{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T03:39:23Z","timestamp":1782790763563,"version":"3.54.5"},"reference-count":95,"publisher":"Association for Computing Machinery (ACM)","issue":"5","license":[{"start":{"date-parts":[[2024,3,26]],"date-time":"2024-03-26T00:00:00Z","timestamp":1711411200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"TJF","award":["22ZYYYJC00020"],"award-info":[{"award-number":["22ZYYYJC00020"]}]},{"DOI":"10.13039\/501100001809","name":"NSFC","doi-asserted-by":"crossref","award":["62076178"],"award-info":[{"award-number":["62076178"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Knowl. Discov. Data"],"published-print":{"date-parts":[[2024,6,30]]},"abstract":"<jats:p>Weighting strategy prevails in machine learning. For example, a common approach in robust machine learning is to exert low weights on samples which are likely to be noisy or quite hard. This study summarizes another less-explored strategy, namely, perturbation. Various incarnations of perturbation have been utilized but it has not been explicitly revealed. Learning with perturbation is called perturbation learning and a systematic taxonomy is constructed for it in this study. In our taxonomy, learning with perturbation is divided on the basis of the perturbation targets, directions, inference manners, and granularity levels. Many existing learning algorithms including some classical ones can be understood with the constructed taxonomy. Alternatively, these algorithms share the same component, namely, perturbation in their procedures. Furthermore, a family of new learning algorithms can be obtained by varying existing learning algorithms with our taxonomy. Specifically, three concrete new learning algorithms are proposed for robust machine learning. Extensive experiments on image classification and text sentiment analysis verify the effectiveness of the three new algorithms. Learning with perturbation can also be used in other various learning scenarios, such as imbalanced learning, clustering, regression, and so on.<\/jats:p>","DOI":"10.1145\/3644391","type":"journal-article","created":{"date-parts":[[2024,2,3]],"date-time":"2024-02-03T11:45:02Z","timestamp":1706960702000},"page":"1-38","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":1,"title":["A Taxonomy for Learning with Perturbation and Algorithms"],"prefix":"10.1145","volume":"18","author":[{"ORCID":"https:\/\/orcid.org\/0009-0001-2738-5786","authenticated-orcid":false,"given":"Rujing","family":"Yao","sequence":"first","affiliation":[{"name":"Department of Information Resources Management, Business School, Nankai University, Tianjin, China and Center for Applied Mathematics, Tianjin University, Tianjin, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6106-6914","authenticated-orcid":false,"given":"Ou","family":"Wu","sequence":"additional","affiliation":[{"name":"Center for Applied Mathematics, Tianjin University, Tianjin, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,3,26]]},"reference":[{"key":"e_1_3_3_2_2","volume-title":"Nonlinear Programming - Theory and Algorithms","author":"Bazaraa M.","year":"1993","unstructured":"M. Bazaraa, H. Sherali, and C. Shetty. 1993. Nonlinear Programming - Theory and Algorithms. John Wiley and Sons, Inc."},{"key":"e_1_3_3_3_2","doi-asserted-by":"publisher","DOI":"10.1145\/1553374.1553380"},{"key":"e_1_3_3_4_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICME51207.2021.9428419"},{"key":"e_1_3_3_5_2","first-page":"1565","volume-title":"Proceedings of the Advances in Neural Information Processing Systems","author":"Cao Kaidi","year":"2019","unstructured":"Kaidi Cao, Colin Wei, Adrien Gaidon, Nikos Arechiga, and Tengyu Ma. 2019. Learning imbalanced datasets with label-distribution-aware margin loss. In Proceedings of the Advances in Neural Information Processing Systems. 1565\u20131576."},{"key":"e_1_3_3_6_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2011.5995437"},{"key":"e_1_3_3_7_2","unstructured":"Ashutosh Chaubey Nikhil Agrawal Kavya Barnwal Keerat K. Guliani and Pramod Mehta. 2020. Universal adversarial perturbations: A survey. arXiv:2005.08087. Retrieved from https:\/\/arxiv.org\/abs\/2005.08087"},{"key":"e_1_3_3_8_2","doi-asserted-by":"crossref","unstructured":"Dubing Chen Yuming Shen Haofeng Zhang and Philip H. S. Torr. 2022. Zero-shot logit adjustment. In Proceedings of the International Joint Conference on Artificial Intelligence. 