{"id":"https://openalex.org/W7162010209","doi":"https://doi.org/10.48550/arxiv.2605.20606","title":"Mind Your Margin and Boundary: Are Your Distilled Datasets Truly Robust?","display_name":"Mind Your Margin and Boundary: Are Your Distilled Datasets Truly Robust?","publication_year":2026,"publication_date":"2026-05-20","ids":{"openalex":"https://openalex.org/W7162010209","doi":"https://doi.org/10.48550/arxiv.2605.20606"},"language":null,"primary_location":{"id":"doi:10.48550/arxiv.2605.20606","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2605.20606","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"type":"preprint","indexed_in":["datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://doi.org/10.48550/arxiv.2605.20606","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5136618799","display_name":"Muquan Li","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Li, Muquan","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5136614285","display_name":"Yingyi Ma","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Ma, Yingyi","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5136618012","display_name":"Yihong Huang","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Huang, Yihong","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5070193665","display_name":"Hang Gou","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Gou, Hang","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5136700717","display_name":"Ke Qin","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Qin, Ke","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5136620675","display_name":"Ming Li","orcid":"https://orcid.org/0000-0001-8415-7010"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Li, Ming","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5017943466","display_name":"Yuan-Fang Li","orcid":"https://orcid.org/0000-0003-4651-2821"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Li, Yuan-Fang","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5136683216","display_name":"Tao He","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"He, Tao","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":8,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9912999868392944,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9912999868392944,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10036","display_name":"Advanced Neural Network Applications","score":0.002899999963119626,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11307","display_name":"Domain Adaptation and Few-Shot Learning","score":0.0010999999940395355,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.8019999861717224},{"id":"https://openalex.org/keywords/decision-boundary","display_name":"Decision boundary","score":0.6234999895095825},{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.5439000129699707},{"id":"https://openalex.org/keywords/margin","display_name":"Margin (machine learning)","score":0.48249998688697815},{"id":"https://openalex.org/keywords/training-set","display_name":"Training set","score":0.44449999928474426},{"id":"https://openalex.org/keywords/robust-statistics","display_name":"Robust statistics","score":0.3813000023365021},{"id":"https://openalex.org/keywords/distillation","display_name":"Distillation","score":0.3736000061035156}],"concepts":[{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.8019999861717224},{"id":"https://openalex.org/C42023084","wikidata":"https://www.wikidata.org/wiki/Q5249231","display_name":"Decision boundary","level":3,"score":0.6234999895095825},{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.5439000129699707},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5101000070571899},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.508400022983551},{"id":"https://openalex.org/C774472","wikidata":"https://www.wikidata.org/wiki/Q6760393","display_name":"Margin (machine learning)","level":2,"score":0.48249998688697815},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.45080000162124634},{"id":"https://openalex.org/C51632099","wikidata":"https://www.wikidata.org/wiki/Q3985153","display_name":"Training set","level":2,"score":0.44449999928474426},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.3864000141620636},{"id":"https://openalex.org/C67226441","wikidata":"https://www.wikidata.org/wiki/Q1665389","display_name":"Robust