Fetching the paper…
Reading the bibliography…
We identify a trade-off between robustness and accuracy that serves as a guiding principle in the design of defenses against adversarial examples.
Extremal properties of central half-spaces for product measures
Franck Barthe · 2001
Earlier work this paper cites.
Covering number bounds of certain regularized linear function classes
Tong Zhang · 2002
Earlier work this paper cites.
Convexity, classification, and risk bounds
Peter L Bartlett, Michael I Jordan, and Jon D McAuliffe · 2006
Earlier work this paper cites.
Intriguing properties of neural networks
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus · 2013
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy · 2015
Earlier work this paper cites.
Learning with a strong adversary
Ruitong Huang, Bing Xu, Dale Schuurmans, and Csaba Szepesvári · 2015
Earlier work this paper cites.
Uri Shaham, Yutaro Yamada, and Sahand Negahban · 2015
Earlier work this paper cites.
Deep residual learning for image recognition
Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun · 2016
Earlier work this paper cites.
Deepfool: a simple and accurate method to fool deep neural networks
Seyed-Mohsen Moosavi-Dezfooli, Alhussein Fawzi, and Pascal Frossard · 2016
Earlier work this paper cites.
Multiclass classification calibration functions
Bernardo Ávila Pires and Csaba Szepesvári · 2016
Earlier work this paper cites.
Exploring the space of adversarial images
Pedro Tabacof and Eduardo Valle · 2016
Earlier work this paper cites.
Wide residual networks
Sergey Zagoruyko and Nikos Komodakis · 2016
Earlier work this paper cites.
Improving the robustness of deep neural networks via stability training
Stephan Zheng, Yang Song, Thomas Leung, and Ian Goodfellow · 2016
Earlier work this paper cites.
Parseval networks: Improving robustness to adversarial examples
Moustapha Cisse, Piotr Bojanowski, Edouard Grave, Yann Dauphin, and Nicolas Usunier · 2017
Earlier work this paper cites.
Towards evaluating the robustness of neural networks
Nicholas Carlini and David Wagner · 2017
Earlier work this paper cites.
A rotation and a translation suffice: Fooling CNNs with simple transformations
Logan Engstrom, Brandon Tran, Dimitris Tsipras, Ludwig Schmidt, and Aleksander Madry · 2017
Earlier work this paper cites.
Adversarial attacks on neural network policies
Sandy Huang, Nicolas Papernot, Ian Goodfellow, Yan Duan, and Pieter Abbeel · 2017
Earlier work this paper cites.
Adversarial example defenses: Ensembles of weak defenses are not strong
Warren He, James Wei, Xinyun Chen, Nicholas Carlini, and Dawn Song · 2017
Earlier work this paper cites.
Adversarial examples for evaluating reading comprehension systems
Robin Jia and Percy Liang · 2017
Earlier work this paper cites.
Adversarial machine learning at scale
Alexey Kurakin, Ian Goodfellow, and Samy Bengio · 2017
Earlier work this paper cites.
Magnet: a two-pronged defense against adversarial examples
Dongyu Meng and Hao Chen · 2017
Earlier work this paper cites.
Cascade adversarial machine learning regularized with a unified embedding
Taesik Na, Jong Hwan Ko, and Saibal Mukhopadhyay · 2017
Earlier work this paper cites.
Foolbox v0. 8.0: A python toolbox to benchmark the robustness of machine learning models
Jonas Rauber, Wieland Brendel, and Matthias Bethge · 2017
Cited alongside, same era.
Andrew Slavin Ross and Finale Doshi-Velez · 2017
Cited alongside, same era.
Adversarial examples for semantic segmentation and object detection
Cihang Xie, Jianyu Wang, Zhishuai Zhang, Yuyin Zhou, Lingxi Xie, and Alan Yuille · 2017
Cited alongside, same era.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
Anish Athalye, Nicholas Carlini, and David Wagner · 2018
Cited alongside, same era.
Unrestricted adversarial examples
Tom B Brown, Nicholas Carlini, Chiyuan Zhang, Catherine Olsson, Paul Christiano, and Ian Goodfellow · 2018
Defense-gan: Protecting classifiers against adversarial attacks using generative models
Pouya Samangouei, Maya Kabkab, and Rama Chellappa · 2018
Later among the works it cites.
Pixeldefend: Leveraging generative models to understand and defend against adversarial examples
Yang Song, Taesup Kim, Sebastian Nowozin, Stefano Ermon, and Nate Kushman · 2018
Later among the works it cites.
Certifiable distributional robustness with principled adversarial training
Aman Sinha, Hongseok Namkoong, and John Duchi · 2018
Later among the works it cites.
Adversarially robust generalization requires more data
Ludwig Schmidt, Shibani Santurkar, Dimitris Tsipras, Kunal Talwar, and Aleksander Mądry · 2018
Later among the works it cites.
