{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,22]],"date-time":"2026-07-22T19:01:09Z","timestamp":1784746869544,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":34,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,8,4]],"date-time":"2023-08-04T00:00:00Z","timestamp":1691107200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"NSF","award":["CNS1815636 IIS1845081 IIS1928278 IIS1955285 IIS2212032"],"award-info":[{"award-number":["CNS1815636 IIS1845081 IIS1928278 IIS1955285 IIS2212032"]}]},{"name":"NSF","award":["IIS2212144 IOS2107215 and IOS203547"],"award-info":[{"award-number":["IIS2212144 IOS2107215 and IOS203547"]}]},{"name":"Army Research Office (ARO)","award":["W911NF-21-1-0198"],"award-info":[{"award-number":["W911NF-21-1-0198"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,8,6]]},"DOI":"10.1145\/3580305.3599381","type":"proceedings-article","created":{"date-parts":[[2023,8,4]],"date-time":"2023-08-04T18:10:58Z","timestamp":1691172658000},"page":"2801-2812","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":2,"title":["How does the Memorization of Neural Networks Impact Adversarial Robust Models?"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-4016-6748","authenticated-orcid":false,"given":"Han","family":"Xu","sequence":"first","affiliation":[{"name":"Michigan State University, East Lansing, MI, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8217-5688","authenticated-orcid":false,"given":"Xiaorui","family":"Liu","sequence":"additional","affiliation":[{"name":"North Carilina State University, Raleigh, NC, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5618-3032","authenticated-orcid":false,"given":"Wentao","family":"Wang","sequence":"additional","affiliation":[{"name":"Michigan State University, East Lansing, MI, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0491-307X","authenticated-orcid":false,"given":"Zitao","family":"Liu","sequence":"additional","affiliation":[{"name":"Jinan University, Guangzhou, Guangdong, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6369-6995","authenticated-orcid":false,"given":"Anil K","family":"Jain","sequence":"additional","affiliation":[{"name":"Michigan State University, East Lansing, MI, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7125-3898","authenticated-orcid":false,"given":"Jiliang","family":"Tang","sequence":"additional","affiliation":[{"name":"Michigan State University, East Lansing, MI, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2023,8,4]]},"reference":[{"key":"e_1_3_2_2_1_1","doi-asserted-by":"publisher","DOI":"10.1073\/pnas.1907378117"},{"key":"e_1_3_2_2_2_1","first-page":"463","article-title":"Rademacher and gaussian complexities: Risk bounds and structural results","volume":"3","author":"Bartlett P. L.","unstructured":"Bartlett , P. L. , and Mendelson , S . Rademacher and gaussian complexities: Risk bounds and structural results . Journal of Machine Learning Research 3 , Nov (2002), 463 -- 482 . Bartlett, P. L., and Mendelson, S. Rademacher and gaussian complexities: Risk bounds and structural results. Journal of Machine Learning Research 3, Nov (2002), 463--482.","journal-title":"Journal of Machine Learning Research"},{"key":"e_1_3_2_2_3_1","unstructured":"Biggio B. Nelson B. and Laskov P. Poisoning attacks against support vector machines. arXiv preprint arXiv:1206.6389 (2012).  Biggio B. Nelson B. and Laskov P. Poisoning attacks against support vector machines. arXiv preprint arXiv:1206.6389 (2012)."},{"key":"e_1_3_2_2_4_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-7908-2604-3_16"},{"key":"e_1_3_2_2_5_1","volume-title":"Distribution density, tails, and outliers in machine learning: Metrics and applications. arXiv preprint arXiv:1910.13427","author":"Carlini N.","year":"2019","unstructured":"Carlini , N. , Erlingsson , U. , and Papernot , N . Distribution density, tails, and outliers in machine learning: Metrics and applications. arXiv preprint arXiv:1910.13427 ( 2019 ). Carlini, N., Erlingsson, U., and Papernot, N. Distribution density, tails, and outliers in machine learning: Metrics and applications. arXiv preprint arXiv:1910.13427 (2019)."