813\u2013819.","DOI":"10.24963\/ijcai.2022\/114"},{"key":"e_1_3_3_9_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW50498.2020.00363"},{"key":"e_1_3_3_10_2","doi-asserted-by":"publisher","DOI":"10.1007\/BF00994018"},{"issue":"3","key":"e_1_3_3_11_2","first-page":"3695","article-title":"ResLT: Residual learning for long-tailed recognition","volume":"45","author":"Cui Jiequan","year":"2023","unstructured":"Jiequan Cui, Shu Liu, Zhuotao Tian, Zhisheng Zhong, and Jiaya Jia. 2023. ResLT: Residual learning for long-tailed recognition. IEEE Transactions on Pattern Analysis and Machine Intelligence 45, 3 (2023), 3695\u20133706.","journal-title":"IEEE Transactions on Pattern Analysis and Machine Intelligence"},{"key":"e_1_3_3_12_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2019.2959254"},{"key":"e_1_3_3_13_2","unstructured":"Antoine de Mathelin Francois Deheeger Mathilde Mougeot and Nicolas Vayatis. 2023. Deep anti-regularized ensembles provide reliable out-of-distribution uncertainty quantification. arXiv:2304.04042. Retrieved from https:\/\/arxiv.org\/abs\/2304.04042"},{"key":"e_1_3_3_14_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"e_1_3_3_15_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2013.81"},{"key":"e_1_3_3_16_2","first-page":"4171","volume-title":"Proceedings of the NAACL-HLT","author":"Devlin Jacob","year":"2019","unstructured":"Jacob Devlin, Ming-Wei Chang, Kenton Lee, and Kristina Toutanova. 2019. Bert: Pre-training of deep bidirectional transformers for language understanding. In Proceedings of the NAACL-HLT. 4171\u20134186."},{"key":"e_1_3_3_17_2","first-page":"2665","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Dhifallah Oussama","year":"2021","unstructured":"Oussama Dhifallah and Yue Lu. 2021. On the inherent regularization effects of noise injection during training. In Proceedings of the International Conference on Machine Learning. 2665\u20132675."},{"key":"e_1_3_3_18_2","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2017.2648880"},{"key":"e_1_3_3_19_2","doi-asserted-by":"publisher","DOI":"10.1109\/TSP.2012.2196696"},{"key":"e_1_3_3_20_2","doi-asserted-by":"publisher","DOI":"10.1006\/jcss.1997.1504"},{"key":"e_1_3_3_21_2","doi-asserted-by":"publisher","DOI":"10.1162\/089976600300015015"},{"key":"e_1_3_3_22_2","unstructured":"Morgane Goibert and Elvis Dohmatob. 2019. Adversarial robustness via label-smoothing. arXiv:1906.11567. Retrieved from https:\/\/arxiv.org\/abs\/1906.11567"},{"key":"e_1_3_3_23_2","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Goldberger Jacob","year":"2017","unstructured":"Jacob Goldberger and Ehud Ben-Reuven. 2017. Training deep neural-networks using a noise adaptation layer. In Proceedings of the International Conference on Learning Representations."},{"key":"e_1_3_3_24_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01249-6_9"},{"key":"e_1_3_3_25_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICPR.1996.547416"},{"key":"e_1_3_3_26_2","first-page":"8536","volume-title":"Proceedings of the Advances in Neural Information Processing Systems","author":"Han Bo","year":"2018","unstructured":"Bo Han, Quanming Yao, Xingrui Yu, Gang Niu, Miao Xu, Weihua Hu, Ivor W. Tsang, and Masashi Sugiyama. 2018. Co-teaching: Robust training of deep neural networks with extremely noisy labels. In Proceedings of the Advances in Neural Information Processing Systems. 8536\u20138546."},{"key":"e_1_3_3_27_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00524"},{"key":"e_1_3_3_28_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"e_1_3_3_29_2","unstructured":"Geoffrey Hinton Oriol Vinyals and Jeff Dean. 2015. Distilling the knowledge in a neural network. arXiv:1503.02531. Retrieved from https:\/\/arxiv.org\/abs\/1503.02531"},{"key":"e_1_3_3_30_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2012.6247673"},{"key":"e_1_3_3_31_2","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2023.3275585"},{"key":"e_1_3_3_32_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.580"},{"key":"e_1_3_3_33_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00342"},{"key":"e_1_3_3_34_2","volume-title":"Proceedings of the Advances in Neural Information Processing Systems","author":"Ilyas Andrew","year":"2019","unstructured":"Andrew Ilyas, Shibani Santurkar, Dimitris Tsipras, Logan Engstrom, Brandon Tran, and Aleksander Madry. 