%%
%% This is file `sample-authordraft.tex',
%% generated with the docstrip utility.
%%
%% The original source files were:
%%
%% samples.dtx  (with options: `authordraft')
%% 
%% IMPORTANT NOTICE:
%% 
%% For the copyright see the source file.
%% 
%% Any modified versions of this file must be renamed
%% with new filenames distinct from sample-authordraft.tex.
%% 
%% For distribution of the original source see the terms
%% for copying and modification in the file samples.dtx.
%% 
%% This generated file may be distributed as long as the
%% original source files, as listed above, are part of the
%% same distribution. (The sources need not necessarily be
%% in the same archive or directory.)
%%
%% Commands for TeXCount
%TC:macro \cite [option:text,text]
%TC:macro \citep [option:text,text]
%TC:macro \citet [option:text,text]
%TC:envir table 0 1
%TC:envir table* 0 1
%TC:envir tabular [ignore] word
%TC:envir displaymath 0 word
%TC:envir math 0 word
%TC:envir comment 0 0
%%
%%
%% The first command in your LaTeX source must be the \documentclass command.
\documentclass[sigconf,authordraft]{acmart}
%% NOTE that a single column version may required for 
%% submission and peer review. This can be done by changing
%% the \doucmentclass[...]{acmart} in this template to 
%% \documentclass[manuscript,screen]{acmart}
%% 
%% To ensure 100% compatibility, please check the white list of
%% approved LaTeX packages to be used with the Master Article Template at
%% https://www.acm.org/publications/taps/whitelist-of-latex-packages 
%% before creating your document. The white list page provides 
%% information on how to submit additional LaTeX packages for 
%% review and adoption.
%% Fonts used in the template cannot be substituted; margin 
%% adjustments are not allowed.

%%
%% \BibTeX command to typeset BibTeX logo in the docs
\AtBeginDocument{%
  \providecommand\BibTeX{{%
    \normalfont B\kern-0.5em{\scshape i\kern-0.25em b}\kern-0.8em\TeX}}}

\settopmatter{printacmref=false} % Removes citation information below abstract
\renewcommand\footnotetextcopyrightpermission[1]{} % removes footnote with conference information in first column
\pagestyle{plain} % removes running headers 
% \setcopyright{none}


\copyrightyear{2024}
\acmYear{2024}
\setcopyright{acmlicensed}
\acmConference[MM '24] {Proceedings of the 32nd ACM International Conference on Multimedia}{October 28--November 1, 2024}{Melbourne, VIC, Australia.}
\acmBooktitle{Proceedings of the 32nd ACM International Conference on Multimedia (MM '24), October 28--November 1, 2024, Melbourne, VIC, Australia}
\acmISBN{979-8-4007-0686-8/24/10}
% \acmDOI{10.1145/XXXXXX.XXXXXX}

%% These commands are for a PROCEEDINGS abstract or paper.
% \acmConference[Conference acronym 'XX]{Make sure to enter the correct
%   conference title from your rights confirmation emai}{June 03--05,
%   2018}{Woodstock, NY}
%
%  Uncomment \acmBooktitle if th title of the proceedings is different
%  from ``Proceedings of ...''!
%
%\acmBooktitle{Woodstock '18: ACM Symposium on Neural Gaze Detection,
%  June 03--05, 2018, Woodstock, NY} 
% \acmISBN{978-1-4503-XXXX-X/18/06}


%%
%% Submission ID.
%% Use this when submitting an article to a sponsored event. You'll
%% receive a unique submission ID from the organizers
%% of the event, and this ID should be used as the parameter to this command.
% \acmSubmissionID{xxxx}

%%
%% For managing citations, it is recommended to use bibliography
%% files in BibTeX format.
%%
%% You can then either use BibTeX with the ACM-Reference-Format style,
%% or BibLaTeX with the acmnumeric or acmauthoryear sytles, that include
%% support for advanced citation of software artefact from the
%% biblatex-software package, also separately available on CTAN.
%%
%% Look at the sample-*-biblatex.tex files for templates showcasing
%% the biblatex styles.
%%

%%
%% For managing citations, it is recommended to use bibliography
%% files in BibTeX format.
%%
%% You can then either use BibTeX with the ACM-Reference-Format style,
%% or BibLaTeX with the acmnumeric or acmauthoryear sytles, that include
%% support for advanced citation of software artefact from the
%% biblatex-software package, also separately available on CTAN.
%%
%% Look at the sample-*-biblatex.tex files for templates showcasing
%% the biblatex styles.
%%

%%
%% The majority of ACM publications use numbered citations and
%% references.  The command \citestyle{authoryear} switches to the
%% "author year" style.
%%
%% If you are preparing content for an event
%% sponsored by ACM SIGGRAPH, you must use the "author year" style of
%% citations and references.
%% Uncommenting
%% the next command will enable that style.
%%\citestyle{acmauthoryear}

%%
%% end of the preamble, start of the body of the document source.
\begin{document}

%%
%% The "title" command has an optional parameter,
%% allowing the author to define a "short title" to be used in page headers.
\title{Supplementary Materials}

%%
%% The "author" command and its associated commands are used to define
%% the authors and their affiliations.
%% Of note is the shared affiliation of the first two authors, and the
%% "authornote" and "authornotemark" commands
%% used to denote shared contribution to the research.
% \author{Ben Trovato}
% \authornote{Both authors contributed equally to this research.}
% \email{trovato@corporation.com}
% \orcid{1234-5678-9012}
% \author{G.K.M. Tobin}
% \authornotemark[1]
% \email{webmaster@marysville-ohio.com}
% \affiliation{%
%   \institution{Institute for Clarity in Documentation}
%   \streetaddress{P.O. Box 1212}
%   \city{Dublin}
%   \state{Ohio}
%   \country{USA}
%   \postcode{43017-6221}
% }

\author{Anonymous Authors}


%%
%% By default, the full list of authors will be used in the page
%% headers. Often, this list is too long, and will overlap
%% other information printed in the page headers. This command allows
%% the author to define a more concise list
%% of authors' names for this purpose.
% \renewcommand{\shortauthors}{Trovato and Tobin, et al.}

%%
%% The abstract is a short summary of the work to be presented in the
%% article.
% \begin{abstract}
%   A clear and well-documented \LaTeX\ document is presented as an
%   article formatted for publication by ACM in a conference proceedings
%   or journal publication. Based on the ``acmart'' document class, this
%   article presents and explains many of the common variations, as well
%   as many of the formatting elements an author may use in the
%   preparation of the documentation of their work.
% \end{abstract}

