{"id":"https://openalex.org/W3210283826","doi":"https://doi.org/10.1145/3474369.3486878","title":"SAT","display_name":"SAT","publication_year":2021,"publication_date":"2021-10-28","ids":{"openalex":"https://openalex.org/W3210283826","doi":"https://doi.org/10.1145/3474369.3486878","mag":"3210283826"},"language":"en","primary_location":{"id":"doi:10.1145/3474369.3486878","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3474369.3486878","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3474369.3486878","source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 14th ACM Workshop on Artificial Intelligence and Security","raw_type":"proceedings-article"},"type":"preprint","indexed_in":["arxiv","crossref"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://dl.acm.org/doi/pdf/10.1145/3474369.3486878","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5040461332","display_name":"Chawin Sitawarin","orcid":"https://orcid.org/0000-0002-4949-9661"},"institutions":[{"id":"https://openalex.org/I95457486","display_name":"University of California, Berkeley","ror":"https://ror.org/01an7q238","country_code":"US","type":"education","lineage":["https://openalex.org/I95457486"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Chawin Sitawarin","raw_affiliation_strings":["University of California, Berkeley, Berkeley, CA, USA"],"affiliations":[{"raw_affiliation_string":"University of California, Berkeley, Berkeley, CA, USA","institution_ids":["https://openalex.org/I95457486"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101527369","display_name":"Supriyo Chakraborty","orcid":"https://orcid.org/0000-0003-3697-0044"},"institutions":[{"id":"https://openalex.org/I4210114115","display_name":"IBM Research - Thomas J. Watson Research Center","ror":"https://ror.org/0265w5591","country_code":"US","type":"facility","lineage":["https://openalex.org/I1341412227","https://openalex.org/I4210114115"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Supriyo Chakraborty","raw_affiliation_strings":["IBM T. J. Watson Research Center, Yorktown Heights, NY, USA"],"affiliations":[{"raw_affiliation_string":"IBM T. J. Watson Research Center, Yorktown Heights, NY, USA","institution_ids":["https://openalex.org/I4210114115"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5062174672","display_name":"David Wagner","orcid":"https://orcid.org/0000-0001-7728-4273"},"institutions":[{"id":"https://openalex.org/I95457486","display_name":"University of California, Berkeley","ror":"https://ror.org/01an7q238","country_code":"US","type":"education","lineage":["https://openalex.org/I95457486"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"David Wagner","raw_affiliation_strings":["University of California, Berkeley, Berkeley, CA, USA"],"affiliations":[{"raw_affiliation_string":"University of California, Berkeley, Berkeley, CA, USA","institution_ids":["https://openalex.org/I95457486"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5040461332"],"corresponding_institution_ids":["https://openalex.org/I95457486"],"apc_list":null,"apc_paid":null,"fwci":1.5396,"has_fulltext":true,"cited_by_count":18,"citation_normalized_percentile":{"value":0.86282861,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":90,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"25","last_page":"36"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11307","display_name":"Domain Adaptation and Few-Shot Learning","score":0.9976999759674072,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10036","display_name":"Advanced Neural Network Applications","score":0.9970999956130981,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/hessian-matrix","display_name":"Hessian matrix","score":0.7710936069488525},{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.683853268623352},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.6482367515563965},{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.641455888748169},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.5410704612731934},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.4638853669166565},{"id":"https://openalex.org/keywords/minimax","display_name":"Minimax","score":0.4307786226272583},{"id":"https://openalex.org/keywords/mathematical-optimization","display_name":"Mathematical optimization","score":0.4164596199989319},{"id":"https://openalex.org/keywords/deep-neural-networks","display_name":"Deep neural networks","score":0.41543954610824585},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.35164910554885864},{"id":"https://openalex.org/keywords/algorithm","display_name":"Algorithm","score":0.33836829662323},{"id":"https://openalex.org/keywords/mathematics","display_name":"Mathematics","score":0.29200130701065063},{"id":"https://openalex.org/keywords/applied-mathematics","display_name":"Applied