{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,7]],"date-time":"2025-11-07T13:42:10Z","timestamp":1762522930090,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":41,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,8,24]],"date-time":"2024-08-24T00:00:00Z","timestamp":1724457600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"National Science Foundation","award":["IIS-1814450"],"award-info":[{"award-number":["IIS-1814450"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,8,25]]},"DOI":"10.1145\/3637528.3672009","type":"proceedings-article","created":{"date-parts":[[2024,8,25]],"date-time":"2024-08-25T04:54:55Z","timestamp":1724561695000},"page":"3001-3012","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":2,"title":["Reinforced Compressive Neural Architecture Search for Versatile Adversarial Robustness"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0005-2407-2337","authenticated-orcid":false,"given":"Dingrong","family":"Wang","sequence":"first","affiliation":[{"name":"Rochester Institute of Technology, Rochester, NY, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5717-8753","authenticated-orcid":false,"given":"Hitesh","family":"Sapkota","sequence":"additional","affiliation":[{"name":"Amazon Inc., Sunnyvale, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5639-7540","authenticated-orcid":false,"given":"Zhiqiang","family":"Tao","sequence":"additional","affiliation":[{"name":"Rochester Institute of Technology, Rochester, NY, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0426-5407","authenticated-orcid":false,"given":"Qi","family":"Yu","sequence":"additional","affiliation":[{"name":"Rochester Institute of Technology, Rochester, NY, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2024,8,24]]},"reference":[{"key":"e_1_3_2_2_1_1","volume-title":"Feature Purification: How Adversarial Training Performs Robust Deep Learning. arxiv","author":"Allen-Zhu Zeyuan","year":"2022","unstructured":"Zeyuan Allen-Zhu and Yuanzhi Li. 2022. Feature Purification: How Adversarial Training Performs Robust Deep Learning. arxiv: 2005.10190 [cs.LG]"},{"volume-title":"International Conference on Learning Representations. https:\/\/openreview.net\/pdf?id=B1hcZZ-AW","author":"Ashok Anubhav","key":"e_1_3_2_2_2_1","unstructured":"Anubhav Ashok, Nicholas Rhinehart, Fares Beainy, and Kris M. Kitani. 2018. N2N learning: Network to Network Compression via Policy Gradient Reinforcement Learning. In International Conference on Learning Representations. https:\/\/openreview.net\/pdf?id=B1hcZZ-AW"},{"key":"e_1_3_2_2_3_1","volume-title":"Hierarchical Object Detection with Deep Reinforcement Learning. In Deep Reinforcement Learning Workshop, NIPS.","author":"Bellver Miriam","year":"2016","unstructured":"Miriam Bellver, Xavier Giro-i Nieto, Ferran Marques, and Jordi Torres. 2016. Hierarchical Object Detection with Deep Reinforcement Learning. In Deep Reinforcement Learning Workshop, NIPS."},{"key":"e_1_3_2_2_4_1","doi-asserted-by":"crossref","unstructured":"Nicholas Carlini and David Wagner. 2017. Towards evaluating the robustness of neural networks. In 2017 ieee symposium on security and privacy (sp). Ieee 39--57.","DOI":"10.1109\/SP.2017.49"},{"key":"e_1_3_2_2_5_1","volume-title":"International conference on machine learning. PMLR, 2206--2216","author":"Croce Francesco","year":"2020","unstructured":"Francesco Croce and Matthias Hein. 2020. Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks. In International conference on machine learning. PMLR, 2206--2216."},{"key":"e_1_3_2_2_6_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCVW54120.2021.00022"},{"key":"e_1_3_2_2_7_1","volume-title":"Adversarially robust neural architectures. arXiv preprint arXiv:2009.00902","author":"Dong Minjing","year":"2020","unstructured":"Minjing Dong, Yanxi Li, Yunhe Wang, and Chang Xu. 2020. Adversarially robust neural architectures. arXiv preprint arXiv:2009.00902 (2020)."