{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,24]],"date-time":"2026-06-24T05:53:52Z","timestamp":1782280432423,"version":"3.54.5"},"reference-count":130,"publisher":"Association for Computing Machinery (ACM)","issue":"6","license":[{"start":{"date-parts":[[2025,2,10]],"date-time":"2025-02-10T00:00:00Z","timestamp":1739145600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"NSFC-ISF Joint Program","award":["62161146001"],"award-info":[{"award-number":["62161146001"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Comput. Surv."],"published-print":{"date-parts":[[2025,6,30]]},"abstract":"<jats:p>With the rapid development of deep learning, AI systems are being used more in complex and important domains and necessitates the simultaneous fulfillment of multiple constraints: accurate, robust, and fair. Accuracy measures how well a DNN can generalize to new data. Robustness demonstrates how well the network can withstand minor perturbations without changing the results. Fairness focuses on treating different groups equally. This survey provides an overview of the triangular trade-off among robustness, accuracy, and fairness in neural networks. This trade-off makes it difficult for AI systems to achieve true intelligence and is connected to generalization, robustness, and fairness in deep learning. The survey explores these trade-offs and their relationships to adversarial examples, adversarial training, and fair machine learning. The trade-offs between accuracy and robustness, accuracy and fairness, and robustness and fairness have been studied to different extents. However, there is a lack of taxonomy and analysis of these trade-offs. The accuracy-robustness trade-off is inherent in Gaussian models, but it varies when classes are not closely distributed. The accuracy-fairness and robustness-fairness trade-offs have been assessed empirically, but their theoretical nature needs more investigation. This survey aims to explore the origins, evolution, influencing factors, and future research directions of these trade-offs.<\/jats:p>","DOI":"10.1145\/3645088","type":"journal-article","created":{"date-parts":[[2024,2,12]],"date-time":"2024-02-12T12:01:30Z","timestamp":1707739290000},"page":"1-40","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":11,"title":["Triangular Trade-off between Robustness, Accuracy, and Fairness in Deep Neural Networks: A Survey"],"prefix":"10.1145","volume":"57","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-3707-4623","authenticated-orcid":false,"given":"Jingyang","family":"Li","sequence":"first","affiliation":[{"name":"School of Software, Shanghai Jiao Tong University, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9005-7112","authenticated-orcid":false,"given":"Guoqiang","family":"Li","sequence":"additional","affiliation":[{"name":"School of Software, Shanghai Jiao Tong University, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2025,2,10]]},"reference":[{"key":"e_1_3_2_2_2","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/D18-1316"},{"issue":"1","key":"e_1_3_2_3_2","first-page":"4","article-title":"VQA: Visual question answering","volume":"123","author":"Antol S.","year":"2015","unstructured":"S. Antol, A. Agrawal, J. Lu, M. Mitchell, and D. Parikh. 2015. VQA: Visual question answering. Int. J. Comput. Vision 123, 1 (2015), 4\u201331.","journal-title":"Int. J. Comput. Vision"},{"key":"e_1_3_2_4_2","first-page":"274","volume-title":"Proceedings of the 35th International Conference on Machine Learning","author":"Athalye A.","year":"2018","unstructured":"A. Athalye, N. Carlini, and D. Wagner. 2018. Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples. In Proceedings of the 35th International Conference on Machine Learning. PMLR, 274\u2013283."},{"key":"e_1_3_2_5_2","unstructured":"Y. Balaji T. Goldstein and J. Hoffman. 2019. Instance adaptive adversarial training: Improved accuracy tradeoffs in neural nets. Retrieved from https:\/\/arxiv.org\/abs\/1910.08051"},{"key":"e_1_3_2_6_2","first-page":"1065","article-title":"Time, privacy, robustness, accuracy: Trade offs for the open vote network protocol.","volume":"2021","author":"Bana Gergei","year":"2021","unstructured":"Gergei Bana, Marco Biroli, Megi Dervishi, Fatima Ezzahra El Orche, R\u00e9mi G\u00e9raud-Stewart, David Naccache, Peter B. Rnne, Peter Y. A. Ryan, and Hugo Waltsburger. 2021. Time, privacy, robustness, accuracy: Trade offs for the open vote network protocol. IACR Cryptol. ePrint Arch. 2021 (2021), 1065.","journal-title":"IACR Cryptol. ePrint Arch."},{"key":"e_1_3_2_7_2","doi-asserted-by":"publisher","DOI":"10.1145\/3432931"},{"key":"e_1_3_2_8_2","first-page":"294","article-title":"Fairness and machine learning limitations and opportunities","volume":"1","author":"Barocas Solon","year":"2018","unstructured":"Solon Barocas, Moritz Hardt, and Arvind Narayanan. 