelov , Ludwig Schmidt , Dimitris Tsipras , and Adrian Vladu . 2017. Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083 ( 2017 ). Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu. 2017. Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083 (2017)."},{"key":"e_1_3_2_1_29_1","unstructured":"Aleksander Madry Aleksandar Makelov Ludwig Schmidt Dimitris Tsipras and Adrian Vladu. 2018. Towards Deep Learning Models Resistant to Adversarial Attacks. In ICLR.  Aleksander Madry Aleksandar Makelov Ludwig Schmidt Dimitris Tsipras and Adrian Vladu. 2018. Towards Deep Learning Models Resistant to Adversarial Attacks. In ICLR."},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"crossref","unstructured":"Bhaskar Mitra Fernando Diaz and Nick Craswell. 2017. Learning to match using local and distributed representations of text for web search. In WWW.  Bhaskar Mitra Fernando Diaz and Nick Craswell. 2017. Learning to match using local and distributed representations of text for web search. In WWW.","DOI":"10.1145\/3038912.3052579"},{"key":"e_1_3_2_1_31_1","volume-title":"Adversarial training methods for semi-supervised text classification. arXiv preprint arXiv:1605.07725","author":"Miyato Takeru","year":"2016","unstructured":"Takeru Miyato , Andrew M Dai , and Ian Goodfellow . 2016. Adversarial training methods for semi-supervised text classification. arXiv preprint arXiv:1605.07725 ( 2016 ). Takeru Miyato, Andrew M Dai, and Ian Goodfellow. 2016. Adversarial training methods for semi-supervised text classification. arXiv preprint arXiv:1605.07725 (2016)."},{"key":"e_1_3_2_1_32_1","volume-title":"MS MARCO: A human generated machine reading comprehension dataset. In CoCo@ NIPS.","author":"Nguyen Tri","year":"2016","unstructured":"Tri Nguyen , Mir Rosenberg , Xia Song , Jianfeng Gao , Saurabh Tiwary , Rangan Majumder , and Li Deng . 2016 . MS MARCO: A human generated machine reading comprehension dataset. In CoCo@ NIPS. Tri Nguyen, Mir Rosenberg, Xia Song, Jianfeng Gao, Saurabh Tiwary, Rangan Majumder, and Li Deng. 2016. MS MARCO: A human generated machine reading comprehension dataset. In CoCo@ NIPS."},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"crossref","unstructured":"Shuzi Niu Jiafeng Guo Yanyan Lan and Xueqi Cheng. 2012. Top-k learning to rank: labeling ranking and evaluation. In SIGIR. 751--760.  Shuzi Niu Jiafeng Guo Yanyan Lan and Xueqi Cheng. 2012. Top-k learning to rank: labeling ranking and evaluation. In SIGIR. 751--760.","DOI":"10.1145\/2348283.2348384"},{"key":"e_1_3_2_1_34_1","volume-title":"Passage Re-ranking with BERT. arXiv preprint arXiv:1901.04085","author":"Nogueira Rodrigo","year":"2019","unstructured":"Rodrigo Nogueira and Kyunghyun Cho . 2019. Passage Re-ranking with BERT. arXiv preprint arXiv:1901.04085 ( 2019 ). Rodrigo Nogueira and Kyunghyun Cho. 2019. Passage Re-ranking with BERT. arXiv preprint arXiv:1901.04085 (2019)."},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/1135777.1135794"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10791-017-9321-y"},{"key":"e_1_3_2_1_37_1","volume-title":"Glove: Global vectors for word representation. In EMNLP. 1532--1543.","author":"Pennington Jeffrey","year":"2014","unstructured":"Jeffrey Pennington , Richard Socher , and Christopher D Manning . 2014 . Glove: Global vectors for word representation. In EMNLP. 1532--1543. Jeffrey Pennington, Richard Socher, and Christopher D Manning. 2014. Glove: Global vectors for word representation. In EMNLP. 1532--1543."},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/1451983.1451990"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"crossref","unstructured":"Jay M Ponte and W Bruce Croft. 1998. A language modeling approach to information retrieval. In SIGIR. 