Fetching the paper…
Reading the bibliography…
The last few years have seen a staggering number of empirical studies of the robustness of neural networks in a model of adversarial perturbations of their inputs.
Admissible probability measurement procedures
E. Shuford, A. Albert, and H.-E. Massengil · 1966
Earlier work this paper cites.
Proper scores for probability forecasters
A.-D. Hendrickson and R.-J. Buehler · 1971
Earlier work this paper cites.
Generalized Linear Models
P. McCullagh and J. Nelder · 1989
Earlier work this paper cites.
On the boosting ability of top-down decision tree learning algorithms
M. Kearns and Y. Mansour · 1996
Earlier work this paper cites.
Methods of Information Geometry
S.-I. Amari and H. Nagaoka · 2000
Earlier work this paper cites.
Vicinal risk minimization
O. Chapelle, J. Weston, L. Bottou, and V. Vapnik · 2000
Earlier work this paper cites.
Training invariant support vector machines
D. DeCoste and B. Schölkopf · 2002
Earlier work this paper cites.
Game theory, maximum entropy, minimum discrepancy and robust Bayesian decision theory
P. Grünwald and P. Dawid · 2004
Earlier work this paper cites.
Loss functions for binary class probability estimation ans classification: structure and applications, 2005
A. Buja, W. Stuetzle, and Y. Shen · 2005
Earlier work this paper cites.
A kernel method for the two-sample-problem
A. Gretton, K.-M. Borgwardt, M.-J. Rasch, B. Schölkopf, and A.-J. Smola · 2006
Earlier work this paper cites.
On the efficient minimization of classification-calibrated surrogates
R. Nock and F. Nielsen · 2008
Earlier work this paper cites.
On integral probability metrics, φ \varphi -divergences and binary classification
B.-K. Sriperumbudur, K. Fukumizu, A. Gretton, B. Schölkopf, and G.-R.-G. Lanckriet · 2009
Earlier work this paper cites.
Optimal transport, old and new
C. Villani · 2009
Earlier work this paper cites.
Composite binary losses
M.-D. Reid and R.-C. Williamson · 2010
Earlier work this paper cites.
Boosting, Foundations and Algorithms
R.-E. Schapire and Y. Freund · 2012
Cited alongside, same era.
Intriguing properties of neural networks
C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, and R. Fergus · 2013
Cited alongside, same era.
Measuring neural net robustness with constraints
O. Bastani, Y. Ioannou, L. Lampropoulos, D. Vytiniotis, A.-V. Nori, and A. Criminisi · 2016
Cited alongside, same era.
Parseval networks: improving robustness to adversarial examples
M. Cissé, P. Bojanowski, E. Grave, Y. Dauphin, and N. Usunier · 2017
Cited alongside, same era.
Formal guarantees on the robustness of a classifier against adversarial manipulation
M. Hein and M. Andriushchenko · 2017
Cited alongside, same era.
Adversarial machine learning at scale
A. Kurakin, I. Goodfellow, and S. Bengio · 2017
Countering adversarial images using input transformations
C. Guo, M. Rana, M. Cisse, and L. van der Maaten · 2018
Closest in time.
Adversarial attacks under restricted threat models
A. Ilias, L. Engstrom, A. Athalye, and J. Lin · 2018
Closest in time.
Characterizing adversarial subspaces using local intrinsic dimensionality
X. Ma, B. Li, Y. Wang, S.-M. Erfani, S. Wijewickrema, G. Schoenebeck, D. Song, M.-E. Houle, and J. Bayley · 2018
Closest in time.
Towards deep learning models resistant to adversarial attacks
A. Madry, A. Makelov, L. Schmidt, D. Tsipras, and A. Vladu · 2018
Closest in time.
Spectral normalization for generative adversarial networks
T. Miyato, T. Kataoka, M. Koyama, and Y. Yoshida · 2018
Closest in time.
Certified defenses against adversarial examples
A. Raghunathan, J. Steinhardt, and P. Liang · 2018
Closest in time.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Cited alongside, same era.
Adversarial examples from computational constraints
S. Bubeck, E. Price, and I. Razenshteyn · 2018
Cited alongside, same era.
Thermometer encoding: one hot way to resist adversarial examples
J. Buckman, A. Roy, C. Raffel, and I. Goodfellow · 2018
Cited alongside, same era.
Curriculum adversarial training
Q.-Z. Cai, M. Du, C. Liu, and D. Song · 2018
Cited alongside, same era.
Lipschitz networks and distributional robustness
Z. Cranko, S. Kornblith, Z. Shi, and R. Nock · 2018
Cited alongside, same era.
Stochastic activation pruning for robust adversarial defense
G. Dhillon, K. Azizzadenesheli, Z.-C. Lipton, J. Bernstein, J. Kossaifi, A. Khanna, and A. Anandkumar · 2018
Cited alongside, same era.
Adversarial vulnerability for any classifier
A. Fawzi, H. Fawzi, and O. Fawzi · 2018
Cited alongside, same era.
Defense-GAN: protecting classifiers against adversarial attacks using generative models
P. Samangouei, M. Kabkab, and R. Chellappa · 2018
Closest in time.
Certifying some distributional robustness with principled adversarial training
A. Sinha, H. Namkoong, and J. Duchi · 2018
Closest in time.
PixelDefend: leveraging generative models to understand and defend against adversarial examples
Y. Song, T. Kim, S. Nowozin, S. Ermon, and N. Kushman · 2018
Closest in time.
Ensemble adversarial training: attacks and defenses
F. Tramèr, A. Kurakin, N. Papernot, I. Goodfellow, D. Boneh, and P. McDaniel · 2018
Closest in time.
Adversarial risk and the dangers of evaluating against weak attacks
J. Uesato, B. O’Donoghue, P. Kohli, and A. van den Oord · 2018
Closest in time.
Analyzing the robustness of nearest neighbors to adversarial examples
Y. Wang, S. Jha, and K. Chaudhuri · 2018
Closest in time.
Provable defense against adversarial examples via the outer adversarial polytope
E. Wong and J. Zico Kolter · 2018
Closest in time.
Robustness may be at odds with accuracy
D. Tsipras, S. Santurkar, L. Engstrom, A. Turner, and A. Madry · 2019
Closest in time.