2019. Adversarial examples are not bugs, they are features. In Proceedings of the Advances in Neural Information Processing Systems."},{"key":"e_1_3_3_35_2","first-page":"2309","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Jiang Lu","year":"2018","unstructured":"Lu Jiang, Zhengyuan Zhou, Thomas Leung, Li-Jia Li, and Li Fei-Fei. 2018. Mentornet: Learning data-driven curriculum for very deep neural networks on corrupted labels. In Proceedings of the International Conference on Machine Learning. 2309\u20132318."},{"key":"e_1_3_3_36_2","doi-asserted-by":"publisher","DOI":"10.1186\/s40537-019-0192-5"},{"key":"e_1_3_3_37_2","volume-title":"Learning Multiple Layers of Features from Tiny Images","author":"Krizhevsky Alex","year":"2009","unstructured":"Alex Krizhevsky and Geoffrey Hinton. 2009. Learning Multiple Layers of Features from Tiny Images. Technical Report."},{"key":"e_1_3_3_38_2","first-page":"1189","volume-title":"Proceedings of the Advances in Neural Information Processing Systems","author":"Kumar M","year":"2010","unstructured":"M Kumar, Benjamin Packer, and Daphne Koller. 2010. Self-paced learning for latent variable models. In Proceedings of the Advances in Neural Information Processing Systems. 1189\u20131197."},{"key":"e_1_3_3_39_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.neunet.2019.10.014"},{"key":"e_1_3_3_40_2","unstructured":"Wonseok Lee Hanbit Lee and Sang-goo Lee. 2020. Semantics-preserving adversarial training. arXiv:2009.10978. Retrieved from https:\/\/arxiv.org\/abs\/2009.10978"},{"key":"e_1_3_3_41_2","unstructured":"Zhaoqi Leng Mingxing Tan Chenxi Liu Ekin Dogus Cubuk Xiaojie Shi Shuyang Cheng and Dragomir Anguelov. 2022. PolyLoss: A polynomial expansion perspective of classification loss functions. In Proceedings of the International Conference on Learning Representations."},{"key":"e_1_3_3_42_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.33018577"},{"key":"e_1_3_3_43_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00519"},{"key":"e_1_3_3_44_2","first-page":"3163","volume-title":"Proceedings of the Advances in Neural Information Processing Systems","author":"Li Mingchen","year":"2021","unstructured":"Mingchen Li, Xuechen Zhang, Christos Thrampoulidis, Jiasi Chen, and Samet Oymak. 2021. AutoBalance: Optimized loss functions for imbalanced data. In Proceedings of the Advances in Neural Information Processing Systems. 3163\u20133177."},{"key":"e_1_3_3_45_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00517"},{"key":"e_1_3_3_46_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.324"},{"key":"e_1_3_3_47_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.00018"},{"key":"e_1_3_3_48_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00303"},{"key":"e_1_3_3_49_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.01222"},{"key":"e_1_3_3_50_2","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2015.2456899"},{"key":"e_1_3_3_51_2","doi-asserted-by":"publisher","DOI":"10.1109\/TCYB.2020.2990908"},{"key":"e_1_3_3_52_2","first-page":"3355","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Ma Xingjun","year":"2018","unstructured":"Xingjun Ma, Yisen Wang, Michael E Houle, Shuo Zhou, Sarah Erfani, Shutao Xia, Sudanthi Wijewickrema, and James Bailey. 2018. Dimensionality-driven learning with noisy labels. In Proceedings of the International Conference on Machine Learning. 3355\u20133364."},{"key":"e_1_3_3_53_2","doi-asserted-by":"publisher","DOI":"10.5555\/2002472.2002491"},{"key":"e_1_3_3_54_2","unstructured":"Aleksander M\u0105dry Aleksandar Makelov Ludwig Schmidt Dimitris Tsipras and Adrian Vladu. 2018. Towards deep learning models resistant to adversarial attacks. In Proceedings of the International Conference on Learning Representations."},{"key":"e_1_3_3_55_2","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2020.3049011"},{"key":"e_1_3_3_56_2","unstructured":"Aditya Krishna Menon Sadeep Jayasumana Ankit Singh Rawat Himanshu Jain Andreas Veit and Sanjiv Kumar. 2021. Long-tail learning via logit adjustment. In Proceedings of the International Conference on Learning Representations."},{"key":"e_1_3_3_57_2","volume-title":"Proceedings of the ICML 2021 Workshop on Adversarial Machine Learning","author":"Metzen Jan Hendrik","year":"2021","unstructured":"Jan Hendrik Metzen, Nicole Finnie, and Robin Hutmacher. 