% \documentclass{uai2022} % for initial submission
\documentclass[accepted]{uai2022} 
%% In your camera-ready you should use the 'accepted' parameter. This shows the authors and how an accepted paper will look like. The footer is 'Acccepted for X'. In the final version, the proceedings chairs will add the page numbers for PMLR and the final footer will be 'Proceedings of X'.
%
%% There is a class option to choose the math font
% \documentclass[mathfont=ptmx]{uai2022} % ptmx math instead of Computer
                                         % Modern (has noticable issues)
% \documentclass[mathfont=newtx]{uai2022} % newtx fonts (improves upon
                                          % ptmx; less tested, no support)
% NOTE: Only keep *one* line above as appropriate, as it will be replaced
%       automatically for papers to be published. Do not make any other
%       change above this note for an accepted version.

%% Choose your variant of English; be consistent
\usepackage[american]{babel}
% \usepackage[british]{babel}

%% Some suggested packages, as needed:
\usepackage{natbib} % has a nice set of citation styles and commands
\bibliographystyle{plainnat}
\renewcommand{\bibsection}{\subsubsection*{References}}


\usepackage{mathtools} % amsmath with fixes and additions
% \usepackage{siunitx} % for proper typesetting of numbers and units
\usepackage{booktabs} % commands to create good-looking tables
\usepackage{tikz} % nice language for creating drawings and diagrams


\newcommand\mycommfont[1]{\footnotesize\ttfamily\textcolor{black}{#1}}
% \SetCommentSty{mycommfont}

\newtheorem{definition}{Definition}[section]
\newtheorem{remark}{Remark}
\newtheorem{proposition}{Proposition}

\usepackage{amssymb}
\usepackage{physics,amsmath}
\usepackage[algoruled, lined, ruled, resetcount,linesnumbered]{algorithm2e}
\usepackage{multicol}
\usepackage{etoolbox}
\usepackage{multicol}
\usepackage{multirow}
\usepackage{xspace}
\usepackage{placeins}

\usepackage{cleveref}


\newcommand{\corruptions}{corruptions\xspace}
\newcommand{\spna}{\texttt{SPN}$-$\texttt{a}\xspace}
\newcommand{\spnas}{\texttt{SPN}$-$\texttt{a}s\xspace}
\newcommand{\cna}{\texttt{CN}$-$\texttt{a}\xspace}
\newcommand{\cnas}{\texttt{CN}$-$\texttt{a}s\xspace}
\newcommand{\spnr}{\texttt{SPN}$-$\texttt{r}\xspace}
\newcommand{\spnrs}{\texttt{SPN}$-$\texttt{r}s\xspace}
\newcommand{\cnr}{\texttt{CN}$-$\texttt{r}\xspace}
\newcommand{\cnrs}{\texttt{CN}$-$\texttt{r}s\xspace}
\newcommand{\spn}{\texttt{SPN}\xspace}
\newcommand{\cn}{\texttt{CN}\xspace}
\newcommand{\spns}{\texttt{SPN}s\xspace}
\newcommand{\cns}{\texttt{CN}s\xspace}
\newcommand{\test}{$\mathcal{T}$\xspace}
\newcommand{\testa}{$\mathcal{T}_a$\xspace}
\newcommand{\testr}{$\mathcal{T}_r$\xspace}

\renewcommand{\cite}[1]{\citep{#1}}

\DeclareMathOperator*{\argmax}{arg\,max}
\DeclareMathOperator*{\argmin}{arg\,min}

\AtBeginEnvironment{tabular}{\smaller}

% Added for camera ready version
\usepackage{xcolor}
\newcommand*{\rohith}{\textcolor{red}}


%% Provided macros
% \smaller: Because the class footnote size is essentially LaTeX's \small,
%           redefining \footnotesize, we provide the original \footnotesize
%           using this macro.
%           (Use only sparingly, e.g., in drawings, as it is quite small.)

%% Self-defined macros
\newcommand{\swap}[3][-]{#3#1#2} % just an example

\title{Robust Learning of Tractable Probabilistic Models (Supplementary Material)}

% The standard author block has changed for UAI 2022 to provide
% more space for long author lists and allow for complex affiliations
%
% All author information is automatically removed by the class for the
% anonymous submission version of your paper, so you can already add your
% information below.
% 
% Important: in case of equal contributions, we strongly recommend to NOT show it in this part of the paper, but rather describe it in the appropriate section at the end of the paper "Author Contribution", where you have more space to describe how each author contributed.
%
% Add authors
% Remember to use the order convention "First/Given name" "Last/Family name", e.g. John Smith, Hanako Yamada, Marco Rossi, Wei Zhang

\author[1]{\href{mailto:<rohith.peddi@utdallas.edu>?Subject=Your UAI 2022 paper}{Rohith Peddi}{}}
\author[1]{Tahrima Rahman}
\author[1]{Vibhav Gogate}
% Add affiliations after the authors
\affil[1]{%
    The University of Texas at Dallas
}

\begin{document}

\maketitle

% \section{SUPPLEMENTARY Material}

\section{Experimental Results on Cutset Networks: TPMs without Latent Variables}

\subsection{Robust Generative Performance}
Tables \ref{tab:cn-ll-1} through \ref{tab:cn-ll-5} report the log-likelihood scores on the test sets \test, \testa, and \testr obtained by cutset networks learned by the algorithm LearnCNet and networks trained by our proposed robust estimation methods. Each of these models were evaluated on three different test sets generated by varying the degree of perturbations ($h=\{1,3,5\}$) using the standard model \cn. Details are described in section 4. 

\cnas and \cnrs have significantly higher log-likelihood scores compared to \cns in all three degrees of perturbations.  

% \input{supplementary/cn-ll-1}
\begin{table*}[]
\begin{center}
\caption{\label{tab:cn-ll-1}
Generative performance: Test set log-likelihood scores of  cutset networks or models without latent variables. $h=1$: hamming distance threshold. \cn : Cutset networks trained on original training data, \cna: CNs learned from adversarially generated training data by \cns, \cnr: trained via joint maximization of standard and robust likelihoods. \test: original test data, \testa: adversarially perturbed \test by \cn, \testr: randomly perturbed \test by \cn.}

\begin{tabular}{|l|ccc|ccc|ccc|l|}
\hline
\multicolumn{1}{|c|}{\multirow{2}{*}{dataset}} & \multicolumn{3}{c|}{\test}                                                                                     & \multicolumn{3}{c|}{\testa}                                                                                    & \multicolumn{3}{c|}{\testr}                                                                                    &  \\ \cline{2-11} 
\multicolumn{1}{|c|}{}                         & \multicolumn{1}{l|}{\cn} & \multicolumn{1}{l|}{\cna} & \multicolumn{1}{l|}{\cnr} & \multicolumn{1}{l|}{\cn} & \multicolumn{1}{l|}{\cna} & \multicolumn{1}{l|}{\cnr} & \multicolumn{1}{l|}{\cn} & \multicolumn{1}{l|}{\cna} & \multicolumn{1}{l|}{\cnr} &  \\ \hline
nltcs                                          & \multicolumn{1}{c|}{-6.05}              & \multicolumn{1}{c|}{-6.08}               & -6.06                                    & \multicolumn{1}{c|}{-12.31}             & \multicolumn{1}{c|}{-10.37}              & -10.66                                   & \multicolumn{1}{c|}{-10.18}             & \multicolumn{1}{c|}{-9.65}               & -9.77                                    &  \\ \hline
msnbc                                          & \multicolumn{1}{c|}{-6.16}              & \multicolumn{1}{c|}{-6.18}               & -6.17                                    & \multicolumn{1}{c|}{-12.40}             & \multicolumn{1}{c|}{-10.18}              & -10.43                                   & \multicolumn{1}{c|}{-10.06}             & \multicolumn{1}{c|}{-9.41}               & -9.51                                    &  \\ \hline
kdd                                            & \multicolumn{1}{c|}{-2.19}              & \multicolumn{1}{c|}{-2.43}               & -2.27                                    & \multicolumn{1}{c|}{-11.09}             & \multicolumn{1}{c|}{-6.48}               & -7.01                                    & \multicolumn{1}{c|}{-10.12}             & \multicolumn{1}{c|}{-6.59}               & -7.39                                    &  \\ \hline
plants                                         & \multicolumn{1}{c|}{-13.50}             & \multicolumn{1}{c|}{-13.61}              & -13.56                                   & \multicolumn{1}{c|}{-35.16}             & \multicolumn{1}{c|}{-29.94}              & -30.68                                   & \multicolumn{1}{c|}{-25.43}             & \multicolumn{1}{c|}{-23.43}              & -23.81                                   &  \\ \hline
baudio                                         & \multicolumn{1}{c|}{-41.98}             & \multicolumn{1}{c|}{-41.97}              & -41.97                                   & \multicolumn{1}{c|}{-51.34}             & \multicolumn{1}{c|}{-51.00}              & -51.14                                   & \multicolumn{1}{c|}{-47.17}             & \multicolumn{1}{c|}{-47.00}              & -47.07                                   &  \\ \hline
jester                                         & \multicolumn{1}{c|}{-55.31}             & \multicolumn{1}{c|}{-55.31}              & -55.31                                   & \multicolumn{1}{c|}{-64.29}             & \multicolumn{1}{c|}{-64.19}              & -64.24                                   & \multicolumn{1}{c|}{-59.82}             & \multicolumn{1}{c|}{-59.78}              & -59.80                                   &  \\ \hline
bnetflix                                       & \multicolumn{1}{c|}{-58.71}             & \multicolumn{1}{c|}{-58.71}              & -58.71                                   & \multicolumn{1}{c|}{-66.26}             & \multicolumn{1}{c|}{-66.19}              & -66.22                                   & \multicolumn{1}{c|}{-62.91}             & \multicolumn{1}{c|}{-62.88}              & -62.89                                   &  \\ \hline
accidents                                      & \multicolumn{1}{c|}{-30.43}             & \multicolumn{1}{c|}{-30.61}              & -30.54                                   & \multicolumn{1}{c|}{-62.54}             & \multicolumn{1}{c|}{-51.57}              & -53.14                                   & \multicolumn{1}{c|}{-45.73}             & \multicolumn{1}{c|}{-42.72}              & -43.32                                   &  \\ \hline
tretail                                        & \multicolumn{1}{c|}{-10.95}             & \multicolumn{1}{c|}{-11.48}              & -11.16                                   & \multicolumn{1}{c|}{-20.22}             & \multicolumn{1}{c|}{-13.88}              & -14.35                                   & \multicolumn{1}{c|}{-18.50}             & \multicolumn{1}{c|}{-15.18}              & -15.70                                   &  \\ \hline
pumsb\_star                                    & \multicolumn{1}{c|}{-24.24}             & \multicolumn{1}{c|}{-24.59}              & -24.42                                   & \multicolumn{1}{c|}{-122.89}            & \multicolumn{1}{c|}{-86.54}              & -91.52                                   & \multicolumn{1}{c|}{-64.63}             & \multicolumn{1}{c|}{-55.98}              & -57.63                                   &  \\ \hline
dna                                            & \multicolumn{1}{c|}{-87.60}             & \multicolumn{1}{c|}{-87.82}              & -87.70                                   & \multicolumn{1}{c|}{-95.74}             & \multicolumn{1}{c|}{-93.52}              & -93.88                                   & \multicolumn{1}{c|}{-94.37}             & \multicolumn{1}{c|}{-93.08}              & -93.36                                   &  \\ \hline
kosarek                                        & \multicolumn{1}{c|}{-11.01}             & \multicolumn{1}{c|}{-11.43}              & -11.16                                   & \multicolumn{1}{c|}{-25.62}             & \multicolumn{1}{c|}{-20.39}              & -21.31                                   & \multicolumn{1}{c|}{-21.32}             & \multicolumn{1}{c|}{-18.43}              & -19.00                                   &  \\ \hline
msweb                                          & \multicolumn{1}{c|}{-10.04}             & \multicolumn{1}{c|}{-10.33}              & -10.16                                   & \multicolumn{1}{c|}{-41.27}             & \multicolumn{1}{c|}{-35.00}              & -35.68                                   & \multicolumn{1}{c|}{-26.05}             & \multicolumn{1}{c|}{-25.00}              & -25.13                                   &  \\ \hline
book                                           & \multicolumn{1}{c|}{-37.35}             & \multicolumn{1}{c|}{-37.68}              & -37.44                                   & \multicolumn{1}{c|}{-58.74}             & \multicolumn{1}{c|}{-52.93}              & -54.89                                   & \multicolumn{1}{c|}{-49.36}             & \multicolumn{1}{c|}{-47.57}              & -48.24                                   &  \\ \hline
tmovie                                         & \multicolumn{1}{c|}{-58.20}             & \multicolumn{1}{c|}{-58.52}              & -58.21                                   & \multicolumn{1}{c|}{-124.66}            & \multicolumn{1}{c|}{-117.42}             & -119.15                                  & \multicolumn{1}{c|}{-86.10}             & \multicolumn{1}{c|}{-83.96}              & -84.53                                   &  \\ \hline
cwebkb                                         & \multicolumn{1}{c|}{-162.43}            & \multicolumn{1}{c|}{-163.04}             & -162.43                                  & \multicolumn{1}{c|}{-202.97}            & \multicolumn{1}{c|}{-193.70}             & -196.72                                  & \multicolumn{1}{c|}{-175.88}            & \multicolumn{1}{c|}{-173.92}             & -174.33                                  &  \\ \hline
cr52                                           & \multicolumn{1}{c|}{-88.63}             & \multicolumn{1}{c|}{-90.63}              & -89.71                                   & \multicolumn{1}{c|}{-173.80}            & \multicolumn{1}{c|}{-156.97}             & -159.88                                  & \multicolumn{1}{c|}{-118.61}            & \multicolumn{1}{c|}{-115.38}             & -115.89                                  &  \\ \hline
c20ng                                          & \multicolumn{1}{c|}{-163.07}            & \multicolumn{1}{c|}{-165.84}             & -164.60                                  & \multicolumn{1}{c|}{-204.58}            & \multicolumn{1}{c|}{-191.69}             & -192.78                                  & \multicolumn{1}{c|}{-178.52}            & \multicolumn{1}{c|}{-175.92}             & -175.84                                  &  \\ \hline
bbc                                            & \multicolumn{1}{c|}{-261.86}            & \multicolumn{1}{c|}{-261.97}             & -261.89                                  & \multicolumn{1}{c|}{-271.99}            & \multicolumn{1}{c|}{-269.79}             & -270.12                                  & \multicolumn{1}{c|}{-269.98}            & \multicolumn{1}{c|}{-268.97}             & -269.21                                  &  \\ \hline
ad                                             & \multicolumn{1}{c|}{-16.88}             & \multicolumn{1}{c|}{-18.32}              & -17.51                                   & \multicolumn{1}{c|}{-68.40}             & \multicolumn{1}{c|}{-55.79}              & -56.34                                   & \multicolumn{1}{c|}{-57.35}             & \multicolumn{1}{c|}{-53.14}              & -53.31                                   &  \\ \hline
avg.                                           & \multicolumn{1}{c|}{-57.33}             & \multicolumn{1}{c|}{-57.83}              & -57.55                                   & \multicolumn{1}{c|}{-86.31}             & \multicolumn{1}{c|}{-78.88}              & -80.01                                   & \multicolumn{1}{c|}{-71.60}             & \multicolumn{1}{c|}{-69.40}              & -69.79                                   &  \\ \hline
\end{tabular}
\end{center}
\end{table*}

% \input{supplementary/cn-ll-3}
\begin{table*}[]
\begin{center}
\caption{\label{tab:cn-ll-3}
Generative performance: Test set log-likelihood scores of  cutset networks or models without latent variables. $h=3$: hamming distance threshold. \cn : Cutset networks trained on original training data, \cna: CNs learned from adversarially generated training data by \cns, \cnr: trained via joint maximization of standard and robust likelihoods. \test: original test data, \testa: adversarially perturbed \test by \cn, \testr: randomly perturbed \test by \cn.}


\begin{tabular}{|c|ccc|ccc|ccc|l|}
\hline
\multirow{2}{*}{dataset} & \multicolumn{3}{c|}{\test}                                                                & \multicolumn{3}{c|}{\testa}                                                               & \multicolumn{3}{c|}{\testr}                                                               &  \\ \cline{2-11} 
                         & \multicolumn{1}{c|}{\cn} & \multicolumn{1}{c|}{\cna} & \cnr & \multicolumn{1}{c|}{\cn} & \multicolumn{1}{c|}{\cna} & \cnr & \multicolumn{1}{c|}{\cn} & \multicolumn{1}{c|}{\cna} & \cnr &  \\ \hline
nltcs                    & \multicolumn{1}{c|}{-6.05}              & \multicolumn{1}{c|}{-6.36}               & -6.17               & \multicolumn{1}{c|}{-20.18}             & \multicolumn{1}{c|}{-15.88}              & -16.49              & \multicolumn{1}{c|}{-14.82}             & \multicolumn{1}{c|}{-13.59}              & -13.74              &  \\ \hline
msnbc                    & \multicolumn{1}{c|}{-6.16}              & \multicolumn{1}{c|}{-6.20}               & -6.18               & \multicolumn{1}{c|}{-21.81}             & \multicolumn{1}{c|}{-16.80}              & -17.47              & \multicolumn{1}{c|}{-15.21}             & \multicolumn{1}{c|}{-13.99}              & -14.13              &  \\ \hline
kdd                      & \multicolumn{1}{c|}{-2.19}              & \multicolumn{1}{c|}{-2.88}               & -2.27               & \multicolumn{1}{c|}{-44.77}             & \multicolumn{1}{c|}{-36.04}              & -37.47              & \multicolumn{1}{c|}{-23.42}             & \multicolumn{1}{c|}{-19.11}              & -21.14              &  \\ \hline
plants                   & \multicolumn{1}{c|}{-13.50}             & \multicolumn{1}{c|}{-13.72}              & -13.62              & \multicolumn{1}{c|}{-58.00}             & \multicolumn{1}{c|}{-48.74}              & -49.66              & \multicolumn{1}{c|}{-38.97}             & \multicolumn{1}{c|}{-34.88}              & -35.27              &  \\ \hline
baudio                   & \multicolumn{1}{c|}{-41.98}             & \multicolumn{1}{c|}{-42.09}              & -41.97              & \multicolumn{1}{c|}{-63.18}             & \multicolumn{1}{c|}{-58.92}              & -62.86              & \multicolumn{1}{c|}{-53.18}             & \multicolumn{1}{c|}{-51.79}              & -53.10              &  \\ \hline
jester                   & \multicolumn{1}{c|}{-55.31}             & \multicolumn{1}{c|}{-55.34}              & -55.32              & \multicolumn{1}{c|}{-76.07}             & \multicolumn{1}{c|}{-74.46}              & -75.20              & \multicolumn{1}{c|}{-64.20}             & \multicolumn{1}{c|}{-63.80}              & -63.98              &  \\ \hline
bnetflix                 & \multicolumn{1}{c|}{-58.71}             & \multicolumn{1}{c|}{-58.70}              & -58.70              & \multicolumn{1}{c|}{-75.09}             & \multicolumn{1}{c|}{-73.07}              & -74.56              & \multicolumn{1}{c|}{-66.56}             & \multicolumn{1}{c|}{-65.95}              & -66.43              &  \\ \hline
accidents                & \multicolumn{1}{c|}{-30.43}             & \multicolumn{1}{c|}{-31.80}              & -31.18              & \multicolumn{1}{c|}{-88.60}             & \multicolumn{1}{c|}{-56.49}              & -60.28              & \multicolumn{1}{c|}{-61.59}             & \multicolumn{1}{c|}{-49.15}              & -50.98              &  \\ \hline
tretail                  & \multicolumn{1}{c|}{-10.95}             & \multicolumn{1}{c|}{-11.76}              & -11.40              & \multicolumn{1}{c|}{-35.23}             & \multicolumn{1}{c|}{-19.57}              & -21.61              & \multicolumn{1}{c|}{-29.42}             & \multicolumn{1}{c|}{-23.09}              & -23.62              &  \\ \hline
pumsb\_star              & \multicolumn{1}{c|}{-24.24}             & \multicolumn{1}{c|}{-29.46}              & -27.28              & \multicolumn{1}{c|}{-232.40}            & \multicolumn{1}{c|}{-102.17}             & -114.24             & \multicolumn{1}{c|}{-100.88}            & \multicolumn{1}{c|}{-76.55}              & -80.75              &  \\ \hline
dna                      & \multicolumn{1}{c|}{-87.60}             & \multicolumn{1}{c|}{-89.74}              & -88.62              & \multicolumn{1}{c|}{-109.12}            & \multicolumn{1}{c|}{-99.34}              & -101.06             & \multicolumn{1}{c|}{-103.41}            & \multicolumn{1}{c|}{-97.78}              & -98.45              &  \\ \hline
kosarek                  & \multicolumn{1}{c|}{-11.01}             & \multicolumn{1}{c|}{-11.01}              & -11.01              & \multicolumn{1}{c|}{-51.91}             & \multicolumn{1}{c|}{-50.78}              & -51.33              & \multicolumn{1}{c|}{-34.81}             & \multicolumn{1}{c|}{-34.41}              & -34.63              &  \\ \hline
msweb                    & \multicolumn{1}{c|}{-10.04}             & \multicolumn{1}{c|}{-20.06}              & -17.33              & \multicolumn{1}{c|}{-69.54}             & \multicolumn{1}{c|}{-47.35}              & -48.32              & \multicolumn{1}{c|}{-46.95}             & \multicolumn{1}{c|}{-48.98}              & -46.72              &  \\ \hline
book                     & \multicolumn{1}{c|}{-37.35}             & \multicolumn{1}{c|}{-37.34}              & -37.34              & \multicolumn{1}{c|}{-76.70}             & \multicolumn{1}{c|}{-75.02}              & -75.61              & \multicolumn{1}{c|}{-63.11}             & \multicolumn{1}{c|}{-62.65}              & -62.85              &  \\ \hline
tmovie                   & \multicolumn{1}{c|}{-58.20}             & \multicolumn{1}{c|}{-58.70}              & -58.37              & \multicolumn{1}{c|}{-184.36}            & \multicolumn{1}{c|}{-174.85}             & -176.03             & \multicolumn{1}{c|}{-112.96}            & \multicolumn{1}{c|}{-109.01}             & -109.62             &  \\ \hline
cwebkb                   & \multicolumn{1}{c|}{-162.43}            & \multicolumn{1}{c|}{-162.55}             & -162.48             & \multicolumn{1}{c|}{-326.57}            & \multicolumn{1}{c|}{-322.72}             & -323.85             & \multicolumn{1}{c|}{-193.89}            & \multicolumn{1}{c|}{-193.04}             & -193.32             &  \\ \hline
cr52                     & \multicolumn{1}{c|}{-88.63}             & \multicolumn{1}{c|}{-89.15}              & -88.94              & \multicolumn{1}{c|}{-268.42}            & \multicolumn{1}{c|}{-248.81}             & -252.28             & \multicolumn{1}{c|}{-151.68}            & \multicolumn{1}{c|}{-146.33}             & -147.38             &  \\ \hline
c20ng                    & \multicolumn{1}{c|}{-163.07}            & \multicolumn{1}{c|}{-165.79}             & -164.51             & \multicolumn{1}{c|}{-408.11}            & \multicolumn{1}{c|}{-382.89}             & -388.35             & \multicolumn{1}{c|}{-197.88}            & \multicolumn{1}{c|}{-190.47}             & -191.67             &  \\ \hline
bbc                      & \multicolumn{1}{c|}{-261.86}            & \multicolumn{1}{c|}{-262.61}             & -262.36             & \multicolumn{1}{c|}{-288.77}            & \multicolumn{1}{c|}{-278.96}             & -280.94             & \multicolumn{1}{c|}{-277.79}            & \multicolumn{1}{c|}{-275.59}             & -275.80             &  \\ \hline
ad                       & \multicolumn{1}{c|}{-16.88}             & \multicolumn{1}{c|}{-35.89}              & -26.01              & \multicolumn{1}{c|}{-152.95}            & \multicolumn{1}{c|}{-121.88}             & -116.87             & \multicolumn{1}{c|}{-84.72}             & \multicolumn{1}{c|}{-86.76}              & -79.27              &  \\ \hline
Avg.                     & \multicolumn{1}{c|}{\textbf{-57.33}}    & \multicolumn{1}{c|}{-59.56}              & -58.55              & \multicolumn{1}{c|}{\textbf{-132.59}}   & \multicolumn{1}{c|}{\textbf{-115.24}}    & \textbf{-117.22}    & \multicolumn{1}{c|}{-86.77}             & \multicolumn{1}{c|}{\textbf{-82.85}}     & \textbf{-83.14}     &  \\ \hline
\end{tabular}
\end{center}
\end{table*}