Is robustness the cost of accuracy? — a comprehensive study on the robustness of 18 deep image classification models
Dong Su, Huan Zhang, Hongge Chen, Jinfeng Yi, Pin-Yu Chen, and Yupeng Gao · 2018
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Cited alongside, same era.
Adversarial examples from cryptographic pseudo-random generators
Sébastien Bubeck, Yin Tat Lee, Eric Price, and Ilya Razenshteyn · 2018
Cited alongside, same era.
Adversarial examples from computational constraints
Sébastien Bubeck, Eric Price, and Ilya Razenshteyn · 2018
Cited alongside, same era.
Decision-based adversarial attacks: Reliable attacks against black-box machine learning models
Wieland Brendel, Jonas Rauber, and Matthias Bethge · 2018
Cited alongside, same era.
Thermometer encoding: One hot way to resist adversarial examples
Jacob Buckman, Aurko Roy, Colin Raffel, and Ian Goodfellow · 2018
Cited alongside, same era.
PAC-learning in the presence of adversaries
Daniel Cullina, Arjun Nitin Bhagoji, and Prateek Mittal · 2018
Cited alongside, same era.
Stochastic activation pruning for robust adversarial defense
Guneet S Dhillon, Kamyar Azizzadenesheli, Zachary C Lipton, Jeremy Bernstein, Jean Kossaifi, Aran Khanna, and Anima Anandkumar · 2018
Cited alongside, same era.
Boosting adversarial attacks with momentum
Yinpeng Dong, Fangzhou Liao, Tianyu Pang, Hang Su, Jun Zhu, Xiaolin Hu, and Jianguo Li · 2018
Cited alongside, same era.
Ensemble adversarial training: Attacks and defenses
Florian Tramèr, Alexey Kurakin, Nicolas Papernot, Ian Goodfellow, Dan Boneh, and Patrick McDaniel · 2018
Later among the works it cites.
Adversarial risk and the dangers of evaluating against weak attacks
Jonathan Uesato, Brendan O’Donoghue, Pushmeet Kohli, and Aaron van den Oord · 2018
Later among the works it cites.
Generalizing to unseen domains via adversarial data augmentation
Riccardo Volpi, Hongseok Namkoong, Ozan Sener, John C Duchi, Vittorio Murino, and Silvio Savarese · 2018
Later among the works it cites.
Scaling provable adversarial defenses
E Wong, F Schmidt, JH Metzen, and JZ Kolter · 2018
Later among the works it cites.
Feature denoising for improving adversarial robustness
Cihang Xie, Yuxin Wu, Laurens van der Maaten, Alan Yuille, and Kaiming He · 2018
Later among the works it cites.
Spatially transformed adversarial examples
Chaowei Xiao, Jun-Yan Zhu, Bo Li, Warren He, Mingyan Liu, and Dawn Song · 2018
Later among the works it cites.
Rademacher complexity for adversarially robust generalization
Dong Yin, Kannan Ramchandran, and Peter Bartlett · 2018
Later among the works it cites.
Stackelberg GAN: Towards provable minimax equilibrium via multi-generator architectures
Hongyang Zhang, Susu Xu, Jiantao Jiao, Pengtao Xie, Ruslan Salakhutdinov, and Eric P Xing · 2018
Later among the works it cites.
ADef: an iterative algorithm to construct adversarial deformations
Rima Alaifari, Giovanni S Alberti, and Tandri Gauksson · 2019
Closest in time.
Unlabeled data improves adversarial robustness
Yair Carmon, Aditi Raghunathan, Ludwig Schmidt, Percy Liang, and John C Duchi · 2019
Closest in time.
Are labels required for improving adversarial robustness?
Robert Stanforth, Alhussein Fawzi, Pushmeet Kohli, et al · 2019
Closest in time.
Adversarial training for free!
Ali Shafahi, Mahyar Najibi, Amin Ghiasi, Zheng Xu, John Dickerson, Christoph Studer, Larry S Davis, Gavin Taylor, and Tom Goldstein · 2019
Closest in time.
Robustness may be at odds with accuracy
Dimitris Tsipras, Shibani Santurkar, Logan Engstrom, Alexander Turner, and Aleksander Madry · 2019
Closest in time.
Adversarially robust generalization just requires more unlabeled data
Runtian Zhai, Tianle Cai, Di He, Chen Dan, Kun He, John Hopcroft, and Liwei Wang · 2019
Closest in time.
The limitations of adversarial training and the blind-spot attack
Huan Zhang, Hongge Chen, Zhao Song, Duane Boning, Inderjit S Dhillon, and Cho-Jui Hsieh · 2019
Closest in time.
Deep neural networks with multi-branch architectures are intrinsically less non-convex
Hongyang Zhang, Junru Shao, and Ruslan Salakhutdinov · 2019
Closest in time.
You only propagate once: Accelerating adversarial training via maximal principle
Dinghuai Zhang, Tianyuan Zhang, Yiping Lu, Zhanxing Zhu, and Bin Dong · 2019
Closest in time.