%%
%% The code below is generated by the tool at http://dl.acm.org/ccs.cfm.
%% Please copy and paste the code instead of the example below.
%%
% \begin{CCSXML}
% <ccs2012>
%  <concept>
%   <concept_id>00000000.0000000.0000000</concept_id>
%   <concept_desc>Do Not Use This Code, Generate the Correct Terms for Your Paper</concept_desc>
%   <concept_significance>500</concept_significance>
%  </concept>
%  <concept>
%   <concept_id>00000000.00000000.00000000</concept_id>
%   <concept_desc>Do Not Use This Code, Generate the Correct Terms for Your Paper</concept_desc>
%   <concept_significance>300</concept_significance>
%  </concept>
%  <concept>
%   <concept_id>00000000.00000000.00000000</concept_id>
%   <concept_desc>Do Not Use This Code, Generate the Correct Terms for Your Paper</concept_desc>
%   <concept_significance>100</concept_significance>
%  </concept>
%  <concept>
%   <concept_id>00000000.00000000.00000000</concept_id>
%   <concept_desc>Do Not Use This Code, Generate the Correct Terms for Your Paper</concept_desc>
%   <concept_significance>100</concept_significance>
%  </concept>
% </ccs2012>
% \end{CCSXML}

% \ccsdesc[500]{Do Not Use This Code~Generate the Correct Terms for Your Paper}
% \ccsdesc[300]{Do Not Use This Code~Generate the Correct Terms for Your Paper}
% \ccsdesc{Do Not Use This Code~Generate the Correct Terms for Your Paper}
% \ccsdesc[100]{Do Not Use This Code~Generate the Correct Terms for Your Paper}

%%
%% Keywords. The author(s) should pick words that accurately describe
%% the work being presented. Separate the keywords with commas.
% \keywords{Do, Not, Us, This, Code, Put, the, Correct, Terms, for,
%   Your, Paper}

%% A "teaser" image appears between the author and affiliation
%% information and the body of the document, and typically spans the
%% page.
% \begin{teaserfigure}
%   \includegraphics[width=\textwidth]{sampleteaser}
%   \caption{Seattle Mariners at Spring Training, 2010.}
%   \Description{Enjoying the baseball game from the third-base
%   seats. Ichiro Suzuki preparing to bat.}
%   \label{fig:teaser}
% \end{teaserfigure}

% \received{20 February 2007}
% \received[revised]{12 March 2009}
% \received[accepted]{5 June 2009}

%%
%% This command processes the author and affiliation and title
%% information and builds the first part of the formatted document.
\maketitle

\section{Theoretical proof}\label{sub:a4}
In this chapter, we give corresponding proofs for Theorem 3.1 and Theorem 3.2 in the paper.

\noindent \textbf{Proof for Theorem 3.1.} 

Denote the input image as $\boldsymbol{x}$. The vector $\boldsymbol{x}$ is in the domain of $[0, 1]^{d}$ and can be expressed as
\[
\boldsymbol{x} = [x_1, x_2, \ldots, x_d]^T,
% \begin{bmatrix}
%     x_1 \\
%     x_2 \\
%     \vdots \\
%     x_d
% \end{bmatrix},
\]
where each $x_i \in [0, 1]$. For Poisson coding, the input is a random vector $\boldsymbol{X_{P}}$, where the vector follows a Bernoulli binomial distribution with probability vector $\boldsymbol{p}$. Here, $\boldsymbol{p} = \boldsymbol{x}$, and thus
\[
\boldsymbol{p} = [p_1, p_2, \ldots, p_d]^T,
% \begin{bmatrix}
%     p_1 \\
%     p_2 \\
%     \vdots \\
%     p_d
% \end{bmatrix}
\]
with each $p_i = x_i$. The expectation of $\boldsymbol{X_{P}}$ is $\boldsymbol{E}[\boldsymbol{X_{P}}] = \boldsymbol{x}$. The covariance matrix, denoted as $\boldsymbol{\Sigma}_{\boldsymbol{X_{P}}}$, is given by
\[
\boldsymbol{\Sigma}_{\boldsymbol{X_{P}}} = \text{diag}(\boldsymbol{x}(1-\boldsymbol{x})) = \text{diag}(x_1(1-x_1), x_2(1-x_2), \ldots, x_d(1-x_d)).
\]


Then we denote the original image as \( \boldsymbol{x} \) and the perturbed image as \( \boldsymbol{x} + \boldsymbol{\epsilon} \) in a linear layer. Denote the linear layer as a deterministic weight matrix \( \boldsymbol{W} \). For Poisson coding, the output as a random variable \( \boldsymbol{Y_{P}} \)  and the expectation of \( \boldsymbol{Y_{P}} \) is given by 
\[
\boldsymbol{E}[\boldsymbol{Y_{P}}] = \boldsymbol{E}[\boldsymbol{WX}] = \boldsymbol{W}\boldsymbol{E}[\boldsymbol{X}] = \boldsymbol{Wx}.
\] For the attack, the expectation of the attacked output \( \boldsymbol{Y_{P_{attack}}} \) is
\[
\boldsymbol{E}[\boldsymbol{Y_{P_{attack}}}] = \boldsymbol{W}(\boldsymbol{x} + \boldsymbol{\epsilon}).
\]

When we examine the covariance matrix of the random variable \( \boldsymbol{Y_{P}} \), denoted as \( \boldsymbol{\Sigma}_{\boldsymbol{Y_{P}}} \). For Poisson coding, the covariance matrix is given by
\[
\boldsymbol{\Sigma}_{\boldsymbol{Y_{P}}} = \boldsymbol{W}\boldsymbol{\Sigma}_{\boldsymbol{X_{P}}}\boldsymbol{W}^T = \boldsymbol{W}\text{diag}(\boldsymbol{x}(1-\boldsymbol{x}))\boldsymbol{W}^T.
\]

When an attack perturbation is added, the covariance matrix of \( \boldsymbol{Y_{P_{attack}}} \), denoted as \( \boldsymbol{\Sigma}_{\boldsymbol{Y_{P_{attack}}}} \), becomes
\[
\boldsymbol{\Sigma}_{\boldsymbol{Y_{P_{attack}}}} = \boldsymbol{W}\text{diag}(\boldsymbol{x}(1-\boldsymbol{x}) + \boldsymbol{\epsilon}(1-2\boldsymbol{x}) - \boldsymbol{\epsilon}^2)\boldsymbol{W}^T.
\] 

% Now we explore the impact of two coding methods on the original image \( \boldsymbol{x} \) and the perturbed image \( \boldsymbol{x} + \boldsymbol{\epsilon} \) in a linear layer. Denote the linear layer as a deterministic weight matrix \( \boldsymbol{W} \), and the output as a random variable \( \boldsymbol{Y} \). 

% For random smoothing, regardless of whether an attack perturbation is added or not, the random variable always follows a Gaussian distribution with a fixed covariance. Therefore, for both before and after the attack, the covariance matrix of \( \boldsymbol{Y}_{\text{ori/att}} \) is given by
% \[
% \boldsymbol{\Sigma}_{\boldsymbol{Y}_{\text{ori/att}}} = \boldsymbol{W}\text{diag}(\boldsymbol{\sigma}^2)\boldsymbol{W}^T.
% \]

\noindent \textbf{Proof for Theorem 3.2.}

Denote the input image as $\boldsymbol{x}$. The vector $\boldsymbol{x}$ is in the domain of $[0, 1]^{d}$ and can be expressed as
\[
\boldsymbol{x} = [x_1, x_2, \ldots, x_d]^T,
% \begin{bmatrix}
%     x_1 \\
%     x_2 \\
%     \vdots \\
%     x_d
% \end{bmatrix},
\]
where each $x_i \in [0, 1]$. 

