Fetching the paper…
Reading the bibliography…
In this paper, we study fast training of adversarially robust models.
Flat minima
S. Hochreiter and J. Schmidhuber · 1997
Earlier work this paper cites.
Gradient-based learning applied to document recognition
Y. LeCun, L. Bottou, Y. Bengio, and P. Haffner · 1998
Earlier work this paper cites.
Adversarial classification
N. Dalvi, P. Domingos, S. Sanghai, D. Verma, et al · 2004
Earlier work this paper cites.
Imagenet: A large-scale hierarchical image database
J. Deng, W. Dong, R. Socher, L.-J. Li, K. Li, and L. Fei-Fei · 2009
Earlier work this paper cites.
Learning multiple layers of features from tiny images
A. Krizhevsky · 2009
Earlier work this paper cites.
Adversarial machine learning
L. Huang, A. D. Joseph, B. Nelson, B. I. Rubinstein, and J. Tygar · 2011
Earlier work this paper cites.
Reading digits in natural images with unsupervised feature learning
Y. Netzer, T. Wang, A. Coates, A. Bissacco, B. Wu, and A. Y. Ng · 2011
Earlier work this paper cites.
Evasion attacks against machine learning at test time
B. Biggio, I. Corona, D. Maiorca, B. Nelson, N. Šrndić, P. Laskov, G. Giacinto, and F. Roli · 2013
Earlier work this paper cites.
Intriguing properties of neural networks
C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, and R. Fergus · 2014
Earlier work this paper cites.
Explaining and harnessing adversarial examples
I. J. Goodfellow, J. Shlens, and C. Szegedy · 2015
Earlier work this paper cites.
Identity mappings in deep residual networks
K. He, X. Zhang, S. Ren, and J. Sun · 2016
Earlier work this paper cites.
Deepfool: a simple and accurate method to fool deep neural networks
S.-M. Moosavi-Dezfooli, A. Fawzi, and P. Frossard · 2016
Earlier work this paper cites.
Distillation as a defense to adversarial perturbations against deep neural networks
N. Papernot, P. McDaniel, X. Wu, S. Jha, and A. Swami · 2016
Earlier work this paper cites.
Rethinking the inception architecture for computer vision
C. Szegedy, V. Vanhoucke, S. Ioffe, J. Shlens, and Z. Wojna · 2016
Earlier work this paper cites.
Wide residual networks
S. Zagoruyko and N. Komodakis · 2016
Earlier work this paper cites.
Adversarial examples are not easily detected: Bypassing ten detection methods
N. Carlini and D. Wagner · 2017
Earlier work this paper cites.
Towards evaluating the robustness of neural networks
N. Carlini and D. Wagner · 2017
Earlier work this paper cites.
Zoo: Zeroth order optimization based black-box attacks to deep neural networks without training substitute models
P.-Y. Chen, H. Zhang, Y. Sharma, J. Yi, and C.-J. Hsieh · 2017
Earlier work this paper cites.
Houdini: Fooling deep structured prediction models
M. Cisse, Y. Adi, N. Neverova, and J. Keshet · 2017
Earlier work this paper cites.
Sharp minima can generalize for deep nets
L. Dinh, R. Pascanu, S. Bengio, and Y. Bengio · 2017
Earlier work this paper cites.
Adversarial attacks on neural network policies, 2017
S. Huang, N. Papernot, I. Goodfellow, Y. Duan, and P. Abbeel · 2017
Cited alongside, same era.
Adversarial examples in the physical world
A. Kurakin, I. Goodfellow, and S. Bengio · 2017
Cited alongside, same era.
Adversarial machine learning at scale
A. Kurakin, I. Goodfellow, and S. Bengio · 2017
Cited alongside, same era.
Delving into transferable adversarial examples and black-box attacks
Y. Liu, X. Chen, C. Liu, and D. Song · 2017
Cited alongside, same era.
Magnet: a two-pronged defense against adversarial examples
D. Meng and H. Chen · 2017
Cited alongside, same era.
