Fetching the paper…
Reading the bibliography…
Many recent works have shown that adversarial examples that fool classifiers can be found by minimally perturbing a normal input.
Problèmes concrets d’analyse fonctionnelle , volume 6
Paul Lévy · 1951
Earlier work this paper cites.
A K-means clustering algorithm
John A Hartigan and Manchek A Wong · 1979
Earlier work this paper cites.
Asymptotic theory of finite dimensional normed spaces
Vitali D Milman and Gideon Schechtman · 1986
Earlier work this paper cites.
Five balltree construction algorithms
Stephen M Omohundro · 1989
Earlier work this paper cites.
Concentration of measure and isoperimetric inequalities in product spaces
Michel Talagrand · 1995
Earlier work this paper cites.
The Concentration of Measure Phenomenon
Michel Ledoux · 2001
Earlier work this paper cites.
Learning minimum volume sets
Clayton D Scott and Robert D Nowak · 2006
Earlier work this paper cites.
The VC dimension of k-fold union
David Eisenstat and Dana Angluin · 2007
Earlier work this paper cites.
Learning multiple layers of features from tiny images
Alex Krizhevsky and Geoffrey Hinton · 2009
Earlier work this paper cites.
MNIST handwritten digit database
Yann LeCun, Corinna Cortes, and CJ Burges · 2010
Earlier work this paper cites.
Reading digits in natural images with unsupervised feature learning
Yuval Netzer, Tao Wang, Adam Coates, Alessandro Bissacco, Bo Wu, and Andrew Y Ng · 2011
Earlier work this paper cites.
Scikit-learn: Machine learning in Python
Fabian Pedregosa, Gaël Varoquaux, Alexandre Gramfort, Vincent Michel, Bertrand Thirion, Olivier Grisel, Mathieu Blondel, Andreas Müller, Joel Nothman, Gilles Louppe, Peter Prettenhofer, Ron Weiss, Vincent Dubourg, Jake Vanderplas, Alexandre Passos, David Cournapeau, Matthieu Brucher, Matthieu Perrot, and Édouard Duchesnay · 2011
Earlier work this paper cites.
A Probabilistic Theory of Pattern Recognition
Luc Devroye, László Györfi, and Gábor Lugosi · 2013
Earlier work this paper cites.
Intriguing properties of neural networks
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus · 2014
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Ian Goodfellow, Jonathon Shlens, and Christian Szegedy · 2015
Cited alongside, same era.
Distillation as a defense to adversarial perturbations against deep neural networks
Nicolas Papernot, Patrick McDaniel, Xi Wu, Somesh Jha, and Ananthram Swami · 2016
Cited alongside, same era.
Towards evaluating the robustness of neural networks
Nicholas Carlini and David Wagner · 2017
Cited alongside, same era.
Exploring generalization in deep learning
Behnam Neyshabur, Srinadh Bhojanapalli, David McAllester, and Nati Srebro · 2017
Cited alongside, same era.
Fashion-MNIST: a novel image dataset for benchmarking machine learning algorithms
Han Xiao, Kashif Rasul, and Roland Vollgraf · 2017
Cited alongside, same era.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
Provable defenses against adversarial examples via the convex outer adversarial polytope
Eric Wong and Zico Kolter · 2018
Later among the works it cites.
Scaling provable adversarial defenses
Eric Wong, Frank R Schmidt, Jan Hendrik Metzen, and Zico Kolter · 2018
Later among the works it cites.
Improved generalization bounds for robust learning
Idan Attias, Aryeh Kontorovich, and Yishay Mansour · 2019
Closest in time.
Lower bounds on adversarial robustness from optimal transport
Arjun Nitin Bhagoji, Daniel Cullina, and Prateek Mittal · 2019
Closest in time.
Scalable verified training for provably robust image classification
Sven Gowal, Krishnamurthy Dvijotham, Robert Stanforth, Rudy Bunel, Chongli Qin, Jonathan Uesato, Relja Arandjelovic, Timothy Mann, and Pushmeet Kohli · 2019
Closest in time.
Understanding the (un)interpretability of natural image distributions using generative models
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Anish Athalye, Nicholas Carlini, and David Wagner · 2018
Cited alongside, same era.
Wild patterns: Ten years after the rise of adversarial machine learning
Battista Biggio and Fabio Roli · 2018
Cited alongside, same era.
PAC-learning in the presence of adversaries
Daniel Cullina, Arjun Nitin Bhagoji, and Prateek Mittal · 2018
Cited alongside, same era.
Adversarial risk and robustness: General definitions and implications for the uniform distribution
Dimitrios Diochnos, Saeed Mahloujifar, and Mohammad Mahmoody · 2018
Cited alongside, same era.
Adversarial vulnerability for any classifier
Alhussein Fawzi, Hamza Fawzi, and Omar Fawzi · 2018
Cited alongside, same era.
Towards deep learning models resistant to adversarial attacks
Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu · 2018
Cited alongside, same era.
Certified defenses against adversarial examples
Aditi Raghunathan, Jacob Steinhardt, and Percy Liang · 2018
Cited alongside, same era.
Ryen Krusinga, Sohil Shah, Matthias Zwicker, Tom Goldstein, and David Jacobs · 2019
Closest in time.
The curse of concentration in robust learning: Evasion and poisoning attacks from concentration of measure
Saeed Mahloujifar, Dimitrios I Diochnos, and Mohammad Mahmoody · 2019
Closest in time.
VC classes are adversarially robustly learnable, but only improperly
Omar Montasser, Steve Hanneke, and Nathan Srebro · 2019
Closest in time.
Adversarial training can hurt generalization
Aditi Raghunathan, Sang Michael Xie, Fanny Yang, John C Duchi, and Percy Liang · 2019
Closest in time.
Towards the first adversarially robust neural network model on MNIST
Lukas Schott, Jonas Rauber, Matthias Bethge, and Wieland Brendel · 2019
Closest in time.
Are adversarial examples inevitable?
Ali Shafahi, W. Ronny Huang, Christoph Studer, Soheil Feizi, and Tom Goldstein · 2019
Closest in time.
Robustness may be at odds with accuracy
Dimitris Tsipras, Shibani Santurkar, Logan Engstrom, Alexander Turner, and Aleksander Madry · 2019
Closest in time.
Rademacher complexity for adversarially robust generalization
Dong Yin, Ramchandran Kannan, and Peter Bartlett · 2019
Closest in time.
Towards stable and efficient training of verifiably robust neural networks
Huan Zhang, Hongge Chen, Chaowei Xiao, Bo Li, Duane Boning, and Cho-Jui Hsieh · 2019
Closest in time.