For randomized smoothing coding, the input is a random vector $\boldsymbol{X_{RS}}$, which follows a normal distribution centered at $\boldsymbol{x}$ with covariance $\boldsymbol{\sigma}^2$, denoted as $\boldsymbol{X_{RS}} \sim \mathcal{N}(\boldsymbol{x}, \boldsymbol{\sigma}^2)$. The covariance matrix, $\boldsymbol{\Sigma}_{\boldsymbol{X_{RS}}}$, is given by
\[
\boldsymbol{\Sigma}_{\boldsymbol{X_{RS}}} = \text{diag}(\boldsymbol{\sigma}^2) = \text{diag}(\sigma_{1}^2, \sigma_{2}^2, \ldots, \sigma_{d}^2).
\]

Then we denote the original image as \( \boldsymbol{x} \) and the perturbed image as \( \boldsymbol{x} + \boldsymbol{\epsilon} \) in a linear layer. Denote the linear layer as a deterministic weight matrix \( \boldsymbol{W} \). For randomized smoothing coding, the output as a random variable \( \boldsymbol{Y_{RS}} \)  and the expectation of \( \boldsymbol{Y_{RS}} \) is given by 

\[
\boldsymbol{E}[\boldsymbol{Y_{RS}}] = \boldsymbol{E}[\boldsymbol{WX_{RS}}] = \boldsymbol{W}\boldsymbol{E}[\boldsymbol{X_{RS}}] = \boldsymbol{Wx}.
\] For the attack, the expectation of the attacked output \( \boldsymbol{Y_{RS_{attack}}} \) is
\[
\boldsymbol{E}[\boldsymbol{Y_{RS_{attack}}}] = \boldsymbol{W}(\boldsymbol{x} + \boldsymbol{\epsilon}).
\]

For randomized smoothing coding, regardless of whether an attack perturbation is added or not, the random variable always follows a Gaussian distribution with a fixed covariance. Therefore, for both before and after the attack, the covariance matrix of \( \boldsymbol{Y_{RS_{original/attack}}} \) is given by
\[
\boldsymbol{\Sigma}_{\boldsymbol{Y_{RS_{original/attack}}}} = \boldsymbol{W}\text{diag}(\boldsymbol{\sigma}^2)\boldsymbol{W}^T.
\]

% Denote the input image as $\boldsymbol{x}$. The vector $\boldsymbol{x}$ is in the domain of $[0, 1]^{d}$ and can be expressed as
% \[
% \boldsymbol{x} = 
% \begin{bmatrix}
%     x_1 \\
%     x_2 \\
%     \vdots \\
%     x_d
% \end{bmatrix},
% \]
% where each $x_i \in [0, 1]$. For Poisson coding, the input is a random vector $\boldsymbol{X}$, where the vector follows a Bernoulli binomial distribution with probability vector $\boldsymbol{p}$. Here, $\boldsymbol{p} = \boldsymbol{x}$, and thus
% \[
% \boldsymbol{p} = 
% \begin{bmatrix}
%     p_1 \\
%     p_2 \\
%     \vdots \\
%     p_d
% \end{bmatrix}
% \]
% with each $p_i = x_i$. The expectation of $\boldsymbol{X}$ is $\boldsymbol{E}[\boldsymbol{X}] = \boldsymbol{x}$. The covariance matrix, denoted as $\boldsymbol{\Sigma}_{\boldsymbol{X}}$, is given by
% \[
% \boldsymbol{\Sigma}_{\boldsymbol{X}} = \text{diag}(\boldsymbol{x}(1-\boldsymbol{x})) = \text{diag}(x_1(1-x_1), x_2(1-x_2), \ldots, x_d(1-x_d)).
% \]

% For random smoothing, the input is a random vector $\boldsymbol{X}$, which follows a normal distribution centered at $\boldsymbol{x}$ with covariance $\boldsymbol{\sigma}^2$, denoted as $\boldsymbol{X} \sim \mathcal{N}(\boldsymbol{x}, \boldsymbol{\sigma}^2)$. The covariance matrix, $\boldsymbol{\Sigma}_{\boldsymbol{X}}$, is given by
% \[
% \boldsymbol{\Sigma}_{\boldsymbol{X}} = \text{diag}(\boldsymbol{\sigma}^2) = \text{diag}(\sigma_{1}^2, \sigma_{2}^2, \ldots, \sigma_{d}^2).
% \]

% Now we explore the impact of two coding methods on the original image \( \boldsymbol{x} \) and the perturbed image \( \boldsymbol{x} + \boldsymbol{\epsilon} \) in a linear layer. Denote the linear layer as a deterministic weight matrix \( \boldsymbol{W} \), and the output as a random variable \( \boldsymbol{Y} \). For both coding methods, the expectation of \( \boldsymbol{Y} \) is given by 
% \[
% \boldsymbol{E}[\boldsymbol{Y}] = \boldsymbol{E}[\boldsymbol{WX}] = \boldsymbol{W}\boldsymbol{E}[\boldsymbol{X}] = \boldsymbol{Wx}.
% \] For the attack, the expectation of the attacked output \( \boldsymbol{Y}_{\text{att}} \) is
% \[
% \boldsymbol{E}[\boldsymbol{Y}_{\text{att}}] = \boldsymbol{W}(\boldsymbol{x} + \boldsymbol{\epsilon}).
% \]

% However, when we examine the covariance matrix of the random variable \( \boldsymbol{Y} \), denoted as \( \boldsymbol{\Sigma}_{\boldsymbol{Y}} \), we notice the difference. For Poisson coding, the covariance matrix is given by
% \[
% \boldsymbol{\Sigma}_{\boldsymbol{Y}} = \boldsymbol{W}\boldsymbol{\Sigma}_{\boldsymbol{X}}\boldsymbol{W}^T = \boldsymbol{W}\text{diag}(\boldsymbol{x}(1-\boldsymbol{x}))\boldsymbol{W}^T.
% \]

% When an attack perturbation is added, the covariance matrix of \( \boldsymbol{Y}_{\text{att}} \), denoted as \( \boldsymbol{\Sigma}_{\boldsymbol{Y}_{\text{att}}} \), becomes
% \[
% \boldsymbol{\Sigma}_{\boldsymbol{Y}_{\text{att}}} = \boldsymbol{W}\text{diag}(\boldsymbol{x}(1-\boldsymbol{x}) + \boldsymbol{\epsilon}(1-2\boldsymbol{x}) - \boldsymbol{\epsilon}^2)\boldsymbol{W}^T.
% \] Now we explore the impact of two coding methods on the original image \( \boldsymbol{x} \) and the perturbed image \( \boldsymbol{x} + \boldsymbol{\epsilon} \) in a linear layer. Denote the linear layer as a deterministic weight matrix \( \boldsymbol{W} \), and the output as a random variable \( \boldsymbol{Y} \). 