% \input{supplementary/cn-ll-5}
\begin{table*}[]
\begin{center}
\caption{\label{tab:cn-ll-5}
Generative performance: Test set log-likelihood scores of  cutset networks or models without latent variables. $h=5$: hamming distance threshold. \cn : Cutset networks trained on original training data, \cna: CNs learned from adversarially generated training data by \cns, \cnr: trained via joint maximization of standard and robust likelihoods. \test: original test data, \testa: adversarially perturbed \test by \cn, \testr: randomly perturbed \test by \cn.}


\begin{tabular}{|l|ccc|ccc|ccc|}
\hline
\multicolumn{1}{|c|}{\multirow{2}{*}{dataset}} & \multicolumn{3}{c|}{\test}                                                                & \multicolumn{3}{c|}{\testa}                                                               & \multicolumn{3}{c|}{\testr}                                                               \\ \cline{2-10} 
\multicolumn{1}{|c|}{}                         & \multicolumn{1}{c|}{\cn} & \multicolumn{1}{c|}{\cna} & \cnr & \multicolumn{1}{c|}{\cn} & \multicolumn{1}{c|}{\cna} & \cnr & \multicolumn{1}{c|}{\cn} & \multicolumn{1}{c|}{\cna} & \cnr \\ \hline
nltcs                                          & \multicolumn{1}{c|}{-6.05}              & \multicolumn{1}{c|}{-6.39}               & -6.16               & \multicolumn{1}{c|}{-25.38}             & \multicolumn{1}{c|}{-21.14}              & -21.81              & \multicolumn{1}{c|}{-17.54}             & \multicolumn{1}{c|}{-16.80}              & -16.89              \\ \hline
msnbc                                          & \multicolumn{1}{c|}{-6.16}              & \multicolumn{1}{c|}{-6.21}               & -6.19               & \multicolumn{1}{c|}{-28.68}             & \multicolumn{1}{c|}{-21.95}              & -22.47              & \multicolumn{1}{c|}{-18.92}             & \multicolumn{1}{c|}{-17.35}              & -17.34              \\ \hline
kdd                                            & \multicolumn{1}{c|}{-2.19}              & \multicolumn{1}{c|}{-2.35}               & -2.26               & \multicolumn{1}{c|}{-52.66}             & \multicolumn{1}{c|}{-43.99}              & -45.32              & \multicolumn{1}{c|}{-35.27}             & \multicolumn{1}{c|}{-31.34}              & -32.10              \\ \hline
plants                                         & \multicolumn{1}{c|}{-13.50}             & \multicolumn{1}{c|}{-13.82}              & -13.63              & \multicolumn{1}{c|}{-72.16}             & \multicolumn{1}{c|}{-58.08}              & -61.65              & \multicolumn{1}{c|}{-49.94}             & \multicolumn{1}{c|}{-42.80}              & -44.80              \\ \hline
baudio                                         & \multicolumn{1}{c|}{-41.98}             & \multicolumn{1}{c|}{-41.97}              & -41.97              & \multicolumn{1}{c|}{-71.35}             & \multicolumn{1}{c|}{-71.02}              & -70.94              & \multicolumn{1}{c|}{-57.79}             & \multicolumn{1}{c|}{-57.70}              & -57.68              \\ \hline
jester                                         & \multicolumn{1}{c|}{-55.31}             & \multicolumn{1}{c|}{-55.35}              & -55.34              & \multicolumn{1}{c|}{-84.09}             & \multicolumn{1}{c|}{-81.46}              & -81.71              & \multicolumn{1}{c|}{-67.17}             & \multicolumn{1}{c|}{-66.62}              & -66.67              \\ \hline
bnetflix                                       & \multicolumn{1}{c|}{-58.71}             & \multicolumn{1}{c|}{-58.72}              & -58.70              & \multicolumn{1}{c|}{-81.19}             & \multicolumn{1}{c|}{-77.69}              & -78.82              & \multicolumn{1}{c|}{-69.04}             & \multicolumn{1}{c|}{-68.08}              & -68.43              \\ \hline
accidents                                      & \multicolumn{1}{c|}{-30.43}             & \multicolumn{1}{c|}{-31.69}              & -31.23              & \multicolumn{1}{c|}{-106.02}            & \multicolumn{1}{c|}{-65.86}              & -69.45              & \multicolumn{1}{c|}{-72.83}             & \multicolumn{1}{c|}{-56.29}              & -58.12              \\ \hline
tretail                                        & \multicolumn{1}{c|}{-10.95}             & \multicolumn{1}{c|}{-11.00}              & -10.97              & \multicolumn{1}{c|}{-48.42}             & \multicolumn{1}{c|}{-36.65}              & -39.04              & \multicolumn{1}{c|}{-39.64}             & \multicolumn{1}{c|}{-35.34}              & -36.24              \\ \hline
pumsb\_star                                    & \multicolumn{1}{c|}{-24.24}             & \multicolumn{1}{c|}{-29.21}              & -27.28              & \multicolumn{1}{c|}{-271.29}            & \multicolumn{1}{c|}{-111.58}             & -126.03             & \multicolumn{1}{c|}{-122.10}            & \multicolumn{1}{c|}{-91.75}              & -95.80              \\ \hline
dna                                            & \multicolumn{1}{c|}{-87.60}             & \multicolumn{1}{c|}{-90.71}              & -89.19              & \multicolumn{1}{c|}{-121.95}            & \multicolumn{1}{c|}{-104.54}             & -107.37             & \multicolumn{1}{c|}{-110.50}            & \multicolumn{1}{c|}{-100.94}             & -101.89             \\ \hline
kosarek                                        & \multicolumn{1}{c|}{-11.01}             & \multicolumn{1}{c|}{-11.03}              & -11.02              & \multicolumn{1}{c|}{-69.92}             & \multicolumn{1}{c|}{-64.78}              & -66.00              & \multicolumn{1}{c|}{-48.06}             & \multicolumn{1}{c|}{-45.57}              & -46.38              \\ \hline
msweb                                          & \multicolumn{1}{c|}{-10.04}             & \multicolumn{1}{c|}{-10.14}              & -10.09              & \multicolumn{1}{c|}{-91.78}             & \multicolumn{1}{c|}{-72.80}              & -75.34              & \multicolumn{1}{c|}{-63.97}             & \multicolumn{1}{c|}{-61.30}              & -61.45              \\ \hline
book                                           & \multicolumn{1}{c|}{-37.35}             & \multicolumn{1}{c|}{-37.34}              & -37.34              & \multicolumn{1}{c|}{-92.93}             & \multicolumn{1}{c|}{-89.81}              & -90.91              & \multicolumn{1}{c|}{-73.64}             & \multicolumn{1}{c|}{-73.10}              & -73.33              \\ \hline
tmovie                                         & \multicolumn{1}{c|}{-58.20}             & \multicolumn{1}{c|}{-58.76}              & -58.77              & \multicolumn{1}{c|}{-233.61}            & \multicolumn{1}{c|}{-222.43}             & -214.66             & \multicolumn{1}{c|}{-131.36}            & \multicolumn{1}{c|}{-126.49}             & -125.46             \\ \hline
cwebkb                                         & \multicolumn{1}{c|}{-162.43}            & \multicolumn{1}{c|}{-163.04}             & -162.43             & \multicolumn{1}{c|}{-362.88}            & \multicolumn{1}{c|}{-354.36}             & -357.71             & \multicolumn{1}{c|}{-207.46}            & \multicolumn{1}{c|}{-200.72}             & -202.83             \\ \hline
cr52                                           & \multicolumn{1}{c|}{-88.63}             & \multicolumn{1}{c|}{-90.71}              & -89.75              & \multicolumn{1}{c|}{-293.80}            & \multicolumn{1}{c|}{-253.27}             & -260.47             & \multicolumn{1}{c|}{-175.38}            & \multicolumn{1}{c|}{-160.28}             & -163.15             \\ \hline
c20ng                                          & \multicolumn{1}{c|}{-163.07}            & \multicolumn{1}{c|}{-165.81}             & -164.52             & \multicolumn{1}{c|}{-556.33}            & \multicolumn{1}{c|}{-518.67}             & -528.86             & \multicolumn{1}{c|}{-211.09}            & \multicolumn{1}{c|}{-200.99}             & -202.75             \\ \hline
bbc                                            & \multicolumn{1}{c|}{-261.86}            & \multicolumn{1}{c|}{-264.97}             & -262.72             & \multicolumn{1}{c|}{-304.09}            & \multicolumn{1}{c|}{-285.92}             & -290.28             & \multicolumn{1}{c|}{-285.14}            & \multicolumn{1}{c|}{-282.64}             & -282.69             \\ \hline
ad                                             & \multicolumn{1}{c|}{-16.88}             & \multicolumn{1}{c|}{-42.73}              & -29.80              & \multicolumn{1}{c|}{-233.57}            & \multicolumn{1}{c|}{-164.26}             & -168.00             & \multicolumn{1}{c|}{-110.54}            & \multicolumn{1}{c|}{-111.97}             & -104.96             \\ \hline
Avg.                                           & \multicolumn{1}{c|}{\textbf{-57.33}}    & \multicolumn{1}{c|}{-59.60}              & -58.47              & \multicolumn{1}{c|}{-160.11}            & \multicolumn{1}{c|}{\textbf{-136.01}}    & \textbf{-138.84}    & \multicolumn{1}{c|}{-98.37}             & \multicolumn{1}{c|}{\textbf{-92.40}}     & \textbf{-92.95}     \\ \hline
\end{tabular}
\end{center}
\end{table*}

\subsection{Robust Predictive Performance}

We report the conditional log-likelihood scores obtained by cutset networks over varying sizes of query and evidence variable sets. We randomly chose \{20\%, 50\%, 80\%\} variables as query variables and set the remaining variables as evidence variables and computed the conditional probabilities of the query variables given evidence over 200 randomly sampled test points. The average CLL scores for each of the 20 datasets are reported in tables \ref{tab:cn-cll-20-1} through \ref{tab:cn-cll-80-5} for varying degrees of corruptions {$h$=\{1,3,5\}} to the test data by the standard model. We observe that the robust models consistently have better CLL scores on both adversarial and random perturbations compared to the standard model.   

% \input{supplementary/cn-cll-20-1}

\begin{table*}[]
\begin{center}
\caption{\label{tab:cn-cll-20-1}Predictive performance: Conditional log-likelihood scores given 80\% evidence for models having no latent variables (CNs). $h=1$: hamming distance threshold. \cn : Cutset networks trained on original training data, \cna: CNs learned from adversarially generated training data by \cns, \cnr: trained via joint maximization of standard and robust likelihoods. \test: original test data, \testa: adversarially perturbed \test by \cn, \testr: randomly perturbed \test by \cn.}

\begin{tabular}{|lccccccccc|}
\hline
\multicolumn{10}{|c|}{CLL Scores on 20\% query, 80\% evidence, h = 1}                                                                                                                                                                                                                                                                                                                                                     \\ \hline
\multicolumn{1}{|c|}{\multirow{2}{*}{dataset}} & \multicolumn{3}{c|}{\test}                                                                                     & \multicolumn{3}{c|}{\testa}                                                                                    & \multicolumn{3}{c|}{\testr}                                                               \\ \cline{2-10} 
\multicolumn{1}{|c|}{}                         & \multicolumn{1}{c|}{\cn} & \multicolumn{1}{c|}{\cna} & \multicolumn{1}{c|}{\cnr} & \multicolumn{1}{c|}{\cn} & \multicolumn{1}{c|}{\cna} & \multicolumn{1}{c|}{\cnr} & \multicolumn{1}{c|}{\cn} & \multicolumn{1}{c|}{\cna} & \cnr \\ \hline
\multicolumn{1}{|l|}{nltcs}                    & \multicolumn{1}{c|}{-1.74}              & \multicolumn{1}{c|}{-1.74}               & \multicolumn{1}{c|}{-1.74}               & \multicolumn{1}{c|}{-3.34}              & \multicolumn{1}{c|}{-2.80}               & \multicolumn{1}{c|}{-2.86}               & \multicolumn{1}{c|}{-3.43}              & \multicolumn{1}{c|}{-3.23}               & -3.29               \\ \hline
\multicolumn{1}{|l|}{msnbc}                    & \multicolumn{1}{c|}{-1.28}              & \multicolumn{1}{c|}{-1.28}               & \multicolumn{1}{c|}{-1.28}               & \multicolumn{1}{c|}{-5.82}              & \multicolumn{1}{c|}{-4.08}               & \multicolumn{1}{c|}{-4.27}               & \multicolumn{1}{c|}{-2.65}              & \multicolumn{1}{c|}{-2.33}               & -2.37               \\ \hline
\multicolumn{1}{|l|}{kdd}                      & \multicolumn{1}{c|}{-0.66}              & \multicolumn{1}{c|}{-0.72}               & \multicolumn{1}{c|}{-0.67}               & \multicolumn{1}{c|}{-9.19}              & \multicolumn{1}{c|}{-4.43}               & \multicolumn{1}{c|}{-5.05}               & \multicolumn{1}{c|}{-3.85}              & \multicolumn{1}{c|}{-2.17}               & -2.51               \\ \hline
\multicolumn{1}{|l|}{plants}                   & \multicolumn{1}{c|}{-4.31}              & \multicolumn{1}{c|}{-4.39}               & \multicolumn{1}{c|}{-4.37}               & \multicolumn{1}{c|}{-17.94}             & \multicolumn{1}{c|}{-13.60}              & \multicolumn{1}{c|}{-14.13}              & \multicolumn{1}{c|}{-11.15}             & \multicolumn{1}{c|}{-9.73}               & -9.96               \\ \hline
\multicolumn{1}{|l|}{baudio}                   & \multicolumn{1}{c|}{-16.61}             & \multicolumn{1}{c|}{-16.58}              & \multicolumn{1}{c|}{-16.59}              & \multicolumn{1}{c|}{-21.58}             & \multicolumn{1}{c|}{-21.29}              & \multicolumn{1}{c|}{-21.40}              & \multicolumn{1}{c|}{-19.69}             & \multicolumn{1}{c|}{-19.56}              & -19.61              \\ \hline
\multicolumn{1}{|l|}{jester}                   & \multicolumn{1}{c|}{-21.20}             & \multicolumn{1}{c|}{-21.18}              & \multicolumn{1}{c|}{-21.19}              & \multicolumn{1}{c|}{-28.71}             & \multicolumn{1}{c|}{-28.61}              & \multicolumn{1}{c|}{-28.66}              & \multicolumn{1}{c|}{-24.17}             & \multicolumn{1}{c|}{-24.15}              & -24.16              \\ \hline
\multicolumn{1}{|l|}{bnetflix}                 & \multicolumn{1}{c|}{-23.55}             & \multicolumn{1}{c|}{-24.14}              & \multicolumn{1}{c|}{-23.64}              & \multicolumn{1}{c|}{-29.33}             & \multicolumn{1}{c|}{-26.66}              & \multicolumn{1}{c|}{-27.46}              & \multicolumn{1}{c|}{-26.68}             & \multicolumn{1}{c|}{-25.67}              & -25.88              \\ \hline
\multicolumn{1}{|l|}{accidents}                & \multicolumn{1}{c|}{-12.59}             & \multicolumn{1}{c|}{-12.67}              & \multicolumn{1}{c|}{-12.64}              & \multicolumn{1}{c|}{-25.95}             & \multicolumn{1}{c|}{-21.51}              & \multicolumn{1}{c|}{-22.14}              & \multicolumn{1}{c|}{-18.98}             & \multicolumn{1}{c|}{-17.73}              & -18.01              \\ \hline
\multicolumn{1}{|l|}{tretail}                  & \multicolumn{1}{c|}{-3.22}              & \multicolumn{1}{c|}{-3.55}               & \multicolumn{1}{c|}{-3.36}               & \multicolumn{1}{c|}{-9.15}              & \multicolumn{1}{c|}{-5.21}               & \multicolumn{1}{c|}{-5.49}               & \multicolumn{1}{c|}{-7.32}              & \multicolumn{1}{c|}{-5.29}               & -5.44               \\ \hline
\multicolumn{1}{|l|}{pumsb\_star}              & \multicolumn{1}{c|}{-8.98}              & \multicolumn{1}{c|}{-9.04}               & \multicolumn{1}{c|}{-9.00}               & \multicolumn{1}{c|}{-35.93}             & \multicolumn{1}{c|}{-25.84}              & \multicolumn{1}{c|}{-27.25}              & \multicolumn{1}{c|}{-19.71}             & \multicolumn{1}{c|}{-17.43}              & -17.83              \\ \hline
\multicolumn{1}{|l|}{dna}                      & \multicolumn{1}{c|}{-32.29}             & \multicolumn{1}{c|}{-32.69}              & \multicolumn{1}{c|}{-32.44}              & \multicolumn{1}{c|}{-36.62}             & \multicolumn{1}{c|}{-34.00}              & \multicolumn{1}{c|}{-34.43}              & \multicolumn{1}{c|}{-35.05}             & \multicolumn{1}{c|}{-34.27}              & -34.36              \\ \hline
\multicolumn{1}{|l|}{kosarek}                  & \multicolumn{1}{c|}{-4.00}              & \multicolumn{1}{c|}{-4.09}               & \multicolumn{1}{c|}{-4.01}               & \multicolumn{1}{c|}{-13.28}             & \multicolumn{1}{c|}{-9.16}               & \multicolumn{1}{c|}{-10.03}              & \multicolumn{1}{c|}{-7.38}              & \multicolumn{1}{c|}{-6.09}               & -6.39               \\ \hline
\multicolumn{1}{|l|}{msweb}                    & \multicolumn{1}{c|}{-1.53}              & \multicolumn{1}{c|}{-1.80}               & \multicolumn{1}{c|}{-1.64}               & \multicolumn{1}{c|}{-9.71}              & \multicolumn{1}{c|}{-5.88}               & \multicolumn{1}{c|}{-6.19}               & \multicolumn{1}{c|}{-6.17}              & \multicolumn{1}{c|}{-5.61}               & -5.58               \\ \hline
\multicolumn{1}{|l|}{book}                     & \multicolumn{1}{c|}{-15.33}             & \multicolumn{1}{c|}{-15.28}              & \multicolumn{1}{c|}{-15.28}              & \multicolumn{1}{c|}{-21.59}             & \multicolumn{1}{c|}{-19.63}              & \multicolumn{1}{c|}{-20.35}              & \multicolumn{1}{c|}{-19.55}             & \multicolumn{1}{c|}{-18.65}              & -19.05              \\ \hline
\multicolumn{1}{|l|}{tmovie}                   & \multicolumn{1}{c|}{-22.32}             & \multicolumn{1}{c|}{-22.13}              & \multicolumn{1}{c|}{-22.16}              & \multicolumn{1}{c|}{-75.88}             & \multicolumn{1}{c|}{-68.80}              & \multicolumn{1}{c|}{-70.53}              & \multicolumn{1}{c|}{-44.57}             & \multicolumn{1}{c|}{-42.17}              & -42.86              \\ \hline
\multicolumn{1}{|l|}{cwebkb}                   & \multicolumn{1}{c|}{-56.93}             & \multicolumn{1}{c|}{-57.16}              & \multicolumn{1}{c|}{-56.93}              & \multicolumn{1}{c|}{-78.76}             & \multicolumn{1}{c|}{-75.06}              & \multicolumn{1}{c|}{-76.34}              & \multicolumn{1}{c|}{-60.25}             & \multicolumn{1}{c|}{-59.78}              & -59.82              \\ \hline
\multicolumn{1}{|l|}{cr52}                     & \multicolumn{1}{c|}{-28.92}             & \multicolumn{1}{c|}{-29.35}              & \multicolumn{1}{c|}{-29.13}              & \multicolumn{1}{c|}{-48.76}             & \multicolumn{1}{c|}{-44.04}              & \multicolumn{1}{c|}{-44.83}              & \multicolumn{1}{c|}{-35.03}             & \multicolumn{1}{c|}{-34.57}              & -34.67              \\ \hline
\multicolumn{1}{|l|}{c20ng}                    & \multicolumn{1}{c|}{-60.61}             & \multicolumn{1}{c|}{-60.73}              & \multicolumn{1}{c|}{-60.64}              & \multicolumn{1}{c|}{-77.92}             & \multicolumn{1}{c|}{-76.10}              & \multicolumn{1}{c|}{-76.67}              & \multicolumn{1}{c|}{-67.38}             & \multicolumn{1}{c|}{-67.01}              & -67.10              \\ \hline
\multicolumn{1}{|l|}{bbc}                      & \multicolumn{1}{c|}{-94.47}             & \multicolumn{1}{c|}{-94.51}              & \multicolumn{1}{c|}{-94.48}              & \multicolumn{1}{c|}{-96.90}             & \multicolumn{1}{c|}{-96.82}              & \multicolumn{1}{c|}{-96.84}              & \multicolumn{1}{c|}{-97.53}             & \multicolumn{1}{c|}{-97.43}              & -97.47              \\ \hline
\multicolumn{1}{|l|}{ad}                       & \multicolumn{1}{c|}{-6.30}              & \multicolumn{1}{c|}{-7.01}               & \multicolumn{1}{c|}{-6.56}               & \multicolumn{1}{c|}{-17.98}             & \multicolumn{1}{c|}{-16.02}              & \multicolumn{1}{c|}{-15.79}              & \multicolumn{1}{c|}{-20.07}             & \multicolumn{1}{c|}{-18.03}              & -18.18              \\ \hline
\multicolumn{1}{|l|}{Avg.}                     & \multicolumn{1}{c|}{-20.84}             & \multicolumn{1}{c|}{-21.00}              & \multicolumn{1}{c|}{-20.89}              & \multicolumn{1}{c|}{-33.22}             & \multicolumn{1}{c|}{-29.98}              & \multicolumn{1}{c|}{-30.54}              & \multicolumn{1}{c|}{-26.53}             & \multicolumn{1}{c|}{-25.55}              & -25.73              \\ \hline
\end{tabular}
\end{center}
\end{table*}