statistics","level":3,"score":0.3813000023365021},{"id":"https://openalex.org/C204030448","wikidata":"https://www.wikidata.org/wiki/Q101017","display_name":"Distillation","level":2,"score":0.3736000061035156},{"id":"https://openalex.org/C177264268","wikidata":"https://www.wikidata.org/wiki/Q1514741","display_name":"Set (abstract data type)","level":2,"score":0.33059999346733093},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.325300008058548},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.3156999945640564},{"id":"https://openalex.org/C160920958","wikidata":"https://www.wikidata.org/wiki/Q7662746","display_name":"Synthetic data","level":2,"score":0.3077000081539154},{"id":"https://openalex.org/C62354387","wikidata":"https://www.wikidata.org/wiki/Q875399","display_name":"Boundary (topology)","level":2,"score":0.28279998898506165},{"id":"https://openalex.org/C11413529","wikidata":"https://www.wikidata.org/wiki/Q8366","display_name":"Algorithm","level":1,"score":0.27970001101493835},{"id":"https://openalex.org/C126255220","wikidata":"https://www.wikidata.org/wiki/Q141495","display_name":"Mathematical optimization","level":1,"score":0.27630001306533813},{"id":"https://openalex.org/C154030694","wikidata":"https://www.wikidata.org/wiki/Q1436074","display_name":"Fractionating column","level":3,"score":0.2678000032901764},{"id":"https://openalex.org/C1921717","wikidata":"https://www.wikidata.org/wiki/Q1334846","display_name":"Mahalanobis distance","level":2,"score":0.25949999690055847},{"id":"https://openalex.org/C47177190","wikidata":"https://www.wikidata.org/wiki/Q207137","display_name":"Curriculum","level":2,"score":0.2500999867916107}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.48550/arxiv.2605.20606","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2605.20606","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"doi:10.48550/arxiv.2605.20606","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2605.20606","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"Dataset":[0,82],"distillation":[1],"(DD)":[2],"compresses":[3],"a":[4,9,39,85,93,98,103,113,128],"large":[5],"training":[6],"set":[7,12],"into":[8],"small":[10],"synthetic":[11],"for":[13,80],"efficient":[14],"training,":[15],"but":[16],"most":[17,121],"DD":[18,30,165],"methods":[19,31],"optimize":[20],"only":[21],"clean":[22],"accuracy":[23],"and":[24,61,147],"leave":[25],"robustness":[26,95,131],"uncontrolled.":[27],"Recent":[28],"robust":[29,53,59,110,124,160,164],"improve":[32],"robustness,":[33],"yet":[34],"they":[35,44],"often":[36],"suffer":[37],"from":[38],"poor":[40],"accuracy-robustness":[41],"trade-off":[42],"because":[43],"(i)":[45],"treat":[46],"all":[47],"adversarially":[48],"perturbed":[49],"examples":[50],"uniformly,":[51],"despite":[52],"risk":[54],"being":[55],"dominated":[56],"by":[57,166],"near-zero":[58],"margins,":[60],"(ii)":[62],"do":[63],"not":[64],"explicitly":[65,137],"increase":[66],"inter-class":[67],"separation":[68,140],"in":[69],"the":[70,117,158],"decision":[71],"boundary":[72,139],"where":[73],"attacks":[74,153],"concentrate.":[75],"We":[76],"present":[77],"Contrastive":[78],"Curriculum":[79],"Robust":[81],"Distillation":[83],"(C$^2$R),":[84],"framework":[86],"that":[87,106,115,120,155],"couples":[88],"an":[89],"attack-aware":[90],"curriculum":[91,114],"with":[92],"contrastive":[94,130],"objective.":[96],"From":[97],"robust-margin":[99],"perspective,":[100],"we":[101],"derive":[102],"perturbation":[104],"score":[105],"approximates":[107],"each":[108],"sample's":[109],"hinge,":[111],"enabling":[112],"prioritizes":[116],"smallest-margin":[118],"adversaries":[119],"directly":[122],"drive":[123],"error.":[125],"In":[126],"parallel,":[127],"class-balanced":[129],"loss":[132],"enforces":[133],"adversarial":[134],"invariance":[135],"while":[136],"widening":[138],"across":[141],"classes.":[142],"Experiments":[143],"on":[144,168],"CIFAR-10/100,":[145],"Tiny-ImageNet,":[146],"multiple":[148],"ImageNet-1K":[149],"subsets":[150],"under":[151],"six":[152],"show":[154],"C$^2$R":[156],"achieves":[157],"best":[159],"accuracy,":[161],"outperforming":[162],"prior":[163],"$2.8$%":[167],"average.":[169]},"counts_by_year":[],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2026-05-22T00:00:00"}
