{"id":"https://openalex.org/W4385562519","doi":"https://doi.org/10.1145/3580305.3599381","title":"How does the Memorization of Neural Networks Impact Adversarial Robust Models?","display_name":"How does the Memorization of Neural Networks Impact Adversarial Robust Models?","publication_year":2023,"publication_date":"2023-08-04","ids":{"openalex":"https://openalex.org/W4385562519","doi":"https://doi.org/10.1145/3580305.3599381"},"language":"en","primary_location":{"id":"doi:10.1145/3580305.3599381","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3580305.3599381","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 29th ACM SIGKDD Conference on Knowledge Discovery and Data Mining","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5043650155","display_name":"Han Xu","orcid":"https://orcid.org/0000-0002-4016-6748"},"institutions":[{"id":"https://openalex.org/I87216513","display_name":"Michigan State University","ror":"https://ror.org/05hs6h993","country_code":"US","type":"education","lineage":["https://openalex.org/I87216513"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Han Xu","raw_affiliation_strings":["Michigan State University, East Lansing, MI, USA"],"affiliations":[{"raw_affiliation_string":"Michigan State University, East Lansing, MI, USA","institution_ids":["https://openalex.org/I87216513"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100621795","display_name":"Xiaorui Liu","orcid":"https://orcid.org/0000-0001-8217-5688"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Xiaorui Liu","raw_affiliation_strings":["North Carilina State University, Raleigh, NC, USA"],"affiliations":[{"raw_affiliation_string":"North Carilina State University, Raleigh, NC, USA","institution_ids":[]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5025401204","display_name":"Wentao Wang","orcid":null},"institutions":[{"id":"https://openalex.org/I87216513","display_name":"Michigan State University","ror":"https://ror.org/05hs6h993","country_code":"US","type":"education","lineage":["https://openalex.org/I87216513"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Wentao Wang","raw_affiliation_strings":["Michigan State University, East Lansing, MI, USA"],"affiliations":[{"raw_affiliation_string":"Michigan State University, East Lansing, MI, USA","institution_ids":["https://openalex.org/I87216513"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5014957271","display_name":"Zitao Liu","orcid":"https://orcid.org/0000-0003-0491-307X"},"institutions":[{"id":"https://openalex.org/I159948400","display_name":"Jinan University","ror":"https://ror.org/02xe5ns62","country_code":"CN","type":"education","lineage":["https://openalex.org/I159948400"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Zitao Liu","raw_affiliation_strings":["Jinan University, Guangzhou, Guangdong, China"],"affiliations":[{"raw_affiliation_string":"Jinan University, Guangzhou, Guangdong, China","institution_ids":["https://openalex.org/I159948400"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100613677","display_name":"Anil K. Jain","orcid":"https://orcid.org/0000-0002-6369-6995"},"institutions":[{"id":"https://openalex.org/I87216513","display_name":"Michigan State University","ror":"https://ror.org/05hs6h993","country_code":"US","type":"education","lineage":["https://openalex.org/I87216513"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Anil K Jain","raw_affiliation_strings":["Michigan State University, East Lansing, MI, USA"],"affiliations":[{"raw_affiliation_string":"Michigan State University, East Lansing, MI, USA","institution_ids":["https://openalex.org/I87216513"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5040639891","display_name":"Jiliang Tang","orcid":"https://orcid.org/0000-0001-7125-3898"},"institutions":[{"id":"https://openalex.org/I87216513","display_name":"Michigan State University","ror":"https://ror.org/05hs6h993","country_code":"US","type":"education","lineage":["https://openalex.org/I87216513"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Jiliang Tang","raw_affiliation_strings":["Michigan State University, East Lansing, MI, USA"],"affiliations":[{"raw_affiliation_string":"Michigan State University, East Lansing, MI, USA","institution_ids":["https://openalex.org/I87216513"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":6,"corresponding_author_ids":["https://openalex.org/A5043650155"],"corresponding_institution_ids":["https://openalex.org/I87216513"],"apc_list":null,"apc_paid":null,"fwci":0.1728,"has_fulltext":false,"cited_by_count":1,"citation_normalized_percentile":{"value":0.55432036,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":91,"max":95},"biblio":{"volume":null,"issue":null,"first_page":"2801","last_page":"2812"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9948999881744385,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10036","display_name":"Advanced Neural Network