% \input{supplementary/cn-cll-20-3}
\begin{table*}[]
\begin{center}
\caption{\label{tab:cn-cll-20-3}Predictive performance: Conditional log-likelihood scores given 80\% evidence for models having no latent variables (CNs). $h=3$: hamming distance threshold. \cn : Cutset networks trained on original training data, \cna: CNs learned from adversarially generated training data by \cns, \cnr: trained via joint maximization of standard and robust likelihoods. \test: original test data, \testa: adversarially perturbed \test by \cn, \testr: randomly perturbed \test by \cn.}

\begin{tabular}{|lccccccccc|}
\hline
\multicolumn{10}{|c|}{CLL Scores on 20\% query, 80\% evidence, h = 3}                                                                                                                                                                                                                                                                                                                                                     \\ \hline
\multicolumn{1}{|c|}{\multirow{2}{*}{dataset}} & \multicolumn{3}{c|}{\test}                                                                                     & \multicolumn{3}{c|}{\testa}                                                                                    & \multicolumn{3}{c|}{\testr}                                                               \\ \cline{2-10} 
\multicolumn{1}{|c|}{}                         & \multicolumn{1}{c|}{\cn} & \multicolumn{1}{c|}{\cna} & \multicolumn{1}{c|}{\cnr} & \multicolumn{1}{c|}{\cn} & \multicolumn{1}{c|}{\cna} & \multicolumn{1}{c|}{\cnr} & \multicolumn{1}{c|}{\cn} & \multicolumn{1}{c|}{\cna} & \cnr \\ \hline
\multicolumn{1}{|l|}{nltcs}                    & \multicolumn{1}{c|}{-1.74}              & \multicolumn{1}{c|}{-1.75}               & \multicolumn{1}{c|}{-1.73}               & \multicolumn{1}{c|}{-7.46}              & \multicolumn{1}{c|}{-5.53}               & \multicolumn{1}{c|}{-5.79}               & \multicolumn{1}{c|}{-4.95}              & \multicolumn{1}{c|}{-4.38}               & -4.45               \\ \hline
\multicolumn{1}{|l|}{msnbc}                    & \multicolumn{1}{c|}{-1.28}              & \multicolumn{1}{c|}{-1.29}               & \multicolumn{1}{c|}{-1.28}               & \multicolumn{1}{c|}{-9.42}              & \multicolumn{1}{c|}{-5.86}               & \multicolumn{1}{c|}{-6.25}               & \multicolumn{1}{c|}{-4.63}              & \multicolumn{1}{c|}{-3.88}               & -3.96               \\ \hline
\multicolumn{1}{|l|}{kdd}                      & \multicolumn{1}{c|}{-0.66}              & \multicolumn{1}{c|}{-0.66}               & \multicolumn{1}{c|}{-0.66}               & \multicolumn{1}{c|}{-36.02}             & \multicolumn{1}{c|}{-34.33}              & \multicolumn{1}{c|}{-34.71}              & \multicolumn{1}{c|}{-10.75}             & \multicolumn{1}{c|}{-9.72}               & -10.71              \\ \hline
\multicolumn{1}{|l|}{plants}                   & \multicolumn{1}{c|}{-4.31}              & \multicolumn{1}{c|}{-4.38}               & \multicolumn{1}{c|}{-4.37}               & \multicolumn{1}{c|}{-31.90}             & \multicolumn{1}{c|}{-23.35}              & \multicolumn{1}{c|}{-24.16}              & \multicolumn{1}{c|}{-18.87}             & \multicolumn{1}{c|}{-15.23}              & -15.52              \\ \hline
\multicolumn{1}{|l|}{baudio}                   & \multicolumn{1}{c|}{-16.61}             & \multicolumn{1}{c|}{-16.56}              & \multicolumn{1}{c|}{-16.60}              & \multicolumn{1}{c|}{-28.59}             & \multicolumn{1}{c|}{-25.51}              & \multicolumn{1}{c|}{-28.30}              & \multicolumn{1}{c|}{-22.22}             & \multicolumn{1}{c|}{-21.36}              & -22.18              \\ \hline
\multicolumn{1}{|l|}{jester}                   & \multicolumn{1}{c|}{-21.20}             & \multicolumn{1}{c|}{-21.07}              & \multicolumn{1}{c|}{-21.12}              & \multicolumn{1}{c|}{-37.81}             & \multicolumn{1}{c|}{-36.25}              & \multicolumn{1}{c|}{-36.98}              & \multicolumn{1}{c|}{-26.71}             & \multicolumn{1}{c|}{-26.39}              & -26.54              \\ \hline
\multicolumn{1}{|l|}{bnetflix}                 & \multicolumn{1}{c|}{-23.55}             & \multicolumn{1}{c|}{-24.56}              & \multicolumn{1}{c|}{-23.90}              & \multicolumn{1}{c|}{-34.99}             & \multicolumn{1}{c|}{-27.88}              & \multicolumn{1}{c|}{-29.03}              & \multicolumn{1}{c|}{-28.56}             & \multicolumn{1}{c|}{-26.44}              & -26.68              \\ \hline
\multicolumn{1}{|l|}{accidents}                & \multicolumn{1}{c|}{-12.59}             & \multicolumn{1}{c|}{-13.06}              & \multicolumn{1}{c|}{-12.86}              & \multicolumn{1}{c|}{-31.77}             & \multicolumn{1}{c|}{-22.15}              & \multicolumn{1}{c|}{-23.28}              & \multicolumn{1}{c|}{-25.26}             & \multicolumn{1}{c|}{-20.17}              & -20.86              \\ \hline
\multicolumn{1}{|l|}{tretail}                  & \multicolumn{1}{c|}{-3.22}              & \multicolumn{1}{c|}{-3.66}               & \multicolumn{1}{c|}{-3.47}               & \multicolumn{1}{c|}{-12.93}             & \multicolumn{1}{c|}{-6.27}               & \multicolumn{1}{c|}{-6.95}               & \multicolumn{1}{c|}{-13.09}             & \multicolumn{1}{c|}{-9.03}               & -9.34               \\ \hline
\multicolumn{1}{|l|}{pumsb\_star}              & \multicolumn{1}{c|}{-8.98}              & \multicolumn{1}{c|}{-10.50}              & \multicolumn{1}{c|}{-9.87}               & \multicolumn{1}{c|}{-73.33}             & \multicolumn{1}{c|}{-32.69}              & \multicolumn{1}{c|}{-36.35}              & \multicolumn{1}{c|}{-30.30}             & \multicolumn{1}{c|}{-23.57}              & -24.79              \\ \hline
\multicolumn{1}{|l|}{dna}                      & \multicolumn{1}{c|}{-32.29}             & \multicolumn{1}{c|}{-33.20}              & \multicolumn{1}{c|}{-32.72}              & \multicolumn{1}{c|}{-41.16}             & \multicolumn{1}{c|}{-36.56}              & \multicolumn{1}{c|}{-37.36}              & \multicolumn{1}{c|}{-38.19}             & \multicolumn{1}{c|}{-36.18}              & -36.36              \\ \hline
\multicolumn{1}{|l|}{kosarek}                  & \multicolumn{1}{c|}{-4.00}              & \multicolumn{1}{c|}{-4.00}               & \multicolumn{1}{c|}{-4.00}               & \multicolumn{1}{c|}{-31.12}             & \multicolumn{1}{c|}{-30.89}              & \multicolumn{1}{c|}{-31.07}              & \multicolumn{1}{c|}{-13.64}             & \multicolumn{1}{c|}{-13.57}              & -13.63              \\ \hline
\multicolumn{1}{|l|}{msweb}                    & \multicolumn{1}{c|}{-1.53}              & \multicolumn{1}{c|}{-1.55}               & \multicolumn{1}{c|}{-1.54}               & \multicolumn{1}{c|}{-20.70}             & \multicolumn{1}{c|}{-15.68}              & \multicolumn{1}{c|}{-16.37}              & \multicolumn{1}{c|}{-14.54}             & \multicolumn{1}{c|}{-13.23}              & -13.41              \\ \hline
\multicolumn{1}{|l|}{book}                     & \multicolumn{1}{c|}{-15.33}             & \multicolumn{1}{c|}{-15.27}              & \multicolumn{1}{c|}{-15.29}              & \multicolumn{1}{c|}{-26.76}             & \multicolumn{1}{c|}{-24.76}              & \multicolumn{1}{c|}{-25.58}              & \multicolumn{1}{c|}{-25.07}             & \multicolumn{1}{c|}{-24.07}              & -24.51              \\ \hline
\multicolumn{1}{|l|}{tmovie}                   & \multicolumn{1}{c|}{-22.32}             & \multicolumn{1}{c|}{-22.21}              & \multicolumn{1}{c|}{-22.14}              & \multicolumn{1}{c|}{-119.33}            & \multicolumn{1}{c|}{-109.02}             & \multicolumn{1}{c|}{-110.43}             & \multicolumn{1}{c|}{-61.20}             & \multicolumn{1}{c|}{-58.05}              & -58.57              \\ \hline
\multicolumn{1}{|l|}{cwebkb}                   & \multicolumn{1}{c|}{-56.93}             & \multicolumn{1}{c|}{-56.92}              & \multicolumn{1}{c|}{-56.93}              & \multicolumn{1}{c|}{-191.32}            & \multicolumn{1}{c|}{-190.35}             & \multicolumn{1}{c|}{-190.82}             & \multicolumn{1}{c|}{-67.77}             & \multicolumn{1}{c|}{-67.63}              & -67.70              \\ \hline
\multicolumn{1}{|l|}{cr52}                     & \multicolumn{1}{c|}{-28.92}             & \multicolumn{1}{c|}{-29.35}              & \multicolumn{1}{c|}{-29.13}              & \multicolumn{1}{c|}{-65.57}             & \multicolumn{1}{c|}{-57.35}              & \multicolumn{1}{c|}{-58.69}              & \multicolumn{1}{c|}{-41.54}             & \multicolumn{1}{c|}{-39.24}              & -39.70              \\ \hline
\multicolumn{1}{|l|}{c20ng}                    & \multicolumn{1}{c|}{-60.61}             & \multicolumn{1}{c|}{-60.73}              & \multicolumn{1}{c|}{-60.64}              & \multicolumn{1}{c|}{-187.22}            & \multicolumn{1}{c|}{-184.41}             & \multicolumn{1}{c|}{-185.31}             & \multicolumn{1}{c|}{-71.40}             & \multicolumn{1}{c|}{-70.17}              & -70.53              \\ \hline
\multicolumn{1}{|l|}{bbc}                      & \multicolumn{1}{c|}{-94.47}             & \multicolumn{1}{c|}{-94.63}              & \multicolumn{1}{c|}{-94.66}              & \multicolumn{1}{c|}{-101.02}            & \multicolumn{1}{c|}{-100.19}             & \multicolumn{1}{c|}{-100.07}             & \multicolumn{1}{c|}{-100.54}            & \multicolumn{1}{c|}{-100.28}             & -100.25             \\ \hline
\multicolumn{1}{|l|}{ad}                       & \multicolumn{1}{c|}{-6.30}              & \multicolumn{1}{c|}{-17.45}              & \multicolumn{1}{c|}{-11.48}              & \multicolumn{1}{c|}{-42.80}             & \multicolumn{1}{c|}{-31.24}              & \multicolumn{1}{c|}{-26.38}              & \multicolumn{1}{c|}{-31.37}             & \multicolumn{1}{c|}{-35.21}              & -30.05              \\ \hline
\multicolumn{1}{|l|}{Avg.}                     & \multicolumn{1}{c|}{-20.84}             & \multicolumn{1}{c|}{-21.64}              & \multicolumn{1}{c|}{-21.22}              & \multicolumn{1}{c|}{-56.56}             & \multicolumn{1}{c|}{-50.01}              & \multicolumn{1}{c|}{-50.69}              & \multicolumn{1}{c|}{-32.53}             & \multicolumn{1}{c|}{-30.89}              & -30.99              \\ \hline
\end{tabular}
\end{center}
\end{table*}

% \input{supplementary/cn-cll-20-5}
\begin{table*}[]
\begin{center}
\caption{\label{tab:cn-cll-20-5}Predictive performance: Conditional log-likelihood scores given 80\% evidence for models having no latent variables (CNs). $h=5$: hamming distance threshold. \cn : Cutset networks trained on original training data, \cna: CNs learned from adversarially generated training data by \cns, \cnr: trained via joint maximization of standard and robust likelihoods. \test: original test data, \testa: adversarially perturbed \test by \cn, \testr: randomly perturbed \test by \cn.}

\begin{tabular}{|cccccccccc|}
\hline
\multicolumn{10}{|c|}{CLL Scores on 20\% query, 80\% evidence, h = 5}                                                                                                                                                                                                                                                                                                                                                     \\ \hline
\multicolumn{1}{|c|}{\multirow{2}{*}{dataset}} & \multicolumn{3}{c|}{\test}                                                                                     & \multicolumn{3}{c|}{\testa}                                                                                    & \multicolumn{3}{c|}{\testr}                                                               \\ \cline{2-10} 
\multicolumn{1}{|c|}{}                         & \multicolumn{1}{c|}{\cn} & \multicolumn{1}{c|}{\cna} & \multicolumn{1}{c|}{\cnr} & \multicolumn{1}{c|}{\cn} & \multicolumn{1}{c|}{\cna} & \multicolumn{1}{c|}{\cnr} & \multicolumn{1}{c|}{\cn} & \multicolumn{1}{c|}{\cna} & \cnr \\ \hline
\multicolumn{1}{|c|}{nltcs}                    & \multicolumn{1}{c|}{-1.74}              & \multicolumn{1}{c|}{-1.76}               & \multicolumn{1}{c|}{-1.74}               & \multicolumn{1}{c|}{-11.56}             & \multicolumn{1}{c|}{-9.50}               & \multicolumn{1}{c|}{-9.86}               & \multicolumn{1}{c|}{-6.23}              & \multicolumn{1}{c|}{-5.91}               & -5.95               \\ \hline
\multicolumn{1}{|c|}{msnbc}                    & \multicolumn{1}{c|}{-1.28}              & \multicolumn{1}{c|}{-1.29}               & \multicolumn{1}{c|}{-1.28}               & \multicolumn{1}{c|}{-12.61}             & \multicolumn{1}{c|}{-7.18}               & \multicolumn{1}{c|}{-7.62}               & \multicolumn{1}{c|}{-5.76}              & \multicolumn{1}{c|}{-4.97}               & -4.97               \\ \hline
\multicolumn{1}{|c|}{kdd}                      & \multicolumn{1}{c|}{-0.66}              & \multicolumn{1}{c|}{-0.66}               & \multicolumn{1}{c|}{-0.66}               & \multicolumn{1}{c|}{-40.49}             & \multicolumn{1}{c|}{-39.76}              & \multicolumn{1}{c|}{-39.86}              & \multicolumn{1}{c|}{-18.86}             & \multicolumn{1}{c|}{-18.91}              & -18.95              \\ \hline
\multicolumn{1}{|c|}{plants}                   & \multicolumn{1}{c|}{-4.31}              & \multicolumn{1}{c|}{-4.43}               & \multicolumn{1}{c|}{-4.37}               & \multicolumn{1}{c|}{-41.78}             & \multicolumn{1}{c|}{-28.56}              & \multicolumn{1}{c|}{-31.39}              & \multicolumn{1}{c|}{-24.33}             & \multicolumn{1}{c|}{-18.71}              & -19.96              \\ \hline
\multicolumn{1}{|c|}{baudio}                   & \multicolumn{1}{c|}{-16.61}             & \multicolumn{1}{c|}{-16.60}              & \multicolumn{1}{c|}{-16.60}              & \multicolumn{1}{c|}{-33.37}             & \multicolumn{1}{c|}{-33.03}              & \multicolumn{1}{c|}{-32.97}              & \multicolumn{1}{c|}{-24.53}             & \multicolumn{1}{c|}{-24.47}              & -24.46              \\ \hline
\multicolumn{1}{|c|}{jester}                   & \multicolumn{1}{c|}{-21.20}             & \multicolumn{1}{c|}{-21.06}              & \multicolumn{1}{c|}{-21.07}              & \multicolumn{1}{c|}{-43.10}             & \multicolumn{1}{c|}{-40.70}              & \multicolumn{1}{c|}{-40.93}              & \multicolumn{1}{c|}{-28.13}             & \multicolumn{1}{c|}{-27.72}              & -27.77              \\ \hline
\multicolumn{1}{|c|}{bnetflix}                 & \multicolumn{1}{c|}{-23.55}             & \multicolumn{1}{c|}{-25.08}              & \multicolumn{1}{c|}{-23.98}              & \multicolumn{1}{c|}{-38.38}             & \multicolumn{1}{c|}{-28.29}              & \multicolumn{1}{c|}{-30.15}              & \multicolumn{1}{c|}{-29.37}             & \multicolumn{1}{c|}{-26.87}              & -27.16              \\ \hline
\multicolumn{1}{|c|}{accidents}                & \multicolumn{1}{c|}{-12.59}             & \multicolumn{1}{c|}{-13.03}              & \multicolumn{1}{c|}{-12.88}              & \multicolumn{1}{c|}{-36.27}             & \multicolumn{1}{c|}{-24.79}              & \multicolumn{1}{c|}{-25.81}              & \multicolumn{1}{c|}{-29.86}             & \multicolumn{1}{c|}{-23.28}              & -23.99              \\ \hline
\multicolumn{1}{|c|}{tretail}                  & \multicolumn{1}{c|}{-3.22}              & \multicolumn{1}{c|}{-3.26}               & \multicolumn{1}{c|}{-3.24}               & \multicolumn{1}{c|}{-16.99}             & \multicolumn{1}{c|}{-12.05}              & \multicolumn{1}{c|}{-12.92}              & \multicolumn{1}{c|}{-15.67}             & \multicolumn{1}{c|}{-12.91}              & -13.38              \\ \hline
\multicolumn{1}{|c|}{pumsb\_star}              & \multicolumn{1}{c|}{-8.98}              & \multicolumn{1}{c|}{-10.60}              & \multicolumn{1}{c|}{-9.95}               & \multicolumn{1}{c|}{-96.95}             & \multicolumn{1}{c|}{-38.27}              & \multicolumn{1}{c|}{-43.56}              & \multicolumn{1}{c|}{-36.85}             & \multicolumn{1}{c|}{-28.19}              & -29.24              \\ \hline
\multicolumn{1}{|c|}{dna}                      & \multicolumn{1}{c|}{-32.29}             & \multicolumn{1}{c|}{-33.58}              & \multicolumn{1}{c|}{-32.94}              & \multicolumn{1}{c|}{-46.68}             & \multicolumn{1}{c|}{-38.87}              & \multicolumn{1}{c|}{-40.14}              & \multicolumn{1}{c|}{-42.16}             & \multicolumn{1}{c|}{-37.82}              & -38.28              \\ \hline
\multicolumn{1}{|c|}{kosarek}                  & \multicolumn{1}{c|}{-4.00}              & \multicolumn{1}{c|}{-4.00}               & \multicolumn{1}{c|}{-4.00}               & \multicolumn{1}{c|}{-42.81}             & \multicolumn{1}{c|}{-39.42}              & \multicolumn{1}{c|}{-40.14}              & \multicolumn{1}{c|}{-19.57}             & \multicolumn{1}{c|}{-18.56}              & -18.95              \\ \hline
\multicolumn{1}{|c|}{msweb}                    & \multicolumn{1}{c|}{-1.53}              & \multicolumn{1}{c|}{-1.55}               & \multicolumn{1}{c|}{-1.54}               & \multicolumn{1}{c|}{-26.04}             & \multicolumn{1}{c|}{-20.42}              & \multicolumn{1}{c|}{-21.17}              & \multicolumn{1}{c|}{-18.88}             & \multicolumn{1}{c|}{-17.46}              & -17.56              \\ \hline
\multicolumn{1}{|c|}{book}                     & \multicolumn{1}{c|}{-15.33}             & \multicolumn{1}{c|}{-15.28}              & \multicolumn{1}{c|}{-15.28}              & \multicolumn{1}{c|}{-29.89}             & \multicolumn{1}{c|}{-27.72}              & \multicolumn{1}{c|}{-28.56}              & \multicolumn{1}{c|}{-25.80}             & \multicolumn{1}{c|}{-24.47}              & -25.00              \\ \hline
\multicolumn{1}{|c|}{tmovie}                   & \multicolumn{1}{c|}{-22.32}             & \multicolumn{1}{c|}{-22.29}              & \multicolumn{1}{c|}{-22.12}              & \multicolumn{1}{c|}{-172.82}            & \multicolumn{1}{c|}{-160.81}             & \multicolumn{1}{c|}{-154.84}             & \multicolumn{1}{c|}{-73.03}             & \multicolumn{1}{c|}{-69.51}              & -68.04              \\ \hline
\multicolumn{1}{|c|}{cwebkb}                   & \multicolumn{1}{c|}{-56.93}             & \multicolumn{1}{c|}{-57.16}              & \multicolumn{1}{c|}{-56.93}              & \multicolumn{1}{c|}{-220.17}            & \multicolumn{1}{c|}{-219.79}             & \multicolumn{1}{c|}{-220.52}             & \multicolumn{1}{c|}{-76.95}             & \multicolumn{1}{c|}{-74.56}              & -75.33              \\ \hline
\multicolumn{1}{|c|}{cr52}                     & \multicolumn{1}{c|}{-28.92}             & \multicolumn{1}{c|}{-29.35}              & \multicolumn{1}{c|}{-29.13}              & \multicolumn{1}{c|}{-67.34}             & \multicolumn{1}{c|}{-59.06}              & \multicolumn{1}{c|}{-60.43}              & \multicolumn{1}{c|}{-49.98}             & \multicolumn{1}{c|}{-45.59}              & -46.45              \\ \hline
\multicolumn{1}{|c|}{c20ng}                    & \multicolumn{1}{c|}{-60.61}             & \multicolumn{1}{c|}{-60.73}              & \multicolumn{1}{c|}{-60.97}              & \multicolumn{1}{c|}{-257.85}            & \multicolumn{1}{c|}{-254.45}             & \multicolumn{1}{c|}{-252.20}             & \multicolumn{1}{c|}{-77.36}             & \multicolumn{1}{c|}{-75.88}              & -75.47              \\ \hline
\multicolumn{1}{|c|}{bbc}                      & \multicolumn{1}{c|}{-94.47}             & \multicolumn{1}{c|}{-95.48}              & \multicolumn{1}{c|}{-94.75}              & \multicolumn{1}{c|}{-107.79}            & \multicolumn{1}{c|}{-103.51}             & \multicolumn{1}{c|}{-104.88}             & \multicolumn{1}{c|}{-102.92}            & \multicolumn{1}{c|}{-102.64}             & -102.56             \\ \hline
\multicolumn{1}{|c|}{ad}                       & \multicolumn{1}{c|}{-6.30}              & \multicolumn{1}{c|}{-21.56}              & \multicolumn{1}{c|}{-13.28}              & \multicolumn{1}{c|}{-88.68}             & \multicolumn{1}{c|}{-57.23}              & \multicolumn{1}{c|}{-55.18}              & \multicolumn{1}{c|}{-39.49}             & \multicolumn{1}{c|}{-44.37}              & -38.73              \\ \hline
\multicolumn{1}{|c|}{Avg.}                     & \multicolumn{1}{c|}{-20.84}             & \multicolumn{1}{c|}{-21.94}              & \multicolumn{1}{c|}{-21.34}              & \multicolumn{1}{c|}{-71.58}             & \multicolumn{1}{c|}{-62.17}              & \multicolumn{1}{c|}{-62.66}              & \multicolumn{1}{c|}{-37.29}             & \multicolumn{1}{c|}{-35.14}              & -35.11              \\ \hline
\end{tabular}
\end{center}
\end{table*}