},{"key":"e_1_3_2_2_6_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"e_1_3_2_2_7_1","volume-title":"Finite-sample analysis of interpolating linear classifiers in the overparameterized regime. arXiv preprint arXiv:2004.12019","author":"Chatterji N. S.","year":"2020","unstructured":"Chatterji , N. S. , and Long , P. M . Finite-sample analysis of interpolating linear classifiers in the overparameterized regime. arXiv preprint arXiv:2004.12019 ( 2020 ). Chatterji, N. S., and Long, P. M. Finite-sample analysis of interpolating linear classifiers in the overparameterized regime. arXiv preprint arXiv:2004.12019 (2020)."},{"key":"e_1_3_2_2_8_1","first-page":"1597","volume-title":"International conference on machine learning","author":"Chen T.","year":"2020","unstructured":"Chen , T. , Kornblith , S. , Norouzi , M. , and Hinton , G . A simple framework for contrastive learning of visual representations . In International conference on machine learning ( 2020 ), PMLR, pp. 1597 -- 1607 . Chen, T., Kornblith, S., Norouzi, M., and Hinton, G. A simple framework for contrastive learning of visual representations. In International conference on machine learning (2020), PMLR, pp. 1597--1607."},{"key":"e_1_3_2_2_9_1","first-page":"2206","volume-title":"International Conference on Machine Learning","author":"Croce F.","year":"2020","unstructured":"Croce , F. , and Hein , M . Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks . In International Conference on Machine Learning ( 2020 ), PMLR, pp. 2206 -- 2216 . Croce, F., and Hein, M. Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks. In International Conference on Machine Learning (2020), PMLR, pp. 2206--2216."},{"key":"e_1_3_2_2_10_1","volume-title":"Data profiling for adversarial training: On the ruin of problematic data. arXiv preprint arXiv:2102.07437","author":"Dong C.","year":"2021","unstructured":"Dong , C. , Liu , L. , and Shang , J . Data profiling for adversarial training: On the ruin of problematic data. arXiv preprint arXiv:2102.07437 ( 2021 ). Dong, C., Liu, L., and Shang, J. Data profiling for adversarial training: On the ruin of problematic data. arXiv preprint arXiv:2102.07437 (2021)."},{"key":"e_1_3_2_2_11_1","volume-title":"Exploring memorization in adversarial training. arXiv preprint arXiv:2106.01606","author":"Dong Y.","year":"2021","unstructured":"Dong , Y. , Xu , K. , Yang , X. , Pang , T. , Deng , Z. , Su , H. , and Zhu , J . Exploring memorization in adversarial training. arXiv preprint arXiv:2106.01606 ( 2021 ). Dong, Y., Xu, K., Yang, X., Pang, T., Deng, Z., Su, H., and Zhu, J. Exploring memorization in adversarial training. arXiv preprint arXiv:2106.01606 (2021)."},{"key":"e_1_3_2_2_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/3357713.3384290"},{"key":"e_1_3_2_2_13_1","volume-title":"What neural networks memorize and why: Discovering the long tail via influence estimation. arXiv preprint arXiv:2008.03703","author":"Feldman V.","year":"2020","unstructured":"Feldman , V. , and Zhang , C . What neural networks memorize and why: Discovering the long tail via influence estimation. arXiv preprint arXiv:2008.03703 ( 2020 ). Feldman, V., and Zhang, C. What neural networks memorize and why: Discovering the long tail via influence estimation. arXiv preprint arXiv:2008.03703 (2020)."},{"key":"e_1_3_2_2_14_1","volume-title":"Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572","author":"Goodfellow I. J.","year":"2014","unstructured":"Goodfellow , I. J. , Shlens , J. , and Szegedy , C . Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572 ( 2014 ). Goodfellow, I. J., Shlens, J., and Szegedy, C. Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572 (2014)."},{"key":"e_1_3_2_2_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"e_1_3_2_2_16_1","unstructured":"Krizhevsky A. Hinton G. etal Learning multiple layers of features from tiny images.  Krizhevsky A. Hinton G. et al. Learning multiple layers of features from tiny images."},{"key":"e_1_3_2_2_17_1","volume-title":"Imagenet classification with deep convolutional neural networks. Advances in neural information processing systems 25","author":"Krizhevsky A.","year":"2012","unstructured":"Krizhevsky , A. , Sutskever , I. , and Hinton , G. E . Imagenet classification with deep convolutional neural networks. Advances in neural information processing systems 25 ( 2012 ), 1097--1105. Krizhevsky, A., Sutskever, I., and Hinton, G. E. Imagenet classification with deep convolutional neural networks. Advances in neural information processing systems 25 (2012), 1097--1105."