Fetching the paper…
Reading the bibliography…
Verifying the robustness property of a general Rectified Linear Unit (ReLU) network is an NP-complete problem [Katz, Barrett, Dill, Julian and Kochenderfer CAV17].
Tensor rank is np-complete
Håstad, J · 1990
Earlier work this paper cites.
A sub-constant error-probability low-degree test, and a sub-constant error-probability pcp characterization of np
Raz, R. and Safra, S · 1997
Earlier work this paper cites.
Probabilistic checking of proofs: A new characterization of np
Arora, S. and Safra, S · 1998
Earlier work this paper cites.
Proof verification and the hardness of approximation problems
Arora, S., Lund, C., Motwani, R., Sudan, M., and Szegedy, M · 1998
Earlier work this paper cites.
Which problems have strongly exponential complexity?
Impagliazzo, R., Paturi, R., and Zane, F · 1998
Earlier work this paper cites.
On the complexity of k-sat
Impagliazzo, R. and Paturi, R · 2001
Earlier work this paper cites.
Relations between average case complexity and approximation complexity
Feige, U · 2002
Earlier work this paper cites.
Algorithmic construction of sets for k-restrictions
Alon, N., Moshkovitz, D., and Safra, S · 2006
Earlier work this paper cites.
Inapproximability results for maximum edge biclique, minimum linear arrangement, and sparsest cut
Ambühl, C., Mastrolilli, M., and Svensson, O · 2011
Earlier work this paper cites.
Lower bounds based on the exponential time hypothesis
Lokshtanov, D., Marx, D., and Saurabh, S · 2013
Earlier work this paper cites.
Intriguing properties of neural networks
Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I., and Fergus, R · 2013
Earlier work this paper cites.
Analytical approach to parallel repetition
Dinur, I. and Steurer, D · 2014
Earlier work this paper cites.
Mildly exponential reduction from gap 3sat to polynomial-gap label-cover
Dinur, I · 2016
Earlier work this paper cites.
Distillation as a defense to adversarial perturbations against deep neural networks
Papernot, N., McDaniel, P., Wu, X., Jha, S., and Swami, A · 2016
Cited alongside, same era.
Weighted low rank approximations with provable guarantees
Razenshteyn, I., Song, Z., and Woodruff, D. P · 2016
Cited alongside, same era.
Zoo: Zeroth order optimization based black-box attacks to deep neural networks without training substitute models
Chen, P.-Y., Zhang, H., Sharma, Y., Yi, J., and Hsieh, C.-J · 2017
Cited alongside, same era.
Maximum resilience of artificial neural networks
Cheng, C.-H., Nührenberg, G., and Ruess, H · 2017
Cited alongside, same era.
Houdini: Fooling deep structured visual and speech recognition models with adversarial examples
Cisse, M. M., Adi, Y., Neverova, N., and Keshet, J · 2017
Cited alongside, same era.
A birthday repetition theorem and complexity of approximating dense csps
Manurangsi, P. and Raghavendra, P · 2017
Later among the works it cites.
Practical black-box attacks against machine learning
Papernot, N., McDaniel, P., Goodfellow, I., Jha, S., Celik, Z. B., and Swami, A · 2017
Later among the works it cites.
Adversary resistant deep neural networks with an application to malware detection
Wang, Q., Guo, W., Zhang, K., Ororbia II, A. G., Xing, X., Liu, X., and Giles, C. L · 2017
Later among the works it cites.
Adversarial examples for semantic segmentation and object detection
Xie, C., Wang, J., Zhang, Z., Zhou, Y., Xie, L., and Yuille, A · 2017
Later among the works it cites.
Approximate clustering with same-cluster queries
Ailon, N., Bhattacharya, A., Jaiswal, R., and Kumar, A · 2018
Closest in time.
The bane of low-dimensionality clustering
Cohen-Addad, V., De Mesmay, A., Rotenberg, E., and Roytman, A · 2018
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Formal verification of piece-wise linear feed-forward neural networks
Ehlers, R · 2017
Cited alongside, same era.
Deep neural networks as 0-1 mixed integer linear programs: A feasibility study
Fischetti, M. and Jo, J · 2017
Cited alongside, same era.
Adversarial example defenses: Ensembles of weak defenses are not strong
He, W., Wei, J., Chen, X., Carlini, N., and Song, D · 2017
Cited alongside, same era.
Formal guarantees on the robustness of a classifier against adversarial manipulation
Hein, M. and Andriushchenko, M · 2017
Cited alongside, same era.
Adversarial examples for evaluating reading comprehension systems
Jia, R. and Liang, P · 2017
Cited alongside, same era.
Reluplex: An efficient smt solver for verifying deep neural networks
Katz, G., Barrett, C., Dill, D. L., Julian, K., and Kochenderfer, M. J · 2017
Cited alongside, same era.
Adversarial machine learning at scale
Kurakin, A., Goodfellow, I., and Bengio, S · 2017
Cited alongside, same era.
Closest in time.
Towards deep learning models resistant to adversarial attacks
Madry, A., Makelov, A., Schmidt, L., Tsipras, D., and Vladu, A · 2018
Closest in time.
Certifiable distributional robustness with principled adversarial training
Sinha, A., Namkoong, H., and Duchi, J · 2018
Closest in time.
Towards a zero-one law for entrywise low rank approximation
Song, Z., Woodruff, D. P., and Zhong, P · 2018
Closest in time.
Ensemble adversarial training: Attacks and defenses
Tramèr, F., Kurakin, A., Papernot, N., Boneh, D., and McDaniel, P · 2018
Closest in time.
Evaluating the robustness of neural networks: An extreme value theory approach
Weng, T.-W., Zhang, H., Chen, P.-Y., Jinfeng, Y., Su, D., Gao, Y., Hsieh, C.-J., and Daniel, L · 2018
Closest in time.
Provable defenses against adversarial examples via the convex outer adversarial polytope
Wong, E. and Kolter, J. Z · 2018
Closest in time.