% \input{supplementary/cn-cll-50-1}
\begin{table*}[]
\begin{center}
\caption{\label{tab:cn-cll-50-1}Conditional log-likelihood scores  of cutset networks with 50\% of the variables set to evidences and corruption size $h=1$. \cn : CN learnt from original training data, \cna: CN learnt from adversarially generated training data by 
\cn, \cnr: CN learnt from data randomly corrupted by \cn. \test: original test data, \testa: adversarially perturbed \test by \cn, \testr: randomly perturbed \test by \cn.}

\begin{tabular}{|l|ccc|ccc|ccc|}
\hline
\multicolumn{1}{|c|}{\multirow{2}{*}{dataset}} & \multicolumn{3}{c|}{\test}                                                                & \multicolumn{3}{c|}{\testa}                                                               & \multicolumn{3}{c|}{\testr}                                                               \\ \cline{2-10} 
\multicolumn{1}{|c|}{}                         & \multicolumn{1}{c|}{\cn} & \multicolumn{1}{c|}{\cna} & \cnr & \multicolumn{1}{c|}{\cn} & \multicolumn{1}{c|}{\cna} & \cnr & \multicolumn{1}{c|}{\cn} & \multicolumn{1}{c|}{\cna} & \cnr \\ \hline
nltcs                                          & \multicolumn{1}{c|}{-3.82}              & \multicolumn{1}{c|}{-3.83}               & -3.82               & \multicolumn{1}{c|}{-9.65}              & \multicolumn{1}{c|}{-7.61}               & -7.92               & \multicolumn{1}{c|}{-7.49}              & \multicolumn{1}{c|}{-7.00}               & -7.12               \\ \hline
msnbc                                          & \multicolumn{1}{c|}{-4.33}              & \multicolumn{1}{c|}{-4.33}               & -4.33               & \multicolumn{1}{c|}{-9.81}              & \multicolumn{1}{c|}{-7.67}               & -7.92               & \multicolumn{1}{c|}{-7.20}              & \multicolumn{1}{c|}{-6.72}               & -6.80               \\ \hline
kdd                                            & \multicolumn{1}{c|}{-1.76}              & \multicolumn{1}{c|}{-1.87}               & -1.78               & \multicolumn{1}{c|}{-10.21}             & \multicolumn{1}{c|}{-5.51}               & -6.11               & \multicolumn{1}{c|}{-8.66}              & \multicolumn{1}{c|}{-5.16}               & -5.83               \\ \hline
plants                                         & \multicolumn{1}{c|}{-9.61}              & \multicolumn{1}{c|}{-9.68}               & -9.64               & \multicolumn{1}{c|}{-31.26}             & \multicolumn{1}{c|}{-25.90}              & -26.65              & \multicolumn{1}{c|}{-20.83}             & \multicolumn{1}{c|}{-18.87}              & -19.23              \\ \hline
baudio                                         & \multicolumn{1}{c|}{-34.29}             & \multicolumn{1}{c|}{-34.26}              & -34.27              & \multicolumn{1}{c|}{-42.97}             & \multicolumn{1}{c|}{-42.59}              & -42.74              & \multicolumn{1}{c|}{-39.42}             & \multicolumn{1}{c|}{-39.25}              & -39.32              \\ \hline
jester                                         & \multicolumn{1}{c|}{-42.83}             & \multicolumn{1}{c|}{-42.81}              & -42.82              & \multicolumn{1}{c|}{-50.94}             & \multicolumn{1}{c|}{-50.84}              & -50.89              & \multicolumn{1}{c|}{-46.11}             & \multicolumn{1}{c|}{-46.08}              & -46.10              \\ \hline
bnetflix                                       & \multicolumn{1}{c|}{-45.29}             & \multicolumn{1}{c|}{-46.12}              & -45.39              & \multicolumn{1}{c|}{-52.51}             & \multicolumn{1}{c|}{-48.87}              & -49.88              & \multicolumn{1}{c|}{-49.28}             & \multicolumn{1}{c|}{-47.95}              & -48.15              \\ \hline
accidents                                      & \multicolumn{1}{c|}{-21.93}             & \multicolumn{1}{c|}{-22.12}              & -22.04              & \multicolumn{1}{c|}{-52.86}             & \multicolumn{1}{c|}{-42.56}              & -43.96              & \multicolumn{1}{c|}{-36.38}             & \multicolumn{1}{c|}{-33.73}              & -34.28              \\ \hline
tretail                                        & \multicolumn{1}{c|}{-7.77}              & \multicolumn{1}{c|}{-8.15}               & -7.94               & \multicolumn{1}{c|}{-17.17}             & \multicolumn{1}{c|}{-10.72}              & -11.28              & \multicolumn{1}{c|}{-14.95}             & \multicolumn{1}{c|}{-11.56}              & -12.10              \\ \hline
pumsb\_star                                    & \multicolumn{1}{c|}{-16.14}             & \multicolumn{1}{c|}{-16.37}              & -16.26              & \multicolumn{1}{c|}{-96.26}             & \multicolumn{1}{c|}{-65.64}              & -69.59              & \multicolumn{1}{c|}{-54.23}             & \multicolumn{1}{c|}{-45.69}              & -47.26              \\ \hline
dna                                            & \multicolumn{1}{c|}{-67.88}             & \multicolumn{1}{c|}{-68.71}              & -68.20              & \multicolumn{1}{c|}{-75.64}             & \multicolumn{1}{c|}{-72.17}              & -72.86              & \multicolumn{1}{c|}{-73.68}             & \multicolumn{1}{c|}{-72.17}              & -72.42              \\ \hline
kosarek                                        & \multicolumn{1}{c|}{-8.41}              & \multicolumn{1}{c|}{-8.68}               & -8.49               & \multicolumn{1}{c|}{-21.35}             & \multicolumn{1}{c|}{-16.05}              & -17.03              & \multicolumn{1}{c|}{-15.29}             & \multicolumn{1}{c|}{-13.18}              & -13.63              \\ \hline
msweb                                          & \multicolumn{1}{c|}{-7.14}              & \multicolumn{1}{c|}{-7.45}               & -7.27               & \multicolumn{1}{c|}{-33.43}             & \multicolumn{1}{c|}{-27.26}              & -27.88              & \multicolumn{1}{c|}{-20.80}             & \multicolumn{1}{c|}{-19.93}              & -20.03              \\ \hline
book                                           & \multicolumn{1}{c|}{-29.82}             & \multicolumn{1}{c|}{-30.02}              & -29.91              & \multicolumn{1}{c|}{-45.68}             & \multicolumn{1}{c|}{-39.73}              & -41.76              & \multicolumn{1}{c|}{-35.88}             & \multicolumn{1}{c|}{-34.18}              & -34.84              \\ \hline
tmovie                                         & \multicolumn{1}{c|}{-41.36}             & \multicolumn{1}{c|}{-41.50}              & -41.35              & \multicolumn{1}{c|}{-107.57}            & \multicolumn{1}{c|}{-100.30}             & -102.19             & \multicolumn{1}{c|}{-74.19}             & \multicolumn{1}{c|}{-71.71}              & -72.49              \\ \hline
cwebkb                                         & \multicolumn{1}{c|}{-125.88}            & \multicolumn{1}{c|}{-126.40}             & -125.91             & \multicolumn{1}{c|}{-155.45}            & \multicolumn{1}{c|}{-148.69}             & -150.97             & \multicolumn{1}{c|}{-133.45}            & \multicolumn{1}{c|}{-131.98}             & -132.32             \\ \hline
cr52                                           & \multicolumn{1}{c|}{-68.01}             & \multicolumn{1}{c|}{-69.35}              & -68.70              & \multicolumn{1}{c|}{-88.07}             & \multicolumn{1}{c|}{-87.55}              & -87.57              & \multicolumn{1}{c|}{-78.14}             & \multicolumn{1}{c|}{-78.24}              & -78.04              \\ \hline
c20ng                                          & \multicolumn{1}{c|}{-128.40}            & \multicolumn{1}{c|}{-128.58}             & -128.43             & \multicolumn{1}{c|}{-151.40}            & \multicolumn{1}{c|}{-147.09}             & -148.44             & \multicolumn{1}{c|}{-139.25}            & \multicolumn{1}{c|}{-137.99}             & -138.29             \\ \hline
bbc                                            & \multicolumn{1}{c|}{-186.91}            & \multicolumn{1}{c|}{-187.00}             & -186.95             & \multicolumn{1}{c|}{-193.91}            & \multicolumn{1}{c|}{-193.24}             & -193.32             & \multicolumn{1}{c|}{-193.95}            & \multicolumn{1}{c|}{-193.50}             & -193.61             \\ \hline
ad                                             & \multicolumn{1}{c|}{-13.63}             & \multicolumn{1}{c|}{-14.84}              & -14.13              & \multicolumn{1}{c|}{-43.34}             & \multicolumn{1}{c|}{-34.37}              & -34.73              & \multicolumn{1}{c|}{-44.67}             & \multicolumn{1}{c|}{-40.96}              & -41.16              \\ \hline
Avg.                                           & \multicolumn{1}{c|}{\textbf{-43.26}}    & \multicolumn{1}{c|}{-43.60}              & -43.38              & \multicolumn{1}{c|}{-64.47}             & \multicolumn{1}{c|}{\textbf{-58.72}}     & \textbf{-59.68}     & \multicolumn{1}{c|}{-54.69}             & \multicolumn{1}{c|}{\textbf{-52.79}}     & \textbf{-53.15}     \\ \hline
\end{tabular}
\end{center}
\end{table*}


% \input{supplementary/cn-cll-50-3}
\begin{table*}[]
\begin{center}
\caption{\label{tab:cn-cll-50-3}Conditional log-likelihood scores  of cutset networks with 50\% of the variables set to evidences and corruption size $h=3$. \cn : CN learnt from original training data, \cna: CN learnt from adversarially generated training data by 
\cn, \cnr: CN learnt from data randomly corrupted by \cn. \test: original test data, \testa: adversarially perturbed \test by \cn, \testr: randomly perturbed \test by \cn.}

\begin{tabular}{|c|ccc|ccc|ccc|}
\hline
\multirow{2}{*}{dataset} & \multicolumn{3}{c|}{\test}                                                                & \multicolumn{3}{c|}{\testa}                                                               & \multicolumn{3}{c|}{\testr}                                                               \\ \cline{2-10} 
                         & \multicolumn{1}{c|}{\cn} & \multicolumn{1}{c|}{\cna} & \cnr & \multicolumn{1}{c|}{\cn} & \multicolumn{1}{c|}{\cna} & \cnr & \multicolumn{1}{c|}{\cn} & \multicolumn{1}{c|}{\cna} & \cnr \\ \hline
nltcs                    & \multicolumn{1}{c|}{-3.82}              & \multicolumn{1}{c|}{-4.05}               & -3.90               & \multicolumn{1}{c|}{-16.17}             & \multicolumn{1}{c|}{-12.03}              & -12.63              & \multicolumn{1}{c|}{-11.37}             & \multicolumn{1}{c|}{-10.11}              & -10.26              \\ \hline
msnbc                    & \multicolumn{1}{c|}{-4.33}              & \multicolumn{1}{c|}{-4.34}               & -4.33               & \multicolumn{1}{c|}{-17.09}             & \multicolumn{1}{c|}{-12.61}              & -13.16              & \multicolumn{1}{c|}{-11.50}             & \multicolumn{1}{c|}{-10.46}              & -10.58              \\ \hline
kdd                      & \multicolumn{1}{c|}{-1.76}              & \multicolumn{1}{c|}{-1.76}               & -1.76               & \multicolumn{1}{c|}{-43.86}             & \multicolumn{1}{c|}{-41.47}              & -42.12              & \multicolumn{1}{c|}{-18.85}             & \multicolumn{1}{c|}{-17.03}              & -18.61              \\ \hline
plants                   & \multicolumn{1}{c|}{-9.61}              & \multicolumn{1}{c|}{-9.80}               & -9.70               & \multicolumn{1}{c|}{-50.67}             & \multicolumn{1}{c|}{-41.50}              & -42.37              & \multicolumn{1}{c|}{-34.00}             & \multicolumn{1}{c|}{-29.51}              & -29.91              \\ \hline
baudio                   & \multicolumn{1}{c|}{-34.29}             & \multicolumn{1}{c|}{-34.24}              & -34.29              & \multicolumn{1}{c|}{-54.37}             & \multicolumn{1}{c|}{-50.00}              & -54.01              & \multicolumn{1}{c|}{-44.22}             & \multicolumn{1}{c|}{-42.90}              & -44.16              \\ \hline
jester                   & \multicolumn{1}{c|}{-42.83}             & \multicolumn{1}{c|}{-42.69}              & -42.74              & \multicolumn{1}{c|}{-61.63}             & \multicolumn{1}{c|}{-59.96}              & -60.72              & \multicolumn{1}{c|}{-49.75}             & \multicolumn{1}{c|}{-49.36}              & -49.54              \\ \hline
bnetflix                 & \multicolumn{1}{c|}{-45.29}             & \multicolumn{1}{c|}{-47.03}              & -45.96              & \multicolumn{1}{c|}{-60.77}             & \multicolumn{1}{c|}{-51.35}              & -52.93              & \multicolumn{1}{c|}{-52.16}             & \multicolumn{1}{c|}{-49.46}              & -49.71              \\ \hline
accidents                & \multicolumn{1}{c|}{-21.93}             & \multicolumn{1}{c|}{-23.20}              & -22.65              & \multicolumn{1}{c|}{-77.83}             & \multicolumn{1}{c|}{-48.06}              & -51.40              & \multicolumn{1}{c|}{-50.90}             & \multicolumn{1}{c|}{-39.30}              & -40.92              \\ \hline
tretail                  & \multicolumn{1}{c|}{-7.77}              & \multicolumn{1}{c|}{-8.31}               & -8.06               & \multicolumn{1}{c|}{-28.45}             & \multicolumn{1}{c|}{-14.38}              & -16.23              & \multicolumn{1}{c|}{-24.05}             & \multicolumn{1}{c|}{-17.87}              & -18.43              \\ \hline
pumsb\_star              & \multicolumn{1}{c|}{-16.14}             & \multicolumn{1}{c|}{-20.18}              & -18.54              & \multicolumn{1}{c|}{-195.94}            & \multicolumn{1}{c|}{-79.00}              & -89.34              & \multicolumn{1}{c|}{-82.66}             & \multicolumn{1}{c|}{-60.14}              & -64.05              \\ \hline
dna                      & \multicolumn{1}{c|}{-67.88}             & \multicolumn{1}{c|}{-69.79}              & -68.80              & \multicolumn{1}{c|}{-86.64}             & \multicolumn{1}{c|}{-77.70}              & -79.34              & \multicolumn{1}{c|}{-80.89}             & \multicolumn{1}{c|}{-76.29}              & -76.81              \\ \hline
kosarek                  & \multicolumn{1}{c|}{-8.41}              & \multicolumn{1}{c|}{-8.41}               & -8.41               & \multicolumn{1}{c|}{-45.39}             & \multicolumn{1}{c|}{-44.91}              & -45.24              & \multicolumn{1}{c|}{-27.27}             & \multicolumn{1}{c|}{-27.13}              & -27.23              \\ \hline
msweb                    & \multicolumn{1}{c|}{-7.14}              & \multicolumn{1}{c|}{-7.20}               & -7.17               & \multicolumn{1}{c|}{-60.28}             & \multicolumn{1}{c|}{-47.87}              & -49.58              & \multicolumn{1}{c|}{-39.12}             & \multicolumn{1}{c|}{-36.84}              & -37.19              \\ \hline
book                     & \multicolumn{1}{c|}{-29.82}             & \multicolumn{1}{c|}{-29.92}              & -29.87              & \multicolumn{1}{c|}{-62.15}             & \multicolumn{1}{c|}{-55.17}              & -57.43              & \multicolumn{1}{c|}{-47.42}             & \multicolumn{1}{c|}{-45.19}              & -46.09              \\ \hline
tmovie                   & \multicolumn{1}{c|}{-41.36}             & \multicolumn{1}{c|}{-41.55}              & -41.38              & \multicolumn{1}{c|}{-159.81}            & \multicolumn{1}{c|}{-147.69}             & -149.37             & \multicolumn{1}{c|}{-96.51}             & \multicolumn{1}{c|}{-92.43}              & -93.12              \\ \hline
cwebkb                   & \multicolumn{1}{c|}{-125.88}            & \multicolumn{1}{c|}{-126.04}             & -125.95             & \multicolumn{1}{c|}{-274.90}            & \multicolumn{1}{c|}{-271.48}             & -272.44             & \multicolumn{1}{c|}{-146.05}            & \multicolumn{1}{c|}{-145.38}             & -145.57             \\ \hline
cr52                     & \multicolumn{1}{c|}{-68.01}             & \multicolumn{1}{c|}{-69.37}              & -68.71              & \multicolumn{1}{c|}{-107.96}            & \multicolumn{1}{c|}{-104.02}             & -105.08             & \multicolumn{1}{c|}{-88.66}             & \multicolumn{1}{c|}{-87.10}              & -87.29              \\ \hline
c20ng                    & \multicolumn{1}{c|}{-128.40}            & \multicolumn{1}{c|}{-128.59}             & -128.43             & \multicolumn{1}{c|}{-213.50}            & \multicolumn{1}{c|}{-206.47}             & -208.43             & \multicolumn{1}{c|}{-147.78}            & \multicolumn{1}{c|}{-145.41}             & -146.03             \\ \hline
bbc                      & \multicolumn{1}{c|}{-186.91}            & \multicolumn{1}{c|}{-187.38}             & -187.23             & \multicolumn{1}{c|}{-204.63}            & \multicolumn{1}{c|}{-199.52}             & -200.42             & \multicolumn{1}{c|}{-200.05}            & \multicolumn{1}{c|}{-199.00}             & -198.99             \\ \hline
ad                       & \multicolumn{1}{c|}{-13.63}             & \multicolumn{1}{c|}{-30.97}              & -21.05              & \multicolumn{1}{c|}{-108.50}            & \multicolumn{1}{c|}{-85.30}              & -78.38              & \multicolumn{1}{c|}{-63.34}             & \multicolumn{1}{c|}{-66.95}              & -58.69              \\ \hline
Avg.                     & \multicolumn{1}{c|}{\textbf{-43.26}}    & \multicolumn{1}{c|}{-44.74}              & -43.95              & \multicolumn{1}{c|}{-96.53}             & \multicolumn{1}{c|}{\textbf{-82.52}}     & \textbf{-84.03}     & \multicolumn{1}{c|}{-65.83}             & \multicolumn{1}{c|}{\textbf{-62.39}}     & \textbf{-62.66}     \\ \hline
\end{tabular}
\end{center}
\end{table*}

% \input{supplementary/cn-cll-50-5}
\begin{table*}[]
\begin{center}
\caption{\label{tab:cn-cll-50-5}Conditional log-likelihood scores  of cutset networks with 50\% of the variables set to evidences and corruption size $h=5$. \cn : CN learnt from original training data, \cna: CN learnt from adversarially generated training data by 
\cn, \cnr: CN learnt from data randomly corrupted by \cn. \test: original test data, \testa: adversarially perturbed \test by \cn, \testr: randomly perturbed \test by \cn.}

\begin{tabular}{|c|ccc|ccc|ccc|}
\hline
\multirow{2}{*}{dataset} & \multicolumn{3}{c|}{\test}                                                                & \multicolumn{3}{c|}{\testa}                                                               & \multicolumn{3}{c|}{\testr}                                                               \\ \cline{2-10} 
                         & \multicolumn{1}{c|}{\cn} & \multicolumn{1}{c|}{\cna} & \cnr & \multicolumn{1}{c|}{\cn} & \multicolumn{1}{c|}{\cna} & \cnr & \multicolumn{1}{c|}{\cn} & \multicolumn{1}{c|}{\cna} & \cnr \\ \hline
nltcs                    & \multicolumn{1}{c|}{-3.82}              & \multicolumn{1}{c|}{-4.09}               & -3.91               & \multicolumn{1}{c|}{-21.04}             & \multicolumn{1}{c|}{-16.83}              & -17.50              & \multicolumn{1}{c|}{-13.60}             & \multicolumn{1}{c|}{-13.00}              & -13.05              \\ \hline
msnbc                    & \multicolumn{1}{c|}{-4.33}              & \multicolumn{1}{c|}{-4.34}               & -4.33               & \multicolumn{1}{c|}{-23.05}             & \multicolumn{1}{c|}{-16.67}              & -17.14              & \multicolumn{1}{c|}{-14.05}             & \multicolumn{1}{c|}{-12.85}              & -12.81              \\ \hline
kdd                      & \multicolumn{1}{c|}{-1.76}              & \multicolumn{1}{c|}{-1.76}               & -1.76               & \multicolumn{1}{c|}{-48.72}             & \multicolumn{1}{c|}{-46.43}              & -47.02              & \multicolumn{1}{c|}{-29.87}             & \multicolumn{1}{c|}{-29.58}              & -29.69              \\ \hline
plants                   & \multicolumn{1}{c|}{-9.61}              & \multicolumn{1}{c|}{-9.89}               & -9.72               & \multicolumn{1}{c|}{-61.56}             & \multicolumn{1}{c|}{-47.99}              & -51.22              & \multicolumn{1}{c|}{-42.68}             & \multicolumn{1}{c|}{-35.87}              & -37.68              \\ \hline
baudio                   & \multicolumn{1}{c|}{-34.29}             & \multicolumn{1}{c|}{-34.29}              & -34.29              & \multicolumn{1}{c|}{-62.18}             & \multicolumn{1}{c|}{-61.80}              & -61.72              & \multicolumn{1}{c|}{-48.57}             & \multicolumn{1}{c|}{-48.49}              & -48.47              \\ \hline
jester                   & \multicolumn{1}{c|}{-42.83}             & \multicolumn{1}{c|}{-42.69}              & -42.70              & \multicolumn{1}{c|}{-68.38}             & \multicolumn{1}{c|}{-65.77}              & -66.02              & \multicolumn{1}{c|}{-52.34}             & \multicolumn{1}{c|}{-51.82}              & -51.87              \\ \hline
bnetflix                 & \multicolumn{1}{c|}{-45.29}             & \multicolumn{1}{c|}{-48.01}              & -46.13              & \multicolumn{1}{c|}{-65.87}             & \multicolumn{1}{c|}{-52.34}              & -55.00              & \multicolumn{1}{c|}{-54.12}             & \multicolumn{1}{c|}{-50.58}              & -50.97              \\ \hline
accidents                & \multicolumn{1}{c|}{-21.93}             & \multicolumn{1}{c|}{-23.10}              & -22.70              & \multicolumn{1}{c|}{-94.10}             & \multicolumn{1}{c|}{-56.40}              & -59.60              & \multicolumn{1}{c|}{-60.96}             & \multicolumn{1}{c|}{-45.67}              & -47.30              \\ \hline
tretail                  & \multicolumn{1}{c|}{-7.77}              & \multicolumn{1}{c|}{-7.82}               & -7.79               & \multicolumn{1}{c|}{-40.71}             & \multicolumn{1}{c|}{-30.12}              & -32.32              & \multicolumn{1}{c|}{-31.53}             & \multicolumn{1}{c|}{-27.24}              & -28.11              \\ \hline
pumsb\_star              & \multicolumn{1}{c|}{-16.14}             & \multicolumn{1}{c|}{-20.07}              & -18.56              & \multicolumn{1}{c|}{-230.84}            & \multicolumn{1}{c|}{-88.93}              & -100.93             & \multicolumn{1}{c|}{-96.36}             & \multicolumn{1}{c|}{-70.60}              & -73.96              \\ \hline
dna                      & \multicolumn{1}{c|}{-67.88}             & \multicolumn{1}{c|}{-70.55}              & -69.24              & \multicolumn{1}{c|}{-97.68}             & \multicolumn{1}{c|}{-82.01}              & -84.64              & \multicolumn{1}{c|}{-87.61}             & \multicolumn{1}{c|}{-79.06}              & -79.96              \\ \hline
kosarek                  & \multicolumn{1}{c|}{-8.41}              & \multicolumn{1}{c|}{-8.44}               & -8.43               & \multicolumn{1}{c|}{-62.99}             & \multicolumn{1}{c|}{-57.95}              & -59.13              & \multicolumn{1}{c|}{-38.12}             & \multicolumn{1}{c|}{-35.96}              & -36.67              \\ \hline
msweb                    & \multicolumn{1}{c|}{-7.14}              & \multicolumn{1}{c|}{-7.23}               & -7.19               & \multicolumn{1}{c|}{-81.78}             & \multicolumn{1}{c|}{-61.83}              & -64.44              & \multicolumn{1}{c|}{-53.11}             & \multicolumn{1}{c|}{-50.23}              & -50.41              \\ \hline
book                     & \multicolumn{1}{c|}{-29.82}             & \multicolumn{1}{c|}{-30.02}              & -29.91              & \multicolumn{1}{c|}{-58.41}             & \multicolumn{1}{c|}{-55.28}              & -57.13              & \multicolumn{1}{c|}{-46.80}             & \multicolumn{1}{c|}{-45.95}              & -46.75              \\ \hline
tmovie                   & \multicolumn{1}{c|}{-41.36}             & \multicolumn{1}{c|}{-41.65}              & -41.62              & \multicolumn{1}{c|}{-217.39}            & \multicolumn{1}{c|}{-203.58}             & -197.10             & \multicolumn{1}{c|}{-112.39}            & \multicolumn{1}{c|}{-107.70}             & -105.93             \\ \hline
cwebkb                   & \multicolumn{1}{c|}{-125.88}            & \multicolumn{1}{c|}{-126.40}             & -125.91             & \multicolumn{1}{c|}{-309.95}            & \multicolumn{1}{c|}{-304.74}             & -307.12             & \multicolumn{1}{c|}{-158.53}            & \multicolumn{1}{c|}{-153.76}             & -155.27             \\ \hline
cr52                     & \multicolumn{1}{c|}{-68.01}             & \multicolumn{1}{c|}{-69.38}              & -68.71              & \multicolumn{1}{c|}{-125.26}            & \multicolumn{1}{c|}{-117.23}             & -119.33             & \multicolumn{1}{c|}{-99.35}             & \multicolumn{1}{c|}{-95.95}              & -96.66              \\ \hline
c20ng                    & \multicolumn{1}{c|}{-128.40}            & \multicolumn{1}{c|}{-128.59}             & -129.19             & \multicolumn{1}{c|}{-244.74}            & \multicolumn{1}{c|}{-236.29}             & -233.75             & \multicolumn{1}{c|}{-156.50}            & \multicolumn{1}{c|}{-152.78}             & -152.04             \\ \hline
bbc                      & \multicolumn{1}{c|}{-186.91}            & \multicolumn{1}{c|}{-188.82}             & -187.43             & \multicolumn{1}{c|}{-214.46}            & \multicolumn{1}{c|}{-204.51}             & -206.93             & \multicolumn{1}{c|}{-205.69}            & \multicolumn{1}{c|}{-204.12}             & -204.31             \\ \hline
ad                       & \multicolumn{1}{c|}{-13.63}             & \multicolumn{1}{c|}{-36.89}              & -24.78              & \multicolumn{1}{c|}{-185.34}            & \multicolumn{1}{c|}{-127.66}             & -128.53             & \multicolumn{1}{c|}{-82.75}             & \multicolumn{1}{c|}{-86.35}              & -78.85              \\ \hline
Avg.                     & \multicolumn{1}{c|}{\textbf{-43.26}}    & \multicolumn{1}{c|}{-45.20}              & -44.22              & \multicolumn{1}{c|}{-115.72}            & \multicolumn{1}{c|}{\textbf{-96.72}}     & \textbf{-98.33}     & \multicolumn{1}{c|}{-74.25}             & \multicolumn{1}{c|}{\textbf{-69.88}}     & \textbf{-70.04}     \\ \hline
\end{tabular}
\end{center}
\end{table*}