% For random smoothing, regardless of whether an attack perturbation is added or not, the random variable always follows a Gaussian distribution with a fixed covariance. Therefore, for both before and after the attack, the covariance matrix of \( \boldsymbol{Y}_{\text{ori/att}} \) is given by
% \[
% \boldsymbol{\Sigma}_{\boldsymbol{Y}_{\text{ori/att}}} = \boldsymbol{W}\text{diag}(\boldsymbol{\sigma}^2)\boldsymbol{W}^T.
% \]


Comparing Poisson coding and random smoothing, we observe that although both methods use random noise to smooth the input for improved adversarial robustness, they exhibit different characteristics in terms of covariance. For Poisson coding, the covariance is influenced both by the magnitude of the input itself and by perturbation attacks. This means that the variance of the input noise in Poisson coding is dependent on the input itself. In contrast, for random smoothing, the noise variance added to the input does not vary with the input itself. This property ensures that the smoothing process in random smoothing is more stable and consistent, making it potentially more effective in certain scenarios.

% \begin{equation}
%     \tag{13}
% \begin{aligned}
%      &\boldsymbol{\Sigma}_{\boldsymbol{Y_{P_{original}}}} = \boldsymbol{W}\text{diag}(\boldsymbol{x}(1-\boldsymbol{x}))\boldsymbol{W}^T. \\ 
%      & \boldsymbol{\Sigma}_{\boldsymbol{Y_{P_{attack}}}} = \boldsymbol{W}\text{diag}(\boldsymbol{x}(1-\boldsymbol{x}) + \boldsymbol{\epsilon}(1-2\boldsymbol{x}) - \boldsymbol{\epsilon}^2)\boldsymbol{W}^T.
% \end{aligned}
% \end{equation}



% \begin{equation}
%  \tag{14}
% \boldsymbol{\Sigma}_{\boldsymbol{Y_{RS_{original/attack}}}} = \boldsymbol{W}\text{diag}(\boldsymbol{\sigma}^2)\boldsymbol{W}^T.
% \end{equation}

\section{Details of Implementation}\label{appendix}
\subsection{Dataset and Training Details}\label{sub:a1}

\quad \textbf{CIFAR.} The CIFAR dataset \citep{krizhevsky2009learning} consists of 50k training images and 10k testing images with the size of $32\times32$. On the CIFAR datasets we use the SNN version of VGG network \cite{simonyan2014very}. We use VGG-5 for CIFAR10 and VGG-11 for CIFAR100. Moreover, random horizontal flip and crop are applied to the training images the augmentation. We use 200 epochs to train the SNN. 
% During the training and inference process, the time step of DIRECT and RSC is $T=8$, and the time step of POISSON is $T=16$. 

\textbf{Tiny-ImageNet.} Tiny-ImageNet \citep{le2015tiny} contains 100k training images and 10k validation images of resolution 64×64 from 200 classes. Moreover, random horizontal flip and crop are applied to the training images the augmentation. We use an SGD optimizer with 0.9 momentum and weight decay $5e-4$. The learning rate is set to 0.1 and cosine decay to 0. We train the SNN version of VGG-16 for 300 epochs. 
% During the training and inference process, the time step of DIRECT and RSC is $T=8$, and the time step of POISSON is $T=16$. 

\textbf{ImageNet.} ImageNet \citep{deng2009imagenet} contains more than 1250k training images and 50k validation images. We crop the images to 224$\times$224 and using the standard augmentation for the training data. We use an SGD optimizer with 0.9 momentum and weight decay $4e-5$. The learning rate is set to 0.1 and cosine decay to 0. We train the SEW-ResNet-18 \citep{fang2021deep} for 320 epochs and the ResNet-19 for 300 epochs.

\begin{table*}[ht]
\caption{Inference timestep training settings of SNN.}
\label{tab:time}
\vskip 0.15in
\begin{center}
\begin{small}
\begin{sc}
\begin{tabular}{cccccc}
\hline
\multicolumn{1}{c}{\bf Architecture}  &\multicolumn{1}{c}{\bf Coding Scheme} &\multicolumn{1}{c}{\bf CIFAR-10} &\multicolumn{1}{c}{\bf CIFAR-100} &\multicolumn{1}{c}{\bf Tiny-ImageNet} &\multicolumn{1}{c}{\bf ImageNet}\\
\hline
\multicolumn{1}{c}{\multirow{3}{*}{VGG-5/11/16}}
    & DIRECT & 8 & 8 & 8 & - \\
    & POISSON & 16 & 16 & 16 & - \\
    & RSC & 8 & 8 & 8 & - \\
    \hline
    \multicolumn{1}{c}{\multirow{3}{*}{ResNet-19}}
    & DIRECT & - & - & - & 1 \\
    & POISSON & - & - & - & 2 \\
    & RSC & - & - & - & 1 \\
    \hline
    \multicolumn{1}{c}{\multirow{3}{*}{SEW-ResNet-18}}
    & DIRECT & - & - & - & 4 \\
    & POISSON & - & - & - & 8 \\
    & RSC & - & - & - & 4 \\
    \hline
% \hline
\end{tabular}
\end{sc}
\end{small}
\end{center}
\vskip -0.1in
\end{table*}

% \footnote{The VGG used follows the implementation in \href{https://github.com/nitin-rathi/hybrid-snn-conversion}{https://github.com/nitin-rathi/hybrid-snn-conversion}.}

\begin{figure}[ht]
% \vskip 0.1in
\begin{center}
\centerline{\includegraphics[width=0.95\columnwidth]{Figure/more_encoding.pdf}}
\caption{Supplementary visual verification of equivalence of RS and Poisson coding. (a) An example of feature maps processed by RS and Poisson coding selected from CIFAR100. (b) An example of feature maps processed by RS and Poisson coding selected from Tiny-ImageNet.}
\label{fig:eq_vis2}
\end{center}
\vskip -0.3in
\end{figure}

\subsection{Details of SNN Implementation}\label{sub:a2}
The architectures used to illustrate the vulnerability in Sec. 3 of the main text are VGG. The leak factor $\lambda $ is set to 1.0 in SNN. Batch normalization are used in the network to overcome the gradient vanishing or explosion for deep SNNs as suggested by \cite{zheng2021going}. The image data is first normalized by the means and variances of the three channels and then fed into SNNs to trigger spikes. All the experiments are conducted on the PyTorch platform \cite{paszke2019pytorch} on NVIDIA A100-PCIE.