275--281.  Jay M Ponte and W Bruce Croft. 1998. A language modeling approach to information retrieval. In SIGIR. 275--281.","DOI":"10.1145\/290941.291008"},{"key":"e_1_3_2_1_40_1","unstructured":"Dragomir R Radev Hong Qi Harris Wu and Weiguo Fan. 2002. Evaluating Web-based Question Answering Systems. In LREC. Citeseer.  Dragomir R Radev Hong Qi Harris Wu and Weiguo Fan. 2002. Evaluating Web-based Question Answering Systems. In LREC. Citeseer."},{"key":"e_1_3_2_1_41_1","unstructured":"Shuhuai Ren Yihe Deng Kun He and Wanxiang Che. 2019. Generating natural language adversarial examples through probability weighted word saliency. In ACL. 1085--1097.  Shuhuai Ren Yihe Deng Kun He and Wanxiang Che. 2019. Generating natural language adversarial examples through probability weighted word saliency. In ACL. 1085--1097."},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"crossref","unstructured":"Marco Tulio Ribeiro Sameer Singh and Carlos Guestrin. 2018. Semantically equivalent adversarial rules for debugging NLP models. In ACL.  Marco Tulio Ribeiro Sameer Singh and Carlos Guestrin. 2018. Semantically equivalent adversarial rules for debugging NLP models. In ACL.","DOI":"10.18653\/v1\/P18-1079"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4471-2099-5_24"},{"key":"e_1_3_2_1_44_1","volume-title":"Beyond the single neuron convex barrier for neural network certification. NIPS","author":"Singh Gagandeep","year":"2019","unstructured":"Gagandeep Singh , Rupanshu Ganvir , Markus P\u00fcschel , and Martin Vechev . 2019. Beyond the single neuron convex barrier for neural network certification. NIPS ( 2019 ). Gagandeep Singh, Rupanshu Ganvir, Markus P\u00fcschel, and Martin Vechev. 2019. Beyond the single neuron convex barrier for neural network certification. NIPS (2019)."},{"key":"e_1_3_2_1_45_1","volume-title":"Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199","author":"Szegedy Christian","year":"2013","unstructured":"Christian Szegedy , Wojciech Zaremba , Ilya Sutskever , Joan Bruna , Dumitru Erhan , Ian Goodfellow , and Rob Fergus . 2013. Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199 ( 2013 ). Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus. 2013. Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199 (2013)."},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.naacl-main.87"},{"key":"e_1_3_2_1_47_1","unstructured":"Yisen Wang Xingjun Ma James Bailey Jinfeng Yi Bowen Zhou and Quanquan Gu. 2019. On the Convergence and Robustness of Adversarial Training. In ICML.  Yisen Wang Xingjun Ma James Bailey Jinfeng Yi Bowen Zhou and Quanquan Gu. 2019. On the Convergence and Robustness of Adversarial Training. In ICML."},{"key":"e_1_3_2_1_48_1","volume-title":"PRADA: Practical Black-Box Adversarial Attacks against Neural Ranking Models. arXiv preprint arXiv:2204.01321","author":"Wu Chen","year":"2022","unstructured":"Chen Wu , Ruqing Zhang , Jiafeng Guo , Maarten de Rijke , Yixing Fan , and Xueqi Cheng . 2022 . PRADA: Practical Black-Box Adversarial Attacks against Neural Ranking Models. arXiv preprint arXiv:2204.01321 (2022). Chen Wu, Ruqing Zhang, Jiafeng Guo, Maarten de Rijke, Yixing Fan, and Xueqi Cheng. 2022. PRADA: Practical Black-Box Adversarial Attacks against Neural Ranking Models. arXiv preprint arXiv:2204.01321 (2022)."},{"key":"e_1_3_2_1_49_1","volume-title":"Are Neural Ranking Models Robust? arXiv preprint arXiv:2108.05018","author":"Wu Chen","year":"2021","unstructured":"Chen Wu , Ruqing Zhang , Jiafeng Guo , Yixing Fan , and Xueqi Cheng . 2021. Are Neural Ranking Models Robust? arXiv preprint arXiv:2108.05018 ( 2021 ). Chen Wu, Ruqing Zhang, Jiafeng Guo, Yixing Fan, and Xueqi Cheng. 