2018. Fairness and machine learning limitations and opportunities. NIPS Tutor. 1 (2018), 294 pages.","journal-title":"NIPS Tutor."},{"key":"e_1_3_2_9_2","first-page":"63:1\u201363:17","article-title":"Nearly-tight VC-dimension and pseudodimension bounds for piecewise linear neural networks","volume":"20","author":"Bartlett P. L.","year":"2017","unstructured":"P. L. Bartlett, N. Harvey, C. Liaw, and A. Mehrabian. 2017. Nearly-tight VC-dimension and pseudodimension bounds for piecewise linear neural networks. J. Mach. Learn. Res 20 (2017), 63:1\u201363:17.","journal-title":"J. Mach. Learn. Res"},{"key":"e_1_3_2_10_2","first-page":"1","article-title":"Cross-validation: What does it estimate and how well does it do it?","author":"Bates Stephen","year":"2023","unstructured":"Stephen Bates, Trevor J. Hastie, and Robert Tibshirani. 2023. Cross-validation: What does it estimate and how well does it do it? J. Amer. Statist. Assoc. (2023), 1\u201312.","journal-title":"J. Amer. Statist. Assoc."},{"key":"e_1_3_2_11_2","first-page":"325","volume-title":"Proceedings of the NeurIPS Workshop on Pre-registration in Machine Learning","volume":"148","author":"Benz Philipp","year":"2020","unstructured":"Philipp Benz, Chaoning Zhang, Adil Karjauv, and In So Kweon. 2020. Robustness may be at odds with fairness: An empirical study on class-wise accuracy. In Proceedings of the NeurIPS Workshop on Pre-registration in Machine Learning, Vol. 148. PMLR, 325\u2013342."},{"key":"e_1_3_2_12_2","first-page":"884","volume-title":"Proceedings of the 38th International Conference on Machine Learning","volume":"139","author":"Bhattacharjee R.","year":"2021","unstructured":"R. Bhattacharjee, S. Jha, and K. Chaudhuri. 2021. Sample complexity of robust linear classification on separated data. In Proceedings of the 38th International Conference on Machine Learning, Vol. 139. PMLR, 884\u2013893."},{"key":"e_1_3_2_13_2","unstructured":"M. Bojarski D Del Testa D. Dworakowski B. Firner B. Flepp P. Goyal L. D. Jackel M. Monfort U. Muller and J. Zhang. 2016. End to end learning for self-driving cars. Retrieved from https:\/\/arXiv:1604.07316"},{"key":"e_1_3_2_14_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.33013240"},{"key":"e_1_3_2_15_2","first-page":"12","volume-title":"Proceedings of the 6th International Conference on Learning Representations","author":"Brendel W.","year":"2018","unstructured":"W. Brendel, J. Rauber, and M. Bethge. 2018. Decision-based adversarial attacks: Reliable attacks against black-box machine learning models. In Proceedings of the 6th International Conference on Learning Representations. OpenReview.net, 12 pages."},{"key":"e_1_3_2_16_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"e_1_3_2_17_2","unstructured":"Hong Chang Ta Duy Nguyen Sasi Kumar Murakonda Ehsan Kazemi and R. Shokri. 2020. On adversarial bias and the robustness of fair machine learning. Retrieved from https:\/\/arxiv:2006.08669"},{"key":"e_1_3_2_18_2","unstructured":"Satrajit Chatterjee and Piotr Zielinski. 2022. On the generalization mystery in deep learning. Retrieved from https:\/\/arxiv:2203.10036"},{"key":"e_1_3_2_19_2","first-page":"3543","volume-title":"Proceedings of Advances in Neural Information Processing Systems 31: Annual Conference on Neural Information Processing Systems","author":"Chen Irene Y.","year":"2018","unstructured":"Irene Y. Chen, Fredrik D. Johansson, and David A. Sontag. 2018. Why is my classifier discriminatory? In Proceedings of Advances in Neural Information Processing Systems 31: Annual Conference on Neural Information Processing Systems. 3543\u20133554."},{"key":"e_1_3_2_20_2","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140448"},{"issue":"4","key":"e_1_3_2_21_2","first-page":"2188","article-title":"Universal adversarial attack on attention and the resulting dataset DAmageNet","volume":"44","author":"Chen S.","year":"2022","unstructured":"S. Chen, Z. He, C. Sun, J. Yang, and X. Huang. 2022. Universal adversarial attack on attention and the resulting dataset DAmageNet. IEEE Trans. Pattern Anal. Mach. Intell. 44, 4 (2022), 2188\u20132197.","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"e_1_3_2_22_2","doi-asserted-by":"publisher","DOI":"10.1145\/3376898"},{"key":"e_1_3_2_23_2","doi-asserted-by":"publisher","DOI":"10.1145\/3461702.3462519"},{"key":"e_1_3_2_24_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"e_1_3_2_25_2","unstructured":"Terrance Devries and Graham W. Taylor. 2017. Improved regularization of convolutional neural networks with cutout. Retrieved from https:\/\/arXiv:1708.04552"},{"key":"e_1_3_2_26_2","unstructured":"Edgar Dobriban Hamed Hassani David Hong and Alexander Robey. 