mathematics","score":0.1903495490550995}],"concepts":[{"id":"https://openalex.org/C203616005","wikidata":"https://www.wikidata.org/wiki/Q620495","display_name":"Hessian matrix","level":2,"score":0.7710936069488525},{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.683853268623352},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6482367515563965},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.641455888748169},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5410704612731934},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.4638853669166565},{"id":"https://openalex.org/C149728462","wikidata":"https://www.wikidata.org/wiki/Q751319","display_name":"Minimax","level":2,"score":0.4307786226272583},{"id":"https://openalex.org/C126255220","wikidata":"https://www.wikidata.org/wiki/Q141495","display_name":"Mathematical optimization","level":1,"score":0.4164596199989319},{"id":"https://openalex.org/C2984842247","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep neural networks","level":3,"score":0.41543954610824585},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.35164910554885864},{"id":"https://openalex.org/C11413529","wikidata":"https://www.wikidata.org/wiki/Q8366","display_name":"Algorithm","level":1,"score":0.33836829662323},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.29200130701065063},{"id":"https://openalex.org/C28826006","wikidata":"https://www.wikidata.org/wiki/Q33521","display_name":"Applied mathematics","level":1,"score":0.1903495490550995},{"id":"https://openalex.org/C185592680","wikidata":"https://www.wikidata.org/wiki/Q2329","display_name":"Chemistry","level":0,"score":0.0},{"id":"https://openalex.org/C55493867","wikidata":"https://www.wikidata.org/wiki/Q7094","display_name":"Biochemistry","level":1,"score":0.0},{"id":"https://openalex.org/C104317684","wikidata":"https://www.wikidata.org/wiki/Q7187","display_name":"Gene","level":2,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1145/3474369.3486878","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3474369.3486878","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3474369.3486878","source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 14th ACM Workshop on Artificial Intelligence and Security","raw_type":"proceedings-article"},{"id":"pmh:oai:arXiv.org:2003.09347","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2003.09347","pdf_url":"https://arxiv.org/pdf/2003.09347","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"}],"best_oa_location":{"id":"doi:10.1145/3474369.3486878","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3474369.3486878","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3474369.3486878","source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 14th ACM Workshop on Artificial Intelligence and Security","raw_type":"proceedings-article"},"sustainable_development_goals":[{"score":0.47999998927116394,"id":"https://metadata.un.org/sdg/9","display_name":"Industry, innovation and infrastructure"}],"awards":[{"id":"https://openalex.org/G2043895709","display_name":null,"funder_award_id":"W911NF-13-2-0045","funder_id":"https://openalex.org/F4320338295","funder_display_name":"Army Research Laboratory"},{"id":"https://openalex.org/G3732666562","display_name":null,"funder_award_id":"W911NF-13","funder_id":"https://openalex.org/F4320338295","funder_display_name":"Army Research Laboratory"},{"id":"https://openalex.org/G4307486606","display_name":null,"funder_award_id":"W911NF-13-2-0045 (ARL Cyber Security CRA)","funder_id":"https://openalex.org/F4320338295","funder_display_name":"Army Research Laboratory"},{"id":"https://openalex.org/G5259331294","display_name":null,"funder_award_id":"W911NF","funder_id":"https://openalex.org/F4320338295","funder_display_name":"Army Research Laboratory"},{"id":"https://openalex.org/G8763038417","display_name":null,"funder_award_id":"Cooperative Agreement Number W911NF-13-2-0045","funder_id":"https://openalex.org/F4320338295","funder_display_name":"Army Research Laboratory"}],"funders":[{"id":"https://openalex.org/F4320315389","display_name":"Open Philanthropy Project","ror":"https://ror.org/004d1k391"},{"id":"https://openalex.org/F4320315784","display_name":"U.S. Army Combat Capabilities Development Command Soldier Center","ror":"https://ror.org/02rdkx920"},{"id":"https://openalex.org/F4320333609","display_name":"Center for Long-Term Cybersecurity, University of California