To address the non-differentiable challenge and facilitate the training of Spiking Neural Networks (SNNs), a surrogate gradient function is employed. This function serves the purpose of providing gradients during both the training process and Back-propagation Through Time (BPTT) attacks.
\begin{equation}
    \frac{\partial {{s}^{l}}\left( t \right)}{\partial {{m}^{l}}\left( {{t}^{-}} \right)}=\frac{1}{{{\gamma }^{2}}}\max \left( \gamma -\left| {{m}^{l}}\left( {{t}^{-}} \right) \right|,0 \right)
\end{equation}
In our implementation, we consistently set $\gamma$ to 1.0 across all experiments. It's important to highlight that we have adapted and customized the implementation of gradient-based attacks from the torchattacks Python package \cite{kim2020torchattacks}. This adaptation is necessary to conduct effective attacks on Spiking Neural Networks (SNNs).

\subsection{Details of Equivalence Visualization}\label{sub:a3}

To verify the equivalence between Poisson and RS coding, we judge by calculating the average cosine similarity of the tensors after all image inputs in the test set pass through the coding layer. The specific calculation process is as follows:
For each input $x$,
\begin{displaymath}
\begin{aligned}
    &\text{PE} = \text{Poisson}(x), \text{PE}\in {{\mathbb{R}}^{T_{poisson}\times C\times H\times W}},  \\ 
    &\text{RSE} = \text{RS}(x), \text{RSE}\in {{\mathbb{R}}^{T_{rs}\times C\times H\times W}},\\
    &\text{FPE}=\text{Flatten}(\text{Mean}(\text{PE},\dim=0)), \text{FPE}\in {{\mathbb{R}}^{1\times N}},  \\ 
    &\text{FRSE}=\text{Flatten}(\text{Mean}(\text{RSE},\dim=0)), \text{FRSE}\in {{\mathbb{R}}^{1\times N}},  \\ 
    % & \text{CS} = \text{F.cosine_similarity}(FPE, FRSE) \\ 
\end{aligned}
\end{displaymath}
where PE represents the result after Poisson processing, RSE represents the result after RSC processing, Mean represents the averaging operation, and Flatten represents the tensor flatten operation.

Assume there are total $n$ inputs in the test set, the final average cosine similarity is calculated as follows
\begin{displaymath}
\text{Avg CS} = \frac{\sum{\text{CS}\left( \text{FPE},\text{FRSE} \right)}}{n},
\end{displaymath}
where CS represents the operation of obtaining cosine similarity, Avg CS is the average cosine similarity.

\subsection{Detailed analysis of the gradient obfuscation checklist}

The white-box attack results reveal that across all experiments, the one-step FGSM consistently underperforms the PGD, thereby attesting to the effectiveness of RSC with respect to Test(1) as enumerated in the checklist table. To substantiate Test(2), we launch black-box assaults on both the proposed models and the vanilla ones. The observed subdued efficacy of the black-box perturbations confirms the fulfillment of Test(2). Tests (3) and (4) are rigorously examined by probing VGG-5 on the CIFAR10 dataset under escalating attack thresholds. As depicted in the figure of the ablation study, the classification accuracy progressively deteriorates, culminating in an accuracy indistinguishable from random chance. In line with the insights from \cite{athalye2018obfuscated}, Test(5) may only fail if gradient-based attacks are incapable of generating adversarial instances that induce misclassification. In conclusion, our findings indicate no discernible gradient obfuscation in RSC.


\section{More results of ablation study}
\subsection{Ablation study of E-RSCT with VGG-5 on CIFAR-10.}
\textbf{Effect of different loss parts of E-RSCT.}
The novel proposed E-RSCT consists of two losses, ${\mathcal{L}}_{KD}$ and ${\mathcal{L}}_{P-S}$. We used the VGG-5 model of RSC to conduct ablation experiments on the CIFAR-10 dataset. The experimental results are shown in Table \ref{tab:abl}. All attack methods are based on BPTT. When training with only ${\mathcal{L}}_{P-S}$, we can see that the clean accuracy drops by 0.55\%, and the accuracy after being attacked by FGSM and PGD drops by 1.44\% and 1.38\% respectively.
The results of the ablation experiment show that using only ${\mathcal{L}}_{P-S}$ can improve the clean accuracy and adversarial robustness of the model, and the combination of ${\mathcal{L}}_{P-S}$ and ${\mathcal{L}}_{KD}$ can work more effectively.

\begin{table}[ht]
\caption{Ablation study of E-RSCT with VGG-5 on CIFAR-10.}
\label{tab:abl}
% \vskip 0.15in
\begin{center}
% % \begin{small}
% \begin{sc}
\begin{adjustbox}{width=0.45\textwidth}  % 设置表格宽度为文本宽度的100%
\begin{tabular}{lcccr}
\toprule
${\mathcal{L}}_{P-S}$ & ${\mathcal{L}}_{KD}$ & Clean & FGSM & PGD  \\
\midrule
$\surd$ & $\surd$ & 82.03 & 54.52 & 39.98 \\
$\surd$ & $\times$ & 81.48 (\textbf{-0.55}) & 53.08 (\textbf{-1.44}) & 38.60(\textbf{-1.38}) \\
$\times$ & $\times$ & 80.29 (\textbf{-1.74}) & 51.29 \textbf{(-3.23)}  & 37.28 (\textbf{-2.70})\\
\bottomrule
\end{tabular}
\end{adjustbox}
% \end{sc}
% % \end{small}
\end{center}
% \vskip -0.3in
% \vspace
\end{table}

\clearpage

% \section{Introduction}
% ACM's consolidated article template, introduced in 2017, provides a
% consistent \LaTeX\ style for use across ACM publications, and
% incorporates accessibility and metadata-extraction functionality
% necessary for future Digital Library endeavors. Numerous ACM and
% SIG-specific \LaTeX\ templates have been examined, and their unique
% features incorporated into this single new template.

% If you are new to publishing with ACM, this document is a valuable
% guide to the process of preparing your work for publication. If you
% have published with ACM before, this document provides insight and
% instruction into more recent changes to the article template.

% The ``\verb|acmart|'' document class can be used to prepare articles
% for any ACM publication --- conference or journal, and for any stage
% of publication, from review to final ``camera-ready'' copy, to the
% author's own version, with {\itshape very} few changes to the source.

% \section{Template Overview}
% As noted in the introduction, the ``\verb|acmart|'' document class can
% be used to prepare many different kinds of documentation --- a
% dual-anonymous initial submission of a full-length technical paper, a
% two-page SIGGRAPH Emerging Technologies abstract, a ``camera-ready''
% journal article, a SIGCHI Extended Abstract, and more --- all by
% selecting the appropriate {\itshape template style} and {\itshape
%   template parameters}.

% This document will explain the major features of the document
% class. For further information, the {\itshape \LaTeX\ User's Guide} is
% available from
% \url{https://www.acm.org/publications/proceedings-template}.