2020. Provable tradeoffs in adversarially robust classification. Retrieved from https:\/\/arXiv:2006.05161"},{"key":"e_1_3_2_27_2","doi-asserted-by":"publisher","DOI":"10.1145\/3320269.3384733"},{"key":"e_1_3_2_28_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-77935-5_9"},{"key":"e_1_3_2_29_2","series-title":"Proceedings of Machine Learning Research","first-page":"2803","volume-title":"Proceedings of the 37th International Conference on Machine Learning","volume":"119","author":"Dutta Sanghamitra","year":"2020","unstructured":"Sanghamitra Dutta, Dennis Wei, Hazar Yueksel, Pin-Yu Chen, Sijia Liu, and Kush R. Varshney. 2020. Is there a trade-off between fairness and accuracy? A perspective using mismatched hypothesis testing. In Proceedings of the 37th International Conference on Machine Learning(Proceedings of Machine Learning Research, Vol. 119). PMLR, 2803\u20132813."},{"key":"e_1_3_2_30_2","first-page":"43","article-title":"An abstraction-based framework for neural network verification","volume":"12224","author":"Elboher Yizhak Yisrael","year":"2019","unstructured":"Yizhak Yisrael Elboher, Justin Emile Gottschlich, and Guy Katz. 2019. An abstraction-based framework for neural network verification. Comput. Aided Verific. 12224 (2019), 43\u201365.","journal-title":"Comput. Aided Verific."},{"key":"e_1_3_2_31_2","doi-asserted-by":"publisher","DOI":"10.1145\/2783258.2783311"},{"key":"e_1_3_2_32_2","doi-asserted-by":"publisher","DOI":"10.1145\/3433949"},{"key":"e_1_3_2_33_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00058"},{"key":"e_1_3_2_34_2","series-title":"Proceedings of Machine Learning Research","first-page":"297","volume-title":"Proceedings of the Conference on Learning Theory","volume":"75","author":"Golowich Noah","year":"2018","unstructured":"Noah Golowich, Alexander Rakhlin, and Ohad Shamir. 2018. Size-independent sample complexity of neural networks. In Proceedings of the Conference on Learning Theory(Proceedings of Machine Learning Research, Vol. 75). PMLR, 297\u2013299."},{"key":"e_1_3_2_35_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10710-017-9314-z"},{"key":"e_1_3_2_36_2","first-page":"11","volume-title":"Proceedings of the 3rd International Conference on Learning Representations","author":"Goodfellow Ian J.","year":"2015","unstructured":"Ian J. Goodfellow, Jonathon Shlens, and Christian Szegedy. 2015. Explaining and harnessing adversarial examples. In Proceedings of the 3rd International Conference on Learning Representations. 11 pages."},{"key":"e_1_3_2_37_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"e_1_3_2_38_2","first-page":"2266","volume-title":"Proceedings of Advances in Neural Information Processing Systems 30: Annual Conference on Neural Information Processing Systems","author":"Hein Matthias","year":"2017","unstructured":"Matthias Hein and Maksym Andriushchenko. 2017. Formal guarantees on the robustness of a classifier against adversarial manipulation. In Proceedings of Advances in Neural Information Processing Systems 30: Annual Conference on Neural Information Processing Systems. 2266\u20132276."},{"key":"e_1_3_2_39_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00745"},{"key":"e_1_3_2_40_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.243"},{"key":"e_1_3_2_41_2","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2020.findings-emnlp.7"},{"key":"e_1_3_2_42_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-63387-9_1"},{"key":"e_1_3_2_43_2","first-page":"125","volume-title":"Proceedings of the Conference on Advances in Neural Information Processing Systems","author":"Ilyas Andrew","year":"2019","unstructured":"Andrew Ilyas, Shibani Santurkar, Dimitris Tsipras, Logan Engstrom, Brandon Tran, and Aleksander Madry. 2019. Adversarial examples are not bugs, they are features. In Proceedings of the Conference on Advances in Neural Information Processing Systems. 125\u2013136."},{"key":"e_1_3_2_44_2","unstructured":"Takahiro Itazuri Yoshihiro Fukuhara Hirokatsu Kataoka and Shigeo Morishima. 2019. What do adversarially robust models look at? Retrieved from https:\/\/arXiv:1905.07666"},{"key":"e_1_3_2_45_2","series-title":"Proceedings of Machine Learning Research","first-page":"2034","volume-title":"Proceedings of the Conference on Learning Theory","volume":"125","author":"Javanmard Adel","year":"2020","unstructured":"Adel Javanmard, Mahdi Soltanolkotabi, and Hamed Hassani. 2020. Precise tradeoffs in adversarial training for linear regression. In Proceedings of the Conference on Learning Theory(Proceedings of Machine Learning Research, Vol. 125). PMLR, 2034\u20132078."},{"key":"e_1_3_2_46_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10115-011-0463-8"},{"key":"e_1_3_2_47_2","doi-asserted-by":"publisher","DOI":"10.1145\/3213586.3226206"},{"key":"e_1_3_2_48_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-63387-9_5"},{"key":"e_1_3_2_49_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-25540-4_26"},{"key":"e_1_3_2_50_2","unstructured":"Kenji Kawaguchi Leslie Pack Kaelbling and Yoshua Bengio. 