{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,14]],"date-time":"2026-02-14T11:01:41Z","timestamp":1771066901372,"version":"3.50.1"},"publisher-location":"New York, NY, USA","reference-count":70,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,4,30]],"date-time":"2023-04-30T00:00:00Z","timestamp":1682812800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,4,30]]},"DOI":"10.1145\/3543507.3583356","type":"proceedings-article","created":{"date-parts":[[2023,4,26]],"date-time":"2023-04-26T23:30:51Z","timestamp":1682551851000},"page":"3734-3743","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":6,"title":["HateProof: Are Hateful Meme Detection Systems really Robust?"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-1339-0549","authenticated-orcid":false,"given":"Piush","family":"Aggarwal","sequence":"first","affiliation":[{"name":"FernUniversit\u00e4t in Hagen, Germany"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8058-340X","authenticated-orcid":false,"given":"Pranit","family":"Chawla","sequence":"additional","affiliation":[{"name":"Indian Institute of Technology Kharagpur, India"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1442-312X","authenticated-orcid":false,"given":"Mithun","family":"Das","sequence":"additional","affiliation":[{"name":"Indian Institute of Technology Kharagpur, India"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3952-2514","authenticated-orcid":false,"given":"Punyajoy","family":"Saha","sequence":"additional","affiliation":[{"name":"Indian Institute of Technology Kharagpur, India"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4853-0345","authenticated-orcid":false,"given":"Binny","family":"Mathew","sequence":"additional","affiliation":[{"name":"Indian Institute of Technology Kharagpur, India"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9678-3825","authenticated-orcid":false,"given":"Torsten","family":"Zesch","sequence":"additional","affiliation":[{"name":"FernUniversit\u00e4t in Hagen, Germany"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4534-0044","authenticated-orcid":false,"given":"Animesh","family":"Mukherjee","sequence":"additional","affiliation":[{"name":"Indian Institute of Technology Kharagpur, India"}]}],"member":"320","published-online":{"date-parts":[[2023,4,30]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","unstructured":"Tariq\u00a0Habib Afridi Aftab Alam Muhammad\u00a0Numan Khan Jawad Khan and Young-Koo Lee. 2020. A Multimodal Memes Classification: A Survey and Open Research Issues. https:\/\/doi.org\/10.48550\/ARXIV.2009.08395","DOI":"10.48550\/ARXIV.2009.08395"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.woah-1.22"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1080\/13600834.2018.1494417"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00636"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/2909827.2930786"},{"key":"e_1_3_2_1_6_1","volume-title":"Machine Learning and Knowledge Discovery in Databases, Hendrik Blockeel, Kristian Kersting, Siegfried Nijssen, and Filip \u017delezn\u00fd (Eds.)","author":"Biggio Battista","unstructured":"Battista Biggio, Igino Corona, Davide Maiorca, Blaine Nelson, Nedim \u0160rndi\u0107, Pavel Laskov, Giorgio Giacinto, and Fabio Roli. 2013. Evasion Attacks against Machine Learning at Test Time. In Machine Learning and Knowledge Discovery in Databases, Hendrik Blockeel, Kristian Kersting, Siegfried Nijssen, and Filip \u017delezn\u00fd (Eds.). Springer Berlin Heidelberg, Berlin, Heidelberg, 387\u2013402."},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"e_1_3_2_1_8_1","volume-title":"Advances in Neural Information Processing Systems, T.\u00a0Leen, T.\u00a0Dietterich, and V.\u00a0Tresp (Eds.). Vol.\u00a013","author":"Chapelle Olivier","year":"2000","unstructured":"Olivier Chapelle, Jason Weston, L\u00e9on Bottou, and Vladimir Vapnik. 2000. Vicinal Risk Minimization. In Advances in Neural Information Processing Systems, T.\u00a0Leen, T.\u00a0Dietterich, and V.\u00a0Tresp (Eds.). Vol.