Fetching the paper…
Reading the bibliography…
The worst-case training principle that minimizes the maximal adversarial loss, also known as adversarial training (AT), has shown to be a state-of-the-art approach for enhancing adversarial robustness.
Gradient-based learning applied to document recognition
Y. Lecun, L. Bottou, Y. Bengio, and P. Haffner · 1998
Earlier work this paper cites.
Convex optimization
S. Boyd and L. Vandenberghe · 2004
Earlier work this paper cites.
Intriguing properties of neural networks
C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, and R. Fergus · 2013
Earlier work this paper cites.
Explaining and harnessing adversarial examples
I. J. Goodfellow, J. Shlens, and C. Szegedy · 2014
Earlier work this paper cites.
Proximal algorithms
N. Parikh, S. Boyd, et al · 2014
Earlier work this paper cites.
Explaining and harnessing adversarial examples
I. Goodfellow, J. Shlens, and C. Szegedy · 2015
Earlier work this paper cites.
Very deep convolutional networks for large-scale image recognition
K. Simonyan and A. Zisserman · 2015
Earlier work this paper cites.
Striving for simplicity: The all convolutional net
J. T. Springenberg, A. Dosovitskiy, T. Brox, and M. A. Riedmiller · 2015
Earlier work this paper cites.
Going deeper with convolutions
C. Szegedy, W. Liu, Y. Jia, P. Sermanet, S. E. Reed, D. Anguelov, D. Erhan, V. Vanhoucke, and A. Rabinovich · 2015
Earlier work this paper cites.
Hidden voice commands
N. Carlini, P. Mishra, T. Vaidya, Y. Zhang, M. Sherr, C. Shields, D. Wagner, and W. Zhou · 2016
Earlier work this paper cites.
Deep residual learning for image recognition
K. He, X. Zhang, S. Ren, and J. Sun · 2016
Earlier work this paper cites.
Linear convergence of gradient and proximal-gradient methods under the polyak-łojasiewicz condition
H. Karimi, J. Nutini, and M. Schmidt · 2016
Earlier work this paper cites.
Deepfool: a simple and accurate method to fool deep neural networks
S. M. Moosavi Dezfooli, A. Fawzi, and P. Frossard · 2016
Earlier work this paper cites.
The limitations of deep learning in adversarial settings
N. Papernot, P. McDaniel, S. Jha, M. Fredrikson, Z. B. Celik, and A. Swami · 2016
Earlier work this paper cites.
Wide residual networks
S. Zagoruyko and N. Komodakis · 2016
Earlier work this paper cites.
Decision-based adversarial attacks: Reliable attacks against black-box machine learning models
W. Brendel, J. Rauber, and M. Bethge · 2017
Earlier work this paper cites.
T. B. Brown, D. Mané, A. Roy, M. Abadi, and J. Gilmer · 2017
Earlier work this paper cites.
Towards evaluating the robustness of neural networks
N. Carlini and D. Wagner · 2017
Earlier work this paper cites.
Formal guarantees on the robustness of a classifier against adversarial manipulation
M. Hein and M. Andriushchenko · 2017
Earlier work this paper cites.
Adversarial attacks on neural network policies
S. Huang, N. Papernot, I. J. Goodfellow, Y. Duan, and P. Abbeel · 2017
Earlier work this paper cites.
Adversarial examples for evaluating reading comprehension systems
R. Jia and P. Liang · 2017
Earlier work this paper cites.
Tactics of adversarial attack on deep reinforcement learning agents
Y. Lin, Z. Hong, Y. Liao, M. Shih, M. Liu, and M. Sun · 2017
Earlier work this paper cites.
Delving into transferable adversarial examples and black-box attacks
Y. Liu, X. Chen, C. Liu, and D. Song · 2017
Earlier work this paper cites.
Towards deep learning models resistant to adversarial attacks
A. Madry, A. Makelov, L. Schmidt, D. Tsipras, and A. Vladu · 2017
Earlier work this paper cites.
Magnet: a two-pronged defense against adversarial examples
D. Meng and H. Chen · 2017
Earlier work this paper cites.
Universal adversarial perturbations against semantic image segmentation
J. H. Metzen, M. C. Kumar, T. Brox, and V. Fischer · 2017
Earlier work this paper cites.
Universal adversarial perturbations
S.-M. Moosavi-Dezfooli, A. Fawzi, O. Fawzi, and P. Frossard · 2017
Cited alongside, same era.
Practical black-box attacks against machine learning
N. Papernot, P. McDaniel, I. Goodfellow, S. Jha, Z. B. Celik, and A. Swami · 2017
Cited alongside, same era.
Foolbox v0.8.0: A python toolbox to benchmark the robustness of machine learning models
J. Rauber, W. Brendel, and M. Bethge · 2017
Cited alongside, same era.
The space of transferable adversarial examples
F. Tramèr, N. Papernot, I. Goodfellow, D. Boneh, and P. McDaniel · 2017
Cited alongside, same era.
Mitigating adversarial effects through randomization
C. Xie, J. Wang, Z. Zhang, Z. Ren, and A. Yuille · 2017
Cited alongside, same era.
Generating natural adversarial examples
Z. Zhao, D. Dua, and S. Singh · 2018
Later among the works it cites.