},{"key":"e_1_3_2_2_18_1","volume-title":"Adversarial machine learning at scale. arXiv preprint arXiv:1611.01236","author":"Kurakin A.","year":"2016","unstructured":"Kurakin , A. , Goodfellow , I. , and Bengio , S . Adversarial machine learning at scale. arXiv preprint arXiv:1611.01236 ( 2016 ). Kurakin, A., Goodfellow, I., and Bengio, S. Adversarial machine learning at scale. arXiv preprint arXiv:1611.01236 (2016)."},{"key":"e_1_3_2_2_19_1","first-page":"7","article-title":"Tiny imagenet visual recognition challenge","volume":"7","author":"Le Y.","year":"2015","unstructured":"Le , Y. , and Yang , X . Tiny imagenet visual recognition challenge . CS 231N 7 ( 2015 ), 7 . Le, Y., and Yang, X. Tiny imagenet visual recognition challenge. CS 231N 7 (2015), 7.","journal-title":"CS 231N"},{"key":"e_1_3_2_2_20_1","first-page":"4313","volume-title":"International Conference on Artificial Intelligence and Statistics","author":"Li M.","year":"2020","unstructured":"Li , M. , Soltanolkotabi , M. , and Oymak , S . Gradient descent with early stopping is provably robust to label noise for overparameterized neural networks . In International Conference on Artificial Intelligence and Statistics ( 2020 ), PMLR, pp. 4313 -- 4324 . Li, M., Soltanolkotabi, M., and Oymak, S. Gradient descent with early stopping is provably robust to label noise for overparameterized neural networks. In International Conference on Artificial Intelligence and Statistics (2020), PMLR, pp. 4313--4324."},{"key":"e_1_3_2_2_21_1","volume-title":"Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083","author":"Madry A.","year":"2017","unstructured":"Madry , A. , Makelov , A. , Schmidt , L. , Tsipras , D. , and Vladu , A . Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083 ( 2017 ). Madry, A., Makelov, A., Schmidt, L., Tsipras, D., and Vladu, A. Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083 (2017)."},{"key":"e_1_3_2_2_22_1","doi-asserted-by":"publisher","DOI":"10.1109\/JSAIT.2020.2984716"},{"key":"e_1_3_2_2_23_1","volume-title":"Deep double descent: Where bigger models and more data hurt. arXiv preprint arXiv:1912.02292","author":"Nakkiran P.","year":"2019","unstructured":"Nakkiran , P. , Kaplun , G. , Bansal , Y. , Yang , T. , Barak , B. , and Sutskever , I . Deep double descent: Where bigger models and more data hurt. arXiv preprint arXiv:1912.02292 ( 2019 ). Nakkiran, P., Kaplun, G., Bansal, Y., Yang, T., Barak, B., and Sutskever, I. Deep double descent: Where bigger models and more data hurt. arXiv preprint arXiv:1912.02292 (2019)."},{"key":"e_1_3_2_2_24_1","first-page":"8093","volume-title":"International Conference on Machine Learning","author":"Rice L.","year":"2020","unstructured":"Rice , L. , Wong , E. , and Kolter , Z . Overfitting in adversarially robust deep learning . In International Conference on Machine Learning ( 2020 ), PMLR, pp. 8093 -- 8104 . Rice, L., Wong, E., and Kolter, Z. Overfitting in adversarially robust deep learning. In International Conference on Machine Learning (2020), PMLR, pp. 8093--8104."},{"key":"e_1_3_2_2_25_1","volume-title":"How benign is benign overfitting? arXiv preprint arXiv:2007.04028","author":"Sanyal A.","year":"2020","unstructured":"Sanyal , A. , Dokania , P. K. , Kanade , V. , and Torr , P. H . How benign is benign overfitting? arXiv preprint arXiv:2007.04028 ( 2020 ). Sanyal, A., Dokania, P. K., Kanade, V., and Torr, P. H. How benign is benign overfitting? arXiv preprint arXiv:2007.04028 (2020)."},{"key":"e_1_3_2_2_26_1","volume-title":"Adversarially robust generalization requires more data. arXiv preprint arXiv:1804.11285","author":"Schmidt L.","year":"2018","unstructured":"Schmidt , L. , Santurkar , S. , Tsipras , D. , Talwar , K. , and Madry , A . Adversarially robust generalization requires more data. arXiv preprint arXiv:1804.11285 ( 2018 ). Schmidt, L., Santurkar, S., Tsipras, D., Talwar, K., and Madry, A. Adversarially robust generalization requires more data. arXiv preprint arXiv:1804.11285 (2018)."},{"key":"e_1_3_2_2_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298682"},{"key":"e_1_3_2_2_28_1","volume-title":"Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199","author":"Szegedy C.","year":"2013","unstructured":"Szegedy , C. , Zaremba , W. , Sutskever , I. , Bruna , J. , Erhan , D. , Goodfellow , I. , and Fergus , R . Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199 ( 2013 ). Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I., and Fergus, R. Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199 (2013)."},{"key":"e_1_3_2_2_29_1","volume-title":"Robustness may be at odds with accuracy. arXiv preprint arXiv:1805.12152","author":"Tsipras D.","year":"2018","unstructured":"Tsipras , D. , Santurkar , S. , Engstrom , L. , Turner , A. , and Madry , A . Robustness may be at odds with accuracy. arXiv preprint arXiv:1805.12152 ( 2018 ). Tsipras, D., Santurkar, S., Engstrom, L., Turner, A., and Madry, A. Robustness may be at odds with accuracy. arXiv preprint arXiv:1805.12152 (2018)."},{"key":"e_1_3_2_2_30_1","volume-title":"International Conference on Learning Representations","author":"Wang Y.","year":"2019","unstructured":"Wang , Y. , Zou , D. , Yi , J. , Bailey , J. , Ma , X. , and Gu , Q . Improving adversarial robustness requires revisiting misclassified examples . In International Conference on Learning Representations ( 2019 ). Wang, Y., Zou, D., Yi, J., Bailey, J., Ma, X., and Gu, Q. Improving adversarial robustness requires revisiting misclassified examples. In International Conference on Learning Representations (2019)."},{"key":"e_1_3_2_2_31_1","volume-title":"Adversarial attacks and defenses in images, graphs and text: A review. arXiv preprint arXiv:1909.08072","author":"Xu H.","year":"2019","unstructured":"Xu , H. , Ma , Y. , Liu , H. , Deb , D. , Liu , H. , Tang , J. , and Jain , A . Adversarial attacks and defenses in images, graphs and text: A review. arXiv preprint arXiv:1909.08072 ( 2019 ). Xu, H., Ma, Y., Liu, H., Deb, D., Liu, H., Tang, J., and Jain, A. Adversarial attacks and defenses in images, graphs and text: A review. arXiv preprint arXiv:1909.08072 (2019)."},{"key":"e_1_3_2_2_32_1","volume-title":"Understanding deep learning requires rethinking generalization. arXiv preprint arXiv:1611.03530","author":"Zhang C.","year":"2016","unstructured":"Zhang , C. , Bengio , S. , Hardt , M. , Recht , B. , and Vinyals , O . Understanding deep learning requires rethinking generalization. arXiv preprint arXiv:1611.03530 ( 2016 ). Zhang, C., Bengio, S., Hardt, M., Recht, B., and Vinyals, O. Understanding deep learning requires rethinking generalization. arXiv preprint arXiv:1611.03530 (2016)."},{"key":"e_1_3_2_2_33_1","volume-title":"Theo-retically principled trade-off between robustness and accuracy. arXiv preprint arXiv:1901.08573","author":"Zhang H.","year":"2019","unstructured":"Zhang , H. , Yu , Y. , Jiao , J. , Xing , E. P. , Ghaoui , L. E. , and Jordan , M. I . Theo-retically principled trade-off between robustness and accuracy. arXiv preprint arXiv:1901.08573 ( 2019 ). Zhang, H., Yu, Y., Jiao, J., Xing, E. P., Ghaoui, L. E., and Jordan, M. I. Theo-retically principled trade-off between robustness and accuracy. arXiv preprint arXiv:1901.08573 (2019)."},{"key":"e_1_3_2_2_34_1","volume-title":"Geometry-aware instance-reweighted adversarial training. arXiv preprint arXiv:2010.01736","author":"Zhang J.","year":"2020","unstructured":"Zhang , J. , Zhu , J. , Niu , G. , Han , B. , Sugiyama , M. , and Kankanhalli , M . Geometry-aware instance-reweighted adversarial training. arXiv preprint arXiv:2010.01736 ( 2020 ). Zhang, J., Zhu, J., Niu, G., Han, B., Sugiyama, M., and Kankanhalli, M. Geometry-aware instance-reweighted adversarial training. arXiv preprint arXiv:2010.01736 (2020)."}],"event":{"name":"KDD '23: The 29th ACM SIGKDD Conference on Knowledge Discovery and Data Mining","location":"Long Beach CA USA","acronym":"KDD '23","sponsor":["SIGMOD ACM Special Interest Group on Management of Data","SIGKDD ACM Special Interest Group on Knowledge Discovery in Data"]},"container-title":["Proceedings of the 29th ACM SIGKDD Conference on Knowledge Discovery and Data Mining"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3580305.3599381","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3580305.3599381","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3580305.3599381","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T16:37:48Z","timestamp":1750178268000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3580305.3599381"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,8,4]]},"references-count":34,"alternative-id":["10.1145\/3580305.3599381","10.1145\/3580305"],"URL":"https:\/\/doi.org\/10.1145\/3580305.3599381","relation":{},"subject":[],"published":{"date-parts":[[2023,8,4]]},"assertion":[{"value":"2023-08-04","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}