\u00a013. MIT Press. https:\/\/proceedings.neurips.cc\/paper\/2000\/file\/ba9a56ce0a9bfa26e8ed9e10b2cc8f46-Paper.pdf"},{"key":"e_1_3_2_1_9_1","volume-title":"A Simple Framework for Contrastive Learning of Visual Representations. arXiv preprint arXiv:2002.05709","author":"Chen Ting","year":"2020","unstructured":"Ting Chen, Simon Kornblith, Mohammad Norouzi, and Geoffrey Hinton. 2020. A Simple Framework for Contrastive Learning of Visual Representations. arXiv preprint arXiv:2002.05709 (2020)."},{"key":"e_1_3_2_1_10_1","volume-title":"Big Self-Supervised Models are Strong Semi-Supervised Learners. arXiv preprint arXiv:2006.10029","author":"Chen Ting","year":"2020","unstructured":"Ting Chen, Simon Kornblith, Kevin Swersky, Mohammad Norouzi, and Geoffrey Hinton. 2020. Big Self-Supervised Models are Strong Semi-Supervised Learners. arXiv preprint arXiv:2006.10029 (2020)."},{"key":"e_1_3_2_1_11_1","volume-title":"Uniter: Universal image-text representation learning. In ECCV.","author":"Chen Yen-Chun","year":"2020","unstructured":"Yen-Chun Chen, Linjie Li, Licheng Yu, Ahmed\u00a0El Kholy, Faisal Ahmed, Zhe Gan, Yu Cheng, and Jingjing Liu. 2020. Uniter: Universal image-text representation learning. In ECCV."},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1"},{"key":"e_1_3_2_1_13_1","volume-title":"Robustness Disparities in Commercial Face Detection. ArXiv abs\/2108.12508","author":"Dooley Samuel","year":"2021","unstructured":"Samuel Dooley, Tom Goldstein, and John\u00a0P. Dickerson. 2021. Robustness Disparities in Commercial Face Detection. ArXiv abs\/2108.12508 (2021)."},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","unstructured":"Ivan Evtimov Russel Howes Brian Dolhansky Hamed Firooz and Cristian\u00a0Canton Ferrer. 2020. Adversarial Evaluation of Multimodal Models under Realistic Gray Box Assumption. https:\/\/doi.org\/10.48550\/ARXIV.2011.12902","DOI":"10.48550\/ARXIV.2011.12902"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.3390\/s18092804"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2022.semeval-1.74"},{"key":"e_1_3_2_1_17_1","volume-title":"Advances in Neural Information Processing Systems, H.\u00a0Larochelle, M.\u00a0Ranzato, R.\u00a0Hadsell, M.F. Balcan, and H.\u00a0Lin (Eds.). Vol.\u00a033. Curran Associates","author":"Gan Zhe","year":"2020","unstructured":"Zhe Gan, Yen-Chun Chen, Linjie Li, Chen Zhu, Yu Cheng, and Jingjing Liu. 2020. Large-Scale Adversarial Training for Vision-and-Language Representation Learning. In Advances in Neural Information Processing Systems, H.\u00a0Larochelle, M.\u00a0Ranzato, R.\u00a0Hadsell, M.F. Balcan, and H.\u00a0Lin (Eds.). Vol.\u00a033. Curran Associates, Inc., 6616\u20136628. https:\/\/proceedings.neurips.cc\/paper\/2020\/file\/49562478de4c54fafd4ec46fdb297de5-Paper.pdf"},{"key":"e_1_3_2_1_18_1","unstructured":"Zhe Gan Yen-Chun Chen Linjie Li Chen Zhu Yu Cheng and Jingjing Liu. 2020. Large-Scale Adversarial Training for Vision-and-Language Representation Learning. arxiv:2006.06195\u00a0[cs.CV]"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.5555\/3495724.3496279"},{"key":"e_1_3_2_1_20_1","unstructured":"Darina Gold Piush Aggarwal and Torsten Zesch. 2021. GerMemeHate: A Parallel Dataset of German Hateful Memes Translated from English. https:\/\/www.inf.uni-hamburg.de\/en\/inst\/ab\/lt\/publications\/2021-alacamyimmam-konvens-mmhs21.pdf#page=9"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/DEXA.2008.43"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","unstructured":"Tommi Gr\u00f6ndahl Luca Pajola Mika Juuti Mauro Conti and N. Asokan. 2018. All You Need is \"Love\": Evading Hate-speech Detection. https:\/\/doi.org\/10.48550\/ARXIV.1808.09115","DOI":"10.48550\/ARXIV.1808.09115"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1007\/s11406-017-9858-4"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","unstructured":"Kaiming He Xiangyu Zhang Shaoqing Ren and Jian Sun. 2015. Deep Residual Learning for Image Recognition. https:\/\/doi.org\/10.48550\/ARXIV.1512.03385","DOI":"10.48550\/ARXIV.1512.03385"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.2204.01734"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1609\/icwsm.v16i1.19300"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2020.acl-main.197"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","unstructured":"Douwe Kiela Hamed Firooz Aravind Mohan Vedanuj Goswami Amanpreet Singh Pratik Ringshia and Davide Testuggine. 