2021. Meta adversarial training against universal patches. In Proceedings of the ICML 2021 Workshop on Adversarial Machine Learning."},{"key":"e_1_3_3_58_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.17"},{"key":"e_1_3_3_59_2","first-page":"1196","volume-title":"Proceedings of the Advances in Neural Information Processing Systems","author":"Natarajan Nagarajan","year":"2013","unstructured":"Nagarajan Natarajan, Inderjit S. Dhillon, Pradeep Ravikumar, and Ambuj Tewari. 2013. Learning with noisy labels. In Proceedings of the Advances in Neural Information Processing Systems. 1196\u20131204."},{"key":"e_1_3_3_60_2","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2021.3105238"},{"key":"e_1_3_3_61_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.2012.2232347"},{"key":"e_1_3_3_62_2","unstructured":"Gabriel Pereyra George Tucker Jan Chorowski \u0141ukasz Kaiser and Geoffrey Hinton. 2017. Regularizing neural networks by penalizing confident output distributions. In Proceedings of the International Conference on Learning Representations Workshop."},{"key":"e_1_3_3_63_2","unstructured":"Scott E. Reed Honglak Lee Dragomir Anguelov Christian Szegedy Dumitru Erhan and Andrew Rabinovich. 2015. Training deep neural networks on noisy labels with bootstrapping. In Proceedings of the International Conference on Learning Representations Workshop."},{"key":"e_1_3_3_64_2","first-page":"4331","volume-title":"ICML","author":"Ren Mengye","year":"2018","unstructured":"Mengye Ren, Wenyuan Zeng, Bin Yang, and Raquel Urtasun. 2018. Learning to reweight examples for robust deep learning. In ICML. 4331\u20134340."},{"key":"e_1_3_3_65_2","doi-asserted-by":"publisher","DOI":"10.1162\/089976600300015565"},{"key":"e_1_3_3_66_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i04.6017"},{"key":"e_1_3_3_67_2","doi-asserted-by":"publisher","DOI":"10.1109\/TCYB.2022.3146388"},{"key":"e_1_3_3_68_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01164"},{"key":"e_1_3_3_69_2","first-page":"1917","volume-title":"Proceedings of the Advances in Neural Information Processing Systems","author":"Shu Jun","year":"2019","unstructured":"Jun Shu, Qi Xie, Lixuan Yi, Qian Zhao, Sanping Zhou, Zongben Xu, and Deyu Meng. 2019. Meta-weight-net: Learning an explicit mapping For sample weighting. In Proceedings of the Advances in Neural Information Processing Systems. 1917\u20131928."},{"key":"e_1_3_3_70_2","doi-asserted-by":"publisher","DOI":"10.1214\/18-EJS1498"},{"key":"e_1_3_3_71_2","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2022.3152527"},{"key":"e_1_3_3_72_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.308"},{"key":"e_1_3_3_73_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00582"},{"key":"e_1_3_3_74_2","unstructured":"Sunil Thulasidasan Tanmoy Bhattacharya Jeffrey Bilmes Gopinath Chennupati and Jamaludin Mohd-Yusof. 2019. Combating label noise in deep learning using abstention. In Proceedings of the International Conference on Machine Learning. 6234\u20136243."},{"key":"e_1_3_3_75_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.01909"},{"key":"e_1_3_3_76_2","doi-asserted-by":"publisher","DOI":"10.1109\/TCYB.2020.3041481"},{"issue":"11","key":"e_1_3_3_77_2","first-page":"8433","article-title":"Meta balanced network for fair face recognition","volume":"44","author":"Wang Mei","year":"2022","unstructured":"Mei Wang, Yaobin Zhang, and Weihong Deng. 2022. Meta balanced network for fair face recognition. IEEE Transactions on Pattern Analysis and Machine Intelligence 44, 11 (2022), 8433\u20138448.","journal-title":"IEEE Transactions on Pattern Analysis and Machine Intelligence"},{"key":"e_1_3_3_78_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00081"},{"key":"e_1_3_3_79_2","first-page":"3646","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Wang Yixin","year":"2017","unstructured":"Yixin Wang, Alp Kucukelbir, and David M. Blei. 2017. Robust probabilistic modeling with bayesian data reweighting. In Proceedings of the International Conference on Machine Learning. 3646\u20133655."},{"key":"e_1_3_3_80_2","first-page":"12614","volume-title":"Proceedings of the Advances in Neural Information Processing Systems","author":"Wang Yulin","year":"2019","unstructured":"Yulin Wang, Xuran Pan, Shiji Song, Hong Zhang, Cheng Wu, and Gao Huang. 