% \input{supplementary/cn-cll-80-1}
\begin{table*}[]
\begin{center}
\caption{\label{tab:cn-cll-80-1}Predictive performance: Conditional log-likelihood scores given 20\% evidence for models having no latent variables (CNs). $h=1$: hamming distance threshold. \cn : Cutset networks trained on original training data, \cna: CNs learned from adversarially generated training data by \cns, \cnr: trained via joint maximization of standard and robust likelihoods. \test: original test data, \testa: adversarially perturbed \test by \cn, \testr: randomly perturbed \test by \cn.}

\begin{tabular}{|lccccccccc|}
\hline
\multicolumn{10}{|c|}{CLL Scores on 80\% query, 20\% evidence, h = 1}                                                    \\ \hline
\multicolumn{1}{|c|}{\multirow{2}{*}{dataset}} & \multicolumn{3}{c|}{\test}                                                                                     & \multicolumn{3}{c|}{\testa}                                                                                    & \multicolumn{3}{c|}{\testr}                                                               \\ \cline{2-10} 
\multicolumn{1}{|c|}{}                         & \multicolumn{1}{c|}{\cn} & \multicolumn{1}{c|}{\cna} & \multicolumn{1}{c|}{\cnr} & \multicolumn{1}{c|}{\cn} & \multicolumn{1}{c|}{\cna} & \multicolumn{1}{c|}{\cnr} & \multicolumn{1}{c|}{\cn} & \multicolumn{1}{c|}{\cna} & \cnr \\ \hline
\multicolumn{1}{|l|}{nltcs}                    & \multicolumn{1}{c|}{-4.82}              & \multicolumn{1}{c|}{-4.87}               & \multicolumn{1}{c|}{-4.85}               & \multicolumn{1}{c|}{-10.88}             & \multicolumn{1}{c|}{-8.87}               & \multicolumn{1}{c|}{-9.16}               & \multicolumn{1}{c|}{-8.79}              & \multicolumn{1}{c|}{-8.34}               & -8.43               \\ \hline
\multicolumn{1}{|l|}{msnbc}                    & \multicolumn{1}{c|}{-5.84}              & \multicolumn{1}{c|}{-5.85}               & \multicolumn{1}{c|}{-5.85}               & \multicolumn{1}{c|}{-11.82}             & \multicolumn{1}{c|}{-9.65}               & \multicolumn{1}{c|}{-9.90}               & \multicolumn{1}{c|}{-9.27}              & \multicolumn{1}{c|}{-8.78}               & -8.87               \\ \hline
\multicolumn{1}{|l|}{kdd}                      & \multicolumn{1}{c|}{-2.13}              & \multicolumn{1}{c|}{-2.31}               & \multicolumn{1}{c|}{-2.16}               & \multicolumn{1}{c|}{-10.72}             & \multicolumn{1}{c|}{-6.09}               & \multicolumn{1}{c|}{-6.64}               & \multicolumn{1}{c|}{-9.92}              & \multicolumn{1}{c|}{-6.34}               & -7.04               \\ \hline
\multicolumn{1}{|l|}{plants}                   & \multicolumn{1}{c|}{-13.06}             & \multicolumn{1}{c|}{-13.15}              & \multicolumn{1}{c|}{-13.11}              & \multicolumn{1}{c|}{-35.55}             & \multicolumn{1}{c|}{-30.17}              & \multicolumn{1}{c|}{-30.93}              & \multicolumn{1}{c|}{-25.84}             & \multicolumn{1}{c|}{-23.80}              & -24.20              \\ \hline
\multicolumn{1}{|l|}{baudio}                   & \multicolumn{1}{c|}{-41.40}             & \multicolumn{1}{c|}{-41.36}              & \multicolumn{1}{c|}{-41.38}              & \multicolumn{1}{c|}{-50.36}             & \multicolumn{1}{c|}{-49.97}              & \multicolumn{1}{c|}{-50.12}              & \multicolumn{1}{c|}{-46.69}             & \multicolumn{1}{c|}{-46.50}              & -46.58              \\ \hline
\multicolumn{1}{|l|}{jester}                   & \multicolumn{1}{c|}{-54.24}             & \multicolumn{1}{c|}{-54.22}              & \multicolumn{1}{c|}{-54.23}              & \multicolumn{1}{c|}{-62.58}             & \multicolumn{1}{c|}{-62.48}              & \multicolumn{1}{c|}{-62.53}              & \multicolumn{1}{c|}{-57.99}             & \multicolumn{1}{c|}{-57.96}              & -57.97              \\ \hline
\multicolumn{1}{|l|}{bnetflix}                 & \multicolumn{1}{c|}{-57.02}             & \multicolumn{1}{c|}{-58.31}              & \multicolumn{1}{c|}{-57.30}              & \multicolumn{1}{c|}{-64.73}             & \multicolumn{1}{c|}{-61.36}              & \multicolumn{1}{c|}{-62.19}              & \multicolumn{1}{c|}{-61.61}             & \multicolumn{1}{c|}{-60.55}              & -60.58              \\ \hline
\multicolumn{1}{|l|}{accidents}                & \multicolumn{1}{c|}{-28.81}             & \multicolumn{1}{c|}{-29.04}              & \multicolumn{1}{c|}{-28.95}              & \multicolumn{1}{c|}{-60.54}             & \multicolumn{1}{c|}{-49.86}              & \multicolumn{1}{c|}{-51.38}              & \multicolumn{1}{c|}{-43.84}             & \multicolumn{1}{c|}{-41.17}              & -41.72              \\ \hline
\multicolumn{1}{|l|}{tretail}                  & \multicolumn{1}{c|}{-9.88}              & \multicolumn{1}{c|}{-10.36}              & \multicolumn{1}{c|}{-10.07}              & \multicolumn{1}{c|}{-19.86}             & \multicolumn{1}{c|}{-13.35}              & \multicolumn{1}{c|}{-13.90}              & \multicolumn{1}{c|}{-17.99}             & \multicolumn{1}{c|}{-14.37}              & -14.92              \\ \hline
\multicolumn{1}{|l|}{pumsb\_star}              & \multicolumn{1}{c|}{-21.94}             & \multicolumn{1}{c|}{-22.25}              & \multicolumn{1}{c|}{-22.10}              & \multicolumn{1}{c|}{-117.20}            & \multicolumn{1}{c|}{-81.32}              & \multicolumn{1}{c|}{-86.19}              & \multicolumn{1}{c|}{-65.25}             & \multicolumn{1}{c|}{-55.58}              & -57.37              \\ \hline
\multicolumn{1}{|l|}{dna}                      & \multicolumn{1}{c|}{-84.33}             & \multicolumn{1}{c|}{-85.17}              & \multicolumn{1}{c|}{-84.65}              & \multicolumn{1}{c|}{-92.21}             & \multicolumn{1}{c|}{-88.76}              & \multicolumn{1}{c|}{-89.43}              & \multicolumn{1}{c|}{-90.94}             & \multicolumn{1}{c|}{-89.21}              & -89.52              \\ \hline
\multicolumn{1}{|l|}{kosarek}                  & \multicolumn{1}{c|}{-9.97}              & \multicolumn{1}{c|}{-10.42}              & \multicolumn{1}{c|}{-10.13}              & \multicolumn{1}{c|}{-23.58}             & \multicolumn{1}{c|}{-18.23}              & \multicolumn{1}{c|}{-19.15}              & \multicolumn{1}{c|}{-19.14}             & \multicolumn{1}{c|}{-16.29}              & -16.87              \\ \hline
\multicolumn{1}{|l|}{msweb}                    & \multicolumn{1}{c|}{-9.03}              & \multicolumn{1}{c|}{-9.34}               & \multicolumn{1}{c|}{-9.17}               & \multicolumn{1}{c|}{-38.62}             & \multicolumn{1}{c|}{-32.12}              & \multicolumn{1}{c|}{-32.80}              & \multicolumn{1}{c|}{-23.90}             & \multicolumn{1}{c|}{-22.91}              & -23.02              \\ \hline
\multicolumn{1}{|l|}{book}                     & \multicolumn{1}{c|}{-38.18}             & \multicolumn{1}{c|}{-38.32}              & \multicolumn{1}{c|}{-38.21}              & \multicolumn{1}{c|}{-52.69}             & \multicolumn{1}{c|}{-46.79}              & \multicolumn{1}{c|}{-48.78}              & \multicolumn{1}{c|}{-43.48}             & \multicolumn{1}{c|}{-41.77}              & -42.42              \\ \hline
\multicolumn{1}{|l|}{tmovie}                   & \multicolumn{1}{c|}{-52.74}             & \multicolumn{1}{c|}{-53.09}              & \multicolumn{1}{c|}{-52.79}              & \multicolumn{1}{c|}{-127.08}            & \multicolumn{1}{c|}{-119.88}             & \multicolumn{1}{c|}{-121.74}             & \multicolumn{1}{c|}{-92.64}             & \multicolumn{1}{c|}{-90.19}              & -90.93              \\ \hline
\multicolumn{1}{|l|}{cwebkb}                   & \multicolumn{1}{c|}{-157.13}            & \multicolumn{1}{c|}{-157.67}             & \multicolumn{1}{c|}{-157.09}             & \multicolumn{1}{c|}{-194.24}            & \multicolumn{1}{c|}{-185.35}             & \multicolumn{1}{c|}{-188.27}             & \multicolumn{1}{c|}{-166.40}            & \multicolumn{1}{c|}{-164.51}             & -164.90             \\ \hline
\multicolumn{1}{|l|}{cr52}                     & \multicolumn{1}{c|}{-84.85}             & \multicolumn{1}{c|}{-86.53}              & \multicolumn{1}{c|}{-85.74}              & \multicolumn{1}{c|}{-95.89}             & \multicolumn{1}{c|}{-95.65}              & \multicolumn{1}{c|}{-95.40}              & \multicolumn{1}{c|}{-93.42}             & \multicolumn{1}{c|}{-93.57}              & -93.18              \\ \hline
\multicolumn{1}{|l|}{c20ng}                    & \multicolumn{1}{c|}{-151.87}            & \multicolumn{1}{c|}{-152.05}             & \multicolumn{1}{c|}{-151.88}             & \multicolumn{1}{c|}{-166.12}            & \multicolumn{1}{c|}{-164.59}             & \multicolumn{1}{c|}{-165.20}             & \multicolumn{1}{c|}{-159.59}            & \multicolumn{1}{c|}{-159.09}             & -159.18             \\ \hline
\multicolumn{1}{|l|}{bbc}                      & \multicolumn{1}{c|}{-247.05}            & \multicolumn{1}{c|}{-247.20}             & \multicolumn{1}{c|}{-247.11}             & \multicolumn{1}{c|}{-256.04}            & \multicolumn{1}{c|}{-255.21}             & \multicolumn{1}{c|}{-255.34}             & \multicolumn{1}{c|}{-256.94}            & \multicolumn{1}{c|}{-256.23}             & -256.42             \\ \hline
\multicolumn{1}{|l|}{ad}                       & \multicolumn{1}{c|}{-17.16}             & \multicolumn{1}{c|}{-18.53}              & \multicolumn{1}{c|}{-17.76}              & \multicolumn{1}{c|}{-64.71}             & \multicolumn{1}{c|}{-52.62}              & \multicolumn{1}{c|}{-53.14}              & \multicolumn{1}{c|}{-56.27}             & \multicolumn{1}{c|}{-51.94}              & -52.13              \\ \hline
\multicolumn{1}{|l|}{Avg.}                     & \multicolumn{1}{c|}{-54.57}             & \multicolumn{1}{c|}{-55.00}              & \multicolumn{1}{c|}{-54.73}              & \multicolumn{1}{c|}{-77.77}             & \multicolumn{1}{c|}{-71.62}              & \multicolumn{1}{c|}{-72.61}              & \multicolumn{1}{c|}{-67.50}             & \multicolumn{1}{c|}{-65.46}              & -65.81              \\ \hline
\end{tabular}
    
\end{center}

\end{table*}

% \input{supplementary/cn-cll-80-3}
\begin{table*}[]
\begin{center}
\caption{\label{tab:cn-cll-80-3}Predictive performance: Conditional log-likelihood scores given 20\% evidence for models having no latent variables (CNs). $h=3$: hamming distance threshold. \cn : Cutset networks trained on original training data, \cna: CNs learned from adversarially generated training data by \cns, \cnr: trained via joint maximization of standard and robust likelihoods. \test: original test data, \testa: adversarially perturbed \test by \cn, \testr: randomly perturbed \test by \cn.}             


\begin{tabular}{|lccccccccc|}
\hline
\multicolumn{10}{|c|}{CLL Scores on 80\% query, 20\% evidence, h = 3}                                                                                                                                                                                                                                                                                                                                                     \\ \hline
\multicolumn{1}{|c|}{\multirow{2}{*}{dataset}} & \multicolumn{3}{c|}{\test}                                                                                     & \multicolumn{3}{c|}{\testa}                                                                                    & \multicolumn{3}{c|}{\testr}                                                               \\ \cline{2-10} 
\multicolumn{1}{|c|}{}                         & \multicolumn{1}{c|}{\cn} & \multicolumn{1}{c|}{\cna} & \multicolumn{1}{c|}{\cnr} & \multicolumn{1}{c|}{\cn} & \multicolumn{1}{c|}{\cna} & \multicolumn{1}{c|}{\cnr} & \multicolumn{1}{c|}{\cn} & \multicolumn{1}{c|}{\cna} & \cnr \\ \hline
\multicolumn{1}{|l|}{nltcs}                    & \multicolumn{1}{c|}{-4.82}              & \multicolumn{1}{c|}{-5.11}               & \multicolumn{1}{c|}{-4.94}               & \multicolumn{1}{c|}{-18.47}             & \multicolumn{1}{c|}{-14.24}              & \multicolumn{1}{c|}{-14.86}              & \multicolumn{1}{c|}{-13.17}             & \multicolumn{1}{c|}{-11.90}              & -12.05              \\ \hline
\multicolumn{1}{|l|}{msnbc}                    & \multicolumn{1}{c|}{-5.84}              & \multicolumn{1}{c|}{-5.86}               & \multicolumn{1}{c|}{-5.85}               & \multicolumn{1}{c|}{-20.79}             & \multicolumn{1}{c|}{-16.11}              & \multicolumn{1}{c|}{-16.71}              & \multicolumn{1}{c|}{-14.39}             & \multicolumn{1}{c|}{-13.27}              & -13.41              \\ \hline
\multicolumn{1}{|l|}{kdd}                      & \multicolumn{1}{c|}{-2.13}              & \multicolumn{1}{c|}{-2.17}               & \multicolumn{1}{c|}{-2.13}               & \multicolumn{1}{c|}{-44.45}             & \multicolumn{1}{c|}{-42.09}              & \multicolumn{1}{c|}{-42.71}              & \multicolumn{1}{c|}{-22.57}             & \multicolumn{1}{c|}{-20.58}              & -22.29              \\ \hline
\multicolumn{1}{|l|}{plants}                   & \multicolumn{1}{c|}{-13.06}             & \multicolumn{1}{c|}{-13.29}              & \multicolumn{1}{c|}{-13.18}              & \multicolumn{1}{c|}{-57.29}             & \multicolumn{1}{c|}{-47.67}              & \multicolumn{1}{c|}{-48.64}              & \multicolumn{1}{c|}{-40.22}             & \multicolumn{1}{c|}{-35.54}              & -35.98              \\ \hline
\multicolumn{1}{|l|}{baudio}                   & \multicolumn{1}{c|}{-41.40}             & \multicolumn{1}{c|}{-41.32}              & \multicolumn{1}{c|}{-41.40}              & \multicolumn{1}{c|}{-62.42}             & \multicolumn{1}{c|}{-57.91}              & \multicolumn{1}{c|}{-62.06}              & \multicolumn{1}{c|}{-52.03}             & \multicolumn{1}{c|}{-50.61}              & -51.97              \\ \hline
\multicolumn{1}{|l|}{jester}                   & \multicolumn{1}{c|}{-54.24}             & \multicolumn{1}{c|}{-54.15}              & \multicolumn{1}{c|}{-54.17}              & \multicolumn{1}{c|}{-74.15}             & \multicolumn{1}{c|}{-72.43}              & \multicolumn{1}{c|}{-73.22}              & \multicolumn{1}{c|}{-62.10}             & \multicolumn{1}{c|}{-61.69}              & -61.88              \\ \hline
\multicolumn{1}{|l|}{bnetflix}                 & \multicolumn{1}{c|}{-57.02}             & \multicolumn{1}{c|}{-59.41}              & \multicolumn{1}{c|}{-58.01}              & \multicolumn{1}{c|}{-73.71}             & \multicolumn{1}{c|}{-64.24}              & \multicolumn{1}{c|}{-65.69}              & \multicolumn{1}{c|}{-64.81}             & \multicolumn{1}{c|}{-62.36}              & -62.42              \\ \hline
\multicolumn{1}{|l|}{accidents}                & \multicolumn{1}{c|}{-28.81}             & \multicolumn{1}{c|}{-30.43}              & \multicolumn{1}{c|}{-29.71}              & \multicolumn{1}{c|}{-86.00}             & \multicolumn{1}{c|}{-55.10}              & \multicolumn{1}{c|}{-58.72}              & \multicolumn{1}{c|}{-60.09}             & \multicolumn{1}{c|}{-47.94}              & -49.66              \\ \hline
\multicolumn{1}{|l|}{tretail}                  & \multicolumn{1}{c|}{-9.88}              & \multicolumn{1}{c|}{-10.63}              & \multicolumn{1}{c|}{-10.30}              & \multicolumn{1}{c|}{-33.73}             & \multicolumn{1}{c|}{-18.06}              & \multicolumn{1}{c|}{-20.04}              & \multicolumn{1}{c|}{-28.69}             & \multicolumn{1}{c|}{-22.09}              & -22.69              \\ \hline
\multicolumn{1}{|l|}{pumsb\_star}              & \multicolumn{1}{c|}{-21.94}             & \multicolumn{1}{c|}{-26.69}              & \multicolumn{1}{c|}{-24.76}              & \multicolumn{1}{c|}{-220.39}            & \multicolumn{1}{c|}{-94.93}              & \multicolumn{1}{c|}{-106.42}             & \multicolumn{1}{c|}{-99.82}             & \multicolumn{1}{c|}{-73.69}              & -78.23              \\ \hline
\multicolumn{1}{|l|}{dna}                      & \multicolumn{1}{c|}{-84.33}             & \multicolumn{1}{c|}{-86.46}              & \multicolumn{1}{c|}{-85.35}              & \multicolumn{1}{c|}{-105.18}            & \multicolumn{1}{c|}{-95.66}              & \multicolumn{1}{c|}{-97.33}              & \multicolumn{1}{c|}{-99.72}             & \multicolumn{1}{c|}{-94.21}              & -94.86              \\ \hline
\multicolumn{1}{|l|}{kosarek}                  & \multicolumn{1}{c|}{-9.97}              & \multicolumn{1}{c|}{-9.97}               & \multicolumn{1}{c|}{-9.97}               & \multicolumn{1}{c|}{-49.97}             & \multicolumn{1}{c|}{-49.47}              & \multicolumn{1}{c|}{-49.82}              & \multicolumn{1}{c|}{-32.12}             & \multicolumn{1}{c|}{-31.97}              & -32.08              \\ \hline
\multicolumn{1}{|l|}{msweb}                    & \multicolumn{1}{c|}{-9.03}              & \multicolumn{1}{c|}{-9.11}               & \multicolumn{1}{c|}{-9.07}               & \multicolumn{1}{c|}{-66.20}             & \multicolumn{1}{c|}{-53.66}              & \multicolumn{1}{c|}{-55.40}              & \multicolumn{1}{c|}{-44.77}             & \multicolumn{1}{c|}{-42.45}              & -42.81              \\ \hline
\multicolumn{1}{|l|}{book}                     & \multicolumn{1}{c|}{-38.18}             & \multicolumn{1}{c|}{-38.24}              & \multicolumn{1}{c|}{-38.19}              & \multicolumn{1}{c|}{-70.37}             & \multicolumn{1}{c|}{-63.38}              & \multicolumn{1}{c|}{-65.61}              & \multicolumn{1}{c|}{-56.63}             & \multicolumn{1}{c|}{-54.28}              & -55.22              \\ \hline
\multicolumn{1}{|l|}{tmovie}                   & \multicolumn{1}{c|}{-52.74}             & \multicolumn{1}{c|}{-53.22}              & \multicolumn{1}{c|}{-52.91}              & \multicolumn{1}{c|}{-184.56}            & \multicolumn{1}{c|}{-172.14}             & \multicolumn{1}{c|}{-173.92}             & \multicolumn{1}{c|}{-117.48}            & \multicolumn{1}{c|}{-113.28}             & -114.00             \\ \hline
\multicolumn{1}{|l|}{cwebkb}                   & \multicolumn{1}{c|}{-157.13}            & \multicolumn{1}{c|}{-157.28}             & \multicolumn{1}{c|}{-157.19}             & \multicolumn{1}{c|}{-319.80}            & \multicolumn{1}{c|}{-316.08}             & \multicolumn{1}{c|}{-317.18}             & \multicolumn{1}{c|}{-182.85}            & \multicolumn{1}{c|}{-182.03}             & -182.29             \\ \hline
\multicolumn{1}{|l|}{cr52}                     & \multicolumn{1}{c|}{-84.85}             & \multicolumn{1}{c|}{-86.56}              & \multicolumn{1}{c|}{-85.75}              & \multicolumn{1}{c|}{-114.44}            & \multicolumn{1}{c|}{-111.35}             & \multicolumn{1}{c|}{-111.94}             & \multicolumn{1}{c|}{-105.37}            & \multicolumn{1}{c|}{-103.73}             & -103.88             \\ \hline
\multicolumn{1}{|l|}{c20ng}                    & \multicolumn{1}{c|}{-151.87}            & \multicolumn{1}{c|}{-152.05}             & \multicolumn{1}{c|}{-151.88}             & \multicolumn{1}{c|}{-180.53}            & \multicolumn{1}{c|}{-178.16}             & \multicolumn{1}{c|}{-179.06}             & \multicolumn{1}{c|}{-169.41}            & \multicolumn{1}{c|}{-168.37}             & -168.72             \\ \hline
\multicolumn{1}{|l|}{bbc}                      & \multicolumn{1}{c|}{-247.05}            & \multicolumn{1}{c|}{-247.69}             & \multicolumn{1}{c|}{-247.56}             & \multicolumn{1}{c|}{-270.45}            & \multicolumn{1}{c|}{-264.42}             & \multicolumn{1}{c|}{-265.33}             & \multicolumn{1}{c|}{-264.35}            & \multicolumn{1}{c|}{-262.92}             & -262.96             \\ \hline
\multicolumn{1}{|l|}{ad}                       & \multicolumn{1}{c|}{-17.16}             & \multicolumn{1}{c|}{-36.00}              & \multicolumn{1}{c|}{-26.25}              & \multicolumn{1}{c|}{-148.77}            & \multicolumn{1}{c|}{-118.60}             & \multicolumn{1}{c|}{-113.54}             & \multicolumn{1}{c|}{-82.62}             & \multicolumn{1}{c|}{-84.49}              & -76.88              \\ \hline
\multicolumn{1}{|l|}{Avg.}                     & \multicolumn{1}{c|}{-54.57}             & \multicolumn{1}{c|}{-56.28}              & \multicolumn{1}{c|}{-55.43}              & \multicolumn{1}{c|}{-110.08}            & \multicolumn{1}{c|}{-95.29}              & \multicolumn{1}{c|}{-96.91}              & \multicolumn{1}{c|}{-80.66}             & \multicolumn{1}{c|}{-76.87}              & -77.21              \\ \hline
\end{tabular}
\end{center}
\end{table*}