2020. The Hateful Memes Challenge: Detecting Hate Speech in Multimodal Memes. https:\/\/doi.org\/10.48550\/ARXIV.2005.04790","DOI":"10.48550\/ARXIV.2005.04790"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1412.6980"},{"key":"e_1_3_2_1_30_1","volume-title":"Quantifying the Carbon Emissions of Machine Learning. arXiv preprint arXiv:1910.09700","author":"Lacoste Alexandre","year":"2019","unstructured":"Alexandre Lacoste, Alexandra Luccioni, Victor Schmidt, and Thomas Dandres. 2019. Quantifying the Carbon Emissions of Machine Learning. arXiv preprint arXiv:1910.09700 (2019)."},{"key":"e_1_3_2_1_31_1","unstructured":"Vijaysinh Lendave. 2021. A guide to different types of noises and image denoising methods. https:\/\/analyticsindiamag.com\/a-guide-to-different-types-of-noises-and-image-denoising-methods\/"},{"key":"e_1_3_2_1_32_1","unstructured":"Linjie Li Zhe Gan and Jingjing Liu. 2021. A Closer Look at the Robustness of Vision-and-Language Pre-trained Models. arxiv:2012.08673\u00a0[cs.CV]"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","unstructured":"Liunian\u00a0Harold Li Mark Yatskar Da Yin Cho-Jui Hsieh and Kai-Wei Chang. 2019. VisualBERT: A Simple and Performant Baseline for Vision and Language. https:\/\/doi.org\/10.48550\/ARXIV.1908.03557","DOI":"10.48550\/ARXIV.1908.03557"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58577-8_8"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","unstructured":"Phillip Lippe Nithin Holla Shantanu Chandra Santhosh Rajamanickam Georgios Antoniou Ekaterina Shutova and Helen Yannakoudakis. 2020. A Multimodal Framework for the Detection of Hateful Memes. (2020). https:\/\/doi.org\/10.48550\/ARXIV.2012.12871","DOI":"10.48550\/ARXIV.2012.12871"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICPR.2018.8545506"},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","unstructured":"Yinhan Liu Myle Ott Naman Goyal Jingfei Du Mandar Joshi Danqi Chen Omer Levy Mike Lewis Luke Zettlemoyer and Veselin Stoyanov. 2019. RoBERTa: A Robustly Optimized BERT Pretraining Approach. https:\/\/doi.org\/10.48550\/ARXIV.1907.11692","DOI":"10.48550\/ARXIV.1907.11692"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","unstructured":"Aleksander Madry Aleksandar Makelov Ludwig Schmidt Dimitris Tsipras and Adrian Vladu. 2017. Towards Deep Learning Models Resistant to Adversarial Attacks. https:\/\/doi.org\/10.48550\/ARXIV.1706.06083","DOI":"10.48550\/ARXIV.1706.06083"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1109\/MIPR.2018.00084"},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.4000\/books.aaccademia.7330"},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.2012.07788"},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","unstructured":"Lin Pan Chung-Wei Hang Avirup Sil and Saloni Potdar. 2021. Improved Text Classification via Contrastive Adversarial Training. https:\/\/doi.org\/10.48550\/ARXIV.2107.10137","DOI":"10.48550\/ARXIV.2107.10137"},{"key":"e_1_3_2_1_43_1","volume-title":"Advances in Neural Information Processing Systems, H.\u00a0Larochelle, M.\u00a0Ranzato, R.\u00a0Hadsell, M.F. Balcan, and H.\u00a0Lin (Eds.). Vol.\u00a033. Curran Associates","author":"Pang Tianyu","year":"2020","unstructured":"Tianyu Pang, Xiao Yang, Yinpeng Dong, Kun Xu, Jun Zhu, and Hang Su. 2020. Boosting Adversarial Training with Hypersphere Embedding. In Advances in Neural Information Processing Systems, H.\u00a0Larochelle, M.\u00a0Ranzato, R.\u00a0Hadsell, M.F. Balcan, and H.\u00a0Lin (Eds.). Vol.\u00a033. Curran Associates, Inc., 7779\u20137792. https:\/\/proceedings.neurips.cc\/paper\/2020\/file\/5898d8095428ee310bf7fa3da1864ff7-Paper.pdf"},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"crossref","unstructured":"Zoe Papakipos and Joanna Bitton. 