Fetching the paper…
Reading the bibliography…
Recent work has uncovered the interesting (and somewhat surprising) finding that training models to be invariant to adversarial perturbations requires substantially larger datasets than those required for standard classification.
Wordnet: a lexical database for english
G. A. Miller · 1995
Earlier work this paper cites.
Combining labeled and unlabeled data with co-training
A. Blum and T. Mitchell · 1998
Earlier work this paper cites.
Adaptive estimation of a quadratic functional by model selection
B. Laurent and P. Massart · 2000
Earlier work this paper cites.
Modeling the shape of the scene: A holistic representation of the spatial envelope
A. Oliva and A. Torralba · 2001
Earlier work this paper cites.
80 million tiny images: a large dataset for non-parametric object and scene recognition
A. Torralba, R. Fergus, and W. T. Freeman · 2008
Earlier work this paper cites.
Semi-Supervised Learning
O. Chapelle, B. Scholkopf, and A. Zien · 2009
Earlier work this paper cites.
Evaluation of gist descriptors for web-scale image search
M. Douze, H. Jégou, H. Sandhawalia, L. Amsaleg, and C. Schmid · 2009
Earlier work this paper cites.
Learning multiple layers of features from tiny images
A. Krizhevsky and G. Hinton · 2009
Earlier work this paper cites.
Evasion attacks against machine learning at test time
B. Biggio, I. Corona, D. Maiorca, B. Nelson, N. Šrndić, P. Laskov, G. Giacinto, and F. Roli · 2013
Earlier work this paper cites.
Learning deep structured semantic models for web search using clickthrough data
P.-S. Huang, X. He, J. Gao, L. Deng, A. Acero, and L. Heck · 2013
Earlier work this paper cites.
Learning with pseudo-ensembles
P. Bachman, O. Alsharif, and D. Precup · 2014
Earlier work this paper cites.
Explaining and harnessing adversarial examples
I. J. Goodfellow, J. Shlens, and C. Szegedy · 2014
Earlier work this paper cites.
Towards deep neural network architectures robust to adversarial examples
S. Gu and L. Rigazio · 2014
Earlier work this paper cites.
Adam: A method for stochastic optimization
D. P. Kingma and J. Ba · 2014
Earlier work this paper cites.
Intriguing properties of neural networks
C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, and R. Fergus · 2014
Earlier work this paper cites.
End to end learning for self-driving cars
M. Bojarski, D. D. Testa, D. Dworakowski, B. Firner, B. Flepp, P. Goyal, L. D. Jackel, M. Monfort, U. Muller, J. Zhang, X. Zhang, J. Zhao, and K. Zieba · 2016
Earlier work this paper cites.
Deep neural networks for Youtube recommendations
P. Covington, J. Adams, and E. Sargin · 2016
Earlier work this paper cites.
Delving into transferable adversarial examples and black-box attacks
Y. Liu, X. Chen, C. Liu, and D. Song · 2016
Earlier work this paper cites.
Regularization with stochastic transformations and perturbations for deep semi-supervised learning
M. Sajjadi, M. Javanmardi, and T. Tasdizen · 2016
Earlier work this paper cites.
Instance normalization: The missing ingredient for fast stylization
D. Ulyanov, A. Vedaldi, and V. Lempitsky · 2016
Cited alongside, same era.
S. Zagoruyko and N. Komodakis · 2016
Cited alongside, same era.
Improving the Robustness of Deep Neural Networks via Stability Training
S. Zheng, Y. Song, T. Leung, and I. Goodfellow · 2016
Cited alongside, same era.
Adversarial examples are not easily detected: Bypassing ten detection methods
N. Carlini and D. Wagner · 2017
Cited alongside, same era.
Towards evaluating the robustness of neural networks
N. Carlini and D. Wagner · 2017
Cited alongside, same era.
Adversarial Machine Learning at Scale
Virtual Adversarial Training: A Regularization Method for Supervised and Semi-Supervised Learning
T. Miyato, S. ichi Maeda, M. Koyama, and S. Ishii · 2018
Later among the works it cites.