2019. Implicit semantic data augmentation for deep networks. In Proceedings of the Advances in Neural Information Processing Systems. 12614\u201312623."},{"key":"e_1_3_3_81_2","doi-asserted-by":"publisher","DOI":"10.1145\/3386252"},{"key":"e_1_3_3_82_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00458"},{"key":"e_1_3_3_83_2","unstructured":"Xiaoxia Wu Ethan Dyer and Behnam Neyshabur. 2021. When do curricula work? In Proceedings of the International Conference on Learning Representations."},{"key":"e_1_3_3_84_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i12.17244"},{"key":"e_1_3_3_85_2","first-page":"2691","volume-title":"Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition","author":"Xiao Tong","year":"2015","unstructured":"Tong Xiao, Tian Xia, Yi Yang, Chang Huang, and Xiaogang Wang. 2015. Learning from massive noisy labeled data for image classification. In Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition. 2691\u20132699."},{"key":"e_1_3_3_86_2","first-page":"11492","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Xu Han","year":"2021","unstructured":"Han Xu, Xiaorui Liu, Yaxin Li, Anil Jain, and Jiliang Tang. 2021. To be robust or to be fair: Towards fairness in adversarial training. In Proceedings of the International Conference on Machine Learning. 11492\u201311501."},{"key":"e_1_3_3_87_2","doi-asserted-by":"publisher","DOI":"10.1109\/TCYB.2018.2882908"},{"key":"e_1_3_3_88_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2018.2877939"},{"key":"e_1_3_3_89_2","volume-title":"Proceedings of the AAAI-22 Workshop on Adversarial Machine Learning and Beyond","author":"Yuan Chia-Hung","year":"2022","unstructured":"Chia-Hung Yuan, Pin-Yu Chen, and Chia-Mu Yu. 2022. Meta adversarial perturbations. In Proceedings of the AAAI-22 Workshop on Adversarial Machine Learning and Beyond."},{"key":"e_1_3_3_90_2","doi-asserted-by":"crossref","unstructured":"Sergey Zagoruyko and Nikos Komodakis. 2016. Wide residual networks. In Proceedings of the British Machine Vision Conference.","DOI":"10.5244\/C.30.87"},{"key":"e_1_3_3_91_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2021.3089942"},{"key":"e_1_3_3_92_2","unstructured":"Hongyi Zhang Moustapha Cisse Yann N. Dauphin and David Lopez-Paz. 2018. Mixup: beyond empirical risk minimization. In Proceedings of the International Conference on Learning Representations."},{"issue":"3","key":"e_1_3_3_93_2","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3374217","article-title":"Adversarial attacks on deep-learning models in natural language processing: A survey","volume":"11","author":"Zhang Wei Emma","year":"2020","unstructured":"Wei Emma Zhang, Quan Z. Sheng, Ahoud Alhazmi, and Chenliang Li. 2020. Adversarial attacks on deep-learning models in natural language processing: A survey. ACM Transactions on Intelligent Systems and Technology 11, 3 (2020), 1\u201341.","journal-title":"ACM Transactions on Intelligent Systems and Technology"},{"key":"e_1_3_3_94_2","doi-asserted-by":"publisher","DOI":"10.1109\/LSP.2020.3026943"},{"key":"e_1_3_3_95_2","first-page":"7037","volume-title":"ACL","author":"Zhou Wangchunshu","year":"2022","unstructured":"Wangchunshu Zhou, Canwen Xu, and Julian McAuley. 2022. BERT learns to teach: Knowledge distillation with meta learning. In ACL. 7037\u20137049."},{"key":"e_1_3_3_96_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v36i3.20271"}],"container-title":["ACM Transactions on Knowledge Discovery from Data"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3644391","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3644391","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T22:50:48Z","timestamp":1750287048000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3644391"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,3,26]]},"references-count":95,"journal-issue":{"issue":"5","published-print":{"date-parts":[[2024,6,30]]}},"alternative-id":["10.1145\/3644391"],"URL":"https:\/\/doi.org\/10.1145\/3644391","relation":{},"ISSN":["1556-4681","1556-472X"],"issn-type":[{"value":"1556-4681","type":"print"},{"value":"1556-472X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,3,26]]},"assertion":[{"value":"2022-10-15","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-01-26","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-03-26","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}