Applications","score":0.972599983215332,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/memorization","display_name":"Memorization","score":0.9254379272460938},{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.7964885234832764},{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.7708888649940491},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7268947958946228},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.6293320059776306},{"id":"https://openalex.org/keywords/deep-neural-networks","display_name":"Deep neural networks","score":0.5826747417449951},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.551952064037323},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.5148341059684753},{"id":"https://openalex.org/keywords/benchmark","display_name":"Benchmark (surveying)","score":0.479168564081192},{"id":"https://openalex.org/keywords/pattern-recognition","display_name":"Pattern recognition (psychology)","score":0.4607575535774231},{"id":"https://openalex.org/keywords/mathematics","display_name":"Mathematics","score":0.15865975618362427}],"concepts":[{"id":"https://openalex.org/C30038468","wikidata":"https://www.wikidata.org/wiki/Q4354775","display_name":"Memorization","level":2,"score":0.9254379272460938},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.7964885234832764},{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.7708888649940491},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7268947958946228},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.6293320059776306},{"id":"https://openalex.org/C2984842247","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep neural networks","level":3,"score":0.5826747417449951},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.551952064037323},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.5148341059684753},{"id":"https://openalex.org/C185798385","wikidata":"https://www.wikidata.org/wiki/Q1161707","display_name":"Benchmark (surveying)","level":2,"score":0.479168564081192},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.4607575535774231},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.15865975618362427},{"id":"https://openalex.org/C145420912","wikidata":"https://www.wikidata.org/wiki/Q853077","display_name":"Mathematics education","level":1,"score":0.0},{"id":"https://openalex.org/C55493867","wikidata":"https://www.wikidata.org/wiki/Q7094","display_name":"Biochemistry","level":1,"score":0.0},{"id":"https://openalex.org/C13280743","wikidata":"https://www.wikidata.org/wiki/Q131089","display_name":"Geodesy","level":1,"score":0.0},{"id":"https://openalex.org/C104317684","wikidata":"https://www.wikidata.org/wiki/Q7187","display_name":"Gene","level":2,"score":0.0},{"id":"https://openalex.org/C185592680","wikidata":"https://www.wikidata.org/wiki/Q2329","display_name":"Chemistry","level":0,"score":0.0},{"id":"https://openalex.org/C205649164","wikidata":"https://www.wikidata.org/wiki/Q1071","display_name":"Geography","level":0,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3580305.3599381","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3580305.3599381","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 29th ACM SIGKDD Conference on Knowledge Discovery and Data Mining","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G1432373144","display_name":null,"funder_award_id":"W911NF-21-1-","funder_id":"https://openalex.org/F4320338281","funder_display_name":"Army Research Office"},{"id":"https://openalex.org/G3412060240","display_name":"CAREER: Real-World Networks: Modeling and Analysis of Signed Networks with Positive and Negative Links","funder_award_id":"1845081","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G3565905726","display_name":"SaTC: CORE: Small: Side-channel Attacks Against Mobile Users: Singularity Detection, Behavior Identification, and Automated Rectification","funder_award_id":"1815636","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G3695851104","display_name":"III:Medium:Computation and Communication Efficient Distributed Learning","funder_award_id":"2212032","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G434729842","display_name":null,"funder_award_id":"1928278","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G545420438","display_name":"Collaborative Research: III: Medium: Graph Neural Networks for Heterophilous Data: Advancing the Theory, Models, and Applications","funder_award_id":"2212144","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G5511827387","display_name":null,"funder_award_id":"2022LSYS003","funder_id":"https://openalex.org/F4320322292","funder_display_name":"Jinan University"},{"id":"https://openalex.org/G5921281487","display_name":null,"funder_award_id":"number","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G6113845086","display_name":null,"funder_award_id":"2035472","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G647087074","display_name":null,"funder_award_id":"IOS2107215","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G7402679956","display_name":null,"funder_award_id":"IOS2035472","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G7452299184","display_name":null,"funder_award_id":"W911NF","funder_id":"https://openalex.org/F4320338281","funder_display_name":"Army