Realistic Evaluation of Deep Semi-Supervised Learning Algorithms
A. Oliver, A. Odena, C. Raffel, E. D. Cubuk, and I. J. Goodfellow · 2018
Later among the works it cites.
Defense-gan: Protecting classifiers against adversarial attacks using generative models
P. Samangouei, M. Kabkab, and R. Chellappa · 2018
Later among the works it cites.
Adversarially Robust Generalization Requires More Data
L. Schmidt, S. Santurkar, D. Tsipras, K. Talwar, and A. Madry · 2018
Later among the works it cites.
Adversarial risk and the dangers of evaluating against weak attacks
J. Uesato, B. O’Donoghue, A. v. d. Oord, and P. Kohli · 2018
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
A. Kurakin, I. Goodfellow, and S. Bengio · 2017
Cited alongside, same era.
Temporal ensembling for semi-supervised learnings
S. Laine and T. Aila · 2017
Cited alongside, same era.
Making deep neural networks robust to label noise: a loss correction approach
G. Patrini, A. Rozza, A. Menon, R. Nock, and L. Qu · 2017
Cited alongside, same era.
Deep learning is robust to massive label noise
D. Rolnick, A. Veit, S. J. Belongie, and N. Shavit · 2017
Cited alongside, same era.
Pixeldefend: Leveraging generative models to understand and defend against adversarial examples
Y. Song, T. Kim, S. Nowozin, S. Ermon, and N. Kushman · 2017
Cited alongside, same era.
Ensemble adversarial training: Attacks and defenses
F. Tramèr, A. Kurakin, N. Papernot, I. Goodfellow, D. Boneh, and P. McDaniel · 2017
Cited alongside, same era.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
A. Athalye, N. Carlini, and D. Wagner · 2018
Cited alongside, same era.
E. Wong, F. R. Schmidt, J. H. Metzen, and J. Z. Kolter · 2018
Later among the works it cites.
Group normalization
Y. Wu and K. He · 2018
Later among the works it cites.
Rademacher complexity for adversarially robust generalization
D. Yin, K. Ramchandran, and P. Bartlett · 2018
Later among the works it cites.
MixMatch: A Holistic Approach to Semi-Supervised Learning
D. Berthelot, N. Carlini, I. Goodfellow, N. Papernot, A. Oliver, and C. Raffel · 2019
Closest in time.
Unlabeled Data Improves Adversarial Robustness
Y. Carmon, A. Raghunathan, L. Schmidt, P. Liang, and J. C. Duchi · 2019
Closest in time.
Adversarial attacks on medical machine learning
S. G. Finlayson, J. D. Bowers, J. Ito, J. L. Zittrain, A. L. Beam, and I. S. Kohane · 2019
Closest in time.
An alternative surrogate loss for pgd-based adversarial testing
S. Gowal, J. Uesato, C. Qin, P.-S. Huang, T. Mann, and P. Kohli · 2019
Closest in time.
Using pre-training can improve model robustness and uncertainty
D. Hendrycks, K. Lee, and M. Mazeika · 2019
Closest in time.
Robustness to Adversarial Perturbations in Learning from Incomplete Data
A. Najafi, S.-i. Maeda, M. Koyama, and T. Miyato · 2019
Closest in time.
Semi supervised learning with scarce annotations
S.-A. Rebuffi, S. Ehrhardt, K. Han, A. Vedaldi, and A. Zisserman · 2019
Closest in time.
Unsupervised Data Augmentation
Q. Xie, Z. Dai, E. Hovy, M.-T. Luong, and Q. V. Le · 2019
Closest in time.
Adversarially Robust Generalization Just Requires More Unlabeled Data
R. Zhai, T. Cai, D. He, C. Dan, K. He, J. Hopcroft, and L. Wang · 2019
Closest in time.
Theoretically Principled Trade-off between Robustness and Accuracy
H. Zhang, Y. Yu, J. Jiao, E. P. Xing, L. E. Ghaoui, and M. I. Jordan · 2019
Closest in time.