2017. Generalization in deep learning. Retrieved from https:\/\/arXiv:1710.05468"},{"key":"e_1_3_2_51_2","first-page":"79","article-title":"Enhancing performance of deep learning models with different data augmentation techniques: A survey","author":"Khosla Cherry","year":"2020","unstructured":"Cherry Khosla and Baljit Singh Saini. 2020. Enhancing performance of deep learning models with different data augmentation techniques: A survey. In Proceedings of the International Conference on Intelligent Engineering and Management (ICIEM\u201920). 79\u201385.","journal-title":"Proceedings of the International Conference on Intelligent Engineering and Management (ICIEM\u201920)"},{"key":"e_1_3_2_52_2","doi-asserted-by":"publisher","DOI":"10.5555\/1643031.1643047"},{"key":"e_1_3_2_53_2","unstructured":"Alex Krizhevsky. 2014. One weird trick for parallelizing convolutional neural networks. Retrieved from https:\/\/arXiv:1404.5997"},{"issue":"4","key":"e_1_3_2_54_2","first-page":"60","article-title":"Learning multiple layers of features from tiny images","volume":"1","author":"Krizhevsky A.","year":"2009","unstructured":"A. Krizhevsky and G. Hinton. 2009. Learning multiple layers of features from tiny images. Handbook System. Autoimm. Dis. 1, 4 (2009), 60 pages.","journal-title":"Handbook System. Autoimm. Dis."},{"key":"e_1_3_2_55_2","unstructured":"Y. Lecun and C. Cortes. 2010. The MNIST database of handwritten digits. http:\/\/yann.lecun.com\/exdb\/mnist\/"},{"key":"e_1_3_2_56_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00044"},{"key":"e_1_3_2_57_2","doi-asserted-by":"publisher","DOI":"10.1111\/cogs.13191"},{"key":"e_1_3_2_58_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00850"},{"key":"e_1_3_2_59_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-10602-1_48"},{"key":"e_1_3_2_60_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10287-022-00425-z"},{"key":"e_1_3_2_61_2","unstructured":"Alessio Lomuscio and Lalit Maganti. 2017. An approach to reachability analysis for feed-forward ReLU neural networks. Retrieved from https:\/\/arXiv:1706.07351"},{"key":"e_1_3_2_62_2","unstructured":"Raphael Gontijo Lopes Dong Yin Ben Poole Justin Gilmer and Ekin D. Cubuk. 2019. Improving robustness without sacrificing accuracy with patch Gaussian augmentation. Retrieved from https:\/\/arXiv:1906.02611"},{"key":"e_1_3_2_63_2","first-page":"19","volume-title":"Proceedings of the 7th International Conference on Learning Representations","author":"Loshchilov Ilya","year":"2019","unstructured":"Ilya Loshchilov and Frank Hutter. 2019. Decoupled weight decay regularization. In Proceedings of the 7th International Conference on Learning Representations. OpenReview.net, 19 pages."},{"key":"e_1_3_2_64_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.56"},{"key":"e_1_3_2_65_2","first-page":"28","volume-title":"Proceedings of the 6th International Conference on Learning Representations","author":"Madry Aleksander","year":"2018","unstructured":"Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu. 2018. Towards deep learning models resistant to adversarial attacks. In Proceedings of the 6th International Conference on Learning Representations. OpenReview.net, 28 pages."},{"key":"e_1_3_2_66_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.ipm.2021.102642"},{"key":"e_1_3_2_67_2","doi-asserted-by":"publisher","DOI":"10.1145\/3457607"},{"key":"e_1_3_2_68_2","series-title":"Proceedings of Machine Learning Research","first-page":"107","volume-title":"Proceedings of the Conference on Fairness, Accountability and Transparency","volume":"81","author":"Menon Aditya Krishna","year":"2018","unstructured":"Aditya Krishna Menon and Robert C. Williamson. 2018. The cost of fairness in binary classification. In Proceedings of the Conference on Fairness, Accountability and Transparency(Proceedings of Machine Learning Research, Vol. 81). PMLR, 107\u2013118."},{"key":"e_1_3_2_69_2","first-page":"3575","volume-title":"Proceedings of the 35th International Conference on Machine Learning (ICML\u201918)","volume":"80","author":"Mirman Matthew","year":"2018","unstructured":"Matthew Mirman, Timon Gehr, and Martin T. Vechev. 2018. Differentiable abstract interpretation for provably robust neural networks. In Proceedings of the 35th International Conference on Machine Learning (ICML\u201918), Vol. 80. 3575\u20133583."},{"key":"e_1_3_2_70_2","first-page":"2574","article-title":"DeepFool: A simple and accurate method to fool deep neural networks","author":"Moosavi-Dezfooli S. M.","year":"2016","unstructured":"S. M. Moosavi-Dezfooli, A. Fawzi, and P. Frossard. 2016. DeepFool: A simple and accurate method to fool deep neural networks. In Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR\u201916). 2574\u20132582.","journal-title":"Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR\u201916)"},{"key":"e_1_3_2_71_2","first-page":"222:1\u2013222:69","article-title":"Classification vs regression in overparameterized regimes: Does the loss function matter?","volume":"22","author":"Muthukumar Vidya","year":"2020","unstructured":"Vidya Muthukumar, Adhyyan Narang, Vignesh Subramanian, Mikhail Belkin, Daniel J. Hsu, and Anant Sahai. 