On detecting adversarial perturbations
J. H. Metzen, T. Genewein, V. Fischer, and B. Bischoff · 2017
Cited alongside, same era.
Countering adversarial images using input transformations
C. Guo, M. Rana, M. Cissé, and L. van der Maaten · 2018
Closest in time.
Improving DNN robustness to adversarial attacks using Jacobian regularization
D. Jakubovitz and R. Giryes · 2018
Closest in time.
H. Kannan, A. Kurakin, and I. Goodfellow · 2018
Closest in time.
Defense against adversarial attacks using high-level representation guided denoiser
F. Liao, M. Liang, Y. Dong, and T. Pang · 2018
Closest in time.
Towards robust neural networks via random self-ensemble
X. Liu, M. Cheng, H. Zhang, and C.-J. Hsieh · 2018
Closest in time.
Towards deep learning models resistant to adversarial attacks
A. Madry, A. Makelov, L. Schmidt, D. Tsipras, and A. Vladu · 2018
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Universal adversarial perturbations against semantic image segmentation
J. H. Metzen, M. C. Kumar, T. Brox, and V. Fischer · 2017
Cited alongside, same era.
Practical black-box attacks against machine learning
N. Papernot, P. McDaniel, I. Goodfellow, S. Jha, Z. B. Celik, and A. Swami · 2017
Cited alongside, same era.
Robust adversarial reinforcement learning
L. Pinto, J. Davidson, R. Sukthankar, and A. Gupta · 2017
Cited alongside, same era.
Adversarial Examples for Semantic Segmentation and Object Detection
C. Xie, J. Wang, Z. Zhang, Y. Zhou, L. Xie, and A. Yuille · 2017
Cited alongside, same era.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
A. Athalye, N. Carlini, and D. Wagner · 2018
Cited alongside, same era.
Synthesizing robust adversarial examples
A. Athalye and I. Sutskever · 2018
Cited alongside, same era.
Closest in time.
Deflecting adversarial attacks with pixel deflection
A. Prakash, N. Moran, S. Garber, A. DiLillo, and J. Storer · 2018
Closest in time.
Certified defenses against adversarial examples
A. Raghunathan, J. Steinhardt, and P. Liang · 2018
Closest in time.
Improving the adversarial robustness and interpretability of deep neural networks by regularizing their input gradients
A. S. Ross and F. Doshi-Velez · 2018
Closest in time.
Defense-GAN: Protecting classifiers against adversarial attacks using generative models
P. Samangouei, M. Kabkab, and R. Chellappa · 2018
Closest in time.
Adversarially robust generalization requires more data
L. Schmidt, S. Santurkar, D. Tsipras, K. Talwar, and A. Madry · 2018
Closest in time.
Certifying some distributional robustness with principled adversarial training
A. Sinha, H. Namkoong, and J. Duchi · 2018
Closest in time.
Pixeldefend: Leveraging generative models to understand and defend against adversarial examples
Y. Song, T. Kim, S. Nowozin, S. Ermon, and N. Kushman · 2018
Closest in time.
Ensemble adversarial training: Attacks and defenses
F. Tramèr, A. Kurakin, N. Papernot, D. Boneh, and P. McDaniel · 2018
Closest in time.
Adversarial risk and the dangers of evaluating against weak attacks
J. Uesato, B. O’Donoghue, A. v. d. Oord, and P. Kohli · 2018
Closest in time.
Mitigating adversarial effects through randomization
C. Xie, J. Wang, Z. Zhang, Z. Ren, and A. Yuille · 2018
Closest in time.
Defense against adversarial images using web-scale nearest-neighbor search
A. Dubey, L. v. d. Maaten, Z. Yalniz, Y. Li, and D. Mahajan · 2019
Closest in time.
Feature denoising for improving adversarial robustness
C. Xie, Y. Wu, L. van der Maaten, A. Yuille, and K. He · 2019
Closest in time.
Theoretically principled trade-off between robustness and accuracy
H. Zhang, Y. Yu, J. Jiao, E. P. Xing, L. E. Ghaoui, and M. I. Jordan · 2019
Closest in time.