% \input{supplementary/cn-cll-80-5}
\begin{table*}[]
\begin{center}
\caption{\label{tab:cn-cll-80-5}Predictive performance: Conditional log-likelihood scores given 20\% evidence for models having no latent variables (CNs). $h=5$: hamming distance threshold. \cn : Cutset networks trained on original training data, \cna: CNs learned from adversarially generated training data by \cns, \cnr: trained via joint maximization of standard and robust likelihoods. \test: original test data, \testa: adversarially perturbed \test by \cn, \testr: randomly perturbed \test by \cn.}             

\begin{tabular}{|lccccccccc|}
\hline
\multicolumn{10}{|c|}{CLL Scores on 80\% query, 20\% evidence, h = 5}                                                                                                                                                                                                                                                                                                                                                     \\ \hline
\multicolumn{1}{|c|}{\multirow{2}{*}{dataset}} & \multicolumn{3}{c|}{\test}                                                                                     & \multicolumn{3}{c|}{\testa}                                                                                    & \multicolumn{3}{c|}{\testr}                                                               \\ \cline{2-10} 
\multicolumn{1}{|c|}{}                         & \multicolumn{1}{c|}{\cn} & \multicolumn{1}{c|}{\cna} & \multicolumn{1}{c|}{\cnr} & \multicolumn{1}{c|}{\cn} & \multicolumn{1}{c|}{\cna} & \multicolumn{1}{c|}{\cnr} & \multicolumn{1}{c|}{\cn} & \multicolumn{1}{c|}{\cna} & \cnr \\ \hline
\multicolumn{1}{|l|}{nltcs}                    & \multicolumn{1}{c|}{-4.55}              & \multicolumn{1}{c|}{-4.82}               & \multicolumn{1}{c|}{-4.64}               & \multicolumn{1}{c|}{-23.00}             & \multicolumn{1}{c|}{-18.67}              & \multicolumn{1}{c|}{-19.37}              & \multicolumn{1}{c|}{-15.26}             & \multicolumn{1}{c|}{-14.60}              & -14.67              \\ \hline
\multicolumn{1}{|l|}{msnbc}                    & \multicolumn{1}{c|}{-5.48}              & \multicolumn{1}{c|}{-5.50}               & \multicolumn{1}{c|}{-5.49}               & \multicolumn{1}{c|}{-27.04}             & \multicolumn{1}{c|}{-20.33}              & \multicolumn{1}{c|}{-20.83}              & \multicolumn{1}{c|}{-17.09}             & \multicolumn{1}{c|}{-15.74}              & -15.70              \\ \hline
\multicolumn{1}{|l|}{kdd}                      & \multicolumn{1}{c|}{-2.13}              & \multicolumn{1}{c|}{-2.13}               & \multicolumn{1}{c|}{-2.13}               & \multicolumn{1}{c|}{-52.61}             & \multicolumn{1}{c|}{-50.27}              & \multicolumn{1}{c|}{-50.87}              & \multicolumn{1}{c|}{-34.94}             & \multicolumn{1}{c|}{-34.44}              & -34.63              \\ \hline
\multicolumn{1}{|l|}{plants}                   & \multicolumn{1}{c|}{-13.06}             & \multicolumn{1}{c|}{-13.39}              & \multicolumn{1}{c|}{-13.21}              & \multicolumn{1}{c|}{-71.02}             & \multicolumn{1}{c|}{-56.49}              & \multicolumn{1}{c|}{-60.04}              & \multicolumn{1}{c|}{-50.17}             & \multicolumn{1}{c|}{-42.95}              & -44.90              \\ \hline
\multicolumn{1}{|l|}{baudio}                   & \multicolumn{1}{c|}{-41.40}             & \multicolumn{1}{c|}{-41.40}              & \multicolumn{1}{c|}{-41.40}              & \multicolumn{1}{c|}{-70.63}             & \multicolumn{1}{c|}{-70.25}              & \multicolumn{1}{c|}{-70.17}              & \multicolumn{1}{c|}{-56.99}             & \multicolumn{1}{c|}{-56.91}              & -56.90              \\ \hline
\multicolumn{1}{|l|}{jester}                   & \multicolumn{1}{c|}{-54.24}             & \multicolumn{1}{c|}{-54.16}              & \multicolumn{1}{c|}{-54.16}              & \multicolumn{1}{c|}{-81.86}             & \multicolumn{1}{c|}{-79.14}              & \multicolumn{1}{c|}{-79.40}              & \multicolumn{1}{c|}{-64.87}             & \multicolumn{1}{c|}{-64.34}              & -64.40              \\ \hline
\multicolumn{1}{|l|}{bnetflix}                 & \multicolumn{1}{c|}{-57.02}             & \multicolumn{1}{c|}{-60.64}              & \multicolumn{1}{c|}{-58.25}              & \multicolumn{1}{c|}{-79.82}             & \multicolumn{1}{c|}{-65.69}              & \multicolumn{1}{c|}{-68.28}              & \multicolumn{1}{c|}{-67.00}             & \multicolumn{1}{c|}{-63.64}              & -63.77              \\ \hline
\multicolumn{1}{|l|}{accidents}                & \multicolumn{1}{c|}{-28.81}             & \multicolumn{1}{c|}{-30.30}              & \multicolumn{1}{c|}{-29.77}              & \multicolumn{1}{c|}{-103.31}            & \multicolumn{1}{c|}{-64.32}              & \multicolumn{1}{c|}{-67.78}              & \multicolumn{1}{c|}{-71.42}             & \multicolumn{1}{c|}{-55.17}              & -56.99              \\ \hline
\multicolumn{1}{|l|}{tretail}                  & \multicolumn{1}{c|}{-9.88}              & \multicolumn{1}{c|}{-9.93}               & \multicolumn{1}{c|}{-9.90}               & \multicolumn{1}{c|}{-46.95}             & \multicolumn{1}{c|}{-35.08}              & \multicolumn{1}{c|}{-37.47}              & \multicolumn{1}{c|}{-38.78}             & \multicolumn{1}{c|}{-34.19}              & -35.14              \\ \hline
\multicolumn{1}{|l|}{pumsb\_star}              & \multicolumn{1}{c|}{-21.94}             & \multicolumn{1}{c|}{-26.58}              & \multicolumn{1}{c|}{-24.81}              & \multicolumn{1}{c|}{-258.73}            & \multicolumn{1}{c|}{-105.61}             & \multicolumn{1}{c|}{-118.99}             & \multicolumn{1}{c|}{-114.87}            & \multicolumn{1}{c|}{-85.59}              & -89.40              \\ \hline
\multicolumn{1}{|l|}{dna}                      & \multicolumn{1}{c|}{-84.33}             & \multicolumn{1}{c|}{-87.40}              & \multicolumn{1}{c|}{-85.90}              & \multicolumn{1}{c|}{-117.66}            & \multicolumn{1}{c|}{-100.74}             & \multicolumn{1}{c|}{-103.50}             & \multicolumn{1}{c|}{-106.96}            & \multicolumn{1}{c|}{-97.35}              & -98.34              \\ \hline
\multicolumn{1}{|l|}{kosarek}                  & \multicolumn{1}{c|}{-9.97}              & \multicolumn{1}{c|}{-10.00}              & \multicolumn{1}{c|}{-9.99}               & \multicolumn{1}{c|}{-67.91}             & \multicolumn{1}{c|}{-62.75}              & \multicolumn{1}{c|}{-63.95}              & \multicolumn{1}{c|}{-44.69}             & \multicolumn{1}{c|}{-42.26}              & -43.04              \\ \hline
\multicolumn{1}{|l|}{msweb}                    & \multicolumn{1}{c|}{-9.03}              & \multicolumn{1}{c|}{-9.14}               & \multicolumn{1}{c|}{-9.09}               & \multicolumn{1}{c|}{-88.44}             & \multicolumn{1}{c|}{-68.35}              & \multicolumn{1}{c|}{-70.99}              & \multicolumn{1}{c|}{-60.89}             & \multicolumn{1}{c|}{-57.96}              & -58.15              \\ \hline
\multicolumn{1}{|l|}{book}                     & \multicolumn{1}{c|}{-38.18}             & \multicolumn{1}{c|}{-38.32}              & \multicolumn{1}{c|}{-38.21}              & \multicolumn{1}{c|}{-68.89}             & \multicolumn{1}{c|}{-66.05}              & \multicolumn{1}{c|}{-67.87}              & \multicolumn{1}{c|}{-62.68}             & \multicolumn{1}{c|}{-61.13}              & -62.24              \\ \hline
\multicolumn{1}{|l|}{tmovie}                   & \multicolumn{1}{c|}{-52.74}             & \multicolumn{1}{c|}{-53.30}              & \multicolumn{1}{c|}{-53.26}              & \multicolumn{1}{c|}{-245.35}            & \multicolumn{1}{c|}{-231.23}             & \multicolumn{1}{c|}{-224.70}             & \multicolumn{1}{c|}{-135.60}            & \multicolumn{1}{c|}{-130.64}             & -128.84             \\ \hline
\multicolumn{1}{|l|}{cwebkb}                   & \multicolumn{1}{c|}{-157.13}            & \multicolumn{1}{c|}{-157.67}             & \multicolumn{1}{c|}{-157.09}             & \multicolumn{1}{c|}{-356.89}            & \multicolumn{1}{c|}{-348.96}             & \multicolumn{1}{c|}{-352.15}             & \multicolumn{1}{c|}{-197.67}            & \multicolumn{1}{c|}{-191.62}             & -193.50             \\ \hline
\multicolumn{1}{|l|}{cr52}                     & \multicolumn{1}{c|}{-84.85}             & \multicolumn{1}{c|}{-86.56}              & \multicolumn{1}{c|}{-85.75}              & \multicolumn{1}{c|}{-114.44}            & \multicolumn{1}{c|}{-111.35}             & \multicolumn{1}{c|}{-111.94}             & \multicolumn{1}{c|}{-105.37}            & \multicolumn{1}{c|}{-103.73}             & -103.88             \\ \hline
\multicolumn{1}{|l|}{c20ng}                    & \multicolumn{1}{c|}{-151.87}            & \multicolumn{1}{c|}{-152.05}             & \multicolumn{1}{c|}{-151.88}             & \multicolumn{1}{c|}{-180.53}            & \multicolumn{1}{c|}{-178.16}             & \multicolumn{1}{c|}{-179.06}             & \multicolumn{1}{c|}{-169.41}            & \multicolumn{1}{c|}{-168.37}             & -168.72             \\ \hline
\multicolumn{1}{|l|}{bbc}                      & \multicolumn{1}{c|}{-247.05}            & \multicolumn{1}{c|}{-250.06}             & \multicolumn{1}{c|}{-247.91}             & \multicolumn{1}{c|}{-285.53}            & \multicolumn{1}{c|}{-271.26}             & \multicolumn{1}{c|}{-274.82}             & \multicolumn{1}{c|}{-271.61}            & \multicolumn{1}{c|}{-269.76}             & -269.77             \\ \hline
\multicolumn{1}{|l|}{ad}                       & \multicolumn{1}{c|}{-17.16}             & \multicolumn{1}{c|}{-42.85}              & \multicolumn{1}{c|}{-30.04}              & \multicolumn{1}{c|}{-229.32}            & \multicolumn{1}{c|}{-161.28}             & \multicolumn{1}{c|}{-164.75}             & \multicolumn{1}{c|}{-106.82}            & \multicolumn{1}{c|}{-108.15}             & -101.14             \\ \hline
\multicolumn{1}{|l|}{Avg.}                     & \multicolumn{1}{c|}{-54.54}             & \multicolumn{1}{c|}{-56.81}              & \multicolumn{1}{c|}{-55.64}              & \multicolumn{1}{c|}{-128.50}            & \multicolumn{1}{c|}{-108.30}             & \multicolumn{1}{c|}{-110.35}             & \multicolumn{1}{c|}{-89.65}             & \multicolumn{1}{c|}{-84.93}              & -85.21              \\ \hline
\end{tabular}
    
\end{center}

\end{table*}

\section{Experimental Results on Sum-Product Networks: TPMs with Latent Variables}

\subsection{Robust Generative Performance}
Tables \ref{tab:spn-ll-1} through \ref{tab:spn-ll-5} report log-likelihood scores on the three different test sets attained by standard SPNs (\spns) and robust SPNs (\spna, \spnr) trained using our proposed method. Similar to cutset networks, \spnas and \spnrs consistently outperform \spns on robust log-likelihood scores.


% \input{supplementary/sup-spn-ll-1}
\begin{table*}[t]
\begin{center} 

\caption{\label{tab:spn-ll-1} Generative performance: Test set log-likelihood scores of models having latent variables. $h=1$: hamming distance threshold. \spn : SPN trained on original training data, \spna: SPN trained on the adversarially generated training data by \spn, \spnr: SPN trained via joint maximization of standard and robust likelihoods. \test: original test data, \testa: adversarially perturbed \test by \spn, \testr: randomly perturbed \test by \spn.} 

\begin{tabular}{ |c | c | c | c | c | c | c | c | c | c |}
\hline 
\hline 
 & \multicolumn{9}{|c|}{$h$=1} \\
\hline 
 & \multicolumn{3}{|c|}{\test}  & \multicolumn{3}{|c|}{\testa} & \multicolumn{3}{|c|}{\testr}  \\
\hline 
 \multicolumn{1}{|c|}{dataset} & \multicolumn{1}{|c|}{\spn} & \multicolumn{1}{|c|}{\spna} & \multicolumn{1}{|c|}{\spnr} & \multicolumn{1}{|c|}{\spn} & \multicolumn{1}{|c|}{\spna} & \multicolumn{1}{|c|}{\spnr} & \multicolumn{1}{|c|}{\spn} & \multicolumn{1}{|c|}{\spna} & \multicolumn{1}{|c|}{\spnr} \\
\hline 
nltcs & -6.02 & -6.9 & -6.41 & -11.51 & -8.37 & -8.52 & -10.98 & -8.36 & -8.57 \\
\hline 
msnbc & -6.06 & -8.76 & -7.02 & -12.55 & -9.27 & -8.86 & -11.97 & -9.81 & -9.32 \\
\hline 
kdd-2k & -2.13 & -3.88 & -2.79 & -11.18 & -7.17 & -10.48 & -10.24 & -8.79 & -8.28 \\
\hline 
plants & -13.52 & -14.17 & -13.8 & -21.78 & -18.01 & -18.2 & -21.18 & -17.83 & -18.28 \\
\hline 
jester & -52.88 & -53.28 & -53.12 & -56.5 & -55.15 & -54.97 & -55.48 & -55.05 & -55.03 \\
\hline 
audio & -40.04 & -41.12 & -40.5 & -45.31 & -43.46 & -43.03 & -43.85 & -43.66 & -43.39 \\
\hline 
netflix & -56.85 & -57.98 & -57.31 & -61.02 & -59.37 & -58.87 & -59.47 & -59.58 & -59.1 \\
\hline 
accidents & -35.74 & -35.82 & -35.72 & -43.09 & -39.46 & -39.89 & -42.08 & -39.33 & -39.66 \\
\hline 
retail & -10.9 & -11.41 & -11.13 & -18.52 & -14.64 & -16.13 & -16.98 & -15.2 & -15.41 \\
\hline 
pumsb-star & -30.92 & -31.38 & -31.01 & -40.06 & -36.12 & -36.54 & -39.1 & -36.15 & -36.72 \\
\hline 
dna & -96.95 & -97.38 & -97.37 & -100.01 & -99.15 & -99.43 & -99.29 & -99.01 & -99.11 \\
\hline 
kosarek & -11.01 & -11.8 & -11.45 & -18.88 & -17.38 & -17.41 & -18.45 & -16.8 & -17.13 \\
\hline 
msweb & -10.04 & -10.73 & -10.3 & -21.57 & -16.83 & -17.58 & -20.9 & -16.56 & -17.19 \\
\hline 
book & -34.94 & -35.59 & -35.33 & -42.59 & -39.6 & -39.83 & -41.6 & -40.42 & -40.53 \\
\hline 
each-movie & -53.33 & -54.47 & -53.83 & -77.64 & -69.13 & -70.72 & -76.91 & -68.62 & -70.27 \\
\hline 
web-kb & -159.21 & -159.53 & -159.94 & -171.15 & -165.91 & -166.12 & -168.87 & -165.88 & -166.51 \\
\hline 
reuters-52 & -90.64 & -91.82 & -91.66 & -111.19 & -102.55 & -102.85 & -108.41 & -103.1 & -105.85 \\
\hline 
20ng & -155.47 & -155.33 & -155.84 & -169.11 & -160.32 & -162.19 & -165.26 & -160.53 & -161.85 \\
\hline 
bbc & -250.75 & -266.75 & -253.7 & -259.35 & -275.39 & -260.35 & -258.37 & -274.78 & -260.54 \\
\hline 
ad & -32.16 & -40.89 & -35.22 & -44.64 & -50.5 & -45.34 & -43.48 & -50.47 & -45.18 \\
\hline 
\hline 
\end{tabular}
\end{center} 
\end{table*}


% \input{supplementary/sup-spn-ll-3}
\begin{table*}[t]
\begin{center} 

\caption{\label{tab:spn-ll-3} Generative performance: Test set log-likelihood scores of models having latent variables. $h=3$: hamming distance threshold. \spn : SPN trained on original training data, \spna: SPN trained on the adversarially generated training data by \spn, \spnr: SPN trained via joint maximization of standard and robust likelihoods. \test: original test data, \testa: adversarially perturbed \test by \spn, \testr: randomly perturbed \test by \spn.} 

\begin{tabular}{ |c | c | c | c | c | c | c | c | c | c |}
\hline 
\hline 
 & \multicolumn{9}{|c|}{$h$=3} \\
\hline 
 & \multicolumn{3}{|c|}{\test}  & \multicolumn{3}{|c|}{\testa} & \multicolumn{3}{|c|}{\testr}  \\
\hline 
 \multicolumn{1}{|c|}{dataset} & \multicolumn{1}{|c|}{\spn} & \multicolumn{1}{|c|}{\spna} & \multicolumn{1}{|c|}{\spnr} & \multicolumn{1}{|c|}{\spn} & \multicolumn{1}{|c|}{\spna} & \multicolumn{1}{|c|}{\spnr} & \multicolumn{1}{|c|}{\spn} & \multicolumn{1}{|c|}{\spna} & \multicolumn{1}{|c|}{\spnr} \\
\hline 
nltcs & -6.02 & -9.04 & -6.68 & -18.68 & -10.54 & -11.01 & -18.16 & -10.57 & -11.03 \\
\hline 
msnbc & -6.06 & -13.41 & -7.08 & -21.09 & -8.15 & -9.9 & -19.9 & -10.22 & -11.96 \\
\hline 
kdd-2k & -2.13 & -7.82 & -2.84 & -25.58 & -15.25 & -17.45 & -22.48 & -18.52 & -18.7 \\
\hline 
plants & -13.52 & -16.04 & -14.46 & -37.47 & -23.83 & -25.06 & -35.67 & -23.83 & -24.86 \\
\hline 
jester & -52.88 & -54.91 & -53.79 & -62.04 & -57.93 & -57.43 & -60.12 & -58.72 & -58.44 \\
\hline 
audio & -40.04 & -43.52 & -41.35 & -52.71 & -47.58 & -46.68 & -50.38 & -49.06 & -47.85 \\
\hline 
netflix & -56.85 & -61.56 & -58.01 & -67.18 & -61.43 & -61.12 & -64.22 & -64.65 & -62.16 \\
\hline 
accidents & -35.74 & -36.8 & -35.9 & -56.8 & -44.7 & -45.68 & -53.9 & -44.58 & -45.49 \\
\hline 
retail & -10.9 & -12.89 & -11.42 & -31.09 & -22.9 & -22.29 & -28.16 & -23.01 & -22.95 \\
\hline 
pumsb-star & -30.92 & -32.85 & -31.91 & -56.97 & -43.54 & -45.2 & -55.23 & -43.6 & -45.13 \\
\hline 
dna & -96.95 & -97.97 & -97.42 & -104.87 & -102.28 & -103.05 & -103.58 & -102.08 & -102.36 \\
\hline 
kosarek & -11.01 & -13.61 & -12.01 & -33.68 & -26.01 & -27.47 & -32.58 & -25.89 & -26.82 \\
\hline 
msweb & -10.04 & -12.59 & -10.91 & -43.35 & -26.2 & -27.57 & -42.35 & -26.19 & -27.38 \\
\hline 
book & -34.94 & -37.11 & -36.02 & -55.85 & -50.6 & -51.39 & -54.2 & -50.67 & -50.82 \\
\hline 
each-movie & -53.33 & -57.82 & -55.13 & -124.37 & -86.04 & -96.13 & -121.93 & -87.12 & -95.49 \\
\hline 
web-kb & -159.21 & -160.88 & -160.75 & -191.55 & -175.45 & -177.97 & -185.88 & -176.41 & -179.1 \\
\hline 
reuters-52 & -90.64 & -93.93 & -92.78 & -146.1 & -119.42 & -120.03 & -138.25 & -119.44 & -124.32 \\
\hline 
20ng & -155.47 & -156.29 & -156.01 & -190.14 & -168.54 & -171.26 & -182.15 & -169.29 & -171.12 \\
\hline 
bbc & -250.75 & -261.12 & -254.68 & -275.56 & -280.13 & -272.46 & -273.37 & -279.1 & -272.4 \\
\hline 
ad & -32.16 & -33.49 & -32.11 & -68.55 & -58.71 & -59.88 & -65.74 & -58.27 & -59.97 \\
\hline 
\hline 
\end{tabular}
\end{center} 
\end{table*}


% \input{supplementary/sup-spn-ll-5}
\begin{table*}[t]
\begin{center} 

\caption{\label{tab:spn-ll-5} Generative performance: Test set log-likelihood scores of models having latent variables. $h=5$: hamming distance threshold. \spn : SPN trained on original training data, \spna: SPN trained on the adversarially generated training data by \spn, \spnr: SPN trained via joint maximization of standard and robust likelihoods. \test: original test data, \testa: adversarially perturbed \test by \spn, \testr: randomly perturbed \test by \spn.} 

\begin{tabular}{ |c | c | c | c | c | c | c | c | c | c |}
\hline 
\hline 
 & \multicolumn{9}{|c|}{$h$=3} \\
\hline 
 & \multicolumn{3}{|c|}{\test}  & \multicolumn{3}{|c|}{\testa} & \multicolumn{3}{|c|}{\testr}  \\
\hline 
 \multicolumn{1}{|c|}{dataset} & \multicolumn{1}{|c|}{\spn} & \multicolumn{1}{|c|}{\spna} & \multicolumn{1}{|c|}{\spnr} & \multicolumn{1}{|c|}{\spn} & \multicolumn{1}{|c|}{\spna} & \multicolumn{1}{|c|}{\spnr} & \multicolumn{1}{|c|}{\spn} & \multicolumn{1}{|c|}{\spna} & \multicolumn{1}{|c|}{\spnr} \\
\hline 
nltcs & -6.02 & -10.75 & -6.71 & -23.22 & -11.23 & -11.36 & -22.44 & -11.19 & -11.42 \\
\hline 
msnbc & -6.06 & -17.85 & -7.04 & -26.06 & -10.1 & -11.96 & -25.18 & -11.53 & -13.26 \\
\hline 
kdd-2k & -2.13 & -11.61 & -2.85 & -37.35 & -25.87 & -23.43 & -33.58 & -26.99 & -25.34 \\
\hline 
plants & -13.52 & -17.9 & -14.68 & -52.31 & -28.35 & -29.77 & -49.19 & -28.38 & -29.58 \\
\hline 
jester & -52.88 & -57.18 & -54.19 & -66.42 & -60.4 & -59.58 & -64.08 & -62.21 & -61.24 \\
\hline 
audio & -40.04 & -46.23 & -41.81 & -58.56 & -50.09 & -49.33 & -55.78 & -53.87 & -51.31 \\
\hline 
netflix & -56.85 & -65.28 & -58.49 & -72.06 & -63.12 & -62.82 & -68.63 & -68.99 & -64.54 \\
\hline 
accidents & -35.74 & -38.93 & -36.64 & -69.76 & -49.22 & -50.42 & -65.38 & -49.19 & -50.26 \\
\hline 
retail & -10.9 & -14.65 & -11.52 & -41.9 & -28.78 & -30.02 & -39.16 & -29.56 & -30.19 \\
\hline 
pumsb-star & -30.92 & -34.77 & -32.47 & -73.13 & -49.94 & -51.59 & -71.02 & -49.84 & -51.47 \\
\hline 
dna & -96.95 & -98.37 & -97.54 & -108.87 & -104.71 & -106.29 & -107.44 & -104.48 & -105.36 \\
\hline 
kosarek & -11.01 & -15.5 & -11.71 & -47.45 & -34.45 & -33.3 & -45.64 & -34.14 & -33.77 \\
\hline 
msweb & -10.04 & -14.63 & -10.64 & -64.78 & -35.18 & -36.66 & -63.55 & -34.74 & -36.62 \\
\hline 
book & -34.94 & -39.21 & -36.44 & -68.06 & -59.48 & -58.26 & -65.97 & -60.28 & -59.1 \\
\hline 
each-movie & -53.33 & -63.87 & -55.88 & -165.06 & -109.16 & -101.77 & -159.01 & -108.74 & -103.39 \\
\hline 
web-kb & -159.21 & -162.14 & -161.1 & -208.77 & -186.24 & -186.78 & -201.04 & -185.39 & -188.32 \\
\hline 
reuters-52 & -90.64 & -96.41 & -93.4 & -173.71 & -123.88 & -131.36 & -161.36 & -130.86 & -137.45 \\
\hline 
20ng & -155.47 & -158.2 & -156.61 & -207.68 & -178.39 & -179.1 & -196.91 & -178.44 & -179.6 \\
\hline 
bbc & -250.75 & -257.18 & -254.13 & -291.12 & -284.1 & -281.15 & -288.14 & -283.67 & -281.78 \\
\hline 
ad & -32.16 & -35.63 & -32.63 & -91.52 & -73.72 & -75.81 & -87.53 & -74.1 & -75.19 \\
\hline 
\hline 
\end{tabular}
\end{center} 
\end{table*}


\subsection{Robust Predictive Performance}
Tables \ref{tab:spn-cll-20-1} through \ref{tab:spn-cll-80-5} report conditional log-likelihood scores of \spns, \spnas and \spnrs on the three test sets \test, \testa and \testr with variable sizes of evidence sets and degree of corruption. \spnas and \spnrs have better robust CLL scores compared to \spns. \\
Until now, our experimental results are obtained under the assumption that an adversary has access to the original \spn (both its structure and parameters). In practice, an adversary may only have access to a weaker model. To evaluate the effectiveness of our proposed method under such assumption we conduct a second set of experiments. For each dataset, we learn simple mixtures of tree Bayesian networks using the Chow-Liu algorithm and assume an adversary has access to the mixture models instead of the highly accurate complex \spn. These mixture of tree BNs serve as our example of weak models. Table \ref{tab:spn-weaker-ll} shows the log-likelihood scores obtained by robust and non-robust SPNs on test data corrupted by these simple SPN. Similar to our previous results, robust SPNs have higher test log-likelihood scores than non-robust SPNs.  