2020. Classification vs regression in overparameterized regimes: Does the loss function matter? J. Mach. Learn. Res. 22 (2020), 222:1\u2013222:69.","journal-title":"J. Mach. Learn. Res."},{"key":"e_1_3_2_72_2","unstructured":"Preetum Nakkiran. 2019. Adversarial robustness may be at odds with simplicity. Retrieved from https:\/\/arXiv:1901.00532"},{"key":"e_1_3_2_73_2","doi-asserted-by":"publisher","DOI":"10.1145\/3534678.3539232"},{"key":"e_1_3_2_74_2","series-title":"Proceedings of Machine Learning Research","first-page":"17258","volume-title":"Proceedings of the International Conference on Machine Learning","volume":"162","author":"Pang Tianyu","year":"2022","unstructured":"Tianyu Pang, Min Lin, Xiao Yang, Jun Zhu, and Shuicheng Yan. 2022. Robustness and accuracy could be reconcilable by (proper) definition. In Proceedings of the International Conference on Machine Learning(Proceedings of Machine Learning Research, Vol. 162). PMLR, 17258\u201317277."},{"key":"e_1_3_2_75_2","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"e_1_3_2_76_2","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"e_1_3_2_77_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00073"},{"key":"e_1_3_2_78_2","doi-asserted-by":"publisher","DOI":"10.5555\/2350156.2350160"},{"key":"e_1_3_2_79_2","unstructured":"Aditi Raghunathan Sang Michael Xie Fanny Yang John C. Duchi and Percy Liang. 2019. Adversarial training can hurt generalization. Retrieved from arXiv:1906.06032."},{"key":"e_1_3_2_80_2","series-title":"Proceedings of Machine Learning Research","first-page":"7909","volume-title":"Proceedings of the 37th International Conference on Machine Learning","volume":"119","author":"Raghunathan Aditi","year":"2020","unstructured":"Aditi Raghunathan, Sang Michael Xie, Fanny Yang, John C. Duchi, and Percy Liang. 2020. Understanding and mitigating the tradeoff between robustness and accuracy. In Proceedings of the 37th International Conference on Machine Learning(Proceedings of Machine Learning Research, Vol. 119). PMLR, 7909\u20137919."},{"key":"e_1_3_2_81_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICMLA.2016.0045"},{"key":"e_1_3_2_82_2","first-page":"16","volume-title":"Proceedings of the 8th International Conference on Learning Representations","author":"Ru Binxin","year":"2020","unstructured":"Binxin Ru, Adam D. Cobb, Arno Blaas, and Yarin Gal. 2020. BayesOpt adversarial attack. In Proceedings of the 8th International Conference on Learning Representations. OpenReview.net, 16 pages."},{"key":"e_1_3_2_83_2","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/N18-2002"},{"key":"e_1_3_2_84_2","first-page":"9832","volume-title":"Proceedings of Advances in Neural Information Processing Systems 32: Annual Conference on Neural Information Processing Systems","author":"Salman Hadi","year":"2019","unstructured":"Hadi Salman, Greg Yang, Huan Zhang, Cho-Jui Hsieh, and Pengchuan Zhang. 2019. A convex relaxation barrier to tight robustness verification of neural networks. In Proceedings of Advances in Neural Information Processing Systems 32: Annual Conference on Neural Information Processing Systems. 9832\u20139842."},{"key":"e_1_3_2_85_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.neunet.2014.09.003"},{"key":"e_1_3_2_86_2","first-page":"5019","volume-title":"Proceedings of Advances in Neural Information Processing Systems 31: Annual Conference on Neural Information Processing Systems","author":"Schmidt Ludwig","year":"2018","unstructured":"Ludwig Schmidt, Shibani Santurkar, Dimitris Tsipras, Kunal Talwar, and Aleksander Madry. 2018. Adversarially robust generalization requires more data. In Proceedings of Advances in Neural Information Processing Systems 31: Annual Conference on Neural Information Processing Systems. 5019\u20135031."},{"key":"e_1_3_2_87_2","doi-asserted-by":"publisher","DOI":"10.1186\/S40537-019-0197-0"},{"key":"e_1_3_2_88_2","doi-asserted-by":"publisher","DOI":"10.1038\/nature16961"},{"key":"e_1_3_2_89_2","first-page":"14","volume-title":"Proceedings of the 3rd International Conference on Learning Representations","author":"Simonyan Karen","year":"2015","unstructured":"Karen Simonyan and Andrew Zisserman. 2015. Very deep convolutional networks for large-scale image recognition. In Proceedings of the 3rd International Conference on Learning Representations. 14 pages."},{"key":"e_1_3_2_90_2","first-page":"10825","volume-title":"Proceedings of Advances in Neural Information Processing Systems 31: Annual Conference on Neural Information Processing Systems","author":"Singh Gagandeep","year":"2018","unstructured":"Gagandeep Singh, Timon Gehr, Matthew Mirman, Markus P\u00fcschel, and Martin T. Vechev. 