% \subsection{Template Styles}

% The primary parameter given to the ``\verb|acmart|'' document class is
% the {\itshape template style} which corresponds to the kind of publication
% or SIG publishing the work. This parameter is enclosed in square
% brackets and is a part of the {\verb|documentclass|} command:
% \begin{verbatim}
%   \documentclass[STYLE]{acmart}
% \end{verbatim}

% Journals use one of three template styles. All but three ACM journals
% use the {\verb|acmsmall|} template style:
% \begin{itemize}
% \item {\verb|acmsmall|}: The default journal template style.
% \item {\verb|acmlarge|}: Used by JOCCH and TAP.
% \item {\verb|acmtog|}: Used by TOG.
% \end{itemize}

% The majority of conference proceedings documentation will use the {\verb|acmconf|} template style.
% \begin{itemize}
% \item {\verb|acmconf|}: The default proceedings template style.
% \item{\verb|sigchi|}: Used for SIGCHI conference articles.
% \item{\verb|sigchi-a|}: Used for SIGCHI ``Extended Abstract'' articles.
% \item{\verb|sigplan|}: Used for SIGPLAN conference articles.
% \end{itemize}

% \subsection{Template Parameters}

% In addition to specifying the {\itshape template style} to be used in
% formatting your work, there are a number of {\itshape template parameters}
% which modify some part of the applied template style. A complete list
% of these parameters can be found in the {\itshape \LaTeX\ User's Guide.}

% Frequently-used parameters, or combinations of parameters, include:
% \begin{itemize}
% \item {\verb|anonymous,review|}: Suitable for a ``dual-anonymous''
%   conference submission. Anonymizes the work and includes line
%   numbers. Use with the \verb|\acmSubmissionID| command to print the
%   submission's unique ID on each page of the work.
% \item{\verb|authorversion|}: Produces a version of the work suitable
%   for posting by the author.
% \item{\verb|screen|}: Produces colored hyperlinks.
% \end{itemize}

% This document uses the following string as the first command in the
% source file:
% \begin{verbatim}
% \documentclass[sigconf,authordraft]{acmart}
% \end{verbatim}

% \section{Modifications}

% Modifying the template --- including but not limited to: adjusting
% margins, typeface sizes, line spacing, paragraph and list definitions,
% and the use of the \verb|\vspace| command to manually adjust the
% vertical spacing between elements of your work --- is not allowed.

% {\bfseries Your document will be returned to you for revision if
%   modifications are discovered.}

% \section{Typefaces}

% The ``\verb|acmart|'' document class requires the use of the
% ``Libertine'' typeface family. Your \TeX\ installation should include
% this set of packages. Please do not substitute other typefaces. The
% ``\verb|lmodern|'' and ``\verb|ltimes|'' packages should not be used,
% as they will override the built-in typeface families.

% \section{Title Information}

% The title of your work should use capital letters appropriately -
% \url{https://capitalizemytitle.com/} has useful rules for
% capitalization. Use the {\verb|title|} command to define the title of
% your work. If your work has a subtitle, define it with the
% {\verb|subtitle|} command.  Do not insert line breaks in your title.

% If your title is lengthy, you must define a short version to be used
% in the page headers, to prevent overlapping text. The \verb|title|
% command has a ``short title'' parameter:
% \begin{verbatim}
%   \title[short title]{full title}
% \end{verbatim}

% \section{Authors and Affiliations}

% Each author must be defined separately for accurate metadata
% identification. Multiple authors may share one affiliation. Authors'
% names should not be abbreviated; use full first names wherever
% possible. Include authors' e-mail addresses whenever possible.

% Grouping authors' names or e-mail addresses, or providing an ``e-mail
% alias,'' as shown below, is not acceptable:
% \begin{verbatim}
%   \author{Brooke Aster, David Mehldau}
%   \email{dave,judy,steve@university.edu}
%   \email{firstname.lastname@phillips.org}
% \end{verbatim}

% The \verb|authornote| and \verb|authornotemark| commands allow a note
% to apply to multiple authors --- for example, if the first two authors
% of an article contributed equally to the work.

% If your author list is lengthy, you must define a shortened version of
% the list of authors to be used in the page headers, to prevent
% overlapping text. The following command should be placed just after
% the last \verb|\author{}| definition:
% \begin{verbatim}
%   \renewcommand{\shortauthors}{McCartney, et al.}
% \end{verbatim}
% Omitting this command will force the use of a concatenated list of all
% of the authors' names, which may result in overlapping text in the
% page headers.

% The article template's documentation, available at
% \url{https://www.acm.org/publications/proceedings-template}, has a
% complete explanation of these commands and tips for their effective
% use.

% Note that authors' addresses are mandatory for journal articles.

% \section{Rights Information}

% Authors of any work published by ACM will need to complete a rights
% form. Depending on the kind of work, and the rights management choice
% made by the author, this may be copyright transfer, permission,
% license, or an OA (open access) agreement.

% Regardless of the rights management choice, the author will receive a
% copy of the completed rights form once it has been submitted. This
% form contains \LaTeX\ commands that must be copied into the source
% document. When the document source is compiled, these commands and
% their parameters add formatted text to several areas of the final
% document:
% \begin{itemize}
% \item the ``ACM Reference Format'' text on the first page.
% \item the ``rights management'' text on the first page.
% \item the conference information in the page header(s).
% \end{itemize}

% Rights information is unique to the work; if you are preparing several
% works for an event, make sure to use the correct set of commands with
% each of the works.

% The ACM Reference Format text is required for all articles over one
% page in length, and is optional for one-page articles (abstracts).

% \section{CCS Concepts and User-Defined Keywords}

% Two elements of the ``acmart'' document class provide powerful
% taxonomic tools for you to help readers find your work in an online
% search.

% The ACM Computing Classification System ---
% \url{https://www.acm.org/publications/class-2012} --- is a set of
% classifiers and concepts that describe the computing
% discipline. Authors can select entries from this classification
% system, via \url{https://dl.acm.org/ccs/ccs.cfm}, and generate the
% commands to be included in the \LaTeX\ source.

% User-defined keywords are a comma-separated list of words and phrases
% of the authors' choosing, providing a more flexible way of describing
% the research being presented.

% CCS concepts and user-defined keywords are required for for all
% articles over two pages in length, and are optional for one- and
% two-page articles (or abstracts).

% \section{Sectioning Commands}

% Your work should use standard \LaTeX\ sectioning commands:
% \verb|section|, \verb|subsection|, \verb|subsubsection|, and
% \verb|paragraph|. They should be numbered; do not remove the numbering
% from the commands.

% Simulating a sectioning command by setting the first word or words of
% a paragraph in boldface or italicized text is {\bfseries not allowed.}

% \section{Tables}

% The ``\verb|acmart|'' document class includes the ``\verb|booktabs|''
% package --- \url{https://ctan.org/pkg/booktabs} --- for preparing
% high-quality tables.

% Table captions are placed {\itshape above} the table.