Research Office"},{"id":"https://openalex.org/G7710557890","display_name":null,"funder_award_id":"IIS1845081","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G7794432752","display_name":null,"funder_award_id":"IIS2212144","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G8316610220","display_name":"III: Medium: Collaborative Research: Towards Scalable and Interpretable Graph Neural Networks","funder_award_id":"1955285","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G848032724","display_name":null,"funder_award_id":"Science","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G8657258523","display_name":"TRTech-PGR: Connecting sequences to functions within and between species through computational modeling and experimental studies","funder_award_id":"2107215","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G877152271","display_name":null,"funder_award_id":"W911NF-21-1-0198","funder_id":"https://openalex.org/F4320338281","funder_display_name":"Army Research Office"},{"id":"https://openalex.org/G8998121839","display_name":null,"funder_award_id":"911NF","funder_id":"https://openalex.org/F4320338281","funder_display_name":"Army Research Office"}],"funders":[{"id":"https://openalex.org/F4320306076","display_name":"National Science Foundation","ror":"https://ror.org/021nxhr62"},{"id":"https://openalex.org/F4320307791","display_name":"Cisco Systems","ror":"https://ror.org/03yt1ez60"},{"id":"https://openalex.org/F4320322292","display_name":"Jinan University","ror":"https://ror.org/02xe5ns62"},{"id":"https://openalex.org/F4320338281","display_name":"Army Research Office","ror":"https://ror.org/05epdh915"}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":11,"referenced_works":["https://openalex.org/W114517082","https://openalex.org/W2096733369","https://openalex.org/W2194775991","https://openalex.org/W2551176409","https://openalex.org/W2579923771","https://openalex.org/W2963857521","https://openalex.org/W3014316192","https://openalex.org/W3018252856","https://openalex.org/W3035261884","https://openalex.org/W6600804061","https://openalex.org/W6601630192"],"related_works":["https://openalex.org/W2950183588","https://openalex.org/W3080754722","https://openalex.org/W4383221314","https://openalex.org/W3093978547","https://openalex.org/W2953536436","https://openalex.org/W3203790781","https://openalex.org/W4313346231","https://openalex.org/W2738001131","https://openalex.org/W4285785480","https://openalex.org/W2997056298"],"abstract_inverted_index":{"Recent":[0],"studies":[1],"suggest":[2],"that":[3,193],"\"memorization\"":[4],"is":[5,119],"one":[6],"necessary":[7],"factor":[8],"for":[9,209],"overparameterized":[10],"deep":[11],"neural":[12],"networks":[13],"(DNNs)":[14],"to":[15,35,122,167],"achieve":[16,57,196],"optimal":[17],"performance.":[18,45],"Specifically,":[19],"the":[20,26,63,71,94,102,145,187],"perfectly":[21],"fitted":[22],"DNNs":[23,47,109],"can":[24,55,163,195],"memorize":[25],"labels":[27,64],"of":[28,65,104,189],"many":[29],"atypical":[30,39,66,74,117,128,140,171,178],"samples,":[31,67,129],"generalize":[32],"their":[33,133],"memorization":[34,105],"correctly":[36],"classify":[37],"test":[38,44,95],"samples":[40,118,141,172,179],"and":[41,91,110,136,173,191],"enjoy":[42],"better":[43,197],"While,":[46],"which":[48,162],"are":[49],"optimized":[50],"via":[51],"adversarial":[52,107,134,165],"training":[53,59,166],"algorithms":[54],"also":[56],"perfect":[58],"performance":[60,147],"by":[61],"memorizing":[62],"as":[68,70,175,180],"well":[69],"adversarially":[72,77],"perturbed":[73],"samples.":[75,150],"However,":[76],"trained":[78,108],"models":[79],"always":[80],"suffer":[81],"from":[82],"poor":[83],"generalization,":[84],"with":[85],"both":[86],"relatively":[87],"low":[88],"clean":[89,127,198],"accuracy":[90,125,199],"robustness":[92,135,201],"on":[93,126,148,152],"set.":[96],"In":[97,182],"this":[98],"work,":[99],"we":[100,156,185],"study":[101],"effect":[103],"in":[106,206],"disclose":[111],"two":[112,154],"important":[113],"findings:":[114],"(a)":[115],"Memorizing":[116,138],"only":[120],"effective":[121],"improve":[123,132],"DNN's":[124,146],"but":[130],"hardly":[131],"(b)":[137],"certain":[139],"will":[142],"even":[143],"hurt":[144],"typical":[149],"Based":[151],"these":[153],"findings,":[155],"propose":[157],"Benign":[158],"Adversarial":[159],"Training":[160],"(BAT)":[161],"facilitate":[164],"avoid":[168],"fitting":[169],"\"harmful\"":[170],"fit":[174],"more":[176],"\"benign\"":[177],"possible.":[181],"our":[183],"experiments,":[184],"validate":[186],"effectiveness":[188],"BAT,":[190],"show":[192],"it":[194],"vs.":[200],"trade-off":[202],"than":[203],"baseline":[204],"methods,":[205],"benchmark":[207],"datasets":[208],"image":[210],"classification.":[211]},"counts_by_year":[{"year":2025,"cited_by_count":1}],"updated_date":"2026-04-10T15:06:20.359241","created_date":"2025-10-10T00:00:00"}