Robust neural networks using randomized adversarial training
A. Araujo, R. Pinot, B. Negrevergne, L. Meunier, Y. Chevaleyre, F. Yger, and J. Atif · 2019
Closest in time.
On evaluating adversarial robustness
N. Carlini, A. Athalye, N. Papernot, W. Brendel, J. Rauber, D. Tsipras, I. J. Goodfellow, A. Madry, and A. Kurakin · 2019
Closest in time.
Certified adversarial robustness via randomized smoothing
J. M. Cohen, E. Rosenfeld, and J. Z. Kolter · 2019
Closest in time.
Provable robustness against all adversarial l p l_{p} -perturbations for p ≥ 1 p\geq 1
F. Croce and M. Hein · 2019
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
A. Athalye, N. Carlini, and D. Wagner · 2018
Cited alongside, same era.
Synthesizing robust adversarial examples
A. Athalye, L. Engstrom, A. Ilyas, and K. Kwok · 2018
Cited alongside, same era.
Synthesizing robust adversarial examples
A. Athalye, L. Engstrom, A. Ilyas, and K. Kwok · 2018
Cited alongside, same era.
Synthesizing robust adversarial examples
A. Athalye and I. Sutskever · 2018
Cited alongside, same era.
Audio adversarial examples: Targeted attacks on speech-to-text
N. Carlini and D. A. Wagner · 2018
Cited alongside, same era.
Attacking visual language grounding with adversarial examples: A case study on neural image captioning
H. Chen, H. Zhang, P.-Y. Chen, J. Yi, and C.-J. Hsieh · 2018
Cited alongside, same era.
Boosting adversarial attacks with momentum
Y. Dong, F. Liao, T. Pang, H. Su, J. Zhu, X. Hu, and J. Li · 2018
Cited alongside, same era.
Closest in time.
Testing robustness against unforeseen adversaries
D. Kang, Y. Sun, D. Hendrycks, T. Brown, and J. Steinhardt · 2019
Closest in time.
Discrete adversarial attacks and submodular optimization with applications to text classification
Q. Lei, L. Wu, P.-Y. Chen, A. G. Dimakis, I. S. Dhillon, and M. Witbrock · 2019
Closest in time.
Min-max optimization without gradients: Convergence and applications to adversarial ML
S. Liu, S. Lu, X. Chen, Y. Feng, K. Xu, A. Al-Dujaili, M. Hong, and U. Obelilly · 2019
Closest in time.
Understand the dynamics of GANs via primal-dual optimization, 2019
S. Lu, R. Singh, X. Chen, Y. Chen, and M. Hong · 2019
Closest in time.
Block alternating optimization for non-convex min-max problems: algorithms and applications in signal processing and communications
S. Lu, I. Tsaknakis, and M. Hong · 2019
Closest in time.
Solving a class of non-convex min-max games using iterative first order methods
M. Nouiehed, M. Sanjabi, J. D. Lee, and M. Razaviyayn · 2019
Closest in time.
Decoupling direction and norm for efficient gradient-based L2 adversarial attacks and defenses
J. Rony, L. G. Hafemann, L. S. Oliveira, I. B. Ayed, R. Sabourin, and E. Granger · 2019
Closest in time.
Towards the first adversarially robust neural network model on MNIST
L. Schott, J. Rauber, M. Bethge, and W. Brendel · 2019
Closest in time.
Adversarial training and robustness for multiple perturbations
F. Tramèr and D. Boneh · 2019
Closest in time.
Structured adversarial attack: Towards general implementation and better interpretability
K. Xu, S. Liu, P. Zhao, P.-Y. Chen, H. Zhang, Q. Fan, D. Erdogmus, Y. Wang, and X. Lin · 2019
Closest in time.
Theoretically principled trade-off between robustness and accuracy
H. Zhang, Y. Yu, J. Jiao, E. P. Xing, L. E. Ghaoui, and M. I. Jordan · 2019
Closest in time.
Square attack: A query-efficient black-box adversarial attack via random search
M. Andriushchenko, F. Croce, N. Flammarion, and M. Hein · 2020
Closest in time.
Adversarial example games
A. J. Bose, G. Gidel, H. Berard, A. Cianflone, P. Vincent, S. Lacoste-Julien, and W. L. Hamilton · 2020
Closest in time.
Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks
F. Croce and M. Hein · 2020
Closest in time.
On gradient descent ascent for nonconvex-concave minimax problems
T. Lin, C. Jin, and M. I. Jordan · 2020
Closest in time.
Adversarial robustness against the union of multiple perturbation models
P. Maini, E. Wong, and J. Z. Kolter · 2020
Closest in time.
Overfitting in adversarially robust deep learning
L. Rice, E. Wong, and J. Z. Kolter · 2020
Closest in time.
Fast is better than free: Revisiting adversarial training
E. Wong, L. Rice, and J. Z. Kolter · 2020
Closest in time.
Adversarial t-shirt! evading person detectors in a physical world
K. Xu, G. Zhang, S. Liu, Q. Fan, M. Sun, H. Chen, P. Chen, Y. Wang, and X. Lin · 2020
Closest in time.
Provably robust classification of adversarial examples with detection
F. Sheikholeslami, A. Lotfi, and J. Z. Kolter · 2021
Closest in time.