},{"key":"e_1_3_2_2_8_1","volume-title":"The lottery ticket hypothesis: Finding sparse, trainable neural networks. arXiv preprint arXiv:1803.03635","author":"Frankle Jonathan","year":"2018","unstructured":"Jonathan Frankle and Michael Carbin. 2018. The lottery ticket hypothesis: Finding sparse, trainable neural networks. arXiv preprint arXiv:1803.03635 (2018)."},{"key":"e_1_3_2_2_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00071"},{"key":"e_1_3_2_2_10_1","volume-title":"Dynamic network surgery for efficient dnns. Advances in neural information processing systems","author":"Guo Yiwen","year":"2016","unstructured":"Yiwen Guo, Anbang Yao, and Yurong Chen. 2016. Dynamic network surgery for efficient dnns. Advances in neural information processing systems, Vol. 29 (2016)."},{"key":"e_1_3_2_2_11_1","volume-title":"Image Classification by Reinforcement Learning With Two-State Q-Learning. Handbook of Intelligent Computing and Optimization for Sustainable Development","author":"Hafiz Abdul Mueed","year":"2022","unstructured":"Abdul Mueed Hafiz. 2022. Image Classification by Reinforcement Learning With Two-State Q-Learning. Handbook of Intelligent Computing and Optimization for Sustainable Development (2022), 171--181."},{"key":"e_1_3_2_2_12_1","first-page":"5545","article-title":"Exploring architectural ingredients of adversarially robust deep neural networks","volume":"34","author":"Huang Hanxun","year":"2021","unstructured":"Hanxun Huang, Yisen Wang, Sarah Erfani, Quanquan Gu, James Bailey, and Xingjun Ma. 2021. Exploring architectural ingredients of adversarially robust deep neural networks. Advances in Neural Information Processing Systems, Vol. 34 (2021), 5545--5559.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_2_13_1","volume-title":"Revisiting Residual Networks for Adversarial Robustness: An Architectural Perspective. arXiv preprint arXiv:2212.11005","author":"Huang Shihua","year":"2022","unstructured":"Shihua Huang, Zhichao Lu, Kalyanmoy Deb, and Vishnu Naresh Boddeti. 2022. Revisiting Residual Networks for Adversarial Robustness: An Architectural Perspective. arXiv preprint arXiv:2212.11005 (2022)."},{"key":"e_1_3_2_2_14_1","volume-title":"SqueezeNet: AlexNet-level accuracy with 50x fewer parameters and < 0.5 MB model size. arXiv preprint arXiv:1602.07360","author":"Iandola Forrest N","year":"2016","unstructured":"Forrest N Iandola, Song Han, Matthew W Moskewicz, Khalid Ashraf, William J Dally, and Kurt Keutzer. 2016. SqueezeNet: AlexNet-level accuracy with 50x fewer parameters and < 0.5 MB model size. arXiv preprint arXiv:1602.07360 (2016)."},{"key":"e_1_3_2_2_15_1","volume-title":"Auto-encoding variational bayes. arXiv preprint arXiv:1312.6114","author":"Kingma Diederik P","year":"2013","unstructured":"Diederik P Kingma and Max Welling. 2013. Auto-encoding variational bayes. arXiv preprint arXiv:1312.6114 (2013)."},{"key":"e_1_3_2_2_16_1","unstructured":"Alex Krizhevsky Geoffrey Hinton et al. 2009. Learning multiple layers of features from tiny images. (2009)."},{"key":"e_1_3_2_2_17_1","volume-title":"Touretzky (Ed.)","volume":"2","author":"LeCun Yann","year":"1989","unstructured":"Yann LeCun, John Denker, and Sara Solla. 1989. Optimal Brain Damage. In Advances in Neural Information Processing Systems, D. Touretzky (Ed.), Vol. 2. Morgan-Kaufmann. https:\/\/proceedings.neurips.cc\/paper_files\/paper\/1989\/file\/6c9882bbac1c7093bd25041881277658-Paper.pdf"},{"key":"e_1_3_2_2_18_1","volume-title":"Proceedings, Part V 13","author":"Lin Tsung-Yi","year":"2014","unstructured":"Tsung-Yi Lin, Michael Maire, Serge Belongie, James Hays, Pietro Perona, Deva Ramanan, Piotr Doll\u00e1r, and C Lawrence Zitnick. 2014. Microsoft coco: Common objects in context. In Computer Vision--ECCV 2014: 13th European Conference, Zurich, Switzerland, September 6--12, 2014, Proceedings, Part V 13. Springer, 740--755."