2018. Fast and effective robustness certification. In Proceedings of Advances in Neural Information Processing Systems 31: Annual Conference on Neural Information Processing Systems. 10825\u201310836."},{"key":"e_1_3_2_91_2","doi-asserted-by":"publisher","DOI":"10.5555\/2627435.2670313"},{"key":"e_1_3_2_92_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00714"},{"key":"e_1_3_2_93_2","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"644","DOI":"10.1007\/978-3-030-01258-8_39","volume-title":"Proceedings of the 15th European Conference of Computer Vision","volume":"11216","author":"Su Dong","year":"2018","unstructured":"Dong Su, Huan Zhang, Hongge Chen, Jinfeng Yi, Pin-Yu Chen, and Yupeng Gao. 2018. Is robustness the cost of accuracy?\u2014A comprehensive study on the robustness of 18 deep image classification models. In Proceedings of the 15th European Conference of Computer Vision(Lecture Notes in Computer Science, Vol. 11216). Springer, 644\u2013661."},{"key":"e_1_3_2_94_2","first-page":"10","volume-title":"Proceedings of the 2nd International Conference on Learning Representations","author":"Szegedy Christian","year":"2014","unstructured":"Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian J. Goodfellow, and Rob Fergus. 2014. Intriguing properties of neural networks. In Proceedings of the 2nd International Conference on Learning Representations. 10 pages."},{"key":"e_1_3_2_95_2","series-title":"Proceedings of Machine Learning Research","first-page":"6105","volume-title":"Proceedings of the 36th International Conference on Machine Learning","volume":"97","author":"Tan Mingxing","year":"2019","unstructured":"Mingxing Tan and Quoc V. Le. 2019. EfficientNet: Rethinking model scaling for convolutional neural networks. In Proceedings of the 36th International Conference on Machine Learning(Proceedings of Machine Learning Research, Vol. 97). PMLR, 6105\u20136114."},{"key":"e_1_3_2_96_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298664"},{"key":"e_1_3_2_97_2","series-title":"JMLR Workshop and Conference Proceedings","first-page":"642","volume-title":"Proceedings of the 30th International Conference on Machine Learning","volume":"28","author":"Torkamani MohamadAli","year":"2013","unstructured":"MohamadAli Torkamani and Daniel Lowd. 2013. Convex adversarial collective classification. In Proceedings of the 30th International Conference on Machine Learning(JMLR Workshop and Conference Proceedings, Vol. 28). JMLR.org, 642\u2013650."},{"key":"e_1_3_2_98_2","series-title":"JMLR Workshop and Conference Proceedings","first-page":"577","volume-title":"Proceedings of the 31th International Conference on Machine Learning","volume":"32","author":"Torkamani MohamadAli","year":"2014","unstructured":"MohamadAli Torkamani and Daniel Lowd. 2014. On robustness and regularization of structural support vector machines. In Proceedings of the 31th International Conference on Machine Learning(JMLR Workshop and Conference Proceedings, Vol. 32). JMLR.org, 577\u2013585."},{"key":"e_1_3_2_99_2","first-page":"23","volume-title":"Proceedings of the 7th International Conference on Learning Representations","author":"Tsipras Dimitris","year":"2019","unstructured":"Dimitris Tsipras, Shibani Santurkar, Logan Engstrom, Alexander Turner, and Aleksander Madry. 2019. Robustness may be at odds with accuracy. In Proceedings of the 7th International Conference on Learning Representations. OpenReview.net, 23 pages."},{"key":"e_1_3_2_100_2","unstructured":"Jon Vadillo and Roberto Santana. 2019. Universal adversarial examples in speech command classification. Retrieved from https:\/\/arXiv:1911.10182"},{"key":"e_1_3_2_101_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2021.102495"},{"key":"e_1_3_2_102_2","doi-asserted-by":"publisher","DOI":"10.1145\/3194770.3194776"},{"key":"e_1_3_2_103_2","first-page":"7449","volume-title":"Proceedings of Advances in Neural Information Processing Systems 33: Annual Conference on Neural Information Processing Systems","volume":"33","author":"Wang Haotao","year":"2020","unstructured":"Haotao Wang, Tianlong Chen, Shupeng Gui, Ting-Kuei Hu, Ji Liu, and Zhangyang Wang. 2020. Once-for-all adversarial training: In-situ tradeoff between robustness and accuracy for free. In Proceedings of Advances in Neural Information Processing Systems 33: Annual Conference on Neural Information Processing Systems, Vol. 33. 7449\u20137461."},{"key":"e_1_3_2_104_2","first-page":"6369","volume-title":"Proceedings of Advances in Neural Information Processing Systems 31: Annual Conference on Neural Information Processing Systems","author":"Wang Shiqi","year":"2018","unstructured":"Shiqi Wang, Kexin Pei, Justin Whitehouse, Junfeng Yang, and Suman Jana. 2018. Efficient formal safety analysis of neural networks. In Proceedings of Advances in Neural Information Processing Systems 31: Annual Conference on Neural Information Processing Systems. 6369\u20136379."