2022. AugLy: Data Augmentations for Robustness. arxiv:2201.06494\u00a0[cs.AI]","DOI":"10.1109\/CVPRW56347.2022.00027"},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","unstructured":"Gabriel Peyr\u00e9 and Marco Cuturi. 2018. Computational Optimal Transport. (2018). https:\/\/doi.org\/10.48550\/ARXIV.1803.00567","DOI":"10.48550\/ARXIV.1803.00567"},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1"},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1"},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","unstructured":"Sylvestre-Alvise Rebuffi Sven Gowal Dan\u00a0A. Calian Florian Stimberg Olivia Wiles and Timothy Mann. 2021. Data Augmentation Can Improve Robustness. https:\/\/doi.org\/10.48550\/ARXIV.2111.05328","DOI":"10.48550\/ARXIV.2111.05328"},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","unstructured":"Sylvestre-Alvise Rebuffi Sven Gowal Dan\u00a0A. Calian Florian Stimberg Olivia Wiles and Timothy Mann. 2021. Fixing Data Augmentation to Improve Adversarial Robustness. https:\/\/doi.org\/10.48550\/ARXIV.2103.01946","DOI":"10.48550\/ARXIV.2103.01946"},{"key":"e_1_3_2_1_50_1","volume-title":"Advances in Neural Information Processing Systems, C.\u00a0Cortes, N.\u00a0Lawrence, D.\u00a0Lee, M.\u00a0Sugiyama, and R.\u00a0Garnett (Eds.). Vol.\u00a028. Curran Associates","author":"Ren Shaoqing","year":"2015","unstructured":"Shaoqing Ren, Kaiming He, Ross Girshick, and Jian Sun. 2015. Faster R-CNN: Towards Real-Time Object Detection with Region Proposal Networks. In Advances in Neural Information Processing Systems, C.\u00a0Cortes, N.\u00a0Lawrence, D.\u00a0Lee, M.\u00a0Sugiyama, and R.\u00a0Garnett (Eds.). Vol.\u00a028. Curran Associates, Inc.https:\/\/proceedings.neurips.cc\/paper\/2015\/file\/14bfa6bb14875e45bba028a21ed38046-Paper.pdf"},{"key":"e_1_3_2_1_51_1","unstructured":"Benet\u00a0Oriol Sabat Cristian\u00a0Canton Ferrer and Xavier\u00a0Giro i Nieto. 2019. Hate Speech in Pixels: Detection of Offensive Memes towards Automatic Moderation. arxiv:1910.02334\u00a0[cs.MM]"},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2020.semeval-1.99"},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-35289-8_17"},{"key":"e_1_3_2_1_54_1","volume-title":"Proceedings of the Second Workshop on Trolling, Aggression and Cyberbullying. European Language Resources Association (ELRA)","author":"Suryawanshi Shardul","year":"2020","unstructured":"Shardul Suryawanshi, Bharathi\u00a0Raja Chakravarthi, Mihael Arcan, and Paul Buitelaar. 2020. Multimodal Meme Dataset (MultiOFF) for Identifying Offensive Content in Image and Text. In Proceedings of the Second Workshop on Trolling, Aggression and Cyberbullying. European Language Resources Association (ELRA), Marseille, France, 32\u201341. https:\/\/aclanthology.org\/2020.trac-1.6"},{"key":"e_1_3_2_1_55_1","doi-asserted-by":"publisher","unstructured":"Christian Szegedy Wojciech Zaremba Ilya Sutskever Joan Bruna Dumitru Erhan Ian Goodfellow and Rob Fergus. 2013. Intriguing properties of neural networks. https:\/\/doi.org\/10.48550\/ARXIV.1312.6199","DOI":"10.48550\/ARXIV.1312.6199"},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1908.07490"},{"key":"e_1_3_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.2991475"},{"key":"e_1_3_2_1_58_1","doi-asserted-by":"publisher","unstructured":"Florian Tram\u00e8r Alexey Kurakin Nicolas Papernot Ian Goodfellow Dan Boneh and Patrick McDaniel. 2017. Ensemble Adversarial Training: Attacks and Defenses. https:\/\/doi.org\/10.48550\/ARXIV.1705.07204","DOI":"10.48550\/ARXIV.1705.07204"},{"key":"e_1_3_2_1_59_1","doi-asserted-by":"publisher","unstructured":"Riza Velioglu and Jewgeni Rose. 2020. Detecting Hate Speech in Memes Using Multimodal Deep Learning Approaches: Prize-winning solution to Hateful Memes Challenge. https:\/\/doi.org\/10.48550\/ARXIV.2012.12975","DOI":"10.48550\/ARXIV.2012.12975"},{"key":"e_1_3_2_1_60_1","doi-asserted-by":"publisher","unstructured":"Nishant Vishwamitra Hongxin Hu Ziming Zhao Long Cheng and Feng Luo. 2021. Understanding and Measuring Robustness of Multimodal Learning. https:\/\/doi.org\/10.48550\/ARXIV.2112.12792","DOI":"10.48550\/ARXIV.2112.12792"},{"key":"e_1_3_2_1_61_1","unstructured":"Nishant Vishwamitra Hongxin Hu Ziming Zhao Long Cheng and Feng Luo. 2021. Understanding and Measuring Robustness of Multimodal Learning. arxiv:2112.12792\u00a0[cs.LG]"},{"key":"e_1_3_2_1_62_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW.2019.00200"},{"key":"e_1_3_2_1_63_1","unstructured":"Yuxin Wu Alexander Kirillov Francisco Massa Wan-Yen Lo and Ross Girshick. 