% \input{supplementary/sup-spn-cll-20-1}
\begin{table*}[t]
\begin{center} 
\caption{\label{tab:spn-cll-20-1} Predictive performance: Conditional log-likelihood scores given 20\% evidence for models having latent variables (SPNs). $h=1$: hamming distance threshold. \spn : SPN trained original training data, \spna: SPN trained on the adversarially generated training data by \spn, \spnr: SPN trained via joint maximization of standard and robust likelihoods. \test: original test data, \testa: adversarially perturbed \test by \spn, \testr: randomly perturbed \test by \spn.}
\begin{tabular}{ |c | c | c | c | c | c | c | c | c | c |}
\hline 
\hline 
 & \multicolumn{9}{|c|}{$h$=1} \\
\hline 
 & \multicolumn{3}{|c|}{\test}  & \multicolumn{3}{|c|}{\testa} & \multicolumn{3}{|c|}{\testr}  \\
\hline 
 \multicolumn{1}{|c|}{dataset} & \multicolumn{1}{|c|}{\spn} & \multicolumn{1}{|c|}{\spna} & \multicolumn{1}{|c|}{\spnr} & \multicolumn{1}{|c|}{\spn} & \multicolumn{1}{|c|}{\spna} & \multicolumn{1}{|c|}{\spnr} & \multicolumn{1}{|c|}{\spn} & \multicolumn{1}{|c|}{\spna} & \multicolumn{1}{|c|}{\spnr} \\
\hline 
nltcs & -4.82 & -5.61 & -5.18 & -10.21 & -7.02 & -7.23 & -9.62 & -6.98 & -7.23 \\
\hline 
msnbc & -4.3 & -6.99 & -5.26 & -10.79 & -7.51 & -7.09 & -10.22 & -8.05 & -7.56 \\
\hline 
kdd-2k & -2.0 & -2.46 & -2.05 & -2.59 & -3.42 & -3.07 & -3.96 & -4.54 & -3.9 \\
\hline 
plants & -9.53 & -10.06 & -9.75 & -15.0 & -12.74 & -12.46 & -14.92 & -12.54 & -13.21 \\
\hline 
jester & -40.61 & -40.99 & -40.83 & -44.0 & -42.6 & -42.47 & -43.02 & -42.72 & -42.54 \\
\hline 
audio & -31.44 & -32.47 & -31.83 & -36.22 & -34.44 & -34.07 & -34.86 & -34.56 & -34.29 \\
\hline 
netflix & -44.42 & -45.52 & -44.87 & -48.4 & -46.79 & -46.31 & -46.76 & -46.93 & -46.45 \\
\hline 
accidents & -26.94 & -26.93 & -26.89 & -31.68 & -28.81 & -29.39 & -31.42 & -29.12 & -30.01 \\
\hline 
retail & -5.69 & -6.17 & -5.9 & -13.31 & -9.38 & -10.9 & -11.41 & -9.4 & -9.77 \\
\hline 
pumsb-star & -23.19 & -23.58 & -23.25 & -30.47 & -27.12 & -27.51 & -29.7 & -27.63 & -27.67 \\
\hline 
dna & -77.25 & -77.67 & -77.67 & -80.19 & -79.32 & -79.62 & -79.44 & -79.13 & -79.22 \\
\hline 
kosarek & -4.46 & -5.25 & -4.88 & -12.32 & -10.82 & -10.84 & -11.87 & -10.24 & -10.55 \\
\hline 
msweb & -3.06 & -3.77 & -3.38 & -13.71 & -9.85 & -10.05 & -13.42 & -9.53 & -9.89 \\
\hline 
book & -26.92 & -27.56 & -27.32 & -34.23 & -30.99 & -31.53 & -33.18 & -31.84 & -32.14 \\
\hline 
each-movie & -37.31 & -38.59 & -37.86 & -59.23 & -47.49 & -53.81 & -58.48 & -52.09 & -53.44 \\
\hline 
web-kb & -127.08 & -127.35 & -127.66 & -137.33 & -132.64 & -132.62 & -135.4 & -132.69 & -133.17 \\
\hline 
reuters-52 & -71.59 & -72.67 & -72.61 & -91.68 & -82.24 & -83.4 & -87.92 & -82.76 & -85.19 \\
\hline 
20ng & -123.39 & -123.16 & -123.75 & -136.7 & -127.81 & -129.8 & -132.45 & -127.76 & -129.12 \\
\hline 
bbc & -163.8 & -178.49 & -166.5 & -172.29 & -187.09 & -173.03 & -171.32 & -186.35 & -173.23 \\
\hline 
ad & -23.71 & -30.6 & -26.1 & -35.32 & -39.39 & -35.42 & -33.48 & -38.59 & -34.49 \\
\hline 
\hline 
\end{tabular}
\end{center} 
\end{table*}

% \input{supplementary/sup-spn-cll-20-3}
\begin{table*}[t]
\begin{center}
\caption{\label{tab:spn-cll-20-3} Predictive performance: Conditional log-likelihood scores given 20\% evidence for models having latent variables (SPNs). $h=3$: hamming distance threshold. \spn : SPN trained original training data, \spna: SPN trained on the adversarially generated training data by \spn, \spnr: SPN trained via joint maximization of standard and robust likelihoods. \test: original test data, \testa: adversarially perturbed \test by \spn, \testr: randomly perturbed \test by \spn.}

\begin{tabular}{ |c | c | c | c | c | c | c | c | c | c |}
\hline 
\hline 
 & \multicolumn{9}{|c|}{$h$=3} \\
\hline 
 & \multicolumn{3}{|c|}{\test}  & \multicolumn{3}{|c|}{\testa} & \multicolumn{3}{|c|}{\testr}  \\
\hline 
 \multicolumn{1}{|c|}{dataset} & \multicolumn{1}{|c|}{\spn} & \multicolumn{1}{|c|}{\spna} & \multicolumn{1}{|c|}{\spnr} & \multicolumn{1}{|c|}{\spn} & \multicolumn{1}{|c|}{\spna} & \multicolumn{1}{|c|}{\spnr} & \multicolumn{1}{|c|}{\spn} & \multicolumn{1}{|c|}{\spna} & \multicolumn{1}{|c|}{\spnr} \\
\hline 
nltcs & -4.82 & -7.33 & -5.36 & -16.26 & -8.61 & -9.01 & -15.92 & -8.68 & -9.13 \\
\hline 
msnbc & -4.3 & -11.63 & -5.31 & -19.33 & -6.37 & -8.13 & -18.13 & -8.43 & -10.19 \\
\hline 
kdd-2k & -2.0 & -5.8 & -2.06 & -14.53 & -8.07 & -11.86 & -13.95 & -11.03 & -13.17 \\
\hline 
plants & -9.53 & -11.68 & -10.31 & -25.22 & -16.25 & -16.91 & -26.76 & -17.23 & -18.12 \\
\hline 
jester & -40.61 & -42.53 & -41.47 & -49.22 & -45.27 & -44.75 & -47.35 & -46.08 & -45.67 \\
\hline 
audio & -31.44 & -34.72 & -32.66 & -42.69 & -37.9 & -37.0 & -40.54 & -39.53 & -38.02 \\
\hline 
netflix & -44.42 & -48.97 & -45.53 & -54.21 & -48.57 & -48.32 & -51.06 & -51.62 & -49.21 \\
\hline 
accidents & -26.94 & -27.72 & -26.98 & -39.79 & -31.94 & -32.62 & -41.54 & -33.27 & -34.5 \\
\hline 
retail & -5.69 & -7.59 & -6.15 & -25.86 & -17.51 & -17.02 & -22.07 & -17.01 & -17.01 \\
\hline 
pumsb-star & -23.19 & -24.64 & -23.99 & -43.75 & -32.55 & -34.08 & -42.26 & -33.08 & -34.21 \\
\hline 
dna & -77.25 & -78.17 & -77.68 & -84.76 & -82.12 & -82.94 & -83.37 & -81.79 & -82.05 \\
\hline 
kosarek & -4.46 & -6.97 & -5.48 & -27.11 & -19.35 & -20.93 & -25.96 & -19.22 & -20.24 \\
\hline 
msweb & -3.06 & -5.48 & -3.92 & -34.04 & -19.06 & -19.27 & -33.73 & -18.85 & -19.55 \\
\hline 
book & -26.92 & -28.96 & -27.92 & -46.6 & -41.22 & -42.33 & -44.88 & -41.13 & -41.56 \\
\hline 
each-movie & -37.31 & -41.44 & -38.97 & -99.8 & -59.92 & -74.58 & -98.01 & -68.56 & -74.29 \\
\hline 
web-kb & -127.08 & -128.45 & -128.3 & -154.04 & -139.85 & -142.59 & -149.67 & -141.09 & -143.73 \\
\hline 
reuters-52 & -71.59 & -74.59 & -73.55 & -122.84 & -97.1 & -97.41 & -114.77 & -97.36 & -101.06 \\
\hline 
20ng & -123.39 & -124.01 & -123.78 & -156.98 & -135.27 & -138.31 & -147.96 & -135.31 & -137.3 \\
\hline 
bbc & -163.8 & -173.16 & -167.35 & -188.43 & -191.88 & -184.94 & -186.22 & -190.87 & -184.84 \\
\hline 
ad & -23.71 & -24.4 & -23.42 & -55.86 & -47.25 & -46.76 & -52.2 & -45.29 & -47.16 \\
\hline 
\hline 
\end{tabular}
\end{center} 
\end{table*}

% \input{supplementary/sup-spn-cll-20-5}
\begin{table*}[t]
\begin{center} 
\caption{\label{tab:spn-cll-20-5} Predictive performance: Conditional log-likelihood scores given 20\% evidence for models having latent variables (SPNs). $h=5$: hamming distance threshold. \spn : SPN trained original training data, \spna: SPN trained on the adversarially generated training data by \spn, \spnr: SPN trained via joint maximization of standard and robust likelihoods. \test: original test data, \testa: adversarially perturbed \test by \spn, \testr: randomly perturbed \test by \spn.}

\begin{tabular}{ |c | c | c | c | c | c | c | c | c | c |}
\hline 
\hline 
 & \multicolumn{9}{|c|}{$h$=3} \\
\hline 
 & \multicolumn{3}{|c|}{\test}  & \multicolumn{3}{|c|}{\testa} & \multicolumn{3}{|c|}{\testr}  \\
\hline 
 \multicolumn{1}{|c|}{dataset} & \multicolumn{1}{|c|}{\spn} & \multicolumn{1}{|c|}{\spna} & \multicolumn{1}{|c|}{\spnr} & \multicolumn{1}{|c|}{\spn} & \multicolumn{1}{|c|}{\spna} & \multicolumn{1}{|c|}{\spnr} & \multicolumn{1}{|c|}{\spn} & \multicolumn{1}{|c|}{\spna} & \multicolumn{1}{|c|}{\spnr} \\
\hline 
nltcs & -4.82 & -8.73 & -5.32 & -19.68 & -9.17 & -8.73 & -19.03 & -9.12 & -8.87 \\
\hline 
msnbc & -4.3 & -16.06 & -5.27 & -24.25 & -8.22 & -10.16 & -23.32 & -9.58 & -11.39 \\
\hline 
kdd-2k & -2.0 & -9.36 & -2.06 & -26.11 & -19.42 & -14.01 & -23.75 & -19.19 & -17.72 \\
\hline 
plants & -9.53 & -13.23 & -10.41 & -35.37 & -19.72 & -20.35 & -37.29 & -21.06 & -21.67 \\
\hline 
jester & -40.61 & -44.77 & -41.87 & -53.32 & -47.42 & -46.55 & -50.96 & -49.29 & -48.2 \\
\hline 
audio & -31.44 & -37.21 & -32.96 & -47.6 & -39.75 & -39.14 & -45.07 & -42.98 & -40.87 \\
\hline 
netflix & -44.42 & -52.38 & -45.94 & -58.67 & -50.09 & -49.81 & -55.2 & -55.31 & -51.27 \\
\hline 
accidents & -26.94 & -29.53 & -27.58 & -48.09 & -35.41 & -35.91 & -50.09 & -37.08 & -37.81 \\
\hline 
retail & -5.69 & -9.28 & -6.23 & -36.67 & -23.23 & -24.73 & -32.32 & -23.2 & -24.32 \\
\hline 
pumsb-star & -23.19 & -26.06 & -24.32 & -56.5 & -37.55 & -38.93 & -54.96 & -37.67 & -38.94 \\
\hline 
dna & -77.25 & -78.53 & -77.76 & -88.43 & -84.26 & -85.87 & -86.82 & -83.92 & -84.71 \\
\hline 
kosarek & -4.46 & -8.84 & -5.18 & -40.85 & -27.77 & -26.74 & -38.96 & -27.42 & -27.15 \\
\hline 
msweb & -3.06 & -7.35 & -3.61 & -53.82 & -27.83 & -27.46 & -54.02 & -27.15 & -28.22 \\
\hline 
book & -26.92 & -30.95 & -28.37 & -57.12 & -49.27 & -47.55 & -55.25 & -49.49 & -48.52 \\
\hline 
each-movie & -37.31 & -47.36 & -39.49 & -133.41 & -73.05 & -81.14 & -125.87 & -87.9 & -80.96 \\
\hline 
web-kb & -127.08 & -129.56 & -128.68 & -168.32 & -149.25 & -148.94 & -162.17 & -148.36 & -150.72 \\
\hline 
reuters-52 & -71.59 & -76.98 & -73.72 & -146.3 & -101.11 & -107.57 & -135.4 & -107.2 & -112.31 \\
\hline 
20ng & -123.39 & -125.59 & -124.4 & -173.73 & -144.78 & -145.36 & -161.37 & -143.36 & -144.58 \\
\hline 
bbc & -163.8 & -169.66 & -166.95 & -203.88 & -196.03 & -193.77 & -200.83 & -195.91 & -194.38 \\
\hline 
ad & -23.71 & -26.12 & -23.73 & -74.72 & -60.34 & -59.47 & -71.48 & -58.33 & -59.55 \\
\hline 
\hline 
\end{tabular}
\end{center} 
\end{table*}


% \input{supplementary/sup-spn-cll-50-1}
\begin{table*}[t]
\begin{center} 
\caption{\label{tab:spn-cll-50-1} Predictive performance: Conditional log-likelihood scores given 50\% evidence for models having latent variables (SPNs). $h=1$: hamming distance threshold. \spn : SPN trained original training data, \spna: SPN trained on the adversarially generated training data by \spn, \spnr: SPN trained via joint maximization of standard and robust likelihoods. \test: original test data, \testa: adversarially perturbed \test by \spn, \testr: randomly perturbed \test by \spn.}

\begin{tabular}{ |c | c | c | c | c | c | c | c | c | c |}
\hline 
\hline 
 & \multicolumn{9}{|c|}{$h$=1} \\
\hline 
 & \multicolumn{3}{|c|}{\test}  & \multicolumn{3}{|c|}{\testa} & \multicolumn{3}{|c|}{\testr}  \\
\hline 
 \multicolumn{1}{|c|}{dataset} & \multicolumn{1}{|c|}{\spn} & \multicolumn{1}{|c|}{\spna} & \multicolumn{1}{|c|}{\spnr} & \multicolumn{1}{|c|}{\spn} & \multicolumn{1}{|c|}{\spna} & \multicolumn{1}{|c|}{\spnr} & \multicolumn{1}{|c|}{\spn} & \multicolumn{1}{|c|}{\spna} & \multicolumn{1}{|c|}{\spnr} \\
\hline 
nltcs & -2.56 & -3.17 & -2.85 & -7.89 & -4.56 & -4.87 & -6.78 & -4.39 & -4.72 \\
\hline 
msnbc & -2.24 & -4.8 & -3.16 & -8.71 & -5.29 & -4.98 & -7.99 & -5.75 & -5.33 \\
\hline 
kdd-2k & -1.06 & -1.31 & -1.1 & -1.3 & -2.21 & -1.74 & -2.33 & -2.86 & -2.45 \\
\hline 
plants & -5.6 & -5.93 & -5.74 & -9.82 & -7.91 & -7.74 & -9.54 & -7.83 & -8.14 \\
\hline 
jester & -25.6 & -25.81 & -25.75 & -27.92 & -26.79 & -26.63 & -27.18 & -26.76 & -26.82 \\
\hline 
audio & -19.15 & -19.74 & -19.31 & -22.12 & -20.74 & -20.67 & -21.27 & -21.0 & -20.92 \\
\hline 
netflix & -28.02 & -28.31 & -28.17 & -29.68 & -29.02 & -28.67 & -29.22 & -29.38 & -28.95 \\
\hline 
accidents & -13.48 & -13.51 & -13.49 & -16.74 & -15.0 & -15.19 & -16.88 & -15.13 & -15.76 \\
\hline 
retail & -3.07 & -3.52 & -3.27 & -10.64 & -6.67 & -8.24 & -7.57 & -6.21 & -6.72 \\
\hline 
pumsb-star & -15.95 & -16.11 & -15.92 & -19.44 & -17.86 & -17.92 & -19.41 & -18.34 & -18.3 \\
\hline 
dna & -49.23 & -49.49 & -49.45 & -50.82 & -50.36 & -50.36 & -50.48 & -50.26 & -50.24 \\
\hline 
kosarek & -2.34 & -2.86 & -2.48 & -8.84 & -8.32 & -7.53 & -8.44 & -7.17 & -7.34 \\
\hline 
msweb & -0.83 & -1.47 & -1.15 & -11.34 & -6.63 & -7.71 & -10.77 & -6.73 & -7.41 \\
\hline 
book & -16.5 & -16.97 & -16.89 & -21.93 & -19.63 & -19.65 & -20.81 & -20.06 & -19.95 \\
\hline 
each-movie & -22.12 & -22.84 & -22.58 & -39.83 & -27.53 & -36.07 & -37.65 & -33.92 & -34.14 \\
\hline 
web-kb & -76.43 & -76.86 & -76.99 & -83.61 & -81.22 & -80.04 & -82.24 & -80.68 & -80.86 \\
\hline 
reuters-52 & -44.07 & -44.96 & -44.95 & -50.89 & -50.21 & -48.77 & -54.07 & -51.9 & -52.64 \\
\hline 
20ng & -76.85 & -76.78 & -77.1 & -86.94 & -79.57 & -81.27 & -83.33 & -79.63 & -80.7 \\
\hline 
bbc & -84.91 & -94.4 & -86.43 & -92.01 & -102.2 & -91.75 & -91.25 & -101.09 & -92.03 \\
\hline 
ad & -15.12 & -19.16 & -17.2 & -18.93 & -26.53 & -20.19 & -20.52 & -24.03 & -22.58 \\
\hline 
\hline 
\end{tabular}
\end{center} 
\end{table*}

% \input{supplementary/sup-spn-cll-50-3}
\begin{table*}[t]
\begin{center} 
\caption{\label{tab:spn-cll-50-3} Predictive performance: Conditional log-likelihood scores given 50\% evidence for models having latent variables (SPNs). $h=3$: hamming distance threshold. \spn : SPN trained original training data, \spna: SPN trained on the adversarially generated training data by \spn, \spnr: SPN trained via joint maximization of standard and robust likelihoods. \test: original test data, \testa: adversarially perturbed \test by \spn, \testr: randomly perturbed \test by \spn.}
\begin{tabular}{ |c | c | c | c | c | c | c | c | c | c |}
\hline 
\hline 
 & \multicolumn{9}{|c|}{$h$=3} \\
\hline 
 & \multicolumn{3}{|c|}{\test}  & \multicolumn{3}{|c|}{\testa} & \multicolumn{3}{|c|}{\testr}  \\
\hline 
 \multicolumn{1}{|c|}{dataset} & \multicolumn{1}{|c|}{\spn} & \multicolumn{1}{|c|}{\spna} & \multicolumn{1}{|c|}{\spnr} & \multicolumn{1}{|c|}{\spn} & \multicolumn{1}{|c|}{\spna} & \multicolumn{1}{|c|}{\spnr} & \multicolumn{1}{|c|}{\spn} & \multicolumn{1}{|c|}{\spna} & \multicolumn{1}{|c|}{\spnr} \\
\hline 
nltcs & -2.56 & -4.32 & -2.94 & -13.01 & -5.49 & -6.06 & -12.12 & -5.49 & -5.94 \\
\hline 
msnbc & -2.24 & -9.05 & -2.9 & -17.18 & -3.67 & -5.67 & -15.34 & -5.41 & -7.34 \\
\hline 
kdd-2k & -1.06 & -4.76 & -1.1 & -11.25 & -6.56 & -10.03 & -11.32 & -8.49 & -10.46 \\
\hline 
plants & -5.6 & -7.01 & -6.08 & -17.94 & -10.06 & -11.25 & -17.98 & -10.35 & -11.68 \\
\hline 
jester & -25.6 & -26.9 & -26.1 & -31.56 & -28.46 & -28.11 & -29.98 & -28.84 & -28.58 \\
\hline 
audio & -19.15 & -21.16 & -19.94 & -26.21 & -23.14 & -22.41 & -24.88 & -24.58 & -23.3 \\
\hline 
netflix & -28.02 & -29.52 & -28.37 & -32.36 & -29.93 & -29.65 & -31.83 & -31.45 & -30.39 \\
\hline 
accidents & -13.48 & -14.13 & -13.51 & -23.31 & -17.58 & -17.89 & -23.97 & -18.21 & -19.11 \\
\hline 
retail & -3.07 & -4.48 & -3.48 & -23.06 & -14.27 & -14.23 & -17.01 & -12.81 & -12.88 \\
\hline 
pumsb-star & -15.95 & -16.64 & -16.41 & -26.94 & -20.62 & -21.5 & -26.3 & -20.72 & -21.77 \\
\hline 
dna & -49.23 & -49.55 & -49.41 & -53.29 & -51.9 & -51.73 & -52.62 & -51.63 & -51.46 \\
\hline 
kosarek & -2.34 & -4.14 & -3.1 & -19.65 & -15.4 & -14.56 & -20.4 & -14.3 & -15.15 \\
\hline 
msweb & -0.83 & -2.66 & -1.6 & -31.39 & -14.53 & -16.69 & -30.52 & -14.95 & -16.73 \\
\hline 
book & -16.5 & -18.16 & -17.01 & -30.99 & -27.96 & -27.28 & -28.38 & -26.53 & -25.61 \\
\hline 
each-movie & -22.12 & -25.81 & -23.24 & -73.07 & -34.55 & -51.86 & -65.35 & -44.54 & -48.86 \\
\hline 
web-kb & -76.43 & -77.5 & -77.64 & -95.82 & -86.15 & -87.43 & -92.33 & -86.38 & -88.21 \\
\hline 
reuters-52 & -44.07 & -46.59 & -45.46 & -69.87 & -58.89 & -56.1 & -70.16 & -60.6 & -62.06 \\
\hline 
20ng & -76.85 & -77.2 & -77.19 & -100.51 & -84.28 & -86.06 & -94.11 & -84.22 & -85.65 \\
\hline 
bbc & -84.91 & -90.92 & -87.01 & -106.37 & -107.94 & -102.25 & -103.83 & -105.91 & -101.66 \\
\hline 
ad & -15.12 & -15.75 & -15.6 & -29.85 & -33.5 & -25.05 & -32.42 & -28.21 & -30.06 \\
\hline 
\hline 
\end{tabular}
\end{center} 
\end{table*}