},{"key":"e_1_3_2_105_2","doi-asserted-by":"publisher","DOI":"10.5555\/3277203.3277323"},{"key":"e_1_3_2_106_2","first-page":"29909","volume-title":"Proceedings of Advances in Neural Information Processing Systems 34: Annual Conference on Neural Information Processing Systems","author":"Wang Shiqi","year":"2021","unstructured":"Shiqi Wang, Huan Zhang, Kaidi Xu, Xue Lin, Suman Jana, Cho-Jui Hsieh, and J. Zico Kolter. 2021. Beta-CROWN: Efficient bound propagation with per-neuron split constraints for neural network robustness verification. In Proceedings of Advances in Neural Information Processing Systems 34: Annual Conference on Neural Information Processing Systems. 29909\u201329921."},{"key":"e_1_3_2_107_2","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2015.2411671"},{"key":"e_1_3_2_108_2","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.naacl-main.87"},{"key":"e_1_3_2_109_2","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2019\/833"},{"key":"e_1_3_2_110_2","series-title":"Proceedings of Machine Learning Research","first-page":"10029","volume-title":"Proceedings of the 37th International Conference on Machine Learning","volume":"119","author":"Wang Xiaobo","year":"2020","unstructured":"Xiaobo Wang, Shuo Wang, Cheng Chi, Shifeng Zhang, and Tao Mei. 2020. Loss function search for face recognition. In Proceedings of the 37th International Conference on Machine Learning(Proceedings of Machine Learning Research, Vol. 119). PMLR, 10029\u201310038."},{"key":"e_1_3_2_111_2","first-page":"5273","volume-title":"Proceedings of the 35th International Conference on Machine Learning (ICML\u201918)","volume":"80","author":"Weng Tsui-Wei","year":"2018","unstructured":"Tsui-Wei Weng, Huan Zhang, Hongge Chen, Zhao Song, Cho-Jui Hsieh, Luca Daniel, Duane S. Boning, and Inderjit S. Dhillon. 2018. Towards fast computation of certified robustness for ReLU networks. In Proceedings of the 35th International Conference on Machine Learning (ICML\u201918), Vol. 80. Stockholmsm\u00e4ssan, 5273\u20135282."},{"key":"e_1_3_2_112_2","first-page":"18","volume-title":"Proceedings of the 6th International Conference on Learning Representations","author":"Weng Tsui-Wei","year":"2018","unstructured":"Tsui-Wei Weng, Huan Zhang, Pin-Yu Chen, Jinfeng Yi, Dong Su, Yupeng Gao, Cho-Jui Hsieh, and Luca Daniel. 2018. Evaluating the robustness of neural networks: An extreme value theory approach. In Proceedings of the 6th International Conference on Learning Representations. OpenReview.net, 18 pages."},{"key":"e_1_3_2_113_2","volume-title":"Data Mining: Practical Machine Learning Tools and Techniques,","author":"Witten Ian H.","year":"2011","unstructured":"Ian H. Witten, Eibe Frank, and Mark A. Hall. 2011. Data Mining: Practical Machine Learning Tools and Techniques, 3rd ed. Morgan Kaufmann, Elsevier."},{"key":"e_1_3_2_114_2","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2018.2808470"},{"key":"e_1_3_2_115_2","series-title":"Proceedings of Machine Learning Research","first-page":"11492","volume-title":"Proceedings of the 38th International Conference on Machine Learning","volume":"139","author":"Xu Han","year":"2021","unstructured":"Han Xu, Xiaorui Liu, Yaxin Li, Anil K. Jain, and Jiliang Tang. 2021. To be robust or to be fair: Towards fairness in adversarial training. In Proceedings of the 38th International Conference on Machine Learning(Proceedings of Machine Learning Research, Vol. 139). PMLR, 11492\u201311501."},{"key":"e_1_3_2_116_2","first-page":"13","volume-title":"Proceedings of Advances in Neural Information Processing Systems 33: Annual Conference on Neural Information Processing Systems","author":"Xu Kaidi","year":"2020","unstructured":"Kaidi Xu, Zhouxing Shi, Huan Zhang, Yihan Wang, Kai-Wei Chang, Minlie Huang, Bhavya Kailkhura, Xue Lin, and Cho-Jui Hsieh. 2020. Automatic perturbation analysis for scalable certified robustness and beyond. In Proceedings of Advances in Neural Information Processing Systems 33: Annual Conference on Neural Information Processing Systems. 13 pages."},{"key":"e_1_3_2_117_2","first-page":"15","volume-title":"Proceedings of the 9th International Conference on Learning Representations","author":"Xu Kaidi","year":"2021","unstructured":"Kaidi Xu, Huan Zhang, Shiqi Wang, Yihan Wang, Suman Jana, Xue Lin, and Cho-Jui Hsieh. 2021. Fast and complete: Enabling complete neural network verification with rapid and massively parallel incomplete verifiers. In Proceedings of the 9th International Conference on Learning Representations. OpenReview.net, 15 pages."},{"key":"e_1_3_2_118_2","doi-asserted-by":"publisher","DOI":"10.1145\/3134600.3134642"},{"key":"e_1_3_2_119_2","first-page":"8588","volume-title":"Proceedings of Advances in Neural Information Processing Systems 33: Annual Conference on Neural Information Processing Systems","volume":"33","author":"Yang Yao-Yuan","year":"2020","unstructured":"Yao-Yuan Yang, Cyrus Rashtchian, Hongyang Zhang, Ruslan Salakhutdinov, and Kamalika Chaudhuri. 