Berkeley","ror":null},{"id":"https://openalex.org/F4320338295","display_name":"Army Research Laboratory","ror":"https://ror.org/011hc8f90"}],"has_content":{"grobid_xml":true,"pdf":true},"content_urls":{"pdf":"https://content.openalex.org/works/W3210283826.pdf","grobid_xml":"https://content.openalex.org/works/W3210283826.grobid-xml"},"referenced_works_count":40,"referenced_works":["https://openalex.org/W9657784","https://openalex.org/W1673923490","https://openalex.org/W1945616565","https://openalex.org/W2093488901","https://openalex.org/W2142426721","https://openalex.org/W2145339207","https://openalex.org/W2296073425","https://openalex.org/W2474090883","https://openalex.org/W2552194003","https://openalex.org/W2579029485","https://openalex.org/W2610512602","https://openalex.org/W2768267830","https://openalex.org/W2777662428","https://openalex.org/W2785355717","https://openalex.org/W2798332588","https://openalex.org/W2912811302","https://openalex.org/W2913266441","https://openalex.org/W2945793108","https://openalex.org/W2951954464","https://openalex.org/W2963143631","https://openalex.org/W2963173418","https://openalex.org/W2963495494","https://openalex.org/W2963636205","https://openalex.org/W2963959597","https://openalex.org/W2964137095","https://openalex.org/W2980728855","https://openalex.org/W2995245581","https://openalex.org/W2996344901","https://openalex.org/W2996564870","https://openalex.org/W3009542902","https://openalex.org/W3035032188","https://openalex.org/W3035226846","https://openalex.org/W3092171228","https://openalex.org/W3092873005","https://openalex.org/W4285706568","https://openalex.org/W4287864733","https://openalex.org/W4287868720","https://openalex.org/W4288363925","https://openalex.org/W4293846201","https://openalex.org/W4393367792"],"related_works":["https://openalex.org/W4283320637","https://openalex.org/W4200062060","https://openalex.org/W2950183588","https://openalex.org/W3080754722","https://openalex.org/W3093978547","https://openalex.org/W2953536436","https://openalex.org/W3203790781","https://openalex.org/W4313346231","https://openalex.org/W2738001131","https://openalex.org/W4285785480"],"abstract_inverted_index":{"Adversarial":[0,38],"training":[1,9,119],"(AT)":[2],"has":[3],"become":[4],"a":[5,27,57,79,86,122,133,147,165,188],"popular":[6],"choice":[7],"for":[8,78,89,121],"robust":[10,174,204],"networks.":[11],"However,":[12],"it":[13],"tends":[14],"to":[15,130,142,146,157,183],"sacrifice":[16],"clean":[17,135,152],"accuracy":[18,136,153,175,205],"heavily":[19],"in":[20,92,150],"favor":[21],"of":[22,48,71,191],"robustness":[23,138,155],"and":[24,64,96,108,126,154,160,173,178,199,203],"suffers":[25],"from":[26],"large":[28,123],"generalization":[29],"error.":[30],"To":[31,163],"address":[32],"these":[33],"concerns,":[34],"we":[35],"propose":[36,97],"Smooth":[37],"Training":[39],"(SAT),":[40],"guided":[41],"by":[42,176,197],"our":[43,168,193],"analysis":[44],"on":[45,61,68,102,180,201],"the":[46,49,69,74,93,103,109,128],"eigenspectrum":[47],"loss":[50,76],"Hessian.":[51],"We":[52,84,113],"find":[53],"that":[54,59,115],"curriculum":[55,90],"learning,":[56],"scheme":[58],"emphasizes":[60],"starting":[62],"\"easy''":[63],"gradually":[65],"ramping":[66],"up":[67],"\"difficulty''":[70],"training,":[72],"smooths":[73],"adversarial":[75,94],"landscape":[77],"suitably":[80],"chosen":[81],"difficulty":[82,99],"metric.":[83],"present":[85],"general":[87],"formulation":[88],"learning":[91],"setting":[95],"two":[98],"metrics":[100],"based":[101],"maximal":[104],"Hessian":[105],"eigenvalue":[106],"(H-SAT)":[107],"softmax":[110],"probability":[111],"(P-SA).":[112],"demonstrate":[114],"SAT":[116],"stabilizes":[117],"network":[118,129],"even":[120],"perturbation":[124],"norm":[125],"allows":[127],"operate":[131],"at":[132],"better":[134],"versus":[137],"trade-off":[139],"curve":[140],"compared":[141,156,182],"AT.":[143],"This":[144],"leads":[145],"significant":[148],"improvement":[149],"both":[151],"AT,":[158,184],"TRADES,":[159],"other":[161],"baselines.":[162],"highlight":[164],"few":[166],"results,":[167],"best":[169],"model":[170,194],"improves":[171],"normal":[172,202],"6%":[177],"1%":[179],"CIFAR-100":[181],"respectively.":[185,206],"On":[186],"Imagenette,":[187],"ten-class":[189],"subset":[190],"ImageNet,":[192],"outperforms":[195],"AT":[196],"23%":[198],"3%":[200]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2025,"cited_by_count":6},{"year":2024,"cited_by_count":6},{"year":2023,"cited_by_count":1},{"year":2022,"cited_by_count":4}],"updated_date":"2026-04-10T15:06:20.359241","created_date":"2021-11-08T00:00:00"}