% \input{supplementary/sup-spn-cll-50-5}
\begin{table*}[t]
\begin{center} 
\caption{\label{tab:spn-cll-50-5} Predictive performance: Conditional log-likelihood scores given 50\% evidence for models having latent variables (SPNs). $h=5$: hamming distance threshold. \spn : SPN trained original training data, \spna: SPN trained on the adversarially generated training data by \spn, \spnr: SPN trained via joint maximization of standard and robust likelihoods. \test: original test data, \testa: adversarially perturbed \test by \spn, \testr: randomly perturbed \test by \spn.}
\begin{tabular}{ |c | c | c | c | c | c | c | c | c | c |}
\hline 
\hline 
 & \multicolumn{9}{|c|}{$h$=3} \\
\hline 
 & \multicolumn{3}{|c|}{\test}  & \multicolumn{3}{|c|}{\testa} & \multicolumn{3}{|c|}{\testr}  \\
\hline 
 \multicolumn{1}{|c|}{dataset} & \multicolumn{1}{|c|}{\spn} & \multicolumn{1}{|c|}{\spna} & \multicolumn{1}{|c|}{\spnr} & \multicolumn{1}{|c|}{\spn} & \multicolumn{1}{|c|}{\spna} & \multicolumn{1}{|c|}{\spnr} & \multicolumn{1}{|c|}{\spn} & \multicolumn{1}{|c|}{\spna} & \multicolumn{1}{|c|}{\spnr} \\
\hline 
nltcs & -2.56 & -5.29 & -2.87 & -14.4 & -5.78 & -5.21 & -13.91 & -5.73 & -5.35 \\
\hline 
msnbc & -2.24 & -13.11 & -2.67 & -20.65 & -4.01 & -6.61 & -19.45 & -5.55 & -7.83 \\
\hline 
kdd-2k & -1.06 & -8.19 & -1.1 & -22.8 & -17.38 & -11.77 & -20.38 & -16.85 & -14.91 \\
\hline 
plants & -5.6 & -7.97 & -6.16 & -25.21 & -12.33 & -13.38 & -25.56 & -12.76 & -13.58 \\
\hline 
jester & -25.6 & -28.03 & -26.31 & -34.35 & -29.77 & -29.1 & -32.25 & -30.75 & -30.24 \\
\hline 
audio & -19.15 & -23.16 & -20.1 & -29.47 & -24.32 & -23.95 & -28.22 & -26.71 & -25.16 \\
\hline 
netflix & -28.02 & -30.14 & -28.62 & -34.73 & -30.78 & -30.58 & -33.69 & -33.12 & -31.73 \\
\hline 
accidents & -13.48 & -15.36 & -14.07 & -30.12 & -20.18 & -20.7 & -31.53 & -21.14 & -21.81 \\
\hline 
retail & -3.07 & -5.82 & -3.42 & -33.69 & -19.6 & -21.71 & -27.05 & -18.16 & -19.54 \\
\hline 
pumsb-star & -15.95 & -17.4 & -16.47 & -33.81 & -23.28 & -24.13 & -33.01 & -23.63 & -23.99 \\
\hline 
dna & -49.23 & -49.75 & -49.51 & -55.38 & -53.21 & -53.36 & -54.65 & -52.9 & -52.95 \\
\hline 
kosarek & -2.34 & -5.21 & -2.8 & -29.97 & -21.86 & -18.73 & -30.42 & -21.18 & -20.41 \\
\hline 
msweb & -0.83 & -4.01 & -1.23 & -50.77 & -22.66 & -24.53 & -50.32 & -22.4 & -24.97 \\
\hline 
book & -16.5 & -19.46 & -17.44 & -36.13 & -32.47 & -29.06 & -34.98 & -32.01 & -29.79 \\
\hline 
each-movie & -22.12 & -30.24 & -23.37 & -95.59 & -43.28 & -55.39 & -86.89 & -60.39 & -53.87 \\
\hline 
web-kb & -76.43 & -78.31 & -78.03 & -107.26 & -93.64 & -92.04 & -101.44 & -91.99 & -93.05 \\
\hline 
reuters-52 & -44.07 & -48.62 & -45.5 & -84.69 & -63.55 & -64.25 & -82.38 & -66.89 & -69.03 \\
\hline 
20ng & -76.85 & -78.17 & -77.53 & -110.89 & -90.77 & -89.97 & -103.14 & -89.41 & -90.15 \\
\hline 
bbc & -84.91 & -88.91 & -87.21 & -119.99 & -112.43 & -110.49 & -115.92 & -110.94 & -110.37 \\
\hline 
ad & -15.12 & -16.56 & -15.54 & -41.19 & -40.94 & -32.16 & -44.82 & -36.33 & -37.66 \\
\hline 
\hline 
\end{tabular}
\end{center} 
\end{table*}


% \input{supplementary/sup-spn-cll-80-1}
\begin{table*}[t]
\begin{center} 
\caption{\label{tab:spn-cll-80-1} Predictive performance: Conditional log-likelihood scores given 80\% evidence for models having latent variables (SPNs). $h=1$: hamming distance threshold. \spn : SPN trained original training data, \spna: SPN trained on the adversarially generated training data by \spn, \spnr: SPN trained via joint maximization of standard and robust likelihoods. \test: original test data, \testa: adversarially perturbed \test by \spn, \testr: randomly perturbed \test by \spn.}
\begin{tabular}{ |c | c | c | c | c | c | c | c | c | c |}
\hline 
\hline 
 & \multicolumn{9}{|c|}{$h$=1} \\
\hline 
 & \multicolumn{3}{|c|}{\test}  & \multicolumn{3}{|c|}{\testa} & \multicolumn{3}{|c|}{\testr}  \\
\hline 
 \multicolumn{1}{|c|}{dataset} & \multicolumn{1}{|c|}{\spn} & \multicolumn{1}{|c|}{\spna} & \multicolumn{1}{|c|}{\spnr} & \multicolumn{1}{|c|}{\spn} & \multicolumn{1}{|c|}{\spna} & \multicolumn{1}{|c|}{\spnr} & \multicolumn{1}{|c|}{\spn} & \multicolumn{1}{|c|}{\spna} & \multicolumn{1}{|c|}{\spnr} \\
\hline 
nltcs & -1.06 & -1.46 & -1.25 & -3.59 & -2.0 & -2.08 & -3.29 & -2.02 & -1.97 \\
\hline 
msnbc & -0.63 & -3.0 & -1.44 & -5.77 & -2.63 & -2.15 & -5.18 & -3.08 & -2.65 \\
\hline 
kdd-2k & -0.37 & -0.4 & -0.38 & -0.43 & -1.0 & -0.6 & -0.51 & -0.75 & -0.61 \\
\hline 
plants & -2.3 & -2.4 & -2.31 & -4.26 & -2.89 & -3.21 & -3.88 & -2.98 & -3.13 \\
\hline 
jester & -10.42 & -10.45 & -10.43 & -11.15 & -10.71 & -10.67 & -11.02 & -10.84 & -10.79 \\
\hline 
audio & -7.71 & -7.98 & -7.78 & -9.2 & -8.38 & -8.45 & -8.61 & -8.57 & -8.4 \\
\hline 
netflix & -11.14 & -11.25 & -11.21 & -12.07 & -11.68 & -11.47 & -11.68 & -11.71 & -11.56 \\
\hline 
accidents & -4.12 & -4.14 & -4.2 & -6.16 & -5.12 & -5.3 & -6.16 & -4.98 & -5.38 \\
\hline 
retail & -1.12 & -1.27 & -1.17 & -1.44 & -1.4 & -1.36 & -2.93 & -2.72 & -2.91 \\
\hline 
pumsb-star & -4.47 & -4.49 & -4.44 & -6.29 & -5.45 & -5.55 & -6.38 & -5.74 & -5.69 \\
\hline 
dna & -20.04 & -20.1 & -20.17 & -20.41 & -20.2 & -20.27 & -20.39 & -20.28 & -20.36 \\
\hline 
kosarek & -0.83 & -1.13 & -0.89 & -4.84 & -4.35 & -4.0 & -4.3 & -3.88 & -3.59 \\
\hline 
msweb & -0.16 & -0.48 & -0.35 & -8.77 & -4.58 & -5.73 & -7.84 & -4.2 & -5.26 \\
\hline 
book & -7.0 & -7.06 & -7.06 & -7.8 & -7.52 & -7.37 & -8.17 & -7.77 & -7.89 \\
\hline 
each-movie & -7.57 & -7.99 & -7.92 & -10.51 & -9.69 & -10.34 & -11.37 & -12.37 & -11.45 \\
\hline 
web-kb & -28.96 & -29.16 & -29.12 & -31.7 & -31.5 & -30.4 & -31.56 & -30.72 & -31.02 \\
\hline 
reuters-52 & -16.46 & -16.63 & -16.71 & -18.01 & -18.5 & -18.01 & -20.83 & -19.67 & -20.37 \\
\hline 
20ng & -31.39 & -31.37 & -31.52 & -35.9 & -32.19 & -33.32 & -34.31 & -32.54 & -33.02 \\
\hline 
bbc & -29.27 & -33.32 & -30.03 & -33.38 & -37.67 & -33.24 & -32.7 & -37.2 & -33.18 \\
\hline 
ad & -7.52 & -8.85 & -8.33 & -8.59 & -10.63 & -9.07 & -9.06 & -10.97 & -10.02 \\
\hline 
\hline 
\end{tabular}
\end{center} 
\end{table*}


% \input{supplementary/sup-spn-cll-80-3}
\begin{table*}[t]
\begin{center} 
\caption{\label{tab:spn-cll-80-3} Predictive performance: Conditional log-likelihood scores given 80\% evidence for models having latent variables (SPNs). $h=3$: hamming distance threshold. \spn : SPN trained original training data, \spna: SPN trained on the adversarially generated training data by \spn, \spnr: SPN trained via joint maximization of standard and robust likelihoods. \test: original test data, \testa: adversarially perturbed \test by \spn, \testr: randomly perturbed \test by \spn.}
\begin{tabular}{ |c | c | c | c | c | c | c | c | c | c |}
\hline 
\hline 
 & \multicolumn{9}{|c|}{$h$=3} \\
\hline 
 & \multicolumn{3}{|c|}{\test}  & \multicolumn{3}{|c|}{\testa} & \multicolumn{3}{|c|}{\testr}  \\
\hline 
 \multicolumn{1}{|c|}{dataset} & \multicolumn{1}{|c|}{\spn} & \multicolumn{1}{|c|}{\spna} & \multicolumn{1}{|c|}{\spnr} & \multicolumn{1}{|c|}{\spn} & \multicolumn{1}{|c|}{\spna} & \multicolumn{1}{|c|}{\spnr} & \multicolumn{1}{|c|}{\spn} & \multicolumn{1}{|c|}{\spna} & \multicolumn{1}{|c|}{\spnr} \\
\hline 
nltcs & -1.06 & -2.07 & -1.25 & -6.94 & -2.79 & -3.0 & -6.58 & -2.83 & -3.03 \\
\hline 
msnbc & -0.63 & -6.29 & -1.01 & -12.02 & -1.4 & -2.35 & -10.58 & -2.66 & -4.07 \\
\hline 
kdd-2k & -0.37 & -2.36 & -0.38 & -1.4 & -2.26 & -2.52 & -3.72 & -3.77 & -3.55 \\
\hline 
plants & -2.3 & -2.83 & -2.44 & -7.34 & -3.59 & -4.49 & -7.23 & -3.91 & -4.7 \\
\hline 
jester & -10.42 & -10.73 & -10.55 & -12.43 & -11.17 & -11.08 & -12.04 & -11.53 & -11.38 \\
\hline 
audio & -7.71 & -8.23 & -8.0 & -11.05 & -9.51 & -9.01 & -10.23 & -9.85 & -9.43 \\
\hline 
netflix & -11.14 & -12.12 & -11.31 & -13.5 & -12.09 & -11.97 & -12.9 & -12.68 & -12.2 \\
\hline 
accidents & -4.12 & -4.59 & -4.2 & -10.87 & -6.91 & -7.26 & -10.48 & -6.91 & -7.64 \\
\hline 
retail & -1.12 & -1.66 & -1.3 & -7.61 & -3.57 & -5.26 & -8.92 & -5.84 & -6.14 \\
\hline 
pumsb-star & -4.47 & -4.83 & -4.64 & -10.19 & -7.31 & -7.39 & -10.07 & -7.29 & -7.6 \\
\hline 
dna & -20.04 & -20.09 & -20.12 & -21.01 & -20.48 & -20.49 & -21.02 & -20.63 & -20.65 \\
\hline 
kosarek & -0.83 & -1.81 & -1.18 & -11.25 & -8.95 & -8.04 & -10.63 & -7.81 & -7.6 \\
\hline 
msweb & -0.16 & -0.94 & -0.56 & -27.1 & -10.06 & -13.72 & -23.83 & -10.56 & -12.36 \\
\hline 
book & -7.0 & -7.76 & -7.24 & -9.72 & -10.26 & -8.86 & -10.2 & -9.4 & -9.61 \\
\hline 
each-movie & -7.57 & -9.14 & -8.16 & -16.38 & -11.65 & -12.92 & -21.84 & -17.88 & -16.36 \\
\hline 
web-kb & -28.96 & -29.57 & -29.71 & -37.6 & -33.55 & -34.28 & -36.3 & -32.86 & -34.51 \\
\hline 
reuters-52 & -16.46 & -17.65 & -16.82 & -25.11 & -23.54 & -21.19 & -27.65 & -24.78 & -24.15 \\
\hline 
20ng & -31.39 & -31.41 & -31.53 & -43.7 & -34.65 & -35.64 & -39.36 & -34.47 & -35.12 \\
\hline 
bbc & -29.27 & -31.5 & -30.22 & -42.68 & -42.23 & -39.85 & -40.63 & -40.53 & -38.2 \\
\hline 
ad & -7.52 & -7.55 & -7.66 & -12.02 & -11.64 & -10.91 & -13.44 & -11.42 & -12.45 \\
\hline 
\hline 
\end{tabular}
\end{center} 
\end{table*}


% \input{supplementary/sup-spn-cll-80-5}

\begin{table*}[t]
\begin{center} 
\caption{\label{tab:spn-cll-80-5} Predictive performance: Conditional log-likelihood scores given 80\% evidence for models having latent variables (SPNs). $h=5$: hamming distance threshold. \spn : SPN trained original training data, \spna: SPN trained on the adversarially generated training data by \spn, \spnr: SPN trained via joint maximization of standard and robust likelihoods. \test: original test data, \testa: adversarially perturbed \test by \spn, \testr: randomly perturbed \test by \spn.}
\begin{tabular}{ |c | c | c | c | c | c | c | c | c | c |}
\hline 
\hline 
 & \multicolumn{9}{|c|}{$h$=3} \\
\hline 
 & \multicolumn{3}{|c|}{\test}  & \multicolumn{3}{|c|}{\testa} & \multicolumn{3}{|c|}{\testr}  \\
\hline 
 \multicolumn{1}{|c|}{dataset} & \multicolumn{1}{|c|}{\spn} & \multicolumn{1}{|c|}{\spna} & \multicolumn{1}{|c|}{\spnr} & \multicolumn{1}{|c|}{\spn} & \multicolumn{1}{|c|}{\spna} & \multicolumn{1}{|c|}{\spnr} & \multicolumn{1}{|c|}{\spn} & \multicolumn{1}{|c|}{\spna} & \multicolumn{1}{|c|}{\spnr} \\
\hline 
nltcs & -1.06 & -2.66 & -1.22 & -7.96 & -2.97 & -2.57 & -7.87 & -2.92 & -2.66 \\
\hline 
msnbc & -0.63 & -8.96 & -0.81 & -13.45 & -0.94 & -1.47 & -12.56 & -1.91 & -2.94 \\
\hline 
kdd-2k & -0.37 & -0.95 & -0.38 & -11.59 & -7.46 & -4.15 & -7.52 & -5.67 & -4.96 \\
\hline 
plants & -2.3 & -3.15 & -2.53 & -10.48 & -4.32 & -5.45 & -10.16 & -4.89 & -5.33 \\
\hline 
jester & -10.42 & -11.17 & -10.6 & -13.62 & -11.63 & -11.61 & -12.92 & -12.26 & -12.02 \\
\hline 
audio & -7.71 & -9.08 & -8.1 & -12.52 & -9.87 & -9.69 & -11.56 & -10.69 & -10.21 \\
\hline 
netflix & -11.14 & -12.63 & -11.41 & -14.66 & -12.42 & -12.37 & -13.73 & -13.32 & -12.68 \\
\hline 
accidents & -4.12 & -5.2 & -4.47 & -15.82 & -8.5 & -9.24 & -15.38 & -8.66 & -9.02 \\
\hline 
retail & -1.12 & -2.31 & -1.25 & -14.79 & -7.74 & -10.32 & -13.35 & -7.88 & -9.65 \\
\hline 
pumsb-star & -4.47 & -5.3 & -4.79 & -13.93 & -8.91 & -9.02 & -13.25 & -8.89 & -8.88 \\
\hline 
dna & -20.04 & -20.06 & -20.13 & -21.6 & -20.8 & -20.73 & -21.68 & -21.02 & -20.92 \\
\hline 
kosarek & -0.83 & -2.08 & -0.89 & -16.48 & -12.97 & -9.58 & -15.96 & -11.5 & -9.9 \\
\hline 
msweb & -0.16 & -1.59 & -0.27 & -44.68 & -16.61 & -20.21 & -39.92 & -15.73 & -18.18 \\
\hline 
book & -7.0 & -7.4 & -7.18 & -11.73 & -11.75 & -9.95 & -12.97 & -10.9 & -11.17 \\
\hline 
each-movie & -7.57 & -12.06 & -8.1 & -19.34 & -14.2 & -13.84 & -26.57 & -23.63 & -18.01 \\
\hline 
web-kb & -28.96 & -29.61 & -29.65 & -43.85 & -38.37 & -36.34 & -39.81 & -35.76 & -36.33 \\
\hline 
reuters-52 & -16.46 & -18.19 & -17.29 & -32.11 & -25.45 & -24.16 & -33.61 & -27.01 & -27.33 \\
\hline 
20ng & -31.39 & -32.19 & -31.71 & -49.79 & -37.22 & -38.25 & -43.65 & -36.84 & -37.17 \\
\hline 
bbc & -29.27 & -31.04 & -30.52 & -51.66 & -46.86 & -45.07 & -47.42 & -44.03 & -43.65 \\
\hline 
ad & -7.52 & -7.98 & -7.64 & -16.45 & -16.24 & -13.72 & -17.31 & -14.5 & -15.59 \\
\hline 
\hline 
\end{tabular}
\end{center} 
\end{table*}


% \input{supplementary/spn-weaker-ll}

\begin{table*}[t]
\begin{center} 

\caption{\label{tab:spn-weaker-ll} Generative performances (test set log-likelihood scores) of models with latent variables. $h\in\{1,2,3\}$: uncertainty set sizes. \spn : SPN learnt from original training data, \spna: SPN learnt from adversarially generated training data by \spn, \spnr: SPN learnt from data randomly corrupted by \spn. W-1: test data corrupted by a weaker model under uncertainty set of size 1, W-3:test data corrupted by a weaker model under uncertainty set of size 3, W-5:test data corrupted by a weaker model under uncertainty set of size 5.} 

\begin{tabular}{ |c | c | c | c | c | c | c | c | c | c |}
\hline 
\hline 
 & \multicolumn{3}{|c|}{W-1}  & \multicolumn{3}{|c|}{W-3} & \multicolumn{3}{|c|}{W-5}  \\
\hline 
 \multicolumn{1}{|c|}{dataset} & \multicolumn{1}{|c|}{\spn} & \multicolumn{1}{|c|}{\spna} & \multicolumn{1}{|c|}{\spnr} & \multicolumn{1}{|c|}{\spn} & \multicolumn{1}{|c|}{\spna} & \multicolumn{1}{|c|}{\spnr} & \multicolumn{1}{|c|}{\spn} & \multicolumn{1}{|c|}{\spna} & \multicolumn{1}{|c|}{\spnr} \\
\hline 
nltcs & -9.69 & -8.42 & -8.48 & -15.42 & -10.54 & -11.3 & -19.09 & -11.28 & -12.0 \\
\hline 
msnbc & -12.36 & -8.18 & -8.2 & -20.41 & -8.87 & -10.46 & -24.93 & -12.11 & -13.9 \\
\hline 
kdd-2k & -10.93 & -6.9 & -5.82 & -20.54 & -20.29 & -17.02 & -27.1 & -25.27 & -27.64 \\
\hline 
plants & -21.19 & -17.83 & -18.2 & -34.13 & -23.76 & -24.77 & -42.97 & -28.18 & -29.37 \\
\hline 
jester & -54.82 & -54.9 & -54.89 & -58.57 & -58.78 & -58.28 & -61.86 & -62.12 & -60.87 \\
\hline 
audio & -43.35 & -43.14 & -42.93 & -48.68 & -46.97 & -47.36 & -53.32 & -52.81 & -50.44 \\
\hline 
netflix & -58.87 & -59.68 & -58.95 & -63.18 & -64.71 & -62.17 & -67.17 & -66.98 & -64.35 \\
\hline 
accidents & -40.24 & -38.81 & -39.08 & -47.83 & -43.48 & -44.14 & -56.2 & -48.05 & -48.63 \\
\hline 
retail & -17.7 & -14.64 & -16.13 & -29.54 & -22.0 & -22.73 & -36.53 & -29.21 & -29.31 \\
\hline 
pumsb-star & -38.26 & -36.26 & -36.7 & -52.94 & -43.54 & -45.09 & -66.47 & -49.78 & -51.31 \\
\hline 
dna & -98.92 & -98.86 & -99.18 & -101.79 & -101.71 & -101.97 & -104.53 & -104.33 & -104.55 \\
\hline 
kosarek & -18.21 & -16.66 & -13.43 & -31.71 & -27.27 & -26.11 & -44.17 & -34.0 & -34.47 \\
\hline 
msweb & -20.27 & -17.18 & -16.84 & -41.71 & -25.84 & -25.81 & -61.93 & -34.48 & -38.68 \\
\hline 
book & -39.56 & -41.07 & -40.5 & -50.69 & -50.62 & -51.53 & -59.94 & -57.4 & -56.0 \\
\hline 
each-movie & -75.91 & -70.36 & -68.64 & -118.83 & -89.22 & -91.61 & -154.37 & -101.68 & -107.71 \\
\hline 
web-kb & -166.85 & -164.88 & -165.02 & -178.66 & -171.85 & -173.59 & -189.35 & -183.35 & -179.67 \\
\hline 
reuters-52 & -97.31 & -98.23 & -97.34 & -118.44 & -117.15 & -114.57 & -136.28 & -123.15 & -124.98 \\
\hline 
20ng & -160.13 & -159.35 & -160.23 & -171.4 & -168.6 & -169.32 & -182.56 & -176.38 & -173.93 \\
\hline 
bbc & -256.84 & -273.79 & -259.74 & -266.79 & -275.87 & -270.09 & -279.54 & -279.13 & -275.67 \\
\hline 
ad & -41.16 & -51.73 & -45.22 & -59.85 & -57.71 & -60.95 & -77.95 & -75.32 & -72.96 \\
\hline 
\hline 
\end{tabular}
\end{center} 
\end{table*}


\end{document}