% Because tables cannot be split across pages, the best placement for
% them is typically the top of the page nearest their initial cite.  To
% ensure this proper ``floating'' placement of tables, use the
% environment \textbf{table} to enclose the table's contents and the
% table caption.  The contents of the table itself must go in the
% \textbf{tabular} environment, to be aligned properly in rows and
% columns, with the desired horizontal and vertical rules.  Again,
% detailed instructions on \textbf{tabular} material are found in the
% \textit{\LaTeX\ User's Guide}.

% Immediately following this sentence is the point at which
% Table~\ref{tab:freq} is included in the input file; compare the
% placement of the table here with the table in the printed output of
% this document.

% \begin{table}
%   \caption{Frequency of Special Characters}
%   \label{tab:freq}
%   \begin{tabular}{ccl}
%     \toprule
%     Non-English or Math&Frequency&Comments\\
%     \midrule
%     \O & 1 in 1,000& For Swedish names\\
%     $\pi$ & 1 in 5& Common in math\\
%     \$ & 4 in 5 & Used in business\\
%     $\Psi^2_1$ & 1 in 40,000& Unexplained usage\\
%   \bottomrule
% \end{tabular}
% \end{table}

% To set a wider table, which takes up the whole width of the page's
% live area, use the environment \textbf{table*} to enclose the table's
% contents and the table caption.  As with a single-column table, this
% wide table will ``float'' to a location deemed more
% desirable. Immediately following this sentence is the point at which
% Table~\ref{tab:commands} is included in the input file; again, it is
% instructive to compare the placement of the table here with the table
% in the printed output of this document.

% \begin{table*}
%   \caption{Some Typical Commands}
%   \label{tab:commands}
%   \begin{tabular}{ccl}
%     \toprule
%     Command &A Number & Comments\\
%     \midrule
%     \texttt{{\char'134}author} & 100& Author \\
%     \texttt{{\char'134}table}& 300 & For tables\\
%     \texttt{{\char'134}table*}& 400& For wider tables\\
%     \bottomrule
%   \end{tabular}
% \end{table*}

% Always use midrule to separate table header rows from data rows, and
% use it only for this purpose. This enables assistive technologies to
% recognise table headers and support their users in navigating tables
% more easily.

% \section{Math Equations}
% You may want to display math equations in three distinct styles:
% inline, numbered or non-numbered display.  Each of the three are
% discussed in the next sections.

% \subsection{Inline (In-text) Equations}
% A formula that appears in the running text is called an inline or
% in-text formula.  It is produced by the \textbf{math} environment,
% which can be invoked with the usual
% \texttt{{\char'134}begin\,\ldots{\char'134}end} construction or with
% the short form \texttt{\$\,\ldots\$}. You can use any of the symbols
% and structures, from $\alpha$ to $\omega$, available in
% \LaTeX~\cite{Lamport:LaTeX}; this section will simply show a few
% examples of in-text equations in context. Notice how this equation:
% \begin{math}
%   \lim_{n\rightarrow \infty}x=0
% \end{math},
% set here in in-line math style, looks slightly different when
% set in display style.  (See next section).

% \subsection{Display Equations}
% A numbered display equation---one set off by vertical space from the
% text and centered horizontally---is produced by the \textbf{equation}
% environment. An unnumbered display equation is produced by the
% \textbf{displaymath} environment.

% Again, in either environment, you can use any of the symbols and
% structures available in \LaTeX\@; this section will just give a couple
% of examples of display equations in context.  First, consider the
% equation, shown as an inline equation above:
% \begin{equation}
%   \lim_{n\rightarrow \infty}x=0
% \end{equation}
% Notice how it is formatted somewhat differently in
% the \textbf{displaymath}
% environment.  Now, we'll enter an unnumbered equation:
% \begin{displaymath}
%   \sum_{i=0}^{\infty} x + 1
% \end{displaymath}
% and follow it with another numbered equation:
% \begin{equation}
%   \sum_{i=0}^{\infty}x_i=\int_{0}^{\pi+2} f
% \end{equation}
% just to demonstrate \LaTeX's able handling of numbering.

% \section{Figures}

% The ``\verb|figure|'' environment should be used for figures. One or
% more images can be placed within a figure. If your figure contains
% third-party material, you must clearly identify it as such, as shown
% in the example below.


% \begin{figure}[h]
%   \centering
%     \fbox{\rule{0pt}{2.5in} \rule{0.9\linewidth}{0pt}}
%   % \includegraphics[width=\linewidth]{sample-franklin}
%   \caption{Example of caption}
% \end{figure}


% Your figures should contain a caption which describes the figure to
% the reader.

% Figure captions are placed {\itshape below} the figure.

% Every figure should also have a figure description unless it is purely
% decorative. These descriptions convey what’s in the image to someone
% who cannot see it. They are also used by search engine crawlers for
% indexing images, and when images cannot be loaded.

% A figure description must be unformatted plain text less than 2000
% characters long (including spaces).  {\bfseries Figure descriptions
%   should not repeat the figure caption – their purpose is to capture
%   important information that is not already provided in the caption or
%   the main text of the paper.} For figures that convey important and
% complex new information, a short text description may not be
% adequate. More complex alternative descriptions can be placed in an
% appendix and referenced in a short figure description. For example,
% provide a data table capturing the information in a bar chart, or a
% structured list representing a graph.  For additional information
% regarding how best to write figure descriptions and why doing this is
% so important, please see
% \url{https://www.acm.org/publications/taps/describing-figures/}.

% \subsection{The ``Teaser Figure''}

% A ``teaser figure'' is an image, or set of images in one figure, that
% are placed after all author and affiliation information, and before
% the body of the article, spanning the page. If you wish to have such a
% figure in your article, place the command immediately before the
% \verb|\maketitle| command:
% \begin{verbatim}
%   \begin{teaserfigure}
%     \includegraphics[width=\textwidth]{sampleteaser}
%     \caption{figure caption}
%     \Description{figure description}
%   \end{teaserfigure}
% \end{verbatim}

% \section{Citations and Bibliographies}

% The use of \BibTeX\ for the preparation and formatting of one's
% references is strongly recommended. Authors' names should be complete
% --- use full first names (``Donald E. Knuth'') not initials
% (``D. E. Knuth'') --- and the salient identifying features of a
% reference should be included: title, year, volume, number, pages,
% article DOI, etc.

% The bibliography is included in your source document with these two
% commands, placed just before the \verb|\end{document}| command:
% \begin{verbatim}
%   \bibliographystyle{ACM-Reference-Format}
%   \bibliography{bibfile}
% \end{verbatim}
% where ``\verb|bibfile|'' is the name, without the ``\verb|.bib|''
% suffix, of the \BibTeX\ file.