2021. Are Neural Ranking Models Robust? arXiv preprint arXiv:2108.05018 (2021)."},{"key":"e_1_3_2_1_50_1","volume-title":"NIPS","volume":"22","author":"Xia Fen","year":"2009","unstructured":"Fen Xia , Tie-Yan Liu , and Hang Li . 2009 . Statistical consistency of top-k ranking . NIPS , Vol. 22 (2009). Fen Xia, Tie-Yan Liu, and Hang Li. 2009. Statistical consistency of top-k ranking. NIPS, Vol. 22 (2009)."},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1145\/3239571"},{"key":"e_1_3_2_1_52_1","volume-title":"SAFER: A structure-free approach for certified robustness to adversarial word substitutions. arXiv preprint arXiv:2005.14424","author":"Ye Mao","year":"2020","unstructured":"Mao Ye , Chengyue Gong , and Qiang Liu . 2020 . SAFER: A structure-free approach for certified robustness to adversarial word substitutions. arXiv preprint arXiv:2005.14424 (2020). Mao Ye, Chengyue Gong, and Qiang Liu. 2020. SAFER: A structure-free approach for certified robustness to adversarial word substitutions. arXiv preprint arXiv:2005.14424 (2020)."},{"key":"e_1_3_2_1_53_1","volume-title":"Word-level textual adversarial attacking as combinatorial optimization. arXiv preprint arXiv:1910.12196","author":"Zang Yuan","year":"2019","unstructured":"Yuan Zang , Fanchao Qi , Chenghao Yang , Zhiyuan Liu , Meng Zhang , Qun Liu , and Maosong Sun . 2019. Word-level textual adversarial attacking as combinatorial optimization. arXiv preprint arXiv:1910.12196 ( 2019 ). Yuan Zang, Fanchao Qi, Chenghao Yang, Zhiyuan Liu, Meng Zhang, Qun Liu, and Maosong Sun. 2019. Word-level textual adversarial attacking as combinatorial optimization. arXiv preprint arXiv:1910.12196 (2019)."},{"key":"e_1_3_2_1_54_1","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3374217","article-title":"Adversarial attacks on deep-learning models in natural language processing: A survey","volume":"11","author":"Zhang Wei Emma","year":"2020","unstructured":"Wei Emma Zhang , Quan Z Sheng , Ahoud Alhazmi , and Chenliang Li . 2020 . Adversarial attacks on deep-learning models in natural language processing: A survey . TIST , Vol. 11 , 3 (2020), 1 -- 41 . Wei Emma Zhang, Quan Z Sheng, Ahoud Alhazmi, and Chenliang Li. 2020. Adversarial attacks on deep-learning models in natural language processing: A survey. TIST, Vol. 11, 3 (2020), 1--41.","journal-title":"TIST"},{"key":"e_1_3_2_1_55_1","doi-asserted-by":"crossref","unstructured":"Mo Zhou Zhenxing Niu Le Wang Qilin Zhang and Gang Hua. 2020. Adversarial ranking attack and defense. In ECCV.  Mo Zhou Zhenxing Niu Le Wang Qilin Zhang and Gang Hua. 2020. Adversarial ranking attack and defense. In ECCV.","DOI":"10.1007\/978-3-030-58568-6_46"}],"event":{"name":"CIKM '22: The 31st ACM International Conference on Information and Knowledge Management","location":"Atlanta GA USA","acronym":"CIKM '22","sponsor":["SIGWEB ACM Special Interest Group on Hypertext, Hypermedia, and Web","SIGIR ACM Special Interest Group on Information Retrieval"]},"container-title":["Proceedings of the 31st ACM International Conference on Information &amp; Knowledge Management"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3511808.3557256","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3511808.3557256","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T17:49:07Z","timestamp":1750182547000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3511808.3557256"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,10,17]]},"references-count":55,"alternative-id":["10.1145\/3511808.3557256","10.1145\/3511808"],"URL":"https:\/\/doi.org\/10.1145\/3511808.3557256","relation":{},"subject":[],"published":{"date-parts":[[2022,10,17]]},"assertion":[{"value":"2022-10-17","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}