2019. Detectron2. https:\/\/github.com\/facebookresearch\/detectron2."},{"key":"e_1_3_2_1_64_1","doi-asserted-by":"publisher","unstructured":"Yonghui Wu Mike Schuster Zhifeng Chen Quoc\u00a0V. Le Mohammad Norouzi Wolfgang Macherey Maxim Krikun Yuan Cao Qin Gao Klaus Macherey Jeff Klingner Apurva Shah Melvin Johnson Xiaobing Liu \u0141ukasz Kaiser Stephan Gouws Yoshikiyo Kato Taku Kudo Hideto Kazawa Keith Stevens George Kurian Nishant Patil Wei Wang Cliff Young Jason Smith Jason Riesa Alex Rudnick Oriol Vinyals Greg Corrado Macduff Hughes and Jeffrey Dean. 2016. Google\u2019s Neural Machine Translation System: Bridging the Gap between Human and Machine Translation. https:\/\/doi.org\/10.48550\/ARXIV.1609.08144","DOI":"10.48550\/ARXIV.1609.08144"},{"key":"e_1_3_2_1_65_1","volume-title":"Feature Denoising for Improving Adversarial Robustness. In The IEEE Conference on Computer Vision and Pattern Recognition (CVPR).","author":"Xie Cihang","year":"2019","unstructured":"Cihang Xie, Yuxin Wu, Laurens van\u00a0der Maaten, Alan\u00a0L. Yuille, and Kaiming He. 2019. Feature Denoising for Improving Adversarial Robustness. In The IEEE Conference on Computer Vision and Pattern Recognition (CVPR)."},{"key":"e_1_3_2_1_66_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00335"},{"key":"e_1_3_2_1_67_1","doi-asserted-by":"publisher","DOI":"10.1145\/3184558.3191531"},{"key":"e_1_3_2_1_68_1","volume-title":"Proceedings of the 36th International Conference on Machine Learning(Proceedings of Machine Learning Research, Vol.\u00a097)","author":"Zhang Hongyang","year":"2019","unstructured":"Hongyang Zhang, Yaodong Yu, Jiantao Jiao, Eric Xing, Laurent\u00a0El Ghaoui, and Michael Jordan. 2019. Theoretically Principled Trade-off between Robustness and Accuracy. In Proceedings of the 36th International Conference on Machine Learning(Proceedings of Machine Learning Research, Vol.\u00a097), Kamalika Chaudhuri and Ruslan Salakhutdinov (Eds.). PMLR, 7472\u20137482. https:\/\/proceedings.mlr.press\/v97\/zhang19p.html"},{"key":"e_1_3_2_1_69_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2021.3112048"},{"key":"e_1_3_2_1_70_1","volume-title":"FreeLB: Enhanced Adversarial Training for Natural Language Understanding. In International Conference on Learning Representations. https:\/\/openreview.net\/forum?id=BygzbyHFvB","author":"Zhu Chen","year":"2020","unstructured":"Chen Zhu, Yu Cheng, Zhe Gan, Siqi Sun, Tom Goldstein, and Jingjing Liu. 2020. FreeLB: Enhanced Adversarial Training for Natural Language Understanding. In International Conference on Learning Representations. https:\/\/openreview.net\/forum?id=BygzbyHFvB"}],"event":{"name":"WWW '23: The ACM Web Conference 2023","location":"Austin TX USA","acronym":"WWW '23","sponsor":["SIGWEB ACM Special Interest Group on Hypertext, Hypermedia, and Web"]},"container-title":["Proceedings of the ACM Web Conference 2023"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3543507.3583356","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3543507.3583356","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T16:37:23Z","timestamp":1750178243000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3543507.3583356"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,4,30]]},"references-count":70,"alternative-id":["10.1145\/3543507.3583356","10.1145\/3543507"],"URL":"https:\/\/doi.org\/10.1145\/3543507.3583356","relation":{},"subject":[],"published":{"date-parts":[[2023,4,30]]},"assertion":[{"value":"2023-04-30","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}