% Citations and references are numbered by default. A small number of
% ACM publications have citations and references formatted in the
% ``author year'' style; for these exceptions, please include this
% command in the {\bfseries preamble} (before the command
% ``\verb|\begin{document}|'') of your \LaTeX\ source:
% \begin{verbatim}
%   \citestyle{acmauthoryear}
% \end{verbatim}

%   Some examples.  A paginated journal article \cite{Abril07}, an
%   enumerated journal article \cite{Cohen07}, a reference to an entire
%   issue \cite{JCohen96}, a monograph (whole book) \cite{Kosiur01}, a
%   monograph/whole book in a series (see 2a in spec. document)
%   \cite{Harel79}, a divisible-book such as an anthology or compilation
%   \cite{Editor00} followed by the same example, however we only output
%   the series if the volume number is given \cite{Editor00a} (so
%   Editor00a's series should NOT be present since it has no vol. no.),
%   a chapter in a divisible book \cite{Spector90}, a chapter in a
%   divisible book in a series \cite{Douglass98}, a multi-volume work as
%   book \cite{Knuth97}, a couple of articles in a proceedings (of a
%   conference, symposium, workshop for example) (paginated proceedings
%   article) \cite{Andler79, Hagerup1993}, a proceedings article with
%   all possible elements \cite{Smith10}, an example of an enumerated
%   proceedings article \cite{VanGundy07}, an informally published work
%   \cite{Harel78}, a couple of preprints \cite{Bornmann2019,
%     AnzarootPBM14}, a doctoral dissertation \cite{Clarkson85}, a
%   master's thesis: \cite{anisi03}, an online document / world wide web
%   resource \cite{Thornburg01, Ablamowicz07, Poker06}, a video game
%   (Case 1) \cite{Obama08} and (Case 2) \cite{Novak03} and \cite{Lee05}
%   and (Case 3) a patent \cite{JoeScientist001}, work accepted for
%   publication \cite{rous08}, 'YYYYb'-test for prolific author
%   \cite{SaeediMEJ10} and \cite{SaeediJETC10}. Other cites might
%   contain 'duplicate' DOI and URLs (some SIAM articles)
%   \cite{Kirschmer:2010:AEI:1958016.1958018}. Boris / Barbara Beeton:
%   multi-volume works as books \cite{MR781536} and \cite{MR781537}. A
%   couple of citations with DOIs:
%   \cite{2004:ITE:1009386.1010128,Kirschmer:2010:AEI:1958016.1958018}. Online
%   citations: \cite{TUGInstmem, Thornburg01, CTANacmart}. Artifacts:
%   \cite{R} and \cite{UMassCitations}.

% \section{Acknowledgments}

% Identification of funding sources and other support, and thanks to
% individuals and groups that assisted in the research and the
% preparation of the work should be included in an acknowledgment
% section, which is placed just before the reference section in your
% document.

% This section has a special environment:
% \begin{verbatim}
%   \begin{acks}
%   ...
%   \end{acks}
% \end{verbatim}
% so that the information contained therein can be more easily collected
% during the article metadata extraction phase, and to ensure
% consistency in the spelling of the section heading.

% Authors should not prepare this section as a numbered or unnumbered {\verb|\section|}; please use the ``{\verb|acks|}'' environment.

% \section{Appendices}

% If your work needs an appendix, add it before the
% ``\verb|\end{document}|'' command at the conclusion of your source
% document.

% Start the appendix with the ``\verb|appendix|'' command:
% \begin{verbatim}
%   \appendix
% \end{verbatim}
% and note that in the appendix, sections are lettered, not
% numbered. This document has two appendices, demonstrating the section
% and subsection identification method.

% \section{Multi-language papers}

% Papers may be written in languages other than English or include
% titles, subtitles, keywords and abstracts in different languages (as a
% rule, a paper in a language other than English should include an
% English title and an English abstract).  Use \verb|language=...| for
% every language used in the paper.  The last language indicated is the
% main language of the paper.  For example, a French paper with
% additional titles and abstracts in English and German may start with
% the following command
% \begin{verbatim}
% \documentclass[sigconf, language=english, language=german,
%                language=french]{acmart}
% \end{verbatim}

% The title, subtitle, keywords and abstract will be typeset in the main
% language of the paper.  The commands \verb|\translatedXXX|, \verb|XXX|
% begin title, subtitle and keywords, can be used to set these elements
% in the other languages.  The environment \verb|translatedabstract| is
% used to set the translation of the abstract.  These commands and
% environment have a mandatory first argument: the language of the
% second argument.  See \verb|sample-sigconf-i13n.tex| file for examples
% of their usage.

% \section{SIGCHI Extended Abstracts}

% The ``\verb|sigchi-a|'' template style (available only in \LaTeX\ and
% not in Word) produces a landscape-orientation formatted article, with
% a wide left margin. Three environments are available for use with the
% ``\verb|sigchi-a|'' template style, and produce formatted output in
% the margin:
% \begin{itemize}
% \item {\verb|sidebar|}:  Place formatted text in the margin.
% \item {\verb|marginfigure|}: Place a figure in the margin.
% \item {\verb|margintable|}: Place a table in the margin.
% \end{itemize}

%%
%% The acknowledgments section is defined using the "acks" environment
%% (and NOT an unnumbered section). This ensures the proper
%% identification of the section in the article metadata, and the
%% consistent spelling of the heading.
% \begin{acks}
% To Robert, for the bagels and explaining CMYK and color spaces.
% \end{acks}

%%
%% The next two lines define the bibliography style to be used, and
%% the bibliography file.
\bibliographystyle{ACM-Reference-Format}
\bibliography{sample-base}

%%
%% If your work has an appendix, this is the place to put it.
% \appendix

% \section{Research Methods}

% \subsection{Part One}

% Lorem ipsum dolor sit amet, consectetur adipiscing elit. Morbi
% malesuada, quam in pulvinar varius, metus nunc fermentum urna, id
% sollicitudin purus odio sit amet enim. Aliquam ullamcorper eu ipsum
% vel mollis. Curabitur quis dictum nisl. Phasellus vel semper risus, et
% lacinia dolor. Integer ultricies commodo sem nec semper.

% \subsection{Part Two}

% Etiam commodo feugiat nisl pulvinar pellentesque. Etiam auctor sodales
% ligula, non varius nibh pulvinar semper. Suspendisse nec lectus non
% ipsum convallis congue hendrerit vitae sapien. Donec at laoreet
% eros. Vivamus non purus placerat, scelerisque diam eu, cursus
% ante. Etiam aliquam tortor auctor efficitur mattis.

% \section{Online Resources}

% Nam id fermentum dui. Suspendisse sagittis tortor a nulla mollis, in
% pulvinar ex pretium. Sed interdum orci quis metus euismod, et sagittis
% enim maximus. Vestibulum gravida massa ut felis suscipit
% congue. Quisque mattis elit a risus ultrices commodo venenatis eget
% dui. Etiam sagittis eleifend elementum.

% Nam interdum magna at lectus dignissim, ac dignissim lorem
% rhoncus. Maecenas eu arcu ac neque placerat aliquam. Nunc pulvinar
% massa et mattis lacinia.

\end{document}
\endinput
%%
%% End of file `sample-authordraft.tex'.