},{"key":"e_1_3_2_2_19_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01468"},{"key":"e_1_3_2_2_20_1","volume-title":"Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083","author":"Madry Aleksander","year":"2017","unstructured":"Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu. 2017. Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083 (2017)."},{"key":"e_1_3_2_2_21_1","volume-title":"Playing atari with deep reinforcement learning. arXiv preprint arXiv:1312.5602","author":"Mnih Volodymyr","year":"2013","unstructured":"Volodymyr Mnih, Koray Kavukcuoglu, David Silver, Alex Graves, Ioannis Antonoglou, Daan Wierstra, and Martin Riedmiller. 2013. Playing atari with deep reinforcement learning. arXiv preprint arXiv:1312.5602 (2013)."},{"key":"e_1_3_2_2_22_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01210"},{"key":"e_1_3_2_2_23_1","volume-title":"Robustness Trade-off. In International Conference on Learning Representations. https:\/\/openreview.net\/forum?id=Azh9QBQ4tR7","author":"Rade Rahul","year":"2022","unstructured":"Rahul Rade and Seyed-Mohsen Moosavi-Dezfooli. 2022. Reducing Excessive Margin to Achieve a Better Accuracy vs. Robustness Trade-off. In International Conference on Learning Representations. https:\/\/openreview.net\/forum?id=Azh9QBQ4tR7"},{"key":"e_1_3_2_2_24_1","volume-title":"100,000 questions for machine comprehension of text. arXiv preprint arXiv:1606.05250","author":"Rajpurkar Pranav","year":"2016","unstructured":"Pranav Rajpurkar, Jian Zhang, Konstantin Lopyrev, and Percy Liang. 2016. Squad: 100,000 questions for machine comprehension of text. arXiv preprint arXiv:1606.05250 (2016)."},{"key":"e_1_3_2_2_25_1","volume-title":"Advances in Neural Information Processing Systems","volume":"33","author":"Sehwag Vikash","year":"2020","unstructured":"Vikash Sehwag, Shiqi Wang, Prateek Mittal, and Suman Jana. 2020. Hydra: Pruning adversarially robust neural networks. Advances in Neural Information Processing Systems, Vol. 33 (2020)."},{"key":"e_1_3_2_2_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2023.3289298"},{"key":"e_1_3_2_2_27_1","first-page":"3008","article-title":"Learning to summarize with human feedback","volume":"33","author":"Stiennon Nisan","year":"2020","unstructured":"Nisan Stiennon, Long Ouyang, Jeffrey Wu, Daniel Ziegler, Ryan Lowe, Chelsea Voss, Alec Radford, Dario Amodei, and Paul F Christiano. 2020. Learning to summarize with human feedback. Advances in Neural Information Processing Systems, Vol. 33 (2020), 3008--3021.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_2_28_1","volume-title":"Advances in Neural Information Processing Systems","volume":"31","author":"Virmaux Aladin","year":"2018","unstructured":"Aladin Virmaux and Kevin Scaman. 2018. Lipschitz regularity of deep neural networks: analysis and efficient estimation. Advances in Neural Information Processing Systems, Vol. 31 (2018)."},{"key":"e_1_3_2_2_29_1","volume-title":"Proceedings of the 40th International Conference on Machine Learning (Proceedings of Machine Learning Research","volume":"36223","author":"Wang Dingrong","year":"2023","unstructured":"Dingrong Wang, Deep Shankar Pandey, Krishna Prasad Neupane, Zhiwei Yu, Ervine Zheng, Zhi Zheng, and Qi Yu. 2023. Deep Temporal Sets with Evidential Reinforced Attentions for Unique Behavioral Pattern Discovery. In Proceedings of the 40th International Conference on Machine Learning (Proceedings of Machine Learning Research, Vol. 202),, Andreas Krause, Emma Brunskill, Kyunghyun Cho, Barbara Engelhardt, Sivan Sabato, and Jonathan Scarlett (Eds.). PMLR, 36205--36223. https:\/\/proceedings.mlr.press\/v202\/wang23ab.html"},{"key":"e_1_3_2_2_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDM51629.2021.00078"},{"key":"e_1_3_2_2_31_1","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2406.06792"},{"key":"e_1_3_2_2_32_1","unstructured":"Yisen Wang Difan Zou Jinfeng Yi James Bailey Xingjun Ma and Quanquan Gu. 2020. Improving Adversarial Robustness Requires Revisiting Misclassified Examples. In ICLR."