2020. A closer look at accuracy vs. robustness. In Proceedings of Advances in Neural Information Processing Systems 33: Annual Conference on Neural Information Processing Systems, Vol. 33. 8588\u20138601."},{"key":"e_1_3_2_120_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i05.6486"},{"key":"e_1_3_2_121_2","volume-title":"Proceedings of the Conference on Neural Information Processing Systems (NeurIPS\u201922)","author":"Yang Zhuolin","year":"2022","unstructured":"Zhuolin Yang, Zhikuan Zhao, Boxin Wang, Jiawei Zhang, Linyi Li, Hengzhi Pei, Bojan Karlas, Ji Liu, Heng Guo, Ce Zhang, and Bo Li. 2022. Improving certified robustness via statistical learning with logical reasoning. In Proceedings of the Conference on Neural Information Processing Systems (NeurIPS\u201922)."},{"key":"e_1_3_2_122_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.01161"},{"key":"e_1_3_2_123_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00060"},{"key":"e_1_3_2_124_2","unstructured":"Lifan Yuan Yichi Zhang Yangyi Chen and Wei Wei. 2021. Bridge the gap between CV and NLP! A gradient-based textual adversarial attack framework. Retrieved from https:\/\/arXiv:2110.15317"},{"key":"e_1_3_2_125_2","doi-asserted-by":"publisher","DOI":"10.1145\/3132847.3132938"},{"key":"e_1_3_2_126_2","series-title":"JMLR Workshop and Conference Proceedings","first-page":"325","volume-title":"Proceedings of the 30th International Conference on Machine Learning","volume":"28","author":"Zemel Richard S.","year":"2013","unstructured":"Richard S. Zemel, Yu Wu, Kevin Swersky, Toniann Pitassi, and Cynthia Dwork. 2013. Learning fair representations. In Proceedings of the 30th International Conference on Machine Learning(JMLR Workshop and Conference Proceedings, Vol. 28). JMLR.org, 325\u2013333."},{"key":"e_1_3_2_127_2","first-page":"15","volume-title":"Proceedings of the 5th International Conference on Learning Representations","author":"Zhang Chiyuan","year":"2017","unstructured":"Chiyuan Zhang, Samy Bengio, Moritz Hardt, Benjamin Recht, and Oriol Vinyals. 2017. Understanding deep learning requires rethinking generalization. In Proceedings of the 5th International Conference on Learning Representations. OpenReview.net, 15 pages."},{"key":"e_1_3_2_128_2","first-page":"4944","volume-title":"Proceedings of Advances in Neural Information Processing Systems 31: Annual Conference on Neural Information Processing Systems","author":"Zhang Huan","year":"2018","unstructured":"Huan Zhang, Tsui-Wei Weng, Pin-Yu Chen, Cho-Jui Hsieh, and Luca Daniel. 2018. Efficient neural network robustness certification with general activation functions. In Proceedings of Advances in Neural Information Processing Systems 31: Annual Conference on Neural Information Processing Systems. 4944\u20134953."},{"key":"e_1_3_2_129_2","series-title":"Proceedings of Machine Learning Research","first-page":"7472","volume-title":"Proceedings of the 36th International Conference on Machine Learning","volume":"97","author":"Zhang Hongyang","year":"2019","unstructured":"Hongyang Zhang, Yaodong Yu, Jiantao Jiao, Eric P. Xing, Laurent El Ghaoui, and Michael I. Jordan. 2019. Theoretically principled trade-off between robustness and accuracy. In Proceedings of the 36th International Conference on Machine Learning(Proceedings of Machine Learning Research, Vol. 97). PMLR, 7472\u20137482."},{"key":"e_1_3_2_130_2","first-page":"57:1\u201357:26","article-title":"Inherent tradeoffs in learning fair representations","volume":"23","author":"Zhao Han","year":"2019","unstructured":"Han Zhao and Geoffrey J. Gordon. 2019. Inherent tradeoffs in learning fair representations. J. Mach. Learn. Res. 23 (2019), 57:1\u201357:26.","journal-title":"J. Mach. Learn. Res."},{"key":"e_1_3_2_131_2","unstructured":"Indre Zliobaite. 2015. On the relation between accuracy and fairness in binary classification. Retrieved from https:\/\/arXiv:1505.05723"}],"container-title":["ACM Computing Surveys"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3645088","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3645088","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T00:03:27Z","timestamp":1750291407000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3645088"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,2,10]]},"references-count":130,"journal-issue":{"issue":"6","published-print":{"date-parts":[[2025,6,30]]}},"alternative-id":["10.1145\/3645088"],"URL":"https:\/\/doi.org\/10.1145\/3645088","relation":{},"ISSN":["0360-0300","1557-7341"],"issn-type":[{"value":"0360-0300","type":"print"},{"value":"1557-7341","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,2,10]]},"assertion":[{"value":"2022-09-14","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-01-31","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-02-10","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}