},{"key":"e_1_3_2_2_33_1","first-page":"7054","article-title":"Do wider neural networks really help adversarial robustness","volume":"34","author":"Wu Boxi","year":"2021","unstructured":"Boxi Wu, Jinghui Chen, Deng Cai, Xiaofei He, and Quanquan Gu. 2021. Do wider neural networks really help adversarial robustness? Advances in Neural Information Processing Systems, Vol. 34 (2021), 7054--7067.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_2_34_1","unstructured":"Dongxian Wu Shu-Tao Xia and Yisen Wang. 2020. Adversarial Weight Perturbation Helps Robust Generalization. In NeurIPS."},{"key":"e_1_3_2_2_35_1","first-page":"26858","article-title":"Automated discovery of adaptive attacks on adversarial defenses","volume":"34","author":"Yao Chengyuan","year":"2021","unstructured":"Chengyuan Yao, Pavol Bielik, Petar Tsankov, and Martin Vechev. 2021. Automated discovery of adaptive attacks on adversarial defenses. Advances in Neural Information Processing Systems, Vol. 34 (2021), 26858--26870.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_2_36_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00020"},{"key":"e_1_3_2_2_37_1","volume-title":"International conference on machine learning. PMLR, 7472--7482","author":"Zhang Hongyang","year":"2019","unstructured":"Hongyang Zhang, Yaodong Yu, Jiantao Jiao, Eric Xing, Laurent El Ghaoui, and Michael Jordan. 2019. Theoretically principled trade-off between robustness and accuracy. In International conference on machine learning. PMLR, 7472--7482."},{"key":"e_1_3_2_2_38_1","volume-title":"Causal imitation learning with unobserved confounders. Advances in neural information processing systems","author":"Zhang Junzhe","year":"2020","unstructured":"Junzhe Zhang, Daniel Kumor, and Elias Bareinboim. 2020. Causal imitation learning with unobserved confounders. Advances in neural information processing systems, Vol. 33 (2020), 12263--12274."},{"key":"e_1_3_2_2_39_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01457"},{"key":"e_1_3_2_2_40_1","volume-title":"Improving Differentiable Architecture Search via Self-Distillation. arXiv preprint arXiv:2302.05629","author":"Zhu Xunyu","year":"2023","unstructured":"Xunyu Zhu, Jian Li, Yong Liu, and Weiping Wang. 2023. Improving Differentiable Architecture Search via Self-Distillation. arXiv preprint arXiv:2302.05629 (2023)."},{"key":"e_1_3_2_2_41_1","volume-title":"Neural architecture search with reinforcement learning. arXiv preprint arXiv:1611.01578","author":"Zoph Barret","year":"2016","unstructured":"Barret Zoph and Quoc V Le. 2016. Neural architecture search with reinforcement learning. arXiv preprint arXiv:1611.01578 (2016)."}],"event":{"name":"KDD '24: The 30th ACM SIGKDD Conference on Knowledge Discovery and Data Mining","sponsor":["SIGMOD ACM Special Interest Group on Management of Data","SIGKDD ACM Special Interest Group on Knowledge Discovery in Data"],"location":"Barcelona Spain","acronym":"KDD '24"},"container-title":["Proceedings of the 30th ACM SIGKDD Conference on Knowledge Discovery and Data Mining"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3637528.3672009","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3637528.3672009","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T00:06:06Z","timestamp":1750291566000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3637528.3672009"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,8,24]]},"references-count":41,"alternative-id":["10.1145\/3637528.3672009","10.1145\/3637528"],"URL":"https:\/\/doi.org\/10.1145\/3637528.3672009","relation":{},"subject":[],"published":{"date-parts":[[2024,8,24]]},"assertion":[{"value":"2024-08-24","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}